From 8de4a55800786e343379e3ebdc52cfc5b162d95a Mon Sep 17 00:00:00 2001 From: d1vious Date: Tue, 16 Aug 2022 15:22:32 -0400 Subject: [PATCH 1/3] removing docs --- docs/Gemfile | 22 - docs/Gemfile.lock | 325 - docs/README.md | 58 - docs/_config.yml | 170 - docs/_data/navigation.yml | 116 - .../_includes/analytics-providers/custom.html | 3 - .../analytics-providers/google-gtag.html | 9 - .../analytics-providers/google-universal.html | 7 - .../_includes/analytics-providers/google.html | 14 - docs/_includes/analytics.html | 14 - docs/_includes/archive-single.html | 30 - .../author-profile-custom-links.html | 7 - docs/_includes/author-profile.html | 246 - docs/_includes/breadcrumbs.html | 40 - docs/_includes/browser-upgrade.html | 3 - docs/_includes/category-list.html | 19 - docs/_includes/comment.html | 22 - docs/_includes/comments-providers/custom.html | 3 - .../comments-providers/custom_scripts.html | 3 - .../comments-providers/discourse.html | 13 - docs/_includes/comments-providers/disqus.html | 15 - .../comments-providers/facebook.html | 8 - docs/_includes/comments-providers/giscus.html | 24 - .../_includes/comments-providers/scripts.html | 20 - .../comments-providers/staticman.html | 40 - .../comments-providers/staticman_v2.html | 40 - .../comments-providers/utterances.html | 21 - docs/_includes/comments.html | 180 - docs/_includes/documents-collection.html | 15 - docs/_includes/feature_row | 41 - docs/_includes/figure | 9 - docs/_includes/footer.html | 21 - docs/_includes/footer/custom.html | 3 - docs/_includes/gallery | 35 - docs/_includes/group-by-array | 47 - docs/_includes/head.html | 25 - docs/_includes/head/custom.html | 5 - docs/_includes/masthead.html | 35 - docs/_includes/nav_list | 26 - docs/_includes/page__date.html | 6 - docs/_includes/page__hero.html | 55 - docs/_includes/page__hero_video.html | 2 - docs/_includes/page__meta.html | 31 - docs/_includes/page__taxonomy.html | 7 - docs/_includes/paginator.html | 69 - docs/_includes/post_pagination.html | 14 - docs/_includes/posts-category.html | 5 - docs/_includes/posts-tag.html | 5 - docs/_includes/scripts.html | 28 - .../search/algolia-search-scripts.html | 61 - .../search/google-search-scripts.html | 30 - .../_includes/search/lunr-search-scripts.html | 10 - docs/_includes/search/search_form.html | 26 - docs/_includes/seo.html | 158 - docs/_includes/sidebar.html | 19 - docs/_includes/skip-links.html | 7 - docs/_includes/social-share.html | 11 - docs/_includes/tag-list.html | 19 - docs/_includes/toc | 7 - docs/_includes/toc.html | 182 - docs/_includes/video | 24 - docs/_layouts/archive-taxonomy.html | 29 - docs/_layouts/archive.html | 26 - docs/_layouts/categories.html | 43 - docs/_layouts/category.html | 10 - docs/_layouts/collection.html | 10 - docs/_layouts/compress.html | 10 - docs/_layouts/default.html | 42 - docs/_layouts/home.html | 22 - docs/_layouts/posts.html | 30 - docs/_layouts/search.html | 42 - docs/_layouts/single.html | 91 - docs/_layouts/splash.html | 22 - docs/_layouts/tag.html | 10 - docs/_layouts/tags.html | 43 - docs/_pages/404.md | 8 - docs/_pages/about.md | 10 - docs/_pages/abuse.md | 9 - docs/_pages/account_compromise.md | 9 - docs/_pages/adversary_tactics.md | 9 - docs/_pages/authentication.md | 9 - docs/_pages/best_practices.md | 9 - docs/_pages/certificates.md | 9 - docs/_pages/change.md | 9 - docs/_pages/change_analysis.md | 9 - docs/_pages/cloud_security.md | 9 - docs/_pages/collection.md | 9 - docs/_pages/command_and_control.md | 9 - docs/_pages/credential_access.md | 9 - docs/_pages/data_destruction.md | 9 - docs/_pages/defense_evasion.md | 9 - docs/_pages/detections.md | 977 - docs/_pages/discovery.md | 9 - docs/_pages/email.md | 9 - docs/_pages/endpoint.md | 9 - docs/_pages/endpoint_filesystem.md | 9 - docs/_pages/endpoint_processes.md | 9 - docs/_pages/endpoint_registry.md | 9 - docs/_pages/execution.md | 9 - docs/_pages/exfiltration.md | 9 - docs/_pages/impact.md | 9 - docs/_pages/initial_access.md | 9 - docs/_pages/lateral_movement.md | 9 - docs/_pages/malware.md | 9 - docs/_pages/network_resolution.md | 9 - docs/_pages/network_sessions.md | 9 - docs/_pages/network_traffic.md | 9 - docs/_pages/ooo.md | 8 - docs/_pages/paybooks.md | 43 - docs/_pages/persistence.md | 9 - docs/_pages/playbooks.md | 43 - docs/_pages/privilege_escalation.md | 9 - docs/_pages/ransomware.md | 9 - docs/_pages/reconnaissance.md | 9 - docs/_pages/resource_development.md | 9 - docs/_pages/risk.md | 9 - docs/_pages/splunk_audit.md | 9 - docs/_pages/splunk_behavioral_analytics.md | 9 - docs/_pages/splunk_enterprise_security.md | 9 - .../splunk_security_analytics_for_aws.md | 9 - docs/_pages/stories.md | 162 - docs/_pages/tag-archive.md | 6 - docs/_pages/ueba.md | 9 - docs/_pages/unauthorized_software.md | 9 - docs/_pages/updates.md | 9 - docs/_pages/vulnerabilities.md | 9 - docs/_pages/vulnerability.md | 9 - docs/_pages/web.md | 9 - .../active_directory_reset_password.md | 41 - docs/_playbooks/aws_disable_user_accounts.md | 45 - docs/_playbooks/aws_find_inactive_users.md | 46 - docs/_playbooks/block_indicators.md | 43 - docs/_playbooks/crowdstrike_malware_triage.md | 41 - docs/_playbooks/delete_detected_files.md | 44 - .../email_notification_for_malware.md | 44 - .../internal_host_ssh_investigate.md | 44 - .../internal_host_ssh_log4j_investigate.md | 44 - .../internal_host_ssh_log4j_respond.md | 44 - .../internal_host_ssh_log4j_response.md | 44 - .../internal_host_winrm_investigate.md | 41 - .../internal_host_winrm_log4j_investigate.md | 44 - .../internal_host_winrm_response.md | 41 - docs/_playbooks/log4j_investigate.md | 58 - docs/_playbooks/log4j_respond.md | 58 - docs/_playbooks/log4j_splunk_investigation.md | 44 - docs/_playbooks/malware_hunt_and_contain.md | 44 - .../ransomware_investigate_and_contain.md | 49 - .../risk_notable_block_indicators.md | 46 - docs/_playbooks/risk_notable_enrich.md | 45 - docs/_playbooks/risk_notable_import_data.md | 49 - docs/_playbooks/risk_notable_investigate.md | 45 - docs/_playbooks/risk_notable_merge_events.md | 45 - docs/_playbooks/risk_notable_mitigate.md | 44 - docs/_playbooks/risk_notable_preprocess.md | 46 - .../risk_notable_protect_assets_and_users.md | 45 - .../risk_notable_review_indicators.md | 45 - docs/_playbooks/risk_notable_verdict.md | 45 - docs/_playbooks/start_investigation.md | 40 - docs/_playbooks/threat_intel_investigate.md | 44 - docs/_playbooks/trustar_enrich_indicators.md | 46 - ...spectre_and_meltdown_vulnerable_systems.md | 150 - ...12-detect_new_login_attempts_to_routers.md | 151 - ...od_without_successful_netbackup_backups.md | 145 - .../2017-09-12-identify_new_user_accounts.md | 153 - ...17-09-12-unsuccessful_netbackup_backups.md | 142 - ...tect_unauthorized_assets_by_mac_address.md | 153 - ...9-15-no_windows_updates_in_a_time_frame.md | 153 - ...9-email_attachments_with_lots_of_spaces.md | 156 - .../2017-09-19-open_redirect_in_splunk_web.md | 147 - ...7-09-20-large_volume_of_dns_any_queries.md | 161 - ...s_scanning_for_vulnerable_jboss_servers.md | 153 - ...cious_requests_to_exploit_jboss_servers.md | 159 - .../2017-09-23-monitor_dns_for_brand_abuse.md | 140 - ...-23-monitor_web_traffic_for_brand_abuse.md | 147 - ...0-13-unusually_long_content-type_length.md | 155 - .../2017-11-27-detect_usb_device_insertion.md | 148 - ...018-01-05-monitor_email_for_brand_abuse.md | 158 - ...nce_started_in_previously_unseen_region.md | 156 - ...ance_started_with_previously_unseen_ami.md | 153 - ...rovisioning_from_previously_unseen_city.md | 162 - ...isioning_from_previously_unseen_country.md | 162 - ...oning_from_previously_unseen_ip_address.md | 152 - ...visioning_from_previously_unseen_region.md | 162 - ...16-detect_new_api_calls_from_user_roles.md | 171 - ...detect_spike_in_security_group_activity.md | 175 - ..._blocked_outbound_traffic_from_your_aws.md | 167 - ...ect_api_activity_from_users_without_mfa.md | 161 - ...21-detect_spike_in_network_acl_activity.md | 173 - ...6-01-detect_large_outbound_icmp_packets.md | 161 - ...plunk_enterprise_information_disclosure.md | 153 - ...18-06-28-detect_s3_access_from_a_new_ip.md | 165 - ...18-10-08-web_fraud_-_account_harvesting.md | 159 - ...8-web_fraud_-_anomalous_user_clickspeed.md | 161 - ...raud_-_password_sharing_across_accounts.md | 150 - ...ce_created_with_previously_unseen_image.md | 160 - ...-10-23-wmi_permanent_event_subscription.md | 162 - ...-10-23-wmi_temporary_event_subscription.md | 160 - ...8-11-02-windows_hosts_file_modification.md | 148 - ...1-27-detect_spike_in_s3_bucket_deletion.md | 175 - .../2018-12-03-remote_wmi_command_attempt.md | 169 - .../_posts/2018-12-03-usn_journal_deletion.md | 167 - .../2018-12-06-suspicious_java_classes.md | 154 - .../2018-12-14-file_with_samsam_extension.md | 152 - .../2018-12-14-samsam_test_file_write.md | 158 - ...01-25-processes_tapping_keyboard_events.md | 149 - ...01-29-osquery_pack_-_coldroot_detection.md | 144 - ...ikatz_via_powershell_and_eventcode_4703.md | 161 - ...ide_files_directories_via_registry_keys.md | 153 - ..._servers_executing_suspicious_processes.md | 157 - .../2019-04-25-suspicious_file_write.md | 144 - ...5-08-unusually_long_command_line_-_mltk.md | 157 - ...9-10-11-prohibited_software_on_endpoint.md | 149 - ...credential_dumping_through_lsass_access.md | 170 - ...-03-detect_mimikatz_using_loaded_images.md | 171 - ...6-access_lsass_memory_for_dump_creation.md | 168 - ...9-12-06-create_remote_thread_into_lsass.md | 168 - ...19-12-06-unsigned_image_loaded_by_lsass.md | 153 - .../2019-12-10-creation_of_shadow_copy.md | 173 - ...-01-22-dns_query_length_outliers_-_mltk.md | 179 - ...0-01-28-auto_admin_logon_registry_entry.md | 166 - ...onitor_registry_keys_for_print_monitors.md | 176 - ...gistry_keys_for_creating_shim_databases.md | 171 - docs/_posts/2020-01-28-sdclt_uac_bypass.md | 170 - .../2020-01-28-silentcleanup_uac_bypass.md | 169 - docs/_posts/2020-01-28-wsreset_uac_bypass.md | 170 - ...-03-creation_of_lsass_dump_with_taskmgr.md | 168 - ...ed_with_previously_unseen_instance_type.md | 155 - ...20-02-07-macos_-_re-opened_applications.md | 152 - .../2020-02-20-gcp_gcr_container_uploaded.md | 141 - ...02-20-new_container_uploaded_to_aws_ecr.md | 143 - .../2020-02-21-dump_lsass_via_comsvcs_dll.md | 180 - ...03-02-remote_registry_key_modifications.md | 144 - ...20-03-16-child_processes_of_spoolsv_exe.md | 168 - .../2020-03-16-detect_rare_executables.md | 163 - .../2020-03-16-process_execution_via_wmi.md | 162 - .../2020-03-16-script_execution_via_wmi.md | 163 - .../_posts/2020-03-16-spike_in_file_writes.md | 148 - ...n_eks_kubernetes_cluster_scan_detection.md | 157 - ...mazon_eks_kubernetes_pod_scan_detection.md | 158 - ...5-gcp_kubernetes_cluster_scan_detection.md | 146 - ...05-19-kubernetes_azure_scan_fingerprint.md | 143 - ...0-first_time_seen_child_process_of_zoom.md | 173 - ...es_azure_detect_sensitive_object_access.md | 136 - ...etes_azure_detect_sensitive_role_access.md | 136 - ...rvice_accounts_forbidden_failure_access.md | 135 - ...0-kubernetes_azure_pod_scan_fingerprint.md | 135 - ...ctive_service_accounts_by_pod_namespace.md | 136 - ...ctive_service_accounts_by_pod_namespace.md | 84 - ...re_detect_rbac_authorization_by_account.md | 137 - ...s_azure_detect_suspicious_kubectl_calls.md | 137 - ...activity_from_previously_unseen_account.md | 162 - ...28-detect_aws_console_login_by_new_user.md | 152 - ...ernetes_cluster_sensitive_object_access.md | 134 - ...ect_most_active_service_accounts_by_pod.md | 134 - ...ws_detect_rbac_authorization_by_account.md | 135 - ...rnetes_aws_detect_sensitive_role_access.md | 134 - ...rvice_accounts_forbidden_failure_access.md | 133 - ...tes_aws_detect_suspicious_kubectl_calls.md | 142 - ...rvice_accounts_forbidden_failure_access.md | 134 - ...interception_by_creation_of_program_exe.md | 184 - ...2020-07-06-short_lived_windows_accounts.md | 166 - .../2020-07-06-windows_event_log_cleared.md | 174 - ...20-07-07-remote_desktop_network_traffic.md | 170 - ...20-07-08-detect_new_local_admin_account.md | 168 - ...ect_most_active_service_accounts_by_pod.md | 134 - ...p_detect_rbac_authorizations_by_account.md | 134 - ...etes_gcp_detect_sensitive_object_access.md | 134 - ...rnetes_gcp_detect_sensitive_role_access.md | 134 - ...tes_gcp_detect_suspicious_kubectl_calls.md | 134 - ...p_kubernetes_cluster_pod_scan_detection.md | 153 - ...lly_high_aws_instances_launched_by_user.md | 160 - ...h_aws_instances_launched_by_user_-_mltk.md | 156 - ...y_high_aws_instances_terminated_by_user.md | 159 - ...aws_instances_terminated_by_user_-_mltk.md | 155 - ...-07-21-attempt_to_stop_security_service.md | 189 - ...ents_connecting_to_multiple_dns_servers.md | 160 - ...api_activities_from_unapproved_accounts.md | 177 - ..._to_phishing_sites_leveraging_evilginx2.md | 182 - ...-detect_excessive_user_account_lockouts.md | 170 - ...-21-detect_long_dns_txt_record_response.md | 165 - ...07-21-detect_new_user_aws_console_login.md | 159 - .../2020-07-21-detect_outbound_smb_traffic.md | 167 - ...1-detect_outlook_exe_writing_a_zip_file.md | 176 - ...-07-21-detect_spike_in_aws_api_activity.md | 181 - ...f_cmd_exe_to_launch_script_interpreters.md | 167 - ...web_traffic_to_dynamic_domain_providers.md | 160 - ...-21-detection_of_tools_built_by_nirsoft.md | 158 - ...ts_resolved_by_unauthorized_dns_servers.md | 161 - docs/_posts/2020-07-21-dns_record_changed.md | 183 - ...ce_modified_with_previously_unseen_user.md | 171 - ...nce_started_with_previously_unseen_user.md | 165 - ...ritten_outside_of_the_outlook_directory.md | 160 - ...rs_sending_high_volume_traffic_to_hosts.md | 166 - .../2020-07-21-excessive_dns_failures.md | 169 - ...1-first_time_seen_command_line_argument.md | 184 - ...first_time_seen_running_windows_service.md | 172 - ...g_files_and_directories_with_attrib_exe.md | 165 - ...me_of_network_traffic_from_email_server.md | 165 - ...shell_process_-_execution_policy_bypass.md | 177 - ...th_invalid_credentials_from_the_same_ip.md | 170 - .../2020-07-21-okta_account_lockout_events.md | 163 - .../2020-07-21-okta_failed_sso_attempts.md | 166 - ...1-okta_user_logins_from_multiple_cities.md | 166 - ...7-21-overwriting_accessibility_binaries.md | 166 - ...7-21-prohibited_network_traffic_allowed.md | 163 - .../2020-07-21-protocol_or_port_mismatch.md | 164 - ...07-21-remote_desktop_network_bruteforce.md | 167 - ...emote_desktop_process_running_on_system.md | 166 - ...21-sc_exe_manipulating_windows_services.md | 177 - ...uled_tasks_used_in_badrabbit_ransomware.md | 153 - ...2020-07-21-sql_injection_with_long_urls.md | 105 - docs/_posts/2020-07-22-smb_traffic_spike.md | 165 - .../2020-07-22-smb_traffic_spike_-_mltk.md | 171 - ...suspicious_changes_to_file_associations.md | 158 - ...20-07-22-suspicious_email_-_uba_anomaly.md | 151 - ...-suspicious_email_attachment_extensions.md | 169 - .../2020-07-22-suspicious_reg_exe_process.md | 173 - ...ous_writes_to_system_volume_information.md | 148 - ...uspicious_writes_to_windows_recycle_bin.md | 163 - docs/_posts/2020-07-22-tor_traffic.md | 166 - ...20-07-22-uncommon_processes_on_endpoint.md | 155 - .../2020-07-22-unload_sysmon_filter_driver.md | 165 - ...-07-27-aws_detect_attach_to_role_policy.md | 148 - ...07-27-aws_detect_permanent_key_creation.md | 158 - .../2020-07-27-aws_detect_role_creation.md | 163 - ...-07-27-aws_detect_sts_assume_role_abuse.md | 157 - ...-aws_detect_sts_get_session_token_abuse.md | 156 - ...ct_windows_dns_sigred_via_splunk_stream.md | 161 - ...7-28-detect_windows_dns_sigred_via_zeek.md | 165 - ...ance_modified_by_previously_unseen_user.md | 180 - ...-08-02-detect_f5_tmui_rce_cve-2020-5902.md | 158 - ...-05-detect_new_open_gcp_storage_buckets.md | 166 - ...detect_gcp_storage_access_from_a_new_ip.md | 177 - .../_posts/2020-08-11-detect_arp_poisoning.md | 179 - .../2020-08-11-detect_rogue_dhcp_server.md | 170 - ...ivity_from_previously_unseen_ip_address.md | 173 - ..._activity_from_previously_unseen_region.md | 175 - ...igh_number_of_cloud_instances_destroyed.md | 177 - ...high_number_of_cloud_instances_launched.md | 178 - ...ection_by_machine_learning_method_-_ssa.md | 93 - ...rocess_running_from_unexpected_location.md | 125 - ...-unusual_lolbas_in_short_period_of_time.md | 111 - ...2020-09-01-gcp_detect_oauth_token_abuse.md | 148 - ...nce_created_in_previously_unused_region.md | 167 - ...calls_from_previously_unseen_user_roles.md | 171 - ...umber_of_cloud_infrastructure_api_calls.md | 178 - ...umber_of_cloud_security_group_api_calls.md | 179 - ...oud_network_access_control_list_deleted.md | 150 - ...ed_with_previously_unseen_instance_type.md | 160 - .../2020-09-15-detect_zerologon_via_zeek.md | 161 - ..._or_delete_windows_shares_using_net_exe.md | 175 - ...computer_changed_with_anonymous_account.md | 162 - ...aws_console_login_by_user_from_new_city.md | 172 - ..._console_login_by_user_from_new_country.md | 172 - ...s_console_login_by_user_from_new_region.md | 172 - ...2020-10-08-gcp_detect_gcploit_framework.md | 158 - ...ng_activity_from_previously_unseen_city.md | 175 - ...activity_from_previously_unseen_country.md | 174 - ...ccounts_with_high_risk_roles_by_project.md | 155 - ...isk_permissions_by_resource_and_account.md | 155 - ...tivity_related_to_pass_the_hash_attacks.md | 170 - .../_posts/2020-10-21-detect_kerberoasting.md | 112 - ...20-10-21-detect_snicat_sni_exfiltration.md | 170 - ...ect_ipv6_network_infrastructure_threats.md | 194 - ...20-10-28-detect_port_security_violation.md | 183 - ...ect_software_download_to_network_device.md | 167 - .../2020-10-28-detect_traffic_mirroring.md | 171 - .../2020-11-06-ryuk_test_files_detected.md | 157 - ...windows_connhost_exe_started_forcefully.md | 150 - ...indows_security_account_manager_stopped.md | 158 - ...2020-11-09-common_ransomware_extensions.md | 168 - .../2020-11-09-common_ransomware_notes.md | 163 - .../2020-11-09-deleting_shadow_copies.md | 170 - ...xcessive_account_lockouts_from_endpoint.md | 175 - ..._system_network_configuration_discovery.md | 172 - ...rohibited_applications_spawning_cmd_exe.md | 176 - ...8-disabling_remote_user_account_control.md | 168 - ...cution_of_file_with_multiple_extensions.md | 166 - ...on_of_file_with_spaces_before_extension.md | 159 - .../2020-11-23-processes_created_by_netsh.md | 151 - ...installation_with_suspicious_parameters.md | 164 - ...pulating_windows_services_registry_keys.md | 176 - ...2-07-schtasks_used_for_forcing_a_reboot.md | 168 - .../2020-12-08-shim_database_file_creation.md | 164 - ...12-08-single_letter_process_on_endpoint.md | 166 - ...processes_run_from_unexpected_locations.md | 177 - .../2020-12-08-unusually_long_command_line.md | 159 - ...i_permanent_event_subscription_-_sysmon.md | 179 - ...burst_correlation_dll_and_network_event.md | 160 - ...12-15-o365_suspicious_rights_delegation.md | 162 - ..._of_login_failures_from_a_single_source.md | 164 - .../2020-12-16-o365_pst_export_alert.md | 157 - ...-o365_suspicious_admin_email_forwarding.md | 164 - ...6-o365_suspicious_user_email_forwarding.md | 164 - ...1-bcdedit_failure_recovery_modification.md | 162 - docs/_posts/2021-01-06-supernova_webshell.md | 164 - ...ng_keys_with_encrypt_policy_without_mfa.md | 165 - ..._with_kms_keys_performing_encryption_s3.md | 160 - ...ontrol_list_created_with_all_open_ports.md | 171 - ...aws_network_access_control_list_deleted.md | 164 - ...cious_microsoft_workflow_compiler_usage.md | 171 - .../2021-01-12-suspicious_msbuild_path.md | 134 - .../2021-01-12-suspicious_msbuild_rename.md | 185 - .../2021-01-12-suspicious_msbuild_spawn.md | 176 - ...21-01-12-suspicious_mshta_child_process.md | 170 - ..._connecting_to_dynamic_domain_providers.md | 174 - ...tiple_suspicious_command-line_arguments.md | 98 - ...ell_process_with_obfuscation_techniques.md | 178 - ...cious_powershell_command-line_arguments.md | 157 - ...20-detect_rundll32_inline_hta_execution.md | 178 - .../2021-01-20-suspicious_mshta_spawn.md | 177 - ...021-01-22-wbadmin_delete_system_backups.md | 165 - ...021-01-25-nltest_domain_trust_discovery.md | 169 - ...l_access_by_provider_user_and_principal.md | 164 - ...01-26-aws_saml_update_identity_provider.md | 163 - ...-26-certutil_exe_certificate_extraction.md | 153 - ...ws_security_hub_alerts_for_ec2_instance.md | 153 - ...ike_in_aws_security_hub_alerts_for_user.md | 150 - ...o365_add_app_role_assignment_grant_user.md | 164 - ...1-01-26-o365_excessive_sso_logon_errors.md | 159 - ...1-01-26-o365_new_federated_domain_added.md | 168 - .../_posts/2021-01-26-revil_registry_entry.md | 164 - ...1-27-detect_baron_samedit_cve-2021-3156.md | 154 - ...baron_samedit_cve-2021-3156_via_osquery.md | 155 - ...ect_regsvr32_application_control_bypass.md | 180 - .../_posts/2021-01-28-ntdsutil_export_ntds.md | 176 - ...cious_regsvr32_register_suspicious_path.md | 180 - ...ct_baron_samedit_cve-2021-3156_segfault.md | 157 - ...21-02-01-dump_lsass_via_procdump_rename.md | 167 - ...32_application_control_bypass_-_advpack.md | 179 - ...2_application_control_bypass_-_setupapi.md | 179 - ...2_application_control_bypass_-_syssetup.md | 179 - .../2021-02-04-suspicious_rundll32_startw.md | 180 - ...9-suspicious_rundll32_dllregisterserver.md | 181 - ...11-detect_html_help_spawn_child_process.md | 178 - ...-02-12-detect_regasm_spawning_a_process.md | 173 - ...02-12-detect_regsvcs_spawning_a_process.md | 173 - ...e_policy_version_to_allow_all_resources.md | 172 - .../2021-02-22-cobalt_strike_named_pipes.md | 167 - ...2-22-suspicious_curl_network_connection.md | 161 - .../2021-02-22-suspicious_plistbuddy_usage.md | 172 - ...suspicious_plistbuddy_usage_via_osquery.md | 160 - ...uspicious_sqlite3_lsquarantine_behavior.md | 159 - .../2021-03-01-any_powershell_downloadfile.md | 175 - ...021-03-01-any_powershell_downloadstring.md | 170 - .../_posts/2021-03-01-fodhelper_uac_bypass.md | 180 - .../2021-03-01-ryuk_wake_on_lan_command.md | 167 - ...us_scheduled_task_from_public_directory.md | 173 - .../2021-03-02-aws_setdefaultpolicyversion.md | 173 - ...ed_messaging_service_spawning_a_process.md | 166 - ...-02-windows_disableantispyware_registry.md | 170 - ...2021-03-03-nishang_powershelltcponeline.md | 172 - docs/_posts/2021-03-03-w3wp_spawning_shell.md | 184 - ...21-03-12-ransomware_notes_bulk_creation.md | 162 - .../2021-03-12-resize_shadowstorage_volume.md | 162 - ...3-16-high_process_termination_frequency.md | 158 - ...16-windows_high_file_deletion_frequency.md | 162 - .../2021-03-17-clop_common_exec_parameter.md | 164 - ...3-17-clop_ransomware_known_service_name.md | 159 - ...021-03-23-certutil_with_decode_argument.md | 168 - ...021-03-29-powershell_start-bitstransfer.md | 166 - ...03-31-aws_iam_successful_group_deletion.md | 165 - ...021-03-31-disabling_firewall_with_netsh.md | 171 - .../2021-03-31-dsquery_domain_discovery.md | 168 - ...-aws_iam_assume_role_policy_brute_force.md | 162 - .../2021-04-01-aws_iam_delete_policy.md | 155 - ...21-04-01-aws_iam_failure_group_deletion.md | 155 - ...icious_powershell_executed_as_a_service.md | 174 - ...o_authenticate_from_host_using_kerberos.md | 167 - ...heduled_task_created_within_public_path.md | 178 - .../2021-04-12-excel_spawning_powershell.md | 169 - ...4-12-excel_spawning_windows_script_host.md | 164 - ...t_scheduled_task_created_to_spawn_shell.md | 174 - .../2021-04-12-winword_spawning_powershell.md | 173 - ...12-winword_spawning_windows_script_host.md | 163 - ...1-04-13-aws_excessive_security_scanning.md | 162 - ...authenticate_using_explicit_credentials.md | 119 - ...ng_to_authenticate_from_host_using_ntlm.md | 166 - ...rs_failing_to_authenticate_from_process.md | 172 - ...otely_failing_to_authenticate_from_host.md | 170 - ...fice_application_spawn_rundll32_process.md | 171 - ...authenticate_using_explicit_credentials.md | 170 - ...o_authenticate_from_host_using_kerberos.md | 115 - ...o_authenticate_from_host_using_kerberos.md | 115 - ...-office_document_creating_schedule_task.md | 165 - ...14-office_document_executing_macro_code.md | 167 - ..._users_failing_to_authenticate_kerberos.md | 165 - ...sers_failed_authentication_via_kerberos.md | 165 - ...-15-dns_exfiltration_using_nslookup_app.md | 168 - ...ng_to_authenticate_from_host_using_ntlm.md | 166 - ..._no_command_line_arguments_with_network.md | 116 - ..._remote_thread_to_known_windows_process.md | 162 - ...hedule_task_with_http_command_arguments.md | 163 - ...dule_task_with_rundll32_command_trigger.md | 166 - ...ess_connecting_to_ip_check_web_services.md | 165 - ...9-wermgr_process_create_executable_file.md | 158 - ...ocess_spawned_cmd_or_powershell_process.md | 166 - ...1-04-21-excessive_usage_of_nslookup_app.md | 164 - ...ultiple_archive_files_http_post_traffic.md | 171 - .../2021-04-22-anomalous_usage_of_7zip.md | 169 - ...e_product_spawning_rundll32_with_no_dll.md | 171 - ...-04-22-plain_http_post_exfiltrated_data.md | 163 - .../_posts/2021-04-22-winword_spawning_cmd.md | 170 - ...04-26-office_product_spawning_bitsadmin.md | 169 - ...-04-26-office_product_spawning_certutil.md | 170 - ...021-04-26-office_product_spawning_mshta.md | 170 - docs/_posts/2021-04-26-trickbot_named_pipe.md | 160 - docs/_posts/2021-04-29-icacls_deny_command.md | 159 - ...021-04-29-suspicious_driver_loaded_path.md | 165 - docs/_posts/2021-04-29-xmrig_driver_loaded.md | 164 - .../2021-05-04-deleting_of_net_users.md | 164 - .../2021-05-04-disabling_net_user_account.md | 164 - ...4-excessive_attempt_to_disable_services.md | 160 - ...21-05-04-excessive_service_stop_attempt.md | 166 - .../2021-05-04-excessive_usage_of_taskkill.md | 165 - .../_posts/2021-05-04-icacls_grant_command.md | 159 - ...odify_acl_permission_to_files_or_folder.md | 109 - ...21-05-04-process_kill_base_on_file_path.md | 169 - ...2021-05-05-suspicious_process_file_path.md | 168 - ...021-05-06-download_files_using_telegram.md | 157 - ...merate_users_local_group_using_telegram.md | 161 - .../2021-05-06-excessive_usage_of_net_app.md | 167 - ...s_or_script_creation_in_suspicious_path.md | 166 - ...2021-05-07-excessive_usage_of_cacls_app.md | 160 - .../2021-05-07-schtasks_run_task_on_demand.md | 161 - ...05-12-delete_shadowcopy_with_powershell.md | 158 - ...2021-05-13-cmlua_or_cmstplua_uac_bypass.md | 164 - docs/_posts/2021-05-13-slui_runas_elevated.md | 171 - .../2021-05-13-slui_spawning_a_process.md | 169 - .../2021-05-18-services_escalate_exe.md | 162 - ...-allow_inbound_traffic_in_firewall_rule.md | 160 - .../2021-05-19-mailsniper_invoke_functions.md | 160 - .../2021-05-20-cmd_echo_pipe_-_escalation.md | 182 - .../2021-05-21-winrm_spawning_a_process.md | 166 - ...6-secretdumps_offline_ntds_dumping_tool.md | 165 - ...27-detect_sharphound_file_modifications.md | 192 - .../2021-05-27-detect_sharphound_usage.md | 198 - ...etect_azurehound_command-line_arguments.md | 196 - ...01-detect_azurehound_file_modifications.md | 188 - ...etect_sharphound_command-line_arguments.md | 194 - .../2021-06-02-conti_common_exec_parameter.md | 163 - .../2021-06-02-modification_of_wallpaper.md | 163 - .../2021-06-02-revil_common_exec_parameter.md | 162 - ...021-06-02-wbemprox_com_object_execution.md | 167 - ...-04-known_services_killed_by_ransomware.md | 157 - ...-excessive_number_of_taskhost_processes.md | 161 - ...ss_process_injection_via_getprocaddress.md | 173 - ..._script_contains_base64_encoded_content.md | 172 - ...re_with_powershell_script_block_logging.md | 167 - ...tz_with_powershell_script_block_logging.md | 161 - ...021-06-09-unloading_amsi_via_reflection.md | 171 - ...ear_unallocated_sector_using_cipher_app.md | 169 - .../2021-06-10-disable_logs_using_wevtutil.md | 165 - ...rmission_modification_using_takeown_app.md | 160 - ...-06-10-powershell_creating_thread_mutex.md | 163 - ...021-06-10-powershell_domain_enumeration.md | 164 - ...ading_dotnet_into_memory_via_reflection.md | 167 - ...o_memory_via_system_reflection_assembly.md | 116 - ...10-powershell_processing_stream_of_data.md | 165 - ...owershell_using_memory_as_backing_store.md | 155 - ...ent_automatic_repair_mode_using_bcdedit.md | 160 - ...6-10-recon_avproduct_through_pwh_or_wmi.md | 156 - .../2021-06-10-recon_using_wmi_class.md | 161 - ...4-wmi_recon_running_process_or_services.md | 158 - ...2021-06-15-wevtutil_usage_to_clear_logs.md | 112 - ...21-06-15-wevtutil_usage_to_disable_logs.md | 111 - ...tect_wmi_event_subscription_persistence.md | 168 - ...7-suspicious_event_log_service_behavior.md | 172 - ...ecute_javascript_with_jscript_com_clsid.md | 164 - ...-powershell_enable_smb1protocol_feature.md | 162 - ...ursive_delete_of_directory_in_batch_cmd.md | 169 - ...w_file_and_printing_sharing_in_firewall.md | 170 - ...-23-allow_network_discovery_in_firewall.md | 171 - ...4-excessive_usage_of_sc_service_utility.md | 165 - ...er_of_service_control_start_as_disabled.md | 166 - ...1-print_spooler_adding_a_printer_driver.md | 174 - ...-print_spooler_failed_to_load_a_plug-in.md | 171 - .../2021-07-01-spoolsv_spawning_rundll32.md | 178 - ...07-01-spoolsv_suspicious_loaded_modules.md | 168 - ...07-01-spoolsv_suspicious_process_access.md | 164 - .../2021-07-01-spoolsv_writing_a_dll.md | 177 - ...21-07-01-spoolsv_writing_a_dll_-_sysmon.md | 172 - ...05-msmpeng_application_dll_side_loading.md | 167 - ...-powershell_disable_security_monitoring.md | 170 - ...-07-12-uac_bypass_mmc_load_unsigned_dll.md | 171 - ...tance_created_by_previously_unseen_user.md | 178 - docs/_posts/2021-07-19-aws_createaccesskey.md | 111 - .../2021-07-19-aws_createloginprofile.md | 171 - .../2021-07-19-aws_updateloginprofile.md | 111 - .../2021-07-19-detect_new_open_s3_buckets.md | 170 - ...detect_new_open_s3_buckets_over_aws_cli.md | 166 - ...a_spawning_rundll32_or_regsvr32_process.md | 172 - ...-07-19-office_product_spawn_cmd_process.md | 170 - .../2021-07-20-detect_shared_ec2_snapshot.md | 165 - ...of_shadowcopy_with_script_block_logging.md | 169 - ...-07-23-sam_database_file_access_attempt.md | 164 - ...-rundll32_createremotethread_in_browser.md | 160 - ...rundll32_process_creating_exe_dll_files.md | 162 - ...7-26-suspicious_icedid_rundll32_cmdline.md | 170 - ...21-07-26-suspicious_rundll32_plugininit.md | 169 - .../2021-07-27-chcp_command_execution.md | 162 - ...gsvr32_with_known_silent_switch_cmdline.md | 175 - ...dll32_create_remote_thread_to_a_process.md | 160 - .../2021-07-30-drop_icedid_license_dat.md | 156 - ...edid_exfiltrated_archived_file_creation.md | 161 - ...fice_application_spawn_regsvr32_process.md | 169 - ...2021-08-03-sqlite_module_in_temp_folder.md | 156 - ...eate_remote_thread_in_shell_application.md | 159 - .../2021-08-09-rundll32_lockworkstation.md | 165 - .../2021-08-09-uninstall_app_using_msiexec.md | 165 - ...021-08-10-powershell_execute_com_object.md | 156 - docs/_posts/2021-08-11-fsutil_zeroing_file.md | 158 - ...8-13-uac_bypass_with_colorui_com_object.md | 163 - ...16-gsuite_drive_share_in_external_email.md | 169 - ...8-16-gsuite_email_suspicious_attachment.md | 165 - ...8-17-7zip_commandline_to_smb_share_path.md | 165 - ...ws_ecr_container_scanning_findings_high.md | 174 - ...ning_findings_low_informational_unknown.md | 174 - ..._ecr_container_scanning_findings_medium.md | 174 - ...mail_with_attachment_to_external_domain.md | 163 - docs/_posts/2021-08-18-esentutl_sam_copy.md | 168 - .../2021-08-18-powershell_4104_hunting.md | 333 - ...container_upload_outside_business_hours.md | 170 - ...9-aws_ecr_container_upload_unknown_user.md | 171 - ...mail_suspicious_subject_with_attachment.md | 161 - ...ols_passing_authentication_in_cleartext.md | 159 - ...1-08-20-github_commit_changes_in_master.md | 151 - ...2021-08-20-kubernetes_nginx_ingress_lfi.md | 169 - ...2021-08-23-getlocaluser_with_powershell.md | 157 - ...tlocaluser_with_powershell_script_block.md | 150 - ...twmiobject_user_account_with_powershell.md | 157 - ...er_account_with_powershell_script_block.md | 154 - ...email_with_known_abuse_web_service_link.md | 160 - ...8-23-gsuite_suspicious_shared_file_name.md | 169 - ...2021-08-23-kubernetes_nginx_ingress_rfi.md | 164 - ...21-08-24-adsisearcher_account_discovery.md | 162 - ...4-domain_account_discovery_with_dsquery.md | 166 - ...4-domain_account_discovery_with_net_app.md | 167 - ...8-24-domain_account_discovery_with_wmic.md | 165 - ...1-08-24-get-domaintrust_with_powershell.md | 163 - ...omaintrust_with_powershell_script_block.md | 162 - .../2021-08-24-get_aduser_with_powershell.md | 167 - ...get_aduser_with_powershell_script_block.md | 161 - ...21-08-24-get_domainuser_with_powershell.md | 165 - ...domainuser_with_powershell_script_block.md | 155 - ...24-getwmiobject_ds_user_with_powershell.md | 165 - ...ct_ds_user_with_powershell_script_block.md | 160 - ...-08-24-kubernetes_scanner_image_pulling.md | 167 - ...omain_group_discovery_with_adsisearcher.md | 159 - ...1-08-25-domain_group_discovery_with_net.md | 167 - ...-08-25-domain_group_discovery_with_wmic.md | 167 - ...08-25-elevated_group_discovery_with_net.md | 169 - ...elevated_group_discovery_with_powerview.md | 161 - ...8-25-elevated_group_discovery_with_wmic.md | 169 - .../2021-08-25-getadgroup_with_powershell.md | 168 - ...getadgroup_with_powershell_script_block.md | 155 - ...21-08-25-getdomaingroup_with_powershell.md | 168 - ...-25-getnettcpconnection_with_powershell.md | 163 - ...5-getwmiobject_ds_group_with_powershell.md | 168 - ...t_ds_group_with_powershell_script_block.md | 159 - ...ultdomainpasswordpolicy_with_powershell.md | 162 - ...wordpolicy_with_powershell_script_block.md | 152 - ...resultantpasswordpolicy_with_powershell.md | 162 - ...wordpolicy_with_powershell_script_block.md | 156 - ...-08-26-get_domainpolicy_with_powershell.md | 162 - ...mainpolicy_with_powershell_script_block.md | 156 - ...omaingroup_with_powershell_script_block.md | 159 - ...8-26-password_policy_discovery_with_net.md | 160 - ...reating_lnk_file_in_suspicious_location.md | 179 - ...8-27-exchange_powershell_abuse_via_ssrf.md | 163 - ...-08-27-exchange_powershell_module_usage.md | 168 - ...domain_controller_discovery_with_nltest.md | 162 - ...-08-30-remote_system_discovery_with_net.md | 162 - ...petitpotam_network_share_access_request.md | 166 - ...itpotam_suspicious_kerberos_tgt_request.md | 162 - ...31-remote_system_discovery_with_dsquery.md | 163 - ...1-09-01-circle_ci_disable_security_step.md | 169 - ...1-domain_controller_discovery_with_wmic.md | 162 - ...-01-domain_group_discovery_with_dsquery.md | 167 - ...adcomputer_with_powershell_script_block.md | 154 - ...s_computer_with_powershell_script_block.md | 154 - .../2021-09-01-github_commit_in_develop.md | 151 - .../2021-09-01-github_dependabot_alert.md | 174 - ...1-github_pull_request_from_unknown_user.md | 176 - ...mote_system_discovery_with_adsisearcher.md | 154 - ...09-01-remote_system_discovery_with_wmic.md | 163 - ...21-09-02-circle_ci_disable_security_job.md | 165 - ...1-09-02-get-foresttrust_with_powershell.md | 163 - ...oresttrust_with_powershell_script_block.md | 158 - ...incomputer_with_powershell_script_block.md | 154 - ...controller_with_powershell_script_block.md | 154 - ...cdedit_command_back_to_normal_mode_boot.md | 158 - ...change_to_safe_mode_with_network_config.md | 158 - ...9-06-correlation_by_repository_and_risk.md | 155 - ...2021-09-06-correlation_by_user_and_risk.md | 155 - ...021-09-07-getadcomputer_with_powershell.md | 162 - ...09-07-getdomaincomputer_with_powershell.md | 162 - ...-07-getdomaincontroller_with_powershell.md | 163 - ...etwmiobject_ds_computer_with_powershell.md | 162 - ...e_by_app_connect_and_create_adsi_object.md | 163 - ...-system_information_discovery_detection.md | 164 - ...l_loading_from_world_writable_directory.md | 177 - ...eate_local_admin_accounts_using_net_exe.md | 173 - .../2021-09-08-office_spawning_control.md | 178 - ...2021-09-08-rundll32_control_rundll_hunt.md | 180 - ...control_rundll_world_writable_directory.md | 180 - ...2021-09-09-extraction_of_registry_hives.md | 171 - ...09-mshtml_module_load_in_office_product.md | 170 - ...connection_with_powershell_script_block.md | 154 - ...0-network_connection_discovery_with_arp.md | 162 - ...0-network_connection_discovery_with_net.md | 163 - ...twork_connection_discovery_with_netstat.md | 162 - ...09-10-office_product_writing_cab_or_inf.md | 175 - ...1-09-13-getcurrent_user_with_powershell.md | 163 - ...rrent_user_with_powershell_script_block.md | 152 - ...-13-jscript_execution_using_cscript_app.md | 166 - ...s_scripting_process_loading_ldap_module.md | 164 - ...ms_scripting_process_loading_wmi_module.md | 164 - ...9-13-office_application_drop_executable.md | 168 - ...-09-13-system_user_discovery_with_query.md | 163 - ...09-13-system_user_discovery_with_whoami.md | 163 - ...user_discovery_with_env_vars_powershell.md | 163 - ...y_with_env_vars_powershell_script_block.md | 151 - ...21-09-13-xsl_script_execution_with_wmic.md | 164 - ...-cmdline_tool_not_executed_in_cmd_shell.md | 169 - ...021-09-14-get_wmiobject_group_discovery.md | 169 - ...oup_discovery_with_script_block_logging.md | 162 - .../2021-09-14-net_localgroup_discovery.md | 171 - ...-14-powershell_get_localgroup_discovery.md | 169 - ...oup_discovery_with_script_block_logging.md | 166 - .../_posts/2021-09-14-wmic_group_discovery.md | 171 - ...1-09-15-check_elevated_cmd_using_whoami.md | 156 - ...me_process_accessing_chrome_default_dir.md | 163 - ...efox_process_access_firefox_profile_dir.md | 164 - ...21-09-16-account_discovery_with_net_app.md | 173 - ...t_to_add_certificate_to_untrusted_store.md | 175 - ...edential_dump_from_registry_via_reg_exe.md | 179 - ...2021-09-16-batch_file_write_to_system32.md | 169 - .../_posts/2021-09-16-bits_job_persistence.md | 169 - .../2021-09-16-bitsadmin_download_file.md | 176 - ...of_shadow_copy_with_wmic_and_powershell.md | 176 - ...mping_via_copy_command_from_shadow_copy.md | 174 - ...tial_dumping_via_symlink_to_shadow_copy.md | 174 - .../2021-09-16-detect_html_help_renamed.md | 173 - ...16-detect_html_help_url_in_command_line.md | 180 - ...ml_help_using_infotech_storage_handlers.md | 180 - ...09-16-detect_mshta_inline_hta_execution.md | 177 - .../_posts/2021-09-16-detect_mshta_renamed.md | 172 - ...-09-16-detect_mshta_url_in_command_line.md | 177 - ...9-16-detect_psexec_with_accepteula_flag.md | 175 - .../_posts/2021-09-16-detect_renamed_7-zip.md | 168 - .../2021-09-16-detect_renamed_psexec.md | 171 - .../2021-09-16-detect_renamed_rclone.md | 166 - .../2021-09-16-detect_renamed_winrar.md | 168 - .../2021-09-16-dump_lsass_via_procdump.md | 175 - ...-09-16-local_account_discovery_with_net.md | 158 - ...09-16-local_account_discovery_with_wmic.md | 158 - ...2021-09-16-office_product_spawning_wmic.md | 172 - .../2021-09-16-processes_launching_netsh.md | 169 - ...t_regasm_with_no_command_line_arguments.md | 122 - ..._regsvcs_with_no_command_line_arguments.md | 122 - ...ument_spawned_child_process_to_download.md | 168 - ...cious_dllhost_no_command_line_arguments.md | 117 - ...ious_gpupdate_no_command_line_arguments.md | 117 - ...ious_microsoft_workflow_compiler_rename.md | 179 - ...ious_rundll32_no_command_line_arguments.md | 132 - ...hprotocolhost_no_command_line_arguments.md | 115 - ...mcos_rat_file_creation_in_remcos_folder.md | 157 - ...icious_image_creation_in_appdata_folder.md | 161 - ...1-suspicious_wav_file_in_appdata_folder.md | 161 - ...1-09-27-change_default_file_association.md | 167 - ...27-logon_script_event_trigger_execution.md | 166 - ...-27-screensaver_event_trigger_execution.md | 168 - ...9-28-print_processor_registry_autostart.md | 169 - .../2021-09-29-verclsid_clsid_execution.md | 170 - ...01-vbscript_execution_using_wscript_app.md | 169 - ...ld_suspicious_spawned_by_script_process.md | 164 - ...32_silent_and_install_param_dll_loading.md | 176 - .../2021-10-05-detect_exchange_web_shell.md | 174 - ...5-malicious_inprocserver32_modification.md | 171 - ...1-10-05-process_writing_dynamicwrapperx.md | 172 - .../2021-10-05-rundll32_shimcache_flush.md | 165 - .../2021-10-05-suspicious_copy_on_system32.md | 169 - .../2021-10-05-winhlp32_spawning_a_process.md | 166 - ...ery_length_with_high_standard_deviation.md | 170 - ...021-10-06-sdelete_application_execution.md | 174 - ...ipt_or_cscript_suspicious_child_process.md | 186 - .../2021-10-11-suspicious_wevtutil_usage.md | 175 - ..._no_command_line_arguments_with_network.md | 116 - ..._no_command_line_arguments_with_network.md | 137 - ...lhost_with_no_command_line_with_network.md | 114 - ...rincipalnames_discovery_with_powershell.md | 179 - ...iceprincipalnames_discovery_with_setspn.md | 180 - .../2021-10-18-disable_schedule_task.md | 162 - ...indows_curl_download_to_suspicious_path.md | 169 - ...ows_task_scheduler_event_action_started.md | 162 - ...-wmic_noninteractive_app_uninstallation.md | 168 - ...21-10-24-gdrive_suspicious_file_sharing.md | 158 - ...10-24-gsuite_suspicious_calendar_invite.md | 158 - docs/_posts/2021-11-03-windows_adfind_exe.md | 166 - .../2021-11-04-attacker_tools_on_endpoint.md | 184 - ..._observed_by_an_event_collecting_device.md | 119 - ...ndows_curl_upload_to_remote_destination.md | 170 - ...ows_service_creation_on_remote_endpoint.md | 172 - ...s_service_initiation_on_remote_endpoint.md | 171 - ...ocess_instantiation_via_winrm_and_winrs.md | 169 - ...sk_creation_on_remote_endpoint_using_at.md | 174 - ...uled_task_initiation_on_remote_endpoint.md | 174 - ...chtasks_scheduling_job_on_remote_system.md | 165 - .../2021-11-11-wmic_xsl_execution_via_url.md | 166 - ...2-aws_iam_accessdenied_discovery_events.md | 157 - ...21-11-12-csc_net_on_the_fly_compilation.md | 167 - ...1-11-12-firewall_allowed_program_enable.md | 166 - ...twork_discovery_using_route_windows_app.md | 166 - ...12-remote_process_instantiation_via_wmi.md | 175 - ...21-11-12-runas_execution_in_commandline.md | 169 - ...12-windows_installutil_credential_theft.md | 171 - ...s_installutil_remote_network_connection.md | 130 - ...12-windows_installutil_uninstall_option.md | 176 - ...stallutil_uninstall_option_with_network.md | 133 - ...windows_installutil_url_in_command_line.md | 174 - ...s_instantiation_via_dcom_and_powershell.md | 170 - ...on_via_dcom_and_powershell_script_block.md | 155 - ...ss_instantiation_via_wmi_and_powershell.md | 165 - ...ion_via_wmi_and_powershell_script_block.md | 154 - ...021-11-15-sdelete_application_execution.md | 116 - .../2021-11-15-windows_diskcryptor_usage.md | 164 - ...requency_copy_of_files_in_network_share.md | 162 - ..._instantiation_via_winrm_and_powershell.md | 170 - ...n_via_winrm_and_powershell_script_block.md | 155 - ...2021-11-17-windows_dism_remove_defender.md | 168 - ...ile_written_in_administrative_smb_share.md | 170 - .../2021-11-18-loading_of_dynwrapx_module.md | 171 - ...info_gathering_using_dxdiag_application.md | 164 - ...-11-22-anomalous_usage_of_archive_tools.md | 111 - ...22-possible_browser_pass_view_parameter.md | 169 - ...services_lolbas_execution_process_spawn.md | 173 - ...-svchost_lolbas_execution_process_spawn.md | 175 - ...ce_created_with_suspicious_service_path.md | 162 - ...dows_service_created_within_public_path.md | 163 - ...wmiprsve_lolbas_execution_process_spawn.md | 165 - ...provhost_lolbas_execution_process_spawn.md | 170 - ...1-23-mmc_lolbas_execution_process_spawn.md | 176 - .../2021-11-24-attempt_to_delete_services.md | 117 - .../2021-11-24-attempt_to_disable_services.md | 108 - ...5-add_or_set_windows_defender_exclusion.md | 172 - ...ell_windows_defender_exclusion_commands.md | 164 - ...ndows_defender_exclusion_registry_entry.md | 171 - ...edential_dump_from_registry_via_reg_exe.md | 109 - ...-29-deny_permission_using_cacls_utility.md | 105 - ...-detect_dump_lsass_memory_using_comsvcs.md | 107 - ...-11-29-detect_rclone_command-line_usage.md | 165 - ...sible_lateral_movement_powershell_spawn.md | 207 - ...-randomly_generated_scheduled_task_name.md | 164 - ...randomly_generated_windows_service_name.md | 161 - docs/_posts/2021-11-30-delete_a_net_user.md | 107 - .../2021-11-30-disable_net_user_account.md | 113 - ...0-first_time_seen_command_line_argument.md | 112 - ...30-grant_permission_using_cacls_utility.md | 105 - ...ify_acls_permission_of_files_or_folders.md | 105 - ...hash_observed_at_the_destination_device.md | 119 - ...-rare_parent-child_process_relationship.md | 121 - .../2021-11-30-resize_shadowstorage_volume.md | 107 - ...r_of_computer_service_tickets_requested.md | 161 - ...f_remote_endpoint_authentication_events.md | 161 - ...-12-03-detect_rclone_command-line_usage.md | 111 - .../2021-12-03-short_lived_scheduled_task.md | 160 - ...ndows_curl_upload_to_remote_destination.md | 115 - ...-06-suspicious_linux_discovery_commands.md | 165 - ...-anomalous_usage_of_account_credentials.md | 109 - ...7-bcdedit_failure_recovery_modification.md | 106 - ...-07-dns_exfiltration_using_nslookup_app.md | 112 - ...excessive_number_of_office_files_copied.md | 98 - docs/_posts/2021-12-07-fsutil_zeroing_file.md | 106 - ...2021-12-07-high_file_deletion_frequency.md | 109 - ...ion_service_writing_active_server_pages.md | 128 - ...ion_service_writing_active_server_pages.md | 178 - ...021-12-07-wbadmin_delete_system_backups.md | 109 - ...windows_raccine_scheduled_task_deletion.md | 164 - ...-08-disable_defender_antivirus_registry.md | 110 - ...-msi_module_loaded_by_non-system_binary.md | 175 - ...-12-10-curl_download_and_bash_execution.md | 172 - ...-12-11-wget_download_and_bash_execution.md | 171 - ...2021-12-13-detect_outbound_ldap_traffic.md | 174 - ..._class_file_download_by_java_user_agent.md | 162 - .../2021-12-13-linux_java_spawning_shell.md | 169 - ...og4shell_jndi_payload_injection_attempt.md | 178 - ...load_injection_with_outbound_connection.md | 187 - ...onnection_from_java_using_default_ports.md | 171 - ...2021-12-13-windows_java_spawning_shells.md | 169 - .../2021-12-14-hunting_for_log4shell.md | 291 - ..._add_files_in_known_crontab_directories.md | 175 - ...-17-linux_at_allow_config_file_creation.md | 174 - ...21-12-17-linux_at_application_execution.md | 172 - ...1-12-17-linux_edit_cron_table_parameter.md | 176 - ..._append_command_to_at_allow_config_file.md | 172 - ..._cronjob_entry_on_existing_cronjob_file.md | 178 - ...ssible_cronjob_modification_with_editor.md | 176 - ...ear_unallocated_sector_using_cipher_app.md | 115 - ...g_files_and_directories_with_attrib_exe.md | 104 - ...ux_file_creation_in_init_boot_directory.md | 171 - ...inux_file_creation_in_profile_directory.md | 172 - ...e_append_command_to_profile_config_file.md | 174 - ...rvice_file_created_in_systemd_directory.md | 177 - .../2021-12-20-linux_service_restarted.md | 176 - ...-12-20-linux_service_started_or_enabled.md | 176 - ...suspicious_computer_account_name_change.md | 173 - ...picious_kerberos_service_ticket_request.md | 177 - .../2021-12-21-linux_add_user_account.md | 171 - ...1-12-21-linux_change_file_owner_to_root.md | 173 - ...21-linux_nopasswd_entry_in_sudoers_file.md | 174 - ...-12-21-linux_setuid_using_chmod_utility.md | 174 - ...12-21-linux_setuid_using_setcap_utility.md | 173 - ...21-12-21-linux_visudo_utility_execution.md | 173 - ...spicious_ticket_granting_ticket_request.md | 171 - ...file_created_in_kernel_driver_directory.md | 174 - ...sert_kernel_module_using_insmod_utility.md | 176 - ...ll_kernel_module_using_modprobe_utility.md | 176 - ...2-22-linux_preload_hijack_library_calls.md | 175 - ...ux_common_process_for_elevation_control.md | 177 - ...1-12-23-linux_sudoers_tmp_file_creation.md | 171 - .../2022-01-04-linux_sudo_or_su_execution.md | 173 - ...022-01-05-linux_doas_conf_file_creation.md | 172 - .../2022-01-05-linux_doas_tool_execution.md | 174 - ...nux_possible_access_to_credential_files.md | 172 - ...0-linux_possible_access_to_sudoers_file.md | 174 - ...ess_or_modification_of_sshd_config_file.md | 173 - ...11-linux_possible_ssh_key_file_creation.md | 171 - ..._connect_to_internet_with_hidden_window.md | 190 - ..._hunting_system_account_targeting_lsass.md | 170 - ...dows_non-system_account_targeting_lsass.md | 170 - ...tentially_malicious_code_on_commandline.md | 166 - ...ownload_from_internal_server_per_entity.md | 124 - ...-cmd_carry_out_string_command_parameter.md | 180 - ...lateral_movement_commandline_parameters.md | 193 - ...us_powershell_process_-_encoded_command.md | 184 - ...shell_remove_windows_defender_directory.md | 166 - ...cess_dns_query_known_abuse_web_services.md | 164 - ...spicious_process_with_discord_dns_query.md | 171 - ...dows_dotnet_binary_in_non_standard_path.md | 187 - ...indows_installutil_in_non_standard_path.md | 187 - ...ive_file_deletion_in_windefender_folder.md | 164 - .../2022-01-20-ping_sleep_batch_command.md | 177 - .../2022-01-21-windows_nirsoft_advancedrun.md | 166 - .../2022-01-24-windows_nirsoft_utilities.md | 167 - ...2-01-26-active_setup_registry_autostart.md | 171 - ...dd_defaultuser_and_password_in_registry.md | 165 - ...bound_traffic_by_firewall_rule_registry.md | 174 - ...1-26-allow_operation_with_consent_admin.md | 164 - ...022-01-26-disable_amsi_through_registry.md | 168 - ...-26-disable_defender_antivirus_registry.md | 168 - ...sable_defender_blockatfirstseen_feature.md | 169 - ...-disable_defender_enhanced_notification.md | 169 - ...1-26-disable_defender_mpengine_registry.md | 168 - ...01-26-disable_defender_spynet_reporting.md | 169 - ...defender_submit_samples_consent_feature.md | 169 - ...6-log4shell_cve-2021-44228_exploitation.md | 177 - ...1-26-registry_keys_used_for_persistence.md | 181 - ...stry_keys_used_for_privilege_escalation.md | 176 - ...26-remcos_client_registry_install_entry.md | 163 - ...22-01-26-start_up_during_safe_mode_boot.md | 163 - ...1-26-time_provider_persistence_registry.md | 172 - ...2022-01-27-disable_etw_through_registry.md | 167 - .../2022-01-27-disable_registry_tool.md | 169 - ...ble_security_logs_using_minint_registry.md | 163 - .../2022-01-27-disable_show_hidden_files.md | 180 - ...22-01-27-disable_uac_remote_restriction.md | 171 - .../2022-01-27-disable_windows_app_hotkeys.md | 166 - ...-27-disable_windows_behavior_monitoring.md | 172 - ...-disable_windows_smartscreen_protection.md | 169 - .../2022-01-27-disabling_cmd_application.md | 169 - .../2022-01-27-disabling_controlpanel.md | 169 - ...-27-windows_possible_credential_dumping.md | 176 - .../2022-01-28-disabling_defender_services.md | 168 - ...disabling_folderoptions_windows_feature.md | 169 - .../2022-01-28-disabling_norun_windows_app.md | 170 - ...-28-disabling_systemrestore_in_registry.md | 164 - .../2022-01-28-disabling_task_manager.md | 170 - ...2-01-28-enable_rdp_in_other_port_number.md | 161 - ...ble_wdigest_uselogoncredential_registry.md | 168 - .../2022-01-28-etw_registry_disabled.md | 175 - docs/_posts/2022-01-28-eventvwr_uac_bypass.md | 174 - ...8-hide_user_account_from_sign-in_screen.md | 167 - ...01-28-linux_pkexec_privilege_escalation.md | 173 - ...tz_passtheticket_commandline_parameters.md | 168 - ...22-02-01-rubeus_command_line_parameters.md | 185 - .../2022-02-01-suspicious_rundll32_rename.md | 184 - ...nload_with_urlcache_and_split_arguments.md | 168 - ...load_with_verifyctl_and_split_arguments.md | 169 - ...2022-02-03-o365_added_service_principal.md | 166 - ...22-02-03-o365_bypass_mfa_via_trusted_ip.md | 170 - docs/_posts/2022-02-03-o365_disable_mfa.md | 159 - ..._ticket_exports_through_winlogon_access.md | 167 - ...dows_remote_assistance_spawning_process.md | 165 - ...7-windows_schtasks_create_run_as_system.md | 175 - ...022-02-08-rundll_loading_dll_by_ordinal.md | 177 - ...r_of_kerberos_service_tickets_requested.md | 166 - ...oasting_spn_request_with_rc4_encryption.md | 169 - ...22-02-11-linux_system_network_discovery.md | 164 - ..._connect_to_internet_with_hidden_window.md | 118 - ...2-02-11-windows_powershell_downloadfile.md | 111 - .../2022-02-14-linux_dd_file_overwrite.md | 167 - .../2022-02-15-detection_of_dns_tunnels.md | 165 - ...2022-02-15-windows_bits_job_persistence.md | 112 - ...2-15-windows_diskshadow_proxy_execution.md | 165 - ...22-02-15-windows_rasautou_dll_execution.md | 178 - ...2-02-16-windows_bitsadmin_download_file.md | 118 - ...2022-02-16-windows_certutil_decode_file.md | 111 - ...2-16-windows_certutil_urlcache_download.md | 111 - ...-16-windows_certutil_verifyctl_download.md | 112 - ...6-windows_powershell_start-bitstransfer.md | 114 - ...pting_interpreter_outbound_ldap_traffic.md | 108 - ...-17-windows_disable_notification_center.md | 167 - ...2-17-windows_diskshadow_proxy_execution.md | 107 - ..._raw_access_to_master_boot_record_drive.md | 174 - ...8-detect_regasm_with_network_connection.md | 172 - ...-detect_regsvcs_with_network_connection.md | 171 - ...authentication_discovery_with_powerview.md | 160 - ...sion_on_remote_endpoint_with_powershell.md | 155 - .../2022-02-18-net_profiler_uac_bypass.md | 163 - ...excessive_authentication_failures_alert.md | 157 - ...-process_deleting_its_process_file_path.md | 166 - docs/_posts/2022-02-18-rundll32_dnsquery.md | 162 - ...cution_policy_to_unrestricted_or_bypass.md | 167 - .../2022-02-18-windows_eventvwr_uac_bypass.md | 119 - .../2022-02-18-windows_wsreset_uac_bypass.md | 116 - ...uthentication_discovery_with_get-aduser.md | 160 - ...ion_flag_disabled_in_useraccountcontrol.md | 158 - ...heduled_task_deleted_or_created_via_cmd.md | 175 - ...2-02-22-windows_wmi_process_call_create.md | 172 - ...ntication_flag_disabled_with_powershell.md | 152 - ...2-23-windows_event_for_service_disabled.md | 163 - ...ndows_excessive_disabled_services_event.md | 168 - .../2022-02-23-windows_mshta_child_process.md | 112 - ...22-02-23-windows_mshta_command-line_url.md | 113 - ...2-23-windows_mshta_inline_hta_execution.md | 113 - ...dows_process_with_namedpipe_commandline.md | 171 - ...3-windows_rundll32_inline_hta_execution.md | 114 - ...s_service_creation_using_registry_entry.md | 179 - ...022-02-24-aws_lambda_updatefunctioncode.md | 157 - ...re_with_powershell_script_block_logging.md | 168 - ...tz_with_powershell_script_block_logging.md | 167 - ...oresttrust_with_powershell_script_block.md | 164 - ...022-02-25-powershell_domain_enumeration.md | 167 - ...-powershell_enable_smb1protocol_feature.md | 163 - ...ss_process_injection_via_getprocaddress.md | 174 - ...25-powershell_processing_stream_of_data.md | 166 - .../2022-02-25-recon_using_wmi_class.md | 167 - ...02-25-windows_disable_memory_crash_dump.md | 177 - ...le_without_extension_in_critical_folder.md | 175 - ...ows_raw_access_to_disk_volume_partition.md | 171 - ...rincipalnames_discovery_with_powershell.md | 174 - ...ve_distinct_processes_from_windows_temp.md | 156 - ...rocesses_created_in_windows_temp_folder.md | 106 - ...ow_compress_color_and_info_tip_registry.md | 169 - docs/_posts/2022-03-03-aws_createaccesskey.md | 168 - .../2022-03-03-aws_updateloginprofile.md | 168 - ...rberos_tgt_request_using_rc4_encryption.md | 153 - docs/_posts/2022-03-04-macos_lolbin.md | 172 - .../2022-03-08-suspicious_msbuild_path.md | 188 - ...isable_change_password_through_registry.md | 175 - ...ck_workstation_feature_through_registry.md | 176 - ..._disable_logoff_button_through_registry.md | 176 - ...isable_shutdown_button_through_registry.md | 174 - ..._group_policy_features_through_registry.md | 177 - ..._notification_features_through_registry.md | 175 - ...own_process_using_the_kerberos_protocol.md | 168 - .../2022-03-10-kerberos_user_enumeration.md | 163 - ...t_regasm_with_no_command_line_arguments.md | 178 - ..._regsvcs_with_no_command_line_arguments.md | 178 - ..._no_command_line_arguments_with_network.md | 166 - ..._no_command_line_arguments_with_network.md | 166 - ...ice_ticket_request_using_rc4_encryption.md | 165 - ..._no_command_line_arguments_with_network.md | 185 - ...lhost_with_no_command_line_with_network.md | 164 - ...cious_dllhost_no_command_line_arguments.md | 167 - ...ious_gpupdate_no_command_line_arguments.md | 167 - ...ious_rundll32_no_command_line_arguments.md | 185 - ...hprotocolhost_no_command_line_arguments.md | 165 - ...s_installutil_remote_network_connection.md | 181 - ...stallutil_uninstall_option_with_network.md | 184 - ...odify_acl_permission_to_files_or_folder.md | 158 - ...wordpolicy_with_powershell_script_block.md | 156 - ...domainuser_with_powershell_script_block.md | 159 - ...oup_discovery_with_script_block_logging.md | 166 - ...getadgroup_with_powershell_script_block.md | 160 - ...rrent_user_with_powershell_script_block.md | 157 - ...tlocaluser_with_powershell_script_block.md | 166 - ...sion_on_remote_endpoint_with_powershell.md | 160 - ...ntication_flag_disabled_with_powershell.md | 157 - ...022-03-22-powershell_execute_com_object.md | 169 - ...owershell_using_memory_as_backing_store.md | 164 - ...3-22-recon_avproduct_through_pwh_or_wmi.md | 161 - ...on_via_dcom_and_powershell_script_block.md | 160 - ...n_via_winrm_and_powershell_script_block.md | 161 - ...y_with_env_vars_powershell_script_block.md | 156 - ...24-splunk_dos_via_malformed_s2s_request.md | 162 - ...2022-03-28-sql_injection_with_long_urls.md | 165 - ...try_by_a_non_critical_process_file_path.md | 175 - ...uter_unconstrained_delegation_discovery.md | 164 - ...view_unconstrained_delegation_discovery.md | 164 - ...03-28-windows_terminating_lsass_process.md | 169 - docs/_posts/2022-03-29-macos_plutil.md | 163 - ...022-03-29-windows_iso_lnk_file_creation.md | 178 - ...-30-windows_drivers_loaded_by_signature.md | 171 - ...erview_constrained_delegation_discovery.md | 165 - ...3-31-windows_registry_certificate_added.md | 175 - ..._modification_for_safe_mode_persistence.md | 174 - ...connection_with_powershell_script_block.md | 155 - ...ithub_actions_disable_security_workflow.md | 174 - ...4-windows_driver_load_non-standard_path.md | 164 - ...4-04-windows_event_for_service_disabled.md | 167 - .../2022-04-05-java_writing_jsp_file.md | 187 - ...05-linux_iptables_firewall_modification.md | 167 - ...04-05-linux_kworker_process_commandline.md | 167 - ...nux_stdout_redirection_to_dev_null_file.md | 174 - ...-04-05-spring4shell_payload_url_request.md | 180 - .../2022-04-05-web_jsp_request_via_url.md | 180 - ...eb_spring_cloud_function_functionrouter.md | 169 - ...indirect_command_execution_via_forfiles.md | 169 - ...s_indirect_command_execution_via_pcalua.md | 169 - ..._spring4shell_http_request_class_module.md | 170 - .../2022-04-07-any_powershell_downloadfile.md | 185 - ...022-04-07-any_powershell_downloadstring.md | 179 - .../2022-04-07-detect_html_help_renamed.md | 176 - .../_posts/2022-04-07-detect_mshta_renamed.md | 175 - .../2022-04-07-detect_renamed_psexec.md | 173 - ...ious_microsoft_workflow_compiler_rename.md | 182 - .../2022-04-07-suspicious_msbuild_rename.md | 188 - .../2022-04-07-suspicious_rundll32_rename.md | 186 - ...unt_manipulation_of_ssh_config_and_keys.md | 187 - .../2022-04-12-linux_deletion_of_cron_jobs.md | 187 - ...12-linux_deletion_of_init_daemon_script.md | 187 - .../2022-04-12-linux_deletion_of_services.md | 187 - ...2-04-12-linux_deletion_of_ssh_hash_conf.md | 183 - .../2022-04-12-linux_deletion_of_ssh_key.md | 183 - ...04-12-linux_deletion_of_ssl_certificate.md | 187 - ...requency_of_file_deletion_in_etc_folder.md | 188 - ...2-04-13-windows_registry_delete_task_sd.md | 177 - ...022-04-18-nltest_domain_trust_discovery.md | 174 - ...nux_adding_crontab_using_list_parameter.md | 178 - ...ing_critical_directory_using_rm_command.md | 167 - .../2022-04-22-linux_disable_services.md | 166 - ...equency_of_file_deletion_in_boot_folder.md | 190 - ...022-04-22-linux_shred_overwrite_command.md | 168 - docs/_posts/2022-04-22-linux_stop_services.md | 166 - ...rocesses_killed_by_industroyer2_malware.md | 169 - ...ndows_linked_policies_in_adsi_discovery.md | 168 - ...s_root_domain_linked_policies_discovery.md | 168 - ..._script_contains_base64_encoded_content.md | 172 - ...oup_discovery_with_script_block_logging.md | 167 - ...6-windows_hidden_schedule_task_settings.md | 170 - ...-04-27-splunk_xss_in_monitoring_console.md | 163 - ...ter_account_created_by_computer_account.md | 167 - ...uter_account_requesting_kerberos_ticket.md | 165 - ...windows_kerberos_local_successful_logon.md | 165 - ...04-28-windows_computer_account_with_spn.md | 169 - ...2022-04-29-path_traversal_spl_injection.md | 161 - ...2-04-29-splunk_user_enumeration_attempt.md | 166 - ...30-linux_iptables_firewall_modification.md | 179 - ...worker_process_in_writable_process_path.md | 173 - ...05-02-delete_shadowcopy_with_powershell.md | 159 - ...-05-02-exchange_powershell_module_usage.md | 167 - ...omaintrust_with_powershell_script_block.md | 161 - ...wordpolicy_with_powershell_script_block.md | 157 - ...mainpolicy_with_powershell_script_block.md | 157 - ...adcomputer_with_powershell_script_block.md | 155 - ...incomputer_with_powershell_script_block.md | 155 - ...controller_with_powershell_script_block.md | 155 - ...omaingroup_with_powershell_script_block.md | 160 - ...s_computer_with_powershell_script_block.md | 155 - ...t_ds_group_with_powershell_script_block.md | 160 - ...ct_ds_user_with_powershell_script_block.md | 161 - ...er_account_with_powershell_script_block.md | 165 - .../2022-05-02-mailsniper_invoke_functions.md | 161 - .../2022-05-02-powershell_4104_hunting.md | 341 - ...-05-02-powershell_creating_thread_mutex.md | 168 - ...ading_dotnet_into_memory_via_reflection.md | 167 - ...shell_remove_windows_defender_directory.md | 167 - ...-02-windows_krbrelayup_service_creation.md | 163 - ...2-wmi_recon_running_process_or_services.md | 159 - ...uthentication_discovery_with_get-aduser.md | 161 - ...authentication_discovery_with_powerview.md | 161 - ...ndows_service_create_kernel_mode_driver.md | 179 - ...10-detect_aws_console_login_by_new_user.md | 156 - ...ontrol_rest_vulnerability_cve-2022-1388.md | 171 - ...22-05-11-potential_password_in_username.md | 182 - .../2022-05-16-cobalt_strike_named_pipes.md | 171 - .../2022-05-16-windows_system_file_on_disk.md | 167 - ...e_policy_version_to_allow_all_resources.md | 181 - ...are_server_side_template_injection_hunt.md | 172 - ...eemarker_server-side_template_injection.md | 171 - ...chtasks_scheduling_job_on_remote_system.md | 169 - ...nd_scripting_interpreter_risky_commands.md | 181 - ...rsonation_weak_encryption_simplerequest.md | 162 - ...-splunk_identified_ssl_tls_certificates.md | 166 - ...rsonation_weak_encryption_configuration.md | 167 - ...22-05-26-linux_at_application_execution.md | 177 - ..._append_command_to_at_allow_config_file.md | 176 - docs/_posts/2022-05-26-macos_plutil.md | 166 - ...tal_certificates_infrastructure_version.md | 165 - ...digital_certificates_lack_of_encryption.md | 165 - ...ss_injection_forwarder_bundle_downloads.md | 164 - ...mpersonation_weak_encryption_selfsigned.md | 162 - ..._and_scripting_interpreter_delete_usage.md | 170 - ...nd_scripting_interpreter_risky_spl_mltk.md | 176 - ...ripting_interpreter_path_traversal_exec.md | 170 - ...ws_execute_arbitrary_commands_with_msdt.md | 179 - ...30-windows_office_product_spawning_msdt.md | 185 - ...01-mshtml_module_load_in_office_product.md | 170 - ...spicious_process_with_discord_dns_query.md | 170 - .../2022-06-01-unload_sysmon_filter_driver.md | 168 - ...ess_connecting_to_ip_check_web_services.md | 165 - ...ting_interpreter_hunting_path_traversal.md | 175 - ...ripting_interpreter_path_traversal_exec.md | 170 - ...01-windows_installutil_credential_theft.md | 171 - ...ed_remote_code_execution_cve-2022-26134.md | 176 - ...2-06-03-excessive_usage_of_nslookup_app.md | 165 - .../2022-06-03-java_writing_jsp_file.md | 188 - ...03-linux_iptables_firewall_modification.md | 179 - ...efense_delete_win_defender_context_menu.md | 170 - ...se_delete_win_defender_profile_registry.md | 170 - ...enses_disable_win_defender_auto_logging.md | 170 - ...windows_msiexec_spawn_discovery_command.md | 170 - ...06-14-windows_msiexec_dllregisterserver.md | 171 - ...ws_msiexec_unregister_dllregisterserver.md | 171 - ...ect_risky_spl_using_pretrained_ml_model.md | 167 - ...2-06-16-windows_msiexec_remote_download.md | 171 - ...indows_msiexec_with_network_connections.md | 174 - ...ws_ecr_container_scanning_findings_high.md | 174 - ...work_info_through_ip_check_web_services.md | 170 - ...s_remote_services_allow_rdp_in_firewall.md | 171 - ...remote_services_allow_remote_assistance.md | 170 - ...6-21-windows_remote_services_rdp_enable.md | 169 - ...-06-21-windows_service_stop_by_deletion.md | 168 - ...fy_registry_disable_toast_notifications.md | 165 - ...y_disable_windows_security_center_notif.md | 165 - ..._modify_registry_disabling_wer_settings.md | 165 - ...ws_modify_registry_disallow_windows_app.md | 164 - ...fy_registry_suppress_win_defender_notif.md | 165 - ...werview_kerberos_service_ticket_request.md | 168 - ...2-06-22-windows_powerview_spn_discovery.md | 168 - ...ows_remote_access_software_rms_registry.md | 165 - ...ry_disable_win_defender_raw_write_notif.md | 165 - ...lid_account_with_never_expires_password.md | 171 - ...ayer_protocol_rms_radmin_tool_namedpipe.md | 164 - ..._impair_defense_add_xml_applocker_rules.md | 170 - ...e_deny_security_software_with_applocker.md | 175 - ...dify_registry_regedit_silent_reg_import.md | 170 - ..._remote_service_rdpwinst_tool_execution.md | 174 - ...onnection_from_java_using_default_ports.md | 173 - .../2022-06-28-windows_odbcconf_load_dll.md | 170 - ...mote_system_discovery_with_adsisearcher.md | 154 - ...ws_execute_arbitrary_commands_with_msdt.md | 179 - .../2022-06-30-windows_odbcconf_hunting.md | 170 - ...-30-windows_odbcconf_load_response_file.md | 170 - ...dows_powershell_import_applocker_policy.md | 160 - ...07-07-office_product_writing_cab_or_inf.md | 177 - ...icious_image_creation_in_appdata_folder.md | 163 - ...7-suspicious_wav_file_in_appdata_folder.md | 163 - ...proxy_execution_mavinject_dll_injection.md | 176 - docs/_posts/2022-07-08-living_off_the_land.md | 177 - ...zure_active_directory_high_risk_sign-in.md | 169 - ...umber_of_failed_authentications_from_ip.md | 173 - ...7-11-windows_identify_protocol_handlers.md | 183 - ...defense_evasion_stop_logging_cloudtrail.md | 168 - ...e_users_failing_to_authenticate_from_ip.md | 170 - ...successful_single-factor_authentication.md | 162 - ...-07-12-spring4shell_payload_url_request.md | 180 - ...3-aws_defense_evasion_delete_cloudtrail.md | 168 - ...ad_successful_powershell_authentication.md | 174 - ...hentication_failed_during_mfa_challenge.md | 179 - ...-15-certutil_exe_certificate_extraction.md | 158 - ...-powershell_disable_security_monitoring.md | 171 - ...s_mof_event_triggered_execution_via_wmi.md | 174 - ...nse_evasion_delete_cloudwatch_log_group.md | 168 - ...7-aws_defense_evasion_update_cloudtrail.md | 168 - ...bound_traffic_by_firewall_rule_registry.md | 176 - ...-wmic_noninteractive_app_uninstallation.md | 169 - ..._and_privilege_escalation_risk_behavior.md | 167 - ...7-20-registry_keys_used_for_persistence.md | 177 - ...-aws_defense_evasion_putbucketlifecycle.md | 173 - ...efense_evasion_impair_security_services.md | 171 - ...2022-07-27-linux_decode_base64_to_shell.md | 179 - ...2-07-27-linux_kernel_module_enumeration.md | 174 - ...ated_files_or_information_base64_decode.md | 172 - ...-linux_ssh_authorized_keys_modification.md | 170 - ...inux_ssh_remote_services_script_execute.md | 169 - ...07-27-windows_system_logoff_commandline.md | 170 - ...07-27-windows_system_reboot_commandline.md | 170 - ...-27-windows_system_shutdown_commandline.md | 170 - .../2022-07-28-linux_clipboard_data_copy.md | 170 - ...ws_command_shell_dcrat_forkbomb_payload.md | 177 - ...ndows_system_time_discovery_w32tm_delay.md | 171 - docs/_sass/minimal-mistakes.scss | 40 - docs/_sass/minimal-mistakes/_animations.scss | 21 - docs/_sass/minimal-mistakes/_archive.scss | 463 - docs/_sass/minimal-mistakes/_base.scss | 357 - docs/_sass/minimal-mistakes/_buttons.scss | 97 - docs/_sass/minimal-mistakes/_footer.scss | 85 - docs/_sass/minimal-mistakes/_forms.scss | 359 - docs/_sass/minimal-mistakes/_masthead.scss | 93 - docs/_sass/minimal-mistakes/_mixins.scss | 92 - docs/_sass/minimal-mistakes/_navigation.scss | 573 - docs/_sass/minimal-mistakes/_notices.scss | 105 - docs/_sass/minimal-mistakes/_page.scss | 564 - docs/_sass/minimal-mistakes/_print.scss | 252 - docs/_sass/minimal-mistakes/_reset.scss | 187 - docs/_sass/minimal-mistakes/_search.scss | 132 - docs/_sass/minimal-mistakes/_sidebar.scss | 353 - docs/_sass/minimal-mistakes/_syntax.scss | 324 - docs/_sass/minimal-mistakes/_tables.scss | 39 - docs/_sass/minimal-mistakes/_utilities.scss | 593 - docs/_sass/minimal-mistakes/_variables.scss | 173 - docs/_sass/minimal-mistakes/skins/_air.scss | 23 - docs/_sass/minimal-mistakes/skins/_aqua.scss | 34 - .../minimal-mistakes/skins/_contrast.scss | 52 - docs/_sass/minimal-mistakes/skins/_dark.scss | 30 - .../minimal-mistakes/skins/_default.scss | 5 - docs/_sass/minimal-mistakes/skins/_dirt.scss | 33 - docs/_sass/minimal-mistakes/skins/_mint.scss | 24 - docs/_sass/minimal-mistakes/skins/_neon.scss | 63 - docs/_sass/minimal-mistakes/skins/_plum.scss | 70 - .../minimal-mistakes/skins/_sunrise.scss | 49 - docs/_stories/acidrain.md | 45 - docs/_stories/active_directory_discovery.md | 133 - .../active_directory_kerberos_attacks.md | 82 - .../active_directory_lateral_movement.md | 85 - .../active_directory_password_spraying.md | 52 - docs/_stories/apache_struts_vulnerability.md | 59 - docs/_stories/asset_tracking.md | 44 - ...e_server_and_data_center_cve-2022-26134.md | 46 - docs/_stories/aws_cross_account_activity.md | 47 - docs/_stories/aws_cryptomining.md | 50 - docs/_stories/aws_defense_evasion.md | 46 - docs/_stories/aws_iam_privilege_escalation.md | 54 - docs/_stories/aws_network_acl_activity.md | 47 - docs/_stories/aws_privilege_escalation.md | 70 - docs/_stories/aws_security_hub_alerts.md | 43 - .../aws_suspicious_provisioning_activities.md | 45 - docs/_stories/aws_user_monitoring.md | 51 - docs/_stories/azorult.md | 100 - ...azure_active_directory_account_takeover.md | 52 - docs/_stories/baron_samedit_cve-2021-3156.md | 43 - docs/_stories/bits_jobs.md | 45 - docs/_stories/blackmatter_ransomware.md | 50 - docs/_stories/brand_monitoring.md | 51 - docs/_stories/caddy_wiper.md | 44 - docs/_stories/clop_ransomware.md | 58 - docs/_stories/cloud_cryptomining.md | 50 - .../cloud_federated_credential_abuse.md | 58 - docs/_stories/cobalt_strike.md | 74 - docs/_stories/coldroot_macos_rat.md | 49 - docs/_stories/collection_and_staging.md | 53 - docs/_stories/command_and_control.md | 65 - docs/_stories/common_phishing_frameworks.md | 46 - ...plantation_monitoring_and_investigation.md | 39 - docs/_stories/credential_dumping.md | 74 - docs/_stories/cyclopsblink.md | 45 - docs/_stories/darkcrystal_rat.md | 62 - docs/_stories/darkside_ransomware.md | 60 - docs/_stories/data_destruction.md | 56 - docs/_stories/data_exfiltration.md | 54 - docs/_stories/data_protection.md | 49 - ...deobfuscate-decode_files_or_information.md | 42 - docs/_stories/detect_zerologon_attack.md | 49 - docs/_stories/dev_sec_ops.md | 64 - docs/_stories/dhs_report_ta18-074a.md | 63 - docs/_stories/disabling_security_tools.md | 50 - docs/_stories/dns_amplification_attacks.md | 44 - docs/_stories/dns_hijacking.md | 57 - docs/_stories/domain_trust_discovery.md | 44 - docs/_stories/double_zero_destructor.md | 46 - docs/_stories/dynamic_dns.md | 52 - .../emotet_malware__dhs_report_ta18-201a_.md | 60 - .../f5_big-ip_vulnerability_cve-2022-1388.md | 46 - docs/_stories/f5_tmui_rce_cve-2020-5902.md | 43 - docs/_stories/fin7.md | 55 - docs/_stories/gcp_cross_account_activity.md | 46 - docs/_stories/hafnium_group.md | 66 - docs/_stories/hermetic_wiper.md | 99 - docs/_stories/hidden_cobra_malware.md | 58 - docs/_stories/host_redirection.md | 44 - docs/_stories/icedid.md | 71 - docs/_stories/industroyer2.md | 68 - docs/_stories/information_sabotage.md | 43 - docs/_stories/ingress_tool_transfer.md | 52 - docs/_stories/insider_threat.md | 54 - docs/_stories/jboss_vulnerability.md | 58 - docs/_stories/kubernetes_scanning_activity.md | 46 - ...rnetes_sensitive_object_access_activity.md | 49 - .../kubernetes_sensitive_role_activity.md | 49 - docs/_stories/lateral_movement.md | 78 - docs/_stories/linux_living_off_the_land.md | 68 - docs/_stories/linux_persistence_techniques.md | 80 - docs/_stories/linux_post-exploitation.md | 42 - docs/_stories/linux_privilege_escalation.md | 78 - docs/_stories/linux_rootkit.md | 48 - docs/_stories/living_off_the_land.md | 128 - ...al_privilege_escalation_with_krbrelayup.md | 52 - docs/_stories/log4shell_cve-2021-44228.md | 65 - docs/_stories/malicious_powershell.md | 84 - .../masquerading_-_rename_system_utilities.md | 54 - docs/_stories/meterpreter.md | 47 - ...ml_remote_code_execution_cve-2021-40444.md | 50 - ...ostic_tool_vulnerability_cve-2022-30190.md | 51 - docs/_stories/monitor_backup_solution.md | 42 - .../monitor_for_unauthorized_software.md | 46 - docs/_stories/monitor_for_updates.md | 44 - docs/_stories/netsh_abuse.md | 46 - docs/_stories/network_discovery.md | 44 - docs/_stories/nobelium_group.md | 61 - docs/_stories/office_365_detections.md | 54 - docs/_stories/orangeworm_attack_group.md | 50 - ...n_active_directory_certificate_services.md | 48 - ...ciated_with_mudcarp_espionage_campaigns.md | 75 - .../_stories/printnightmare_cve-2021-34527.md | 59 - ...ed_traffic_allowed_or_protocol_mismatch.md | 53 - docs/_stories/proxyshell.md | 51 - docs/_stories/ransomware.md | 124 - docs/_stories/ransomware_cloud.md | 45 - docs/_stories/remcos.md | 71 - docs/_stories/revil_ransomware.md | 51 - .../router_and_infrastructure_security.md | 54 - docs/_stories/ryuk_ransomware.md | 63 - ...ing_and_domain_controller_impersonation.md | 46 - docs/_stories/samsam_ransomware.md | 70 - ...gned_binary_proxy_execution_installutil.md | 53 - docs/_stories/silver_sparrow.md | 46 - docs/_stories/spearphishing_attachments.md | 74 - .../spectre_and_meltdown_vulnerabilities.md | 42 - .../splunk_enterprise_vulnerability.md | 51 - ...enterprise_vulnerability_cve-2018-11409.md | 46 - docs/_stories/splunk_vulnerabilities.md | 61 - docs/_stories/spring4shell_cve-2022-22965.md | 54 - docs/_stories/sql_injection.md | 44 - .../_stories/suspicious_aws_ec2_activities.md | 47 - .../suspicious_aws_login_activities.md | 46 - docs/_stories/suspicious_aws_s3_activities.md | 48 - docs/_stories/suspicious_aws_traffic.md | 45 - ...picious_cloud_authentication_activities.md | 49 - .../suspicious_cloud_instance_activities.md | 46 - ...uspicious_cloud_provisioning_activities.md | 47 - .../suspicious_cloud_user_activities.md | 50 - .../suspicious_command-line_executions.md | 52 - .../suspicious_compiled_html_activity.md | 50 - docs/_stories/suspicious_dns_traffic.md | 56 - docs/_stories/suspicious_emails.md | 50 - .../suspicious_gcp_storage_activities.md | 43 - docs/_stories/suspicious_mshta_activity.md | 65 - docs/_stories/suspicious_okta_activity.md | 48 - .../suspicious_regsvcs_regasm_activity.md | 49 - docs/_stories/suspicious_regsvr32_activity.md | 49 - docs/_stories/suspicious_rundll32_activity.md | 57 - .../suspicious_windows_registry_activities.md | 55 - docs/_stories/suspicious_wmi_use.md | 54 - .../suspicious_zoom_child_processes.md | 46 - docs/_stories/trickbot.md | 60 - ...ted_developer_utilities_proxy_execution.md | 46 - ...loper_utilities_proxy_execution_msbuild.md | 63 - .../_stories/unusual_aws_ec2_modifications.md | 42 - docs/_stories/unusual_processes.md | 65 - docs/_stories/use_of_cleartext_protocols.md | 43 - ...side_injection_and_privilege_escalation.md | 44 - docs/_stories/web_fraud_detection.md | 50 - docs/_stories/whispergate.md | 66 - .../windows_defense_evasion_tactics.md | 94 - docs/_stories/windows_discovery_techniques.md | 45 - .../windows_dns_sigred_cve-2020-1350.md | 44 - docs/_stories/windows_drivers.md | 53 - ...ws_file_extension_and_association_abuse.md | 49 - docs/_stories/windows_log_manipulation.md | 49 - .../windows_persistence_techniques.md | 77 - docs/_stories/windows_privilege_escalation.md | 56 - docs/_stories/windows_registry_abuse.md | 106 - docs/_stories/windows_service_abuse.md | 46 - ...s_system_binary_proxy_execution_msiexec.md | 46 - docs/_stories/xmrig.md | 68 - docs/assets/css/main.scss | 41 - docs/assets/js/_main.js | 136 - docs/assets/js/lunr/lunr-en.js | 73 - docs/assets/js/lunr/lunr-gr.js | 526 - docs/assets/js/lunr/lunr-store.js | 49 - docs/assets/js/lunr/lunr.js | 3475 - docs/assets/js/lunr/lunr.min.js | 6 - docs/assets/js/main.min.js | 6 - docs/assets/js/plugins/gumshoe.js | 484 - .../js/plugins/jquery.ba-throttle-debounce.js | 252 - docs/assets/js/plugins/jquery.fitvids.js | 82 - .../js/plugins/jquery.greedy-navigation.js | 127 - .../js/plugins/jquery.magnific-popup.js | 1860 - docs/assets/js/plugins/smooth-scroll.js | 650 - docs/detections.wiki | 58930 ---------------- docs/favicon.ico | Bin 15406 -> 0 bytes docs/index.html | 8 - docs/index.markdown | 62 - docs/stories.wiki | 16516 ----- 1497 files changed, 288838 deletions(-) delete mode 100644 docs/Gemfile delete mode 100644 docs/Gemfile.lock delete mode 100644 docs/README.md delete mode 100644 docs/_config.yml delete mode 100644 docs/_data/navigation.yml delete mode 100644 docs/_includes/analytics-providers/custom.html delete mode 100644 docs/_includes/analytics-providers/google-gtag.html delete mode 100644 docs/_includes/analytics-providers/google-universal.html delete mode 100644 docs/_includes/analytics-providers/google.html delete mode 100644 docs/_includes/analytics.html delete mode 100644 docs/_includes/archive-single.html delete mode 100644 docs/_includes/author-profile-custom-links.html delete mode 100644 docs/_includes/author-profile.html delete mode 100644 docs/_includes/breadcrumbs.html delete mode 100644 docs/_includes/browser-upgrade.html delete mode 100644 docs/_includes/category-list.html delete mode 100644 docs/_includes/comment.html delete mode 100644 docs/_includes/comments-providers/custom.html delete mode 100644 docs/_includes/comments-providers/custom_scripts.html delete mode 100644 docs/_includes/comments-providers/discourse.html delete mode 100644 docs/_includes/comments-providers/disqus.html delete mode 100644 docs/_includes/comments-providers/facebook.html delete mode 100644 docs/_includes/comments-providers/giscus.html delete mode 100644 docs/_includes/comments-providers/scripts.html delete mode 100644 docs/_includes/comments-providers/staticman.html delete mode 100644 docs/_includes/comments-providers/staticman_v2.html delete mode 100644 docs/_includes/comments-providers/utterances.html delete mode 100644 docs/_includes/comments.html delete mode 100644 docs/_includes/documents-collection.html delete mode 100644 docs/_includes/feature_row delete mode 100644 docs/_includes/figure delete mode 100644 docs/_includes/footer.html delete mode 100644 docs/_includes/footer/custom.html delete mode 100644 docs/_includes/gallery delete mode 100644 docs/_includes/group-by-array delete mode 100644 docs/_includes/head.html delete mode 100644 docs/_includes/head/custom.html delete mode 100644 docs/_includes/masthead.html delete mode 100644 docs/_includes/nav_list delete mode 100644 docs/_includes/page__date.html delete mode 100644 docs/_includes/page__hero.html delete mode 100644 docs/_includes/page__hero_video.html delete mode 100644 docs/_includes/page__meta.html delete mode 100644 docs/_includes/page__taxonomy.html delete mode 100644 docs/_includes/paginator.html delete mode 100644 docs/_includes/post_pagination.html delete mode 100644 docs/_includes/posts-category.html delete mode 100644 docs/_includes/posts-tag.html delete mode 100644 docs/_includes/scripts.html delete mode 100644 docs/_includes/search/algolia-search-scripts.html delete mode 100644 docs/_includes/search/google-search-scripts.html delete mode 100644 docs/_includes/search/lunr-search-scripts.html delete mode 100644 docs/_includes/search/search_form.html delete mode 100644 docs/_includes/seo.html delete mode 100644 docs/_includes/sidebar.html delete mode 100644 docs/_includes/skip-links.html delete mode 100644 docs/_includes/social-share.html delete mode 100644 docs/_includes/tag-list.html delete mode 100644 docs/_includes/toc delete mode 100644 docs/_includes/toc.html delete mode 100644 docs/_includes/video delete mode 100644 docs/_layouts/archive-taxonomy.html delete mode 100644 docs/_layouts/archive.html delete mode 100644 docs/_layouts/categories.html delete mode 100644 docs/_layouts/category.html delete mode 100644 docs/_layouts/collection.html delete mode 100644 docs/_layouts/compress.html delete mode 100644 docs/_layouts/default.html delete mode 100644 docs/_layouts/home.html delete mode 100644 docs/_layouts/posts.html delete mode 100644 docs/_layouts/search.html delete mode 100644 docs/_layouts/single.html delete mode 100644 docs/_layouts/splash.html delete mode 100644 docs/_layouts/tag.html delete mode 100644 docs/_layouts/tags.html delete mode 100644 docs/_pages/404.md delete mode 100644 docs/_pages/about.md delete mode 100644 docs/_pages/abuse.md delete mode 100644 docs/_pages/account_compromise.md delete mode 100644 docs/_pages/adversary_tactics.md delete mode 100644 docs/_pages/authentication.md delete mode 100644 docs/_pages/best_practices.md delete mode 100644 docs/_pages/certificates.md delete mode 100644 docs/_pages/change.md delete mode 100644 docs/_pages/change_analysis.md delete mode 100644 docs/_pages/cloud_security.md delete mode 100644 docs/_pages/collection.md delete mode 100644 docs/_pages/command_and_control.md delete mode 100644 docs/_pages/credential_access.md delete mode 100644 docs/_pages/data_destruction.md delete mode 100644 docs/_pages/defense_evasion.md delete mode 100644 docs/_pages/detections.md delete mode 100644 docs/_pages/discovery.md delete mode 100644 docs/_pages/email.md delete mode 100644 docs/_pages/endpoint.md delete mode 100644 docs/_pages/endpoint_filesystem.md delete mode 100644 docs/_pages/endpoint_processes.md delete mode 100644 docs/_pages/endpoint_registry.md delete mode 100644 docs/_pages/execution.md delete mode 100644 docs/_pages/exfiltration.md delete mode 100644 docs/_pages/impact.md delete mode 100644 docs/_pages/initial_access.md delete mode 100644 docs/_pages/lateral_movement.md delete mode 100644 docs/_pages/malware.md delete mode 100644 docs/_pages/network_resolution.md delete mode 100644 docs/_pages/network_sessions.md delete mode 100644 docs/_pages/network_traffic.md delete mode 100644 docs/_pages/ooo.md delete mode 100644 docs/_pages/paybooks.md delete mode 100644 docs/_pages/persistence.md delete mode 100644 docs/_pages/playbooks.md delete mode 100644 docs/_pages/privilege_escalation.md delete mode 100644 docs/_pages/ransomware.md delete mode 100644 docs/_pages/reconnaissance.md delete mode 100644 docs/_pages/resource_development.md delete mode 100644 docs/_pages/risk.md delete mode 100644 docs/_pages/splunk_audit.md delete mode 100644 docs/_pages/splunk_behavioral_analytics.md delete mode 100644 docs/_pages/splunk_enterprise_security.md delete mode 100644 docs/_pages/splunk_security_analytics_for_aws.md delete mode 100644 docs/_pages/stories.md delete mode 100644 docs/_pages/tag-archive.md delete mode 100644 docs/_pages/ueba.md delete mode 100644 docs/_pages/unauthorized_software.md delete mode 100644 docs/_pages/updates.md delete mode 100644 docs/_pages/vulnerabilities.md delete mode 100644 docs/_pages/vulnerability.md delete mode 100644 docs/_pages/web.md delete mode 100644 docs/_playbooks/active_directory_reset_password.md delete mode 100644 docs/_playbooks/aws_disable_user_accounts.md delete mode 100644 docs/_playbooks/aws_find_inactive_users.md delete mode 100644 docs/_playbooks/block_indicators.md delete mode 100644 docs/_playbooks/crowdstrike_malware_triage.md delete mode 100644 docs/_playbooks/delete_detected_files.md delete mode 100644 docs/_playbooks/email_notification_for_malware.md delete mode 100644 docs/_playbooks/internal_host_ssh_investigate.md delete mode 100644 docs/_playbooks/internal_host_ssh_log4j_investigate.md delete mode 100644 docs/_playbooks/internal_host_ssh_log4j_respond.md delete mode 100644 docs/_playbooks/internal_host_ssh_log4j_response.md delete mode 100644 docs/_playbooks/internal_host_winrm_investigate.md delete mode 100644 docs/_playbooks/internal_host_winrm_log4j_investigate.md delete mode 100644 docs/_playbooks/internal_host_winrm_response.md delete mode 100644 docs/_playbooks/log4j_investigate.md delete mode 100644 docs/_playbooks/log4j_respond.md delete mode 100644 docs/_playbooks/log4j_splunk_investigation.md delete mode 100644 docs/_playbooks/malware_hunt_and_contain.md delete mode 100644 docs/_playbooks/ransomware_investigate_and_contain.md delete mode 100644 docs/_playbooks/risk_notable_block_indicators.md delete mode 100644 docs/_playbooks/risk_notable_enrich.md delete mode 100644 docs/_playbooks/risk_notable_import_data.md delete mode 100644 docs/_playbooks/risk_notable_investigate.md delete mode 100644 docs/_playbooks/risk_notable_merge_events.md delete mode 100644 docs/_playbooks/risk_notable_mitigate.md delete mode 100644 docs/_playbooks/risk_notable_preprocess.md delete mode 100644 docs/_playbooks/risk_notable_protect_assets_and_users.md delete mode 100644 docs/_playbooks/risk_notable_review_indicators.md delete mode 100644 docs/_playbooks/risk_notable_verdict.md delete mode 100644 docs/_playbooks/start_investigation.md delete mode 100644 docs/_playbooks/threat_intel_investigate.md delete mode 100644 docs/_playbooks/trustar_enrich_indicators.md delete mode 100644 docs/_posts/2017-01-07-spectre_and_meltdown_vulnerable_systems.md delete mode 100644 docs/_posts/2017-09-12-detect_new_login_attempts_to_routers.md delete mode 100644 docs/_posts/2017-09-12-extended_period_without_successful_netbackup_backups.md delete mode 100644 docs/_posts/2017-09-12-identify_new_user_accounts.md delete mode 100644 docs/_posts/2017-09-12-unsuccessful_netbackup_backups.md delete mode 100644 docs/_posts/2017-09-13-detect_unauthorized_assets_by_mac_address.md delete mode 100644 docs/_posts/2017-09-15-no_windows_updates_in_a_time_frame.md delete mode 100644 docs/_posts/2017-09-19-email_attachments_with_lots_of_spaces.md delete mode 100644 docs/_posts/2017-09-19-open_redirect_in_splunk_web.md delete mode 100644 docs/_posts/2017-09-20-large_volume_of_dns_any_queries.md delete mode 100644 docs/_posts/2017-09-23-detect_attackers_scanning_for_vulnerable_jboss_servers.md delete mode 100644 docs/_posts/2017-09-23-detect_malicious_requests_to_exploit_jboss_servers.md delete mode 100644 docs/_posts/2017-09-23-monitor_dns_for_brand_abuse.md delete mode 100644 docs/_posts/2017-09-23-monitor_web_traffic_for_brand_abuse.md delete mode 100644 docs/_posts/2017-10-13-unusually_long_content-type_length.md delete mode 100644 docs/_posts/2017-11-27-detect_usb_device_insertion.md delete mode 100644 docs/_posts/2018-01-05-monitor_email_for_brand_abuse.md delete mode 100644 docs/_posts/2018-02-23-ec2_instance_started_in_previously_unseen_region.md delete mode 100644 docs/_posts/2018-03-12-ec2_instance_started_with_previously_unseen_ami.md delete mode 100644 docs/_posts/2018-03-16-aws_cloud_provisioning_from_previously_unseen_city.md delete mode 100644 docs/_posts/2018-03-16-aws_cloud_provisioning_from_previously_unseen_country.md delete mode 100644 docs/_posts/2018-03-16-aws_cloud_provisioning_from_previously_unseen_ip_address.md delete mode 100644 docs/_posts/2018-03-16-aws_cloud_provisioning_from_previously_unseen_region.md delete mode 100644 docs/_posts/2018-04-16-detect_new_api_calls_from_user_roles.md delete mode 100644 docs/_posts/2018-04-18-detect_spike_in_security_group_activity.md delete mode 100644 docs/_posts/2018-05-07-detect_spike_in_blocked_outbound_traffic_from_your_aws.md delete mode 100644 docs/_posts/2018-05-17-detect_api_activity_from_users_without_mfa.md delete mode 100644 docs/_posts/2018-05-21-detect_spike_in_network_acl_activity.md delete mode 100644 docs/_posts/2018-06-01-detect_large_outbound_icmp_packets.md delete mode 100644 docs/_posts/2018-06-14-splunk_enterprise_information_disclosure.md delete mode 100644 docs/_posts/2018-06-28-detect_s3_access_from_a_new_ip.md delete mode 100644 docs/_posts/2018-10-08-web_fraud_-_account_harvesting.md delete mode 100644 docs/_posts/2018-10-08-web_fraud_-_anomalous_user_clickspeed.md delete mode 100644 docs/_posts/2018-10-08-web_fraud_-_password_sharing_across_accounts.md delete mode 100644 docs/_posts/2018-10-12-cloud_compute_instance_created_with_previously_unseen_image.md delete mode 100644 docs/_posts/2018-10-23-wmi_permanent_event_subscription.md delete mode 100644 docs/_posts/2018-10-23-wmi_temporary_event_subscription.md delete mode 100644 docs/_posts/2018-11-02-windows_hosts_file_modification.md delete mode 100644 docs/_posts/2018-11-27-detect_spike_in_s3_bucket_deletion.md delete mode 100644 docs/_posts/2018-12-03-remote_wmi_command_attempt.md delete mode 100644 docs/_posts/2018-12-03-usn_journal_deletion.md delete mode 100644 docs/_posts/2018-12-06-suspicious_java_classes.md delete mode 100644 docs/_posts/2018-12-14-file_with_samsam_extension.md delete mode 100644 docs/_posts/2018-12-14-samsam_test_file_write.md delete mode 100644 docs/_posts/2019-01-25-processes_tapping_keyboard_events.md delete mode 100644 docs/_posts/2019-01-29-osquery_pack_-_coldroot_detection.md delete mode 100644 docs/_posts/2019-02-27-detect_mimikatz_via_powershell_and_eventcode_4703.md delete mode 100644 docs/_posts/2019-02-27-reg_exe_used_to_hide_files_directories_via_registry_keys.md delete mode 100644 docs/_posts/2019-04-01-web_servers_executing_suspicious_processes.md delete mode 100644 docs/_posts/2019-04-25-suspicious_file_write.md delete mode 100644 docs/_posts/2019-05-08-unusually_long_command_line_-_mltk.md delete mode 100644 docs/_posts/2019-10-11-prohibited_software_on_endpoint.md delete mode 100644 docs/_posts/2019-12-03-detect_credential_dumping_through_lsass_access.md delete mode 100644 docs/_posts/2019-12-03-detect_mimikatz_using_loaded_images.md delete mode 100644 docs/_posts/2019-12-06-access_lsass_memory_for_dump_creation.md delete mode 100644 docs/_posts/2019-12-06-create_remote_thread_into_lsass.md delete mode 100644 docs/_posts/2019-12-06-unsigned_image_loaded_by_lsass.md delete mode 100644 docs/_posts/2019-12-10-creation_of_shadow_copy.md delete mode 100644 docs/_posts/2020-01-22-dns_query_length_outliers_-_mltk.md delete mode 100644 docs/_posts/2020-01-28-auto_admin_logon_registry_entry.md delete mode 100644 docs/_posts/2020-01-28-monitor_registry_keys_for_print_monitors.md delete mode 100644 docs/_posts/2020-01-28-registry_keys_for_creating_shim_databases.md delete mode 100644 docs/_posts/2020-01-28-sdclt_uac_bypass.md delete mode 100644 docs/_posts/2020-01-28-silentcleanup_uac_bypass.md delete mode 100644 docs/_posts/2020-01-28-wsreset_uac_bypass.md delete mode 100644 docs/_posts/2020-02-03-creation_of_lsass_dump_with_taskmgr.md delete mode 100644 docs/_posts/2020-02-07-ec2_instance_started_with_previously_unseen_instance_type.md delete mode 100644 docs/_posts/2020-02-07-macos_-_re-opened_applications.md delete mode 100644 docs/_posts/2020-02-20-gcp_gcr_container_uploaded.md delete mode 100644 docs/_posts/2020-02-20-new_container_uploaded_to_aws_ecr.md delete mode 100644 docs/_posts/2020-02-21-dump_lsass_via_comsvcs_dll.md delete mode 100644 docs/_posts/2020-03-02-remote_registry_key_modifications.md delete mode 100644 docs/_posts/2020-03-16-child_processes_of_spoolsv_exe.md delete mode 100644 docs/_posts/2020-03-16-detect_rare_executables.md delete mode 100644 docs/_posts/2020-03-16-process_execution_via_wmi.md delete mode 100644 docs/_posts/2020-03-16-script_execution_via_wmi.md delete mode 100644 docs/_posts/2020-03-16-spike_in_file_writes.md delete mode 100644 docs/_posts/2020-04-15-amazon_eks_kubernetes_cluster_scan_detection.md delete mode 100644 docs/_posts/2020-04-15-amazon_eks_kubernetes_pod_scan_detection.md delete mode 100644 docs/_posts/2020-04-15-gcp_kubernetes_cluster_scan_detection.md delete mode 100644 docs/_posts/2020-05-19-kubernetes_azure_scan_fingerprint.md delete mode 100644 docs/_posts/2020-05-20-first_time_seen_child_process_of_zoom.md delete mode 100644 docs/_posts/2020-05-20-kubernetes_azure_detect_sensitive_object_access.md delete mode 100644 docs/_posts/2020-05-20-kubernetes_azure_detect_sensitive_role_access.md delete mode 100644 docs/_posts/2020-05-20-kubernetes_azure_detect_service_accounts_forbidden_failure_access.md delete mode 100644 docs/_posts/2020-05-20-kubernetes_azure_pod_scan_fingerprint.md delete mode 100644 docs/_posts/2020-05-26-kubernetes_azure_active_service_accounts_by_pod_namespace.md delete mode 100644 docs/_posts/2020-05-26-kubernetes_azure_detect_most_active_service_accounts_by_pod_namespace.md delete mode 100644 docs/_posts/2020-05-26-kubernetes_azure_detect_rbac_authorization_by_account.md delete mode 100644 docs/_posts/2020-05-26-kubernetes_azure_detect_suspicious_kubectl_calls.md delete mode 100644 docs/_posts/2020-05-28-aws_cross_account_activity_from_previously_unseen_account.md delete mode 100644 docs/_posts/2020-05-28-detect_aws_console_login_by_new_user.md delete mode 100644 docs/_posts/2020-06-23-aws_eks_kubernetes_cluster_sensitive_object_access.md delete mode 100644 docs/_posts/2020-06-23-kubernetes_aws_detect_most_active_service_accounts_by_pod.md delete mode 100644 docs/_posts/2020-06-23-kubernetes_aws_detect_rbac_authorization_by_account.md delete mode 100644 docs/_posts/2020-06-23-kubernetes_aws_detect_sensitive_role_access.md delete mode 100644 docs/_posts/2020-06-23-kubernetes_aws_detect_service_accounts_forbidden_failure_access.md delete mode 100644 docs/_posts/2020-06-23-kubernetes_aws_detect_suspicious_kubectl_calls.md delete mode 100644 docs/_posts/2020-06-23-kubernetes_gcp_detect_service_accounts_forbidden_failure_access.md delete mode 100644 docs/_posts/2020-07-03-detect_path_interception_by_creation_of_program_exe.md delete mode 100644 docs/_posts/2020-07-06-short_lived_windows_accounts.md delete mode 100644 docs/_posts/2020-07-06-windows_event_log_cleared.md delete mode 100644 docs/_posts/2020-07-07-remote_desktop_network_traffic.md delete mode 100644 docs/_posts/2020-07-08-detect_new_local_admin_account.md delete mode 100644 docs/_posts/2020-07-10-kubernetes_gcp_detect_most_active_service_accounts_by_pod.md delete mode 100644 docs/_posts/2020-07-11-kubernetes_gcp_detect_rbac_authorizations_by_account.md delete mode 100644 docs/_posts/2020-07-11-kubernetes_gcp_detect_sensitive_object_access.md delete mode 100644 docs/_posts/2020-07-11-kubernetes_gcp_detect_sensitive_role_access.md delete mode 100644 docs/_posts/2020-07-11-kubernetes_gcp_detect_suspicious_kubectl_calls.md delete mode 100644 docs/_posts/2020-07-17-gcp_kubernetes_cluster_pod_scan_detection.md delete mode 100644 docs/_posts/2020-07-21-abnormally_high_aws_instances_launched_by_user.md delete mode 100644 docs/_posts/2020-07-21-abnormally_high_aws_instances_launched_by_user_-_mltk.md delete mode 100644 docs/_posts/2020-07-21-abnormally_high_aws_instances_terminated_by_user.md delete mode 100644 docs/_posts/2020-07-21-abnormally_high_aws_instances_terminated_by_user_-_mltk.md delete mode 100644 docs/_posts/2020-07-21-attempt_to_stop_security_service.md delete mode 100644 docs/_posts/2020-07-21-clients_connecting_to_multiple_dns_servers.md delete mode 100644 docs/_posts/2020-07-21-detect_aws_api_activities_from_unapproved_accounts.md delete mode 100644 docs/_posts/2020-07-21-detect_dns_requests_to_phishing_sites_leveraging_evilginx2.md delete mode 100644 docs/_posts/2020-07-21-detect_excessive_user_account_lockouts.md delete mode 100644 docs/_posts/2020-07-21-detect_long_dns_txt_record_response.md delete mode 100644 docs/_posts/2020-07-21-detect_new_user_aws_console_login.md delete mode 100644 docs/_posts/2020-07-21-detect_outbound_smb_traffic.md delete mode 100644 docs/_posts/2020-07-21-detect_outlook_exe_writing_a_zip_file.md delete mode 100644 docs/_posts/2020-07-21-detect_spike_in_aws_api_activity.md delete mode 100644 docs/_posts/2020-07-21-detect_use_of_cmd_exe_to_launch_script_interpreters.md delete mode 100644 docs/_posts/2020-07-21-detect_web_traffic_to_dynamic_domain_providers.md delete mode 100644 docs/_posts/2020-07-21-detection_of_tools_built_by_nirsoft.md delete mode 100644 docs/_posts/2020-07-21-dns_query_requests_resolved_by_unauthorized_dns_servers.md delete mode 100644 docs/_posts/2020-07-21-dns_record_changed.md delete mode 100644 docs/_posts/2020-07-21-ec2_instance_modified_with_previously_unseen_user.md delete mode 100644 docs/_posts/2020-07-21-ec2_instance_started_with_previously_unseen_user.md delete mode 100644 docs/_posts/2020-07-21-email_files_written_outside_of_the_outlook_directory.md delete mode 100644 docs/_posts/2020-07-21-email_servers_sending_high_volume_traffic_to_hosts.md delete mode 100644 docs/_posts/2020-07-21-excessive_dns_failures.md delete mode 100644 docs/_posts/2020-07-21-first_time_seen_command_line_argument.md delete mode 100644 docs/_posts/2020-07-21-first_time_seen_running_windows_service.md delete mode 100644 docs/_posts/2020-07-21-hiding_files_and_directories_with_attrib_exe.md delete mode 100644 docs/_posts/2020-07-21-hosts_receiving_high_volume_of_network_traffic_from_email_server.md delete mode 100644 docs/_posts/2020-07-21-malicious_powershell_process_-_execution_policy_bypass.md delete mode 100644 docs/_posts/2020-07-21-multiple_okta_users_with_invalid_credentials_from_the_same_ip.md delete mode 100644 docs/_posts/2020-07-21-okta_account_lockout_events.md delete mode 100644 docs/_posts/2020-07-21-okta_failed_sso_attempts.md delete mode 100644 docs/_posts/2020-07-21-okta_user_logins_from_multiple_cities.md delete mode 100644 docs/_posts/2020-07-21-overwriting_accessibility_binaries.md delete mode 100644 docs/_posts/2020-07-21-prohibited_network_traffic_allowed.md delete mode 100644 docs/_posts/2020-07-21-protocol_or_port_mismatch.md delete mode 100644 docs/_posts/2020-07-21-remote_desktop_network_bruteforce.md delete mode 100644 docs/_posts/2020-07-21-remote_desktop_process_running_on_system.md delete mode 100644 docs/_posts/2020-07-21-sc_exe_manipulating_windows_services.md delete mode 100644 docs/_posts/2020-07-21-scheduled_tasks_used_in_badrabbit_ransomware.md delete mode 100644 docs/_posts/2020-07-21-sql_injection_with_long_urls.md delete mode 100644 docs/_posts/2020-07-22-smb_traffic_spike.md delete mode 100644 docs/_posts/2020-07-22-smb_traffic_spike_-_mltk.md delete mode 100644 docs/_posts/2020-07-22-suspicious_changes_to_file_associations.md delete mode 100644 docs/_posts/2020-07-22-suspicious_email_-_uba_anomaly.md delete mode 100644 docs/_posts/2020-07-22-suspicious_email_attachment_extensions.md delete mode 100644 docs/_posts/2020-07-22-suspicious_reg_exe_process.md delete mode 100644 docs/_posts/2020-07-22-suspicious_writes_to_system_volume_information.md delete mode 100644 docs/_posts/2020-07-22-suspicious_writes_to_windows_recycle_bin.md delete mode 100644 docs/_posts/2020-07-22-tor_traffic.md delete mode 100644 docs/_posts/2020-07-22-uncommon_processes_on_endpoint.md delete mode 100644 docs/_posts/2020-07-22-unload_sysmon_filter_driver.md delete mode 100644 docs/_posts/2020-07-27-aws_detect_attach_to_role_policy.md delete mode 100644 docs/_posts/2020-07-27-aws_detect_permanent_key_creation.md delete mode 100644 docs/_posts/2020-07-27-aws_detect_role_creation.md delete mode 100644 docs/_posts/2020-07-27-aws_detect_sts_assume_role_abuse.md delete mode 100644 docs/_posts/2020-07-27-aws_detect_sts_get_session_token_abuse.md delete mode 100644 docs/_posts/2020-07-28-detect_windows_dns_sigred_via_splunk_stream.md delete mode 100644 docs/_posts/2020-07-28-detect_windows_dns_sigred_via_zeek.md delete mode 100644 docs/_posts/2020-07-29-cloud_instance_modified_by_previously_unseen_user.md delete mode 100644 docs/_posts/2020-08-02-detect_f5_tmui_rce_cve-2020-5902.md delete mode 100644 docs/_posts/2020-08-05-detect_new_open_gcp_storage_buckets.md delete mode 100644 docs/_posts/2020-08-10-detect_gcp_storage_access_from_a_new_ip.md delete mode 100644 docs/_posts/2020-08-11-detect_arp_poisoning.md delete mode 100644 docs/_posts/2020-08-11-detect_rogue_dhcp_server.md delete mode 100644 docs/_posts/2020-08-16-cloud_provisioning_activity_from_previously_unseen_ip_address.md delete mode 100644 docs/_posts/2020-08-16-cloud_provisioning_activity_from_previously_unseen_region.md delete mode 100644 docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_destroyed.md delete mode 100644 docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_launched.md delete mode 100644 docs/_posts/2020-08-25-phishing_email_detection_by_machine_learning_method_-_ssa.md delete mode 100644 docs/_posts/2020-08-25-system_process_running_from_unexpected_location.md delete mode 100644 docs/_posts/2020-08-25-unusual_lolbas_in_short_period_of_time.md delete mode 100644 docs/_posts/2020-09-01-gcp_detect_oauth_token_abuse.md delete mode 100644 docs/_posts/2020-09-02-cloud_compute_instance_created_in_previously_unused_region.md delete mode 100644 docs/_posts/2020-09-04-cloud_api_calls_from_previously_unseen_user_roles.md delete mode 100644 docs/_posts/2020-09-07-abnormally_high_number_of_cloud_infrastructure_api_calls.md delete mode 100644 docs/_posts/2020-09-07-abnormally_high_number_of_cloud_security_group_api_calls.md delete mode 100644 docs/_posts/2020-09-08-cloud_network_access_control_list_deleted.md delete mode 100644 docs/_posts/2020-09-12-cloud_compute_instance_created_with_previously_unseen_instance_type.md delete mode 100644 docs/_posts/2020-09-15-detect_zerologon_via_zeek.md delete mode 100644 docs/_posts/2020-09-16-create_or_delete_windows_shares_using_net_exe.md delete mode 100644 docs/_posts/2020-09-18-detect_computer_changed_with_anonymous_account.md delete mode 100644 docs/_posts/2020-10-07-detect_aws_console_login_by_user_from_new_city.md delete mode 100644 docs/_posts/2020-10-07-detect_aws_console_login_by_user_from_new_country.md delete mode 100644 docs/_posts/2020-10-07-detect_aws_console_login_by_user_from_new_region.md delete mode 100644 docs/_posts/2020-10-08-gcp_detect_gcploit_framework.md delete mode 100644 docs/_posts/2020-10-09-cloud_provisioning_activity_from_previously_unseen_city.md delete mode 100644 docs/_posts/2020-10-09-cloud_provisioning_activity_from_previously_unseen_country.md delete mode 100644 docs/_posts/2020-10-09-gcp_detect_accounts_with_high_risk_roles_by_project.md delete mode 100644 docs/_posts/2020-10-09-gcp_detect_high_risk_permissions_by_resource_and_account.md delete mode 100644 docs/_posts/2020-10-15-detect_activity_related_to_pass_the_hash_attacks.md delete mode 100644 docs/_posts/2020-10-21-detect_kerberoasting.md delete mode 100644 docs/_posts/2020-10-21-detect_snicat_sni_exfiltration.md delete mode 100644 docs/_posts/2020-10-28-detect_ipv6_network_infrastructure_threats.md delete mode 100644 docs/_posts/2020-10-28-detect_port_security_violation.md delete mode 100644 docs/_posts/2020-10-28-detect_software_download_to_network_device.md delete mode 100644 docs/_posts/2020-10-28-detect_traffic_mirroring.md delete mode 100644 docs/_posts/2020-11-06-ryuk_test_files_detected.md delete mode 100644 docs/_posts/2020-11-06-windows_connhost_exe_started_forcefully.md delete mode 100644 docs/_posts/2020-11-06-windows_security_account_manager_stopped.md delete mode 100644 docs/_posts/2020-11-09-common_ransomware_extensions.md delete mode 100644 docs/_posts/2020-11-09-common_ransomware_notes.md delete mode 100644 docs/_posts/2020-11-09-deleting_shadow_copies.md delete mode 100644 docs/_posts/2020-11-09-detect_excessive_account_lockouts_from_endpoint.md delete mode 100644 docs/_posts/2020-11-10-detect_processes_used_for_system_network_configuration_discovery.md delete mode 100644 docs/_posts/2020-11-10-detect_prohibited_applications_spawning_cmd_exe.md delete mode 100644 docs/_posts/2020-11-18-disabling_remote_user_account_control.md delete mode 100644 docs/_posts/2020-11-18-execution_of_file_with_multiple_extensions.md delete mode 100644 docs/_posts/2020-11-19-execution_of_file_with_spaces_before_extension.md delete mode 100644 docs/_posts/2020-11-23-processes_created_by_netsh.md delete mode 100644 docs/_posts/2020-11-23-shim_database_installation_with_suspicious_parameters.md delete mode 100644 docs/_posts/2020-11-26-reg_exe_manipulating_windows_services_registry_keys.md delete mode 100644 docs/_posts/2020-12-07-schtasks_used_for_forcing_a_reboot.md delete mode 100644 docs/_posts/2020-12-08-shim_database_file_creation.md delete mode 100644 docs/_posts/2020-12-08-single_letter_process_on_endpoint.md delete mode 100644 docs/_posts/2020-12-08-system_processes_run_from_unexpected_locations.md delete mode 100644 docs/_posts/2020-12-08-unusually_long_command_line.md delete mode 100644 docs/_posts/2020-12-08-wmi_permanent_event_subscription_-_sysmon.md delete mode 100644 docs/_posts/2020-12-14-sunburst_correlation_dll_and_network_event.md delete mode 100644 docs/_posts/2020-12-15-o365_suspicious_rights_delegation.md delete mode 100644 docs/_posts/2020-12-16-high_number_of_login_failures_from_a_single_source.md delete mode 100644 docs/_posts/2020-12-16-o365_pst_export_alert.md delete mode 100644 docs/_posts/2020-12-16-o365_suspicious_admin_email_forwarding.md delete mode 100644 docs/_posts/2020-12-16-o365_suspicious_user_email_forwarding.md delete mode 100644 docs/_posts/2020-12-21-bcdedit_failure_recovery_modification.md delete mode 100644 docs/_posts/2021-01-06-supernova_webshell.md delete mode 100644 docs/_posts/2021-01-11-aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.md delete mode 100644 docs/_posts/2021-01-11-aws_detect_users_with_kms_keys_performing_encryption_s3.md delete mode 100644 docs/_posts/2021-01-11-aws_network_access_control_list_created_with_all_open_ports.md delete mode 100644 docs/_posts/2021-01-12-aws_network_access_control_list_deleted.md delete mode 100644 docs/_posts/2021-01-12-suspicious_microsoft_workflow_compiler_usage.md delete mode 100644 docs/_posts/2021-01-12-suspicious_msbuild_path.md delete mode 100644 docs/_posts/2021-01-12-suspicious_msbuild_rename.md delete mode 100644 docs/_posts/2021-01-12-suspicious_msbuild_spawn.md delete mode 100644 docs/_posts/2021-01-12-suspicious_mshta_child_process.md delete mode 100644 docs/_posts/2021-01-14-detect_hosts_connecting_to_dynamic_domain_providers.md delete mode 100644 docs/_posts/2021-01-19-malicious_powershell_process_-_multiple_suspicious_command-line_arguments.md delete mode 100644 docs/_posts/2021-01-19-malicious_powershell_process_with_obfuscation_techniques.md delete mode 100644 docs/_posts/2021-01-19-suspicious_powershell_command-line_arguments.md delete mode 100644 docs/_posts/2021-01-20-detect_rundll32_inline_hta_execution.md delete mode 100644 docs/_posts/2021-01-20-suspicious_mshta_spawn.md delete mode 100644 docs/_posts/2021-01-22-wbadmin_delete_system_backups.md delete mode 100644 docs/_posts/2021-01-25-nltest_domain_trust_discovery.md delete mode 100644 docs/_posts/2021-01-26-aws_saml_access_by_provider_user_and_principal.md delete mode 100644 docs/_posts/2021-01-26-aws_saml_update_identity_provider.md delete mode 100644 docs/_posts/2021-01-26-certutil_exe_certificate_extraction.md delete mode 100644 docs/_posts/2021-01-26-detect_spike_in_aws_security_hub_alerts_for_ec2_instance.md delete mode 100644 docs/_posts/2021-01-26-detect_spike_in_aws_security_hub_alerts_for_user.md delete mode 100644 docs/_posts/2021-01-26-o365_add_app_role_assignment_grant_user.md delete mode 100644 docs/_posts/2021-01-26-o365_excessive_sso_logon_errors.md delete mode 100644 docs/_posts/2021-01-26-o365_new_federated_domain_added.md delete mode 100644 docs/_posts/2021-01-26-revil_registry_entry.md delete mode 100644 docs/_posts/2021-01-27-detect_baron_samedit_cve-2021-3156.md delete mode 100644 docs/_posts/2021-01-28-detect_baron_samedit_cve-2021-3156_via_osquery.md delete mode 100644 docs/_posts/2021-01-28-detect_regsvr32_application_control_bypass.md delete mode 100644 docs/_posts/2021-01-28-ntdsutil_export_ntds.md delete mode 100644 docs/_posts/2021-01-28-suspicious_regsvr32_register_suspicious_path.md delete mode 100644 docs/_posts/2021-01-29-detect_baron_samedit_cve-2021-3156_segfault.md delete mode 100644 docs/_posts/2021-02-01-dump_lsass_via_procdump_rename.md delete mode 100644 docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_advpack.md delete mode 100644 docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_setupapi.md delete mode 100644 docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_syssetup.md delete mode 100644 docs/_posts/2021-02-04-suspicious_rundll32_startw.md delete mode 100644 docs/_posts/2021-02-09-suspicious_rundll32_dllregisterserver.md delete mode 100644 docs/_posts/2021-02-11-detect_html_help_spawn_child_process.md delete mode 100644 docs/_posts/2021-02-12-detect_regasm_spawning_a_process.md delete mode 100644 docs/_posts/2021-02-12-detect_regsvcs_spawning_a_process.md delete mode 100644 docs/_posts/2021-02-22-aws_create_policy_version_to_allow_all_resources.md delete mode 100644 docs/_posts/2021-02-22-cobalt_strike_named_pipes.md delete mode 100644 docs/_posts/2021-02-22-suspicious_curl_network_connection.md delete mode 100644 docs/_posts/2021-02-22-suspicious_plistbuddy_usage.md delete mode 100644 docs/_posts/2021-02-22-suspicious_plistbuddy_usage_via_osquery.md delete mode 100644 docs/_posts/2021-02-22-suspicious_sqlite3_lsquarantine_behavior.md delete mode 100644 docs/_posts/2021-03-01-any_powershell_downloadfile.md delete mode 100644 docs/_posts/2021-03-01-any_powershell_downloadstring.md delete mode 100644 docs/_posts/2021-03-01-fodhelper_uac_bypass.md delete mode 100644 docs/_posts/2021-03-01-ryuk_wake_on_lan_command.md delete mode 100644 docs/_posts/2021-03-01-suspicious_scheduled_task_from_public_directory.md delete mode 100644 docs/_posts/2021-03-02-aws_setdefaultpolicyversion.md delete mode 100644 docs/_posts/2021-03-02-unified_messaging_service_spawning_a_process.md delete mode 100644 docs/_posts/2021-03-02-windows_disableantispyware_registry.md delete mode 100644 docs/_posts/2021-03-03-nishang_powershelltcponeline.md delete mode 100644 docs/_posts/2021-03-03-w3wp_spawning_shell.md delete mode 100644 docs/_posts/2021-03-12-ransomware_notes_bulk_creation.md delete mode 100644 docs/_posts/2021-03-12-resize_shadowstorage_volume.md delete mode 100644 docs/_posts/2021-03-16-high_process_termination_frequency.md delete mode 100644 docs/_posts/2021-03-16-windows_high_file_deletion_frequency.md delete mode 100644 docs/_posts/2021-03-17-clop_common_exec_parameter.md delete mode 100644 docs/_posts/2021-03-17-clop_ransomware_known_service_name.md delete mode 100644 docs/_posts/2021-03-23-certutil_with_decode_argument.md delete mode 100644 docs/_posts/2021-03-29-powershell_start-bitstransfer.md delete mode 100644 docs/_posts/2021-03-31-aws_iam_successful_group_deletion.md delete mode 100644 docs/_posts/2021-03-31-disabling_firewall_with_netsh.md delete mode 100644 docs/_posts/2021-03-31-dsquery_domain_discovery.md delete mode 100644 docs/_posts/2021-04-01-aws_iam_assume_role_policy_brute_force.md delete mode 100644 docs/_posts/2021-04-01-aws_iam_delete_policy.md delete mode 100644 docs/_posts/2021-04-01-aws_iam_failure_group_deletion.md delete mode 100644 docs/_posts/2021-04-07-malicious_powershell_executed_as_a_service.md delete mode 100644 docs/_posts/2021-04-08-multiple_users_failing_to_authenticate_from_host_using_kerberos.md delete mode 100644 docs/_posts/2021-04-08-winevent_scheduled_task_created_within_public_path.md delete mode 100644 docs/_posts/2021-04-12-excel_spawning_powershell.md delete mode 100644 docs/_posts/2021-04-12-excel_spawning_windows_script_host.md delete mode 100644 docs/_posts/2021-04-12-winevent_scheduled_task_created_to_spawn_shell.md delete mode 100644 docs/_posts/2021-04-12-winword_spawning_powershell.md delete mode 100644 docs/_posts/2021-04-12-winword_spawning_windows_script_host.md delete mode 100644 docs/_posts/2021-04-13-aws_excessive_security_scanning.md delete mode 100644 docs/_posts/2021-04-13-multiple_users_attempting_to_authenticate_using_explicit_credentials.md delete mode 100644 docs/_posts/2021-04-13-multiple_users_failing_to_authenticate_from_host_using_ntlm.md delete mode 100644 docs/_posts/2021-04-13-multiple_users_failing_to_authenticate_from_process.md delete mode 100644 docs/_posts/2021-04-13-multiple_users_remotely_failing_to_authenticate_from_host.md delete mode 100644 docs/_posts/2021-04-13-office_application_spawn_rundll32_process.md delete mode 100644 docs/_posts/2021-04-13-windows_users_authenticate_using_explicit_credentials.md delete mode 100644 docs/_posts/2021-04-14-multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.md delete mode 100644 docs/_posts/2021-04-14-multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.md delete mode 100644 docs/_posts/2021-04-14-office_document_creating_schedule_task.md delete mode 100644 docs/_posts/2021-04-14-office_document_executing_macro_code.md delete mode 100644 docs/_posts/2021-04-14-windows_disabled_users_failing_to_authenticate_kerberos.md delete mode 100644 docs/_posts/2021-04-14-windows_invalid_users_failed_authentication_via_kerberos.md delete mode 100644 docs/_posts/2021-04-15-dns_exfiltration_using_nslookup_app.md delete mode 100644 docs/_posts/2021-04-15-multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.md delete mode 100644 docs/_posts/2021-04-19-gpupdate_with_no_command_line_arguments_with_network.md delete mode 100644 docs/_posts/2021-04-19-powershell_remote_thread_to_known_windows_process.md delete mode 100644 docs/_posts/2021-04-19-schedule_task_with_http_command_arguments.md delete mode 100644 docs/_posts/2021-04-19-schedule_task_with_rundll32_command_trigger.md delete mode 100644 docs/_posts/2021-04-19-wermgr_process_connecting_to_ip_check_web_services.md delete mode 100644 docs/_posts/2021-04-19-wermgr_process_create_executable_file.md delete mode 100644 docs/_posts/2021-04-19-wermgr_process_spawned_cmd_or_powershell_process.md delete mode 100644 docs/_posts/2021-04-21-excessive_usage_of_nslookup_app.md delete mode 100644 docs/_posts/2021-04-21-multiple_archive_files_http_post_traffic.md delete mode 100644 docs/_posts/2021-04-22-anomalous_usage_of_7zip.md delete mode 100644 docs/_posts/2021-04-22-office_product_spawning_rundll32_with_no_dll.md delete mode 100644 docs/_posts/2021-04-22-plain_http_post_exfiltrated_data.md delete mode 100644 docs/_posts/2021-04-22-winword_spawning_cmd.md delete mode 100644 docs/_posts/2021-04-26-office_product_spawning_bitsadmin.md delete mode 100644 docs/_posts/2021-04-26-office_product_spawning_certutil.md delete mode 100644 docs/_posts/2021-04-26-office_product_spawning_mshta.md delete mode 100644 docs/_posts/2021-04-26-trickbot_named_pipe.md delete mode 100644 docs/_posts/2021-04-29-icacls_deny_command.md delete mode 100644 docs/_posts/2021-04-29-suspicious_driver_loaded_path.md delete mode 100644 docs/_posts/2021-04-29-xmrig_driver_loaded.md delete mode 100644 docs/_posts/2021-05-04-deleting_of_net_users.md delete mode 100644 docs/_posts/2021-05-04-disabling_net_user_account.md delete mode 100644 docs/_posts/2021-05-04-excessive_attempt_to_disable_services.md delete mode 100644 docs/_posts/2021-05-04-excessive_service_stop_attempt.md delete mode 100644 docs/_posts/2021-05-04-excessive_usage_of_taskkill.md delete mode 100644 docs/_posts/2021-05-04-icacls_grant_command.md delete mode 100644 docs/_posts/2021-05-04-modify_acl_permission_to_files_or_folder.md delete mode 100644 docs/_posts/2021-05-04-process_kill_base_on_file_path.md delete mode 100644 docs/_posts/2021-05-05-suspicious_process_file_path.md delete mode 100644 docs/_posts/2021-05-06-download_files_using_telegram.md delete mode 100644 docs/_posts/2021-05-06-enumerate_users_local_group_using_telegram.md delete mode 100644 docs/_posts/2021-05-06-excessive_usage_of_net_app.md delete mode 100644 docs/_posts/2021-05-06-executables_or_script_creation_in_suspicious_path.md delete mode 100644 docs/_posts/2021-05-07-excessive_usage_of_cacls_app.md delete mode 100644 docs/_posts/2021-05-07-schtasks_run_task_on_demand.md delete mode 100644 docs/_posts/2021-05-12-delete_shadowcopy_with_powershell.md delete mode 100644 docs/_posts/2021-05-13-cmlua_or_cmstplua_uac_bypass.md delete mode 100644 docs/_posts/2021-05-13-slui_runas_elevated.md delete mode 100644 docs/_posts/2021-05-13-slui_spawning_a_process.md delete mode 100644 docs/_posts/2021-05-18-services_escalate_exe.md delete mode 100644 docs/_posts/2021-05-19-allow_inbound_traffic_in_firewall_rule.md delete mode 100644 docs/_posts/2021-05-19-mailsniper_invoke_functions.md delete mode 100644 docs/_posts/2021-05-20-cmd_echo_pipe_-_escalation.md delete mode 100644 docs/_posts/2021-05-21-winrm_spawning_a_process.md delete mode 100644 docs/_posts/2021-05-26-secretdumps_offline_ntds_dumping_tool.md delete mode 100644 docs/_posts/2021-05-27-detect_sharphound_file_modifications.md delete mode 100644 docs/_posts/2021-05-27-detect_sharphound_usage.md delete mode 100644 docs/_posts/2021-06-01-detect_azurehound_command-line_arguments.md delete mode 100644 docs/_posts/2021-06-01-detect_azurehound_file_modifications.md delete mode 100644 docs/_posts/2021-06-01-detect_sharphound_command-line_arguments.md delete mode 100644 docs/_posts/2021-06-02-conti_common_exec_parameter.md delete mode 100644 docs/_posts/2021-06-02-modification_of_wallpaper.md delete mode 100644 docs/_posts/2021-06-02-revil_common_exec_parameter.md delete mode 100644 docs/_posts/2021-06-02-wbemprox_com_object_execution.md delete mode 100644 docs/_posts/2021-06-04-known_services_killed_by_ransomware.md delete mode 100644 docs/_posts/2021-06-07-excessive_number_of_taskhost_processes.md delete mode 100644 docs/_posts/2021-06-08-powershell_fileless_process_injection_via_getprocaddress.md delete mode 100644 docs/_posts/2021-06-08-powershell_fileless_script_contains_base64_encoded_content.md delete mode 100644 docs/_posts/2021-06-09-detect_empire_with_powershell_script_block_logging.md delete mode 100644 docs/_posts/2021-06-09-detect_mimikatz_with_powershell_script_block_logging.md delete mode 100644 docs/_posts/2021-06-09-unloading_amsi_via_reflection.md delete mode 100644 docs/_posts/2021-06-10-clear_unallocated_sector_using_cipher_app.md delete mode 100644 docs/_posts/2021-06-10-disable_logs_using_wevtutil.md delete mode 100644 docs/_posts/2021-06-10-permission_modification_using_takeown_app.md delete mode 100644 docs/_posts/2021-06-10-powershell_creating_thread_mutex.md delete mode 100644 docs/_posts/2021-06-10-powershell_domain_enumeration.md delete mode 100644 docs/_posts/2021-06-10-powershell_loading_dotnet_into_memory_via_reflection.md delete mode 100644 docs/_posts/2021-06-10-powershell_loading_dotnet_into_memory_via_system_reflection_assembly.md delete mode 100644 docs/_posts/2021-06-10-powershell_processing_stream_of_data.md delete mode 100644 docs/_posts/2021-06-10-powershell_using_memory_as_backing_store.md delete mode 100644 docs/_posts/2021-06-10-prevent_automatic_repair_mode_using_bcdedit.md delete mode 100644 docs/_posts/2021-06-10-recon_avproduct_through_pwh_or_wmi.md delete mode 100644 docs/_posts/2021-06-10-recon_using_wmi_class.md delete mode 100644 docs/_posts/2021-06-14-wmi_recon_running_process_or_services.md delete mode 100644 docs/_posts/2021-06-15-wevtutil_usage_to_clear_logs.md delete mode 100644 docs/_posts/2021-06-15-wevtutil_usage_to_disable_logs.md delete mode 100644 docs/_posts/2021-06-16-detect_wmi_event_subscription_persistence.md delete mode 100644 docs/_posts/2021-06-17-suspicious_event_log_service_behavior.md delete mode 100644 docs/_posts/2021-06-22-execute_javascript_with_jscript_com_clsid.md delete mode 100644 docs/_posts/2021-06-22-powershell_enable_smb1protocol_feature.md delete mode 100644 docs/_posts/2021-06-22-recursive_delete_of_directory_in_batch_cmd.md delete mode 100644 docs/_posts/2021-06-23-allow_file_and_printing_sharing_in_firewall.md delete mode 100644 docs/_posts/2021-06-23-allow_network_discovery_in_firewall.md delete mode 100644 docs/_posts/2021-06-24-excessive_usage_of_sc_service_utility.md delete mode 100644 docs/_posts/2021-06-25-excessive_number_of_service_control_start_as_disabled.md delete mode 100644 docs/_posts/2021-07-01-print_spooler_adding_a_printer_driver.md delete mode 100644 docs/_posts/2021-07-01-print_spooler_failed_to_load_a_plug-in.md delete mode 100644 docs/_posts/2021-07-01-spoolsv_spawning_rundll32.md delete mode 100644 docs/_posts/2021-07-01-spoolsv_suspicious_loaded_modules.md delete mode 100644 docs/_posts/2021-07-01-spoolsv_suspicious_process_access.md delete mode 100644 docs/_posts/2021-07-01-spoolsv_writing_a_dll.md delete mode 100644 docs/_posts/2021-07-01-spoolsv_writing_a_dll_-_sysmon.md delete mode 100644 docs/_posts/2021-07-05-msmpeng_application_dll_side_loading.md delete mode 100644 docs/_posts/2021-07-05-powershell_disable_security_monitoring.md delete mode 100644 docs/_posts/2021-07-12-uac_bypass_mmc_load_unsigned_dll.md delete mode 100644 docs/_posts/2021-07-13-cloud_compute_instance_created_by_previously_unseen_user.md delete mode 100644 docs/_posts/2021-07-19-aws_createaccesskey.md delete mode 100644 docs/_posts/2021-07-19-aws_createloginprofile.md delete mode 100644 docs/_posts/2021-07-19-aws_updateloginprofile.md delete mode 100644 docs/_posts/2021-07-19-detect_new_open_s3_buckets.md delete mode 100644 docs/_posts/2021-07-19-detect_new_open_s3_buckets_over_aws_cli.md delete mode 100644 docs/_posts/2021-07-19-mshta_spawning_rundll32_or_regsvr32_process.md delete mode 100644 docs/_posts/2021-07-19-office_product_spawn_cmd_process.md delete mode 100644 docs/_posts/2021-07-20-detect_shared_ec2_snapshot.md delete mode 100644 docs/_posts/2021-07-21-detect_copy_of_shadowcopy_with_script_block_logging.md delete mode 100644 docs/_posts/2021-07-23-sam_database_file_access_attempt.md delete mode 100644 docs/_posts/2021-07-26-rundll32_createremotethread_in_browser.md delete mode 100644 docs/_posts/2021-07-26-rundll32_process_creating_exe_dll_files.md delete mode 100644 docs/_posts/2021-07-26-suspicious_icedid_rundll32_cmdline.md delete mode 100644 docs/_posts/2021-07-26-suspicious_rundll32_plugininit.md delete mode 100644 docs/_posts/2021-07-27-chcp_command_execution.md delete mode 100644 docs/_posts/2021-07-27-regsvr32_with_known_silent_switch_cmdline.md delete mode 100644 docs/_posts/2021-07-29-rundll32_create_remote_thread_to_a_process.md delete mode 100644 docs/_posts/2021-07-30-drop_icedid_license_dat.md delete mode 100644 docs/_posts/2021-07-30-icedid_exfiltrated_archived_file_creation.md delete mode 100644 docs/_posts/2021-07-30-office_application_spawn_regsvr32_process.md delete mode 100644 docs/_posts/2021-08-03-sqlite_module_in_temp_folder.md delete mode 100644 docs/_posts/2021-08-04-create_remote_thread_in_shell_application.md delete mode 100644 docs/_posts/2021-08-09-rundll32_lockworkstation.md delete mode 100644 docs/_posts/2021-08-09-uninstall_app_using_msiexec.md delete mode 100644 docs/_posts/2021-08-10-powershell_execute_com_object.md delete mode 100644 docs/_posts/2021-08-11-fsutil_zeroing_file.md delete mode 100644 docs/_posts/2021-08-13-uac_bypass_with_colorui_com_object.md delete mode 100644 docs/_posts/2021-08-16-gsuite_drive_share_in_external_email.md delete mode 100644 docs/_posts/2021-08-16-gsuite_email_suspicious_attachment.md delete mode 100644 docs/_posts/2021-08-17-7zip_commandline_to_smb_share_path.md delete mode 100644 docs/_posts/2021-08-17-aws_ecr_container_scanning_findings_high.md delete mode 100644 docs/_posts/2021-08-17-aws_ecr_container_scanning_findings_low_informational_unknown.md delete mode 100644 docs/_posts/2021-08-17-aws_ecr_container_scanning_findings_medium.md delete mode 100644 docs/_posts/2021-08-17-gsuite_outbound_email_with_attachment_to_external_domain.md delete mode 100644 docs/_posts/2021-08-18-esentutl_sam_copy.md delete mode 100644 docs/_posts/2021-08-18-powershell_4104_hunting.md delete mode 100644 docs/_posts/2021-08-19-aws_ecr_container_upload_outside_business_hours.md delete mode 100644 docs/_posts/2021-08-19-aws_ecr_container_upload_unknown_user.md delete mode 100644 docs/_posts/2021-08-19-gsuite_email_suspicious_subject_with_attachment.md delete mode 100644 docs/_posts/2021-08-19-protocols_passing_authentication_in_cleartext.md delete mode 100644 docs/_posts/2021-08-20-github_commit_changes_in_master.md delete mode 100644 docs/_posts/2021-08-20-kubernetes_nginx_ingress_lfi.md delete mode 100644 docs/_posts/2021-08-23-getlocaluser_with_powershell.md delete mode 100644 docs/_posts/2021-08-23-getlocaluser_with_powershell_script_block.md delete mode 100644 docs/_posts/2021-08-23-getwmiobject_user_account_with_powershell.md delete mode 100644 docs/_posts/2021-08-23-getwmiobject_user_account_with_powershell_script_block.md delete mode 100644 docs/_posts/2021-08-23-gsuite_email_with_known_abuse_web_service_link.md delete mode 100644 docs/_posts/2021-08-23-gsuite_suspicious_shared_file_name.md delete mode 100644 docs/_posts/2021-08-23-kubernetes_nginx_ingress_rfi.md delete mode 100644 docs/_posts/2021-08-24-adsisearcher_account_discovery.md delete mode 100644 docs/_posts/2021-08-24-domain_account_discovery_with_dsquery.md delete mode 100644 docs/_posts/2021-08-24-domain_account_discovery_with_net_app.md delete mode 100644 docs/_posts/2021-08-24-domain_account_discovery_with_wmic.md delete mode 100644 docs/_posts/2021-08-24-get-domaintrust_with_powershell.md delete mode 100644 docs/_posts/2021-08-24-get-domaintrust_with_powershell_script_block.md delete mode 100644 docs/_posts/2021-08-24-get_aduser_with_powershell.md delete mode 100644 docs/_posts/2021-08-24-get_aduser_with_powershell_script_block.md delete mode 100644 docs/_posts/2021-08-24-get_domainuser_with_powershell.md delete mode 100644 docs/_posts/2021-08-24-get_domainuser_with_powershell_script_block.md delete mode 100644 docs/_posts/2021-08-24-getwmiobject_ds_user_with_powershell.md delete mode 100644 docs/_posts/2021-08-24-getwmiobject_ds_user_with_powershell_script_block.md delete mode 100644 docs/_posts/2021-08-24-kubernetes_scanner_image_pulling.md delete mode 100644 docs/_posts/2021-08-25-domain_group_discovery_with_adsisearcher.md delete mode 100644 docs/_posts/2021-08-25-domain_group_discovery_with_net.md delete mode 100644 docs/_posts/2021-08-25-domain_group_discovery_with_wmic.md delete mode 100644 docs/_posts/2021-08-25-elevated_group_discovery_with_net.md delete mode 100644 docs/_posts/2021-08-25-elevated_group_discovery_with_powerview.md delete mode 100644 docs/_posts/2021-08-25-elevated_group_discovery_with_wmic.md delete mode 100644 docs/_posts/2021-08-25-getadgroup_with_powershell.md delete mode 100644 docs/_posts/2021-08-25-getadgroup_with_powershell_script_block.md delete mode 100644 docs/_posts/2021-08-25-getdomaingroup_with_powershell.md delete mode 100644 docs/_posts/2021-08-25-getnettcpconnection_with_powershell.md delete mode 100644 docs/_posts/2021-08-25-getwmiobject_ds_group_with_powershell.md delete mode 100644 docs/_posts/2021-08-25-getwmiobject_ds_group_with_powershell_script_block.md delete mode 100644 docs/_posts/2021-08-26-get_addefaultdomainpasswordpolicy_with_powershell.md delete mode 100644 docs/_posts/2021-08-26-get_addefaultdomainpasswordpolicy_with_powershell_script_block.md delete mode 100644 docs/_posts/2021-08-26-get_aduserresultantpasswordpolicy_with_powershell.md delete mode 100644 docs/_posts/2021-08-26-get_aduserresultantpasswordpolicy_with_powershell_script_block.md delete mode 100644 docs/_posts/2021-08-26-get_domainpolicy_with_powershell.md delete mode 100644 docs/_posts/2021-08-26-get_domainpolicy_with_powershell_script_block.md delete mode 100644 docs/_posts/2021-08-26-getdomaingroup_with_powershell_script_block.md delete mode 100644 docs/_posts/2021-08-26-password_policy_discovery_with_net.md delete mode 100644 docs/_posts/2021-08-26-process_creating_lnk_file_in_suspicious_location.md delete mode 100644 docs/_posts/2021-08-27-exchange_powershell_abuse_via_ssrf.md delete mode 100644 docs/_posts/2021-08-27-exchange_powershell_module_usage.md delete mode 100644 docs/_posts/2021-08-30-domain_controller_discovery_with_nltest.md delete mode 100644 docs/_posts/2021-08-30-remote_system_discovery_with_net.md delete mode 100644 docs/_posts/2021-08-31-petitpotam_network_share_access_request.md delete mode 100644 docs/_posts/2021-08-31-petitpotam_suspicious_kerberos_tgt_request.md delete mode 100644 docs/_posts/2021-08-31-remote_system_discovery_with_dsquery.md delete mode 100644 docs/_posts/2021-09-01-circle_ci_disable_security_step.md delete mode 100644 docs/_posts/2021-09-01-domain_controller_discovery_with_wmic.md delete mode 100644 docs/_posts/2021-09-01-domain_group_discovery_with_dsquery.md delete mode 100644 docs/_posts/2021-09-01-getadcomputer_with_powershell_script_block.md delete mode 100644 docs/_posts/2021-09-01-getwmiobject_ds_computer_with_powershell_script_block.md delete mode 100644 docs/_posts/2021-09-01-github_commit_in_develop.md delete mode 100644 docs/_posts/2021-09-01-github_dependabot_alert.md delete mode 100644 docs/_posts/2021-09-01-github_pull_request_from_unknown_user.md delete mode 100644 docs/_posts/2021-09-01-remote_system_discovery_with_adsisearcher.md delete mode 100644 docs/_posts/2021-09-01-remote_system_discovery_with_wmic.md delete mode 100644 docs/_posts/2021-09-02-circle_ci_disable_security_job.md delete mode 100644 docs/_posts/2021-09-02-get-foresttrust_with_powershell.md delete mode 100644 docs/_posts/2021-09-02-get-foresttrust_with_powershell_script_block.md delete mode 100644 docs/_posts/2021-09-02-getdomaincomputer_with_powershell_script_block.md delete mode 100644 docs/_posts/2021-09-02-getdomaincontroller_with_powershell_script_block.md delete mode 100644 docs/_posts/2021-09-06-bcdedit_command_back_to_normal_mode_boot.md delete mode 100644 docs/_posts/2021-09-06-change_to_safe_mode_with_network_config.md delete mode 100644 docs/_posts/2021-09-06-correlation_by_repository_and_risk.md delete mode 100644 docs/_posts/2021-09-06-correlation_by_user_and_risk.md delete mode 100644 docs/_posts/2021-09-07-getadcomputer_with_powershell.md delete mode 100644 docs/_posts/2021-09-07-getdomaincomputer_with_powershell.md delete mode 100644 docs/_posts/2021-09-07-getdomaincontroller_with_powershell.md delete mode 100644 docs/_posts/2021-09-07-getwmiobject_ds_computer_with_powershell.md delete mode 100644 docs/_posts/2021-09-07-schcache_change_by_app_connect_and_create_adsi_object.md delete mode 100644 docs/_posts/2021-09-07-system_information_discovery_detection.md delete mode 100644 docs/_posts/2021-09-08-control_loading_from_world_writable_directory.md delete mode 100644 docs/_posts/2021-09-08-create_local_admin_accounts_using_net_exe.md delete mode 100644 docs/_posts/2021-09-08-office_spawning_control.md delete mode 100644 docs/_posts/2021-09-08-rundll32_control_rundll_hunt.md delete mode 100644 docs/_posts/2021-09-08-rundll32_control_rundll_world_writable_directory.md delete mode 100644 docs/_posts/2021-09-09-extraction_of_registry_hives.md delete mode 100644 docs/_posts/2021-09-09-mshtml_module_load_in_office_product.md delete mode 100644 docs/_posts/2021-09-10-getnettcpconnection_with_powershell_script_block.md delete mode 100644 docs/_posts/2021-09-10-network_connection_discovery_with_arp.md delete mode 100644 docs/_posts/2021-09-10-network_connection_discovery_with_net.md delete mode 100644 docs/_posts/2021-09-10-network_connection_discovery_with_netstat.md delete mode 100644 docs/_posts/2021-09-10-office_product_writing_cab_or_inf.md delete mode 100644 docs/_posts/2021-09-13-getcurrent_user_with_powershell.md delete mode 100644 docs/_posts/2021-09-13-getcurrent_user_with_powershell_script_block.md delete mode 100644 docs/_posts/2021-09-13-jscript_execution_using_cscript_app.md delete mode 100644 docs/_posts/2021-09-13-ms_scripting_process_loading_ldap_module.md delete mode 100644 docs/_posts/2021-09-13-ms_scripting_process_loading_wmi_module.md delete mode 100644 docs/_posts/2021-09-13-office_application_drop_executable.md delete mode 100644 docs/_posts/2021-09-13-system_user_discovery_with_query.md delete mode 100644 docs/_posts/2021-09-13-system_user_discovery_with_whoami.md delete mode 100644 docs/_posts/2021-09-13-user_discovery_with_env_vars_powershell.md delete mode 100644 docs/_posts/2021-09-13-user_discovery_with_env_vars_powershell_script_block.md delete mode 100644 docs/_posts/2021-09-13-xsl_script_execution_with_wmic.md delete mode 100644 docs/_posts/2021-09-14-cmdline_tool_not_executed_in_cmd_shell.md delete mode 100644 docs/_posts/2021-09-14-get_wmiobject_group_discovery.md delete mode 100644 docs/_posts/2021-09-14-get_wmiobject_group_discovery_with_script_block_logging.md delete mode 100644 docs/_posts/2021-09-14-net_localgroup_discovery.md delete mode 100644 docs/_posts/2021-09-14-powershell_get_localgroup_discovery.md delete mode 100644 docs/_posts/2021-09-14-powershell_get_localgroup_discovery_with_script_block_logging.md delete mode 100644 docs/_posts/2021-09-14-wmic_group_discovery.md delete mode 100644 docs/_posts/2021-09-15-check_elevated_cmd_using_whoami.md delete mode 100644 docs/_posts/2021-09-15-non_chrome_process_accessing_chrome_default_dir.md delete mode 100644 docs/_posts/2021-09-15-non_firefox_process_access_firefox_profile_dir.md delete mode 100644 docs/_posts/2021-09-16-account_discovery_with_net_app.md delete mode 100644 docs/_posts/2021-09-16-attempt_to_add_certificate_to_untrusted_store.md delete mode 100644 docs/_posts/2021-09-16-attempted_credential_dump_from_registry_via_reg_exe.md delete mode 100644 docs/_posts/2021-09-16-batch_file_write_to_system32.md delete mode 100644 docs/_posts/2021-09-16-bits_job_persistence.md delete mode 100644 docs/_posts/2021-09-16-bitsadmin_download_file.md delete mode 100644 docs/_posts/2021-09-16-creation_of_shadow_copy_with_wmic_and_powershell.md delete mode 100644 docs/_posts/2021-09-16-credential_dumping_via_copy_command_from_shadow_copy.md delete mode 100644 docs/_posts/2021-09-16-credential_dumping_via_symlink_to_shadow_copy.md delete mode 100644 docs/_posts/2021-09-16-detect_html_help_renamed.md delete mode 100644 docs/_posts/2021-09-16-detect_html_help_url_in_command_line.md delete mode 100644 docs/_posts/2021-09-16-detect_html_help_using_infotech_storage_handlers.md delete mode 100644 docs/_posts/2021-09-16-detect_mshta_inline_hta_execution.md delete mode 100644 docs/_posts/2021-09-16-detect_mshta_renamed.md delete mode 100644 docs/_posts/2021-09-16-detect_mshta_url_in_command_line.md delete mode 100644 docs/_posts/2021-09-16-detect_psexec_with_accepteula_flag.md delete mode 100644 docs/_posts/2021-09-16-detect_renamed_7-zip.md delete mode 100644 docs/_posts/2021-09-16-detect_renamed_psexec.md delete mode 100644 docs/_posts/2021-09-16-detect_renamed_rclone.md delete mode 100644 docs/_posts/2021-09-16-detect_renamed_winrar.md delete mode 100644 docs/_posts/2021-09-16-dump_lsass_via_procdump.md delete mode 100644 docs/_posts/2021-09-16-local_account_discovery_with_net.md delete mode 100644 docs/_posts/2021-09-16-local_account_discovery_with_wmic.md delete mode 100644 docs/_posts/2021-09-16-office_product_spawning_wmic.md delete mode 100644 docs/_posts/2021-09-16-processes_launching_netsh.md delete mode 100644 docs/_posts/2021-09-20-detect_regasm_with_no_command_line_arguments.md delete mode 100644 docs/_posts/2021-09-20-detect_regsvcs_with_no_command_line_arguments.md delete mode 100644 docs/_posts/2021-09-20-office_document_spawned_child_process_to_download.md delete mode 100644 docs/_posts/2021-09-20-suspicious_dllhost_no_command_line_arguments.md delete mode 100644 docs/_posts/2021-09-20-suspicious_gpupdate_no_command_line_arguments.md delete mode 100644 docs/_posts/2021-09-20-suspicious_microsoft_workflow_compiler_rename.md delete mode 100644 docs/_posts/2021-09-20-suspicious_rundll32_no_command_line_arguments.md delete mode 100644 docs/_posts/2021-09-20-suspicious_searchprotocolhost_no_command_line_arguments.md delete mode 100644 docs/_posts/2021-09-21-remcos_rat_file_creation_in_remcos_folder.md delete mode 100644 docs/_posts/2021-09-21-suspicious_image_creation_in_appdata_folder.md delete mode 100644 docs/_posts/2021-09-21-suspicious_wav_file_in_appdata_folder.md delete mode 100644 docs/_posts/2021-09-27-change_default_file_association.md delete mode 100644 docs/_posts/2021-09-27-logon_script_event_trigger_execution.md delete mode 100644 docs/_posts/2021-09-27-screensaver_event_trigger_execution.md delete mode 100644 docs/_posts/2021-09-28-print_processor_registry_autostart.md delete mode 100644 docs/_posts/2021-09-29-verclsid_clsid_execution.md delete mode 100644 docs/_posts/2021-10-01-vbscript_execution_using_wscript_app.md delete mode 100644 docs/_posts/2021-10-04-msbuild_suspicious_spawned_by_script_process.md delete mode 100644 docs/_posts/2021-10-04-regsvr32_silent_and_install_param_dll_loading.md delete mode 100644 docs/_posts/2021-10-05-detect_exchange_web_shell.md delete mode 100644 docs/_posts/2021-10-05-malicious_inprocserver32_modification.md delete mode 100644 docs/_posts/2021-10-05-process_writing_dynamicwrapperx.md delete mode 100644 docs/_posts/2021-10-05-rundll32_shimcache_flush.md delete mode 100644 docs/_posts/2021-10-05-suspicious_copy_on_system32.md delete mode 100644 docs/_posts/2021-10-05-winhlp32_spawning_a_process.md delete mode 100644 docs/_posts/2021-10-06-dns_query_length_with_high_standard_deviation.md delete mode 100644 docs/_posts/2021-10-06-sdelete_application_execution.md delete mode 100644 docs/_posts/2021-10-06-wscript_or_cscript_suspicious_child_process.md delete mode 100644 docs/_posts/2021-10-11-suspicious_wevtutil_usage.md delete mode 100644 docs/_posts/2021-10-13-dllhost_with_no_command_line_arguments_with_network.md delete mode 100644 docs/_posts/2021-10-13-rundll32_with_no_command_line_arguments_with_network.md delete mode 100644 docs/_posts/2021-10-13-searchprotocolhost_with_no_command_line_with_network.md delete mode 100644 docs/_posts/2021-10-14-serviceprincipalnames_discovery_with_powershell.md delete mode 100644 docs/_posts/2021-10-14-serviceprincipalnames_discovery_with_setspn.md delete mode 100644 docs/_posts/2021-10-18-disable_schedule_task.md delete mode 100644 docs/_posts/2021-10-19-windows_curl_download_to_suspicious_path.md delete mode 100644 docs/_posts/2021-10-19-winevent_windows_task_scheduler_event_action_started.md delete mode 100644 docs/_posts/2021-10-20-wmic_noninteractive_app_uninstallation.md delete mode 100644 docs/_posts/2021-10-24-gdrive_suspicious_file_sharing.md delete mode 100644 docs/_posts/2021-10-24-gsuite_suspicious_calendar_invite.md delete mode 100644 docs/_posts/2021-11-03-windows_adfind_exe.md delete mode 100644 docs/_posts/2021-11-04-attacker_tools_on_endpoint.md delete mode 100644 docs/_posts/2021-11-05-potential_pass_the_token_or_hash_observed_by_an_event_collecting_device.md delete mode 100644 docs/_posts/2021-11-10-windows_curl_upload_to_remote_destination.md delete mode 100644 docs/_posts/2021-11-10-windows_service_creation_on_remote_endpoint.md delete mode 100644 docs/_posts/2021-11-10-windows_service_initiation_on_remote_endpoint.md delete mode 100644 docs/_posts/2021-11-11-remote_process_instantiation_via_winrm_and_winrs.md delete mode 100644 docs/_posts/2021-11-11-scheduled_task_creation_on_remote_endpoint_using_at.md delete mode 100644 docs/_posts/2021-11-11-scheduled_task_initiation_on_remote_endpoint.md delete mode 100644 docs/_posts/2021-11-11-schtasks_scheduling_job_on_remote_system.md delete mode 100644 docs/_posts/2021-11-11-wmic_xsl_execution_via_url.md delete mode 100644 docs/_posts/2021-11-12-aws_iam_accessdenied_discovery_events.md delete mode 100644 docs/_posts/2021-11-12-csc_net_on_the_fly_compilation.md delete mode 100644 docs/_posts/2021-11-12-firewall_allowed_program_enable.md delete mode 100644 docs/_posts/2021-11-12-network_discovery_using_route_windows_app.md delete mode 100644 docs/_posts/2021-11-12-remote_process_instantiation_via_wmi.md delete mode 100644 docs/_posts/2021-11-12-runas_execution_in_commandline.md delete mode 100644 docs/_posts/2021-11-12-windows_installutil_credential_theft.md delete mode 100644 docs/_posts/2021-11-12-windows_installutil_remote_network_connection.md delete mode 100644 docs/_posts/2021-11-12-windows_installutil_uninstall_option.md delete mode 100644 docs/_posts/2021-11-12-windows_installutil_uninstall_option_with_network.md delete mode 100644 docs/_posts/2021-11-12-windows_installutil_url_in_command_line.md delete mode 100644 docs/_posts/2021-11-15-remote_process_instantiation_via_dcom_and_powershell.md delete mode 100644 docs/_posts/2021-11-15-remote_process_instantiation_via_dcom_and_powershell_script_block.md delete mode 100644 docs/_posts/2021-11-15-remote_process_instantiation_via_wmi_and_powershell.md delete mode 100644 docs/_posts/2021-11-15-remote_process_instantiation_via_wmi_and_powershell_script_block.md delete mode 100644 docs/_posts/2021-11-15-sdelete_application_execution.md delete mode 100644 docs/_posts/2021-11-15-windows_diskcryptor_usage.md delete mode 100644 docs/_posts/2021-11-16-high_frequency_copy_of_files_in_network_share.md delete mode 100644 docs/_posts/2021-11-16-remote_process_instantiation_via_winrm_and_powershell.md delete mode 100644 docs/_posts/2021-11-16-remote_process_instantiation_via_winrm_and_powershell_script_block.md delete mode 100644 docs/_posts/2021-11-17-windows_dism_remove_defender.md delete mode 100644 docs/_posts/2021-11-18-executable_file_written_in_administrative_smb_share.md delete mode 100644 docs/_posts/2021-11-18-loading_of_dynwrapx_module.md delete mode 100644 docs/_posts/2021-11-19-system_info_gathering_using_dxdiag_application.md delete mode 100644 docs/_posts/2021-11-22-anomalous_usage_of_archive_tools.md delete mode 100644 docs/_posts/2021-11-22-possible_browser_pass_view_parameter.md delete mode 100644 docs/_posts/2021-11-22-services_lolbas_execution_process_spawn.md delete mode 100644 docs/_posts/2021-11-22-svchost_lolbas_execution_process_spawn.md delete mode 100644 docs/_posts/2021-11-22-windows_service_created_with_suspicious_service_path.md delete mode 100644 docs/_posts/2021-11-22-windows_service_created_within_public_path.md delete mode 100644 docs/_posts/2021-11-22-wmiprsve_lolbas_execution_process_spawn.md delete mode 100644 docs/_posts/2021-11-22-wsmprovhost_lolbas_execution_process_spawn.md delete mode 100644 docs/_posts/2021-11-23-mmc_lolbas_execution_process_spawn.md delete mode 100644 docs/_posts/2021-11-24-attempt_to_delete_services.md delete mode 100644 docs/_posts/2021-11-24-attempt_to_disable_services.md delete mode 100644 docs/_posts/2021-11-25-add_or_set_windows_defender_exclusion.md delete mode 100644 docs/_posts/2021-11-25-powershell_windows_defender_exclusion_commands.md delete mode 100644 docs/_posts/2021-11-25-windows_defender_exclusion_registry_entry.md delete mode 100644 docs/_posts/2021-11-29-attempted_credential_dump_from_registry_via_reg_exe.md delete mode 100644 docs/_posts/2021-11-29-deny_permission_using_cacls_utility.md delete mode 100644 docs/_posts/2021-11-29-detect_dump_lsass_memory_using_comsvcs.md delete mode 100644 docs/_posts/2021-11-29-detect_rclone_command-line_usage.md delete mode 100644 docs/_posts/2021-11-29-possible_lateral_movement_powershell_spawn.md delete mode 100644 docs/_posts/2021-11-29-randomly_generated_scheduled_task_name.md delete mode 100644 docs/_posts/2021-11-29-randomly_generated_windows_service_name.md delete mode 100644 docs/_posts/2021-11-30-delete_a_net_user.md delete mode 100644 docs/_posts/2021-11-30-disable_net_user_account.md delete mode 100644 docs/_posts/2021-11-30-first_time_seen_command_line_argument.md delete mode 100644 docs/_posts/2021-11-30-grant_permission_using_cacls_utility.md delete mode 100644 docs/_posts/2021-11-30-modify_acls_permission_of_files_or_folders.md delete mode 100644 docs/_posts/2021-11-30-potential_pass_the_token_or_hash_observed_at_the_destination_device.md delete mode 100644 docs/_posts/2021-11-30-rare_parent-child_process_relationship.md delete mode 100644 docs/_posts/2021-11-30-resize_shadowstorage_volume.md delete mode 100644 docs/_posts/2021-12-01-unusual_number_of_computer_service_tickets_requested.md delete mode 100644 docs/_posts/2021-12-01-unusual_number_of_remote_endpoint_authentication_events.md delete mode 100644 docs/_posts/2021-12-03-detect_rclone_command-line_usage.md delete mode 100644 docs/_posts/2021-12-03-short_lived_scheduled_task.md delete mode 100644 docs/_posts/2021-12-03-windows_curl_upload_to_remote_destination.md delete mode 100644 docs/_posts/2021-12-06-suspicious_linux_discovery_commands.md delete mode 100644 docs/_posts/2021-12-07-anomalous_usage_of_account_credentials.md delete mode 100644 docs/_posts/2021-12-07-bcdedit_failure_recovery_modification.md delete mode 100644 docs/_posts/2021-12-07-dns_exfiltration_using_nslookup_app.md delete mode 100644 docs/_posts/2021-12-07-excessive_number_of_office_files_copied.md delete mode 100644 docs/_posts/2021-12-07-fsutil_zeroing_file.md delete mode 100644 docs/_posts/2021-12-07-high_file_deletion_frequency.md delete mode 100644 docs/_posts/2021-12-07-microsoft_exchange_mailbox_replication_service_writing_active_server_pages.md delete mode 100644 docs/_posts/2021-12-07-ms_exchange_mailbox_replication_service_writing_active_server_pages.md delete mode 100644 docs/_posts/2021-12-07-wbadmin_delete_system_backups.md delete mode 100644 docs/_posts/2021-12-07-windows_raccine_scheduled_task_deletion.md delete mode 100644 docs/_posts/2021-12-08-disable_defender_antivirus_registry.md delete mode 100644 docs/_posts/2021-12-08-msi_module_loaded_by_non-system_binary.md delete mode 100644 docs/_posts/2021-12-10-curl_download_and_bash_execution.md delete mode 100644 docs/_posts/2021-12-11-wget_download_and_bash_execution.md delete mode 100644 docs/_posts/2021-12-13-detect_outbound_ldap_traffic.md delete mode 100644 docs/_posts/2021-12-13-java_class_file_download_by_java_user_agent.md delete mode 100644 docs/_posts/2021-12-13-linux_java_spawning_shell.md delete mode 100644 docs/_posts/2021-12-13-log4shell_jndi_payload_injection_attempt.md delete mode 100644 docs/_posts/2021-12-13-log4shell_jndi_payload_injection_with_outbound_connection.md delete mode 100644 docs/_posts/2021-12-13-outbound_network_connection_from_java_using_default_ports.md delete mode 100644 docs/_posts/2021-12-13-windows_java_spawning_shells.md delete mode 100644 docs/_posts/2021-12-14-hunting_for_log4shell.md delete mode 100644 docs/_posts/2021-12-17-linux_add_files_in_known_crontab_directories.md delete mode 100644 docs/_posts/2021-12-17-linux_at_allow_config_file_creation.md delete mode 100644 docs/_posts/2021-12-17-linux_at_application_execution.md delete mode 100644 docs/_posts/2021-12-17-linux_edit_cron_table_parameter.md delete mode 100644 docs/_posts/2021-12-17-linux_possible_append_command_to_at_allow_config_file.md delete mode 100644 docs/_posts/2021-12-17-linux_possible_append_cronjob_entry_on_existing_cronjob_file.md delete mode 100644 docs/_posts/2021-12-17-linux_possible_cronjob_modification_with_editor.md delete mode 100644 docs/_posts/2021-12-20-clear_unallocated_sector_using_cipher_app.md delete mode 100644 docs/_posts/2021-12-20-hiding_files_and_directories_with_attrib_exe.md delete mode 100644 docs/_posts/2021-12-20-linux_file_creation_in_init_boot_directory.md delete mode 100644 docs/_posts/2021-12-20-linux_file_creation_in_profile_directory.md delete mode 100644 docs/_posts/2021-12-20-linux_possible_append_command_to_profile_config_file.md delete mode 100644 docs/_posts/2021-12-20-linux_service_file_created_in_systemd_directory.md delete mode 100644 docs/_posts/2021-12-20-linux_service_restarted.md delete mode 100644 docs/_posts/2021-12-20-linux_service_started_or_enabled.md delete mode 100644 docs/_posts/2021-12-20-suspicious_computer_account_name_change.md delete mode 100644 docs/_posts/2021-12-20-suspicious_kerberos_service_ticket_request.md delete mode 100644 docs/_posts/2021-12-21-linux_add_user_account.md delete mode 100644 docs/_posts/2021-12-21-linux_change_file_owner_to_root.md delete mode 100644 docs/_posts/2021-12-21-linux_nopasswd_entry_in_sudoers_file.md delete mode 100644 docs/_posts/2021-12-21-linux_setuid_using_chmod_utility.md delete mode 100644 docs/_posts/2021-12-21-linux_setuid_using_setcap_utility.md delete mode 100644 docs/_posts/2021-12-21-linux_visudo_utility_execution.md delete mode 100644 docs/_posts/2021-12-21-suspicious_ticket_granting_ticket_request.md delete mode 100644 docs/_posts/2021-12-22-linux_file_created_in_kernel_driver_directory.md delete mode 100644 docs/_posts/2021-12-22-linux_insert_kernel_module_using_insmod_utility.md delete mode 100644 docs/_posts/2021-12-22-linux_install_kernel_module_using_modprobe_utility.md delete mode 100644 docs/_posts/2021-12-22-linux_preload_hijack_library_calls.md delete mode 100644 docs/_posts/2021-12-23-linux_common_process_for_elevation_control.md delete mode 100644 docs/_posts/2021-12-23-linux_sudoers_tmp_file_creation.md delete mode 100644 docs/_posts/2022-01-04-linux_sudo_or_su_execution.md delete mode 100644 docs/_posts/2022-01-05-linux_doas_conf_file_creation.md delete mode 100644 docs/_posts/2022-01-05-linux_doas_tool_execution.md delete mode 100644 docs/_posts/2022-01-10-linux_possible_access_to_credential_files.md delete mode 100644 docs/_posts/2022-01-10-linux_possible_access_to_sudoers_file.md delete mode 100644 docs/_posts/2022-01-11-linux_possible_access_or_modification_of_sshd_config_file.md delete mode 100644 docs/_posts/2022-01-11-linux_possible_ssh_key_file_creation.md delete mode 100644 docs/_posts/2022-01-12-powershell_-_connect_to_internet_with_hidden_window.md delete mode 100644 docs/_posts/2022-01-12-windows_hunting_system_account_targeting_lsass.md delete mode 100644 docs/_posts/2022-01-12-windows_non-system_account_targeting_lsass.md delete mode 100644 docs/_posts/2022-01-14-potentially_malicious_code_on_commandline.md delete mode 100644 docs/_posts/2022-01-17-unusual_volume_of_data_download_from_internal_server_per_entity.md delete mode 100644 docs/_posts/2022-01-18-cmd_carry_out_string_command_parameter.md delete mode 100644 docs/_posts/2022-01-18-impacket_lateral_movement_commandline_parameters.md delete mode 100644 docs/_posts/2022-01-18-malicious_powershell_process_-_encoded_command.md delete mode 100644 docs/_posts/2022-01-18-powershell_remove_windows_defender_directory.md delete mode 100644 docs/_posts/2022-01-18-suspicious_process_dns_query_known_abuse_web_services.md delete mode 100644 docs/_posts/2022-01-19-suspicious_process_with_discord_dns_query.md delete mode 100644 docs/_posts/2022-01-19-windows_dotnet_binary_in_non_standard_path.md delete mode 100644 docs/_posts/2022-01-19-windows_installutil_in_non_standard_path.md delete mode 100644 docs/_posts/2022-01-20-excessive_file_deletion_in_windefender_folder.md delete mode 100644 docs/_posts/2022-01-20-ping_sleep_batch_command.md delete mode 100644 docs/_posts/2022-01-21-windows_nirsoft_advancedrun.md delete mode 100644 docs/_posts/2022-01-24-windows_nirsoft_utilities.md delete mode 100644 docs/_posts/2022-01-26-active_setup_registry_autostart.md delete mode 100644 docs/_posts/2022-01-26-add_defaultuser_and_password_in_registry.md delete mode 100644 docs/_posts/2022-01-26-allow_inbound_traffic_by_firewall_rule_registry.md delete mode 100644 docs/_posts/2022-01-26-allow_operation_with_consent_admin.md delete mode 100644 docs/_posts/2022-01-26-disable_amsi_through_registry.md delete mode 100644 docs/_posts/2022-01-26-disable_defender_antivirus_registry.md delete mode 100644 docs/_posts/2022-01-26-disable_defender_blockatfirstseen_feature.md delete mode 100644 docs/_posts/2022-01-26-disable_defender_enhanced_notification.md delete mode 100644 docs/_posts/2022-01-26-disable_defender_mpengine_registry.md delete mode 100644 docs/_posts/2022-01-26-disable_defender_spynet_reporting.md delete mode 100644 docs/_posts/2022-01-26-disable_defender_submit_samples_consent_feature.md delete mode 100644 docs/_posts/2022-01-26-log4shell_cve-2021-44228_exploitation.md delete mode 100644 docs/_posts/2022-01-26-registry_keys_used_for_persistence.md delete mode 100644 docs/_posts/2022-01-26-registry_keys_used_for_privilege_escalation.md delete mode 100644 docs/_posts/2022-01-26-remcos_client_registry_install_entry.md delete mode 100644 docs/_posts/2022-01-26-start_up_during_safe_mode_boot.md delete mode 100644 docs/_posts/2022-01-26-time_provider_persistence_registry.md delete mode 100644 docs/_posts/2022-01-27-disable_etw_through_registry.md delete mode 100644 docs/_posts/2022-01-27-disable_registry_tool.md delete mode 100644 docs/_posts/2022-01-27-disable_security_logs_using_minint_registry.md delete mode 100644 docs/_posts/2022-01-27-disable_show_hidden_files.md delete mode 100644 docs/_posts/2022-01-27-disable_uac_remote_restriction.md delete mode 100644 docs/_posts/2022-01-27-disable_windows_app_hotkeys.md delete mode 100644 docs/_posts/2022-01-27-disable_windows_behavior_monitoring.md delete mode 100644 docs/_posts/2022-01-27-disable_windows_smartscreen_protection.md delete mode 100644 docs/_posts/2022-01-27-disabling_cmd_application.md delete mode 100644 docs/_posts/2022-01-27-disabling_controlpanel.md delete mode 100644 docs/_posts/2022-01-27-windows_possible_credential_dumping.md delete mode 100644 docs/_posts/2022-01-28-disabling_defender_services.md delete mode 100644 docs/_posts/2022-01-28-disabling_folderoptions_windows_feature.md delete mode 100644 docs/_posts/2022-01-28-disabling_norun_windows_app.md delete mode 100644 docs/_posts/2022-01-28-disabling_systemrestore_in_registry.md delete mode 100644 docs/_posts/2022-01-28-disabling_task_manager.md delete mode 100644 docs/_posts/2022-01-28-enable_rdp_in_other_port_number.md delete mode 100644 docs/_posts/2022-01-28-enable_wdigest_uselogoncredential_registry.md delete mode 100644 docs/_posts/2022-01-28-etw_registry_disabled.md delete mode 100644 docs/_posts/2022-01-28-eventvwr_uac_bypass.md delete mode 100644 docs/_posts/2022-01-28-hide_user_account_from_sign-in_screen.md delete mode 100644 docs/_posts/2022-01-28-linux_pkexec_privilege_escalation.md delete mode 100644 docs/_posts/2022-02-01-mimikatz_passtheticket_commandline_parameters.md delete mode 100644 docs/_posts/2022-02-01-rubeus_command_line_parameters.md delete mode 100644 docs/_posts/2022-02-01-suspicious_rundll32_rename.md delete mode 100644 docs/_posts/2022-02-03-certutil_download_with_urlcache_and_split_arguments.md delete mode 100644 docs/_posts/2022-02-03-certutil_download_with_verifyctl_and_split_arguments.md delete mode 100644 docs/_posts/2022-02-03-o365_added_service_principal.md delete mode 100644 docs/_posts/2022-02-03-o365_bypass_mfa_via_trusted_ip.md delete mode 100644 docs/_posts/2022-02-03-o365_disable_mfa.md delete mode 100644 docs/_posts/2022-02-07-rubeus_kerberos_ticket_exports_through_winlogon_access.md delete mode 100644 docs/_posts/2022-02-07-windows_remote_assistance_spawning_process.md delete mode 100644 docs/_posts/2022-02-07-windows_schtasks_create_run_as_system.md delete mode 100644 docs/_posts/2022-02-08-rundll_loading_dll_by_ordinal.md delete mode 100644 docs/_posts/2022-02-08-unusual_number_of_kerberos_service_tickets_requested.md delete mode 100644 docs/_posts/2022-02-09-kerberoasting_spn_request_with_rc4_encryption.md delete mode 100644 docs/_posts/2022-02-11-linux_system_network_discovery.md delete mode 100644 docs/_posts/2022-02-11-windows_powershell_connect_to_internet_with_hidden_window.md delete mode 100644 docs/_posts/2022-02-11-windows_powershell_downloadfile.md delete mode 100644 docs/_posts/2022-02-14-linux_dd_file_overwrite.md delete mode 100644 docs/_posts/2022-02-15-detection_of_dns_tunnels.md delete mode 100644 docs/_posts/2022-02-15-windows_bits_job_persistence.md delete mode 100644 docs/_posts/2022-02-15-windows_diskshadow_proxy_execution.md delete mode 100644 docs/_posts/2022-02-15-windows_rasautou_dll_execution.md delete mode 100644 docs/_posts/2022-02-16-windows_bitsadmin_download_file.md delete mode 100644 docs/_posts/2022-02-16-windows_certutil_decode_file.md delete mode 100644 docs/_posts/2022-02-16-windows_certutil_urlcache_download.md delete mode 100644 docs/_posts/2022-02-16-windows_certutil_verifyctl_download.md delete mode 100644 docs/_posts/2022-02-16-windows_powershell_start-bitstransfer.md delete mode 100644 docs/_posts/2022-02-17-tcp_command_and_scripting_interpreter_outbound_ldap_traffic.md delete mode 100644 docs/_posts/2022-02-17-windows_disable_notification_center.md delete mode 100644 docs/_posts/2022-02-17-windows_diskshadow_proxy_execution.md delete mode 100644 docs/_posts/2022-02-17-windows_raw_access_to_master_boot_record_drive.md delete mode 100644 docs/_posts/2022-02-18-detect_regasm_with_network_connection.md delete mode 100644 docs/_posts/2022-02-18-detect_regsvcs_with_network_connection.md delete mode 100644 docs/_posts/2022-02-18-disabled_kerberos_pre-authentication_discovery_with_powerview.md delete mode 100644 docs/_posts/2022-02-18-interactive_session_on_remote_endpoint_with_powershell.md delete mode 100644 docs/_posts/2022-02-18-net_profiler_uac_bypass.md delete mode 100644 docs/_posts/2022-02-18-o365_excessive_authentication_failures_alert.md delete mode 100644 docs/_posts/2022-02-18-process_deleting_its_process_file_path.md delete mode 100644 docs/_posts/2022-02-18-rundll32_dnsquery.md delete mode 100644 docs/_posts/2022-02-18-set_default_powershell_execution_policy_to_unrestricted_or_bypass.md delete mode 100644 docs/_posts/2022-02-18-windows_eventvwr_uac_bypass.md delete mode 100644 docs/_posts/2022-02-18-windows_wsreset_uac_bypass.md delete mode 100644 docs/_posts/2022-02-22-disabled_kerberos_pre-authentication_discovery_with_get-aduser.md delete mode 100644 docs/_posts/2022-02-22-kerberos_pre-authentication_flag_disabled_in_useraccountcontrol.md delete mode 100644 docs/_posts/2022-02-22-scheduled_task_deleted_or_created_via_cmd.md delete mode 100644 docs/_posts/2022-02-22-windows_wmi_process_call_create.md delete mode 100644 docs/_posts/2022-02-23-kerberos_pre-authentication_flag_disabled_with_powershell.md delete mode 100644 docs/_posts/2022-02-23-windows_event_for_service_disabled.md delete mode 100644 docs/_posts/2022-02-23-windows_excessive_disabled_services_event.md delete mode 100644 docs/_posts/2022-02-23-windows_mshta_child_process.md delete mode 100644 docs/_posts/2022-02-23-windows_mshta_command-line_url.md delete mode 100644 docs/_posts/2022-02-23-windows_mshta_inline_hta_execution.md delete mode 100644 docs/_posts/2022-02-23-windows_process_with_namedpipe_commandline.md delete mode 100644 docs/_posts/2022-02-23-windows_rundll32_inline_hta_execution.md delete mode 100644 docs/_posts/2022-02-23-windows_service_creation_using_registry_entry.md delete mode 100644 docs/_posts/2022-02-24-aws_lambda_updatefunctioncode.md delete mode 100644 docs/_posts/2022-02-24-detect_empire_with_powershell_script_block_logging.md delete mode 100644 docs/_posts/2022-02-24-detect_mimikatz_with_powershell_script_block_logging.md delete mode 100644 docs/_posts/2022-02-24-get-foresttrust_with_powershell_script_block.md delete mode 100644 docs/_posts/2022-02-25-powershell_domain_enumeration.md delete mode 100644 docs/_posts/2022-02-25-powershell_enable_smb1protocol_feature.md delete mode 100644 docs/_posts/2022-02-25-powershell_fileless_process_injection_via_getprocaddress.md delete mode 100644 docs/_posts/2022-02-25-powershell_processing_stream_of_data.md delete mode 100644 docs/_posts/2022-02-25-recon_using_wmi_class.md delete mode 100644 docs/_posts/2022-02-25-windows_disable_memory_crash_dump.md delete mode 100644 docs/_posts/2022-02-25-windows_file_without_extension_in_critical_folder.md delete mode 100644 docs/_posts/2022-02-25-windows_raw_access_to_disk_volume_partition.md delete mode 100644 docs/_posts/2022-02-26-serviceprincipalnames_discovery_with_powershell.md delete mode 100644 docs/_posts/2022-02-28-excessive_distinct_processes_from_windows_temp.md delete mode 100644 docs/_posts/2022-02-28-excessive_number_of_distinct_processes_created_in_windows_temp_folder.md delete mode 100644 docs/_posts/2022-03-02-windows_modify_show_compress_color_and_info_tip_registry.md delete mode 100644 docs/_posts/2022-03-03-aws_createaccesskey.md delete mode 100644 docs/_posts/2022-03-03-aws_updateloginprofile.md delete mode 100644 docs/_posts/2022-03-04-kerberos_tgt_request_using_rc4_encryption.md delete mode 100644 docs/_posts/2022-03-04-macos_lolbin.md delete mode 100644 docs/_posts/2022-03-08-suspicious_msbuild_path.md delete mode 100644 docs/_posts/2022-03-08-windows_disable_change_password_through_registry.md delete mode 100644 docs/_posts/2022-03-08-windows_disable_lock_workstation_feature_through_registry.md delete mode 100644 docs/_posts/2022-03-08-windows_disable_logoff_button_through_registry.md delete mode 100644 docs/_posts/2022-03-08-windows_disable_shutdown_button_through_registry.md delete mode 100644 docs/_posts/2022-03-08-windows_disable_windows_group_policy_features_through_registry.md delete mode 100644 docs/_posts/2022-03-08-windows_hide_notification_features_through_registry.md delete mode 100644 docs/_posts/2022-03-09-unknown_process_using_the_kerberos_protocol.md delete mode 100644 docs/_posts/2022-03-10-kerberos_user_enumeration.md delete mode 100644 docs/_posts/2022-03-15-detect_regasm_with_no_command_line_arguments.md delete mode 100644 docs/_posts/2022-03-15-detect_regsvcs_with_no_command_line_arguments.md delete mode 100644 docs/_posts/2022-03-15-dllhost_with_no_command_line_arguments_with_network.md delete mode 100644 docs/_posts/2022-03-15-gpupdate_with_no_command_line_arguments_with_network.md delete mode 100644 docs/_posts/2022-03-15-kerberos_service_ticket_request_using_rc4_encryption.md delete mode 100644 docs/_posts/2022-03-15-rundll32_with_no_command_line_arguments_with_network.md delete mode 100644 docs/_posts/2022-03-15-searchprotocolhost_with_no_command_line_with_network.md delete mode 100644 docs/_posts/2022-03-15-suspicious_dllhost_no_command_line_arguments.md delete mode 100644 docs/_posts/2022-03-15-suspicious_gpupdate_no_command_line_arguments.md delete mode 100644 docs/_posts/2022-03-15-suspicious_rundll32_no_command_line_arguments.md delete mode 100644 docs/_posts/2022-03-15-suspicious_searchprotocolhost_no_command_line_arguments.md delete mode 100644 docs/_posts/2022-03-16-windows_installutil_remote_network_connection.md delete mode 100644 docs/_posts/2022-03-16-windows_installutil_uninstall_option_with_network.md delete mode 100644 docs/_posts/2022-03-17-modify_acl_permission_to_files_or_folder.md delete mode 100644 docs/_posts/2022-03-22-get_addefaultdomainpasswordpolicy_with_powershell_script_block.md delete mode 100644 docs/_posts/2022-03-22-get_domainuser_with_powershell_script_block.md delete mode 100644 docs/_posts/2022-03-22-get_wmiobject_group_discovery_with_script_block_logging.md delete mode 100644 docs/_posts/2022-03-22-getadgroup_with_powershell_script_block.md delete mode 100644 docs/_posts/2022-03-22-getcurrent_user_with_powershell_script_block.md delete mode 100644 docs/_posts/2022-03-22-getlocaluser_with_powershell_script_block.md delete mode 100644 docs/_posts/2022-03-22-interactive_session_on_remote_endpoint_with_powershell.md delete mode 100644 docs/_posts/2022-03-22-kerberos_pre-authentication_flag_disabled_with_powershell.md delete mode 100644 docs/_posts/2022-03-22-powershell_execute_com_object.md delete mode 100644 docs/_posts/2022-03-22-powershell_using_memory_as_backing_store.md delete mode 100644 docs/_posts/2022-03-22-recon_avproduct_through_pwh_or_wmi.md delete mode 100644 docs/_posts/2022-03-22-remote_process_instantiation_via_dcom_and_powershell_script_block.md delete mode 100644 docs/_posts/2022-03-22-remote_process_instantiation_via_winrm_and_powershell_script_block.md delete mode 100644 docs/_posts/2022-03-22-user_discovery_with_env_vars_powershell_script_block.md delete mode 100644 docs/_posts/2022-03-24-splunk_dos_via_malformed_s2s_request.md delete mode 100644 docs/_posts/2022-03-28-sql_injection_with_long_urls.md delete mode 100644 docs/_posts/2022-03-28-windows_deleted_registry_by_a_non_critical_process_file_path.md delete mode 100644 docs/_posts/2022-03-28-windows_get-adcomputer_unconstrained_delegation_discovery.md delete mode 100644 docs/_posts/2022-03-28-windows_powerview_unconstrained_delegation_discovery.md delete mode 100644 docs/_posts/2022-03-28-windows_terminating_lsass_process.md delete mode 100644 docs/_posts/2022-03-29-macos_plutil.md delete mode 100644 docs/_posts/2022-03-29-windows_iso_lnk_file_creation.md delete mode 100644 docs/_posts/2022-03-30-windows_drivers_loaded_by_signature.md delete mode 100644 docs/_posts/2022-03-31-windows_powerview_constrained_delegation_discovery.md delete mode 100644 docs/_posts/2022-03-31-windows_registry_certificate_added.md delete mode 100644 docs/_posts/2022-03-31-windows_registry_modification_for_safe_mode_persistence.md delete mode 100644 docs/_posts/2022-04-02-getnettcpconnection_with_powershell_script_block.md delete mode 100644 docs/_posts/2022-04-04-github_actions_disable_security_workflow.md delete mode 100644 docs/_posts/2022-04-04-windows_driver_load_non-standard_path.md delete mode 100644 docs/_posts/2022-04-04-windows_event_for_service_disabled.md delete mode 100644 docs/_posts/2022-04-05-java_writing_jsp_file.md delete mode 100644 docs/_posts/2022-04-05-linux_iptables_firewall_modification.md delete mode 100644 docs/_posts/2022-04-05-linux_kworker_process_commandline.md delete mode 100644 docs/_posts/2022-04-05-linux_stdout_redirection_to_dev_null_file.md delete mode 100644 docs/_posts/2022-04-05-spring4shell_payload_url_request.md delete mode 100644 docs/_posts/2022-04-05-web_jsp_request_via_url.md delete mode 100644 docs/_posts/2022-04-05-web_spring_cloud_function_functionrouter.md delete mode 100644 docs/_posts/2022-04-05-windows_indirect_command_execution_via_forfiles.md delete mode 100644 docs/_posts/2022-04-05-windows_indirect_command_execution_via_pcalua.md delete mode 100644 docs/_posts/2022-04-06-web_spring4shell_http_request_class_module.md delete mode 100644 docs/_posts/2022-04-07-any_powershell_downloadfile.md delete mode 100644 docs/_posts/2022-04-07-any_powershell_downloadstring.md delete mode 100644 docs/_posts/2022-04-07-detect_html_help_renamed.md delete mode 100644 docs/_posts/2022-04-07-detect_mshta_renamed.md delete mode 100644 docs/_posts/2022-04-07-detect_renamed_psexec.md delete mode 100644 docs/_posts/2022-04-07-suspicious_microsoft_workflow_compiler_rename.md delete mode 100644 docs/_posts/2022-04-07-suspicious_msbuild_rename.md delete mode 100644 docs/_posts/2022-04-07-suspicious_rundll32_rename.md delete mode 100644 docs/_posts/2022-04-12-linux_account_manipulation_of_ssh_config_and_keys.md delete mode 100644 docs/_posts/2022-04-12-linux_deletion_of_cron_jobs.md delete mode 100644 docs/_posts/2022-04-12-linux_deletion_of_init_daemon_script.md delete mode 100644 docs/_posts/2022-04-12-linux_deletion_of_services.md delete mode 100644 docs/_posts/2022-04-12-linux_deletion_of_ssh_hash_conf.md delete mode 100644 docs/_posts/2022-04-12-linux_deletion_of_ssh_key.md delete mode 100644 docs/_posts/2022-04-12-linux_deletion_of_ssl_certificate.md delete mode 100644 docs/_posts/2022-04-12-linux_high_frequency_of_file_deletion_in_etc_folder.md delete mode 100644 docs/_posts/2022-04-13-windows_registry_delete_task_sd.md delete mode 100644 docs/_posts/2022-04-18-nltest_domain_trust_discovery.md delete mode 100644 docs/_posts/2022-04-22-linux_adding_crontab_using_list_parameter.md delete mode 100644 docs/_posts/2022-04-22-linux_deleting_critical_directory_using_rm_command.md delete mode 100644 docs/_posts/2022-04-22-linux_disable_services.md delete mode 100644 docs/_posts/2022-04-22-linux_high_frequency_of_file_deletion_in_boot_folder.md delete mode 100644 docs/_posts/2022-04-22-linux_shred_overwrite_command.md delete mode 100644 docs/_posts/2022-04-22-linux_stop_services.md delete mode 100644 docs/_posts/2022-04-22-windows_processes_killed_by_industroyer2_malware.md delete mode 100644 docs/_posts/2022-04-25-windows_linked_policies_in_adsi_discovery.md delete mode 100644 docs/_posts/2022-04-25-windows_root_domain_linked_policies_discovery.md delete mode 100644 docs/_posts/2022-04-26-powershell_fileless_script_contains_base64_encoded_content.md delete mode 100644 docs/_posts/2022-04-26-powershell_get_localgroup_discovery_with_script_block_logging.md delete mode 100644 docs/_posts/2022-04-26-windows_hidden_schedule_task_settings.md delete mode 100644 docs/_posts/2022-04-27-splunk_xss_in_monitoring_console.md delete mode 100644 docs/_posts/2022-04-27-windows_computer_account_created_by_computer_account.md delete mode 100644 docs/_posts/2022-04-27-windows_computer_account_requesting_kerberos_ticket.md delete mode 100644 docs/_posts/2022-04-27-windows_kerberos_local_successful_logon.md delete mode 100644 docs/_posts/2022-04-28-windows_computer_account_with_spn.md delete mode 100644 docs/_posts/2022-04-29-path_traversal_spl_injection.md delete mode 100644 docs/_posts/2022-04-29-splunk_user_enumeration_attempt.md delete mode 100644 docs/_posts/2022-04-30-linux_iptables_firewall_modification.md delete mode 100644 docs/_posts/2022-04-30-linux_kworker_process_in_writable_process_path.md delete mode 100644 docs/_posts/2022-05-02-delete_shadowcopy_with_powershell.md delete mode 100644 docs/_posts/2022-05-02-exchange_powershell_module_usage.md delete mode 100644 docs/_posts/2022-05-02-get-domaintrust_with_powershell_script_block.md delete mode 100644 docs/_posts/2022-05-02-get_aduserresultantpasswordpolicy_with_powershell_script_block.md delete mode 100644 docs/_posts/2022-05-02-get_domainpolicy_with_powershell_script_block.md delete mode 100644 docs/_posts/2022-05-02-getadcomputer_with_powershell_script_block.md delete mode 100644 docs/_posts/2022-05-02-getdomaincomputer_with_powershell_script_block.md delete mode 100644 docs/_posts/2022-05-02-getdomaincontroller_with_powershell_script_block.md delete mode 100644 docs/_posts/2022-05-02-getdomaingroup_with_powershell_script_block.md delete mode 100644 docs/_posts/2022-05-02-getwmiobject_ds_computer_with_powershell_script_block.md delete mode 100644 docs/_posts/2022-05-02-getwmiobject_ds_group_with_powershell_script_block.md delete mode 100644 docs/_posts/2022-05-02-getwmiobject_ds_user_with_powershell_script_block.md delete mode 100644 docs/_posts/2022-05-02-getwmiobject_user_account_with_powershell_script_block.md delete mode 100644 docs/_posts/2022-05-02-mailsniper_invoke_functions.md delete mode 100644 docs/_posts/2022-05-02-powershell_4104_hunting.md delete mode 100644 docs/_posts/2022-05-02-powershell_creating_thread_mutex.md delete mode 100644 docs/_posts/2022-05-02-powershell_loading_dotnet_into_memory_via_reflection.md delete mode 100644 docs/_posts/2022-05-02-powershell_remove_windows_defender_directory.md delete mode 100644 docs/_posts/2022-05-02-windows_krbrelayup_service_creation.md delete mode 100644 docs/_posts/2022-05-02-wmi_recon_running_process_or_services.md delete mode 100644 docs/_posts/2022-05-03-disabled_kerberos_pre-authentication_discovery_with_get-aduser.md delete mode 100644 docs/_posts/2022-05-03-disabled_kerberos_pre-authentication_discovery_with_powerview.md delete mode 100644 docs/_posts/2022-05-05-windows_service_create_kernel_mode_driver.md delete mode 100644 docs/_posts/2022-05-10-detect_aws_console_login_by_new_user.md delete mode 100644 docs/_posts/2022-05-10-f5_big-ip_icontrol_rest_vulnerability_cve-2022-1388.md delete mode 100644 docs/_posts/2022-05-11-potential_password_in_username.md delete mode 100644 docs/_posts/2022-05-16-cobalt_strike_named_pipes.md delete mode 100644 docs/_posts/2022-05-16-windows_system_file_on_disk.md delete mode 100644 docs/_posts/2022-05-17-aws_create_policy_version_to_allow_all_resources.md delete mode 100644 docs/_posts/2022-05-19-vmware_server_side_template_injection_hunt.md delete mode 100644 docs/_posts/2022-05-19-vmware_workspace_one_freemarker_server-side_template_injection.md delete mode 100644 docs/_posts/2022-05-23-schtasks_scheduling_job_on_remote_system.md delete mode 100644 docs/_posts/2022-05-23-splunk_command_and_scripting_interpreter_risky_commands.md delete mode 100644 docs/_posts/2022-05-24-splunk_protocol_impersonation_weak_encryption_simplerequest.md delete mode 100644 docs/_posts/2022-05-25-splunk_identified_ssl_tls_certificates.md delete mode 100644 docs/_posts/2022-05-25-splunk_protocol_impersonation_weak_encryption_configuration.md delete mode 100644 docs/_posts/2022-05-26-linux_at_application_execution.md delete mode 100644 docs/_posts/2022-05-26-linux_possible_append_command_to_at_allow_config_file.md delete mode 100644 docs/_posts/2022-05-26-macos_plutil.md delete mode 100644 docs/_posts/2022-05-26-splunk_digital_certificates_infrastructure_version.md delete mode 100644 docs/_posts/2022-05-26-splunk_digital_certificates_lack_of_encryption.md delete mode 100644 docs/_posts/2022-05-26-splunk_process_injection_forwarder_bundle_downloads.md delete mode 100644 docs/_posts/2022-05-26-splunk_protocol_impersonation_weak_encryption_selfsigned.md delete mode 100644 docs/_posts/2022-05-27-splunk_command_and_scripting_interpreter_delete_usage.md delete mode 100644 docs/_posts/2022-05-27-splunk_command_and_scripting_interpreter_risky_spl_mltk.md delete mode 100644 docs/_posts/2022-05-30-windows_command_and_scripting_interpreter_path_traversal_exec.md delete mode 100644 docs/_posts/2022-05-30-windows_execute_arbitrary_commands_with_msdt.md delete mode 100644 docs/_posts/2022-05-30-windows_office_product_spawning_msdt.md delete mode 100644 docs/_posts/2022-06-01-mshtml_module_load_in_office_product.md delete mode 100644 docs/_posts/2022-06-01-suspicious_process_with_discord_dns_query.md delete mode 100644 docs/_posts/2022-06-01-unload_sysmon_filter_driver.md delete mode 100644 docs/_posts/2022-06-01-wermgr_process_connecting_to_ip_check_web_services.md delete mode 100644 docs/_posts/2022-06-01-windows_command_and_scripting_interpreter_hunting_path_traversal.md delete mode 100644 docs/_posts/2022-06-01-windows_command_and_scripting_interpreter_path_traversal_exec.md delete mode 100644 docs/_posts/2022-06-01-windows_installutil_credential_theft.md delete mode 100644 docs/_posts/2022-06-03-confluence_unauthenticated_remote_code_execution_cve-2022-26134.md delete mode 100644 docs/_posts/2022-06-03-excessive_usage_of_nslookup_app.md delete mode 100644 docs/_posts/2022-06-03-java_writing_jsp_file.md delete mode 100644 docs/_posts/2022-06-03-linux_iptables_firewall_modification.md delete mode 100644 docs/_posts/2022-06-07-windows_impair_defense_delete_win_defender_context_menu.md delete mode 100644 docs/_posts/2022-06-07-windows_impair_defense_delete_win_defender_profile_registry.md delete mode 100644 docs/_posts/2022-06-07-windows_impair_defenses_disable_win_defender_auto_logging.md delete mode 100644 docs/_posts/2022-06-13-windows_msiexec_spawn_discovery_command.md delete mode 100644 docs/_posts/2022-06-14-windows_msiexec_dllregisterserver.md delete mode 100644 docs/_posts/2022-06-14-windows_msiexec_unregister_dllregisterserver.md delete mode 100644 docs/_posts/2022-06-16-detect_risky_spl_using_pretrained_ml_model.md delete mode 100644 docs/_posts/2022-06-16-windows_msiexec_remote_download.md delete mode 100644 docs/_posts/2022-06-16-windows_msiexec_with_network_connections.md delete mode 100644 docs/_posts/2022-06-21-aws_ecr_container_scanning_findings_high.md delete mode 100644 docs/_posts/2022-06-21-windows_gather_victim_network_info_through_ip_check_web_services.md delete mode 100644 docs/_posts/2022-06-21-windows_remote_services_allow_rdp_in_firewall.md delete mode 100644 docs/_posts/2022-06-21-windows_remote_services_allow_remote_assistance.md delete mode 100644 docs/_posts/2022-06-21-windows_remote_services_rdp_enable.md delete mode 100644 docs/_posts/2022-06-21-windows_service_stop_by_deletion.md delete mode 100644 docs/_posts/2022-06-22-windows_modify_registry_disable_toast_notifications.md delete mode 100644 docs/_posts/2022-06-22-windows_modify_registry_disable_windows_security_center_notif.md delete mode 100644 docs/_posts/2022-06-22-windows_modify_registry_disabling_wer_settings.md delete mode 100644 docs/_posts/2022-06-22-windows_modify_registry_disallow_windows_app.md delete mode 100644 docs/_posts/2022-06-22-windows_modify_registry_suppress_win_defender_notif.md delete mode 100644 docs/_posts/2022-06-22-windows_powerview_kerberos_service_ticket_request.md delete mode 100644 docs/_posts/2022-06-22-windows_powerview_spn_discovery.md delete mode 100644 docs/_posts/2022-06-22-windows_remote_access_software_rms_registry.md delete mode 100644 docs/_posts/2022-06-23-windows_modify_registry_disable_win_defender_raw_write_notif.md delete mode 100644 docs/_posts/2022-06-23-windows_valid_account_with_never_expires_password.md delete mode 100644 docs/_posts/2022-06-24-windows_application_layer_protocol_rms_radmin_tool_namedpipe.md delete mode 100644 docs/_posts/2022-06-24-windows_impair_defense_add_xml_applocker_rules.md delete mode 100644 docs/_posts/2022-06-24-windows_impair_defense_deny_security_software_with_applocker.md delete mode 100644 docs/_posts/2022-06-24-windows_modify_registry_regedit_silent_reg_import.md delete mode 100644 docs/_posts/2022-06-24-windows_remote_service_rdpwinst_tool_execution.md delete mode 100644 docs/_posts/2022-06-28-outbound_network_connection_from_java_using_default_ports.md delete mode 100644 docs/_posts/2022-06-28-windows_odbcconf_load_dll.md delete mode 100644 docs/_posts/2022-06-29-remote_system_discovery_with_adsisearcher.md delete mode 100644 docs/_posts/2022-06-29-windows_execute_arbitrary_commands_with_msdt.md delete mode 100644 docs/_posts/2022-06-30-windows_odbcconf_hunting.md delete mode 100644 docs/_posts/2022-06-30-windows_odbcconf_load_response_file.md delete mode 100644 docs/_posts/2022-06-30-windows_powershell_import_applocker_policy.md delete mode 100644 docs/_posts/2022-07-07-office_product_writing_cab_or_inf.md delete mode 100644 docs/_posts/2022-07-07-suspicious_image_creation_in_appdata_folder.md delete mode 100644 docs/_posts/2022-07-07-suspicious_wav_file_in_appdata_folder.md delete mode 100644 docs/_posts/2022-07-07-windows_binary_proxy_execution_mavinject_dll_injection.md delete mode 100644 docs/_posts/2022-07-08-living_off_the_land.md delete mode 100644 docs/_posts/2022-07-11-azure_active_directory_high_risk_sign-in.md delete mode 100644 docs/_posts/2022-07-11-azure_ad_unusual_number_of_failed_authentications_from_ip.md delete mode 100644 docs/_posts/2022-07-11-windows_identify_protocol_handlers.md delete mode 100644 docs/_posts/2022-07-12-aws_defense_evasion_stop_logging_cloudtrail.md delete mode 100644 docs/_posts/2022-07-12-azure_ad_multiple_users_failing_to_authenticate_from_ip.md delete mode 100644 docs/_posts/2022-07-12-azure_ad_successful_single-factor_authentication.md delete mode 100644 docs/_posts/2022-07-12-spring4shell_payload_url_request.md delete mode 100644 docs/_posts/2022-07-13-aws_defense_evasion_delete_cloudtrail.md delete mode 100644 docs/_posts/2022-07-13-azure_ad_successful_powershell_authentication.md delete mode 100644 docs/_posts/2022-07-14-azure_ad_authentication_failed_during_mfa_challenge.md delete mode 100644 docs/_posts/2022-07-15-certutil_exe_certificate_extraction.md delete mode 100644 docs/_posts/2022-07-15-powershell_disable_security_monitoring.md delete mode 100644 docs/_posts/2022-07-15-windows_mof_event_triggered_execution_via_wmi.md delete mode 100644 docs/_posts/2022-07-17-aws_defense_evasion_delete_cloudwatch_log_group.md delete mode 100644 docs/_posts/2022-07-17-aws_defense_evasion_update_cloudtrail.md delete mode 100644 docs/_posts/2022-07-19-allow_inbound_traffic_by_firewall_rule_registry.md delete mode 100644 docs/_posts/2022-07-19-wmic_noninteractive_app_uninstallation.md delete mode 100644 docs/_posts/2022-07-20-linux_persistence_and_privilege_escalation_risk_behavior.md delete mode 100644 docs/_posts/2022-07-20-registry_keys_used_for_persistence.md delete mode 100644 docs/_posts/2022-07-25-aws_defense_evasion_putbucketlifecycle.md delete mode 100644 docs/_posts/2022-07-26-aws_defense_evasion_impair_security_services.md delete mode 100644 docs/_posts/2022-07-27-linux_decode_base64_to_shell.md delete mode 100644 docs/_posts/2022-07-27-linux_kernel_module_enumeration.md delete mode 100644 docs/_posts/2022-07-27-linux_obfuscated_files_or_information_base64_decode.md delete mode 100644 docs/_posts/2022-07-27-linux_ssh_authorized_keys_modification.md delete mode 100644 docs/_posts/2022-07-27-linux_ssh_remote_services_script_execute.md delete mode 100644 docs/_posts/2022-07-27-windows_system_logoff_commandline.md delete mode 100644 docs/_posts/2022-07-27-windows_system_reboot_commandline.md delete mode 100644 docs/_posts/2022-07-27-windows_system_shutdown_commandline.md delete mode 100644 docs/_posts/2022-07-28-linux_clipboard_data_copy.md delete mode 100644 docs/_posts/2022-07-28-windows_command_shell_dcrat_forkbomb_payload.md delete mode 100644 docs/_posts/2022-07-28-windows_system_time_discovery_w32tm_delay.md delete mode 100644 docs/_sass/minimal-mistakes.scss delete mode 100644 docs/_sass/minimal-mistakes/_animations.scss delete mode 100644 docs/_sass/minimal-mistakes/_archive.scss delete mode 100644 docs/_sass/minimal-mistakes/_base.scss delete mode 100644 docs/_sass/minimal-mistakes/_buttons.scss delete mode 100644 docs/_sass/minimal-mistakes/_footer.scss delete mode 100644 docs/_sass/minimal-mistakes/_forms.scss delete mode 100644 docs/_sass/minimal-mistakes/_masthead.scss delete mode 100644 docs/_sass/minimal-mistakes/_mixins.scss delete mode 100644 docs/_sass/minimal-mistakes/_navigation.scss delete mode 100644 docs/_sass/minimal-mistakes/_notices.scss delete mode 100644 docs/_sass/minimal-mistakes/_page.scss delete mode 100644 docs/_sass/minimal-mistakes/_print.scss delete mode 100644 docs/_sass/minimal-mistakes/_reset.scss delete mode 100644 docs/_sass/minimal-mistakes/_search.scss delete mode 100644 docs/_sass/minimal-mistakes/_sidebar.scss delete mode 100644 docs/_sass/minimal-mistakes/_syntax.scss delete mode 100644 docs/_sass/minimal-mistakes/_tables.scss delete mode 100644 docs/_sass/minimal-mistakes/_utilities.scss delete mode 100644 docs/_sass/minimal-mistakes/_variables.scss delete mode 100644 docs/_sass/minimal-mistakes/skins/_air.scss delete mode 100644 docs/_sass/minimal-mistakes/skins/_aqua.scss delete mode 100644 docs/_sass/minimal-mistakes/skins/_contrast.scss delete mode 100644 docs/_sass/minimal-mistakes/skins/_dark.scss delete mode 100644 docs/_sass/minimal-mistakes/skins/_default.scss delete mode 100644 docs/_sass/minimal-mistakes/skins/_dirt.scss delete mode 100644 docs/_sass/minimal-mistakes/skins/_mint.scss delete mode 100644 docs/_sass/minimal-mistakes/skins/_neon.scss delete mode 100644 docs/_sass/minimal-mistakes/skins/_plum.scss delete mode 100644 docs/_sass/minimal-mistakes/skins/_sunrise.scss delete mode 100644 docs/_stories/acidrain.md delete mode 100644 docs/_stories/active_directory_discovery.md delete mode 100644 docs/_stories/active_directory_kerberos_attacks.md delete mode 100644 docs/_stories/active_directory_lateral_movement.md delete mode 100644 docs/_stories/active_directory_password_spraying.md delete mode 100644 docs/_stories/apache_struts_vulnerability.md delete mode 100644 docs/_stories/asset_tracking.md delete mode 100644 docs/_stories/atlassian_confluence_server_and_data_center_cve-2022-26134.md delete mode 100644 docs/_stories/aws_cross_account_activity.md delete mode 100644 docs/_stories/aws_cryptomining.md delete mode 100644 docs/_stories/aws_defense_evasion.md delete mode 100644 docs/_stories/aws_iam_privilege_escalation.md delete mode 100644 docs/_stories/aws_network_acl_activity.md delete mode 100644 docs/_stories/aws_privilege_escalation.md delete mode 100644 docs/_stories/aws_security_hub_alerts.md delete mode 100644 docs/_stories/aws_suspicious_provisioning_activities.md delete mode 100644 docs/_stories/aws_user_monitoring.md delete mode 100644 docs/_stories/azorult.md delete mode 100644 docs/_stories/azure_active_directory_account_takeover.md delete mode 100644 docs/_stories/baron_samedit_cve-2021-3156.md delete mode 100644 docs/_stories/bits_jobs.md delete mode 100644 docs/_stories/blackmatter_ransomware.md delete mode 100644 docs/_stories/brand_monitoring.md delete mode 100644 docs/_stories/caddy_wiper.md delete mode 100644 docs/_stories/clop_ransomware.md delete mode 100644 docs/_stories/cloud_cryptomining.md delete mode 100644 docs/_stories/cloud_federated_credential_abuse.md delete mode 100644 docs/_stories/cobalt_strike.md delete mode 100644 docs/_stories/coldroot_macos_rat.md delete mode 100644 docs/_stories/collection_and_staging.md delete mode 100644 docs/_stories/command_and_control.md delete mode 100644 docs/_stories/common_phishing_frameworks.md delete mode 100644 docs/_stories/container_implantation_monitoring_and_investigation.md delete mode 100644 docs/_stories/credential_dumping.md delete mode 100644 docs/_stories/cyclopsblink.md delete mode 100644 docs/_stories/darkcrystal_rat.md delete mode 100644 docs/_stories/darkside_ransomware.md delete mode 100644 docs/_stories/data_destruction.md delete mode 100644 docs/_stories/data_exfiltration.md delete mode 100644 docs/_stories/data_protection.md delete mode 100644 docs/_stories/deobfuscate-decode_files_or_information.md delete mode 100644 docs/_stories/detect_zerologon_attack.md delete mode 100644 docs/_stories/dev_sec_ops.md delete mode 100644 docs/_stories/dhs_report_ta18-074a.md delete mode 100644 docs/_stories/disabling_security_tools.md delete mode 100644 docs/_stories/dns_amplification_attacks.md delete mode 100644 docs/_stories/dns_hijacking.md delete mode 100644 docs/_stories/domain_trust_discovery.md delete mode 100644 docs/_stories/double_zero_destructor.md delete mode 100644 docs/_stories/dynamic_dns.md delete mode 100644 docs/_stories/emotet_malware__dhs_report_ta18-201a_.md delete mode 100644 docs/_stories/f5_big-ip_vulnerability_cve-2022-1388.md delete mode 100644 docs/_stories/f5_tmui_rce_cve-2020-5902.md delete mode 100644 docs/_stories/fin7.md delete mode 100644 docs/_stories/gcp_cross_account_activity.md delete mode 100644 docs/_stories/hafnium_group.md delete mode 100644 docs/_stories/hermetic_wiper.md delete mode 100644 docs/_stories/hidden_cobra_malware.md delete mode 100644 docs/_stories/host_redirection.md delete mode 100644 docs/_stories/icedid.md delete mode 100644 docs/_stories/industroyer2.md delete mode 100644 docs/_stories/information_sabotage.md delete mode 100644 docs/_stories/ingress_tool_transfer.md delete mode 100644 docs/_stories/insider_threat.md delete mode 100644 docs/_stories/jboss_vulnerability.md delete mode 100644 docs/_stories/kubernetes_scanning_activity.md delete mode 100644 docs/_stories/kubernetes_sensitive_object_access_activity.md delete mode 100644 docs/_stories/kubernetes_sensitive_role_activity.md delete mode 100644 docs/_stories/lateral_movement.md delete mode 100644 docs/_stories/linux_living_off_the_land.md delete mode 100644 docs/_stories/linux_persistence_techniques.md delete mode 100644 docs/_stories/linux_post-exploitation.md delete mode 100644 docs/_stories/linux_privilege_escalation.md delete mode 100644 docs/_stories/linux_rootkit.md delete mode 100644 docs/_stories/living_off_the_land.md delete mode 100644 docs/_stories/local_privilege_escalation_with_krbrelayup.md delete mode 100644 docs/_stories/log4shell_cve-2021-44228.md delete mode 100644 docs/_stories/malicious_powershell.md delete mode 100644 docs/_stories/masquerading_-_rename_system_utilities.md delete mode 100644 docs/_stories/meterpreter.md delete mode 100644 docs/_stories/microsoft_mshtml_remote_code_execution_cve-2021-40444.md delete mode 100644 docs/_stories/microsoft_support_diagnostic_tool_vulnerability_cve-2022-30190.md delete mode 100644 docs/_stories/monitor_backup_solution.md delete mode 100644 docs/_stories/monitor_for_unauthorized_software.md delete mode 100644 docs/_stories/monitor_for_updates.md delete mode 100644 docs/_stories/netsh_abuse.md delete mode 100644 docs/_stories/network_discovery.md delete mode 100644 docs/_stories/nobelium_group.md delete mode 100644 docs/_stories/office_365_detections.md delete mode 100644 docs/_stories/orangeworm_attack_group.md delete mode 100644 docs/_stories/petitpotam_ntlm_relay_on_active_directory_certificate_services.md delete mode 100644 docs/_stories/possible_backdoor_activity_associated_with_mudcarp_espionage_campaigns.md delete mode 100644 docs/_stories/printnightmare_cve-2021-34527.md delete mode 100644 docs/_stories/prohibited_traffic_allowed_or_protocol_mismatch.md delete mode 100644 docs/_stories/proxyshell.md delete mode 100644 docs/_stories/ransomware.md delete mode 100644 docs/_stories/ransomware_cloud.md delete mode 100644 docs/_stories/remcos.md delete mode 100644 docs/_stories/revil_ransomware.md delete mode 100644 docs/_stories/router_and_infrastructure_security.md delete mode 100644 docs/_stories/ryuk_ransomware.md delete mode 100644 docs/_stories/samaccountname_spoofing_and_domain_controller_impersonation.md delete mode 100644 docs/_stories/samsam_ransomware.md delete mode 100644 docs/_stories/signed_binary_proxy_execution_installutil.md delete mode 100644 docs/_stories/silver_sparrow.md delete mode 100644 docs/_stories/spearphishing_attachments.md delete mode 100644 docs/_stories/spectre_and_meltdown_vulnerabilities.md delete mode 100644 docs/_stories/splunk_enterprise_vulnerability.md delete mode 100644 docs/_stories/splunk_enterprise_vulnerability_cve-2018-11409.md delete mode 100644 docs/_stories/splunk_vulnerabilities.md delete mode 100644 docs/_stories/spring4shell_cve-2022-22965.md delete mode 100644 docs/_stories/sql_injection.md delete mode 100644 docs/_stories/suspicious_aws_ec2_activities.md delete mode 100644 docs/_stories/suspicious_aws_login_activities.md delete mode 100644 docs/_stories/suspicious_aws_s3_activities.md delete mode 100644 docs/_stories/suspicious_aws_traffic.md delete mode 100644 docs/_stories/suspicious_cloud_authentication_activities.md delete mode 100644 docs/_stories/suspicious_cloud_instance_activities.md delete mode 100644 docs/_stories/suspicious_cloud_provisioning_activities.md delete mode 100644 docs/_stories/suspicious_cloud_user_activities.md delete mode 100644 docs/_stories/suspicious_command-line_executions.md delete mode 100644 docs/_stories/suspicious_compiled_html_activity.md delete mode 100644 docs/_stories/suspicious_dns_traffic.md delete mode 100644 docs/_stories/suspicious_emails.md delete mode 100644 docs/_stories/suspicious_gcp_storage_activities.md delete mode 100644 docs/_stories/suspicious_mshta_activity.md delete mode 100644 docs/_stories/suspicious_okta_activity.md delete mode 100644 docs/_stories/suspicious_regsvcs_regasm_activity.md delete mode 100644 docs/_stories/suspicious_regsvr32_activity.md delete mode 100644 docs/_stories/suspicious_rundll32_activity.md delete mode 100644 docs/_stories/suspicious_windows_registry_activities.md delete mode 100644 docs/_stories/suspicious_wmi_use.md delete mode 100644 docs/_stories/suspicious_zoom_child_processes.md delete mode 100644 docs/_stories/trickbot.md delete mode 100644 docs/_stories/trusted_developer_utilities_proxy_execution.md delete mode 100644 docs/_stories/trusted_developer_utilities_proxy_execution_msbuild.md delete mode 100644 docs/_stories/unusual_aws_ec2_modifications.md delete mode 100644 docs/_stories/unusual_processes.md delete mode 100644 docs/_stories/use_of_cleartext_protocols.md delete mode 100644 docs/_stories/vmware_server_side_injection_and_privilege_escalation.md delete mode 100644 docs/_stories/web_fraud_detection.md delete mode 100644 docs/_stories/whispergate.md delete mode 100644 docs/_stories/windows_defense_evasion_tactics.md delete mode 100644 docs/_stories/windows_discovery_techniques.md delete mode 100644 docs/_stories/windows_dns_sigred_cve-2020-1350.md delete mode 100644 docs/_stories/windows_drivers.md delete mode 100644 docs/_stories/windows_file_extension_and_association_abuse.md delete mode 100644 docs/_stories/windows_log_manipulation.md delete mode 100644 docs/_stories/windows_persistence_techniques.md delete mode 100644 docs/_stories/windows_privilege_escalation.md delete mode 100644 docs/_stories/windows_registry_abuse.md delete mode 100644 docs/_stories/windows_service_abuse.md delete mode 100644 docs/_stories/windows_system_binary_proxy_execution_msiexec.md delete mode 100644 docs/_stories/xmrig.md delete mode 100644 docs/assets/css/main.scss delete mode 100644 docs/assets/js/_main.js delete mode 100644 docs/assets/js/lunr/lunr-en.js delete mode 100644 docs/assets/js/lunr/lunr-gr.js delete mode 100644 docs/assets/js/lunr/lunr-store.js delete mode 100644 docs/assets/js/lunr/lunr.js delete mode 100644 docs/assets/js/lunr/lunr.min.js delete mode 100644 docs/assets/js/main.min.js delete mode 100644 docs/assets/js/plugins/gumshoe.js delete mode 100644 docs/assets/js/plugins/jquery.ba-throttle-debounce.js delete mode 100644 docs/assets/js/plugins/jquery.fitvids.js delete mode 100644 docs/assets/js/plugins/jquery.greedy-navigation.js delete mode 100644 docs/assets/js/plugins/jquery.magnific-popup.js delete mode 100644 docs/assets/js/plugins/smooth-scroll.js delete mode 100644 docs/detections.wiki delete mode 100644 docs/favicon.ico delete mode 100644 docs/index.html delete mode 100644 docs/index.markdown delete mode 100644 docs/stories.wiki diff --git a/docs/Gemfile b/docs/Gemfile deleted file mode 100644 index 08a1d7017f..0000000000 --- a/docs/Gemfile +++ /dev/null @@ -1,22 +0,0 @@ -source "https://rubygems.org" - -gem "github-pages", group: :jekyll_plugins - -gem "tzinfo-data" -gem "wdm", "~> 0.1.0" if Gem.win_platform? - -# If you have any plugins, put them here! -group :jekyll_plugins do - gem "jekyll-paginate" - gem "jekyll-sitemap" - gem "jekyll-gist" - gem "jekyll-feed" - gem "jemoji" - gem "jekyll-include-cache" - gem "jekyll-algolia" -end - -gem "webrick", "~> 1.7" -gem "activesupport", ">= 4.1.11" - - diff --git a/docs/Gemfile.lock b/docs/Gemfile.lock deleted file mode 100644 index 7d8aa9f01b..0000000000 --- a/docs/Gemfile.lock +++ /dev/null @@ -1,325 +0,0 @@ -GEM - remote: https://rubygems.org/ - specs: - activesupport (6.0.4.4) - concurrent-ruby (~> 1.0, >= 1.0.2) - i18n (>= 0.7, < 2) - minitest (~> 5.1) - tzinfo (~> 1.1) - zeitwerk (~> 2.2, >= 2.2.2) - addressable (2.8.0) - public_suffix (>= 2.0.2, < 5.0) - algolia_html_extractor (2.6.4) - json (~> 2.0) - nokogiri (~> 1.10) - algoliasearch (1.27.5) - httpclient (~> 2.8, >= 2.8.3) - json (>= 1.5.1) - coffee-script (2.4.1) - coffee-script-source - execjs - coffee-script-source (1.11.1) - colorator (1.1.0) - commonmarker (0.17.13) - ruby-enum (~> 0.5) - concurrent-ruby (1.1.9) - dnsruby (1.61.9) - simpleidn (~> 0.1) - em-websocket (0.5.3) - eventmachine (>= 0.12.9) - http_parser.rb (~> 0) - ethon (0.15.0) - ffi (>= 1.15.0) - eventmachine (1.2.7) - execjs (2.8.1) - faraday (1.9.3) - faraday-em_http (~> 1.0) - faraday-em_synchrony (~> 1.0) - faraday-excon (~> 1.1) - faraday-httpclient (~> 1.0) - faraday-multipart (~> 1.0) - faraday-net_http (~> 1.0) - faraday-net_http_persistent (~> 1.0) - faraday-patron (~> 1.0) - faraday-rack (~> 1.0) - faraday-retry (~> 1.0) - ruby2_keywords (>= 0.0.4) - faraday-em_http (1.0.0) - faraday-em_synchrony (1.0.0) - faraday-excon (1.1.0) - faraday-httpclient (1.0.1) - faraday-multipart (1.0.3) - multipart-post (>= 1.2, < 3) - faraday-net_http (1.0.1) - faraday-net_http_persistent (1.2.0) - faraday-patron (1.0.0) - faraday-rack (1.0.0) - faraday-retry (1.0.3) - ffi (1.15.5) - filesize (0.2.0) - forwardable-extended (2.6.0) - gemoji (3.0.1) - github-pages (223) - github-pages-health-check (= 1.17.9) - jekyll (= 3.9.0) - jekyll-avatar (= 0.7.0) - jekyll-coffeescript (= 1.1.1) - jekyll-commonmark-ghpages (= 0.1.6) - jekyll-default-layout (= 0.1.4) - jekyll-feed (= 0.15.1) - jekyll-gist (= 1.5.0) - jekyll-github-metadata (= 2.13.0) - jekyll-include-cache (= 0.2.1) - jekyll-mentions (= 1.6.0) - jekyll-optional-front-matter (= 0.3.2) - jekyll-paginate (= 1.1.0) - jekyll-readme-index (= 0.3.0) - jekyll-redirect-from (= 0.16.0) - jekyll-relative-links (= 0.6.1) - jekyll-remote-theme (= 0.4.3) - jekyll-sass-converter (= 1.5.2) - jekyll-seo-tag (= 2.7.1) - jekyll-sitemap (= 1.4.0) - jekyll-swiss (= 1.0.0) - jekyll-theme-architect (= 0.2.0) - jekyll-theme-cayman (= 0.2.0) - jekyll-theme-dinky (= 0.2.0) - jekyll-theme-hacker (= 0.2.0) - jekyll-theme-leap-day (= 0.2.0) - jekyll-theme-merlot (= 0.2.0) - jekyll-theme-midnight (= 0.2.0) - jekyll-theme-minimal (= 0.2.0) - jekyll-theme-modernist (= 0.2.0) - jekyll-theme-primer (= 0.6.0) - jekyll-theme-slate (= 0.2.0) - jekyll-theme-tactile (= 0.2.0) - jekyll-theme-time-machine (= 0.2.0) - jekyll-titles-from-headings (= 0.5.3) - jemoji (= 0.12.0) - kramdown (= 2.3.1) - kramdown-parser-gfm (= 1.1.0) - liquid (= 4.0.3) - mercenary (~> 0.3) - minima (= 2.5.1) - nokogiri (>= 1.12.5, < 2.0) - rouge (= 3.26.0) - terminal-table (~> 1.4) - github-pages-health-check (1.17.9) - addressable (~> 2.3) - dnsruby (~> 1.60) - octokit (~> 4.0) - public_suffix (>= 3.0, < 5.0) - typhoeus (~> 1.3) - html-pipeline (2.14.0) - activesupport (>= 2) - nokogiri (>= 1.4) - http_parser.rb (0.8.0) - httpclient (2.8.3) - i18n (0.9.5) - concurrent-ruby (~> 1.0) - jekyll (3.9.0) - addressable (~> 2.4) - colorator (~> 1.0) - em-websocket (~> 0.5) - i18n (~> 0.7) - jekyll-sass-converter (~> 1.0) - jekyll-watch (~> 2.0) - kramdown (>= 1.17, < 3) - liquid (~> 4.0) - mercenary (~> 0.3.3) - pathutil (~> 0.9) - rouge (>= 1.7, < 4) - safe_yaml (~> 1.0) - jekyll-algolia (1.7.1) - algolia_html_extractor (~> 2.6) - algoliasearch (~> 1.26) - filesize (~> 0.1) - jekyll (>= 3.6, < 5.0) - json (~> 2.0) - nokogiri (~> 1.6) - progressbar (~> 1.9) - verbal_expressions (~> 0.1.5) - jekyll-avatar (0.7.0) - jekyll (>= 3.0, < 5.0) - jekyll-coffeescript (1.1.1) - coffee-script (~> 2.2) - coffee-script-source (~> 1.11.1) - jekyll-commonmark (1.3.1) - commonmarker (~> 0.14) - jekyll (>= 3.7, < 5.0) - jekyll-commonmark-ghpages (0.1.6) - commonmarker (~> 0.17.6) - jekyll-commonmark (~> 1.2) - rouge (>= 2.0, < 4.0) - jekyll-default-layout (0.1.4) - jekyll (~> 3.0) - jekyll-feed (0.15.1) - jekyll (>= 3.7, < 5.0) - jekyll-gist (1.5.0) - octokit (~> 4.2) - jekyll-github-metadata (2.13.0) - jekyll (>= 3.4, < 5.0) - octokit (~> 4.0, != 4.4.0) - jekyll-include-cache (0.2.1) - jekyll (>= 3.7, < 5.0) - jekyll-mentions (1.6.0) - html-pipeline (~> 2.3) - jekyll (>= 3.7, < 5.0) - jekyll-optional-front-matter (0.3.2) - jekyll (>= 3.0, < 5.0) - jekyll-paginate (1.1.0) - jekyll-readme-index (0.3.0) - jekyll (>= 3.0, < 5.0) - jekyll-redirect-from (0.16.0) - jekyll (>= 3.3, < 5.0) - jekyll-relative-links (0.6.1) - jekyll (>= 3.3, < 5.0) - jekyll-remote-theme (0.4.3) - addressable (~> 2.0) - jekyll (>= 3.5, < 5.0) - jekyll-sass-converter (>= 1.0, <= 3.0.0, != 2.0.0) - rubyzip (>= 1.3.0, < 3.0) - jekyll-sass-converter (1.5.2) - sass (~> 3.4) - jekyll-seo-tag (2.7.1) - jekyll (>= 3.8, < 5.0) - jekyll-sitemap (1.4.0) - jekyll (>= 3.7, < 5.0) - jekyll-swiss (1.0.0) - jekyll-theme-architect (0.2.0) - jekyll (> 3.5, < 5.0) - jekyll-seo-tag (~> 2.0) - jekyll-theme-cayman (0.2.0) - jekyll (> 3.5, < 5.0) - jekyll-seo-tag (~> 2.0) - jekyll-theme-dinky (0.2.0) - jekyll (> 3.5, < 5.0) - jekyll-seo-tag (~> 2.0) - jekyll-theme-hacker (0.2.0) - jekyll (> 3.5, < 5.0) - jekyll-seo-tag (~> 2.0) - jekyll-theme-leap-day (0.2.0) - jekyll (> 3.5, < 5.0) - jekyll-seo-tag (~> 2.0) - jekyll-theme-merlot (0.2.0) - jekyll (> 3.5, < 5.0) - jekyll-seo-tag (~> 2.0) - jekyll-theme-midnight (0.2.0) - jekyll (> 3.5, < 5.0) - jekyll-seo-tag (~> 2.0) - jekyll-theme-minimal (0.2.0) - jekyll (> 3.5, < 5.0) - jekyll-seo-tag (~> 2.0) - jekyll-theme-modernist (0.2.0) - jekyll (> 3.5, < 5.0) - jekyll-seo-tag (~> 2.0) - jekyll-theme-primer (0.6.0) - jekyll (> 3.5, < 5.0) - jekyll-github-metadata (~> 2.9) - jekyll-seo-tag (~> 2.0) - jekyll-theme-slate (0.2.0) - jekyll (> 3.5, < 5.0) - jekyll-seo-tag (~> 2.0) - jekyll-theme-tactile (0.2.0) - jekyll (> 3.5, < 5.0) - jekyll-seo-tag (~> 2.0) - jekyll-theme-time-machine (0.2.0) - jekyll (> 3.5, < 5.0) - jekyll-seo-tag (~> 2.0) - jekyll-titles-from-headings (0.5.3) - jekyll (>= 3.3, < 5.0) - jekyll-watch (2.2.1) - listen (~> 3.0) - jemoji (0.12.0) - gemoji (~> 3.0) - html-pipeline (~> 2.2) - jekyll (>= 3.0, < 5.0) - json (2.6.1) - kramdown (2.3.1) - rexml - kramdown-parser-gfm (1.1.0) - kramdown (~> 2.0) - liquid (4.0.3) - listen (3.7.1) - rb-fsevent (~> 0.10, >= 0.10.3) - rb-inotify (~> 0.9, >= 0.9.10) - mercenary (0.3.6) - mini_portile2 (2.8.0) - minima (2.5.1) - jekyll (>= 3.5, < 5.0) - jekyll-feed (~> 0.9) - jekyll-seo-tag (~> 2.1) - minitest (5.15.0) - multipart-post (2.1.1) - nokogiri (1.13.7) - mini_portile2 (~> 2.8.0) - racc (~> 1.4) - nokogiri (1.13.7-x86_64-darwin) - racc (~> 1.4) - nokogiri (1.13.7-x86_64-linux) - racc (~> 1.4) - octokit (4.22.0) - faraday (>= 0.9) - sawyer (~> 0.8.0, >= 0.5.3) - pathutil (0.16.2) - forwardable-extended (~> 2.6) - progressbar (1.11.0) - public_suffix (4.0.6) - racc (1.6.0) - rb-fsevent (0.11.1) - rb-inotify (0.10.1) - ffi (~> 1.0) - rexml (3.2.5) - rouge (3.26.0) - ruby-enum (0.9.0) - i18n - ruby2_keywords (0.0.5) - rubyzip (2.3.2) - safe_yaml (1.0.5) - sass (3.7.4) - sass-listen (~> 4.0.0) - sass-listen (4.0.0) - rb-fsevent (~> 0.9, >= 0.9.4) - rb-inotify (~> 0.9, >= 0.9.7) - sawyer (0.8.2) - addressable (>= 2.3.5) - faraday (> 0.8, < 2.0) - simpleidn (0.2.1) - unf (~> 0.1.4) - terminal-table (1.8.0) - unicode-display_width (~> 1.1, >= 1.1.1) - thread_safe (0.3.6) - typhoeus (1.4.0) - ethon (>= 0.9.0) - tzinfo (1.2.9) - thread_safe (~> 0.1) - tzinfo-data (1.2021.5) - tzinfo (>= 1.0.0) - unf (0.1.4) - unf_ext - unf_ext (0.0.8) - unicode-display_width (1.8.0) - verbal_expressions (0.1.5) - webrick (1.7.0) - zeitwerk (2.5.4) - -PLATFORMS - ruby - x86_64-darwin-20 - x86_64-linux - -DEPENDENCIES - activesupport (>= 4.1.11) - github-pages - jekyll-algolia - jekyll-feed - jekyll-gist - jekyll-include-cache - jekyll-paginate - jekyll-sitemap - jemoji - tzinfo-data - webrick (~> 1.7) - -BUNDLED WITH - 2.3.6 diff --git a/docs/README.md b/docs/README.md deleted file mode 100644 index 93eb6daccd..0000000000 --- a/docs/README.md +++ /dev/null @@ -1,58 +0,0 @@ -# Splunk Security Content -![](static/logo.png) - -Welcome to the Splunk Security Content - -This project gives you access to our repository of Analytic Stories that are security guides which provide background on TTPs, mapped to the MITRE framework, the Lockheed Martin Kill Chain, and CIS controls. They include Splunk searches, machine-learning algorithms, and Splunk Phantom playbooks (where available)—all designed to work together to detect, investigate, and respond to threats. - -## View Our Content - -* [Analytic Stories](https://github.com/splunk/security_content/blob/develop/docs/stories.md) -* [Detections](https://github.com/splunk/security_content/blob/develop/docs/detections.md) - -If you prefer working with the command line, check out our [API](https://docs.splunkresearch.com/?version=latest): - -``` -curl -s https://content.splunkresearch.com | jq -{ - "hello": "welcome to Splunks Research security content api" -} -``` - -## Test Out The Detections -The [attack_range](https://github.com/splunk/attack_range) project allows you to spin up an enviroment and launch attacks against it to test the detections. - -## Questions? -If you get stuck or need help with any of our tools, see our [support options](https://github.com/splunk/security_content#support). - -## Contribute Content -If you want to help the rest of the security community by sharing your own detections, see our [contributor guide](https://github.com/splunk/security_content/wiki/Contributing-to-the-Project). Digital defenders unite! - - -## Content Parts -* [stories/](https://github.com/splunk/security_content/tree/develop/stories): All Analytic Stories -* [detections/](https://github.com/splunk/security_content/tree/develop/detections): Splunk Enterprise, Splunk UBA, and Splunk Phantom detections that power Analytic Stories -* [response_tasks/](https://github.com/splunk/security_content/tree/develop/response_tasks): Splunk Enterprise and Splunk Phantom investigative searches and playbooks employed by Analytic Stories -* [responses/](https://github.com/splunk/security_content/tree/develop/responses): Automated Splunk Enterprise and Splunk Phantom responses triggered by Analytic Stories - - -#### Content Spec Files -* [stories](https://github.com/splunk/security_content/blob/develop/docs/spec/stories.md) -* [detections](https://github.com/splunk/security_content/blob/develop/docs/spec/detections.md) -* [deployments](https://github.com/splunk/security_content/blob/develop/docs/spec/deployments.md) -* [responses](https://github.com/splunk/security_content/blob/develop/docs/spec/responses.md) -* [response_tasks](https://github.com/splunk/security_content/blob/develop/docs/spec/response_tasks.md) -* [lookups](https://github.com/splunk/security_content/blob/develop/docs/spec/lookups.md) -* [macros](https://github.com/splunk/security_content/blob/develop/docs/spec/macros.md) - -# MITRE ATT&CK ⚔️ -### Detection Coverage -To view an up-to-date detection coverage map for all the content tagged with MITRE techniques visit: [https://mitremap.splunkresearch.com/](https://mitremap.splunkresearch.com/) under the **Detection Coverage** layer. Below is a snapshot in time of what technique we currently have some detection coverage for. The darker the shade of blue the more detections we have for this particular technique. This map is automatically updated on every release and generated from the [generate-coverage-map.py](https://github.com/splunk/security_content/blob/develop/bin/generate-coverage-map.py). - -![](https://github.com/splunk/security_content/blob/develop/docs/mitre-map/coverage.png) - -### Detection Priority by Threat Actors -If curious about how the Threat Research team prioritizes what content to build refer to our **Detection Priority by Threat Actors** layer in [https://mitremap.splunkresearch.com/](https://mitremap.splunkresearch.com/). Using the actor data from [MITRE CTI](https://github.com/mitre/cti) we add a point for every threat actor that uses a particular technique, and then subtract a point of every detection we have mapped to that technique. The resulting map below is how we prioritize what techniques and detections to focus on next. This map is automatically updated on every release and is generated by the [generate-actors-map.py](https://github.com/splunk/security_content/blob/develop/bin/generate-actors-map.py) script. - -![](https://github.com/splunk/security_content/blob/develop/docs/mitre-map/priority.png) - diff --git a/docs/_config.yml b/docs/_config.yml deleted file mode 100644 index f06753c6b4..0000000000 --- a/docs/_config.yml +++ /dev/null @@ -1,170 +0,0 @@ -title: Splunk Security Content -email: research@splunk.com -description: >- # this means to ignore newlines until "baseurl:" - This project gives you access to our repository of Analytic Stories, - security guides that provide background on tactics, techniques and procedures (TTPs), - mapped to the MITRE ATT&CK Framework, the Lockheed Martin Cyber Kill Chain, and CIS Controls. - They include Splunk searches, machine learning algorithms and - Splunk Phantom playbooks (where available)—all designed to work together to detect, investigate, and respond to threats. -name: Splunk Threat Research Team (STRT) -url: "https://splunkresearch.com" -baseurl: "/" # the subpath of your site, e.g. /blog -url: "https://splunkresearch.com" # the base hostname & protocol for your site, e.g. http://example.com -repository: splunk/security_content -logo: "/static/logo.png" -#teaser: "/static/logo.png" -masthead_title: "Security Content" -words_per_minute: 200 -search: true -search_full_content: true -# Social Sharing -twitter: - username: splunk -twitter_username: splunk -github_username: splunk - -# Build settings -#theme: minimal-mistakes-jekyll -#remote_theme: "mmistakes/minimal-mistakes" -minimal_mistakes_skin: "contrast" #default, neon, dark are also options -#minimal_mistakes_skin: "neon" - -# Build settings -markdown: kramdown -highlighter: rouge -lsi: false -excerpt_separator: "\n\n" -incremental: false - -# Markdown Processing -kramdown: - input: GFM - hard_wrap: false - auto_ids: true - footnote_nr: 1 - entity_output: as_char - toc_levels: 1..6 - smart_quotes: lsquo,rsquo,ldquo,rdquo - enable_coderay: false - syntax_highlighter_opts: - block: - line_numbers: true - -remote_theme: mmistakes/minimal-mistakes - -# Outputting -permalink: /:categories/:title/ -paginate: 5 # amount of posts to show -paginate_path: /page:num/ -timezone: # https://en.wikipedia.org/wiki/List_of_tz_database_time_zones - -include: - - _pages - -# Exclude from processing. -# The following items will not be processed, by default. Create a custom list -# to override the default setting. -# exclude: -# - Gemfile -# - Gemfile.lock -# - node_modules -# - vendor/bundle/ -# - vendor/cache/ -# - vendor/gems/ -# - vendor/ruby/ - -# Plugins (previously gems:) -plugins: - - jekyll-paginate - - jekyll-sitemap - - jekyll-gist - - jekyll-feed - - jemoji - - jekyll-include-cache - -# Site Author -author: - name : "Splunk Threat Reasearch Team (STRT)" - avatar : "/static/team_photo.png" - bio : "We help security teams around the globe strengthen operations by providing tactical guidance and insights to detect, investigate and respond against the latest threats." - location : "The Mothership" - email : "research@splunk.com" - links: - - label: "Website" - icon: "fas fa-fw fa-link" - url: "https://www.splunk.com/en_us/cyber-security/threat-research.html" - # -# Site Footer -footer: - links: - - label: "Twitter" - icon: "fab fa-fw fa-twitter-square" - url: "https://twitter.com/splunk" - - label: "GitHub" - icon: "fab fa-fw fa-github" - url: "https://github.com/splunk/security_content" - -collections: - stories: - output: true - permalink: /:collection/:path/ - playbooks: - output: true - permalink: /:collection/:path/ - -defaults: - # _docs - # _posts - - scope: - path: "" - type: posts - values: - layout: single - author_profile: false - read_time: false - comments: false - share: true - related: false - toc: true - # _pages - - scope: - path: "_pages" - type: pages - values: - layout: single - author_profile: false - # _analytic_stories - - scope: - path: "_stories" - type: stories - values: - layout: single - author_profile: false - comments: false - share: true - related: false - toc: true - # _playbooks - - scope: - path: "_playbooks" - type: playbooks - values: - layout: single - author_profile: false - comments: false - share: true - related: true - toc: true -category_archive: - type: liquid - path: /categories/ -tag_archive: - type: liquid - path: /tags/ - -# analytics -analytics: - provider: "google-gtag" - google: - tracking_id: "G-294P2LYRR5" - anonymize_ip: false # default \ No newline at end of file diff --git a/docs/_data/navigation.yml b/docs/_data/navigation.yml deleted file mode 100644 index 6c3f138879..0000000000 --- a/docs/_data/navigation.yml +++ /dev/null @@ -1,116 +0,0 @@ -main: - - title: "Detections" - url: /detections/ - - title: "Analytic Stories" - url: /stories/ - - title: "Playbooks" - url: /playbooks/ - - title: "Blog" - url: https://www.splunk.com/en_us/blog/author/secmrkt-research.html - - title: "About" - url: https://www.splunk.com/en_us/cyber-security/threat-research.html -detections: - - title: "Tactic" - children: - - title: Collection - url: /detections/collection/ - - title: Command And Control - url: /detections/command_and_control/ - - title: Credential Access - url: /detections/credential_access/ - - title: Defense Evasion - url: /detections/defense_evasion/ - - title: Discovery - url: /detections/discovery/ - - title: Execution - url: /detections/execution/ - - title: Exfiltration - url: /detections/exfiltration/ - - title: Impact - url: /detections/impact/ - - title: Initial Access - url: /detections/initial_access/ - - title: Lateral Movement - url: /detections/lateral_movement/ - - title: Persistence - url: /detections/persistence/ - - title: Privilege Escalation - url: /detections/privilege_escalation/ - - title: Reconnaissance - url: /detections/reconnaissance/ - - title: Resource Development - url: /detections/resource_development/ - - title: "Datamodel" - children: - - title: Authentication - url: /detections/authentication/ - - title: Change - url: /detections/change/ - - title: Change_Analysis - url: /detections/change_analysis/ - - title: Email - url: /detections/email/ - - title: Endpoint - url: /detections/endpoint/ - - title: Network_Resolution - url: /detections/network_resolution/ - - title: Network_Sessions - url: /detections/network_sessions/ - - title: Network_Traffic - url: /detections/network_traffic/ - - title: Risk - url: /detections/risk/ - - title: Splunk_Audit - url: /detections/splunk_audit/ - - title: UEBA - url: /detections/ueba/ - - title: Updates - url: /detections/updates/ - - title: Vulnerabilities - url: /detections/vulnerabilities/ - - title: Web - url: /detections/web/ - - title: "Product" - children: - - title: "Splunk Enterprise" - url: /tags/#splunk-enterprise - - title: "Splunk Cloud" - url: /tags/#splunk-cloud - - title: "Splunk Enterprise Security" - url: /tags/#splunk-enterprise-security - - title: "Splunk Behavioral Analytics" - url: /tags/#splunk-behavioral-analytics -stories: - - title: "Use Case" - children: - - title: Abuse - url: /stories/abuse/ - - title: Account Compromise - url: /stories/account_compromise/ - - title: Adversary Tactics - url: /stories/adversary_tactics/ - - title: Best Practices - url: /stories/best_practices/ - - title: Cloud Security - url: /stories/cloud_security/ - - title: Data Destruction - url: /stories/data_destruction/ - - title: Lateral Movement - url: /stories/lateral_movement/ - - title: Malware - url: /stories/malware/ - - title: Privilege Escalation - url: /stories/privilege_escalation/ - - title: Ransomware - url: /stories/ransomware/ - - title: Unauthorized Software - url: /stories/unauthorized_software/ - - title: Vulnerability - url: /stories/vulnerability/ -playbooks: - - title: "Type" - children: - - title: "Response" - url: /tags/#response/ - - title: "Investigation" - url: /tags/#investigation/ \ No newline at end of file diff --git a/docs/_includes/analytics-providers/custom.html b/docs/_includes/analytics-providers/custom.html deleted file mode 100644 index c34b97ad90..0000000000 --- a/docs/_includes/analytics-providers/custom.html +++ /dev/null @@ -1,3 +0,0 @@ - - - \ No newline at end of file diff --git a/docs/_includes/analytics-providers/google-gtag.html b/docs/_includes/analytics-providers/google-gtag.html deleted file mode 100644 index 16d0cf176b..0000000000 --- a/docs/_includes/analytics-providers/google-gtag.html +++ /dev/null @@ -1,9 +0,0 @@ - - - diff --git a/docs/_includes/analytics-providers/google-universal.html b/docs/_includes/analytics-providers/google-universal.html deleted file mode 100644 index 68c2674ba9..0000000000 --- a/docs/_includes/analytics-providers/google-universal.html +++ /dev/null @@ -1,7 +0,0 @@ - - diff --git a/docs/_includes/analytics-providers/google.html b/docs/_includes/analytics-providers/google.html deleted file mode 100644 index c5742b9817..0000000000 --- a/docs/_includes/analytics-providers/google.html +++ /dev/null @@ -1,14 +0,0 @@ - diff --git a/docs/_includes/analytics.html b/docs/_includes/analytics.html deleted file mode 100644 index 371469f0af..0000000000 --- a/docs/_includes/analytics.html +++ /dev/null @@ -1,14 +0,0 @@ -{% if jekyll.environment == 'production' and site.analytics.provider and page.analytics != false %} - -{% case site.analytics.provider %} -{% when "google" %} - {% include /analytics-providers/google.html %} -{% when "google-universal" %} - {% include /analytics-providers/google-universal.html %} -{% when "google-gtag" %} - {% include /analytics-providers/google-gtag.html %} -{% when "custom" %} - {% include /analytics-providers/custom.html %} -{% endcase %} - -{% endif %} \ No newline at end of file diff --git a/docs/_includes/archive-single.html b/docs/_includes/archive-single.html deleted file mode 100644 index 68174807ef..0000000000 --- a/docs/_includes/archive-single.html +++ /dev/null @@ -1,30 +0,0 @@ -{% if post.header.teaser %} - {% capture teaser %}{{ post.header.teaser }}{% endcapture %} -{% else %} - {% assign teaser = site.teaser %} -{% endif %} - -{% if post.id %} - {% assign title = post.title | markdownify | remove: "

" | remove: "

" %} -{% else %} - {% assign title = post.title %} -{% endif %} - -
-
- {% if include.type == "grid" and teaser %} -
- -
- {% endif %} -

- {% if post.link %} - {{ title }} Permalink - {% else %} - {{ title }} - {% endif %} -

- {% include page__meta.html type=include.type %} - {% if post.excerpt %}

{{ post.excerpt | markdownify | strip_html | truncate: 160 }}

{% endif %} -
-
diff --git a/docs/_includes/author-profile-custom-links.html b/docs/_includes/author-profile-custom-links.html deleted file mode 100644 index 1a3d4caefc..0000000000 --- a/docs/_includes/author-profile-custom-links.html +++ /dev/null @@ -1,7 +0,0 @@ - \ No newline at end of file diff --git a/docs/_includes/author-profile.html b/docs/_includes/author-profile.html deleted file mode 100644 index a6ac64e77c..0000000000 --- a/docs/_includes/author-profile.html +++ /dev/null @@ -1,246 +0,0 @@ -{% assign author = page.author | default: page.authors[0] | default: site.author %} -{% assign author = site.data.authors[author] | default: author %} - -
- - {% if author.avatar %} -
- - {{ author.name }} - -
- {% endif %} - -
-

- -

- {% if author.bio %} -
- {{ author.bio | markdownify }} -
- {% endif %} -
- -
- - -
-
\ No newline at end of file diff --git a/docs/_includes/breadcrumbs.html b/docs/_includes/breadcrumbs.html deleted file mode 100644 index 75c032a4b7..0000000000 --- a/docs/_includes/breadcrumbs.html +++ /dev/null @@ -1,40 +0,0 @@ -{% case site.category_archive.type %} - {% when "liquid" %} - {% assign path_type = "#" %} - {% when "jekyll-archives" %} - {% assign path_type = nil %} -{% endcase %} - -{% if page.collection != 'posts' %} - {% assign path_type = nil %} - {% assign crumb_path = '/' %} -{% else %} - {% assign crumb_path = site.category_archive.path %} -{% endif %} - - diff --git a/docs/_includes/browser-upgrade.html b/docs/_includes/browser-upgrade.html deleted file mode 100644 index ec6ad0acc5..0000000000 --- a/docs/_includes/browser-upgrade.html +++ /dev/null @@ -1,3 +0,0 @@ - diff --git a/docs/_includes/category-list.html b/docs/_includes/category-list.html deleted file mode 100644 index ad9a3fc714..0000000000 --- a/docs/_includes/category-list.html +++ /dev/null @@ -1,19 +0,0 @@ -{% case site.category_archive.type %} - {% when "liquid" %} - {% assign path_type = "#" %} - {% when "jekyll-archives" %} - {% assign path_type = nil %} -{% endcase %} - -{% if site.category_archive.path %} - {% assign categories_sorted = page.categories | sort_natural %} - -

- {{ site.data.ui-text[site.locale].categories_label | default: "Categories:" }} - - {% for category_word in categories_sorted %} - {% unless forloop.last %}, {% endunless %} - {% endfor %} - -

-{% endif %} \ No newline at end of file diff --git a/docs/_includes/comment.html b/docs/_includes/comment.html deleted file mode 100644 index 2e3013ee2a..0000000000 --- a/docs/_includes/comment.html +++ /dev/null @@ -1,22 +0,0 @@ -
-
- {{ include.name }} -
-
- -

- {% if include.date %} - {% if include.index %}{% endif %} - {% endif %} -

-
{{ include.message | markdownify }}
-
-
diff --git a/docs/_includes/comments-providers/custom.html b/docs/_includes/comments-providers/custom.html deleted file mode 100644 index 90993691ed..0000000000 --- a/docs/_includes/comments-providers/custom.html +++ /dev/null @@ -1,3 +0,0 @@ - - - \ No newline at end of file diff --git a/docs/_includes/comments-providers/custom_scripts.html b/docs/_includes/comments-providers/custom_scripts.html deleted file mode 100644 index 6947946a73..0000000000 --- a/docs/_includes/comments-providers/custom_scripts.html +++ /dev/null @@ -1,3 +0,0 @@ - - - \ No newline at end of file diff --git a/docs/_includes/comments-providers/discourse.html b/docs/_includes/comments-providers/discourse.html deleted file mode 100644 index aca62cc848..0000000000 --- a/docs/_includes/comments-providers/discourse.html +++ /dev/null @@ -1,13 +0,0 @@ -{% if site.comments.discourse.server %} -{% capture canonical %}{% if site.permalink contains '.html' %}{{ page.url | absolute_url }}{% else %}{{ page.url | absolute_url | remove:'index.html' | strip_slash }}{% endif %}{% endcapture %} - - -{% endif %} diff --git a/docs/_includes/comments-providers/disqus.html b/docs/_includes/comments-providers/disqus.html deleted file mode 100644 index 16a6027c71..0000000000 --- a/docs/_includes/comments-providers/disqus.html +++ /dev/null @@ -1,15 +0,0 @@ -{% if site.comments.disqus.shortname %} - - -{% endif %} diff --git a/docs/_includes/comments-providers/facebook.html b/docs/_includes/comments-providers/facebook.html deleted file mode 100644 index 009dc1c6c5..0000000000 --- a/docs/_includes/comments-providers/facebook.html +++ /dev/null @@ -1,8 +0,0 @@ -
- \ No newline at end of file diff --git a/docs/_includes/comments-providers/giscus.html b/docs/_includes/comments-providers/giscus.html deleted file mode 100644 index e89d41cea1..0000000000 --- a/docs/_includes/comments-providers/giscus.html +++ /dev/null @@ -1,24 +0,0 @@ - \ No newline at end of file diff --git a/docs/_includes/comments-providers/scripts.html b/docs/_includes/comments-providers/scripts.html deleted file mode 100644 index e87badabd3..0000000000 --- a/docs/_includes/comments-providers/scripts.html +++ /dev/null @@ -1,20 +0,0 @@ -{% if site.comments.provider and page.comments %} -{% case site.comments.provider %} - {% when "disqus" %} - {% include /comments-providers/disqus.html %} - {% when "discourse" %} - {% include /comments-providers/discourse.html %} - {% when "facebook" %} - {% include /comments-providers/facebook.html %} - {% when "staticman" %} - {% include /comments-providers/staticman.html %} - {% when "staticman_v2" %} - {% include /comments-providers/staticman_v2.html %} - {% when "utterances" %} - {% include /comments-providers/utterances.html %} - {% when "giscus" %} - {% include /comments-providers/giscus.html %} - {% when "custom" %} - {% include /comments-providers/custom_scripts.html %} -{% endcase %} -{% endif %} \ No newline at end of file diff --git a/docs/_includes/comments-providers/staticman.html b/docs/_includes/comments-providers/staticman.html deleted file mode 100644 index ae3991d9d6..0000000000 --- a/docs/_includes/comments-providers/staticman.html +++ /dev/null @@ -1,40 +0,0 @@ -{% if site.repository and site.staticman.branch %} - -{% endif %} diff --git a/docs/_includes/comments-providers/staticman_v2.html b/docs/_includes/comments-providers/staticman_v2.html deleted file mode 100644 index 3d8ba1112b..0000000000 --- a/docs/_includes/comments-providers/staticman_v2.html +++ /dev/null @@ -1,40 +0,0 @@ -{% if site.repository and site.comments.staticman.branch %} - -{% endif %} diff --git a/docs/_includes/comments-providers/utterances.html b/docs/_includes/comments-providers/utterances.html deleted file mode 100644 index 5cf6c5ccbb..0000000000 --- a/docs/_includes/comments-providers/utterances.html +++ /dev/null @@ -1,21 +0,0 @@ - diff --git a/docs/_includes/comments.html b/docs/_includes/comments.html deleted file mode 100644 index b27c893bba..0000000000 --- a/docs/_includes/comments.html +++ /dev/null @@ -1,180 +0,0 @@ -
- {% capture comments_label %}{{ site.data.ui-text[site.locale].comments_label | default: "Comments" }}{% endcapture %} - {% case site.comments.provider %} - {% when "discourse" %} -

{{ comments_label }}

-
- {% when "disqus" %} -

{{ comments_label }}

-
- {% when "facebook" %} -

{{ comments_label }}

-
- {% when "staticman_v2" %} -
- {% if site.repository and site.comments.staticman.branch %} - -
- {% if site.data.comments[page.slug] %} -

{{ site.data.ui-text[site.locale].comments_title | default: "Comments" }}

- {% assign comments = site.data.comments[page.slug] %} - - - {% assign commentObjects = '' | split: '' %} - {% for comment in comments %} - {% assign commentObject = comment[1] %} - {% assign commentObjects = commentObjects | push: commentObject %} - {% endfor %} - {% assign comments = commentObjects | sort: "date" %} - - {% for comment in comments %} - {% assign email = comment.email %} - {% assign name = comment.name %} - {% assign url = comment.url %} - {% assign date = comment.date %} - {% assign message = comment.message %} - {% include comment.html index=forloop.index email=email name=name url=url date=date message=message %} - {% endfor %} - {% endif %} -
- - - -
-

{{ site.data.ui-text[site.locale].comments_label | default: "Leave a Comment" }}

-

{{ site.data.ui-text[site.locale].comment_form_info | default: "Your email address will not be published. Required fields are marked" }} *

-
-
- - {{ site.data.ui-text[site.locale].loading_label | default: "Loading..." }} -
- -
- - - -
-
- - -
-
- - -
-
- - -
- - - - - {% if site.reCaptcha.siteKey %} -
-
-
- {% endif %} -
- -
-
-
- - {% if site.reCaptcha.siteKey %}{% endif %} - {% endif %} -
- {% when "staticman" %} -
- {% if site.repository and site.staticman.branch %} - -
- {% if site.data.comments[page.slug] %} -

{{ site.data.ui-text[site.locale].comments_title | default: "Comments" }}

- {% assign comments = site.data.comments[page.slug] %} - - - {% assign commentObjects = '' | split: '' %} - {% for comment in comments %} - {% assign commentObject = comment[1] %} - {% assign commentObjects = commentObjects | push: commentObject %} - {% endfor %} - {% assign comments = commentObjects | sort: "date" %} - - {% for comment in comments %} - {% assign email = comment.email %} - {% assign name = comment.name %} - {% assign url = comment.url %} - {% assign date = comment.date %} - {% assign message = comment.message %} - {% include comment.html index=forloop.index email=email name=name url=url date=date message=message %} - {% endfor %} - {% endif %} -
- - - -
-

{{ site.data.ui-text[site.locale].comments_label | default: "Leave a Comment" }}

-

{{ site.data.ui-text[site.locale].comment_form_info | default: "Your email address will not be published. Required fields are marked" }} *

-
-
- - {{ site.data.ui-text[site.locale].loading_label | default: "Loading..." }} -
- -
- - - -
-
- - -
-
- - -
-
- - -
- - - - -
- -
-
-
- - {% endif %} -
- {% when "utterances" %} -

{{ comments_label }}

-
- {% when "giscus" %} -

{{ comments_label }}

-
- {% when "custom" %} - {% include /comments-providers/custom.html %} - {% endcase %} -
diff --git a/docs/_includes/documents-collection.html b/docs/_includes/documents-collection.html deleted file mode 100644 index e88d8c4c46..0000000000 --- a/docs/_includes/documents-collection.html +++ /dev/null @@ -1,15 +0,0 @@ -{% assign entries = site[include.collection] %} - -{% if include.sort_by %} - {% assign entries = entries | sort: include.sort_by %} -{% endif %} - -{% if include.sort_order == 'reverse' %} - {% assign entries = entries | reverse %} -{% endif %} - -{%- for post in entries -%} - {%- unless post.hidden -%} - {% include archive-single.html %} - {%- endunless -%} -{%- endfor -%} diff --git a/docs/_includes/feature_row b/docs/_includes/feature_row deleted file mode 100644 index 03f09c15cf..0000000000 --- a/docs/_includes/feature_row +++ /dev/null @@ -1,41 +0,0 @@ -{% if include.id %} - {% assign feature_row = page[include.id] %} -{% else %} - {% assign feature_row = page.feature_row %} -{% endif %} - -
- - {% for f in feature_row %} -
-
- {% if f.image_path %} -
- {% if f.alt %}{{ f.alt }}{% endif %} - {% if f.image_caption %} - {{ f.image_caption | markdownify | remove: "

" | remove: "

" }}
- {% endif %} -
- {% endif %} - -
- {% if f.title %} -

{{ f.title }}

- {% endif %} - - {% if f.excerpt %} -
- {{ f.excerpt | markdownify }} -
- {% endif %} - - {% if f.url %} -

{{ f.btn_label | default: site.data.ui-text[site.locale].more_label | default: "Learn More" }}

- {% endif %} -
-
-
- {% endfor %} - -
diff --git a/docs/_includes/figure b/docs/_includes/figure deleted file mode 100644 index dacc668d10..0000000000 --- a/docs/_includes/figure +++ /dev/null @@ -1,9 +0,0 @@ -
- {% if include.alt %}{{ include.alt }}{% endif %} - {%- if include.caption -%} -
- {{ include.caption | markdownify | remove: "

" | remove: "

" }} -
- {%- endif -%} -
diff --git a/docs/_includes/footer.html b/docs/_includes/footer.html deleted file mode 100644 index 2b53a253ee..0000000000 --- a/docs/_includes/footer.html +++ /dev/null @@ -1,21 +0,0 @@ - - - diff --git a/docs/_includes/footer/custom.html b/docs/_includes/footer/custom.html deleted file mode 100644 index d512599d1a..0000000000 --- a/docs/_includes/footer/custom.html +++ /dev/null @@ -1,3 +0,0 @@ - - - \ No newline at end of file diff --git a/docs/_includes/gallery b/docs/_includes/gallery deleted file mode 100644 index 71a9e1e1b3..0000000000 --- a/docs/_includes/gallery +++ /dev/null @@ -1,35 +0,0 @@ -{% if include.id %} - {% assign gallery = page[include.id] %} -{% else %} - {% assign gallery = page.gallery %} -{% endif %} - -{% if include.layout %} - {% assign gallery_layout = include.layout %} -{% else %} - {% if gallery.size == 2 %} - {% assign gallery_layout = 'half' %} - {% elsif gallery.size >= 3 %} - {% assign gallery_layout = 'third' %} - {% else %} - {% assign gallery_layout = '' %} - {% endif %} -{% endif %} - - diff --git a/docs/_includes/group-by-array b/docs/_includes/group-by-array deleted file mode 100644 index 708de41ae3..0000000000 --- a/docs/_includes/group-by-array +++ /dev/null @@ -1,47 +0,0 @@ - - - -{% assign __empty_array = '' | split: ',' %} -{% assign group_names = __empty_array %} -{% assign group_items = __empty_array %} - - -{% assign __names = include.collection | map: include.field %} - - -{% assign __names = __names | join: ',' | join: ',' | split: ',' %} - - -{% assign __names = __names | sort %} -{% for name in __names %} - - -{% unless name == previous %} - - -{% assign group_names = group_names | push: name %} -{% endunless %} - -{% assign previous = name %} -{% endfor %} - - - -{% for name in group_names %} - - -{% assign __item = __empty_array %} -{% for __element in include.collection %} -{% if __element[include.field] contains name %} -{% assign __item = __item | push: __element %} -{% endif %} -{% endfor %} - - -{% assign group_items = group_items | push: __item %} -{% endfor %} \ No newline at end of file diff --git a/docs/_includes/head.html b/docs/_includes/head.html deleted file mode 100644 index 73e5637970..0000000000 --- a/docs/_includes/head.html +++ /dev/null @@ -1,25 +0,0 @@ - - -{% include seo.html %} - -{% unless site.atom_feed.hide %} - -{% endunless %} - - - - - - - - - - - -{% if site.head_scripts %} - {% for script in site.head_scripts %} - - {% endfor %} -{% endif %} diff --git a/docs/_includes/head/custom.html b/docs/_includes/head/custom.html deleted file mode 100644 index 978d84fd8b..0000000000 --- a/docs/_includes/head/custom.html +++ /dev/null @@ -1,5 +0,0 @@ - - - - - diff --git a/docs/_includes/masthead.html b/docs/_includes/masthead.html deleted file mode 100644 index 0c66aa65a4..0000000000 --- a/docs/_includes/masthead.html +++ /dev/null @@ -1,35 +0,0 @@ -{% capture logo_path %}{{ site.logo }}{% endcapture %} - -
-
-
- -
-
-
diff --git a/docs/_includes/nav_list b/docs/_includes/nav_list deleted file mode 100644 index a035a5bd7b..0000000000 --- a/docs/_includes/nav_list +++ /dev/null @@ -1,26 +0,0 @@ -{% assign navigation = site.data.navigation[include.nav] %} - - diff --git a/docs/_includes/page__date.html b/docs/_includes/page__date.html deleted file mode 100644 index ec02005f13..0000000000 --- a/docs/_includes/page__date.html +++ /dev/null @@ -1,6 +0,0 @@ -{% assign date_format = site.date_format | default: "%B %-d, %Y" %} -{% if page.last_modified_at %} -

{{ site.data.ui-text[site.locale].date_label | default: "Updated:" }}

-{% elsif page.date %} -

{{ site.data.ui-text[site.locale].date_label | default: "Updated:" }}

-{% endif %} \ No newline at end of file diff --git a/docs/_includes/page__hero.html b/docs/_includes/page__hero.html deleted file mode 100644 index dd1c26fbf1..0000000000 --- a/docs/_includes/page__hero.html +++ /dev/null @@ -1,55 +0,0 @@ -{% capture overlay_img_path %}{{ page.header.overlay_image | relative_url }}{% endcapture %} - -{% if page.header.overlay_filter contains "gradient" %} - {% capture overlay_filter %}{{ page.header.overlay_filter }}{% endcapture %} -{% elsif page.header.overlay_filter contains "rgba" %} - {% capture overlay_filter %}{{ page.header.overlay_filter }}{% endcapture %} - {% capture overlay_filter %}linear-gradient({{ overlay_filter }}, {{ overlay_filter }}){% endcapture %} -{% elsif page.header.overlay_filter %} - {% capture overlay_filter %}rgba(0, 0, 0, {{ page.header.overlay_filter }}){% endcapture %} - {% capture overlay_filter %}linear-gradient({{ overlay_filter }}, {{ overlay_filter }}){% endcapture %} -{% endif %} - -{% if page.header.image_description %} - {% assign image_description = page.header.image_description %} -{% else %} - {% assign image_description = page.title %} -{% endif %} - -{% assign image_description = image_description | markdownify | strip_html | strip_newlines | escape_once %} - -
- {% if page.header.overlay_color or page.header.overlay_image %} -
-

- {% if paginator and site.paginate_show_page_num %} - {{ site.title }}{% unless paginator.page == 1 %} {{ site.data.ui-text[site.locale].page | default: "Page" }} {{ paginator.page }}{% endunless %} - {% else %} - {{ page.title | default: site.title | markdownify | remove: "

" | remove: "

" }} - {% endif %} -

- {% if page.tagline %} -

{{ page.tagline | markdownify | remove: "

" | remove: "

" }}

- {% elsif page.header.show_overlay_excerpt != false and page.excerpt %} -

{{ page.excerpt | markdownify | remove: "

" | remove: "

" }}

- {% endif %} - {% include page__meta.html %} - {% if page.header.cta_url %} -

{{ page.header.cta_label | default: site.data.ui-text[site.locale].more_label | default: "Learn More" }}

- {% endif %} - {% if page.header.actions %} -

- {% for action in page.header.actions %} - {{ action.label | default: site.data.ui-text[site.locale].more_label | default: "Learn More" }} - {% endfor %} - {% endif %} -

- {% else %} - {{ image_description }} - {% endif %} - {% if page.header.caption %} - {{ page.header.caption | markdownify | remove: "

" | remove: "

" }}
- {% endif %} -
diff --git a/docs/_includes/page__hero_video.html b/docs/_includes/page__hero_video.html deleted file mode 100644 index a313a23d45..0000000000 --- a/docs/_includes/page__hero_video.html +++ /dev/null @@ -1,2 +0,0 @@ -{% assign video = page.header.video %} -{% include video id=video.id provider=video.provider danmaku=video.danmaku %} diff --git a/docs/_includes/page__meta.html b/docs/_includes/page__meta.html deleted file mode 100644 index 3d228c9212..0000000000 --- a/docs/_includes/page__meta.html +++ /dev/null @@ -1,31 +0,0 @@ -{% assign document = post | default: page %} -{% if document.read_time or document.show_date %} -

- {% if document.show_date and document.date %} - {% assign date = document.date %} - - - {% assign date_format = site.date_format | default: "%B %-d, %Y" %} - - - {% endif %} - - {% if document.read_time and document.show_date %}{% endif %} - - {% if document.read_time %} - {% assign words_per_minute = document.words_per_minute | default: site.words_per_minute | default: 200 %} - {% assign words = document.content | strip_html | number_of_words %} - - - - {% if words < words_per_minute %} - {{ site.data.ui-text[site.locale].less_than | default: "less than" }} 1 {{ site.data.ui-text[site.locale].minute_read | default: "minute read" }} - {% elsif words == words_per_minute %} - 1 {{ site.data.ui-text[site.locale].minute_read | default: "minute read" }} - {% else %} - {{ words | divided_by: words_per_minute }} {{ site.data.ui-text[site.locale].minute_read | default: "minute read" }} - {% endif %} - - {% endif %} -

-{% endif %} diff --git a/docs/_includes/page__taxonomy.html b/docs/_includes/page__taxonomy.html deleted file mode 100644 index 75c76c81dd..0000000000 --- a/docs/_includes/page__taxonomy.html +++ /dev/null @@ -1,7 +0,0 @@ -{% if site.tag_archive.type and page.tags[0] %} - {% include tag-list.html %} -{% endif %} - -{% if site.category_archive.type and page.categories[0] %} - {% include category-list.html %} -{% endif %} \ No newline at end of file diff --git a/docs/_includes/paginator.html b/docs/_includes/paginator.html deleted file mode 100644 index bffa079467..0000000000 --- a/docs/_includes/paginator.html +++ /dev/null @@ -1,69 +0,0 @@ -{% if paginator.total_pages > 1 %} - -{% endif %} diff --git a/docs/_includes/post_pagination.html b/docs/_includes/post_pagination.html deleted file mode 100644 index a93c627976..0000000000 --- a/docs/_includes/post_pagination.html +++ /dev/null @@ -1,14 +0,0 @@ -{% if page.previous or page.next %} - -{% endif %} \ No newline at end of file diff --git a/docs/_includes/posts-category.html b/docs/_includes/posts-category.html deleted file mode 100644 index b364f30e94..0000000000 --- a/docs/_includes/posts-category.html +++ /dev/null @@ -1,5 +0,0 @@ -{%- for post in site.categories[include.taxonomy] -%} - {%- unless post.hidden -%} - {% include archive-single.html %} - {%- endunless -%} -{%- endfor -%} diff --git a/docs/_includes/posts-tag.html b/docs/_includes/posts-tag.html deleted file mode 100644 index 46fade02a0..0000000000 --- a/docs/_includes/posts-tag.html +++ /dev/null @@ -1,5 +0,0 @@ -{%- for post in site.tags[include.taxonomy] -%} - {%- unless post.hidden -%} - {% include archive-single.html %} - {%- endunless -%} -{%- endfor -%} diff --git a/docs/_includes/scripts.html b/docs/_includes/scripts.html deleted file mode 100644 index bbdaddff0b..0000000000 --- a/docs/_includes/scripts.html +++ /dev/null @@ -1,28 +0,0 @@ -{% if site.footer_scripts %} - {% for script in site.footer_scripts %} - - {% endfor %} -{% else %} - -{% endif %} - -{% if site.search == true or page.layout == "search" %} - {%- assign search_provider = site.search_provider | default: "lunr" -%} - {%- case search_provider -%} - {%- when "lunr" -%} - {% include_cached search/lunr-search-scripts.html %} - {%- when "google" -%} - {% include_cached search/google-search-scripts.html %} - {%- when "algolia" -%} - {% include_cached search/algolia-search-scripts.html %} - {%- endcase -%} -{% endif %} - -{% include analytics.html %} -{% include /comments-providers/scripts.html %} - -{% if site.after_footer_scripts %} - {% for script in site.after_footer_scripts %} - - {% endfor %} -{% endif %} diff --git a/docs/_includes/search/algolia-search-scripts.html b/docs/_includes/search/algolia-search-scripts.html deleted file mode 100644 index 2728d290e2..0000000000 --- a/docs/_includes/search/algolia-search-scripts.html +++ /dev/null @@ -1,61 +0,0 @@ - - - - - - diff --git a/docs/_includes/search/google-search-scripts.html b/docs/_includes/search/google-search-scripts.html deleted file mode 100644 index 4af7423bb3..0000000000 --- a/docs/_includes/search/google-search-scripts.html +++ /dev/null @@ -1,30 +0,0 @@ - \ No newline at end of file diff --git a/docs/_includes/search/lunr-search-scripts.html b/docs/_includes/search/lunr-search-scripts.html deleted file mode 100644 index 574c390094..0000000000 --- a/docs/_includes/search/lunr-search-scripts.html +++ /dev/null @@ -1,10 +0,0 @@ -{% assign lang = site.locale | slice: 0,2 | default: "en" %} -{% case lang %} -{% when "gr" %} - {% assign lang = "gr" %} -{% else %} - {% assign lang = "en" %} -{% endcase %} - - - \ No newline at end of file diff --git a/docs/_includes/search/search_form.html b/docs/_includes/search/search_form.html deleted file mode 100644 index b9de365c6e..0000000000 --- a/docs/_includes/search/search_form.html +++ /dev/null @@ -1,26 +0,0 @@ -
- {%- assign search_provider = site.search_provider | default: "lunr" -%} - {%- case search_provider -%} - {%- when "lunr" -%} - -
- {%- when "google" -%} - -
- -
- {%- when "algolia" -%} - -
- {%- endcase -%} -
diff --git a/docs/_includes/seo.html b/docs/_includes/seo.html deleted file mode 100644 index c9d01e946a..0000000000 --- a/docs/_includes/seo.html +++ /dev/null @@ -1,158 +0,0 @@ - -{%- if site.url -%} - {%- assign seo_url = site.url | append: site.baseurl -%} -{%- endif -%} -{%- assign seo_url = seo_url | default: site.github.url -%} - -{% assign title_separator = site.title_separator | default: '-' | replace: '|', '|' %} - -{%- if page.title -%} - {%- assign seo_title = page.title | append: " " | append: title_separator | append: " " | append: site.title -%} -{%- endif -%} - -{%- if seo_title -%} - {%- assign seo_title = seo_title | markdownify | strip_html | strip_newlines | escape_once -%} -{%- endif -%} - -{% if page.canonical_url %} - {%- assign canonical_url = page.canonical_url %} -{% else %} - {%- assign canonical_url = page.url | replace: "index.html", "" | absolute_url %} -{% endif %} - -{%- assign seo_description = page.description | default: page.excerpt | default: site.description -%} -{%- if seo_description -%} - {%- assign seo_description = seo_description | markdownify | strip_html | newline_to_br | strip_newlines | replace: '
', ' ' | escape_once | strip -%} -{%- endif -%} - -{%- assign author = page.author | default: page.authors[0] | default: site.author -%} -{%- assign author = site.data.authors[author] | default: author -%} - -{%- if author.twitter -%} - {%- assign author_twitter = author.twitter | replace: "@", "" -%} -{%- endif -%} - -{%- assign page_large_image = page.header.og_image | default: page.header.overlay_image | default: page.header.image | absolute_url -%} -{%- assign page_large_image = page_large_image | escape -%} - -{%- assign page_teaser_image = page.header.teaser | default: site.og_image | absolute_url -%} -{%- assign page_teaser_image = page_teaser_image | escape -%} - -{%- assign site_og_image = site.og_image | absolute_url -%} -{%- assign site_og_image = site_og_image | escape -%} - -{%- if page.date -%} - {%- assign og_type = "article" -%} -{%- else -%} - {%- assign og_type = "website" -%} -{%- endif -%} - -{{ seo_title | default: site.title }}{% if paginator %}{% unless paginator.page == 1 %} {{ title_separator }} {{ site.data.ui-text[site.locale].page | default: "Page" }} {{ paginator.page }}{% endunless %}{% endif %} - - -{% if author.name %} - - {% if og_type == "article" %} - - {% endif %} -{% endif %} - - - - - - - -{% if seo_description %} - -{% endif %} - -{% if page_large_image %} - -{% elsif page_teaser_image %} - -{% endif %} - -{% if site.twitter.username %} - - - - - - {% if page_large_image %} - - - {% else %} - - {% if page_teaser_image %} - - {% endif %} - {% endif %} - - {% if author_twitter %} - - {% endif %} -{% endif %} - -{% if page.date %} - -{% endif %} - -{% if og_type == "article" and page.last_modified_at %} - -{% endif %} - -{% if site.facebook %} - {% if site.facebook.publisher %} - - {% endif %} - - {% if site.facebook.app_id %} - - {% endif %} -{% endif %} - - - -{% if paginator.previous_page %} - -{% endif %} -{% if paginator.next_page %} - -{% endif %} - - - -{% if site.google_site_verification %} - -{% endif %} -{% if site.bing_site_verification %} - -{% endif %} -{% if site.alexa_site_verification %} - -{% endif %} -{% if site.yandex_site_verification %} - -{% endif %} -{% if site.naver_site_verification %} - -{% endif %} -{% if site.baidu_site_verification %} - -{% endif %} - diff --git a/docs/_includes/sidebar.html b/docs/_includes/sidebar.html deleted file mode 100644 index a4ca1ca781..0000000000 --- a/docs/_includes/sidebar.html +++ /dev/null @@ -1,19 +0,0 @@ -{% if page.author_profile or layout.author_profile or page.sidebar %} - -{% endif %} diff --git a/docs/_includes/skip-links.html b/docs/_includes/skip-links.html deleted file mode 100644 index c2d52235e1..0000000000 --- a/docs/_includes/skip-links.html +++ /dev/null @@ -1,7 +0,0 @@ - diff --git a/docs/_includes/social-share.html b/docs/_includes/social-share.html deleted file mode 100644 index 0b377982b2..0000000000 --- a/docs/_includes/social-share.html +++ /dev/null @@ -1,11 +0,0 @@ -
- {% if site.data.ui-text[site.locale].share_on_label %} - - {% endif %} - - - - - - LinkedIn -
diff --git a/docs/_includes/tag-list.html b/docs/_includes/tag-list.html deleted file mode 100644 index 5893ee4e4d..0000000000 --- a/docs/_includes/tag-list.html +++ /dev/null @@ -1,19 +0,0 @@ -{% case site.tag_archive.type %} - {% when "liquid" %} - {% assign path_type = "#" %} - {% when "jekyll-archives" %} - {% assign path_type = nil %} -{% endcase %} - -{% if site.tag_archive.path %} - {% assign tags_sorted = page.tags | sort_natural %} - -

- {{ site.data.ui-text[site.locale].tags_label | default: "Tags:" }} - - {% for tag_word in tags_sorted %} - {% unless forloop.last %}, {% endunless %} - {% endfor %} - -

-{% endif %} \ No newline at end of file diff --git a/docs/_includes/toc b/docs/_includes/toc deleted file mode 100644 index 6423ccdc72..0000000000 --- a/docs/_includes/toc +++ /dev/null @@ -1,7 +0,0 @@ - \ No newline at end of file diff --git a/docs/_includes/toc.html b/docs/_includes/toc.html deleted file mode 100644 index 8c71007227..0000000000 --- a/docs/_includes/toc.html +++ /dev/null @@ -1,182 +0,0 @@ -{% capture tocWorkspace %} - {% comment %} - Copyright (c) 2017 Vladimir "allejo" Jimenez - - Permission is hereby granted, free of charge, to any person - obtaining a copy of this software and associated documentation - files (the "Software"), to deal in the Software without - restriction, including without limitation the rights to use, - copy, modify, merge, publish, distribute, sublicense, and/or sell - copies of the Software, and to permit persons to whom the - Software is furnished to do so, subject to the following - conditions: - - The above copyright notice and this permission notice shall be - included in all copies or substantial portions of the Software. - - THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, - EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES - OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND - NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT - HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, - WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING - FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR - OTHER DEALINGS IN THE SOFTWARE. - {% endcomment %} - {% comment %} - Version 1.1.0 - https://github.com/allejo/jekyll-toc - - "...like all things liquid - where there's a will, and ~36 hours to spare, there's usually a/some way" ~jaybe - - Usage: - {% include toc.html html=content sanitize=true class="inline_toc" id="my_toc" h_min=2 h_max=3 %} - - Parameters: - * html (string) - the HTML of compiled markdown generated by kramdown in Jekyll - - Optional Parameters: - * sanitize (bool) : false - when set to true, the headers will be stripped of any HTML in the TOC - * class (string) : '' - a CSS class assigned to the TOC - * id (string) : '' - an ID to assigned to the TOC - * h_min (int) : 1 - the minimum TOC header level to use; any header lower than this value will be ignored - * h_max (int) : 6 - the maximum TOC header level to use; any header greater than this value will be ignored - * ordered (bool) : false - when set to true, an ordered list will be outputted instead of an unordered list - * item_class (string) : '' - add custom class(es) for each list item; has support for '%level%' placeholder, which is the current heading level - * submenu_class (string) : '' - add custom class(es) for each child group of headings; has support for '%level%' placeholder which is the current "submenu" heading level - * base_url (string) : '' - add a base url to the TOC links for when your TOC is on another page than the actual content - * anchor_class (string) : '' - add custom class(es) for each anchor element - * skip_no_ids (bool) : false - skip headers that do not have an `id` attribute - - Output: - An ordered or unordered list representing the table of contents of a markdown block. This snippet will only - generate the table of contents and will NOT output the markdown given to it - {% endcomment %} - - {% capture newline %} - {% endcapture %} - {% assign newline = newline | rstrip %} - - {% capture deprecation_warnings %}{% endcapture %} - - {% if include.baseurl %} - {% capture deprecation_warnings %}{{ deprecation_warnings }}{{ newline }}{% endcapture %} - {% endif %} - - {% if include.skipNoIDs %} - {% capture deprecation_warnings %}{{ deprecation_warnings }}{{ newline }}{% endcapture %} - {% endif %} - - {% capture jekyll_toc %}{% endcapture %} - {% assign orderedList = include.ordered | default: false %} - {% assign baseURL = include.base_url | default: include.baseurl | default: '' %} - {% assign skipNoIDs = include.skip_no_ids | default: include.skipNoIDs | default: false %} - {% assign minHeader = include.h_min | default: 1 %} - {% assign maxHeader = include.h_max | default: 6 %} - {% assign nodes = include.html | strip | split: ' maxHeader %} - {% continue %} - {% endif %} - - {% assign _workspace = node | split: '' | first }}>{% endcapture %} - {% assign header = _workspace[0] | replace: _hAttrToStrip, '' %} - - {% if include.item_class and include.item_class != blank %} - {% capture listItemClass %} class="{{ include.item_class | replace: '%level%', currLevel | split: '.' | join: ' ' }}"{% endcapture %} - {% endif %} - - {% if include.submenu_class and include.submenu_class != blank %} - {% assign subMenuLevel = currLevel | minus: 1 %} - {% capture subMenuClass %} class="{{ include.submenu_class | replace: '%level%', subMenuLevel | split: '.' | join: ' ' }}"{% endcapture %} - {% endif %} - - {% capture anchorBody %}{% if include.sanitize %}{{ header | strip_html }}{% else %}{{ header }}{% endif %}{% endcapture %} - - {% if htmlID %} - {% capture anchorAttributes %} href="{% if baseURL %}{{ baseURL }}{% endif %}#{{ htmlID }}"{% endcapture %} - - {% if include.anchor_class %} - {% capture anchorAttributes %}{{ anchorAttributes }} class="{{ include.anchor_class | split: '.' | join: ' ' }}"{% endcapture %} - {% endif %} - - {% capture listItem %}{{ anchorBody }}{% endcapture %} - {% elsif skipNoIDs == true %} - {% continue %} - {% else %} - {% capture listItem %}{{ anchorBody }}{% endcapture %} - {% endif %} - - {% if currLevel > lastLevel %} - {% capture jekyll_toc %}{{ jekyll_toc }}<{{ listModifier }}{{ subMenuClass }}>{% endcapture %} - {% elsif currLevel < lastLevel %} - {% assign repeatCount = lastLevel | minus: currLevel %} - - {% for i in (1..repeatCount) %} - {% capture jekyll_toc %}{{ jekyll_toc }}{% endcapture %} - {% endfor %} - - {% capture jekyll_toc %}{{ jekyll_toc }}{% endcapture %} - {% else %} - {% capture jekyll_toc %}{{ jekyll_toc }}{% endcapture %} - {% endif %} - - {% capture jekyll_toc %}{{ jekyll_toc }}{{ listItem }}{% endcapture %} - - {% assign lastLevel = currLevel %} - {% assign firstHeader = false %} - {% endfor %} - - {% assign repeatCount = minHeader | minus: 1 %} - {% assign repeatCount = lastLevel | minus: repeatCount %} - {% for i in (1..repeatCount) %} - {% capture jekyll_toc %}{{ jekyll_toc }}{% endcapture %} - {% endfor %} - - {% if jekyll_toc != '' %} - {% assign rootAttributes = '' %} - {% if include.class and include.class != blank %} - {% capture rootAttributes %} class="{{ include.class | split: '.' | join: ' ' }}"{% endcapture %} - {% endif %} - - {% if include.id and include.id != blank %} - {% capture rootAttributes %}{{ rootAttributes }} id="{{ include.id }}"{% endcapture %} - {% endif %} - - {% if rootAttributes %} - {% assign nodes = jekyll_toc | split: '>' %} - {% capture jekyll_toc %}<{{ listModifier }}{{ rootAttributes }}>{{ nodes | shift | join: '>' }}>{% endcapture %} - {% endif %} - {% endif %} -{% endcapture %}{% assign tocWorkspace = '' %}{{ deprecation_warnings }}{{ jekyll_toc }} diff --git a/docs/_includes/video b/docs/_includes/video deleted file mode 100644 index c85a868c1d..0000000000 --- a/docs/_includes/video +++ /dev/null @@ -1,24 +0,0 @@ -{% capture video_id %}{{ include.id }}{% endcapture %} -{% capture video_provider %}{{ include.provider }}{% endcapture %} -{% capture video_danmaku %}{{ include.danmaku | default: 0 }}{% endcapture %} - -{% capture video_src %} - {% case video_provider %} - {% when "vimeo" %} - https://player.vimeo.com/video/{{ video_id }}?dnt=true - {% when "youtube" %} - https://www.youtube-nocookie.com/embed/{{ video_id }} - {% when "google-drive" %} - https://drive.google.com/file/d/{{ video_id }}/preview - {% when "bilibili" %} - https://player.bilibili.com/player.html?bvid={{ video_id }}&page=1&as_wide=1&high_quality=1&danmaku={{ video_danmaku }} - {% endcase %} -{% endcapture %} -{% assign video_src = video_src | strip %} - - -{% unless video_src == "" %} -
- -
-{% endunless %} diff --git a/docs/_layouts/archive-taxonomy.html b/docs/_layouts/archive-taxonomy.html deleted file mode 100644 index eb62a874d0..0000000000 --- a/docs/_layouts/archive-taxonomy.html +++ /dev/null @@ -1,29 +0,0 @@ ---- -layout: default -author_profile: false ---- - -{% if page.header.overlay_color or page.header.overlay_image or page.header.image %} - {% include page__hero.html %} -{% elsif page.header.video.id and page.header.video.provider %} - {% include page__hero_video.html %} -{% endif %} - -{% if page.url != "/" and site.breadcrumbs %} - {% unless paginator %} - {% include breadcrumbs.html %} - {% endunless %} -{% endif %} - -
- {% include sidebar.html %} - -
- {% unless page.header.overlay_color or page.header.overlay_image %} -

{{ page.title }}

- {% endunless %} - {% for post in page.posts %} - {% include archive-single.html %} - {% endfor %} -
-
diff --git a/docs/_layouts/archive.html b/docs/_layouts/archive.html deleted file mode 100644 index 08beb89af5..0000000000 --- a/docs/_layouts/archive.html +++ /dev/null @@ -1,26 +0,0 @@ ---- -layout: default ---- - -{% if page.header.overlay_color or page.header.overlay_image or page.header.image %} - {% include page__hero.html %} -{% elsif page.header.video.id and page.header.video.provider %} - {% include page__hero_video.html %} -{% endif %} - -{% if page.url != "/" and site.breadcrumbs %} - {% unless paginator %} - {% include breadcrumbs.html %} - {% endunless %} -{% endif %} - -
- {% include sidebar.html %} - -
- {% unless page.header.overlay_color or page.header.overlay_image %} -

{{ page.title }}

- {% endunless %} - {{ content }} -
-
\ No newline at end of file diff --git a/docs/_layouts/categories.html b/docs/_layouts/categories.html deleted file mode 100644 index f5448a2934..0000000000 --- a/docs/_layouts/categories.html +++ /dev/null @@ -1,43 +0,0 @@ ---- -layout: archive ---- - -{{ content }} - -{% assign categories_max = 0 %} -{% for category in site.categories %} - {% if category[1].size > categories_max %} - {% assign categories_max = category[1].size %} - {% endif %} -{% endfor %} - -
    - {% for i in (1..categories_max) reversed %} - {% for category in site.categories %} - {% if category[1].size == i %} -
  • - - {{ category[0] }} {{ i }} - -
  • - {% endif %} - {% endfor %} - {% endfor %} -
- -{% assign entries_layout = page.entries_layout | default: 'list' %} -{% for i in (1..categories_max) reversed %} - {% for category in site.categories %} - {% if category[1].size == i %} -
-

{{ category[0] }}

-
- {% for post in category.last %} - {% include archive-single.html type=entries_layout %} - {% endfor %} -
- {{ site.data.ui-text[site.locale].back_to_top | default: 'Back to Top' }} ↑ -
- {% endif %} - {% endfor %} -{% endfor %} diff --git a/docs/_layouts/category.html b/docs/_layouts/category.html deleted file mode 100644 index b281c85603..0000000000 --- a/docs/_layouts/category.html +++ /dev/null @@ -1,10 +0,0 @@ ---- -layout: archive ---- - -{{ content }} - -{% assign entries_layout = page.entries_layout | default: 'list' %} -
- {% include posts-category.html taxonomy=page.taxonomy type=entries_layout %} -
diff --git a/docs/_layouts/collection.html b/docs/_layouts/collection.html deleted file mode 100644 index d23d0c723b..0000000000 --- a/docs/_layouts/collection.html +++ /dev/null @@ -1,10 +0,0 @@ ---- -layout: archive ---- - -{{ content }} - -{% assign entries_layout = page.entries_layout | default: 'list' %} -
- {% include documents-collection.html collection=page.collection sort_by=page.sort_by sort_order=page.sort_order type=entries_layout %} -
diff --git a/docs/_layouts/compress.html b/docs/_layouts/compress.html deleted file mode 100644 index bb34487d2a..0000000000 --- a/docs/_layouts/compress.html +++ /dev/null @@ -1,10 +0,0 @@ ---- -# Jekyll layout that compresses HTML -# v3.1.0 -# http://jch.penibelst.de/ -# © 2014–2015 Anatol Broder -# MIT License ---- - -{% capture _LINE_FEED %} -{% endcapture %}{% if site.compress_html.ignore.envs contains jekyll.environment or site.compress_html.ignore.envs == "all" %}{{ content }}{% else %}{% capture _content %}{{ content }}{% endcapture %}{% assign _profile = site.compress_html.profile %}{% if site.compress_html.endings == "all" %}{% assign _endings = "html head body li dt dd optgroup option colgroup caption thead tbody tfoot tr td th" | split: " " %}{% else %}{% assign _endings = site.compress_html.endings %}{% endif %}{% for _element in _endings %}{% capture _end %}{% endcapture %}{% assign _content = _content | remove: _end %}{% endfor %}{% if _profile and _endings %}{% assign _profile_endings = _content | size | plus: 1 %}{% endif %}{% for _element in site.compress_html.startings %}{% capture _start %}<{{ _element }}>{% endcapture %}{% assign _content = _content | remove: _start %}{% endfor %}{% if _profile and site.compress_html.startings %}{% assign _profile_startings = _content | size | plus: 1 %}{% endif %}{% if site.compress_html.comments == "all" %}{% assign _comments = "" | split: " " %}{% else %}{% assign _comments = site.compress_html.comments %}{% endif %}{% if _comments.size == 2 %}{% capture _comment_befores %}.{{ _content }}{% endcapture %}{% assign _comment_befores = _comment_befores | split: _comments.first %}{% for _comment_before in _comment_befores %}{% if forloop.first %}{% continue %}{% endif %}{% capture _comment_outside %}{% if _carry %}{{ _comments.first }}{% endif %}{{ _comment_before }}{% endcapture %}{% capture _comment %}{% unless _carry %}{{ _comments.first }}{% endunless %}{{ _comment_outside | split: _comments.last | first }}{% if _comment_outside contains _comments.last %}{{ _comments.last }}{% assign _carry = false %}{% else %}{% assign _carry = true %}{% endif %}{% endcapture %}{% assign _content = _content | remove_first: _comment %}{% endfor %}{% if _profile %}{% assign _profile_comments = _content | size | plus: 1 %}{% endif %}{% endif %}{% assign _pre_befores = _content | split: "" %}{% assign _pres_after = "" %}{% if _pres.size != 0 %}{% if site.compress_html.blanklines %}{% assign _lines = _pres.last | split: _LINE_FEED %}{% capture _pres_after %}{% for _line in _lines %}{% assign _trimmed = _line | split: " " | join: " " %}{% if _trimmed != empty or forloop.last %}{% unless forloop.first %}{{ _LINE_FEED }}{% endunless %}{{ _line }}{% endif %}{% endfor %}{% endcapture %}{% else %}{% assign _pres_after = _pres.last | split: " " | join: " " %}{% endif %}{% endif %}{% capture _content %}{{ _content }}{% if _pre_before contains "" %}{% endif %}{% unless _pre_before contains "" and _pres.size == 1 %}{{ _pres_after }}{% endunless %}{% endcapture %}{% endfor %}{% if _profile %}{% assign _profile_collapse = _content | size | plus: 1 %}{% endif %}{% if site.compress_html.clippings == "all" %}{% assign _clippings = "html head title base link meta style body article section nav aside h1 h2 h3 h4 h5 h6 hgroup header footer address p hr blockquote ol ul li dl dt dd figure figcaption main div table caption colgroup col tbody thead tfoot tr td th" | split: " " %}{% else %}{% assign _clippings = site.compress_html.clippings %}{% endif %}{% for _element in _clippings %}{% assign _edges = " ;; ;" | replace: "e", _element | split: ";" %}{% assign _content = _content | replace: _edges[0], _edges[1] | replace: _edges[2], _edges[3] | replace: _edges[4], _edges[5] %}{% endfor %}{% if _profile and _clippings %}{% assign _profile_clippings = _content | size | plus: 1 %}{% endif %}{{ _content }}{% if _profile %}
Step Bytes
raw {{ content | size }}{% if _profile_endings %}
endings {{ _profile_endings }}{% endif %}{% if _profile_startings %}
startings {{ _profile_startings }}{% endif %}{% if _profile_comments %}
comments {{ _profile_comments }}{% endif %}{% if _profile_collapse %}
collapse {{ _profile_collapse }}{% endif %}{% if _profile_clippings %}
clippings {{ _profile_clippings }}{% endif %}
{% endif %}{% endif %} diff --git a/docs/_layouts/default.html b/docs/_layouts/default.html deleted file mode 100644 index 5abd964538..0000000000 --- a/docs/_layouts/default.html +++ /dev/null @@ -1,42 +0,0 @@ ---- ---- - - - - - - {% include head.html %} - {% include head/custom.html %} - - - - {% include_cached skip-links.html %} - {% include_cached browser-upgrade.html %} - {% include_cached masthead.html %} - -
- {{ content }} -
- - {% if site.search == true %} -
- {% include_cached search/search_form.html %} -
- {% endif %} - - - - {% include scripts.html %} - - - diff --git a/docs/_layouts/home.html b/docs/_layouts/home.html deleted file mode 100644 index 02e96eb81c..0000000000 --- a/docs/_layouts/home.html +++ /dev/null @@ -1,22 +0,0 @@ ---- -layout: archive ---- - -{{ content }} - -

{{ site.data.ui-text[site.locale].recent_posts | default: "Recent Posts" }}

- -{% if paginator %} - {% assign posts = paginator.posts %} -{% else %} - {% assign posts = site.posts %} -{% endif %} - -{% assign entries_layout = page.entries_layout | default: 'list' %} -
- {% for post in posts %} - {% include archive-single.html type=entries_layout %} - {% endfor %} -
- -{% include paginator.html %} diff --git a/docs/_layouts/posts.html b/docs/_layouts/posts.html deleted file mode 100644 index 13fc707cf0..0000000000 --- a/docs/_layouts/posts.html +++ /dev/null @@ -1,30 +0,0 @@ ---- -layout: archive ---- - -{{ content }} - -
    - {% assign postsInYear = site.posts | where_exp: "item", "item.hidden != true" | group_by_exp: 'post', 'post.date | date: "%Y"' %} - {% for year in postsInYear %} -
  • - - {{ year.name }} {{ year.items | size }} - -
  • - {% endfor %} -
- -{% assign entries_layout = page.entries_layout | default: 'list' %} -{% assign postsByYear = site.posts | where_exp: "item", "item.hidden != true" | group_by_exp: 'post', 'post.date | date: "%Y"' %} -{% for year in postsByYear %} -
-

{{ year.name }}

-
- {% for post in year.items %} - {% include archive-single.html type=entries_layout %} - {% endfor %} -
- {{ site.data.ui-text[site.locale].back_to_top | default: 'Back to Top' }} ↑ -
-{% endfor %} diff --git a/docs/_layouts/search.html b/docs/_layouts/search.html deleted file mode 100644 index 9e661a364b..0000000000 --- a/docs/_layouts/search.html +++ /dev/null @@ -1,42 +0,0 @@ ---- -layout: default ---- - -{% if page.header.overlay_color or page.header.overlay_image or page.header.image %} - {% include page__hero.html %} -{% endif %} - -{% if page.url != "/" and site.breadcrumbs %} - {% unless paginator %} - {% include breadcrumbs.html %} - {% endunless %} -{% endif %} - -
- {% include sidebar.html %} - -
- {% unless page.header.overlay_color or page.header.overlay_image %} -

{{ page.title }}

- {% endunless %} - - {{ content }} - - {%- assign search_provider = site.search_provider | default: "lunr" -%} - {%- case search_provider -%} - {%- when "lunr" -%} - -
- {%- when "google" -%} -
- -
-
- -
- {%- when "algolia" -%} - -
- {%- endcase -%} -
-
diff --git a/docs/_layouts/single.html b/docs/_layouts/single.html deleted file mode 100644 index 91ac1c8f82..0000000000 --- a/docs/_layouts/single.html +++ /dev/null @@ -1,91 +0,0 @@ ---- -layout: default ---- - -{% if page.header.overlay_color or page.header.overlay_image or page.header.image %} - {% include page__hero.html %} -{% elsif page.header.video.id and page.header.video.provider %} - {% include page__hero_video.html %} -{% endif %} - -{% if page.url != "/" and site.breadcrumbs %} - {% unless paginator %} - {% include breadcrumbs.html %} - {% endunless %} -{% endif %} - -
- {% include sidebar.html %} - -
- {% if page.title %}{% endif %} - {% if page.excerpt %}{% endif %} - {% if page.date %}{% endif %} - {% if page.last_modified_at %}{% endif %} - -
- {% unless page.header.overlay_color or page.header.overlay_image %} -
- {% if page.title %}

- -

{% endif %} - {% include page__meta.html %} -
- {% endunless %} - -
- {% if page.toc %} - - {% endif %} - {{ content }} - {% if page.link %}{% endif %} -
- -
- {% if site.data.ui-text[site.locale].meta_label %} -

{{ site.data.ui-text[site.locale].meta_label }}

- {% endif %} - {% include page__taxonomy.html %} - {% include page__date.html %} -
- - {% if page.share %}{% include social-share.html %}{% endif %} - - {% include post_pagination.html %} -
- - {% if jekyll.environment == 'production' and site.comments.provider and page.comments %} - {% include comments.html %} - {% endif %} -
- - {% comment %}{% endcomment %} - {% if page.id and page.related and site.related_posts.size > 0 %} - - {% comment %}{% endcomment %} - {% elsif page.id and page.related %} - - {% endif %} -
\ No newline at end of file diff --git a/docs/_layouts/splash.html b/docs/_layouts/splash.html deleted file mode 100644 index 2116502402..0000000000 --- a/docs/_layouts/splash.html +++ /dev/null @@ -1,22 +0,0 @@ ---- -layout: default ---- - -{% if page.header.overlay_color or page.header.overlay_image or page.header.image %} - {% include page__hero.html %} -{% elsif page.header.video.id and page.header.video.provider %} - {% include page__hero_video.html %} -{% endif %} - -
-
- {% if page.title %}{% endif %} - {% if page.excerpt %}{% endif %} - {% if page.date %}{% endif %} - {% if page.last_modified_at %}{% endif %} - -
- {{ content }} -
-
-
diff --git a/docs/_layouts/tag.html b/docs/_layouts/tag.html deleted file mode 100644 index 8b1c188500..0000000000 --- a/docs/_layouts/tag.html +++ /dev/null @@ -1,10 +0,0 @@ ---- -layout: archive ---- - -{{ content }} - -{% assign entries_layout = page.entries_layout | default: 'list' %} -
- {% include posts-tag.html taxonomy=page.taxonomy type=entries_layout %} -
diff --git a/docs/_layouts/tags.html b/docs/_layouts/tags.html deleted file mode 100644 index daa11828f8..0000000000 --- a/docs/_layouts/tags.html +++ /dev/null @@ -1,43 +0,0 @@ ---- -layout: archive ---- - -{{ content }} - -{% assign tags_max = 0 %} -{% for tag in site.tags %} - {% if tag[1].size > tags_max %} - {% assign tags_max = tag[1].size %} - {% endif %} -{% endfor %} - -
    - {% for i in (1..tags_max) reversed %} - {% for tag in site.tags %} - {% if tag[1].size == i %} -
  • - - {{ tag[0] }} {{ i }} - -
  • - {% endif %} - {% endfor %} - {% endfor %} -
- -{% assign entries_layout = page.entries_layout | default: 'list' %} -{% for i in (1..tags_max) reversed %} - {% for tag in site.tags %} - {% if tag[1].size == i %} -
-

{{ tag[0] }}

-
- {% for post in tag.last %} - {% include archive-single.html type=entries_layout %} - {% endfor %} -
- {{ site.data.ui-text[site.locale].back_to_top | default: 'Back to Top' }} ↑ -
- {% endif %} - {% endfor %} -{% endfor %} diff --git a/docs/_pages/404.md b/docs/_pages/404.md deleted file mode 100644 index b3025a6053..0000000000 --- a/docs/_pages/404.md +++ /dev/null @@ -1,8 +0,0 @@ ---- -title: "Page Not Found" -excerpt: "Page not found. Your pixels are in another canvas." -sitemap: false -permalink: /404.html ---- - -Sorry, but the page you were trying to view does not exist. diff --git a/docs/_pages/about.md b/docs/_pages/about.md deleted file mode 100644 index aa3056b2d8..0000000000 --- a/docs/_pages/about.md +++ /dev/null @@ -1,10 +0,0 @@ ---- -permalink: /about/ -title: "About" -author_profile: true -layout: category ---- - -Tempor velit sint sunt ipsum tempor enim ad qui ullamco. Est dolore anim ad velit duis dolore minim sunt aliquip amet commodo labore. Ut eu pariatur aute ea aute excepteur laborum. Esse ea esse excepteur minim mollit qui cillum excepteur ex dolore magna. Labore deserunt fugiat incididunt incididunt sint ea. Consequat dolore aute laboris quis proident quis non et est consectetur ex eiusmod sit culpa. - -Cupidatat ea do et in excepteur in. Ad nostrud ut est esse eu duis ea sunt eiusmod. Aliquip tempor veniam sint elit fugiat. Velit incididunt laboris amet incididunt labore dolore irure velit excepteur commodo deserunt laborum. Consectetur eu fugiat veniam veniam Lorem labore magna eiusmod. Ea occaecat reprehenderit pariatur consectetur minim labore ut aliquip. diff --git a/docs/_pages/abuse.md b/docs/_pages/abuse.md deleted file mode 100644 index ecf00dcac7..0000000000 --- a/docs/_pages/abuse.md +++ /dev/null @@ -1,9 +0,0 @@ ---- -title: Abuse -layout: tag -author_profile: false -taxonomy: Abuse -permalink: /detections/abuse/ -sidebar: - nav: "detections" ---- \ No newline at end of file diff --git a/docs/_pages/account_compromise.md b/docs/_pages/account_compromise.md deleted file mode 100644 index f713b0823b..0000000000 --- a/docs/_pages/account_compromise.md +++ /dev/null @@ -1,9 +0,0 @@ ---- -title: Account Compromise -layout: tag -author_profile: false -taxonomy: Account Compromise -permalink: /detections/account_compromise/ -sidebar: - nav: "detections" ---- \ No newline at end of file diff --git a/docs/_pages/adversary_tactics.md b/docs/_pages/adversary_tactics.md deleted file mode 100644 index f5a2ac8395..0000000000 --- a/docs/_pages/adversary_tactics.md +++ /dev/null @@ -1,9 +0,0 @@ ---- -title: Adversary Tactics -layout: tag -author_profile: false -taxonomy: Adversary Tactics -permalink: /detections/adversary_tactics/ -sidebar: - nav: "detections" ---- \ No newline at end of file diff --git a/docs/_pages/authentication.md b/docs/_pages/authentication.md deleted file mode 100644 index 73fd390798..0000000000 --- a/docs/_pages/authentication.md +++ /dev/null @@ -1,9 +0,0 @@ ---- -title: Authentication -layout: tag -author_profile: false -taxonomy: Authentication -permalink: /detections/authentication/ -sidebar: - nav: "detections" ---- \ No newline at end of file diff --git a/docs/_pages/best_practices.md b/docs/_pages/best_practices.md deleted file mode 100644 index 4a51438a99..0000000000 --- a/docs/_pages/best_practices.md +++ /dev/null @@ -1,9 +0,0 @@ ---- -title: Best Practices -layout: tag -author_profile: false -taxonomy: Best Practices -permalink: /detections/best_practices/ -sidebar: - nav: "detections" ---- \ No newline at end of file diff --git a/docs/_pages/certificates.md b/docs/_pages/certificates.md deleted file mode 100644 index 652c0d5885..0000000000 --- a/docs/_pages/certificates.md +++ /dev/null @@ -1,9 +0,0 @@ ---- -title: Certificates -layout: tag -author_profile: false -taxonomy: Certificates -permalink: /detections/certificates/ -sidebar: - nav: "detections" ---- \ No newline at end of file diff --git a/docs/_pages/change.md b/docs/_pages/change.md deleted file mode 100644 index 530765d8db..0000000000 --- a/docs/_pages/change.md +++ /dev/null @@ -1,9 +0,0 @@ ---- -title: Change -layout: tag -author_profile: false -taxonomy: Change -permalink: /detections/change/ -sidebar: - nav: "detections" ---- \ No newline at end of file diff --git a/docs/_pages/change_analysis.md b/docs/_pages/change_analysis.md deleted file mode 100644 index 8e0aa5ad5f..0000000000 --- a/docs/_pages/change_analysis.md +++ /dev/null @@ -1,9 +0,0 @@ ---- -title: Change_Analysis -layout: tag -author_profile: false -taxonomy: Change_Analysis -permalink: /detections/change_analysis/ -sidebar: - nav: "detections" ---- \ No newline at end of file diff --git a/docs/_pages/cloud_security.md b/docs/_pages/cloud_security.md deleted file mode 100644 index 8f5f4767d1..0000000000 --- a/docs/_pages/cloud_security.md +++ /dev/null @@ -1,9 +0,0 @@ ---- -title: Cloud Security -layout: tag -author_profile: false -taxonomy: Cloud Security -permalink: /detections/cloud_security/ -sidebar: - nav: "detections" ---- \ No newline at end of file diff --git a/docs/_pages/collection.md b/docs/_pages/collection.md deleted file mode 100644 index e30491cef8..0000000000 --- a/docs/_pages/collection.md +++ /dev/null @@ -1,9 +0,0 @@ ---- -title: Collection -layout: tag -author_profile: false -taxonomy: Collection -permalink: /detections/collection/ -sidebar: - nav: "detections" ---- \ No newline at end of file diff --git a/docs/_pages/command_and_control.md b/docs/_pages/command_and_control.md deleted file mode 100644 index 3b312aee78..0000000000 --- a/docs/_pages/command_and_control.md +++ /dev/null @@ -1,9 +0,0 @@ ---- -title: Command And Control -layout: tag -author_profile: false -taxonomy: Command And Control -permalink: /detections/command_and_control/ -sidebar: - nav: "detections" ---- \ No newline at end of file diff --git a/docs/_pages/credential_access.md b/docs/_pages/credential_access.md deleted file mode 100644 index 226d1076f3..0000000000 --- a/docs/_pages/credential_access.md +++ /dev/null @@ -1,9 +0,0 @@ ---- -title: Credential Access -layout: tag -author_profile: false -taxonomy: Credential Access -permalink: /detections/credential_access/ -sidebar: - nav: "detections" ---- \ No newline at end of file diff --git a/docs/_pages/data_destruction.md b/docs/_pages/data_destruction.md deleted file mode 100644 index 9eb6556f8b..0000000000 --- a/docs/_pages/data_destruction.md +++ /dev/null @@ -1,9 +0,0 @@ ---- -title: Data Destruction -layout: tag -author_profile: false -taxonomy: Data Destruction -permalink: /detections/data_destruction/ -sidebar: - nav: "detections" ---- \ No newline at end of file diff --git a/docs/_pages/defense_evasion.md b/docs/_pages/defense_evasion.md deleted file mode 100644 index ad5abb3c31..0000000000 --- a/docs/_pages/defense_evasion.md +++ /dev/null @@ -1,9 +0,0 @@ ---- -title: Defense Evasion -layout: tag -author_profile: false -taxonomy: Defense Evasion -permalink: /detections/defense_evasion/ -sidebar: - nav: "detections" ---- \ No newline at end of file diff --git a/docs/_pages/detections.md b/docs/_pages/detections.md deleted file mode 100644 index 4064f6c8c6..0000000000 --- a/docs/_pages/detections.md +++ /dev/null @@ -1,977 +0,0 @@ ---- -title: "Detections" -layout: categories -author_profile: false -permalink: /detections/ -classes: wide -sidebar: - nav: "detections" ---- - -| Name | Technique | Type | -| -------------- | --------------- | --------------- | -| [7zip CommandLine To SMB Share Path](/endpoint/7zip_commandline_to_smb_share_path/) | [Archive via Utility](/tags/#archive-via-utility), [Archive Collected Data](/tags/#archive-collected-data) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [AWS Cloud Provisioning From Previously Unseen City](/deprecated/aws_cloud_provisioning_from_previously_unseen_city/) | [Unused/Unsupported Cloud Regions](/tags/#unused/unsupported-cloud-regions) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [AWS Cloud Provisioning From Previously Unseen Country](/deprecated/aws_cloud_provisioning_from_previously_unseen_country/) | [Unused/Unsupported Cloud Regions](/tags/#unused/unsupported-cloud-regions) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [AWS Cloud Provisioning From Previously Unseen IP Address](/deprecated/aws_cloud_provisioning_from_previously_unseen_ip_address/) | None | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [AWS Cloud Provisioning From Previously Unseen Region](/deprecated/aws_cloud_provisioning_from_previously_unseen_region/) | [Unused/Unsupported Cloud Regions](/tags/#unused/unsupported-cloud-regions) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [AWS Create Policy Version to allow all resources](/cloud/aws_create_policy_version_to_allow_all_resources/) | [Cloud Accounts](/tags/#cloud-accounts), [Valid Accounts](/tags/#valid-accounts) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [AWS CreateAccessKey](/cloud/aws_createaccesskey/) | [Cloud Account](/tags/#cloud-account), [Create Account](/tags/#create-account) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [AWS CreateLoginProfile](/cloud/aws_createloginprofile/) | [Cloud Account](/tags/#cloud-account), [Create Account](/tags/#create-account) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [AWS Cross Account Activity From Previously Unseen Account](/cloud/aws_cross_account_activity_from_previously_unseen_account/) | None | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [AWS Defense Evasion Delete CloudWatch Log Group](/cloud/aws_defense_evasion_delete_cloudwatch_log_group/) | [Impair Defenses](/tags/#impair-defenses), [Disable Cloud Logs](/tags/#disable-cloud-logs) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [AWS Defense Evasion Delete Cloudtrail](/cloud/aws_defense_evasion_delete_cloudtrail/) | [Disable Cloud Logs](/tags/#disable-cloud-logs), [Impair Defenses](/tags/#impair-defenses) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [AWS Defense Evasion Impair Security Services](/cloud/aws_defense_evasion_impair_security_services/) | [Disable Cloud Logs](/tags/#disable-cloud-logs), [Impair Defenses](/tags/#impair-defenses) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [AWS Defense Evasion PutBucketLifecycle](/cloud/aws_defense_evasion_putbucketlifecycle/) | [Disable Cloud Logs](/tags/#disable-cloud-logs), [Impair Defenses](/tags/#impair-defenses) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [AWS Defense Evasion Stop Logging Cloudtrail](/cloud/aws_defense_evasion_stop_logging_cloudtrail/) | [Disable Cloud Logs](/tags/#disable-cloud-logs), [Impair Defenses](/tags/#impair-defenses) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [AWS Defense Evasion Update Cloudtrail](/cloud/aws_defense_evasion_update_cloudtrail/) | [Impair Defenses](/tags/#impair-defenses), [Disable Cloud Logs](/tags/#disable-cloud-logs) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [AWS Detect Users creating keys with encrypt policy without MFA](/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa/) | [Data Encrypted for Impact](/tags/#data-encrypted-for-impact) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [AWS Detect Users with KMS keys performing encryption S3](/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3/) | [Data Encrypted for Impact](/tags/#data-encrypted-for-impact) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [AWS ECR Container Scanning Findings High](/cloud/aws_ecr_container_scanning_findings_high/) | [Malicious Image](/tags/#malicious-image), [User Execution](/tags/#user-execution) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [AWS ECR Container Scanning Findings Low Informational Unknown](/cloud/aws_ecr_container_scanning_findings_low_informational_unknown/) | [Malicious Image](/tags/#malicious-image), [User Execution](/tags/#user-execution) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [AWS ECR Container Scanning Findings Medium](/cloud/aws_ecr_container_scanning_findings_medium/) | [Malicious Image](/tags/#malicious-image), [User Execution](/tags/#user-execution) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [AWS ECR Container Upload Outside Business Hours](/cloud/aws_ecr_container_upload_outside_business_hours/) | [Malicious Image](/tags/#malicious-image), [User Execution](/tags/#user-execution) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [AWS ECR Container Upload Unknown User](/cloud/aws_ecr_container_upload_unknown_user/) | [Malicious Image](/tags/#malicious-image), [User Execution](/tags/#user-execution) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [AWS EKS Kubernetes cluster sensitive object access](/deprecated/aws_eks_kubernetes_cluster_sensitive_object_access/) | None | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [AWS Excessive Security Scanning](/cloud/aws_excessive_security_scanning/) | [Cloud Service Discovery](/tags/#cloud-service-discovery) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [AWS IAM AccessDenied Discovery Events](/cloud/aws_iam_accessdenied_discovery_events/) | [Cloud Infrastructure Discovery](/tags/#cloud-infrastructure-discovery) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [AWS IAM Assume Role Policy Brute Force](/cloud/aws_iam_assume_role_policy_brute_force/) | [Cloud Infrastructure Discovery](/tags/#cloud-infrastructure-discovery), [Brute Force](/tags/#brute-force) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [AWS IAM Delete Policy](/cloud/aws_iam_delete_policy/) | [Account Manipulation](/tags/#account-manipulation) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [AWS IAM Failure Group Deletion](/cloud/aws_iam_failure_group_deletion/) | [Account Manipulation](/tags/#account-manipulation) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [AWS IAM Successful Group Deletion](/cloud/aws_iam_successful_group_deletion/) | [Cloud Groups](/tags/#cloud-groups), [Account Manipulation](/tags/#account-manipulation), [Permission Groups Discovery](/tags/#permission-groups-discovery) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [AWS Lambda UpdateFunctionCode](/cloud/aws_lambda_updatefunctioncode/) | [User Execution](/tags/#user-execution) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [AWS Network Access Control List Created with All Open Ports](/cloud/aws_network_access_control_list_created_with_all_open_ports/) | [Disable or Modify Cloud Firewall](/tags/#disable-or-modify-cloud-firewall), [Impair Defenses](/tags/#impair-defenses) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [AWS Network Access Control List Deleted](/cloud/aws_network_access_control_list_deleted/) | [Disable or Modify Cloud Firewall](/tags/#disable-or-modify-cloud-firewall), [Impair Defenses](/tags/#impair-defenses) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [AWS SAML Access by Provider User and Principal](/cloud/aws_saml_access_by_provider_user_and_principal/) | [Valid Accounts](/tags/#valid-accounts) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [AWS SAML Update identity provider](/cloud/aws_saml_update_identity_provider/) | [Valid Accounts](/tags/#valid-accounts) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [AWS SetDefaultPolicyVersion](/cloud/aws_setdefaultpolicyversion/) | [Cloud Accounts](/tags/#cloud-accounts), [Valid Accounts](/tags/#valid-accounts) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [AWS UpdateLoginProfile](/cloud/aws_updateloginprofile/) | [Cloud Account](/tags/#cloud-account), [Create Account](/tags/#create-account) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Abnormally High AWS Instances Launched by User](/deprecated/abnormally_high_aws_instances_launched_by_user/) | [Cloud Accounts](/tags/#cloud-accounts) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Abnormally High AWS Instances Launched by User - MLTK](/deprecated/abnormally_high_aws_instances_launched_by_user_-_mltk/) | [Cloud Accounts](/tags/#cloud-accounts) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Abnormally High AWS Instances Terminated by User](/deprecated/abnormally_high_aws_instances_terminated_by_user/) | [Cloud Accounts](/tags/#cloud-accounts) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Abnormally High AWS Instances Terminated by User - MLTK](/deprecated/abnormally_high_aws_instances_terminated_by_user_-_mltk/) | [Cloud Accounts](/tags/#cloud-accounts) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Abnormally High Number Of Cloud Infrastructure API Calls](/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls/) | [Cloud Accounts](/tags/#cloud-accounts), [Valid Accounts](/tags/#valid-accounts) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Abnormally High Number Of Cloud Instances Destroyed](/cloud/abnormally_high_number_of_cloud_instances_destroyed/) | [Cloud Accounts](/tags/#cloud-accounts), [Valid Accounts](/tags/#valid-accounts) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Abnormally High Number Of Cloud Instances Launched](/cloud/abnormally_high_number_of_cloud_instances_launched/) | [Cloud Accounts](/tags/#cloud-accounts), [Valid Accounts](/tags/#valid-accounts) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Abnormally High Number Of Cloud Security Group API Calls](/cloud/abnormally_high_number_of_cloud_security_group_api_calls/) | [Cloud Accounts](/tags/#cloud-accounts), [Valid Accounts](/tags/#valid-accounts) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Access LSASS Memory for Dump Creation](/endpoint/access_lsass_memory_for_dump_creation/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Account Discovery With Net App](/endpoint/account_discovery_with_net_app/) | [Domain Account](/tags/#domain-account), [Account Discovery](/tags/#account-discovery) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Active Setup Registry Autostart](/endpoint/active_setup_registry_autostart/) | [Active Setup](/tags/#active-setup), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Add DefaultUser And Password In Registry](/endpoint/add_defaultuser_and_password_in_registry/) | [Credentials in Registry](/tags/#credentials-in-registry), [Unsecured Credentials](/tags/#unsecured-credentials) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Add or Set Windows Defender Exclusion](/endpoint/add_or_set_windows_defender_exclusion/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [AdsiSearcher Account Discovery](/endpoint/adsisearcher_account_discovery/) | [Domain Account](/tags/#domain-account), [Account Discovery](/tags/#account-discovery) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Allow File And Printing Sharing In Firewall](/endpoint/allow_file_and_printing_sharing_in_firewall/) | [Disable or Modify Cloud Firewall](/tags/#disable-or-modify-cloud-firewall), [Impair Defenses](/tags/#impair-defenses) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Allow Inbound Traffic By Firewall Rule Registry](/endpoint/allow_inbound_traffic_by_firewall_rule_registry/) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol), [Remote Services](/tags/#remote-services) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Allow Inbound Traffic In Firewall Rule](/endpoint/allow_inbound_traffic_in_firewall_rule/) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol), [Remote Services](/tags/#remote-services) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Allow Network Discovery In Firewall](/endpoint/allow_network_discovery_in_firewall/) | [Disable or Modify Cloud Firewall](/tags/#disable-or-modify-cloud-firewall), [Impair Defenses](/tags/#impair-defenses) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Allow Operation with Consent Admin](/endpoint/allow_operation_with_consent_admin/) | [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Amazon EKS Kubernetes Pod scan detection](/cloud/amazon_eks_kubernetes_pod_scan_detection/) | [Cloud Service Discovery](/tags/#cloud-service-discovery) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Amazon EKS Kubernetes cluster scan detection](/cloud/amazon_eks_kubernetes_cluster_scan_detection/) | [Cloud Service Discovery](/tags/#cloud-service-discovery) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Anomalous usage of 7zip](/endpoint/anomalous_usage_of_7zip/) | [Archive via Utility](/tags/#archive-via-utility), [Archive Collected Data](/tags/#archive-collected-data) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Any Powershell DownloadFile](/endpoint/any_powershell_downloadfile/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell), [Ingress Tool Transfer](/tags/#ingress-tool-transfer) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Any Powershell DownloadString](/endpoint/any_powershell_downloadstring/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell), [Ingress Tool Transfer](/tags/#ingress-tool-transfer) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Attacker Tools On Endpoint](/endpoint/attacker_tools_on_endpoint/) | [Match Legitimate Name or Location](/tags/#match-legitimate-name-or-location), [Masquerading](/tags/#masquerading), [OS Credential Dumping](/tags/#os-credential-dumping), [Active Scanning](/tags/#active-scanning) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Attempt To Add Certificate To Untrusted Store](/endpoint/attempt_to_add_certificate_to_untrusted_store/) | [Install Root Certificate](/tags/#install-root-certificate), [Subvert Trust Controls](/tags/#subvert-trust-controls) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Attempt To Stop Security Service](/endpoint/attempt_to_stop_security_service/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Attempted Credential Dump From Registry via Reg exe](/endpoint/attempted_credential_dump_from_registry_via_reg_exe/) | [Security Account Manager](/tags/#security-account-manager), [OS Credential Dumping](/tags/#os-credential-dumping) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Auto Admin Logon Registry Entry](/endpoint/auto_admin_logon_registry_entry/) | [Credentials in Registry](/tags/#credentials-in-registry), [Unsecured Credentials](/tags/#unsecured-credentials) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Azure AD Authentication Failed During MFA Challenge](/cloud/azure_ad_authentication_failed_during_mfa_challenge/) | [Valid Accounts](/tags/#valid-accounts), [Cloud Accounts](/tags/#cloud-accounts), [Multi-Factor Authentication Request Generation](/tags/#multi-factor-authentication-request-generation) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Azure AD Multiple Users Failing To Authenticate From Ip](/cloud/azure_ad_multiple_users_failing_to_authenticate_from_ip/) | [Brute Force](/tags/#brute-force), [Password Spraying](/tags/#password-spraying) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Azure AD Successful PowerShell Authentication](/cloud/azure_ad_successful_powershell_authentication/) | [Valid Accounts](/tags/#valid-accounts), [Cloud Accounts](/tags/#cloud-accounts) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Azure AD Successful Single-Factor Authentication](/cloud/azure_ad_successful_single-factor_authentication/) | [Security Account Manager](/tags/#security-account-manager) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Azure AD Unusual Number of Failed Authentications From Ip](/cloud/azure_ad_unusual_number_of_failed_authentications_from_ip/) | [Brute Force](/tags/#brute-force), [Password Spraying](/tags/#password-spraying) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Azure Active Directory High Risk Sign-in](/cloud/azure_active_directory_high_risk_sign-in/) | [Brute Force](/tags/#brute-force), [Password Spraying](/tags/#password-spraying) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [BCDEdit Failure Recovery Modification](/endpoint/bcdedit_failure_recovery_modification/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [BITS Job Persistence](/endpoint/bits_job_persistence/) | [BITS Jobs](/tags/#bits-jobs) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [BITSAdmin Download File](/endpoint/bitsadmin_download_file/) | [BITS Jobs](/tags/#bits-jobs), [Ingress Tool Transfer](/tags/#ingress-tool-transfer) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Batch File Write to System32](/endpoint/batch_file_write_to_system32/) | [User Execution](/tags/#user-execution), [Malicious File](/tags/#malicious-file) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Bcdedit Command Back To Normal Mode Boot](/endpoint/bcdedit_command_back_to_normal_mode_boot/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [CHCP Command Execution](/endpoint/chcp_command_execution/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [CMD Carry Out String Command Parameter](/endpoint/cmd_carry_out_string_command_parameter/) | [Windows Command Shell](/tags/#windows-command-shell), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [CMD Echo Pipe - Escalation](/endpoint/cmd_echo_pipe_-_escalation/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Windows Command Shell](/tags/#windows-command-shell), [Windows Service](/tags/#windows-service), [Create or Modify System Process](/tags/#create-or-modify-system-process) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [CMLUA Or CMSTPLUA UAC Bypass](/endpoint/cmlua_or_cmstplua_uac_bypass/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [CMSTP](/tags/#cmstp) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [CSC Net On The Fly Compilation](/endpoint/csc_net_on_the_fly_compilation/) | [Compile After Delivery](/tags/#compile-after-delivery), [Obfuscated Files or Information](/tags/#obfuscated-files-or-information) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [CertUtil Download With URLCache and Split Arguments](/endpoint/certutil_download_with_urlcache_and_split_arguments/) | [Ingress Tool Transfer](/tags/#ingress-tool-transfer) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [CertUtil Download With VerifyCtl and Split Arguments](/endpoint/certutil_download_with_verifyctl_and_split_arguments/) | [Ingress Tool Transfer](/tags/#ingress-tool-transfer) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [CertUtil With Decode Argument](/endpoint/certutil_with_decode_argument/) | [Deobfuscate/Decode Files or Information](/tags/#deobfuscate/decode-files-or-information) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Certutil exe certificate extraction](/endpoint/certutil_exe_certificate_extraction/) | None | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Change Default File Association](/endpoint/change_default_file_association/) | [Change Default File Association](/tags/#change-default-file-association), [Event Triggered Execution](/tags/#event-triggered-execution) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Change To Safe Mode With Network Config](/endpoint/change_to_safe_mode_with_network_config/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Check Elevated CMD using whoami](/endpoint/check_elevated_cmd_using_whoami/) | [System Owner/User Discovery](/tags/#system-owner/user-discovery) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Child Processes of Spoolsv exe](/endpoint/child_processes_of_spoolsv_exe/) | [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Circle CI Disable Security Job](/cloud/circle_ci_disable_security_job/) | [Compromise Client Software Binary](/tags/#compromise-client-software-binary) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Circle CI Disable Security Step](/cloud/circle_ci_disable_security_step/) | [Compromise Client Software Binary](/tags/#compromise-client-software-binary) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Clear Unallocated Sector Using Cipher App](/endpoint/clear_unallocated_sector_using_cipher_app/) | [File Deletion](/tags/#file-deletion), [Indicator Removal on Host](/tags/#indicator-removal-on-host) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Clients Connecting to Multiple DNS Servers](/deprecated/clients_connecting_to_multiple_dns_servers/) | [Exfiltration Over Unencrypted Non-C2 Protocol](/tags/#exfiltration-over-unencrypted-non-c2-protocol) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Clop Common Exec Parameter](/endpoint/clop_common_exec_parameter/) | [User Execution](/tags/#user-execution) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Clop Ransomware Known Service Name](/endpoint/clop_ransomware_known_service_name/) | [Create or Modify System Process](/tags/#create-or-modify-system-process) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Cloud API Calls From Previously Unseen User Roles](/cloud/cloud_api_calls_from_previously_unseen_user_roles/) | [Valid Accounts](/tags/#valid-accounts) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Cloud Compute Instance Created By Previously Unseen User](/cloud/cloud_compute_instance_created_by_previously_unseen_user/) | [Cloud Accounts](/tags/#cloud-accounts), [Valid Accounts](/tags/#valid-accounts) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Cloud Compute Instance Created In Previously Unused Region](/cloud/cloud_compute_instance_created_in_previously_unused_region/) | [Unused/Unsupported Cloud Regions](/tags/#unused/unsupported-cloud-regions) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Cloud Compute Instance Created With Previously Unseen Image](/cloud/cloud_compute_instance_created_with_previously_unseen_image/) | None | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Cloud Compute Instance Created With Previously Unseen Instance Type](/cloud/cloud_compute_instance_created_with_previously_unseen_instance_type/) | None | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Cloud Instance Modified By Previously Unseen User](/cloud/cloud_instance_modified_by_previously_unseen_user/) | [Cloud Accounts](/tags/#cloud-accounts), [Valid Accounts](/tags/#valid-accounts) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Cloud Network Access Control List Deleted](/deprecated/cloud_network_access_control_list_deleted/) | None | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Cloud Provisioning Activity From Previously Unseen City](/cloud/cloud_provisioning_activity_from_previously_unseen_city/) | [Valid Accounts](/tags/#valid-accounts) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Cloud Provisioning Activity From Previously Unseen Country](/cloud/cloud_provisioning_activity_from_previously_unseen_country/) | [Valid Accounts](/tags/#valid-accounts) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Cloud Provisioning Activity From Previously Unseen IP Address](/cloud/cloud_provisioning_activity_from_previously_unseen_ip_address/) | [Valid Accounts](/tags/#valid-accounts) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Cloud Provisioning Activity From Previously Unseen Region](/cloud/cloud_provisioning_activity_from_previously_unseen_region/) | [Valid Accounts](/tags/#valid-accounts) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Cmdline Tool Not Executed In CMD Shell](/endpoint/cmdline_tool_not_executed_in_cmd_shell/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [JavaScript](/tags/#javascript) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Cobalt Strike Named Pipes](/endpoint/cobalt_strike_named_pipes/) | [Process Injection](/tags/#process-injection) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Common Ransomware Extensions](/endpoint/common_ransomware_extensions/) | [Data Destruction](/tags/#data-destruction) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Common Ransomware Notes](/endpoint/common_ransomware_notes/) | [Data Destruction](/tags/#data-destruction) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Confluence Unauthenticated Remote Code Execution CVE-2022-26134](/web/confluence_unauthenticated_remote_code_execution_cve-2022-26134/) | [Server Software Component](/tags/#server-software-component), [Exploit Public-Facing Application](/tags/#exploit-public-facing-application) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Conti Common Exec parameter](/endpoint/conti_common_exec_parameter/) | [User Execution](/tags/#user-execution) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Control Loading from World Writable Directory](/endpoint/control_loading_from_world_writable_directory/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Control Panel](/tags/#control-panel) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Correlation by Repository and Risk](/cloud/correlation_by_repository_and_risk/) | [Malicious Image](/tags/#malicious-image), [User Execution](/tags/#user-execution) | [Correlation](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Correlation by User and Risk](/cloud/correlation_by_user_and_risk/) | [Malicious Image](/tags/#malicious-image), [User Execution](/tags/#user-execution) | [Correlation](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Create Remote Thread In Shell Application](/endpoint/create_remote_thread_in_shell_application/) | [Process Injection](/tags/#process-injection) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Create Remote Thread into LSASS](/endpoint/create_remote_thread_into_lsass/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Create local admin accounts using net exe](/endpoint/create_local_admin_accounts_using_net_exe/) | [Local Account](/tags/#local-account), [Create Account](/tags/#create-account) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Create or delete windows shares using net exe](/endpoint/create_or_delete_windows_shares_using_net_exe/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host), [Network Share Connection Removal](/tags/#network-share-connection-removal) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Creation of Shadow Copy](/endpoint/creation_of_shadow_copy/) | [NTDS](/tags/#ntds), [OS Credential Dumping](/tags/#os-credential-dumping) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Creation of Shadow Copy with wmic and powershell](/endpoint/creation_of_shadow_copy_with_wmic_and_powershell/) | [NTDS](/tags/#ntds), [OS Credential Dumping](/tags/#os-credential-dumping) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Creation of lsass Dump with Taskmgr](/endpoint/creation_of_lsass_dump_with_taskmgr/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Credential Dumping via Copy Command from Shadow Copy](/endpoint/credential_dumping_via_copy_command_from_shadow_copy/) | [NTDS](/tags/#ntds), [OS Credential Dumping](/tags/#os-credential-dumping) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Credential Dumping via Symlink to Shadow Copy](/endpoint/credential_dumping_via_symlink_to_shadow_copy/) | [NTDS](/tags/#ntds), [OS Credential Dumping](/tags/#os-credential-dumping) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Curl Download and Bash Execution](/endpoint/curl_download_and_bash_execution/) | [Ingress Tool Transfer](/tags/#ingress-tool-transfer) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [DLLHost with no Command Line Arguments with Network](/endpoint/dllhost_with_no_command_line_arguments_with_network/) | [Process Injection](/tags/#process-injection) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [DNS Exfiltration Using Nslookup App](/endpoint/dns_exfiltration_using_nslookup_app/) | [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [DNS Query Length Outliers - MLTK](/network/dns_query_length_outliers_-_mltk/) | [DNS](/tags/#dns), [Application Layer Protocol](/tags/#application-layer-protocol) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [DNS Query Length With High Standard Deviation](/network/dns_query_length_with_high_standard_deviation/) | [Exfiltration Over Unencrypted Non-C2 Protocol](/tags/#exfiltration-over-unencrypted-non-c2-protocol), [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [DNS Query Requests Resolved by Unauthorized DNS Servers](/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers/) | [DNS](/tags/#dns) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [DNS record changed](/deprecated/dns_record_changed/) | [DNS](/tags/#dns) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [DSQuery Domain Discovery](/endpoint/dsquery_domain_discovery/) | [Domain Trust Discovery](/tags/#domain-trust-discovery) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Delete ShadowCopy With PowerShell](/endpoint/delete_shadowcopy_with_powershell/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Deleting Of Net Users](/endpoint/deleting_of_net_users/) | [Account Access Removal](/tags/#account-access-removal) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Deleting Shadow Copies](/endpoint/deleting_shadow_copies/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect API activity from users without MFA](/deprecated/detect_api_activity_from_users_without_mfa/) | None | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect ARP Poisoning](/network/detect_arp_poisoning/) | [Hardware Additions](/tags/#hardware-additions), [Network Denial of Service](/tags/#network-denial-of-service), [Adversary-in-the-Middle](/tags/#adversary-in-the-middle), [ARP Cache Poisoning](/tags/#arp-cache-poisoning) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect AWS API Activities From Unapproved Accounts](/deprecated/detect_aws_api_activities_from_unapproved_accounts/) | [Cloud Accounts](/tags/#cloud-accounts) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect AWS Console Login by New User](/cloud/detect_aws_console_login_by_new_user/) | None | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect AWS Console Login by User from New City](/cloud/detect_aws_console_login_by_user_from_new_city/) | [Unused/Unsupported Cloud Regions](/tags/#unused/unsupported-cloud-regions) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect AWS Console Login by User from New Country](/cloud/detect_aws_console_login_by_user_from_new_country/) | [Unused/Unsupported Cloud Regions](/tags/#unused/unsupported-cloud-regions) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect AWS Console Login by User from New Region](/cloud/detect_aws_console_login_by_user_from_new_region/) | [Unused/Unsupported Cloud Regions](/tags/#unused/unsupported-cloud-regions) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect Activity Related to Pass the Hash Attacks](/endpoint/detect_activity_related_to_pass_the_hash_attacks/) | [Use Alternate Authentication Material](/tags/#use-alternate-authentication-material), [Pass the Hash](/tags/#pass-the-hash) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect AzureHound Command-Line Arguments](/endpoint/detect_azurehound_command-line_arguments/) | [Domain Account](/tags/#domain-account), [Local Groups](/tags/#local-groups), [Domain Trust Discovery](/tags/#domain-trust-discovery), [Local Account](/tags/#local-account), [Account Discovery](/tags/#account-discovery), [Domain Groups](/tags/#domain-groups), [Permission Groups Discovery](/tags/#permission-groups-discovery) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect AzureHound File Modifications](/endpoint/detect_azurehound_file_modifications/) | [Domain Account](/tags/#domain-account), [Local Groups](/tags/#local-groups), [Domain Trust Discovery](/tags/#domain-trust-discovery), [Local Account](/tags/#local-account), [Account Discovery](/tags/#account-discovery), [Domain Groups](/tags/#domain-groups), [Permission Groups Discovery](/tags/#permission-groups-discovery) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect Baron Samedit CVE-2021-3156](/endpoint/detect_baron_samedit_cve-2021-3156/) | [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect Baron Samedit CVE-2021-3156 Segfault](/endpoint/detect_baron_samedit_cve-2021-3156_segfault/) | [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect Baron Samedit CVE-2021-3156 via OSQuery](/endpoint/detect_baron_samedit_cve-2021-3156_via_osquery/) | [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect Computer Changed with Anonymous Account](/endpoint/detect_computer_changed_with_anonymous_account/) | [Exploitation of Remote Services](/tags/#exploitation-of-remote-services) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect Copy of ShadowCopy with Script Block Logging](/endpoint/detect_copy_of_shadowcopy_with_script_block_logging/) | [Security Account Manager](/tags/#security-account-manager), [OS Credential Dumping](/tags/#os-credential-dumping) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect Credential Dumping through LSASS access](/endpoint/detect_credential_dumping_through_lsass_access/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect DNS requests to Phishing Sites leveraging EvilGinx2](/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2/) | [Spearphishing via Service](/tags/#spearphishing-via-service) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect Empire with PowerShell Script Block Logging](/endpoint/detect_empire_with_powershell_script_block_logging/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect Excessive Account Lockouts From Endpoint](/endpoint/detect_excessive_account_lockouts_from_endpoint/) | [Valid Accounts](/tags/#valid-accounts), [Domain Accounts](/tags/#domain-accounts) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect Excessive User Account Lockouts](/endpoint/detect_excessive_user_account_lockouts/) | [Valid Accounts](/tags/#valid-accounts), [Local Accounts](/tags/#local-accounts) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect Exchange Web Shell](/endpoint/detect_exchange_web_shell/) | [Server Software Component](/tags/#server-software-component), [Web Shell](/tags/#web-shell), [Exploit Public-Facing Application](/tags/#exploit-public-facing-application) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect F5 TMUI RCE CVE-2020-5902](/web/detect_f5_tmui_rce_cve-2020-5902/) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect GCP Storage access from a new IP](/cloud/detect_gcp_storage_access_from_a_new_ip/) | [Data from Cloud Storage Object](/tags/#data-from-cloud-storage-object) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect HTML Help Renamed](/endpoint/detect_html_help_renamed/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Compiled HTML File](/tags/#compiled-html-file) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect HTML Help Spawn Child Process](/endpoint/detect_html_help_spawn_child_process/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Compiled HTML File](/tags/#compiled-html-file) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect HTML Help URL in Command Line](/endpoint/detect_html_help_url_in_command_line/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Compiled HTML File](/tags/#compiled-html-file) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect HTML Help Using InfoTech Storage Handlers](/endpoint/detect_html_help_using_infotech_storage_handlers/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Compiled HTML File](/tags/#compiled-html-file) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect IPv6 Network Infrastructure Threats](/network/detect_ipv6_network_infrastructure_threats/) | [Hardware Additions](/tags/#hardware-additions), [Network Denial of Service](/tags/#network-denial-of-service), [Adversary-in-the-Middle](/tags/#adversary-in-the-middle), [ARP Cache Poisoning](/tags/#arp-cache-poisoning) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect Large Outbound ICMP Packets](/network/detect_large_outbound_icmp_packets/) | [Non-Application Layer Protocol](/tags/#non-application-layer-protocol) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect Long DNS TXT Record Response](/deprecated/detect_long_dns_txt_record_response/) | [Exfiltration Over Unencrypted Non-C2 Protocol](/tags/#exfiltration-over-unencrypted-non-c2-protocol) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect MSHTA Url in Command Line](/endpoint/detect_mshta_url_in_command_line/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Mshta](/tags/#mshta) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect Mimikatz Using Loaded Images](/endpoint/detect_mimikatz_using_loaded_images/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect Mimikatz Via PowerShell And EventCode 4703](/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703/) | [LSASS Memory](/tags/#lsass-memory) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect Mimikatz With PowerShell Script Block Logging](/endpoint/detect_mimikatz_with_powershell_script_block_logging/) | [OS Credential Dumping](/tags/#os-credential-dumping), [PowerShell](/tags/#powershell) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect New Local Admin account](/endpoint/detect_new_local_admin_account/) | [Local Account](/tags/#local-account), [Create Account](/tags/#create-account) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect New Login Attempts to Routers](/application/detect_new_login_attempts_to_routers/) | None | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect New Open GCP Storage Buckets](/cloud/detect_new_open_gcp_storage_buckets/) | [Data from Cloud Storage Object](/tags/#data-from-cloud-storage-object) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect New Open S3 Buckets over AWS CLI](/cloud/detect_new_open_s3_buckets_over_aws_cli/) | [Data from Cloud Storage Object](/tags/#data-from-cloud-storage-object) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect New Open S3 buckets](/cloud/detect_new_open_s3_buckets/) | [Data from Cloud Storage Object](/tags/#data-from-cloud-storage-object) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect Outbound LDAP Traffic](/network/detect_outbound_ldap_traffic/) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect Outbound SMB Traffic](/network/detect_outbound_smb_traffic/) | [File Transfer Protocols](/tags/#file-transfer-protocols), [Application Layer Protocol](/tags/#application-layer-protocol) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect Outlook exe writing a zip file](/endpoint/detect_outlook_exe_writing_a_zip_file/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect Path Interception By Creation Of program exe](/endpoint/detect_path_interception_by_creation_of_program_exe/) | [Path Interception by Unquoted Path](/tags/#path-interception-by-unquoted-path), [Hijack Execution Flow](/tags/#hijack-execution-flow) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect Port Security Violation](/network/detect_port_security_violation/) | [Hardware Additions](/tags/#hardware-additions), [Network Denial of Service](/tags/#network-denial-of-service), [Adversary-in-the-Middle](/tags/#adversary-in-the-middle), [ARP Cache Poisoning](/tags/#arp-cache-poisoning) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect Prohibited Applications Spawning cmd exe](/endpoint/detect_prohibited_applications_spawning_cmd_exe/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Windows Command Shell](/tags/#windows-command-shell) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect PsExec With accepteula Flag](/endpoint/detect_psexec_with_accepteula_flag/) | [Remote Services](/tags/#remote-services), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect RClone Command-Line Usage](/endpoint/detect_rclone_command-line_usage/) | [Automated Exfiltration](/tags/#automated-exfiltration) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect Rare Executables](/endpoint/detect_rare_executables/) | None | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect Regasm Spawning a Process](/endpoint/detect_regasm_spawning_a_process/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Regsvcs/Regasm](/tags/#regsvcs/regasm) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect Regasm with Network Connection](/endpoint/detect_regasm_with_network_connection/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Regsvcs/Regasm](/tags/#regsvcs/regasm) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect Regasm with no Command Line Arguments](/endpoint/detect_regasm_with_no_command_line_arguments/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Regsvcs/Regasm](/tags/#regsvcs/regasm) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect Regsvcs Spawning a Process](/endpoint/detect_regsvcs_spawning_a_process/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Regsvcs/Regasm](/tags/#regsvcs/regasm) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect Regsvcs with Network Connection](/endpoint/detect_regsvcs_with_network_connection/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Regsvcs/Regasm](/tags/#regsvcs/regasm) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect Regsvcs with No Command Line Arguments](/endpoint/detect_regsvcs_with_no_command_line_arguments/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Regsvcs/Regasm](/tags/#regsvcs/regasm) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect Regsvr32 Application Control Bypass](/endpoint/detect_regsvr32_application_control_bypass/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Regsvr32](/tags/#regsvr32) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect Renamed 7-Zip](/endpoint/detect_renamed_7-zip/) | [Archive via Utility](/tags/#archive-via-utility), [Archive Collected Data](/tags/#archive-collected-data) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect Renamed PSExec](/endpoint/detect_renamed_psexec/) | [System Services](/tags/#system-services), [Service Execution](/tags/#service-execution) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect Renamed RClone](/endpoint/detect_renamed_rclone/) | [Automated Exfiltration](/tags/#automated-exfiltration) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect Renamed WinRAR](/endpoint/detect_renamed_winrar/) | [Archive via Utility](/tags/#archive-via-utility), [Archive Collected Data](/tags/#archive-collected-data) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect Risky SPL using Pretrained ML Model](/application/detect_risky_spl_using_pretrained_ml_model/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect Rogue DHCP Server](/network/detect_rogue_dhcp_server/) | [Hardware Additions](/tags/#hardware-additions), [Network Denial of Service](/tags/#network-denial-of-service), [Adversary-in-the-Middle](/tags/#adversary-in-the-middle) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect Rundll32 Application Control Bypass - advpack](/endpoint/detect_rundll32_application_control_bypass_-_advpack/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Rundll32](/tags/#rundll32) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect Rundll32 Application Control Bypass - setupapi](/endpoint/detect_rundll32_application_control_bypass_-_setupapi/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Rundll32](/tags/#rundll32) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect Rundll32 Application Control Bypass - syssetup](/endpoint/detect_rundll32_application_control_bypass_-_syssetup/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Rundll32](/tags/#rundll32) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect Rundll32 Inline HTA Execution](/endpoint/detect_rundll32_inline_hta_execution/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Mshta](/tags/#mshta) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect S3 access from a new IP](/cloud/detect_s3_access_from_a_new_ip/) | [Data from Cloud Storage Object](/tags/#data-from-cloud-storage-object) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect SNICat SNI Exfiltration](/network/detect_snicat_sni_exfiltration/) | [Exfiltration Over C2 Channel](/tags/#exfiltration-over-c2-channel) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect SharpHound Command-Line Arguments](/endpoint/detect_sharphound_command-line_arguments/) | [Domain Account](/tags/#domain-account), [Local Groups](/tags/#local-groups), [Domain Trust Discovery](/tags/#domain-trust-discovery), [Local Account](/tags/#local-account), [Account Discovery](/tags/#account-discovery), [Domain Groups](/tags/#domain-groups), [Permission Groups Discovery](/tags/#permission-groups-discovery) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect SharpHound File Modifications](/endpoint/detect_sharphound_file_modifications/) | [Domain Account](/tags/#domain-account), [Local Groups](/tags/#local-groups), [Domain Trust Discovery](/tags/#domain-trust-discovery), [Local Account](/tags/#local-account), [Account Discovery](/tags/#account-discovery), [Domain Groups](/tags/#domain-groups), [Permission Groups Discovery](/tags/#permission-groups-discovery) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect SharpHound Usage](/endpoint/detect_sharphound_usage/) | [Domain Account](/tags/#domain-account), [Local Groups](/tags/#local-groups), [Domain Trust Discovery](/tags/#domain-trust-discovery), [Local Account](/tags/#local-account), [Account Discovery](/tags/#account-discovery), [Domain Groups](/tags/#domain-groups), [Permission Groups Discovery](/tags/#permission-groups-discovery) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect Software Download To Network Device](/network/detect_software_download_to_network_device/) | [TFTP Boot](/tags/#tftp-boot), [Pre-OS Boot](/tags/#pre-os-boot) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect Spike in AWS API Activity](/deprecated/detect_spike_in_aws_api_activity/) | [Cloud Accounts](/tags/#cloud-accounts) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect Spike in AWS Security Hub Alerts for EC2 Instance](/cloud/detect_spike_in_aws_security_hub_alerts_for_ec2_instance/) | None | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect Spike in AWS Security Hub Alerts for User](/cloud/detect_spike_in_aws_security_hub_alerts_for_user/) | None | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect Spike in Network ACL Activity](/deprecated/detect_spike_in_network_acl_activity/) | [Disable or Modify Cloud Firewall](/tags/#disable-or-modify-cloud-firewall) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect Spike in S3 Bucket deletion](/cloud/detect_spike_in_s3_bucket_deletion/) | [Data from Cloud Storage Object](/tags/#data-from-cloud-storage-object) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect Spike in Security Group Activity](/deprecated/detect_spike_in_security_group_activity/) | [Cloud Accounts](/tags/#cloud-accounts) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect Spike in blocked Outbound Traffic from your AWS](/cloud/detect_spike_in_blocked_outbound_traffic_from_your_aws/) | None | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect Traffic Mirroring](/network/detect_traffic_mirroring/) | [Hardware Additions](/tags/#hardware-additions), [Automated Exfiltration](/tags/#automated-exfiltration), [Network Denial of Service](/tags/#network-denial-of-service), [Traffic Duplication](/tags/#traffic-duplication) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect USB device insertion](/deprecated/detect_usb_device_insertion/) | None | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect Unauthorized Assets by MAC address](/network/detect_unauthorized_assets_by_mac_address/) | None | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect Use of cmd exe to Launch Script Interpreters](/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Windows Command Shell](/tags/#windows-command-shell) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect WMI Event Subscription Persistence](/endpoint/detect_wmi_event_subscription_persistence/) | [Windows Management Instrumentation Event Subscription](/tags/#windows-management-instrumentation-event-subscription), [Event Triggered Execution](/tags/#event-triggered-execution) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect Windows DNS SIGRed via Splunk Stream](/network/detect_windows_dns_sigred_via_splunk_stream/) | [Exploitation for Client Execution](/tags/#exploitation-for-client-execution) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect Windows DNS SIGRed via Zeek](/network/detect_windows_dns_sigred_via_zeek/) | [Exploitation for Client Execution](/tags/#exploitation-for-client-execution) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect Zerologon via Zeek](/network/detect_zerologon_via_zeek/) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect attackers scanning for vulnerable JBoss servers](/web/detect_attackers_scanning_for_vulnerable_jboss_servers/) | [System Information Discovery](/tags/#system-information-discovery) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect hosts connecting to dynamic domain providers](/network/detect_hosts_connecting_to_dynamic_domain_providers/) | [Drive-by Compromise](/tags/#drive-by-compromise) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect malicious requests to exploit JBoss servers](/web/detect_malicious_requests_to_exploit_jboss_servers/) | None | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect mshta inline hta execution](/endpoint/detect_mshta_inline_hta_execution/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Mshta](/tags/#mshta) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect mshta renamed](/endpoint/detect_mshta_renamed/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Mshta](/tags/#mshta) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect new API calls from user roles](/deprecated/detect_new_api_calls_from_user_roles/) | [Cloud Accounts](/tags/#cloud-accounts) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect new user AWS Console Login](/deprecated/detect_new_user_aws_console_login/) | [Cloud Accounts](/tags/#cloud-accounts) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect processes used for System Network Configuration Discovery](/endpoint/detect_processes_used_for_system_network_configuration_discovery/) | [System Network Configuration Discovery](/tags/#system-network-configuration-discovery) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect shared ec2 snapshot](/cloud/detect_shared_ec2_snapshot/) | [Transfer Data to Cloud Account](/tags/#transfer-data-to-cloud-account) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detect web traffic to dynamic domain providers](/deprecated/detect_web_traffic_to_dynamic_domain_providers/) | [Web Protocols](/tags/#web-protocols) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detection of DNS Tunnels](/deprecated/detection_of_dns_tunnels/) | [Exfiltration Over Unencrypted Non-C2 Protocol](/tags/#exfiltration-over-unencrypted-non-c2-protocol) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Detection of tools built by NirSoft](/endpoint/detection_of_tools_built_by_nirsoft/) | [Software Deployment Tools](/tags/#software-deployment-tools) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Disable AMSI Through Registry](/endpoint/disable_amsi_through_registry/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Disable Defender AntiVirus Registry](/endpoint/disable_defender_antivirus_registry/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Disable Defender BlockAtFirstSeen Feature](/endpoint/disable_defender_blockatfirstseen_feature/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Disable Defender Enhanced Notification](/endpoint/disable_defender_enhanced_notification/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Disable Defender MpEngine Registry](/endpoint/disable_defender_mpengine_registry/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Disable Defender Spynet Reporting](/endpoint/disable_defender_spynet_reporting/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Disable Defender Submit Samples Consent Feature](/endpoint/disable_defender_submit_samples_consent_feature/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Disable ETW Through Registry](/endpoint/disable_etw_through_registry/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Disable Logs Using WevtUtil](/endpoint/disable_logs_using_wevtutil/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host), [Clear Windows Event Logs](/tags/#clear-windows-event-logs) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Disable Registry Tool](/endpoint/disable_registry_tool/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Disable Schedule Task](/endpoint/disable_schedule_task/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Disable Security Logs Using MiniNt Registry](/endpoint/disable_security_logs_using_minint_registry/) | [Modify Registry](/tags/#modify-registry) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Disable Show Hidden Files](/endpoint/disable_show_hidden_files/) | [Hidden Files and Directories](/tags/#hidden-files-and-directories), [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Hide Artifacts](/tags/#hide-artifacts), [Impair Defenses](/tags/#impair-defenses) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Disable UAC Remote Restriction](/endpoint/disable_uac_remote_restriction/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Disable Windows App Hotkeys](/endpoint/disable_windows_app_hotkeys/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Disable Windows Behavior Monitoring](/endpoint/disable_windows_behavior_monitoring/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Disable Windows SmartScreen Protection](/endpoint/disable_windows_smartscreen_protection/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Disabled Kerberos Pre-Authentication Discovery With Get-ADUser](/endpoint/disabled_kerberos_pre-authentication_discovery_with_get-aduser/) | [Steal or Forge Kerberos Tickets](/tags/#steal-or-forge-kerberos-tickets), [AS-REP Roasting](/tags/#as-rep-roasting) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Disabled Kerberos Pre-Authentication Discovery With PowerView](/endpoint/disabled_kerberos_pre-authentication_discovery_with_powerview/) | [Steal or Forge Kerberos Tickets](/tags/#steal-or-forge-kerberos-tickets), [AS-REP Roasting](/tags/#as-rep-roasting) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Disabling CMD Application](/endpoint/disabling_cmd_application/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Disabling ControlPanel](/endpoint/disabling_controlpanel/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Disabling Defender Services](/endpoint/disabling_defender_services/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Disabling Firewall with Netsh](/endpoint/disabling_firewall_with_netsh/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Disabling FolderOptions Windows Feature](/endpoint/disabling_folderoptions_windows_feature/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Disabling Net User Account](/endpoint/disabling_net_user_account/) | [Account Access Removal](/tags/#account-access-removal) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Disabling NoRun Windows App](/endpoint/disabling_norun_windows_app/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Disabling Remote User Account Control](/endpoint/disabling_remote_user_account_control/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Disabling SystemRestore In Registry](/endpoint/disabling_systemrestore_in_registry/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Disabling Task Manager](/endpoint/disabling_task_manager/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Domain Account Discovery With Net App](/endpoint/domain_account_discovery_with_net_app/) | [Domain Account](/tags/#domain-account), [Account Discovery](/tags/#account-discovery) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Domain Account Discovery with Dsquery](/endpoint/domain_account_discovery_with_dsquery/) | [Domain Account](/tags/#domain-account), [Account Discovery](/tags/#account-discovery) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Domain Account Discovery with Wmic](/endpoint/domain_account_discovery_with_wmic/) | [Domain Account](/tags/#domain-account), [Account Discovery](/tags/#account-discovery) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Domain Controller Discovery with Nltest](/endpoint/domain_controller_discovery_with_nltest/) | [Remote System Discovery](/tags/#remote-system-discovery) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Domain Controller Discovery with Wmic](/endpoint/domain_controller_discovery_with_wmic/) | [Remote System Discovery](/tags/#remote-system-discovery) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Domain Group Discovery With Dsquery](/endpoint/domain_group_discovery_with_dsquery/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Domain Groups](/tags/#domain-groups) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Domain Group Discovery With Net](/endpoint/domain_group_discovery_with_net/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Domain Groups](/tags/#domain-groups) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Domain Group Discovery With Wmic](/endpoint/domain_group_discovery_with_wmic/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Domain Groups](/tags/#domain-groups) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Domain Group Discovery with Adsisearcher](/endpoint/domain_group_discovery_with_adsisearcher/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Domain Groups](/tags/#domain-groups) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Download Files Using Telegram](/endpoint/download_files_using_telegram/) | [Ingress Tool Transfer](/tags/#ingress-tool-transfer) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Drop IcedID License dat](/endpoint/drop_icedid_license_dat/) | [User Execution](/tags/#user-execution), [Malicious File](/tags/#malicious-file) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Dump LSASS via comsvcs DLL](/endpoint/dump_lsass_via_comsvcs_dll/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Dump LSASS via procdump](/endpoint/dump_lsass_via_procdump/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Dump LSASS via procdump Rename](/deprecated/dump_lsass_via_procdump_rename/) | [LSASS Memory](/tags/#lsass-memory) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [EC2 Instance Modified With Previously Unseen User](/deprecated/ec2_instance_modified_with_previously_unseen_user/) | [Cloud Accounts](/tags/#cloud-accounts) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [EC2 Instance Started In Previously Unseen Region](/deprecated/ec2_instance_started_in_previously_unseen_region/) | [Unused/Unsupported Cloud Regions](/tags/#unused/unsupported-cloud-regions) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [EC2 Instance Started With Previously Unseen AMI](/deprecated/ec2_instance_started_with_previously_unseen_ami/) | None | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [EC2 Instance Started With Previously Unseen Instance Type](/deprecated/ec2_instance_started_with_previously_unseen_instance_type/) | None | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [EC2 Instance Started With Previously Unseen User](/deprecated/ec2_instance_started_with_previously_unseen_user/) | [Cloud Accounts](/tags/#cloud-accounts) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [ETW Registry Disabled](/endpoint/etw_registry_disabled/) | [Indicator Blocking](/tags/#indicator-blocking), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Impair Defenses](/tags/#impair-defenses) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Elevated Group Discovery With Net](/endpoint/elevated_group_discovery_with_net/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Domain Groups](/tags/#domain-groups) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Elevated Group Discovery With Wmic](/endpoint/elevated_group_discovery_with_wmic/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Domain Groups](/tags/#domain-groups) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Elevated Group Discovery with PowerView](/endpoint/elevated_group_discovery_with_powerview/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Domain Groups](/tags/#domain-groups) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Email Attachments With Lots Of Spaces](/application/email_attachments_with_lots_of_spaces/) | None | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Email files written outside of the Outlook directory](/application/email_files_written_outside_of_the_outlook_directory/) | [Email Collection](/tags/#email-collection), [Local Email Collection](/tags/#local-email-collection) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Email servers sending high volume traffic to hosts](/application/email_servers_sending_high_volume_traffic_to_hosts/) | [Email Collection](/tags/#email-collection), [Remote Email Collection](/tags/#remote-email-collection) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Enable RDP In Other Port Number](/endpoint/enable_rdp_in_other_port_number/) | [Remote Services](/tags/#remote-services) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Enable WDigest UseLogonCredential Registry](/endpoint/enable_wdigest_uselogoncredential_registry/) | [Modify Registry](/tags/#modify-registry), [OS Credential Dumping](/tags/#os-credential-dumping) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Enumerate Users Local Group Using Telegram](/endpoint/enumerate_users_local_group_using_telegram/) | [Account Discovery](/tags/#account-discovery) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Esentutl SAM Copy](/endpoint/esentutl_sam_copy/) | [Security Account Manager](/tags/#security-account-manager), [OS Credential Dumping](/tags/#os-credential-dumping) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Eventvwr UAC Bypass](/endpoint/eventvwr_uac_bypass/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Excel Spawning PowerShell](/endpoint/excel_spawning_powershell/) | [Security Account Manager](/tags/#security-account-manager), [OS Credential Dumping](/tags/#os-credential-dumping) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Excel Spawning Windows Script Host](/endpoint/excel_spawning_windows_script_host/) | [Security Account Manager](/tags/#security-account-manager), [OS Credential Dumping](/tags/#os-credential-dumping) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Excessive Attempt To Disable Services](/endpoint/excessive_attempt_to_disable_services/) | [Service Stop](/tags/#service-stop) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Excessive DNS Failures](/network/excessive_dns_failures/) | [DNS](/tags/#dns), [Application Layer Protocol](/tags/#application-layer-protocol) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Excessive File Deletion In WinDefender Folder](/endpoint/excessive_file_deletion_in_windefender_folder/) | [Data Destruction](/tags/#data-destruction) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Excessive Service Stop Attempt](/endpoint/excessive_service_stop_attempt/) | [Service Stop](/tags/#service-stop) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Excessive Usage Of Cacls App](/endpoint/excessive_usage_of_cacls_app/) | [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Excessive Usage Of Net App](/endpoint/excessive_usage_of_net_app/) | [Account Access Removal](/tags/#account-access-removal) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Excessive Usage Of SC Service Utility](/endpoint/excessive_usage_of_sc_service_utility/) | [System Services](/tags/#system-services), [Service Execution](/tags/#service-execution) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Excessive Usage Of Taskkill](/endpoint/excessive_usage_of_taskkill/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Excessive Usage of NSLOOKUP App](/endpoint/excessive_usage_of_nslookup_app/) | [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Excessive distinct processes from Windows Temp](/endpoint/excessive_distinct_processes_from_windows_temp/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Excessive number of service control start as disabled](/endpoint/excessive_number_of_service_control_start_as_disabled/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Excessive number of taskhost processes](/endpoint/excessive_number_of_taskhost_processes/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Exchange PowerShell Abuse via SSRF](/endpoint/exchange_powershell_abuse_via_ssrf/) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Exchange PowerShell Module Usage](/endpoint/exchange_powershell_module_usage/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Executable File Written in Administrative SMB Share](/endpoint/executable_file_written_in_administrative_smb_share/) | [Remote Services](/tags/#remote-services), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Executables Or Script Creation In Suspicious Path](/endpoint/executables_or_script_creation_in_suspicious_path/) | [Masquerading](/tags/#masquerading) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Execute Javascript With Jscript COM CLSID](/endpoint/execute_javascript_with_jscript_com_clsid/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Visual Basic](/tags/#visual-basic) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Execution of File With Spaces Before Extension](/deprecated/execution_of_file_with_spaces_before_extension/) | [Rename System Utilities](/tags/#rename-system-utilities) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Execution of File with Multiple Extensions](/endpoint/execution_of_file_with_multiple_extensions/) | [Masquerading](/tags/#masquerading), [Rename System Utilities](/tags/#rename-system-utilities) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Extended Period Without Successful Netbackup Backups](/deprecated/extended_period_without_successful_netbackup_backups/) | None | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Extraction of Registry Hives](/endpoint/extraction_of_registry_hives/) | [Security Account Manager](/tags/#security-account-manager), [OS Credential Dumping](/tags/#os-credential-dumping) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [F5 BIG-IP iControl REST Vulnerability CVE-2022-1388](/network/f5_big-ip_icontrol_rest_vulnerability_cve-2022-1388/) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [File with Samsam Extension](/endpoint/file_with_samsam_extension/) | None | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Firewall Allowed Program Enable](/endpoint/firewall_allowed_program_enable/) | [Disable or Modify System Firewall](/tags/#disable-or-modify-system-firewall), [Impair Defenses](/tags/#impair-defenses) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [First Time Seen Child Process of Zoom](/endpoint/first_time_seen_child_process_of_zoom/) | [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [First Time Seen Running Windows Service](/endpoint/first_time_seen_running_windows_service/) | [System Services](/tags/#system-services), [Service Execution](/tags/#service-execution) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [First time seen command line argument](/deprecated/first_time_seen_command_line_argument/) | [PowerShell](/tags/#powershell), [Windows Command Shell](/tags/#windows-command-shell) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [FodHelper UAC Bypass](/endpoint/fodhelper_uac_bypass/) | [Modify Registry](/tags/#modify-registry), [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Fsutil Zeroing File](/endpoint/fsutil_zeroing_file/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [GCP Detect accounts with high risk roles by project](/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project/) | [Valid Accounts](/tags/#valid-accounts) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [GCP Detect gcploit framework](/cloud/gcp_detect_gcploit_framework/) | [Valid Accounts](/tags/#valid-accounts) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [GCP Detect high risk permissions by resource and account](/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account/) | [Valid Accounts](/tags/#valid-accounts) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [GCP Kubernetes cluster pod scan detection](/cloud/gcp_kubernetes_cluster_pod_scan_detection/) | [Cloud Service Discovery](/tags/#cloud-service-discovery) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [GCP Kubernetes cluster scan detection](/deprecated/gcp_kubernetes_cluster_scan_detection/) | [Cloud Service Discovery](/tags/#cloud-service-discovery) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [GPUpdate with no Command Line Arguments with Network](/endpoint/gpupdate_with_no_command_line_arguments_with_network/) | [Process Injection](/tags/#process-injection) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [GSuite Email Suspicious Attachment](/cloud/gsuite_email_suspicious_attachment/) | [Spearphishing Attachment](/tags/#spearphishing-attachment), [Phishing](/tags/#phishing) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Gdrive suspicious file sharing](/cloud/gdrive_suspicious_file_sharing/) | [Phishing](/tags/#phishing) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Get ADDefaultDomainPasswordPolicy with Powershell](/endpoint/get_addefaultdomainpasswordpolicy_with_powershell/) | [Password Policy Discovery](/tags/#password-policy-discovery) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Get ADDefaultDomainPasswordPolicy with Powershell Script Block](/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block/) | [Password Policy Discovery](/tags/#password-policy-discovery) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Get ADUser with PowerShell](/endpoint/get_aduser_with_powershell/) | [Domain Account](/tags/#domain-account), [Account Discovery](/tags/#account-discovery) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Get ADUser with PowerShell Script Block](/endpoint/get_aduser_with_powershell_script_block/) | [Domain Account](/tags/#domain-account), [Account Discovery](/tags/#account-discovery) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Get ADUserResultantPasswordPolicy with Powershell](/endpoint/get_aduserresultantpasswordpolicy_with_powershell/) | [Password Policy Discovery](/tags/#password-policy-discovery) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Get ADUserResultantPasswordPolicy with Powershell Script Block](/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block/) | [Password Policy Discovery](/tags/#password-policy-discovery) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Get DomainPolicy with Powershell](/endpoint/get_domainpolicy_with_powershell/) | [Password Policy Discovery](/tags/#password-policy-discovery) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Get DomainPolicy with Powershell Script Block](/endpoint/get_domainpolicy_with_powershell_script_block/) | [Password Policy Discovery](/tags/#password-policy-discovery) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Get DomainUser with PowerShell](/endpoint/get_domainuser_with_powershell/) | [Domain Account](/tags/#domain-account), [Account Discovery](/tags/#account-discovery) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Get DomainUser with PowerShell Script Block](/endpoint/get_domainuser_with_powershell_script_block/) | [Domain Account](/tags/#domain-account), [Account Discovery](/tags/#account-discovery) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Get WMIObject Group Discovery](/endpoint/get_wmiobject_group_discovery/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Local Groups](/tags/#local-groups) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Get WMIObject Group Discovery with Script Block Logging](/endpoint/get_wmiobject_group_discovery_with_script_block_logging/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Local Groups](/tags/#local-groups) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Get-DomainTrust with PowerShell](/endpoint/get-domaintrust_with_powershell/) | [Domain Trust Discovery](/tags/#domain-trust-discovery) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Get-DomainTrust with PowerShell Script Block](/endpoint/get-domaintrust_with_powershell_script_block/) | [Domain Trust Discovery](/tags/#domain-trust-discovery) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Get-ForestTrust with PowerShell](/endpoint/get-foresttrust_with_powershell/) | [Domain Trust Discovery](/tags/#domain-trust-discovery) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Get-ForestTrust with PowerShell Script Block](/endpoint/get-foresttrust_with_powershell_script_block/) | [Domain Trust Discovery](/tags/#domain-trust-discovery), [PowerShell](/tags/#powershell) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [GetAdComputer with PowerShell](/endpoint/getadcomputer_with_powershell/) | [Remote System Discovery](/tags/#remote-system-discovery) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [GetAdComputer with PowerShell Script Block](/endpoint/getadcomputer_with_powershell_script_block/) | [Remote System Discovery](/tags/#remote-system-discovery) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [GetAdGroup with PowerShell](/endpoint/getadgroup_with_powershell/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Domain Groups](/tags/#domain-groups) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [GetAdGroup with PowerShell Script Block](/endpoint/getadgroup_with_powershell_script_block/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Domain Groups](/tags/#domain-groups) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [GetCurrent User with PowerShell](/endpoint/getcurrent_user_with_powershell/) | [System Owner/User Discovery](/tags/#system-owner/user-discovery) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [GetCurrent User with PowerShell Script Block](/endpoint/getcurrent_user_with_powershell_script_block/) | [System Owner/User Discovery](/tags/#system-owner/user-discovery) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [GetDomainComputer with PowerShell](/endpoint/getdomaincomputer_with_powershell/) | [Remote System Discovery](/tags/#remote-system-discovery) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [GetDomainComputer with PowerShell Script Block](/endpoint/getdomaincomputer_with_powershell_script_block/) | [Remote System Discovery](/tags/#remote-system-discovery) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [GetDomainController with PowerShell](/endpoint/getdomaincontroller_with_powershell/) | [Remote System Discovery](/tags/#remote-system-discovery) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [GetDomainController with PowerShell Script Block](/endpoint/getdomaincontroller_with_powershell_script_block/) | [Remote System Discovery](/tags/#remote-system-discovery) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [GetDomainGroup with PowerShell](/endpoint/getdomaingroup_with_powershell/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Domain Groups](/tags/#domain-groups) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [GetDomainGroup with PowerShell Script Block](/endpoint/getdomaingroup_with_powershell_script_block/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Domain Groups](/tags/#domain-groups) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [GetLocalUser with PowerShell](/endpoint/getlocaluser_with_powershell/) | [Account Discovery](/tags/#account-discovery), [Local Account](/tags/#local-account) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [GetLocalUser with PowerShell Script Block](/endpoint/getlocaluser_with_powershell_script_block/) | [Account Discovery](/tags/#account-discovery), [Local Account](/tags/#local-account), [PowerShell](/tags/#powershell) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [GetNetTcpconnection with PowerShell](/endpoint/getnettcpconnection_with_powershell/) | [System Network Connections Discovery](/tags/#system-network-connections-discovery) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [GetNetTcpconnection with PowerShell Script Block](/endpoint/getnettcpconnection_with_powershell_script_block/) | [System Network Connections Discovery](/tags/#system-network-connections-discovery) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [GetWmiObject DS User with PowerShell](/endpoint/getwmiobject_ds_user_with_powershell/) | [Domain Account](/tags/#domain-account), [Account Discovery](/tags/#account-discovery) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [GetWmiObject DS User with PowerShell Script Block](/endpoint/getwmiobject_ds_user_with_powershell_script_block/) | [Domain Account](/tags/#domain-account), [Account Discovery](/tags/#account-discovery) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [GetWmiObject Ds Computer with PowerShell](/endpoint/getwmiobject_ds_computer_with_powershell/) | [Remote System Discovery](/tags/#remote-system-discovery) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [GetWmiObject Ds Computer with PowerShell Script Block](/endpoint/getwmiobject_ds_computer_with_powershell_script_block/) | [Remote System Discovery](/tags/#remote-system-discovery) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [GetWmiObject Ds Group with PowerShell](/endpoint/getwmiobject_ds_group_with_powershell/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Domain Groups](/tags/#domain-groups) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [GetWmiObject Ds Group with PowerShell Script Block](/endpoint/getwmiobject_ds_group_with_powershell_script_block/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Domain Groups](/tags/#domain-groups) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [GetWmiObject User Account with PowerShell](/endpoint/getwmiobject_user_account_with_powershell/) | [Account Discovery](/tags/#account-discovery), [Local Account](/tags/#local-account) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [GetWmiObject User Account with PowerShell Script Block](/endpoint/getwmiobject_user_account_with_powershell_script_block/) | [Account Discovery](/tags/#account-discovery), [Local Account](/tags/#local-account), [PowerShell](/tags/#powershell) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [GitHub Actions Disable Security Workflow](/cloud/github_actions_disable_security_workflow/) | [Compromise Software Supply Chain](/tags/#compromise-software-supply-chain), [Supply Chain Compromise](/tags/#supply-chain-compromise) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [GitHub Dependabot Alert](/cloud/github_dependabot_alert/) | [Compromise Software Dependencies and Development Tools](/tags/#compromise-software-dependencies-and-development-tools), [Supply Chain Compromise](/tags/#supply-chain-compromise) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [GitHub Pull Request from Unknown User](/cloud/github_pull_request_from_unknown_user/) | [Compromise Software Dependencies and Development Tools](/tags/#compromise-software-dependencies-and-development-tools), [Supply Chain Compromise](/tags/#supply-chain-compromise) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Github Commit Changes In Master](/cloud/github_commit_changes_in_master/) | [Trusted Relationship](/tags/#trusted-relationship) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Github Commit In Develop](/cloud/github_commit_in_develop/) | [Trusted Relationship](/tags/#trusted-relationship) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Gsuite Drive Share In External Email](/cloud/gsuite_drive_share_in_external_email/) | [Exfiltration to Cloud Storage](/tags/#exfiltration-to-cloud-storage), [Exfiltration Over Web Service](/tags/#exfiltration-over-web-service) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Gsuite Email Suspicious Subject With Attachment](/cloud/gsuite_email_suspicious_subject_with_attachment/) | [Spearphishing Attachment](/tags/#spearphishing-attachment), [Phishing](/tags/#phishing) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Gsuite Email With Known Abuse Web Service Link](/cloud/gsuite_email_with_known_abuse_web_service_link/) | [Spearphishing Attachment](/tags/#spearphishing-attachment), [Phishing](/tags/#phishing) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Gsuite Outbound Email With Attachment To External Domain](/cloud/gsuite_outbound_email_with_attachment_to_external_domain/) | [Exfiltration Over Unencrypted Non-C2 Protocol](/tags/#exfiltration-over-unencrypted-non-c2-protocol), [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Gsuite Suspicious Shared File Name](/cloud/gsuite_suspicious_shared_file_name/) | [Spearphishing Attachment](/tags/#spearphishing-attachment), [Phishing](/tags/#phishing) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Gsuite suspicious calendar invite](/cloud/gsuite_suspicious_calendar_invite/) | [Phishing](/tags/#phishing) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Hide User Account From Sign-In Screen](/endpoint/hide_user_account_from_sign-in_screen/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Hiding Files And Directories With Attrib exe](/endpoint/hiding_files_and_directories_with_attrib_exe/) | [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification), [Windows File and Directory Permissions Modification](/tags/#windows-file-and-directory-permissions-modification) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [High Frequency Copy Of Files In Network Share](/endpoint/high_frequency_copy_of_files_in_network_share/) | [Transfer Data to Cloud Account](/tags/#transfer-data-to-cloud-account) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [High Number of Login Failures from a single source](/cloud/high_number_of_login_failures_from_a_single_source/) | [Password Guessing](/tags/#password-guessing), [Brute Force](/tags/#brute-force) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [High Process Termination Frequency](/endpoint/high_process_termination_frequency/) | [Data Encrypted for Impact](/tags/#data-encrypted-for-impact) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Hosts receiving high volume of network traffic from email server](/network/hosts_receiving_high_volume_of_network_traffic_from_email_server/) | [Remote Email Collection](/tags/#remote-email-collection), [Email Collection](/tags/#email-collection) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Hunting for Log4Shell](/endpoint/hunting_for_log4shell/) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [ICACLS Grant Command](/endpoint/icacls_grant_command/) | [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Icacls Deny Command](/endpoint/icacls_deny_command/) | [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [IcedID Exfiltrated Archived File Creation](/endpoint/icedid_exfiltrated_archived_file_creation/) | [Archive via Utility](/tags/#archive-via-utility), [Archive Collected Data](/tags/#archive-collected-data) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Identify New User Accounts](/deprecated/identify_new_user_accounts/) | [Domain Accounts](/tags/#domain-accounts) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Impacket Lateral Movement Commandline Parameters](/endpoint/impacket_lateral_movement_commandline_parameters/) | [Remote Services](/tags/#remote-services), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares), [Distributed Component Object Model](/tags/#distributed-component-object-model), [Windows Management Instrumentation](/tags/#windows-management-instrumentation), [Windows Service](/tags/#windows-service) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Interactive Session on Remote Endpoint with PowerShell](/endpoint/interactive_session_on_remote_endpoint_with_powershell/) | [Remote Services](/tags/#remote-services), [Windows Remote Management](/tags/#windows-remote-management) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Java Class File download by Java User Agent](/endpoint/java_class_file_download_by_java_user_agent/) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Java Writing JSP File](/endpoint/java_writing_jsp_file/) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Jscript Execution Using Cscript App](/endpoint/jscript_execution_using_cscript_app/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [JavaScript](/tags/#javascript) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Kerberoasting spn request with RC4 encryption](/endpoint/kerberoasting_spn_request_with_rc4_encryption/) | [Steal or Forge Kerberos Tickets](/tags/#steal-or-forge-kerberos-tickets), [Kerberoasting](/tags/#kerberoasting) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Kerberos Pre-Authentication Flag Disabled in UserAccountControl](/endpoint/kerberos_pre-authentication_flag_disabled_in_useraccountcontrol/) | [Steal or Forge Kerberos Tickets](/tags/#steal-or-forge-kerberos-tickets), [AS-REP Roasting](/tags/#as-rep-roasting) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Kerberos Pre-Authentication Flag Disabled with PowerShell](/endpoint/kerberos_pre-authentication_flag_disabled_with_powershell/) | [Steal or Forge Kerberos Tickets](/tags/#steal-or-forge-kerberos-tickets), [AS-REP Roasting](/tags/#as-rep-roasting) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Kerberos Service Ticket Request Using RC4 Encryption](/endpoint/kerberos_service_ticket_request_using_rc4_encryption/) | [Steal or Forge Kerberos Tickets](/tags/#steal-or-forge-kerberos-tickets), [Golden Ticket](/tags/#golden-ticket) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Kerberos TGT Request Using RC4 Encryption](/endpoint/kerberos_tgt_request_using_rc4_encryption/) | [Use Alternate Authentication Material](/tags/#use-alternate-authentication-material) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Kerberos User Enumeration](/endpoint/kerberos_user_enumeration/) | [Gather Victim Identity Information](/tags/#gather-victim-identity-information), [Email Addresses](/tags/#email-addresses) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Known Services Killed by Ransomware](/endpoint/known_services_killed_by_ransomware/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Kubernetes AWS detect RBAC authorization by account](/deprecated/kubernetes_aws_detect_rbac_authorization_by_account/) | None | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Kubernetes AWS detect most active service accounts by pod](/deprecated/kubernetes_aws_detect_most_active_service_accounts_by_pod/) | None | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Kubernetes AWS detect sensitive role access](/deprecated/kubernetes_aws_detect_sensitive_role_access/) | None | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Kubernetes AWS detect service accounts forbidden failure access](/deprecated/kubernetes_aws_detect_service_accounts_forbidden_failure_access/) | None | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Kubernetes AWS detect suspicious kubectl calls](/cloud/kubernetes_aws_detect_suspicious_kubectl_calls/) | None | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Kubernetes Azure active service accounts by pod namespace](/deprecated/kubernetes_azure_active_service_accounts_by_pod_namespace/) | None | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Kubernetes Azure detect RBAC authorization by account](/deprecated/kubernetes_azure_detect_rbac_authorization_by_account/) | None | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Kubernetes Azure detect sensitive object access](/deprecated/kubernetes_azure_detect_sensitive_object_access/) | None | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Kubernetes Azure detect sensitive role access](/deprecated/kubernetes_azure_detect_sensitive_role_access/) | None | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Kubernetes Azure detect service accounts forbidden failure access](/deprecated/kubernetes_azure_detect_service_accounts_forbidden_failure_access/) | None | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Kubernetes Azure detect suspicious kubectl calls](/deprecated/kubernetes_azure_detect_suspicious_kubectl_calls/) | None | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Kubernetes Azure pod scan fingerprint](/deprecated/kubernetes_azure_pod_scan_fingerprint/) | None | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Kubernetes Azure scan fingerprint](/deprecated/kubernetes_azure_scan_fingerprint/) | [Cloud Service Discovery](/tags/#cloud-service-discovery) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Kubernetes GCP detect RBAC authorizations by account](/deprecated/kubernetes_gcp_detect_rbac_authorizations_by_account/) | None | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Kubernetes GCP detect most active service accounts by pod](/deprecated/kubernetes_gcp_detect_most_active_service_accounts_by_pod/) | None | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Kubernetes GCP detect sensitive object access](/deprecated/kubernetes_gcp_detect_sensitive_object_access/) | None | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Kubernetes GCP detect sensitive role access](/deprecated/kubernetes_gcp_detect_sensitive_role_access/) | None | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Kubernetes GCP detect service accounts forbidden failure access](/deprecated/kubernetes_gcp_detect_service_accounts_forbidden_failure_access/) | None | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Kubernetes GCP detect suspicious kubectl calls](/deprecated/kubernetes_gcp_detect_suspicious_kubectl_calls/) | None | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Kubernetes Nginx Ingress LFI](/cloud/kubernetes_nginx_ingress_lfi/) | [Exploitation for Credential Access](/tags/#exploitation-for-credential-access) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Kubernetes Nginx Ingress RFI](/cloud/kubernetes_nginx_ingress_rfi/) | [Exploitation for Credential Access](/tags/#exploitation-for-credential-access) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Kubernetes Scanner Image Pulling](/cloud/kubernetes_scanner_image_pulling/) | [Cloud Service Discovery](/tags/#cloud-service-discovery) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Large Volume of DNS ANY Queries](/network/large_volume_of_dns_any_queries/) | [Network Denial of Service](/tags/#network-denial-of-service), [Reflection Amplification](/tags/#reflection-amplification) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Linux Account Manipulation Of SSH Config and Keys](/endpoint/linux_account_manipulation_of_ssh_config_and_keys/) | [Data Destruction](/tags/#data-destruction), [File Deletion](/tags/#file-deletion), [Indicator Removal on Host](/tags/#indicator-removal-on-host) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Linux Add Files In Known Crontab Directories](/endpoint/linux_add_files_in_known_crontab_directories/) | [Cron](/tags/#cron), [Scheduled Task/Job](/tags/#scheduled-task/job) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Linux Add User Account](/endpoint/linux_add_user_account/) | [Local Account](/tags/#local-account), [Create Account](/tags/#create-account) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Linux Adding Crontab Using List Parameter](/endpoint/linux_adding_crontab_using_list_parameter/) | [Cron](/tags/#cron), [Scheduled Task/Job](/tags/#scheduled-task/job) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Linux At Allow Config File Creation](/endpoint/linux_at_allow_config_file_creation/) | [Cron](/tags/#cron), [Scheduled Task/Job](/tags/#scheduled-task/job) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Linux At Application Execution](/endpoint/linux_at_application_execution/) | [At](/tags/#at), [Scheduled Task/Job](/tags/#scheduled-task/job) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Linux Change File Owner To Root](/endpoint/linux_change_file_owner_to_root/) | [Linux and Mac File and Directory Permissions Modification](/tags/#linux-and-mac-file-and-directory-permissions-modification), [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Linux Clipboard Data Copy](/endpoint/linux_clipboard_data_copy/) | [Clipboard Data](/tags/#clipboard-data) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Linux Common Process For Elevation Control](/endpoint/linux_common_process_for_elevation_control/) | [Setuid and Setgid](/tags/#setuid-and-setgid), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Linux DD File Overwrite](/endpoint/linux_dd_file_overwrite/) | [Data Destruction](/tags/#data-destruction) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Linux Decode Base64 to Shell](/endpoint/linux_decode_base64_to_shell/) | [Obfuscated Files or Information](/tags/#obfuscated-files-or-information), [Unix Shell](/tags/#unix-shell) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Linux Deleting Critical Directory Using RM Command](/endpoint/linux_deleting_critical_directory_using_rm_command/) | [Data Destruction](/tags/#data-destruction) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Linux Deletion Of Cron Jobs](/endpoint/linux_deletion_of_cron_jobs/) | [Data Destruction](/tags/#data-destruction), [File Deletion](/tags/#file-deletion), [Indicator Removal on Host](/tags/#indicator-removal-on-host) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Linux Deletion Of Init Daemon Script](/endpoint/linux_deletion_of_init_daemon_script/) | [Data Destruction](/tags/#data-destruction), [File Deletion](/tags/#file-deletion), [Indicator Removal on Host](/tags/#indicator-removal-on-host) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Linux Deletion Of Services](/endpoint/linux_deletion_of_services/) | [Data Destruction](/tags/#data-destruction), [File Deletion](/tags/#file-deletion), [Indicator Removal on Host](/tags/#indicator-removal-on-host) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Linux Deletion of SSL Certificate](/endpoint/linux_deletion_of_ssl_certificate/) | [Data Destruction](/tags/#data-destruction), [File Deletion](/tags/#file-deletion), [Indicator Removal on Host](/tags/#indicator-removal-on-host) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Linux Disable Services](/endpoint/linux_disable_services/) | [Service Stop](/tags/#service-stop) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Linux Doas Conf File Creation](/endpoint/linux_doas_conf_file_creation/) | [Sudo and Sudo Caching](/tags/#sudo-and-sudo-caching), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Linux Doas Tool Execution](/endpoint/linux_doas_tool_execution/) | [Sudo and Sudo Caching](/tags/#sudo-and-sudo-caching), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Linux Edit Cron Table Parameter](/endpoint/linux_edit_cron_table_parameter/) | [Cron](/tags/#cron), [Scheduled Task/Job](/tags/#scheduled-task/job) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Linux File Created In Kernel Driver Directory](/endpoint/linux_file_created_in_kernel_driver_directory/) | [Kernel Modules and Extensions](/tags/#kernel-modules-and-extensions), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Linux File Creation In Init Boot Directory](/endpoint/linux_file_creation_in_init_boot_directory/) | [RC Scripts](/tags/#rc-scripts), [Boot or Logon Initialization Scripts](/tags/#boot-or-logon-initialization-scripts) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Linux File Creation In Profile Directory](/endpoint/linux_file_creation_in_profile_directory/) | [Unix Shell Configuration Modification](/tags/#unix-shell-configuration-modification), [Event Triggered Execution](/tags/#event-triggered-execution) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Linux High Frequency Of File Deletion In Boot Folder](/endpoint/linux_high_frequency_of_file_deletion_in_boot_folder/) | [Data Destruction](/tags/#data-destruction), [File Deletion](/tags/#file-deletion), [Indicator Removal on Host](/tags/#indicator-removal-on-host) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Linux High Frequency Of File Deletion In Etc Folder](/endpoint/linux_high_frequency_of_file_deletion_in_etc_folder/) | [Data Destruction](/tags/#data-destruction), [File Deletion](/tags/#file-deletion), [Indicator Removal on Host](/tags/#indicator-removal-on-host) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Linux Insert Kernel Module Using Insmod Utility](/endpoint/linux_insert_kernel_module_using_insmod_utility/) | [Kernel Modules and Extensions](/tags/#kernel-modules-and-extensions), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Linux Install Kernel Module Using Modprobe Utility](/endpoint/linux_install_kernel_module_using_modprobe_utility/) | [Kernel Modules and Extensions](/tags/#kernel-modules-and-extensions), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Linux Iptables Firewall Modification](/endpoint/linux_iptables_firewall_modification/) | [Disable or Modify System Firewall](/tags/#disable-or-modify-system-firewall), [Impair Defenses](/tags/#impair-defenses) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Linux Java Spawning Shell](/endpoint/linux_java_spawning_shell/) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Linux Kernel Module Enumeration](/endpoint/linux_kernel_module_enumeration/) | [System Information Discovery](/tags/#system-information-discovery), [Rootkit](/tags/#rootkit) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Linux Kworker Process In Writable Process Path](/endpoint/linux_kworker_process_in_writable_process_path/) | [Masquerade Task or Service](/tags/#masquerade-task-or-service), [Masquerading](/tags/#masquerading) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Linux NOPASSWD Entry In Sudoers File](/endpoint/linux_nopasswd_entry_in_sudoers_file/) | [Sudo and Sudo Caching](/tags/#sudo-and-sudo-caching), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Linux Obfuscated Files or Information Base64 Decode](/endpoint/linux_obfuscated_files_or_information_base64_decode/) | [Obfuscated Files or Information](/tags/#obfuscated-files-or-information) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Linux Persistence and Privilege Escalation Risk Behavior](/endpoint/linux_persistence_and_privilege_escalation_risk_behavior/) | [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | [Correlation](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Linux Possible Access Or Modification Of sshd Config File](/endpoint/linux_possible_access_or_modification_of_sshd_config_file/) | [SSH Authorized Keys](/tags/#ssh-authorized-keys), [Account Manipulation](/tags/#account-manipulation) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Linux Possible Access To Credential Files](/endpoint/linux_possible_access_to_credential_files/) | [/etc/passwd and /etc/shadow](/tags/#/etc/passwd-and-/etc/shadow), [OS Credential Dumping](/tags/#os-credential-dumping) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Linux Possible Access To Sudoers File](/endpoint/linux_possible_access_to_sudoers_file/) | [Sudo and Sudo Caching](/tags/#sudo-and-sudo-caching), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Linux Possible Append Command To At Allow Config File](/endpoint/linux_possible_append_command_to_at_allow_config_file/) | [At](/tags/#at), [Scheduled Task/Job](/tags/#scheduled-task/job) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Linux Possible Append Command To Profile Config File](/endpoint/linux_possible_append_command_to_profile_config_file/) | [Unix Shell Configuration Modification](/tags/#unix-shell-configuration-modification), [Event Triggered Execution](/tags/#event-triggered-execution) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Linux Possible Append Cronjob Entry on Existing Cronjob File](/endpoint/linux_possible_append_cronjob_entry_on_existing_cronjob_file/) | [Cron](/tags/#cron), [Scheduled Task/Job](/tags/#scheduled-task/job) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Linux Possible Cronjob Modification With Editor](/endpoint/linux_possible_cronjob_modification_with_editor/) | [Cron](/tags/#cron), [Scheduled Task/Job](/tags/#scheduled-task/job) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Linux Possible Ssh Key File Creation](/endpoint/linux_possible_ssh_key_file_creation/) | [SSH Authorized Keys](/tags/#ssh-authorized-keys), [Account Manipulation](/tags/#account-manipulation) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Linux Preload Hijack Library Calls](/endpoint/linux_preload_hijack_library_calls/) | [Dynamic Linker Hijacking](/tags/#dynamic-linker-hijacking), [Hijack Execution Flow](/tags/#hijack-execution-flow) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Linux SSH Authorized Keys Modification](/endpoint/linux_ssh_authorized_keys_modification/) | [SSH Authorized Keys](/tags/#ssh-authorized-keys) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Linux SSH Remote Services Script Execute](/endpoint/linux_ssh_remote_services_script_execute/) | [SSH](/tags/#ssh) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Linux Service File Created In Systemd Directory](/endpoint/linux_service_file_created_in_systemd_directory/) | [Systemd Timers](/tags/#systemd-timers), [Scheduled Task/Job](/tags/#scheduled-task/job) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Linux Service Restarted](/endpoint/linux_service_restarted/) | [Systemd Timers](/tags/#systemd-timers), [Scheduled Task/Job](/tags/#scheduled-task/job) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Linux Service Started Or Enabled](/endpoint/linux_service_started_or_enabled/) | [Systemd Timers](/tags/#systemd-timers), [Scheduled Task/Job](/tags/#scheduled-task/job) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Linux Setuid Using Chmod Utility](/endpoint/linux_setuid_using_chmod_utility/) | [Setuid and Setgid](/tags/#setuid-and-setgid), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Linux Setuid Using Setcap Utility](/endpoint/linux_setuid_using_setcap_utility/) | [Setuid and Setgid](/tags/#setuid-and-setgid), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Linux Shred Overwrite Command](/endpoint/linux_shred_overwrite_command/) | [Data Destruction](/tags/#data-destruction) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Linux Stdout Redirection To Dev Null File](/endpoint/linux_stdout_redirection_to_dev_null_file/) | [Disable or Modify System Firewall](/tags/#disable-or-modify-system-firewall), [Impair Defenses](/tags/#impair-defenses) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Linux Stop Services](/endpoint/linux_stop_services/) | [Service Stop](/tags/#service-stop) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Linux Sudo OR Su Execution](/endpoint/linux_sudo_or_su_execution/) | [Sudo and Sudo Caching](/tags/#sudo-and-sudo-caching), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Linux Sudoers Tmp File Creation](/endpoint/linux_sudoers_tmp_file_creation/) | [Sudo and Sudo Caching](/tags/#sudo-and-sudo-caching), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Linux System Network Discovery](/endpoint/linux_system_network_discovery/) | [System Network Configuration Discovery](/tags/#system-network-configuration-discovery) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Linux Visudo Utility Execution](/endpoint/linux_visudo_utility_execution/) | [Sudo and Sudo Caching](/tags/#sudo-and-sudo-caching), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Linux pkexec Privilege Escalation](/endpoint/linux_pkexec_privilege_escalation/) | [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Living Off The Land](/endpoint/living_off_the_land/) | [Ingress Tool Transfer](/tags/#ingress-tool-transfer), [Exploit Public-Facing Application](/tags/#exploit-public-facing-application), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter) | [Correlation](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Loading Of Dynwrapx Module](/endpoint/loading_of_dynwrapx_module/) | [Process Injection](/tags/#process-injection), [Dynamic-link Library Injection](/tags/#dynamic-link-library-injection) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Local Account Discovery With Wmic](/endpoint/local_account_discovery_with_wmic/) | [Account Discovery](/tags/#account-discovery), [Local Account](/tags/#local-account) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Local Account Discovery with Net](/endpoint/local_account_discovery_with_net/) | [Account Discovery](/tags/#account-discovery), [Local Account](/tags/#local-account) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Log4Shell CVE-2021-44228 Exploitation](/endpoint/log4shell_cve-2021-44228_exploitation/) | [Ingress Tool Transfer](/tags/#ingress-tool-transfer), [Exploit Public-Facing Application](/tags/#exploit-public-facing-application), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter) | [Correlation](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Log4Shell JNDI Payload Injection Attempt](/web/log4shell_jndi_payload_injection_attempt/) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Log4Shell JNDI Payload Injection with Outbound Connection](/web/log4shell_jndi_payload_injection_with_outbound_connection/) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Logon Script Event Trigger Execution](/endpoint/logon_script_event_trigger_execution/) | [Boot or Logon Initialization Scripts](/tags/#boot-or-logon-initialization-scripts), [Logon Script (Windows)](/tags/#logon-script-(windows)) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [MS Exchange Mailbox Replication service writing Active Server Pages](/endpoint/ms_exchange_mailbox_replication_service_writing_active_server_pages/) | [Server Software Component](/tags/#server-software-component), [Web Shell](/tags/#web-shell), [Exploit Public-Facing Application](/tags/#exploit-public-facing-application) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [MS Scripting Process Loading Ldap Module](/endpoint/ms_scripting_process_loading_ldap_module/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [JavaScript](/tags/#javascript) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [MS Scripting Process Loading WMI Module](/endpoint/ms_scripting_process_loading_wmi_module/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [JavaScript](/tags/#javascript) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [MSBuild Suspicious Spawned By Script Process](/endpoint/msbuild_suspicious_spawned_by_script_process/) | [MSBuild](/tags/#msbuild), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [MSHTML Module Load in Office Product](/endpoint/mshtml_module_load_in_office_product/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [MSI Module Loaded by Non-System Binary](/endpoint/msi_module_loaded_by_non-system_binary/) | [DLL Side-Loading](/tags/#dll-side-loading), [Hijack Execution Flow](/tags/#hijack-execution-flow) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [MacOS - Re-opened Applications](/endpoint/macos_-_re-opened_applications/) | None | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [MacOS LOLbin](/endpoint/macos_lolbin/) | [Unix Shell](/tags/#unix-shell), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [MacOS plutil](/endpoint/macos_plutil/) | [Plist File Modification](/tags/#plist-file-modification) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Mailsniper Invoke functions](/endpoint/mailsniper_invoke_functions/) | [Email Collection](/tags/#email-collection), [Local Email Collection](/tags/#local-email-collection) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Malicious InProcServer32 Modification](/endpoint/malicious_inprocserver32_modification/) | [Regsvr32](/tags/#regsvr32), [Modify Registry](/tags/#modify-registry) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Malicious PowerShell Process - Encoded Command](/endpoint/malicious_powershell_process_-_encoded_command/) | [Obfuscated Files or Information](/tags/#obfuscated-files-or-information) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Malicious PowerShell Process - Execution Policy Bypass](/endpoint/malicious_powershell_process_-_execution_policy_bypass/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Malicious PowerShell Process With Obfuscation Techniques](/endpoint/malicious_powershell_process_with_obfuscation_techniques/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Malicious Powershell Executed As A Service](/endpoint/malicious_powershell_executed_as_a_service/) | [System Services](/tags/#system-services), [Service Execution](/tags/#service-execution) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Mimikatz PassTheTicket CommandLine Parameters](/endpoint/mimikatz_passtheticket_commandline_parameters/) | [Use Alternate Authentication Material](/tags/#use-alternate-authentication-material), [Pass the Ticket](/tags/#pass-the-ticket) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Mmc LOLBAS Execution Process Spawn](/endpoint/mmc_lolbas_execution_process_spawn/) | [Remote Services](/tags/#remote-services), [Distributed Component Object Model](/tags/#distributed-component-object-model), [MMC](/tags/#mmc) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Modification Of Wallpaper](/endpoint/modification_of_wallpaper/) | [Defacement](/tags/#defacement) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Modify ACL permission To Files Or Folder](/endpoint/modify_acl_permission_to_files_or_folder/) | [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Monitor DNS For Brand Abuse](/deprecated/monitor_dns_for_brand_abuse/) | None | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Monitor Email For Brand Abuse](/application/monitor_email_for_brand_abuse/) | None | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Monitor Registry Keys for Print Monitors](/endpoint/monitor_registry_keys_for_print_monitors/) | [Port Monitors](/tags/#port-monitors), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Monitor Web Traffic For Brand Abuse](/web/monitor_web_traffic_for_brand_abuse/) | None | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Mshta spawning Rundll32 OR Regsvr32 Process](/endpoint/mshta_spawning_rundll32_or_regsvr32_process/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Mshta](/tags/#mshta) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Msmpeng Application DLL Side Loading](/endpoint/msmpeng_application_dll_side_loading/) | [DLL Side-Loading](/tags/#dll-side-loading), [Hijack Execution Flow](/tags/#hijack-execution-flow) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Multiple Archive Files Http Post Traffic](/network/multiple_archive_files_http_post_traffic/) | [Exfiltration Over Unencrypted Non-C2 Protocol](/tags/#exfiltration-over-unencrypted-non-c2-protocol), [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Multiple Invalid Users Failing To Authenticate From Host Using NTLM](/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm/) | [Password Spraying](/tags/#password-spraying), [Brute Force](/tags/#brute-force) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Multiple Okta Users With Invalid Credentials From The Same IP](/application/multiple_okta_users_with_invalid_credentials_from_the_same_ip/) | [Valid Accounts](/tags/#valid-accounts), [Default Accounts](/tags/#default-accounts) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Multiple Users Failing To Authenticate From Host Using Kerberos](/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos/) | [Password Spraying](/tags/#password-spraying), [Brute Force](/tags/#brute-force) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Multiple Users Failing To Authenticate From Host Using NTLM](/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm/) | [Password Spraying](/tags/#password-spraying), [Brute Force](/tags/#brute-force) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Multiple Users Failing To Authenticate From Process](/endpoint/multiple_users_failing_to_authenticate_from_process/) | [Password Spraying](/tags/#password-spraying), [Brute Force](/tags/#brute-force) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Multiple Users Remotely Failing To Authenticate From Host](/endpoint/multiple_users_remotely_failing_to_authenticate_from_host/) | [Password Spraying](/tags/#password-spraying), [Brute Force](/tags/#brute-force) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [NET Profiler UAC bypass](/endpoint/net_profiler_uac_bypass/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [NLTest Domain Trust Discovery](/endpoint/nltest_domain_trust_discovery/) | [Domain Trust Discovery](/tags/#domain-trust-discovery) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Net Localgroup Discovery](/endpoint/net_localgroup_discovery/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Local Groups](/tags/#local-groups) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Network Connection Discovery With Arp](/endpoint/network_connection_discovery_with_arp/) | [System Network Connections Discovery](/tags/#system-network-connections-discovery) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Network Connection Discovery With Net](/endpoint/network_connection_discovery_with_net/) | [System Network Connections Discovery](/tags/#system-network-connections-discovery) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Network Connection Discovery With Netstat](/endpoint/network_connection_discovery_with_netstat/) | [System Network Connections Discovery](/tags/#system-network-connections-discovery) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Network Discovery Using Route Windows App](/endpoint/network_discovery_using_route_windows_app/) | [System Network Configuration Discovery](/tags/#system-network-configuration-discovery), [Internet Connection Discovery](/tags/#internet-connection-discovery) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Nishang PowershellTCPOneLine](/endpoint/nishang_powershelltcponeline/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [No Windows Updates in a time frame](/application/no_windows_updates_in_a_time_frame/) | None | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Non Chrome Process Accessing Chrome Default Dir](/endpoint/non_chrome_process_accessing_chrome_default_dir/) | [Credentials from Password Stores](/tags/#credentials-from-password-stores), [Credentials from Web Browsers](/tags/#credentials-from-web-browsers) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Non Firefox Process Access Firefox Profile Dir](/endpoint/non_firefox_process_access_firefox_profile_dir/) | [Credentials from Password Stores](/tags/#credentials-from-password-stores), [Credentials from Web Browsers](/tags/#credentials-from-web-browsers) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Ntdsutil Export NTDS](/endpoint/ntdsutil_export_ntds/) | [NTDS](/tags/#ntds), [OS Credential Dumping](/tags/#os-credential-dumping) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [O365 Add App Role Assignment Grant User](/cloud/o365_add_app_role_assignment_grant_user/) | [Cloud Account](/tags/#cloud-account), [Create Account](/tags/#create-account) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [O365 Added Service Principal](/cloud/o365_added_service_principal/) | [Cloud Account](/tags/#cloud-account), [Create Account](/tags/#create-account) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [O365 Bypass MFA via Trusted IP](/cloud/o365_bypass_mfa_via_trusted_ip/) | [Disable or Modify Cloud Firewall](/tags/#disable-or-modify-cloud-firewall), [Impair Defenses](/tags/#impair-defenses) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [O365 Disable MFA](/cloud/o365_disable_mfa/) | [Modify Authentication Process](/tags/#modify-authentication-process) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [O365 Excessive Authentication Failures Alert](/cloud/o365_excessive_authentication_failures_alert/) | [Brute Force](/tags/#brute-force) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [O365 Excessive SSO logon errors](/cloud/o365_excessive_sso_logon_errors/) | [Modify Authentication Process](/tags/#modify-authentication-process) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [O365 New Federated Domain Added](/cloud/o365_new_federated_domain_added/) | [Cloud Account](/tags/#cloud-account), [Create Account](/tags/#create-account) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [O365 PST export alert](/cloud/o365_pst_export_alert/) | [Email Collection](/tags/#email-collection) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [O365 Suspicious Admin Email Forwarding](/cloud/o365_suspicious_admin_email_forwarding/) | [Email Forwarding Rule](/tags/#email-forwarding-rule), [Email Collection](/tags/#email-collection) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [O365 Suspicious Rights Delegation](/cloud/o365_suspicious_rights_delegation/) | [Remote Email Collection](/tags/#remote-email-collection), [Email Collection](/tags/#email-collection) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [O365 Suspicious User Email Forwarding](/cloud/o365_suspicious_user_email_forwarding/) | [Email Forwarding Rule](/tags/#email-forwarding-rule), [Email Collection](/tags/#email-collection) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Office Application Drop Executable](/endpoint/office_application_drop_executable/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Office Application Spawn Regsvr32 process](/endpoint/office_application_spawn_regsvr32_process/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Office Application Spawn rundll32 process](/endpoint/office_application_spawn_rundll32_process/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Office Document Creating Schedule Task](/endpoint/office_document_creating_schedule_task/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Office Document Executing Macro Code](/endpoint/office_document_executing_macro_code/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Office Document Spawned Child Process To Download](/endpoint/office_document_spawned_child_process_to_download/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Office Product Spawn CMD Process](/endpoint/office_product_spawn_cmd_process/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Mshta](/tags/#mshta) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Office Product Spawning BITSAdmin](/endpoint/office_product_spawning_bitsadmin/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Office Product Spawning CertUtil](/endpoint/office_product_spawning_certutil/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Office Product Spawning MSHTA](/endpoint/office_product_spawning_mshta/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Office Product Spawning Rundll32 with no DLL](/endpoint/office_product_spawning_rundll32_with_no_dll/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Office Product Spawning Wmic](/endpoint/office_product_spawning_wmic/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Office Product Writing cab or inf](/endpoint/office_product_writing_cab_or_inf/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Office Spawning Control](/endpoint/office_spawning_control/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Okta Account Lockout Events](/application/okta_account_lockout_events/) | [Valid Accounts](/tags/#valid-accounts), [Default Accounts](/tags/#default-accounts) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Okta Failed SSO Attempts](/application/okta_failed_sso_attempts/) | [Valid Accounts](/tags/#valid-accounts), [Default Accounts](/tags/#default-accounts) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Okta User Logins From Multiple Cities](/application/okta_user_logins_from_multiple_cities/) | [Valid Accounts](/tags/#valid-accounts), [Default Accounts](/tags/#default-accounts) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Open Redirect in Splunk Web](/deprecated/open_redirect_in_splunk_web/) | None | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Osquery pack - ColdRoot detection](/deprecated/osquery_pack_-_coldroot_detection/) | None | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Outbound Network Connection from Java Using Default Ports](/endpoint/outbound_network_connection_from_java_using_default_ports/) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Overwriting Accessibility Binaries](/endpoint/overwriting_accessibility_binaries/) | [Event Triggered Execution](/tags/#event-triggered-execution), [Accessibility Features](/tags/#accessibility-features) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Password Policy Discovery with Net](/endpoint/password_policy_discovery_with_net/) | [Password Policy Discovery](/tags/#password-policy-discovery) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Path traversal SPL injection](/application/path_traversal_spl_injection/) | [File and Directory Discovery](/tags/#file-and-directory-discovery) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Permission Modification using Takeown App](/endpoint/permission_modification_using_takeown_app/) | [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [PetitPotam Network Share Access Request](/endpoint/petitpotam_network_share_access_request/) | [Forced Authentication](/tags/#forced-authentication) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [PetitPotam Suspicious Kerberos TGT Request](/endpoint/petitpotam_suspicious_kerberos_tgt_request/) | [OS Credential Dumping](/tags/#os-credential-dumping) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Ping Sleep Batch Command](/endpoint/ping_sleep_batch_command/) | [Virtualization/Sandbox Evasion](/tags/#virtualization/sandbox-evasion), [Time Based Evasion](/tags/#time-based-evasion) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Plain HTTP POST Exfiltrated Data](/network/plain_http_post_exfiltrated_data/) | [Exfiltration Over Unencrypted Non-C2 Protocol](/tags/#exfiltration-over-unencrypted-non-c2-protocol), [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Possible Browser Pass View Parameter](/endpoint/possible_browser_pass_view_parameter/) | [Credentials from Web Browsers](/tags/#credentials-from-web-browsers), [Credentials from Password Stores](/tags/#credentials-from-password-stores) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Possible Lateral Movement PowerShell Spawn](/endpoint/possible_lateral_movement_powershell_spawn/) | [Remote Services](/tags/#remote-services), [Distributed Component Object Model](/tags/#distributed-component-object-model), [Windows Remote Management](/tags/#windows-remote-management), [Windows Management Instrumentation](/tags/#windows-management-instrumentation), [Scheduled Task](/tags/#scheduled-task), [Windows Service](/tags/#windows-service), [PowerShell](/tags/#powershell), [MMC](/tags/#mmc) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Potential password in username](/endpoint/potential_password_in_username/) | [Local Accounts](/tags/#local-accounts), [Credentials In Files](/tags/#credentials-in-files) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Potentially malicious code on commandline](/endpoint/potentially_malicious_code_on_commandline/) | [Windows Command Shell](/tags/#windows-command-shell) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [PowerShell - Connect To Internet With Hidden Window](/endpoint/powershell_-_connect_to_internet_with_hidden_window/) | [PowerShell](/tags/#powershell), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [PowerShell 4104 Hunting](/endpoint/powershell_4104_hunting/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [PowerShell Domain Enumeration](/endpoint/powershell_domain_enumeration/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [PowerShell Get LocalGroup Discovery](/endpoint/powershell_get_localgroup_discovery/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Local Groups](/tags/#local-groups) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [PowerShell Loading DotNET into Memory via Reflection](/endpoint/powershell_loading_dotnet_into_memory_via_reflection/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [PowerShell Start-BitsTransfer](/endpoint/powershell_start-bitstransfer/) | [BITS Jobs](/tags/#bits-jobs) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Powershell Creating Thread Mutex](/endpoint/powershell_creating_thread_mutex/) | [Obfuscated Files or Information](/tags/#obfuscated-files-or-information), [Indicator Removal from Tools](/tags/#indicator-removal-from-tools), [PowerShell](/tags/#powershell) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Powershell Disable Security Monitoring](/endpoint/powershell_disable_security_monitoring/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Powershell Enable SMB1Protocol Feature](/endpoint/powershell_enable_smb1protocol_feature/) | [Obfuscated Files or Information](/tags/#obfuscated-files-or-information), [Indicator Removal from Tools](/tags/#indicator-removal-from-tools) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Powershell Execute COM Object](/endpoint/powershell_execute_com_object/) | [Component Object Model Hijacking](/tags/#component-object-model-hijacking), [Event Triggered Execution](/tags/#event-triggered-execution), [PowerShell](/tags/#powershell) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Powershell Fileless Process Injection via GetProcAddress](/endpoint/powershell_fileless_process_injection_via_getprocaddress/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Process Injection](/tags/#process-injection), [PowerShell](/tags/#powershell) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Powershell Fileless Script Contains Base64 Encoded Content](/endpoint/powershell_fileless_script_contains_base64_encoded_content/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Obfuscated Files or Information](/tags/#obfuscated-files-or-information), [PowerShell](/tags/#powershell) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Powershell Get LocalGroup Discovery with Script Block Logging](/endpoint/powershell_get_localgroup_discovery_with_script_block_logging/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Local Groups](/tags/#local-groups) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Powershell Processing Stream Of Data](/endpoint/powershell_processing_stream_of_data/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Powershell Remote Thread To Known Windows Process](/endpoint/powershell_remote_thread_to_known_windows_process/) | [Process Injection](/tags/#process-injection) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Powershell Remove Windows Defender Directory](/endpoint/powershell_remove_windows_defender_directory/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Powershell Using memory As Backing Store](/endpoint/powershell_using_memory_as_backing_store/) | [PowerShell](/tags/#powershell), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Powershell Windows Defender Exclusion Commands](/endpoint/powershell_windows_defender_exclusion_commands/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Prevent Automatic Repair Mode using Bcdedit](/endpoint/prevent_automatic_repair_mode_using_bcdedit/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Print Processor Registry Autostart](/endpoint/print_processor_registry_autostart/) | [Print Processors](/tags/#print-processors), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Print Spooler Adding A Printer Driver](/endpoint/print_spooler_adding_a_printer_driver/) | [Print Processors](/tags/#print-processors), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Print Spooler Failed to Load a Plug-in](/endpoint/print_spooler_failed_to_load_a_plug-in/) | [Print Processors](/tags/#print-processors), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Process Creating LNK file in Suspicious Location](/endpoint/process_creating_lnk_file_in_suspicious_location/) | [Phishing](/tags/#phishing), [Spearphishing Link](/tags/#spearphishing-link) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Process Deleting Its Process File Path](/endpoint/process_deleting_its_process_file_path/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Process Execution via WMI](/endpoint/process_execution_via_wmi/) | [Windows Management Instrumentation](/tags/#windows-management-instrumentation) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Process Kill Base On File Path](/endpoint/process_kill_base_on_file_path/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Process Writing DynamicWrapperX](/endpoint/process_writing_dynamicwrapperx/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Component Object Model](/tags/#component-object-model) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Processes Tapping Keyboard Events](/endpoint/processes_tapping_keyboard_events/) | None | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Processes created by netsh](/deprecated/processes_created_by_netsh/) | [Disable or Modify System Firewall](/tags/#disable-or-modify-system-firewall) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Processes launching netsh](/endpoint/processes_launching_netsh/) | [Disable or Modify System Firewall](/tags/#disable-or-modify-system-firewall), [Impair Defenses](/tags/#impair-defenses) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Prohibited Network Traffic Allowed](/network/prohibited_network_traffic_allowed/) | [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Prohibited Software On Endpoint](/deprecated/prohibited_software_on_endpoint/) | None | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Protocol or Port Mismatch](/network/protocol_or_port_mismatch/) | [Exfiltration Over Unencrypted Non-C2 Protocol](/tags/#exfiltration-over-unencrypted-non-c2-protocol), [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Protocols passing authentication in cleartext](/network/protocols_passing_authentication_in_cleartext/) | None | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Randomly Generated Scheduled Task Name](/endpoint/randomly_generated_scheduled_task_name/) | [Scheduled Task/Job](/tags/#scheduled-task/job), [Scheduled Task](/tags/#scheduled-task) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Randomly Generated Windows Service Name](/endpoint/randomly_generated_windows_service_name/) | [Create or Modify System Process](/tags/#create-or-modify-system-process), [Windows Service](/tags/#windows-service) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Ransomware Notes bulk creation](/endpoint/ransomware_notes_bulk_creation/) | [Data Encrypted for Impact](/tags/#data-encrypted-for-impact) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Recon AVProduct Through Pwh or WMI](/endpoint/recon_avproduct_through_pwh_or_wmi/) | [Gather Victim Host Information](/tags/#gather-victim-host-information) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Recon Using WMI Class](/endpoint/recon_using_wmi_class/) | [Gather Victim Host Information](/tags/#gather-victim-host-information), [PowerShell](/tags/#powershell) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Recursive Delete of Directory In Batch CMD](/endpoint/recursive_delete_of_directory_in_batch_cmd/) | [File Deletion](/tags/#file-deletion), [Indicator Removal on Host](/tags/#indicator-removal-on-host) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Reg exe Manipulating Windows Services Registry Keys](/endpoint/reg_exe_manipulating_windows_services_registry_keys/) | [Services Registry Permissions Weakness](/tags/#services-registry-permissions-weakness), [Hijack Execution Flow](/tags/#hijack-execution-flow) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Reg exe used to hide files directories via registry keys](/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys/) | [Hidden Files and Directories](/tags/#hidden-files-and-directories) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Registry Keys Used For Persistence](/endpoint/registry_keys_used_for_persistence/) | [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Registry Keys Used For Privilege Escalation](/endpoint/registry_keys_used_for_privilege_escalation/) | [Image File Execution Options Injection](/tags/#image-file-execution-options-injection), [Event Triggered Execution](/tags/#event-triggered-execution) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Registry Keys for Creating SHIM Databases](/endpoint/registry_keys_for_creating_shim_databases/) | [Application Shimming](/tags/#application-shimming), [Event Triggered Execution](/tags/#event-triggered-execution) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Regsvr32 Silent and Install Param Dll Loading](/endpoint/regsvr32_silent_and_install_param_dll_loading/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Regsvr32](/tags/#regsvr32) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Regsvr32 with Known Silent Switch Cmdline](/endpoint/regsvr32_with_known_silent_switch_cmdline/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Regsvr32](/tags/#regsvr32) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Remcos RAT File Creation in Remcos Folder](/endpoint/remcos_rat_file_creation_in_remcos_folder/) | [Screen Capture](/tags/#screen-capture) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Remcos client registry install entry](/endpoint/remcos_client_registry_install_entry/) | [Modify Registry](/tags/#modify-registry) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Remote Desktop Network Bruteforce](/network/remote_desktop_network_bruteforce/) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol), [Remote Services](/tags/#remote-services) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Remote Desktop Network Traffic](/network/remote_desktop_network_traffic/) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol), [Remote Services](/tags/#remote-services) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Remote Desktop Process Running On System](/endpoint/remote_desktop_process_running_on_system/) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol), [Remote Services](/tags/#remote-services) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Remote Process Instantiation via DCOM and PowerShell](/endpoint/remote_process_instantiation_via_dcom_and_powershell/) | [Remote Services](/tags/#remote-services), [Distributed Component Object Model](/tags/#distributed-component-object-model) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Remote Process Instantiation via DCOM and PowerShell Script Block](/endpoint/remote_process_instantiation_via_dcom_and_powershell_script_block/) | [Remote Services](/tags/#remote-services), [Distributed Component Object Model](/tags/#distributed-component-object-model) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Remote Process Instantiation via WMI](/endpoint/remote_process_instantiation_via_wmi/) | [Windows Management Instrumentation](/tags/#windows-management-instrumentation) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Remote Process Instantiation via WMI and PowerShell](/endpoint/remote_process_instantiation_via_wmi_and_powershell/) | [Windows Management Instrumentation](/tags/#windows-management-instrumentation) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Remote Process Instantiation via WMI and PowerShell Script Block](/endpoint/remote_process_instantiation_via_wmi_and_powershell_script_block/) | [Windows Management Instrumentation](/tags/#windows-management-instrumentation) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Remote Process Instantiation via WinRM and PowerShell](/endpoint/remote_process_instantiation_via_winrm_and_powershell/) | [Remote Services](/tags/#remote-services), [Windows Remote Management](/tags/#windows-remote-management) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Remote Process Instantiation via WinRM and PowerShell Script Block](/endpoint/remote_process_instantiation_via_winrm_and_powershell_script_block/) | [Remote Services](/tags/#remote-services), [Windows Remote Management](/tags/#windows-remote-management) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Remote Process Instantiation via WinRM and Winrs](/endpoint/remote_process_instantiation_via_winrm_and_winrs/) | [Remote Services](/tags/#remote-services), [Windows Remote Management](/tags/#windows-remote-management) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Remote Registry Key modifications](/deprecated/remote_registry_key_modifications/) | None | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Remote System Discovery with Adsisearcher](/endpoint/remote_system_discovery_with_adsisearcher/) | [Remote System Discovery](/tags/#remote-system-discovery) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Remote System Discovery with Dsquery](/endpoint/remote_system_discovery_with_dsquery/) | [Remote System Discovery](/tags/#remote-system-discovery) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Remote System Discovery with Net](/endpoint/remote_system_discovery_with_net/) | [Remote System Discovery](/tags/#remote-system-discovery) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Remote System Discovery with Wmic](/endpoint/remote_system_discovery_with_wmic/) | [Remote System Discovery](/tags/#remote-system-discovery) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Remote WMI Command Attempt](/endpoint/remote_wmi_command_attempt/) | [Windows Management Instrumentation](/tags/#windows-management-instrumentation) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Resize ShadowStorage volume](/endpoint/resize_shadowstorage_volume/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Revil Common Exec Parameter](/endpoint/revil_common_exec_parameter/) | [User Execution](/tags/#user-execution) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Revil Registry Entry](/endpoint/revil_registry_entry/) | [Modify Registry](/tags/#modify-registry) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Rubeus Command Line Parameters](/endpoint/rubeus_command_line_parameters/) | [Use Alternate Authentication Material](/tags/#use-alternate-authentication-material), [Pass the Ticket](/tags/#pass-the-ticket), [Steal or Forge Kerberos Tickets](/tags/#steal-or-forge-kerberos-tickets), [Kerberoasting](/tags/#kerberoasting), [AS-REP Roasting](/tags/#as-rep-roasting) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Rubeus Kerberos Ticket Exports Through Winlogon Access](/endpoint/rubeus_kerberos_ticket_exports_through_winlogon_access/) | [Use Alternate Authentication Material](/tags/#use-alternate-authentication-material), [Pass the Ticket](/tags/#pass-the-ticket) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [RunDLL Loading DLL By Ordinal](/endpoint/rundll_loading_dll_by_ordinal/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Rundll32](/tags/#rundll32) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Runas Execution in CommandLine](/endpoint/runas_execution_in_commandline/) | [Access Token Manipulation](/tags/#access-token-manipulation), [Token Impersonation/Theft](/tags/#token-impersonation/theft) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Rundll32 Control RunDLL Hunt](/endpoint/rundll32_control_rundll_hunt/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Rundll32](/tags/#rundll32) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Rundll32 Control RunDLL World Writable Directory](/endpoint/rundll32_control_rundll_world_writable_directory/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Rundll32](/tags/#rundll32) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Rundll32 Create Remote Thread To A Process](/endpoint/rundll32_create_remote_thread_to_a_process/) | [Process Injection](/tags/#process-injection) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Rundll32 CreateRemoteThread In Browser](/endpoint/rundll32_createremotethread_in_browser/) | [Process Injection](/tags/#process-injection) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Rundll32 DNSQuery](/endpoint/rundll32_dnsquery/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Rundll32](/tags/#rundll32) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Rundll32 LockWorkStation](/endpoint/rundll32_lockworkstation/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Rundll32](/tags/#rundll32) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Rundll32 Process Creating Exe Dll Files](/endpoint/rundll32_process_creating_exe_dll_files/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Rundll32](/tags/#rundll32) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Rundll32 Shimcache Flush](/endpoint/rundll32_shimcache_flush/) | [Modify Registry](/tags/#modify-registry) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Rundll32 with no Command Line Arguments with Network](/endpoint/rundll32_with_no_command_line_arguments_with_network/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Rundll32](/tags/#rundll32) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Ryuk Test Files Detected](/endpoint/ryuk_test_files_detected/) | [Data Encrypted for Impact](/tags/#data-encrypted-for-impact) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Ryuk Wake on LAN Command](/endpoint/ryuk_wake_on_lan_command/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Windows Command Shell](/tags/#windows-command-shell) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [SAM Database File Access Attempt](/endpoint/sam_database_file_access_attempt/) | [Security Account Manager](/tags/#security-account-manager), [OS Credential Dumping](/tags/#os-credential-dumping) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [SLUI RunAs Elevated](/endpoint/slui_runas_elevated/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [SLUI Spawning a Process](/endpoint/slui_spawning_a_process/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [SMB Traffic Spike](/network/smb_traffic_spike/) | [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares), [Remote Services](/tags/#remote-services) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [SMB Traffic Spike - MLTK](/network/smb_traffic_spike_-_mltk/) | [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares), [Remote Services](/tags/#remote-services) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [SQL Injection with Long URLs](/web/sql_injection_with_long_urls/) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Samsam Test File Write](/endpoint/samsam_test_file_write/) | [Data Encrypted for Impact](/tags/#data-encrypted-for-impact) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Sc exe Manipulating Windows Services](/endpoint/sc_exe_manipulating_windows_services/) | [Windows Service](/tags/#windows-service), [Create or Modify System Process](/tags/#create-or-modify-system-process) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [SchCache Change By App Connect And Create ADSI Object](/endpoint/schcache_change_by_app_connect_and_create_adsi_object/) | [Domain Account](/tags/#domain-account), [Account Discovery](/tags/#account-discovery) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Schedule Task with HTTP Command Arguments](/endpoint/schedule_task_with_http_command_arguments/) | [Scheduled Task/Job](/tags/#scheduled-task/job) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Schedule Task with Rundll32 Command Trigger](/endpoint/schedule_task_with_rundll32_command_trigger/) | [Scheduled Task/Job](/tags/#scheduled-task/job) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Scheduled Task Creation on Remote Endpoint using At](/endpoint/scheduled_task_creation_on_remote_endpoint_using_at/) | [Scheduled Task/Job](/tags/#scheduled-task/job), [At](/tags/#at) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Scheduled Task Deleted Or Created via CMD](/endpoint/scheduled_task_deleted_or_created_via_cmd/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Scheduled Task Initiation on Remote Endpoint](/endpoint/scheduled_task_initiation_on_remote_endpoint/) | [Scheduled Task/Job](/tags/#scheduled-task/job), [Scheduled Task](/tags/#scheduled-task) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Scheduled tasks used in BadRabbit ransomware](/deprecated/scheduled_tasks_used_in_badrabbit_ransomware/) | [Scheduled Task](/tags/#scheduled-task) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Schtasks Run Task On Demand](/endpoint/schtasks_run_task_on_demand/) | [Scheduled Task/Job](/tags/#scheduled-task/job) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Schtasks scheduling job on remote system](/endpoint/schtasks_scheduling_job_on_remote_system/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Schtasks used for forcing a reboot](/endpoint/schtasks_used_for_forcing_a_reboot/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Screensaver Event Trigger Execution](/endpoint/screensaver_event_trigger_execution/) | [Event Triggered Execution](/tags/#event-triggered-execution), [Screensaver](/tags/#screensaver) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Script Execution via WMI](/endpoint/script_execution_via_wmi/) | [Windows Management Instrumentation](/tags/#windows-management-instrumentation) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Sdclt UAC Bypass](/endpoint/sdclt_uac_bypass/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Sdelete Application Execution](/endpoint/sdelete_application_execution/) | [Data Destruction](/tags/#data-destruction), [File Deletion](/tags/#file-deletion), [Indicator Removal on Host](/tags/#indicator-removal-on-host) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [SearchProtocolHost with no Command Line with Network](/endpoint/searchprotocolhost_with_no_command_line_with_network/) | [Process Injection](/tags/#process-injection) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [SecretDumps Offline NTDS Dumping Tool](/endpoint/secretdumps_offline_ntds_dumping_tool/) | [NTDS](/tags/#ntds), [OS Credential Dumping](/tags/#os-credential-dumping) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [ServicePrincipalNames Discovery with PowerShell](/endpoint/serviceprincipalnames_discovery_with_powershell/) | [Kerberoasting](/tags/#kerberoasting) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [ServicePrincipalNames Discovery with SetSPN](/endpoint/serviceprincipalnames_discovery_with_setspn/) | [Kerberoasting](/tags/#kerberoasting) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Services Escalate Exe](/endpoint/services_escalate_exe/) | [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Services LOLBAS Execution Process Spawn](/endpoint/services_lolbas_execution_process_spawn/) | [Create or Modify System Process](/tags/#create-or-modify-system-process), [Windows Service](/tags/#windows-service) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Set Default PowerShell Execution Policy To Unrestricted or Bypass](/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Shim Database File Creation](/endpoint/shim_database_file_creation/) | [Application Shimming](/tags/#application-shimming), [Event Triggered Execution](/tags/#event-triggered-execution) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Shim Database Installation With Suspicious Parameters](/endpoint/shim_database_installation_with_suspicious_parameters/) | [Application Shimming](/tags/#application-shimming), [Event Triggered Execution](/tags/#event-triggered-execution) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Short Lived Scheduled Task](/endpoint/short_lived_scheduled_task/) | [Scheduled Task](/tags/#scheduled-task) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Short Lived Windows Accounts](/endpoint/short_lived_windows_accounts/) | [Local Account](/tags/#local-account), [Create Account](/tags/#create-account) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [SilentCleanup UAC Bypass](/endpoint/silentcleanup_uac_bypass/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Single Letter Process On Endpoint](/endpoint/single_letter_process_on_endpoint/) | [User Execution](/tags/#user-execution), [Malicious File](/tags/#malicious-file) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Spectre and Meltdown Vulnerable Systems](/deprecated/spectre_and_meltdown_vulnerable_systems/) | None | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Spike in File Writes](/endpoint/spike_in_file_writes/) | None | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Splunk Command and Scripting Interpreter Delete Usage](/application/splunk_command_and_scripting_interpreter_delete_usage/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Splunk Command and Scripting Interpreter Risky Commands](/application/splunk_command_and_scripting_interpreter_risky_commands/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Splunk Command and Scripting Interpreter Risky SPL MLTK](/application/splunk_command_and_scripting_interpreter_risky_spl_mltk/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Splunk Digital Certificates Infrastructure Version](/application/splunk_digital_certificates_infrastructure_version/) | [Digital Certificates](/tags/#digital-certificates) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Splunk Digital Certificates Lack of Encryption](/application/splunk_digital_certificates_lack_of_encryption/) | [Digital Certificates](/tags/#digital-certificates) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Splunk DoS via Malformed S2S Request](/application/splunk_dos_via_malformed_s2s_request/) | [Network Denial of Service](/tags/#network-denial-of-service) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Splunk Enterprise Information Disclosure](/deprecated/splunk_enterprise_information_disclosure/) | None | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Splunk Identified SSL TLS Certificates](/network/splunk_identified_ssl_tls_certificates/) | [Network Sniffing](/tags/#network-sniffing) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Splunk Process Injection Forwarder Bundle Downloads](/application/splunk_process_injection_forwarder_bundle_downloads/) | [Process Injection](/tags/#process-injection) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Splunk Protocol Impersonation Weak Encryption Configuration](/application/splunk_protocol_impersonation_weak_encryption_configuration/) | [Protocol Impersonation](/tags/#protocol-impersonation) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Splunk User Enumeration Attempt](/application/splunk_user_enumeration_attempt/) | [Valid Accounts](/tags/#valid-accounts) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Splunk XSS in Monitoring Console](/application/splunk_xss_in_monitoring_console/) | [Drive-by Compromise](/tags/#drive-by-compromise) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Splunk protocol impersonation weak encryption selfsigned](/application/splunk_protocol_impersonation_weak_encryption_selfsigned/) | [Digital Certificates](/tags/#digital-certificates) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Splunk protocol impersonation weak encryption simplerequest](/application/splunk_protocol_impersonation_weak_encryption_simplerequest/) | [Digital Certificates](/tags/#digital-certificates) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Spoolsv Spawning Rundll32](/endpoint/spoolsv_spawning_rundll32/) | [Print Processors](/tags/#print-processors), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Spoolsv Suspicious Loaded Modules](/endpoint/spoolsv_suspicious_loaded_modules/) | [Print Processors](/tags/#print-processors), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Spoolsv Suspicious Process Access](/endpoint/spoolsv_suspicious_process_access/) | [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Spoolsv Writing a DLL](/endpoint/spoolsv_writing_a_dll/) | [Print Processors](/tags/#print-processors), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Spoolsv Writing a DLL - Sysmon](/endpoint/spoolsv_writing_a_dll_-_sysmon/) | [Print Processors](/tags/#print-processors), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Spring4Shell Payload URL Request](/web/spring4shell_payload_url_request/) | [Web Shell](/tags/#web-shell), [Server Software Component](/tags/#server-software-component), [Exploit Public-Facing Application](/tags/#exploit-public-facing-application) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Sqlite Module In Temp Folder](/endpoint/sqlite_module_in_temp_folder/) | [Data from Local System](/tags/#data-from-local-system) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Sunburst Correlation DLL and Network Event](/endpoint/sunburst_correlation_dll_and_network_event/) | [Exploitation for Client Execution](/tags/#exploitation-for-client-execution) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Supernova Webshell](/web/supernova_webshell/) | [Web Shell](/tags/#web-shell) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Suspicious Changes to File Associations](/deprecated/suspicious_changes_to_file_associations/) | [Change Default File Association](/tags/#change-default-file-association) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Suspicious Computer Account Name Change](/endpoint/suspicious_computer_account_name_change/) | [Valid Accounts](/tags/#valid-accounts), [Domain Accounts](/tags/#domain-accounts) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Suspicious Copy on System32](/endpoint/suspicious_copy_on_system32/) | [Rename System Utilities](/tags/#rename-system-utilities), [Masquerading](/tags/#masquerading) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Suspicious Curl Network Connection](/endpoint/suspicious_curl_network_connection/) | [Ingress Tool Transfer](/tags/#ingress-tool-transfer) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Suspicious DLLHost no Command Line Arguments](/endpoint/suspicious_dllhost_no_command_line_arguments/) | [Process Injection](/tags/#process-injection) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Suspicious Driver Loaded Path](/endpoint/suspicious_driver_loaded_path/) | [Windows Service](/tags/#windows-service), [Create or Modify System Process](/tags/#create-or-modify-system-process) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Suspicious Email - UBA Anomaly](/deprecated/suspicious_email_-_uba_anomaly/) | [Phishing](/tags/#phishing) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Suspicious Email Attachment Extensions](/application/suspicious_email_attachment_extensions/) | [Spearphishing Attachment](/tags/#spearphishing-attachment), [Phishing](/tags/#phishing) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Suspicious Event Log Service Behavior](/endpoint/suspicious_event_log_service_behavior/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host), [Clear Windows Event Logs](/tags/#clear-windows-event-logs) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Suspicious File Write](/deprecated/suspicious_file_write/) | None | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Suspicious GPUpdate no Command Line Arguments](/endpoint/suspicious_gpupdate_no_command_line_arguments/) | [Process Injection](/tags/#process-injection) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Suspicious IcedID Rundll32 Cmdline](/endpoint/suspicious_icedid_rundll32_cmdline/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Rundll32](/tags/#rundll32) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Suspicious Image Creation In Appdata Folder](/endpoint/suspicious_image_creation_in_appdata_folder/) | [Screen Capture](/tags/#screen-capture) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Suspicious Java Classes](/application/suspicious_java_classes/) | None | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Suspicious Kerberos Service Ticket Request](/endpoint/suspicious_kerberos_service_ticket_request/) | [Valid Accounts](/tags/#valid-accounts), [Domain Accounts](/tags/#domain-accounts) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Suspicious Linux Discovery Commands](/endpoint/suspicious_linux_discovery_commands/) | [Unix Shell](/tags/#unix-shell) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Suspicious MSBuild Rename](/endpoint/suspicious_msbuild_rename/) | [Masquerading](/tags/#masquerading), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Rename System Utilities](/tags/#rename-system-utilities), [MSBuild](/tags/#msbuild) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Suspicious MSBuild Spawn](/endpoint/suspicious_msbuild_spawn/) | [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [MSBuild](/tags/#msbuild) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Suspicious PlistBuddy Usage](/endpoint/suspicious_plistbuddy_usage/) | [Launch Agent](/tags/#launch-agent), [Create or Modify System Process](/tags/#create-or-modify-system-process) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Suspicious PlistBuddy Usage via OSquery](/endpoint/suspicious_plistbuddy_usage_via_osquery/) | [Launch Agent](/tags/#launch-agent), [Create or Modify System Process](/tags/#create-or-modify-system-process) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Suspicious Powershell Command-Line Arguments](/deprecated/suspicious_powershell_command-line_arguments/) | [PowerShell](/tags/#powershell) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Suspicious Process DNS Query Known Abuse Web Services](/endpoint/suspicious_process_dns_query_known_abuse_web_services/) | [Visual Basic](/tags/#visual-basic), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Suspicious Process File Path](/endpoint/suspicious_process_file_path/) | [Create or Modify System Process](/tags/#create-or-modify-system-process) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Suspicious Process With Discord DNS Query](/endpoint/suspicious_process_with_discord_dns_query/) | [Visual Basic](/tags/#visual-basic), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Suspicious Reg exe Process](/endpoint/suspicious_reg_exe_process/) | [Modify Registry](/tags/#modify-registry) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Suspicious Regsvr32 Register Suspicious Path](/endpoint/suspicious_regsvr32_register_suspicious_path/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Regsvr32](/tags/#regsvr32) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Suspicious Rundll32 PluginInit](/endpoint/suspicious_rundll32_plugininit/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Rundll32](/tags/#rundll32) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Suspicious Rundll32 Rename](/deprecated/suspicious_rundll32_rename/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Masquerading](/tags/#masquerading), [Rundll32](/tags/#rundll32), [Rename System Utilities](/tags/#rename-system-utilities) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Suspicious Rundll32 StartW](/endpoint/suspicious_rundll32_startw/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Rundll32](/tags/#rundll32) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Suspicious Rundll32 dllregisterserver](/endpoint/suspicious_rundll32_dllregisterserver/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Rundll32](/tags/#rundll32) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Suspicious Rundll32 no Command Line Arguments](/endpoint/suspicious_rundll32_no_command_line_arguments/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Rundll32](/tags/#rundll32) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Suspicious SQLite3 LSQuarantine Behavior](/endpoint/suspicious_sqlite3_lsquarantine_behavior/) | [Data Staged](/tags/#data-staged) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Suspicious Scheduled Task from Public Directory](/endpoint/suspicious_scheduled_task_from_public_directory/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Suspicious SearchProtocolHost no Command Line Arguments](/endpoint/suspicious_searchprotocolhost_no_command_line_arguments/) | [Process Injection](/tags/#process-injection) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Suspicious Ticket Granting Ticket Request](/endpoint/suspicious_ticket_granting_ticket_request/) | [Valid Accounts](/tags/#valid-accounts), [Domain Accounts](/tags/#domain-accounts) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Suspicious WAV file in Appdata Folder](/endpoint/suspicious_wav_file_in_appdata_folder/) | [Screen Capture](/tags/#screen-capture) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Suspicious microsoft workflow compiler rename](/endpoint/suspicious_microsoft_workflow_compiler_rename/) | [Masquerading](/tags/#masquerading), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Rename System Utilities](/tags/#rename-system-utilities) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Suspicious microsoft workflow compiler usage](/endpoint/suspicious_microsoft_workflow_compiler_usage/) | [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Suspicious msbuild path](/endpoint/suspicious_msbuild_path/) | [Masquerading](/tags/#masquerading), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Rename System Utilities](/tags/#rename-system-utilities), [MSBuild](/tags/#msbuild) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Suspicious mshta child process](/endpoint/suspicious_mshta_child_process/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Mshta](/tags/#mshta) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Suspicious mshta spawn](/endpoint/suspicious_mshta_spawn/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Mshta](/tags/#mshta) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Suspicious wevtutil Usage](/endpoint/suspicious_wevtutil_usage/) | [Clear Windows Event Logs](/tags/#clear-windows-event-logs), [Indicator Removal on Host](/tags/#indicator-removal-on-host) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Suspicious writes to System Volume Information](/deprecated/suspicious_writes_to_system_volume_information/) | [Masquerading](/tags/#masquerading) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Suspicious writes to windows Recycle Bin](/endpoint/suspicious_writes_to_windows_recycle_bin/) | [Masquerading](/tags/#masquerading) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Svchost LOLBAS Execution Process Spawn](/endpoint/svchost_lolbas_execution_process_spawn/) | [Scheduled Task/Job](/tags/#scheduled-task/job), [Scheduled Task](/tags/#scheduled-task) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [System Info Gathering Using Dxdiag Application](/endpoint/system_info_gathering_using_dxdiag_application/) | [Gather Victim Host Information](/tags/#gather-victim-host-information) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [System Information Discovery Detection](/endpoint/system_information_discovery_detection/) | [System Information Discovery](/tags/#system-information-discovery) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [System Processes Run From Unexpected Locations](/endpoint/system_processes_run_from_unexpected_locations/) | [Masquerading](/tags/#masquerading), [Rename System Utilities](/tags/#rename-system-utilities) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [System User Discovery With Query](/endpoint/system_user_discovery_with_query/) | [System Owner/User Discovery](/tags/#system-owner/user-discovery) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [System User Discovery With Whoami](/endpoint/system_user_discovery_with_whoami/) | [System Owner/User Discovery](/tags/#system-owner/user-discovery) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [TOR Traffic](/network/tor_traffic/) | [Application Layer Protocol](/tags/#application-layer-protocol), [Web Protocols](/tags/#web-protocols) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Time Provider Persistence Registry](/endpoint/time_provider_persistence_registry/) | [Time Providers](/tags/#time-providers), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Trickbot Named Pipe](/endpoint/trickbot_named_pipe/) | [Process Injection](/tags/#process-injection) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [UAC Bypass MMC Load Unsigned Dll](/endpoint/uac_bypass_mmc_load_unsigned_dll/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism), [MMC](/tags/#mmc) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [UAC Bypass With Colorui COM Object](/endpoint/uac_bypass_with_colorui_com_object/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [CMSTP](/tags/#cmstp) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [USN Journal Deletion](/endpoint/usn_journal_deletion/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Uncommon Processes On Endpoint](/deprecated/uncommon_processes_on_endpoint/) | [Malicious File](/tags/#malicious-file) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Unified Messaging Service Spawning a Process](/endpoint/unified_messaging_service_spawning_a_process/) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Uninstall App Using MsiExec](/endpoint/uninstall_app_using_msiexec/) | [Msiexec](/tags/#msiexec), [System Binary Proxy Execution](/tags/#system-binary-proxy-execution) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Unknown Process Using The Kerberos Protocol](/endpoint/unknown_process_using_the_kerberos_protocol/) | [Use Alternate Authentication Material](/tags/#use-alternate-authentication-material) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Unload Sysmon Filter Driver](/endpoint/unload_sysmon_filter_driver/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Unloading AMSI via Reflection](/endpoint/unloading_amsi_via_reflection/) | [Impair Defenses](/tags/#impair-defenses), [PowerShell](/tags/#powershell), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Unsigned Image Loaded by LSASS](/deprecated/unsigned_image_loaded_by_lsass/) | [LSASS Memory](/tags/#lsass-memory) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Unsuccessful Netbackup backups](/deprecated/unsuccessful_netbackup_backups/) | None | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Unusual Number of Computer Service Tickets Requested](/endpoint/unusual_number_of_computer_service_tickets_requested/) | [Valid Accounts](/tags/#valid-accounts) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Unusual Number of Kerberos Service Tickets Requested](/endpoint/unusual_number_of_kerberos_service_tickets_requested/) | [Steal or Forge Kerberos Tickets](/tags/#steal-or-forge-kerberos-tickets), [Kerberoasting](/tags/#kerberoasting) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Unusual Number of Remote Endpoint Authentication Events](/endpoint/unusual_number_of_remote_endpoint_authentication_events/) | [Valid Accounts](/tags/#valid-accounts) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Unusually Long Command Line](/endpoint/unusually_long_command_line/) | None | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Unusually Long Command Line - MLTK](/endpoint/unusually_long_command_line_-_mltk/) | None | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Unusually Long Content-Type Length](/network/unusually_long_content-type_length/) | None | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [User Discovery With Env Vars PowerShell](/endpoint/user_discovery_with_env_vars_powershell/) | [System Owner/User Discovery](/tags/#system-owner/user-discovery) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [User Discovery With Env Vars PowerShell Script Block](/endpoint/user_discovery_with_env_vars_powershell_script_block/) | [System Owner/User Discovery](/tags/#system-owner/user-discovery) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [VMware Server Side Template Injection Hunt](/web/vmware_server_side_template_injection_hunt/) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [VMware Workspace ONE Freemarker Server-side Template Injection](/web/vmware_workspace_one_freemarker_server-side_template_injection/) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Vbscript Execution Using Wscript App](/endpoint/vbscript_execution_using_wscript_app/) | [Visual Basic](/tags/#visual-basic), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Verclsid CLSID Execution](/endpoint/verclsid_clsid_execution/) | [Verclsid](/tags/#verclsid), [System Binary Proxy Execution](/tags/#system-binary-proxy-execution) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [W3WP Spawning Shell](/endpoint/w3wp_spawning_shell/) | [Server Software Component](/tags/#server-software-component), [Web Shell](/tags/#web-shell) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [WBAdmin Delete System Backups](/endpoint/wbadmin_delete_system_backups/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [WMI Permanent Event Subscription](/endpoint/wmi_permanent_event_subscription/) | [Windows Management Instrumentation](/tags/#windows-management-instrumentation) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [WMI Permanent Event Subscription - Sysmon](/endpoint/wmi_permanent_event_subscription_-_sysmon/) | [Windows Management Instrumentation Event Subscription](/tags/#windows-management-instrumentation-event-subscription), [Event Triggered Execution](/tags/#event-triggered-execution) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [WMI Recon Running Process Or Services](/endpoint/wmi_recon_running_process_or_services/) | [Gather Victim Host Information](/tags/#gather-victim-host-information) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [WMI Temporary Event Subscription](/endpoint/wmi_temporary_event_subscription/) | [Windows Management Instrumentation](/tags/#windows-management-instrumentation) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [WMIC XSL Execution via URL](/endpoint/wmic_xsl_execution_via_url/) | [XSL Script Processing](/tags/#xsl-script-processing) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [WSReset UAC Bypass](/endpoint/wsreset_uac_bypass/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Wbemprox COM Object Execution](/endpoint/wbemprox_com_object_execution/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [CMSTP](/tags/#cmstp) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Web Fraud - Account Harvesting](/deprecated/web_fraud_-_account_harvesting/) | [Create Account](/tags/#create-account) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Web Fraud - Anomalous User Clickspeed](/deprecated/web_fraud_-_anomalous_user_clickspeed/) | [Valid Accounts](/tags/#valid-accounts) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Web Fraud - Password Sharing Across Accounts](/deprecated/web_fraud_-_password_sharing_across_accounts/) | None | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Web JSP Request via URL](/web/web_jsp_request_via_url/) | [Web Shell](/tags/#web-shell), [Server Software Component](/tags/#server-software-component), [Exploit Public-Facing Application](/tags/#exploit-public-facing-application) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Web Servers Executing Suspicious Processes](/application/web_servers_executing_suspicious_processes/) | [System Information Discovery](/tags/#system-information-discovery) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Web Spring Cloud Function FunctionRouter](/web/web_spring_cloud_function_functionrouter/) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Web Spring4Shell HTTP Request Class Module](/web/web_spring4shell_http_request_class_module/) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Wermgr Process Connecting To IP Check Web Services](/endpoint/wermgr_process_connecting_to_ip_check_web_services/) | [Gather Victim Network Information](/tags/#gather-victim-network-information), [IP Addresses](/tags/#ip-addresses) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Wermgr Process Create Executable File](/endpoint/wermgr_process_create_executable_file/) | [Obfuscated Files or Information](/tags/#obfuscated-files-or-information) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Wermgr Process Spawned CMD Or Powershell Process](/endpoint/wermgr_process_spawned_cmd_or_powershell_process/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Wget Download and Bash Execution](/endpoint/wget_download_and_bash_execution/) | [Ingress Tool Transfer](/tags/#ingress-tool-transfer) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [WinEvent Scheduled Task Created Within Public Path](/endpoint/winevent_scheduled_task_created_within_public_path/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [WinEvent Scheduled Task Created to Spawn Shell](/endpoint/winevent_scheduled_task_created_to_spawn_shell/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [WinEvent Windows Task Scheduler Event Action Started](/endpoint/winevent_windows_task_scheduler_event_action_started/) | [Scheduled Task](/tags/#scheduled-task) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [WinRM Spawning a Process](/endpoint/winrm_spawning_a_process/) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows AdFind Exe](/endpoint/windows_adfind_exe/) | [Remote System Discovery](/tags/#remote-system-discovery) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Application Layer Protocol RMS Radmin Tool Namedpipe](/endpoint/windows_application_layer_protocol_rms_radmin_tool_namedpipe/) | [Application Layer Protocol](/tags/#application-layer-protocol) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Binary Proxy Execution Mavinject DLL Injection](/endpoint/windows_binary_proxy_execution_mavinject_dll_injection/) | [Mavinject](/tags/#mavinject), [System Binary Proxy Execution](/tags/#system-binary-proxy-execution) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Command Shell DCRat ForkBomb Payload](/endpoint/windows_command_shell_dcrat_forkbomb_payload/) | [Windows Command Shell](/tags/#windows-command-shell), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Command and Scripting Interpreter Hunting Path Traversal](/endpoint/windows_command_and_scripting_interpreter_hunting_path_traversal/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Command and Scripting Interpreter Path Traversal Exec](/endpoint/windows_command_and_scripting_interpreter_path_traversal_exec/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Computer Account Created by Computer Account](/endpoint/windows_computer_account_created_by_computer_account/) | [Steal or Forge Kerberos Tickets](/tags/#steal-or-forge-kerberos-tickets) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Computer Account Requesting Kerberos Ticket](/endpoint/windows_computer_account_requesting_kerberos_ticket/) | [Steal or Forge Kerberos Tickets](/tags/#steal-or-forge-kerberos-tickets) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Computer Account With SPN](/endpoint/windows_computer_account_with_spn/) | [Steal or Forge Kerberos Tickets](/tags/#steal-or-forge-kerberos-tickets) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Curl Download to Suspicious Path](/endpoint/windows_curl_download_to_suspicious_path/) | [Ingress Tool Transfer](/tags/#ingress-tool-transfer) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Curl Upload to Remote Destination](/endpoint/windows_curl_upload_to_remote_destination/) | [Ingress Tool Transfer](/tags/#ingress-tool-transfer) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows DISM Remove Defender](/endpoint/windows_dism_remove_defender/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Defender Exclusion Registry Entry](/endpoint/windows_defender_exclusion_registry_entry/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Deleted Registry By A Non Critical Process File Path](/endpoint/windows_deleted_registry_by_a_non_critical_process_file_path/) | [Modify Registry](/tags/#modify-registry) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Disable Change Password Through Registry](/endpoint/windows_disable_change_password_through_registry/) | [Modify Registry](/tags/#modify-registry) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Disable Lock Workstation Feature Through Registry](/endpoint/windows_disable_lock_workstation_feature_through_registry/) | [Modify Registry](/tags/#modify-registry) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Disable LogOff Button Through Registry](/endpoint/windows_disable_logoff_button_through_registry/) | [Modify Registry](/tags/#modify-registry) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Disable Memory Crash Dump](/endpoint/windows_disable_memory_crash_dump/) | [Data Destruction](/tags/#data-destruction) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Disable Notification Center](/endpoint/windows_disable_notification_center/) | [Modify Registry](/tags/#modify-registry) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Disable Shutdown Button Through Registry](/endpoint/windows_disable_shutdown_button_through_registry/) | [Modify Registry](/tags/#modify-registry) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Disable Windows Group Policy Features Through Registry](/endpoint/windows_disable_windows_group_policy_features_through_registry/) | [Modify Registry](/tags/#modify-registry) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows DisableAntiSpyware Registry](/endpoint/windows_disableantispyware_registry/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Disabled Users Failing To Authenticate Kerberos](/endpoint/windows_disabled_users_failing_to_authenticate_kerberos/) | [Password Spraying](/tags/#password-spraying), [Brute Force](/tags/#brute-force) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows DiskCryptor Usage](/endpoint/windows_diskcryptor_usage/) | [Data Encrypted for Impact](/tags/#data-encrypted-for-impact) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Diskshadow Proxy Execution](/endpoint/windows_diskshadow_proxy_execution/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows DotNet Binary in Non Standard Path](/endpoint/windows_dotnet_binary_in_non_standard_path/) | [Masquerading](/tags/#masquerading), [Rename System Utilities](/tags/#rename-system-utilities), [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [InstallUtil](/tags/#installutil) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Driver Load Non-Standard Path](/endpoint/windows_driver_load_non-standard_path/) | [Rootkit](/tags/#rootkit) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Drivers Loaded by Signature](/endpoint/windows_drivers_loaded_by_signature/) | [Rootkit](/tags/#rootkit), [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Event For Service Disabled](/endpoint/windows_event_for_service_disabled/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Event Log Cleared](/endpoint/windows_event_log_cleared/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host), [Clear Windows Event Logs](/tags/#clear-windows-event-logs) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Excessive Disabled Services Event](/endpoint/windows_excessive_disabled_services_event/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Execute Arbitrary Commands with MSDT](/endpoint/windows_execute_arbitrary_commands_with_msdt/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows File Without Extension In Critical Folder](/endpoint/windows_file_without_extension_in_critical_folder/) | [Data Destruction](/tags/#data-destruction) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Gather Victim Network Info Through Ip Check Web Services](/endpoint/windows_gather_victim_network_info_through_ip_check_web_services/) | [IP Addresses](/tags/#ip-addresses), [Gather Victim Network Information](/tags/#gather-victim-network-information) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Get-AdComputer Unconstrained Delegation Discovery](/endpoint/windows_get-adcomputer_unconstrained_delegation_discovery/) | [Remote System Discovery](/tags/#remote-system-discovery) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Hidden Schedule Task Settings](/endpoint/windows_hidden_schedule_task_settings/) | [Scheduled Task/Job](/tags/#scheduled-task/job) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Hide Notification Features Through Registry](/endpoint/windows_hide_notification_features_through_registry/) | [Modify Registry](/tags/#modify-registry) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows High File Deletion Frequency](/endpoint/windows_high_file_deletion_frequency/) | [Data Destruction](/tags/#data-destruction) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Hunting System Account Targeting Lsass](/endpoint/windows_hunting_system_account_targeting_lsass/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows ISO LNK File Creation](/endpoint/windows_iso_lnk_file_creation/) | [Spearphishing Attachment](/tags/#spearphishing-attachment), [Phishing](/tags/#phishing), [Malicious Link](/tags/#malicious-link), [User Execution](/tags/#user-execution) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Identify Protocol Handlers](/endpoint/windows_identify_protocol_handlers/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Impair Defense Add Xml Applocker Rules](/endpoint/windows_impair_defense_add_xml_applocker_rules/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Impair Defense Delete Win Defender Context Menu](/endpoint/windows_impair_defense_delete_win_defender_context_menu/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Impair Defense Delete Win Defender Profile Registry](/endpoint/windows_impair_defense_delete_win_defender_profile_registry/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Impair Defense Deny Security Software With Applocker](/endpoint/windows_impair_defense_deny_security_software_with_applocker/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Impair Defenses Disable Win Defender Auto Logging](/endpoint/windows_impair_defenses_disable_win_defender_auto_logging/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Indirect Command Execution Via forfiles](/endpoint/windows_indirect_command_execution_via_forfiles/) | [Indirect Command Execution](/tags/#indirect-command-execution) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Indirect Command Execution Via pcalua](/endpoint/windows_indirect_command_execution_via_pcalua/) | [Indirect Command Execution](/tags/#indirect-command-execution) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows InstallUtil Credential Theft](/endpoint/windows_installutil_credential_theft/) | [InstallUtil](/tags/#installutil), [System Binary Proxy Execution](/tags/#system-binary-proxy-execution) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows InstallUtil Remote Network Connection](/endpoint/windows_installutil_remote_network_connection/) | [InstallUtil](/tags/#installutil), [System Binary Proxy Execution](/tags/#system-binary-proxy-execution) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows InstallUtil URL in Command Line](/endpoint/windows_installutil_url_in_command_line/) | [InstallUtil](/tags/#installutil), [System Binary Proxy Execution](/tags/#system-binary-proxy-execution) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows InstallUtil Uninstall Option](/endpoint/windows_installutil_uninstall_option/) | [InstallUtil](/tags/#installutil), [System Binary Proxy Execution](/tags/#system-binary-proxy-execution) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows InstallUtil Uninstall Option with Network](/endpoint/windows_installutil_uninstall_option_with_network/) | [InstallUtil](/tags/#installutil), [System Binary Proxy Execution](/tags/#system-binary-proxy-execution) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows InstallUtil in Non Standard Path](/endpoint/windows_installutil_in_non_standard_path/) | [Masquerading](/tags/#masquerading), [Rename System Utilities](/tags/#rename-system-utilities), [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [InstallUtil](/tags/#installutil) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Invalid Users Failed Authentication via Kerberos](/endpoint/windows_invalid_users_failed_authentication_via_kerberos/) | [Password Spraying](/tags/#password-spraying), [Brute Force](/tags/#brute-force) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Java Spawning Shells](/endpoint/windows_java_spawning_shells/) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Kerberos Local Successful Logon](/endpoint/windows_kerberos_local_successful_logon/) | [Steal or Forge Kerberos Tickets](/tags/#steal-or-forge-kerberos-tickets) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows KrbRelayUp Service Creation](/endpoint/windows_krbrelayup_service_creation/) | [Windows Service](/tags/#windows-service) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Linked Policies In ADSI Discovery](/endpoint/windows_linked_policies_in_adsi_discovery/) | [Domain Account](/tags/#domain-account), [Account Discovery](/tags/#account-discovery) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows MOF Event Triggered Execution via WMI](/endpoint/windows_mof_event_triggered_execution_via_wmi/) | [Windows Management Instrumentation Event Subscription](/tags/#windows-management-instrumentation-event-subscription) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows MSIExec DLLRegisterServer](/endpoint/windows_msiexec_dllregisterserver/) | [Msiexec](/tags/#msiexec) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows MSIExec Remote Download](/endpoint/windows_msiexec_remote_download/) | [Msiexec](/tags/#msiexec) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows MSIExec Spawn Discovery Command](/endpoint/windows_msiexec_spawn_discovery_command/) | [Msiexec](/tags/#msiexec) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows MSIExec Unregister DLLRegisterServer](/endpoint/windows_msiexec_unregister_dllregisterserver/) | [Msiexec](/tags/#msiexec) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows MSIExec With Network Connections](/endpoint/windows_msiexec_with_network_connections/) | [Msiexec](/tags/#msiexec) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Modify Registry DisAllow Windows App](/endpoint/windows_modify_registry_disallow_windows_app/) | [Modify Registry](/tags/#modify-registry) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Modify Registry Disable Toast Notifications](/endpoint/windows_modify_registry_disable_toast_notifications/) | [Modify Registry](/tags/#modify-registry) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Modify Registry Disable Win Defender Raw Write Notif](/endpoint/windows_modify_registry_disable_win_defender_raw_write_notif/) | [Modify Registry](/tags/#modify-registry) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Modify Registry Disable Windows Security Center Notif](/endpoint/windows_modify_registry_disable_windows_security_center_notif/) | [Modify Registry](/tags/#modify-registry) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Modify Registry Disabling WER Settings](/endpoint/windows_modify_registry_disabling_wer_settings/) | [Modify Registry](/tags/#modify-registry) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Modify Registry Regedit Silent Reg Import](/endpoint/windows_modify_registry_regedit_silent_reg_import/) | [Modify Registry](/tags/#modify-registry) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Modify Registry Suppress Win Defender Notif](/endpoint/windows_modify_registry_suppress_win_defender_notif/) | [Modify Registry](/tags/#modify-registry) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Modify Show Compress Color And Info Tip Registry](/endpoint/windows_modify_show_compress_color_and_info_tip_registry/) | [Modify Registry](/tags/#modify-registry) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows NirSoft AdvancedRun](/endpoint/windows_nirsoft_advancedrun/) | [Tool](/tags/#tool) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows NirSoft Utilities](/endpoint/windows_nirsoft_utilities/) | [Tool](/tags/#tool) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Non-System Account Targeting Lsass](/endpoint/windows_non-system_account_targeting_lsass/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Odbcconf Hunting](/endpoint/windows_odbcconf_hunting/) | [Odbcconf](/tags/#odbcconf) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Odbcconf Load DLL](/endpoint/windows_odbcconf_load_dll/) | [Odbcconf](/tags/#odbcconf) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Odbcconf Load Response File](/endpoint/windows_odbcconf_load_response_file/) | [Odbcconf](/tags/#odbcconf) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Office Product Spawning MSDT](/endpoint/windows_office_product_spawning_msdt/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Possible Credential Dumping](/endpoint/windows_possible_credential_dumping/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows PowerView Constrained Delegation Discovery](/endpoint/windows_powerview_constrained_delegation_discovery/) | [Remote System Discovery](/tags/#remote-system-discovery) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows PowerView Kerberos Service Ticket Request](/endpoint/windows_powerview_kerberos_service_ticket_request/) | [Steal or Forge Kerberos Tickets](/tags/#steal-or-forge-kerberos-tickets), [Kerberoasting](/tags/#kerberoasting) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows PowerView SPN Discovery](/endpoint/windows_powerview_spn_discovery/) | [Steal or Forge Kerberos Tickets](/tags/#steal-or-forge-kerberos-tickets), [Kerberoasting](/tags/#kerberoasting) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows PowerView Unconstrained Delegation Discovery](/endpoint/windows_powerview_unconstrained_delegation_discovery/) | [Remote System Discovery](/tags/#remote-system-discovery) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Powershell Import Applocker Policy](/endpoint/windows_powershell_import_applocker_policy/) | [PowerShell](/tags/#powershell) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Process With NamedPipe CommandLine](/endpoint/windows_process_with_namedpipe_commandline/) | [Process Injection](/tags/#process-injection) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Processes Killed By Industroyer2 Malware](/endpoint/windows_processes_killed_by_industroyer2_malware/) | [Service Stop](/tags/#service-stop) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Raccine Scheduled Task Deletion](/endpoint/windows_raccine_scheduled_task_deletion/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Rasautou DLL Execution](/endpoint/windows_rasautou_dll_execution/) | [Dynamic-link Library Injection](/tags/#dynamic-link-library-injection), [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Process Injection](/tags/#process-injection) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Raw Access To Disk Volume Partition](/endpoint/windows_raw_access_to_disk_volume_partition/) | [Disk Structure Wipe](/tags/#disk-structure-wipe), [Disk Wipe](/tags/#disk-wipe) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Raw Access To Master Boot Record Drive](/endpoint/windows_raw_access_to_master_boot_record_drive/) | [Disk Structure Wipe](/tags/#disk-structure-wipe), [Disk Wipe](/tags/#disk-wipe) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Registry Certificate Added](/endpoint/windows_registry_certificate_added/) | [Install Root Certificate](/tags/#install-root-certificate), [Subvert Trust Controls](/tags/#subvert-trust-controls) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Registry Delete Task SD](/endpoint/windows_registry_delete_task_sd/) | [Scheduled Task](/tags/#scheduled-task), [Impair Defenses](/tags/#impair-defenses) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Registry Modification for Safe Mode Persistence](/endpoint/windows_registry_modification_for_safe_mode_persistence/) | [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Remote Access Software RMS Registry](/endpoint/windows_remote_access_software_rms_registry/) | [Remote Access Software](/tags/#remote-access-software) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Remote Assistance Spawning Process](/endpoint/windows_remote_assistance_spawning_process/) | [Process Injection](/tags/#process-injection) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Remote Service Rdpwinst Tool Execution](/endpoint/windows_remote_service_rdpwinst_tool_execution/) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol), [Remote Services](/tags/#remote-services) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Remote Services Allow Rdp In Firewall](/endpoint/windows_remote_services_allow_rdp_in_firewall/) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol), [Remote Services](/tags/#remote-services) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Remote Services Allow Remote Assistance](/endpoint/windows_remote_services_allow_remote_assistance/) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol), [Remote Services](/tags/#remote-services) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Remote Services Rdp Enable](/endpoint/windows_remote_services_rdp_enable/) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol), [Remote Services](/tags/#remote-services) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Root Domain linked policies Discovery](/endpoint/windows_root_domain_linked_policies_discovery/) | [Domain Account](/tags/#domain-account), [Account Discovery](/tags/#account-discovery) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Schtasks Create Run As System](/endpoint/windows_schtasks_create_run_as_system/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Security Account Manager Stopped](/endpoint/windows_security_account_manager_stopped/) | [Service Stop](/tags/#service-stop) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Service Create Kernel Mode Driver](/endpoint/windows_service_create_kernel_mode_driver/) | [Windows Service](/tags/#windows-service), [Create or Modify System Process](/tags/#create-or-modify-system-process), [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Service Created With Suspicious Service Path](/endpoint/windows_service_created_with_suspicious_service_path/) | [System Services](/tags/#system-services), [Service Execution](/tags/#service-execution) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Service Created Within Public Path](/endpoint/windows_service_created_within_public_path/) | [Create or Modify System Process](/tags/#create-or-modify-system-process), [Windows Service](/tags/#windows-service) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Service Creation Using Registry Entry](/endpoint/windows_service_creation_using_registry_entry/) | [Services Registry Permissions Weakness](/tags/#services-registry-permissions-weakness) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Service Creation on Remote Endpoint](/endpoint/windows_service_creation_on_remote_endpoint/) | [Create or Modify System Process](/tags/#create-or-modify-system-process), [Windows Service](/tags/#windows-service) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Service Initiation on Remote Endpoint](/endpoint/windows_service_initiation_on_remote_endpoint/) | [Create or Modify System Process](/tags/#create-or-modify-system-process), [Windows Service](/tags/#windows-service) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Service Stop By Deletion](/endpoint/windows_service_stop_by_deletion/) | [Service Stop](/tags/#service-stop) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows System File on Disk](/endpoint/windows_system_file_on_disk/) | [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows System LogOff Commandline](/endpoint/windows_system_logoff_commandline/) | [System Shutdown/Reboot](/tags/#system-shutdown/reboot) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows System Reboot CommandLine](/endpoint/windows_system_reboot_commandline/) | [System Shutdown/Reboot](/tags/#system-shutdown/reboot) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows System Shutdown CommandLine](/endpoint/windows_system_shutdown_commandline/) | [System Shutdown/Reboot](/tags/#system-shutdown/reboot) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows System Time Discovery W32tm Delay](/endpoint/windows_system_time_discovery_w32tm_delay/) | [System Time Discovery](/tags/#system-time-discovery) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Terminating Lsass Process](/endpoint/windows_terminating_lsass_process/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Users Authenticate Using Explicit Credentials](/endpoint/windows_users_authenticate_using_explicit_credentials/) | [Password Spraying](/tags/#password-spraying), [Brute Force](/tags/#brute-force) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows Valid Account With Never Expires Password](/endpoint/windows_valid_account_with_never_expires_password/) | [Service Stop](/tags/#service-stop) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows WMI Process Call Create](/endpoint/windows_wmi_process_call_create/) | [Windows Management Instrumentation](/tags/#windows-management-instrumentation) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows connhost exe started forcefully](/deprecated/windows_connhost_exe_started_forcefully/) | [Windows Command Shell](/tags/#windows-command-shell) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Windows hosts file modification](/deprecated/windows_hosts_file_modification/) | None | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Winhlp32 Spawning a Process](/endpoint/winhlp32_spawning_a_process/) | [Process Injection](/tags/#process-injection) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Winword Spawning Cmd](/endpoint/winword_spawning_cmd/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Winword Spawning PowerShell](/endpoint/winword_spawning_powershell/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Winword Spawning Windows Script Host](/endpoint/winword_spawning_windows_script_host/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Wmic Group Discovery](/endpoint/wmic_group_discovery/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Local Groups](/tags/#local-groups) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Wmic NonInteractive App Uninstallation](/endpoint/wmic_noninteractive_app_uninstallation/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Wmiprsve LOLBAS Execution Process Spawn](/endpoint/wmiprsve_lolbas_execution_process_spawn/) | [Windows Management Instrumentation](/tags/#windows-management-instrumentation) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Wscript Or Cscript Suspicious Child Process](/endpoint/wscript_or_cscript_suspicious_child_process/) | [Process Injection](/tags/#process-injection), [Create or Modify System Process](/tags/#create-or-modify-system-process), [Parent PID Spoofing](/tags/#parent-pid-spoofing), [Access Token Manipulation](/tags/#access-token-manipulation) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [Wsmprovhost LOLBAS Execution Process Spawn](/endpoint/wsmprovhost_lolbas_execution_process_spawn/) | [Remote Services](/tags/#remote-services), [Windows Remote Management](/tags/#windows-remote-management) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [XMRIG Driver Loaded](/endpoint/xmrig_driver_loaded/) | [Windows Service](/tags/#windows-service), [Create or Modify System Process](/tags/#create-or-modify-system-process) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [XSL Script Execution With WMIC](/endpoint/xsl_script_execution_with_wmic/) | [XSL Script Processing](/tags/#xsl-script-processing) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [aws detect attach to role policy](/cloud/aws_detect_attach_to_role_policy/) | [Valid Accounts](/tags/#valid-accounts) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [aws detect permanent key creation](/cloud/aws_detect_permanent_key_creation/) | [Valid Accounts](/tags/#valid-accounts) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [aws detect role creation](/cloud/aws_detect_role_creation/) | [Valid Accounts](/tags/#valid-accounts) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [aws detect sts assume role abuse](/cloud/aws_detect_sts_assume_role_abuse/) | [Valid Accounts](/tags/#valid-accounts) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [aws detect sts get session token abuse](/cloud/aws_detect_sts_get_session_token_abuse/) | [Use Alternate Authentication Material](/tags/#use-alternate-authentication-material) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | -| [gcp detect oauth token abuse](/deprecated/gcp_detect_oauth_token_abuse/) | [Valid Accounts](/tags/#valid-accounts) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) | \ No newline at end of file diff --git a/docs/_pages/discovery.md b/docs/_pages/discovery.md deleted file mode 100644 index aa938bbdfa..0000000000 --- a/docs/_pages/discovery.md +++ /dev/null @@ -1,9 +0,0 @@ ---- -title: Discovery -layout: tag -author_profile: false -taxonomy: Discovery -permalink: /detections/discovery/ -sidebar: - nav: "detections" ---- \ No newline at end of file diff --git a/docs/_pages/email.md b/docs/_pages/email.md deleted file mode 100644 index 5261178804..0000000000 --- a/docs/_pages/email.md +++ /dev/null @@ -1,9 +0,0 @@ ---- -title: Email -layout: tag -author_profile: false -taxonomy: Email -permalink: /detections/email/ -sidebar: - nav: "detections" ---- \ No newline at end of file diff --git a/docs/_pages/endpoint.md b/docs/_pages/endpoint.md deleted file mode 100644 index 3405d11c96..0000000000 --- a/docs/_pages/endpoint.md +++ /dev/null @@ -1,9 +0,0 @@ ---- -title: Endpoint -layout: tag -author_profile: false -taxonomy: Endpoint -permalink: /detections/endpoint/ -sidebar: - nav: "detections" ---- \ No newline at end of file diff --git a/docs/_pages/endpoint_filesystem.md b/docs/_pages/endpoint_filesystem.md deleted file mode 100644 index 94b3445de7..0000000000 --- a/docs/_pages/endpoint_filesystem.md +++ /dev/null @@ -1,9 +0,0 @@ ---- -title: Endpoint_Filesystem -layout: tag -author_profile: false -taxonomy: Endpoint_Filesystem -permalink: /detections/endpoint_filesystem/ -sidebar: - nav: "detections" ---- \ No newline at end of file diff --git a/docs/_pages/endpoint_processes.md b/docs/_pages/endpoint_processes.md deleted file mode 100644 index fa2114cac3..0000000000 --- a/docs/_pages/endpoint_processes.md +++ /dev/null @@ -1,9 +0,0 @@ ---- -title: Endpoint_Processes -layout: tag -author_profile: false -taxonomy: Endpoint_Processes -permalink: /detections/endpoint_processes/ -sidebar: - nav: "detections" ---- \ No newline at end of file diff --git a/docs/_pages/endpoint_registry.md b/docs/_pages/endpoint_registry.md deleted file mode 100644 index 9c10f41486..0000000000 --- a/docs/_pages/endpoint_registry.md +++ /dev/null @@ -1,9 +0,0 @@ ---- -title: Endpoint_Registry -layout: tag -author_profile: false -taxonomy: Endpoint_Registry -permalink: /detections/endpoint_registry/ -sidebar: - nav: "detections" ---- \ No newline at end of file diff --git a/docs/_pages/execution.md b/docs/_pages/execution.md deleted file mode 100644 index 525ce8a7c2..0000000000 --- a/docs/_pages/execution.md +++ /dev/null @@ -1,9 +0,0 @@ ---- -title: Execution -layout: tag -author_profile: false -taxonomy: Execution -permalink: /detections/execution/ -sidebar: - nav: "detections" ---- \ No newline at end of file diff --git a/docs/_pages/exfiltration.md b/docs/_pages/exfiltration.md deleted file mode 100644 index 4b2ab567fe..0000000000 --- a/docs/_pages/exfiltration.md +++ /dev/null @@ -1,9 +0,0 @@ ---- -title: Exfiltration -layout: tag -author_profile: false -taxonomy: Exfiltration -permalink: /detections/exfiltration/ -sidebar: - nav: "detections" ---- \ No newline at end of file diff --git a/docs/_pages/impact.md b/docs/_pages/impact.md deleted file mode 100644 index 0fcf8a7099..0000000000 --- a/docs/_pages/impact.md +++ /dev/null @@ -1,9 +0,0 @@ ---- -title: Impact -layout: tag -author_profile: false -taxonomy: Impact -permalink: /detections/impact/ -sidebar: - nav: "detections" ---- \ No newline at end of file diff --git a/docs/_pages/initial_access.md b/docs/_pages/initial_access.md deleted file mode 100644 index 9ac8bd46b2..0000000000 --- a/docs/_pages/initial_access.md +++ /dev/null @@ -1,9 +0,0 @@ ---- -title: Initial Access -layout: tag -author_profile: false -taxonomy: Initial Access -permalink: /detections/initial_access/ -sidebar: - nav: "detections" ---- \ No newline at end of file diff --git a/docs/_pages/lateral_movement.md b/docs/_pages/lateral_movement.md deleted file mode 100644 index d43228c982..0000000000 --- a/docs/_pages/lateral_movement.md +++ /dev/null @@ -1,9 +0,0 @@ ---- -title: Lateral Movement -layout: tag -author_profile: false -taxonomy: Lateral Movement -permalink: /detections/lateral_movement/ -sidebar: - nav: "detections" ---- \ No newline at end of file diff --git a/docs/_pages/malware.md b/docs/_pages/malware.md deleted file mode 100644 index c4d4949baa..0000000000 --- a/docs/_pages/malware.md +++ /dev/null @@ -1,9 +0,0 @@ ---- -title: Malware -layout: tag -author_profile: false -taxonomy: Malware -permalink: /detections/malware/ -sidebar: - nav: "detections" ---- \ No newline at end of file diff --git a/docs/_pages/network_resolution.md b/docs/_pages/network_resolution.md deleted file mode 100644 index f290dba017..0000000000 --- a/docs/_pages/network_resolution.md +++ /dev/null @@ -1,9 +0,0 @@ ---- -title: Network_Resolution -layout: tag -author_profile: false -taxonomy: Network_Resolution -permalink: /detections/network_resolution/ -sidebar: - nav: "detections" ---- \ No newline at end of file diff --git a/docs/_pages/network_sessions.md b/docs/_pages/network_sessions.md deleted file mode 100644 index c9a6ff437c..0000000000 --- a/docs/_pages/network_sessions.md +++ /dev/null @@ -1,9 +0,0 @@ ---- -title: Network_Sessions -layout: tag -author_profile: false -taxonomy: Network_Sessions -permalink: /detections/network_sessions/ -sidebar: - nav: "detections" ---- \ No newline at end of file diff --git a/docs/_pages/network_traffic.md b/docs/_pages/network_traffic.md deleted file mode 100644 index 2f1abacc7c..0000000000 --- a/docs/_pages/network_traffic.md +++ /dev/null @@ -1,9 +0,0 @@ ---- -title: Network_Traffic -layout: tag -author_profile: false -taxonomy: Network_Traffic -permalink: /detections/network_traffic/ -sidebar: - nav: "detections" ---- \ No newline at end of file diff --git a/docs/_pages/ooo.md b/docs/_pages/ooo.md deleted file mode 100644 index 357fcce059..0000000000 --- a/docs/_pages/ooo.md +++ /dev/null @@ -1,8 +0,0 @@ ---- -permalink: /ooo/ -title: "OOO" -author_profile: false -layout: single ---- - -![ooo](https://media.giphy.com/media/lPuW5AlR9AeWzSsIqi/giphy.gif) diff --git a/docs/_pages/paybooks.md b/docs/_pages/paybooks.md deleted file mode 100644 index 1a71491911..0000000000 --- a/docs/_pages/paybooks.md +++ /dev/null @@ -1,43 +0,0 @@ ---- -title: "Playbooks" -layout: collection -author_profile: false -permalink: /playbooks/ -classes: wide -sidebar: - nav: "playbooks" ---- - -| Name | Detections | Type | -| --------| ---------- | ----------- | -| [AWS Disable User Accounts](/playbooks/aws_disable_user_accounts/)| None | Response | -| [AWS Find Inactive Users](/playbooks/aws_find_inactive_users/)| None | Investigation | -| [Active Directory Reset password](/playbooks/active_directory_reset_password/)| None | Response | -| [Block Indicators](/playbooks/block_indicators/)| None | Response | -| [Crowdstrike Malware Triage](/playbooks/crowdstrike_malware_triage/)| None | Response | -| [Delete Detected Files](/playbooks/delete_detected_files/)|[Executable File Written in Administrative SMB Share]((/detection/executable_file_written_in_administrative_smb_share/)| Response | -| [Email Notification for Malware](/playbooks/email_notification_for_malware/)| None | Response | -| [Internal Host SSH Investigate](/playbooks/internal_host_ssh_investigate/)| None | Investigation | -| [Internal Host SSH Log4j Investigate](/playbooks/internal_host_ssh_log4j_investigate/)| None | Investigation | -| [Internal Host SSH Log4j Response](/playbooks/internal_host_ssh_log4j_response/)| None | Response | -| [Internal Host WinRM Investigate](/playbooks/internal_host_winrm_investigate/)| None | Investigation | -| [Internal Host WinRM Log4j Investigate](/playbooks/internal_host_winrm_log4j_investigate/)| None | Investigation | -| [Internal Host WinRM Response](/playbooks/internal_host_winrm_response/)| None | Response | -| [Log4j Investigate](/playbooks/log4j_investigate/)|[Curl Download and Bash Execution]((/detection/curl_download_and_bash_execution/)[Wget Download and Bash Execution]((/detection/wget_download_and_bash_execution/)[Linux Java Spawning Shell]((/detection/linux_java_spawning_shell/)[Windows Java Spawning Shell]((/detection/windows_java_spawning_shell/)[Java Class File download by Java User Agent]((/detection/java_class_file_download_by_java_user_agent/)[Outbound Network Connection from Java Using Default Ports]((/detection/outbound_network_connection_from_java_using_default_ports/)[Log4Shell JNDI Payload Injection Attempt]((/detection/log4shell_jndi_payload_injection_attempt/)[Log4Shell JNDI Payload Injection with Outbound Connection]((/detection/log4shell_jndi_payload_injection_with_outbound_connection/)[Detect Outbound LDAP Traffic]((/detection/detect_outbound_ldap_traffic/)| Investigation | -| [Log4j Respond](/playbooks/log4j_respond/)|[Curl Download and Bash Execution]((/detection/curl_download_and_bash_execution/)[Wget Download and Bash Execution]((/detection/wget_download_and_bash_execution/)[Linux Java Spawning Shell]((/detection/linux_java_spawning_shell/)[Windows Java Spawning Shell]((/detection/windows_java_spawning_shell/)[Java Class File download by Java User Agent]((/detection/java_class_file_download_by_java_user_agent/)[Outbound Network Connection from Java Using Default Ports]((/detection/outbound_network_connection_from_java_using_default_ports/)[Log4Shell JNDI Payload Injection Attempt]((/detection/log4shell_jndi_payload_injection_attempt/)[Log4Shell JNDI Payload Injection with Outbound Connection]((/detection/log4shell_jndi_payload_injection_with_outbound_connection/)[Detect Outbound LDAP Traffic]((/detection/detect_outbound_ldap_traffic/)| Response | -| [Log4j Splunk Investigation](/playbooks/log4j_splunk_investigation/)| None | Investigation | -| [Malware Hunt and Contain](/playbooks/malware_hunt_and_contain/)| None | Response | -| [Ransomware Investigate and Contain](/playbooks/ransomware_investigate_and_contain/)|[Conti Common Exec parameter]((/detection/conti_common_exec_parameter/)| Response | -| [Risk Notable Block Indicators](/playbooks/risk_notable_block_indicators/)| None | Response | -| [Risk Notable Enrich](/playbooks/risk_notable_enrich/)| None | Investigation | -| [Risk Notable Import Data](/playbooks/risk_notable_import_data/)| None | Investigation | -| [Risk Notable Investigate](/playbooks/risk_notable_investigate/)| None | Investigation | -| [Risk Notable Merge Events](/playbooks/risk_notable_merge_events/)| None | Investigation | -| [Risk Notable Mitigate](/playbooks/risk_notable_mitigate/)| None | Response | -| [Risk Notable Preprocess](/playbooks/risk_notable_preprocess/)| None | Investigation | -| [Risk Notable Protect Assets and Users](/playbooks/risk_notable_protect_assets_and_users/)| None | Response | -| [Risk Notable Review Indicators](/playbooks/risk_notable_review_indicators/)| None | Response | -| [Risk Notable Verdict](/playbooks/risk_notable_verdict/)| None | Response | -| [Start Investigation](/playbooks/start_investigation/)| None | Investigation | -| [Threat Intel Investigate](/playbooks/threat_intel_investigate/)| None | Investigation | -| [TruSTAR Enrich Indicators](/playbooks/trustar_enrich_indicators/)| None | Investigation | diff --git a/docs/_pages/persistence.md b/docs/_pages/persistence.md deleted file mode 100644 index 7b802d6881..0000000000 --- a/docs/_pages/persistence.md +++ /dev/null @@ -1,9 +0,0 @@ ---- -title: Persistence -layout: tag -author_profile: false -taxonomy: Persistence -permalink: /detections/persistence/ -sidebar: - nav: "detections" ---- \ No newline at end of file diff --git a/docs/_pages/playbooks.md b/docs/_pages/playbooks.md deleted file mode 100644 index 892ea13122..0000000000 --- a/docs/_pages/playbooks.md +++ /dev/null @@ -1,43 +0,0 @@ ---- -title: "Playbooks" -layout: collection -author_profile: false -permalink: /playbooks/ -classes: wide -sidebar: - nav: "playbooks" ---- - -| Name | Detections | Type | -| --------| ---------- | ----------- | -| [AWS Disable User Accounts](/playbooks/aws_disable_user_accounts/)| None | Response | -| [AWS Find Inactive Users](/playbooks/aws_find_inactive_users/)| None | Investigation | -| [Active Directory Reset password](/playbooks/active_directory_reset_password/)| None | Response | -| [Block Indicators](/playbooks/block_indicators/)| None | Response | -| [Crowdstrike Malware Triage](/playbooks/crowdstrike_malware_triage/)| None | Response | -| [Delete Detected Files](/playbooks/delete_detected_files/)|[Executable File Written in Administrative SMB Share](/endpoint/executable_file_written_in_administrative_smb_share/)| Response | -| [Email Notification for Malware](/playbooks/email_notification_for_malware/)| None | Response | -| [Internal Host SSH Investigate](/playbooks/internal_host_ssh_investigate/)| None | Investigation | -| [Internal Host SSH Log4j Investigate](/playbooks/internal_host_ssh_log4j_investigate/)| None | Investigation | -| [Internal Host SSH Log4j Response](/playbooks/internal_host_ssh_log4j_response/)| None | Response | -| [Internal Host WinRM Investigate](/playbooks/internal_host_winrm_investigate/)| None | Investigation | -| [Internal Host WinRM Log4j Investigate](/playbooks/internal_host_winrm_log4j_investigate/)| None | Investigation | -| [Internal Host WinRM Response](/playbooks/internal_host_winrm_response/)| None | Response | -| [Log4j Investigate](/playbooks/log4j_investigate/)|[Curl Download and Bash Execution](/endpoint/curl_download_and_bash_execution/)[Wget Download and Bash Execution](/endpoint/wget_download_and_bash_execution/)[Linux Java Spawning Shell](/endpoint/linux_java_spawning_shell/)[Java Class File download by Java User Agent](/endpoint/java_class_file_download_by_java_user_agent/)[Outbound Network Connection from Java Using Default Ports](/endpoint/outbound_network_connection_from_java_using_default_ports/)[Log4Shell JNDI Payload Injection Attempt](/web/log4shell_jndi_payload_injection_attempt/)[Log4Shell JNDI Payload Injection with Outbound Connection](/web/log4shell_jndi_payload_injection_with_outbound_connection/)[Detect Outbound LDAP Traffic](/network/detect_outbound_ldap_traffic/)| Investigation | -| [Log4j Respond](/playbooks/log4j_respond/)|[Curl Download and Bash Execution](/endpoint/curl_download_and_bash_execution/)[Wget Download and Bash Execution](/endpoint/wget_download_and_bash_execution/)[Linux Java Spawning Shell](/endpoint/linux_java_spawning_shell/)[Java Class File download by Java User Agent](/endpoint/java_class_file_download_by_java_user_agent/)[Outbound Network Connection from Java Using Default Ports](/endpoint/outbound_network_connection_from_java_using_default_ports/)[Log4Shell JNDI Payload Injection Attempt](/web/log4shell_jndi_payload_injection_attempt/)[Log4Shell JNDI Payload Injection with Outbound Connection](/web/log4shell_jndi_payload_injection_with_outbound_connection/)[Detect Outbound LDAP Traffic](/network/detect_outbound_ldap_traffic/)| Response | -| [Log4j Splunk Investigation](/playbooks/log4j_splunk_investigation/)| None | Investigation | -| [Malware Hunt and Contain](/playbooks/malware_hunt_and_contain/)| None | Response | -| [Ransomware Investigate and Contain](/playbooks/ransomware_investigate_and_contain/)|[Conti Common Exec parameter](/endpoint/conti_common_exec_parameter/)| Response | -| [Risk Notable Block Indicators](/playbooks/risk_notable_block_indicators/)| None | Response | -| [Risk Notable Enrich](/playbooks/risk_notable_enrich/)| None | Investigation | -| [Risk Notable Import Data](/playbooks/risk_notable_import_data/)| None | Investigation | -| [Risk Notable Investigate](/playbooks/risk_notable_investigate/)| None | Investigation | -| [Risk Notable Merge Events](/playbooks/risk_notable_merge_events/)| None | Investigation | -| [Risk Notable Mitigate](/playbooks/risk_notable_mitigate/)| None | Response | -| [Risk Notable Preprocess](/playbooks/risk_notable_preprocess/)| None | Investigation | -| [Risk Notable Protect Assets and Users](/playbooks/risk_notable_protect_assets_and_users/)| None | Response | -| [Risk Notable Review Indicators](/playbooks/risk_notable_review_indicators/)| None | Response | -| [Risk Notable Verdict](/playbooks/risk_notable_verdict/)| None | Response | -| [Start Investigation](/playbooks/start_investigation/)| None | Investigation | -| [Threat Intel Investigate](/playbooks/threat_intel_investigate/)| None | Investigation | -| [TruSTAR Enrich Indicators](/playbooks/trustar_enrich_indicators/)| None | Investigation | diff --git a/docs/_pages/privilege_escalation.md b/docs/_pages/privilege_escalation.md deleted file mode 100644 index 60bde4562d..0000000000 --- a/docs/_pages/privilege_escalation.md +++ /dev/null @@ -1,9 +0,0 @@ ---- -title: Privilege Escalation -layout: tag -author_profile: false -taxonomy: Privilege Escalation -permalink: /detections/privilege_escalation/ -sidebar: - nav: "detections" ---- \ No newline at end of file diff --git a/docs/_pages/ransomware.md b/docs/_pages/ransomware.md deleted file mode 100644 index 2568a01143..0000000000 --- a/docs/_pages/ransomware.md +++ /dev/null @@ -1,9 +0,0 @@ ---- -title: Ransomware -layout: tag -author_profile: false -taxonomy: Ransomware -permalink: /detections/ransomware/ -sidebar: - nav: "detections" ---- \ No newline at end of file diff --git a/docs/_pages/reconnaissance.md b/docs/_pages/reconnaissance.md deleted file mode 100644 index 7f2e48f7ba..0000000000 --- a/docs/_pages/reconnaissance.md +++ /dev/null @@ -1,9 +0,0 @@ ---- -title: Reconnaissance -layout: tag -author_profile: false -taxonomy: Reconnaissance -permalink: /detections/reconnaissance/ -sidebar: - nav: "detections" ---- \ No newline at end of file diff --git a/docs/_pages/resource_development.md b/docs/_pages/resource_development.md deleted file mode 100644 index 7e7c021f89..0000000000 --- a/docs/_pages/resource_development.md +++ /dev/null @@ -1,9 +0,0 @@ ---- -title: Resource Development -layout: tag -author_profile: false -taxonomy: Resource Development -permalink: /detections/resource_development/ -sidebar: - nav: "detections" ---- \ No newline at end of file diff --git a/docs/_pages/risk.md b/docs/_pages/risk.md deleted file mode 100644 index 21b9834c0e..0000000000 --- a/docs/_pages/risk.md +++ /dev/null @@ -1,9 +0,0 @@ ---- -title: Risk -layout: tag -author_profile: false -taxonomy: Risk -permalink: /detections/risk/ -sidebar: - nav: "detections" ---- \ No newline at end of file diff --git a/docs/_pages/splunk_audit.md b/docs/_pages/splunk_audit.md deleted file mode 100644 index 7613bed97f..0000000000 --- a/docs/_pages/splunk_audit.md +++ /dev/null @@ -1,9 +0,0 @@ ---- -title: Splunk_Audit -layout: tag -author_profile: false -taxonomy: Splunk_Audit -permalink: /detections/splunk_audit/ -sidebar: - nav: "detections" ---- \ No newline at end of file diff --git a/docs/_pages/splunk_behavioral_analytics.md b/docs/_pages/splunk_behavioral_analytics.md deleted file mode 100644 index 8cd1210b3d..0000000000 --- a/docs/_pages/splunk_behavioral_analytics.md +++ /dev/null @@ -1,9 +0,0 @@ ---- -title: "Splunk Behavioral Analytics" -layout: tag -author_profile: false -taxonomy: Splunk Behavioral Analytics -permalink: /product/splunk_behavioral_analytics -sidebar: - nav: "detections" ---- diff --git a/docs/_pages/splunk_enterprise_security.md b/docs/_pages/splunk_enterprise_security.md deleted file mode 100644 index ae99ab59e8..0000000000 --- a/docs/_pages/splunk_enterprise_security.md +++ /dev/null @@ -1,9 +0,0 @@ ---- -title: "Splunk Enterprise Security" -layout: tag -author_profile: false -taxonomy: Splunk Enterprise Security -permalink: /product/splunk_enterprise_security -sidebar: - nav: "detections" ---- diff --git a/docs/_pages/splunk_security_analytics_for_aws.md b/docs/_pages/splunk_security_analytics_for_aws.md deleted file mode 100644 index 8c240c507c..0000000000 --- a/docs/_pages/splunk_security_analytics_for_aws.md +++ /dev/null @@ -1,9 +0,0 @@ ---- -title: "Splunk Behavioral Analytics" -layout: tag -author_profile: false -taxonomy: Splunk Behavioral Analytics -permalink: /product/splunk_security_analytics_for_aws -sidebar: - nav: "detections" ---- diff --git a/docs/_pages/stories.md b/docs/_pages/stories.md deleted file mode 100644 index 477d0defa1..0000000000 --- a/docs/_pages/stories.md +++ /dev/null @@ -1,162 +0,0 @@ ---- -title: Analytic Stories -layout: collection -permalink: /stories/ -collection: stories -classes: wide -sidebar: - nav: "stories" ---- - -| Name | Technique | Tactic | -| ----------- | ----------- |--------------| -| [AWS Cross Account Activity](aws_cross_account_activity) | [Valid Accounts](/tags/#valid-accounts), [Use Alternate Authentication Material](/tags/#use-alternate-authentication-material) | [Defense Evasion](/tags/#defense-evasion), [Initial Access](/tags/#initial-access), [Lateral Movement](/tags/#lateral-movement), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | -| [AWS Cryptomining](aws_cryptomining) | [Cloud Accounts](/tags/#cloud-accounts), [Unused/Unsupported Cloud Regions](/tags/#unused/unsupported-cloud-regions) | [Defense Evasion](/tags/#defense-evasion), [Initial Access](/tags/#initial-access), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | -| [AWS Defense Evasion](aws_defense_evasion) | [Disable Cloud Logs](/tags/#disable-cloud-logs), [Impair Defenses](/tags/#impair-defenses) | [Defense Evasion](/tags/#defense-evasion) | -| [AWS IAM Privilege Escalation](aws_iam_privilege_escalation) | [Cloud Accounts](/tags/#cloud-accounts), [Valid Accounts](/tags/#valid-accounts), [Cloud Account](/tags/#cloud-account), [Create Account](/tags/#create-account), [Cloud Infrastructure Discovery](/tags/#cloud-infrastructure-discovery), [Brute Force](/tags/#brute-force), [Account Manipulation](/tags/#account-manipulation), [Cloud Groups](/tags/#cloud-groups), [Permission Groups Discovery](/tags/#permission-groups-discovery) | [Credential Access](/tags/#credential-access), [Defense Evasion](/tags/#defense-evasion), [Discovery](/tags/#discovery), [Initial Access](/tags/#initial-access), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | -| [AWS Network ACL Activity](aws_network_acl_activity) | [Disable or Modify Cloud Firewall](/tags/#disable-or-modify-cloud-firewall), [Impair Defenses](/tags/#impair-defenses) | [Defense Evasion](/tags/#defense-evasion) | -| [AWS Security Hub Alerts](aws_security_hub_alerts) | None | None | -| [AWS Suspicious Provisioning Activities](aws_suspicious_provisioning_activities) | [Unused/Unsupported Cloud Regions](/tags/#unused/unsupported-cloud-regions) | [Defense Evasion](/tags/#defense-evasion) | -| [AWS User Monitoring](aws_user_monitoring) | [Cloud Service Discovery](/tags/#cloud-service-discovery), [Cloud Accounts](/tags/#cloud-accounts) | [Defense Evasion](/tags/#defense-evasion), [Discovery](/tags/#discovery), [Initial Access](/tags/#initial-access), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | -| [AcidRain](acidrain) | [Data Destruction](/tags/#data-destruction), [File Deletion](/tags/#file-deletion), [Indicator Removal on Host](/tags/#indicator-removal-on-host) | [Defense Evasion](/tags/#defense-evasion), [Impact](/tags/#impact) | -| [Active Directory Discovery](active_directory_discovery) | [Domain Account](/tags/#domain-account), [Account Discovery](/tags/#account-discovery), [Remote System Discovery](/tags/#remote-system-discovery), [Permission Groups Discovery](/tags/#permission-groups-discovery), [Domain Groups](/tags/#domain-groups), [Domain Trust Discovery](/tags/#domain-trust-discovery), [Password Policy Discovery](/tags/#password-policy-discovery), [PowerShell](/tags/#powershell), [Local Groups](/tags/#local-groups), [System Owner/User Discovery](/tags/#system-owner/user-discovery), [Local Account](/tags/#local-account), [System Network Connections Discovery](/tags/#system-network-connections-discovery), [System Network Configuration Discovery](/tags/#system-network-configuration-discovery), [Internet Connection Discovery](/tags/#internet-connection-discovery), [Kerberoasting](/tags/#kerberoasting), [Scheduled Task/Job](/tags/#scheduled-task/job) | [Credential Access](/tags/#credential-access), [Discovery](/tags/#discovery), [Execution](/tags/#execution), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | -| [Active Directory Kerberos Attacks](active_directory_kerberos_attacks) | [Steal or Forge Kerberos Tickets](/tags/#steal-or-forge-kerberos-tickets), [AS-REP Roasting](/tags/#as-rep-roasting), [Kerberoasting](/tags/#kerberoasting), [Golden Ticket](/tags/#golden-ticket), [Use Alternate Authentication Material](/tags/#use-alternate-authentication-material), [Gather Victim Identity Information](/tags/#gather-victim-identity-information), [Email Addresses](/tags/#email-addresses), [Pass the Ticket](/tags/#pass-the-ticket), [Password Spraying](/tags/#password-spraying), [Brute Force](/tags/#brute-force), [OS Credential Dumping](/tags/#os-credential-dumping), [Valid Accounts](/tags/#valid-accounts), [Domain Accounts](/tags/#domain-accounts), [Remote System Discovery](/tags/#remote-system-discovery) | [Credential Access](/tags/#credential-access), [Defense Evasion](/tags/#defense-evasion), [Discovery](/tags/#discovery), [Initial Access](/tags/#initial-access), [Lateral Movement](/tags/#lateral-movement), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation), [Reconnaissance](/tags/#reconnaissance) | -| [Active Directory Lateral Movement](active_directory_lateral_movement) | [Use Alternate Authentication Material](/tags/#use-alternate-authentication-material), [Pass the Hash](/tags/#pass-the-hash), [Remote Services](/tags/#remote-services), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares), [System Services](/tags/#system-services), [Service Execution](/tags/#service-execution), [Distributed Component Object Model](/tags/#distributed-component-object-model), [Windows Management Instrumentation](/tags/#windows-management-instrumentation), [Windows Service](/tags/#windows-service), [Windows Remote Management](/tags/#windows-remote-management), [MMC](/tags/#mmc), [Scheduled Task](/tags/#scheduled-task), [PowerShell](/tags/#powershell), [Scheduled Task/Job](/tags/#scheduled-task/job), [At](/tags/#at), [Create or Modify System Process](/tags/#create-or-modify-system-process), [Services Registry Permissions Weakness](/tags/#services-registry-permissions-weakness), [Remote Desktop Protocol](/tags/#remote-desktop-protocol), [Valid Accounts](/tags/#valid-accounts) | [Defense Evasion](/tags/#defense-evasion), [Execution](/tags/#execution), [Initial Access](/tags/#initial-access), [Lateral Movement](/tags/#lateral-movement), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | -| [Active Directory Password Spraying](active_directory_password_spraying) | [Password Spraying](/tags/#password-spraying), [Brute Force](/tags/#brute-force) | [Credential Access](/tags/#credential-access) | -| [Apache Struts Vulnerability](apache_struts_vulnerability) | [System Information Discovery](/tags/#system-information-discovery) | [Discovery](/tags/#discovery) | -| [Asset Tracking](asset_tracking) | None | None | -| [Atlassian Confluence Server and Data Center CVE-2022-26134](atlassian_confluence_server_and_data_center_cve-2022-26134) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application), [Server Software Component](/tags/#server-software-component) | [Initial Access](/tags/#initial-access), [Persistence](/tags/#persistence) | -| [Azorult](azorult) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol), [Remote Services](/tags/#remote-services), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism), [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Windows Command Shell](/tags/#windows-command-shell), [Local Account](/tags/#local-account), [Create Account](/tags/#create-account), [Hidden Files and Directories](/tags/#hidden-files-and-directories), [Hide Artifacts](/tags/#hide-artifacts), [Bypass User Account Control](/tags/#bypass-user-account-control), [Service Stop](/tags/#service-stop), [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification), [Account Access Removal](/tags/#account-access-removal), [System Services](/tags/#system-services), [Service Execution](/tags/#service-execution), [Masquerading](/tags/#masquerading), [Disable or Modify System Firewall](/tags/#disable-or-modify-system-firewall), [Windows File and Directory Permissions Modification](/tags/#windows-file-and-directory-permissions-modification), [Permission Groups Discovery](/tags/#permission-groups-discovery), [Local Groups](/tags/#local-groups), [System Network Connections Discovery](/tags/#system-network-connections-discovery), [Credentials from Password Stores](/tags/#credentials-from-password-stores), [Credentials from Web Browsers](/tags/#credentials-from-web-browsers), [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution), [Windows Service](/tags/#windows-service), [Create or Modify System Process](/tags/#create-or-modify-system-process), [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job), [Application Layer Protocol](/tags/#application-layer-protocol), [IP Addresses](/tags/#ip-addresses), [Gather Victim Network Information](/tags/#gather-victim-network-information), [Modify Registry](/tags/#modify-registry), [PowerShell](/tags/#powershell), [Remote Access Software](/tags/#remote-access-software) | [Command And Control](/tags/#command-and-control), [Credential Access](/tags/#credential-access), [Defense Evasion](/tags/#defense-evasion), [Discovery](/tags/#discovery), [Execution](/tags/#execution), [Impact](/tags/#impact), [Lateral Movement](/tags/#lateral-movement), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation), [Reconnaissance](/tags/#reconnaissance) | -| [Azure Active Directory Account Takeover](azure_active_directory_account_takeover) | [Brute Force](/tags/#brute-force), [Password Spraying](/tags/#password-spraying), [Valid Accounts](/tags/#valid-accounts), [Cloud Accounts](/tags/#cloud-accounts), [Multi-Factor Authentication Request Generation](/tags/#multi-factor-authentication-request-generation), [Security Account Manager](/tags/#security-account-manager) | [Credential Access](/tags/#credential-access), [Defense Evasion](/tags/#defense-evasion), [Initial Access](/tags/#initial-access), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | -| [BITS Jobs](bits_jobs) | [BITS Jobs](/tags/#bits-jobs), [Ingress Tool Transfer](/tags/#ingress-tool-transfer) | [Command And Control](/tags/#command-and-control), [Defense Evasion](/tags/#defense-evasion), [Persistence](/tags/#persistence) | -| [Baron Samedit CVE-2021-3156](baron_samedit_cve-2021-3156) | [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation) | [Privilege Escalation](/tags/#privilege-escalation) | -| [BlackMatter Ransomware](blackmatter_ransomware) | [Credentials in Registry](/tags/#credentials-in-registry), [Unsecured Credentials](/tags/#unsecured-credentials), [Inhibit System Recovery](/tags/#inhibit-system-recovery), [Defacement](/tags/#defacement), [Data Encrypted for Impact](/tags/#data-encrypted-for-impact) | [Credential Access](/tags/#credential-access), [Impact](/tags/#impact) | -| [Brand Monitoring](brand_monitoring) | None | None | -| [Caddy Wiper](caddy_wiper) | [Disk Structure Wipe](/tags/#disk-structure-wipe), [Disk Wipe](/tags/#disk-wipe) | [Impact](/tags/#impact) | -| [Clop Ransomware](clop_ransomware) | [User Execution](/tags/#user-execution), [Create or Modify System Process](/tags/#create-or-modify-system-process), [Data Destruction](/tags/#data-destruction), [Inhibit System Recovery](/tags/#inhibit-system-recovery), [Data Encrypted for Impact](/tags/#data-encrypted-for-impact), [Indicator Removal on Host](/tags/#indicator-removal-on-host), [Clear Windows Event Logs](/tags/#clear-windows-event-logs), [System Services](/tags/#system-services), [Service Execution](/tags/#service-execution) | [Defense Evasion](/tags/#defense-evasion), [Execution](/tags/#execution), [Impact](/tags/#impact), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | -| [Cloud Cryptomining](cloud_cryptomining) | [Cloud Accounts](/tags/#cloud-accounts), [Valid Accounts](/tags/#valid-accounts), [Unused/Unsupported Cloud Regions](/tags/#unused/unsupported-cloud-regions) | [Defense Evasion](/tags/#defense-evasion), [Initial Access](/tags/#initial-access), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | -| [Cloud Federated Credential Abuse](cloud_federated_credential_abuse) | [Valid Accounts](/tags/#valid-accounts), [Cloud Account](/tags/#cloud-account), [Create Account](/tags/#create-account), [Modify Authentication Process](/tags/#modify-authentication-process), [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping), [Image File Execution Options Injection](/tags/#image-file-execution-options-injection), [Event Triggered Execution](/tags/#event-triggered-execution) | [Credential Access](/tags/#credential-access), [Defense Evasion](/tags/#defense-evasion), [Initial Access](/tags/#initial-access), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | -| [Cobalt Strike](cobalt_strike) | [Archive via Utility](/tags/#archive-via-utility), [Archive Collected Data](/tags/#archive-collected-data), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Windows Command Shell](/tags/#windows-command-shell), [Windows Service](/tags/#windows-service), [Create or Modify System Process](/tags/#create-or-modify-system-process), [Process Injection](/tags/#process-injection), [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Regsvr32](/tags/#regsvr32), [Rundll32](/tags/#rundll32), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism), [Masquerading](/tags/#masquerading), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Rename System Utilities](/tags/#rename-system-utilities), [MSBuild](/tags/#msbuild) | [Collection](/tags/#collection), [Defense Evasion](/tags/#defense-evasion), [Execution](/tags/#execution), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | -| [ColdRoot MacOS RAT](coldroot_macos_rat) | None | None | -| [Collection and Staging](collection_and_staging) | [Masquerading](/tags/#masquerading), [Archive via Utility](/tags/#archive-via-utility), [Archive Collected Data](/tags/#archive-collected-data), [Email Collection](/tags/#email-collection), [Local Email Collection](/tags/#local-email-collection), [Remote Email Collection](/tags/#remote-email-collection) | [Collection](/tags/#collection), [Defense Evasion](/tags/#defense-evasion) | -| [Command and Control](command_and_control) | [Exfiltration Over Unencrypted Non-C2 Protocol](/tags/#exfiltration-over-unencrypted-non-c2-protocol), [DNS](/tags/#dns), [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol), [Non-Application Layer Protocol](/tags/#non-application-layer-protocol), [Application Layer Protocol](/tags/#application-layer-protocol), [Web Protocols](/tags/#web-protocols), [Drive-by Compromise](/tags/#drive-by-compromise) | [Command And Control](/tags/#command-and-control), [Exfiltration](/tags/#exfiltration), [Initial Access](/tags/#initial-access) | -| [Common Phishing Frameworks](common_phishing_frameworks) | [Spearphishing via Service](/tags/#spearphishing-via-service) | [Initial Access](/tags/#initial-access) | -| [Container Implantation Monitoring and Investigation](container_implantation_monitoring_and_investigation) | None | None | -| [Credential Dumping](credential_dumping) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping), [Security Account Manager](/tags/#security-account-manager), [NTDS](/tags/#ntds), [Modify Registry](/tags/#modify-registry), [Local Accounts](/tags/#local-accounts), [Credentials In Files](/tags/#credentials-in-files), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell) | [Credential Access](/tags/#credential-access), [Defense Evasion](/tags/#defense-evasion), [Execution](/tags/#execution), [Initial Access](/tags/#initial-access), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | -| [CyclopsBLink](cyclopsblink) | [Disable or Modify System Firewall](/tags/#disable-or-modify-system-firewall), [Impair Defenses](/tags/#impair-defenses), [Masquerade Task or Service](/tags/#masquerade-task-or-service), [Masquerading](/tags/#masquerading) | [Defense Evasion](/tags/#defense-evasion) | -| [DHS Report TA18-074A](dhs_report_ta18-074a) | [PowerShell](/tags/#powershell), [Windows Command Shell](/tags/#windows-command-shell), [Local Account](/tags/#local-account), [Create Account](/tags/#create-account), [Remote Services](/tags/#remote-services), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares), [System Services](/tags/#system-services), [Service Execution](/tags/#service-execution), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Disable or Modify System Firewall](/tags/#disable-or-modify-system-firewall), [Impair Defenses](/tags/#impair-defenses), [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution), [Windows Service](/tags/#windows-service), [Create or Modify System Process](/tags/#create-or-modify-system-process), [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job), [User Execution](/tags/#user-execution), [Malicious File](/tags/#malicious-file), [Modify Registry](/tags/#modify-registry), [File Transfer Protocols](/tags/#file-transfer-protocols), [Application Layer Protocol](/tags/#application-layer-protocol) | [Command And Control](/tags/#command-and-control), [Defense Evasion](/tags/#defense-evasion), [Execution](/tags/#execution), [Lateral Movement](/tags/#lateral-movement), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | -| [DNS Amplification Attacks](dns_amplification_attacks) | [Network Denial of Service](/tags/#network-denial-of-service), [Reflection Amplification](/tags/#reflection-amplification) | [Impact](/tags/#impact) | -| [DNS Hijacking](dns_hijacking) | [Exfiltration Over Unencrypted Non-C2 Protocol](/tags/#exfiltration-over-unencrypted-non-c2-protocol), [DNS](/tags/#dns), [Drive-by Compromise](/tags/#drive-by-compromise) | [Command And Control](/tags/#command-and-control), [Exfiltration](/tags/#exfiltration), [Initial Access](/tags/#initial-access) | -| [DarkCrystal RAT](darkcrystal_rat) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell), [Ingress Tool Transfer](/tags/#ingress-tool-transfer), [Windows Command Shell](/tags/#windows-command-shell), [Masquerading](/tags/#masquerading), [Obfuscated Files or Information](/tags/#obfuscated-files-or-information), [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment), [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Mshta](/tags/#mshta), [Create or Modify System Process](/tags/#create-or-modify-system-process), [IP Addresses](/tags/#ip-addresses), [Gather Victim Network Information](/tags/#gather-victim-network-information), [Data Destruction](/tags/#data-destruction), [System Shutdown/Reboot](/tags/#system-shutdown/reboot), [System Time Discovery](/tags/#system-time-discovery) | [Command And Control](/tags/#command-and-control), [Defense Evasion](/tags/#defense-evasion), [Discovery](/tags/#discovery), [Execution](/tags/#execution), [Impact](/tags/#impact), [Initial Access](/tags/#initial-access), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation), [Reconnaissance](/tags/#reconnaissance) | -| [DarkSide Ransomware](darkside_ransomware) | [Security Account Manager](/tags/#security-account-manager), [OS Credential Dumping](/tags/#os-credential-dumping), [BITS Jobs](/tags/#bits-jobs), [Ingress Tool Transfer](/tags/#ingress-tool-transfer), [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [CMSTP](/tags/#cmstp), [Process Injection](/tags/#process-injection), [Inhibit System Recovery](/tags/#inhibit-system-recovery), [LSASS Memory](/tags/#lsass-memory), [Remote Services](/tags/#remote-services), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares), [Automated Exfiltration](/tags/#automated-exfiltration), [System Services](/tags/#system-services), [Service Execution](/tags/#service-execution), [Data Encrypted for Impact](/tags/#data-encrypted-for-impact), [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | [Command And Control](/tags/#command-and-control), [Credential Access](/tags/#credential-access), [Defense Evasion](/tags/#defense-evasion), [Execution](/tags/#execution), [Exfiltration](/tags/#exfiltration), [Impact](/tags/#impact), [Lateral Movement](/tags/#lateral-movement), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | -| [Data Destruction](data_destruction) | [Windows Command Shell](/tags/#windows-command-shell), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Remote Services](/tags/#remote-services), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares), [Masquerading](/tags/#masquerading), [Data Destruction](/tags/#data-destruction), [File Deletion](/tags/#file-deletion), [Indicator Removal on Host](/tags/#indicator-removal-on-host), [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Regsvr32](/tags/#regsvr32), [Create or Modify System Process](/tags/#create-or-modify-system-process), [Modify Registry](/tags/#modify-registry), [Disk Structure Wipe](/tags/#disk-structure-wipe), [Disk Wipe](/tags/#disk-wipe) | [Defense Evasion](/tags/#defense-evasion), [Execution](/tags/#execution), [Impact](/tags/#impact), [Lateral Movement](/tags/#lateral-movement), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | -| [Data Exfiltration](data_exfiltration) | [Transfer Data to Cloud Account](/tags/#transfer-data-to-cloud-account), [Email Collection](/tags/#email-collection), [Email Forwarding Rule](/tags/#email-forwarding-rule), [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol), [Local Email Collection](/tags/#local-email-collection), [Phishing](/tags/#phishing), [Exfiltration Over C2 Channel](/tags/#exfiltration-over-c2-channel), [Exfiltration Over Unencrypted Non-C2 Protocol](/tags/#exfiltration-over-unencrypted-non-c2-protocol) | [Collection](/tags/#collection), [Exfiltration](/tags/#exfiltration), [Initial Access](/tags/#initial-access) | -| [Data Protection](data_protection) | [Exfiltration Over Unencrypted Non-C2 Protocol](/tags/#exfiltration-over-unencrypted-non-c2-protocol), [Drive-by Compromise](/tags/#drive-by-compromise) | [Exfiltration](/tags/#exfiltration), [Initial Access](/tags/#initial-access) | -| [Deobfuscate-Decode Files or Information](deobfuscate-decode_files_or_information) | [Deobfuscate/Decode Files or Information](/tags/#deobfuscate/decode-files-or-information) | [Defense Evasion](/tags/#defense-evasion) | -| [Detect Zerologon Attack](detect_zerologon_attack) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping), [Exploitation of Remote Services](/tags/#exploitation-of-remote-services), [Exploit Public-Facing Application](/tags/#exploit-public-facing-application) | [Credential Access](/tags/#credential-access), [Initial Access](/tags/#initial-access), [Lateral Movement](/tags/#lateral-movement) | -| [Dev Sec Ops](dev_sec_ops) | [Malicious Image](/tags/#malicious-image), [User Execution](/tags/#user-execution), [Compromise Client Software Binary](/tags/#compromise-client-software-binary), [Compromise Software Supply Chain](/tags/#compromise-software-supply-chain), [Supply Chain Compromise](/tags/#supply-chain-compromise), [Trusted Relationship](/tags/#trusted-relationship), [Compromise Software Dependencies and Development Tools](/tags/#compromise-software-dependencies-and-development-tools), [Exfiltration to Cloud Storage](/tags/#exfiltration-to-cloud-storage), [Exfiltration Over Web Service](/tags/#exfiltration-over-web-service), [Spearphishing Attachment](/tags/#spearphishing-attachment), [Phishing](/tags/#phishing), [Exfiltration Over Unencrypted Non-C2 Protocol](/tags/#exfiltration-over-unencrypted-non-c2-protocol), [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol), [Exploitation for Credential Access](/tags/#exploitation-for-credential-access), [Cloud Service Discovery](/tags/#cloud-service-discovery) | [Credential Access](/tags/#credential-access), [Discovery](/tags/#discovery), [Execution](/tags/#execution), [Exfiltration](/tags/#exfiltration), [Initial Access](/tags/#initial-access), [Persistence](/tags/#persistence) | -| [Disabling Security Tools](disabling_security_tools) | [Install Root Certificate](/tags/#install-root-certificate), [Subvert Trust Controls](/tags/#subvert-trust-controls), [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses), [Disable or Modify System Firewall](/tags/#disable-or-modify-system-firewall), [Windows Service](/tags/#windows-service), [Create or Modify System Process](/tags/#create-or-modify-system-process), [Modify Registry](/tags/#modify-registry) | [Defense Evasion](/tags/#defense-evasion), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | -| [Domain Trust Discovery](domain_trust_discovery) | [Domain Trust Discovery](/tags/#domain-trust-discovery), [Remote System Discovery](/tags/#remote-system-discovery) | [Discovery](/tags/#discovery) | -| [Double Zero Destructor](double_zero_destructor) | [Masquerading](/tags/#masquerading), [Create or Modify System Process](/tags/#create-or-modify-system-process), [Modify Registry](/tags/#modify-registry), [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | [Defense Evasion](/tags/#defense-evasion), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | -| [Dynamic DNS](dynamic_dns) | [Web Protocols](/tags/#web-protocols), [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol), [Drive-by Compromise](/tags/#drive-by-compromise) | [Command And Control](/tags/#command-and-control), [Exfiltration](/tags/#exfiltration), [Initial Access](/tags/#initial-access) | -| [Emotet Malware DHS Report TA18-201A ](emotet_malware__dhs_report_ta18-201a_) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Windows Command Shell](/tags/#windows-command-shell), [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution), [Spearphishing Attachment](/tags/#spearphishing-attachment), [Phishing](/tags/#phishing), [Software Deployment Tools](/tags/#software-deployment-tools), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares), [Remote Services](/tags/#remote-services) | [Execution](/tags/#execution), [Initial Access](/tags/#initial-access), [Lateral Movement](/tags/#lateral-movement), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | -| [F5 BIG-IP Vulnerability CVE-2022-1388](f5_big-ip_vulnerability_cve-2022-1388) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application) | [Initial Access](/tags/#initial-access) | -| [F5 TMUI RCE CVE-2020-5902](f5_tmui_rce_cve-2020-5902) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application) | [Initial Access](/tags/#initial-access) | -| [FIN7](fin7) | [System Owner/User Discovery](/tags/#system-owner/user-discovery), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [JavaScript](/tags/#javascript), [Credentials from Password Stores](/tags/#credentials-from-password-stores), [Credentials from Web Browsers](/tags/#credentials-from-web-browsers), [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment), [Visual Basic](/tags/#visual-basic), [Process Injection](/tags/#process-injection), [Create or Modify System Process](/tags/#create-or-modify-system-process), [Parent PID Spoofing](/tags/#parent-pid-spoofing), [Access Token Manipulation](/tags/#access-token-manipulation), [XSL Script Processing](/tags/#xsl-script-processing) | [Credential Access](/tags/#credential-access), [Defense Evasion](/tags/#defense-evasion), [Discovery](/tags/#discovery), [Execution](/tags/#execution), [Initial Access](/tags/#initial-access), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | -| [GCP Cross Account Activity](gcp_cross_account_activity) | [Valid Accounts](/tags/#valid-accounts) | [Defense Evasion](/tags/#defense-evasion), [Initial Access](/tags/#initial-access), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | -| [HAFNIUM Group](hafnium_group) | [LSASS Memory](/tags/#lsass-memory), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell), [Ingress Tool Transfer](/tags/#ingress-tool-transfer), [Server Software Component](/tags/#server-software-component), [Web Shell](/tags/#web-shell), [Exploit Public-Facing Application](/tags/#exploit-public-facing-application), [Local Account](/tags/#local-account), [Create Account](/tags/#create-account), [Remote Services](/tags/#remote-services), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares), [System Services](/tags/#system-services), [Service Execution](/tags/#service-execution), [OS Credential Dumping](/tags/#os-credential-dumping), [NTDS](/tags/#ntds), [Email Collection](/tags/#email-collection), [Remote Email Collection](/tags/#remote-email-collection) | [Collection](/tags/#collection), [Command And Control](/tags/#command-and-control), [Credential Access](/tags/#credential-access), [Execution](/tags/#execution), [Initial Access](/tags/#initial-access), [Lateral Movement](/tags/#lateral-movement), [Persistence](/tags/#persistence) | -| [Hermetic Wiper](hermetic_wiper) | [PowerShell](/tags/#powershell), [Malicious File](/tags/#malicious-file), [Active Setup](/tags/#active-setup), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Ingress Tool Transfer](/tags/#ingress-tool-transfer), [Change Default File Association](/tags/#change-default-file-association), [Event Triggered Execution](/tags/#event-triggered-execution), [Windows Command Shell](/tags/#windows-command-shell), [OS Credential Dumping](/tags/#os-credential-dumping), [Indicator Blocking](/tags/#indicator-blocking), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Impair Defenses](/tags/#impair-defenses), [Remote Services](/tags/#remote-services), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares), [Masquerading](/tags/#masquerading), [Steal or Forge Kerberos Tickets](/tags/#steal-or-forge-kerberos-tickets), [Kerberoasting](/tags/#kerberoasting), [Exploit Public-Facing Application](/tags/#exploit-public-facing-application), [Boot or Logon Initialization Scripts](/tags/#boot-or-logon-initialization-scripts), [Logon Script (Windows)](/tags/#logon-script-(windows)), [Obfuscated Files or Information](/tags/#obfuscated-files-or-information), [DLL Side-Loading](/tags/#dll-side-loading), [Hijack Execution Flow](/tags/#hijack-execution-flow), [Accessibility Features](/tags/#accessibility-features), [Distributed Component Object Model](/tags/#distributed-component-object-model), [Windows Remote Management](/tags/#windows-remote-management), [Windows Management Instrumentation](/tags/#windows-management-instrumentation), [Scheduled Task](/tags/#scheduled-task), [Windows Service](/tags/#windows-service), [MMC](/tags/#mmc), [Indicator Removal from Tools](/tags/#indicator-removal-from-tools), [Component Object Model Hijacking](/tags/#component-object-model-hijacking), [Process Injection](/tags/#process-injection), [Gather Victim Host Information](/tags/#gather-victim-host-information), [Image File Execution Options Injection](/tags/#image-file-execution-options-injection), [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Regsvr32](/tags/#regsvr32), [Access Token Manipulation](/tags/#access-token-manipulation), [Token Impersonation/Theft](/tags/#token-impersonation/theft), [Screensaver](/tags/#screensaver), [Create or Modify System Process](/tags/#create-or-modify-system-process), [Time Providers](/tags/#time-providers), [Server Software Component](/tags/#server-software-component), [Web Shell](/tags/#web-shell), [Data Destruction](/tags/#data-destruction), [Modify Registry](/tags/#modify-registry), [Disk Structure Wipe](/tags/#disk-structure-wipe), [Disk Wipe](/tags/#disk-wipe), [Spearphishing Attachment](/tags/#spearphishing-attachment), [Phishing](/tags/#phishing), [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation), [Print Processors](/tags/#print-processors) | [Command And Control](/tags/#command-and-control), [Credential Access](/tags/#credential-access), [Defense Evasion](/tags/#defense-evasion), [Execution](/tags/#execution), [Impact](/tags/#impact), [Initial Access](/tags/#initial-access), [Lateral Movement](/tags/#lateral-movement), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation), [Reconnaissance](/tags/#reconnaissance) | -| [Hidden Cobra Malware](hidden_cobra_malware) | [PowerShell](/tags/#powershell), [Windows Command Shell](/tags/#windows-command-shell), [Indicator Removal on Host](/tags/#indicator-removal-on-host), [Network Share Connection Removal](/tags/#network-share-connection-removal), [Remote Desktop Protocol](/tags/#remote-desktop-protocol), [Remote Services](/tags/#remote-services), [File Transfer Protocols](/tags/#file-transfer-protocols), [Application Layer Protocol](/tags/#application-layer-protocol), [DNS](/tags/#dns), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares), [Exfiltration Over Unencrypted Non-C2 Protocol](/tags/#exfiltration-over-unencrypted-non-c2-protocol), [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol) | [Command And Control](/tags/#command-and-control), [Defense Evasion](/tags/#defense-evasion), [Execution](/tags/#execution), [Exfiltration](/tags/#exfiltration), [Lateral Movement](/tags/#lateral-movement) | -| [Host Redirection](host_redirection) | [Exfiltration Over Unencrypted Non-C2 Protocol](/tags/#exfiltration-over-unencrypted-non-c2-protocol), [DNS](/tags/#dns) | [Command And Control](/tags/#command-and-control), [Exfiltration](/tags/#exfiltration) | -| [IcedID](icedid) | [Domain Account](/tags/#domain-account), [Account Discovery](/tags/#account-discovery), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Windows Command Shell](/tags/#windows-command-shell), [Process Injection](/tags/#process-injection), [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses), [User Execution](/tags/#user-execution), [Malicious File](/tags/#malicious-file), [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism), [Modify Registry](/tags/#modify-registry), [Archive via Utility](/tags/#archive-via-utility), [Archive Collected Data](/tags/#archive-collected-data), [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Mshta](/tags/#mshta), [Domain Trust Discovery](/tags/#domain-trust-discovery), [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment), [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution), [Regsvr32](/tags/#regsvr32), [Rundll32](/tags/#rundll32), [Scheduled Task/Job](/tags/#scheduled-task/job), [Data from Local System](/tags/#data-from-local-system), [Scheduled Task](/tags/#scheduled-task) | [Collection](/tags/#collection), [Defense Evasion](/tags/#defense-evasion), [Discovery](/tags/#discovery), [Execution](/tags/#execution), [Initial Access](/tags/#initial-access), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | -| [Industroyer2](industroyer2) | [Domain Account](/tags/#domain-account), [Account Discovery](/tags/#account-discovery), [Security Account Manager](/tags/#security-account-manager), [OS Credential Dumping](/tags/#os-credential-dumping), [LSASS Memory](/tags/#lsass-memory), [Remote Services](/tags/#remote-services), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares), [Masquerading](/tags/#masquerading), [Distributed Component Object Model](/tags/#distributed-component-object-model), [Windows Management Instrumentation](/tags/#windows-management-instrumentation), [Windows Service](/tags/#windows-service), [Cron](/tags/#cron), [Scheduled Task/Job](/tags/#scheduled-task/job), [Data Destruction](/tags/#data-destruction), [Service Stop](/tags/#service-stop), [File Deletion](/tags/#file-deletion), [Indicator Removal on Host](/tags/#indicator-removal-on-host), [System Network Configuration Discovery](/tags/#system-network-configuration-discovery), [Gather Victim Host Information](/tags/#gather-victim-host-information), [PowerShell](/tags/#powershell), [Create or Modify System Process](/tags/#create-or-modify-system-process), [Scheduled Task](/tags/#scheduled-task), [Disable or Modify System Firewall](/tags/#disable-or-modify-system-firewall), [Impair Defenses](/tags/#impair-defenses) | [Credential Access](/tags/#credential-access), [Defense Evasion](/tags/#defense-evasion), [Discovery](/tags/#discovery), [Execution](/tags/#execution), [Impact](/tags/#impact), [Lateral Movement](/tags/#lateral-movement), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation), [Reconnaissance](/tags/#reconnaissance) | -| [Information Sabotage](information_sabotage) | [Transfer Data to Cloud Account](/tags/#transfer-data-to-cloud-account) | [Exfiltration](/tags/#exfiltration) | -| [Ingress Tool Transfer](ingress_tool_transfer) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell), [Ingress Tool Transfer](/tags/#ingress-tool-transfer), [BITS Jobs](/tags/#bits-jobs) | [Command And Control](/tags/#command-and-control), [Defense Evasion](/tags/#defense-evasion), [Execution](/tags/#execution), [Persistence](/tags/#persistence) | -| [Insider Threat](insider_threat) | [Exfiltration to Cloud Storage](/tags/#exfiltration-to-cloud-storage), [Exfiltration Over Web Service](/tags/#exfiltration-over-web-service), [Exfiltration Over Unencrypted Non-C2 Protocol](/tags/#exfiltration-over-unencrypted-non-c2-protocol), [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol), [Transfer Data to Cloud Account](/tags/#transfer-data-to-cloud-account), [Password Spraying](/tags/#password-spraying), [Brute Force](/tags/#brute-force), [Local Accounts](/tags/#local-accounts), [Credentials In Files](/tags/#credentials-in-files) | [Credential Access](/tags/#credential-access), [Defense Evasion](/tags/#defense-evasion), [Exfiltration](/tags/#exfiltration), [Initial Access](/tags/#initial-access), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | -| [JBoss Vulnerability](jboss_vulnerability) | [System Information Discovery](/tags/#system-information-discovery) | [Discovery](/tags/#discovery) | -| [Kubernetes Scanning Activity](kubernetes_scanning_activity) | [Cloud Service Discovery](/tags/#cloud-service-discovery) | [Discovery](/tags/#discovery) | -| [Kubernetes Sensitive Object Access Activity](kubernetes_sensitive_object_access_activity) | None | None | -| [Kubernetes Sensitive Role Activity](kubernetes_sensitive_role_activity) | None | None | -| [Linux Living Off The Land](linux_living_off_the_land) | [Ingress Tool Transfer](/tags/#ingress-tool-transfer), [Cron](/tags/#cron), [Scheduled Task/Job](/tags/#scheduled-task/job), [At](/tags/#at), [Linux and Mac File and Directory Permissions Modification](/tags/#linux-and-mac-file-and-directory-permissions-modification), [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification), [Clipboard Data](/tags/#clipboard-data), [Setuid and Setgid](/tags/#setuid-and-setgid), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism), [Obfuscated Files or Information](/tags/#obfuscated-files-or-information), [Unix Shell](/tags/#unix-shell), [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation), [SSH Authorized Keys](/tags/#ssh-authorized-keys), [Account Manipulation](/tags/#account-manipulation), [Systemd Timers](/tags/#systemd-timers), [SSH](/tags/#ssh) | [Collection](/tags/#collection), [Command And Control](/tags/#command-and-control), [Defense Evasion](/tags/#defense-evasion), [Execution](/tags/#execution), [Lateral Movement](/tags/#lateral-movement), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | -| [Linux Persistence Techniques](linux_persistence_techniques) | [Cron](/tags/#cron), [Scheduled Task/Job](/tags/#scheduled-task/job), [Local Account](/tags/#local-account), [Create Account](/tags/#create-account), [At](/tags/#at), [Linux and Mac File and Directory Permissions Modification](/tags/#linux-and-mac-file-and-directory-permissions-modification), [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification), [Setuid and Setgid](/tags/#setuid-and-setgid), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism), [Sudo and Sudo Caching](/tags/#sudo-and-sudo-caching), [Kernel Modules and Extensions](/tags/#kernel-modules-and-extensions), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution), [RC Scripts](/tags/#rc-scripts), [Boot or Logon Initialization Scripts](/tags/#boot-or-logon-initialization-scripts), [Unix Shell Configuration Modification](/tags/#unix-shell-configuration-modification), [Event Triggered Execution](/tags/#event-triggered-execution), [SSH Authorized Keys](/tags/#ssh-authorized-keys), [Account Manipulation](/tags/#account-manipulation), [/etc/passwd and /etc/shadow](/tags/#/etc/passwd-and-/etc/shadow), [OS Credential Dumping](/tags/#os-credential-dumping), [Dynamic Linker Hijacking](/tags/#dynamic-linker-hijacking), [Hijack Execution Flow](/tags/#hijack-execution-flow), [Systemd Timers](/tags/#systemd-timers), [Data Destruction](/tags/#data-destruction) | [Credential Access](/tags/#credential-access), [Defense Evasion](/tags/#defense-evasion), [Execution](/tags/#execution), [Impact](/tags/#impact), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | -| [Linux Post-Exploitation](linux_post-exploitation) | [Unix Shell](/tags/#unix-shell) | [Execution](/tags/#execution) | -| [Linux Privilege Escalation](linux_privilege_escalation) | [Cron](/tags/#cron), [Scheduled Task/Job](/tags/#scheduled-task/job), [Local Account](/tags/#local-account), [Create Account](/tags/#create-account), [At](/tags/#at), [Linux and Mac File and Directory Permissions Modification](/tags/#linux-and-mac-file-and-directory-permissions-modification), [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification), [Setuid and Setgid](/tags/#setuid-and-setgid), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism), [Sudo and Sudo Caching](/tags/#sudo-and-sudo-caching), [Kernel Modules and Extensions](/tags/#kernel-modules-and-extensions), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution), [RC Scripts](/tags/#rc-scripts), [Boot or Logon Initialization Scripts](/tags/#boot-or-logon-initialization-scripts), [Unix Shell Configuration Modification](/tags/#unix-shell-configuration-modification), [Event Triggered Execution](/tags/#event-triggered-execution), [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation), [SSH Authorized Keys](/tags/#ssh-authorized-keys), [Account Manipulation](/tags/#account-manipulation), [/etc/passwd and /etc/shadow](/tags/#/etc/passwd-and-/etc/shadow), [OS Credential Dumping](/tags/#os-credential-dumping), [Dynamic Linker Hijacking](/tags/#dynamic-linker-hijacking), [Hijack Execution Flow](/tags/#hijack-execution-flow), [Systemd Timers](/tags/#systemd-timers), [Data Destruction](/tags/#data-destruction) | [Credential Access](/tags/#credential-access), [Defense Evasion](/tags/#defense-evasion), [Execution](/tags/#execution), [Impact](/tags/#impact), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | -| [Linux Rootkit](linux_rootkit) | [Kernel Modules and Extensions](/tags/#kernel-modules-and-extensions), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution), [System Information Discovery](/tags/#system-information-discovery), [Rootkit](/tags/#rootkit) | [Defense Evasion](/tags/#defense-evasion), [Discovery](/tags/#discovery), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | -| [Living Off The Land](living_off_the_land) | [BITS Jobs](/tags/#bits-jobs), [Ingress Tool Transfer](/tags/#ingress-tool-transfer), [Deobfuscate/Decode Files or Information](/tags/#deobfuscate/decode-files-or-information), [Windows Command Shell](/tags/#windows-command-shell), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Control Panel](/tags/#control-panel), [NTDS](/tags/#ntds), [OS Credential Dumping](/tags/#os-credential-dumping), [Compiled HTML File](/tags/#compiled-html-file), [Mshta](/tags/#mshta), [Regsvcs/Regasm](/tags/#regsvcs/regasm), [Regsvr32](/tags/#regsvr32), [Rundll32](/tags/#rundll32), [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses), [LSASS Memory](/tags/#lsass-memory), [Security Account Manager](/tags/#security-account-manager), [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism), [Exploit Public-Facing Application](/tags/#exploit-public-facing-application), [Unix Shell](/tags/#unix-shell), [Plist File Modification](/tags/#plist-file-modification), [Remote Services](/tags/#remote-services), [Distributed Component Object Model](/tags/#distributed-component-object-model), [MMC](/tags/#mmc), [Services Registry Permissions Weakness](/tags/#services-registry-permissions-weakness), [Hijack Execution Flow](/tags/#hijack-execution-flow), [Windows Management Instrumentation](/tags/#windows-management-instrumentation), [Process Injection](/tags/#process-injection), [Modify Registry](/tags/#modify-registry), [Scheduled Task/Job](/tags/#scheduled-task/job), [At](/tags/#at), [Scheduled Task](/tags/#scheduled-task), [Create or Modify System Process](/tags/#create-or-modify-system-process), [Windows Service](/tags/#windows-service), [Masquerading](/tags/#masquerading), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Rename System Utilities](/tags/#rename-system-utilities), [MSBuild](/tags/#msbuild), [Mavinject](/tags/#mavinject), [Indirect Command Execution](/tags/#indirect-command-execution), [InstallUtil](/tags/#installutil), [Windows Management Instrumentation Event Subscription](/tags/#windows-management-instrumentation-event-subscription), [Odbcconf](/tags/#odbcconf) | [Command And Control](/tags/#command-and-control), [Credential Access](/tags/#credential-access), [Defense Evasion](/tags/#defense-evasion), [Execution](/tags/#execution), [Initial Access](/tags/#initial-access), [Lateral Movement](/tags/#lateral-movement), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | -| [Local Privilege Escalation With KrbRelayUp](local_privilege_escalation_with_krbrelayup) | [Steal or Forge Kerberos Tickets](/tags/#steal-or-forge-kerberos-tickets), [Windows Service](/tags/#windows-service) | [Credential Access](/tags/#credential-access), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | -| [Log4Shell CVE-2021-44228](log4shell_cve-2021-44228) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell), [Ingress Tool Transfer](/tags/#ingress-tool-transfer), [Windows Command Shell](/tags/#windows-command-shell), [Exploit Public-Facing Application](/tags/#exploit-public-facing-application) | [Command And Control](/tags/#command-and-control), [Execution](/tags/#execution), [Initial Access](/tags/#initial-access) | -| [Malicious PowerShell](malicious_powershell) | [PowerShell](/tags/#powershell), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Ingress Tool Transfer](/tags/#ingress-tool-transfer), [OS Credential Dumping](/tags/#os-credential-dumping), [Account Discovery](/tags/#account-discovery), [Local Account](/tags/#local-account), [Obfuscated Files or Information](/tags/#obfuscated-files-or-information), [Remote Services](/tags/#remote-services), [Distributed Component Object Model](/tags/#distributed-component-object-model), [Windows Remote Management](/tags/#windows-remote-management), [Windows Management Instrumentation](/tags/#windows-management-instrumentation), [Scheduled Task](/tags/#scheduled-task), [Windows Service](/tags/#windows-service), [MMC](/tags/#mmc), [Indicator Removal from Tools](/tags/#indicator-removal-from-tools), [Component Object Model Hijacking](/tags/#component-object-model-hijacking), [Event Triggered Execution](/tags/#event-triggered-execution), [Process Injection](/tags/#process-injection), [Gather Victim Host Information](/tags/#gather-victim-host-information), [Kerberoasting](/tags/#kerberoasting), [Impair Defenses](/tags/#impair-defenses) | [Command And Control](/tags/#command-and-control), [Credential Access](/tags/#credential-access), [Defense Evasion](/tags/#defense-evasion), [Discovery](/tags/#discovery), [Execution](/tags/#execution), [Lateral Movement](/tags/#lateral-movement), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation), [Reconnaissance](/tags/#reconnaissance) | -| [Masquerading - Rename System Utilities](masquerading_-_rename_system_utilities) | [Rename System Utilities](/tags/#rename-system-utilities), [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Masquerading](/tags/#masquerading), [Rundll32](/tags/#rundll32), [Data Destruction](/tags/#data-destruction), [File Deletion](/tags/#file-deletion), [Indicator Removal on Host](/tags/#indicator-removal-on-host), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [MSBuild](/tags/#msbuild), [InstallUtil](/tags/#installutil) | [Defense Evasion](/tags/#defense-evasion), [Impact](/tags/#impact) | -| [Meterpreter](meterpreter) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter) | [Execution](/tags/#execution) | -| [Microsoft MSHTML Remote Code Execution CVE-2021-40444](microsoft_mshtml_remote_code_execution_cve-2021-40444) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Control Panel](/tags/#control-panel), [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment), [Rundll32](/tags/#rundll32) | [Defense Evasion](/tags/#defense-evasion), [Initial Access](/tags/#initial-access) | -| [Microsoft Support Diagnostic Tool Vulnerability CVE-2022-30190](microsoft_support_diagnostic_tool_vulnerability_cve-2022-30190) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | [Defense Evasion](/tags/#defense-evasion), [Execution](/tags/#execution), [Initial Access](/tags/#initial-access) | -| [Monitor Backup Solution](monitor_backup_solution) | None | None | -| [Monitor for Unauthorized Software](monitor_for_unauthorized_software) | [Match Legitimate Name or Location](/tags/#match-legitimate-name-or-location), [Masquerading](/tags/#masquerading), [OS Credential Dumping](/tags/#os-credential-dumping), [Active Scanning](/tags/#active-scanning) | [Credential Access](/tags/#credential-access), [Defense Evasion](/tags/#defense-evasion), [Reconnaissance](/tags/#reconnaissance) | -| [Monitor for Updates](monitor_for_updates) | None | None | -| [NOBELIUM Group](nobelium_group) | [Archive via Utility](/tags/#archive-via-utility), [Archive Collected Data](/tags/#archive-collected-data), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Windows Command Shell](/tags/#windows-command-shell), [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Mshta](/tags/#mshta), [Obfuscated Files or Information](/tags/#obfuscated-files-or-information), [Windows Service](/tags/#windows-service), [Create or Modify System Process](/tags/#create-or-modify-system-process), [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job), [Remote System Discovery](/tags/#remote-system-discovery), [System Services](/tags/#system-services), [Service Execution](/tags/#service-execution), [Exploitation for Client Execution](/tags/#exploitation-for-client-execution), [File Transfer Protocols](/tags/#file-transfer-protocols), [Application Layer Protocol](/tags/#application-layer-protocol), [Web Protocols](/tags/#web-protocols), [Web Shell](/tags/#web-shell) | [Collection](/tags/#collection), [Command And Control](/tags/#command-and-control), [Defense Evasion](/tags/#defense-evasion), [Discovery](/tags/#discovery), [Execution](/tags/#execution), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | -| [Netsh Abuse](netsh_abuse) | [Disable or Modify System Firewall](/tags/#disable-or-modify-system-firewall), [Impair Defenses](/tags/#impair-defenses) | [Defense Evasion](/tags/#defense-evasion) | -| [Network Discovery](network_discovery) | [System Network Configuration Discovery](/tags/#system-network-configuration-discovery) | [Discovery](/tags/#discovery) | -| [Office 365 Detections](office_365_detections) | [Cloud Account](/tags/#cloud-account), [Create Account](/tags/#create-account), [Disable or Modify Cloud Firewall](/tags/#disable-or-modify-cloud-firewall), [Impair Defenses](/tags/#impair-defenses), [Modify Authentication Process](/tags/#modify-authentication-process), [Brute Force](/tags/#brute-force), [Email Collection](/tags/#email-collection), [Email Forwarding Rule](/tags/#email-forwarding-rule), [Remote Email Collection](/tags/#remote-email-collection), [Password Guessing](/tags/#password-guessing) | [Collection](/tags/#collection), [Credential Access](/tags/#credential-access), [Defense Evasion](/tags/#defense-evasion), [Persistence](/tags/#persistence) | -| [Orangeworm Attack Group](orangeworm_attack_group) | [PowerShell](/tags/#powershell), [Windows Command Shell](/tags/#windows-command-shell), [Windows Service](/tags/#windows-service), [Create or Modify System Process](/tags/#create-or-modify-system-process), [System Services](/tags/#system-services), [Service Execution](/tags/#service-execution) | [Execution](/tags/#execution), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | -| [PetitPotam NTLM Relay on Active Directory Certificate Services](petitpotam_ntlm_relay_on_active_directory_certificate_services) | [Forced Authentication](/tags/#forced-authentication), [OS Credential Dumping](/tags/#os-credential-dumping) | [Credential Access](/tags/#credential-access) | -| [Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns](possible_backdoor_activity_associated_with_mudcarp_espionage_campaigns) | [PowerShell](/tags/#powershell), [Windows Command Shell](/tags/#windows-command-shell), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | [Execution](/tags/#execution), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | -| [PrintNightmare CVE-2021-34527](printnightmare_cve-2021-34527) | [Print Processors](/tags/#print-processors), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution), [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Rundll32](/tags/#rundll32), [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation) | [Defense Evasion](/tags/#defense-evasion), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | -| [Prohibited Traffic Allowed or Protocol Mismatch](prohibited_traffic_allowed_or_protocol_mismatch) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol), [Remote Services](/tags/#remote-services), [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol), [Exfiltration Over Unencrypted Non-C2 Protocol](/tags/#exfiltration-over-unencrypted-non-c2-protocol), [Application Layer Protocol](/tags/#application-layer-protocol), [Web Protocols](/tags/#web-protocols), [Drive-by Compromise](/tags/#drive-by-compromise) | [Command And Control](/tags/#command-and-control), [Exfiltration](/tags/#exfiltration), [Initial Access](/tags/#initial-access), [Lateral Movement](/tags/#lateral-movement) | -| [ProxyShell](proxyshell) | [Server Software Component](/tags/#server-software-component), [Web Shell](/tags/#web-shell), [Exploit Public-Facing Application](/tags/#exploit-public-facing-application), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell) | [Execution](/tags/#execution), [Initial Access](/tags/#initial-access), [Persistence](/tags/#persistence) | -| [Ransomware](ransomware) | [Scheduled Task](/tags/#scheduled-task), [Archive via Utility](/tags/#archive-via-utility), [Archive Collected Data](/tags/#archive-collected-data), [Disable or Modify Cloud Firewall](/tags/#disable-or-modify-cloud-firewall), [Impair Defenses](/tags/#impair-defenses), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism), [Inhibit System Recovery](/tags/#inhibit-system-recovery), [File Deletion](/tags/#file-deletion), [Indicator Removal on Host](/tags/#indicator-removal-on-host), [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [CMSTP](/tags/#cmstp), [Data Destruction](/tags/#data-destruction), [User Execution](/tags/#user-execution), [Automated Exfiltration](/tags/#automated-exfiltration), [Domain Account](/tags/#domain-account), [Local Groups](/tags/#local-groups), [Domain Trust Discovery](/tags/#domain-trust-discovery), [Local Account](/tags/#local-account), [Account Discovery](/tags/#account-discovery), [Domain Groups](/tags/#domain-groups), [Permission Groups Discovery](/tags/#permission-groups-discovery), [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Clear Windows Event Logs](/tags/#clear-windows-event-logs), [Service Stop](/tags/#service-stop), [Account Access Removal](/tags/#account-access-removal), [System Services](/tags/#system-services), [Service Execution](/tags/#service-execution), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Visual Basic](/tags/#visual-basic), [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification), [Defacement](/tags/#defacement), [DLL Side-Loading](/tags/#dll-side-loading), [Hijack Execution Flow](/tags/#hijack-execution-flow), [Obfuscated Files or Information](/tags/#obfuscated-files-or-information), [Indicator Removal from Tools](/tags/#indicator-removal-from-tools), [Component Object Model Hijacking](/tags/#component-object-model-hijacking), [Event Triggered Execution](/tags/#event-triggered-execution), [PowerShell](/tags/#powershell), [Gather Victim Host Information](/tags/#gather-victim-host-information), [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution), [Windows Management Instrumentation](/tags/#windows-management-instrumentation), [Modify Registry](/tags/#modify-registry), [Rundll32](/tags/#rundll32), [Scheduled Task/Job](/tags/#scheduled-task/job), [Masquerading](/tags/#masquerading), [Rename System Utilities](/tags/#rename-system-utilities), [Msiexec](/tags/#msiexec), [Data Encrypted for Impact](/tags/#data-encrypted-for-impact), [InstallUtil](/tags/#installutil), [Tool](/tags/#tool), [Server Software Component](/tags/#server-software-component), [Web Shell](/tags/#web-shell), [Exploit Public-Facing Application](/tags/#exploit-public-facing-application), [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares), [Remote Services](/tags/#remote-services), [Application Layer Protocol](/tags/#application-layer-protocol), [Web Protocols](/tags/#web-protocols) | [Collection](/tags/#collection), [Command And Control](/tags/#command-and-control), [Defense Evasion](/tags/#defense-evasion), [Discovery](/tags/#discovery), [Execution](/tags/#execution), [Exfiltration](/tags/#exfiltration), [Impact](/tags/#impact), [Initial Access](/tags/#initial-access), [Lateral Movement](/tags/#lateral-movement), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation), [Reconnaissance](/tags/#reconnaissance), [Resource Development](/tags/#resource-development) | -| [Ransomware Cloud](ransomware_cloud) | [Data Encrypted for Impact](/tags/#data-encrypted-for-impact) | [Impact](/tags/#impact) | -| [Remcos](remcos) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses), [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism), [Masquerading](/tags/#masquerading), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [JavaScript](/tags/#javascript), [Process Injection](/tags/#process-injection), [Dynamic-link Library Injection](/tags/#dynamic-link-library-injection), [Regsvr32](/tags/#regsvr32), [Modify Registry](/tags/#modify-registry), [Credentials from Password Stores](/tags/#credentials-from-password-stores), [Credentials from Web Browsers](/tags/#credentials-from-web-browsers), [Indicator Removal on Host](/tags/#indicator-removal-on-host), [Component Object Model](/tags/#component-object-model), [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution), [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Screen Capture](/tags/#screen-capture), [Visual Basic](/tags/#visual-basic), [Create or Modify System Process](/tags/#create-or-modify-system-process), [Gather Victim Host Information](/tags/#gather-victim-host-information), [Parent PID Spoofing](/tags/#parent-pid-spoofing), [Access Token Manipulation](/tags/#access-token-manipulation) | [Collection](/tags/#collection), [Credential Access](/tags/#credential-access), [Defense Evasion](/tags/#defense-evasion), [Execution](/tags/#execution), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation), [Reconnaissance](/tags/#reconnaissance) | -| [Revil Ransomware](revil_ransomware) | [Disable or Modify Cloud Firewall](/tags/#disable-or-modify-cloud-firewall), [Impair Defenses](/tags/#impair-defenses), [Inhibit System Recovery](/tags/#inhibit-system-recovery), [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Defacement](/tags/#defacement), [DLL Side-Loading](/tags/#dll-side-loading), [Hijack Execution Flow](/tags/#hijack-execution-flow), [User Execution](/tags/#user-execution), [Modify Registry](/tags/#modify-registry), [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [CMSTP](/tags/#cmstp) | [Defense Evasion](/tags/#defense-evasion), [Execution](/tags/#execution), [Impact](/tags/#impact), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | -| [Router and Infrastructure Security](router_and_infrastructure_security) | [Hardware Additions](/tags/#hardware-additions), [Network Denial of Service](/tags/#network-denial-of-service), [Adversary-in-the-Middle](/tags/#adversary-in-the-middle), [ARP Cache Poisoning](/tags/#arp-cache-poisoning), [TFTP Boot](/tags/#tftp-boot), [Pre-OS Boot](/tags/#pre-os-boot), [Automated Exfiltration](/tags/#automated-exfiltration), [Traffic Duplication](/tags/#traffic-duplication) | [Collection](/tags/#collection), [Credential Access](/tags/#credential-access), [Defense Evasion](/tags/#defense-evasion), [Exfiltration](/tags/#exfiltration), [Impact](/tags/#impact), [Initial Access](/tags/#initial-access), [Persistence](/tags/#persistence) | -| [Ryuk Ransomware](ryuk_ransomware) | [Windows Command Shell](/tags/#windows-command-shell), [Inhibit System Recovery](/tags/#inhibit-system-recovery), [Data Destruction](/tags/#data-destruction), [Domain Trust Discovery](/tags/#domain-trust-discovery), [Data Encrypted for Impact](/tags/#data-encrypted-for-impact), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job), [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses), [Service Stop](/tags/#service-stop), [Remote Desktop Protocol](/tags/#remote-desktop-protocol), [Remote Services](/tags/#remote-services) | [Defense Evasion](/tags/#defense-evasion), [Discovery](/tags/#discovery), [Execution](/tags/#execution), [Impact](/tags/#impact), [Lateral Movement](/tags/#lateral-movement), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | -| [SQL Injection](sql_injection) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application) | [Initial Access](/tags/#initial-access) | -| [SamSam Ransomware](samsam_ransomware) | [Match Legitimate Name or Location](/tags/#match-legitimate-name-or-location), [Masquerading](/tags/#masquerading), [OS Credential Dumping](/tags/#os-credential-dumping), [Active Scanning](/tags/#active-scanning), [User Execution](/tags/#user-execution), [Malicious File](/tags/#malicious-file), [Data Destruction](/tags/#data-destruction), [Inhibit System Recovery](/tags/#inhibit-system-recovery), [Remote Services](/tags/#remote-services), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares), [System Services](/tags/#system-services), [Service Execution](/tags/#service-execution), [Data Encrypted for Impact](/tags/#data-encrypted-for-impact), [Remote Desktop Protocol](/tags/#remote-desktop-protocol), [System Information Discovery](/tags/#system-information-discovery) | [Credential Access](/tags/#credential-access), [Defense Evasion](/tags/#defense-evasion), [Discovery](/tags/#discovery), [Execution](/tags/#execution), [Impact](/tags/#impact), [Lateral Movement](/tags/#lateral-movement), [Reconnaissance](/tags/#reconnaissance) | -| [Signed Binary Proxy Execution InstallUtil](signed_binary_proxy_execution_installutil) | [Masquerading](/tags/#masquerading), [Rename System Utilities](/tags/#rename-system-utilities), [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [InstallUtil](/tags/#installutil) | [Defense Evasion](/tags/#defense-evasion) | -| [Silver Sparrow](silver_sparrow) | [Ingress Tool Transfer](/tags/#ingress-tool-transfer), [Launch Agent](/tags/#launch-agent), [Create or Modify System Process](/tags/#create-or-modify-system-process), [Data Staged](/tags/#data-staged) | [Collection](/tags/#collection), [Command And Control](/tags/#command-and-control), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | -| [Spearphishing Attachments](spearphishing_attachments) | [Security Account Manager](/tags/#security-account-manager), [OS Credential Dumping](/tags/#os-credential-dumping), [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment), [Spearphishing Link](/tags/#spearphishing-link), [Malicious Link](/tags/#malicious-link), [User Execution](/tags/#user-execution) | [Credential Access](/tags/#credential-access), [Execution](/tags/#execution), [Initial Access](/tags/#initial-access) | -| [Spectre And Meltdown Vulnerabilities](spectre_and_meltdown_vulnerabilities) | None | None | -| [Splunk Vulnerabilities](splunk_vulnerabilities) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [File and Directory Discovery](/tags/#file-and-directory-discovery), [Digital Certificates](/tags/#digital-certificates), [Network Denial of Service](/tags/#network-denial-of-service), [Process Injection](/tags/#process-injection), [Protocol Impersonation](/tags/#protocol-impersonation), [Digital Certificates](/tags/#digital-certificates), [Valid Accounts](/tags/#valid-accounts), [Drive-by Compromise](/tags/#drive-by-compromise), [Network Sniffing](/tags/#network-sniffing) | [Command And Control](/tags/#command-and-control), [Credential Access](/tags/#credential-access), [Defense Evasion](/tags/#defense-evasion), [Discovery](/tags/#discovery), [Execution](/tags/#execution), [Impact](/tags/#impact), [Initial Access](/tags/#initial-access), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation), [Resource Development](/tags/#resource-development) | -| [Spring4Shell CVE-2022-22965](spring4shell_cve-2022-22965) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application), [Web Shell](/tags/#web-shell), [Server Software Component](/tags/#server-software-component) | [Initial Access](/tags/#initial-access), [Persistence](/tags/#persistence) | -| [Suspicious AWS EC2 Activities](suspicious_aws_ec2_activities) | [Cloud Accounts](/tags/#cloud-accounts), [Unused/Unsupported Cloud Regions](/tags/#unused/unsupported-cloud-regions) | [Defense Evasion](/tags/#defense-evasion), [Initial Access](/tags/#initial-access), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | -| [Suspicious AWS Login Activities](suspicious_aws_login_activities) | [Unused/Unsupported Cloud Regions](/tags/#unused/unsupported-cloud-regions), [Cloud Accounts](/tags/#cloud-accounts) | [Defense Evasion](/tags/#defense-evasion), [Initial Access](/tags/#initial-access), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | -| [Suspicious AWS S3 Activities](suspicious_aws_s3_activities) | [Data from Cloud Storage Object](/tags/#data-from-cloud-storage-object) | [Collection](/tags/#collection) | -| [Suspicious AWS Traffic](suspicious_aws_traffic) | None | None | -| [Suspicious Cloud Authentication Activities](suspicious_cloud_authentication_activities) | [Unused/Unsupported Cloud Regions](/tags/#unused/unsupported-cloud-regions) | [Defense Evasion](/tags/#defense-evasion) | -| [Suspicious Cloud Instance Activities](suspicious_cloud_instance_activities) | [Cloud Accounts](/tags/#cloud-accounts), [Valid Accounts](/tags/#valid-accounts), [Transfer Data to Cloud Account](/tags/#transfer-data-to-cloud-account) | [Defense Evasion](/tags/#defense-evasion), [Exfiltration](/tags/#exfiltration), [Initial Access](/tags/#initial-access), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | -| [Suspicious Cloud Provisioning Activities](suspicious_cloud_provisioning_activities) | [Valid Accounts](/tags/#valid-accounts) | [Defense Evasion](/tags/#defense-evasion), [Initial Access](/tags/#initial-access), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | -| [Suspicious Cloud User Activities](suspicious_cloud_user_activities) | [Cloud Accounts](/tags/#cloud-accounts), [Valid Accounts](/tags/#valid-accounts), [Cloud Infrastructure Discovery](/tags/#cloud-infrastructure-discovery), [User Execution](/tags/#user-execution) | [Defense Evasion](/tags/#defense-evasion), [Discovery](/tags/#discovery), [Execution](/tags/#execution), [Initial Access](/tags/#initial-access), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | -| [Suspicious Command-Line Executions](suspicious_command-line_executions) | [PowerShell](/tags/#powershell), [Windows Command Shell](/tags/#windows-command-shell), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Masquerading](/tags/#masquerading), [Rename System Utilities](/tags/#rename-system-utilities) | [Defense Evasion](/tags/#defense-evasion), [Execution](/tags/#execution) | -| [Suspicious Compiled HTML Activity](suspicious_compiled_html_activity) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Compiled HTML File](/tags/#compiled-html-file) | [Defense Evasion](/tags/#defense-evasion) | -| [Suspicious DNS Traffic](suspicious_dns_traffic) | [Exfiltration Over Unencrypted Non-C2 Protocol](/tags/#exfiltration-over-unencrypted-non-c2-protocol), [DNS](/tags/#dns), [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol), [Application Layer Protocol](/tags/#application-layer-protocol), [Drive-by Compromise](/tags/#drive-by-compromise) | [Command And Control](/tags/#command-and-control), [Exfiltration](/tags/#exfiltration), [Initial Access](/tags/#initial-access) | -| [Suspicious Emails](suspicious_emails) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | [Initial Access](/tags/#initial-access) | -| [Suspicious GCP Storage Activities](suspicious_gcp_storage_activities) | [Data from Cloud Storage Object](/tags/#data-from-cloud-storage-object) | [Collection](/tags/#collection) | -| [Suspicious MSHTA Activity](suspicious_mshta_activity) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Mshta](/tags/#mshta), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Windows Command Shell](/tags/#windows-command-shell), [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | [Defense Evasion](/tags/#defense-evasion), [Execution](/tags/#execution), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | -| [Suspicious Okta Activity](suspicious_okta_activity) | [Valid Accounts](/tags/#valid-accounts), [Default Accounts](/tags/#default-accounts) | [Defense Evasion](/tags/#defense-evasion), [Initial Access](/tags/#initial-access), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | -| [Suspicious Regsvcs Regasm Activity](suspicious_regsvcs_regasm_activity) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Regsvcs/Regasm](/tags/#regsvcs/regasm) | [Defense Evasion](/tags/#defense-evasion) | -| [Suspicious Regsvr32 Activity](suspicious_regsvr32_activity) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Regsvr32](/tags/#regsvr32), [Modify Registry](/tags/#modify-registry) | [Defense Evasion](/tags/#defense-evasion) | -| [Suspicious Rundll32 Activity](suspicious_rundll32_activity) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Masquerading](/tags/#masquerading), [Rundll32](/tags/#rundll32), [Rename System Utilities](/tags/#rename-system-utilities), [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping) | [Credential Access](/tags/#credential-access), [Defense Evasion](/tags/#defense-evasion) | -| [Suspicious WMI Use](suspicious_wmi_use) | [Windows Management Instrumentation Event Subscription](/tags/#windows-management-instrumentation-event-subscription), [Event Triggered Execution](/tags/#event-triggered-execution), [Windows Management Instrumentation](/tags/#windows-management-instrumentation), [XSL Script Processing](/tags/#xsl-script-processing) | [Defense Evasion](/tags/#defense-evasion), [Execution](/tags/#execution), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | -| [Suspicious Windows Registry Activities](suspicious_windows_registry_activities) | [Hidden Files and Directories](/tags/#hidden-files-and-directories), [Change Default File Association](/tags/#change-default-file-association), [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism), [Port Monitors](/tags/#port-monitors), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution), [Application Shimming](/tags/#application-shimming), [Event Triggered Execution](/tags/#event-triggered-execution), [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder), [Image File Execution Options Injection](/tags/#image-file-execution-options-injection), [Services Registry Permissions Weakness](/tags/#services-registry-permissions-weakness) | [Defense Evasion](/tags/#defense-evasion), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | -| [Suspicious Zoom Child Processes](suspicious_zoom_child_processes) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Windows Command Shell](/tags/#windows-command-shell), [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation) | [Execution](/tags/#execution), [Privilege Escalation](/tags/#privilege-escalation) | -| [Trickbot](trickbot) | [Domain Account](/tags/#domain-account), [Account Discovery](/tags/#account-discovery), [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses), [Process Injection](/tags/#process-injection), [Remote Services](/tags/#remote-services), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares), [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Mshta](/tags/#mshta), [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment), [Scheduled Task/Job](/tags/#scheduled-task/job), [Rundll32](/tags/#rundll32), [Gather Victim Network Information](/tags/#gather-victim-network-information), [IP Addresses](/tags/#ip-addresses), [Obfuscated Files or Information](/tags/#obfuscated-files-or-information), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter) | [Defense Evasion](/tags/#defense-evasion), [Discovery](/tags/#discovery), [Execution](/tags/#execution), [Initial Access](/tags/#initial-access), [Lateral Movement](/tags/#lateral-movement), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation), [Reconnaissance](/tags/#reconnaissance) | -| [Trusted Developer Utilities Proxy Execution](trusted_developer_utilities_proxy_execution) | [Masquerading](/tags/#masquerading), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Rename System Utilities](/tags/#rename-system-utilities) | [Defense Evasion](/tags/#defense-evasion) | -| [Trusted Developer Utilities Proxy Execution MSBuild](trusted_developer_utilities_proxy_execution_msbuild) | [MSBuild](/tags/#msbuild), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Masquerading](/tags/#masquerading), [Rename System Utilities](/tags/#rename-system-utilities) | [Defense Evasion](/tags/#defense-evasion) | -| [Unusual AWS EC2 Modifications](unusual_aws_ec2_modifications) | [Cloud Accounts](/tags/#cloud-accounts) | [Defense Evasion](/tags/#defense-evasion), [Initial Access](/tags/#initial-access), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | -| [Unusual Processes](unusual_processes) | [Malicious File](/tags/#malicious-file), [Match Legitimate Name or Location](/tags/#match-legitimate-name-or-location), [Masquerading](/tags/#masquerading), [OS Credential Dumping](/tags/#os-credential-dumping), [Active Scanning](/tags/#active-scanning), [System Network Configuration Discovery](/tags/#system-network-configuration-discovery), [Modify Registry](/tags/#modify-registry), [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Rundll32](/tags/#rundll32), [Rename System Utilities](/tags/#rename-system-utilities), [Verclsid](/tags/#verclsid), [InstallUtil](/tags/#installutil), [Tool](/tags/#tool), [Process Injection](/tags/#process-injection), [Create or Modify System Process](/tags/#create-or-modify-system-process), [Parent PID Spoofing](/tags/#parent-pid-spoofing), [Access Token Manipulation](/tags/#access-token-manipulation), [Exploit Public-Facing Application](/tags/#exploit-public-facing-application) | [Credential Access](/tags/#credential-access), [Defense Evasion](/tags/#defense-evasion), [Discovery](/tags/#discovery), [Execution](/tags/#execution), [Initial Access](/tags/#initial-access), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation), [Reconnaissance](/tags/#reconnaissance), [Resource Development](/tags/#resource-development) | -| [Use of Cleartext Protocols](use_of_cleartext_protocols) | None | None | -| [VMware Server Side Injection and Privilege Escalation](vmware_server_side_injection_and_privilege_escalation) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application) | [Initial Access](/tags/#initial-access) | -| [Web Fraud Detection](web_fraud_detection) | [Create Account](/tags/#create-account), [Valid Accounts](/tags/#valid-accounts) | [Defense Evasion](/tags/#defense-evasion), [Initial Access](/tags/#initial-access), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | -| [WhisperGate](whispergate) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses), [Windows Command Shell](/tags/#windows-command-shell), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Data Destruction](/tags/#data-destruction), [Masquerading](/tags/#masquerading), [Remote Services](/tags/#remote-services), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares), [Distributed Component Object Model](/tags/#distributed-component-object-model), [Windows Management Instrumentation](/tags/#windows-management-instrumentation), [Windows Service](/tags/#windows-service), [Obfuscated Files or Information](/tags/#obfuscated-files-or-information), [Virtualization/Sandbox Evasion](/tags/#virtualization/sandbox-evasion), [Time Based Evasion](/tags/#time-based-evasion), [Indicator Removal on Host](/tags/#indicator-removal-on-host), [Visual Basic](/tags/#visual-basic), [Create or Modify System Process](/tags/#create-or-modify-system-process), [Rename System Utilities](/tags/#rename-system-utilities), [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [InstallUtil](/tags/#installutil), [Tool](/tags/#tool), [Disk Structure Wipe](/tags/#disk-structure-wipe), [Disk Wipe](/tags/#disk-wipe), [Process Injection](/tags/#process-injection), [Parent PID Spoofing](/tags/#parent-pid-spoofing), [Access Token Manipulation](/tags/#access-token-manipulation) | [Defense Evasion](/tags/#defense-evasion), [Discovery](/tags/#discovery), [Execution](/tags/#execution), [Impact](/tags/#impact), [Lateral Movement](/tags/#lateral-movement), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation), [Resource Development](/tags/#resource-development) | -| [Windows DNS SIGRed CVE-2020-1350](windows_dns_sigred_cve-2020-1350) | [Exploitation for Client Execution](/tags/#exploitation-for-client-execution) | [Execution](/tags/#execution) | -| [Windows Defense Evasion Tactics](windows_defense_evasion_tactics) | [Hidden Files and Directories](/tags/#hidden-files-and-directories), [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses), [Compile After Delivery](/tags/#compile-after-delivery), [Obfuscated Files or Information](/tags/#obfuscated-files-or-information), [Modify Registry](/tags/#modify-registry), [Hide Artifacts](/tags/#hide-artifacts), [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism), [Inhibit System Recovery](/tags/#inhibit-system-recovery), [Disable or Modify System Firewall](/tags/#disable-or-modify-system-firewall), [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification), [Windows File and Directory Permissions Modification](/tags/#windows-file-and-directory-permissions-modification), [MMC](/tags/#mmc), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Process Injection](/tags/#process-injection), [Dynamic-link Library Injection](/tags/#dynamic-link-library-injection), [System Binary Proxy Execution](/tags/#system-binary-proxy-execution) | [Defense Evasion](/tags/#defense-evasion), [Execution](/tags/#execution), [Impact](/tags/#impact), [Privilege Escalation](/tags/#privilege-escalation) | -| [Windows Discovery Techniques](windows_discovery_techniques) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Local Groups](/tags/#local-groups) | [Discovery](/tags/#discovery) | -| [Windows Drivers](windows_drivers) | [Rootkit](/tags/#rootkit), [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation), [Install Root Certificate](/tags/#install-root-certificate), [Subvert Trust Controls](/tags/#subvert-trust-controls), [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution), [Windows Service](/tags/#windows-service), [Create or Modify System Process](/tags/#create-or-modify-system-process) | [Defense Evasion](/tags/#defense-evasion), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | -| [Windows File Extension and Association Abuse](windows_file_extension_and_association_abuse) | [Rename System Utilities](/tags/#rename-system-utilities), [Change Default File Association](/tags/#change-default-file-association), [Masquerading](/tags/#masquerading) | [Defense Evasion](/tags/#defense-evasion), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | -| [Windows Log Manipulation](windows_log_manipulation) | [Inhibit System Recovery](/tags/#inhibit-system-recovery), [Indicator Removal on Host](/tags/#indicator-removal-on-host), [Clear Windows Event Logs](/tags/#clear-windows-event-logs) | [Defense Evasion](/tags/#defense-evasion), [Impact](/tags/#impact) | -| [Windows Persistence Techniques](windows_persistence_techniques) | [Hidden Files and Directories](/tags/#hidden-files-and-directories), [Active Setup](/tags/#active-setup), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution), [Change Default File Association](/tags/#change-default-file-association), [Event Triggered Execution](/tags/#event-triggered-execution), [Path Interception by Unquoted Path](/tags/#path-interception-by-unquoted-path), [Hijack Execution Flow](/tags/#hijack-execution-flow), [Indicator Blocking](/tags/#indicator-blocking), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Impair Defenses](/tags/#impair-defenses), [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification), [Windows File and Directory Permissions Modification](/tags/#windows-file-and-directory-permissions-modification), [Boot or Logon Initialization Scripts](/tags/#boot-or-logon-initialization-scripts), [Logon Script (Windows)](/tags/#logon-script-(windows)), [Port Monitors](/tags/#port-monitors), [Services Registry Permissions Weakness](/tags/#services-registry-permissions-weakness), [Application Shimming](/tags/#application-shimming), [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder), [Windows Service](/tags/#windows-service), [Create or Modify System Process](/tags/#create-or-modify-system-process), [Scheduled Task/Job](/tags/#scheduled-task/job), [Scheduled Task](/tags/#scheduled-task), [Screensaver](/tags/#screensaver), [Time Providers](/tags/#time-providers), [Print Processors](/tags/#print-processors) | [Defense Evasion](/tags/#defense-evasion), [Execution](/tags/#execution), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | -| [Windows Privilege Escalation](windows_privilege_escalation) | [Malicious File](/tags/#malicious-file), [Active Setup](/tags/#active-setup), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution), [Change Default File Association](/tags/#change-default-file-association), [Event Triggered Execution](/tags/#event-triggered-execution), [Indicator Blocking](/tags/#indicator-blocking), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Impair Defenses](/tags/#impair-defenses), [Steal or Forge Kerberos Tickets](/tags/#steal-or-forge-kerberos-tickets), [Kerberoasting](/tags/#kerberoasting), [Boot or Logon Initialization Scripts](/tags/#boot-or-logon-initialization-scripts), [Logon Script (Windows)](/tags/#logon-script-(windows)), [DLL Side-Loading](/tags/#dll-side-loading), [Hijack Execution Flow](/tags/#hijack-execution-flow), [Accessibility Features](/tags/#accessibility-features), [Image File Execution Options Injection](/tags/#image-file-execution-options-injection), [Access Token Manipulation](/tags/#access-token-manipulation), [Token Impersonation/Theft](/tags/#token-impersonation/theft), [Screensaver](/tags/#screensaver), [Time Providers](/tags/#time-providers), [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation), [Print Processors](/tags/#print-processors) | [Credential Access](/tags/#credential-access), [Defense Evasion](/tags/#defense-evasion), [Execution](/tags/#execution), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | -| [Windows Registry Abuse](windows_registry_abuse) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol), [Remote Services](/tags/#remote-services), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism), [Security Account Manager](/tags/#security-account-manager), [OS Credential Dumping](/tags/#os-credential-dumping), [Credentials in Registry](/tags/#credentials-in-registry), [Unsecured Credentials](/tags/#unsecured-credentials), [Change Default File Association](/tags/#change-default-file-association), [Event Triggered Execution](/tags/#event-triggered-execution), [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses), [Modify Registry](/tags/#modify-registry), [Hidden Files and Directories](/tags/#hidden-files-and-directories), [Hide Artifacts](/tags/#hide-artifacts), [Bypass User Account Control](/tags/#bypass-user-account-control), [Inhibit System Recovery](/tags/#inhibit-system-recovery), [Indicator Blocking](/tags/#indicator-blocking), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Defacement](/tags/#defacement), [Port Monitors](/tags/#port-monitors), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution), [Application Shimming](/tags/#application-shimming), [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder), [Image File Execution Options Injection](/tags/#image-file-execution-options-injection), [Screensaver](/tags/#screensaver), [Time Providers](/tags/#time-providers), [Data Destruction](/tags/#data-destruction), [Install Root Certificate](/tags/#install-root-certificate), [Subvert Trust Controls](/tags/#subvert-trust-controls), [Scheduled Task](/tags/#scheduled-task), [Services Registry Permissions Weakness](/tags/#services-registry-permissions-weakness) | [Credential Access](/tags/#credential-access), [Defense Evasion](/tags/#defense-evasion), [Execution](/tags/#execution), [Impact](/tags/#impact), [Lateral Movement](/tags/#lateral-movement), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | -| [Windows Service Abuse](windows_service_abuse) | [Services Registry Permissions Weakness](/tags/#services-registry-permissions-weakness), [Hijack Execution Flow](/tags/#hijack-execution-flow), [Windows Service](/tags/#windows-service), [Create or Modify System Process](/tags/#create-or-modify-system-process), [System Services](/tags/#system-services), [Service Execution](/tags/#service-execution) | [Defense Evasion](/tags/#defense-evasion), [Execution](/tags/#execution), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | -| [Windows System Binary Proxy Execution MSIExec](windows_system_binary_proxy_execution_msiexec) | [Msiexec](/tags/#msiexec) | [Defense Evasion](/tags/#defense-evasion) | -| [XMRig](xmrig) | [Match Legitimate Name or Location](/tags/#match-legitimate-name-or-location), [Masquerading](/tags/#masquerading), [OS Credential Dumping](/tags/#os-credential-dumping), [Active Scanning](/tags/#active-scanning), [Account Access Removal](/tags/#account-access-removal), [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses), [Ingress Tool Transfer](/tags/#ingress-tool-transfer), [Account Discovery](/tags/#account-discovery), [Service Stop](/tags/#service-stop), [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification), [Scheduled Task/Job](/tags/#scheduled-task/job), [Windows Service](/tags/#windows-service), [Create or Modify System Process](/tags/#create-or-modify-system-process) | [Command And Control](/tags/#command-and-control), [Credential Access](/tags/#credential-access), [Defense Evasion](/tags/#defense-evasion), [Discovery](/tags/#discovery), [Execution](/tags/#execution), [Impact](/tags/#impact), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation), [Reconnaissance](/tags/#reconnaissance) | -| [sAMAccountName Spoofing and Domain Controller Impersonation](samaccountname_spoofing_and_domain_controller_impersonation) | [Valid Accounts](/tags/#valid-accounts), [Domain Accounts](/tags/#domain-accounts) | [Defense Evasion](/tags/#defense-evasion), [Initial Access](/tags/#initial-access), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) | \ No newline at end of file diff --git a/docs/_pages/tag-archive.md b/docs/_pages/tag-archive.md deleted file mode 100644 index 72c6dcbe01..0000000000 --- a/docs/_pages/tag-archive.md +++ /dev/null @@ -1,6 +0,0 @@ ---- -title: "Content by Tag" -permalink: /tags/ -layout: tags -author_profile: false ---- diff --git a/docs/_pages/ueba.md b/docs/_pages/ueba.md deleted file mode 100644 index 7fe40b183e..0000000000 --- a/docs/_pages/ueba.md +++ /dev/null @@ -1,9 +0,0 @@ ---- -title: UEBA -layout: tag -author_profile: false -taxonomy: UEBA -permalink: /detections/ueba/ -sidebar: - nav: "detections" ---- \ No newline at end of file diff --git a/docs/_pages/unauthorized_software.md b/docs/_pages/unauthorized_software.md deleted file mode 100644 index ff4ba9d15a..0000000000 --- a/docs/_pages/unauthorized_software.md +++ /dev/null @@ -1,9 +0,0 @@ ---- -title: Unauthorized Software -layout: tag -author_profile: false -taxonomy: Unauthorized Software -permalink: /detections/unauthorized_software/ -sidebar: - nav: "detections" ---- \ No newline at end of file diff --git a/docs/_pages/updates.md b/docs/_pages/updates.md deleted file mode 100644 index 0350a9551e..0000000000 --- a/docs/_pages/updates.md +++ /dev/null @@ -1,9 +0,0 @@ ---- -title: Updates -layout: tag -author_profile: false -taxonomy: Updates -permalink: /detections/updates/ -sidebar: - nav: "detections" ---- \ No newline at end of file diff --git a/docs/_pages/vulnerabilities.md b/docs/_pages/vulnerabilities.md deleted file mode 100644 index ddc8ba1f7e..0000000000 --- a/docs/_pages/vulnerabilities.md +++ /dev/null @@ -1,9 +0,0 @@ ---- -title: Vulnerabilities -layout: tag -author_profile: false -taxonomy: Vulnerabilities -permalink: /detections/vulnerabilities/ -sidebar: - nav: "detections" ---- \ No newline at end of file diff --git a/docs/_pages/vulnerability.md b/docs/_pages/vulnerability.md deleted file mode 100644 index 39843cd0da..0000000000 --- a/docs/_pages/vulnerability.md +++ /dev/null @@ -1,9 +0,0 @@ ---- -title: Vulnerability -layout: tag -author_profile: false -taxonomy: Vulnerability -permalink: /detections/vulnerability/ -sidebar: - nav: "detections" ---- \ No newline at end of file diff --git a/docs/_pages/web.md b/docs/_pages/web.md deleted file mode 100644 index ce69596b2f..0000000000 --- a/docs/_pages/web.md +++ /dev/null @@ -1,9 +0,0 @@ ---- -title: Web -layout: tag -author_profile: false -taxonomy: Web -permalink: /detections/web/ -sidebar: - nav: "detections" ---- \ No newline at end of file diff --git a/docs/_playbooks/active_directory_reset_password.md b/docs/_playbooks/active_directory_reset_password.md deleted file mode 100644 index f1f4cd70d7..0000000000 --- a/docs/_playbooks/active_directory_reset_password.md +++ /dev/null @@ -1,41 +0,0 @@ ---- -title: "Active Directory Reset password" -last_modified_at: 2020-12-08 -toc: true -toc_label: "" -tags: - - Response - - Splunk SOAR - - LDAP ---- - -[Try in Splunk SOAR](https://www.splunk.com/en_us/software/splunk-security-orchestration-and-automation.html){: .btn .btn--success} - -#### Description - -This playbook resets the password of a potentially compromised user account. First, an analyst is prompted to evaluate the situation and choose whether to reset the account. If they approve, a strong password is generated and the password is reset. - -- **Type**: Response -- **Product**: Splunk SOAR -- **Apps**: [LDAP](https://splunkbase.splunk.com/apps/#/search/LDAP/product/soar) -- **Last Updated**: 2020-12-08 -- **Author**: Philip Royer, Splunk -- **ID**: fc0edc96-ff2b-48b0-9f6f-63da6783fd63 - -#### Associated Detections - - -#### How To Implement -This playbook works on artifacts with artifact:*.cef.compromisedUserName which can be created as shown in the playbook "recorded_future_handle_leaked_credentials" - The prompt is hard-coded to use "admin" as the user, so change it to the correct user or role - -#### Playbooks -![](https://raw.githubusercontent.com/splunk/security_content/develop/playbooks/activedirectory_reset_password.png) - -#### Required field - - -#### Reference - - - -[*source*](https://github.com/splunk/security_content/tree/develop/playbooks/active_directory_reset_password.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_playbooks/aws_disable_user_accounts.md b/docs/_playbooks/aws_disable_user_accounts.md deleted file mode 100644 index 195f7c5d3f..0000000000 --- a/docs/_playbooks/aws_disable_user_accounts.md +++ /dev/null @@ -1,45 +0,0 @@ ---- -title: "AWS Disable User Accounts" -last_modified_at: 2021-11-01 -toc: true -toc_label: "" -tags: - - Response - - Splunk SOAR - - AWS IAM - - Cloud ---- - -[Try in Splunk SOAR](https://www.splunk.com/en_us/software/splunk-security-orchestration-and-automation.html){: .btn .btn--success} - -#### Description - -Disable a list of AWS IAM user accounts. After checking the list of accounts against an allowlist and confirming with an analyst, each account is disabled. The change can be reversed with the `enable user` action. - -- **Type**: Response -- **Product**: Splunk SOAR -- **Apps**: [AWS IAM](https://splunkbase.splunk.com/apps/#/search/AWS IAM/product/soar) -- **Last Updated**: 2021-11-01 -- **Author**: Philip Royer, Splunk -- **ID**: fc0edc75-ff2b-48c0-5f6f-63da6423fd63 - -#### Associated Detections - - -#### How To Implement -This playbook works with the community playbook aws_find_inactive_users using the usernames discovered by that playbook. Change the prompt block from admin to the correct analyst user or role. You should create a custom list called aws_inactive_user_allowlist. Any user names in that list will be ignored by this playbook. - -#### Playbooks -![](https://raw.githubusercontent.com/splunk/security_content/develop/playbooks/aws_disable_user_accounts.png) - -#### Required field - - -#### Reference - -* [https://www.splunk.com/en_us/blog/security/splunk-soar-playbooks-finding-and-disabling-inactive-users-on-aws.html](https://www.splunk.com/en_us/blog/security/splunk-soar-playbooks-finding-and-disabling-inactive-users-on-aws.html) - - - - -[*source*](https://github.com/splunk/security_content/tree/develop/playbooks/aws_disable_user_accounts.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_playbooks/aws_find_inactive_users.md b/docs/_playbooks/aws_find_inactive_users.md deleted file mode 100644 index cceaa0afc4..0000000000 --- a/docs/_playbooks/aws_find_inactive_users.md +++ /dev/null @@ -1,46 +0,0 @@ ---- -title: "AWS Find Inactive Users" -last_modified_at: 2021-11-01 -toc: true -toc_label: "" -tags: - - Investigation - - Splunk SOAR - - AWS IAM - - Phantom - - Cloud ---- - -[Try in Splunk SOAR](https://www.splunk.com/en_us/software/splunk-security-orchestration-and-automation.html){: .btn .btn--success} - -#### Description - -Find AWS accounts that have not been used for a long time (90 days by default). For each unused account, gather additional group and policy information and create an artifact to enable further automation or manual action. - -- **Type**: Investigation -- **Product**: Splunk SOAR -- **Apps**: [AWS IAM](https://splunkbase.splunk.com/apps/#/search/AWS IAM/product/soar), [Phantom](https://splunkbase.splunk.com/apps/#/search/Phantom/product/soar) -- **Last Updated**: 2021-11-01 -- **Author**: Philip Royer, Splunk -- **ID**: fc0edc76-ff2b-48b0-5f6f-63da6423fd63 - -#### Associated Detections - - -#### How To Implement -This playbook is meant to run on a Timer, such as once per week. To adjust the lookback period away from the default, change the number of days to a different negative number in the 'calculate_start_time' block. Note that this playbook will ignore accounts where the password has never been used. These could be unused human accounts or they could be API accounts where the access keys are actively used. - -#### Playbooks -![](https://raw.githubusercontent.com/splunk/security_content/develop/playbooks/aws_find_inactive_users.png) - -#### Required field - - -#### Reference - -* [https://www.splunk.com/en_us/blog/security/splunk-soar-playbooks-finding-and-disabling-inactive-users-on-aws.html](https://www.splunk.com/en_us/blog/security/splunk-soar-playbooks-finding-and-disabling-inactive-users-on-aws.html) - - - - -[*source*](https://github.com/splunk/security_content/tree/develop/playbooks/aws_find_inactive_users.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_playbooks/block_indicators.md b/docs/_playbooks/block_indicators.md deleted file mode 100644 index 5864997166..0000000000 --- a/docs/_playbooks/block_indicators.md +++ /dev/null @@ -1,43 +0,0 @@ ---- -title: "Block Indicators" -last_modified_at: 2021-01-21 -toc: true -toc_label: "" -tags: - - Response - - Splunk SOAR - - Palo Alto Networks Firewall - - CarbonBlack Response - - OpenDNS Umbrella ---- - -[Try in Splunk SOAR](https://www.splunk.com/en_us/software/splunk-security-orchestration-and-automation.html){: .btn .btn--success} - -#### Description - -This playbook retrieves IP addresses, domains, and file hashes, blocks them on various services, and adds them to specific blocklists as custom lists. - -- **Type**: Response -- **Product**: Splunk SOAR -- **Apps**: [Palo Alto Networks Firewall](https://splunkbase.splunk.com/apps/#/search/Palo Alto Networks Firewall/product/soar), [CarbonBlack Response](https://splunkbase.splunk.com/apps/#/search/CarbonBlack Response/product/soar), [OpenDNS Umbrella](https://splunkbase.splunk.com/apps/#/search/OpenDNS Umbrella/product/soar) -- **Last Updated**: 2021-01-21 -- **Author**: Philip Royer, Splunk -- **ID**: fc0edc76-ff2b-48b0-5f6f-63da6783fd63 - -#### Associated Detections - - -#### How To Implement -This playbook uses the following custom lists: ip_address_blocklist, domain_blocklist, filehash_blocklist. This playbook provides an easy, automated, and straightforward solution to maintaining up-to-date IP address, file, and domain blocklists. The playbook looks for any of the required CEF fields within the container. The CEF value is then cross-referenced with their respective Custom Lists. IP addresses are blocked on a Firewall, while domains are blocked using a blocklist service. The blocking of these two will prevent access to the IOCs. Finally, file hashes are blocked using an endpoint protection service, which will prevent the process from running on affected endpoints within a network. After the IOCs are blocked using various apps, they are added to their respective custom lists as to maintain a running blocklist record. - -#### Playbooks -![](https://raw.githubusercontent.com/splunk/security_content/develop/playbooks/block_indicators.png) - -#### Required field - - -#### Reference - - - -[*source*](https://github.com/splunk/security_content/tree/develop/playbooks/block_indicators.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_playbooks/crowdstrike_malware_triage.md b/docs/_playbooks/crowdstrike_malware_triage.md deleted file mode 100644 index 00a0c273ca..0000000000 --- a/docs/_playbooks/crowdstrike_malware_triage.md +++ /dev/null @@ -1,41 +0,0 @@ ---- -title: "Crowdstrike Malware Triage" -last_modified_at: 2021-02-25 -toc: true -toc_label: "" -tags: - - Response - - Splunk SOAR - - Crowdstrike OAuth ---- - -[Try in Splunk SOAR](https://www.splunk.com/en_us/software/splunk-security-orchestration-and-automation.html){: .btn .btn--success} - -#### Description - -This playbook is used to enrich and respond to a CrowdStrike Falcon detection involving a potentially malicious executable on an endpoint. Check for previous sightings of the same executable, hunt across other endpoints for the file, gather details about all processes associated with the file, and collect all the gathered information into a prompt for an analyst to review. Based on the analyst's choice, the file can be added to the custom indicators list in CrowdStrike with a detection policy of "detect" or "none", and the endpoint can be optionally quarantined from the network. - -- **Type**: Response -- **Product**: Splunk SOAR -- **Apps**: [Crowdstrike OAuth](https://splunkbase.splunk.com/apps/#/search/Crowdstrike OAuth/product/soar) -- **Last Updated**: 2021-02-25 -- **Author**: Philip Royer, Splunk -- **ID**: fc0edc96-fa2b-48b0-9a6f-63da6783fd63 - -#### Associated Detections - - -#### How To Implement -This playbook uses the Crowdstrike OAuth app. Change the target user of the prompt from admin to the appropriate user or role. - -#### Playbooks -![](https://raw.githubusercontent.com/splunk/security_content/develop/playbooks/crowdstrike_malware_triage.png) - -#### Required field - - -#### Reference - - - -[*source*](https://github.com/splunk/security_content/tree/develop/playbooks/crowdstrike_malware_triage.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_playbooks/delete_detected_files.md b/docs/_playbooks/delete_detected_files.md deleted file mode 100644 index 38f5735950..0000000000 --- a/docs/_playbooks/delete_detected_files.md +++ /dev/null @@ -1,44 +0,0 @@ ---- -title: "Delete Detected Files" -last_modified_at: 2021-03-29 -toc: true -toc_label: "" -tags: - - Response - - Splunk SOAR - - Windows Remote Management ---- - -[Try in Splunk SOAR](https://www.splunk.com/en_us/software/splunk-security-orchestration-and-automation.html){: .btn .btn--success} - -#### Description - -This playbook acts upon events where a file has been determined to be malicious (ie webshells being dropped on an end host). Before deleting the file, we run a "more" command on the file in question to extract its contents. We then run a delete on the file in question. - -- **Type**: Response -- **Product**: Splunk SOAR -- **Apps**: [Windows Remote Management](https://splunkbase.splunk.com/apps/#/search/Windows Remote Management/product/soar) -- **Last Updated**: 2021-03-29 -- **Author**: Philip Royer, Splunk -- **ID**: fc0edc96-ff2b-48b0-9a6f-63da6783fd63 - -#### Associated Detections - -* [Executable File Written in Administrative SMB Share](/detection/executable_file_written_in_administrative_smb_share/) - - - -#### How To Implement -This playbook reads and then deletes files stored with artifact:*.cef.filePath from hosts stored in artifact:*.cef.destinationAddress. Windows Remote Management must be enabled on the remote computer. - -#### Playbooks -![](https://raw.githubusercontent.com/splunk/security_content/develop/playbooks/delete_detected_files.png) - -#### Required field - - -#### Reference - - - -[*source*](https://github.com/splunk/security_content/tree/develop/playbooks/delete_detected_files.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_playbooks/email_notification_for_malware.md b/docs/_playbooks/email_notification_for_malware.md deleted file mode 100644 index 3d6bf851a5..0000000000 --- a/docs/_playbooks/email_notification_for_malware.md +++ /dev/null @@ -1,44 +0,0 @@ ---- -title: "Email Notification for Malware" -last_modified_at: 2021-01-19 -toc: true -toc_label: "" -tags: - - Response - - Splunk SOAR - - VirusTotal - - WildFire - - CarbonBlack Response - - SMTP ---- - -[Try in Splunk SOAR](https://www.splunk.com/en_us/software/splunk-security-orchestration-and-automation.html){: .btn .btn--success} - -#### Description - -This playbook tries to determine if a file is malware and whether or not the file is present on any managed machines. VirusTotal "file reputation" and PAN WildFire "detonate file" are used to determine if a file is malware, and CarbonBlack Response "hunt file" is used to search managed machines for the file. The results of these investigations are summarized in an email to the incident response team. - -- **Type**: Response -- **Product**: Splunk SOAR -- **Apps**: [VirusTotal](https://splunkbase.splunk.com/apps/#/search/VirusTotal/product/soar), [WildFire](https://splunkbase.splunk.com/apps/#/search/WildFire/product/soar), [CarbonBlack Response](https://splunkbase.splunk.com/apps/#/search/CarbonBlack Response/product/soar), [SMTP](https://splunkbase.splunk.com/apps/#/search/SMTP/product/soar) -- **Last Updated**: 2021-01-19 -- **Author**: Philip Royer, Splunk -- **ID**: fb3edc76-ff2b-48b0-5f6f-63da6483fd63 - -#### Associated Detections - - -#### How To Implement -Be sure to update asset naming to reflect the asset names configured in your environment. - -#### Playbooks -![](https://raw.githubusercontent.com/splunk/security_content/develop/playbooks/email_notification_for_malware.png) - -#### Required field - - -#### Reference - - - -[*source*](https://github.com/splunk/security_content/tree/develop/playbooks/email_notification_for_malware.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_playbooks/internal_host_ssh_investigate.md b/docs/_playbooks/internal_host_ssh_investigate.md deleted file mode 100644 index 64b4f3f7f1..0000000000 --- a/docs/_playbooks/internal_host_ssh_investigate.md +++ /dev/null @@ -1,44 +0,0 @@ ---- -title: "Internal Host SSH Investigate" -last_modified_at: 2021-12-14 -toc: true -toc_label: "" -tags: - - Investigation - - Splunk SOAR - - SSH ---- - -[Try in Splunk SOAR](https://www.splunk.com/en_us/software/splunk-security-orchestration-and-automation.html){: .btn .btn--success} - -#### Description - -Investigate an internal unix host using SSH. This pushes a bash script to the endpoint and runs it, collecting generic information about the processes, user activity, and network activity. This includes the process list, login history, cron jobs, and open sockets. The results are zipped up in .csv files and added to the vault for an analyst to review. - -- **Type**: Investigation -- **Product**: Splunk SOAR -- **Apps**: [SSH](https://splunkbase.splunk.com/apps/#/search/SSH/product/soar) -- **Last Updated**: 2021-12-14 -- **Author**: Philip Royer, Splunk -- **ID**: fdb65816-6688-41d8-8698-755b7b4ec44e - -#### Associated Detections - - -#### How To Implement -The ssh asset requires sudo access to view the processes with open sockets. - -#### Playbooks -![](https://raw.githubusercontent.com/splunk/security_content/develop/playbooks/internal_host_ssh_investigate.png) - -#### Required field - - -#### Reference - -* [https://github.com/Neo23x0/Fenrir/blob/master/fenrir.sh](https://github.com/Neo23x0/Fenrir/blob/master/fenrir.sh) - - - - -[*source*](https://github.com/splunk/security_content/tree/develop/playbooks/internal_host_ssh_investigate.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_playbooks/internal_host_ssh_log4j_investigate.md b/docs/_playbooks/internal_host_ssh_log4j_investigate.md deleted file mode 100644 index 4f8560e3e2..0000000000 --- a/docs/_playbooks/internal_host_ssh_log4j_investigate.md +++ /dev/null @@ -1,44 +0,0 @@ ---- -title: "Internal Host SSH Log4j Investigate" -last_modified_at: 2021-12-14 -toc: true -toc_label: "" -tags: - - Investigation - - Splunk SOAR - - SSH ---- - -[Try in Splunk SOAR](https://www.splunk.com/en_us/software/splunk-security-orchestration-and-automation.html){: .btn .btn--success} - -#### Description - -Investigate an internal unix host using SSH. This pushes a bash script to the endpoint and runs it, collecting information specific to the December 2021 log4j vulnerability disclosure. This includes the java version installed on the host, any running java processes, and the results of a scan for the affected JndiLookup.class file or log4j .jar files. - -- **Type**: Investigation -- **Product**: Splunk SOAR -- **Apps**: [SSH](https://splunkbase.splunk.com/apps/#/search/SSH/product/soar) -- **Last Updated**: 2021-12-14 -- **Author**: Philip Royer, Splunk -- **ID**: 49b2b88c-8e22-48a6-8808-ace1efcb194b - -#### Associated Detections - - -#### How To Implement -The ssh asset requires sudo access to scan the whole file system. - -#### Playbooks -![](https://raw.githubusercontent.com/splunk/security_content/develop/playbooks/internal_host_ssh_log4j_investigate.png) - -#### Required field - - -#### Reference - -* [https://github.com/Neo23x0/Fenrir/blob/master/fenrir.sh](https://github.com/Neo23x0/Fenrir/blob/master/fenrir.sh) - - - - -[*source*](https://github.com/splunk/security_content/tree/develop/playbooks/internal_host_ssh_log4j_investigate.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_playbooks/internal_host_ssh_log4j_respond.md b/docs/_playbooks/internal_host_ssh_log4j_respond.md deleted file mode 100644 index e328bbe6f1..0000000000 --- a/docs/_playbooks/internal_host_ssh_log4j_respond.md +++ /dev/null @@ -1,44 +0,0 @@ ---- -title: "Internal Host SSH Log4j Respond" -last_modified_at: 2021-12-14 -toc: true -toc_label: "" -tags: - - Respond - - Splunk SOAR - - SSH ---- - -[Try in Splunk SOAR](https://www.splunk.com/en_us/software/splunk-security-orchestration-and-automation.html){: .btn .btn--success} - -#### Description - -Published in response to CVE-2021-44228, this playbook accepts a list of hosts and filenames to remediate on the endpoint. If filenames are provided, the endpoints will be searched and then the user can approve deletion. Then the user is prompted to quarantine the endpoint. - -- **Type**: Respond -- **Product**: Splunk SOAR -- **Apps**: [SSH](https://splunkbase.splunk.com/apps/#/search/SSH/product/soar) -- **Last Updated**: 2021-12-14 -- **Author**: Kelby Shelton, Splunk -- **ID**: 6ea2007c-8ef8-4647-a4a4-7825cfee3866 - -#### Associated Detections - - -#### How To Implement -The ssh asset may require ssh access to delete some files depending on their permissions. - -#### Playbooks -![](https://raw.githubusercontent.com/splunk/security_content/develop/playbooks/internal_host_ssh_log4j_respond.png) - -#### Required field - - -#### Reference - -* [https://github.com/Neo23x0/Fenrir/blob/master/fenrir.sh](https://github.com/Neo23x0/Fenrir/blob/master/fenrir.sh) - - - - -[*source*](https://github.com/splunk/security_content/tree/develop/playbooks/internal_host_ssh_log4j_respond.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_playbooks/internal_host_ssh_log4j_response.md b/docs/_playbooks/internal_host_ssh_log4j_response.md deleted file mode 100644 index 3ad67f75b1..0000000000 --- a/docs/_playbooks/internal_host_ssh_log4j_response.md +++ /dev/null @@ -1,44 +0,0 @@ ---- -title: "Internal Host SSH Log4j Response" -last_modified_at: 2021-12-14 -toc: true -toc_label: "" -tags: - - Response - - Splunk SOAR - - SSH ---- - -[Try in Splunk SOAR](https://www.splunk.com/en_us/software/splunk-security-orchestration-and-automation.html){: .btn .btn--success} - -#### Description - -Published in response to CVE-2021-44228, this playbook accepts a list of hosts and filenames to remediate on the endpoint. If filenames are provided, the endpoints will be searched and then the user can approve deletion. Then the user is prompted to quarantine the endpoint. - -- **Type**: Response -- **Product**: Splunk SOAR -- **Apps**: [SSH](https://splunkbase.splunk.com/apps/#/search/SSH/product/soar) -- **Last Updated**: 2021-12-14 -- **Author**: Kelby Shelton, Splunk -- **ID**: 6ea2007c-8ef8-4647-a4a4-7825cfee3866 - -#### Associated Detections - - -#### How To Implement -The ssh asset may require ssh access to delete some files depending on their permissions. - -#### Playbooks -![](https://raw.githubusercontent.com/splunk/security_content/develop/playbooks/internal_host_ssh_log4j_respond.png) - -#### Required field - - -#### Reference - -* [https://github.com/Neo23x0/Fenrir/blob/master/fenrir.sh](https://github.com/Neo23x0/Fenrir/blob/master/fenrir.sh) - - - - -[*source*](https://github.com/splunk/security_content/tree/develop/playbooks/internal_host_ssh_log4j_response.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_playbooks/internal_host_winrm_investigate.md b/docs/_playbooks/internal_host_winrm_investigate.md deleted file mode 100644 index cfb6f7d2fd..0000000000 --- a/docs/_playbooks/internal_host_winrm_investigate.md +++ /dev/null @@ -1,41 +0,0 @@ ---- -title: "Internal Host WinRM Investigate" -last_modified_at: 2021-12-14 -toc: true -toc_label: "" -tags: - - Investigation - - Splunk SOAR - - Windows Remote Management ---- - -[Try in Splunk SOAR](https://www.splunk.com/en_us/software/splunk-security-orchestration-and-automation.html){: .btn .btn--success} - -#### Description - -Performs a general investigation on key aspects of a windows device using windows remote management. Important files related to the endpoint are generated, bundled into a zip, and copied to the container vault. - -- **Type**: Investigation -- **Product**: Splunk SOAR -- **Apps**: [Windows Remote Management](https://splunkbase.splunk.com/apps/#/search/Windows Remote Management/product/soar) -- **Last Updated**: 2021-12-14 -- **Author**: Kelby Shelton, Splunk -- **ID**: 32fd9db5-5201-4a2f-b2c2-9299c7b3495d - -#### Associated Detections - - -#### How To Implement -The winrm asset requires Administrator access to gather certain files. - -#### Playbooks -![](https://raw.githubusercontent.com/splunk/security_content/develop/playbooks/internal_host_winrm_investigate.png) - -#### Required field - - -#### Reference - - - -[*source*](https://github.com/splunk/security_content/tree/develop/playbooks/internal_host_winrm_investigate.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_playbooks/internal_host_winrm_log4j_investigate.md b/docs/_playbooks/internal_host_winrm_log4j_investigate.md deleted file mode 100644 index b9b65e7275..0000000000 --- a/docs/_playbooks/internal_host_winrm_log4j_investigate.md +++ /dev/null @@ -1,44 +0,0 @@ ---- -title: "Internal Host WinRM Log4j Investigate" -last_modified_at: 2021-12-14 -toc: true -toc_label: "" -tags: - - Investigation - - Splunk SOAR - - Windows Remote Management ---- - -[Try in Splunk SOAR](https://www.splunk.com/en_us/software/splunk-security-orchestration-and-automation.html){: .btn .btn--success} - -#### Description - -Published in response to CVE-2021-44228, this playbook uses WinRM to scan Windows endpoints for the presence of "jndilookup.class" in all .jar files. The presence of that string could indicate a log4j vulnerability. - -- **Type**: Investigation -- **Product**: Splunk SOAR -- **Apps**: [Windows Remote Management](https://splunkbase.splunk.com/apps/#/search/Windows Remote Management/product/soar) -- **Last Updated**: 2021-12-14 -- **Author**: Kelby Shelton, Splunk -- **ID**: 2cf7c9f4-b273-44f6-a27c-e0db668ff05a - -#### Associated Detections - - -#### How To Implement -The winrm asset requires Administrator access to scan the whole file system. - -#### Playbooks -![](https://raw.githubusercontent.com/splunk/security_content/develop/playbooks/internal_host_winrm_log4j_investigate.png) - -#### Required field - - -#### Reference - -* [https://twitter.com/CyberRaiju/status/1469505677580124160](https://twitter.com/CyberRaiju/status/1469505677580124160) - - - - -[*source*](https://github.com/splunk/security_content/tree/develop/playbooks/internal_host_winrm_log4j_investigate.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_playbooks/internal_host_winrm_response.md b/docs/_playbooks/internal_host_winrm_response.md deleted file mode 100644 index 51bd64f1ab..0000000000 --- a/docs/_playbooks/internal_host_winrm_response.md +++ /dev/null @@ -1,41 +0,0 @@ ---- -title: "Internal Host WinRM Response" -last_modified_at: 2021-12-14 -toc: true -toc_label: "" -tags: - - Response - - Splunk SOAR - - Windows Remote Management ---- - -[Try in Splunk SOAR](https://www.splunk.com/en_us/software/splunk-security-orchestration-and-automation.html){: .btn .btn--success} - -#### Description - -Published in response to CVE-2021-44228, this playbook accepts a list of hosts and filenames to remediate on the endpoint. If filenames are provided, the endpoints will be searched and then the user can approve deletion. Then the user is prompted to quarantine the endpoint. - -- **Type**: Response -- **Product**: Splunk SOAR -- **Apps**: [Windows Remote Management](https://splunkbase.splunk.com/apps/#/search/Windows Remote Management/product/soar) -- **Last Updated**: 2021-12-14 -- **Author**: Kelby Shelton, Splunk -- **ID**: 32fd9db5-5201-4b2f-b2c2-9299c7b3495d - -#### Associated Detections - - -#### How To Implement -The winrm asset requires Administrator access to gather certain files. - -#### Playbooks -![](https://raw.githubusercontent.com/splunk/security_content/develop/playbooks/internal_host_winrm_log4j_respond.png) - -#### Required field - - -#### Reference - - - -[*source*](https://github.com/splunk/security_content/tree/develop/playbooks/internal_host_winrm_response.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_playbooks/log4j_investigate.md b/docs/_playbooks/log4j_investigate.md deleted file mode 100644 index f14e01676f..0000000000 --- a/docs/_playbooks/log4j_investigate.md +++ /dev/null @@ -1,58 +0,0 @@ ---- -title: "Log4j Investigate" -last_modified_at: 2021-12-14 -toc: true -toc_label: "" -tags: - - Investigation - - Splunk SOAR - - Log4J ---- - -[Try in Splunk SOAR](https://www.splunk.com/en_us/software/splunk-security-orchestration-and-automation.html){: .btn .btn--success} - -#### Description - -Published in response to CVE-2021-44228, this playbook and its sub-playbooks can be used to investigate and respond to attacks against hosts running vulnerable Java applications which use log4j. Between the parent playbook and seven sub-playbooks, each potentially compromised host found in Splunk Enteprise can be investigated and the risk can be mitigated using SSH for unix systems and WinRM for Windows systems. - -- **Type**: Investigation -- **Product**: Splunk SOAR -- **Apps**: -- **Last Updated**: 2021-12-14 -- **Author**: Philip Royer, Splunk -- **ID**: e609d729-0076-421a-b8f7-9e545d000381 - -#### Associated Detections - -* [Curl Download and Bash Execution](/detection/curl_download_and_bash_execution/) -* [Wget Download and Bash Execution](/detection/wget_download_and_bash_execution/) -* [Linux Java Spawning Shell](/detection/linux_java_spawning_shell/) -* [Windows Java Spawning Shell](/detection/windows_java_spawning_shell/) -* [Java Class File download by Java User Agent](/detection/java_class_file_download_by_java_user_agent/) -* [Outbound Network Connection from Java Using Default Ports](/detection/outbound_network_connection_from_java_using_default_ports/) -* [Log4Shell JNDI Payload Injection Attempt](/detection/log4shell_jndi_payload_injection_attempt/) -* [Log4Shell JNDI Payload Injection with Outbound Connection](/detection/log4shell_jndi_payload_injection_with_outbound_connection/) -* [Detect Outbound LDAP Traffic](/detection/detect_outbound_ldap_traffic/) - - - -#### How To Implement -To start this playbook, create a custom list called "log4j_hosts" with a format in which the first column should be an IP or hostname of a potentially affected log4j host, the second should be the operating system family (either unix or windows). If the operating system is unknown it can be left blank. In the block called "fetch_hosts_from_custom_list", change the custom list name from "log4j_hosts" if needed. If the operating system family ("windows" or "unix") is not known, both ssh and winrm will be attempted. If ssh and/or winrm are not the preferred endpoint management methods, these playbooks could be ported to use Google's GRR, osquery, CrowdStrike's RTR, Carbon Black's EDR API, or similar tools. The artifact scope "all" is used throughout this playbook because the artifact list can be added to as the playbook progresses. - -#### Playbooks -![](https://raw.githubusercontent.com/splunk/security_content/develop/playbooks/log4j_investigate.png) - -#### Required field - - -#### Reference - -* [https://github.com/Neo23x0/Fenrir/blob/master/fenrir.sh](https://github.com/Neo23x0/Fenrir/blob/master/fenrir.sh) -* [https://isc.sans.edu/diary/Log4j++Log4Shell+Followup%3A+What+we+see+and+how+to+defend+%28and+how+to+access+our+data%29/28122](https://isc.sans.edu/diary/Log4j++Log4Shell+Followup%3A+What+we+see+and+how+to+defend+%28and+how+to+access+our+data%29/28122) -* [https://twitter.com/ElektroWolle/status/1469962895849140224?ref_src=twsrc%5Etfw%7Ctwcamp%5Etweetembed%7Ctwterm%5E1469962895849140224%7Ctwgr%5E%7Ctwcon%5Es1_c10&ref_url=https%3A%2F%2Fpublish.twitter.com%2F%3Fquery%3Dhttps3A2F2Ftwitter.com2FElektroWolle2Fstatus2F1469962895849140224widget%3DTweet](https://twitter.com/ElektroWolle/status/1469962895849140224?ref_src=twsrc%5Etfw%7Ctwcamp%5Etweetembed%7Ctwterm%5E1469962895849140224%7Ctwgr%5E%7Ctwcon%5Es1_c10&ref_url=https%3A%2F%2Fpublish.twitter.com%2F%3Fquery%3Dhttps3A2F2Ftwitter.com2FElektroWolle2Fstatus2F1469962895849140224widget%3DTweet) -* [https://blog.cloudflare.com/cve-2021-44228-log4j-rce-0-day-mitigation/](https://blog.cloudflare.com/cve-2021-44228-log4j-rce-0-day-mitigation/) - - - - -[*source*](https://github.com/splunk/security_content/tree/develop/playbooks/log4j_investigate.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_playbooks/log4j_respond.md b/docs/_playbooks/log4j_respond.md deleted file mode 100644 index f00f194f1f..0000000000 --- a/docs/_playbooks/log4j_respond.md +++ /dev/null @@ -1,58 +0,0 @@ ---- -title: "Log4j Respond" -last_modified_at: 2021-12-14 -toc: true -toc_label: "" -tags: - - Response - - Splunk SOAR - - Log4J ---- - -[Try in Splunk SOAR](https://www.splunk.com/en_us/software/splunk-security-orchestration-and-automation.html){: .btn .btn--success} - -#### Description - -Published in response to CVE-2021-44228, this playbook is meant to be launched after log4j_investigate. In this playbook, the risk from exploited hosts can be mitigated by optionally deleting malicious files from the hosts, blocking outbound network connections from the hosts, and/or shutting down the hosts - -- **Type**: Response -- **Product**: Splunk SOAR -- **Apps**: -- **Last Updated**: 2021-12-14 -- **Author**: Philip Royer, Splunk -- **ID**: e609d729-4076-421a-b8f7-9e545d000381 - -#### Associated Detections - -* [Curl Download and Bash Execution](/detection/curl_download_and_bash_execution/) -* [Wget Download and Bash Execution](/detection/wget_download_and_bash_execution/) -* [Linux Java Spawning Shell](/detection/linux_java_spawning_shell/) -* [Windows Java Spawning Shell](/detection/windows_java_spawning_shell/) -* [Java Class File download by Java User Agent](/detection/java_class_file_download_by_java_user_agent/) -* [Outbound Network Connection from Java Using Default Ports](/detection/outbound_network_connection_from_java_using_default_ports/) -* [Log4Shell JNDI Payload Injection Attempt](/detection/log4shell_jndi_payload_injection_attempt/) -* [Log4Shell JNDI Payload Injection with Outbound Connection](/detection/log4shell_jndi_payload_injection_with_outbound_connection/) -* [Detect Outbound LDAP Traffic](/detection/detect_outbound_ldap_traffic/) - - - -#### How To Implement -To use this playbook, create a custom list called "log4j_hosts_and_files" with a format in which the first column should be an IP or hostname of a potentially affected log4j host, the second should be the operating system family (either unix or windows), and the third should be a full path to a file to delete if there are any. The first two are mandatory and the file is optional. In the block called "enumerate_files_to_delete", change the custom list name from "log4j_hosts_and_files" if needed. If ssh and/or winrm are not the preferred endpoint management methods, these playbooks could be ported to use Google's GRR, osquery, CrowdStrike's RTR, Carbon Black's EDR API, or similar tools. The artifact scope "all" is used throughout this playbook because the artifact list can be added to as the playbook progresses. - -#### Playbooks -![](https://raw.githubusercontent.com/splunk/security_content/develop/playbooks/log4j_respond.png) - -#### Required field - - -#### Reference - -* [https://github.com/Neo23x0/Fenrir/blob/master/fenrir.sh](https://github.com/Neo23x0/Fenrir/blob/master/fenrir.sh) -* [https://isc.sans.edu/diary/Log4j++Log4Shell+Followup%3A+What+we+see+and+how+to+defend+%28and+how+to+access+our+data%29/28122](https://isc.sans.edu/diary/Log4j++Log4Shell+Followup%3A+What+we+see+and+how+to+defend+%28and+how+to+access+our+data%29/28122) -* [https://twitter.com/ElektroWolle/status/1469962895849140224?ref_src=twsrc%5Etfw%7Ctwcamp%5Etweetembed%7Ctwterm%5E1469962895849140224%7Ctwgr%5E%7Ctwcon%5Es1_c10&ref_url=https%3A%2F%2Fpublish.twitter.com%2F%3Fquery%3Dhttps3A2F2Ftwitter.com2FElektroWolle2Fstatus2F1469962895849140224widget%3DTweet](https://twitter.com/ElektroWolle/status/1469962895849140224?ref_src=twsrc%5Etfw%7Ctwcamp%5Etweetembed%7Ctwterm%5E1469962895849140224%7Ctwgr%5E%7Ctwcon%5Es1_c10&ref_url=https%3A%2F%2Fpublish.twitter.com%2F%3Fquery%3Dhttps3A2F2Ftwitter.com2FElektroWolle2Fstatus2F1469962895849140224widget%3DTweet) -* [https://blog.cloudflare.com/cve-2021-44228-log4j-rce-0-day-mitigation/](https://blog.cloudflare.com/cve-2021-44228-log4j-rce-0-day-mitigation/) - - - - -[*source*](https://github.com/splunk/security_content/tree/develop/playbooks/log4j_respond.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_playbooks/log4j_splunk_investigation.md b/docs/_playbooks/log4j_splunk_investigation.md deleted file mode 100644 index 7f8eb8a39b..0000000000 --- a/docs/_playbooks/log4j_splunk_investigation.md +++ /dev/null @@ -1,44 +0,0 @@ ---- -title: "Log4j Splunk Investigation" -last_modified_at: 2021-12-14 -toc: true -toc_label: "" -tags: - - Investigation - - Splunk SOAR - - Splunk ---- - -[Try in Splunk SOAR](https://www.splunk.com/en_us/software/splunk-security-orchestration-and-automation.html){: .btn .btn--success} - -#### Description - -Published in response to CVE-2021-44228, this playbook utilizes data already in your Splunk environment to help investigate and remediate impacts caused by this vulnerability in your environment. - -- **Type**: Investigation -- **Product**: Splunk SOAR -- **Apps**: [Splunk](https://splunkbase.splunk.com/apps/#/search/Splunk/product/soar) -- **Last Updated**: 2021-12-14 -- **Author**: Lou Stella, Splunk -- **ID**: fc0adc66-ff2b-48b0-9a6f-63da6783fd63 - -#### Associated Detections - - -#### How To Implement -This playbook presumes you have Enterprise Security and have configured Assets & Identities, as well as the Endpoint.Processes datamodel - -#### Playbooks -![](https://raw.githubusercontent.com/splunk/security_content/develop/playbooks/internal_host_splunk_investigate_log4j.png) - -#### Required field - - -#### Reference - -* [https://www.splunk.com/en_us/blog/security/log-jammin-log4j-2-rce.html](https://www.splunk.com/en_us/blog/security/log-jammin-log4j-2-rce.html) - - - - -[*source*](https://github.com/splunk/security_content/tree/develop/playbooks/log4j_splunk_investigation.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_playbooks/malware_hunt_and_contain.md b/docs/_playbooks/malware_hunt_and_contain.md deleted file mode 100644 index f09245f174..0000000000 --- a/docs/_playbooks/malware_hunt_and_contain.md +++ /dev/null @@ -1,44 +0,0 @@ ---- -title: "Malware Hunt and Contain" -last_modified_at: 2021-01-21 -toc: true -toc_label: "" -tags: - - Response - - Splunk SOAR - - LDAP - - ServiceNow - - CarbonBlack Response - - VirusTotal ---- - -[Try in Splunk SOAR](https://www.splunk.com/en_us/software/splunk-security-orchestration-and-automation.html){: .btn .btn--success} - -#### Description - -This playbook investigates and remediates malware infections on the endpoint. - -- **Type**: Response -- **Product**: Splunk SOAR -- **Apps**: [LDAP](https://splunkbase.splunk.com/apps/#/search/LDAP/product/soar), [ServiceNow](https://splunkbase.splunk.com/apps/#/search/ServiceNow/product/soar), [CarbonBlack Response](https://splunkbase.splunk.com/apps/#/search/CarbonBlack Response/product/soar), [VirusTotal](https://splunkbase.splunk.com/apps/#/search/VirusTotal/product/soar) -- **Last Updated**: 2021-01-21 -- **Author**: Philip Royer, Splunk -- **ID**: fb3edc76-ff2b-43c0-5f6f-63da4483fd63 - -#### Associated Detections - - -#### How To Implement -Be sure to update asset naming to reflect the asset names configured in your environment. - -#### Playbooks -![](https://raw.githubusercontent.com/splunk/security_content/develop/playbooks/malware_hunt_and_contain.png) - -#### Required field - - -#### Reference - - - -[*source*](https://github.com/splunk/security_content/tree/develop/playbooks/malware_hunt_and_contain.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_playbooks/ransomware_investigate_and_contain.md b/docs/_playbooks/ransomware_investigate_and_contain.md deleted file mode 100644 index de4214097d..0000000000 --- a/docs/_playbooks/ransomware_investigate_and_contain.md +++ /dev/null @@ -1,49 +0,0 @@ ---- -title: "Ransomware Investigate and Contain" -last_modified_at: 2018-02-04 -toc: true -toc_label: "" -tags: - - Response - - Splunk SOAR - - Carbon Black Response - - LDAP - - Palo Alto Networks Firewall - - WildFire - - Cylance - - Ransomware ---- - -[Try in Splunk SOAR](https://www.splunk.com/en_us/software/splunk-security-orchestration-and-automation.html){: .btn .btn--success} - -#### Description - -This playbook investigates and contains ransomware detected on endpoints. - -- **Type**: Response -- **Product**: Splunk SOAR -- **Apps**: [Carbon Black Response](https://splunkbase.splunk.com/apps/#/search/Carbon Black Response/product/soar), [LDAP](https://splunkbase.splunk.com/apps/#/search/LDAP/product/soar), [Palo Alto Networks Firewall](https://splunkbase.splunk.com/apps/#/search/Palo Alto Networks Firewall/product/soar), [WildFire](https://splunkbase.splunk.com/apps/#/search/WildFire/product/soar), [Cylance](https://splunkbase.splunk.com/apps/#/search/Cylance/product/soar) -- **Last Updated**: 2018-02-04 -- **Author**: Philip Royer, Splunk -- **ID**: fc0edc96-ff2b-48b0-9f6f-63da3783fd63 - -#### Associated Detections - -* [Conti Common Exec parameter](/detection/conti_common_exec_parameter/) - - - -#### How To Implement -This playbook requires the Splunk SOAR apps for Palo Alto Networks Firewalls, Palo Alto Wildfire, LDAP, and Carbon Black Response. - -#### Playbooks -![](https://raw.githubusercontent.com/splunk/security_content/develop/playbooks/ransomware_investigate_and_contain.png) - -#### Required field - - -#### Reference - - - -[*source*](https://github.com/splunk/security_content/tree/develop/playbooks/ransomware_investigate_and_contain.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_playbooks/risk_notable_block_indicators.md b/docs/_playbooks/risk_notable_block_indicators.md deleted file mode 100644 index e5df6b504d..0000000000 --- a/docs/_playbooks/risk_notable_block_indicators.md +++ /dev/null @@ -1,46 +0,0 @@ ---- -title: "Risk Notable Block Indicators" -last_modified_at: 2021-10-22 -toc: true -toc_label: "" -tags: - - Response - - Splunk SOAR - - None - - Risk Notable ---- - -[Try in Splunk SOAR](https://www.splunk.com/en_us/software/splunk-security-orchestration-and-automation.html){: .btn .btn--success} - -#### Description - -This playbook handles locating indicators marked for blocking and determining if any blocking playbooks exist. If there is a match to the appropriate tags in the playbook, a filter block routes the name of the playbook to launch to a code block. - -- **Type**: Response -- **Product**: Splunk SOAR -- **Apps**: [None](https://splunkbase.splunk.com/apps/#/search/None/product/soar) -- **Last Updated**: 2021-10-22 -- **Author**: Kelby Shelton, Splunk -- **ID**: rn0edc96-ff2b-48b0-9f6f-83da3783fd63 - -#### Associated Detections - - -#### How To Implement -tbd - -#### Playbooks -![](https://raw.githubusercontent.com/splunk/security_content/develop/playbooks/risk_notable_block_indicators.png) - -#### Required field - - -#### Reference - -* [https://docs.splunk.com/Documentation/ESSOC/latest/user/Useplaybookpack#Call_child_playbooks_with_the_dynamic_playbook_system](https://docs.splunk.com/Documentation/ESSOC/latest/user/Useplaybookpack#Call_child_playbooks_with_the_dynamic_playbook_system) -* [https://docs.splunk.com/Documentation/ESSOC/latest/user/Useplaybookpack#Indicator_tagging_system](https://docs.splunk.com/Documentation/ESSOC/latest/user/Useplaybookpack#Indicator_tagging_system) - - - - -[*source*](https://github.com/splunk/security_content/tree/develop/playbooks/risk_notable_block_indicators.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_playbooks/risk_notable_enrich.md b/docs/_playbooks/risk_notable_enrich.md deleted file mode 100644 index 911ffb3162..0000000000 --- a/docs/_playbooks/risk_notable_enrich.md +++ /dev/null @@ -1,45 +0,0 @@ ---- -title: "Risk Notable Enrich" -last_modified_at: 2021-10-22 -toc: true -toc_label: "" -tags: - - Investigation - - Splunk SOAR - - None - - Risk Notable ---- - -[Try in Splunk SOAR](https://www.splunk.com/en_us/software/splunk-security-orchestration-and-automation.html){: .btn .btn--success} - -#### Description - -This playbook collects the available Indicator data types within the event as well as available investigative playbooks. It will launch any playbooks that meet the filtered criteria. - -- **Type**: Investigation -- **Product**: Splunk SOAR -- **Apps**: [None](https://splunkbase.splunk.com/apps/#/search/None/product/soar) -- **Last Updated**: 2021-10-22 -- **Author**: Kelby Shelton, Splunk -- **ID**: rn0edc96-ff2b-48b0-9f6f-43da3783fd63 - -#### Associated Detections - - -#### How To Implement -tbd - -#### Playbooks -![](https://raw.githubusercontent.com/splunk/security_content/develop/playbooks/risk_notable_enrich.png) - -#### Required field - - -#### Reference - -* [https://docs.splunk.com/Documentation/ESSOC/latest/user/Useplaybookpack#Call_child_playbooks_with_the_dynamic_playbook_system](https://docs.splunk.com/Documentation/ESSOC/latest/user/Useplaybookpack#Call_child_playbooks_with_the_dynamic_playbook_system) - - - - -[*source*](https://github.com/splunk/security_content/tree/develop/playbooks/risk_notable_enrich.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_playbooks/risk_notable_import_data.md b/docs/_playbooks/risk_notable_import_data.md deleted file mode 100644 index b6fc3c0dc7..0000000000 --- a/docs/_playbooks/risk_notable_import_data.md +++ /dev/null @@ -1,49 +0,0 @@ ---- -title: "Risk Notable Import Data" -last_modified_at: 2021-10-22 -toc: true -toc_label: "" -tags: - - Investigation - - Splunk SOAR - - Splunk - - Risk Notable ---- - -[Try in Splunk SOAR](https://www.splunk.com/en_us/software/splunk-security-orchestration-and-automation.html){: .btn .btn--success} - -#### Description - -This playbook gathers all of the events associated with the risk notable and imports them as artifacts. It also generates a custom markdown formatted note. - -- **Type**: Investigation -- **Product**: Splunk SOAR -- **Apps**: [Splunk](https://splunkbase.splunk.com/apps/#/search/Splunk/product/soar) -- **Last Updated**: 2021-10-22 -- **Author**: Kelby Shelton, Splunk -- **ID**: rn0edc96-ff2b-48b0-9f6f-23da3783fd63 - -#### Associated Detections - - -#### How To Implement -The Splunk search used to locate contributing events requires three fields in the notable artifact\: risk_object, info_min_time, and info_max_time. The query also performs some deduplication on contributing events and may need to be adjusted based on individual Enterprise Security environments. Mitre Tactics and Techniques appear if using the annotation framework in Splunk ES." -```index=risk risk_object=\"{0}\" earliest=\"{1}\" latest="{2}\" | rex field=source \".*-\s(?.*)\s+-\s+\w+\s+-\s+Rule\" | fillnull value=\"unknown\" threat_object | eval risk_message=coalesce(risk_message,source) | stats values(*) as * by _time source threat_object risk_message | rename annotations.mitre_attack.mitre_technique_id as mitre_technique_id annotations.mitre_attack.mitre_tactic as mitre_tactic annotations.mitre_attack.mitre_technique as mitre_technique | fields - annotations* risk_object_* date_* orig_* user_* src_user_* src_* dest_* dest_user_* info_* search_* splunk_* tag* risk_modifier* risk_rule* sourcetype timestamp index next_cron_time timeendpos timestartpos testmode linecount | sort + _time | `uitime(_time)` | dedup source threat_object``` -A custom code block sorts the returned event data and produces a markdown formatted note into the note_content output field. This field is then available for use in downstream playbooks." - - -#### Playbooks -![](https://raw.githubusercontent.com/splunk/security_content/develop/playbooks/risk_notable_import_data.png) - -#### Required field - - -#### Reference - -* [https://docs.splunk.com/Documentation/ESSOC/latest/user/Useplaybookpack](https://docs.splunk.com/Documentation/ESSOC/latest/user/Useplaybookpack) -* [http://docs.splunk.com/Documentation/ES/6.6.2/Admin/Configurecorrelationsearches#Use_security_framework_annotations_in_correlation_searches](http://docs.splunk.com/Documentation/ES/6.6.2/Admin/Configurecorrelationsearches#Use_security_framework_annotations_in_correlation_searches) - - - - -[*source*](https://github.com/splunk/security_content/tree/develop/playbooks/risk_notable_import_data.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_playbooks/risk_notable_investigate.md b/docs/_playbooks/risk_notable_investigate.md deleted file mode 100644 index 2ccd662d03..0000000000 --- a/docs/_playbooks/risk_notable_investigate.md +++ /dev/null @@ -1,45 +0,0 @@ ---- -title: "Risk Notable Investigate" -last_modified_at: 2021-10-22 -toc: true -toc_label: "" -tags: - - Investigation - - Splunk SOAR - - None - - Risk Notable ---- - -[Try in Splunk SOAR](https://www.splunk.com/en_us/software/splunk-security-orchestration-and-automation.html){: .btn .btn--success} - -#### Description - -This playbook checks for the presence of the Risk Investigation workbook and updates tasks or leaves generic notes. - -- **Type**: Investigation -- **Product**: Splunk SOAR -- **Apps**: [None](https://splunkbase.splunk.com/apps/#/search/None/product/soar) -- **Last Updated**: 2021-10-22 -- **Author**: Kelby Shelton, Splunk -- **ID**: rn0edc96-ff2b-48b0-9f6f-03da3783fd63 - -#### Associated Detections - - -#### How To Implement -Set this playbook to run in Active mode on the Risk Notable label in Splunk SOAR. - -#### Playbooks -![](https://raw.githubusercontent.com/splunk/security_content/develop/playbooks/risk_notable_investigate.png) - -#### Required field - - -#### Reference - -* [https://docs.splunk.com/Documentation/ESSOC/latest/user/Useplaybookpack](https://docs.splunk.com/Documentation/ESSOC/latest/user/Useplaybookpack) - - - - -[*source*](https://github.com/splunk/security_content/tree/develop/playbooks/risk_notable_investigate.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_playbooks/risk_notable_merge_events.md b/docs/_playbooks/risk_notable_merge_events.md deleted file mode 100644 index 19e4abac0b..0000000000 --- a/docs/_playbooks/risk_notable_merge_events.md +++ /dev/null @@ -1,45 +0,0 @@ ---- -title: "Risk Notable Merge Events" -last_modified_at: 2021-10-22 -toc: true -toc_label: "" -tags: - - Investigation - - Splunk SOAR - - None - - Risk Notable ---- - -[Try in Splunk SOAR](https://www.splunk.com/en_us/software/splunk-security-orchestration-and-automation.html){: .btn .btn--success} - -#### Description - -This playbook finds related events based on key fields in a risk notable and allows the user to process the results and decide which events to merge into the current investigation. - -- **Type**: Investigation -- **Product**: Splunk SOAR -- **Apps**: [None](https://splunkbase.splunk.com/apps/#/search/None/product/soar) -- **Last Updated**: 2021-10-22 -- **Author**: Kelby Shelton, Splunk -- **ID**: rn0edc96-ff2b-48b0-9f6f-53da3783fd63 - -#### Associated Detections - - -#### How To Implement -Combining the list_merge utility within the playbook with the find_related_containers utility allows for fine-tuning of related event criteria. For example, the default filtering criteria uses description, risk_object, and threat_object as the important fields and requires at least three matches before an event is considered related. There are several options to customize the associated criteria, including adding more fields in list_merge, reducing or increasing the minimum match count, or utilizing the wildcard feature of find_related_containers. - -#### Playbooks -![](https://raw.githubusercontent.com/splunk/security_content/develop/playbooks/risk_notable_merge_events.png) - -#### Required field - - -#### Reference - -* [https://docs.splunk.com/Documentation/ESSOC/latest/user/Useplaybookpack](https://docs.splunk.com/Documentation/ESSOC/latest/user/Useplaybookpack) - - - - -[*source*](https://github.com/splunk/security_content/tree/develop/playbooks/risk_notable_merge_events.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_playbooks/risk_notable_mitigate.md b/docs/_playbooks/risk_notable_mitigate.md deleted file mode 100644 index 75dfad7eb7..0000000000 --- a/docs/_playbooks/risk_notable_mitigate.md +++ /dev/null @@ -1,44 +0,0 @@ ---- -title: "Risk Notable Mitigate" -last_modified_at: 2021-10-22 -toc: true -toc_label: "" -tags: - - Response - - Splunk SOAR - - Risk Notable ---- - -[Try in Splunk SOAR](https://www.splunk.com/en_us/software/splunk-security-orchestration-and-automation.html){: .btn .btn--success} - -#### Description - -This playbook checks for the presence of the Risk Response workbook and updates tasks or leaves generic notes. The risk_notable_verdict playbooks recommends this playbook as a second phase of the investigation. Additionally, this playbook can be used in ad-hoc investigations or incorporated into custom workbooks. - -- **Type**: Response -- **Product**: Splunk SOAR -- **Apps**: -- **Last Updated**: 2021-10-22 -- **Author**: Kelby Shelton, Splunk -- **ID**: rn0edc96-ff2b-48b0-9f6f-63da3783fd63 - -#### Associated Detections - - -#### How To Implement -tbd - -#### Playbooks -![](https://raw.githubusercontent.com/splunk/security_content/develop/playbooks/risk_notable_mitigate.png) - -#### Required field - - -#### Reference - -* [https://docs.splunk.com/Documentation/ESSOC/latest/user/Useplaybookpack](https://docs.splunk.com/Documentation/ESSOC/latest/user/Useplaybookpack) - - - - -[*source*](https://github.com/splunk/security_content/tree/develop/playbooks/risk_notable_mitigate.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_playbooks/risk_notable_preprocess.md b/docs/_playbooks/risk_notable_preprocess.md deleted file mode 100644 index c951db2439..0000000000 --- a/docs/_playbooks/risk_notable_preprocess.md +++ /dev/null @@ -1,46 +0,0 @@ ---- -title: "Risk Notable Preprocess" -last_modified_at: 2021-10-22 -toc: true -toc_label: "" -tags: - - Investigation - - Splunk SOAR - - Splunk - - Risk Notable ---- - -[Try in Splunk SOAR](https://www.splunk.com/en_us/software/splunk-security-orchestration-and-automation.html){: .btn .btn--success} - -#### Description - -"This playbook prepares a risk notable for investigation by performing the following tasks: 1. Ensures that a risk notable links back to the original notable event with a card pinned to the HUD. 2. Posts a link to this container in the comment field of Splunk ES. 3. Updates the container name, description, and severity to reflect the data in the notable artifact." - - -- **Type**: Investigation -- **Product**: Splunk SOAR -- **Apps**: [Splunk](https://splunkbase.splunk.com/apps/#/search/Splunk/product/soar) -- **Last Updated**: 2021-10-22 -- **Author**: Kelby Shelton, Splunk -- **ID**: rn0edc96-ff2b-48b0-9f6f-13da3783fd63 - -#### Associated Detections - - -#### How To Implement -tbd - -#### Playbooks -![](https://raw.githubusercontent.com/splunk/security_content/develop/playbooks/risk_notable_preprocess.png) - -#### Required field - - -#### Reference - -* [https://docs.splunk.com/Documentation/ESSOC/latest/user/Useplaybookpack](https://docs.splunk.com/Documentation/ESSOC/latest/user/Useplaybookpack) - - - - -[*source*](https://github.com/splunk/security_content/tree/develop/playbooks/risk_notable_preprocess.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_playbooks/risk_notable_protect_assets_and_users.md b/docs/_playbooks/risk_notable_protect_assets_and_users.md deleted file mode 100644 index e809d14113..0000000000 --- a/docs/_playbooks/risk_notable_protect_assets_and_users.md +++ /dev/null @@ -1,45 +0,0 @@ ---- -title: "Risk Notable Protect Assets and Users" -last_modified_at: 2021-10-22 -toc: true -toc_label: "" -tags: - - Response - - Splunk SOAR - - None - - Risk Notable ---- - -[Try in Splunk SOAR](https://www.splunk.com/en_us/software/splunk-security-orchestration-and-automation.html){: .btn .btn--success} - -#### Description - -This playbook attempts to find assets and users from the notable event and match those with assets and identities from Splunk ES. If a match was found and the user has playbooks available to contain entities, the analyst decides which entities to disable or quarantine. - -- **Type**: Response -- **Product**: Splunk SOAR -- **Apps**: [None](https://splunkbase.splunk.com/apps/#/search/None/product/soar) -- **Last Updated**: 2021-10-22 -- **Author**: Kelby Shelton, Splunk -- **ID**: rn0edc96-ff2b-48b0-9f6f-93da3783fd63 - -#### Associated Detections - - -#### How To Implement -tbd - -#### Playbooks -![](https://raw.githubusercontent.com/splunk/security_content/develop/playbooks/risk_notable_protect_assets_and_users.png) - -#### Required field - - -#### Reference - -* [https://docs.splunk.com/Documentation/ESSOC/latest/user/Useplaybookpack#Call_child_playbooks_with_the_dynamic_playbook_system](https://docs.splunk.com/Documentation/ESSOC/latest/user/Useplaybookpack#Call_child_playbooks_with_the_dynamic_playbook_system) - - - - -[*source*](https://github.com/splunk/security_content/tree/develop/playbooks/risk_notable_protect_assets_and_users.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_playbooks/risk_notable_review_indicators.md b/docs/_playbooks/risk_notable_review_indicators.md deleted file mode 100644 index e23c0ec468..0000000000 --- a/docs/_playbooks/risk_notable_review_indicators.md +++ /dev/null @@ -1,45 +0,0 @@ ---- -title: "Risk Notable Review Indicators" -last_modified_at: 2021-10-22 -toc: true -toc_label: "" -tags: - - Response - - Splunk SOAR - - None - - Risk Notable ---- - -[Try in Splunk SOAR](https://www.splunk.com/en_us/software/splunk-security-orchestration-and-automation.html){: .btn .btn--success} - -#### Description - -This playbook was designed to be called by a user to process indicators that are marked as suspicious within the SOAR platform. Analysts will review indicators in a prompt and mark them as blocked or safe. - -- **Type**: Response -- **Product**: Splunk SOAR -- **Apps**: [None](https://splunkbase.splunk.com/apps/#/search/None/product/soar) -- **Last Updated**: 2021-10-22 -- **Author**: Kelby Shelton, Splunk -- **ID**: rn0edc96-ff2b-48b0-9f6f-73da3783fd63 - -#### Associated Detections - - -#### How To Implement -tbd - -#### Playbooks -![](https://raw.githubusercontent.com/splunk/security_content/develop/playbooks/risk_notable_review_indicators.png) - -#### Required field - - -#### Reference - -* [https://docs.splunk.com/Documentation/ESSOC/latest/user/Useplaybookpack#Indicator_tagging_system](https://docs.splunk.com/Documentation/ESSOC/latest/user/Useplaybookpack#Indicator_tagging_system) - - - - -[*source*](https://github.com/splunk/security_content/tree/develop/playbooks/risk_notable_review_indicators.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_playbooks/risk_notable_verdict.md b/docs/_playbooks/risk_notable_verdict.md deleted file mode 100644 index 1acb9d2b77..0000000000 --- a/docs/_playbooks/risk_notable_verdict.md +++ /dev/null @@ -1,45 +0,0 @@ ---- -title: "Risk Notable Verdict" -last_modified_at: 2021-10-22 -toc: true -toc_label: "" -tags: - - Response - - Splunk SOAR - - None - - Risk Notable ---- - -[Try in Splunk SOAR](https://www.splunk.com/en_us/software/splunk-security-orchestration-and-automation.html){: .btn .btn--success} - -#### Description - -This playbook locates available playbooks with the response tag and presents them to the analyst. Based on the analyst selection, it will launch its chosen playbook. - -- **Type**: Response -- **Product**: Splunk SOAR -- **Apps**: [None](https://splunkbase.splunk.com/apps/#/search/None/product/soar) -- **Last Updated**: 2021-10-22 -- **Author**: Kelby Shelton, Splunk -- **ID**: rn0edc96-ff2b-48b0-9f6f-33da3783fd63 - -#### Associated Detections - - -#### How To Implement -tbd - -#### Playbooks -![](https://raw.githubusercontent.com/splunk/security_content/develop/playbooks/risk_notable_verdict.png) - -#### Required field - - -#### Reference - -* [https://docs.splunk.com/Documentation/ESSOC/latest/user/Useplaybookpack#Call_child_playbooks_with_the_dynamic_playbook_system](https://docs.splunk.com/Documentation/ESSOC/latest/user/Useplaybookpack#Call_child_playbooks_with_the_dynamic_playbook_system) - - - - -[*source*](https://github.com/splunk/security_content/tree/develop/playbooks/risk_notable_verdict.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_playbooks/start_investigation.md b/docs/_playbooks/start_investigation.md deleted file mode 100644 index 95e68ad998..0000000000 --- a/docs/_playbooks/start_investigation.md +++ /dev/null @@ -1,40 +0,0 @@ ---- -title: "Start Investigation" -last_modified_at: 2021-10-07 -toc: true -toc_label: "" -tags: - - Investigation - - Splunk SOAR ---- - -[Try in Splunk SOAR](https://www.splunk.com/en_us/software/splunk-security-orchestration-and-automation.html){: .btn .btn--success} - -#### Description - -Handle cases in Splunk SOAR with consistency that only automation can provide. This playbook ensures that cases are being assigned to analysts, and follow on work gets started. - -- **Type**: Investigation -- **Product**: Splunk SOAR -- **Apps**: -- **Last Updated**: 2021-10-07 -- **Author**: Kelby Shelton, Splunk -- **ID**: fc5adc76-f3ab-4cb0-5f6f-63bc3493fd46 - -#### Associated Detections - - -#### How To Implement -This is a playbook that is designed to be recommended within a workbook. If used in this manner, the playbook will assign the user that launched the playbook as the owner of the event, move the event status to "Open", and complete the workbook task where this playbook appears. If there is a task after the one where the playbook appears (within the same phase), it will set the next task to "In Progress." - -#### Playbooks -![](https://raw.githubusercontent.com/splunk/security_content/develop/playbooks/start_investigation.png) - -#### Required field - - -#### Reference - - - -[*source*](https://github.com/splunk/security_content/tree/develop/playbooks/start_investigation.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_playbooks/threat_intel_investigate.md b/docs/_playbooks/threat_intel_investigate.md deleted file mode 100644 index 36c18abbca..0000000000 --- a/docs/_playbooks/threat_intel_investigate.md +++ /dev/null @@ -1,44 +0,0 @@ ---- -title: "Threat Intel Investigate" -last_modified_at: 2021-11-30 -toc: true -toc_label: "" -tags: - - Investigation - - Splunk SOAR - - threat_intel ---- - -[Try in Splunk SOAR](https://www.splunk.com/en_us/software/splunk-security-orchestration-and-automation.html){: .btn .btn--success} - -#### Description - -This parent playbook collects data and launches appropriate child playbooks to gather threat intelligence information about indicators. After the child playbooks have run, this playbook posts the notes to the container and prompts the analyst to add tags to each enriched indicator based on the intelligence provided. - -- **Type**: Investigation -- **Product**: Splunk SOAR -- **Apps**: -- **Last Updated**: 2021-11-30 -- **Author**: Philip Royer, Splunk -- **ID**: fc5adc76-fd2b-48b0-5f6f-63bc3493fd46 - -#### Associated Detections - - -#### How To Implement -The prompt is currently sent to the Administrator role, but should be changed to the appropriate user and role. The "list_investigate_playbooks" block fetches playbooks from the local repository with the tags "investigate" and "threat_intel" by default. The playbook "trustar_enrich_indicators" is meant to be used by this playbook, and others can be created to replace it or work alongside it. To add a new input playbook, copy it to the local repository and give it the necessary tags. Define a playbook input with the name "indicators" and the data type matching the types of indicators the playbook can process. To add a new tag to the preconfigured list, add it to the "choices" array in the "threat_intel_indicator_review" prompt block, and add it to the "response_to_tag_map" in "process_indicators". - -#### Playbooks -![](https://raw.githubusercontent.com/splunk/security_content/develop/playbooks/threat_intel_investigate.png) - -#### Required field - - -#### Reference - -* [https://www.splunk.com/en_us/blog/security/TruSTAR-Enrich-Indicators-soar-in-seconds.html](https://www.splunk.com/en_us/blog/security/TruSTAR-Enrich-Indicators-soar-in-seconds.html) - - - - -[*source*](https://github.com/splunk/security_content/tree/develop/playbooks/threat_intel_investigate.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_playbooks/trustar_enrich_indicators.md b/docs/_playbooks/trustar_enrich_indicators.md deleted file mode 100644 index 524edba7c8..0000000000 --- a/docs/_playbooks/trustar_enrich_indicators.md +++ /dev/null @@ -1,46 +0,0 @@ ---- -title: "TruSTAR Enrich Indicators" -last_modified_at: 2021-11-24 -toc: true -toc_label: "" -tags: - - Investigation - - Splunk SOAR - - TruSTAR - - threat_intel - - risk_notable ---- - -[Try in Splunk SOAR](https://www.splunk.com/en_us/software/splunk-security-orchestration-and-automation.html){: .btn .btn--success} - -#### Description - -Use TruSTAR to gather threat information about indicators in a SOAR event. Tag the indicators with the normalized priority score from TruSTAR and summarize the findings in an analyst note. This playbook is meant to be used as a child playbook executed by a parent playbook such as "threat_intel_investigate". - -- **Type**: Investigation -- **Product**: Splunk SOAR -- **Apps**: [TruSTAR](https://splunkbase.splunk.com/apps/#/search/TruSTAR/product/soar) -- **Last Updated**: 2021-11-24 -- **Author**: Philip Royer, Splunk -- **ID**: fc5adc76-fd2b-48b0-5f6f-63da6423fd63 - -#### Associated Detections - - -#### How To Implement -To use this playbook as a sub-playbook of "threat_intel_investigate", copy it to the local git repository and make sure it has the tags "investigate" and "threat_intel". To use this playbook as a sub-playbook of "risk_notable_enrich", copy it to local and make sure it has the tags "investigate" and "risk_notable" To control the types of indicators processed by this playbook, change the data types of the "indicators" input" - -#### Playbooks -![](https://raw.githubusercontent.com/splunk/security_content/develop/playbooks/trustar_enrich_indicators.png) - -#### Required field - - -#### Reference - -* [https://www.splunk.com/en_us/blog/security/TruSTAR-Enrich-Indicators-soar-in-seconds.html](https://www.splunk.com/en_us/blog/security/TruSTAR-Enrich-Indicators-soar-in-seconds.html) - - - - -[*source*](https://github.com/splunk/security_content/tree/develop/playbooks/trustar_enrich_indicators.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2017-01-07-spectre_and_meltdown_vulnerable_systems.md b/docs/_posts/2017-01-07-spectre_and_meltdown_vulnerable_systems.md deleted file mode 100644 index d284f074ec..0000000000 --- a/docs/_posts/2017-01-07-spectre_and_meltdown_vulnerable_systems.md +++ /dev/null @@ -1,150 +0,0 @@ ---- -title: "Spectre and Meltdown Vulnerable Systems" -excerpt: "" -categories: - - Deprecated -last_modified_at: 2017-01-07 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2017-5753 - - Vulnerabilities ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The search is used to detect systems that are still vulnerable to the Spectre and Meltdown vulnerabilities. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Vulnerabilities](https://docs.splunk.com/Documentation/CIM/latest/User/Vulnerabilities) -- **Last Updated**: 2017-01-07 -- **Author**: David Dorsey, Splunk -- **ID**: 354be8e0-32cd-4da0-8c47-796de13b60ea - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* ID.RA -* RS.MI -* PR.IP -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 4 - - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2017-5753](https://nvd.nist.gov/vuln/detail/CVE-2017-5753) | Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis. | 4.7 | - - - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` min(_time) as firstTime max(_time) as lastTime from datamodel=Vulnerabilities where Vulnerabilities.cve ="CVE-2017-5753" OR Vulnerabilities.cve ="CVE-2017-5715" OR Vulnerabilities.cve ="CVE-2017-5754" by Vulnerabilities.dest -| `drop_dm_object_name(Vulnerabilities)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `spectre_and_meltdown_vulnerable_systems_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **spectre_and_meltdown_vulnerable_systems_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -The search requires that you are ingesting your vulnerability-scanner data and that it reports the CVE of the vulnerability identified. - -#### Known False Positives -It is possible that your vulnerability scanner is not detecting that the patches have been applied. - -#### Associated Analytic story -* [Spectre And Meltdown Vulnerabilities](/stories/spectre_and_meltdown_vulnerabilities) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/spectre_and_meltdown_vulnerable_systems.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2017-09-12-detect_new_login_attempts_to_routers.md b/docs/_posts/2017-09-12-detect_new_login_attempts_to_routers.md deleted file mode 100644 index ec79fde91f..0000000000 --- a/docs/_posts/2017-09-12-detect_new_login_attempts_to_routers.md +++ /dev/null @@ -1,151 +0,0 @@ ---- -title: "Detect New Login Attempts to Routers" -excerpt: "" -categories: - - Application -last_modified_at: 2017-09-12 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Authentication ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The search queries the authentication logs for assets that are categorized as routers in the ES Assets and Identity Framework, to identify connections that have not been seen before in the last 30 days. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Authentication](https://docs.splunk.com/Documentation/CIM/latest/User/Authentication) -- **Last Updated**: 2017-09-12 -- **Author**: Bhavin Patel, Splunk -- **ID**: bce3ed7c-9b1f-42a0-abdf-d8b123a34836 - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* PR.AC -* PR.IP - - - -
-
- -
- CIS20 - -
- -* CIS 11 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count earliest(_time) as earliest latest(_time) as latest from datamodel=Authentication where Authentication.dest_category=router by Authentication.dest Authentication.user -| eval isOutlier=if(earliest >= relative_time(now(), "-30d@d"), 1, 0) -| where isOutlier=1 -| `security_content_ctime(earliest)` -| `security_content_ctime(latest)` -| `drop_dm_object_name("Authentication")` -| `detect_new_login_attempts_to_routers_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **detect_new_login_attempts_to_routers_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Authentication.dest_category -* Authentication.dest -* Authentication.user - - -#### How To Implement -To successfully implement this search, you must ensure the network router devices are categorized as "router" in the Assets and identity table. You must also populate the Authentication data model with logs related to users authenticating to routing infrastructure. - -#### Known False Positives -Legitimate router connections may appear as new connections - -#### Associated Analytic story -* [Router and Infrastructure Security](/stories/router_and_infrastructure_security) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/application/detect_new_login_attempts_to_routers.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2017-09-12-extended_period_without_successful_netbackup_backups.md b/docs/_posts/2017-09-12-extended_period_without_successful_netbackup_backups.md deleted file mode 100644 index 64449b47a3..0000000000 --- a/docs/_posts/2017-09-12-extended_period_without_successful_netbackup_backups.md +++ /dev/null @@ -1,145 +0,0 @@ ---- -title: "Extended Period Without Successful Netbackup Backups" -excerpt: "" -categories: - - Deprecated -last_modified_at: 2017-09-12 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search returns a list of hosts that have not successfully completed a backup in over a week. Deprecated because it's a infrastructure monitoring. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2017-09-12 -- **Author**: David Dorsey, Splunk -- **ID**: a34aae96-ccf8-4aef-952c-3ea214444440 - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* PR.IP - - - -
-
- -
- CIS20 - -
- -* CIS 10 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`netbackup` MESSAGE="Disk/Partition backup completed successfully." -| stats latest(_time) as latestTime by COMPUTERNAME -| `security_content_ctime(latestTime)` -| rename COMPUTERNAME as dest -| eval isOutlier=if(latestTime <= relative_time(now(), "-7d@d"), 1, 0) -| search isOutlier=1 -| table latestTime, dest -| `extended_period_without_successful_netbackup_backups_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [netbackup](https://github.com/splunk/security_content/blob/develop/macros/netbackup.yml) - -> :information_source: -> **extended_period_without_successful_netbackup_backups_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* MESSAGE -* COMPUTERNAME - - -#### How To Implement -To successfully implement this search you need to first obtain data from your backup solution, either from the backup logs on your hosts, or from a central server responsible for performing the backups. If you do not use Netbackup, you can modify this search for your backup solution. Depending on how often you backup your systems, you may want to modify how far in the past to look for a successful backup, other than the default of seven days. - -#### Known False Positives -None identified - -#### Associated Analytic story -* [Monitor Backup Solution](/stories/monitor_backup_solution) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/extended_period_without_successful_netbackup_backups.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2017-09-12-identify_new_user_accounts.md b/docs/_posts/2017-09-12-identify_new_user_accounts.md deleted file mode 100644 index 2db91f8f64..0000000000 --- a/docs/_posts/2017-09-12-identify_new_user_accounts.md +++ /dev/null @@ -1,153 +0,0 @@ ---- -title: "Identify New User Accounts" -excerpt: "Domain Accounts -" -categories: - - Deprecated -last_modified_at: 2017-09-12 -toc: true -toc_label: "" -tags: - - Domain Accounts - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This detection search will help profile user accounts in your environment by identifying newly created accounts that have been added to your network in the past week. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2017-09-12 -- **Author**: Bhavin Patel, Splunk -- **ID**: 475b9e27-17e4-46e2-b7e2-648221be3b89 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1078.002](https://attack.mitre.org/techniques/T1078/002/) | Domain Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* PR.IP - - - -
-
- -
- CIS20 - -
- -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| from datamodel Identity_Management.All_Identities -| eval empStatus=case((now()-startDate)<604800, "Accounts created in last week") -| search empStatus="Accounts created in last week" -| `security_content_ctime(endDate)` -| `security_content_ctime(startDate)` -| table identity empStatus endDate startDate -| `identify_new_user_accounts_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **identify_new_user_accounts_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -To successfully implement this search, you need to be populating the Enterprise Security Identity_Management data model in the assets and identity framework. - -#### Known False Positives -If the Identity_Management data model is not updated regularly, this search could give you false positive alerts. Please consider this and investigate appropriately. - -#### Associated Analytic story -* [Account Monitoring and Controls](/stories/account_monitoring_and_controls) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/identify_new_user_accounts.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2017-09-12-unsuccessful_netbackup_backups.md b/docs/_posts/2017-09-12-unsuccessful_netbackup_backups.md deleted file mode 100644 index 14cc93f2cc..0000000000 --- a/docs/_posts/2017-09-12-unsuccessful_netbackup_backups.md +++ /dev/null @@ -1,142 +0,0 @@ ---- -title: "Unsuccessful Netbackup backups" -excerpt: "" -categories: - - Deprecated -last_modified_at: 2017-09-12 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search gives you the hosts where a backup was attempted and then failed. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2017-09-12 -- **Author**: David Dorsey, Splunk -- **ID**: a34aae96-ccf8-4aaa-952c-3ea21444444f - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* PR.IP - - - -
-
- -
- CIS20 - -
- -* CIS 10 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`netbackup` -| stats latest(_time) as latestTime by COMPUTERNAME, MESSAGE -| search MESSAGE="An error occurred, failed to backup." -| `security_content_ctime(latestTime)` -| rename COMPUTERNAME as dest, MESSAGE as signature -| table latestTime, dest, signature -| `unsuccessful_netbackup_backups_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [netbackup](https://github.com/splunk/security_content/blob/develop/macros/netbackup.yml) - -> :information_source: -> **unsuccessful_netbackup_backups_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -To successfully implement this search you need to obtain data from your backup solution, either from the backup logs on your endpoints or from a central server responsible for performing the backups. If you do not use Netbackup, you can modify this search for your specific backup solution. - -#### Known False Positives -None identified - -#### Associated Analytic story -* [Monitor Backup Solution](/stories/monitor_backup_solution) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/unsuccessful_netbackup_backups.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2017-09-13-detect_unauthorized_assets_by_mac_address.md b/docs/_posts/2017-09-13-detect_unauthorized_assets_by_mac_address.md deleted file mode 100644 index c9e73bfaa9..0000000000 --- a/docs/_posts/2017-09-13-detect_unauthorized_assets_by_mac_address.md +++ /dev/null @@ -1,153 +0,0 @@ ---- -title: "Detect Unauthorized Assets by MAC address" -excerpt: "" -categories: - - Network -last_modified_at: 2017-09-13 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Network_Sessions ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -By populating the organization's assets within the assets_by_str.csv, we will be able to detect unauthorized devices that are trying to connect with the organization's network by inspecting DHCP request packets, which are issued by devices when they attempt to obtain an IP address from the DHCP server. The MAC address associated with the source of the DHCP request is checked against the list of known devices, and reports on those that are not found. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Network_Sessions](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkSessions) -- **Last Updated**: 2017-09-13 -- **Author**: Bhavin Patel, Splunk -- **ID**: dcfd6b40-42f9-469d-a433-2e53f7489ff4 - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance -* Delivery -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* ID.AM -* PR.DS - - - -
-
- -
- CIS20 - -
- -* CIS 1 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count from datamodel=Network_Sessions where nodename=All_Sessions.DHCP All_Sessions.tag=dhcp by All_Sessions.dest_ip All_Sessions.dest_mac -| dedup All_Sessions.dest_mac -| `drop_dm_object_name("Network_Sessions")` -|`drop_dm_object_name("All_Sessions")` -| search NOT [ -| inputlookup asset_lookup_by_str -|rename mac as dest_mac -| fields + dest_mac] -| `detect_unauthorized_assets_by_mac_address_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **detect_unauthorized_assets_by_mac_address_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* All_Sessions.signature -* All_Sessions.src_ip -* All_Sessions.dest_mac - - -#### How To Implement -This search uses the Network_Sessions data model shipped with Enterprise Security. It leverages the Assets and Identity framework to populate the assets_by_str.csv file located in SA-IdentityManagement, which will contain a list of known authorized organizational assets including their MAC addresses. Ensure that all inventoried systems have their MAC address populated. - -#### Known False Positives -This search might be prone to high false positives. Please consider this when conducting analysis or investigations. Authorized devices may be detected as unauthorized. If this is the case, verify the MAC address of the system responsible for the false positive and add it to the Assets and Identity framework with the proper information. - -#### Associated Analytic story -* [Asset Tracking](/stories/asset_tracking) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/network/detect_unauthorized_assets_by_mac_address.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2017-09-15-no_windows_updates_in_a_time_frame.md b/docs/_posts/2017-09-15-no_windows_updates_in_a_time_frame.md deleted file mode 100644 index fe4ce2296c..0000000000 --- a/docs/_posts/2017-09-15-no_windows_updates_in_a_time_frame.md +++ /dev/null @@ -1,153 +0,0 @@ ---- -title: "No Windows Updates in a time frame" -excerpt: "" -categories: - - Application -last_modified_at: 2017-09-15 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Updates ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for Windows endpoints that have not generated an event indicating a successful Windows update in the last 60 days. Windows updates are typically released monthly and applied shortly thereafter. An endpoint that has not successfully applied an update in this time frame indicates the endpoint is not regularly being patched for some reason. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Updates](https://docs.splunk.com/Documentation/CIM/latest/User/Updates) -- **Last Updated**: 2017-09-15 -- **Author**: Bhavin Patel, Splunk -- **ID**: 1a77c08c-2f56-409c-a2d3-7d64617edd4f - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* PR.PT -* PR.MA - - - -
-
- -
- CIS20 - -
- -* CIS 18 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` max(_time) as lastTime from datamodel=Updates where Updates.status=Installed Updates.vendor_product="Microsoft Windows" by Updates.dest Updates.status Updates.vendor_product -| rename Updates.dest as Host -| rename Updates.status as "Update Status" -| rename Updates.vendor_product as Product -| eval isOutlier=if(lastTime <= relative_time(now(), "-60d@d"), 1, 0) -| `security_content_ctime(lastTime)` -| search isOutlier=1 -| rename lastTime as "Last Update Time", -| table Host, "Update Status", Product, "Last Update Time" -| `no_windows_updates_in_a_time_frame_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **no_windows_updates_in_a_time_frame_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Updates.status -* Updates.vendor_product -* Updates.dest - - -#### How To Implement -To successfully implement this search, it requires that the 'Update' data model is being populated. This can be accomplished by ingesting Windows events or the Windows Update log via a universal forwarder on the Windows endpoints you wish to monitor. The Windows add-on should be also be installed and configured to properly parse Windows events in Splunk. There may be other data sources which can populate this data model, including vulnerability management systems. - -#### Known False Positives -None identified - -#### Associated Analytic story -* [Monitor for Updates](/stories/monitor_for_updates) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/application/no_windows_updates_in_a_time_frame.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2017-09-19-email_attachments_with_lots_of_spaces.md b/docs/_posts/2017-09-19-email_attachments_with_lots_of_spaces.md deleted file mode 100644 index d522844132..0000000000 --- a/docs/_posts/2017-09-19-email_attachments_with_lots_of_spaces.md +++ /dev/null @@ -1,156 +0,0 @@ ---- -title: "Email Attachments With Lots Of Spaces" -excerpt: "" -categories: - - Application -last_modified_at: 2017-09-19 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Email ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -Attackers often use spaces as a means to obfuscate an attachment's file extension. This search looks for messages with email attachments that have many spaces within the file names. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Email](https://docs.splunk.com/Documentation/CIM/latest/User/Email) -- **Last Updated**: 2017-09-19 -- **Author**: David Dorsey, Splunk -- **ID**: 56e877a6-1455-4479-ada6-0550dc1e22f8 - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Delivery - - -
-
- - -
- NIST - -
- -* PR.IP - - - -
-
- -
- CIS20 - -
- -* CIS 7 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count values(All_Email.recipient) as recipient_address min(_time) as firstTime max(_time) as lastTime from datamodel=Email where All_Email.file_name="*" by All_Email.src_user, All_Email.file_name All_Email.message_id -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `drop_dm_object_name("All_Email")` -| eval space_ratio = (mvcount(split(file_name," "))-1)/len(file_name) -| search space_ratio >= 0.1 -| rex field=recipient_address "(?.*)@" -| `email_attachments_with_lots_of_spaces_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **email_attachments_with_lots_of_spaces_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* All_Email.recipient -* All_Email.file_name -* All_Email.src_user -* All_Email.file_name -* All_Email.message_id - - -#### How To Implement -You need to ingest data from emails. Specifically, the sender's address and the file names of any attachments must be mapped to the Email data model. The threshold ratio is set to 10%, but this value can be configured to suit each environment. \ - **Splunk Phantom Playbook Integration**\ -If Splunk Phantom is also configured in your environment, a playbook called "Suspicious Email Attachment Investigate and Delete" can be configured to run when any results are found by this detection search. To use this integration, install the Phantom App for Splunk `https://splunkbase.splunk.com/app/3411/` and add the correct hostname to the "Phantom Instance" field in the Adaptive Response Actions when configuring this detection search. The notable event will be sent to Phantom and the playbook will gather further information about the file attachment and its network behaviors. If Phantom finds malicious behavior and an analyst approves of the results, the email will be deleted from the user's inbox. - -#### Known False Positives -None at this time - -#### Associated Analytic story -* [Hermetic Wiper](/stories/hermetic_wiper) -* [Emotet Malware DHS Report TA18-201A ](/stories/emotet_malware__dhs_report_ta18-201a_) -* [Suspicious Emails](/stories/suspicious_emails) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/application/email_attachments_with_lots_of_spaces.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2017-09-19-open_redirect_in_splunk_web.md b/docs/_posts/2017-09-19-open_redirect_in_splunk_web.md deleted file mode 100644 index 45c130424f..0000000000 --- a/docs/_posts/2017-09-19-open_redirect_in_splunk_web.md +++ /dev/null @@ -1,147 +0,0 @@ ---- -title: "Open Redirect in Splunk Web" -excerpt: "" -categories: - - Deprecated -last_modified_at: 2017-09-19 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2016-4859 ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search allows you to look for evidence of exploitation for CVE-2016-4859, the Splunk Open Redirect Vulnerability. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2017-09-19 -- **Author**: Bhavin Patel, Splunk -- **ID**: d199fb99-2312-451a-9daa-e5efa6ed76a7 - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Delivery - - -
-
- - -
- NIST - -
- -* ID.RA -* RS.MI -* PR.PT -* PR.AC -* PR.IP -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 4 -* CIS 18 - - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2016-4859](https://nvd.nist.gov/vuln/detail/CVE-2016-4859) | Open redirect vulnerability in Splunk Enterprise 6.4.x prior to 6.4.3, Splunk Enterprise 6.3.x prior to 6.3.6, Splunk Enterprise 6.2.x prior to 6.2.10, Splunk Enterprise 6.1.x prior to 6.1.11, Splunk Enterprise 6.0.x prior to 6.0.12, Splunk Enterprise 5.0.x prior to 5.0.16 and Splunk Light prior to 6.4.3 allows to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. | 5.8 | - - - -
-
- -#### Search - -``` -index=_internal sourcetype=splunk_web_access return_to="/%09/*" -| `open_redirect_in_splunk_web_filter` -``` - -#### Macros -The SPL above uses the following Macros: - -> :information_source: -> **open_redirect_in_splunk_web_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -No extra steps needed to implement this search. - -#### Known False Positives -None identified - -#### Associated Analytic story -* [Splunk Vulnerabilities](/stories/splunk_vulnerabilities) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/open_redirect_in_splunk_web.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2017-09-20-large_volume_of_dns_any_queries.md b/docs/_posts/2017-09-20-large_volume_of_dns_any_queries.md deleted file mode 100644 index 0c3e2400b8..0000000000 --- a/docs/_posts/2017-09-20-large_volume_of_dns_any_queries.md +++ /dev/null @@ -1,161 +0,0 @@ ---- -title: "Large Volume of DNS ANY Queries" -excerpt: "Network Denial of Service -, Reflection Amplification -" -categories: - - Network -last_modified_at: 2017-09-20 -toc: true -toc_label: "" -tags: - - Network Denial of Service - - Reflection Amplification - - Impact - - Impact - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Network_Resolution ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The search is used to identify attempts to use your DNS Infrastructure for DDoS purposes via a DNS amplification attack leveraging ANY queries. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Network_Resolution](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkResolution) -- **Last Updated**: 2017-09-20 -- **Author**: Bhavin Patel, Splunk -- **ID**: 8fa891f7-a533-4b3c-af85-5aa2e7c1f1eb - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1498](https://attack.mitre.org/techniques/T1498/) | Network Denial of Service | Impact | - -| [T1498.002](https://attack.mitre.org/techniques/T1498/002/) | Reflection Amplification | Impact | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.AE -* PR.IP - - - -
-
- -
- CIS20 - -
- -* CIS 11 -* CIS 12 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count from datamodel=Network_Resolution where nodename=DNS "DNS.message_type"="QUERY" "DNS.record_type"="ANY" by "DNS.dest" -| `drop_dm_object_name("DNS")` -| where count>200 -| `large_volume_of_dns_any_queries_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **large_volume_of_dns_any_queries_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* DNS.message_type -* DNS.record_type -* DNS.dest - - -#### How To Implement -To successfully implement this search you must ensure that DNS data is populating the Network_Resolution data model. - -#### Known False Positives -Legitimate ANY requests may trigger this search, however it is unusual to see a large volume of them under typical circumstances. You may modify the threshold in the search to better suit your environment. - -#### Associated Analytic story -* [DNS Amplification Attacks](/stories/dns_amplification_attacks) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/network/large_volume_of_dns_any_queries.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2017-09-23-detect_attackers_scanning_for_vulnerable_jboss_servers.md b/docs/_posts/2017-09-23-detect_attackers_scanning_for_vulnerable_jboss_servers.md deleted file mode 100644 index 410a212365..0000000000 --- a/docs/_posts/2017-09-23-detect_attackers_scanning_for_vulnerable_jboss_servers.md +++ /dev/null @@ -1,153 +0,0 @@ ---- -title: "Detect attackers scanning for vulnerable JBoss servers" -excerpt: "System Information Discovery -" -categories: - - Web -last_modified_at: 2017-09-23 -toc: true -toc_label: "" -tags: - - System Information Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Web ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for specific GET or HEAD requests to web servers that are indicative of reconnaissance attempts to identify vulnerable JBoss servers. JexBoss is described as the exploit tool of choice for this malicious activity. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Web](https://docs.splunk.com/Documentation/CIM/latest/User/Web) -- **Last Updated**: 2017-09-23 -- **Author**: Bhavin Patel, Splunk -- **ID**: 104658f4-afdc-499e-9719-17243f982681 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1082](https://attack.mitre.org/techniques/T1082/) | System Information Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Web where (Web.http_method="GET" OR Web.http_method="HEAD") AND (Web.url="*/web-console/ServerInfo.jsp*" OR Web.url="*web-console*" OR Web.url="*jmx-console*" OR Web.url = "*invoker*") by Web.http_method, Web.url, Web.src, Web.dest -| `drop_dm_object_name("Web")` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_attackers_scanning_for_vulnerable_jboss_servers_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **detect_attackers_scanning_for_vulnerable_jboss_servers_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Web.http_method -* Web.url -* Web.src -* Web.dest - - -#### How To Implement -You must be ingesting data from the web server or network traffic that contains web specific information, and populating the Web data model. - -#### Known False Positives -It's possible for legitimate HTTP requests to be made to URLs containing the suspicious paths. - -#### Associated Analytic story -* [JBoss Vulnerability](/stories/jboss_vulnerability) -* [SamSam Ransomware](/stories/samsam_ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/web/detect_attackers_scanning_for_vulnerable_jboss_servers.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2017-09-23-detect_malicious_requests_to_exploit_jboss_servers.md b/docs/_posts/2017-09-23-detect_malicious_requests_to_exploit_jboss_servers.md deleted file mode 100644 index 421516f284..0000000000 --- a/docs/_posts/2017-09-23-detect_malicious_requests_to_exploit_jboss_servers.md +++ /dev/null @@ -1,159 +0,0 @@ ---- -title: "Detect malicious requests to exploit JBoss servers" -excerpt: "" -categories: - - Web -last_modified_at: 2017-09-23 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Web ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is used to detect malicious HTTP requests crafted to exploit jmx-console in JBoss servers. The malicious requests have a long URL length, as the payload is embedded in the URL. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Web](https://docs.splunk.com/Documentation/CIM/latest/User/Web) -- **Last Updated**: 2017-09-23 -- **Author**: Bhavin Patel, Splunk -- **ID**: c8bff7a4-11ea-4416-a27d-c5bca472913d - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Delivery - - -
-
- - -
- NIST - -
- -* ID.RA -* PR.PT -* PR.IP -* DE.AE -* PR.MA -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 12 -* CIS 4 -* CIS 18 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Web where (Web.http_method="GET" OR Web.http_method="HEAD") by Web.http_method, Web.url,Web.url_length Web.src, Web.dest -| search Web.url="*jmx-console/HtmlAdaptor?action=invokeOpByName&name=jboss.admin*import*" AND Web.url_length > 200 -| `drop_dm_object_name("Web")` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| table src, dest_ip, http_method, url, firstTime, lastTime -| `detect_malicious_requests_to_exploit_jboss_servers_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **detect_malicious_requests_to_exploit_jboss_servers_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Web.http_method -* Web.url -* Web.url_length -* Web.src -* Web.dest - - -#### How To Implement -You must ingest data from the web server or capture network data that contains web specific information with solutions such as Bro or Splunk Stream, and populating the Web data model - -#### Known False Positives -No known false positives for this detection. - -#### Associated Analytic story -* [JBoss Vulnerability](/stories/jboss_vulnerability) -* [SamSam Ransomware](/stories/samsam_ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/web/detect_malicious_requests_to_exploit_jboss_servers.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2017-09-23-monitor_dns_for_brand_abuse.md b/docs/_posts/2017-09-23-monitor_dns_for_brand_abuse.md deleted file mode 100644 index 5860da8991..0000000000 --- a/docs/_posts/2017-09-23-monitor_dns_for_brand_abuse.md +++ /dev/null @@ -1,140 +0,0 @@ ---- -title: "Monitor DNS For Brand Abuse" -excerpt: "" -categories: - - Deprecated -last_modified_at: 2017-09-23 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Network_Resolution ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for DNS requests for faux domains similar to the domains that you want to have monitored for abuse. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Network_Resolution](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkResolution) -- **Last Updated**: 2017-09-23 -- **Author**: David Dorsey, Splunk -- **ID**: 24dd17b1-e2fb-4c31-878c-d4f746595bfa - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Delivery -* Actions on Objectives - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` values(DNS.answer) as IPs min(_time) as firstTime from datamodel=Network_Resolution by DNS.src, DNS.query -| `drop_dm_object_name("DNS")` -| `security_content_ctime(firstTime)` -| `brand_abuse_dns` -| `monitor_dns_for_brand_abuse_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [brand_abuse_dns](https://github.com/splunk/security_content/blob/develop/macros/brand_abuse_dns.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **monitor_dns_for_brand_abuse_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -You need to ingest data from your DNS logs. Specifically you must ingest the domain that is being queried and the IP of the host originating the request. Ideally, you should also be ingesting the answer to the query and the query type. This approach allows you to also create your own localized passive DNS capability which can aid you in future investigations. You also need to have run the search "ESCU - DNSTwist Domain Names", which creates the permutations of the domain that will be checked for. You also need the [`dnstwist`](https://gist.github.com/d1vious/c4c2aae7fa7d5cbb1f24adc5f6303) custom command. - -#### Known False Positives -None at this time - -#### Associated Analytic story -* [Brand Monitoring](/stories/brand_monitoring) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/monitor_dns_for_brand_abuse.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2017-09-23-monitor_web_traffic_for_brand_abuse.md b/docs/_posts/2017-09-23-monitor_web_traffic_for_brand_abuse.md deleted file mode 100644 index 051f22e654..0000000000 --- a/docs/_posts/2017-09-23-monitor_web_traffic_for_brand_abuse.md +++ /dev/null @@ -1,147 +0,0 @@ ---- -title: "Monitor Web Traffic For Brand Abuse" -excerpt: "" -categories: - - Web -last_modified_at: 2017-09-23 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Web ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for Web requests to faux domains similar to the one that you want to have monitored for abuse. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Web](https://docs.splunk.com/Documentation/CIM/latest/User/Web) -- **Last Updated**: 2017-09-23 -- **Author**: David Dorsey, Splunk -- **ID**: 134da869-e264-4a8f-8d7e-fcd0ec88f301 - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Delivery - - -
-
- - -
- NIST - -
- -* PR.IP - - - -
-
- -
- CIS20 - -
- -* CIS 7 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` values(Web.url) as urls min(_time) as firstTime from datamodel=Web by Web.src -| `drop_dm_object_name("Web")` -| `security_content_ctime(firstTime)` -| `brand_abuse_web` -| `monitor_web_traffic_for_brand_abuse_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [brand_abuse_web](https://github.com/splunk/security_content/blob/develop/macros/brand_abuse_web.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **monitor_web_traffic_for_brand_abuse_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Web.url -* Web.src - - -#### How To Implement -You need to ingest data from your web traffic. This can be accomplished by indexing data from a web proxy, or using a network traffic analysis tool, such as Bro or Splunk Stream. You also need to have run the search "ESCU - DNSTwist Domain Names", which creates the permutations of the domain that will be checked for. - -#### Known False Positives -None at this time - -#### Associated Analytic story -* [Brand Monitoring](/stories/brand_monitoring) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/web/monitor_web_traffic_for_brand_abuse.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2017-10-13-unusually_long_content-type_length.md b/docs/_posts/2017-10-13-unusually_long_content-type_length.md deleted file mode 100644 index 022670955d..0000000000 --- a/docs/_posts/2017-10-13-unusually_long_content-type_length.md +++ /dev/null @@ -1,155 +0,0 @@ ---- -title: "Unusually Long Content-Type Length" -excerpt: "" -categories: - - Network -last_modified_at: 2017-10-13 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for unusually long strings in the Content-Type http header that the client sends the server. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2017-10-13 -- **Author**: Bhavin Patel, Splunk -- **ID**: 57a0a2bf-353f-40c1-84dc-29293f3c35b7 - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Delivery - - -
-
- - -
- NIST - -
- -* ID.RA -* RS.MI -* PR.PT -* PR.IP -* DE.AE -* PR.MA -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 4 -* CIS 18 -* CIS 12 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`stream_http` -| eval cs_content_type_length = len(cs_content_type) -| where cs_content_type_length > 100 -| table endtime src_ip dest_ip cs_content_type_length cs_content_type url -| `unusually_long_content_type_length_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [stream_http](https://github.com/splunk/security_content/blob/develop/macros/stream_http.yml) - -> :information_source: -> **unusually_long_content-type_length_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* cs_content_type -* endtime -* src_ip -* dest_ip -* url - - -#### How To Implement -This particular search leverages data extracted from Stream:HTTP. You must configure the http stream using the Splunk Stream App on your Splunk Stream deployment server to extract the cs_content_type field. - -#### Known False Positives -Very few legitimate Content-Type fields will have a length greater than 100 characters. - -#### Associated Analytic story -* [Apache Struts Vulnerability](/stories/apache_struts_vulnerability) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/network/unusually_long_content_type_length.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2017-11-27-detect_usb_device_insertion.md b/docs/_posts/2017-11-27-detect_usb_device_insertion.md deleted file mode 100644 index d728677662..0000000000 --- a/docs/_posts/2017-11-27-detect_usb_device_insertion.md +++ /dev/null @@ -1,148 +0,0 @@ ---- -title: "Detect USB device insertion" -excerpt: "" -categories: - - Deprecated -last_modified_at: 2017-11-27 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Change_Analysis ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The search is used to detect hosts that generate Windows Event ID 4663 for successful attempts to write to or read from a removable storage and Event ID 4656 for failures, which occurs when a USB drive is plugged in. In this scenario we are querying the Change_Analysis data model to look for Windows Event ID 4656 or 4663 where the priority of the affected host is marked as high in the ES Assets and Identity Framework. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Change_Analysis](https://docs.splunk.com/Documentation/CIM/latest/User/ChangeAnalysis) -- **Last Updated**: 2017-11-27 -- **Author**: Bhavin Patel, Splunk -- **ID**: 104658f4-afdc-499f-9719-17a43f9826f5 - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Installation -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* PR.DS - - - -
-
- -
- CIS20 - -
- -* CIS 13 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count earliest(_time) AS earliest latest(_time) AS latest from datamodel=Change_Analysis where (nodename = All_Changes) All_Changes.result="Removable Storage device" (All_Changes.result_id=4663 OR All_Changes.result_id=4656) (All_Changes.src_priority=high) by All_Changes.dest -| `drop_dm_object_name("All_Changes")` -| `security_content_ctime(earliest)` -| `security_content_ctime(latest)` -| `detect_usb_device_insertion_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **detect_usb_device_insertion_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* All_Changes.result -* All_Changes.result_id -* All_Changes.src_priority -* All_Changes.dest - - -#### How To Implement -To successfully implement this search, you must ingest Windows Security Event logs and track event code 4663 and 4656. Ensure that the field from the event logs is being mapped to the result_id field in the Change_Analysis data model. To minimize the alert volume, this search leverages the Assets and Identity framework to filter out events from those assets not marked high priority in the Enterprise Security Assets and Identity Framework. - -#### Known False Positives -Legitimate USB activity will also be detected. Please verify and investigate as appropriate. - -#### Associated Analytic story -* [Data Protection](/stories/data_protection) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/detect_usb_device_insertion.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2018-01-05-monitor_email_for_brand_abuse.md b/docs/_posts/2018-01-05-monitor_email_for_brand_abuse.md deleted file mode 100644 index bfdf6ece90..0000000000 --- a/docs/_posts/2018-01-05-monitor_email_for_brand_abuse.md +++ /dev/null @@ -1,158 +0,0 @@ ---- -title: "Monitor Email For Brand Abuse" -excerpt: "" -categories: - - Application -last_modified_at: 2018-01-05 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Email ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for emails claiming to be sent from a domain similar to one that you want to have monitored for abuse. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Email](https://docs.splunk.com/Documentation/CIM/latest/User/Email) -- **Last Updated**: 2018-01-05 -- **Author**: David Dorsey, Splunk -- **ID**: b2ea1f38-3a3e-4b8a-9cf1-82760d86a6b8 - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Delivery - - -
-
- - -
- NIST - -
- -* PR.IP - - - -
-
- -
- CIS20 - -
- -* CIS 7 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` values(All_Email.recipient) as recipients, min(_time) as firstTime, max(_time) as lastTime from datamodel=Email by All_Email.src_user, All_Email.message_id -| `drop_dm_object_name("All_Email")` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| eval temp=split(src_user, "@") -| eval email_domain=mvindex(temp, 1) -| lookup update=true brandMonitoring_lookup domain as email_domain OUTPUT domain_abuse -| search domain_abuse=true -| table message_id, src_user, email_domain, recipients, firstTime, lastTime -| `monitor_email_for_brand_abuse_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **monitor_email_for_brand_abuse_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Lookups -The SPL above uses the following Lookups: - -* [brandMonitoring_lookup](https://github.com/splunk/security_content/blob/develop/lookups/brandMonitoring_lookup.yml) with [data](https://github.com/splunk/security_content/tree/develop/lookups/brandMonitoring_lookup.csv) - -#### Required field -* _time -* All_Email.recipient -* All_Email.src_user -* All_Email.message_id - - -#### How To Implement -You need to ingest email header data. Specifically the sender's address (src_user) must be populated. You also need to have run the search "ESCU - DNSTwist Domain Names", which creates the permutations of the domain that will be checked for. - -#### Known False Positives -None at this time - -#### Associated Analytic story -* [Brand Monitoring](/stories/brand_monitoring) -* [Suspicious Emails](/stories/suspicious_emails) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/application/monitor_email_for_brand_abuse.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2018-02-23-ec2_instance_started_in_previously_unseen_region.md b/docs/_posts/2018-02-23-ec2_instance_started_in_previously_unseen_region.md deleted file mode 100644 index 5208a6be64..0000000000 --- a/docs/_posts/2018-02-23-ec2_instance_started_in_previously_unseen_region.md +++ /dev/null @@ -1,156 +0,0 @@ ---- -title: "EC2 Instance Started In Previously Unseen Region" -excerpt: "Unused/Unsupported Cloud Regions -" -categories: - - Deprecated -last_modified_at: 2018-02-23 -toc: true -toc_label: "" -tags: - - Unused/Unsupported Cloud Regions - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for AWS CloudTrail events where an instance is started in a particular region in the last one hour and then compares it to a lookup file of previously seen regions where an instance was started - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2018-02-23 -- **Author**: Bhavin Patel, Splunk -- **ID**: ada0f478-84a8-4641-a3f3-d82362d6fd75 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1535](https://attack.mitre.org/techniques/T1535/) | Unused/Unsupported Cloud Regions | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.DP -* DE.AE - - - -
-
- -
- CIS20 - -
- -* CIS 12 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cloudtrail` earliest=-1h StartInstances -| stats earliest(_time) as earliest latest(_time) as latest by awsRegion -| inputlookup append=t previously_seen_aws_regions.csv -| stats min(earliest) as earliest max(latest) as latest by awsRegion -| outputlookup previously_seen_aws_regions.csv -| eval regionStatus=if(earliest >= relative_time(now(),"-1d@d"), "Instance Started in a New Region","Previously Seen Region") -| `security_content_ctime(earliest)` -| `security_content_ctime(latest)` -| where regionStatus="Instance Started in a New Region" -| `ec2_instance_started_in_previously_unseen_region_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) - -> :information_source: -> **ec2_instance_started_in_previously_unseen_region_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* awsRegion - - -#### How To Implement -You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your AWS CloudTrail inputs. Run the "Previously seen AWS Regions" support search only once to create of baseline of previously seen regions. This search is deprecated and have been translated to use the latest Change Datamodel. - -#### Known False Positives -It's possible that a user has unknowingly started an instance in a new region. Please verify that this activity is legitimate. - -#### Associated Analytic story -* [AWS Cryptomining](/stories/aws_cryptomining) -* [Suspicious AWS EC2 Activities](/stories/suspicious_aws_ec2_activities) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/ec2_instance_started_in_previously_unseen_region.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2018-03-12-ec2_instance_started_with_previously_unseen_ami.md b/docs/_posts/2018-03-12-ec2_instance_started_with_previously_unseen_ami.md deleted file mode 100644 index 3c1752ed2c..0000000000 --- a/docs/_posts/2018-03-12-ec2_instance_started_with_previously_unseen_ami.md +++ /dev/null @@ -1,153 +0,0 @@ ---- -title: "EC2 Instance Started With Previously Unseen AMI" -excerpt: "" -categories: - - Deprecated -last_modified_at: 2018-03-12 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for EC2 instances being created with previously unseen AMIs. This search is deprecated and have been translated to use the latest Change Datamodel. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2018-03-12 -- **Author**: David Dorsey, Splunk -- **ID**: 347ec301-601b-48b9-81aa-9ddf9c829dd3 - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* ID.AM - - - -
-
- -
- CIS20 - -
- -* CIS 1 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cloudtrail` eventName=RunInstances [search `cloudtrail` eventName=RunInstances errorCode=success -| stats earliest(_time) as firstTime latest(_time) as lastTime by requestParameters.instancesSet.items{}.imageId -| rename requestParameters.instancesSet.items{}.imageId as amiID -| inputlookup append=t previously_seen_ec2_amis.csv -| stats min(firstTime) as firstTime max(lastTime) as lastTime by amiID -| outputlookup previously_seen_ec2_amis.csv -| eval newAMI=if(firstTime >= relative_time(now(), "-70m@m"), 1, 0) -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -| where newAMI=1 -| rename amiID as requestParameters.instancesSet.items{}.imageId -| table requestParameters.instancesSet.items{}.imageId] -| rename requestParameters.instanceType as instanceType, responseElements.instancesSet.items{}.instanceId as dest, userIdentity.arn as arn, requestParameters.instancesSet.items{}.imageId as amiID -| table firstTime, lastTime, arn, amiID, dest, instanceType -| `ec2_instance_started_with_previously_unseen_ami_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) - -> :information_source: -> **ec2_instance_started_with_previously_unseen_ami_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* eventName -* errorCode -* requestParameters.instancesSet.items{}.imageId - - -#### How To Implement -You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your AWS CloudTrail inputs. This search works best when you run the "Previously Seen EC2 AMIs" support search once to create a history of previously seen AMIs. - -#### Known False Positives -After a new AMI is created, the first systems created with that AMI will cause this alert to fire. Verify that the AMI being used was created by a legitimate user. - -#### Associated Analytic story -* [AWS Cryptomining](/stories/aws_cryptomining) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_ami.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2018-03-16-aws_cloud_provisioning_from_previously_unseen_city.md b/docs/_posts/2018-03-16-aws_cloud_provisioning_from_previously_unseen_city.md deleted file mode 100644 index 3549d32c1a..0000000000 --- a/docs/_posts/2018-03-16-aws_cloud_provisioning_from_previously_unseen_city.md +++ /dev/null @@ -1,162 +0,0 @@ ---- -title: "AWS Cloud Provisioning From Previously Unseen City" -excerpt: "Unused/Unsupported Cloud Regions -" -categories: - - Deprecated -last_modified_at: 2018-03-16 -toc: true -toc_label: "" -tags: - - Unused/Unsupported Cloud Regions - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for AWS provisioning activities from previously unseen cities. Provisioning activities are defined broadly as any event that begins with "Run" or "Create." This search is deprecated and have been translated to use the latest Change Datamodel. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2018-03-16 -- **Author**: David Dorsey, Splunk -- **ID**: 344a1778-0b25-490c-adb1-de8beddf59cd - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1535](https://attack.mitre.org/techniques/T1535/) | Unused/Unsupported Cloud Regions | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* ID.AM - - - -
-
- -
- CIS20 - -
- -* CIS 1 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cloudtrail` (eventName=Run* OR eventName=Create*) -| iplocation sourceIPAddress -| search City=* [search `cloudtrail` (eventName=Run* OR eventName=Create*) -| iplocation sourceIPAddress -| search City=* -| stats earliest(_time) as firstTime, latest(_time) as lastTime by sourceIPAddress, City, Region, Country -| inputlookup append=t previously_seen_provisioning_activity_src.csv -| stats min(firstTime) as firstTime max(lastTime) as lastTime by sourceIPAddress, City, Region, Country -| outputlookup previously_seen_provisioning_activity_src.csv -| stats min(firstTime) as firstTime max(lastTime) as lastTime by City -| eval newCity=if(firstTime >= relative_time(now(), "-70m@m"), 1, 0) -| where newCity=1 -| table City] -| spath output=user userIdentity.arn -| rename sourceIPAddress as src_ip -| table _time, user, src_ip, City, eventName, errorCode -| `aws_cloud_provisioning_from_previously_unseen_city_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) - -> :information_source: -> **aws_cloud_provisioning_from_previously_unseen_city_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* eventName -* sourceIPAddress - - -#### How To Implement -You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your AWS CloudTrail inputs. This search works best when you run the "Previously Seen AWS Provisioning Activity Sources" support search once to create a history of previously seen locations that have provisioned AWS resources. - -#### Known False Positives -This is a strictly behavioral search, so we define "false positive" slightly differently. Every time this fires, it will accurately reflect the first occurrence in the time period you're searching within, plus what is stored in the cache feature. But while there are really no "false positives" in a traditional sense, there is definitely lots of noise.\ - This search will fire any time a new city is seen in the **GeoIP** database for any kind of provisioning activity. If you typically do all provisioning from tools inside of your city, there should be few false positives. If you are located in countries where the free version of **MaxMind GeoIP** that ships by default with Splunk has weak resolution (particularly small countries in less economically powerful regions), this may be much less valuable to you. - -#### Associated Analytic story -* [AWS Suspicious Provisioning Activities](/stories/aws_suspicious_provisioning_activities) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2018-03-16-aws_cloud_provisioning_from_previously_unseen_country.md b/docs/_posts/2018-03-16-aws_cloud_provisioning_from_previously_unseen_country.md deleted file mode 100644 index df3f85325a..0000000000 --- a/docs/_posts/2018-03-16-aws_cloud_provisioning_from_previously_unseen_country.md +++ /dev/null @@ -1,162 +0,0 @@ ---- -title: "AWS Cloud Provisioning From Previously Unseen Country" -excerpt: "Unused/Unsupported Cloud Regions -" -categories: - - Deprecated -last_modified_at: 2018-03-16 -toc: true -toc_label: "" -tags: - - Unused/Unsupported Cloud Regions - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for AWS provisioning activities from previously unseen countries. Provisioning activities are defined broadly as any event that begins with "Run" or "Create." This search is deprecated and have been translated to use the latest Change Datamodel. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2018-03-16 -- **Author**: David Dorsey, Splunk -- **ID**: ceb8d3d8-06cb-49eb-beaf-829526e33ff0 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1535](https://attack.mitre.org/techniques/T1535/) | Unused/Unsupported Cloud Regions | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* ID.AM - - - -
-
- -
- CIS20 - -
- -* CIS 1 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cloudtrail` (eventName=Run* OR eventName=Create*) -| iplocation sourceIPAddress -| search Country=* [search `cloudtrail` (eventName=Run* OR eventName=Create*) -| iplocation sourceIPAddress -| search Country=* -| stats earliest(_time) as firstTime, latest(_time) as lastTime by sourceIPAddress, City, Region, Country -| inputlookup append=t previously_seen_provisioning_activity_src.csv -| stats min(firstTime) as firstTime max(lastTime) as lastTime by sourceIPAddress, City, Region, Country -| outputlookup previously_seen_provisioning_activity_src.csv -| stats min(firstTime) as firstTime max(lastTime) as lastTime by Country -| eval newCountry=if(firstTime >= relative_time(now(), "-70m@m"), 1, 0) -| where newCountry=1 -| table Country] -| spath output=user userIdentity.arn -| rename sourceIPAddress as src_ip -| table _time, user, src_ip, Country, eventName, errorCode -| `aws_cloud_provisioning_from_previously_unseen_country_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) - -> :information_source: -> **aws_cloud_provisioning_from_previously_unseen_country_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* eventName -* sourceIPAddress - - -#### How To Implement -You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your AWS CloudTrail inputs. This search works best when you run the "Previously Seen AWS Provisioning Activity Sources" support search once to create a history of previously seen locations that have provisioned AWS resources. - -#### Known False Positives -This is a strictly behavioral search, so we define "false positive" slightly differently. Every time this fires, it will accurately reflect the first occurrence in the time period you're searching over plus what is stored in the cache feature. But while there are really no "false positives" in a traditional sense, there is definitely lots of noise.\ - This search will fire any time a new country is seen in the **GeoIP** database for any kind of provisioning activity. If you typically do all provisioning from tools inside of your country, there should be few false positives. If you are located in countries where the free version of **MaxMind GeoIP** that ships by default with Splunk has weak resolution (particularly small countries in less economically powerful regions), this may be much less valuable to you. - -#### Associated Analytic story -* [AWS Suspicious Provisioning Activities](/stories/aws_suspicious_provisioning_activities) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2018-03-16-aws_cloud_provisioning_from_previously_unseen_ip_address.md b/docs/_posts/2018-03-16-aws_cloud_provisioning_from_previously_unseen_ip_address.md deleted file mode 100644 index de6d30f26d..0000000000 --- a/docs/_posts/2018-03-16-aws_cloud_provisioning_from_previously_unseen_ip_address.md +++ /dev/null @@ -1,152 +0,0 @@ ---- -title: "AWS Cloud Provisioning From Previously Unseen IP Address" -excerpt: "" -categories: - - Deprecated -last_modified_at: 2018-03-16 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for AWS provisioning activities from previously unseen IP addresses. Provisioning activities are defined broadly as any event that begins with "Run" or "Create." This search is deprecated and have been translated to use the latest Change Datamodel. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2018-03-16 -- **Author**: David Dorsey, Splunk -- **ID**: 42e15012-ac14-4801-94f4-f1acbe64880b - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* ID.AM - - - -
-
- -
- CIS20 - -
- -* CIS 1 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cloudtrail` (eventName=Run* OR eventName=Create*) [search `cloudtrail` (eventName=Run* OR eventName=Create*) -| iplocation sourceIPAddress -| search Country=* -| stats earliest(_time) as firstTime, latest(_time) as lastTime by sourceIPAddress, City, Region, Country -| inputlookup append=t previously_seen_provisioning_activity_src.csv -| stats min(firstTime) as firstTime max(lastTime) as lastTime by sourceIPAddress, City, Region, Country -| outputlookup previously_seen_provisioning_activity_src.csv -| stats min(firstTime) as firstTime max(lastTime) as lastTime by sourceIPAddress -| eval newIP=if(firstTime >= relative_time(now(), "-70m@m"), 1, 0) -| where newIP=1 -| table sourceIPAddress] -| spath output=user userIdentity.arn -| rename sourceIPAddress as src_ip -| table _time, user, src_ip, eventName, errorCode -| `aws_cloud_provisioning_from_previously_unseen_ip_address_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) - -> :information_source: -> **aws_cloud_provisioning_from_previously_unseen_ip_address_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* eventName -* sourceIPAddress - - -#### How To Implement -You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your AWS CloudTrail inputs. This search works best when you run the "Previously Seen AWS Provisioning Activity Sources" support search once to create a history of previously seen locations that have provisioned AWS resources. - -#### Known False Positives -This is a strictly behavioral search, so we define "false positive" slightly differently. Every time this fires, it will accurately reflect the first occurrence in the time period you're searching within, plus what is stored in the cache feature. But while there are really no "false positives" in a traditional sense, there is definitely lots of noise.\ - This search will fire any time a new IP address is seen in the **GeoIP** database for any kind of provisioning activity. If you typically do all provisioning from tools inside of your country, there should be few false positives. If you are located in countries where the free version of **MaxMind GeoIP** that ships by default with Splunk has weak resolution (particularly small countries in less economically powerful regions), this may be much less valuable to you. - -#### Associated Analytic story -* [AWS Suspicious Provisioning Activities](/stories/aws_suspicious_provisioning_activities) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_ip_address.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2018-03-16-aws_cloud_provisioning_from_previously_unseen_region.md b/docs/_posts/2018-03-16-aws_cloud_provisioning_from_previously_unseen_region.md deleted file mode 100644 index c208be78bb..0000000000 --- a/docs/_posts/2018-03-16-aws_cloud_provisioning_from_previously_unseen_region.md +++ /dev/null @@ -1,162 +0,0 @@ ---- -title: "AWS Cloud Provisioning From Previously Unseen Region" -excerpt: "Unused/Unsupported Cloud Regions -" -categories: - - Deprecated -last_modified_at: 2018-03-16 -toc: true -toc_label: "" -tags: - - Unused/Unsupported Cloud Regions - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for AWS provisioning activities from previously unseen regions. Region in this context is similar to a state in the United States. Provisioning activities are defined broadly as any event that begins with "Run" or "Create." This search is deprecated and have been translated to use the latest Change Datamodel. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2018-03-16 -- **Author**: David Dorsey, Splunk -- **ID**: 7971d3df-da82-4648-a6e5-b5637bea5253 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1535](https://attack.mitre.org/techniques/T1535/) | Unused/Unsupported Cloud Regions | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* ID.AM - - - -
-
- -
- CIS20 - -
- -* CIS 1 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cloudtrail` (eventName=Run* OR eventName=Create*) -| iplocation sourceIPAddress -| search Region=* [search `cloudtrail` (eventName=Run* OR eventName=Create*) -| iplocation sourceIPAddress -| search Region=* -| stats earliest(_time) as firstTime, latest(_time) as lastTime by sourceIPAddress, City, Region, Country -| inputlookup append=t previously_seen_provisioning_activity_src.csv -| stats min(firstTime) as firstTime max(lastTime) as lastTime by sourceIPAddress, City, Region, Country -| outputlookup previously_seen_provisioning_activity_src.csv -| stats min(firstTime) as firstTime max(lastTime) as lastTime by Region -| eval newRegion=if(firstTime >= relative_time(now(), "-70m@m"), 1, 0) -| where newRegion=1 -| table Region] -| spath output=user userIdentity.arn -| rename sourceIPAddress as src_ip -| table _time, user, src_ip, Region, eventName, errorCode -| `aws_cloud_provisioning_from_previously_unseen_region_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) - -> :information_source: -> **aws_cloud_provisioning_from_previously_unseen_region_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* eventName -* sourceIPAddress - - -#### How To Implement -You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your AWS CloudTrail inputs. This search works best when you run the "Previously Seen AWS Provisioning Activity Sources" support search once to create a history of previously seen locations that have provisioned AWS resources. - -#### Known False Positives -This is a strictly behavioral search, so we define "false positive" slightly differently. Every time this fires, it will accurately reflect the first occurrence in the time period you're searching within, plus what is stored in the cache feature. But while there are really no "false positives" in a traditional sense, there is definitely lots of noise.\ - This search will fire any time a new region is seen in the **GeoIP** database for any kind of provisioning activity. If you typically do all provisioning from tools inside of your region, there should be few false positives. If you are located in regions where the free version of **MaxMind GeoIP** that ships by default with Splunk has weak resolution (particularly small countries in less economically powerful regions), this may be much less valuable to you. - -#### Associated Analytic story -* [AWS Suspicious Provisioning Activities](/stories/aws_suspicious_provisioning_activities) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2018-04-16-detect_new_api_calls_from_user_roles.md b/docs/_posts/2018-04-16-detect_new_api_calls_from_user_roles.md deleted file mode 100644 index 3bc744ed03..0000000000 --- a/docs/_posts/2018-04-16-detect_new_api_calls_from_user_roles.md +++ /dev/null @@ -1,171 +0,0 @@ ---- -title: "Detect new API calls from user roles" -excerpt: "Cloud Accounts -" -categories: - - Deprecated -last_modified_at: 2018-04-16 -toc: true -toc_label: "" -tags: - - Cloud Accounts - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search detects new API calls that have either never been seen before or that have not been seen in the previous hour, where the identity type is `AssumedRole`. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2018-04-16 -- **Author**: Bhavin Patel, Splunk -- **ID**: 22773e84-bac0-4595-b086-20d3f335b4f1 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1078.004](https://attack.mitre.org/techniques/T1078/004/) | Cloud Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* ID.AM - - - -
-
- -
- CIS20 - -
- -* CIS 1 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cloudtrail` eventType=AwsApiCall errorCode=success userIdentity.type=AssumedRole [search `cloudtrail` eventType=AwsApiCall errorCode=success userIdentity.type=AssumedRole -| stats earliest(_time) as earliest latest(_time) as latest by userName eventName -| inputlookup append=t previously_seen_api_calls_from_user_roles -| stats min(earliest) as earliest, max(latest) as latest by userName eventName -| outputlookup previously_seen_api_calls_from_user_roles -| eval newApiCallfromUserRole=if(earliest>=relative_time(now(), "-70m@m"), 1, 0) -| where newApiCallfromUserRole=1 -| `security_content_ctime(earliest)` -| `security_content_ctime(latest)` -| table eventName userName] -|rename userName as user -| stats values(eventName) earliest(_time) as earliest latest(_time) as latest by user -| `security_content_ctime(earliest)` -| `security_content_ctime(latest)` -| `detect_new_api_calls_from_user_roles_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) - -> :information_source: -> **detect_new_api_calls_from_user_roles_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Lookups -The SPL above uses the following Lookups: - -* [previously_seen_api_calls_from_user_roles](https://github.com/splunk/security_content/blob/develop/lookups/previously_seen_api_calls_from_user_roles.yml) with [data](https://github.com/splunk/security_content/tree/develop/lookups/previously_seen_api_calls_from_user_roles.csv) - -#### Required field -* _time -* eventType -* errorCode -* userIdentity.type -* userName -* eventName - - -#### How To Implement -You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your AWS CloudTrail inputs. This search works best when you run the "Previously seen API call per user roles in AWS CloudTrail" support search once to create a history of previously seen user roles. - -#### Known False Positives -It is possible that there are legitimate user roles making new or infrequently used API calls in your infrastructure, causing the search to trigger. - -#### Associated Analytic story -* [AWS User Monitoring](/stories/aws_user_monitoring) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2018-04-18-detect_spike_in_security_group_activity.md b/docs/_posts/2018-04-18-detect_spike_in_security_group_activity.md deleted file mode 100644 index ba87d130b6..0000000000 --- a/docs/_posts/2018-04-18-detect_spike_in_security_group_activity.md +++ /dev/null @@ -1,175 +0,0 @@ ---- -title: "Detect Spike in Security Group Activity" -excerpt: "Cloud Accounts -" -categories: - - Deprecated -last_modified_at: 2018-04-18 -toc: true -toc_label: "" -tags: - - Cloud Accounts - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search will detect users creating spikes in API activity related to security groups in your AWS environment. It will also update the cache file that factors in the latest data. This search is deprecated and have been translated to use the latest Change Datamodel. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2018-04-18 -- **Author**: Bhavin Patel, Splunk -- **ID**: ada0f478-84a8-4641-a3f1-e32372d4bd53 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1078.004](https://attack.mitre.org/techniques/T1078/004/) | Cloud Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.DP -* DE.CM -* PR.AC - - - -
-
- -
- CIS20 - -
- -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cloudtrail` `security_group_api_calls` [search `cloudtrail` `security_group_api_calls` -| spath output=arn path=userIdentity.arn -| stats count as apiCalls by arn -| inputlookup security_group_activity_baseline append=t -| fields - latestCount -| stats values(*) as * by arn -| rename apiCalls as latestCount -| eval newAvgApiCalls=avgApiCalls + (latestCount-avgApiCalls)/720 -| eval newStdevApiCalls=sqrt(((pow(stdevApiCalls, 2)*719 + (latestCount-newAvgApiCalls)*(latestCount-avgApiCalls))/720)) -| eval avgApiCalls=coalesce(newAvgApiCalls, avgApiCalls), stdevApiCalls=coalesce(newStdevApiCalls, stdevApiCalls), numDataPoints=if(isnull(latestCount), numDataPoints, numDataPoints+1) -| table arn, latestCount, numDataPoints, avgApiCalls, stdevApiCalls -| outputlookup security_group_activity_baseline -| eval dataPointThreshold = 15, deviationThreshold = 3 -| eval isSpike=if((latestCount > avgApiCalls+deviationThreshold*stdevApiCalls) AND numDataPoints > dataPointThreshold, 1, 0) -| where isSpike=1 -| rename arn as userIdentity.arn -| table userIdentity.arn] -| spath output=user userIdentity.arn -| stats values(eventName) as eventNames, count as numberOfApiCalls, dc(eventName) as uniqueApisCalled by user -| `detect_spike_in_security_group_activity_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_group_api_calls](https://github.com/splunk/security_content/blob/develop/macros/security_group_api_calls.yml) -* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) - -> :information_source: -> **detect_spike_in_security_group_activity_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Lookups -The SPL above uses the following Lookups: - -* [security_group_activity_baseline](https://github.com/splunk/security_content/blob/develop/lookups/security_group_activity_baseline.yml) with [data](https://github.com/splunk/security_content/tree/develop/lookups/security_group_activity_baseline.csv) -* [security_group_activity_baseline](https://github.com/splunk/security_content/blob/develop/lookups/security_group_activity_baseline.yml) with [data](https://github.com/splunk/security_content/tree/develop/lookups/security_group_activity_baseline.csv) - -#### Required field -* _time -* serIdentity.arn - - -#### How To Implement -You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your AWS CloudTrail inputs. You can modify `dataPointThreshold` and `deviationThreshold` to better fit your environment. The `dataPointThreshold` variable is the minimum number of data points required to have a statistically significant amount of data to determine. The `deviationThreshold` variable is the number of standard deviations away from the mean that the value must be to be considered a spike.This search works best when you run the "Baseline of Security Group Activity by ARN" support search once to create a history of previously seen Security Group Activity. To add or remove API event names for security groups, edit the macro `security_group_api_calls`. - -#### Known False Positives -Based on the values of`dataPointThreshold` and `deviationThreshold`, the false positive rate may vary. Please modify this according the your environment. - -#### Associated Analytic story -* [AWS User Monitoring](/stories/aws_user_monitoring) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/detect_spike_in_security_group_activity.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2018-05-07-detect_spike_in_blocked_outbound_traffic_from_your_aws.md b/docs/_posts/2018-05-07-detect_spike_in_blocked_outbound_traffic_from_your_aws.md deleted file mode 100644 index b7091dac1a..0000000000 --- a/docs/_posts/2018-05-07-detect_spike_in_blocked_outbound_traffic_from_your_aws.md +++ /dev/null @@ -1,167 +0,0 @@ ---- -title: "Detect Spike in blocked Outbound Traffic from your AWS" -excerpt: "" -categories: - - Cloud -last_modified_at: 2018-05-07 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search will detect spike in blocked outbound network connections originating from within your AWS environment. It will also update the cache file that factors in the latest data. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2018-05-07 -- **Author**: Bhavin Patel, Splunk -- **ID**: d3fffa37-492f-487b-a35d-c60fcb2acf01 - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives -* Command & Control - - -
-
- - -
- NIST - -
- -* DE.AE -* DE.CM -* PR.AC - - - -
-
- -
- CIS20 - -
- -* CIS 11 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cloudwatchlogs_vpcflow` action=blocked (src_ip=10.0.0.0/8 OR src_ip=172.16.0.0/12 OR src_ip=192.168.0.0/16) ( dest_ip!=10.0.0.0/8 AND dest_ip!=172.16.0.0/12 AND dest_ip!=192.168.0.0/16) [search `cloudwatchlogs_vpcflow` action=blocked (src_ip=10.0.0.0/8 OR src_ip=172.16.0.0/12 OR src_ip=192.168.0.0/16) ( dest_ip!=10.0.0.0/8 AND dest_ip!=172.16.0.0/12 AND dest_ip!=192.168.0.0/16) -| stats count as numberOfBlockedConnections by src_ip -| inputlookup baseline_blocked_outbound_connections append=t -| fields - latestCount -| stats values(*) as * by src_ip -| rename numberOfBlockedConnections as latestCount -| eval newAvgBlockedConnections=avgBlockedConnections + (latestCount-avgBlockedConnections)/720 -| eval newStdevBlockedConnections=sqrt(((pow(stdevBlockedConnections, 2)*719 + (latestCount-newAvgBlockedConnections)*(latestCount-avgBlockedConnections))/720)) -| eval avgBlockedConnections=coalesce(newAvgBlockedConnections, avgBlockedConnections), stdevBlockedConnections=coalesce(newStdevBlockedConnections, stdevBlockedConnections), numDataPoints=if(isnull(latestCount), numDataPoints, numDataPoints+1) -| table src_ip, latestCount, numDataPoints, avgBlockedConnections, stdevBlockedConnections -| outputlookup baseline_blocked_outbound_connections -| eval dataPointThreshold = 5, deviationThreshold = 3 -| eval isSpike=if((latestCount > avgBlockedConnections+deviationThreshold*stdevBlockedConnections) AND numDataPoints > dataPointThreshold, 1, 0) -| where isSpike=1 -| table src_ip] -| stats values(dest_ip) as "Blocked Destination IPs", values(interface_id) as "resourceId" count as numberOfBlockedConnections, dc(dest_ip) as uniqueDestConnections by src_ip -| `detect_spike_in_blocked_outbound_traffic_from_your_aws_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [cloudwatchlogs_vpcflow](https://github.com/splunk/security_content/blob/develop/macros/cloudwatchlogs_vpcflow.yml) - -> :information_source: -> **detect_spike_in_blocked_outbound_traffic_from_your_aws_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Lookups -The SPL above uses the following Lookups: - -* [baseline_blocked_outbound_connections](https://github.com/splunk/security_content/blob/develop/lookups/baseline_blocked_outbound_connections.yml) with [data](https://github.com/splunk/security_content/tree/develop/lookups/baseline_blocked_outbound_connections.csv) -* [baseline_blocked_outbound_connections](https://github.com/splunk/security_content/blob/develop/lookups/baseline_blocked_outbound_connections.yml) with [data](https://github.com/splunk/security_content/tree/develop/lookups/baseline_blocked_outbound_connections.csv) - -#### Required field -* _time -* action -* src_ip -* dest_ip - - -#### How To Implement -You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your VPC Flow logs. You can modify `dataPointThreshold` and `deviationThreshold` to better fit your environment. The `dataPointThreshold` variable is the number of data points required to meet the definition of "spike." The `deviationThreshold` variable is the number of standard deviations away from the mean that the value must be to be considered a spike. This search works best when you run the "Baseline of Blocked Outbound Connection" support search once to create a history of previously seen blocked outbound connections. - -#### Known False Positives -The false-positive rate may vary based on the values of`dataPointThreshold` and `deviationThreshold`. Additionally, false positives may result when AWS administrators roll out policies enforcing network blocks, causing sudden increases in the number of blocked outbound connections. - -#### Associated Analytic story -* [AWS Network ACL Activity](/stories/aws_network_acl_activity) -* [Suspicious AWS Traffic](/stories/suspicious_aws_traffic) -* [Command and Control](/stories/command_and_control) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/cloud/detect_spike_in_blocked_outbound_traffic_from_your_aws.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2018-05-17-detect_api_activity_from_users_without_mfa.md b/docs/_posts/2018-05-17-detect_api_activity_from_users_without_mfa.md deleted file mode 100644 index 2a13cabd7e..0000000000 --- a/docs/_posts/2018-05-17-detect_api_activity_from_users_without_mfa.md +++ /dev/null @@ -1,161 +0,0 @@ ---- -title: "Detect API activity from users without MFA" -excerpt: "" -categories: - - Deprecated -last_modified_at: 2018-05-17 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for AWS CloudTrail events where a user logged into the AWS account, is making API calls and has not enabled Multi Factor authentication. Multi factor authentication adds a layer of security by forcing the users to type a unique authentication code from an approved authentication device when they access AWS websites or services. AWS Best Practices recommend that you enable MFA for privileged IAM users. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2018-05-17 -- **Author**: Bhavin Patel, Splunk -- **ID**: 4d46e8bd-4072-48e4-92db-0325889ef894 - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.DP -* PR.AC - - - -
-
- -
- CIS20 - -
- -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cloudtrail` userIdentity.sessionContext.attributes.mfaAuthenticated=false -| search NOT [ -| inputlookup aws_service_accounts -| fields identity -| rename identity as user] -| stats count min(_time) as firstTime max(_time) as lastTime values(eventName) as eventName by userIdentity.arn userIdentity.type user -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_api_activity_from_users_without_mfa_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) - -> :information_source: -> **detect_api_activity_from_users_without_mfa_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Lookups -The SPL above uses the following Lookups: - -* [aws_service_accounts](https://github.com/splunk/security_content/blob/develop/lookups/aws_service_accounts.yml) with [data](https://github.com/splunk/security_content/tree/develop/lookups/aws_service_accounts.csv) - -#### Required field -* _time -* userIdentity.sessionContext.attributes.mfaAuthenticated -* eventName -* userIdentity.arn -* userIdentity.type -* user - - -#### How To Implement -You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your AWS CloudTrail inputs. Leverage the support search `Create a list of approved AWS service accounts`: run it once every 30 days to create a list of service accounts and validate them.\ -This search produces fields (`eventName`,`userIdentity.type`,`userIdentity.arn`) that are not yet supported by ES Incident Review and therefore cannot be viewed when a notable event is raised. These fields contribute additional context to the notable. To see the additional metadata, add the following fields, if not already present, to Incident Review - Event Attributes (Configure > Incident Management > Incident Review Settings > Add New Entry):\\n1. **Label:** AWS Event Name, **Field:** eventName\ -1. \ -1. **Label:** AWS User ARN, **Field:** userIdentity.arn\ -1. \ -1. **Label:** AWS User Type, **Field:** userIdentity.type\ -Detailed documentation on how to create a new field within Incident Review may be found here: `https://docs.splunk.com/Documentation/ES/5.3.0/Admin/Customizenotables#Add_a_field_to_the_notable_event_details` - -#### Known False Positives -Many service accounts configured within an AWS infrastructure do not have multi factor authentication enabled. Please ignore the service accounts, if triggered and instead add them to the aws_service_accounts.csv file to fine tune the detection. It is also possible that the search detects users in your environment using Single Sign-On systems, since the MFA is not handled by AWS. - -#### Associated Analytic story -* [AWS User Monitoring](/stories/aws_user_monitoring) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/detect_api_activity_from_users_without_mfa.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2018-05-21-detect_spike_in_network_acl_activity.md b/docs/_posts/2018-05-21-detect_spike_in_network_acl_activity.md deleted file mode 100644 index c5f5fd575e..0000000000 --- a/docs/_posts/2018-05-21-detect_spike_in_network_acl_activity.md +++ /dev/null @@ -1,173 +0,0 @@ ---- -title: "Detect Spike in Network ACL Activity" -excerpt: "Disable or Modify Cloud Firewall -" -categories: - - Deprecated -last_modified_at: 2018-05-21 -toc: true -toc_label: "" -tags: - - Disable or Modify Cloud Firewall - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search will detect users creating spikes in API activity related to network access-control lists (ACLs)in your AWS environment. This search is deprecated and have been translated to use the latest Change Datamodel. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2018-05-21 -- **Author**: Bhavin Patel, Splunk -- **ID**: ada0f478-84a8-4641-a1f1-e32372d4bd53 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.007](https://attack.mitre.org/techniques/T1562/007/) | Disable or Modify Cloud Firewall | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.DP -* DE.CM -* PR.AC - - - -
-
- -
- CIS20 - -
- -* CIS 12 -* CIS 11 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cloudtrail` `network_acl_events` [search `cloudtrail` `network_acl_events` -| spath output=arn path=userIdentity.arn -| stats count as apiCalls by arn -| inputlookup network_acl_activity_baseline append=t -| fields - latestCount -| stats values(*) as * by arn -| rename apiCalls as latestCount -| eval newAvgApiCalls=avgApiCalls + (latestCount-avgApiCalls)/720 -| eval newStdevApiCalls=sqrt(((pow(stdevApiCalls, 2)*719 + (latestCount-newAvgApiCalls)*(latestCount-avgApiCalls))/720)) -| eval avgApiCalls=coalesce(newAvgApiCalls, avgApiCalls), stdevApiCalls=coalesce(newStdevApiCalls, stdevApiCalls), numDataPoints=if(isnull(latestCount), numDataPoints, numDataPoints+1) -| table arn, latestCount, numDataPoints, avgApiCalls, stdevApiCalls -| outputlookup network_acl_activity_baseline -| eval dataPointThreshold = 15, deviationThreshold = 3 -| eval isSpike=if((latestCount > avgApiCalls+deviationThreshold*stdevApiCalls) AND numDataPoints > dataPointThreshold, 1, 0) -| where isSpike=1 -| rename arn as userIdentity.arn -| table userIdentity.arn] -| spath output=user userIdentity.arn -| stats values(eventName) as eventNames, count as numberOfApiCalls, dc(eventName) as uniqueApisCalled by user -| `detect_spike_in_network_acl_activity_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) -* [network_acl_events](https://github.com/splunk/security_content/blob/develop/macros/network_acl_events.yml) - -> :information_source: -> **detect_spike_in_network_acl_activity_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Lookups -The SPL above uses the following Lookups: - -* [network_acl_activity_baseline](https://github.com/splunk/security_content/blob/develop/lookups/network_acl_activity_baseline.yml) with [data](https://github.com/splunk/security_content/tree/develop/lookups/network_acl_activity_baseline.csv) -* [network_acl_activity_baseline](https://github.com/splunk/security_content/blob/develop/lookups/network_acl_activity_baseline.yml) with [data](https://github.com/splunk/security_content/tree/develop/lookups/network_acl_activity_baseline.csv) - -#### Required field -* _time -* userIdentity.arn - - -#### How To Implement -You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your AWS CloudTrail inputs. You can modify `dataPointThreshold` and `deviationThreshold` to better fit your environment. The `dataPointThreshold` variable is the minimum number of data points required to have a statistically significant amount of data to determine. The `deviationThreshold` variable is the number of standard deviations away from the mean that the value must be to be considered a spike. This search works best when you run the "Baseline of Network ACL Activity by ARN" support search once to create a lookup file of previously seen Network ACL Activity. To add or remove API event names related to network ACLs, edit the macro `network_acl_events`. - -#### Known False Positives -The false-positive rate may vary based on the values of`dataPointThreshold` and `deviationThreshold`. Please modify this according the your environment. - -#### Associated Analytic story -* [AWS Network ACL Activity](/stories/aws_network_acl_activity) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/detect_spike_in_network_acl_activity.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2018-06-01-detect_large_outbound_icmp_packets.md b/docs/_posts/2018-06-01-detect_large_outbound_icmp_packets.md deleted file mode 100644 index 638971b92a..0000000000 --- a/docs/_posts/2018-06-01-detect_large_outbound_icmp_packets.md +++ /dev/null @@ -1,161 +0,0 @@ ---- -title: "Detect Large Outbound ICMP Packets" -excerpt: "Non-Application Layer Protocol -" -categories: - - Network -last_modified_at: 2018-06-01 -toc: true -toc_label: "" -tags: - - Non-Application Layer Protocol - - Command And Control - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Network_Traffic ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for outbound ICMP packets with a packet size larger than 1,000 bytes. Various threat actors have been known to use ICMP as a command and control channel for their attack infrastructure. Large ICMP packets from an endpoint to a remote host may be indicative of this activity. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Network_Traffic](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkTraffic) -- **Last Updated**: 2018-06-01 -- **Author**: Rico Valdez, Splunk -- **ID**: e9c102de-4d43-42a7-b1c8-8062ea297419 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1095](https://attack.mitre.org/techniques/T1095/) | Non-Application Layer Protocol | Command And Control | - -
-
- - -
- Kill Chain Phase - -
- -* Command & Control - - -
-
- - -
- NIST - -
- -* DE.AE - - - -
-
- -
- CIS20 - -
- -* CIS 9 -* CIS 12 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count earliest(_time) as firstTime latest(_time) as lastTime values(All_Traffic.action) values(All_Traffic.bytes) from datamodel=Network_Traffic where All_Traffic.action !=blocked All_Traffic.dest_category !=internal (All_Traffic.protocol=icmp OR All_Traffic.transport=icmp) All_Traffic.bytes > 1000 by All_Traffic.src_ip All_Traffic.dest_ip -| `drop_dm_object_name("All_Traffic")` -| search ( dest_ip!=10.0.0.0/8 AND dest_ip!=172.16.0.0/12 AND dest_ip!=192.168.0.0/16) -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -| `detect_large_outbound_icmp_packets_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **detect_large_outbound_icmp_packets_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* All_Traffic.action -* All_Traffic.bytes -* All_Traffic.dest_category -* All_Traffic.protocol -* All_Traffic.transport -* All_Traffic.src_ip -* All_Traffic.dest_ip - - -#### How To Implement -In order to run this search effectively, we highly recommend that you leverage the Assets and Identity framework. It is important that you have a good understanding of how your network segments are designed and that you are able to distinguish internal from external address space. Add a category named `internal` to the CIDRs that host the company's assets in the `assets_by_cidr.csv` lookup file, which is located in `$SPLUNK_HOME/etc/apps/SA-IdentityManagement/lookups/`. More information on updating this lookup can be found here: https://docs.splunk.com/Documentation/ES/5.0.0/Admin/Addassetandidentitydata. This search also requires you to be ingesting your network traffic and populating the Network_Traffic data model - -#### Known False Positives -ICMP packets are used in a variety of ways to help troubleshoot networking issues and ensure the proper flow of traffic. As such, it is possible that a large ICMP packet could be perfectly legitimate. If large ICMP packets are associated with command and control traffic, there will typically be a large number of these packets observed over time. If the search is providing a large number of false positives, you can modify the macro `detect_large_outbound_icmp_packets_filter` to adjust the byte threshold or add specific IP addresses to an allow list. - -#### Associated Analytic story -* [Command and Control](/stories/command_and_control) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/network/detect_large_outbound_icmp_packets.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2018-06-14-splunk_enterprise_information_disclosure.md b/docs/_posts/2018-06-14-splunk_enterprise_information_disclosure.md deleted file mode 100644 index 8f627c8fea..0000000000 --- a/docs/_posts/2018-06-14-splunk_enterprise_information_disclosure.md +++ /dev/null @@ -1,153 +0,0 @@ ---- -title: "Splunk Enterprise Information Disclosure" -excerpt: "" -categories: - - Deprecated -last_modified_at: 2018-06-14 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2018-11409 ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search allows you to look for evidence of exploitation for CVE-2018-11409, a Splunk Enterprise Information Disclosure Bug. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2018-06-14 -- **Author**: David Dorsey, Splunk -- **ID**: f6a26b7b-7e80-4963-a9a8-d836e7534ebd - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Delivery - - -
-
- - -
- NIST - -
- -* ID.RA -* RS.MI -* PR.PT -* PR.AC -* PR.IP -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 4 -* CIS 18 - - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2018-11409](https://nvd.nist.gov/vuln/detail/CVE-2018-11409) | Splunk through 7.0.1 allows information disclosure by appending __raw/services/server/info/server-info?output_mode=json to a query, as demonstrated by discovering a license key. | 5.0 | - - - -
-
- -#### Search - -``` -index=_internal sourcetype=splunkd_ui_access server-info -| search clientip!=127.0.0.1 uri_path="*raw/services/server/info/server-info" -| rename clientip as src_ip, splunk_server as dest -| stats earliest(_time) as firstTime, latest(_time) as lastTime, values(uri) as uri, values(useragent) as http_user_agent, values(user) as user by src_ip, dest -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `splunk_enterprise_information_disclosure_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **splunk_enterprise_information_disclosure_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -The REST endpoint that exposes system information is also necessary for the proper operation of Splunk clustering and instrumentation. Whitelisting your Splunk systems will reduce false positives. - -#### Known False Positives -Retrieving server information may be a legitimate API request. Verify that the attempt is a valid request for information. - -#### Associated Analytic story -* [Splunk Vulnerabilities](/stories/splunk_vulnerabilities) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/splunk_enterprise_information_disclosure.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2018-06-28-detect_s3_access_from_a_new_ip.md b/docs/_posts/2018-06-28-detect_s3_access_from_a_new_ip.md deleted file mode 100644 index 473271fdc1..0000000000 --- a/docs/_posts/2018-06-28-detect_s3_access_from_a_new_ip.md +++ /dev/null @@ -1,165 +0,0 @@ ---- -title: "Detect S3 access from a new IP" -excerpt: "Data from Cloud Storage Object -" -categories: - - Cloud -last_modified_at: 2018-06-28 -toc: true -toc_label: "" -tags: - - Data from Cloud Storage Object - - Collection - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks at S3 bucket-access logs and detects new or previously unseen remote IP addresses that have successfully accessed an S3 bucket. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2018-06-28 -- **Author**: Bhavin Patel, Splunk -- **ID**: e6f1bb1b-f441-492b-9126-902acda217da - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1530](https://attack.mitre.org/techniques/T1530/) | Data from Cloud Storage Object | Collection | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.DS -* PR.AC -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 13 -* CIS 14 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`aws_s3_accesslogs` http_status=200 [search `aws_s3_accesslogs` http_status=200 -| stats earliest(_time) as firstTime latest(_time) as lastTime by bucket_name remote_ip -| inputlookup append=t previously_seen_S3_access_from_remote_ip.csv -| stats min(firstTime) as firstTime, max(lastTime) as lastTime by bucket_name remote_ip -| outputlookup previously_seen_S3_access_from_remote_ip.csv -| eval newIP=if(firstTime >= relative_time(now(), "-70m@m"), 1, 0) -| where newIP=1 -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| table bucket_name remote_ip] -| iplocation remote_ip -|rename remote_ip as src_ip -| table _time bucket_name src_ip City Country operation request_uri -| `detect_s3_access_from_a_new_ip_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [aws_s3_accesslogs](https://github.com/splunk/security_content/blob/develop/macros/aws_s3_accesslogs.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **detect_s3_access_from_a_new_ip_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* http_status -* bucket_name -* remote_ip - - -#### How To Implement -You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your S3 access logs' inputs. This search works best when you run the "Previously Seen S3 Bucket Access by Remote IP" support search once to create a history of previously seen remote IPs and bucket names. - -#### Known False Positives -S3 buckets can be accessed from any IP, as long as it can make a successful connection. This will be a false postive, since the search is looking for a new IP within the past hour - -#### Associated Analytic story -* [Suspicious AWS S3 Activities](/stories/suspicious_aws_s3_activities) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/cloud/detect_s3_access_from_a_new_ip.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2018-10-08-web_fraud_-_account_harvesting.md b/docs/_posts/2018-10-08-web_fraud_-_account_harvesting.md deleted file mode 100644 index a344e32104..0000000000 --- a/docs/_posts/2018-10-08-web_fraud_-_account_harvesting.md +++ /dev/null @@ -1,159 +0,0 @@ ---- -title: "Web Fraud - Account Harvesting" -excerpt: "Create Account -" -categories: - - Deprecated -last_modified_at: 2018-10-08 -toc: true -toc_label: "" -tags: - - Create Account - - Persistence - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is used to identify the creation of multiple user accounts using the same email domain name. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2018-10-08 -- **Author**: Jim Apger, Splunk -- **ID**: bf1d7b5c-df2f-4249-a401-c09fdc221ddf - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1136](https://attack.mitre.org/techniques/T1136/) | Create Account | Persistence | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.CM -* DE.DP - - - -
-
- -
- CIS20 - -
- -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`stream_http` http_content_type=text* uri="/magento2/customer/account/loginPost/" -| rex field=cookie "form_key=(?\w+)" -| rex field=form_data "login\[username\]=(?[^& -|^$]+)" -| search Username=* -| rex field=Username "@(?.*)" -| stats dc(Username) as UniqueUsernames list(Username) as src_user by email_domain -| where UniqueUsernames> 25 -| `web_fraud___account_harvesting_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [stream_http](https://github.com/splunk/security_content/blob/develop/macros/stream_http.yml) - -> :information_source: -> **web_fraud_-_account_harvesting_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* http_content_type -* uri -* cookie - - -#### How To Implement -We start with a dataset that provides visibility into the email address used for the account creation. In this example, we are narrowing our search down to the single web page that hosts the Magento2 e-commerce platform (via URI) used for account creation, the single http content-type to grab only the user's clicks, and the http field that provides the username (form_data), for performance reasons. After we have the username and email domain, we look for numerous account creations per email domain. Common data sources used for this detection are customized Apache logs or Splunk Stream. - -#### Known False Positives -As is common with many fraud-related searches, we are usually looking to attribute risk or synthesize relevant context with loosely written detections that simply detect anamolous behavior. This search will need to be customized to fit your environment—improving its fidelity by counting based on something much more specific, such as a device ID that may be present in your dataset. Consideration for whether the large number of registrations are occuring from a first-time seen domain may also be important. Extending the search window to look further back in time, or even calculating the average per hour/day for each email domain to look for an anomalous spikes, will improve this search. You can also use Shannon entropy or Levenshtein Distance (both courtesy of URL Toolbox) to consider the randomness or similarity of the email name or email domain, as the names are often machine-generated. - -#### Associated Analytic story -* [Web Fraud Detection](/stories/web_fraud_detection) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://splunkbase.splunk.com/app/2734/](https://splunkbase.splunk.com/app/2734/) -* [https://splunkbase.splunk.com/app/1809/](https://splunkbase.splunk.com/app/1809/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/web_fraud___account_harvesting.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2018-10-08-web_fraud_-_anomalous_user_clickspeed.md b/docs/_posts/2018-10-08-web_fraud_-_anomalous_user_clickspeed.md deleted file mode 100644 index 2574e71e9f..0000000000 --- a/docs/_posts/2018-10-08-web_fraud_-_anomalous_user_clickspeed.md +++ /dev/null @@ -1,161 +0,0 @@ ---- -title: "Web Fraud - Anomalous User Clickspeed" -excerpt: "Valid Accounts -" -categories: - - Deprecated -last_modified_at: 2018-10-08 -toc: true -toc_label: "" -tags: - - Valid Accounts - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is used to examine web sessions to identify those where the clicks are occurring too quickly for a human or are occurring with a near-perfect cadence (high periodicity or low standard deviation), resembling a script driven session. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2018-10-08 -- **Author**: Jim Apger, Splunk -- **ID**: 31337bbb-bc22-4752-b599-ef192df2dc7a - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.AE -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 6 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`stream_http` http_content_type=text* -| rex field=cookie "form_key=(?\w+)" -| streamstats window=2 current=1 range(_time) as TimeDelta by session_id -| where TimeDelta>0 -|stats count stdev(TimeDelta) as ClickSpeedStdDev avg(TimeDelta) as ClickSpeedAvg by session_id -| where count>5 AND (ClickSpeedStdDev<.5 OR ClickSpeedAvg<.5) -| `web_fraud___anomalous_user_clickspeed_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [stream_http](https://github.com/splunk/security_content/blob/develop/macros/stream_http.yml) - -> :information_source: -> **web_fraud_-_anomalous_user_clickspeed_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* http_content_type -* cookie - - -#### How To Implement -Start with a dataset that allows you to see clickstream data for each user click on the website. That data must have a time stamp and must contain a reference to the session identifier being used by the website. This ties the clicks together into clickstreams. This value is usually found in the http cookie. With a bit of tuning, a version of this search could be used in high-volume scenarios, such as scraping, crawling, application DDOS, credit-card testing, account takeover, etc. Common data sources used for this detection are customized Apache logs, customized IIS, and Splunk Stream. - -#### Known False Positives -As is common with many fraud-related searches, we are usually looking to attribute risk or synthesize relevant context with loosly written detections that simply detect anamoluous behavior. - -#### Associated Analytic story -* [Web Fraud Detection](/stories/web_fraud_detection) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://en.wikipedia.org/wiki/Session_ID](https://en.wikipedia.org/wiki/Session_ID) -* [https://en.wikipedia.org/wiki/Session_(computer_science)](https://en.wikipedia.org/wiki/Session_(computer_science)) -* [https://en.wikipedia.org/wiki/HTTP_cookie](https://en.wikipedia.org/wiki/HTTP_cookie) -* [https://splunkbase.splunk.com/app/1809/](https://splunkbase.splunk.com/app/1809/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2018-10-08-web_fraud_-_password_sharing_across_accounts.md b/docs/_posts/2018-10-08-web_fraud_-_password_sharing_across_accounts.md deleted file mode 100644 index 5518f2b34e..0000000000 --- a/docs/_posts/2018-10-08-web_fraud_-_password_sharing_across_accounts.md +++ /dev/null @@ -1,150 +0,0 @@ ---- -title: "Web Fraud - Password Sharing Across Accounts" -excerpt: "" -categories: - - Deprecated -last_modified_at: 2018-10-08 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is used to identify user accounts that share a common password. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2018-10-08 -- **Author**: Jim Apger, Splunk -- **ID**: 31337a1a-53b9-4e05-96e9-55c934cb71d3 - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.DP - - - -
-
- -
- CIS20 - -
- -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`stream_http` http_content_type=text* uri=/magento2/customer/account/loginPost* -| rex field=form_data "login\[username\]=(?[^& -|^$]+)" -| rex field=form_data "login\[password\]=(?[^& -|^$]+)" -| stats dc(Username) as UniqueUsernames values(Username) as user list(src_ip) as src_ip by Password -|where UniqueUsernames>5 -| `web_fraud___password_sharing_across_accounts_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [stream_http](https://github.com/splunk/security_content/blob/develop/macros/stream_http.yml) - -> :information_source: -> **web_fraud_-_password_sharing_across_accounts_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* http_content_type -* uri - - -#### How To Implement -We need to start with a dataset that allows us to see the values of usernames and passwords that users are submitting to the website hosting the Magento2 e-commerce platform (commonly found in the HTTP form_data field). A tokenized or hashed value of a password is acceptable and certainly preferable to a clear-text password. Common data sources used for this detection are customized Apache logs, customized IIS, and Splunk Stream. - -#### Known False Positives -As is common with many fraud-related searches, we are usually looking to attribute risk or synthesize relevant context with loosely written detections that simply detect anamoluous behavior. - -#### Associated Analytic story -* [Web Fraud Detection](/stories/web_fraud_detection) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://en.wikipedia.org/wiki/Session_ID](https://en.wikipedia.org/wiki/Session_ID) -* [https://en.wikipedia.org/wiki/Session_(computer_science)](https://en.wikipedia.org/wiki/Session_(computer_science)) -* [https://en.wikipedia.org/wiki/HTTP_cookie](https://en.wikipedia.org/wiki/HTTP_cookie) -* [https://splunkbase.splunk.com/app/1809/](https://splunkbase.splunk.com/app/1809/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/web_fraud___password_sharing_across_accounts.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2018-10-12-cloud_compute_instance_created_with_previously_unseen_image.md b/docs/_posts/2018-10-12-cloud_compute_instance_created_with_previously_unseen_image.md deleted file mode 100644 index 689349d50f..0000000000 --- a/docs/_posts/2018-10-12-cloud_compute_instance_created_with_previously_unseen_image.md +++ /dev/null @@ -1,160 +0,0 @@ ---- -title: "Cloud Compute Instance Created With Previously Unseen Image" -excerpt: "" -categories: - - Cloud -last_modified_at: 2018-10-12 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Change ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for cloud compute instances being created with previously unseen image IDs. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Change](https://docs.splunk.com/Documentation/CIM/latest/User/Change)- **Datasource**: [Splunk Add-on for Amazon Kinesis Firehose](https://splunkbase.splunk.com/app/3719) -- **Last Updated**: 2018-10-12 -- **Author**: David Dorsey, Splunk -- **ID**: bc24922d-987c-4645-b288-f8c73ec194c4 - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* ID.AM - - - -
-
- -
- CIS20 - -
- -* CIS 1 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats count earliest(_time) as firstTime, latest(_time) as lastTime values(All_Changes.object_id) as dest from datamodel=Change where All_Changes.action=created by All_Changes.Instance_Changes.image_id, All_Changes.user -| `drop_dm_object_name("All_Changes")` -| `drop_dm_object_name("Instance_Changes")` -| where image_id != "unknown" -| lookup previously_seen_cloud_compute_images image_id as image_id OUTPUT firstTimeSeen, enough_data -| eventstats max(enough_data) as enough_data -| where enough_data=1 -| eval firstTimeSeenImage=min(firstTimeSeen) -| where isnull(firstTimeSeenImage) OR firstTimeSeenImage > relative_time(now(), "-24h@h") -| table firstTime, user, image_id, count, dest -| `security_content_ctime(firstTime)` -| `cloud_compute_instance_created_with_previously_unseen_image_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **cloud_compute_instance_created_with_previously_unseen_image_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Lookups -The SPL above uses the following Lookups: - -* [previously_seen_cloud_compute_images](https://github.com/splunk/security_content/blob/develop/lookups/previously_seen_cloud_compute_images.yml) with [data](https://github.com/splunk/security_content/tree/develop/lookups/previously_seen_cloud_compute_images.csv) - -#### Required field -* _time -* All_Changes.object_id -* All_Changes.action -* All_Changes.Instance_Changes.image_id -* All_Changes.user - - -#### How To Implement -You must be ingesting your cloud infrastructure logs from your cloud provider. You should run the baseline search `Previously Seen Cloud Compute Images - Initial` to build the initial table of images observed and times. You must also enable the second baseline search `Previously Seen Cloud Compute Images - Update` to keep this table up to date and to age out old data. You can also provide additional filtering for this search by customizing the `cloud_compute_instance_created_with_previously_unseen_image_filter` macro. - -#### Known False Positives -After a new image is created, the first systems created with that image will cause this alert to fire. Verify that the image being used was created by a legitimate user. - -#### Associated Analytic story -* [Cloud Cryptomining](/stories/cloud_cryptomining) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 36.0 | 60 | 60 | User $user$ is creating an instance $dest$ with an image that has not been previously seen. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/cloud_compute_instance_created_with_previously_unseen_image.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2018-10-23-wmi_permanent_event_subscription.md b/docs/_posts/2018-10-23-wmi_permanent_event_subscription.md deleted file mode 100644 index 7ddc9ec68b..0000000000 --- a/docs/_posts/2018-10-23-wmi_permanent_event_subscription.md +++ /dev/null @@ -1,162 +0,0 @@ ---- -title: "WMI Permanent Event Subscription" -excerpt: "Windows Management Instrumentation -" -categories: - - Endpoint -last_modified_at: 2018-10-23 -toc: true -toc_label: "" -tags: - - Windows Management Instrumentation - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for the creation of WMI permanent event subscriptions. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2018-10-23 -- **Author**: Rico Valdez, Splunk -- **ID**: 71bfdb13-f200-4c6c-b2c9-a2e07adf437d - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1047](https://attack.mitre.org/techniques/T1047/) | Windows Management Instrumentation | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* PR.AT -* PR.AC -* PR.IP - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`wmi` EventCode=5861 Binding -| rex field=Message "Consumer =\s+(?[^; -|^$]+)" -| search consumer!="NTEventLogEventConsumer=\"SCM Event Log Consumer\"" -| stats count min(_time) as firstTime max(_time) as lastTime by ComputerName, consumer, Message -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| rename ComputerName as dest -| `wmi_permanent_event_subscription_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [wmi](https://github.com/splunk/security_content/blob/develop/macros/wmi.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **wmi_permanent_event_subscription_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Message -* consumer -* ComputerName - - -#### How To Implement -To successfully implement this search, you must be ingesting the Windows WMI activity logs. This can be done by adding a stanza to inputs.conf on the system generating logs with a title of [WinEventLog://Microsoft-Windows-WMI-Activity/Operational]. - -#### Known False Positives -Although unlikely, administrators may use event subscriptions for legitimate purposes. - -#### Associated Analytic story -* [Suspicious WMI Use](/stories/suspicious_wmi_use) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/endpoint/wmi_permanent_event_subscription.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2018-10-23-wmi_temporary_event_subscription.md b/docs/_posts/2018-10-23-wmi_temporary_event_subscription.md deleted file mode 100644 index 02ca8ce578..0000000000 --- a/docs/_posts/2018-10-23-wmi_temporary_event_subscription.md +++ /dev/null @@ -1,160 +0,0 @@ ---- -title: "WMI Temporary Event Subscription" -excerpt: "Windows Management Instrumentation -" -categories: - - Endpoint -last_modified_at: 2018-10-23 -toc: true -toc_label: "" -tags: - - Windows Management Instrumentation - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for the creation of WMI temporary event subscriptions. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2018-10-23 -- **Author**: Rico Valdez, Splunk -- **ID**: 38cbd42c-1098-41bb-99cf-9d6d2b296d83 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1047](https://attack.mitre.org/techniques/T1047/) | Windows Management Instrumentation | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* PR.AT -* PR.AC -* PR.IP - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`wmi` EventCode=5860 Temporary -| rex field=Message "NotificationQuery =\s+(?[^; -|^$]+)" -| search query!="SELECT * FROM Win32_ProcessStartTrace WHERE ProcessName = 'wsmprovhost.exe'" AND query!="SELECT * FROM __InstanceOperationEvent WHERE TargetInstance ISA 'AntiVirusProduct' OR TargetInstance ISA 'FirewallProduct' OR TargetInstance ISA 'AntiSpywareProduct'" -| stats count min(_time) as firstTime max(_time) as lastTime by ComputerName, query -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `wmi_temporary_event_subscription_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [wmi](https://github.com/splunk/security_content/blob/develop/macros/wmi.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **wmi_temporary_event_subscription_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Message -* query - - -#### How To Implement -To successfully implement this search, you must be ingesting the Windows WMI activity logs. This can be done by adding a stanza to inputs.conf on the system generating logs with a title of [WinEventLog://Microsoft-Windows-WMI-Activity/Operational]. - -#### Known False Positives -Some software may create WMI temporary event subscriptions for various purposes. The included search contains an exception for two of these that occur by default on Windows 10 systems. You may need to modify the search to create exceptions for other legitimate events. - -#### Associated Analytic story -* [Suspicious WMI Use](/stories/suspicious_wmi_use) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/endpoint/wmi_temporary_event_subscription.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2018-11-02-windows_hosts_file_modification.md b/docs/_posts/2018-11-02-windows_hosts_file_modification.md deleted file mode 100644 index a4d2ecf6d7..0000000000 --- a/docs/_posts/2018-11-02-windows_hosts_file_modification.md +++ /dev/null @@ -1,148 +0,0 @@ ---- -title: "Windows hosts file modification" -excerpt: "" -categories: - - Deprecated -last_modified_at: 2018-11-02 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The search looks for modifications to the hosts file on all Windows endpoints across your environment. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2018-11-02 -- **Author**: Rico Valdez, Splunk -- **ID**: 06a6fc63-a72d-41dc-8736-7e3dd9612116 - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Command & Control - - -
-
- - -
- NIST - -
- -* PR.IP -* PR.PT -* PR.AC -* DE.AE -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 8 -* CIS 12 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem by Filesystem.file_name Filesystem.file_path Filesystem.dest -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| search Filesystem.file_name=hosts AND Filesystem.file_path=*Windows\\System32\\* -| `drop_dm_object_name(Filesystem)` -| `windows_hosts_file_modification_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_hosts_file_modification_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -To successfully implement this search, you must be ingesting data that records the file-system activity from your hosts to populate the Endpoint.Filesystem data model node. This is typically populated via endpoint detection-and-response product, such as Carbon Black, or by other endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report file-system reads and writes. - -#### Known False Positives -There may be legitimate reasons for system administrators to add entries to this file. - -#### Associated Analytic story -* [Host Redirection](/stories/host_redirection) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/windows_hosts_file_modification.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2018-11-27-detect_spike_in_s3_bucket_deletion.md b/docs/_posts/2018-11-27-detect_spike_in_s3_bucket_deletion.md deleted file mode 100644 index 4a5b791d4c..0000000000 --- a/docs/_posts/2018-11-27-detect_spike_in_s3_bucket_deletion.md +++ /dev/null @@ -1,175 +0,0 @@ ---- -title: "Detect Spike in S3 Bucket deletion" -excerpt: "Data from Cloud Storage Object -" -categories: - - Cloud -last_modified_at: 2018-11-27 -toc: true -toc_label: "" -tags: - - Data from Cloud Storage Object - - Collection - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search detects users creating spikes in API activity related to deletion of S3 buckets in your AWS environment. It will also update the cache file that factors in the latest data. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2018-11-27 -- **Author**: Bhavin Patel, Splunk -- **ID**: e733a326-59d2-446d-b8db-14a17151aa68 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1530](https://attack.mitre.org/techniques/T1530/) | Data from Cloud Storage Object | Collection | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.DP -* DE.CM -* PR.AC - - - -
-
- -
- CIS20 - -
- -* CIS 13 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cloudtrail` eventName=DeleteBucket [search `cloudtrail` eventName=DeleteBucket -| spath output=arn path=userIdentity.arn -| stats count as apiCalls by arn -| inputlookup s3_deletion_baseline append=t -| fields - latestCount -| stats values(*) as * by arn -| rename apiCalls as latestCount -| eval newAvgApiCalls=avgApiCalls + (latestCount-avgApiCalls)/720 -| eval newStdevApiCalls=sqrt(((pow(stdevApiCalls, 2)*719 + (latestCount-newAvgApiCalls)*(latestCount-avgApiCalls))/720)) -| eval avgApiCalls=coalesce(newAvgApiCalls, avgApiCalls), stdevApiCalls=coalesce(newStdevApiCalls, stdevApiCalls), numDataPoints=if(isnull(latestCount), numDataPoints, numDataPoints+1) -| table arn, latestCount, numDataPoints, avgApiCalls, stdevApiCalls -| outputlookup s3_deletion_baseline -| eval dataPointThreshold = 15, deviationThreshold = 3 -| eval isSpike=if((latestCount > avgApiCalls+deviationThreshold*stdevApiCalls) AND numDataPoints > dataPointThreshold, 1, 0) -| where isSpike=1 -| rename arn as userIdentity.arn -| table userIdentity.arn] -| spath output=user userIdentity.arn -| spath output=bucketName path=requestParameters.bucketName -| stats values(bucketName) as bucketName, count as numberOfApiCalls, dc(eventName) as uniqueApisCalled by user -| `detect_spike_in_s3_bucket_deletion_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) - -> :information_source: -> **detect_spike_in_s3_bucket_deletion_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Lookups -The SPL above uses the following Lookups: - -* [s3_deletion_baseline](https://github.com/splunk/security_content/blob/develop/lookups/s3_deletion_baseline.yml) with [data](https://github.com/splunk/security_content/tree/develop/lookups/s3_deletion_baseline.csv) -* [s3_deletion_baseline](https://github.com/splunk/security_content/blob/develop/lookups/s3_deletion_baseline.yml) with [data](https://github.com/splunk/security_content/tree/develop/lookups/s3_deletion_baseline.csv) - -#### Required field -* _time -* eventName -* userIdentity.arn - - -#### How To Implement -You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your AWS CloudTrail inputs. You can modify `dataPointThreshold` and `deviationThreshold` to better fit your environment. The `dataPointThreshold` variable is the minimum number of data points required to have a statistically significant amount of data to determine. The `deviationThreshold` variable is the number of standard deviations away from the mean that the value must be to be considered a spike. This search works best when you run the "Baseline of S3 Bucket deletion activity by ARN" support search once to create a baseline of previously seen S3 bucket-deletion activity. - -#### Known False Positives -Based on the values of`dataPointThreshold` and `deviationThreshold`, the false positive rate may vary. Please modify this according the your environment. - -#### Associated Analytic story -* [Suspicious AWS S3 Activities](/stories/suspicious_aws_s3_activities) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/cloud/detect_spike_in_s3_bucket_deletion.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2018-12-03-remote_wmi_command_attempt.md b/docs/_posts/2018-12-03-remote_wmi_command_attempt.md deleted file mode 100644 index cc8964e565..0000000000 --- a/docs/_posts/2018-12-03-remote_wmi_command_attempt.md +++ /dev/null @@ -1,169 +0,0 @@ ---- -title: "Remote WMI Command Attempt" -excerpt: "Windows Management Instrumentation -" -categories: - - Endpoint -last_modified_at: 2018-12-03 -toc: true -toc_label: "" -tags: - - Windows Management Instrumentation - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies usage of `wmic.exe` spawning a local or remote process, identified by the `node` switch. During triage, review parallel processes for additional commands executed. Look for any file modifications before and after `wmic.exe` execution. In addition, identify the remote endpoint and confirm execution or file modifications. Contain and isolate the endpoint as needed. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2018-12-03 -- **Author**: Rico Valdez, Michael Haag, Splunk -- **ID**: 272df6de-61f1-4784-877c-1fbc3e2d0838 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1047](https://attack.mitre.org/techniques/T1047/) | Windows Management Instrumentation | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* PR.AT -* PR.AC -* PR.IP - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_wmic` Processes.process=*node* by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `remote_wmi_command_attempt_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [process_wmic](https://github.com/splunk/security_content/blob/develop/macros/process_wmic.yml) - -> :information_source: -> **remote_wmi_command_attempt_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.user -* Processes.process_name -* Processes.parent_process_name -* Processes.dest -* Processes.parent_process -* Processes.parent_process_id -* Processes.process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. Deprecated because duplicate of Remote Process Instantiation via WMI. - -#### Known False Positives -Administrators may use this legitimately to gather info from remote systems. Filter as needed. - -#### Associated Analytic story -* [Suspicious WMI Use](/stories/suspicious_wmi_use) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 36.0 | 60 | 60 | A wmic.exe process $process$ contain node commandline $process$ in host $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1047/T1047.yaml](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1047/T1047.yaml) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1047/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1047/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/remote_wmi_command_attempt.yml) \| *version*: **4** \ No newline at end of file diff --git a/docs/_posts/2018-12-03-usn_journal_deletion.md b/docs/_posts/2018-12-03-usn_journal_deletion.md deleted file mode 100644 index c7193842d3..0000000000 --- a/docs/_posts/2018-12-03-usn_journal_deletion.md +++ /dev/null @@ -1,167 +0,0 @@ ---- -title: "USN Journal Deletion" -excerpt: "Indicator Removal on Host -" -categories: - - Endpoint -last_modified_at: 2018-12-03 -toc: true -toc_label: "" -tags: - - Indicator Removal on Host - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The fsutil.exe application is a legitimate Windows utility used to perform tasks related to the file allocation table (FAT) and NTFS file systems. The update sequence number (USN) change journal provides a log of all changes made to the files on the disk. This search looks for fsutil.exe deleting the USN journal. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2018-12-03 -- **Author**: David Dorsey, Splunk -- **ID**: b6e0ff70-b122-4227-9368-4cf322ab43c3 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1070](https://attack.mitre.org/techniques/T1070/) | Indicator Removal on Host | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.CM -* PR.PT -* DE.AE -* DE.DP -* PR.IP - - - -
-
- -
- CIS20 - -
- -* CIS 6 -* CIS 8 -* CIS 10 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count values(Processes.process) as process values(Processes.parent_process) as parent_process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=fsutil.exe by Processes.user Processes.process_name Processes.parent_process_name Processes.dest -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| search process="*deletejournal*" AND process="*usn*" -| `usn_journal_deletion_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **usn_journal_deletion_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process -* Processes.parent_process -* Processes.process_name -* Processes.user -* Processes.parent_process_name -* Processes.dest - - -#### How To Implement -You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. - -#### Known False Positives -None identified - -#### Associated Analytic story -* [Windows Log Manipulation](/stories/windows_log_manipulation) -* [Ransomware](/stories/ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 45.0 | 50 | 90 | Possible USN journal deletion on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/usn_journal_deletion.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2018-12-06-suspicious_java_classes.md b/docs/_posts/2018-12-06-suspicious_java_classes.md deleted file mode 100644 index 3e1d527e90..0000000000 --- a/docs/_posts/2018-12-06-suspicious_java_classes.md +++ /dev/null @@ -1,154 +0,0 @@ ---- -title: "Suspicious Java Classes" -excerpt: "" -categories: - - Application -last_modified_at: 2018-12-06 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for suspicious Java classes that are often used to exploit remote command execution in common Java frameworks, such as Apache Struts. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2018-12-06 -- **Author**: Jose Hernandez, Splunk -- **ID**: 6ed33786-5e87-4f55-b62c-cb5f1168b831 - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.AE - - - -
-
- -
- CIS20 - -
- -* CIS 7 -* CIS 12 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`stream_http` http_method=POST http_content_length>1 -| regex form_data="(?i)java\.lang\.(?:runtime -|processbuilder)" -| rename src_ip as src -| stats count earliest(_time) as firstTime, latest(_time) as lastTime, values(url) as uri, values(status) as status, values(http_user_agent) as http_user_agent by src, dest -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `suspicious_java_classes_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [stream_http](https://github.com/splunk/security_content/blob/develop/macros/stream_http.yml) - -> :information_source: -> **suspicious_java_classes_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* http_method -* http_content_length -* src_ip -* url -* status -* http_user_agent -* src -* dest - - -#### How To Implement -In order to properly run this search, Splunk needs to ingest data from your web-traffic appliances that serve or sit in the path of your Struts application servers. This can be accomplished by indexing data from a web proxy, or by using network traffic-analysis tools, such as Splunk Stream or Bro. - -#### Known False Positives -There are no known false positives. - -#### Associated Analytic story -* [Apache Struts Vulnerability](/stories/apache_struts_vulnerability) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/application/suspicious_java_classes.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2018-12-14-file_with_samsam_extension.md b/docs/_posts/2018-12-14-file_with_samsam_extension.md deleted file mode 100644 index 92a288413c..0000000000 --- a/docs/_posts/2018-12-14-file_with_samsam_extension.md +++ /dev/null @@ -1,152 +0,0 @@ ---- -title: "File with Samsam Extension" -excerpt: "" -categories: - - Endpoint -last_modified_at: 2018-12-14 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The search looks for file writes with extensions consistent with a SamSam ransomware attack. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2018-12-14 -- **Author**: Rico Valdez, Splunk -- **ID**: 02c6cfc2-ae66-4735-bfc7-6291da834cbf - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Installation - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Filesystem.user) as user values(Filesystem.dest) as dest values(Filesystem.file_path) as file_path from datamodel=Endpoint.Filesystem by Filesystem.file_name -| `drop_dm_object_name(Filesystem)` -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| rex field=file_name "(?\.[^\.]+)$" -| search file_extension=.stubbin OR file_extension=.berkshire OR file_extension=.satoshi OR file_extension=.sophos OR file_extension=.keyxml -| `file_with_samsam_extension_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **file_with_samsam_extension_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Filesystem.user -* Filesystem.dest -* Filesystem.file_path -* Filesystem.file_name - - -#### How To Implement -You must be ingesting data that records file-system activity from your hosts to populate the Endpoint file-system data-model node. If you are using Sysmon, you will need a Splunk Universal Forwarder on each endpoint from which you want to collect data. - -#### Known False Positives -Because these extensions are not typically used in normal operations, you should investigate all results. - -#### Associated Analytic story -* [SamSam Ransomware](/stories/samsam_ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 90.0 | 100 | 90 | File writes $file_name$ with extensions consistent with a SamSam ransomware attack seen on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036.003/samsam_extension/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036.003/samsam_extension/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/file_with_samsam_extension.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2018-12-14-samsam_test_file_write.md b/docs/_posts/2018-12-14-samsam_test_file_write.md deleted file mode 100644 index 57b1aa725c..0000000000 --- a/docs/_posts/2018-12-14-samsam_test_file_write.md +++ /dev/null @@ -1,158 +0,0 @@ ---- -title: "Samsam Test File Write" -excerpt: "Data Encrypted for Impact -" -categories: - - Endpoint -last_modified_at: 2018-12-14 -toc: true -toc_label: "" -tags: - - Data Encrypted for Impact - - Impact - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The search looks for a file named "test.txt" written to the windows system directory tree, which is consistent with Samsam propagation. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2018-12-14 -- **Author**: Rico Valdez, Splunk -- **ID**: 493a879d-519d-428f-8f57-a06a0fdc107e - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1486](https://attack.mitre.org/techniques/T1486/) | Data Encrypted for Impact | Impact | - -
-
- - -
- Kill Chain Phase - -
- -* Delivery - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Filesystem.user) as user values(Filesystem.dest) as dest values(Filesystem.file_name) as file_name from datamodel=Endpoint.Filesystem where Filesystem.file_path=*\\windows\\system32\\test.txt by Filesystem.file_path -| `drop_dm_object_name(Filesystem)` -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `samsam_test_file_write_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **samsam_test_file_write_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Filesystem.user -* Filesystem.dest -* Filesystem.file_name -* Filesystem.file_path - - -#### How To Implement -You must be ingesting data that records the file-system activity from your hosts to populate the Endpoint file-system data-model node. If you are using Sysmon, you will need a Splunk Universal Forwarder on each endpoint from which you want to collect data. - -#### Known False Positives -No false positives have been identified. - -#### Associated Analytic story -* [SamSam Ransomware](/stories/samsam_ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 12.0 | 60 | 20 | A samsam ransomware test file creation in $file_path$ in host $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1486/sam_sam_note/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1486/sam_sam_note/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/samsam_test_file_write.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2019-01-25-processes_tapping_keyboard_events.md b/docs/_posts/2019-01-25-processes_tapping_keyboard_events.md deleted file mode 100644 index 9b822ee34d..0000000000 --- a/docs/_posts/2019-01-25-processes_tapping_keyboard_events.md +++ /dev/null @@ -1,149 +0,0 @@ ---- -title: "Processes Tapping Keyboard Events" -excerpt: "" -categories: - - Endpoint -last_modified_at: 2019-01-25 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for processes in an MacOS system that is tapping keyboard events in MacOS, and essentially monitoring all keystrokes made by a user. This is a common technique used by RATs to log keystrokes from a victim, although it can also be used by legitimate processes like Siri to react on human input - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2019-01-25 -- **Author**: Jose Hernandez, Splunk -- **ID**: 2a371608-331d-4034-ae2c-21dda8f1d0ec - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Command & Control - - -
-
- - -
- NIST - -
- -* DE.DP - - - -
-
- -
- CIS20 - -
- -* CIS 4 -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| from datamodel Alerts.Alerts -| search app=osquery:results name=pack_osx-attacks_Keyboard_Event_Taps -| rename columns.cmdline as cmd, columns.name as process_name, columns.pid as process_id -| dedup host,process_name -| table host,process_name, cmd, process_id -| `processes_tapping_keyboard_events_filter` -``` - -#### Macros -The SPL above uses the following Macros: - -> :information_source: -> **processes_tapping_keyboard_events_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* app -* name -* columns.cmdline -* columns.name -* columns.pid -* host - - -#### How To Implement -In order to properly run this search, Splunk needs to ingest data from your osquery deployed agents with the [osx-attacks.conf](https://github.com/facebook/osquery/blob/experimental/packs/osx-attacks.conf#L599) pack enabled. Also the [TA-OSquery](https://github.com/d1vious/TA-osquery) must be deployed across your indexers and universal forwarders in order to have the osquery data populate the Alerts data model. - -#### Known False Positives -There might be some false positives as keyboard event taps are used by processes like Siri and Zoom video chat, for some good examples of processes to exclude please see [this](https://github.com/facebook/osquery/pull/5345#issuecomment-454639161) comment. - -#### Associated Analytic story -* [ColdRoot MacOS RAT](/stories/coldroot_macos_rat) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/endpoint/processes_tapping_keyboard_events.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2019-01-29-osquery_pack_-_coldroot_detection.md b/docs/_posts/2019-01-29-osquery_pack_-_coldroot_detection.md deleted file mode 100644 index ac2903d714..0000000000 --- a/docs/_posts/2019-01-29-osquery_pack_-_coldroot_detection.md +++ /dev/null @@ -1,144 +0,0 @@ ---- -title: "Osquery pack - ColdRoot detection" -excerpt: "" -categories: - - Deprecated -last_modified_at: 2019-01-29 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for ColdRoot events from the osx-attacks osquery pack. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2019-01-29 -- **Author**: Rico Valdez, Splunk -- **ID**: a6fffe5e-05c3-4c04-badc-887607fbb8dc - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Installation -* Command & Control - - -
-
- - -
- NIST - -
- -* DE.DP -* DE.CM -* PR.PT - - - -
-
- -
- CIS20 - -
- -* CIS 4 -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| from datamodel Alerts.Alerts -| search app=osquery:results (name=pack_osx-attacks_OSX_ColdRoot_RAT_Launchd OR name=pack_osx-attacks_OSX_ColdRoot_RAT_Files) -| rename columns.path as path -| bucket _time span=30s -| stats count(path) by _time, host, user, path -| `osquery_pack___coldroot_detection_filter` -``` - -#### Macros -The SPL above uses the following Macros: - -> :information_source: -> **osquery_pack_-_coldroot_detection_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -In order to properly run this search, Splunk needs to ingest data from your osquery deployed agents with the [osx-attacks.conf](https://github.com/facebook/osquery/blob/experimental/packs/osx-attacks.conf#L599) pack enabled. Also the [TA-OSquery](https://github.com/d1vious/TA-osquery) must be deployed across your indexers and universal forwarders in order to have the osquery data populate the Alerts data model - -#### Known False Positives -There are no known false positives. - -#### Associated Analytic story -* [ColdRoot MacOS RAT](/stories/coldroot_macos_rat) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/osquery_pack___coldroot_detection.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2019-02-27-detect_mimikatz_via_powershell_and_eventcode_4703.md b/docs/_posts/2019-02-27-detect_mimikatz_via_powershell_and_eventcode_4703.md deleted file mode 100644 index dae186beec..0000000000 --- a/docs/_posts/2019-02-27-detect_mimikatz_via_powershell_and_eventcode_4703.md +++ /dev/null @@ -1,161 +0,0 @@ ---- -title: "Detect Mimikatz Via PowerShell And EventCode 4703" -excerpt: "LSASS Memory -" -categories: - - Deprecated -last_modified_at: 2019-02-27 -toc: true -toc_label: "" -tags: - - LSASS Memory - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for PowerShell requesting privileges consistent with credential dumping. Deprecated, looks like things changed from a logging perspective. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2019-02-27 -- **Author**: Rico Valdez, Splunk -- **ID**: 98917be2-bfc8-475a-8618-a9bb06575188 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1003.001](https://attack.mitre.org/techniques/T1003/001/) | LSASS Memory | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.IP -* PR.AC -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`wineventlog_security` signature_id=4703 Process_Name=*powershell.exe -| rex field=Message "Enabled Privileges:\s+(?\w+)\s+Disabled Privileges:" -| where privs="SeDebugPrivilege" -| stats count min(_time) as firstTime max(_time) as lastTime by dest, Process_Name, privs, Process_ID, Message -| rename privs as "Enabled Privilege" -| rename Process_Name as process -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_mimikatz_via_powershell_and_eventcode_4703_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **detect_mimikatz_via_powershell_and_eventcode_4703_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* signature_id -* Process_Name -* Message -* dest -* Process_ID - - -#### How To Implement -You must be ingesting Windows Security logs. You must also enable the account change auditing here: http://docs.splunk.com/Documentation/Splunk/7.0.2/Data/MonitorWindowseventlogdata. Additionally, this search requires you to enable your Group Management Audit Logs in your Local Windows Security Policy and to be ingesting those logs. More information on how to enable them can be found here: http://whatevernetworks.com/auditing-group-membership-changes-in-active-directory/. Finally, please make sure that the local administrator group name is "Administrators" to be able to look for the right group membership changes. - -#### Known False Positives -The activity may be legitimate. PowerShell is often used by administrators to perform various tasks, and it's possible this event could be generated in those cases. In these cases, false positives should be fairly obvious and you may need to tweak the search to eliminate noise. - -#### Associated Analytic story -* [Cloud Federated Credential Abuse](/stories/cloud_federated_credential_abuse) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2019-02-27-reg_exe_used_to_hide_files_directories_via_registry_keys.md b/docs/_posts/2019-02-27-reg_exe_used_to_hide_files_directories_via_registry_keys.md deleted file mode 100644 index 48fbc32d63..0000000000 --- a/docs/_posts/2019-02-27-reg_exe_used_to_hide_files_directories_via_registry_keys.md +++ /dev/null @@ -1,153 +0,0 @@ ---- -title: "Reg exe used to hide files directories via registry keys" -excerpt: "Hidden Files and Directories -" -categories: - - Deprecated -last_modified_at: 2019-02-27 -toc: true -toc_label: "" -tags: - - Hidden Files and Directories - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The search looks for command-line arguments used to hide a file or directory using the reg add command. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2019-02-27 -- **Author**: Bhavin Patel, Splunk -- **ID**: 61a7d1e6-f5d4-41d9-a9be-39a1ffe69459 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1564.001](https://attack.mitre.org/techniques/T1564/001/) | Hidden Files and Directories | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = reg.exe Processes.process="*add*" Processes.process="*Hidden*" Processes.process="*REG_DWORD*" by Processes.process_name Processes.parent_process_name Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -| regex process = "(/d\s+2)" -| `reg_exe_used_to_hide_files_directories_via_registry_keys_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **reg_exe_used_to_hide_files_directories_via_registry_keys_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. - -#### Known False Positives -None at the moment - -#### Associated Analytic story -* [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics) -* [Suspicious Windows Registry Activities](/stories/suspicious_windows_registry_activities) -* [Windows Persistence Techniques](/stories/windows_persistence_techniques) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2019-04-01-web_servers_executing_suspicious_processes.md b/docs/_posts/2019-04-01-web_servers_executing_suspicious_processes.md deleted file mode 100644 index 36e29731e8..0000000000 --- a/docs/_posts/2019-04-01-web_servers_executing_suspicious_processes.md +++ /dev/null @@ -1,157 +0,0 @@ ---- -title: "Web Servers Executing Suspicious Processes" -excerpt: "System Information Discovery -" -categories: - - Application -last_modified_at: 2019-04-01 -toc: true -toc_label: "" -tags: - - System Information Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for suspicious processes on all systems labeled as web servers. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2019-04-01 -- **Author**: David Dorsey, Splunk -- **ID**: ec3b7601-689a-4463-94e0-c9f45638efb9 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1082](https://attack.mitre.org/techniques/T1082/) | System Information Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.IP - - - -
-
- -
- CIS20 - -
- -* CIS 3 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.dest_category="web_server" AND (Processes.process="*whoami*" OR Processes.process="*ping*" OR Processes.process="*iptables*" OR Processes.process="*wget*" OR Processes.process="*service*" OR Processes.process="*curl*") by Processes.process Processes.process_name, Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `web_servers_executing_suspicious_processes_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **web_servers_executing_suspicious_processes_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest_category -* Processes.process -* Processes.process_name -* Processes.dest -* Processes.user - - -#### How To Implement -You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. In addition, web servers will need to be identified in the Assets and Identity Framework of Enterprise Security. - -#### Known False Positives -Some of these processes may be used legitimately on web servers during maintenance or other administrative tasks. - -#### Associated Analytic story -* [Apache Struts Vulnerability](/stories/apache_struts_vulnerability) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/application/web_servers_executing_suspicious_processes.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2019-04-25-suspicious_file_write.md b/docs/_posts/2019-04-25-suspicious_file_write.md deleted file mode 100644 index dd9f2854a8..0000000000 --- a/docs/_posts/2019-04-25-suspicious_file_write.md +++ /dev/null @@ -1,144 +0,0 @@ ---- -title: "Suspicious File Write" -excerpt: "" -categories: - - Deprecated -last_modified_at: 2019-04-25 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The search looks for files created with names that have been linked to malicious activity. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2019-04-25 -- **Author**: Rico Valdez, Splunk -- **ID**: 57f76b8a-32f0-42ed-b358-d9fa3ca7bac8 - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count values(Filesystem.action) as action values(Filesystem.file_path) as file_path min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem by Filesystem.file_name Filesystem.dest -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `drop_dm_object_name(Filesystem)` -| `suspicious_writes` -| `suspicious_file_write_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [suspicious_writes](https://github.com/splunk/security_content/blob/develop/macros/suspicious_writes.yml) - -> :information_source: -> **suspicious_file_write_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -You must be ingesting data that records the filesystem activity from your hosts to populate the Endpoint file-system data model node. This is typically populated via endpoint detection-and-response product, such as Carbon Black, or via other endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report file system reads and writes. In addition, this search leverages an included lookup file that contains the names of the files to watch for, as well as a note to communicate why that file name is being monitored. This lookup file can be edited to add or remove file the file names you want to monitor. - -#### Known False Positives -It's possible for a legitimate file to be created with the same name as one noted in the lookup file. Filenames listed in the lookup file should be unique enough that collisions are rare. Looking at the location of the file and the process responsible for the activity can help determine whether or not the activity is legitimate. - -#### Associated Analytic story -* [Hidden Cobra Malware](/stories/hidden_cobra_malware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/suspicious_file_write.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2019-05-08-unusually_long_command_line_-_mltk.md b/docs/_posts/2019-05-08-unusually_long_command_line_-_mltk.md deleted file mode 100644 index 903fc504cb..0000000000 --- a/docs/_posts/2019-05-08-unusually_long_command_line_-_mltk.md +++ /dev/null @@ -1,157 +0,0 @@ ---- -title: "Unusually Long Command Line - MLTK" -excerpt: "" -categories: - - Endpoint -last_modified_at: 2019-05-08 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -Command lines that are extremely long may be indicative of malicious activity on your hosts. This search leverages the Machine Learning Toolkit (MLTK) to help identify command lines with lengths that are unusual for a given user. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2019-05-08 -- **Author**: Rico Valdez, Splunk -- **ID**: 57edaefa-a73b-45e5-bbae-f39c1473f941 - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes by Processes.user Processes.dest Processes.process_name Processes.process -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| eval processlen=len(process) -| search user!=unknown -| apply cmdline_pdfmodel threshold=0.01 -| rename "IsOutlier(processlen)" as isOutlier -| search isOutlier > 0 -| table firstTime lastTime user dest process_name process processlen count -| `unusually_long_command_line___mltk_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **unusually_long_command_line_-_mltk_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.user -* Processes.dest -* Processes.process_name -* Processes.process - - -#### How To Implement -You must be ingesting endpoint data that monitors command lines and populates the Endpoint data model in the Processes node. The command-line arguments are mapped to the "process" field in the Endpoint data model. In addition, MLTK version >= 4.2 must be installed on your search heads, along with any required dependencies. Finally, the support search "Baseline of Command Line Length - MLTK" must be executed before this detection search, as it builds an ML model over the historical data used by this search. It is important that this search is run in the same app context as the associated support search, so that the model created by the support search is available for use. You should periodically re-run the support search to rebuild the model with the latest data available in your environment. - -#### Known False Positives -Some legitimate applications use long command lines for installs or updates. You should review identified command lines for legitimacy. You may modify the first part of the search to omit legitimate command lines from consideration. If you are seeing more results than desired, you may consider changing the value of threshold in the search to a smaller value. You should also periodically re-run the support search to re-build the ML model on the latest data. You may get unexpected results if the user identified in the results is not present in the data used to build the associated model. - -#### Associated Analytic story -* [Suspicious Command-Line Executions](/stories/suspicious_command-line_executions) -* [Unusual Processes](/stories/unusual_processes) -* [Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns](/stories/possible_backdoor_activity_associated_with_mudcarp_espionage_campaigns) -* [Ransomware](/stories/ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/endpoint/unusually_long_command_line___mltk.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2019-10-11-prohibited_software_on_endpoint.md b/docs/_posts/2019-10-11-prohibited_software_on_endpoint.md deleted file mode 100644 index 52db687451..0000000000 --- a/docs/_posts/2019-10-11-prohibited_software_on_endpoint.md +++ /dev/null @@ -1,149 +0,0 @@ ---- -title: "Prohibited Software On Endpoint" -excerpt: "" -categories: - - Deprecated -last_modified_at: 2019-10-11 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for applications on the endpoint that you have marked as prohibited. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2019-10-11 -- **Author**: David Dorsey, Splunk -- **ID**: a51bfe1a-94f0-48cc-b4e4-b6ae50145893 - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Installation -* Command & Control -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* ID.AM -* PR.DS - - - -
-
- -
- CIS20 - -
- -* CIS 2 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes by Processes.dest Processes.user Processes.process_name -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `drop_dm_object_name(Processes)` -| `prohibited_softwares` -| `prohibited_software_on_endpoint_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [prohibited_softwares](https://github.com/splunk/security_content/blob/develop/macros/prohibited_softwares.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **prohibited_software_on_endpoint_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _times - - -#### How To Implement -To successfully implement this search, you must be ingesting data that records process activity from your hosts to populate the endpoint data model in the processes node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is usually generated via logs that report process tracking in your Windows audit settings. In addition, you must also have only the `process_name` (not the entire process path) marked as "prohibited" in the Enterprise Security `interesting processes` table. To include the process names marked as "prohibited", which is included with ES Content Updates, run the included search Add Prohibited Processes to Enterprise Security. - -#### Known False Positives -None identified - -#### Associated Analytic story -* [Monitor for Unauthorized Software](/stories/monitor_for_unauthorized_software) -* [Emotet Malware DHS Report TA18-201A ](/stories/emotet_malware__dhs_report_ta18-201a_) -* [SamSam Ransomware](/stories/samsam_ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/prohibited_software_on_endpoint.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2019-12-03-detect_credential_dumping_through_lsass_access.md b/docs/_posts/2019-12-03-detect_credential_dumping_through_lsass_access.md deleted file mode 100644 index 875ff5b43e..0000000000 --- a/docs/_posts/2019-12-03-detect_credential_dumping_through_lsass_access.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: "Detect Credential Dumping through LSASS access" -excerpt: "LSASS Memory -, OS Credential Dumping -" -categories: - - Endpoint -last_modified_at: 2019-12-03 -toc: true -toc_label: "" -tags: - - LSASS Memory - - OS Credential Dumping - - Credential Access - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for reading lsass memory consistent with credential dumping. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2019-12-03 -- **Author**: Patrick Bareiss, Splunk -- **ID**: 2c365e57-4414-4540-8dc0-73ab10729996 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1003.001](https://attack.mitre.org/techniques/T1003/001/) | LSASS Memory | Credential Access | - -| [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.IP -* PR.AC -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventCode=10 TargetImage=*lsass.exe (GrantedAccess=0x1010 OR GrantedAccess=0x1410) -| stats count min(_time) as firstTime max(_time) as lastTime by Computer, SourceImage, SourceProcessId, TargetImage, TargetProcessId, EventCode, GrantedAccess -| rename Computer as dest -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_credential_dumping_through_lsass_access_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **detect_credential_dumping_through_lsass_access_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* TargetImage -* GrantedAccess -* Computer -* SourceImage -* SourceProcessId -* TargetImage -* TargetProcessId - - -#### How To Implement -This search needs Sysmon Logs and a sysmon configuration, which includes EventCode 10 with lsass.exe. This search uses an input macro named `sysmon`. We strongly recommend that you specify your environment-specific configurations (index, source, sourcetype, etc.) for Windows Sysmon logs. Replace the macro definition with configurations for your Splunk environment. The search also uses a post-filter macro designed to filter out known false positives. - -#### Known False Positives -The activity may be legitimate. Other tools can access lsass for legitimate reasons, and it's possible this event could be generated in those cases. In these cases, false positives should be fairly obvious and you may need to tweak the search to eliminate noise. - -#### Associated Analytic story -* [Credential Dumping](/stories/credential_dumping) -* [Detect Zerologon Attack](/stories/detect_zerologon_attack) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | The $source_image$ has attempted access to read $TargetImage$ was identified on endpoint $Computer$, this is indicative of credential dumping and should be investigated. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.001/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.001/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2019-12-03-detect_mimikatz_using_loaded_images.md b/docs/_posts/2019-12-03-detect_mimikatz_using_loaded_images.md deleted file mode 100644 index 445b0aa8ec..0000000000 --- a/docs/_posts/2019-12-03-detect_mimikatz_using_loaded_images.md +++ /dev/null @@ -1,171 +0,0 @@ ---- -title: "Detect Mimikatz Using Loaded Images" -excerpt: "LSASS Memory -, OS Credential Dumping -" -categories: - - Endpoint -last_modified_at: 2019-12-03 -toc: true -toc_label: "" -tags: - - LSASS Memory - - OS Credential Dumping - - Credential Access - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for reading loaded Images unique to credential dumping with Mimikatz. Deprecated because mimikatz libraries changed and very noisy sysmon Event Code. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2019-12-03 -- **Author**: Patrick Bareiss, Splunk -- **ID**: 29e307ba-40af-4ab2-91b2-3c6b392bbba0 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1003.001](https://attack.mitre.org/techniques/T1003/001/) | LSASS Memory | Credential Access | - -| [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.AE -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 6 -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventCode=7 -| stats values(ImageLoaded) as ImageLoaded values(ProcessId) as ProcessId by Computer, Image -| search ImageLoaded=*WinSCard.dll ImageLoaded=*cryptdll.dll ImageLoaded=*hid.dll ImageLoaded=*samlib.dll ImageLoaded=*vaultcli.dll -| rename Computer as dest -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_mimikatz_using_loaded_images_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **detect_mimikatz_using_loaded_images_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* ImageLoaded -* ProcessId -* Computer -* Image - - -#### How To Implement -This search needs Sysmon Logs and a sysmon configuration, which includes EventCode 7 with powershell.exe. This search uses an input macro named `sysmon`. We strongly recommend that you specify your environment-specific configurations (index, source, sourcetype, etc.) for Windows Sysmon logs. Replace the macro definition with configurations for your Splunk environment. The search also uses a post-filter macro designed to filter out known false positives. - -#### Known False Positives -Other tools can import the same DLLs. These tools should be part of a whitelist. False positives may be present with any process that authenticates or uses credentials, PowerShell included. Filter based on parent process. - -#### Associated Analytic story -* [Credential Dumping](/stories/credential_dumping) -* [Detect Zerologon Attack](/stories/detect_zerologon_attack) -* [Cloud Federated Credential Abuse](/stories/cloud_federated_credential_abuse) -* [DarkSide Ransomware](/stories/darkside_ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 64.0 | 80 | 80 | A process, $Image$, has loaded $ImageLoaded$ that are typically related to credential dumping on $Computer$. Review for further details. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://cyberwardog.blogspot.com/2017/03/chronicles-of-threat-hunter-hunting-for.html](https://cyberwardog.blogspot.com/2017/03/chronicles-of-threat-hunter-hunting-for.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2019-12-06-access_lsass_memory_for_dump_creation.md b/docs/_posts/2019-12-06-access_lsass_memory_for_dump_creation.md deleted file mode 100644 index 6228d32f4a..0000000000 --- a/docs/_posts/2019-12-06-access_lsass_memory_for_dump_creation.md +++ /dev/null @@ -1,168 +0,0 @@ ---- -title: "Access LSASS Memory for Dump Creation" -excerpt: "LSASS Memory -, OS Credential Dumping -" -categories: - - Endpoint -last_modified_at: 2019-12-06 -toc: true -toc_label: "" -tags: - - LSASS Memory - - OS Credential Dumping - - Credential Access - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -Detect memory dumping of the LSASS process. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2019-12-06 -- **Author**: Patrick Bareiss, Splunk -- **ID**: fb4c31b0-13e8-4155-8aa5-24de4b8d6717 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1003.001](https://attack.mitre.org/techniques/T1003/001/) | LSASS Memory | Credential Access | - -| [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 6 -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventCode=10 TargetImage=*lsass.exe CallTrace=*dbgcore.dll* OR CallTrace=*dbghelp.dll* -| stats count min(_time) as firstTime max(_time) as lastTime by Computer, TargetImage, TargetProcessId, SourceImage, SourceProcessId -| rename Computer as dest -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `access_lsass_memory_for_dump_creation_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **access_lsass_memory_for_dump_creation_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* TargetImage -* CallTrace -* Computer -* TargetProcessId -* SourceImage -* SourceProcessId - - -#### How To Implement -This search requires Sysmon Logs and a Sysmon configuration, which includes EventCode 10 for lsass.exe. This search uses an input macro named `sysmon`. We strongly recommend that you specify your environment-specific configurations (index, source, sourcetype, etc.) for Windows Sysmon logs. Replace the macro definition with configurations for your Splunk environment. The search also uses a post-filter macro designed to filter out known false positives. - -#### Known False Positives -Administrators can create memory dumps for debugging purposes, but memory dumps of the LSASS process would be unusual. - -#### Associated Analytic story -* [Credential Dumping](/stories/credential_dumping) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 63.0 | 70 | 90 | process $SourceImage$ injected into $TargetImage$ and was attempted dump LSASS on $dest$. Adversaries tend to do this when trying to accesss credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS). | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf](https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.001/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.001/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2019-12-06-create_remote_thread_into_lsass.md b/docs/_posts/2019-12-06-create_remote_thread_into_lsass.md deleted file mode 100644 index 01a8bca88b..0000000000 --- a/docs/_posts/2019-12-06-create_remote_thread_into_lsass.md +++ /dev/null @@ -1,168 +0,0 @@ ---- -title: "Create Remote Thread into LSASS" -excerpt: "LSASS Memory -, OS Credential Dumping -" -categories: - - Endpoint -last_modified_at: 2019-12-06 -toc: true -toc_label: "" -tags: - - LSASS Memory - - OS Credential Dumping - - Credential Access - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -Detect remote thread creation into LSASS consistent with credential dumping. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2019-12-06 -- **Author**: Patrick Bareiss, Splunk -- **ID**: 67d4dbef-9564-4699-8da8-03a151529edc - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1003.001](https://attack.mitre.org/techniques/T1003/001/) | LSASS Memory | Credential Access | - -| [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventID=8 TargetImage=*lsass.exe -| stats count min(_time) as firstTime max(_time) as lastTime by Computer, EventCode, TargetImage, TargetProcessId -| rename Computer as dest -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `create_remote_thread_into_lsass_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **create_remote_thread_into_lsass_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventID -* TargetImage -* Computer -* EventCode -* TargetImage -* TargetProcessId -* dest - - -#### How To Implement -This search needs Sysmon Logs with a Sysmon configuration, which includes EventCode 8 with lsass.exe. This search uses an input macro named `sysmon`. We strongly recommend that you specify your environment-specific configurations (index, source, sourcetype, etc.) for Windows Sysmon logs. Replace the macro definition with configurations for your Splunk environment. The search also uses a post-filter macro designed to filter out known false positives. - -#### Known False Positives -Other tools can access LSASS for legitimate reasons and generate an event. In these cases, tweaking the search may help eliminate noise. - -#### Associated Analytic story -* [Credential Dumping](/stories/credential_dumping) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 81.0 | 90 | 90 | A process has created a remote thread into $TargetImage$ on $dest$. This behavior is indicative of credential dumping and should be investigated. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf](https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.001/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.001/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/create_remote_thread_into_lsass.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2019-12-06-unsigned_image_loaded_by_lsass.md b/docs/_posts/2019-12-06-unsigned_image_loaded_by_lsass.md deleted file mode 100644 index 6ce1a2e91d..0000000000 --- a/docs/_posts/2019-12-06-unsigned_image_loaded_by_lsass.md +++ /dev/null @@ -1,153 +0,0 @@ ---- -title: "Unsigned Image Loaded by LSASS" -excerpt: "LSASS Memory -" -categories: - - Deprecated -last_modified_at: 2019-12-06 -toc: true -toc_label: "" -tags: - - LSASS Memory - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search detects loading of unsigned images by LSASS. Deprecated because too noisy. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2019-12-06 -- **Author**: Patrick Bareiss, Splunk -- **ID**: 56ef054c-76ef-45f9-af4a-a634695dcd65 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1003.001](https://attack.mitre.org/techniques/T1003/001/) | LSASS Memory | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventID=7 Image=*lsass.exe Signed=false -| stats count min(_time) as firstTime max(_time) as lastTime by Computer, Image, ImageLoaded, Signed, SHA1 -| rename Computer as dest -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `unsigned_image_loaded_by_lsass_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **unsigned_image_loaded_by_lsass_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -This search needs Sysmon Logs with a sysmon configuration, which includes EventCode 7 with lsass.exe. This search uses an input macro named `sysmon`. We strongly recommend that you specify your environment-specific configurations (index, source, sourcetype, etc.) for Windows Sysmon logs. Replace the macro definition with configurations for your Splunk environment. The search also uses a post-filter macro designed to filter out known false positives. - -#### Known False Positives -Other tools could load images into LSASS for legitimate reason. But enterprise tools should always use signed DLLs. - -#### Associated Analytic story -* [Credential Dumping](/stories/credential_dumping) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf](https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2019-12-10-creation_of_shadow_copy.md b/docs/_posts/2019-12-10-creation_of_shadow_copy.md deleted file mode 100644 index 08da7eedb3..0000000000 --- a/docs/_posts/2019-12-10-creation_of_shadow_copy.md +++ /dev/null @@ -1,173 +0,0 @@ ---- -title: "Creation of Shadow Copy" -excerpt: "NTDS -, OS Credential Dumping -" -categories: - - Endpoint -last_modified_at: 2019-12-10 -toc: true -toc_label: "" -tags: - - NTDS - - OS Credential Dumping - - Credential Access - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -Monitor for signs that Vssadmin or Wmic has been used to create a shadow copy. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2019-12-10 -- **Author**: Patrick Bareiss, Splunk -- **ID**: eb120f5f-b879-4a63-97c1-93352b5df844 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1003.003](https://attack.mitre.org/techniques/T1003/003/) | NTDS | Credential Access | - -| [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name=vssadmin.exe Processes.process=*create* Processes.process=*shadow*) OR (Processes.process_name=wmic.exe Processes.process=*shadowcopy* Processes.process=*create*) by Processes.dest Processes.user Processes.process_name Processes.process Processes.parent_process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `creation_of_shadow_copy_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **creation_of_shadow_copy_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -You must be ingesting endpoint data that tracks process activity, including parent-child relationships from your endpoints, to populate the Endpoint data model in the Processes node. The command-line arguments are mapped to the "process" field in the Endpoint data model. - -#### Known False Positives -Legitimate administrator usage of Vssadmin or Wmic will create false positives. - -#### Associated Analytic story -* [Credential Dumping](/stories/credential_dumping) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 81.0 | 90 | 90 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to create a shadow copy to perform offline password cracking. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf](https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.003/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.003/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/creation_of_shadow_copy.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-01-22-dns_query_length_outliers_-_mltk.md b/docs/_posts/2020-01-22-dns_query_length_outliers_-_mltk.md deleted file mode 100644 index 0634b112b0..0000000000 --- a/docs/_posts/2020-01-22-dns_query_length_outliers_-_mltk.md +++ /dev/null @@ -1,179 +0,0 @@ ---- -title: "DNS Query Length Outliers - MLTK" -excerpt: "DNS -, Application Layer Protocol -" -categories: - - Network -last_modified_at: 2020-01-22 -toc: true -toc_label: "" -tags: - - DNS - - Application Layer Protocol - - Command And Control - - Command And Control - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Network_Resolution ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search allows you to identify DNS requests that are unusually large for the record type being requested in your environment. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Network_Resolution](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkResolution) -- **Last Updated**: 2020-01-22 -- **Author**: Rico Valdez, Splunk -- **ID**: 85fbcfe8-9718-4911-adf6-7000d077a3a9 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1071.004](https://attack.mitre.org/techniques/T1071/004/) | DNS | Command And Control | - -| [T1071](https://attack.mitre.org/techniques/T1071/) | Application Layer Protocol | Command And Control | - -
-
- - -
- Kill Chain Phase - -
- -* Command & Control - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.AE -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 -* CIS 12 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as start_time max(_time) as end_time values(DNS.src) as src values(DNS.dest) as dest from datamodel=Network_Resolution by DNS.query DNS.record_type -| search DNS.record_type=* -| `drop_dm_object_name(DNS)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| eval query_length = len(query) -| apply dns_query_pdfmodel threshold=0.01 -| rename "IsOutlier(query_length)" as isOutlier -| search isOutlier > 0 -| sort -query_length -| table start_time end_time query record_type count src dest query_length -| `dns_query_length_outliers___mltk_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **dns_query_length_outliers_-_mltk_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* DNS.src -* DNS.dest -* DNS.query -* DNS.record_type - - -#### How To Implement -To successfully implement this search, you will need to ensure that DNS data is populating the Network_Resolution data model. In addition, the Machine Learning Toolkit (MLTK) version 4.2 or greater must be installed on your search heads, along with any required dependencies. Finally, the support search "Baseline of DNS Query Length - MLTK" must be executed before this detection search, because it builds a machine-learning (ML) model over the historical data used by this search. It is important that this search is run in the same app context as the associated support search, so that the model created by the support search is available for use. You should periodically re-run the support search to rebuild the model with the latest data available in your environment.\ -This search produces fields (`query`,`query_length`,`count`) that are not yet supported by ES Incident Review and therefore cannot be viewed when a notable event is raised. These fields contribute additional context to the notable. To see the additional metadata, add the following fields, if not already present, to Incident Review - Event Attributes (Configure > Incident Management > Incident Review Settings > Add New Entry):\\n1. **Label:** DNS Query, **Field:** query\ -1. \ -1. **Label:** DNS Query Length, **Field:** query_length\ -1. \ -1. **Label:** Number of events, **Field:** count\ -Detailed documentation on how to create a new field within Incident Review may be found here: `https://docs.splunk.com/Documentation/ES/5.3.0/Admin/Customizenotables#Add_a_field_to_the_notable_event_details` - -#### Known False Positives -If you are seeing more results than desired, you may consider reducing the value for threshold in the search. You should also periodically re-run the support search to re-build the ML model on the latest data. - -#### Associated Analytic story -* [Hidden Cobra Malware](/stories/hidden_cobra_malware) -* [Suspicious DNS Traffic](/stories/suspicious_dns_traffic) -* [Command and Control](/stories/command_and_control) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/network/dns_query_length_outliers___mltk.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2020-01-28-auto_admin_logon_registry_entry.md b/docs/_posts/2020-01-28-auto_admin_logon_registry_entry.md deleted file mode 100644 index 42350216ad..0000000000 --- a/docs/_posts/2020-01-28-auto_admin_logon_registry_entry.md +++ /dev/null @@ -1,166 +0,0 @@ ---- -title: "Auto Admin Logon Registry Entry" -excerpt: "Credentials in Registry -, Unsecured Credentials -" -categories: - - Endpoint -last_modified_at: 2020-01-28 -toc: true -toc_label: "" -tags: - - Credentials in Registry - - Unsecured Credentials - - Credential Access - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -this search is to detect a suspicious registry modification to implement auto admin logon to a host. This technique was seen in BlackMatter ransomware to automatically logon to the compromise host after triggering a safemode boot to continue encrypting the whole network. This behavior is not a common practice and really a suspicious TTP or alert need to be consider if found within then network premise. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2020-01-28 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 1379d2b8-0f18-11ec-8ca3-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1552.002](https://attack.mitre.org/techniques/T1552/002/) | Credentials in Registry | Credential Access | - -| [T1552](https://attack.mitre.org/techniques/T1552/) | Unsecured Credentials | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon*" AND Registry.registry_value_name=AutoAdminLogon AND Registry.registry_value_data=1 by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.process_guid Registry.registry_key_name Registry.registry_value_data -| `drop_dm_object_name(Registry)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] -| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name -| `auto_admin_logon_registry_entry_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **auto_admin_logon_registry_entry_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.registry_path -* Registry.registry_key_name -* Registry.registry_value_name -* Registry.dest - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [BlackMatter Ransomware](/stories/blackmatter_ransomware) -* [Windows Registry Abuse](/stories/windows_registry_abuse) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 63.0 | 70 | 90 | modified registry key $registry_key_name$ with registry value $registry_value_name$ to prepare autoadminlogon | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://news.sophos.com/en-us/2021/08/09/blackmatter-ransomware-emerges-from-the-shadow-of-darkside/](https://news.sophos.com/en-us/2021/08/09/blackmatter-ransomware-emerges-from-the-shadow-of-darkside/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1552.002/autoadminlogon/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1552.002/autoadminlogon/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/auto_admin_logon_registry_entry.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2020-01-28-monitor_registry_keys_for_print_monitors.md b/docs/_posts/2020-01-28-monitor_registry_keys_for_print_monitors.md deleted file mode 100644 index 188aa23b88..0000000000 --- a/docs/_posts/2020-01-28-monitor_registry_keys_for_print_monitors.md +++ /dev/null @@ -1,176 +0,0 @@ ---- -title: "Monitor Registry Keys for Print Monitors" -excerpt: "Port Monitors -, Boot or Logon Autostart Execution -" -categories: - - Endpoint -last_modified_at: 2020-01-28 -toc: true -toc_label: "" -tags: - - Port Monitors - - Boot or Logon Autostart Execution - - Persistence - - Privilege Escalation - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for registry activity associated with modifications to the registry key `HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors`. In this scenario, an attacker can load an arbitrary .dll into the print-monitor registry by giving the full path name to the after.dll. The system will execute the .dll with elevated (SYSTEM) permissions and will persist after reboot. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2020-01-28 -- **Author**: Bhavin Patel, Teoderick Contreras, Splunk -- **ID**: f5f6af30-7ba7-4295-bfe9-07de87c01bbc - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1547.010](https://attack.mitre.org/techniques/T1547/010/) | Port Monitors | Persistence, Privilege Escalation | - -| [T1547](https://attack.mitre.org/techniques/T1547/) | Boot or Logon Autostart Execution | Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM -* PR.AC - - - -
-
- -
- CIS20 - -
- -* CIS 8 -* CIS 5 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry where Registry.action=modified AND Registry.registry_path="*CurrentControlSet\\Control\\Print\\Monitors*" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.process_guid Registry.registry_key_name Registry.registry_value_data -| `drop_dm_object_name(Registry)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] -| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name -| `monitor_registry_keys_for_print_monitors_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **monitor_registry_keys_for_print_monitors_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.action -* Registry.registry_path -* Registry.dest -* Registry.registry_key_name -* Registry.user -* Registry.registry_value_name - - -#### How To Implement -To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black, or via other endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report registry modifications. - -#### Known False Positives -You will encounter noise from legitimate print-monitor registry entries. - -#### Associated Analytic story -* [Suspicious Windows Registry Activities](/stories/suspicious_windows_registry_activities) -* [Windows Persistence Techniques](/stories/windows_persistence_techniques) -* [Windows Registry Abuse](/stories/windows_registry_abuse) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 64.0 | 80 | 80 | New print monitor added on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.010/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.010/atomic_red_team/windows-sysmon.log) -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.010/atomic_red_team/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.010/atomic_red_team/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/monitor_registry_keys_for_print_monitors.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2020-01-28-registry_keys_for_creating_shim_databases.md b/docs/_posts/2020-01-28-registry_keys_for_creating_shim_databases.md deleted file mode 100644 index a47e8d36a9..0000000000 --- a/docs/_posts/2020-01-28-registry_keys_for_creating_shim_databases.md +++ /dev/null @@ -1,171 +0,0 @@ ---- -title: "Registry Keys for Creating SHIM Databases" -excerpt: "Application Shimming -, Event Triggered Execution -" -categories: - - Endpoint -last_modified_at: 2020-01-28 -toc: true -toc_label: "" -tags: - - Application Shimming - - Event Triggered Execution - - Persistence - - Privilege Escalation - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for registry activity associated with application compatibility shims, which can be leveraged by attackers for various nefarious purposes. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2020-01-28 -- **Author**: Bhavin Patel, Patrick Bareiss, Teoderick Contreras, Splunk -- **ID**: f5f6af30-7aa7-4295-bfe9-07fe87c01bbb - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1546.011](https://attack.mitre.org/techniques/T1546/011/) | Application Shimming | Persistence, Privilege Escalation | - -| [T1546](https://attack.mitre.org/techniques/T1546/) | Event Triggered Execution | Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry where Registry.registry_path=*CurrentVersion\\AppCompatFlags\\Custom* OR Registry.registry_path=*CurrentVersion\\AppCompatFlags\\InstalledSDB* by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid -| `drop_dm_object_name(Registry)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] -| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data -| `registry_keys_for_creating_shim_databases_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **registry_keys_for_creating_shim_databases_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.registry_key_name -* Registry.registry_path -* Registry.dest -* Registry.user - - -#### How To Implement -To successfully implement this search, you must populate the Change_Analysis data model. This is typically populated via endpoint detection and response product, such as Carbon Black or other endpoint data sources such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. - -#### Known False Positives -There are many legitimate applications that leverage shim databases for compatibility purposes for legacy applications - -#### Associated Analytic story -* [Suspicious Windows Registry Activities](/stories/suspicious_windows_registry_activities) -* [Windows Persistence Techniques](/stories/windows_persistence_techniques) -* [Windows Registry Abuse](/stories/windows_registry_abuse) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 56.0 | 70 | 80 | A registry activity in $registry_path$ related to shim modication in host $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.011/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.011/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml) \| *version*: **4** \ No newline at end of file diff --git a/docs/_posts/2020-01-28-sdclt_uac_bypass.md b/docs/_posts/2020-01-28-sdclt_uac_bypass.md deleted file mode 100644 index 085dfaab15..0000000000 --- a/docs/_posts/2020-01-28-sdclt_uac_bypass.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: "Sdclt UAC Bypass" -excerpt: "Bypass User Account Control -, Abuse Elevation Control Mechanism -" -categories: - - Endpoint -last_modified_at: 2020-01-28 -toc: true -toc_label: "" -tags: - - Bypass User Account Control - - Abuse Elevation Control Mechanism - - Defense Evasion - - Privilege Escalation - - Defense Evasion - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect a suspicious sdclt.exe registry modification. This technique is commonly seen when attacker try to bypassed UAC by using sdclt.exe application by modifying some registry that sdclt.exe tries to open or query with payload file path on it to be executed. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2020-01-28 -- **Author**: Teoderick Contreras, Splunk -- **ID**: d71efbf6-da63-11eb-8c6e-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1548.002](https://attack.mitre.org/techniques/T1548/002/) | Bypass User Account Control | Defense Evasion, Privilege Escalation | - -| [T1548](https://attack.mitre.org/techniques/T1548/) | Abuse Elevation Control Mechanism | Defense Evasion, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where (Registry.registry_path= "*\\Windows\\CurrentVersion\\App Paths\\control.exe*" OR Registry.registry_path= "*\\exefile\\shell\\runas\\command\\*") (Registry.registry_value_name = "(Default)" OR Registry.registry_value_name = "IsolatedCommand") by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.process_guid Registry.registry_key_name Registry.registry_value_data -| `drop_dm_object_name(Registry)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] -| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name -| `sdclt_uac_bypass_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **sdclt_uac_bypass_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.registry_path -* Registry.registry_key_name -* Registry.registry_value_name -* Registry.dest - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Limited to no false positives are expected. - -#### Associated Analytic story -* [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics) -* [Windows Registry Abuse](/stories/windows_registry_abuse) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 63.0 | 70 | 90 | Suspicious modification of registry $registry_path$ with possible payload path $registry_value_name$ in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://enigma0x3.net/2017/03/17/fileless-uac-bypass-using-sdclt-exe/](https://enigma0x3.net/2017/03/17/fileless-uac-bypass-using-sdclt-exe/) -* [https://github.com/hfiref0x/UACME](https://github.com/hfiref0x/UACME) -* [https://www.cyborgsecurity.com/cyborg-labs/threat-hunt-deep-dives-user-account-control-bypass-via-registry-modification/](https://www.cyborgsecurity.com/cyborg-labs/threat-hunt-deep-dives-user-account-control-bypass-via-registry-modification/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/uac_bypass/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/uac_bypass/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/sdclt_uac_bypass.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2020-01-28-silentcleanup_uac_bypass.md b/docs/_posts/2020-01-28-silentcleanup_uac_bypass.md deleted file mode 100644 index 038de74027..0000000000 --- a/docs/_posts/2020-01-28-silentcleanup_uac_bypass.md +++ /dev/null @@ -1,169 +0,0 @@ ---- -title: "SilentCleanup UAC Bypass" -excerpt: "Bypass User Account Control -, Abuse Elevation Control Mechanism -" -categories: - - Endpoint -last_modified_at: 2020-01-28 -toc: true -toc_label: "" -tags: - - Bypass User Account Control - - Abuse Elevation Control Mechanism - - Defense Evasion - - Privilege Escalation - - Defense Evasion - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect a suspicious modification of registry that may related to UAC bypassed. This registry will be trigger once the attacker abuse the silentcleanup task schedule to gain high privilege execution that will bypass User control account. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2020-01-28 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 56d7cfcc-da63-11eb-92d4-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1548.002](https://attack.mitre.org/techniques/T1548/002/) | Bypass User Account Control | Defense Evasion, Privilege Escalation | - -| [T1548](https://attack.mitre.org/techniques/T1548/) | Abuse Elevation Control Mechanism | Defense Evasion, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path= "*\\Environment\\windir" Registry.registry_value_data = "*.exe*" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid Registry.registry_key_name -| `drop_dm_object_name(Registry)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] -| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name -| `silentcleanup_uac_bypass_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **silentcleanup_uac_bypass_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.registry_path -* Registry.registry_key_name -* Registry.registry_value_name -* Registry.dest - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics) -* [Windows Registry Abuse](/stories/windows_registry_abuse) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 63.0 | 70 | 90 | Suspicious modification of registry $registry_path$ with possible payload path $registry_value_name$ in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/hfiref0x/UACME](https://github.com/hfiref0x/UACME) -* [https://www.intezer.com/blog/malware-analysis/klingon-rat-holding-on-for-dear-life/](https://www.intezer.com/blog/malware-analysis/klingon-rat-holding-on-for-dear-life/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/uac_bypass/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/uac_bypass/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/silentcleanup_uac_bypass.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2020-01-28-wsreset_uac_bypass.md b/docs/_posts/2020-01-28-wsreset_uac_bypass.md deleted file mode 100644 index 81ff1f4cb3..0000000000 --- a/docs/_posts/2020-01-28-wsreset_uac_bypass.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: "WSReset UAC Bypass" -excerpt: "Bypass User Account Control -, Abuse Elevation Control Mechanism -" -categories: - - Endpoint -last_modified_at: 2020-01-28 -toc: true -toc_label: "" -tags: - - Bypass User Account Control - - Abuse Elevation Control Mechanism - - Defense Evasion - - Privilege Escalation - - Defense Evasion - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect a suspicious modification of registry related to UAC bypass. This technique is to modify the registry in this detection, create a registry value with the path of the payload and run WSreset.exe to bypass User account Control. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2020-01-28 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 8b5901bc-da63-11eb-be43-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1548.002](https://attack.mitre.org/techniques/T1548/002/) | Bypass User Account Control | Defense Evasion, Privilege Escalation | - -| [T1548](https://attack.mitre.org/techniques/T1548/) | Abuse Elevation Control Mechanism | Defense Evasion, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path= "*\\AppX82a6gwre4fdg3bt635tn5ctqjf8msdd2\\Shell\\open\\command*" AND (Registry.registry_value_name = "(Default)" OR Registry.registry_value_name = "DelegateExecute") by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid Registry.registry_key_name -| `drop_dm_object_name(Registry)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] -| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name -| `wsreset_uac_bypass_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **wsreset_uac_bypass_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.registry_path -* Registry.registry_key_name -* Registry.registry_value_name -* Registry.dest - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics) -* [Living Off The Land](/stories/living_off_the_land) -* [Windows Registry Abuse](/stories/windows_registry_abuse) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 63.0 | 70 | 90 | Suspicious modification of registry $registry_path$ with possible payload path $registry_value_name$ in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/hfiref0x/UACME](https://github.com/hfiref0x/UACME) -* [https://blog.morphisec.com/trickbot-uses-a-new-windows-10-uac-bypass](https://blog.morphisec.com/trickbot-uses-a-new-windows-10-uac-bypass) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/uac_bypass/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/uac_bypass/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/wsreset_uac_bypass.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2020-02-03-creation_of_lsass_dump_with_taskmgr.md b/docs/_posts/2020-02-03-creation_of_lsass_dump_with_taskmgr.md deleted file mode 100644 index e89e183dd1..0000000000 --- a/docs/_posts/2020-02-03-creation_of_lsass_dump_with_taskmgr.md +++ /dev/null @@ -1,168 +0,0 @@ ---- -title: "Creation of lsass Dump with Taskmgr" -excerpt: "LSASS Memory -, OS Credential Dumping -" -categories: - - Endpoint -last_modified_at: 2020-02-03 -toc: true -toc_label: "" -tags: - - LSASS Memory - - OS Credential Dumping - - Credential Access - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -Detect the hands on keyboard behavior of Windows Task Manager creating a process dump of lsass.exe. Upon this behavior occurring, a file write/modification will occur in the users profile under \AppData\Local\Temp. The dump file, lsass.dmp, cannot be renamed, however if the dump occurs more than once, it will be named lsass (2).dmp. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-02-03 -- **Author**: Michael Haag, Splunk -- **ID**: b2fbe95a-9c62-4c12-8a29-24b97e84c0cd - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1003.001](https://attack.mitre.org/techniques/T1003/001/) | LSASS Memory | Credential Access | - -| [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 6 -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventID=11 process_name=taskmgr.exe TargetFilename=*lsass*.dmp -| stats count min(_time) as firstTime max(_time) as lastTime by Computer, object_category, process_name, TargetFilename -| rename Computer as dest -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `creation_of_lsass_dump_with_taskmgr_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **creation_of_lsass_dump_with_taskmgr_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventID -* process_name -* TargetFilename -* Computer -* object_category - - -#### How To Implement -This search requires Sysmon Logs and a Sysmon configuration, which includes EventCode 11 for detecting file create of lsass.dmp. This search uses an input macro named `sysmon`. We strongly recommend that you specify your environment-specific configurations (index, source, sourcetype, etc.) for Windows Sysmon logs. Replace the macro definition with configurations for your Splunk environment. The search also uses a post-filter macro designed to filter out known false positives. - -#### Known False Positives -Administrators can create memory dumps for debugging purposes, but memory dumps of the LSASS process would be unusual. - -#### Associated Analytic story -* [Credential Dumping](/stories/credential_dumping) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | $process_name$ was identified on endpoint $Computer$ writing $TargetFilename$ to disk. This behavior is related to dumping credentials via Task Manager. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1003.001/T1003.001.md#atomic-test-5---dump-lsassexe-memory-using-windows-task-manager](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1003.001/T1003.001.md#atomic-test-5---dump-lsassexe-memory-using-windows-task-manager) -* [https://attack.mitre.org/techniques/T1003/001/](https://attack.mitre.org/techniques/T1003/001/) -* [https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf](https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.001/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.001/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-02-07-ec2_instance_started_with_previously_unseen_instance_type.md b/docs/_posts/2020-02-07-ec2_instance_started_with_previously_unseen_instance_type.md deleted file mode 100644 index 68804c7335..0000000000 --- a/docs/_posts/2020-02-07-ec2_instance_started_with_previously_unseen_instance_type.md +++ /dev/null @@ -1,155 +0,0 @@ ---- -title: "EC2 Instance Started With Previously Unseen Instance Type" -excerpt: "" -categories: - - Deprecated -last_modified_at: 2020-02-07 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for EC2 instances being created with previously unseen instance types. This search is deprecated and have been translated to use the latest Change Datamodel. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-02-07 -- **Author**: David Dorsey, Splunk -- **ID**: 65541c80-03c7-4e05-83c8-1dcd57a2e1ad - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* ID.AM - - - -
-
- -
- CIS20 - -
- -* CIS 1 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cloudtrail` eventName=RunInstances [search `cloudtrail` eventName=RunInstances errorCode=success -| fillnull value="m1.small" requestParameters.instanceType -| stats earliest(_time) as earliest latest(_time) as latest by requestParameters.instanceType -| rename requestParameters.instanceType as instanceType -| inputlookup append=t previously_seen_ec2_instance_types.csv -| stats min(earliest) as earliest max(latest) as latest by instanceType -| outputlookup previously_seen_ec2_instance_types.csv -| eval newType=if(earliest >= relative_time(now(), "-70m@m"), 1, 0) -| `security_content_ctime(earliest)` -| `security_content_ctime(latest)` -| where newType=1 -| rename instanceType as requestParameters.instanceType -| table requestParameters.instanceType] -| spath output=user userIdentity.arn -| rename requestParameters.instanceType as instanceType, responseElements.instancesSet.items{}.instanceId as dest -| table _time, user, dest, instanceType -| `ec2_instance_started_with_previously_unseen_instance_type_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) - -> :information_source: -> **ec2_instance_started_with_previously_unseen_instance_type_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* eventName -* errorCode -* requestParameters.instanceType - - -#### How To Implement -You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your AWS CloudTrail inputs. This search works best when you run the "Previously Seen EC2 Instance Types" support search once to create a history of previously seen instance types. - -#### Known False Positives -It is possible that an admin will create a new system using a new instance type never used before. Verify with the creator that they intended to create the system with the new instance type. - -#### Associated Analytic story -* [AWS Cryptomining](/stories/aws_cryptomining) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_instance_type.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2020-02-07-macos_-_re-opened_applications.md b/docs/_posts/2020-02-07-macos_-_re-opened_applications.md deleted file mode 100644 index 39452d1266..0000000000 --- a/docs/_posts/2020-02-07-macos_-_re-opened_applications.md +++ /dev/null @@ -1,152 +0,0 @@ ---- -title: "MacOS - Re-opened Applications" -excerpt: "" -categories: - - Endpoint -last_modified_at: 2020-02-07 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for processes referencing the plist files that determine which applications are re-opened when a user reboots their machine. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2020-02-07 -- **Author**: Jamie Windley, Splunk -- **ID**: 40bb64f9-f619-4e3d-8732-328d40377c4b - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Installation -* Command & Control - - -
-
- - -
- NIST - -
- -* DE.DP -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count values(Processes.process) as process values(Processes.parent_process) as parent_process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process="*com.apple.loginwindow*" by Processes.user Processes.process_name Processes.parent_process_name Processes.dest -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `macos___re_opened_applications_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **macos_-_re-opened_applications_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process -* Processes.parent_process -* Processes.user -* Processes.process_name -* Processes.parent_process_name -* Processes.dest - - -#### How To Implement -In order to properly run this search, Splunk needs to ingest process data from your osquery deployed agents with the [splunk.conf](https://github.com/splunk/TA-osquery/blob/master/config/splunk.conf) pack enabled. Also the [TA-OSquery](https://github.com/splunk/TA-osquery) must be deployed across your indexers and universal forwarders in order to have the data populate the Endpoint data model. - -#### Known False Positives -At this stage, there are no known false positives. During testing, no process events refering the com.apple.loginwindow.plist files were observed during normal operation of re-opening applications on reboot. Therefore, it can be asumed that any occurences of this in the process events would be worth investigating. In the event that the legitimate modification by the system of these files is in fact logged to the process log, then the process_name of that process can be added to an allow list. - -#### Associated Analytic story -* [ColdRoot MacOS RAT](/stories/coldroot_macos_rat) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/endpoint/macos___re_opened_applications.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-02-20-gcp_gcr_container_uploaded.md b/docs/_posts/2020-02-20-gcp_gcr_container_uploaded.md deleted file mode 100644 index 19682f6191..0000000000 --- a/docs/_posts/2020-02-20-gcp_gcr_container_uploaded.md +++ /dev/null @@ -1,141 +0,0 @@ ---- -title: "GCP GCR container uploaded" -excerpt: "Implant Internal Image -" -categories: - - Deprecated -last_modified_at: 2020-02-20 -toc: true -toc_label: "" -tags: - - Implant Internal Image - - Persistence - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search show information on uploaded containers including source user, account, action, bucket name event name, http user agent, message and destination path. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-02-20 -- **Author**: Rod Soto, Rico Valdez, Splunk -- **ID**: 4f00ca88-e766-4605-ac65-ae51c9fd185b - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1525](https://attack.mitre.org/techniques/T1525/) | Implant Internal Image | Persistence | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -|tstats count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Cloud_Infrastructure.Storage where Storage.event_name=storage.objects.create by Storage.src_user Storage.account Storage.action Storage.bucket_name Storage.event_name Storage.http_user_agent Storage.msg Storage.object_path -| `drop_dm_object_name("Storage")` -| `gcp_gcr_container_uploaded_filter` -``` - -#### Macros -The SPL above uses the following Macros: - -> :information_source: -> **gcp_gcr_container_uploaded_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -You must install the GCP App for Splunk (version 2.0.0 or later), then configure stackdriver and set a subpub subscription to be imported to Splunk. You must also install Cloud Infrastructure data model. Please also customize the `container_implant_gcp_detection_filter` macro to filter out the false positives. - -#### Known False Positives -Uploading container is a normal behavior from developers or users with access to container registry. GCP GCR registers container upload as a Storage event, this search must be considered under the context of CONTAINER upload creation which automatically generates a bucket entry for destination path. - -#### Associated Analytic story -* [Container Implantation Monitoring and Investigation](/stories/container_implantation_monitoring_and_investigation) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/gcp_gcr_container_uploaded.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-02-20-new_container_uploaded_to_aws_ecr.md b/docs/_posts/2020-02-20-new_container_uploaded_to_aws_ecr.md deleted file mode 100644 index 0dcb29abc5..0000000000 --- a/docs/_posts/2020-02-20-new_container_uploaded_to_aws_ecr.md +++ /dev/null @@ -1,143 +0,0 @@ ---- -title: "New container uploaded to AWS ECR" -excerpt: "Implant Internal Image -" -categories: - - Cloud -last_modified_at: 2020-02-20 -toc: true -toc_label: "" -tags: - - Implant Internal Image - - Persistence - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This searches show information on uploaded containers including source user, image id, source IP user type, http user agent, region, first time, last time of operation (PutImage). These searches are based on Cloud Infrastructure Data Model. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-02-20 -- **Author**: Rod Soto, Rico Valdez, Splunk -- **ID**: f0f70b40-f7ad-489d-9905-23d149da8099 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1525](https://attack.mitre.org/techniques/T1525/) | Implant Internal Image | Persistence | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Cloud_Infrastructure.Compute where Compute.user_type!="AssumeRole" AND Compute.http_user_agent="AWS Internal" AND Compute.event_name="PutImage" by Compute.image_id Compute.src_user Compute.src Compute.region Compute.msg Compute.user_type -| `drop_dm_object_name("Compute")` -| `new_container_uploaded_to_aws_ecr_filter` -``` - -#### Macros -The SPL above uses the following Macros: - -> :information_source: -> **new_container_uploaded_to_aws_ecr_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your AWS CloudTrail inputs. You must also install Cloud Infrastructure data model. Please also customize the `container_implant_aws_detection_filter` macro to filter out the false positives. - -#### Known False Positives -Uploading container is a normal behavior from developers or users with access to container registry. - -#### Associated Analytic story -* [Container Implantation Monitoring and Investigation](/stories/container_implantation_monitoring_and_investigation) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/cloud/new_container_uploaded_to_aws_ecr.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-02-21-dump_lsass_via_comsvcs_dll.md b/docs/_posts/2020-02-21-dump_lsass_via_comsvcs_dll.md deleted file mode 100644 index 6a0338fdad..0000000000 --- a/docs/_posts/2020-02-21-dump_lsass_via_comsvcs_dll.md +++ /dev/null @@ -1,180 +0,0 @@ ---- -title: "Dump LSASS via comsvcs DLL" -excerpt: "LSASS Memory -, OS Credential Dumping -" -categories: - - Endpoint -last_modified_at: 2020-02-21 -toc: true -toc_label: "" -tags: - - LSASS Memory - - OS Credential Dumping - - Credential Access - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -Detect the usage of comsvcs.dll for dumping the lsass process. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2020-02-21 -- **Author**: Patrick Bareiss, Splunk -- **ID**: 8943b567-f14d-4ee8-a0bb-2121d4ce3184 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1003.001](https://attack.mitre.org/techniques/T1003/001/) | LSASS Memory | Credential Access | - -| [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_rundll32` Processes.process=*comsvcs.dll* Processes.process=*MiniDump* by Processes.user Processes.process_name Processes.original_file_name Processes.process Processes.dest -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `dump_lsass_via_comsvcs_dll_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [process_rundll32](https://github.com/splunk/security_content/blob/develop/macros/process_rundll32.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **dump_lsass_via_comsvcs_dll_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -None identified. - -#### Associated Analytic story -* [Credential Dumping](/stories/credential_dumping) -* [Suspicious Rundll32 Activity](/stories/suspicious_rundll32_activity) -* [HAFNIUM Group](/stories/hafnium_group) -* [Living Off The Land](/stories/living_off_the_land) -* [Industroyer2](/stories/industroyer2) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified accessing credentials using comsvcs.dll on endpoint $dest$ by user $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://modexp.wordpress.com/2019/08/30/minidumpwritedump-via-com-services-dll/](https://modexp.wordpress.com/2019/08/30/minidumpwritedump-via-com-services-dll/) -* [https://twitter.com/SBousseaden/status/1167417096374050817](https://twitter.com/SBousseaden/status/1167417096374050817) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.001/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.001/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2020-03-02-remote_registry_key_modifications.md b/docs/_posts/2020-03-02-remote_registry_key_modifications.md deleted file mode 100644 index 9182f443c0..0000000000 --- a/docs/_posts/2020-03-02-remote_registry_key_modifications.md +++ /dev/null @@ -1,144 +0,0 @@ ---- -title: "Remote Registry Key modifications" -excerpt: "" -categories: - - Deprecated -last_modified_at: 2020-03-02 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search monitors for remote modifications to registry keys. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-03-02 -- **Author**: Bhavin Patel, Splunk -- **ID**: c9f4b923-f8af-4155-b697-1354f5dcbc5e - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count values(Registry.registry_key_name) as registry_key_name values(Registry.registry_path) as registry_path min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path="\\\\*" by Registry.dest , Registry.user -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `drop_dm_object_name(Registry)` -| `remote_registry_key_modifications_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **remote_registry_key_modifications_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -To successfully implement this search, you must populate the `Endpoint` data model. This is typically populated via endpoint detection-and-response product, such as Carbon Black, or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. Deprecated because I don't think the logic is right. - -#### Known False Positives -This technique may be legitimately used by administrators to modify remote registries, so it's important to filter these events out. - -#### Associated Analytic story -* [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics) -* [Suspicious Windows Registry Activities](/stories/suspicious_windows_registry_activities) -* [Windows Persistence Techniques](/stories/windows_persistence_techniques) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/remote_registry_key_modifications.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2020-03-16-child_processes_of_spoolsv_exe.md b/docs/_posts/2020-03-16-child_processes_of_spoolsv_exe.md deleted file mode 100644 index 33c18be258..0000000000 --- a/docs/_posts/2020-03-16-child_processes_of_spoolsv_exe.md +++ /dev/null @@ -1,168 +0,0 @@ ---- -title: "Child Processes of Spoolsv exe" -excerpt: "Exploitation for Privilege Escalation -" -categories: - - Endpoint -last_modified_at: 2020-03-16 -toc: true -toc_label: "" -tags: - - Exploitation for Privilege Escalation - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2018-8440 - - Endpoint ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for child processes of spoolsv.exe. This activity is associated with a POC privilege-escalation exploit associated with CVE-2018-8440. Spoolsv.exe is the process associated with the Print Spooler service in Windows and typically runs as SYSTEM. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2020-03-16 -- **Author**: Rico Valdez, Splunk -- **ID**: aa0c4aeb-5b18-41c4-8c07-f1442d7599df - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1068](https://attack.mitre.org/techniques/T1068/) | Exploitation for Privilege Escalation | Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* PR.AC -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 5 -* CIS 8 - - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2018-8440](https://nvd.nist.gov/vuln/detail/CVE-2018-8440) | An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC), aka "Windows ALPC Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. | 7.2 | - - - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count values(Processes.process_name) as process_name values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=spoolsv.exe AND Processes.process_name!=regsvr32.exe by Processes.dest Processes.parent_process Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `child_processes_of_spoolsv_exe_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **child_processes_of_spoolsv_exe_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process_name -* Processes.process -* Processes.parent_process_name -* Processes.process_name -* Processes.dest -* Processes.parent_process -* Processes.user - - -#### How To Implement -You must be ingesting endpoint data that tracks process activity, including parent-child relationships from your endpoints to populate the Endpoint data model in the Processes node. The command-line arguments are mapped to the "process" field in the Endpoint data model. Update the `children_of_spoolsv_filter` macro to filter out legitimate child processes spawned by spoolsv.exe. - -#### Known False Positives -Some legitimate printer-related processes may show up as children of spoolsv.exe. You should confirm that any activity as legitimate and may be added as exclusions in the search. - -#### Associated Analytic story -* [Windows Privilege Escalation](/stories/windows_privilege_escalation) -* [Hermetic Wiper](/stories/hermetic_wiper) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/endpoint/child_processes_of_spoolsv_exe.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2020-03-16-detect_rare_executables.md b/docs/_posts/2020-03-16-detect_rare_executables.md deleted file mode 100644 index 11c14b9a07..0000000000 --- a/docs/_posts/2020-03-16-detect_rare_executables.md +++ /dev/null @@ -1,163 +0,0 @@ ---- -title: "Detect Rare Executables" -excerpt: "" -categories: - - Endpoint -last_modified_at: 2020-03-16 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search will return a table of rare processes, the names of the systems running them, and the users who initiated each process. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2020-03-16 -- **Author**: Bhavin Patel, Splunk -- **ID**: 44fddcb2-8d3b-454c-874e-7c6de5a4f7ac - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Installation -* Command & Control -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* ID.AM -* PR.PT -* PR.DS -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 2 -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count values(Processes.dest) as dest values(Processes.user) as user min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes by Processes.process_name -| rename Processes.process_name as process -| rex field=user "(?.*)\\\\(?.*)" -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| search [ -| tstats count from datamodel=Endpoint.Processes by Processes.process_name -| rare Processes.process_name limit=30 -| rename Processes.process_name as process -| `filter_rare_process_allow_list` -| table process ] -| `detect_rare_executables_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [filter_rare_process_allow_list](https://github.com/splunk/security_content/blob/develop/macros/filter_rare_process_allow_list.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **detect_rare_executables_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.process_name - - -#### How To Implement -To successfully implement this search, you must be ingesting data that records process activity from your hosts and populating the endpoint data model with the resultant dataset. The macro `filter_rare_process_allow_list` searches two lookup files for allowed processes. These consist of `rare_process_allow_list_default.csv` and `rare_process_allow_list_local.csv`. To add your own processes to the allow list, add them to `rare_process_allow_list_local.csv`. If you wish to remove an entry from the default lookup file, you will have to modify the macro itself to set the allow_list value for that process to false. You can modify the limit parameter and search scheduling to better suit your environment. - -#### Known False Positives -Some legitimate processes may be only rarely executed in your environment. As these are identified, update `rare_process_allow_list_local.csv` to filter them out of your search results. - -#### Associated Analytic story -* [Emotet Malware DHS Report TA18-201A ](/stories/emotet_malware__dhs_report_ta18-201a_) -* [Unusual Processes](/stories/unusual_processes) -* [Cloud Federated Credential Abuse](/stories/cloud_federated_credential_abuse) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/endpoint/detect_rare_executables.yml) \| *version*: **5** \ No newline at end of file diff --git a/docs/_posts/2020-03-16-process_execution_via_wmi.md b/docs/_posts/2020-03-16-process_execution_via_wmi.md deleted file mode 100644 index ee4bab1330..0000000000 --- a/docs/_posts/2020-03-16-process_execution_via_wmi.md +++ /dev/null @@ -1,162 +0,0 @@ ---- -title: "Process Execution via WMI" -excerpt: "Windows Management Instrumentation -" -categories: - - Endpoint -last_modified_at: 2020-03-16 -toc: true -toc_label: "" -tags: - - Windows Management Instrumentation - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies `WmiPrvSE.exe` spawning a process. This typically occurs when a process is instantiated from a local or remote process using `wmic.exe`. During triage, review parallel processes for suspicious behavior or commands executed. Review the process and command-line spawning from `wmiprvse.exe`. Contain and remediate the endpoint as necessary. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2020-03-16 -- **Author**: Rico Valdez, Michael Haag, Splunk -- **ID**: 24869767-8579-485d-9a4f-d9ddfd8f0cac - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1047](https://attack.mitre.org/techniques/T1047/) | Windows Management Instrumentation | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* PR.AT -* PR.AC -* PR.IP - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=WmiPrvSE.exe by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `process_execution_via_wmi_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **process_execution_via_wmi_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process -* Processes.parent_process_name -* Processes.user -* Processes.dest -* Processes.process_name - - -#### How To Implement -You must be ingesting endpoint data that tracks process activity, including parent-child relationships from your endpoints to populate the Endpoint data model in the Processes node. The command-line arguments are mapped to the "process" field in the Endpoint data model. - -#### Known False Positives -Although unlikely, administrators may use wmi to execute commands for legitimate purposes. - -#### Associated Analytic story -* [Suspicious WMI Use](/stories/suspicious_wmi_use) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | A remote instance execution of wmic.exe that will spawn $parent_process_name$ in host $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1047/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1047/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/process_execution_via_wmi.yml) \| *version*: **4** \ No newline at end of file diff --git a/docs/_posts/2020-03-16-script_execution_via_wmi.md b/docs/_posts/2020-03-16-script_execution_via_wmi.md deleted file mode 100644 index 8cfa6e77a5..0000000000 --- a/docs/_posts/2020-03-16-script_execution_via_wmi.md +++ /dev/null @@ -1,163 +0,0 @@ ---- -title: "Script Execution via WMI" -excerpt: "Windows Management Instrumentation -" -categories: - - Endpoint -last_modified_at: 2020-03-16 -toc: true -toc_label: "" -tags: - - Windows Management Instrumentation - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for scripts launched via WMI. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2020-03-16 -- **Author**: Rico Valdez, Michael Haag, Splunk -- **ID**: aa73f80d-d728-4077-b226-81ea0c8be589 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1047](https://attack.mitre.org/techniques/T1047/) | Windows Management Instrumentation | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* PR.AT -* PR.AC -* PR.IP - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=scrcons.exe by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `script_execution_via_wmi_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **script_execution_via_wmi_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process_name -* Processes.user -* Processes.dest - - -#### How To Implement -You must be ingesting endpoint data that tracks process activity, including parent-child relationships from your endpoints to populate the Endpoint data model in the Processes node. The command-line arguments are mapped to the "process" field in the Endpoint data model. - -#### Known False Positives -Although unlikely, administrators may use wmi to launch scripts for legitimate purposes. Filter as needed. - -#### Associated Analytic story -* [Suspicious WMI Use](/stories/suspicious_wmi_use) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 36.0 | 60 | 60 | A wmic.exe process $process_name$ taht execute script in host $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://redcanary.com/blog/child-processes/](https://redcanary.com/blog/child-processes/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1047/execution_scrcons/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1047/execution_scrcons/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/script_execution_via_wmi.yml) \| *version*: **4** \ No newline at end of file diff --git a/docs/_posts/2020-03-16-spike_in_file_writes.md b/docs/_posts/2020-03-16-spike_in_file_writes.md deleted file mode 100644 index 7e3c952049..0000000000 --- a/docs/_posts/2020-03-16-spike_in_file_writes.md +++ /dev/null @@ -1,148 +0,0 @@ ---- -title: "Spike in File Writes" -excerpt: "" -categories: - - Endpoint -last_modified_at: 2020-03-16 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The search looks for a sharp increase in the number of files written to a particular host - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-03-16 -- **Author**: David Dorsey, Splunk -- **ID**: fdb0f805-74e4-4539-8c00-618927333aae - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Filesystem where Filesystem.action=created by _time span=1h, Filesystem.dest -| `drop_dm_object_name(Filesystem)` -| eventstats max(_time) as maxtime -| stats count as num_data_samples max(eval(if(_time >= relative_time(maxtime, "-1d@d"), count, null))) as "count" avg(eval(if(_time upperBound) AND num_data_samples >=20, 1, 0) -| search isOutlier=1 -| `spike_in_file_writes_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **spike_in_file_writes_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Filesystem.action -* Filesystem.dest - - -#### How To Implement -In order to implement this search, you must populate the Endpoint file-system data model node. This is typically populated via endpoint detection and response product, such as Carbon Black or endpoint data sources such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the file system. - -#### Known False Positives -It is important to understand that if you happen to install any new applications on your hosts or are copying a large number of files, you can expect to see a large increase of file modifications. - -#### Associated Analytic story -* [SamSam Ransomware](/stories/samsam_ransomware) -* [Ryuk Ransomware](/stories/ryuk_ransomware) -* [Ransomware](/stories/ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/endpoint/spike_in_file_writes.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2020-04-15-amazon_eks_kubernetes_cluster_scan_detection.md b/docs/_posts/2020-04-15-amazon_eks_kubernetes_cluster_scan_detection.md deleted file mode 100644 index 1309557b22..0000000000 --- a/docs/_posts/2020-04-15-amazon_eks_kubernetes_cluster_scan_detection.md +++ /dev/null @@ -1,157 +0,0 @@ ---- -title: "Amazon EKS Kubernetes cluster scan detection" -excerpt: "Cloud Service Discovery -" -categories: - - Cloud -last_modified_at: 2020-04-15 -toc: true -toc_label: "" -tags: - - Cloud Service Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search provides information of unauthenticated requests via user agent, and authentication data against Kubernetes cluster in AWS - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-04-15 -- **Author**: Rod Soto, Splunk -- **ID**: 294c4686-63dd-4fe6-93a2-ca807626704a - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1526](https://attack.mitre.org/techniques/T1526/) | Cloud Service Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`aws_cloudwatchlogs_eks` "user.username"="system:anonymous" userAgent!="AWS Security Scanner" -| rename sourceIPs{} as src_ip -| stats count min(_time) as firstTime max(_time) as lastTime values(responseStatus.reason) values(source) as cluster_name values(responseStatus.code) values(userAgent) as http_user_agent values(verb) values(requestURI) by src_ip user.username user.groups{} -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -|`amazon_eks_kubernetes_cluster_scan_detection_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [aws_cloudwatchlogs_eks](https://github.com/splunk/security_content/blob/develop/macros/aws_cloudwatchlogs_eks.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **amazon_eks_kubernetes_cluster_scan_detection_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* user.username -* userAgent -* sourceIPs{} -* responseStatus.reason -* source -* responseStatus.code -* verb -* requestURI -* src_ip -* user.groups{} - - -#### How To Implement -You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your CloudWatch EKS Logs inputs. - -#### Known False Positives -Not all unauthenticated requests are malicious, but frequency, UA and source IPs will provide context. - -#### Associated Analytic story -* [Kubernetes Scanning Activity](/stories/kubernetes_scanning_activity) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/cloud/amazon_eks_kubernetes_cluster_scan_detection.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-04-15-amazon_eks_kubernetes_pod_scan_detection.md b/docs/_posts/2020-04-15-amazon_eks_kubernetes_pod_scan_detection.md deleted file mode 100644 index 881939da87..0000000000 --- a/docs/_posts/2020-04-15-amazon_eks_kubernetes_pod_scan_detection.md +++ /dev/null @@ -1,158 +0,0 @@ ---- -title: "Amazon EKS Kubernetes Pod scan detection" -excerpt: "Cloud Service Discovery -" -categories: - - Cloud -last_modified_at: 2020-04-15 -toc: true -toc_label: "" -tags: - - Cloud Service Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search provides detection information on unauthenticated requests against Kubernetes' Pods API - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-04-15 -- **Author**: Rod Soto, Splunk -- **ID**: dbfca1dd-b8e5-4ba4-be0e-e565e5d62002 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1526](https://attack.mitre.org/techniques/T1526/) | Cloud Service Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`aws_cloudwatchlogs_eks` "user.username"="system:anonymous" verb=list objectRef.resource=pods requestURI="/api/v1/pods" -| rename source as cluster_name sourceIPs{} as src_ip -| stats count min(_time) as firstTime max(_time) as lastTime values(responseStatus.reason) values(responseStatus.code) values(userAgent) values(verb) values(requestURI) by src_ip cluster_name user.username user.groups{} -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `amazon_eks_kubernetes_pod_scan_detection_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [aws_cloudwatchlogs_eks](https://github.com/splunk/security_content/blob/develop/macros/aws_cloudwatchlogs_eks.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **amazon_eks_kubernetes_pod_scan_detection_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* user.username -* verb -* objectRef.resource -* requestURI -* source -* sourceIPs{} -* responseStatus.reason -* responseStatus.code -* userAgent -* src_ip -* user.groups{} - - -#### How To Implement -You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on forAWS (version 4.4.0 or later), then configure your AWS CloudWatch EKS Logs.Please also customize the `kubernetes_pods_aws_scan_fingerprint_detection` macro to filter out the false positives. - -#### Known False Positives -Not all unauthenticated requests are malicious, but frequency, UA and source IPs and direct request to API provide context. - -#### Associated Analytic story -* [Kubernetes Scanning Activity](/stories/kubernetes_scanning_activity) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/cloud/amazon_eks_kubernetes_pod_scan_detection.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-04-15-gcp_kubernetes_cluster_scan_detection.md b/docs/_posts/2020-04-15-gcp_kubernetes_cluster_scan_detection.md deleted file mode 100644 index 3937632e2a..0000000000 --- a/docs/_posts/2020-04-15-gcp_kubernetes_cluster_scan_detection.md +++ /dev/null @@ -1,146 +0,0 @@ ---- -title: "GCP Kubernetes cluster scan detection" -excerpt: "Cloud Service Discovery -" -categories: - - Deprecated -last_modified_at: 2020-04-15 -toc: true -toc_label: "" -tags: - - Cloud Service Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search provides information of unauthenticated requests via user agent, and authentication data against Kubernetes cluster - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-04-15 -- **Author**: Rod Soto, Splunk -- **ID**: db5957ec-0144-4c56-b512-9dccbe7a2d26 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1526](https://attack.mitre.org/techniques/T1526/) | Cloud Service Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`google_gcp_pubsub_message` data.protoPayload.requestMetadata.callerIp!=127.0.0.1 data.protoPayload.requestMetadata.callerIp!=::1 "data.labels.authorization.k8s.io/decision"=forbid "data.protoPayload.status.message"=PERMISSION_DENIED data.protoPayload.authenticationInfo.principalEmail="system:anonymous" -| rename data.protoPayload.requestMetadata.callerIp as src_ip -| stats count min(_time) as firstTime max(_time) as lastTime values(data.protoPayload.methodName) as method_name values(data.protoPayload.resourceName) as resource_name values(data.protoPayload.requestMetadata.callerSuppliedUserAgent) as http_user_agent by src_ip data.resource.labels.cluster_name -| rename data.resource.labels.cluster_name as cluster_name -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `gcp_kubernetes_cluster_scan_detection_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [google_gcp_pubsub_message](https://github.com/splunk/security_content/blob/develop/macros/google_gcp_pubsub_message.yml) - -> :information_source: -> **gcp_kubernetes_cluster_scan_detection_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -You must install the GCP App for Splunk (version 2.0.0 or later), then configure stackdriver and set a Pub/Sub subscription to be imported to Splunk. You must also install Cloud Infrastructure data model.Customize the macro kubernetes_gcp_scan_fingerprint_attack_detection to filter out FPs. - -#### Known False Positives -Not all unauthenticated requests are malicious, but frequency, User Agent and source IPs will provide context. - -#### Associated Analytic story -* [Kubernetes Scanning Activity](/stories/kubernetes_scanning_activity) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/gcp_kubernetes_cluster_scan_detection.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-05-19-kubernetes_azure_scan_fingerprint.md b/docs/_posts/2020-05-19-kubernetes_azure_scan_fingerprint.md deleted file mode 100644 index 36dfc30861..0000000000 --- a/docs/_posts/2020-05-19-kubernetes_azure_scan_fingerprint.md +++ /dev/null @@ -1,143 +0,0 @@ ---- -title: "Kubernetes Azure scan fingerprint" -excerpt: "Cloud Service Discovery -" -categories: - - Deprecated -last_modified_at: 2020-05-19 -toc: true -toc_label: "" -tags: - - Cloud Service Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search provides information of unauthenticated requests via source IP user agent, request URI and response status data against Kubernetes cluster in Azure - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-05-19 -- **Author**: Rod Soto, Splunk -- **ID**: c5e5bd5c-1013-4841-8b23-e7b3253c840a - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1526](https://attack.mitre.org/techniques/T1526/) | Cloud Service Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`kubernetes_azure` category=kube-audit -| spath input=properties.log -| search responseStatus.code=401 -| table sourceIPs{} userAgent verb requestURI responseStatus.reason -|`kubernetes_azure_scan_fingerprint_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [kubernetes_azure](https://github.com/splunk/security_content/blob/develop/macros/kubernetes_azure.yml) - -> :information_source: -> **kubernetes_azure_scan_fingerprint_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -You must install the Add-on for Microsoft Cloud Services and Configure Kube-Audit data diagnostics - -#### Known False Positives -Not all unauthenticated requests are malicious, but source IPs, userAgent, verb, request URI and response status will provide context. - -#### Associated Analytic story -* [Kubernetes Scanning Activity](/stories/kubernetes_scanning_activity) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/kubernetes_azure_scan_fingerprint.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-05-20-first_time_seen_child_process_of_zoom.md b/docs/_posts/2020-05-20-first_time_seen_child_process_of_zoom.md deleted file mode 100644 index 1164dc80d2..0000000000 --- a/docs/_posts/2020-05-20-first_time_seen_child_process_of_zoom.md +++ /dev/null @@ -1,173 +0,0 @@ ---- -title: "First Time Seen Child Process of Zoom" -excerpt: "Exploitation for Privilege Escalation -" -categories: - - Endpoint -last_modified_at: 2020-05-20 -toc: true -toc_label: "" -tags: - - Exploitation for Privilege Escalation - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for child processes spawned by zoom.exe or zoom.us that has not previously been seen. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2020-05-20 -- **Author**: David Dorsey, Splunk -- **ID**: e91bd102-d630-4e76-ab73-7e3ba22c5961 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1068](https://attack.mitre.org/techniques/T1068/) | Exploitation for Privilege Escalation | Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM -* PR.IP - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` min(_time) as firstTime values(Processes.parent_process_name) as parent_process_name values(Processes.parent_process_id) as parent_process_id values(Processes.process_name) as process_name values(Processes.process) as process from datamodel=Endpoint.Processes where (Processes.parent_process_name=zoom.exe OR Processes.parent_process_name=zoom.us) by Processes.process_id Processes.dest -| `drop_dm_object_name(Processes)` -| lookup zoom_first_time_child_process dest as dest process_name as process_name OUTPUT firstTimeSeen -| where isnull(firstTimeSeen) OR firstTimeSeen > relative_time(now(), "`previously_seen_zoom_child_processes_window`") -| `security_content_ctime(firstTime)` -| table firstTime dest, process_id, process_name, parent_process_id, parent_process_name -|`first_time_seen_child_process_of_zoom_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [previously_seen_zoom_child_processes_window](https://github.com/splunk/security_content/blob/develop/macros/previously_seen_zoom_child_processes_window.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **first_time_seen_child_process_of_zoom_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Lookups -The SPL above uses the following Lookups: - -* [zoom_first_time_child_process](https://github.com/splunk/security_content/blob/develop/lookups/zoom_first_time_child_process.yml) with [data](https://github.com/splunk/security_content/tree/develop/lookups/zoom_first_time_child_process.csv) - -#### Required field -* _time -* Processes.parent_process_name -* Processes.parent_process_id -* Processes.process_name -* Processes.process -* Processes.parent_process_name -* Processes.process_id -* Processes.dest - - -#### How To Implement -You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You should run the baseline search `Previously Seen Zoom Child Processes - Initial` to build the initial table of child processes and hostnames for this search to work. You should also schedule at the same interval as this search the second baseline search `Previously Seen Zoom Child Processes - Update` to keep this table up to date and to age out old child processes. Please update the `previously_seen_zoom_child_processes_window` macro to adjust the time window. - -#### Known False Positives -A new child process of zoom isn't malicious by that fact alone. Further investigation of the actions of the child process is needed to verify any malicious behavior is taken. - -#### Associated Analytic story -* [Suspicious Zoom Child Processes](/stories/suspicious_zoom_child_processes) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 64.0 | 80 | 80 | Child process $process_name$ with $process_id$ spawned by zoom.exe or zoom.us which has not been previously on host $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1068/zoom_child_process/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1068/zoom_child_process/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/endpoint/first_time_seen_child_process_of_zoom.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-05-20-kubernetes_azure_detect_sensitive_object_access.md b/docs/_posts/2020-05-20-kubernetes_azure_detect_sensitive_object_access.md deleted file mode 100644 index a83b69baa0..0000000000 --- a/docs/_posts/2020-05-20-kubernetes_azure_detect_sensitive_object_access.md +++ /dev/null @@ -1,136 +0,0 @@ ---- -title: "Kubernetes Azure detect sensitive object access" -excerpt: "" -categories: - - Deprecated -last_modified_at: 2020-05-20 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search provides information on Kubernetes accounts accessing sensitve objects such as configmpas or secrets - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-05-20 -- **Author**: Rod Soto, Splunk -- **ID**: 1bba382b-07fd-4ffa-b390-8002739b76e8 - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`kubernetes_azure` category=kube-audit -| spath input=properties.log -| search objectRef.resource=secrets OR configmaps user.username=system.anonymous OR annotations.authorization.k8s.io/decision=allow -|table user.username user.groups{} objectRef.resource objectRef.namespace objectRef.name annotations.authorization.k8s.io/reason -|dedup user.username user.groups{} -|`kubernetes_azure_detect_sensitive_object_access_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [kubernetes_azure](https://github.com/splunk/security_content/blob/develop/macros/kubernetes_azure.yml) - -> :information_source: -> **kubernetes_azure_detect_sensitive_object_access_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -You must install the Add-on for Microsoft Cloud Services and Configure Kube-Audit data diagnostics - -#### Known False Positives -Sensitive object access is not necessarily malicious but user and object context can provide guidance for detection. - -#### Associated Analytic story -* [Kubernetes Sensitive Object Access Activity](/stories/kubernetes_sensitive_object_access_activity) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/kubernetes_azure_detect_sensitive_object_access.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-05-20-kubernetes_azure_detect_sensitive_role_access.md b/docs/_posts/2020-05-20-kubernetes_azure_detect_sensitive_role_access.md deleted file mode 100644 index 999685f9e7..0000000000 --- a/docs/_posts/2020-05-20-kubernetes_azure_detect_sensitive_role_access.md +++ /dev/null @@ -1,136 +0,0 @@ ---- -title: "Kubernetes Azure detect sensitive role access" -excerpt: "" -categories: - - Deprecated -last_modified_at: 2020-05-20 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search provides information on Kubernetes accounts accessing sensitve objects such as configmpas or secrets - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-05-20 -- **Author**: Rod Soto, Splunk -- **ID**: f27349e5-1641-4f6a-9e68-30402be0ad4c - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`kubernetes_azure` category=kube-audit -| spath input=properties.log -| search objectRef.resource=clusterroles OR clusterrolebindings -| table sourceIPs{} user.username user.groups{} objectRef.namespace requestURI annotations.authorization.k8s.io/reason -| dedup user.username user.groups{} -|`kubernetes_azure_detect_sensitive_role_access_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [kubernetes_azure](https://github.com/splunk/security_content/blob/develop/macros/kubernetes_azure.yml) - -> :information_source: -> **kubernetes_azure_detect_sensitive_role_access_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -You must install the Add-on for Microsoft Cloud Services and Configure Kube-Audit data diagnostics - -#### Known False Positives -Sensitive role resource access is necessary for cluster operation, however source IP, namespace and user group may indicate possible malicious use. - -#### Associated Analytic story -* [Kubernetes Sensitive Role Activity](/stories/kubernetes_sensitive_role_activity) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/kubernetes_azure_detect_sensitive_role_access.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-05-20-kubernetes_azure_detect_service_accounts_forbidden_failure_access.md b/docs/_posts/2020-05-20-kubernetes_azure_detect_service_accounts_forbidden_failure_access.md deleted file mode 100644 index 57ba835865..0000000000 --- a/docs/_posts/2020-05-20-kubernetes_azure_detect_service_accounts_forbidden_failure_access.md +++ /dev/null @@ -1,135 +0,0 @@ ---- -title: "Kubernetes Azure detect service accounts forbidden failure access" -excerpt: "" -categories: - - Deprecated -last_modified_at: 2020-05-20 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search provides information on Kubernetes service accounts with failure or forbidden access status - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-05-20 -- **Author**: Rod Soto, Splunk -- **ID**: 019690d7-420f-4da0-b320-f27b09961514 - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`kubernetes_azure` category=kube-audit -| spath input=properties.log -| search user.groups{}=system:serviceaccounts* responseStatus.reason=Forbidden -| table sourceIPs{} user.username userAgent verb responseStatus.reason responseStatus.status properties.pod objectRef.namespace -|`kubernetes_azure_detect_service_accounts_forbidden_failure_access_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [kubernetes_azure](https://github.com/splunk/security_content/blob/develop/macros/kubernetes_azure.yml) - -> :information_source: -> **kubernetes_azure_detect_service_accounts_forbidden_failure_access_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -You must install the Add-on for Microsoft Cloud Services and Configure Kube-Audit data diagnostics - -#### Known False Positives -This search can give false positives as there might be inherent issues with authentications and permissions at cluster. - -#### Associated Analytic story -* [Kubernetes Sensitive Object Access Activity](/stories/kubernetes_sensitive_object_access_activity) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-05-20-kubernetes_azure_pod_scan_fingerprint.md b/docs/_posts/2020-05-20-kubernetes_azure_pod_scan_fingerprint.md deleted file mode 100644 index ff0236cf16..0000000000 --- a/docs/_posts/2020-05-20-kubernetes_azure_pod_scan_fingerprint.md +++ /dev/null @@ -1,135 +0,0 @@ ---- -title: "Kubernetes Azure pod scan fingerprint" -excerpt: "" -categories: - - Deprecated -last_modified_at: 2020-05-20 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search provides information of unauthenticated requests via source IP user agent, request URI and response status data against Kubernetes cluster pod in Azure - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-05-20 -- **Author**: Rod Soto, Splunk -- **ID**: 86aad3e0-732f-4f66-bbbc-70df448e461d - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`kubernetes_azure` category=kube-audit -| spath input=properties.log -| search responseStatus.code=401 -| table sourceIPs{} userAgent verb requestURI responseStatus.reason properties.pod -|`kubernetes_azure_pod_scan_fingerprint_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [kubernetes_azure](https://github.com/splunk/security_content/blob/develop/macros/kubernetes_azure.yml) - -> :information_source: -> **kubernetes_azure_pod_scan_fingerprint_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -You must install the Add-on for Microsoft Cloud Services and Configure Kube-Audit data diagnostics - -#### Known False Positives -Not all unauthenticated requests are malicious, but source IPs, userAgent, verb, request URI and response status will provide context. - -#### Associated Analytic story -* [Kubernetes Scanning Activity](/stories/kubernetes_scanning_activity) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/kubernetes_azure_pod_scan_fingerprint.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-05-26-kubernetes_azure_active_service_accounts_by_pod_namespace.md b/docs/_posts/2020-05-26-kubernetes_azure_active_service_accounts_by_pod_namespace.md deleted file mode 100644 index 8822a44cf5..0000000000 --- a/docs/_posts/2020-05-26-kubernetes_azure_active_service_accounts_by_pod_namespace.md +++ /dev/null @@ -1,136 +0,0 @@ ---- -title: "Kubernetes Azure active service accounts by pod namespace" -excerpt: "" -categories: - - Deprecated -last_modified_at: 2020-05-26 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search provides information on Kubernetes service accounts,accessing pods and namespaces by IP address and verb - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-05-26 -- **Author**: Rod Soto, Splunk -- **ID**: 55a2264a-b7f0-45e5-addd-1e5ab3415c72 - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`kubernetes_azure` category=kube-audit -| spath input=properties.log -| search user.groups{}=system:serviceaccounts* OR user.username=system.anonymous OR annotations.authorization.k8s.io/decision=allow -| table sourceIPs{} user.username userAgent verb responseStatus.reason responseStatus.status properties.pod objectRef.namespace -| top sourceIPs{} user.username verb responseStatus.status properties.pod objectRef.namespace -|`kubernetes_azure_active_service_accounts_by_pod_namespace_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [kubernetes_azure](https://github.com/splunk/security_content/blob/develop/macros/kubernetes_azure.yml) - -> :information_source: -> **kubernetes_azure_active_service_accounts_by_pod_namespace_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -You must install the Add-on for Microsoft Cloud Services and Configure Kube-Audit data diagnostics - -#### Known False Positives -Not all service accounts interactions are malicious. Analyst must consider IP and verb context when trying to detect maliciousness. - -#### Associated Analytic story -* [Kubernetes Sensitive Role Activity](/stories/kubernetes_sensitive_role_activity) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/kubernetes_azure_active_service_accounts_by_pod_namespace.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-05-26-kubernetes_azure_detect_most_active_service_accounts_by_pod_namespace.md b/docs/_posts/2020-05-26-kubernetes_azure_detect_most_active_service_accounts_by_pod_namespace.md deleted file mode 100644 index 6ebab02f21..0000000000 --- a/docs/_posts/2020-05-26-kubernetes_azure_detect_most_active_service_accounts_by_pod_namespace.md +++ /dev/null @@ -1,84 +0,0 @@ ---- -title: "Kubernetes Azure detect most active service accounts by pod namespace" -excerpt: "" -categories: - - Deprecated -last_modified_at: 2020-05-26 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This search provides information on Kubernetes service accounts,accessing pods and namespaces by IP address and verb - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/object-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: -- **Last Updated**: 2020-05-26 -- **Author**: Rod Soto, Splunk -- **ID**: 55a2264a-b7f0-45e5-addd-1e5ab3415c72 - -#### Search - -``` -`kubernetes_azure` category=kube-audit -| spath input=properties.log -| search user.groups{}=system:serviceaccounts* OR user.username=system.anonymous OR annotations.authorization.k8s.io/decision=allow -| table sourceIPs{} user.username userAgent verb responseStatus.reason responseStatus.status properties.pod objectRef.namespace -| top sourceIPs{} user.username verb responseStatus.status properties.pod objectRef.namespace -|`kubernetes_azure_detect_most_active_service_accounts_by_pod_namespace_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [kubernetes_azure](https://github.com/splunk/security_content/blob/develop/macros/kubernetes_azure.yml) - -Note that `kubernetes_azure_detect_most_active_service_accounts_by_pod_namespace_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -You must install the Add-on for Microsoft Cloud Services and Configure Kube-Audit data diagnostics - -#### Known False Positives -Not all service accounts interactions are malicious. Analyst must consider IP and verb context when trying to detect maliciousness. - -#### Associated Analytic story -* [Kubernetes Sensitive Role Activity](/stories/kubernetes_sensitive_role_activity) - - -#### Kill Chain Phase -* Exploitation - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - - - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/kubernetes_azure_detect_most_active_service_accounts_by_pod_namespace.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-05-26-kubernetes_azure_detect_rbac_authorization_by_account.md b/docs/_posts/2020-05-26-kubernetes_azure_detect_rbac_authorization_by_account.md deleted file mode 100644 index 76c3469a2e..0000000000 --- a/docs/_posts/2020-05-26-kubernetes_azure_detect_rbac_authorization_by_account.md +++ /dev/null @@ -1,137 +0,0 @@ ---- -title: "Kubernetes Azure detect RBAC authorization by account" -excerpt: "" -categories: - - Deprecated -last_modified_at: 2020-05-26 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search provides information on Kubernetes RBAC authorizations by accounts, this search can be modified by adding rare or top to see both extremes of RBAC by accounts occurrences - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-05-26 -- **Author**: Rod Soto, Splunk -- **ID**: 47af7d20-0607-4079-97d7-7a29af58b54e - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`kubernetes_azure` category=kube-audit -| spath input=properties.log -| search annotations.authorization.k8s.io/reason=* -| table sourceIPs{} user.username userAgent annotations.authorization.k8s.io/reason -|stats count by user.username annotations.authorization.k8s.io/reason -| rare user.username annotations.authorization.k8s.io/reason -|`kubernetes_azure_detect_rbac_authorization_by_account_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [kubernetes_azure](https://github.com/splunk/security_content/blob/develop/macros/kubernetes_azure.yml) - -> :information_source: -> **kubernetes_azure_detect_rbac_authorization_by_account_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -You must install the Add-on for Microsoft Cloud Services and Configure Kube-Audit data diagnostics - -#### Known False Positives -Not all RBAC Authorications are malicious. RBAC authorizations can uncover malicious activity specially if sensitive Roles have been granted. - -#### Associated Analytic story -* [Kubernetes Sensitive Role Activity](/stories/kubernetes_sensitive_role_activity) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/kubernetes_azure_detect_rbac_authorization_by_account.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-05-26-kubernetes_azure_detect_suspicious_kubectl_calls.md b/docs/_posts/2020-05-26-kubernetes_azure_detect_suspicious_kubectl_calls.md deleted file mode 100644 index bf7375293b..0000000000 --- a/docs/_posts/2020-05-26-kubernetes_azure_detect_suspicious_kubectl_calls.md +++ /dev/null @@ -1,137 +0,0 @@ ---- -title: "Kubernetes Azure detect suspicious kubectl calls" -excerpt: "" -categories: - - Deprecated -last_modified_at: 2020-05-26 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search provides information on rare Kubectl calls with IP, verb namespace and object access context - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-05-26 -- **Author**: Rod Soto, Splunk -- **ID**: 4b6d1ba8-0000-4cec-87e6-6cbbd71651b5 - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`kubernetes_azure` category=kube-audit -| spath input=properties.log -| spath input=responseObject.metadata.annotations.kubectl.kubernetes.io/last-applied-configuration -| search userAgent=kubectl* sourceIPs{}!=127.0.0.1 sourceIPs{}!=::1 -| table sourceIPs{} verb userAgent user.groups{} objectRef.resource objectRef.namespace requestURI -| rare sourceIPs{} verb userAgent user.groups{} objectRef.resource objectRef.namespace requestURI -|`kubernetes_azure_detect_suspicious_kubectl_calls_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [kubernetes_azure](https://github.com/splunk/security_content/blob/develop/macros/kubernetes_azure.yml) - -> :information_source: -> **kubernetes_azure_detect_suspicious_kubectl_calls_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -You must install the Add-on for Microsoft Cloud Services and Configure Kube-Audit data diagnostics - -#### Known False Positives -Kubectl calls are not malicious by nature. However source IP, verb and Object can reveal potential malicious activity, specially suspicious IPs and sensitive objects such as configmaps or secrets - -#### Associated Analytic story -* [Kubernetes Sensitive Object Access Activity](/stories/kubernetes_sensitive_object_access_activity) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/kubernetes_azure_detect_suspicious_kubectl_calls.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-05-28-aws_cross_account_activity_from_previously_unseen_account.md b/docs/_posts/2020-05-28-aws_cross_account_activity_from_previously_unseen_account.md deleted file mode 100644 index 32c6d8bbf7..0000000000 --- a/docs/_posts/2020-05-28-aws_cross_account_activity_from_previously_unseen_account.md +++ /dev/null @@ -1,162 +0,0 @@ ---- -title: "AWS Cross Account Activity From Previously Unseen Account" -excerpt: "" -categories: - - Cloud -last_modified_at: 2020-05-28 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Authentication ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for AssumeRole events where an IAM role in a different account is requested for the first time. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Authentication](https://docs.splunk.com/Documentation/CIM/latest/User/Authentication) -- **Last Updated**: 2020-05-28 -- **Author**: Rico Valdez, Splunk -- **ID**: 21193641-cb96-4a2c-a707-d9b9a7f7792b - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.AC -* PR.DS -* DE.AE - - - -
-
- -
- CIS20 - -
- -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats min(_time) as firstTime max(_time) as lastTime from datamodel=Authentication where Authentication.signature=AssumeRole by Authentication.vendor_account Authentication.user Authentication.src Authentication.user_role -| `drop_dm_object_name(Authentication)` -| rex field=user_role "arn:aws:sts:*:(?.*):" -| where vendor_account != dest_account -| rename vendor_account as requestingAccountId dest_account as requestedAccountId -| lookup previously_seen_aws_cross_account_activity requestingAccountId, requestedAccountId, OUTPUTNEW firstTime -| eval status = if(firstTime > relative_time(now(), "-24h@h"),"New Cross Account Activity","Previously Seen") -| where status = "New Cross Account Activity" -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `aws_cross_account_activity_from_previously_unseen_account_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **aws_cross_account_activity_from_previously_unseen_account_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Lookups -The SPL above uses the following Lookups: - -* [previously_seen_aws_cross_account_activity](https://github.com/splunk/security_content/blob/develop/lookups/previously_seen_aws_cross_account_activity.yml) with [data](https://github.com/splunk/security_content/tree/develop/lookups/previously_seen_aws_cross_account_activity.csv) - -#### Required field -* _time -* Authentication.signature -* Authentication.vendor_account -* Authentication.user -* Authentication.user_role -* Authentication.src - - -#### How To Implement -You must be ingesting your cloud infrastructure logs from your cloud provider. You should run the baseline search `Previously Seen AWS Cross Account Activity - Initial` to build the initial table of source IP address, geographic locations, and times. You must also enable the second baseline search `Previously Seen AWS Cross Account Activity - Update` to keep this table up to date and to age out old data. You can also provide additional filtering for this search by customizing the `aws_cross_account_activity_from_previously_unseen_account_filter` macro. - -#### Known False Positives -Using multiple AWS accounts and roles is perfectly valid behavior. It's suspicious when an account requests privileges of an account it hasn't before. You should validate with the account owner that this is a legitimate request. - -#### Associated Analytic story -* [Suspicious Cloud Authentication Activities](/stories/suspicious_cloud_authentication_activities) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | AWS account $requestingAccountId$ is trying to access resource from some other account $requestedAccountId$, for the first time. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/aws_cross_account_activity_from_previously_unseen_account.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-05-28-detect_aws_console_login_by_new_user.md b/docs/_posts/2020-05-28-detect_aws_console_login_by_new_user.md deleted file mode 100644 index 30b0dc8279..0000000000 --- a/docs/_posts/2020-05-28-detect_aws_console_login_by_new_user.md +++ /dev/null @@ -1,152 +0,0 @@ ---- -title: "Detect AWS Console Login by New User" -excerpt: "" -categories: - - Cloud -last_modified_at: 2020-05-28 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Authentication ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for AWS CloudTrail events wherein a console login event by a user was recorded within the last hour, then compares the event to a lookup file of previously seen users (by ARN values) who have logged into the console. The alert is fired if the user has logged into the console for the first time within the last hour - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Authentication](https://docs.splunk.com/Documentation/CIM/latest/User/Authentication) -- **Last Updated**: 2020-05-28 -- **Author**: Rico Valdez, Splunk -- **ID**: bc91a8cd-35e7-4bb2-6140-e756cc46fd71 - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.DP -* DE.AE - - - -
-
- -
- CIS20 - -
- -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats earliest(_time) as firstTime latest(_time) as lastTime from datamodel=Authentication where Authentication.signature=ConsoleLogin by Authentication.user -| `drop_dm_object_name(Authentication)` -| join user type=outer [ inputlookup previously_seen_users_console_logins -| stats min(firstTime) as earliestseen by user] -| eval userStatus=if(earliestseen >= relative_time(now(), "-24h@h") OR isnull(earliestseen), "First Time Logging into AWS Console", "Previously Seen User") -| where userStatus="First Time Logging into AWS Console" -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_aws_console_login_by_new_user_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -Note that **detect_aws_console_login_by_new_user_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Lookups -The SPL above uses the following Lookups: - -* [previously_seen_users_console_logins](https://github.com/splunk/security_content/blob/develop/lookups/previously_seen_users_console_logins.yml) with [data](https://github.com/splunk/security_content/tree/develop/lookups/previously_seen_users_console_logins.csv) - -#### Required field -* _time -* Authentication.signature -* Authentication.user - - -#### How To Implement -You must install and configure the Splunk Add-on for AWS (version 5.1.0 or later) and Enterprise Security 6.2, which contains the required updates to the Authentication data model for cloud use cases. Run the `Previously Seen Users in AWS CloudTrail - Initial` support search only once to create a baseline of previously seen IAM users within the last 30 days. Run `Previously Seen Users in AWS CloudTrail - Update` hourly (or more frequently depending on how often you run the detection searches) to refresh the baselines. - -#### Known False Positives -When a legitimate new user logins for the first time, this activity will be detected. Check how old the account is and verify that the user activity is legitimate. - -#### Associated Analytic story -* [Suspicious Cloud Authentication Activities](/stories/suspicious_cloud_authentication_activities) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 30.0 | 50 | 60 | User $user$ is logging into the AWS console for the first time | - - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/detect_aws_console_login_by_new_user.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-06-23-aws_eks_kubernetes_cluster_sensitive_object_access.md b/docs/_posts/2020-06-23-aws_eks_kubernetes_cluster_sensitive_object_access.md deleted file mode 100644 index 857a1af639..0000000000 --- a/docs/_posts/2020-06-23-aws_eks_kubernetes_cluster_sensitive_object_access.md +++ /dev/null @@ -1,134 +0,0 @@ ---- -title: "AWS EKS Kubernetes cluster sensitive object access" -excerpt: "" -categories: - - Deprecated -last_modified_at: 2020-06-23 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search provides information on Kubernetes accounts accessing sensitve objects such as configmaps or secrets - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-06-23 -- **Author**: Rod Soto, Splunk -- **ID**: 7f227943-2196-4d4d-8d6a-ac8cb308e61c - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`aws_cloudwatchlogs_eks` objectRef.resource=secrets OR configmaps sourceIPs{}!=::1 sourceIPs{}!=127.0.0.1 -|table sourceIPs{} user.username user.groups{} objectRef.resource objectRef.namespace objectRef.name annotations.authorization.k8s.io/reason -|dedup user.username user.groups{} -|`aws_eks_kubernetes_cluster_sensitive_object_access_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [aws_cloudwatchlogs_eks](https://github.com/splunk/security_content/blob/develop/macros/aws_cloudwatchlogs_eks.yml) - -> :information_source: -> **aws_eks_kubernetes_cluster_sensitive_object_access_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -You must install Splunk Add-on for Amazon Web Services and Splunk App for AWS. This search works with cloudwatch logs. - -#### Known False Positives -Sensitive object access is not necessarily malicious but user and object context can provide guidance for detection. - -#### Associated Analytic story -* [Kubernetes Sensitive Object Access Activity](/stories/kubernetes_sensitive_object_access_activity) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/aws_eks_kubernetes_cluster_sensitive_object_access.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-06-23-kubernetes_aws_detect_most_active_service_accounts_by_pod.md b/docs/_posts/2020-06-23-kubernetes_aws_detect_most_active_service_accounts_by_pod.md deleted file mode 100644 index 17d6b651cd..0000000000 --- a/docs/_posts/2020-06-23-kubernetes_aws_detect_most_active_service_accounts_by_pod.md +++ /dev/null @@ -1,134 +0,0 @@ ---- -title: "Kubernetes AWS detect most active service accounts by pod" -excerpt: "" -categories: - - Deprecated -last_modified_at: 2020-06-23 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search provides information on Kubernetes service accounts,accessing pods by IP address, verb and decision - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-06-23 -- **Author**: Rod Soto, Splunk -- **ID**: 5b30b25d-7d32-42d8-95ca-64dfcd9076e6 - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`aws_cloudwatchlogs_eks` user.groups{}=system:serviceaccounts objectRef.resource=pods -| table sourceIPs{} user.username userAgent verb annotations.authorization.k8s.io/decision -| top sourceIPs{} user.username verb annotations.authorization.k8s.io/decision -|`kubernetes_aws_detect_most_active_service_accounts_by_pod_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [aws_cloudwatchlogs_eks](https://github.com/splunk/security_content/blob/develop/macros/aws_cloudwatchlogs_eks.yml) - -> :information_source: -> **kubernetes_aws_detect_most_active_service_accounts_by_pod_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -You must install splunk AWS add on and Splunk App for AWS. This search works with cloudwatch logs - -#### Known False Positives -Not all service accounts interactions are malicious. Analyst must consider IP, verb and decision context when trying to detect maliciousness. - -#### Associated Analytic story -* [Kubernetes Sensitive Role Activity](/stories/kubernetes_sensitive_role_activity) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-06-23-kubernetes_aws_detect_rbac_authorization_by_account.md b/docs/_posts/2020-06-23-kubernetes_aws_detect_rbac_authorization_by_account.md deleted file mode 100644 index 527c1cbb72..0000000000 --- a/docs/_posts/2020-06-23-kubernetes_aws_detect_rbac_authorization_by_account.md +++ /dev/null @@ -1,135 +0,0 @@ ---- -title: "Kubernetes AWS detect RBAC authorization by account" -excerpt: "" -categories: - - Deprecated -last_modified_at: 2020-06-23 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search provides information on Kubernetes RBAC authorizations by accounts, this search can be modified by adding top to see both extremes of RBAC by accounts occurrences - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-06-23 -- **Author**: Rod Soto, Splunk -- **ID**: de7264ed-3ed9-4fef-bb01-6eefc87cefe8 - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`aws_cloudwatchlogs_eks` annotations.authorization.k8s.io/reason=* -| table sourceIPs{} user.username userAgent annotations.authorization.k8s.io/reason -| stats count by user.username annotations.authorization.k8s.io/reason -| rare user.username annotations.authorization.k8s.io/reason -|`kubernetes_aws_detect_rbac_authorization_by_account_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [aws_cloudwatchlogs_eks](https://github.com/splunk/security_content/blob/develop/macros/aws_cloudwatchlogs_eks.yml) - -> :information_source: -> **kubernetes_aws_detect_rbac_authorization_by_account_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -You must install splunk AWS add on and Splunk App for AWS. This search works with cloudwatch logs - -#### Known False Positives -Not all RBAC Authorications are malicious. RBAC authorizations can uncover malicious activity specially if sensitive Roles have been granted. - -#### Associated Analytic story -* [Kubernetes Sensitive Role Activity](/stories/kubernetes_sensitive_role_activity) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/kubernetes_aws_detect_rbac_authorization_by_account.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-06-23-kubernetes_aws_detect_sensitive_role_access.md b/docs/_posts/2020-06-23-kubernetes_aws_detect_sensitive_role_access.md deleted file mode 100644 index 5fbb443ddb..0000000000 --- a/docs/_posts/2020-06-23-kubernetes_aws_detect_sensitive_role_access.md +++ /dev/null @@ -1,134 +0,0 @@ ---- -title: "Kubernetes AWS detect sensitive role access" -excerpt: "" -categories: - - Deprecated -last_modified_at: 2020-06-23 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search provides information on Kubernetes accounts accessing sensitve objects such as configmpas or secrets - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-06-23 -- **Author**: Rod Soto, Splunk -- **ID**: b6013a7b-85e0-4a45-b051-10b252d69569 - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`aws_cloudwatchlogs_eks` objectRef.resource=clusterroles OR clusterrolebindings sourceIPs{}!=::1 sourceIPs{}!=127.0.0.1 -| table sourceIPs{} user.username user.groups{} objectRef.namespace requestURI annotations.authorization.k8s.io/reason -| dedup user.username user.groups{} -|`kubernetes_aws_detect_sensitive_role_access_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [aws_cloudwatchlogs_eks](https://github.com/splunk/security_content/blob/develop/macros/aws_cloudwatchlogs_eks.yml) - -> :information_source: -> **kubernetes_aws_detect_sensitive_role_access_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -You must install splunk AWS add on and Splunk App for AWS. This search works with cloudwatch logs. - -#### Known False Positives -Sensitive role resource access is necessary for cluster operation, however source IP, namespace and user group may indicate possible malicious use. - -#### Associated Analytic story -* [Kubernetes Sensitive Role Activity](/stories/kubernetes_sensitive_role_activity) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/kubernetes_aws_detect_sensitive_role_access.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-06-23-kubernetes_aws_detect_service_accounts_forbidden_failure_access.md b/docs/_posts/2020-06-23-kubernetes_aws_detect_service_accounts_forbidden_failure_access.md deleted file mode 100644 index 5f9aabff04..0000000000 --- a/docs/_posts/2020-06-23-kubernetes_aws_detect_service_accounts_forbidden_failure_access.md +++ /dev/null @@ -1,133 +0,0 @@ ---- -title: "Kubernetes AWS detect service accounts forbidden failure access" -excerpt: "" -categories: - - Deprecated -last_modified_at: 2020-06-23 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search provides information on Kubernetes service accounts with failure or forbidden access status, this search can be extended by using top or rare operators to find trends or rarities in failure status, user agents, source IPs and request URI - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-06-23 -- **Author**: Rod Soto, Splunk -- **ID**: a6959c57-fa8f-4277-bb86-7c32fba579d5 - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`aws_cloudwatchlogs_eks` user.groups{}=system:serviceaccounts responseStatus.status = Failure -| table sourceIPs{} user.username userAgent verb responseStatus.status requestURI -| `kubernetes_aws_detect_service_accounts_forbidden_failure_access_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [aws_cloudwatchlogs_eks](https://github.com/splunk/security_content/blob/develop/macros/aws_cloudwatchlogs_eks.yml) - -> :information_source: -> **kubernetes_aws_detect_service_accounts_forbidden_failure_access_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -You must install splunk AWS add on and Splunk App for AWS. This search works with cloudwatch logs. - -#### Known False Positives -This search can give false positives as there might be inherent issues with authentications and permissions at cluster. - -#### Associated Analytic story -* [Kubernetes Sensitive Object Access Activity](/stories/kubernetes_sensitive_object_access_activity) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-06-23-kubernetes_aws_detect_suspicious_kubectl_calls.md b/docs/_posts/2020-06-23-kubernetes_aws_detect_suspicious_kubectl_calls.md deleted file mode 100644 index cccf5193a7..0000000000 --- a/docs/_posts/2020-06-23-kubernetes_aws_detect_suspicious_kubectl_calls.md +++ /dev/null @@ -1,142 +0,0 @@ ---- -title: "Kubernetes AWS detect suspicious kubectl calls" -excerpt: "" -categories: - - Cloud -last_modified_at: 2020-06-23 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search provides information on anonymous Kubectl calls with IP, verb namespace and object access context - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-06-23 -- **Author**: Rod Soto, Splunk -- **ID**: 042a3d32-8318-4763-9679-09db2644a8f2 - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`aws_cloudwatchlogs_eks` userAgent=kubectl* sourceIPs{}!=127.0.0.1 sourceIPs{}!=::1 src_user=system:anonymous -| table src_ip src_user verb userAgent requestURI -| stats count by src_ip src_user verb userAgent requestURI -|`kubernetes_aws_detect_suspicious_kubectl_calls_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [aws_cloudwatchlogs_eks](https://github.com/splunk/security_content/blob/develop/macros/aws_cloudwatchlogs_eks.yml) - -> :information_source: -> **kubernetes_aws_detect_suspicious_kubectl_calls_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* userAgent -* sourceIPs{} -* src_user -* src_ip -* verb -* requestURI - - -#### How To Implement -You must install splunk AWS add on and Splunk App for AWS. This search works with cloudwatch logs. - -#### Known False Positives -Kubectl calls are not malicious by nature. However source IP, verb and Object can reveal potential malicious activity, specially anonymous suspicious IPs and sensitive objects such as configmaps or secrets - -#### Associated Analytic story -* [Kubernetes Sensitive Object Access Activity](/stories/kubernetes_sensitive_object_access_activity) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/cloud/kubernetes_aws_detect_suspicious_kubectl_calls.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-06-23-kubernetes_gcp_detect_service_accounts_forbidden_failure_access.md b/docs/_posts/2020-06-23-kubernetes_gcp_detect_service_accounts_forbidden_failure_access.md deleted file mode 100644 index dcefd7f403..0000000000 --- a/docs/_posts/2020-06-23-kubernetes_gcp_detect_service_accounts_forbidden_failure_access.md +++ /dev/null @@ -1,134 +0,0 @@ ---- -title: "Kubernetes GCP detect service accounts forbidden failure access" -excerpt: "" -categories: - - Deprecated -last_modified_at: 2020-06-23 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search provides information on Kubernetes service accounts with failure or forbidden access status, this search can be extended by using top or rare operators to find trends or rarities in failure status, user agents, source IPs and request URI - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-06-23 -- **Author**: Rod Soto, Splunk -- **ID**: 7094808d-432a-48e7-bb3c-77e96c894f3b - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`google_gcp_pubsub_message` system:serviceaccounts data.protoPayload.response.status.allowed!=* -| table src_ip src_user http_user_agent data.protoPayload.response.spec.resourceAttributes.namespace data.resource.labels.cluster_name data.protoPayload.response.spec.resourceAttributes.verb data.protoPayload.request.status.allowed data.protoPayload.response.status.reason data.labels.authorization.k8s.io/decision -| dedup src_ip src_user -| `kubernetes_gcp_detect_service_accounts_forbidden_failure_access_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [google_gcp_pubsub_message](https://github.com/splunk/security_content/blob/develop/macros/google_gcp_pubsub_message.yml) - -> :information_source: -> **kubernetes_gcp_detect_service_accounts_forbidden_failure_access_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -You must install splunk add on for GCP. This search works with pubsub messaging service logs. - -#### Known False Positives -This search can give false positives as there might be inherent issues with authentications and permissions at cluster. - -#### Associated Analytic story -* [Kubernetes Sensitive Object Access Activity](/stories/kubernetes_sensitive_object_access_activity) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-07-03-detect_path_interception_by_creation_of_program_exe.md b/docs/_posts/2020-07-03-detect_path_interception_by_creation_of_program_exe.md deleted file mode 100644 index e170e0f832..0000000000 --- a/docs/_posts/2020-07-03-detect_path_interception_by_creation_of_program_exe.md +++ /dev/null @@ -1,184 +0,0 @@ ---- -title: "Detect Path Interception By Creation Of program exe" -excerpt: "Path Interception by Unquoted Path -, Hijack Execution Flow -" -categories: - - Endpoint -last_modified_at: 2020-07-03 -toc: true -toc_label: "" -tags: - - Path Interception by Unquoted Path - - Hijack Execution Flow - - Defense Evasion - - Persistence - - Privilege Escalation - - Defense Evasion - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The detection Detect Path Interception By Creation Of program exe is detecting the abuse of unquoted service paths, which is a popular technique for privilege escalation. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2020-07-03 -- **Author**: Patrick Bareiss, Splunk -- **ID**: cbef820c-e1ff-407f-887f-0a9240a2d477 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1574.009](https://attack.mitre.org/techniques/T1574/009/) | Path Interception by Unquoted Path | Defense Evasion, Persistence, Privilege Escalation | - -| [T1574](https://attack.mitre.org/techniques/T1574/) | Hijack Execution Flow | Defense Evasion, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=services.exe by Processes.user Processes.process_name Processes.process Processes.dest -| `drop_dm_object_name(Processes)` -| rex field=process "^.*?\\\\(?[^\\\\]*\.(?:exe -|bat -|com -|ps1))" -| eval process_name = lower(process_name) -| eval service_process = lower(service_process) -| where process_name != service_process -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_path_interception_by_creation_of_program_exe_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **detect_path_interception_by_creation_of_program_exe_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Windows Persistence Techniques](/stories/windows_persistence_techniques) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to perform privilege escalation by using unquoted service paths. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://medium.com/@SumitVerma101/windows-privilege-escalation-part-1-unquoted-service-path-c7a011a8d8ae](https://medium.com/@SumitVerma101/windows-privilege-escalation-part-1-unquoted-service-path-c7a011a8d8ae) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1574.009/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1574.009/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/detect_path_interception_by_creation_of_program_exe.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2020-07-06-short_lived_windows_accounts.md b/docs/_posts/2020-07-06-short_lived_windows_accounts.md deleted file mode 100644 index 3412fb9342..0000000000 --- a/docs/_posts/2020-07-06-short_lived_windows_accounts.md +++ /dev/null @@ -1,166 +0,0 @@ ---- -title: "Short Lived Windows Accounts" -excerpt: "Local Account -, Create Account -" -categories: - - Endpoint -last_modified_at: 2020-07-06 -toc: true -toc_label: "" -tags: - - Local Account - - Create Account - - Persistence - - Persistence - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Change ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search detects accounts that were created and deleted in a short time period. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Change](https://docs.splunk.com/Documentation/CIM/latest/User/Change) -- **Last Updated**: 2020-07-06 -- **Author**: David Dorsey, Splunk -- **ID**: b25f6f62-0782-43c1-b403-083231ffd97d - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1136.001](https://attack.mitre.org/techniques/T1136/001/) | Local Account | Persistence | - -| [T1136](https://attack.mitre.org/techniques/T1136/) | Create Account | Persistence | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* PR.IP - - - -
-
- -
- CIS20 - -
- -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` values(All_Changes.result_id) as result_id count min(_time) as firstTime max(_time) as lastTime from datamodel=Change where All_Changes.result_id=4720 OR All_Changes.result_id=4726 by _time span=4h All_Changes.user All_Changes.dest -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `drop_dm_object_name("All_Changes")` -| search result_id = 4720 result_id=4726 -| transaction user connected=false maxspan=240m -| table firstTime lastTime count user dest result_id -| `short_lived_windows_accounts_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **short_lived_windows_accounts_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* All_Changes.result_id -* All_Changes.user -* All_Changes.dest - - -#### How To Implement -This search requires you to have enabled your Group Management Audit Logs in your Local Windows Security Policy and be ingesting those logs. More information on how to enable them can be found here: http://whatevernetworks.com/auditing-group-membership-changes-in-active-directory/ - -#### Known False Positives -It is possible that an administrator created and deleted an account in a short time period. Verifying activity with an administrator is advised. - -#### Associated Analytic story -* [Account Monitoring and Controls](/stories/account_monitoring_and_controls) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 63.0 | 70 | 90 | A user account created or delete shortly in host $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.001/atomic_red_team/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.001/atomic_red_team/windows-security.log) -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.001/atomic_red_team/windows-system.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.001/atomic_red_team/windows-system.log) -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.001/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.001/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/short_lived_windows_accounts.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2020-07-06-windows_event_log_cleared.md b/docs/_posts/2020-07-06-windows_event_log_cleared.md deleted file mode 100644 index e77d0c4535..0000000000 --- a/docs/_posts/2020-07-06-windows_event_log_cleared.md +++ /dev/null @@ -1,174 +0,0 @@ ---- -title: "Windows Event Log Cleared" -excerpt: "Indicator Removal on Host -, Clear Windows Event Logs -" -categories: - - Endpoint -last_modified_at: 2020-07-06 -toc: true -toc_label: "" -tags: - - Indicator Removal on Host - - Clear Windows Event Logs - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes Windows Security Event ID 1102 or System log event 104 to identify when a Windows event log is cleared. Note that this analytic will require tuning or restricted to specific endpoints based on criticality. During triage, based on time of day and user, determine if this was planned. If not planned, follow through with reviewing parallel alerts and other data sources to determine what else may have occurred. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-07-06 -- **Author**: Rico Valdez, Michael Haag, Splunk -- **ID**: ad517544-aff9-4c96-bd99-d6eb43bfbb6a - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1070](https://attack.mitre.org/techniques/T1070/) | Indicator Removal on Host | Defense Evasion | - -| [T1070.001](https://attack.mitre.org/techniques/T1070/001/) | Clear Windows Event Logs | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.DP -* PR.IP -* PR.AC -* PR.AT -* DE.AE - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 6 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -(`wineventlog_security` EventCode=1102) OR (`wineventlog_system` EventCode=104) -| stats count min(_time) as firstTime max(_time) as lastTime by dest Message EventCode -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_event_log_cleared_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [wineventlog_system](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_system.yml) - -> :information_source: -> **windows_event_log_cleared_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* dest - - -#### How To Implement -To successfully implement this search, you need to be ingesting Windows event logs from your hosts. In addition, the Splunk Windows TA is needed. - -#### Known False Positives -It is possible that these logs may be legitimately cleared by Administrators. Filter as needed. - -#### Associated Analytic story -* [Windows Log Manipulation](/stories/windows_log_manipulation) -* [Ransomware](/stories/ransomware) -* [Clop Ransomware](/stories/clop_ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 70.0 | 70 | 100 | Windows event logs cleared on $dest$ via EventCode $EventCode$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-1102](https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-1102) -* [https://www.ired.team/offensive-security/defense-evasion/disabling-windows-event-logs-by-suspending-eventlog-service-threads](https://www.ired.team/offensive-security/defense-evasion/disabling-windows-event-logs-by-suspending-eventlog-service-threads) -* [https://attack.mitre.org/techniques/T1070/001/](https://attack.mitre.org/techniques/T1070/001/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1070.001/T1070.001.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1070.001/T1070.001.md) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070.001/atomic_red_team/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070.001/atomic_red_team/windows-security.log) -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070.001/atomic_red_team/windows-system.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070.001/atomic_red_team/windows-system.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_event_log_cleared.yml) \| *version*: **6** \ No newline at end of file diff --git a/docs/_posts/2020-07-07-remote_desktop_network_traffic.md b/docs/_posts/2020-07-07-remote_desktop_network_traffic.md deleted file mode 100644 index 545796a26c..0000000000 --- a/docs/_posts/2020-07-07-remote_desktop_network_traffic.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: "Remote Desktop Network Traffic" -excerpt: "Remote Desktop Protocol -, Remote Services -" -categories: - - Network -last_modified_at: 2020-07-07 -toc: true -toc_label: "" -tags: - - Remote Desktop Protocol - - Remote Services - - Lateral Movement - - Lateral Movement - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Network_Traffic ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for network traffic on TCP/3389, the default port used by remote desktop. While remote desktop traffic is not uncommon on a network, it is usually associated with known hosts. This search will ignore common RDP sources and common RDP destinations so you can focus on the uncommon uses of remote desktop on your network. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Network_Traffic](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkTraffic) -- **Last Updated**: 2020-07-07 -- **Author**: David Dorsey, Splunk -- **ID**: 272b8407-842d-4b3d-bead-a704584003d3 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1021.001](https://attack.mitre.org/techniques/T1021/001/) | Remote Desktop Protocol | Lateral Movement | - -| [T1021](https://attack.mitre.org/techniques/T1021/) | Remote Services | Lateral Movement | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.AE -* PR.AC -* PR.IP - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 9 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Network_Traffic where All_Traffic.dest_port=3389 AND All_Traffic.dest_category!=common_rdp_destination AND All_Traffic.src_category!=common_rdp_source by All_Traffic.src All_Traffic.dest All_Traffic.dest_port -| `drop_dm_object_name("All_Traffic")` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `remote_desktop_network_traffic_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **remote_desktop_network_traffic_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* All_Traffic.dest_port -* All_Traffic.dest_category -* All_Traffic.src_category -* All_Traffic.src -* All_Traffic.dest -* All_Traffic.dest_port - - -#### How To Implement -To successfully implement this search you need to identify systems that commonly originate remote desktop traffic and that commonly receive remote desktop traffic. You can use the included support search "Identify Systems Creating Remote Desktop Traffic" to identify systems that originate the traffic and the search "Identify Systems Receiving Remote Desktop Traffic" to identify systems that receive a lot of remote desktop traffic. After identifying these systems, you will need to add the "common_rdp_source" or "common_rdp_destination" category to that system depending on the usage, using the Enterprise Security Assets and Identities framework. This can be done by adding an entry in the assets.csv file located in SA-IdentityManagement/lookups. - -#### Known False Positives -Remote Desktop may be used legitimately by users on the network. - -#### Associated Analytic story -* [SamSam Ransomware](/stories/samsam_ransomware) -* [Ryuk Ransomware](/stories/ryuk_ransomware) -* [Hidden Cobra Malware](/stories/hidden_cobra_malware) -* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/network/remote_desktop_network_traffic.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2020-07-08-detect_new_local_admin_account.md b/docs/_posts/2020-07-08-detect_new_local_admin_account.md deleted file mode 100644 index b14f43e277..0000000000 --- a/docs/_posts/2020-07-08-detect_new_local_admin_account.md +++ /dev/null @@ -1,168 +0,0 @@ ---- -title: "Detect New Local Admin account" -excerpt: "Local Account -, Create Account -" -categories: - - Endpoint -last_modified_at: 2020-07-08 -toc: true -toc_label: "" -tags: - - Local Account - - Create Account - - Persistence - - Persistence - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for newly created accounts that have been elevated to local administrators. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-07-08 -- **Author**: David Dorsey, Splunk -- **ID**: b25f6f62-0712-43c1-b203-083231ffd97d - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1136.001](https://attack.mitre.org/techniques/T1136/001/) | Local Account | Persistence | - -| [T1136](https://attack.mitre.org/techniques/T1136/) | Create Account | Persistence | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives -* Command & Control - - -
-
- - -
- NIST - -
- -* PR.AC -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`wineventlog_security` EventCode=4720 OR (EventCode=4732 Group_Name=Administrators) -| transaction member_id connected=false maxspan=180m -| rename member_id as user -| stats count min(_time) as firstTime max(_time) as lastTime by user dest -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_new_local_admin_account_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **detect_new_local_admin_account_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Group_Name -* member_id -* dest -* user - - -#### How To Implement -You must be ingesting Windows event logs using the Splunk Windows TA and collecting event code 4720 and 4732 - -#### Known False Positives -The activity may be legitimate. For this reason, it's best to verify the account with an administrator and ask whether there was a valid service request for the account creation. If your local administrator group name is not "Administrators", this search may generate an excessive number of false positives - -#### Associated Analytic story -* [DHS Report TA18-074A](/stories/dhs_report_ta18-074a) -* [HAFNIUM Group](/stories/hafnium_group) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 42.0 | 60 | 70 | A $user$ on $dest$ was added recently. Identify if this was legitimate behavior or not. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.001/atomic_red_team/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.001/atomic_red_team/windows-security.log) -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.001/atomic_red_team/windows-system.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.001/atomic_red_team/windows-system.log) -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.001/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.001/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/detect_new_local_admin_account.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2020-07-10-kubernetes_gcp_detect_most_active_service_accounts_by_pod.md b/docs/_posts/2020-07-10-kubernetes_gcp_detect_most_active_service_accounts_by_pod.md deleted file mode 100644 index feb73ec06a..0000000000 --- a/docs/_posts/2020-07-10-kubernetes_gcp_detect_most_active_service_accounts_by_pod.md +++ /dev/null @@ -1,134 +0,0 @@ ---- -title: "Kubernetes GCP detect most active service accounts by pod" -excerpt: "" -categories: - - Deprecated -last_modified_at: 2020-07-10 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search provides information on Kubernetes service accounts,accessing pods by IP address, verb and decision - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-07-10 -- **Author**: Rod Soto, Splunk -- **ID**: 7f5c2779-88a0-4824-9caa-0f606c8f260f - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`google_gcp_pubsub_message` data.protoPayload.request.spec.group{}=system:serviceaccounts -| table src_ip src_user http_user_agent data.protoPayload.request.spec.nonResourceAttributes.verb data.labels.authorization.k8s.io/decision data.protoPayload.response.spec.resourceAttributes.resource -| top src_ip src_user http_user_agent data.labels.authorization.k8s.io/decision data.protoPayload.response.spec.resourceAttributes.resource -|`kubernetes_gcp_detect_most_active_service_accounts_by_pod_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [google_gcp_pubsub_message](https://github.com/splunk/security_content/blob/develop/macros/google_gcp_pubsub_message.yml) - -> :information_source: -> **kubernetes_gcp_detect_most_active_service_accounts_by_pod_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -You must install splunk GCP add on. This search works with pubsub messaging service logs - -#### Known False Positives -Not all service accounts interactions are malicious. Analyst must consider IP, verb and decision context when trying to detect maliciousness. - -#### Associated Analytic story -* [Kubernetes Sensitive Role Activity](/stories/kubernetes_sensitive_role_activity) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-07-11-kubernetes_gcp_detect_rbac_authorizations_by_account.md b/docs/_posts/2020-07-11-kubernetes_gcp_detect_rbac_authorizations_by_account.md deleted file mode 100644 index 6be0597aa9..0000000000 --- a/docs/_posts/2020-07-11-kubernetes_gcp_detect_rbac_authorizations_by_account.md +++ /dev/null @@ -1,134 +0,0 @@ ---- -title: "Kubernetes GCP detect RBAC authorizations by account" -excerpt: "" -categories: - - Deprecated -last_modified_at: 2020-07-11 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search provides information on Kubernetes RBAC authorizations by accounts, this search can be modified by adding top to see both extremes of RBAC by accounts occurrences - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-07-11 -- **Author**: Rod Soto, Splunk -- **ID**: 99487de3-7192-4b41-939d-fbe9acfb1340 - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`google_gcp_pubsub_message` data.labels.authorization.k8s.io/reason=ClusterRoleBinding OR Clusterrole -| table src_ip src_user data.labels.authorization.k8s.io/decision data.labels.authorization.k8s.io/reason -| rare src_user data.labels.authorization.k8s.io/reason -|`kubernetes_gcp_detect_rbac_authorizations_by_account_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [google_gcp_pubsub_message](https://github.com/splunk/security_content/blob/develop/macros/google_gcp_pubsub_message.yml) - -> :information_source: -> **kubernetes_gcp_detect_rbac_authorizations_by_account_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -You must install splunk AWS add on for GCP. This search works with pubsub messaging service logs - -#### Known False Positives -Not all RBAC Authorications are malicious. RBAC authorizations can uncover malicious activity specially if sensitive Roles have been granted. - -#### Associated Analytic story -* [Kubernetes Sensitive Role Activity](/stories/kubernetes_sensitive_role_activity) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/kubernetes_gcp_detect_rbac_authorizations_by_account.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-07-11-kubernetes_gcp_detect_sensitive_object_access.md b/docs/_posts/2020-07-11-kubernetes_gcp_detect_sensitive_object_access.md deleted file mode 100644 index 0c7e245591..0000000000 --- a/docs/_posts/2020-07-11-kubernetes_gcp_detect_sensitive_object_access.md +++ /dev/null @@ -1,134 +0,0 @@ ---- -title: "Kubernetes GCP detect sensitive object access" -excerpt: "" -categories: - - Deprecated -last_modified_at: 2020-07-11 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search provides information on Kubernetes accounts accessing sensitve objects such as configmaps or secrets - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-07-11 -- **Author**: Rod Soto, Splunk -- **ID**: bdb6d596-86a0-4aba-8369-418ae8b9963a - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`google_gcp_pubsub_message` data.protoPayload.authorizationInfo{}.resource=configmaps OR secrets -| table data.protoPayload.requestMetadata.callerIp src_user data.resource.labels.cluster_name data.protoPayload.request.metadata.namespace data.labels.authorization.k8s.io/decision -| dedup data.protoPayload.requestMetadata.callerIp src_user data.resource.labels.cluster_name -|`kubernetes_gcp_detect_sensitive_object_access_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [google_gcp_pubsub_message](https://github.com/splunk/security_content/blob/develop/macros/google_gcp_pubsub_message.yml) - -> :information_source: -> **kubernetes_gcp_detect_sensitive_object_access_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -You must install splunk add on for GCP . This search works with pubsub messaging service logs. - -#### Known False Positives -Sensitive object access is not necessarily malicious but user and object context can provide guidance for detection. - -#### Associated Analytic story -* [Kubernetes Sensitive Object Access Activity](/stories/kubernetes_sensitive_object_access_activity) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/kubernetes_gcp_detect_sensitive_object_access.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-07-11-kubernetes_gcp_detect_sensitive_role_access.md b/docs/_posts/2020-07-11-kubernetes_gcp_detect_sensitive_role_access.md deleted file mode 100644 index d81d2ffbba..0000000000 --- a/docs/_posts/2020-07-11-kubernetes_gcp_detect_sensitive_role_access.md +++ /dev/null @@ -1,134 +0,0 @@ ---- -title: "Kubernetes GCP detect sensitive role access" -excerpt: "" -categories: - - Deprecated -last_modified_at: 2020-07-11 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search provides information on Kubernetes accounts accessing sensitve objects such as configmpas or secrets - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-07-11 -- **Author**: Rod Soto, Splunk -- **ID**: a46923f6-36b9-4806-a681-31f314907c30 - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`google_gcp_pubsub_message` data.labels.authorization.k8s.io/reason=ClusterRoleBinding OR Clusterrole dest=apis/rbac.authorization.k8s.io/v1 src_ip!=::1 -| table src_ip src_user http_user_agent data.labels.authorization.k8s.io/decision data.labels.authorization.k8s.io/reason -| dedup src_ip src_user -|`kubernetes_gcp_detect_sensitive_role_access_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [google_gcp_pubsub_message](https://github.com/splunk/security_content/blob/develop/macros/google_gcp_pubsub_message.yml) - -> :information_source: -> **kubernetes_gcp_detect_sensitive_role_access_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -You must install splunk add on for GCP. This search works with pubsub messaging servicelogs. - -#### Known False Positives -Sensitive role resource access is necessary for cluster operation, however source IP, user agent, decision and reason may indicate possible malicious use. - -#### Associated Analytic story -* [Kubernetes Sensitive Role Activity](/stories/kubernetes_sensitive_role_activity) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/kubernetes_gcp_detect_sensitive_role_access.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-07-11-kubernetes_gcp_detect_suspicious_kubectl_calls.md b/docs/_posts/2020-07-11-kubernetes_gcp_detect_suspicious_kubectl_calls.md deleted file mode 100644 index f908f11f35..0000000000 --- a/docs/_posts/2020-07-11-kubernetes_gcp_detect_suspicious_kubectl_calls.md +++ /dev/null @@ -1,134 +0,0 @@ ---- -title: "Kubernetes GCP detect suspicious kubectl calls" -excerpt: "" -categories: - - Deprecated -last_modified_at: 2020-07-11 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search provides information on anonymous Kubectl calls with IP, verb namespace and object access context - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-07-11 -- **Author**: Rod Soto, Splunk -- **ID**: a5bed417-070a-41f2-a1e4-82b6aa281557 - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`google_gcp_pubsub_message` data.protoPayload.requestMetadata.callerSuppliedUserAgent=kubectl* src_user=system:unsecured OR src_user=system:anonymous -| table src_ip src_user data.protoPayload.requestMetadata.callerSuppliedUserAgent data.protoPayload.authorizationInfo{}.granted object_path -|dedup src_ip src_user -|`kubernetes_gcp_detect_suspicious_kubectl_calls_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [google_gcp_pubsub_message](https://github.com/splunk/security_content/blob/develop/macros/google_gcp_pubsub_message.yml) - -> :information_source: -> **kubernetes_gcp_detect_suspicious_kubectl_calls_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -You must install splunk add on for GCP. This search works with pubsub messaging logs. - -#### Known False Positives -Kubectl calls are not malicious by nature. However source IP, source user, user agent, object path, and authorization context can reveal potential malicious activity, specially anonymous suspicious IPs and sensitive objects such as configmaps or secrets - -#### Associated Analytic story -* [Kubernetes Sensitive Object Access Activity](/stories/kubernetes_sensitive_object_access_activity) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/kubernetes_gcp_detect_suspicious_kubectl_calls.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-07-17-gcp_kubernetes_cluster_pod_scan_detection.md b/docs/_posts/2020-07-17-gcp_kubernetes_cluster_pod_scan_detection.md deleted file mode 100644 index a2cd8ed0ac..0000000000 --- a/docs/_posts/2020-07-17-gcp_kubernetes_cluster_pod_scan_detection.md +++ /dev/null @@ -1,153 +0,0 @@ ---- -title: "GCP Kubernetes cluster pod scan detection" -excerpt: "Cloud Service Discovery -" -categories: - - Cloud -last_modified_at: 2020-07-17 -toc: true -toc_label: "" -tags: - - Cloud Service Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search provides information of unauthenticated requests via user agent, and authentication data against Kubernetes cluster's pods - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-07-17 -- **Author**: Rod Soto, Splunk -- **ID**: 19b53215-4a16-405b-8087-9e6acf619842 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1526](https://attack.mitre.org/techniques/T1526/) | Cloud Service Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`google_gcp_pubsub_message` category=kube-audit -|spath input=properties.log -|search responseStatus.code=401 -|table sourceIPs{} userAgent verb requestURI responseStatus.reason properties.pod -| `gcp_kubernetes_cluster_pod_scan_detection_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [google_gcp_pubsub_message](https://github.com/splunk/security_content/blob/develop/macros/google_gcp_pubsub_message.yml) - -> :information_source: -> **gcp_kubernetes_cluster_pod_scan_detection_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* category -* responseStatus.code -* sourceIPs{} -* userAgent -* verb -* requestURI -* responseStatus.reason -* properties.pod - - -#### How To Implement -You must install the GCP App for Splunk (version 2.0.0 or later), then configure stackdriver and set a Pub/Sub subscription to be imported to Splunk. - -#### Known False Positives -Not all unauthenticated requests are malicious, but frequency, User Agent, source IPs and pods will provide context. - -#### Associated Analytic story -* [Kubernetes Scanning Activity](/stories/kubernetes_scanning_activity) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/cloud/gcp_kubernetes_cluster_pod_scan_detection.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-07-21-abnormally_high_aws_instances_launched_by_user.md b/docs/_posts/2020-07-21-abnormally_high_aws_instances_launched_by_user.md deleted file mode 100644 index 539d7a9e2e..0000000000 --- a/docs/_posts/2020-07-21-abnormally_high_aws_instances_launched_by_user.md +++ /dev/null @@ -1,160 +0,0 @@ ---- -title: "Abnormally High AWS Instances Launched by User" -excerpt: "Cloud Accounts -" -categories: - - Deprecated -last_modified_at: 2020-07-21 -toc: true -toc_label: "" -tags: - - Cloud Accounts - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for AWS CloudTrail events where a user successfully launches an abnormally high number of instances. This search is deprecated and have been translated to use the latest Change Datamodel - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-07-21 -- **Author**: Bhavin Patel, Splunk -- **ID**: 2a9b80d3-6340-4345-b5ad-290bf5d0dac4 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1078.004](https://attack.mitre.org/techniques/T1078/004/) | Cloud Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.DP -* DE.AE - - - -
-
- -
- CIS20 - -
- -* CIS 13 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cloudtrail` eventName=RunInstances errorCode=success -| bucket span=10m _time -| stats count AS instances_launched by _time userName -| eventstats avg(instances_launched) as total_launched_avg, stdev(instances_launched) as total_launched_stdev -| eval threshold_value = 4 -| eval isOutlier=if(instances_launched > total_launched_avg+(total_launched_stdev * threshold_value), 1, 0) -| search isOutlier=1 AND _time >= relative_time(now(), "-10m@m") -| eval num_standard_deviations_away = round(abs(instances_launched - total_launched_avg) / total_launched_stdev, 2) -| table _time, userName, instances_launched, num_standard_deviations_away, total_launched_avg, total_launched_stdev -| `abnormally_high_aws_instances_launched_by_user_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) - -> :information_source: -> **abnormally_high_aws_instances_launched_by_user_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* eventName -* errorCode -* userName - - -#### How To Implement -You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your AWS CloudTrail inputs. The threshold value should be tuned to your environment. - -#### Known False Positives -Many service accounts configured within an AWS infrastructure are known to exhibit this behavior. Please adjust the threshold values and filter out service accounts from the output. Always verify if this search alerted on a human user. - -#### Associated Analytic story -* [AWS Cryptomining](/stories/aws_cryptomining) -* [Suspicious AWS EC2 Activities](/stories/suspicious_aws_ec2_activities) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2020-07-21-abnormally_high_aws_instances_launched_by_user_-_mltk.md b/docs/_posts/2020-07-21-abnormally_high_aws_instances_launched_by_user_-_mltk.md deleted file mode 100644 index 37c866d798..0000000000 --- a/docs/_posts/2020-07-21-abnormally_high_aws_instances_launched_by_user_-_mltk.md +++ /dev/null @@ -1,156 +0,0 @@ ---- -title: "Abnormally High AWS Instances Launched by User - MLTK" -excerpt: "Cloud Accounts -" -categories: - - Deprecated -last_modified_at: 2020-07-21 -toc: true -toc_label: "" -tags: - - Cloud Accounts - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for AWS CloudTrail events where a user successfully launches an abnormally high number of instances. This search is deprecated and have been translated to use the latest Change Datamodel. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-07-21 -- **Author**: Jason Brewer, Splunk -- **ID**: dec41ad5-d579-42cb-b4c6-f5dbb778bbe5 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1078.004](https://attack.mitre.org/techniques/T1078/004/) | Cloud Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.DP -* DE.AE - - - -
-
- -
- CIS20 - -
- -* CIS 13 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cloudtrail` eventName=RunInstances errorCode=success `abnormally_high_aws_instances_launched_by_user___mltk_filter` -| bucket span=10m _time -| stats count as instances_launched by _time src_user -| apply ec2_excessive_runinstances_v1 -| rename "IsOutlier(instances_launched)" as isOutlier -| where isOutlier=1 -``` - -#### Macros -The SPL above uses the following Macros: -* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) - -> :information_source: -> **abnormally_high_aws_instances_launched_by_user_-_mltk_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* eventName -* errorCode -* src_user - - -#### How To Implement -You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your AWS CloudTrail inputs. The threshold value should be tuned to your environment. - -#### Known False Positives -Many service accounts configured within an AWS infrastructure are known to exhibit this behavior. Please adjust the threshold values and filter out service accounts from the output. Always verify if this search alerted on a human user. - -#### Associated Analytic story -* [AWS Cryptomining](/stories/aws_cryptomining) -* [Suspicious AWS EC2 Activities](/stories/suspicious_aws_ec2_activities) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2020-07-21-abnormally_high_aws_instances_terminated_by_user.md b/docs/_posts/2020-07-21-abnormally_high_aws_instances_terminated_by_user.md deleted file mode 100644 index 43c1ded8d9..0000000000 --- a/docs/_posts/2020-07-21-abnormally_high_aws_instances_terminated_by_user.md +++ /dev/null @@ -1,159 +0,0 @@ ---- -title: "Abnormally High AWS Instances Terminated by User" -excerpt: "Cloud Accounts -" -categories: - - Deprecated -last_modified_at: 2020-07-21 -toc: true -toc_label: "" -tags: - - Cloud Accounts - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for AWS CloudTrail events where an abnormally high number of instances were successfully terminated by a user in a 10-minute window. This search is deprecated and have been translated to use the latest Change Datamodel. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-07-21 -- **Author**: Bhavin Patel, Splunk -- **ID**: 8d301246-fccf-45e2-a8e7-3655fd14379c - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1078.004](https://attack.mitre.org/techniques/T1078/004/) | Cloud Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.DP -* DE.AE - - - -
-
- -
- CIS20 - -
- -* CIS 13 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cloudtrail` eventName=TerminateInstances errorCode=success -| bucket span=10m _time -| stats count AS instances_terminated by _time userName -| eventstats avg(instances_terminated) as total_terminations_avg, stdev(instances_terminated) as total_terminations_stdev -| eval threshold_value = 4 -| eval isOutlier=if(instances_terminated > total_terminations_avg+(total_terminations_stdev * threshold_value), 1, 0) -| search isOutlier=1 AND _time >= relative_time(now(), "-10m@m") -| eval num_standard_deviations_away = round(abs(instances_terminated - total_terminations_avg) / total_terminations_stdev, 2) -|table _time, userName, instances_terminated, num_standard_deviations_away, total_terminations_avg, total_terminations_stdev -| `abnormally_high_aws_instances_terminated_by_user_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) - -> :information_source: -> **abnormally_high_aws_instances_terminated_by_user_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* eventName -* errorCode -* userName - - -#### How To Implement -You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your AWS CloudTrail inputs. - -#### Known False Positives -Many service accounts configured with your AWS infrastructure are known to exhibit this behavior. Please adjust the threshold values and filter out service accounts from the output. Always verify whether this search alerted on a human user. - -#### Associated Analytic story -* [Suspicious AWS EC2 Activities](/stories/suspicious_aws_ec2_activities) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2020-07-21-abnormally_high_aws_instances_terminated_by_user_-_mltk.md b/docs/_posts/2020-07-21-abnormally_high_aws_instances_terminated_by_user_-_mltk.md deleted file mode 100644 index efcb916ee8..0000000000 --- a/docs/_posts/2020-07-21-abnormally_high_aws_instances_terminated_by_user_-_mltk.md +++ /dev/null @@ -1,155 +0,0 @@ ---- -title: "Abnormally High AWS Instances Terminated by User - MLTK" -excerpt: "Cloud Accounts -" -categories: - - Deprecated -last_modified_at: 2020-07-21 -toc: true -toc_label: "" -tags: - - Cloud Accounts - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for AWS CloudTrail events where a user successfully terminates an abnormally high number of instances. This search is deprecated and have been translated to use the latest Change Datamodel. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-07-21 -- **Author**: Jason Brewer, Splunk -- **ID**: 1c02b86a-cd85-473e-a50b-014a9ac8fe3e - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1078.004](https://attack.mitre.org/techniques/T1078/004/) | Cloud Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.DP -* DE.AE - - - -
-
- -
- CIS20 - -
- -* CIS 13 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cloudtrail` eventName=TerminateInstances errorCode=success `abnormally_high_aws_instances_terminated_by_user___mltk_filter` -| bucket span=10m _time -| stats count as instances_terminated by _time src_user -| apply ec2_excessive_terminateinstances_v1 -| rename "IsOutlier(instances_terminated)" as isOutlier -| where isOutlier=1 -``` - -#### Macros -The SPL above uses the following Macros: -* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) - -> :information_source: -> **abnormally_high_aws_instances_terminated_by_user_-_mltk_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* eventName -* errorCode -* src_user - - -#### How To Implement -You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your AWS CloudTrail inputs. The threshold value should be tuned to your environment. - -#### Known False Positives -Many service accounts configured within an AWS infrastructure are known to exhibit this behavior. Please adjust the threshold values and filter out service accounts from the output. Always verify if this search alerted on a human user. - -#### Associated Analytic story -* [Suspicious AWS EC2 Activities](/stories/suspicious_aws_ec2_activities) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2020-07-21-attempt_to_stop_security_service.md b/docs/_posts/2020-07-21-attempt_to_stop_security_service.md deleted file mode 100644 index 62acb2404b..0000000000 --- a/docs/_posts/2020-07-21-attempt_to_stop_security_service.md +++ /dev/null @@ -1,189 +0,0 @@ ---- -title: "Attempt To Stop Security Service" -excerpt: "Disable or Modify Tools -, Impair Defenses -" -categories: - - Endpoint -last_modified_at: 2020-07-21 -toc: true -toc_label: "" -tags: - - Disable or Modify Tools - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for attempts to stop security-related services on the endpoint. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2020-07-21 -- **Author**: Rico Valdez, Splunk -- **ID**: c8e349c6-b97c-486e-8949-bd7bcd1f3910 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Installation -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM -* PR.IP - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_net` OR Processes.process_name = sc.exe Processes.process="* stop *" by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -|lookup security_services_lookup service as process OUTPUTNEW category, description -| search category=security -| `attempt_to_stop_security_service_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_net](https://github.com/splunk/security_content/blob/develop/macros/process_net.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **attempt_to_stop_security_service_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Lookups -The SPL above uses the following Lookups: - -* [security_services_lookup](https://github.com/splunk/security_content/blob/develop/lookups/security_services_lookup.yml) with [data](https://github.com/splunk/security_content/tree/develop/lookups/security_services_lookup.csv) - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -None identified. Attempts to disable security-related services should be identified and understood. - -#### Associated Analytic story -* [Disabling Security Tools](/stories/disabling_security_tools) -* [Trickbot](/stories/trickbot) -* [WhisperGate](/stories/whispergate) -* [Azorult](/stories/azorult) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 20.0 | 40 | 50 | An instance of $parent_process_name$ spawning $process_name$ was identified attempting to disable security services on endpoint $dest$ by user $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1562.001/T1562.001.md#atomic-test-14---disable-arbitrary-security-windows-service](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1562.001/T1562.001.md#atomic-test-14---disable-arbitrary-security-windows-service) -* [https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/](https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_defend_service_stop/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_defend_service_stop/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/attempt_to_stop_security_service.yml) \| *version*: **4** \ No newline at end of file diff --git a/docs/_posts/2020-07-21-clients_connecting_to_multiple_dns_servers.md b/docs/_posts/2020-07-21-clients_connecting_to_multiple_dns_servers.md deleted file mode 100644 index 7141cbd45d..0000000000 --- a/docs/_posts/2020-07-21-clients_connecting_to_multiple_dns_servers.md +++ /dev/null @@ -1,160 +0,0 @@ ---- -title: "Clients Connecting to Multiple DNS Servers" -excerpt: "Exfiltration Over Unencrypted Non-C2 Protocol -" -categories: - - Deprecated -last_modified_at: 2020-07-21 -toc: true -toc_label: "" -tags: - - Exfiltration Over Unencrypted Non-C2 Protocol - - Exfiltration - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Network_Resolution ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search allows you to identify the endpoints that have connected to more than five DNS servers and made DNS Queries over the time frame of the search. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Network_Resolution](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkResolution) -- **Last Updated**: 2020-07-21 -- **Author**: David Dorsey, Splunk -- **ID**: 74ec6f18-604b-4202-a567-86b2066be3ce - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1048.003](https://attack.mitre.org/techniques/T1048/003/) | Exfiltration Over Unencrypted Non-C2 Protocol | Exfiltration | - -
-
- - -
- Kill Chain Phase - -
- -* Command & Control - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.AE -* PR.DS - - - -
-
- -
- CIS20 - -
- -* CIS 9 -* CIS 12 -* CIS 13 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count, values(DNS.dest) AS dest dc(DNS.dest) as dest_count from datamodel=Network_Resolution where DNS.message_type=QUERY by DNS.src -| `drop_dm_object_name("Network_Resolution")` -|where dest_count > 5 -| `clients_connecting_to_multiple_dns_servers_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **clients_connecting_to_multiple_dns_servers_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* DNS.dest -* DNS.message_type -* DNS.src - - -#### How To Implement -This search requires that DNS data is being ingested and populating the `Network_Resolution` data model. This data can come from DNS logs or from solutions that parse network traffic for this data, such as Splunk Stream or Bro.\ -This search produces fields (`dest_count`) that are not yet supported by ES Incident Review and therefore cannot be viewed when a notable event is raised. These fields contribute additional context to the notable. To see the additional metadata, add the following fields, if not already present, to Incident Review - Event Attributes (Configure > Incident Management > Incident Review Settings > Add New Entry):\\n1. **Label:** Distinct DNS Connections, **Field:** dest_count\ -Detailed documentation on how to create a new field within Incident Review may be found here: `https://docs.splunk.com/Documentation/ES/5.3.0/Admin/Customizenotables#Add_a_field_to_the_notable_event_details` - -#### Known False Positives -It's possible that an enterprise has more than five DNS servers that are configured in a round-robin rotation. Please customize the search, as appropriate. - -#### Associated Analytic story -* [DNS Hijacking](/stories/dns_hijacking) -* [Suspicious DNS Traffic](/stories/suspicious_dns_traffic) -* [Host Redirection](/stories/host_redirection) -* [Command and Control](/stories/command_and_control) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2020-07-21-detect_aws_api_activities_from_unapproved_accounts.md b/docs/_posts/2020-07-21-detect_aws_api_activities_from_unapproved_accounts.md deleted file mode 100644 index 73fd4e7abe..0000000000 --- a/docs/_posts/2020-07-21-detect_aws_api_activities_from_unapproved_accounts.md +++ /dev/null @@ -1,177 +0,0 @@ ---- -title: "Detect AWS API Activities From Unapproved Accounts" -excerpt: "Cloud Accounts -" -categories: - - Deprecated -last_modified_at: 2020-07-21 -toc: true -toc_label: "" -tags: - - Cloud Accounts - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for successful AWS CloudTrail activity by user accounts that are not listed in the identity table or `aws_service_accounts.csv`. It returns event names and count, as well as the first and last time a specific user or service is detected, grouped by users. Deprecated because managing this list can be quite hard. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-07-21 -- **Author**: Bhavin Patel, Splunk -- **ID**: ada0f478-84a8-4641-a3f1-d82362d4bd55 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1078.004](https://attack.mitre.org/techniques/T1078/004/) | Cloud Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.DP -* DE.CM -* PR.AC -* ID.AM - - - -
-
- -
- CIS20 - -
- -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cloudtrail` errorCode=success -| rename userName as identity -| search NOT [ -| inputlookup identity_lookup_expanded -| fields identity] -| search NOT [ -| inputlookup aws_service_accounts -| fields identity] -| rename identity as user -| stats count min(_time) as firstTime max(_time) as lastTime values(eventName) as eventName by user -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_aws_api_activities_from_unapproved_accounts_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) - -> :information_source: -> **detect_aws_api_activities_from_unapproved_accounts_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Lookups -The SPL above uses the following Lookups: - -* [aws_service_accounts](https://github.com/splunk/security_content/blob/develop/lookups/aws_service_accounts.yml) with [data](https://github.com/splunk/security_content/tree/develop/lookups/aws_service_accounts.csv) - -#### Required field -* _time -* errorCode -* userName -* eventName -* user - - -#### How To Implement -You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your AWS CloudTrail inputs. You must also populate the `identity_lookup_expanded` lookup shipped with the Asset and Identity framework to be able to look up users in your identity table in Enterprise Security (ES). Leverage the support search called "Create a list of approved AWS service accounts": run it once every 30 days to create and validate a list of service accounts.\ -This search produces fields (`eventName`,`firstTime`,`lastTime`) that are not yet supported by ES Incident Review and therefore cannot be viewed when a notable event is raised. These fields contribute additional context to the notable. To see the additional metadata, add the following fields, if not already present, to Incident Review - Event Attributes (Configure > Incident Management > Incident Review Settings > Add New Entry):\\n1. **Label:** AWS Event Name, **Field:** eventName\ -1. \ -1. **Label:** First Time, **Field:** firstTime\ -1. \ -1. **Label:** Last Time, **Field:** lastTime\ -Detailed documentation on how to create a new field within Incident Review may be found here: `https://docs.splunk.com/Documentation/ES/5.3.0/Admin/Customizenotables#Add_a_field_to_the_notable_event_details` - -#### Known False Positives -It's likely that you'll find activity detected by users/service accounts that are not listed in the `identity_lookup_expanded` or ` aws_service_accounts.csv` file. If the user is a legitimate service account, update the `aws_service_accounts.csv` table with that entry. - -#### Associated Analytic story -* [AWS User Monitoring](/stories/aws_user_monitoring) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2020-07-21-detect_dns_requests_to_phishing_sites_leveraging_evilginx2.md b/docs/_posts/2020-07-21-detect_dns_requests_to_phishing_sites_leveraging_evilginx2.md deleted file mode 100644 index 680f315e32..0000000000 --- a/docs/_posts/2020-07-21-detect_dns_requests_to_phishing_sites_leveraging_evilginx2.md +++ /dev/null @@ -1,182 +0,0 @@ ---- -title: "Detect DNS requests to Phishing Sites leveraging EvilGinx2" -excerpt: "Spearphishing via Service -" -categories: - - Deprecated -last_modified_at: 2020-07-21 -toc: true -toc_label: "" -tags: - - Spearphishing via Service - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Network_Resolution ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for DNS requests for phishing domains that are leveraging EvilGinx tools to mimic websites. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Network_Resolution](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkResolution) -- **Last Updated**: 2020-07-21 -- **Author**: Bhavin Patel, Splunk -- **ID**: 24dd17b1-e2fb-4c31-878c-d4f226595bfa - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1566.003](https://attack.mitre.org/techniques/T1566/003/) | Spearphishing via Service | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Delivery -* Command & Control - - -
-
- - -
- NIST - -
- -* ID.AM -* PR.DS -* PR.IP -* DE.AE -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 -* CIS 7 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(DNS.answer) as answer from datamodel=Network_Resolution.DNS by DNS.dest DNS.src DNS.query host -| `drop_dm_object_name(DNS)` -| rex field=query ".*?(?[^./:]+\.(\S{2,3} -|\S{2,3}.\S{2,3}))$" -| stats count values(query) as query by domain dest src answer -| search `evilginx_phishlets_amazon` OR `evilginx_phishlets_facebook` OR `evilginx_phishlets_github` OR `evilginx_phishlets_0365` OR `evilginx_phishlets_outlook` OR `evilginx_phishlets_aws` OR `evilginx_phishlets_google` -| search NOT [ inputlookup legit_domains.csv -| fields domain] -| join domain type=outer [ -| tstats count `security_content_summariesonly` values(Web.url) as url from datamodel=Web.Web by Web.dest Web.site -| rename "Web.*" as * -| rex field=site ".*?(?[^./:]+\.(\S{2,3} -|\S{2,3}.\S{2,3}))$" -| table dest domain url] -| table count src dest query answer domain url -| `detect_dns_requests_to_phishing_sites_leveraging_evilginx2_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [evilginx_phishlets_facebook](https://github.com/splunk/security_content/blob/develop/macros/evilginx_phishlets_facebook.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [evilginx_phishlets_0365](https://github.com/splunk/security_content/blob/develop/macros/evilginx_phishlets_0365.yml) -* [evilginx_phishlets_aws](https://github.com/splunk/security_content/blob/develop/macros/evilginx_phishlets_aws.yml) -* [evilginx_phishlets_outlook](https://github.com/splunk/security_content/blob/develop/macros/evilginx_phishlets_outlook.yml) -* [evilginx_phishlets_github](https://github.com/splunk/security_content/blob/develop/macros/evilginx_phishlets_github.yml) -* [evilginx_phishlets_google](https://github.com/splunk/security_content/blob/develop/macros/evilginx_phishlets_google.yml) -* [evilginx_phishlets_amazon](https://github.com/splunk/security_content/blob/develop/macros/evilginx_phishlets_amazon.yml) - -> :information_source: -> **detect_dns_requests_to_phishing_sites_leveraging_evilginx2_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* DNS.answer -* DNS.dest -* DNS.src -* DNS.query -* host - - -#### How To Implement -You need to ingest data from your DNS logs in the Network_Resolution datamodel. Specifically you must ingest the domain that is being queried and the IP of the host originating the request. Ideally, you should also be ingesting the answer to the query and the query type. This approach allows you to also create your own localized passive DNS capability which can aid you in future investigations. You will have to add legitimate domain names to the `legit_domains.csv` file shipped with the app. \ - **Splunk>Phantom Playbook Integration**\ -If Splunk>Phantom is also configured in your environment, a Playbook called `Lets Encrypt Domain Investigate` can be configured to run when any results are found by this detection search. To use this integration, install the Phantom App for Splunk `https://splunkbase.splunk.com/app/3411/`, add the correct hostname to the "Phantom Instance" field in the Adaptive Response Actions when configuring this detection search, and set the corresponding Playbook to active. \ -(Playbook link:`https://my.phantom.us/4.2/playbook/lets-encrypt-domain-investigate/`).\ - - -#### Known False Positives -If a known good domain is not listed in the legit_domains.csv file, then the search could give you false postives. Please update that lookup file to filter out DNS requests to legitimate domains. - -#### Associated Analytic story -* [Common Phishing Frameworks](/stories/common_phishing_frameworks) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2020-07-21-detect_excessive_user_account_lockouts.md b/docs/_posts/2020-07-21-detect_excessive_user_account_lockouts.md deleted file mode 100644 index e9fd64eac7..0000000000 --- a/docs/_posts/2020-07-21-detect_excessive_user_account_lockouts.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: "Detect Excessive User Account Lockouts" -excerpt: "Valid Accounts -, Local Accounts -" -categories: - - Endpoint -last_modified_at: 2020-07-21 -toc: true -toc_label: "" -tags: - - Valid Accounts - - Local Accounts - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Change ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search detects user accounts that have been locked out a relatively high number of times in a short period. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Change](https://docs.splunk.com/Documentation/CIM/latest/User/Change) -- **Last Updated**: 2020-07-21 -- **Author**: David Dorsey, Splunk -- **ID**: 95a7f9a5-6096-437e-a19e-86f42ac609bd - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -| [T1078.003](https://attack.mitre.org/techniques/T1078/003/) | Local Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* PR.IP - - - -
-
- -
- CIS20 - -
- -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Change.All_Changes where nodename=All_Changes.Account_Management All_Changes.result="lockout" by All_Changes.user All_Changes.result -|`drop_dm_object_name("All_Changes")` -|`drop_dm_object_name("Account_Management")` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| search count > 5 -| `detect_excessive_user_account_lockouts_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **detect_excessive_user_account_lockouts_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* All_Changes.result -* nodename -* All_Changes.user - - -#### How To Implement -ou must ingest your Windows security event logs in the `Change` datamodel under the nodename is `Account_Management`, for this search to execute successfully. Please consider updating the cron schedule and the count of lockouts you want to monitor, according to your environment. - -#### Known False Positives -It is possible that a legitimate user is experiencing an issue causing multiple account login failures leading to lockouts. - -#### Associated Analytic story -* [Account Monitoring and Controls](/stories/account_monitoring_and_controls) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 36.0 | 60 | 60 | Multiple accounts have been locked out. Review $nodename$ and $result$ related to $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078.002/account_lockout/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078.002/account_lockout/windows-security.log) -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078.002/account_lockout/windows-system.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078.002/account_lockout/windows-system.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2020-07-21-detect_long_dns_txt_record_response.md b/docs/_posts/2020-07-21-detect_long_dns_txt_record_response.md deleted file mode 100644 index 8a71757140..0000000000 --- a/docs/_posts/2020-07-21-detect_long_dns_txt_record_response.md +++ /dev/null @@ -1,165 +0,0 @@ ---- -title: "Detect Long DNS TXT Record Response" -excerpt: "Exfiltration Over Unencrypted Non-C2 Protocol -" -categories: - - Deprecated -last_modified_at: 2020-07-21 -toc: true -toc_label: "" -tags: - - Exfiltration Over Unencrypted Non-C2 Protocol - - Exfiltration - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Network_Resolution ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is used to detect attempts to use DNS tunneling, by calculating the length of responses to DNS TXT queries. Endpoints using DNS as a method of transmission for data exfiltration, command and control, or evasion of security controls can often be detected by noting unusually large volumes of DNS traffic. Deprecated because this detection should focus on DNS queries instead of DNS responses. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Network_Resolution](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkResolution) -- **Last Updated**: 2020-07-21 -- **Author**: Rico Valdez, Splunk -- **ID**: 05437c07-62f5-452e-afdc-04dd44815bb9 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1048.003](https://attack.mitre.org/techniques/T1048/003/) | Exfiltration Over Unencrypted Non-C2 Protocol | Exfiltration | - -
-
- - -
- Kill Chain Phase - -
- -* Command & Control - - -
-
- - -
- NIST - -
- -* PR.DS -* PR.PT -* DE.AE -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 -* CIS 12 -* CIS 13 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Network_Resolution where DNS.message_type=response AND DNS.record_type=TXT by DNS.src DNS.dest DNS.answer DNS.record_type -| `drop_dm_object_name("DNS")` -| eval anslen=len(answer) -| search anslen>100 -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| rename src as "Source IP", dest as "Destination IP", answer as "DNS Answer" anslen as "Answer Length" record_type as "DNS Record Type" firstTime as "First Time" lastTime as "Last Time" count as Count -| table "Source IP" "Destination IP" "DNS Answer" "DNS Record Type" "Answer Length" Count "First Time" "Last Time" -| `detect_long_dns_txt_record_response_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **detect_long_dns_txt_record_response_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* DNS.message_type -* DNS.record_type -* DNS.src -* DNS.dest -* DNS.answer - - -#### How To Implement -To successfully implement this search you need to ingest data from your DNS logs, or monitor DNS traffic using Stream, Bro or something similar. Specifically, this query requires that the DNS data model is populated with information regarding the DNS record type that is being returned as well as the data in the answer section of the protocol. - -#### Known False Positives -It's possible that legitimate TXT record responses can be long enough to trigger this search. You can modify the packet threshold for this search to help mitigate false positives. - -#### Associated Analytic story -* [Suspicious DNS Traffic](/stories/suspicious_dns_traffic) -* [Command and Control](/stories/command_and_control) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/detect_long_dns_txt_record_response.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2020-07-21-detect_new_user_aws_console_login.md b/docs/_posts/2020-07-21-detect_new_user_aws_console_login.md deleted file mode 100644 index 8694a6d3a9..0000000000 --- a/docs/_posts/2020-07-21-detect_new_user_aws_console_login.md +++ /dev/null @@ -1,159 +0,0 @@ ---- -title: "Detect new user AWS Console Login" -excerpt: "Cloud Accounts -" -categories: - - Deprecated -last_modified_at: 2020-07-21 -toc: true -toc_label: "" -tags: - - Cloud Accounts - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for AWS CloudTrail events wherein a console login event by a user was recorded within the last hour, then compares the event to a lookup file of previously seen users (by ARN values) who have logged into the console. The alert is fired if the user has logged into the console for the first time within the last hour. Deprecated now this search is updated to use the Authentication datamodel. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-07-21 -- **Author**: Bhavin Patel, Splunk -- **ID**: ada0f478-84a8-4641-a3f3-d82362dffd75 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1078.004](https://attack.mitre.org/techniques/T1078/004/) | Cloud Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.DP -* DE.AE - - - -
-
- -
- CIS20 - -
- -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cloudtrail` eventName=ConsoleLogin -| rename userIdentity.arn as user -| stats earliest(_time) as firstTime latest(_time) as lastTime by user -| inputlookup append=t previously_seen_users_console_logins_cloudtrail -| stats min(firstTime) as firstTime max(lastTime) as lastTime by user -| eval userStatus=if(firstTime >= relative_time(now(), "-70m@m"), "First Time Logging into AWS Console","Previously Seen User") -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -| where userStatus ="First Time Logging into AWS Console" -| `detect_new_user_aws_console_login_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) - -> :information_source: -> **detect_new_user_aws_console_login_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* eventName -* userIdentity.arn - - -#### How To Implement -You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your AWS CloudTrail inputs. Run the "Previously seen users in AWS CloudTrail" support search only once to create a baseline of previously seen IAM users within the last 30 days. Run "Update previously seen users in AWS CloudTrail" hourly (or more frequently depending on how often you run the detection searches) to refresh the baselines. - -#### Known False Positives -When a legitimate new user logins for the first time, this activity will be detected. Check how old the account is and verify that the user activity is legitimate. - -#### Associated Analytic story -* [Suspicious AWS Login Activities](/stories/suspicious_aws_login_activities) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/detect_new_user_aws_console_login.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2020-07-21-detect_outbound_smb_traffic.md b/docs/_posts/2020-07-21-detect_outbound_smb_traffic.md deleted file mode 100644 index 0282f5b820..0000000000 --- a/docs/_posts/2020-07-21-detect_outbound_smb_traffic.md +++ /dev/null @@ -1,167 +0,0 @@ ---- -title: "Detect Outbound SMB Traffic" -excerpt: "File Transfer Protocols -, Application Layer Protocol -" -categories: - - Network -last_modified_at: 2020-07-21 -toc: true -toc_label: "" -tags: - - File Transfer Protocols - - Application Layer Protocol - - Command And Control - - Command And Control - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Network_Traffic ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for outbound SMB connections made by hosts within your network to the Internet. SMB traffic is used for Windows file-sharing activity. One of the techniques often used by attackers involves retrieving the credential hash using an SMB request made to a compromised server controlled by the threat actor. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Network_Traffic](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkTraffic) -- **Last Updated**: 2020-07-21 -- **Author**: Bhavin Patel, Stuart Hopkins from Splunk -- **ID**: 1bed7774-304a-4e8f-9d72-d80e45ff492b - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1071.002](https://attack.mitre.org/techniques/T1071/002/) | File Transfer Protocols | Command And Control | - -| [T1071](https://attack.mitre.org/techniques/T1071/) | Application Layer Protocol | Command And Control | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives -* Command & Control - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 12 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` earliest(_time) as start_time latest(_time) as end_time values(All_Traffic.action) as action values(All_Traffic.app) as app values(All_Traffic.dest_ip) as dest_ip values(All_Traffic.dest_port) as dest_port values(sourcetype) as sourcetype count from datamodel=Network_Traffic where ((All_Traffic.dest_port=139 OR All_Traffic.dest_port=445 OR All_Traffic.app="smb") AND NOT (All_Traffic.action="blocked" OR All_Traffic.dest_category="internal" OR All_Traffic.dest_ip=10.0.0.0/8 OR All_Traffic.dest_ip=172.16.0.0/12 OR All_Traffic.dest_ip=192.168.0.0/16 OR All_Traffic.dest_ip=100.64.0.0/10)) by All_Traffic.src_ip -| `drop_dm_object_name("All_Traffic")` -| `security_content_ctime(start_time)` -| `security_content_ctime(end_time)` -| `detect_outbound_smb_traffic_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **detect_outbound_smb_traffic_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* All_Traffic.action -* All_Traffic.app -* All_Traffic.dest_ip -* All_Traffic.dest_port -* sourcetype -* All_Traffic.dest_category -* All_Traffic.src_ip - - -#### How To Implement -In order to run this search effectively, we highly recommend that you leverage the Assets and Identity framework. It is important that you have good understanding of how your network segments are designed, and be able to distinguish internal from external address space. Add a category named `internal` to the CIDRs that host the companys assets in `assets_by_cidr.csv` lookup file, which is located in `$SPLUNK_HOME/etc/apps/SA-IdentityManagement/lookups/`. More information on updating this lookup can be found here: https://docs.splunk.com/Documentation/ES/5.0.0/Admin/Addassetandidentitydata. This search also requires you to be ingesting your network traffic and populating the Network_Traffic data model - -#### Known False Positives -It is likely that the outbound Server Message Block (SMB) traffic is legitimate, if the company's internal networks are not well-defined in the Assets and Identity Framework. Categorize the internal CIDR blocks as `internal` in the lookup file to avoid creating notable events for traffic destined to those CIDR blocks. Any other network connection that is going out to the Internet should be investigated and blocked. Best practices suggest preventing external communications of all SMB versions and related protocols at the network boundary. - -#### Associated Analytic story -* [Hidden Cobra Malware](/stories/hidden_cobra_malware) -* [DHS Report TA18-074A](/stories/dhs_report_ta18-074a) -* [NOBELIUM Group](/stories/nobelium_group) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/network/detect_outbound_smb_traffic.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2020-07-21-detect_outlook_exe_writing_a_zip_file.md b/docs/_posts/2020-07-21-detect_outlook_exe_writing_a_zip_file.md deleted file mode 100644 index d8e12c392f..0000000000 --- a/docs/_posts/2020-07-21-detect_outlook_exe_writing_a_zip_file.md +++ /dev/null @@ -1,176 +0,0 @@ ---- -title: "Detect Outlook exe writing a zip file" -excerpt: "Phishing -, Spearphishing Attachment -" -categories: - - Endpoint -last_modified_at: 2020-07-21 -toc: true -toc_label: "" -tags: - - Phishing - - Spearphishing Attachment - - Initial Access - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for execution of process `outlook.exe` where the process is writing a `.zip` file to the disk. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-07-21 -- **Author**: Bhavin Patel, Splunk -- **ID**: a51bfe1a-94f0-4822-b1e4-16ae10145893 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | - -| [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Installation -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* ID.AM -* PR.DS - - - -
-
- -
- CIS20 - -
- -* CIS 7 -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes where Processes.process_name=outlook.exe OR Processes.process_name=explorer.exe by _time span=5m Processes.parent_process_id Processes.process_id Processes.dest Processes.process_name Processes.parent_process_name Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| rename process_id as malicious_id -| rename parent_process_id as outlook_id -| join malicious_id type=inner[ -| tstats `security_content_summariesonly` count values(Filesystem.file_path) as file_path values(Filesystem.file_name) as file_name FROM datamodel=Endpoint.Filesystem where (Filesystem.file_path=*zip* OR Filesystem.file_name=*.lnk ) AND (Filesystem.file_path=C:\\Users* OR Filesystem.file_path=*Local\\Temp*) by _time span=5m Filesystem.process_id Filesystem.file_hash Filesystem.dest -| `drop_dm_object_name(Filesystem)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| rename process_id as malicious_id -| fields malicious_id outlook_id dest file_path file_name file_hash count file_id] -| table firstTime lastTime user malicious_id outlook_id process_name parent_process_name file_name file_path -| where file_name != "" -| `detect_outlook_exe_writing_a_zip_file_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **detect_outlook_exe_writing_a_zip_file_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process_name -* Processes.parent_process_id -* Processes.process_id -* Processes.dest -* Processes.parent_process_name -* Processes.user - - -#### How To Implement -You must be ingesting data that records filesystem and process activity from your hosts to populate the Endpoint data model. This is typically populated via endpoint detection-and-response product, such as Carbon Black, or endpoint data sources, such as Sysmon. - -#### Known False Positives -It is not uncommon for outlook to write legitimate zip files to the disk. - -#### Associated Analytic story -* [Spearphishing Attachments](/stories/spearphishing_attachments) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/endpoint/detect_outlook_exe_writing_a_zip_file.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2020-07-21-detect_spike_in_aws_api_activity.md b/docs/_posts/2020-07-21-detect_spike_in_aws_api_activity.md deleted file mode 100644 index b5b8ea361f..0000000000 --- a/docs/_posts/2020-07-21-detect_spike_in_aws_api_activity.md +++ /dev/null @@ -1,181 +0,0 @@ ---- -title: "Detect Spike in AWS API Activity" -excerpt: "Cloud Accounts -" -categories: - - Deprecated -last_modified_at: 2020-07-21 -toc: true -toc_label: "" -tags: - - Cloud Accounts - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search will detect users creating spikes of API activity in your AWS environment. It will also update the cache file that factors in the latest data. This search is deprecated and have been translated to use the latest Change Datamodel. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-07-21 -- **Author**: David Dorsey, Splunk -- **ID**: ada0f478-84a8-4641-a3f1-d32362d4bd55 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1078.004](https://attack.mitre.org/techniques/T1078/004/) | Cloud Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.DP -* DE.CM -* PR.AC - - - -
-
- -
- CIS20 - -
- -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cloudtrail` eventType=AwsApiCall [search `cloudtrail` eventType=AwsApiCall -| spath output=arn path=userIdentity.arn -| stats count as apiCalls by arn -| inputlookup api_call_by_user_baseline append=t -| fields - latestCount -| stats values(*) as * by arn -| rename apiCalls as latestCount -| eval newAvgApiCalls=avgApiCalls + (latestCount-avgApiCalls)/720 -| eval newStdevApiCalls=sqrt(((pow(stdevApiCalls, 2)*719 + (latestCount-newAvgApiCalls)*(latestCount-avgApiCalls))/720)) -| eval avgApiCalls=coalesce(newAvgApiCalls, avgApiCalls), stdevApiCalls=coalesce(newStdevApiCalls, stdevApiCalls), numDataPoints=if(isnull(latestCount), numDataPoints, numDataPoints+1) -| table arn, latestCount, numDataPoints, avgApiCalls, stdevApiCalls -| outputlookup api_call_by_user_baseline -| eval dataPointThreshold = 15, deviationThreshold = 3 -| eval isSpike=if((latestCount > avgApiCalls+deviationThreshold*stdevApiCalls) AND numDataPoints > dataPointThreshold, 1, 0) -| where isSpike=1 -| rename arn as userIdentity.arn -| table userIdentity.arn] -| spath output=user userIdentity.arn -| stats values(eventName) as eventName, count as numberOfApiCalls, dc(eventName) as uniqueApisCalled by user -| `detect_spike_in_aws_api_activity_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) - -> :information_source: -> **detect_spike_in_aws_api_activity_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Lookups -The SPL above uses the following Lookups: - -* [api_call_by_user_baseline](https://github.com/splunk/security_content/blob/develop/lookups/api_call_by_user_baseline.yml) with [data](https://github.com/splunk/security_content/tree/develop/lookups/api_call_by_user_baseline.csv) -* [api_call_by_user_baseline](https://github.com/splunk/security_content/blob/develop/lookups/api_call_by_user_baseline.yml) with [data](https://github.com/splunk/security_content/tree/develop/lookups/api_call_by_user_baseline.csv) - -#### Required field -* _time -* eventType -* userIdentity.arn - - -#### How To Implement -You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your AWS CloudTrail inputs. You can modify `dataPointThreshold` and `deviationThreshold` to better fit your environment. The `dataPointThreshold` variable is the minimum number of data points required to have a statistically significant amount of data to determine. The `deviationThreshold` variable is the number of standard deviations away from the mean that the value must be to be considered a spike.\ -This search produces fields (`eventName`,`numberOfApiCalls`,`uniqueApisCalled`) that are not yet supported by ES Incident Review and therefore cannot be viewed when a notable event is raised. These fields contribute additional context to the notable. To see the additional metadata, add the following fields, if not already present, to Incident Review - Event Attributes (Configure > Incident Management > Incident Review Settings > Add New Entry):\\n1. **Label:** AWS Event Name, **Field:** eventName\ -1. \ -1. **Label:** Number of API Calls, **Field:** numberOfApiCalls\ -1. \ -1. **Label:** Unique API Calls, **Field:** uniqueApisCalled\ -Detailed documentation on how to create a new field within Incident Review may be found here: `https://docs.splunk.com/Documentation/ES/5.3.0/Admin/Customizenotables#Add_a_field_to_the_notable_event_details` - -#### Known False Positives - - -#### Associated Analytic story -* [AWS User Monitoring](/stories/aws_user_monitoring) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2020-07-21-detect_use_of_cmd_exe_to_launch_script_interpreters.md b/docs/_posts/2020-07-21-detect_use_of_cmd_exe_to_launch_script_interpreters.md deleted file mode 100644 index 6bc4eddfd5..0000000000 --- a/docs/_posts/2020-07-21-detect_use_of_cmd_exe_to_launch_script_interpreters.md +++ /dev/null @@ -1,167 +0,0 @@ ---- -title: "Detect Use of cmd exe to Launch Script Interpreters" -excerpt: "Command and Scripting Interpreter -, Windows Command Shell -" -categories: - - Endpoint -last_modified_at: 2020-07-21 -toc: true -toc_label: "" -tags: - - Command and Scripting Interpreter - - Windows Command Shell - - Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for the execution of the cscript.exe or wscript.exe processes, with a parent of cmd.exe. The search will return the count, the first and last time this execution was seen on a machine, the user, and the destination of the machine - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2020-07-21 -- **Author**: Bhavin Patel, Mauricio Velazco, Splunk -- **ID**: b89919ed-fe5f-492c-b139-95dbb162039e - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -| [T1059.003](https://attack.mitre.org/techniques/T1059/003/) | Windows Command Shell | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count values(Processes.process) min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name="cmd.exe" (Processes.process_name=cscript.exe OR Processes.process_name =wscript.exe) by Processes.parent_process Processes.process_name Processes.user Processes.dest -| `drop_dm_object_name("Processes")` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -| `detect_use_of_cmd_exe_to_launch_script_interpreters_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **detect_use_of_cmd_exe_to_launch_script_interpreters_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process -* Processes.parent_process_name -* Processes.process_name -* Processes.parent_process -* Processes.user -* Processes.dest - - -#### How To Implement -To successfully implement this search, you must be ingesting data that records process activity from your hosts to populate the endpoint data model in the processes node. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -Some legitimate applications may exhibit this behavior. - -#### Associated Analytic story -* [Emotet Malware DHS Report TA18-201A ](/stories/emotet_malware__dhs_report_ta18-201a_) -* [Suspicious Command-Line Executions](/stories/suspicious_command-line_executions) -* [Azorult](/stories/azorult) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 35.0 | 70 | 50 | cmd.exe launching script interpreters on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.003/cmd_spawns_cscript/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.003/cmd_spawns_cscript/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml) \| *version*: **4** \ No newline at end of file diff --git a/docs/_posts/2020-07-21-detect_web_traffic_to_dynamic_domain_providers.md b/docs/_posts/2020-07-21-detect_web_traffic_to_dynamic_domain_providers.md deleted file mode 100644 index da4c4419a2..0000000000 --- a/docs/_posts/2020-07-21-detect_web_traffic_to_dynamic_domain_providers.md +++ /dev/null @@ -1,160 +0,0 @@ ---- -title: "Detect web traffic to dynamic domain providers" -excerpt: "Web Protocols -" -categories: - - Deprecated -last_modified_at: 2020-07-21 -toc: true -toc_label: "" -tags: - - Web Protocols - - Command And Control - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Web ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for web connections to dynamic DNS providers. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Web](https://docs.splunk.com/Documentation/CIM/latest/User/Web) -- **Last Updated**: 2020-07-21 -- **Author**: Bhavin Patel, Splunk -- **ID**: 134da869-e264-4a8f-8d7e-fcd01c18f301 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1071.001](https://attack.mitre.org/techniques/T1071/001/) | Web Protocols | Command And Control | - -
-
- - -
- Kill Chain Phase - -
- -* Command & Control -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.IP -* DE.DP - - - -
-
- -
- CIS20 - -
- -* CIS 7 -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count values(Web.url) as url min(_time) as firstTime from datamodel=Web where Web.status=200 by Web.src Web.dest Web.status -| `drop_dm_object_name("Web")` -| `security_content_ctime(firstTime)` -| `dynamic_dns_web_traffic` -| `detect_web_traffic_to_dynamic_domain_providers_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [dynamic_dns_web_traffic](https://github.com/splunk/security_content/blob/develop/macros/dynamic_dns_web_traffic.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **detect_web_traffic_to_dynamic_domain_providers_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Web.url -* Web.status -* Web.src -* Web.dest - - -#### How To Implement -This search requires you to be ingesting web-traffic logs. You can obtain these logs from indexing data from a web proxy or by using a network-traffic-analysis tool, such as Bro or Splunk Stream. The web data model must contain the URL being requested, the IP address of the host initiating the request, and the destination IP. This search also leverages a lookup file, `dynamic_dns_providers_default.csv`, which contains a non-exhaustive list of dynamic DNS providers. Consider periodically updating this local lookup file with new domains.\ -This search produces fields (`isDynDNS`) that are not yet supported by ES Incident Review and therefore cannot be viewed when a notable event is raised. These fields contribute additional context to the notable. To see the additional metadata, add the following fields, if not already present, to Incident Review - Event Attributes (Configure > Incident Management > Incident Review Settings > Add New Entry):\\n1. **Label:** IsDynamicDNS, **Field:** isDynDNS\ -Detailed documentation on how to create a new field within Incident Review may be found here: `https://docs.splunk.com/Documentation/ES/5.3.0/Admin/Customizenotables#Add_a_field_to_the_notable_event_details` Deprecated because duplicate. - -#### Known False Positives -It is possible that list of dynamic DNS providers is outdated and/or that the URL being requested is legitimate. - -#### Associated Analytic story -* [Dynamic DNS](/stories/dynamic_dns) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2020-07-21-detection_of_tools_built_by_nirsoft.md b/docs/_posts/2020-07-21-detection_of_tools_built_by_nirsoft.md deleted file mode 100644 index 79bd71b2c0..0000000000 --- a/docs/_posts/2020-07-21-detection_of_tools_built_by_nirsoft.md +++ /dev/null @@ -1,158 +0,0 @@ ---- -title: "Detection of tools built by NirSoft" -excerpt: "Software Deployment Tools -" -categories: - - Endpoint -last_modified_at: 2020-07-21 -toc: true -toc_label: "" -tags: - - Software Deployment Tools - - Execution - - Lateral Movement - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for specific command-line arguments that may indicate the execution of tools made by Nirsoft, which are legitimate, but may be abused by attackers. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2020-07-21 -- **Author**: Bhavin Patel, Splunk -- **ID**: 3d8d201c-aa03-422d-b0ee-2e5ecf9718c0 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1072](https://attack.mitre.org/techniques/T1072/) | Software Deployment Tools | Execution, Lateral Movement | - -
-
- - -
- Kill Chain Phase - -
- -* Installation -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.IP - - - -
-
- -
- CIS20 - -
- -* CIS 3 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) values(Processes.process) as process max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process="* /stext *" OR Processes.process="* /scomma *" ) by Processes.parent_process Processes.process_name Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -| `detection_of_tools_built_by_nirsoft_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **detection_of_tools_built_by_nirsoft_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process -* Processes.parent_process -* Processes.process_name -* Processes.user - - -#### How To Implement -You must be ingesting endpoint data that tracks process activity, including parent-child relationships from your endpoints to populate the Endpoint data model in the Processes node. The command-line arguments are mapped to the "process" field in the Endpoint data model. - -#### Known False Positives -While legitimate, these NirSoft tools are prone to abuse. You should verfiy that the tool was used for a legitimate purpose. - -#### Associated Analytic story -* [Emotet Malware DHS Report TA18-201A ](/stories/emotet_malware__dhs_report_ta18-201a_) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/endpoint/detection_of_tools_built_by_nirsoft.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2020-07-21-dns_query_requests_resolved_by_unauthorized_dns_servers.md b/docs/_posts/2020-07-21-dns_query_requests_resolved_by_unauthorized_dns_servers.md deleted file mode 100644 index 8209ea0b8c..0000000000 --- a/docs/_posts/2020-07-21-dns_query_requests_resolved_by_unauthorized_dns_servers.md +++ /dev/null @@ -1,161 +0,0 @@ ---- -title: "DNS Query Requests Resolved by Unauthorized DNS Servers" -excerpt: "DNS -" -categories: - - Deprecated -last_modified_at: 2020-07-21 -toc: true -toc_label: "" -tags: - - DNS - - Command And Control - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Network_Resolution ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search will detect DNS requests resolved by unauthorized DNS servers. Legitimate DNS servers should be identified in the Enterprise Security Assets and Identity Framework. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Network_Resolution](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkResolution) -- **Last Updated**: 2020-07-21 -- **Author**: Bhavin Patel, Splunk -- **ID**: 1a67f15a-f4ff-4170-84e9-08cf6f75d6f6 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1071.004](https://attack.mitre.org/techniques/T1071/004/) | DNS | Command And Control | - -
-
- - -
- Kill Chain Phase - -
- -* Command & Control - - -
-
- - -
- NIST - -
- -* ID.AM -* PR.DS -* PR.IP -* DE.AE -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 1 -* CIS 3 -* CIS 8 -* CIS 12 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count from datamodel=Network_Resolution where DNS.dest_category != dns_server AND DNS.src_category != dns_server by DNS.src DNS.dest -| `drop_dm_object_name("DNS")` -| `dns_query_requests_resolved_by_unauthorized_dns_servers_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **dns_query_requests_resolved_by_unauthorized_dns_servers_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* DNS.dest_category -* DNS.src_category -* DNS.src -* DNS.dest - - -#### How To Implement -To successfully implement this search you will need to ensure that DNS data is populating the Network_Resolution data model. It also requires that your DNS servers are identified correctly in the Assets and Identity table of Enterprise Security. - -#### Known False Positives -Legitimate DNS activity can be detected in this search. Investigate, verify and update the list of authorized DNS servers as appropriate. - -#### Associated Analytic story -* [DNS Hijacking](/stories/dns_hijacking) -* [Suspicious DNS Traffic](/stories/suspicious_dns_traffic) -* [Host Redirection](/stories/host_redirection) -* [Command and Control](/stories/command_and_control) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2020-07-21-dns_record_changed.md b/docs/_posts/2020-07-21-dns_record_changed.md deleted file mode 100644 index 075b207ee2..0000000000 --- a/docs/_posts/2020-07-21-dns_record_changed.md +++ /dev/null @@ -1,183 +0,0 @@ ---- -title: "DNS record changed" -excerpt: "DNS -" -categories: - - Deprecated -last_modified_at: 2020-07-21 -toc: true -toc_label: "" -tags: - - DNS - - Command And Control - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Network_Resolution ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The search takes the DNS records and their answers results of the discovered_dns_records lookup and finds if any records have changed by searching DNS response from the Network_Resolution datamodel across the last day. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Network_Resolution](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkResolution) -- **Last Updated**: 2020-07-21 -- **Author**: Jose Hernandez, Splunk -- **ID**: 44d3a43e-dcd5-49f7-8356-5209bb369065 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1071.004](https://attack.mitre.org/techniques/T1071/004/) | DNS | Command And Control | - -
-
- - -
- Kill Chain Phase - -
- -* Command & Control - - -
-
- - -
- NIST - -
- -* ID.AM -* PR.DS -* PR.IP -* DE.AE -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 1 -* CIS 3 -* CIS 8 -* CIS 12 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| inputlookup discovered_dns_records -| rename answer as discovered_answer -| join domain[ -|tstats `security_content_summariesonly` count values(DNS.record_type) as type, values(DNS.answer) as current_answer values(DNS.src) as src from datamodel=Network_Resolution where DNS.message_type=RESPONSE DNS.answer!="unknown" DNS.answer!="" by DNS.query -| rename DNS.query as query -| where query!="unknown" -| rex field=query "(?\w+\.\w+?)(?:$ -|/)"] -| makemv delim=" " answer -| makemv delim=" " type -| sort -count -| table count,src,domain,type,query,current_answer,discovered_answer -| makemv current_answer -| mvexpand current_answer -| makemv discovered_answer -| eval n=mvfind(discovered_answer, current_answer) -| where isnull(n) -| `dns_record_changed_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **dns_record_changed_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Lookups -The SPL above uses the following Lookups: - -* [discovered_dns_records](https://github.com/splunk/security_content/blob/develop/lookups/discovered_dns_records.yml) with [data](https://github.com/splunk/security_content/tree/develop/lookups/discovered_dns_records.csv) - -#### Required field -* _time -* DNS.record_type -* DNS.answer -* DNS.src -* DNS.message_type -* DNS.query - - -#### How To Implement -To successfully implement this search you will need to ensure that DNS data is populating the `Network_Resolution` data model. It also requires that the `discover_dns_record` lookup table be populated by the included support search "Discover DNS record". \ - **Splunk>Phantom Playbook Integration**\ -If Splunk>Phantom is also configured in your environment, a Playbook called "DNS Hijack Enrichment" can be configured to run when any results are found by this detection search. The playbook takes in the DNS record changed and uses Geoip, whois, Censys and PassiveTotal to detect if DNS issuers changed. To use this integration, install the Phantom App for Splunk `https://splunkbase.splunk.com/app/3411/`, add the correct hostname to the "Phantom Instance" field in the Adaptive Response Actions when configuring this detection search, and set the corresponding Playbook to active. \ -(Playbook Link:`https://my.phantom.us/4.2/playbook/dns-hijack-enrichment/`).\ - - -#### Known False Positives -Legitimate DNS changes can be detected in this search. Investigate, verify and update the list of provided current answers for the domains in question as appropriate. - -#### Associated Analytic story -* [DNS Hijacking](/stories/dns_hijacking) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/dns_record_changed.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2020-07-21-ec2_instance_modified_with_previously_unseen_user.md b/docs/_posts/2020-07-21-ec2_instance_modified_with_previously_unseen_user.md deleted file mode 100644 index be6ba9b32f..0000000000 --- a/docs/_posts/2020-07-21-ec2_instance_modified_with_previously_unseen_user.md +++ /dev/null @@ -1,171 +0,0 @@ ---- -title: "EC2 Instance Modified With Previously Unseen User" -excerpt: "Cloud Accounts -" -categories: - - Deprecated -last_modified_at: 2020-07-21 -toc: true -toc_label: "" -tags: - - Cloud Accounts - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for EC2 instances being modified by users who have not previously modified them. This search is deprecated and have been translated to use the latest Change Datamodel. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-07-21 -- **Author**: David Dorsey, Splunk -- **ID**: 56f91724-cf3f-4666-84e1-e3712fb41e76 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1078.004](https://attack.mitre.org/techniques/T1078/004/) | Cloud Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* ID.AM - - - -
-
- -
- CIS20 - -
- -* CIS 1 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cloudtrail` `ec2_modification_api_calls` [search `cloudtrail` `ec2_modification_api_calls` errorCode=success -| stats earliest(_time) as firstTime latest(_time) as lastTime by userIdentity.arn -| rename userIdentity.arn as arn -| inputlookup append=t previously_seen_ec2_modifications_by_user -| stats min(firstTime) as firstTime, max(lastTime) as lastTime by arn -| outputlookup previously_seen_ec2_modifications_by_user -| eval newUser=if(firstTime >= relative_time(now(), "-70m@m"), 1, 0) -| where newUser=1 -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| rename arn as userIdentity.arn -| table userIdentity.arn] -| spath output=dest responseElements.instancesSet.items{}.instanceId -| spath output=user userIdentity.arn -| table _time, user, dest -| `ec2_instance_modified_with_previously_unseen_user_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) -* [ec2_modification_api_calls](https://github.com/splunk/security_content/blob/develop/macros/ec2_modification_api_calls.yml) - -> :information_source: -> **ec2_instance_modified_with_previously_unseen_user_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Lookups -The SPL above uses the following Lookups: - -* [previously_seen_ec2_modifications_by_user](https://github.com/splunk/security_content/blob/develop/lookups/previously_seen_ec2_modifications_by_user.yml) with [data](https://github.com/splunk/security_content/tree/develop/lookups/previously_seen_ec2_modifications_by_user.csv) -* [previously_seen_ec2_modifications_by_user](https://github.com/splunk/security_content/blob/develop/lookups/previously_seen_ec2_modifications_by_user.yml) with [data](https://github.com/splunk/security_content/tree/develop/lookups/previously_seen_ec2_modifications_by_user.csv) - -#### Required field -* _time -* errorCode -* userIdentity.arn - - -#### How To Implement -You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your AWS CloudTrail inputs. This search works best when you run the "Previously Seen EC2 Launches By User" support search once to create a history of previously seen ARNs. To add or remove APIs that modify an EC2 instance, edit the macro `ec2_modification_api_calls`. - -#### Known False Positives -It's possible that a new user will start to modify EC2 instances when they haven't before for any number of reasons. Verify with the user that is modifying instances that this is the intended behavior. - -#### Associated Analytic story -* [Unusual AWS EC2 Modifications](/stories/unusual_aws_ec2_modifications) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2020-07-21-ec2_instance_started_with_previously_unseen_user.md b/docs/_posts/2020-07-21-ec2_instance_started_with_previously_unseen_user.md deleted file mode 100644 index a779faf335..0000000000 --- a/docs/_posts/2020-07-21-ec2_instance_started_with_previously_unseen_user.md +++ /dev/null @@ -1,165 +0,0 @@ ---- -title: "EC2 Instance Started With Previously Unseen User" -excerpt: "Cloud Accounts -" -categories: - - Deprecated -last_modified_at: 2020-07-21 -toc: true -toc_label: "" -tags: - - Cloud Accounts - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for EC2 instances being created by users who have not created them before. This search is deprecated and have been translated to use the latest Change Datamodel. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-07-21 -- **Author**: David Dorsey, Splunk -- **ID**: 22773e84-bac0-4595-b086-20d3f735b4f1 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1078.004](https://attack.mitre.org/techniques/T1078/004/) | Cloud Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* ID.AM - - - -
-
- -
- CIS20 - -
- -* CIS 1 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cloudtrail` eventName=RunInstances [search `cloudtrail` eventName=RunInstances errorCode=success -| stats earliest(_time) as firstTime latest(_time) as lastTime by userIdentity.arn -| rename userIdentity.arn as arn -| inputlookup append=t previously_seen_ec2_launches_by_user.csv -| stats min(firstTime) as firstTime, max(lastTime) as lastTime by arn -| outputlookup previously_seen_ec2_launches_by_user.csv -| eval newUser=if(firstTime >= relative_time(now(), "-70m@m"), 1, 0) -| where newUser=1 -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| rename arn as userIdentity.arn -| table userIdentity.arn] -| rename requestParameters.instanceType as instanceType, responseElements.instancesSet.items{}.instanceId as dest, userIdentity.arn as user -| table _time, user, dest, instanceType -| `ec2_instance_started_with_previously_unseen_user_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) - -> :information_source: -> **ec2_instance_started_with_previously_unseen_user_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* eventName -* errorCode -* userIdentity.arn - - -#### How To Implement -You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your AWS CloudTrail inputs. This search works best when you run the "Previously Seen EC2 Launches By User" support search once to create a history of previously seen ARNs. - -#### Known False Positives -It's possible that a user will start to create EC2 instances when they haven't before for any number of reasons. Verify with the user that is launching instances that this is the intended behavior. - -#### Associated Analytic story -* [AWS Cryptomining](/stories/aws_cryptomining) -* [Suspicious AWS EC2 Activities](/stories/suspicious_aws_ec2_activities) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2020-07-21-email_files_written_outside_of_the_outlook_directory.md b/docs/_posts/2020-07-21-email_files_written_outside_of_the_outlook_directory.md deleted file mode 100644 index 602677cc95..0000000000 --- a/docs/_posts/2020-07-21-email_files_written_outside_of_the_outlook_directory.md +++ /dev/null @@ -1,160 +0,0 @@ ---- -title: "Email files written outside of the Outlook directory" -excerpt: "Email Collection -, Local Email Collection -" -categories: - - Application -last_modified_at: 2020-07-21 -toc: true -toc_label: "" -tags: - - Email Collection - - Local Email Collection - - Collection - - Collection - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The search looks at the change-analysis data model and detects email files created outside the normal Outlook directory. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2020-07-21 -- **Author**: Bhavin Patel, Splunk -- **ID**: 8d52cf03-ba25-4101-aa78-07994aed4f74 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1114](https://attack.mitre.org/techniques/T1114/) | Email Collection | Collection | - -| [T1114.001](https://attack.mitre.org/techniques/T1114/001/) | Local Email Collection | Collection | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count values(Filesystem.file_path) as file_path min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Filesystem where (Filesystem.file_name=*.pst OR Filesystem.file_name=*.ost) Filesystem.file_path != "C:\\Users\\*\\My Documents\\Outlook Files\\*" Filesystem.file_path!="C:\\Users\\*\\AppData\\Local\\Microsoft\\Outlook*" by Filesystem.action Filesystem.process_id Filesystem.file_name Filesystem.dest -| `drop_dm_object_name("Filesystem")` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `email_files_written_outside_of_the_outlook_directory_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **email_files_written_outside_of_the_outlook_directory_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Filesystem.file_path -* Filesystem.file_name -* Filesystem.action -* Filesystem.process_id -* Filesystem.dest - - -#### How To Implement -To successfully implement this search, you must be ingesting data that records the file-system activity from your hosts to populate the Endpoint.Filesystem data model node. This is typically populated via endpoint detection-and-response product, such as Carbon Black, or by other endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report file-system reads and writes. - -#### Known False Positives -Administrators and users sometimes prefer backing up their email data by moving the email files into a different folder. These attempts will be detected by the search. - -#### Associated Analytic story -* [Collection and Staging](/stories/collection_and_staging) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/application/email_files_written_outside_of_the_outlook_directory.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2020-07-21-email_servers_sending_high_volume_traffic_to_hosts.md b/docs/_posts/2020-07-21-email_servers_sending_high_volume_traffic_to_hosts.md deleted file mode 100644 index 4d71eec0cf..0000000000 --- a/docs/_posts/2020-07-21-email_servers_sending_high_volume_traffic_to_hosts.md +++ /dev/null @@ -1,166 +0,0 @@ ---- -title: "Email servers sending high volume traffic to hosts" -excerpt: "Email Collection -, Remote Email Collection -" -categories: - - Application -last_modified_at: 2020-07-21 -toc: true -toc_label: "" -tags: - - Email Collection - - Remote Email Collection - - Collection - - Collection - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Network_Traffic ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for an increase of data transfers from your email server to your clients. This could be indicative of a malicious actor collecting data using your email server. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Network_Traffic](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkTraffic) -- **Last Updated**: 2020-07-21 -- **Author**: Bhavin Patel, Splunk -- **ID**: 7f5fb3e1-4209-4914-90db-0ec21b556378 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1114](https://attack.mitre.org/techniques/T1114/) | Email Collection | Collection | - -| [T1114.002](https://attack.mitre.org/techniques/T1114/002/) | Remote Email Collection | Collection | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM -* DE.AE - - - -
-
- -
- CIS20 - -
- -* CIS 7 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` sum(All_Traffic.bytes_out) as bytes_out from datamodel=Network_Traffic where All_Traffic.src_category=email_server by All_Traffic.dest_ip _time span=1d -| `drop_dm_object_name("All_Traffic")` -| eventstats avg(bytes_out) as avg_bytes_out stdev(bytes_out) as stdev_bytes_out -| eventstats count as num_data_samples avg(eval(if(_time < relative_time(now(), "@d"), bytes_out, null))) as per_source_avg_bytes_out stdev(eval(if(_time < relative_time(now(), "@d"), bytes_out, null))) as per_source_stdev_bytes_out by dest_ip -| eval minimum_data_samples = 4, deviation_threshold = 3 -| where num_data_samples >= minimum_data_samples AND bytes_out > (avg_bytes_out + (deviation_threshold * stdev_bytes_out)) AND bytes_out > (per_source_avg_bytes_out + (deviation_threshold * per_source_stdev_bytes_out)) AND _time >= relative_time(now(), "@d") -| eval num_standard_deviations_away_from_server_average = round(abs(bytes_out - avg_bytes_out) / stdev_bytes_out, 2), num_standard_deviations_away_from_client_average = round(abs(bytes_out - per_source_avg_bytes_out) / per_source_stdev_bytes_out, 2) -| table dest_ip, _time, bytes_out, avg_bytes_out, per_source_avg_bytes_out, num_standard_deviations_away_from_server_average, num_standard_deviations_away_from_client_average -| `email_servers_sending_high_volume_traffic_to_hosts_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **email_servers_sending_high_volume_traffic_to_hosts_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* All_Traffic.bytes_out -* All_Traffic.src_category -* All_Traffic.dest_ip - - -#### How To Implement -This search requires you to be ingesting your network traffic and populating the Network_Traffic data model. Your email servers must be categorized as "email_server" for the search to work, as well. You may need to adjust the deviation_threshold and minimum_data_samples values based on the network traffic in your environment. The "deviation_threshold" field is a multiplying factor to control how much variation you're willing to tolerate. The "minimum_data_samples" field is the minimum number of connections of data samples required for the statistic to be valid. - -#### Known False Positives -The false-positive rate will vary based on how you set the deviation_threshold and data_samples values. Our recommendation is to adjust these values based on your network traffic to and from your email servers. - -#### Associated Analytic story -* [Collection and Staging](/stories/collection_and_staging) -* [HAFNIUM Group](/stories/hafnium_group) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/application/email_servers_sending_high_volume_traffic_to_hosts.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2020-07-21-excessive_dns_failures.md b/docs/_posts/2020-07-21-excessive_dns_failures.md deleted file mode 100644 index 873bef1137..0000000000 --- a/docs/_posts/2020-07-21-excessive_dns_failures.md +++ /dev/null @@ -1,169 +0,0 @@ ---- -title: "Excessive DNS Failures" -excerpt: "DNS -, Application Layer Protocol -" -categories: - - Network -last_modified_at: 2020-07-21 -toc: true -toc_label: "" -tags: - - DNS - - Application Layer Protocol - - Command And Control - - Command And Control - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Network_Resolution ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search identifies DNS query failures by counting the number of DNS responses that do not indicate success, and trigger on more than 50 occurrences. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Network_Resolution](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkResolution) -- **Last Updated**: 2020-07-21 -- **Author**: Bhavin Patel, Splunk -- **ID**: 104658f4-afdc-499e-9719-17243f9826f1 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1071.004](https://attack.mitre.org/techniques/T1071/004/) | DNS | Command And Control | - -| [T1071](https://attack.mitre.org/techniques/T1071/) | Application Layer Protocol | Command And Control | - -
-
- - -
- Kill Chain Phase - -
- -* Command & Control - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.AE -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 -* CIS 9 -* CIS 12 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count values("DNS.query") as queries from datamodel=Network_Resolution where nodename=DNS "DNS.reply_code"!="No Error" "DNS.reply_code"!="NoError" DNS.reply_code!="unknown" NOT "DNS.query"="*.arpa" "DNS.query"="*.*" by "DNS.src","DNS.query" -| `drop_dm_object_name("DNS")` -| lookup cim_corporate_web_domain_lookup domain as query OUTPUT domain -| where isnull(domain) -| lookup update=true alexa_lookup_by_str domain as query OUTPUT rank -| where isnull(rank) -| stats sum(count) as count mode(queries) as queries by src -| `get_asset(src)` -| where count>50 -| `excessive_dns_failures_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **excessive_dns_failures_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* DNS.query -* DNS.reply_code -* DNS.src - - -#### How To Implement -To successfully implement this search you must ensure that DNS data is populating the Network_Resolution data model. - -#### Known False Positives -It is possible legitimate traffic can trigger this rule. Please investigate as appropriate. The threshold for generating an event can also be customized to better suit your environment. - -#### Associated Analytic story -* [Suspicious DNS Traffic](/stories/suspicious_dns_traffic) -* [Command and Control](/stories/command_and_control) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/network/excessive_dns_failures.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2020-07-21-first_time_seen_command_line_argument.md b/docs/_posts/2020-07-21-first_time_seen_command_line_argument.md deleted file mode 100644 index 29a348aab2..0000000000 --- a/docs/_posts/2020-07-21-first_time_seen_command_line_argument.md +++ /dev/null @@ -1,184 +0,0 @@ ---- -title: "First time seen command line argument" -excerpt: "PowerShell -, Windows Command Shell -" -categories: - - Deprecated -last_modified_at: 2020-07-21 -toc: true -toc_label: "" -tags: - - PowerShell - - Windows Command Shell - - Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for command-line arguments that use a `/c` parameter to execute a command that has not previously been seen. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2020-07-21 -- **Author**: Bhavin Patel, Splunk -- **ID**: a1b6e73f-98d5-470f-99ac-77aacd578473 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | - -| [T1059.003](https://attack.mitre.org/techniques/T1059/003/) | Windows Command Shell | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Command & Control -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM -* PR.IP - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = cmd.exe Processes.process = "* /c *" by Processes.process Processes.process_name Processes.parent_process_name Processes.dest -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| search [ -| tstats `security_content_summariesonly` earliest(_time) as firstTime latest(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = cmd.exe Processes.process = "* /c *" by Processes.process -| `drop_dm_object_name(Processes)` -| inputlookup append=t previously_seen_cmd_line_arguments -| stats min(firstTime) as firstTime, max(lastTime) as lastTime by process -| outputlookup previously_seen_cmd_line_arguments -| eval newCmdLineArgument=if(firstTime >= relative_time(now(), "-70m@m"), 1, 0) -| where newCmdLineArgument=1 -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| table process] -| `first_time_seen_command_line_argument_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **first_time_seen_command_line_argument_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Lookups -The SPL above uses the following Lookups: - -* [previously_seen_cmd_line_arguments](https://github.com/splunk/security_content/blob/develop/lookups/previously_seen_cmd_line_arguments.yml) with [data](https://github.com/splunk/security_content/tree/develop/lookups/previously_seen_cmd_line_arguments.csv) -* [previously_seen_cmd_line_arguments](https://github.com/splunk/security_content/blob/develop/lookups/previously_seen_cmd_line_arguments.yml) with [data](https://github.com/splunk/security_content/tree/develop/lookups/previously_seen_cmd_line_arguments.csv) - -#### Required field -* _time -* Processes.process_name -* Processes.process -* Processes.parent_process_name -* Processes.dest - - -#### How To Implement -You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must be ingesting logs with both the process name and command line from your endpoints. The complete process name with command-line arguments are mapped to the "process" field in the Endpoint data model. Please make sure you run the support search "Previously seen command line arguments,"—which creates a lookup file called `previously_seen_cmd_line_arguments.csv`—a historical baseline of all command-line arguments. You must also validate this list. For the search to do accurate calculation, ensure the search scheduling is the same value as the `relative_time` evaluation function. - -#### Known False Positives -Legitimate programs can also use command-line arguments to execute. Please verify the command-line arguments to check what command/program is being executed. We recommend customizing the `first_time_seen_cmd_line_filter` macro to exclude legitimate parent_process_name - -#### Associated Analytic story -* [DHS Report TA18-074A](/stories/dhs_report_ta18-074a) -* [Suspicious Command-Line Executions](/stories/suspicious_command-line_executions) -* [Orangeworm Attack Group](/stories/orangeworm_attack_group) -* [Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns](/stories/possible_backdoor_activity_associated_with_mudcarp_espionage_campaigns) -* [Hidden Cobra Malware](/stories/hidden_cobra_malware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/first_time_seen_command_line_argument.yml) \| *version*: **5** \ No newline at end of file diff --git a/docs/_posts/2020-07-21-first_time_seen_running_windows_service.md b/docs/_posts/2020-07-21-first_time_seen_running_windows_service.md deleted file mode 100644 index 97977c0cfd..0000000000 --- a/docs/_posts/2020-07-21-first_time_seen_running_windows_service.md +++ /dev/null @@ -1,172 +0,0 @@ ---- -title: "First Time Seen Running Windows Service" -excerpt: "System Services -, Service Execution -" -categories: - - Endpoint -last_modified_at: 2020-07-21 -toc: true -toc_label: "" -tags: - - System Services - - Service Execution - - Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for the first and last time a Windows service is seen running in your environment. This table is then cached. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-07-21 -- **Author**: David Dorsey, Splunk -- **ID**: 823136f2-d755-4b6d-ae04-372b486a5808 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1569](https://attack.mitre.org/techniques/T1569/) | System Services | Execution | - -| [T1569.002](https://attack.mitre.org/techniques/T1569/002/) | Service Execution | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Installation -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* ID.AM -* PR.DS -* PR.AC -* DE.AE - - - -
-
- -
- CIS20 - -
- -* CIS 2 -* CIS 9 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`wineventlog_system` EventCode=7036 -| rex field=Message "The (?[-\(\)\s\w]+) service entered the (?\w+) state" -| where state="running" -| lookup previously_seen_running_windows_services service as service OUTPUT firstTimeSeen -| where isnull(firstTimeSeen) OR firstTimeSeen > relative_time(now(), `previously_seen_windows_services_window`) -| table _time dest service -| `first_time_seen_running_windows_service_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [previously_seen_windows_services_window](https://github.com/splunk/security_content/blob/develop/macros/previously_seen_windows_services_window.yml) -* [wineventlog_system](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_system.yml) - -> :information_source: -> **first_time_seen_running_windows_service_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Lookups -The SPL above uses the following Lookups: - -* [previously_seen_running_windows_services](https://github.com/splunk/security_content/blob/develop/lookups/previously_seen_running_windows_services.yml) with [data](https://github.com/splunk/security_content/tree/develop/lookups/previously_seen_running_windows_services.csv) - -#### Required field -* _time -* EventCode -* Message -* dest - - -#### How To Implement -While this search does not require you to adhere to Splunk CIM, you must be ingesting your Windows system event logs in order for this search to execute successfully. You should run the baseline search `Previously Seen Running Windows Services - Initial` to build the initial table of child processes and hostnames for this search to work. You should also schedule at the same interval as this search the second baseline search `Previously Seen Running Windows Services - Update` to keep this table up to date and to age out old Windows Services. Please update the `previously_seen_windows_services_window` macro to adjust the time window. Please ensure that the Splunk Add-on for Microsoft Windows is version 8.0.0 or above. - -#### Known False Positives -A previously unseen service is not necessarily malicious. Verify that the service is legitimate and that was installed by a legitimate process. - -#### Associated Analytic story -* [Windows Service Abuse](/stories/windows_service_abuse) -* [Orangeworm Attack Group](/stories/orangeworm_attack_group) -* [NOBELIUM Group](/stories/nobelium_group) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/endpoint/first_time_seen_running_windows_service.yml) \| *version*: **4** \ No newline at end of file diff --git a/docs/_posts/2020-07-21-hiding_files_and_directories_with_attrib_exe.md b/docs/_posts/2020-07-21-hiding_files_and_directories_with_attrib_exe.md deleted file mode 100644 index ee2f30531a..0000000000 --- a/docs/_posts/2020-07-21-hiding_files_and_directories_with_attrib_exe.md +++ /dev/null @@ -1,165 +0,0 @@ ---- -title: "Hiding Files And Directories With Attrib exe" -excerpt: "File and Directory Permissions Modification -, Windows File and Directory Permissions Modification -" -categories: - - Endpoint -last_modified_at: 2020-07-21 -toc: true -toc_label: "" -tags: - - File and Directory Permissions Modification - - Windows File and Directory Permissions Modification - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -Attackers leverage an existing Windows binary, attrib.exe, to mark specific as hidden by using specific flags so that the victim does not see the file. The search looks for specific command-line arguments to detect the use of attrib.exe to hide files. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2020-07-21 -- **Author**: Bhavin Patel, Splunk -- **ID**: 6e5a3ae4-90a3-462d-9aa6-0119f638c0f1 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1222](https://attack.mitre.org/techniques/T1222/) | File and Directory Permissions Modification | Defense Evasion | - -| [T1222.001](https://attack.mitre.org/techniques/T1222/001/) | Windows File and Directory Permissions Modification | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) values(Processes.process) as process max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=attrib.exe (Processes.process=*+h*) by Processes.parent_process Processes.process_name Processes.user Processes.dest -| `drop_dm_object_name("Processes")` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -| `hiding_files_and_directories_with_attrib_exe_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **hiding_files_and_directories_with_attrib_exe_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process -* Processes.process_name -* Processes.parent_process -* Processes.user -* Processes.dest - - -#### How To Implement -You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. - -#### Known False Positives -Some applications and users may legitimately use attrib.exe to interact with the files. - -#### Associated Analytic story -* [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics) -* [Windows Persistence Techniques](/stories/windows_persistence_techniques) -* [Azorult](/stories/azorult) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 72.0 | 90 | 80 | Attrib.exe with +h flag to hide files on $dest$ executed by $user$ is detected. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.001/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.001/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml) \| *version*: **4** \ No newline at end of file diff --git a/docs/_posts/2020-07-21-hosts_receiving_high_volume_of_network_traffic_from_email_server.md b/docs/_posts/2020-07-21-hosts_receiving_high_volume_of_network_traffic_from_email_server.md deleted file mode 100644 index ef0ed5756f..0000000000 --- a/docs/_posts/2020-07-21-hosts_receiving_high_volume_of_network_traffic_from_email_server.md +++ /dev/null @@ -1,165 +0,0 @@ ---- -title: "Hosts receiving high volume of network traffic from email server" -excerpt: "Remote Email Collection -, Email Collection -" -categories: - - Network -last_modified_at: 2020-07-21 -toc: true -toc_label: "" -tags: - - Remote Email Collection - - Email Collection - - Collection - - Collection - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Network_Traffic ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for an increase of data transfers from your email server to your clients. This could be indicative of a malicious actor collecting data using your email server. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Network_Traffic](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkTraffic) -- **Last Updated**: 2020-07-21 -- **Author**: Bhavin Patel, Splunk -- **ID**: 7f5fb3e1-4209-4914-90db-0ec21b556368 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1114.002](https://attack.mitre.org/techniques/T1114/002/) | Remote Email Collection | Collection | - -| [T1114](https://attack.mitre.org/techniques/T1114/) | Email Collection | Collection | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM -* DE.AE - - - -
-
- -
- CIS20 - -
- -* CIS 7 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` sum(All_Traffic.bytes_in) as bytes_in from datamodel=Network_Traffic where All_Traffic.dest_category=email_server by All_Traffic.src_ip _time span=1d -| `drop_dm_object_name("All_Traffic")` -| eventstats avg(bytes_in) as avg_bytes_in stdev(bytes_in) as stdev_bytes_in -| eventstats count as num_data_samples avg(eval(if(_time < relative_time(now(), "@d"), bytes_in, null))) as per_source_avg_bytes_in stdev(eval(if(_time < relative_time(now(), "@d"), bytes_in, null))) as per_source_stdev_bytes_in by src_ip -| eval minimum_data_samples = 4, deviation_threshold = 3 -| where num_data_samples >= minimum_data_samples AND bytes_in > (avg_bytes_in + (deviation_threshold * stdev_bytes_in)) AND bytes_in > (per_source_avg_bytes_in + (deviation_threshold * per_source_stdev_bytes_in)) AND _time >= relative_time(now(), "@d") -| eval num_standard_deviations_away_from_server_average = round(abs(bytes_in - avg_bytes_in) / stdev_bytes_in, 2), num_standard_deviations_away_from_client_average = round(abs(bytes_in - per_source_avg_bytes_in) / per_source_stdev_bytes_in, 2) -| table src_ip, _time, bytes_in, avg_bytes_in, per_source_avg_bytes_in, num_standard_deviations_away_from_server_average, num_standard_deviations_away_from_client_average -| `hosts_receiving_high_volume_of_network_traffic_from_email_server_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **hosts_receiving_high_volume_of_network_traffic_from_email_server_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* All_Traffic.bytes_in -* All_Traffic.dest_category -* All_Traffic.src_ip - - -#### How To Implement -This search requires you to be ingesting your network traffic and populating the Network_Traffic data model. Your email servers must be categorized as "email_server" for the search to work, as well. You may need to adjust the deviation_threshold and minimum_data_samples values based on the network traffic in your environment. The "deviation_threshold" field is a multiplying factor to control how much variation you're willing to tolerate. The "minimum_data_samples" field is the minimum number of connections of data samples required for the statistic to be valid. - -#### Known False Positives -The false-positive rate will vary based on how you set the deviation_threshold and data_samples values. Our recommendation is to adjust these values based on your network traffic to and from your email servers. - -#### Associated Analytic story -* [Collection and Staging](/stories/collection_and_staging) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/network/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2020-07-21-malicious_powershell_process_-_execution_policy_bypass.md b/docs/_posts/2020-07-21-malicious_powershell_process_-_execution_policy_bypass.md deleted file mode 100644 index 6ae13fd45b..0000000000 --- a/docs/_posts/2020-07-21-malicious_powershell_process_-_execution_policy_bypass.md +++ /dev/null @@ -1,177 +0,0 @@ ---- -title: "Malicious PowerShell Process - Execution Policy Bypass" -excerpt: "Command and Scripting Interpreter -, PowerShell -" -categories: - - Endpoint -last_modified_at: 2020-07-21 -toc: true -toc_label: "" -tags: - - Command and Scripting Interpreter - - PowerShell - - Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for PowerShell processes started with parameters used to bypass the local execution policy for scripts. These parameters are often observed in attacks leveraging PowerShell scripts as they override the default PowerShell execution policy. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2020-07-21 -- **Author**: Rico Valdez, Mauricio Velazco, Splunk -- **ID**: 9be56c82-b1cc-4318-87eb-d138afaaca39 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -| [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Command & Control -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM -* PR.IP - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 7 -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` values(Processes.process_id) as process_id, values(Processes.parent_process_id) as parent_process_id values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_powershell` (Processes.process="* -ex*" OR Processes.process="* bypass *") by Processes.process_id, Processes.user, Processes.dest -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `malicious_powershell_process___execution_policy_bypass_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml) - -> :information_source: -> **malicious_powershell_process_-_execution_policy_bypass_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -There may be legitimate reasons to bypass the PowerShell execution policy. The PowerShell script being run with this parameter should be validated to ensure that it is legitimate. - -#### Associated Analytic story -* [DHS Report TA18-074A](/stories/dhs_report_ta18-074a) -* [HAFNIUM Group](/stories/hafnium_group) -* [DarkCrystal RAT](/stories/darkcrystal_rat) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 42.0 | 70 | 60 | PowerShell local execution policy bypass attempt on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/encoded_powershell/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/encoded_powershell/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml) \| *version*: **5** \ No newline at end of file diff --git a/docs/_posts/2020-07-21-multiple_okta_users_with_invalid_credentials_from_the_same_ip.md b/docs/_posts/2020-07-21-multiple_okta_users_with_invalid_credentials_from_the_same_ip.md deleted file mode 100644 index ca52418ecb..0000000000 --- a/docs/_posts/2020-07-21-multiple_okta_users_with_invalid_credentials_from_the_same_ip.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: "Multiple Okta Users With Invalid Credentials From The Same IP" -excerpt: "Valid Accounts -, Default Accounts -" -categories: - - Application -last_modified_at: 2020-07-21 -toc: true -toc_label: "" -tags: - - Valid Accounts - - Default Accounts - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search detects Okta login failures due to bad credentials for multiple users originating from the same ip address. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-07-21 -- **Author**: Rico Valdez, Splunk -- **ID**: 19cba45f-cad3-4032-8911-0c09e0444552 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -| [T1078.001](https://attack.mitre.org/techniques/T1078/001/) | Default Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`okta` outcome.reason=INVALID_CREDENTIALS -| rename client.geographicalContext.country as country, client.geographicalContext.state as state, client.geographicalContext.city as city -| stats min(_time) as firstTime max(_time) as lastTime dc(user) as distinct_users values(user) as users by src_ip, displayMessage, outcome.reason, country, state, city -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| search distinct_users > 5 -| `multiple_okta_users_with_invalid_credentials_from_the_same_ip_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [okta](https://github.com/splunk/security_content/blob/develop/macros/okta.yml) - -> :information_source: -> **multiple_okta_users_with_invalid_credentials_from_the_same_ip_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* outcome.reason -* client.geographicalContext.country -* client.geographicalContext.state -* client.geographicalContext.city -* user -* src_ip -* displayMessage - - -#### How To Implement -This search is specific to Okta and requires Okta logs are being ingested in your Splunk deployment. - -#### Known False Positives -A single public IP address servicing multiple legitmate users may trigger this search. In addition, the threshold of 5 distinct users may be too low for your needs. You may modify the included filter macro `multiple_okta_users_with_invalid_credentials_from_the_same_ip_filter` to raise the threshold or except specific IP adresses from triggering this search. - -#### Associated Analytic story -* [Suspicious Okta Activity](/stories/suspicious_okta_activity) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/application/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2020-07-21-okta_account_lockout_events.md b/docs/_posts/2020-07-21-okta_account_lockout_events.md deleted file mode 100644 index 3e61a87988..0000000000 --- a/docs/_posts/2020-07-21-okta_account_lockout_events.md +++ /dev/null @@ -1,163 +0,0 @@ ---- -title: "Okta Account Lockout Events" -excerpt: "Valid Accounts -, Default Accounts -" -categories: - - Application -last_modified_at: 2020-07-21 -toc: true -toc_label: "" -tags: - - Valid Accounts - - Default Accounts - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -Detect Okta user lockout events - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-07-21 -- **Author**: Rico Valdez, Splunk -- **ID**: 62b70968-a0a5-4724-8ac4-67871e6f544d - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -| [T1078.001](https://attack.mitre.org/techniques/T1078/001/) | Default Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`okta` displayMessage="Max sign in attempts exceeded" -| rename client.geographicalContext.country as country, client.geographicalContext.state as state, client.geographicalContext.city as city -| table _time, user, country, state, city, src_ip -| `okta_account_lockout_events_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [okta](https://github.com/splunk/security_content/blob/develop/macros/okta.yml) - -> :information_source: -> **okta_account_lockout_events_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* displayMessage -* client.geographicalContext.country -* client.geographicalContext.state -* client.geographicalContext.city - - -#### How To Implement -This search is specific to Okta and requires Okta logs are being ingested in your Splunk deployment. - -#### Known False Positives -None. Account lockouts should be followed up on to determine if the actual user was the one who caused the lockout, or if it was an unauthorized actor. - -#### Associated Analytic story -* [Suspicious Okta Activity](/stories/suspicious_okta_activity) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/application/okta_account_lockout_events.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2020-07-21-okta_failed_sso_attempts.md b/docs/_posts/2020-07-21-okta_failed_sso_attempts.md deleted file mode 100644 index 6df573f907..0000000000 --- a/docs/_posts/2020-07-21-okta_failed_sso_attempts.md +++ /dev/null @@ -1,166 +0,0 @@ ---- -title: "Okta Failed SSO Attempts" -excerpt: "Valid Accounts -, Default Accounts -" -categories: - - Application -last_modified_at: 2020-07-21 -toc: true -toc_label: "" -tags: - - Valid Accounts - - Default Accounts - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -Detect failed Okta SSO events - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-07-21 -- **Author**: Rico Valdez, Splunk -- **ID**: 371a6545-2618-4032-ad84-93386b8698c5 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -| [T1078.001](https://attack.mitre.org/techniques/T1078/001/) | Default Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`okta` displayMessage="User attempted unauthorized access to app" -| stats min(_time) as firstTime max(_time) as lastTime values(app) as Apps count by user, result ,displayMessage, src_ip -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `okta_failed_sso_attempts_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [okta](https://github.com/splunk/security_content/blob/develop/macros/okta.yml) - -> :information_source: -> **okta_failed_sso_attempts_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* displayMessage -* app -* user -* result -* src_ip - - -#### How To Implement -This search is specific to Okta and requires Okta logs are being ingested in your Splunk deployment. - -#### Known False Positives -There may be a faulty config preventing legitmate users from accessing apps they should have access to. - -#### Associated Analytic story -* [Suspicious Okta Activity](/stories/suspicious_okta_activity) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/application/okta_failed_sso_attempts.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2020-07-21-okta_user_logins_from_multiple_cities.md b/docs/_posts/2020-07-21-okta_user_logins_from_multiple_cities.md deleted file mode 100644 index b931e0738d..0000000000 --- a/docs/_posts/2020-07-21-okta_user_logins_from_multiple_cities.md +++ /dev/null @@ -1,166 +0,0 @@ ---- -title: "Okta User Logins From Multiple Cities" -excerpt: "Valid Accounts -, Default Accounts -" -categories: - - Application -last_modified_at: 2020-07-21 -toc: true -toc_label: "" -tags: - - Valid Accounts - - Default Accounts - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search detects logins from the same user from different cities in a 24 hour period. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-07-21 -- **Author**: Rico Valdez, Splunk -- **ID**: 7594fa07-9f34-4d01-81cc-d6af6a5db9e8 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -| [T1078.001](https://attack.mitre.org/techniques/T1078/001/) | Default Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`okta` displayMessage="User login to Okta" client.geographicalContext.city!=null -| stats min(_time) as firstTime max(_time) as lastTime dc(client.geographicalContext.city) as locations values(client.geographicalContext.city) as cities values(client.geographicalContext.state) as states by user -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `okta_user_logins_from_multiple_cities_filter` -| search locations > 1 -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [okta](https://github.com/splunk/security_content/blob/develop/macros/okta.yml) - -> :information_source: -> **okta_user_logins_from_multiple_cities_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* displayMessage -* client.geographicalContext.city -* client.geographicalContext.state -* user - - -#### How To Implement -This search is specific to Okta and requires Okta logs are being ingested in your Splunk deployment. - -#### Known False Positives -Users in your enviornment may legitmately be travelling and loggin in from different locations. This search is useful for those users that should *not* be travelling for some reason, such as the COVID-19 pandemic. The search also relies on the geographical information being populated in the Okta logs. It is also possible that a connection from another region may be attributed to a login from a remote VPN endpoint. - -#### Associated Analytic story -* [Suspicious Okta Activity](/stories/suspicious_okta_activity) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/application/okta_user_logins_from_multiple_cities.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2020-07-21-overwriting_accessibility_binaries.md b/docs/_posts/2020-07-21-overwriting_accessibility_binaries.md deleted file mode 100644 index 3d3a23142f..0000000000 --- a/docs/_posts/2020-07-21-overwriting_accessibility_binaries.md +++ /dev/null @@ -1,166 +0,0 @@ ---- -title: "Overwriting Accessibility Binaries" -excerpt: "Event Triggered Execution -, Accessibility Features -" -categories: - - Endpoint -last_modified_at: 2020-07-21 -toc: true -toc_label: "" -tags: - - Event Triggered Execution - - Accessibility Features - - Persistence - - Privilege Escalation - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -Microsoft Windows contains accessibility features that can be launched with a key combination before a user has logged in. An adversary can modify or replace these programs so they can get a command prompt or backdoor without logging in to the system. This search looks for modifications to these binaries. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2020-07-21 -- **Author**: David Dorsey, Splunk -- **ID**: 13c2f6c3-10c5-4deb-9ba1-7c4460ebe4ae - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1546](https://attack.mitre.org/techniques/T1546/) | Event Triggered Execution | Persistence, Privilege Escalation | - -| [T1546.008](https://attack.mitre.org/techniques/T1546/008/) | Accessibility Features | Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Filesystem.user) as user values(Filesystem.dest) as dest values(Filesystem.file_path) as file_path from datamodel=Endpoint.Filesystem where (Filesystem.file_path=*\\Windows\\System32\\sethc.exe* OR Filesystem.file_path=*\\Windows\\System32\\utilman.exe* OR Filesystem.file_path=*\\Windows\\System32\\osk.exe* OR Filesystem.file_path=*\\Windows\\System32\\Magnify.exe* OR Filesystem.file_path=*\\Windows\\System32\\Narrator.exe* OR Filesystem.file_path=*\\Windows\\System32\\DisplaySwitch.exe* OR Filesystem.file_path=*\\Windows\\System32\\AtBroker.exe*) by Filesystem.file_name Filesystem.dest -| `drop_dm_object_name(Filesystem)` -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `overwriting_accessibility_binaries_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **overwriting_accessibility_binaries_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Filesystem.dest -* Filesystem.file_path -* Filesystem.file_name -* Filesystem.dest - - -#### How To Implement -You must be ingesting data that records the filesystem activity from your hosts to populate the Endpoint file-system data model node. If you are using Sysmon, you will need a Splunk Universal Forwarder on each endpoint from which you want to collect data. - -#### Known False Positives -Microsoft may provide updates to these binaries. Verify that these changes do not correspond with your normal software update cycle. - -#### Associated Analytic story -* [Windows Privilege Escalation](/stories/windows_privilege_escalation) -* [Hermetic Wiper](/stories/hermetic_wiper) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 72.0 | 80 | 90 | A suspicious file modification or replace in $file_path$ in host $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.008/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.008/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/overwriting_accessibility_binaries.yml) \| *version*: **4** \ No newline at end of file diff --git a/docs/_posts/2020-07-21-prohibited_network_traffic_allowed.md b/docs/_posts/2020-07-21-prohibited_network_traffic_allowed.md deleted file mode 100644 index 631e7a941c..0000000000 --- a/docs/_posts/2020-07-21-prohibited_network_traffic_allowed.md +++ /dev/null @@ -1,163 +0,0 @@ ---- -title: "Prohibited Network Traffic Allowed" -excerpt: "Exfiltration Over Alternative Protocol -" -categories: - - Network -last_modified_at: 2020-07-21 -toc: true -toc_label: "" -tags: - - Exfiltration Over Alternative Protocol - - Exfiltration - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Network_Traffic ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for network traffic defined by port and transport layer protocol in the Enterprise Security lookup table "lookup_interesting_ports", that is marked as prohibited, and has an associated 'allow' action in the Network_Traffic data model. This could be indicative of a misconfigured network device. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Network_Traffic](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkTraffic) -- **Last Updated**: 2020-07-21 -- **Author**: Rico Valdez, Splunk -- **ID**: ce5a0962-849f-4720-a678-753fe6674479 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1048](https://attack.mitre.org/techniques/T1048/) | Exfiltration Over Alternative Protocol | Exfiltration | - -
-
- - -
- Kill Chain Phase - -
- -* Delivery -* Command & Control - - -
-
- - -
- NIST - -
- -* DE.AE -* PR.AC - - - -
-
- -
- CIS20 - -
- -* CIS 9 -* CIS 12 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Network_Traffic where All_Traffic.action = allowed by All_Traffic.src_ip All_Traffic.dest_ip All_Traffic.dest_port All_Traffic.action -| lookup update=true interesting_ports_lookup dest_port as All_Traffic.dest_port OUTPUT app is_prohibited note transport -| search is_prohibited=true -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `drop_dm_object_name("All_Traffic")` -| `prohibited_network_traffic_allowed_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **prohibited_network_traffic_allowed_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* All_Traffic.action -* All_Traffic.src_ip -* All_Traffic.dest_ip -* All_Traffic.dest_port - - -#### How To Implement -In order to properly run this search, Splunk needs to ingest data from firewalls or other network control devices that mediate the traffic allowed into an environment. This is necessary so that the search can identify an 'action' taken on the traffic of interest. The search requires the Network_Traffic data model be populated. - -#### Known False Positives -None identified - -#### Associated Analytic story -* [Prohibited Traffic Allowed or Protocol Mismatch](/stories/prohibited_traffic_allowed_or_protocol_mismatch) -* [Ransomware](/stories/ransomware) -* [Command and Control](/stories/command_and_control) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/network/prohibited_network_traffic_allowed.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2020-07-21-protocol_or_port_mismatch.md b/docs/_posts/2020-07-21-protocol_or_port_mismatch.md deleted file mode 100644 index 2a83d0b689..0000000000 --- a/docs/_posts/2020-07-21-protocol_or_port_mismatch.md +++ /dev/null @@ -1,164 +0,0 @@ ---- -title: "Protocol or Port Mismatch" -excerpt: "Exfiltration Over Unencrypted Non-C2 Protocol -, Exfiltration Over Alternative Protocol -" -categories: - - Network -last_modified_at: 2020-07-21 -toc: true -toc_label: "" -tags: - - Exfiltration Over Unencrypted Non-C2 Protocol - - Exfiltration Over Alternative Protocol - - Exfiltration - - Exfiltration - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Network_Traffic ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for network traffic on common ports where a higher layer protocol does not match the port that is being used. For example, this search should identify cases where protocols other than HTTP are running on TCP port 80. This can be used by attackers to circumvent firewall restrictions, or as an attempt to hide malicious communications over ports and protocols that are typically allowed and not well inspected. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Network_Traffic](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkTraffic) -- **Last Updated**: 2020-07-21 -- **Author**: Rico Valdez, Splunk -- **ID**: 54dc1265-2f74-4b6d-b30d-49eb506a31b3 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1048.003](https://attack.mitre.org/techniques/T1048/003/) | Exfiltration Over Unencrypted Non-C2 Protocol | Exfiltration | - -| [T1048](https://attack.mitre.org/techniques/T1048/) | Exfiltration Over Alternative Protocol | Exfiltration | - -
-
- - -
- Kill Chain Phase - -
- -* Command & Control - - -
-
- - -
- NIST - -
- -* DE.AE -* PR.AC - - - -
-
- -
- CIS20 - -
- -* CIS 9 -* CIS 12 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Network_Traffic where (All_Traffic.app=dns NOT All_Traffic.dest_port=53) OR ((All_Traffic.app=web-browsing OR All_Traffic.app=http) NOT (All_Traffic.dest_port=80 OR All_Traffic.dest_port=8080 OR All_Traffic.dest_port=8000)) OR (All_Traffic.app=ssl NOT (All_Traffic.dest_port=443 OR All_Traffic.dest_port=8443)) OR (All_Traffic.app=smtp NOT All_Traffic.dest_port=25) by All_Traffic.src_ip, All_Traffic.dest_ip, All_Traffic.app, All_Traffic.dest_port -|`security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `drop_dm_object_name("All_Traffic")` -| `protocol_or_port_mismatch_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **protocol_or_port_mismatch_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* All_Traffic.app -* All_Traffic.dest_port -* All_Traffic.src_ip -* All_Traffic.dest_ip - - -#### How To Implement -Running this search properly requires a technology that can inspect network traffic and identify common protocols. Technologies such as Bro and Palo Alto Networks firewalls are two examples that will identify protocols via inspection, and not just assume a specific protocol based on the transport protocol and ports. - -#### Known False Positives -None identified - -#### Associated Analytic story -* [Prohibited Traffic Allowed or Protocol Mismatch](/stories/prohibited_traffic_allowed_or_protocol_mismatch) -* [Command and Control](/stories/command_and_control) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/network/protocol_or_port_mismatch.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2020-07-21-remote_desktop_network_bruteforce.md b/docs/_posts/2020-07-21-remote_desktop_network_bruteforce.md deleted file mode 100644 index 0092abd883..0000000000 --- a/docs/_posts/2020-07-21-remote_desktop_network_bruteforce.md +++ /dev/null @@ -1,167 +0,0 @@ ---- -title: "Remote Desktop Network Bruteforce" -excerpt: "Remote Desktop Protocol -, Remote Services -" -categories: - - Network -last_modified_at: 2020-07-21 -toc: true -toc_label: "" -tags: - - Remote Desktop Protocol - - Remote Services - - Lateral Movement - - Lateral Movement - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Network_Traffic ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for RDP application network traffic and filters any source/destination pair generating more than twice the standard deviation of the average traffic. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Network_Traffic](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkTraffic) -- **Last Updated**: 2020-07-21 -- **Author**: Jose Hernandez, Splunk -- **ID**: a98727cc-286b-4ff2-b898-41df64695923 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1021.001](https://attack.mitre.org/techniques/T1021/001/) | Remote Desktop Protocol | Lateral Movement | - -| [T1021](https://attack.mitre.org/techniques/T1021/) | Remote Services | Lateral Movement | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance -* Delivery - - -
-
- - -
- NIST - -
- -* DE.AE -* PR.AC -* PR.IP - - - -
-
- -
- CIS20 - -
- -* CIS 12 -* CIS 9 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Network_Traffic where All_Traffic.app=rdp by All_Traffic.src All_Traffic.dest All_Traffic.dest_port -| eventstats stdev(count) AS stdev avg(count) AS avg p50(count) AS p50 -| where count>(avg + stdev*2) -| rename All_Traffic.src AS src All_Traffic.dest AS dest -| table firstTime lastTime src dest count avg p50 stdev -| `remote_desktop_network_bruteforce_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **remote_desktop_network_bruteforce_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* All_Traffic.app -* All_Traffic.src -* All_Traffic.dest -* All_Traffic.dest_port - - -#### How To Implement -You must ensure that your network traffic data is populating the Network_Traffic data model. - -#### Known False Positives -RDP gateways may have unusually high amounts of traffic from all other hosts' RDP applications in the network. - -#### Associated Analytic story -* [SamSam Ransomware](/stories/samsam_ransomware) -* [Ryuk Ransomware](/stories/ryuk_ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/network/remote_desktop_network_bruteforce.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2020-07-21-remote_desktop_process_running_on_system.md b/docs/_posts/2020-07-21-remote_desktop_process_running_on_system.md deleted file mode 100644 index 80127df206..0000000000 --- a/docs/_posts/2020-07-21-remote_desktop_process_running_on_system.md +++ /dev/null @@ -1,166 +0,0 @@ ---- -title: "Remote Desktop Process Running On System" -excerpt: "Remote Desktop Protocol -, Remote Services -" -categories: - - Endpoint -last_modified_at: 2020-07-21 -toc: true -toc_label: "" -tags: - - Remote Desktop Protocol - - Remote Services - - Lateral Movement - - Lateral Movement - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for the remote desktop process mstsc.exe running on systems upon which it doesn't typically run. This is accomplished by filtering out all systems that are noted in the `common_rdp_source category` in the Assets and Identity framework. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2020-07-21 -- **Author**: David Dorsey, Splunk -- **ID**: f5939373-8054-40ad-8c64-cec478a22a4a - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1021.001](https://attack.mitre.org/techniques/T1021/001/) | Remote Desktop Protocol | Lateral Movement | - -| [T1021](https://attack.mitre.org/techniques/T1021/) | Remote Services | Lateral Movement | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.AE -* PR.AC -* PR.IP - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 9 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process=*mstsc.exe AND Processes.dest_category!=common_rdp_source by Processes.dest Processes.user Processes.process -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `drop_dm_object_name(Processes)` -| `remote_desktop_process_running_on_system_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **remote_desktop_process_running_on_system_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process -* Processes.dest_category -* Processes.dest -* Processes.user - - -#### How To Implement -To successfully implement this search, you must be ingesting data that records process activity from your hosts to populate the endpoint data model in the processes node. The search requires you to identify systems that do not commonly use remote desktop. You can use the included support search "Identify Systems Using Remote Desktop" to identify these systems. After identifying them, you will need to add the "common_rdp_source" category to that system using the Enterprise Security Assets and Identities framework. This can be done by adding an entry in the assets.csv file located in `SA-IdentityManagement/lookups`. - -#### Known False Positives -Remote Desktop may be used legitimately by users on the network. - -#### Associated Analytic story -* [Hidden Cobra Malware](/stories/hidden_cobra_malware) -* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/endpoint/remote_desktop_process_running_on_system.yml) \| *version*: **5** \ No newline at end of file diff --git a/docs/_posts/2020-07-21-sc_exe_manipulating_windows_services.md b/docs/_posts/2020-07-21-sc_exe_manipulating_windows_services.md deleted file mode 100644 index a8bbdeb2cf..0000000000 --- a/docs/_posts/2020-07-21-sc_exe_manipulating_windows_services.md +++ /dev/null @@ -1,177 +0,0 @@ ---- -title: "Sc exe Manipulating Windows Services" -excerpt: "Windows Service -, Create or Modify System Process -" -categories: - - Endpoint -last_modified_at: 2020-07-21 -toc: true -toc_label: "" -tags: - - Windows Service - - Create or Modify System Process - - Persistence - - Privilege Escalation - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for arguments to sc.exe indicating the creation or modification of a Windows service. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2020-07-21 -- **Author**: Rico Valdez, Splunk -- **ID**: f0c693d8-2a89-4ce7-80b4-98fea4c3ea6d - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1543.003](https://attack.mitre.org/techniques/T1543/003/) | Windows Service | Persistence, Privilege Escalation | - -| [T1543](https://attack.mitre.org/techniques/T1543/) | Create or Modify System Process | Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Installation - - -
-
- - -
- NIST - -
- -* PR.IP -* PR.PT -* PR.AC -* PR.AT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = sc.exe (Processes.process="* create *" OR Processes.process="* config *") by Processes.process_name Processes.parent_process_name Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `sc_exe_manipulating_windows_services_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **sc_exe_manipulating_windows_services_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process_name -* Processes.process -* Processes.parent_process_name -* Processes.dest -* Processes.user - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Using sc.exe to manipulate Windows services is uncommon. However, there may be legitimate instances of this behavior. It is important to validate and investigate as appropriate. - -#### Associated Analytic story -* [Windows Service Abuse](/stories/windows_service_abuse) -* [DHS Report TA18-074A](/stories/dhs_report_ta18-074a) -* [Orangeworm Attack Group](/stories/orangeworm_attack_group) -* [Windows Persistence Techniques](/stories/windows_persistence_techniques) -* [Disabling Security Tools](/stories/disabling_security_tools) -* [NOBELIUM Group](/stories/nobelium_group) -* [Azorult](/stories/azorult) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 56.0 | 70 | 80 | A sc process $process_name$ with commandline $process$ to create of configure services in host $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1543.003/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1543.003/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml) \| *version*: **4** \ No newline at end of file diff --git a/docs/_posts/2020-07-21-scheduled_tasks_used_in_badrabbit_ransomware.md b/docs/_posts/2020-07-21-scheduled_tasks_used_in_badrabbit_ransomware.md deleted file mode 100644 index 1e8576cece..0000000000 --- a/docs/_posts/2020-07-21-scheduled_tasks_used_in_badrabbit_ransomware.md +++ /dev/null @@ -1,153 +0,0 @@ ---- -title: "Scheduled tasks used in BadRabbit ransomware" -excerpt: "Scheduled Task -" -categories: - - Deprecated -last_modified_at: 2020-07-21 -toc: true -toc_label: "" -tags: - - Scheduled Task - - Execution - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for flags passed to schtasks.exe on the command-line that indicate that task names related to the execution of Bad Rabbit ransomware were created or deleted. Deprecated because we already have a similar detection - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2020-07-21 -- **Author**: Bhavin Patel, Splunk -- **ID**: 1297fb80-f42a-4b4a-9c8b-78c066437cf6 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1053.005](https://attack.mitre.org/techniques/T1053/005/) | Scheduled Task | Execution, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.IP - - - -
-
- -
- CIS20 - -
- -* CIS 3 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Processes.process) as process from datamodel=Endpoint.Processes where Processes.process_name=schtasks.exe (Processes.process= "*create*" OR Processes.process= "*delete*") by Processes.parent_process Processes.process_name Processes.user -| `drop_dm_object_name("Processes")` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -| search (process=*rhaegal* OR process=*drogon* OR *viserion_*) -| `scheduled_tasks_used_in_badrabbit_ransomware_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **scheduled_tasks_used_in_badrabbit_ransomware_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. - -#### Known False Positives -No known false positives - -#### Associated Analytic story -* [Ransomware](/stories/ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2020-07-21-sql_injection_with_long_urls.md b/docs/_posts/2020-07-21-sql_injection_with_long_urls.md deleted file mode 100644 index fe8bc0fef9..0000000000 --- a/docs/_posts/2020-07-21-sql_injection_with_long_urls.md +++ /dev/null @@ -1,105 +0,0 @@ ---- -title: "SQL Injection with Long URLs" -excerpt: "Exploit Public-Facing Application -" -categories: - - Web -last_modified_at: 2020-07-21 -toc: true -toc_label: "" -tags: - - Exploit Public-Facing Application - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Web ---- - -### WARNING THIS IS A EXPERIMENTAL object -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for long URLs that have several SQL commands visible within them. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/object-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Web](https://docs.splunk.com/Documentation/CIM/latest/User/Web) - -- **Last Updated**: 2020-07-21 -- **Author**: Bhavin Patel, Splunk -- **ID**: e0aad4cf-0790-423b-8328-7564d0d938f9 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1190](https://attack.mitre.org/techniques/T1190/) | Exploit Public-Facing Application | Initial Access | - -#### Search - -``` - -| tstats `security_content_summariesonly` count from datamodel=Web where Web.dest_category=web_server AND (Web.url_length > 1024 OR Web.http_user_agent_length > 200) by Web.src Web.dest Web.url Web.url_length Web.http_user_agent -| `drop_dm_object_name("Web")` -| eval num_sql_cmds=mvcount(split(url, "alter%20table")) + mvcount(split(url, "between")) + mvcount(split(url, "create%20table")) + mvcount(split(url, "create%20database")) + mvcount(split(url, "create%20index")) + mvcount(split(url, "create%20view")) + mvcount(split(url, "delete")) + mvcount(split(url, "drop%20database")) + mvcount(split(url, "drop%20index")) + mvcount(split(url, "drop%20table")) + mvcount(split(url, "exists")) + mvcount(split(url, "exec")) + mvcount(split(url, "group%20by")) + mvcount(split(url, "having")) + mvcount(split(url, "insert%20into")) + mvcount(split(url, "inner%20join")) + mvcount(split(url, "left%20join")) + mvcount(split(url, "right%20join")) + mvcount(split(url, "full%20join")) + mvcount(split(url, "select")) + mvcount(split(url, "distinct")) + mvcount(split(url, "select%20top")) + mvcount(split(url, "union")) + mvcount(split(url, "xp_cmdshell")) - 24 -| where num_sql_cmds > 3 -| `sql_injection_with_long_urls_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -Note that `sql_injection_with_long_urls_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Web.dest_category -* Web.url_length -* Web.http_user_agent_length -* Web.src -* Web.dest -* Web.url -* Web.http_user_agent - - -#### How To Implement -To successfully implement this search, you need to be monitoring network communications to your web servers or ingesting your HTTP logs and populating the Web data model. You must also identify your web servers in the Enterprise Security assets table. - -#### Known False Positives -It's possible that legitimate traffic will have long URLs or long user agent strings and that common SQL commands may be found within the URL. Please investigate as appropriate. - -#### Associated Analytic story -* [SQL Injection](/stories/sql_injection) - - -#### Kill Chain Phase -* Delivery - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - - - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/web/sql_injection_with_long_urls.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2020-07-22-smb_traffic_spike.md b/docs/_posts/2020-07-22-smb_traffic_spike.md deleted file mode 100644 index 6873538aff..0000000000 --- a/docs/_posts/2020-07-22-smb_traffic_spike.md +++ /dev/null @@ -1,165 +0,0 @@ ---- -title: "SMB Traffic Spike" -excerpt: "SMB/Windows Admin Shares -, Remote Services -" -categories: - - Network -last_modified_at: 2020-07-22 -toc: true -toc_label: "" -tags: - - SMB/Windows Admin Shares - - Remote Services - - Lateral Movement - - Lateral Movement - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Network_Traffic ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for spikes in the number of Server Message Block (SMB) traffic connections. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Network_Traffic](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkTraffic) -- **Last Updated**: 2020-07-22 -- **Author**: David Dorsey, Splunk -- **ID**: 7f5fb3e1-4209-4914-90db-0ec21b936378 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1021.002](https://attack.mitre.org/techniques/T1021/002/) | SMB/Windows Admin Shares | Lateral Movement | - -| [T1021](https://attack.mitre.org/techniques/T1021/) | Remote Services | Lateral Movement | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count from datamodel=Network_Traffic where All_Traffic.dest_port=139 OR All_Traffic.dest_port=445 OR All_Traffic.app=smb by _time span=1h, All_Traffic.src -| `drop_dm_object_name("All_Traffic")` -| eventstats max(_time) as maxtime -| stats count as num_data_samples max(eval(if(_time >= relative_time(maxtime, "-70m@m"), count, null))) as count avg(eval(if(_time upperBound AND num_data_samples >=50, 1, 0) -| where isOutlier=1 -| table src count -| `smb_traffic_spike_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **smb_traffic_spike_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* All_Traffic.dest_port -* All_Traffic.app -* All_Traffic.src - - -#### How To Implement -This search requires you to be ingesting your network traffic logs and populating the `Network_Traffic` data model. - -#### Known False Positives -A file server may experience high-demand loads that could cause this analytic to trigger. - -#### Associated Analytic story -* [Emotet Malware DHS Report TA18-201A ](/stories/emotet_malware__dhs_report_ta18-201a_) -* [Hidden Cobra Malware](/stories/hidden_cobra_malware) -* [Ransomware](/stories/ransomware) -* [DHS Report TA18-074A](/stories/dhs_report_ta18-074a) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/network/smb_traffic_spike.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2020-07-22-smb_traffic_spike_-_mltk.md b/docs/_posts/2020-07-22-smb_traffic_spike_-_mltk.md deleted file mode 100644 index cfd5b27ab8..0000000000 --- a/docs/_posts/2020-07-22-smb_traffic_spike_-_mltk.md +++ /dev/null @@ -1,171 +0,0 @@ ---- -title: "SMB Traffic Spike - MLTK" -excerpt: "SMB/Windows Admin Shares -, Remote Services -" -categories: - - Network -last_modified_at: 2020-07-22 -toc: true -toc_label: "" -tags: - - SMB/Windows Admin Shares - - Remote Services - - Lateral Movement - - Lateral Movement - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Network_Traffic ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search uses the Machine Learning Toolkit (MLTK) to identify spikes in the number of Server Message Block (SMB) connections. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Network_Traffic](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkTraffic) -- **Last Updated**: 2020-07-22 -- **Author**: Rico Valdez, Splunk -- **ID**: d25773ba-9ad8-48d1-858e-07ad0bbeb828 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1021.002](https://attack.mitre.org/techniques/T1021/002/) | SMB/Windows Admin Shares | Lateral Movement | - -| [T1021](https://attack.mitre.org/techniques/T1021/) | Remote Services | Lateral Movement | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count values(All_Traffic.dest_ip) as dest values(All_Traffic.dest_port) as port from datamodel=Network_Traffic where All_Traffic.dest_port=139 OR All_Traffic.dest_port=445 OR All_Traffic.app=smb by _time span=1h, All_Traffic.src -| eval HourOfDay=strftime(_time, "%H") -| eval DayOfWeek=strftime(_time, "%A") -| `drop_dm_object_name(All_Traffic)` -| apply smb_pdfmodel threshold=0.001 -| rename "IsOutlier(count)" as isOutlier -| search isOutlier > 0 -| sort -count -| table _time src dest port count -| `smb_traffic_spike___mltk_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **smb_traffic_spike_-_mltk_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* All_Traffic.dest_ip -* All_Traffic.dest_port -* All_Traffic.app -* All_Traffic.src - - -#### How To Implement -To successfully implement this search, you will need to ensure that DNS data is populating the Network_Resolution data model. In addition, the Machine Learning Toolkit (MLTK) version 4.2 or greater must be installed on your search heads, along with any required dependencies. Finally, the support search "Baseline of SMB Traffic - MLTK" must be executed before this detection search, because it builds a machine-learning (ML) model over the historical data used by this search. It is important that this search is run in the same app context as the associated support search, so that the model created by the support search is available for use. You should periodically re-run the support search to rebuild the model with the latest data available in your environment.\ -This search produces a field (Number of events,count) that are not yet supported by ES Incident Review and therefore cannot be viewed when a notable event is raised. This field contributes additional context to the notable. To see the additional metadata, add the following field, if not already present, to Incident Review - Event Attributes (Configure > Incident Management > Incident Review Settings > Add New Entry): \ -1. **Label:** Number of events, **Field:** count\ -Detailed documentation on how to create a new field within Incident Review is found here: `https://docs.splunk.com/Documentation/ES/5.3.0/Admin/Customizenotables#Add_a_field_to_the_notable_event_details` - -#### Known False Positives -If you are seeing more results than desired, you may consider reducing the value of the threshold in the search. You should also periodically re-run the support search to re-build the ML model on the latest data. Please update the `smb_traffic_spike_mltk_filter` macro to filter out false positive results - -#### Associated Analytic story -* [Emotet Malware DHS Report TA18-201A ](/stories/emotet_malware__dhs_report_ta18-201a_) -* [Hidden Cobra Malware](/stories/hidden_cobra_malware) -* [Ransomware](/stories/ransomware) -* [DHS Report TA18-074A](/stories/dhs_report_ta18-074a) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/network/smb_traffic_spike___mltk.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2020-07-22-suspicious_changes_to_file_associations.md b/docs/_posts/2020-07-22-suspicious_changes_to_file_associations.md deleted file mode 100644 index ee8e48bbb9..0000000000 --- a/docs/_posts/2020-07-22-suspicious_changes_to_file_associations.md +++ /dev/null @@ -1,158 +0,0 @@ ---- -title: "Suspicious Changes to File Associations" -excerpt: "Change Default File Association -" -categories: - - Deprecated -last_modified_at: 2020-07-22 -toc: true -toc_label: "" -tags: - - Change Default File Association - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for changes to registry values that control Windows file associations, executed by a process that is not typical for legitimate, routine changes to this area. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-07-22 -- **Author**: Rico Valdez, Splunk -- **ID**: 1b989a0e-0129-4446-a695-f193a5b746fc - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1546.001](https://attack.mitre.org/techniques/T1546/001/) | Change Default File Association | Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.CM -* PR.PT -* PR.IP - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Processes.process_name) as process_name values(Processes.parent_process_name) as parent_process_name FROM datamodel=Endpoint.Processes where Processes.process_name!=Explorer.exe AND Processes.process_name!=OpenWith.exe by Processes.process_id Processes.dest -| `drop_dm_object_name("Processes")` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| join [ -| tstats `security_content_summariesonly` values(Registry.registry_path) as registry_path count from datamodel=Endpoint.Registry where Registry.registry_path=*\\Explorer\\FileExts* by Registry.process_id Registry.dest -| `drop_dm_object_name("Registry")` -| table process_id dest registry_path] -| `suspicious_changes_to_file_associations_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **suspicious_changes_to_file_associations_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -To successfully implement this search you need to be ingesting information on registry changes that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` and `Registry` nodes. - -#### Known False Positives -There may be other processes in your environment that users may legitimately use to modify file associations. If this is the case and you are finding false positives, you can modify the search to add those processes as exceptions. - -#### Associated Analytic story -* [Suspicious Windows Registry Activities](/stories/suspicious_windows_registry_activities) -* [Windows File Extension and Association Abuse](/stories/windows_file_extension_and_association_abuse) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/suspicious_changes_to_file_associations.yml) \| *version*: **4** \ No newline at end of file diff --git a/docs/_posts/2020-07-22-suspicious_email_-_uba_anomaly.md b/docs/_posts/2020-07-22-suspicious_email_-_uba_anomaly.md deleted file mode 100644 index 8610cdf3c4..0000000000 --- a/docs/_posts/2020-07-22-suspicious_email_-_uba_anomaly.md +++ /dev/null @@ -1,151 +0,0 @@ ---- -title: "Suspicious Email - UBA Anomaly" -excerpt: "Phishing -" -categories: - - Deprecated -last_modified_at: 2020-07-22 -toc: true -toc_label: "" -tags: - - Phishing - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - UEBA ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This detection looks for emails that are suspicious because of their sender, domain rareness, or behavior differences. This is an anomaly generated by Splunk User Behavior Analytics (UBA). - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [UEBA](https://docs.splunk.com/Documentation/CIM/latest/User/UEBA) -- **Last Updated**: 2020-07-22 -- **Author**: Bhavin Patel, Splunk -- **ID**: 56e877a6-1455-4479-ad16-0550dc1e33f8 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Delivery - - -
-
- - -
- NIST - -
- -* PR.IP - - - -
-
- -
- CIS20 - -
- -* CIS 7 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -|tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(All_UEBA_Events.category) as category from datamodel=UEBA where nodename=All_UEBA_Events.UEBA_Anomalies All_UEBA_Events.UEBA_Anomalies.uba_model = "SuspiciousEmailDetectionModel" by All_UEBA_Events.description All_UEBA_Events.severity All_UEBA_Events.user All_UEBA_Events.uba_event_type All_UEBA_Events.link All_UEBA_Events.signature All_UEBA_Events.url All_UEBA_Events.UEBA_Anomalies.uba_model -| `drop_dm_object_name(All_UEBA_Events)` -| `drop_dm_object_name(UEBA_Anomalies)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `suspicious_email___uba_anomaly_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **suspicious_email_-_uba_anomaly_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -You must be ingesting data from email logs and have Splunk integrated with UBA. This anomaly is raised by a UBA detection model called "SuspiciousEmailDetectionModel." Ensure that this model is enabled on your UBA instance. - -#### Known False Positives -This detection model will alert on any sender domain that is seen for the first time. This could be a potential false positive. The next step is to investigate and add the URL to an allow list if you determine that it is a legitimate sender. - -#### Associated Analytic story -* [Suspicious Emails](/stories/suspicious_emails) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/suspicious_email___uba_anomaly.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2020-07-22-suspicious_email_attachment_extensions.md b/docs/_posts/2020-07-22-suspicious_email_attachment_extensions.md deleted file mode 100644 index 7032505da1..0000000000 --- a/docs/_posts/2020-07-22-suspicious_email_attachment_extensions.md +++ /dev/null @@ -1,169 +0,0 @@ ---- -title: "Suspicious Email Attachment Extensions" -excerpt: "Spearphishing Attachment -, Phishing -" -categories: - - Application -last_modified_at: 2020-07-22 -toc: true -toc_label: "" -tags: - - Spearphishing Attachment - - Phishing - - Initial Access - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Email ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for emails that have attachments with suspicious file extensions. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Email](https://docs.splunk.com/Documentation/CIM/latest/User/Email) -- **Last Updated**: 2020-07-22 -- **Author**: David Dorsey, Splunk -- **ID**: 473bd65f-06ca-4dfe-a2b8-ba04ab4a0084 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | - -| [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Delivery - - -
-
- - -
- NIST - -
- -* DE.AE -* PR.IP - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 7 -* CIS 12 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Email where All_Email.file_name="*" by All_Email.src_user, All_Email.file_name All_Email.message_id -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `drop_dm_object_name("All_Email")` -| `suspicious_email_attachments` -| `suspicious_email_attachment_extensions_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [suspicious_email_attachments](https://github.com/splunk/security_content/blob/develop/macros/suspicious_email_attachments.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **suspicious_email_attachment_extensions_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* All_Email.file_name -* All_Email.src_user -* All_Email.message_id - - -#### How To Implement -You need to ingest data from emails. Specifically, the sender's address and the file names of any attachments must be mapped to the Email data model. \ - **Splunk Phantom Playbook Integration**\ -If Splunk Phantom is also configured in your environment, a Playbook called "Suspicious Email Attachment Investigate and Delete" can be configured to run when any results are found by this detection search. To use this integration, install the Phantom App for Splunk `https://splunkbase.splunk.com/app/3411/`, and add the correct hostname to the "Phantom Instance" field in the Adaptive Response Actions when configuring this detection search. The notable event will be sent to Phantom and the playbook will gather further information about the file attachment and its network behaviors. If Phantom finds malicious behavior and an analyst approves of the results, the email will be deleted from the user's inbox. - -#### Known False Positives -None identified - -#### Associated Analytic story -* [Hermetic Wiper](/stories/hermetic_wiper) -* [Emotet Malware DHS Report TA18-201A ](/stories/emotet_malware__dhs_report_ta18-201a_) -* [Suspicious Emails](/stories/suspicious_emails) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/application/suspicious_email_attachment_extensions.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2020-07-22-suspicious_reg_exe_process.md b/docs/_posts/2020-07-22-suspicious_reg_exe_process.md deleted file mode 100644 index 64c07fce81..0000000000 --- a/docs/_posts/2020-07-22-suspicious_reg_exe_process.md +++ /dev/null @@ -1,173 +0,0 @@ ---- -title: "Suspicious Reg exe Process" -excerpt: "Modify Registry -" -categories: - - Endpoint -last_modified_at: 2020-07-22 -toc: true -toc_label: "" -tags: - - Modify Registry - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for reg.exe being launched from a command prompt not started by the user. When a user launches cmd.exe, the parent process is usually explorer.exe. This search filters out those instances. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2020-07-22 -- **Author**: David Dorsey, Splunk -- **ID**: a6b3ab4e-dd77-4213-95fa-fc94701995e0 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1112](https://attack.mitre.org/techniques/T1112/) | Modify Registry | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes where Processes.parent_process_name != explorer.exe Processes.process_name =cmd.exe by Processes.user Processes.process_name Processes.parent_process_name Processes.dest Processes.process_id Processes.parent_process_id -| `drop_dm_object_name("Processes")` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| search [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.parent_process_name=cmd.exe Processes.process_name= reg.exe by Processes.parent_process_id Processes.dest Processes.process_name -| `drop_dm_object_name("Processes")` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| rename parent_process_id as process_id -|dedup process_id -| table process_id dest] -| `suspicious_reg_exe_process_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **suspicious_reg_exe_process_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.parent_process_name -* Processes.process_name -* Processes.user -* Processes.parent_process_name -* Processes.dest -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. - -#### Known False Positives -It's possible for system administrators to write scripts that exhibit this behavior. If this is the case, the search will need to be modified to filter them out. - -#### Associated Analytic story -* [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics) -* [Disabling Security Tools](/stories/disabling_security_tools) -* [DHS Report TA18-074A](/stories/dhs_report_ta18-074a) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 35.0 | 70 | 50 | Suspicious $Processes.process_path.file_path$ process running with an uncommon parent process $Processes.parent_process_name$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://car.mitre.org/wiki/CAR-2013-03-001/](https://car.mitre.org/wiki/CAR-2013-03-001/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1112/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1112/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/suspicious_reg_exe_process.yml) \| *version*: **4** \ No newline at end of file diff --git a/docs/_posts/2020-07-22-suspicious_writes_to_system_volume_information.md b/docs/_posts/2020-07-22-suspicious_writes_to_system_volume_information.md deleted file mode 100644 index 9b0f587725..0000000000 --- a/docs/_posts/2020-07-22-suspicious_writes_to_system_volume_information.md +++ /dev/null @@ -1,148 +0,0 @@ ---- -title: "Suspicious writes to System Volume Information" -excerpt: "Masquerading -" -categories: - - Deprecated -last_modified_at: 2020-07-22 -toc: true -toc_label: "" -tags: - - Masquerading - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search detects writes to the 'System Volume Information' folder by something other than the System process. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-07-22 -- **Author**: Rico Valdez, Splunk -- **ID**: cd6297cd-2bdd-4aa1-84aa-5d2f84228fac - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1036](https://attack.mitre.org/techniques/T1036/) | Masquerading | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -(`sysmon` OR tag=process) EventCode=11 process_id!=4 file_path=*System\ Volume\ Information* -| stats count min(_time) as firstTime max(_time) as lastTime by dest, Image, file_path -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `suspicious_writes_to_system_volume_information_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **suspicious_writes_to_system_volume_information_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -You need to be ingesting logs with both the process name and command-line from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -It is possible that other utilities or system processes may legitimately write to this folder. Investigate and modify the search to include exceptions as appropriate. - -#### Associated Analytic story -* [Collection and Staging](/stories/collection_and_staging) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2020-07-22-suspicious_writes_to_windows_recycle_bin.md b/docs/_posts/2020-07-22-suspicious_writes_to_windows_recycle_bin.md deleted file mode 100644 index a63a4323e3..0000000000 --- a/docs/_posts/2020-07-22-suspicious_writes_to_windows_recycle_bin.md +++ /dev/null @@ -1,163 +0,0 @@ ---- -title: "Suspicious writes to windows Recycle Bin" -excerpt: "Masquerading -" -categories: - - Endpoint -last_modified_at: 2020-07-22 -toc: true -toc_label: "" -tags: - - Masquerading - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search detects writes to the recycle bin by a process other than explorer.exe. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2020-07-22 -- **Author**: Rico Valdez, Splunk -- **ID**: b5541828-8ffd-4070-9d95-b3da4de924cb - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1036](https://attack.mitre.org/techniques/T1036/) | Masquerading | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Filesystem.file_path) as file_path values(Filesystem.file_name) as file_name FROM datamodel=Endpoint.Filesystem where Filesystem.file_path = "*$Recycle.Bin*" by Filesystem.process_id Filesystem.dest -| `drop_dm_object_name("Filesystem")` -| search [ -| tstats `security_content_summariesonly` values(Processes.user) as user values(Processes.process_name) as process_name values(Processes.parent_process_name) as parent_process_name FROM datamodel=Endpoint.Processes where Processes.process_name != "explorer.exe" by Processes.process_id Processes.dest -| `drop_dm_object_name("Processes")` -| table process_id dest] -| `suspicious_writes_to_windows_recycle_bin_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **suspicious_writes_to_windows_recycle_bin_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Filesystem.file_path -* Filesystem.file_name -* Filesystem.process_id -* Filesystem.dest -* Processes.user -* Processes.process_name -* Processes.parent_process_name -* Processes.process_id -* Processes.dest - - -#### How To Implement -To successfully implement this search you need to be ingesting information on filesystem and process logs responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` and `Filesystem` nodes. - -#### Known False Positives -Because the Recycle Bin is a hidden folder in modern versions of Windows, it would be unusual for a process other than explorer.exe to write to it. Incidents should be investigated as appropriate. - -#### Associated Analytic story -* [Collection and Staging](/stories/collection_and_staging) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 28.0 | 40 | 70 | Suspicious writes to windows Recycle Bin process $Processes.process_name$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036/write_to_recycle_bin/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036/write_to_recycle_bin/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml) \| *version*: **4** \ No newline at end of file diff --git a/docs/_posts/2020-07-22-tor_traffic.md b/docs/_posts/2020-07-22-tor_traffic.md deleted file mode 100644 index f6411060b4..0000000000 --- a/docs/_posts/2020-07-22-tor_traffic.md +++ /dev/null @@ -1,166 +0,0 @@ ---- -title: "TOR Traffic" -excerpt: "Application Layer Protocol -, Web Protocols -" -categories: - - Network -last_modified_at: 2020-07-22 -toc: true -toc_label: "" -tags: - - Application Layer Protocol - - Web Protocols - - Command And Control - - Command And Control - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Network_Traffic ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for network traffic identified as The Onion Router (TOR), a benign anonymity network which can be abused for a variety of nefarious purposes. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Network_Traffic](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkTraffic) -- **Last Updated**: 2020-07-22 -- **Author**: David Dorsey, Splunk -- **ID**: ea688274-9c06-4473-b951-e4cb7a5d7a45 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1071](https://attack.mitre.org/techniques/T1071/) | Application Layer Protocol | Command And Control | - -| [T1071.001](https://attack.mitre.org/techniques/T1071/001/) | Web Protocols | Command And Control | - -
-
- - -
- Kill Chain Phase - -
- -* Command & Control - - -
-
- - -
- NIST - -
- -* DE.AE - - - -
-
- -
- CIS20 - -
- -* CIS 9 -* CIS 12 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Network_Traffic where All_Traffic.app=tor AND All_Traffic.action=allowed by All_Traffic.src_ip All_Traffic.dest_ip All_Traffic.dest_port All_Traffic.action -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `drop_dm_object_name("All_Traffic")` -| `tor_traffic_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **tor_traffic_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* All_Traffic.app -* All_Traffic.action -* All_Traffic.src_ip -* All_Traffic.dest_ip -* All_Traffic.dest_port - - -#### How To Implement -In order to properly run this search, Splunk needs to ingest data from firewalls or other network control devices that mediate the traffic allowed into an environment. This is necessary so that the search can identify an 'action' taken on the traffic of interest. The search requires the Network_Traffic data model be populated. - -#### Known False Positives -None at this time - -#### Associated Analytic story -* [Prohibited Traffic Allowed or Protocol Mismatch](/stories/prohibited_traffic_allowed_or_protocol_mismatch) -* [Ransomware](/stories/ransomware) -* [NOBELIUM Group](/stories/nobelium_group) -* [Command and Control](/stories/command_and_control) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/network/tor_traffic.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2020-07-22-uncommon_processes_on_endpoint.md b/docs/_posts/2020-07-22-uncommon_processes_on_endpoint.md deleted file mode 100644 index d5664f0705..0000000000 --- a/docs/_posts/2020-07-22-uncommon_processes_on_endpoint.md +++ /dev/null @@ -1,155 +0,0 @@ ---- -title: "Uncommon Processes On Endpoint" -excerpt: "Malicious File -" -categories: - - Deprecated -last_modified_at: 2020-07-22 -toc: true -toc_label: "" -tags: - - Malicious File - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for applications on the endpoint that you have marked as uncommon. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2020-07-22 -- **Author**: David Dorsey, Splunk -- **ID**: 29ccce64-a10c-4389-a45f-337cb29ba1f7 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1204.002](https://attack.mitre.org/techniques/T1204/002/) | Malicious File | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* ID.AM -* PR.DS - - - -
-
- -
- CIS20 - -
- -* CIS 2 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes by Processes.dest Processes.user Processes.process Processes.process_name -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `drop_dm_object_name(Processes)` -| `uncommon_processes` -|`uncommon_processes_on_endpoint_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [uncommon_processes](https://github.com/splunk/security_content/blob/develop/macros/uncommon_processes.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **uncommon_processes_on_endpoint_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. This search uses a lookup file `uncommon_processes_default.csv` to track various features of process names that are usually uncommon in most environments. Please consider updating `uncommon_processes_local.csv` to hunt for processes that are uncommon in your environment. - -#### Known False Positives -None identified - -#### Associated Analytic story -* [Windows Privilege Escalation](/stories/windows_privilege_escalation) -* [Unusual Processes](/stories/unusual_processes) -* [Hermetic Wiper](/stories/hermetic_wiper) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/uncommon_processes_on_endpoint.yml) \| *version*: **4** \ No newline at end of file diff --git a/docs/_posts/2020-07-22-unload_sysmon_filter_driver.md b/docs/_posts/2020-07-22-unload_sysmon_filter_driver.md deleted file mode 100644 index 912002b532..0000000000 --- a/docs/_posts/2020-07-22-unload_sysmon_filter_driver.md +++ /dev/null @@ -1,165 +0,0 @@ ---- -title: "Unload Sysmon Filter Driver" -excerpt: "Disable or Modify Tools -, Impair Defenses -" -categories: - - Endpoint -last_modified_at: 2020-07-22 -toc: true -toc_label: "" -tags: - - Disable or Modify Tools - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -Attackers often disable security tools to avoid detection. This search looks for the usage of process `fltMC.exe` to unload a Sysmon Driver that will stop sysmon from collecting the data. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2020-07-22 -- **Author**: Bhavin Patel, Splunk -- **ID**: e5928ff3-23eb-4d8b-b8a4-dcbc844fdfbe - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime values(Processes.process) as process max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=fltMC.exe AND Processes.process=*unload* AND Processes.process=*SysmonDrv* by Processes.process_name Processes.process_id Processes.parent_process_name Processes.process Processes.dest Processes.user -| `drop_dm_object_name("Processes")` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -|`unload_sysmon_filter_driver_filter` -| table firstTime lastTime dest user count process_name process_id parent_process_name process -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **unload_sysmon_filter_driver_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_name -* Processes.dest -* Processes.user - - -#### How To Implement -You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. This search is also shipped with `unload_sysmon_filter_driver_filter` macro, update this macro to filter out false positives. - -#### Known False Positives - - -#### Associated Analytic story -* [Disabling Security Tools](/stories/disabling_security_tools) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 45.0 | 50 | 90 | Possible Sysmon filter driver unloading on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/unload_sysmon_filter_driver.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2020-07-27-aws_detect_attach_to_role_policy.md b/docs/_posts/2020-07-27-aws_detect_attach_to_role_policy.md deleted file mode 100644 index f244f1b407..0000000000 --- a/docs/_posts/2020-07-27-aws_detect_attach_to_role_policy.md +++ /dev/null @@ -1,148 +0,0 @@ ---- -title: "aws detect attach to role policy" -excerpt: "Valid Accounts -" -categories: - - Cloud -last_modified_at: 2020-07-27 -toc: true -toc_label: "" -tags: - - Valid Accounts - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search provides detection of an user attaching itself to a different role trust policy. This can be used for lateral movement and escalation of privileges. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-07-27 -- **Author**: Rod Soto, Splunk -- **ID**: 88fc31dd-f331-448c-9856-d3d51dd5d3a1 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`aws_cloudwatchlogs_eks` attach policy -| spath requestParameters.policyArn -| table sourceIPAddress user_access_key userIdentity.arn userIdentity.sessionContext.sessionIssuer.arn eventName errorCode errorMessage status action requestParameters.policyArn userIdentity.sessionContext.attributes.mfaAuthenticated userIdentity.sessionContext.attributes.creationDate -| `aws_detect_attach_to_role_policy_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [aws_cloudwatchlogs_eks](https://github.com/splunk/security_content/blob/develop/macros/aws_cloudwatchlogs_eks.yml) - -> :information_source: -> **aws_detect_attach_to_role_policy_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* requestParameters.policyArn - - -#### How To Implement -You must install splunk AWS add-on and Splunk App for AWS. This search works with cloudwatch logs - -#### Known False Positives -Attach to policy can create a lot of noise. This search can be adjusted to provide specific values to identify cases of abuse (i.e status=failure). The search can provide context for common users attaching themselves to higher privilege policies or even newly created policies. - -#### Associated Analytic story -* [AWS Cross Account Activity](/stories/aws_cross_account_activity) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/cloud/aws_detect_attach_to_role_policy.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-07-27-aws_detect_permanent_key_creation.md b/docs/_posts/2020-07-27-aws_detect_permanent_key_creation.md deleted file mode 100644 index 96d1918cb8..0000000000 --- a/docs/_posts/2020-07-27-aws_detect_permanent_key_creation.md +++ /dev/null @@ -1,158 +0,0 @@ ---- -title: "aws detect permanent key creation" -excerpt: "Valid Accounts -" -categories: - - Cloud -last_modified_at: 2020-07-27 -toc: true -toc_label: "" -tags: - - Valid Accounts - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search provides detection of accounts creating permanent keys. Permanent keys are not created by default and they are only needed for programmatic calls. Creation of Permanent key is an important event to monitor. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-07-27 -- **Author**: Rod Soto, Splunk -- **ID**: 12d6d713-3cb4-4ffc-a064-1dca3d1cca01 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`aws_cloudwatchlogs_eks` CreateAccessKey -| spath eventName -| search eventName=CreateAccessKey "userIdentity.type"=IAMUser -| table sourceIPAddress userName userIdentity.type userAgent action status responseElements.accessKey.createDate responseElements.accessKey.status responseElements.accessKey.accessKeyId -|`aws_detect_permanent_key_creation_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [aws_cloudwatchlogs_eks](https://github.com/splunk/security_content/blob/develop/macros/aws_cloudwatchlogs_eks.yml) - -> :information_source: -> **aws_detect_permanent_key_creation_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* eventName -* userIdentity.type -* sourceIPAddress -* userName userIdentity.type -* userAgent -* action -* status -* responseElements.accessKey.createDate -* esponseElements.accessKey.status -* responseElements.accessKey.accessKeyId - - -#### How To Implement -You must install splunk AWS add on and Splunk App for AWS. This search works with cloudwatch logs - -#### Known False Positives -Not all permanent key creations are malicious. If there is a policy of rotating keys this search can be adjusted to provide better context. - -#### Associated Analytic story -* [AWS Cross Account Activity](/stories/aws_cross_account_activity) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/cloud/aws_detect_permanent_key_creation.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-07-27-aws_detect_role_creation.md b/docs/_posts/2020-07-27-aws_detect_role_creation.md deleted file mode 100644 index 6bb03c240f..0000000000 --- a/docs/_posts/2020-07-27-aws_detect_role_creation.md +++ /dev/null @@ -1,163 +0,0 @@ ---- -title: "aws detect role creation" -excerpt: "Valid Accounts -" -categories: - - Cloud -last_modified_at: 2020-07-27 -toc: true -toc_label: "" -tags: - - Valid Accounts - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search provides detection of role creation by IAM users. Role creation is an event by itself if user is creating a new role with trust policies different than the available in AWS and it can be used for lateral movement and escalation of privileges. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-07-27 -- **Author**: Rod Soto, Splunk -- **ID**: 5f04081e-ddee-4353-afe4-504f288de9ad - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`aws_cloudwatchlogs_eks` event_name=CreateRole action=created userIdentity.type=AssumedRole requestParameters.description=Allows* -| table sourceIPAddress userIdentity.principalId userIdentity.arn action event_name awsRegion http_user_agent mfa_auth msg requestParameters.roleName requestParameters.description responseElements.role.arn responseElements.role.createDate -| `aws_detect_role_creation_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [aws_cloudwatchlogs_eks](https://github.com/splunk/security_content/blob/develop/macros/aws_cloudwatchlogs_eks.yml) - -> :information_source: -> **aws_detect_role_creation_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* event_name -* action -* userIdentity.type -* requestParameters.description -* sourceIPAddress -* userIdentity.principalId -* userIdentity.arn -* action -* event_name -* awsRegion -* http_user_agent -* mfa_auth -* msg -* requestParameters.roleName -* requestParameters.description -* responseElements.role.arn -* responseElements.role.createDate - - -#### How To Implement -You must install splunk AWS add-on and Splunk App for AWS. This search works with cloudwatch logs - -#### Known False Positives -CreateRole is not very common in common users. This search can be adjusted to provide specific values to identify cases of abuse. In general AWS provides plenty of trust policies that fit most use cases. - -#### Associated Analytic story -* [AWS Cross Account Activity](/stories/aws_cross_account_activity) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/cloud/aws_detect_role_creation.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-07-27-aws_detect_sts_assume_role_abuse.md b/docs/_posts/2020-07-27-aws_detect_sts_assume_role_abuse.md deleted file mode 100644 index b5a83d1228..0000000000 --- a/docs/_posts/2020-07-27-aws_detect_sts_assume_role_abuse.md +++ /dev/null @@ -1,157 +0,0 @@ ---- -title: "aws detect sts assume role abuse" -excerpt: "Valid Accounts -" -categories: - - Cloud -last_modified_at: 2020-07-27 -toc: true -toc_label: "" -tags: - - Valid Accounts - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search provides detection of suspicious use of sts:AssumeRole. These tokens can be created on the go and used by attackers to move laterally and escalate privileges. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-07-27 -- **Author**: Rod Soto, Splunk -- **ID**: 8e565314-b6a2-46d8-9f05-1a34a176a662 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cloudtrail` user_type=AssumedRole userIdentity.sessionContext.sessionIssuer.type=Role -| table sourceIPAddress userIdentity.arn user_agent user_access_key status action requestParameters.roleName responseElements.role.roleName responseElements.role.createDate -| `aws_detect_sts_assume_role_abuse_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) - -> :information_source: -> **aws_detect_sts_assume_role_abuse_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* user_type -* userIdentity.sessionContext.sessionIssuer.type -* sourceIPAddress -* userIdentity.arn -* user_agent -* user_access_key -* status -* action -* requestParameters.roleName -* esponseElements.role.roleName -* esponseElements.role.createDate - - -#### How To Implement -You must install splunk AWS add on and Splunk App for AWS. This search works with AWS CloudTrail logs - -#### Known False Positives -Sts:AssumeRole can be very noisy as it is a standard mechanism to provide cross account and cross resources access. This search can be adjusted to provide specific values to identify cases of abuse. - -#### Associated Analytic story -* [AWS Cross Account Activity](/stories/aws_cross_account_activity) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/cloud/aws_detect_sts_assume_role_abuse.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-07-27-aws_detect_sts_get_session_token_abuse.md b/docs/_posts/2020-07-27-aws_detect_sts_get_session_token_abuse.md deleted file mode 100644 index 5eb316ad2a..0000000000 --- a/docs/_posts/2020-07-27-aws_detect_sts_get_session_token_abuse.md +++ /dev/null @@ -1,156 +0,0 @@ ---- -title: "aws detect sts get session token abuse" -excerpt: "Use Alternate Authentication Material -" -categories: - - Cloud -last_modified_at: 2020-07-27 -toc: true -toc_label: "" -tags: - - Use Alternate Authentication Material - - Defense Evasion - - Lateral Movement - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search provides detection of suspicious use of sts:GetSessionToken. These tokens can be created on the go and used by attackers to move laterally and escalate privileges. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-07-27 -- **Author**: Rod Soto, Splunk -- **ID**: 85d7b35f-b8b5-4b01-916f-29b81e7a0551 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1550](https://attack.mitre.org/techniques/T1550/) | Use Alternate Authentication Material | Defense Evasion, Lateral Movement | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`aws_cloudwatchlogs_eks` ASIA userIdentity.type=IAMUser -| spath eventName -| search eventName=GetSessionToken -| table sourceIPAddress eventTime userIdentity.arn userName userAgent user_type status region -| `aws_detect_sts_get_session_token_abuse_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [aws_cloudwatchlogs_eks](https://github.com/splunk/security_content/blob/develop/macros/aws_cloudwatchlogs_eks.yml) - -> :information_source: -> **aws_detect_sts_get_session_token_abuse_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* userIdentity.type -* eventName -* sourceIPAddress -* eventTime -* userIdentity.arn -* userName -* userAgent -* user_type -* status -* region - - -#### How To Implement -You must install splunk AWS add-on and Splunk App for AWS. This search works with cloudwatch logs - -#### Known False Positives -Sts:GetSessionToken can be very noisy as in certain environments numerous calls of this type can be executed. This search can be adjusted to provide specific values to identify cases of abuse. In specific environments the use of field requestParameters.serialNumber will need to be used. - -#### Associated Analytic story -* [AWS Cross Account Activity](/stories/aws_cross_account_activity) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/cloud/aws_detect_sts_get_session_token_abuse.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_splunk_stream.md b/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_splunk_stream.md deleted file mode 100644 index 906d51e1ca..0000000000 --- a/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_splunk_stream.md +++ /dev/null @@ -1,161 +0,0 @@ ---- -title: "Detect Windows DNS SIGRed via Splunk Stream" -excerpt: "Exploitation for Client Execution -" -categories: - - Network -last_modified_at: 2020-07-28 -toc: true -toc_label: "" -tags: - - Exploitation for Client Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2020-1350 ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search detects SIGRed via Splunk Stream. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-07-28 -- **Author**: Shannon Davis, Splunk -- **ID**: babd8d10-d073-11ea-87d0-0242ac130003 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1203](https://attack.mitre.org/techniques/T1203/) | Exploitation for Client Execution | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 -* CIS 12 - - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2020-1350](https://nvd.nist.gov/vuln/detail/CVE-2020-1350) | A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle requests, aka 'Windows DNS Server Remote Code Execution Vulnerability'. | 10.0 | - - - -
-
- -#### Search - -``` -`stream_dns` -| spath "query_type{}" -| search "query_type{}" IN (SIG,KEY) -| spath protocol_stack -| search protocol_stack="ip:tcp:dns" -| append [search `stream_tcp` bytes_out>65000] -| `detect_windows_dns_sigred_via_splunk_stream_filter` -| stats count by flow_id -| where count>1 -| fields - count -``` - -#### Macros -The SPL above uses the following Macros: -* [stream_tcp](https://github.com/splunk/security_content/blob/develop/macros/stream_tcp.yml) -* [stream_dns](https://github.com/splunk/security_content/blob/develop/macros/stream_dns.yml) - -> :information_source: -> **detect_windows_dns_sigred_via_splunk_stream_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -You must be ingesting Splunk Stream DNS and Splunk Stream TCP. We are detecting SIG and KEY records via stream:dns and TCP payload over 65KB in size via stream:tcp. Replace the macro definitions ('stream:dns' and 'stream:tcp') with configurations for your Splunk environment. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Windows DNS SIGRed CVE-2020-1350](/stories/windows_dns_sigred_cve-2020-1350) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/network/detect_windows_dns_sigred_via_splunk_stream.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_zeek.md b/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_zeek.md deleted file mode 100644 index c3a70bd263..0000000000 --- a/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_zeek.md +++ /dev/null @@ -1,165 +0,0 @@ ---- -title: "Detect Windows DNS SIGRed via Zeek" -excerpt: "Exploitation for Client Execution -" -categories: - - Network -last_modified_at: 2020-07-28 -toc: true -toc_label: "" -tags: - - Exploitation for Client Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2020-1350 - - Network_Resolution ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search detects SIGRed via Zeek DNS and Zeek Conn data. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Network_Resolution](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkResolution) -- **Last Updated**: 2020-07-28 -- **Author**: Shannon Davis, Splunk -- **ID**: c5c622e4-d073-11ea-87d0-0242ac130003 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1203](https://attack.mitre.org/techniques/T1203/) | Exploitation for Client Execution | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 -* CIS 16 - - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2020-1350](https://nvd.nist.gov/vuln/detail/CVE-2020-1350) | A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle requests, aka 'Windows DNS Server Remote Code Execution Vulnerability'. | 10.0 | - - - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count from datamodel=Network_Resolution where DNS.query_type IN (SIG,KEY) by DNS.flow_id -| rename DNS.flow_id as flow_id -| append [ -| tstats `security_content_summariesonly` count from datamodel=Network_Traffic where All_Traffic.bytes_in>65000 by All_Traffic.flow_id -| rename All_Traffic.flow_id as flow_id] -| `detect_windows_dns_sigred_via_zeek_filter` -| stats count by flow_id -| where count>1 -| fields - count -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **detect_windows_dns_sigred_via_zeek_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* DNS.query_type -* DNS.flow_id -* All_Traffic.bytes_in -* All_Traffic.flow_id - - -#### How To Implement -You must be ingesting Zeek DNS and Zeek Conn data into Splunk. Zeek data should also be getting ingested in JSON format. We are detecting SIG and KEY records via bro:dns:json and TCP payload over 65KB in size via bro:conn:json. The Network Resolution and Network Traffic datamodels are in use for this search. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Windows DNS SIGRed CVE-2020-1350](/stories/windows_dns_sigred_cve-2020-1350) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/network/detect_windows_dns_sigred_via_zeek.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-07-29-cloud_instance_modified_by_previously_unseen_user.md b/docs/_posts/2020-07-29-cloud_instance_modified_by_previously_unseen_user.md deleted file mode 100644 index 86f9ad6e66..0000000000 --- a/docs/_posts/2020-07-29-cloud_instance_modified_by_previously_unseen_user.md +++ /dev/null @@ -1,180 +0,0 @@ ---- -title: "Cloud Instance Modified By Previously Unseen User" -excerpt: "Cloud Accounts -, Valid Accounts -" -categories: - - Cloud -last_modified_at: 2020-07-29 -toc: true -toc_label: "" -tags: - - Cloud Accounts - - Valid Accounts - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Change ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for cloud instances being modified by users who have not previously modified them. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Change](https://docs.splunk.com/Documentation/CIM/latest/User/Change)- **Datasource**: [Splunk Add-on for Amazon Kinesis Firehose](https://splunkbase.splunk.com/app/3719) -- **Last Updated**: 2020-07-29 -- **Author**: Rico Valdez, Splunk -- **ID**: 7fb15084-b14e-405a-bd61-a6de15a40722 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1078.004](https://attack.mitre.org/techniques/T1078/004/) | Cloud Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* ID.AM - - - -
-
- -
- CIS20 - -
- -* CIS 1 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count earliest(_time) as firstTime, latest(_time) as lastTime values(All_Changes.object_id) as object_id values(All_Changes.command) as command from datamodel=Change where All_Changes.action=modified All_Changes.change_type=EC2 All_Changes.status=success by All_Changes.user -| `drop_dm_object_name("All_Changes")` -| lookup previously_seen_cloud_instance_modifications_by_user user as user OUTPUTNEW firstTimeSeen, enough_data -| eventstats max(enough_data) as enough_data -| where enough_data=1 -| eval firstTimeSeenUser=min(firstTimeSeen) -| where isnull(firstTimeSeenUser) OR firstTimeSeenUser > relative_time(now(), "-24h@h") -| table firstTime user command object_id count -| `security_content_ctime(firstTime)` -| `cloud_instance_modified_by_previously_unseen_user_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **cloud_instance_modified_by_previously_unseen_user_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Lookups -The SPL above uses the following Lookups: - -* [previously_seen_cloud_instance_modifications_by_user](https://github.com/splunk/security_content/blob/develop/lookups/previously_seen_cloud_instance_modifications_by_user.yml) with [data](https://github.com/splunk/security_content/tree/develop/lookups/previously_seen_cloud_instance_modifications_by_user.csv) - -#### Required field -* _time -* All_Changes.object_id -* All_Changes.command -* All_Changes.action -* All_Changes.change_type -* All_Changes.status -* All_Changes.user - - -#### How To Implement -This search has a dependency on other searches to create and update a baseline of users observed to be associated with this activity. The search "Previously Seen Cloud Instance Modifications By User - Update" should be enabled for this detection to properly work. - -#### Known False Positives -It's possible that a new user will start to modify EC2 instances when they haven't before for any number of reasons. Verify with the user that is modifying instances that this is the intended behavior. - -#### Associated Analytic story -* [Suspicious Cloud Instance Activities](/stories/suspicious_cloud_instance_activities) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 42.0 | 70 | 60 | User $user$ is modifying an instance $dest$ for the first time. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/cloud_instance_modified_by_previously_unseen_user.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-08-02-detect_f5_tmui_rce_cve-2020-5902.md b/docs/_posts/2020-08-02-detect_f5_tmui_rce_cve-2020-5902.md deleted file mode 100644 index 0bf065f1fb..0000000000 --- a/docs/_posts/2020-08-02-detect_f5_tmui_rce_cve-2020-5902.md +++ /dev/null @@ -1,158 +0,0 @@ ---- -title: "Detect F5 TMUI RCE CVE-2020-5902" -excerpt: "Exploit Public-Facing Application -" -categories: - - Web -last_modified_at: 2020-08-02 -toc: true -toc_label: "" -tags: - - Exploit Public-Facing Application - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2020-5902 ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search detects remote code exploit attempts on F5 BIG-IP, BIG-IQ, and Traffix SDC devices - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-08-02 -- **Author**: Shannon Davis, Splunk -- **ID**: 810e4dbc-d46e-11ea-87d0-0242ac130003 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1190](https://attack.mitre.org/techniques/T1190/) | Exploit Public-Facing Application | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 -* CIS 11 - - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2020-5902](https://nvd.nist.gov/vuln/detail/CVE-2020-5902) | In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has a Remote Code Execution (RCE) vulnerability in undisclosed pages. | 10.0 | - - - -
-
- -#### Search - -``` -`f5_bigip_rogue` -| regex _raw="(hsqldb; -|.*\\.\\.;.*)" -| search `detect_f5_tmui_rce_cve_2020_5902_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [f5_bigip_rogue](https://github.com/splunk/security_content/blob/develop/macros/f5_bigip_rogue.yml) - -> :information_source: -> **detect_f5_tmui_rce_cve-2020-5902_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -To consistently detect exploit attempts on F5 devices using the vulnerabilities contained within CVE-2020-5902 it is recommended to ingest logs via syslog. As many BIG-IP devices will have SSL enabled on their management interfaces, detections via wire data may not pick anything up unless you are decrypting SSL traffic in order to inspect it. I am using a regex string from a Cloudflare mitigation technique to try and always catch the offending string (..;), along with the other exploit of using (hsqldb;). - -#### Known False Positives -unknown - -#### Associated Analytic story -* [F5 TMUI RCE CVE-2020-5902](/stories/f5_tmui_rce_cve-2020-5902) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.ptsecurity.com/ww-en/about/news/f5-fixes-critical-vulnerability-discovered-by-positive-technologies-in-big-ip-application-delivery-controller/](https://www.ptsecurity.com/ww-en/about/news/f5-fixes-critical-vulnerability-discovered-by-positive-technologies-in-big-ip-application-delivery-controller/) -* [https://support.f5.com/csp/article/K52145254](https://support.f5.com/csp/article/K52145254) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/web/detect_f5_tmui_rce_cve_2020_5902.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-08-05-detect_new_open_gcp_storage_buckets.md b/docs/_posts/2020-08-05-detect_new_open_gcp_storage_buckets.md deleted file mode 100644 index 1b4266809c..0000000000 --- a/docs/_posts/2020-08-05-detect_new_open_gcp_storage_buckets.md +++ /dev/null @@ -1,166 +0,0 @@ ---- -title: "Detect New Open GCP Storage Buckets" -excerpt: "Data from Cloud Storage Object -" -categories: - - Cloud -last_modified_at: 2020-08-05 -toc: true -toc_label: "" -tags: - - Data from Cloud Storage Object - - Collection - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for GCP PubSub events where a user has created an open/public GCP Storage bucket. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-08-05 -- **Author**: Shannon Davis, Splunk -- **ID**: f6ea3466-d6bb-11ea-87d0-0242ac130003 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1530](https://attack.mitre.org/techniques/T1530/) | Data from Cloud Storage Object | Collection | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.DS -* PR.AC -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 13 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`google_gcp_pubsub_message` data.resource.type=gcs_bucket data.protoPayload.methodName=storage.setIamPermissions -| spath output=action path=data.protoPayload.serviceData.policyDelta.bindingDeltas{}.action -| spath output=user path=data.protoPayload.authenticationInfo.principalEmail -| spath output=location path=data.protoPayload.resourceLocation.currentLocations{} -| spath output=src path=data.protoPayload.requestMetadata.callerIp -| spath output=bucketName path=data.protoPayload.resourceName -| spath output=role path=data.protoPayload.serviceData.policyDelta.bindingDeltas{}.role -| spath output=member path=data.protoPayload.serviceData.policyDelta.bindingDeltas{}.member -| search (member=allUsers AND action=ADD) -| table _time, bucketName, src, user, location, action, role, member -| search `detect_new_open_gcp_storage_buckets_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [google_gcp_pubsub_message](https://github.com/splunk/security_content/blob/develop/macros/google_gcp_pubsub_message.yml) - -> :information_source: -> **detect_new_open_gcp_storage_buckets_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* data.resource.type -* data.protoPayload.methodName -* data.protoPayload.serviceData.policyDelta.bindingDeltas{}.action -* data.protoPayload.authenticationInfo.principalEmail -* data.protoPayload.resourceLocation.currentLocations{} -* data.protoPayload.requestMetadata.callerIp -* data.protoPayload.resourceName -* data.protoPayload.serviceData.policyDelta.bindingDeltas{}.role -* data.protoPayload.serviceData.policyDelta.bindingDeltas{}.member - - -#### How To Implement -This search relies on the Splunk Add-on for Google Cloud Platform, setting up a Cloud Pub/Sub input, along with the relevant GCP PubSub topics and logging sink to capture GCP Storage Bucket events (https://cloud.google.com/logging/docs/routing/overview). - -#### Known False Positives -While this search has no known false positives, it is possible that a GCP admin has legitimately created a public bucket for a specific purpose. That said, GCP strongly advises against granting full control to the "allUsers" group. - -#### Associated Analytic story -* [Suspicious GCP Storage Activities](/stories/suspicious_gcp_storage_activities) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/cloud/detect_new_open_gcp_storage_buckets.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-08-10-detect_gcp_storage_access_from_a_new_ip.md b/docs/_posts/2020-08-10-detect_gcp_storage_access_from_a_new_ip.md deleted file mode 100644 index acf476a817..0000000000 --- a/docs/_posts/2020-08-10-detect_gcp_storage_access_from_a_new_ip.md +++ /dev/null @@ -1,177 +0,0 @@ ---- -title: "Detect GCP Storage access from a new IP" -excerpt: "Data from Cloud Storage Object -" -categories: - - Cloud -last_modified_at: 2020-08-10 -toc: true -toc_label: "" -tags: - - Data from Cloud Storage Object - - Collection - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks at GCP Storage bucket-access logs and detects new or previously unseen remote IP addresses that have successfully accessed a GCP Storage bucket. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-08-10 -- **Author**: Shannon Davis, Splunk -- **ID**: ccc3246a-daa1-11ea-87d0-0242ac130022 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1530](https://attack.mitre.org/techniques/T1530/) | Data from Cloud Storage Object | Collection | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.DS -* PR.AC -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 13 -* CIS 14 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`google_gcp_pubsub_message` -| multikv -| rename sc_status_ as status -| rename cs_object_ as bucket_name -| rename c_ip_ as remote_ip -| rename cs_uri_ as request_uri -| rename cs_method_ as operation -| search status="\"200\"" -| stats earliest(_time) as firstTime latest(_time) as lastTime by bucket_name remote_ip operation request_uri -| table firstTime, lastTime, bucket_name, remote_ip, operation, request_uri -| inputlookup append=t previously_seen_gcp_storage_access_from_remote_ip -| stats min(firstTime) as firstTime, max(lastTime) as lastTime by bucket_name remote_ip operation request_uri -| outputlookup previously_seen_gcp_storage_access_from_remote_ip -| eval newIP=if(firstTime >= relative_time(now(),"-70m@m"), 1, 0) -| where newIP=1 -| eval first_time=strftime(firstTime,"%m/%d/%y %H:%M:%S") -| eval last_time=strftime(lastTime,"%m/%d/%y %H:%M:%S") -| table first_time last_time bucket_name remote_ip operation request_uri -| `detect_gcp_storage_access_from_a_new_ip_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [google_gcp_pubsub_message](https://github.com/splunk/security_content/blob/develop/macros/google_gcp_pubsub_message.yml) - -> :information_source: -> **detect_gcp_storage_access_from_a_new_ip_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Lookups -The SPL above uses the following Lookups: - -* [previously_seen_gcp_storage_access_from_remote_ip](https://github.com/splunk/security_content/blob/develop/lookups/previously_seen_gcp_storage_access_from_remote_ip.yml) with [data](https://github.com/splunk/security_content/tree/develop/lookups/previously_seen_gcp_storage_access_from_remote_ip.csv) -* [previously_seen_gcp_storage_access_from_remote_ip](https://github.com/splunk/security_content/blob/develop/lookups/previously_seen_gcp_storage_access_from_remote_ip.yml) with [data](https://github.com/splunk/security_content/tree/develop/lookups/previously_seen_gcp_storage_access_from_remote_ip.csv) - -#### Required field -* _time -* sc_status_ -* cs_object_ -* c_ip_ -* cs_uri_ -* cs_method_ - - -#### How To Implement -This search relies on the Splunk Add-on for Google Cloud Platform, setting up a Cloud Pub/Sub input, along with the relevant GCP PubSub topics and logging sink to capture GCP Storage Bucket events (https://cloud.google.com/logging/docs/routing/overview). In order to capture public GCP Storage Bucket access logs, you must also enable storage bucket logging to your PubSub Topic as per https://cloud.google.com/storage/docs/access-logs. These logs are deposited into the nominated Storage Bucket on an hourly basis and typically show up by 15 minutes past the hour. It is recommended to configure any saved searches or correlation searches in Enterprise Security to run on an hourly basis at 30 minutes past the hour (cron definition of 30 * * * *). A lookup table (previously_seen_gcp_storage_access_from_remote_ip.csv) stores the previously seen access requests, and is used by this search to determine any newly seen IP addresses accessing the Storage Buckets. - -#### Known False Positives -GCP Storage buckets can be accessed from any IP (if the ACLs are open to allow it), as long as it can make a successful connection. This will be a false postive, since the search is looking for a new IP within the past two hours. - -#### Associated Analytic story -* [Suspicious GCP Storage Activities](/stories/suspicious_gcp_storage_activities) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/cloud/detect_gcp_storage_access_from_a_new_ip.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-08-11-detect_arp_poisoning.md b/docs/_posts/2020-08-11-detect_arp_poisoning.md deleted file mode 100644 index d979e3ae58..0000000000 --- a/docs/_posts/2020-08-11-detect_arp_poisoning.md +++ /dev/null @@ -1,179 +0,0 @@ ---- -title: "Detect ARP Poisoning" -excerpt: "Hardware Additions -, Network Denial of Service -, Adversary-in-the-Middle -, ARP Cache Poisoning -" -categories: - - Network -last_modified_at: 2020-08-11 -toc: true -toc_label: "" -tags: - - Hardware Additions - - Network Denial of Service - - Adversary-in-the-Middle - - ARP Cache Poisoning - - Initial Access - - Impact - - Collection - - Credential Access - - Collection - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -By enabling Dynamic ARP Inspection as a Layer 2 Security measure on the organization's network devices, we will be able to detect ARP Poisoning attacks in the Infrastructure. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-08-11 -- **Author**: Mikael Bjerkeland, Splunk -- **ID**: b44bebd6-bd39-467b-9321-73971bcd7aac - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1200](https://attack.mitre.org/techniques/T1200/) | Hardware Additions | Initial Access | - -| [T1498](https://attack.mitre.org/techniques/T1498/) | Network Denial of Service | Impact | - -| [T1557](https://attack.mitre.org/techniques/T1557/) | Adversary-in-the-Middle | Collection, Credential Access | - -| [T1557.002](https://attack.mitre.org/techniques/T1557/002/) | ARP Cache Poisoning | Collection, Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance -* Delivery -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* ID.AM -* PR.DS - - - -
-
- -
- CIS20 - -
- -* CIS 1 -* CIS 11 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cisco_networks` facility="PM" mnemonic="ERR_DISABLE" disable_cause="arp-inspection" -| eval src_interface=src_int_prefix_long+src_int_suffix -| stats min(_time) AS firstTime max(_time) AS lastTime count BY host src_interface -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -| `detect_arp_poisoning_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [cisco_networks](https://github.com/splunk/security_content/blob/develop/macros/cisco_networks.yml) - -> :information_source: -> **detect_arp_poisoning_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* facility -* mnemonic -* disable_cause -* src_int_prefix_long -* src_int_suffix -* host -* src_interface - - -#### How To Implement -This search uses a standard SPL query on logs from Cisco Network devices. The network devices must be configured with DHCP Snooping (see https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst2960x/software/15-0_2_EX/security/configuration_guide/b_sec_152ex_2960-x_cg/b_sec_152ex_2960-x_cg_chapter_01101.html) and Dynamic ARP Inspection (see https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst2960x/software/15-2_2_e/security/configuration_guide/b_sec_1522e_2960x_cg/b_sec_1522e_2960x_cg_chapter_01111.html) and log with a severity level of minimum "5 - notification". The search also requires that the Cisco Networks Add-on for Splunk (https://splunkbase.splunk.com/app/1467) is used to parse the logs from the Cisco network devices. - -#### Known False Positives -This search might be prone to high false positives if DHCP Snooping or ARP inspection has been incorrectly configured, or if a device normally sends many ARP packets (unlikely). - -#### Associated Analytic story -* [Router and Infrastructure Security](/stories/router_and_infrastructure_security) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/network/detect_arp_poisoning.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-08-11-detect_rogue_dhcp_server.md b/docs/_posts/2020-08-11-detect_rogue_dhcp_server.md deleted file mode 100644 index 8b78997c54..0000000000 --- a/docs/_posts/2020-08-11-detect_rogue_dhcp_server.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: "Detect Rogue DHCP Server" -excerpt: "Hardware Additions -, Network Denial of Service -, Adversary-in-the-Middle -" -categories: - - Network -last_modified_at: 2020-08-11 -toc: true -toc_label: "" -tags: - - Hardware Additions - - Network Denial of Service - - Adversary-in-the-Middle - - Initial Access - - Impact - - Collection - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -By enabling DHCP Snooping as a Layer 2 Security measure on the organization's network devices, we will be able to detect unauthorized DHCP servers handing out DHCP leases to devices on the network (Man in the Middle attack). - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-08-11 -- **Author**: Mikael Bjerkeland, Splunk -- **ID**: 6e1ada88-7a0d-4ac1-92c6-03d354686079 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1200](https://attack.mitre.org/techniques/T1200/) | Hardware Additions | Initial Access | - -| [T1498](https://attack.mitre.org/techniques/T1498/) | Network Denial of Service | Impact | - -| [T1557](https://attack.mitre.org/techniques/T1557/) | Adversary-in-the-Middle | Collection, Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance -* Delivery -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* ID.AM -* PR.DS - - - -
-
- -
- CIS20 - -
- -* CIS 1 -* CIS 11 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cisco_networks` facility="DHCP_SNOOPING" mnemonic="DHCP_SNOOPING_UNTRUSTED_PORT" -| stats min(_time) AS firstTime max(_time) AS lastTime count values(message_type) AS message_type values(src_mac) AS src_mac BY host -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -| `detect_rogue_dhcp_server_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [cisco_networks](https://github.com/splunk/security_content/blob/develop/macros/cisco_networks.yml) - -> :information_source: -> **detect_rogue_dhcp_server_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* facility -* mnemonic -* message_type -* src_mac -* host - - -#### How To Implement -This search uses a standard SPL query on logs from Cisco Network devices. The network devices must be configured with DHCP Snooping enabled (see https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst2960x/software/15-0_2_EX/security/configuration_guide/b_sec_152ex_2960-x_cg/b_sec_152ex_2960-x_cg_chapter_01101.html) and log with a severity level of minimum "5 - notification". The search also requires that the Cisco Networks Add-on for Splunk (https://splunkbase.splunk.com/app/1467) is used to parse the logs from the Cisco network devices. - -#### Known False Positives -This search might be prone to high false positives if DHCP Snooping has been incorrectly configured or in the unlikely event that the DHCP server has been moved to another network interface. - -#### Associated Analytic story -* [Router and Infrastructure Security](/stories/router_and_infrastructure_security) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/network/detect_rogue_dhcp_server.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-08-16-cloud_provisioning_activity_from_previously_unseen_ip_address.md b/docs/_posts/2020-08-16-cloud_provisioning_activity_from_previously_unseen_ip_address.md deleted file mode 100644 index 5d755ac2d1..0000000000 --- a/docs/_posts/2020-08-16-cloud_provisioning_activity_from_previously_unseen_ip_address.md +++ /dev/null @@ -1,173 +0,0 @@ ---- -title: "Cloud Provisioning Activity From Previously Unseen IP Address" -excerpt: "Valid Accounts -" -categories: - - Cloud -last_modified_at: 2020-08-16 -toc: true -toc_label: "" -tags: - - Valid Accounts - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Change ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for cloud provisioning activities from previously unseen IP addresses. Provisioning activities are defined broadly as any event that runs or creates something. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Change](https://docs.splunk.com/Documentation/CIM/latest/User/Change)- **Datasource**: [Splunk Add-on for Amazon Kinesis Firehose](https://splunkbase.splunk.com/app/3719) -- **Last Updated**: 2020-08-16 -- **Author**: Rico Valdez, Splunk -- **ID**: f86a8ec9-b042-45eb-92f4-e9ed1d781078 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* ID.AM - - - -
-
- -
- CIS20 - -
- -* CIS 1 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats earliest(_time) as firstTime, latest(_time) as lastTime, values(All_Changes.object_id) as object_id from datamodel=Change where (All_Changes.action=started OR All_Changes.action=created) All_Changes.status=success by All_Changes.src, All_Changes.user, All_Changes.command -| `drop_dm_object_name("All_Changes")` -| lookup previously_seen_cloud_provisioning_activity_sources src as src OUTPUT firstTimeSeen, enough_data -| eventstats max(enough_data) as enough_data -| where enough_data=1 -| eval firstTimeSeenSrc=min(firstTimeSeen) -| where isnull(firstTimeSeenSrc) OR firstTimeSeenSrc > relative_time(now(), `previously_unseen_cloud_provisioning_activity_window`) -| table firstTime, src, user, object_id, command -| `cloud_provisioning_activity_from_previously_unseen_ip_address_filter` -| `security_content_ctime(firstTime)` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [previously_unseen_cloud_provisioning_activity_window](https://github.com/splunk/security_content/blob/develop/macros/previously_unseen_cloud_provisioning_activity_window.yml) - -> :information_source: -> **cloud_provisioning_activity_from_previously_unseen_ip_address_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Lookups -The SPL above uses the following Lookups: - -* [previously_seen_cloud_provisioning_activity_sources](https://github.com/splunk/security_content/blob/develop/lookups/previously_seen_cloud_provisioning_activity_sources.yml) with [data](https://github.com/splunk/security_content/tree/develop/lookups/previously_seen_cloud_provisioning_activity_sources.csv) - -#### Required field -* _time -* All_Changes.object_id -* All_Changes.action -* All_Changes.status -* All_Changes.src -* All_Changes.user -* All_Changes.command - - -#### How To Implement -You must be ingesting your cloud infrastructure logs from your cloud provider. You should run the baseline search `Previously Seen Cloud Provisioning Activity Sources - Initial` to build the initial table of source IP address, geographic locations, and times. You must also enable the second baseline search `Previously Seen Cloud Provisioning Activity Sources - Update` to keep this table up to date and to age out old data. You can adjust the time window for this search by updating the `previously_unseen_cloud_provisioning_activity_window` macro. You can also provide additional filtering for this search by customizing the `cloud_provisioning_activity_from_previously_unseen_ip_address_filter` macro. - -#### Known False Positives -This is a strictly behavioral search, so we define "false positive" slightly differently. Every time this fires, it will accurately reflect the first occurrence in the time period you're searching within, plus what is stored in the cache feature. But while there are really no "false positives" in a traditional sense, there is definitely lots of noise.\ - This search will fire any time a new IP address is seen in the **GeoIP** database for any kind of provisioning activity. If you typically do all provisioning from tools inside of your country, there should be few false positives. If you are located in countries where the free version of **MaxMind GeoIP** that ships by default with Splunk has weak resolution (particularly small countries in less economically powerful regions), this may be much less valuable to you. - -#### Associated Analytic story -* [Suspicious Cloud Provisioning Activities](/stories/suspicious_cloud_provisioning_activities) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 42.0 | 70 | 60 | User $user$ is starting or creating an instance $object_id$ for the first time from IP address $src$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/cloud_provisioning_activity_from_previously_unseen_ip_address.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-08-16-cloud_provisioning_activity_from_previously_unseen_region.md b/docs/_posts/2020-08-16-cloud_provisioning_activity_from_previously_unseen_region.md deleted file mode 100644 index ec5531bf28..0000000000 --- a/docs/_posts/2020-08-16-cloud_provisioning_activity_from_previously_unseen_region.md +++ /dev/null @@ -1,175 +0,0 @@ ---- -title: "Cloud Provisioning Activity From Previously Unseen Region" -excerpt: "Valid Accounts -" -categories: - - Cloud -last_modified_at: 2020-08-16 -toc: true -toc_label: "" -tags: - - Valid Accounts - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Change ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for cloud provisioning activities from previously unseen regions. Provisioning activities are defined broadly as any event that runs or creates something. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Change](https://docs.splunk.com/Documentation/CIM/latest/User/Change)- **Datasource**: [Splunk Add-on for Amazon Kinesis Firehose](https://splunkbase.splunk.com/app/3719) -- **Last Updated**: 2020-08-16 -- **Author**: Rico Valdez, Bhavin Patel, Splunk -- **ID**: 5aba1860-9617-4af9-b19d-aecac16fe4f2 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* ID.AM - - - -
-
- -
- CIS20 - -
- -* CIS 1 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats earliest(_time) as firstTime, latest(_time) as lastTime from datamodel=Change where (All_Changes.action=started OR All_Changes.action=created) All_Changes.status=success by All_Changes.src, All_Changes.user, All_Changes.object, All_Changes.command -| `drop_dm_object_name("All_Changes")` -| iplocation src -| where isnotnull(Region) -| lookup previously_seen_cloud_provisioning_activity_sources Region as Region OUTPUT firstTimeSeen, enough_data -| eventstats max(enough_data) as enough_data -| where enough_data=1 -| eval firstTimeSeenRegion=min(firstTimeSeen) -| where isnull(firstTimeSeenRegion) OR firstTimeSeenRegion > relative_time(now(), `previously_unseen_cloud_provisioning_activity_window`) -| table firstTime, src, Region, user, object, command -| `cloud_provisioning_activity_from_previously_unseen_region_filter` -| `security_content_ctime(firstTime)` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [previously_unseen_cloud_provisioning_activity_window](https://github.com/splunk/security_content/blob/develop/macros/previously_unseen_cloud_provisioning_activity_window.yml) - -> :information_source: -> **cloud_provisioning_activity_from_previously_unseen_region_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Lookups -The SPL above uses the following Lookups: - -* [previously_seen_cloud_provisioning_activity_sources](https://github.com/splunk/security_content/blob/develop/lookups/previously_seen_cloud_provisioning_activity_sources.yml) with [data](https://github.com/splunk/security_content/tree/develop/lookups/previously_seen_cloud_provisioning_activity_sources.csv) - -#### Required field -* _time -* All_Changes.action -* All_Changes.status -* All_Changes.src -* All_Changes.user -* All_Changes.object -* All_Changes.command - - -#### How To Implement -You must be ingesting your cloud infrastructure logs from your cloud provider. You should run the baseline search `Previously Seen Cloud Provisioning Activity Sources - Initial` to build the initial table of source IP address, geographic locations, and times. You must also enable the second baseline search `Previously Seen Cloud Provisioning Activity Sources - Update` to keep this table up to date and to age out old data. You can adjust the time window for this search by updating the `previously_unseen_cloud_provisioning_activity_window` macro. You can also provide additional filtering for this search by customizing the `cloud_provisioning_activity_from_previously_unseen_region_filter` macro. - -#### Known False Positives -This is a strictly behavioral search, so we define "false positive" slightly differently. Every time this fires, it will accurately reflect the first occurrence in the time period you're searching within, plus what is stored in the cache feature. But while there are really no "false positives" in a traditional sense, there is definitely lots of noise.\ - This search will fire any time a new IP address is seen in the **GeoIP** database for any kind of provisioning activity. If you typically do all provisioning from tools inside of your country, there should be few false positives. If you are located in countries where the free version of **MaxMind GeoIP** that ships by default with Splunk has weak resolution (particularly small countries in less economically powerful regions), this may be much less valuable to you. - -#### Associated Analytic story -* [Suspicious Cloud Provisioning Activities](/stories/suspicious_cloud_provisioning_activities) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 42.0 | 70 | 60 | User $user$ is starting or creating an instance $object$ for the first time in region $Region$ from IP address $src$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/cloud_provisioning_activity_from_previously_unseen_region.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_destroyed.md b/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_destroyed.md deleted file mode 100644 index 5169315b7a..0000000000 --- a/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_destroyed.md +++ /dev/null @@ -1,177 +0,0 @@ ---- -title: "Abnormally High Number Of Cloud Instances Destroyed" -excerpt: "Cloud Accounts -, Valid Accounts -" -categories: - - Cloud -last_modified_at: 2020-08-21 -toc: true -toc_label: "" -tags: - - Cloud Accounts - - Valid Accounts - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Change ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search finds for the number successfully destroyed cloud instances for every 4 hour block. This is split up between weekdays and the weekend. It then applies the probability densitiy model previously created and alerts on any outliers. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Change](https://docs.splunk.com/Documentation/CIM/latest/User/Change) -- **Last Updated**: 2020-08-21 -- **Author**: David Dorsey, Splunk -- **ID**: ef629fc9-1583-4590-b62a-f2247fbf7bbf - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1078.004](https://attack.mitre.org/techniques/T1078/004/) | Cloud Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.DP -* DE.AE - - - -
-
- -
- CIS20 - -
- -* CIS 13 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats count as instances_destroyed values(All_Changes.object_id) as object_id from datamodel=Change where All_Changes.action=deleted AND All_Changes.status=success AND All_Changes.object_category=instance by All_Changes.user _time span=1h -| `drop_dm_object_name("All_Changes")` -| eval HourOfDay=strftime(_time, "%H") -| eval HourOfDay=floor(HourOfDay/4)*4 -| eval DayOfWeek=strftime(_time, "%w") -| eval isWeekend=if(DayOfWeek >= 1 AND DayOfWeek <= 5, 0, 1) -| join HourOfDay isWeekend [summary cloud_excessive_instances_destroyed_v1] -| where cardinality >=16 -| apply cloud_excessive_instances_destroyed_v1 threshold=0.005 -| rename "IsOutlier(instances_destroyed)" as isOutlier -| where isOutlier=1 -| eval expected_upper_threshold = mvindex(split(mvindex(BoundaryRanges, -1), ":"), 0) -| eval distance_from_threshold = instances_destroyed - expected_upper_threshold -| table _time, user, instances_destroyed, expected_upper_threshold, distance_from_threshold, object_id -| `abnormally_high_number_of_cloud_instances_destroyed_filter` -``` - -#### Macros -The SPL above uses the following Macros: - -> :information_source: -> **abnormally_high_number_of_cloud_instances_destroyed_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* All_Changes.object_id -* All_Changes.action -* All_Changes.status -* All_Changes.object_category -* All_Changes.user - - -#### How To Implement -You must be ingesting your cloud infrastructure logs. You also must run the baseline search `Baseline Of Cloud Instances Destroyed` to create the probability density function. - -#### Known False Positives -Many service accounts configured within a cloud infrastructure are known to exhibit this behavior. Please adjust the threshold values and filter out service accounts from the output. Always verify if this search alerted on a human user. - -#### Associated Analytic story -* [Suspicious Cloud Instance Activities](/stories/suspicious_cloud_instance_activities) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/cloud/abnormally_high_number_of_cloud_instances_destroyed.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_launched.md b/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_launched.md deleted file mode 100644 index 8e4de14598..0000000000 --- a/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_launched.md +++ /dev/null @@ -1,178 +0,0 @@ ---- -title: "Abnormally High Number Of Cloud Instances Launched" -excerpt: "Cloud Accounts -, Valid Accounts -" -categories: - - Cloud -last_modified_at: 2020-08-21 -toc: true -toc_label: "" -tags: - - Cloud Accounts - - Valid Accounts - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Change ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search finds for the number successfully created cloud instances for every 4 hour block. This is split up between weekdays and the weekend. It then applies the probability densitiy model previously created and alerts on any outliers. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Change](https://docs.splunk.com/Documentation/CIM/latest/User/Change) -- **Last Updated**: 2020-08-21 -- **Author**: David Dorsey, Splunk -- **ID**: f2361e9f-3928-496c-a556-120cd4223a65 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1078.004](https://attack.mitre.org/techniques/T1078/004/) | Cloud Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.DP -* DE.AE - - - -
-
- -
- CIS20 - -
- -* CIS 13 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats count as instances_launched values(All_Changes.object_id) as object_id from datamodel=Change where (All_Changes.action=created) AND All_Changes.status=success AND All_Changes.object_category=instance by All_Changes.user _time span=1h -| `drop_dm_object_name("All_Changes")` -| eval HourOfDay=strftime(_time, "%H") -| eval HourOfDay=floor(HourOfDay/4)*4 -| eval DayOfWeek=strftime(_time, "%w") -| eval isWeekend=if(DayOfWeek >= 1 AND DayOfWeek <= 5, 0, 1) -| join HourOfDay isWeekend [summary cloud_excessive_instances_created_v1] -| where cardinality >=16 -| apply cloud_excessive_instances_created_v1 threshold=0.005 -| rename "IsOutlier(instances_launched)" as isOutlier -| where isOutlier=1 -| eval expected_upper_threshold = mvindex(split(mvindex(BoundaryRanges, -1), ":"), 0) -| eval distance_from_threshold = instances_launched - expected_upper_threshold -| table _time, user, instances_launched, expected_upper_threshold, distance_from_threshold, object_id -| `abnormally_high_number_of_cloud_instances_launched_filter` -``` - -#### Macros -The SPL above uses the following Macros: - -> :information_source: -> **abnormally_high_number_of_cloud_instances_launched_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* All_Changes.object_id -* All_Changes.action -* All_Changes.status -* All_Changes.object_category -* All_Changes.user - - -#### How To Implement -You must be ingesting your cloud infrastructure logs. You also must run the baseline search `Baseline Of Cloud Instances Launched` to create the probability density function. - -#### Known False Positives -Many service accounts configured within an AWS infrastructure are known to exhibit this behavior. Please adjust the threshold values and filter out service accounts from the output. Always verify if this search alerted on a human user. - -#### Associated Analytic story -* [Cloud Cryptomining](/stories/cloud_cryptomining) -* [Suspicious Cloud Instance Activities](/stories/suspicious_cloud_instance_activities) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/cloud/abnormally_high_number_of_cloud_instances_launched.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2020-08-25-phishing_email_detection_by_machine_learning_method_-_ssa.md b/docs/_posts/2020-08-25-phishing_email_detection_by_machine_learning_method_-_ssa.md deleted file mode 100644 index bfef2b3a5c..0000000000 --- a/docs/_posts/2020-08-25-phishing_email_detection_by_machine_learning_method_-_ssa.md +++ /dev/null @@ -1,93 +0,0 @@ ---- -title: "Phishing Email Detection by Machine Learning Method - SSA" -excerpt: "Phishing" -categories: - - Application -last_modified_at: 2020-08-25 -toc: true -toc_label: "" -tags: - - Phishing - - Initial Access - - Splunk Behavioral Analytics ---- - -### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Malicious mails can conduct phishing that induces readers to open attachment, click links or trigger third party service. This detect uses Natural Language Processing (NLP) approach to analyze an email message's content (Sender, Subject and Body) and judge whether it is a phishing email. The detection adopts a deep learning (neural network) model that employs character level embeddings plus LSTM layers to perform classification. The model is pre-trained and then published as ONNX format. Current sample model is trained using the dataset published at https://github.com/splunk/attack_data/tree/master/datasets/T1566_Phishing_Email/splunk_train.json User are expected to re-train the model by combining with their own training data for better accuracy using the provided model file (SMLE notebook). DSP pipeline then processes the email message and passes it as an event to Apply ML Models function, which returns the probability of a phishing email. Current implementation assumes the email is fed to DSP in JSON format contains at least email's sender, subject and its message body, including reply content, if any. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: -- **Last Updated**: 2020-08-25 -- **Author**: Xiao Lin, Splunk -- **ID**: 4b237388-dfa1-41a6-91d4-4de2d598376f - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | - -#### Search - -``` - -| from read_ssa_enriched_events() -| eval eventLine=concat(ucast(map_get(input_event, "From"), "string", " "), " ", ucast(map_get(input_event, "Subject"), "string", " "), " ", ucast(map_get(input_event, "Content"), "string", " "), " "), _time=map_get(input_event, "_time") -| where eventLine IS NOT NULL -| eval mapC={" ": 32, "!": 33, "\"": 34, "#": 35, "$": 36, "%": 37, "&": 38, "`": 39, "(": 40, ")": 41, "*": 42, "+": 43, ",": 44, "-": 45, ".": 46, "/": 47, "0": 48, "1": 49, "2": 50, "3": 51, "4": 52, "5": 53, "6": 54, "7": 55, "8": 56, "9": 57, ":": 58, ";": 59, "<": 60, "=": 61, ">": 62, "?": 63, "@": 64, "A": 65, "B": 66, "C": 67, "D": 68, "E": 69, "F": 70, "G": 71, "H": 72, "I": 73, "J": 74, "K": 75, "L": 76, "M": 77, "N": 78, "O": 79, "P": 80, "Q": 81, "R": 82, "S": 83, "T": 84, "U": 85, "V": 86, "W": 87, "X": 88, "Y": 89, "Z": 90, "[": 91, "\\": 92, "]": 93, "^": 94, "_": 95, "`": 96, "a": 97, "b": 98, "c": 99, "d": 100, "e": 101, "f": 102, "g": 103, "h": 104, "i": 105, "j": 106, "k": 107, "l": 108, "m": 109, "n": 110, "o": 111, "p": 112, "q": 113, "r": 114, "s": 115, "t": 116, "u": 117, "v": 118, "w": 119, "x": 120, "y": 121, "z": 122, "{": 123, " -|": 124, "}": 125, "~": 126}, ml_in = for_each(iterator(mvrange(1,129), "i"), cast(map_get(mapC, substr(eventLine, i, 1)), "float") ) -| apply_model connection_id="YOUR_S3_ONNX_CONNECTOR_ID" name="phishing_email_v8" path="s3://smle-experiments/models/phishing_email" -| eval probability = mvindex(ml_out, 0) -| where probability > 0.5 -| eval start_time=_time, end_time=_time, entities="TBD", body="TBD" -| select probability, body, entities, start_time, end_time -| into write_ssa_detected_events(); -``` - -#### Macros -The SPL above uses the following Macros: - -Note that `phishing_email_detection_by_machine_learning_method_-_ssa_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field - - -#### How To Implement -Events are fed to DSP contains at least email's sender, subject and its message body. - -#### Known False Positives -Because of imbalance of anomaly data in training, the model will less likely report false positive. Instead, the model is more prone to false negative. Current best recall score is ~85% - -#### Associated Analytic story - - -#### Kill Chain Phase -* Actions on Objectives - - - - -Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` - - - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/application/phishing_email_detection_by_machine_learning_method_-_ssa.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-08-25-system_process_running_from_unexpected_location.md b/docs/_posts/2020-08-25-system_process_running_from_unexpected_location.md deleted file mode 100644 index a8c7f7b4b9..0000000000 --- a/docs/_posts/2020-08-25-system_process_running_from_unexpected_location.md +++ /dev/null @@ -1,125 +0,0 @@ ---- -title: "System Process Running from Unexpected Location" -excerpt: "Masquerading" -categories: - - Endpoint -last_modified_at: 2020-08-25 -toc: true -toc_label: "" -tags: - - Masquerading - - Defense Evasion - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -An attacker tries might try to use different version of a system command without overriding original, or they might try to avoid some detection running the process from a different folder. This detection checks that a list of system processes run inside C:\\Windows\System32 or C:\\Windows\SysWOW64 The list of system processes has been extracted from https://github.com/splunk/security_content/blob/develop/lookups/is_windows_system_file.csv and the original detection https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2020-08-25 -- **Author**: Ignacio Bermudez Corrales, Splunk -- **ID**: 28179107-099a-464a-94d3-08301e6c055f - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1036](https://attack.mitre.org/techniques/T1036/) | Masquerading | Defense Evasion | - -#### Search - -``` - $ssa_input = -| from read_ssa_enriched_events() -| eval device=ucast(map_get(input_event, "dest_device_id"), "string", null), user=ucast(map_get(input_event, "dest_user_id"), "string", null), timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), process_path=lower(ucast(map_get(input_event, "process_path"), "string", null)), event_id=ucast(map_get(input_event, "event_id"), "string", null); -$cond_1 = -| from $ssa_input -| where process_name="arp.exe" OR process_name="adaptertroubleshooter.exe" OR process_name="applicationframehost.exe" OR process_name="atbroker.exe" OR process_name="authhost.exe" OR process_name="autoworkplace.exe" OR process_name="axinstui.exe" OR process_name="backgroundtransferhost.exe" OR process_name="bdehdcfg.exe" OR process_name="bdeuisrv.exe" OR process_name="bdeunlockwizard.exe" OR process_name="bitlockerdeviceencryption.exe" OR process_name="bitlockerwizard.exe" OR process_name="bitlockerwizardelev.exe" OR process_name="bytecodegenerator.exe" OR process_name="camerasettingsuihost.exe" OR process_name="castsrv.exe" OR process_name="certenrollctrl.exe" OR process_name="checknetisolation.exe" OR process_name="clipup.exe" OR process_name="cloudexperiencehostbroker.exe" OR process_name="cloudnotifications.exe" OR process_name="cloudstoragewizard.exe" OR process_name="compmgmtlauncher.exe" OR process_name="compattelrunner.exe" OR process_name="computerdefaults.exe" OR process_name="credentialuibroker.exe" OR process_name="dfdwiz.exe" OR process_name="dwwin.exe" OR process_name="dataexchangehost.exe" OR process_name="defrag.exe" OR process_name="devicedisplayobjectprovider.exe" OR process_name="deviceeject.exe" OR process_name="deviceenroller.exe" OR process_name="devicepairingwizard.exe" OR process_name="deviceproperties.exe" OR process_name="disksnapshot.exe" OR process_name="dism.exe" OR process_name="displayswitch.exe" OR process_name="dmnotificationbroker.exe" OR process_name="dmomacpmo.exe" OR process_name="dpiscaling.exe" OR process_name="dsmusertask.exe" OR process_name="dxpserver.exe" OR process_name="edpcleanup.exe" OR process_name="eosnotify.exe" OR process_name="eap3host.exe" OR process_name="easpoliciesbrokerhost.exe" OR process_name="easeofaccessdialog.exe" OR process_name="ehstorauthn.exe" OR process_name="fxscover.exe" OR process_name="fxssvc.exe" OR process_name="fxsunatd.exe" OR process_name="filehistory.exe" OR process_name="fondue.exe" OR process_name="gamepanel.exe" OR process_name="genvalobj.exe" OR process_name="gettingstarted.exe" OR process_name="hostname.exe" OR process_name="icsentitlementhost.exe" OR process_name="infdefaultinstall.exe" OR process_name="installagent.exe" OR process_name="languagecomponentsinstallercomhandler.exe" OR process_name="launchtm.exe" OR process_name="launchwinapp.exe" OR process_name="legacynetuxhost.exe" OR process_name="licensemanagershellext.exe" OR process_name="licensingui.exe" OR process_name="locationnotificationwindows.exe" OR process_name="locationnotifications.exe" OR process_name="locator.exe" OR process_name="lockapphost.exe" OR process_name="lockscreencontentserver.exe" OR process_name="logonui.exe" OR process_name="lsaiso.exe" OR process_name="mdeserver.exe" OR process_name="mdmagent.exe" OR process_name="mdmappinstaller.exe" OR process_name="mrinfo.exe" OR process_name="mrt.exe" OR process_name="mschedexe.exe" OR process_name="magnify.exe" OR process_name="mbaeparsertask.exe" OR process_name="mdres.exe" OR process_name="mdsched.exe" OR process_name="migautoplay.exe" OR process_name="mpsigstub.exe" OR process_name="msspellcheckinghost.exe" OR process_name="muiunattend.exe" OR process_name="multidigimon.exe" OR process_name="musnotification.exe" OR process_name="musnotificationux.exe" OR process_name="napstat.exe" OR process_name="netstat.exe" OR process_name="narrator.exe" OR process_name="netcfgnotifyobjecthost.exe" OR process_name="netevtfwdr.exe" OR process_name="netproj.exe" OR process_name="netplwiz.exe" OR process_name="networkuxbroker.exe"; -$cond_2 = -| from $ssa_input -| where process_name="openwith.exe" OR process_name="optionalfeatures.exe" OR process_name="pathping.exe" OR process_name="ping.exe" OR process_name="passwordonwakesettingflyout.exe" OR process_name="pickerhost.exe" OR process_name="pkgmgr.exe" OR process_name="pnpunattend.exe" OR process_name="pnputil.exe" OR process_name="presentationhost.exe" OR process_name="presentationsettings.exe" OR process_name="printbrmui.exe" OR process_name="printdialoghost.exe" OR process_name="printdialoghost3d.exe" OR process_name="printisolationhost.exe" OR process_name="proximityuxhost.exe" OR process_name="rdspnf.exe" OR process_name="rmactivate.exe" OR process_name="rmactivate_isv.exe" OR process_name="rmactivate_ssp.exe" OR process_name="rmactivate_ssp_isv.exe" OR process_name="route.exe" OR process_name="rdpsa.exe" OR process_name="rdpsaproxy.exe" OR process_name="rdpsauachelper.exe" OR process_name="reagentc.exe" OR process_name="recoverydrive.exe" OR process_name="register-cimprovider.exe" OR process_name="registeriepkeys.exe" OR process_name="relpost.exe" OR process_name="remoteposworker.exe" OR process_name="rmclient.exe" OR process_name="robocopy.exe" OR process_name="rpcping.exe" OR process_name="runlegacycplelevated.exe" OR process_name="runtimebroker.exe" OR process_name="sihclient.exe" OR process_name="searchfilterhost.exe" OR process_name="searchindexer.exe" OR process_name="searchprotocolhost.exe" OR process_name="secedit.exe" OR process_name="sensordataservice.exe" OR process_name="setieinstalleddate.exe" OR process_name="settingsynchost.exe" OR process_name="slidetoshutdown.exe" OR process_name="smartscreensettings.exe" OR process_name="sndvol.exe" OR process_name="snippingtool.exe" OR process_name="soundrecorder.exe" OR process_name="spaceagent.exe" OR process_name="sppextcomobj.exe" OR process_name="srtasks.exe" OR process_name="stikynot.exe" OR process_name="synchost.exe" OR process_name="sysreseterr.exe" OR process_name="systempropertiesadvanced.exe" OR process_name="systempropertiescomputername.exe" OR process_name="systempropertiesdataexecutionprevention.exe" OR process_name="systempropertieshardware.exe" OR process_name="systempropertiesperformance.exe" OR process_name="systempropertiesprotection.exe" OR process_name="systempropertiesremote.exe" OR process_name="systemsettingsadminflows.exe" OR process_name="systemsettingsbroker.exe" OR process_name="systemsettingsremovedevice.exe" OR process_name="tcpsvcs.exe" OR process_name="tracert.exe" OR process_name="tstheme.exe" OR process_name="tswbprxy.exe" OR process_name="tapiunattend.exe" OR process_name="taskmgr.exe" OR process_name="thumbnailextractionhost.exe" OR process_name="tokenbrokercookies.exe" OR process_name="tpminit.exe" OR process_name="tswpfwrp.exe" OR process_name="ui0detect.exe" OR process_name="upgraderesultsui.exe" OR process_name="useraccountbroker.exe" OR process_name="useraccountcontrolsettings.exe" OR process_name="usoclient.exe" OR process_name="utilman.exe" OR process_name="vssvc.exe" OR process_name="vaultcmd.exe" OR process_name="vaultsysui.exe" OR process_name="wfs.exe" OR process_name="wmpdmc.exe" OR process_name="wpdshextautoplay.exe" OR process_name="wscollect.exe" OR process_name="wsmanhttpconfig.exe" OR process_name="wsreset.exe" OR process_name="wudfhost.exe" OR process_name="wwahost.exe" OR process_name="wallpaperhost.exe" OR process_name="webcache.exe" OR process_name="werfault.exe" OR process_name="werfaultsecure.exe" OR process_name="winsat.exe" OR process_name="windows.media.backgroundplayback.exe" OR process_name="windowsactiondialog.exe" OR process_name="windowsanytimeupgrade.exe" OR process_name="windowsanytimeupgraderesults.exe"; -$cond_3 = -| from $ssa_input -| where process_name="windowsanytimeupgradeui.exe" OR process_name="windowsupdateelevatedinstaller.exe" OR process_name="workfolders.exe" OR process_name="wpcmon.exe" OR process_name="acu.exe" OR process_name="aitagent.exe" OR process_name="aitstatic.exe" OR process_name="alg.exe" OR process_name="appidcertstorecheck.exe" OR process_name="appidpolicyconverter.exe" OR process_name="at.exe" OR process_name="attrib.exe" OR process_name="audiodg.exe" OR process_name="auditpol.exe" OR process_name="autochk.exe" OR process_name="autoconv.exe" OR process_name="autofmt.exe" OR process_name="baaupdate.exe" OR process_name="backgroundtaskhost.exe" OR process_name="bcastdvr.exe" OR process_name="bcdboot.exe" OR process_name="bcdedit.exe" OR process_name="bdechangepin.exe" OR process_name="bdeunlock.exe" OR process_name="bitsadmin.exe" OR process_name="bootcfg.exe" OR process_name="bootim.exe" OR process_name="bootsect.exe" OR process_name="bridgeunattend.exe" OR process_name="browser_broker.exe" OR process_name="bthudtask.exe" OR process_name="cacls.exe" OR process_name="calc.exe" OR process_name="cdpreference.exe" OR process_name="certreq.exe" OR process_name="certutil.exe" OR process_name="change.exe" OR process_name="changepk.exe" OR process_name="charmap.exe" OR process_name="chglogon.exe" OR process_name="chgport.exe" OR process_name="chgusr.exe" OR process_name="chkdsk.exe" OR process_name="chkntfs.exe" OR process_name="choice.exe" OR process_name="cipher.exe" OR process_name="cleanmgr.exe" OR process_name="cliconfg.exe" OR process_name="clip.exe" OR process_name="cmd.exe" OR process_name="cmdkey.exe" OR process_name="cmdl32.exe" OR process_name="cmmon32.exe" OR process_name="cmstp.exe" OR process_name="cofire.exe" OR process_name="colorcpl.exe" OR process_name="comp.exe" OR process_name="compact.exe" OR process_name="conhost.exe" OR process_name="consent.exe" OR process_name="control.exe" OR process_name="convert.exe" OR process_name="credwiz.exe" OR process_name="cscript.exe" OR process_name="csrss.exe" OR process_name="ctfmon.exe" OR process_name="cttune.exe" OR process_name="cttunesvr.exe" OR process_name="dashost.exe" OR process_name="dccw.exe" OR process_name="dcomcnfg.exe" OR process_name="ddodiag.exe" OR process_name="dfrgui.exe" OR process_name="dialer.exe" OR process_name="diantz.exe" OR process_name="dinotify.exe" OR process_name="diskpart.exe" OR process_name="diskperf.exe" OR process_name="diskraid.exe" OR process_name="dispdiag.exe" OR process_name="djoin.exe" OR process_name="dllhost.exe" OR process_name="dllhst3g.exe" OR process_name="dmcertinst.exe" OR process_name="dmcfghost.exe" OR process_name="dmclient.exe" OR process_name="dnscacheugc.exe" OR process_name="doskey.exe" OR process_name="dpapimig.exe" OR process_name="dpnsvr.exe" OR process_name="driverquery.exe" OR process_name="drvcfg.exe" OR process_name="drvinst.exe" OR process_name="dsregcmd.exe" OR process_name="dstokenclean.exe" OR process_name="dvdplay.exe" OR process_name="dvdupgrd.exe" OR process_name="dwm.exe" OR process_name="dxdiag.exe" OR process_name="easinvoker.exe" OR process_name="efsui.exe"; -$cond_4 = -| from $ssa_input -| where process_name="embeddedapplauncher.exe" OR process_name="esentutl.exe" OR process_name="eudcedit.exe" OR process_name="eventcreate.exe" OR process_name="eventvwr.exe" OR process_name="expand.exe" OR process_name="extrac32.exe" OR process_name="fc.exe" OR process_name="fhmanagew.exe" OR process_name="find.exe" OR process_name="findstr.exe" OR process_name="finger.exe" OR process_name="fixmapi.exe" OR process_name="fltmc.exe" OR process_name="fodhelper.exe" OR process_name="fontdrvhost.exe" OR process_name="fontview.exe" OR process_name="forfiles.exe" OR process_name="fsavailux.exe" OR process_name="fsquirt.exe" OR process_name="fsutil.exe" OR process_name="ftp.exe" OR process_name="fvenotify.exe" OR process_name="fveprompt.exe" OR process_name="getmac.exe" OR process_name="gpresult.exe" OR process_name="gpscript.exe" OR process_name="gpupdate.exe" OR process_name="grpconv.exe" OR process_name="hdwwiz.exe" OR process_name="help.exe" OR process_name="hwrcomp.exe" OR process_name="hwrreg.exe" OR process_name="icacls.exe" OR process_name="icardagt.exe" OR process_name="icsunattend.exe" OR process_name="ie4uinit.exe" OR process_name="ieunatt.exe" OR process_name="ieetwcollector.exe" OR process_name="iexpress.exe" OR process_name="immersivetpmvscmgrsvr.exe" OR process_name="ipconfig.exe" OR process_name="irftp.exe" OR process_name="iscsicli.exe" OR process_name="iscsicpl.exe" OR process_name="isoburn.exe" OR process_name="klist.exe" OR process_name="ksetup.exe" OR process_name="ktmutil.exe" OR process_name="label.exe" OR process_name="licensingdiag.exe" OR process_name="lodctr.exe" OR process_name="logagent.exe" OR process_name="logman.exe" OR process_name="logoff.exe" OR process_name="lpkinstall.exe" OR process_name="lpksetup.exe" OR process_name="lpremove.exe" OR process_name="lsass.exe" OR process_name="lsm.exe" OR process_name="makecab.exe" OR process_name="manage-bde.exe" OR process_name="mblctr.exe" OR process_name="mcbuilder.exe" OR process_name="mctadmin.exe" OR process_name="mfpmp.exe" OR process_name="mmc.exe" OR process_name="mobsync.exe" OR process_name="mountvol.exe" OR process_name="mpnotify.exe" OR process_name="msconfig.exe" OR process_name="msdt.exe" OR process_name="msdtc.exe" OR process_name="msfeedssync.exe" OR process_name="msg.exe" OR process_name="mshta.exe" OR process_name="msiexec.exe" OR process_name="msinfo32.exe" OR process_name="mspaint.exe" OR process_name="msra.exe" OR process_name="mstsc.exe" OR process_name="mtstocom.exe" OR process_name="nbtstat.exe" OR process_name="ndadmin.exe" OR process_name="net.exe" OR process_name="net1.exe" OR process_name="netbtugc.exe" OR process_name="netcfg.exe" OR process_name="netiougc.exe" OR process_name="netsh.exe" OR process_name="newdev.exe" OR process_name="nltest.exe" OR process_name="notepad.exe" OR process_name="nslookup.exe" OR process_name="ntoskrnl.exe" OR process_name="ntprint.exe" OR process_name="ocsetup.exe" OR process_name="odbcad32.exe" OR process_name="odbcconf.exe" OR process_name="omadmclient.exe" OR process_name="omadmprc.exe"; -$cond_5 = -| from $ssa_input -| where process_name="openfiles.exe" OR process_name="osk.exe" OR process_name="p2phost.exe" OR process_name="pcalua.exe" OR process_name="pcaui.exe" OR process_name="pcawrk.exe" OR process_name="pcwrun.exe" OR process_name="perfmon.exe" OR process_name="phoneactivate.exe" OR process_name="plasrv.exe" OR process_name="poqexec.exe" OR process_name="powercfg.exe" OR process_name="prevhost.exe" OR process_name="print.exe" OR process_name="printfilterpipelinesvc.exe" OR process_name="printui.exe" OR process_name="proquota.exe" OR process_name="provtool.exe" OR process_name="psr.exe" OR process_name="pwlauncher.exe" OR process_name="qappsrv.exe" OR process_name="qprocess.exe" OR process_name="query.exe" OR process_name="quser.exe" OR process_name="qwinsta.exe" OR process_name="rasautou.exe" OR process_name="rasdial.exe" OR process_name="raserver.exe" OR process_name="rasphone.exe" OR process_name="rdpclip.exe" OR process_name="rdpinput.exe" OR process_name="rdrleakdiag.exe" OR process_name="recdisc.exe" OR process_name="recover.exe" OR process_name="reg.exe" OR process_name="regedt32.exe" OR process_name="regini.exe" OR process_name="regsvr32.exe" OR process_name="rekeywiz.exe" OR process_name="relog.exe" OR process_name="repair-bde.exe" OR process_name="replace.exe" OR process_name="reset.exe" OR process_name="resmon.exe" OR process_name="rmttpmvscmgrsvr.exe" OR process_name="rrinstaller.exe" OR process_name="rstrui.exe" OR process_name="runas.exe" OR process_name="rundll32.exe" OR process_name="runonce.exe" OR process_name="rwinsta.exe" OR process_name="sbunattend.exe" OR process_name="sc.exe" OR process_name="schtasks.exe" OR process_name="sdbinst.exe" OR process_name="sdchange.exe" OR process_name="sdclt.exe" OR process_name="sdiagnhost.exe" OR process_name="secinit.exe" OR process_name="services.exe" OR process_name="sessionmsg.exe" OR process_name="sethc.exe" OR process_name="setspn.exe" OR process_name="setupcl.exe" OR process_name="setupugc.exe" OR process_name="setx.exe" OR process_name="sfc.exe" OR process_name="shadow.exe" OR process_name="shrpubw.exe" OR process_name="shutdown.exe" OR process_name="sigverif.exe" OR process_name="sihost.exe" OR process_name="slui.exe" OR process_name="smss.exe" OR process_name="snmptrap.exe" OR process_name="sort.exe" OR process_name="spinstall.exe" OR process_name="spoolsv.exe" OR process_name="sppsvc.exe" OR process_name="spreview.exe" OR process_name="srdelayed.exe" OR process_name="subst.exe" OR process_name="svchost.exe" OR process_name="sxstrace.exe" OR process_name="syskey.exe" OR process_name="systeminfo.exe" OR process_name="systemreset.exe" OR process_name="systray.exe" OR process_name="tabcal.exe" OR process_name="takeown.exe" OR process_name="taskeng.exe" OR process_name="taskhost.exe" OR process_name="taskhostw.exe" OR process_name="taskkill.exe" OR process_name="tasklist.exe" OR process_name="taskmgr.exe" OR process_name="tcmsetup.exe" OR process_name="timeout.exe" OR process_name="tpmvscmgr.exe" OR process_name="tpmvscmgrsvr.exe"; -$cond_6 = -| from $ssa_input -| where process_name="tracerpt.exe" OR process_name="tscon.exe" OR process_name="tsdiscon.exe" OR process_name="tskill.exe" OR process_name="typeperf.exe" OR process_name="tzsync.exe" OR process_name="tzutil.exe" OR process_name="ucsvc.exe" OR process_name="unlodctr.exe" OR process_name="unregmp2.exe" OR process_name="upnpcont.exe" OR process_name="userinit.exe" OR process_name="vds.exe" OR process_name="vdsldr.exe" OR process_name="verclsid.exe" OR process_name="verifier.exe" OR process_name="verifiergui.exe" OR process_name="vmicsvc.exe" OR process_name="vssadmin.exe" OR process_name="w32tm.exe" OR process_name="waitfor.exe" OR process_name="wbadmin.exe" OR process_name="wbengine.exe" OR process_name="wecutil.exe" OR process_name="wermgr.exe" OR process_name="wevtutil.exe" OR process_name="wextract.exe" OR process_name="where.exe" OR process_name="whoami.exe" OR process_name="wiaacmgr.exe" OR process_name="wiawow64.exe" OR process_name="wifitask.exe" OR process_name="wimserv.exe" OR process_name="wininit.exe" OR process_name="winload.exe" OR process_name="winlogon.exe" OR process_name="winresume.exe" OR process_name="winrs.exe" OR process_name="winrshost.exe" OR process_name="winver.exe" OR process_name="wisptis.exe" OR process_name="wkspbroker.exe" OR process_name="wksprt.exe" OR process_name="wlanext.exe" OR process_name="wlrmdr.exe" OR process_name="wowreg32.exe" OR process_name="wpnpinst.exe" OR process_name="wpr.exe" OR process_name="write.exe" OR process_name="wscript.exe" OR process_name="wsmprovhost.exe" OR process_name="wsqmcons.exe" OR process_name="wuapihost.exe" OR process_name="wuapp.exe" OR process_name="wuauclt.exe" OR process_name="wusa.exe" OR process_name="xcopy.exe" OR process_name="xpsrchvw.exe" OR process_name="xwizard.exe"; - -| from $cond_1 -| union $cond_2 -| union $cond_3 -| union $cond_4 -| union $cond_5 -| union $cond_6 -| where match_regex(process_path, /(?i)\\windows\\system32/)=false AND match_regex(process_path, /(?i)\\windows\\syswow64/)=false -| eval start_time=timestamp, end_time=timestamp, entities=mvappend(device, user), body=create_map(["event_id", event_id, "process_path", process_path, "process_name", process_name]) -| into write_ssa_detected_events(); -``` - -#### Macros -The SPL above uses the following Macros: - -Note that `system_process_running_from_unexpected_location_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* dest_device_id -* process_name -* _time -* dest_user_id -* process_path - - -#### How To Implement -Collect endpoint data such as sysmon or 4688 events. - -#### Known False Positives -None - -#### Associated Analytic story -* [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics) -* [Masquerading - Rename System Utilities](/stories/masquerading_-_rename_system_utilities) - - -#### Kill Chain Phase -* Actions on Objectives - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 56.0 | 70 | 80 | A system process $process_name$ with commandline $cmd_line$ spawn in non-default folder path in host $dest_device_id$ | - - -Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` - - - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036/system_process_running_unexpected_location/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036/system_process_running_unexpected_location/windows-security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/system_process_running_from_unexpected_location.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2020-08-25-unusual_lolbas_in_short_period_of_time.md b/docs/_posts/2020-08-25-unusual_lolbas_in_short_period_of_time.md deleted file mode 100644 index a927fb39b3..0000000000 --- a/docs/_posts/2020-08-25-unusual_lolbas_in_short_period_of_time.md +++ /dev/null @@ -1,111 +0,0 @@ ---- -title: "Unusual LOLBAS in short period of time" -excerpt: "Command and Scripting Interpreter, Scheduled Task/Job" -categories: - - Endpoint -last_modified_at: 2020-08-25 -toc: true -toc_label: "" -tags: - - Command and Scripting Interpreter - - Execution - - Scheduled Task/Job - - Execution - - Persistence - - Privilege Escalation - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Attacker activity may compromise executing several LOLBAS applications in conjunction to accomplish their objectives. We are looking for more than usual LOLBAS applications over a window of time, by building profiles per machine. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2020-08-25 -- **Author**: Ignacio Bermudez Corrales, Splunk -- **ID**: 59c0dd70-169c-4900-9a1f-bfcf13302f93 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -| [T1053](https://attack.mitre.org/techniques/T1053/) | Scheduled Task/Job | Execution, Persistence, Privilege Escalation | - -#### Search - -``` - -| from read_ssa_enriched_events() -| eval device=ucast(map_get(input_event, "dest_device_id"), "string", null), process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)) -| where process_name=="regsvcs.exe" OR process_name=="ftp.exe" OR process_name=="dfsvc.exe" OR process_name=="rasautou.exe" OR process_name=="schtasks.exe" OR process_name=="xwizard.exe" OR process_name=="findstr.exe" OR process_name=="esentutl.exe" OR process_name=="cscript.exe" OR process_name=="reg.exe" OR process_name=="csc.exe" OR process_name=="atbroker.exe" OR process_name=="print.exe" OR process_name=="pcwrun.exe" OR process_name=="vbc.exe" OR process_name=="rpcping.exe" OR process_name=="wsreset.exe" OR process_name=="ilasm.exe" OR process_name=="certutil.exe" OR process_name=="replace.exe" OR process_name=="mshta.exe" OR process_name=="bitsadmin.exe" OR process_name=="wscript.exe" OR process_name=="ieexec.exe" OR process_name=="cmd.exe" OR process_name=="microsoft.workflow.compiler.exe" OR process_name=="runscripthelper.exe" OR process_name=="makecab.exe" OR process_name=="forfiles.exe" OR process_name=="desktopimgdownldr.exe" OR process_name=="control.exe" OR process_name=="msbuild.exe" OR process_name=="register-cimprovider.exe" OR process_name=="tttracer.exe" OR process_name=="ie4uinit.exe" OR process_name=="sc.exe" OR process_name=="bash.exe" OR process_name=="hh.exe" OR process_name=="cmstp.exe" OR process_name=="mmc.exe" OR process_name=="jsc.exe" OR process_name=="scriptrunner.exe" OR process_name=="odbcconf.exe" OR process_name=="extexport.exe" OR process_name=="msdt.exe" OR process_name=="diskshadow.exe" OR process_name=="extrac32.exe" OR process_name=="eventvwr.exe" OR process_name=="mavinject.exe" OR process_name=="regasm.exe" OR process_name=="gpscript.exe" OR process_name=="rundll32.exe" OR process_name=="regsvr32.exe" OR process_name=="regedit.exe" OR process_name=="msiexec.exe" OR process_name=="gfxdownloadwrapper.exe" OR process_name=="presentationhost.exe" OR process_name=="regini.exe" OR process_name=="wmic.exe" OR process_name=="runonce.exe" OR process_name=="syncappvpublishingserver.exe" OR process_name=="verclsid.exe" OR process_name=="psr.exe" OR process_name=="infdefaultinstall.exe" OR process_name=="explorer.exe" OR process_name=="expand.exe" OR process_name=="installutil.exe" OR process_name=="netsh.exe" OR process_name=="wab.exe" OR process_name=="dnscmd.exe" OR process_name=="at.exe" OR process_name=="pcalua.exe" OR process_name=="cmdkey.exe" OR process_name=="msconfig.exe" -| stats count(process_name) as lolbas_counter by device,span(timestamp, 300s) -| eval lolbas_counter=lolbas_counter*1.0 -| rename window_end as timestamp -| adaptive_threshold algorithm="quantile" value="lolbas_counter" entity="device" window=2419200000L -| where label AND quantile>0.99 -| eval start_time = window_start, end_time = timestamp, entities = mvappend(device), body=create_map(["lolbas_counter", lolbas_counter, "quantile", quantile, "device", device]) -| into write_ssa_detected_events(); -``` - -#### Macros -The SPL above uses the following Macros: - -Note that `unusual_lolbas_in_short_period_of_time_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* dest_device_id -* _time -* process_name - - -#### How To Implement -Collect endpoint data such as sysmon or 4688 events. - -#### Known False Positives -Some administrative tasks may involve multiple use of LOLBAS applications in a short period of time. This might trigger false positives at the beginning when it hasn't collected yet enough data to construct the baseline. - - -#### Associated Analytic story -* [Unusual Processes](/stories/unusual_processes) - - -#### Kill Chain Phase -* Exploitation - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | A system process $process_name$ with commandline $cmd_line$ spawn iin short period of time in host $dest_device_id$ | - - -Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` - - - -#### Reference - -* [https://github.com/LOLBAS-Project/LOLBAS/tree/master/yml/OSBinaries](https://github.com/LOLBAS-Project/LOLBAS/tree/master/yml/OSBinaries) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/unusual_lolbas_in_short_period_of_time.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2020-09-01-gcp_detect_oauth_token_abuse.md b/docs/_posts/2020-09-01-gcp_detect_oauth_token_abuse.md deleted file mode 100644 index ccedfd0460..0000000000 --- a/docs/_posts/2020-09-01-gcp_detect_oauth_token_abuse.md +++ /dev/null @@ -1,148 +0,0 @@ ---- -title: "gcp detect oauth token abuse" -excerpt: "Valid Accounts -" -categories: - - Deprecated -last_modified_at: 2020-09-01 -toc: true -toc_label: "" -tags: - - Valid Accounts - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search provides detection of possible GCP Oauth token abuse. GCP Oauth token without time limit can be exfiltrated and reused for keeping access sessions alive without further control of authentication, allowing attackers to access and move laterally. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-09-01 -- **Author**: Rod Soto, Splunk -- **ID**: a7e9f7bb-8901-4ad0-8d88-0a4ab07b1972 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`google_gcp_pubsub_message` type.googleapis.com/google.cloud.audit.AuditLog -|table protoPayload.@type protoPayload.status.details{}.@type protoPayload.status.details{}.violations{}.callerIp protoPayload.status.details{}.violations{}.type protoPayload.status.message -| `gcp_detect_oauth_token_abuse_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [google_gcp_pubsub_message](https://github.com/splunk/security_content/blob/develop/macros/google_gcp_pubsub_message.yml) - -> :information_source: -> **gcp_detect_oauth_token_abuse_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -You must install splunk GCP add-on. This search works with gcp:pubsub:message logs - -#### Known False Positives -GCP Oauth token abuse detection will only work if there are access policies in place along with audit logs. - -#### Associated Analytic story -* [GCP Cross Account Activity](/stories/gcp_cross_account_activity) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.netskope.com/blog/gcp-oauth-token-hijacking-in-google-cloud-part-1](https://www.netskope.com/blog/gcp-oauth-token-hijacking-in-google-cloud-part-1) -* [https://www.netskope.com/blog/gcp-oauth-token-hijacking-in-google-cloud-part-2](https://www.netskope.com/blog/gcp-oauth-token-hijacking-in-google-cloud-part-2) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-09-02-cloud_compute_instance_created_in_previously_unused_region.md b/docs/_posts/2020-09-02-cloud_compute_instance_created_in_previously_unused_region.md deleted file mode 100644 index ccd7bb4de7..0000000000 --- a/docs/_posts/2020-09-02-cloud_compute_instance_created_in_previously_unused_region.md +++ /dev/null @@ -1,167 +0,0 @@ ---- -title: "Cloud Compute Instance Created In Previously Unused Region" -excerpt: "Unused/Unsupported Cloud Regions -" -categories: - - Cloud -last_modified_at: 2020-09-02 -toc: true -toc_label: "" -tags: - - Unused/Unsupported Cloud Regions - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Change ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks at cloud-infrastructure events where an instance is created in any region within the last hour and then compares it to a lookup file of previously seen regions where instances have been created. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Change](https://docs.splunk.com/Documentation/CIM/latest/User/Change)- **Datasource**: [Splunk Add-on for Amazon Kinesis Firehose](https://splunkbase.splunk.com/app/3719) -- **Last Updated**: 2020-09-02 -- **Author**: David Dorsey, Splunk -- **ID**: fa4089e2-50e3-40f7-8469-d2cc1564ca59 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1535](https://attack.mitre.org/techniques/T1535/) | Unused/Unsupported Cloud Regions | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.DP -* DE.AE - - - -
-
- -
- CIS20 - -
- -* CIS 12 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats earliest(_time) as firstTime latest(_time) as lastTime values(All_Changes.object_id) as dest, count from datamodel=Change where All_Changes.action=created by All_Changes.vendor_region, All_Changes.user -| `drop_dm_object_name("All_Changes")` -| lookup previously_seen_cloud_regions vendor_region as vendor_region OUTPUTNEW firstTimeSeen, enough_data -| eventstats max(enough_data) as enough_data -| where enough_data=1 -| eval firstTimeSeenRegion=min(firstTimeSeen) -| where isnull(firstTimeSeenRegion) OR firstTimeSeenRegion > relative_time(now(), "-24h@h") -| table firstTime, user, dest, count , vendor_region -| `security_content_ctime(firstTime)` -| `cloud_compute_instance_created_in_previously_unused_region_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **cloud_compute_instance_created_in_previously_unused_region_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Lookups -The SPL above uses the following Lookups: - -* [previously_seen_cloud_regions](https://github.com/splunk/security_content/blob/develop/lookups/previously_seen_cloud_regions.yml) with [data](https://github.com/splunk/security_content/tree/develop/lookups/previously_seen_cloud_regions.csv) - -#### Required field -* _time -* All_Changes.object_id -* All_Changes.action -* All_Changes.vendor_region -* All_Changes.user - - -#### How To Implement -You must be ingesting your cloud infrastructure logs from your cloud provider. You should run the baseline search `Previously Seen Cloud Regions - Initial` to build the initial table of images observed and times. You must also enable the second baseline search `Previously Seen Cloud Regions - Update` to keep this table up to date and to age out old data. You can also provide additional filtering for this search by customizing the `cloud_compute_instance_created_in_previously_unused_region_filter` macro. - -#### Known False Positives -It's possible that a user has unknowingly started an instance in a new region. Please verify that this activity is legitimate. - -#### Associated Analytic story -* [Cloud Cryptomining](/stories/cloud_cryptomining) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 42.0 | 70 | 60 | User $user$ is creating an instance $dest$ in a new region for the first time | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/cloud_compute_instance_created_in_previously_unused_region.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-09-04-cloud_api_calls_from_previously_unseen_user_roles.md b/docs/_posts/2020-09-04-cloud_api_calls_from_previously_unseen_user_roles.md deleted file mode 100644 index 3111f5ba42..0000000000 --- a/docs/_posts/2020-09-04-cloud_api_calls_from_previously_unseen_user_roles.md +++ /dev/null @@ -1,171 +0,0 @@ ---- -title: "Cloud API Calls From Previously Unseen User Roles" -excerpt: "Valid Accounts -" -categories: - - Cloud -last_modified_at: 2020-09-04 -toc: true -toc_label: "" -tags: - - Valid Accounts - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Change ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for new commands from each user role. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Change](https://docs.splunk.com/Documentation/CIM/latest/User/Change)- **Datasource**: [Splunk Add-on for Amazon Kinesis Firehose](https://splunkbase.splunk.com/app/3719) -- **Last Updated**: 2020-09-04 -- **Author**: David Dorsey, Splunk -- **ID**: 2181ad1f-1e73-4d0c-9780-e8880482a08f - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* ID.AM - - - -
-
- -
- CIS20 - -
- -* CIS 1 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats earliest(_time) as firstTime, latest(_time) as lastTime from datamodel=Change where All_Changes.user_type=AssumedRole AND All_Changes.status=success by All_Changes.user, All_Changes.command All_Changes.object -| `drop_dm_object_name("All_Changes")` -| lookup previously_seen_cloud_api_calls_per_user_role user as user, command as command OUTPUT firstTimeSeen, enough_data -| eventstats max(enough_data) as enough_data -| where enough_data=1 -| eval firstTimeSeenUserApiCall=min(firstTimeSeen) -| where isnull(firstTimeSeenUserApiCall) OR firstTimeSeenUserApiCall > relative_time(now(),"-24h@h") -| table firstTime, user, object, command -|`security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `cloud_api_calls_from_previously_unseen_user_roles_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **cloud_api_calls_from_previously_unseen_user_roles_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Lookups -The SPL above uses the following Lookups: - -* [previously_seen_cloud_api_calls_per_user_role](https://github.com/splunk/security_content/blob/develop/lookups/previously_seen_cloud_api_calls_per_user_role.yml) with [data](https://github.com/splunk/security_content/tree/develop/lookups/previously_seen_cloud_api_calls_per_user_role.csv) - -#### Required field -* _time -* All_Changes.user -* All_Changes.user_type -* All_Changes.status -* All_Changes.command -* All_Changes.object - - -#### How To Implement -You must be ingesting your cloud infrastructure logs from your cloud provider. You should run the baseline search `Previously Seen Cloud API Calls Per User Role - Initial` to build the initial table of user roles, commands, and times. You must also enable the second baseline search `Previously Seen Cloud API Calls Per User Role - Update` to keep this table up to date and to age out old data. You can adjust the time window for this search by updating the `cloud_api_calls_from_previously_unseen_user_roles_activity_window` macro. You can also provide additional filtering for this search by customizing the `cloud_api_calls_from_previously_unseen_user_roles_filter` - -#### Known False Positives -. - -#### Associated Analytic story -* [Suspicious Cloud User Activities](/stories/suspicious_cloud_user_activities) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 36.0 | 60 | 60 | User $user$ of type AssumedRole attempting to execute new API calls $command$ that have not been seen before | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-09-07-abnormally_high_number_of_cloud_infrastructure_api_calls.md b/docs/_posts/2020-09-07-abnormally_high_number_of_cloud_infrastructure_api_calls.md deleted file mode 100644 index 82531f443b..0000000000 --- a/docs/_posts/2020-09-07-abnormally_high_number_of_cloud_infrastructure_api_calls.md +++ /dev/null @@ -1,178 +0,0 @@ ---- -title: "Abnormally High Number Of Cloud Infrastructure API Calls" -excerpt: "Cloud Accounts -, Valid Accounts -" -categories: - - Cloud -last_modified_at: 2020-09-07 -toc: true -toc_label: "" -tags: - - Cloud Accounts - - Valid Accounts - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Change ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search will detect a spike in the number of API calls made to your cloud infrastructure environment by a user. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Change](https://docs.splunk.com/Documentation/CIM/latest/User/Change)- **Datasource**: [Splunk Add-on for Amazon Kinesis Firehose](https://splunkbase.splunk.com/app/3719) -- **Last Updated**: 2020-09-07 -- **Author**: David Dorsey, Splunk -- **ID**: 0840ddf1-8c89-46ff-b730-c8d6722478c0 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1078.004](https://attack.mitre.org/techniques/T1078/004/) | Cloud Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.DP -* DE.CM -* PR.AC - - - -
-
- -
- CIS20 - -
- -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats count as api_calls values(All_Changes.command) as command from datamodel=Change where All_Changes.user!=unknown All_Changes.status=success by All_Changes.user _time span=1h -| `drop_dm_object_name("All_Changes")` -| eval HourOfDay=strftime(_time, "%H") -| eval HourOfDay=floor(HourOfDay/4)*4 -| eval DayOfWeek=strftime(_time, "%w") -| eval isWeekend=if(DayOfWeek >= 1 AND DayOfWeek <= 5, 0, 1) -| join user HourOfDay isWeekend [ summary cloud_excessive_api_calls_v1] -| where cardinality >=16 -| apply cloud_excessive_api_calls_v1 threshold=0.005 -| rename "IsOutlier(api_calls)" as isOutlier -| where isOutlier=1 -| eval expected_upper_threshold = mvindex(split(mvindex(BoundaryRanges, -1), ":"), 0) -| where api_calls > expected_upper_threshold -| eval distance_from_threshold = api_calls - expected_upper_threshold -| table _time, user, command, api_calls, expected_upper_threshold, distance_from_threshold -| `abnormally_high_number_of_cloud_infrastructure_api_calls_filter` -``` - -#### Macros -The SPL above uses the following Macros: - -> :information_source: -> **abnormally_high_number_of_cloud_infrastructure_api_calls_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* All_Changes.command -* All_Changes.user -* All_Changes.status - - -#### How To Implement -You must be ingesting your cloud infrastructure logs. You also must run the baseline search `Baseline Of Cloud Infrastructure API Calls Per User` to create the probability density function. - -#### Known False Positives - - -#### Associated Analytic story -* [Suspicious Cloud User Activities](/stories/suspicious_cloud_user_activities) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | user $user$ has made $api_calls$ api calls, violating the dynamic threshold of $expected_upper_threshold$ with the following command $command$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-09-07-abnormally_high_number_of_cloud_security_group_api_calls.md b/docs/_posts/2020-09-07-abnormally_high_number_of_cloud_security_group_api_calls.md deleted file mode 100644 index 8ad2f03735..0000000000 --- a/docs/_posts/2020-09-07-abnormally_high_number_of_cloud_security_group_api_calls.md +++ /dev/null @@ -1,179 +0,0 @@ ---- -title: "Abnormally High Number Of Cloud Security Group API Calls" -excerpt: "Cloud Accounts -, Valid Accounts -" -categories: - - Cloud -last_modified_at: 2020-09-07 -toc: true -toc_label: "" -tags: - - Cloud Accounts - - Valid Accounts - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Change ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search will detect a spike in the number of API calls made to your cloud infrastructure environment about security groups by a user. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Change](https://docs.splunk.com/Documentation/CIM/latest/User/Change)- **Datasource**: [Splunk Add-on for Amazon Kinesis Firehose](https://splunkbase.splunk.com/app/3719) -- **Last Updated**: 2020-09-07 -- **Author**: David Dorsey, Splunk -- **ID**: d4dfb7f3-7a37-498a-b5df-f19334e871af - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1078.004](https://attack.mitre.org/techniques/T1078/004/) | Cloud Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.DP -* DE.CM -* PR.AC - - - -
-
- -
- CIS20 - -
- -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats count as security_group_api_calls values(All_Changes.command) as command from datamodel=Change where All_Changes.object_category=firewall AND All_Changes.status=success by All_Changes.user _time span=1h -| `drop_dm_object_name("All_Changes")` -| eval HourOfDay=strftime(_time, "%H") -| eval HourOfDay=floor(HourOfDay/4)*4 -| eval DayOfWeek=strftime(_time, "%w") -| eval isWeekend=if(DayOfWeek >= 1 AND DayOfWeek <= 5, 0, 1) -| join user HourOfDay isWeekend [ summary cloud_excessive_security_group_api_calls_v1] -| where cardinality >=16 -| apply cloud_excessive_security_group_api_calls_v1 threshold=0.005 -| rename "IsOutlier(security_group_api_calls)" as isOutlier -| where isOutlier=1 -| eval expected_upper_threshold = mvindex(split(mvindex(BoundaryRanges, -1), ":"), 0) -| where security_group_api_calls > expected_upper_threshold -| eval distance_from_threshold = security_group_api_calls - expected_upper_threshold -| table _time, user, command, security_group_api_calls, expected_upper_threshold, distance_from_threshold -| `abnormally_high_number_of_cloud_security_group_api_calls_filter` -``` - -#### Macros -The SPL above uses the following Macros: - -> :information_source: -> **abnormally_high_number_of_cloud_security_group_api_calls_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* All_Changes.command -* All_Changes.object_category -* All_Changes.status -* All_Changes.user - - -#### How To Implement -You must be ingesting your cloud infrastructure logs. You also must run the baseline search `Baseline Of Cloud Security Group API Calls Per User` to create the probability density function model. - -#### Known False Positives - - -#### Associated Analytic story -* [Suspicious Cloud User Activities](/stories/suspicious_cloud_user_activities) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | user $user$ has made $api_calls$ api calls related to security groups, violating the dynamic threshold of $expected_upper_threshold$ with the following command $command$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-09-08-cloud_network_access_control_list_deleted.md b/docs/_posts/2020-09-08-cloud_network_access_control_list_deleted.md deleted file mode 100644 index 5369ba31dd..0000000000 --- a/docs/_posts/2020-09-08-cloud_network_access_control_list_deleted.md +++ /dev/null @@ -1,150 +0,0 @@ ---- -title: "Cloud Network Access Control List Deleted" -excerpt: "" -categories: - - Deprecated -last_modified_at: 2020-09-08 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -Enforcing network-access controls is one of the defensive mechanisms used by cloud administrators to restrict access to a cloud instance. After the attacker has gained control of the console by compromising an admin account, they can delete a network ACL and gain access to the instance from anywhere. This search will query the Change datamodel to detect users deleting network ACLs. Deprecated because it's a duplicate - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-09-08 -- **Author**: Peter Gael, Splunk -- **ID**: 021abc51-1862-41dd-ad43-43c739c0a983 - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.DP -* DE.AE - - - -
-
- -
- CIS20 - -
- -* CIS 11 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cloudtrail` eventName=DeleteNetworkAcl -|rename userIdentity.arn as arn -| stats count min(_time) as firstTime max(_time) as lastTime values(errorMessage) values(errorCode) values(userAgent) values(userIdentity.*) by src userName arn eventName -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `cloud_network_access_control_list_deleted_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) - -> :information_source: -> **cloud_network_access_control_list_deleted_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* eventName -* userIdentity.arn -* errorMessage -* errorCode -* userAgent -* src -* userName -* arn - - -#### How To Implement -You must be ingesting your cloud infrastructure logs from your cloud provider. You can also provide additional filtering for this search by customizing the `cloud_network_access_control_list_deleted_filter` macro. - -#### Known False Positives -It's possible that a user has legitimately deleted a network ACL. - -#### Associated Analytic story -* [Cloud Network ACL Activity](/stories/cloud_network_acl_activity) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/cloud_network_access_control_list_deleted.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-09-12-cloud_compute_instance_created_with_previously_unseen_instance_type.md b/docs/_posts/2020-09-12-cloud_compute_instance_created_with_previously_unseen_instance_type.md deleted file mode 100644 index e17374d24e..0000000000 --- a/docs/_posts/2020-09-12-cloud_compute_instance_created_with_previously_unseen_instance_type.md +++ /dev/null @@ -1,160 +0,0 @@ ---- -title: "Cloud Compute Instance Created With Previously Unseen Instance Type" -excerpt: "" -categories: - - Cloud -last_modified_at: 2020-09-12 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Change ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -Find EC2 instances being created with previously unseen instance types. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Change](https://docs.splunk.com/Documentation/CIM/latest/User/Change)- **Datasource**: [Splunk Add-on for Amazon Kinesis Firehose](https://splunkbase.splunk.com/app/3719) -- **Last Updated**: 2020-09-12 -- **Author**: David Dorsey, Splunk -- **ID**: c6ddbf53-9715-49f3-bb4c-fb2e8a309cda - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* ID.AM - - - -
-
- -
- CIS20 - -
- -* CIS 1 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats earliest(_time) as firstTime, latest(_time) as lastTime values(All_Changes.object_id) as dest, count from datamodel=Change where All_Changes.action=created by All_Changes.Instance_Changes.instance_type, All_Changes.user -| `drop_dm_object_name("All_Changes")` -| `drop_dm_object_name("Instance_Changes")` -| where instance_type != "unknown" -| lookup previously_seen_cloud_compute_instance_types instance_type as instance_type OUTPUTNEW firstTimeSeen, enough_data -| eventstats max(enough_data) as enough_data -| where enough_data=1 -| eval firstTimeSeenInstanceType=min(firstTimeSeen) -| where isnull(firstTimeSeenInstanceType) OR firstTimeSeenInstanceType > relative_time(now(), "-24h@h") -| table firstTime, user, dest, count, instance_type -| `security_content_ctime(firstTime)` -| `cloud_compute_instance_created_with_previously_unseen_instance_type_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **cloud_compute_instance_created_with_previously_unseen_instance_type_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Lookups -The SPL above uses the following Lookups: - -* [previously_seen_cloud_compute_instance_types](https://github.com/splunk/security_content/blob/develop/lookups/previously_seen_cloud_compute_instance_types.yml) with [data](https://github.com/splunk/security_content/tree/develop/lookups/previously_seen_cloud_compute_instance_types.csv) - -#### Required field -* _time -* All_Changes.object_id -* All_Changes.action -* All_Changes.Instance_Changes.instance_type -* All_Changes.user - - -#### How To Implement -You must be ingesting your cloud infrastructure logs from your cloud provider. You should run the baseline search `Previously Seen Cloud Compute Instance Types - Initial` to build the initial table of instance types observed and times. You must also enable the second baseline search `Previously Seen Cloud Compute Instance Types - Update` to keep this table up to date and to age out old data. You can also provide additional filtering for this search by customizing the `cloud_compute_instance_created_with_previously_unseen_instance_type_filter` macro. - -#### Known False Positives -It is possible that an admin will create a new system using a new instance type that has never been used before. Verify with the creator that they intended to create the system with the new instance type. - -#### Associated Analytic story -* [Cloud Cryptomining](/stories/cloud_cryptomining) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 30.0 | 50 | 60 | User $user$ is creating an instance $dest$ with an instance type $instance_type$ that has not been previously seen. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/cloud_compute_instance_created_with_previously_unseen_instance_type.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-09-15-detect_zerologon_via_zeek.md b/docs/_posts/2020-09-15-detect_zerologon_via_zeek.md deleted file mode 100644 index 531f64ad85..0000000000 --- a/docs/_posts/2020-09-15-detect_zerologon_via_zeek.md +++ /dev/null @@ -1,161 +0,0 @@ ---- -title: "Detect Zerologon via Zeek" -excerpt: "Exploit Public-Facing Application -" -categories: - - Network -last_modified_at: 2020-09-15 -toc: true -toc_label: "" -tags: - - Exploit Public-Facing Application - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2020-1472 ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search detects attempts to run exploits for the Zerologon CVE-2020-1472 vulnerability via Zeek RPC - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-09-15 -- **Author**: Shannon Davis, Splunk -- **ID**: bf7a06ec-f703-11ea-adc1-0242ac120002 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1190](https://attack.mitre.org/techniques/T1190/) | Exploit Public-Facing Application | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 -* CIS 11 - - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2020-1472](https://nvd.nist.gov/vuln/detail/CVE-2020-1472) | An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC), aka 'Netlogon Elevation of Privilege Vulnerability'. | 9.3 | - - - -
-
- -#### Search - -``` -`zeek_rpc` operation IN (NetrServerPasswordSet2,NetrServerReqChallenge,NetrServerAuthenticate3) -| bin span=5m _time -| stats values(operation) dc(operation) as opscount count(eval(operation=="NetrServerReqChallenge")) as challenge count(eval(operation=="NetrServerAuthenticate3")) as authcount count(eval(operation=="NetrServerPasswordSet2")) as passcount count as totalcount by _time,src_ip,dest_ip -| search opscount=3 authcount>4 passcount>0 -| search `detect_zerologon_via_zeek_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [zeek_rpc](https://github.com/splunk/security_content/blob/develop/macros/zeek_rpc.yml) - -> :information_source: -> **detect_zerologon_via_zeek_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* operation - - -#### How To Implement -You must be ingesting Zeek DCE-RPC data into Splunk. Zeek data should also be getting ingested in JSON format. We are detecting when all three RPC operations (NetrServerReqChallenge, NetrServerAuthenticate3, NetrServerPasswordSet2) are splunk_security_essentials_app via bro:rpc:json. These three operations are then correlated on the Zeek UID field. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Detect Zerologon Attack](/stories/detect_zerologon_attack) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.secura.com/blog/zero-logon](https://www.secura.com/blog/zero-logon) -* [https://github.com/SecuraBV/CVE-2020-1472](https://github.com/SecuraBV/CVE-2020-1472) -* [https://msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1472](https://msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1472) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/network/detect_zerologon_via_zeek.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-09-16-create_or_delete_windows_shares_using_net_exe.md b/docs/_posts/2020-09-16-create_or_delete_windows_shares_using_net_exe.md deleted file mode 100644 index e7d3584681..0000000000 --- a/docs/_posts/2020-09-16-create_or_delete_windows_shares_using_net_exe.md +++ /dev/null @@ -1,175 +0,0 @@ ---- -title: "Create or delete windows shares using net exe" -excerpt: "Indicator Removal on Host -, Network Share Connection Removal -" -categories: - - Endpoint -last_modified_at: 2020-09-16 -toc: true -toc_label: "" -tags: - - Indicator Removal on Host - - Network Share Connection Removal - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for the creation or deletion of hidden shares using net.exe. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2020-09-16 -- **Author**: Bhavin Patel, Splunk -- **ID**: 743a322c-9a68-4a0f-9c17-85d9cce2a27c - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1070](https://attack.mitre.org/techniques/T1070/) | Indicator Removal on Host | Defense Evasion | - -| [T1070.005](https://attack.mitre.org/techniques/T1070/005/) | Network Share Connection Removal | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count values(Processes.user) as user values(Processes.parent_process) as parent_process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_net` by Processes.process Processes.process_name Processes.original_file_name Processes.dest -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| search process=*share* -| `create_or_delete_windows_shares_using_net_exe_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_net](https://github.com/splunk/security_content/blob/develop/macros/process_net.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **create_or_delete_windows_shares_using_net_exe_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Administrators often leverage net.exe to create or delete network shares. You should verify that the activity was intentional and is legitimate. - -#### Associated Analytic story -* [Hidden Cobra Malware](/stories/hidden_cobra_malware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ enumerating Windows file shares. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1070/005/](https://attack.mitre.org/techniques/T1070/005/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070.005/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070.005/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml) \| *version*: **6** \ No newline at end of file diff --git a/docs/_posts/2020-09-18-detect_computer_changed_with_anonymous_account.md b/docs/_posts/2020-09-18-detect_computer_changed_with_anonymous_account.md deleted file mode 100644 index 8ddd5dd1cf..0000000000 --- a/docs/_posts/2020-09-18-detect_computer_changed_with_anonymous_account.md +++ /dev/null @@ -1,162 +0,0 @@ ---- -title: "Detect Computer Changed with Anonymous Account" -excerpt: "Exploitation of Remote Services -" -categories: - - Endpoint -last_modified_at: 2020-09-18 -toc: true -toc_label: "" -tags: - - Exploitation of Remote Services - - Lateral Movement - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2020-1472 ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for Event Code 4742 (Computer Change) or EventCode 4624 (An account was successfully logged on) with an anonymous account. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-09-18 -- **Author**: Rod Soto, Jose Hernandez, Splunk -- **ID**: 1400624a-d42d-484d-8843-e6753e6e3645 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1210](https://attack.mitre.org/techniques/T1210/) | Exploitation of Remote Services | Lateral Movement | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.AE -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 6 -* CIS 8 - - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2020-1472](https://nvd.nist.gov/vuln/detail/CVE-2020-1472) | An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC), aka 'Netlogon Elevation of Privilege Vulnerability'. | 9.3 | - - - -
-
- -#### Search - -``` -`wineventlog_security` EventCode=4624 OR EventCode=4742 TargetUserName="ANONYMOUS LOGON" LogonType=3 -| stats count values(host) as host, values(TargetDomainName) as Domain, values(user) as user -| `detect_computer_changed_with_anonymous_account_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) - -> :information_source: -> **detect_computer_changed_with_anonymous_account_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* TargetUserName -* LogonType -* TargetDomainName -* user - - -#### How To Implement -This search requires audit computer account management to be enabled on the system in order to generate Event ID 4742. We strongly recommend that you specify your environment-specific configurations (index, source, sourcetype, etc.) for Windows Event Logs. Replace the macro definition with configurations for your Splunk environment. The search also uses a post-filter macro designed to filter out known false positives. - -#### Known False Positives -None thus far found - -#### Associated Analytic story -* [Detect Zerologon Attack](/stories/detect_zerologon_attack) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | The following $EventCode$ occurred on $dest$ by $user$ with Logon Type 3, which may be indicative of the an account or group being changed by an anonymous account. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.lares.com/blog/from-lares-labs-defensive-guidance-for-zerologon-cve-2020-1472/](https://www.lares.com/blog/from-lares-labs-defensive-guidance-for-zerologon-cve-2020-1472/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/endpoint/detect_computer_changed_with_anonymous_account.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-10-07-detect_aws_console_login_by_user_from_new_city.md b/docs/_posts/2020-10-07-detect_aws_console_login_by_user_from_new_city.md deleted file mode 100644 index 3ab32e1a92..0000000000 --- a/docs/_posts/2020-10-07-detect_aws_console_login_by_user_from_new_city.md +++ /dev/null @@ -1,172 +0,0 @@ ---- -title: "Detect AWS Console Login by User from New City" -excerpt: "Unused/Unsupported Cloud Regions -" -categories: - - Cloud -last_modified_at: 2020-10-07 -toc: true -toc_label: "" -tags: - - Unused/Unsupported Cloud Regions - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Authentication ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for AWS CloudTrail events wherein a console login event by a user was recorded within the last hour, then compares the event to a lookup file of previously seen users (by ARN values) who have logged into the console. The alert is fired if the user has logged into the console for the first time within the last hour - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Authentication](https://docs.splunk.com/Documentation/CIM/latest/User/Authentication) -- **Last Updated**: 2020-10-07 -- **Author**: Bhavin Patel, Splunk -- **ID**: 121b0b11-f8ac-4ed6-a132-3800ca4fc07a - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1535](https://attack.mitre.org/techniques/T1535/) | Unused/Unsupported Cloud Regions | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.DP -* DE.AE - - - -
-
- -
- CIS20 - -
- -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats earliest(_time) as firstTime latest(_time) as lastTime from datamodel=Authentication where Authentication.signature=ConsoleLogin by Authentication.user Authentication.src -| iplocation Authentication.src -| `drop_dm_object_name(Authentication)` -| table firstTime lastTime user City -| join user type=outer [ -| inputlookup previously_seen_users_console_logins -| stats min(firstTime) AS earliestseen by user City -| fields earliestseen user City] -| eval userCity=if(firstTime >= relative_time(now(), "-24h@h"), "New City","Previously Seen City") -| eval userStatus=if(earliestseen >= relative_time(now(), "-24h@h") OR isnull(earliestseen), "New User","Old User") -| where userCity = "New City" AND userStatus != "Old User" -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| table firstTime lastTime user City userStatus userCity -| `detect_aws_console_login_by_user_from_new_city_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **detect_aws_console_login_by_user_from_new_city_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Lookups -The SPL above uses the following Lookups: - -* [previously_seen_users_console_logins](https://github.com/splunk/security_content/blob/develop/lookups/previously_seen_users_console_logins.yml) with [data](https://github.com/splunk/security_content/tree/develop/lookups/previously_seen_users_console_logins.csv) - -#### Required field -* _time -* Authentication.signature -* Authentication.user -* Authentication.src - - -#### How To Implement -You must install and configure the Splunk Add-on for AWS (version 5.1.0 or later) and Enterprise Security 6.2, which contains the required updates to the Authentication data model for cloud use cases. Run the `Previously Seen Users in AWS CloudTrail - Initial` support search only once to create a baseline of previously seen IAM users within the last 30 days. Run `Previously Seen Users in AWS CloudTrail - Update` hourly (or more frequently depending on how often you run the detection searches) to refresh the baselines. You can also provide additional filtering for this search by customizing the `detect_aws_console_login_by_user_from_new_city_filter` macro. - -#### Known False Positives -When a legitimate new user logins for the first time, this activity will be detected. Check how old the account is and verify that the user activity is legitimate. - -#### Associated Analytic story -* [Suspicious AWS Login Activities](/stories/suspicious_aws_login_activities) -* [Suspicious Cloud Authentication Activities](/stories/suspicious_cloud_authentication_activities) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 18.0 | 30 | 60 | User $user$ is logging into the AWS console from City $City$ for the first time | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/detect_aws_console_login_by_user_from_new_city.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-10-07-detect_aws_console_login_by_user_from_new_country.md b/docs/_posts/2020-10-07-detect_aws_console_login_by_user_from_new_country.md deleted file mode 100644 index f72f7a8ed3..0000000000 --- a/docs/_posts/2020-10-07-detect_aws_console_login_by_user_from_new_country.md +++ /dev/null @@ -1,172 +0,0 @@ ---- -title: "Detect AWS Console Login by User from New Country" -excerpt: "Unused/Unsupported Cloud Regions -" -categories: - - Cloud -last_modified_at: 2020-10-07 -toc: true -toc_label: "" -tags: - - Unused/Unsupported Cloud Regions - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Authentication ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for AWS CloudTrail events wherein a console login event by a user was recorded within the last hour, then compares the event to a lookup file of previously seen users (by ARN values) who have logged into the console. The alert is fired if the user has logged into the console for the first time within the last hour - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Authentication](https://docs.splunk.com/Documentation/CIM/latest/User/Authentication) -- **Last Updated**: 2020-10-07 -- **Author**: Bhavin Patel, Splunk -- **ID**: 67bd3def-c41c-4bf6-837b-ae196b4257c6 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1535](https://attack.mitre.org/techniques/T1535/) | Unused/Unsupported Cloud Regions | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.DP -* DE.AE - - - -
-
- -
- CIS20 - -
- -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats earliest(_time) as firstTime latest(_time) as lastTime from datamodel=Authentication where Authentication.signature=ConsoleLogin by Authentication.user Authentication.src -| iplocation Authentication.src -| `drop_dm_object_name(Authentication)` -| table firstTime lastTime user Country -| join user type=outer [ -| inputlookup previously_seen_users_console_logins -| stats min(firstTime) AS earliestseen by user Country -| fields earliestseen user Country] -| eval userCountry=if(firstTime >= relative_time(now(), "-24h@h"), "New Country","Previously Seen Country") -| eval userStatus=if(earliestseen >= relative_time(now(),"-24h@h") OR isnull(earliestseen), "New User","Old User") -| where userCountry = "New Country" AND userStatus != "Old User" -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| table firstTime lastTime user Country userStatus userCountry -| `detect_aws_console_login_by_user_from_new_country_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **detect_aws_console_login_by_user_from_new_country_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Lookups -The SPL above uses the following Lookups: - -* [previously_seen_users_console_logins](https://github.com/splunk/security_content/blob/develop/lookups/previously_seen_users_console_logins.yml) with [data](https://github.com/splunk/security_content/tree/develop/lookups/previously_seen_users_console_logins.csv) - -#### Required field -* _time -* Authentication.signature -* Authentication.user -* Authentication.src - - -#### How To Implement -You must install and configure the Splunk Add-on for AWS (version 5.1.0 or later) and Enterprise Security 6.2, which contains the required updates to the Authentication data model for cloud use cases. Run the `Previously Seen Users in AWS CloudTrail - Initial` support search only once to create a baseline of previously seen IAM users within the last 30 days. Run `Previously Seen Users in AWS CloudTrail - Update` hourly (or more frequently depending on how often you run the detection searches) to refresh the baselines. You can also provide additional filtering for this search by customizing the `detect_aws_console_login_by_user_from_new_country_filter` macro. - -#### Known False Positives -When a legitimate new user logins for the first time, this activity will be detected. Check how old the account is and verify that the user activity is legitimate. - -#### Associated Analytic story -* [Suspicious AWS Login Activities](/stories/suspicious_aws_login_activities) -* [Suspicious Cloud Authentication Activities](/stories/suspicious_cloud_authentication_activities) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 42.0 | 70 | 60 | User $user$ is logging into the AWS console from Country $Country$ for the first time | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/detect_aws_console_login_by_user_from_new_country.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-10-07-detect_aws_console_login_by_user_from_new_region.md b/docs/_posts/2020-10-07-detect_aws_console_login_by_user_from_new_region.md deleted file mode 100644 index 35f900bb8d..0000000000 --- a/docs/_posts/2020-10-07-detect_aws_console_login_by_user_from_new_region.md +++ /dev/null @@ -1,172 +0,0 @@ ---- -title: "Detect AWS Console Login by User from New Region" -excerpt: "Unused/Unsupported Cloud Regions -" -categories: - - Cloud -last_modified_at: 2020-10-07 -toc: true -toc_label: "" -tags: - - Unused/Unsupported Cloud Regions - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Authentication ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for AWS CloudTrail events wherein a console login event by a user was recorded within the last hour, then compares the event to a lookup file of previously seen users (by ARN values) who have logged into the console. The alert is fired if the user has logged into the console for the first time within the last hour - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Authentication](https://docs.splunk.com/Documentation/CIM/latest/User/Authentication) -- **Last Updated**: 2020-10-07 -- **Author**: Bhavin Patel, Splunk -- **ID**: 9f31aa8e-e37c-46bc-bce1-8b3be646d026 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1535](https://attack.mitre.org/techniques/T1535/) | Unused/Unsupported Cloud Regions | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.DP -* DE.AE - - - -
-
- -
- CIS20 - -
- -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats earliest(_time) as firstTime latest(_time) as lastTime from datamodel=Authentication where Authentication.signature=ConsoleLogin by Authentication.user Authentication.src -| iplocation Authentication.src -| `drop_dm_object_name(Authentication)` -| table firstTime lastTime user Region -| join user type=outer [ -| inputlookup previously_seen_users_console_logins -| stats min(firstTime) AS earliestseen by user Region -| fields earliestseen user Region] -| eval userRegion=if(firstTime >= relative_time(now(), "-24h@h"), "New Region","Previously Seen Region") -| eval userStatus=if(earliestseen >= relative_time(now(), "-24h@h") OR isnull(earliestseen), "New User","Old User") -| where userRegion = "New Region" AND userStatus != "Old User" -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| table firstTime lastTime user Region userStatus userRegion -| `detect_aws_console_login_by_user_from_new_region_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **detect_aws_console_login_by_user_from_new_region_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Lookups -The SPL above uses the following Lookups: - -* [previously_seen_users_console_logins](https://github.com/splunk/security_content/blob/develop/lookups/previously_seen_users_console_logins.yml) with [data](https://github.com/splunk/security_content/tree/develop/lookups/previously_seen_users_console_logins.csv) - -#### Required field -* _time -* Authentication.signature -* Authentication.user -* Authentication.src - - -#### How To Implement -You must install and configure the Splunk Add-on for AWS (version 5.1.0 or later) and Enterprise Security 6.2, which contains the required updates to the Authentication data model for cloud use cases. Run the `Previously Seen Users in AWS CloudTrail - Initial` support search only once to create a baseline of previously seen IAM users within the last 30 days. Run `Previously Seen Users in AWS CloudTrail - Update` hourly (or more frequently depending on how often you run the detection searches) to refresh the baselines. You can also provide additional filtering for this search by customizing the `detect_aws_console_login_by_user_from_new_region_filter` macro. - -#### Known False Positives -When a legitimate new user logins for the first time, this activity will be detected. Check how old the account is and verify that the user activity is legitimate. - -#### Associated Analytic story -* [Suspicious AWS Login Activities](/stories/suspicious_aws_login_activities) -* [Suspicious Cloud Authentication Activities](/stories/suspicious_cloud_authentication_activities) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 36.0 | 60 | 60 | User $user$ is logging into the AWS console from Region $Region$ for the first time | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/detect_aws_console_login_by_user_from_new_region.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-10-08-gcp_detect_gcploit_framework.md b/docs/_posts/2020-10-08-gcp_detect_gcploit_framework.md deleted file mode 100644 index 8aa8408d06..0000000000 --- a/docs/_posts/2020-10-08-gcp_detect_gcploit_framework.md +++ /dev/null @@ -1,158 +0,0 @@ ---- -title: "GCP Detect gcploit framework" -excerpt: "Valid Accounts -" -categories: - - Cloud -last_modified_at: 2020-10-08 -toc: true -toc_label: "" -tags: - - Valid Accounts - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search provides detection of GCPloit exploitation framework. This framework can be used to escalate privileges and move laterally from compromised high privilege accounts. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-10-08 -- **Author**: Rod Soto, Splunk -- **ID**: a1c5a85e-a162-410c-a5d9-99ff639e5a52 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`google_gcp_pubsub_message` data.protoPayload.request.function.timeout=539s -| table src src_user data.resource.labels.project_id data.protoPayload.request.function.serviceAccountEmail data.protoPayload.authorizationInfo{}.permission data.protoPayload.request.location http_user_agent -| `gcp_detect_gcploit_framework_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [google_gcp_pubsub_message](https://github.com/splunk/security_content/blob/develop/macros/google_gcp_pubsub_message.yml) - -> :information_source: -> **gcp_detect_gcploit_framework_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* data.protoPayload.request.function.timeout -* src -* src_user -* data.resource.labels.project_id -* data.protoPayload.request.function.serviceAccountEmail -* data.protoPayload.authorizationInfo{}.permission -* data.protoPayload.request.location -* http_user_agent - - -#### How To Implement -You must install splunk GCP add-on. This search works with gcp:pubsub:message logs - -#### Known False Positives -Payload.request.function.timeout value can possibly be match with other functions or requests however the source user and target request account may indicate an attempt to move laterally accross acounts or projects - -#### Associated Analytic story -* [GCP Cross Account Activity](/stories/gcp_cross_account_activity) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/dxa4481/gcploit](https://github.com/dxa4481/gcploit) -* [https://www.youtube.com/watch?v=Ml09R38jpok](https://www.youtube.com/watch?v=Ml09R38jpok) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/cloud/gcp_detect_gcploit_framework.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-10-09-cloud_provisioning_activity_from_previously_unseen_city.md b/docs/_posts/2020-10-09-cloud_provisioning_activity_from_previously_unseen_city.md deleted file mode 100644 index f0a1718ed9..0000000000 --- a/docs/_posts/2020-10-09-cloud_provisioning_activity_from_previously_unseen_city.md +++ /dev/null @@ -1,175 +0,0 @@ ---- -title: "Cloud Provisioning Activity From Previously Unseen City" -excerpt: "Valid Accounts -" -categories: - - Cloud -last_modified_at: 2020-10-09 -toc: true -toc_label: "" -tags: - - Valid Accounts - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Change ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for cloud provisioning activities from previously unseen cities. Provisioning activities are defined broadly as any event that runs or creates something. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Change](https://docs.splunk.com/Documentation/CIM/latest/User/Change)- **Datasource**: [Splunk Add-on for Amazon Kinesis Firehose](https://splunkbase.splunk.com/app/3719) -- **Last Updated**: 2020-10-09 -- **Author**: Rico Valdez, Bhavin Patel, Splunk -- **ID**: e7ecc5e0-88df-48b9-91af-51104c68f02f - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* ID.AM - - - -
-
- -
- CIS20 - -
- -* CIS 1 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats earliest(_time) as firstTime, latest(_time) as lastTime from datamodel=Change where (All_Changes.action=started OR All_Changes.action=created) All_Changes.status=success by All_Changes.src, All_Changes.user, All_Changes.object, All_Changes.command -| `drop_dm_object_name("All_Changes")` -| iplocation src -| where isnotnull(City) -| lookup previously_seen_cloud_provisioning_activity_sources City as City OUTPUT firstTimeSeen, enough_data -| eventstats max(enough_data) as enough_data -| where enough_data=1 -| eval firstTimeSeenCity=min(firstTimeSeen) -| where isnull(firstTimeSeenCity) OR firstTimeSeenCity > relative_time(now(), `previously_unseen_cloud_provisioning_activity_window`) -| table firstTime, src, City, user, object, command -| `cloud_provisioning_activity_from_previously_unseen_city_filter` -| `security_content_ctime(firstTime)` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [previously_unseen_cloud_provisioning_activity_window](https://github.com/splunk/security_content/blob/develop/macros/previously_unseen_cloud_provisioning_activity_window.yml) - -> :information_source: -> **cloud_provisioning_activity_from_previously_unseen_city_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Lookups -The SPL above uses the following Lookups: - -* [previously_seen_cloud_provisioning_activity_sources](https://github.com/splunk/security_content/blob/develop/lookups/previously_seen_cloud_provisioning_activity_sources.yml) with [data](https://github.com/splunk/security_content/tree/develop/lookups/previously_seen_cloud_provisioning_activity_sources.csv) - -#### Required field -* _time -* All_Changes.action -* All_Changes.status -* All_Changes.src -* All_Changes.user -* All_Changes.object -* All_Changes.command - - -#### How To Implement -You must be ingesting your cloud infrastructure logs from your cloud provider. You should run the baseline search `Previously Seen Cloud Provisioning Activity Sources - Initial` to build the initial table of source IP address, geographic locations, and times. You must also enable the second baseline search `Previously Seen Cloud Provisioning Activity Sources - Update` to keep this table up to date and to age out old data. You can adjust the time window for this search by updating the `previously_unseen_cloud_provisioning_activity_window` macro. You can also provide additional filtering for this search by customizing the `cloud_provisioning_activity_from_previously_unseen_city_filter` macro. - -#### Known False Positives -This is a strictly behavioral search, so we define "false positive" slightly differently. Every time this fires, it will accurately reflect the first occurrence in the time period you're searching within, plus what is stored in the cache feature. But while there are really no "false positives" in a traditional sense, there is definitely lots of noise.\ - This search will fire any time a new IP address is seen in the **GeoIP** database for any kind of provisioning activity. If you typically do all provisioning from tools inside of your country, there should be few false positives. If you are located in countries where the free version of **MaxMind GeoIP** that ships by default with Splunk has weak resolution (particularly small countries in less economically powerful regions), this may be much less valuable to you. - -#### Associated Analytic story -* [Suspicious Cloud Provisioning Activities](/stories/suspicious_cloud_provisioning_activities) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 18.0 | 30 | 60 | User $user$ is starting or creating an instance $dest$ for the first time in City $City$ from IP address $src$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/cloud_provisioning_activity_from_previously_unseen_city.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-10-09-cloud_provisioning_activity_from_previously_unseen_country.md b/docs/_posts/2020-10-09-cloud_provisioning_activity_from_previously_unseen_country.md deleted file mode 100644 index 01ba185772..0000000000 --- a/docs/_posts/2020-10-09-cloud_provisioning_activity_from_previously_unseen_country.md +++ /dev/null @@ -1,174 +0,0 @@ ---- -title: "Cloud Provisioning Activity From Previously Unseen Country" -excerpt: "Valid Accounts -" -categories: - - Cloud -last_modified_at: 2020-10-09 -toc: true -toc_label: "" -tags: - - Valid Accounts - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Change ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for cloud provisioning activities from previously unseen countries. Provisioning activities are defined broadly as any event that runs or creates something. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Change](https://docs.splunk.com/Documentation/CIM/latest/User/Change)- **Datasource**: [Splunk Add-on for Amazon Kinesis Firehose](https://splunkbase.splunk.com/app/3719) -- **Last Updated**: 2020-10-09 -- **Author**: Rico Valdez, Bhavin Patel, Splunk -- **ID**: 94994255-3acf-4213-9b3f-0494df03bb31 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* ID.AM - - - -
-
- -
- CIS20 - -
- -* CIS 1 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats earliest(_time) as firstTime, latest(_time) as lastTime from datamodel=Change where (All_Changes.action=started OR All_Changes.action=created) All_Changes.status=success by All_Changes.src, All_Changes.user, All_Changes.object, All_Changes.command -| `drop_dm_object_name("All_Changes")` -| iplocation src -| where isnotnull(Country) -| lookup previously_seen_cloud_provisioning_activity_sources Country as Country OUTPUT firstTimeSeen, enough_data -| eventstats max(enough_data) as enough_data -| where enough_data=1 -| eval firstTimeSeenCountry=min(firstTimeSeen) -| where isnull(firstTimeSeenCountry) OR firstTimeSeenCountry > relative_time(now(), "-24h@h") -| table firstTime, src, Country, user, object, command -| `cloud_provisioning_activity_from_previously_unseen_country_filter` -| `security_content_ctime(firstTime)` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **cloud_provisioning_activity_from_previously_unseen_country_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Lookups -The SPL above uses the following Lookups: - -* [previously_seen_cloud_provisioning_activity_sources](https://github.com/splunk/security_content/blob/develop/lookups/previously_seen_cloud_provisioning_activity_sources.yml) with [data](https://github.com/splunk/security_content/tree/develop/lookups/previously_seen_cloud_provisioning_activity_sources.csv) - -#### Required field -* _time -* All_Changes.action -* All_Changes.status -* All_Changes.src -* All_Changes.user -* All_Changes.object -* All_Changes.command - - -#### How To Implement -You must be ingesting your cloud infrastructure logs from your cloud provider. You should run the baseline search `Previously Seen Cloud Provisioning Activity Sources - Initial` to build the initial table of source IP address, geographic locations, and times. You must also enable the second baseline search `Previously Seen Cloud Provisioning Activity Sources - Update` to keep this table up to date and to age out old data. You can adjust the time window for this search by updating the `previously_unseen_cloud_provisioning_activity_window` macro. You can also provide additional filtering for this search by customizing the `cloud_provisioning_activity_from_previously_unseen_country_filter` macro. - -#### Known False Positives -This is a strictly behavioral search, so we define "false positive" slightly differently. Every time this fires, it will accurately reflect the first occurrence in the time period you're searching within, plus what is stored in the cache feature. But while there are really no "false positives" in a traditional sense, there is definitely lots of noise.\ - This search will fire any time a new IP address is seen in the **GeoIP** database for any kind of provisioning activity. If you typically do all provisioning from tools inside of your country, there should be few false positives. If you are located in countries where the free version of **MaxMind GeoIP** that ships by default with Splunk has weak resolution (particularly small countries in less economically powerful regions), this may be much less valuable to you. - -#### Associated Analytic story -* [Suspicious Cloud Provisioning Activities](/stories/suspicious_cloud_provisioning_activities) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 42.0 | 70 | 60 | User $user$ is starting or creating an instance $object$ for the first time in Country $Country$ from IP address $src$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/cloud_provisioning_activity_from_previously_unseen_country.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-10-09-gcp_detect_accounts_with_high_risk_roles_by_project.md b/docs/_posts/2020-10-09-gcp_detect_accounts_with_high_risk_roles_by_project.md deleted file mode 100644 index 20294cef79..0000000000 --- a/docs/_posts/2020-10-09-gcp_detect_accounts_with_high_risk_roles_by_project.md +++ /dev/null @@ -1,155 +0,0 @@ ---- -title: "GCP Detect accounts with high risk roles by project" -excerpt: "Valid Accounts -" -categories: - - Deprecated -last_modified_at: 2020-10-09 -toc: true -toc_label: "" -tags: - - Valid Accounts - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search provides detection of accounts with high risk roles by projects. Compromised accounts with high risk roles can move laterally or even scalate privileges at different projects depending on organization schema. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-10-09 -- **Author**: Rod Soto, Splunk -- **ID**: 27af8c15-38b0-4408-b339-920170724adb - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`google_gcp_pubsub_message` data.protoPayload.request.policy.bindings{}.role=roles/owner OR roles/editor OR roles/iam.serviceAccountUser OR roles/iam.serviceAccountAdmin OR roles/iam.serviceAccountTokenCreator OR roles/dataflow.developer OR roles/dataflow.admin OR roles/composer.admin OR roles/dataproc.admin OR roles/dataproc.editor -| table data.resource.type data.protoPayload.authenticationInfo.principalEmail data.protoPayload.authorizationInfo{}.permission data.protoPayload.authorizationInfo{}.resource data.protoPayload.response.bindings{}.role data.protoPayload.response.bindings{}.members{} -| `gcp_detect_accounts_with_high_risk_roles_by_project_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [google_gcp_pubsub_message](https://github.com/splunk/security_content/blob/develop/macros/google_gcp_pubsub_message.yml) - -> :information_source: -> **gcp_detect_accounts_with_high_risk_roles_by_project_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* data.protoPayload.request.policy.bindings{}.role -* data.resource.type data.protoPayload.authenticationInfo.principalEmail -* data.protoPayload.authorizationInfo{}.permission -* data.protoPayload.authorizationInfo{}.resource -* data.protoPayload.response.bindings{}.role -* data.protoPayload.response.bindings{}.members{} - - -#### How To Implement -You must install splunk GCP add-on. This search works with gcp:pubsub:message logs - -#### Known False Positives -Accounts with high risk roles should be reduced to the minimum number needed, however specific tasks and setups may be simply expected behavior within organization - -#### Associated Analytic story -* [GCP Cross Account Activity](/stories/gcp_cross_account_activity) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/dxa4481/gcploit](https://github.com/dxa4481/gcploit) -* [https://www.youtube.com/watch?v=Ml09R38jpok](https://www.youtube.com/watch?v=Ml09R38jpok) -* [https://cloud.google.com/iam/docs/understanding-roles](https://cloud.google.com/iam/docs/understanding-roles) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-10-09-gcp_detect_high_risk_permissions_by_resource_and_account.md b/docs/_posts/2020-10-09-gcp_detect_high_risk_permissions_by_resource_and_account.md deleted file mode 100644 index 492ffb66c4..0000000000 --- a/docs/_posts/2020-10-09-gcp_detect_high_risk_permissions_by_resource_and_account.md +++ /dev/null @@ -1,155 +0,0 @@ ---- -title: "GCP Detect high risk permissions by resource and account" -excerpt: "Valid Accounts -" -categories: - - Deprecated -last_modified_at: 2020-10-09 -toc: true -toc_label: "" -tags: - - Valid Accounts - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search provides detection of high risk permissions by resource and accounts. These are permissions that can allow attackers with compromised accounts to move laterally and escalate privileges. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-10-09 -- **Author**: Rod Soto, Splunk -- **ID**: 2e70ef35-2187-431f-aedc-4503dc9b06ba - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`google_gcp_pubsub_message` data.protoPayload.authorizationInfo{}.permission=iam.serviceAccounts.getaccesstoken OR iam.serviceAccounts.setIamPolicy OR iam.serviceAccounts.actas OR dataflow.jobs.create OR composer.environments.create OR dataproc.clusters.create -|table data.protoPayload.requestMetadata.callerIp data.protoPayload.authenticationInfo.principalEmail data.protoPayload.authorizationInfo{}.permission data.protoPayload.response.bindings{}.members{} data.resource.labels.project_id -| `gcp_detect_high_risk_permissions_by_resource_and_account_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [google_gcp_pubsub_message](https://github.com/splunk/security_content/blob/develop/macros/google_gcp_pubsub_message.yml) - -> :information_source: -> **gcp_detect_high_risk_permissions_by_resource_and_account_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* data.protoPayload.authorizationInfo{}.permission -* data.protoPayload.requestMetadata.callerIp -* data.protoPayload.authenticationInfo.principalEmail -* data.protoPayload.authorizationInfo{}.permission -* data.protoPayload.response.bindings{}.members{} -* data.resource.labels.project_id - - -#### How To Implement -You must install splunk GCP add-on. This search works with gcp:pubsub:message logs - -#### Known False Positives -High risk permissions are part of any GCP environment, however it is important to track resource and accounts usage, this search may produce false positives. - -#### Associated Analytic story -* [GCP Cross Account Activity](/stories/gcp_cross_account_activity) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/dxa4481/gcploit](https://github.com/dxa4481/gcploit) -* [https://www.youtube.com/watch?v=Ml09R38jpok](https://www.youtube.com/watch?v=Ml09R38jpok) -* [https://cloud.google.com/iam/docs/permissions-reference](https://cloud.google.com/iam/docs/permissions-reference) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-10-15-detect_activity_related_to_pass_the_hash_attacks.md b/docs/_posts/2020-10-15-detect_activity_related_to_pass_the_hash_attacks.md deleted file mode 100644 index d7016c612e..0000000000 --- a/docs/_posts/2020-10-15-detect_activity_related_to_pass_the_hash_attacks.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: "Detect Activity Related to Pass the Hash Attacks" -excerpt: "Use Alternate Authentication Material -, Pass the Hash -" -categories: - - Endpoint -last_modified_at: 2020-10-15 -toc: true -toc_label: "" -tags: - - Use Alternate Authentication Material - - Pass the Hash - - Defense Evasion - - Lateral Movement - - Defense Evasion - - Lateral Movement - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for specific authentication events from the Windows Security Event logs to detect potential attempts at using the Pass-the-Hash technique. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-10-15 -- **Author**: Bhavin Patel, Patrick Bareiss, Splunk -- **ID**: f5939373-8054-40ad-8c64-cec478a22a4b - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1550](https://attack.mitre.org/techniques/T1550/) | Use Alternate Authentication Material | Defense Evasion, Lateral Movement | - -| [T1550.002](https://attack.mitre.org/techniques/T1550/002/) | Pass the Hash | Defense Evasion, Lateral Movement | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* PR.AT -* PR.AC -* PR.IP - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`wineventlog_security` EventCode=4624 (Logon_Type=3 Logon_Process=NtLmSsp WorkstationName=WORKSTATION NOT AccountName="ANONYMOUS LOGON") OR (Logon_Type=9 Logon_Process=seclogo) -| fillnull -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode, Logon_Type, WorkstationName, user, dest -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_activity_related_to_pass_the_hash_attacks_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **detect_activity_related_to_pass_the_hash_attacks_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Logon_Type -* Logon_Process -* WorkstationName -* user -* dest - - -#### How To Implement -To successfully implement this search, you must ingest your Windows Security Event logs and leverage the latest TA for Windows. - -#### Known False Positives -Legitimate logon activity by authorized NTLM systems may be detected by this search. Please investigate as appropriate. - -#### Associated Analytic story -* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | The following $EventCode$ occurred on $dest$ by $user$ with Logon Type 3, which may be indicative of the pass the hash technique. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1550.002/atomic_red_team/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1550.002/atomic_red_team/windows-security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml) \| *version*: **5** \ No newline at end of file diff --git a/docs/_posts/2020-10-21-detect_kerberoasting.md b/docs/_posts/2020-10-21-detect_kerberoasting.md deleted file mode 100644 index ac558b4614..0000000000 --- a/docs/_posts/2020-10-21-detect_kerberoasting.md +++ /dev/null @@ -1,112 +0,0 @@ ---- -title: "Detect Kerberoasting" -excerpt: "Kerberoasting, Steal or Forge Kerberos Tickets" -categories: - - Endpoint -last_modified_at: 2020-10-21 -toc: true -toc_label: "" -tags: - - Kerberoasting - - Credential Access - - Steal or Forge Kerberos Tickets - - Credential Access - - Splunk Behavioral Analytics - - Certificates ---- - -### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This search detects a potential kerberoasting attack via service principal name requests - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Certificates](https://docs.splunk.com/Documentation/CIM/latest/User/Certificates) -- **Last Updated**: 2020-10-21 -- **Author**: Xiao Lin, Splunk -- **ID**: dabdd6d7-3e10-42be-8711-4e124f7a3850 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1558.003](https://attack.mitre.org/techniques/T1558/003/) | Kerberoasting | Credential Access | - -| [T1558](https://attack.mitre.org/techniques/T1558/) | Steal or Forge Kerberos Tickets | Credential Access | - -#### Search - -``` - -| from read_ssa_enriched_events() -| eval _time=map_get(input_event, "_time"), EventCode=map_get(input_event, "event_code"), TicketOptions=map_get(input_event, "ticket_options"), TicketEncryptionType=map_get(input_event, "ticket_encryption_type"), ServiceName=map_get(input_event, "service_name"), ServiceID=map_get(input_event, "service_id"), dest_user_id=ucast(map_get(input_event, "dest_user_id"), "string", null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where EventCode="4769" AND TicketOptions="0x40810000" AND TicketEncryptionType="0x17" -| first_time_event input_columns=["EventCode","TicketOptions","TicketEncryptionType","ServiceName","ServiceID"] -| where first_time_EventCode_TicketOptions_TicketEncryptionType_ServiceName_ServiceID -| eval start_time=_time, end_time=_time -| eval body=create_map(["event_id", event_id, "EventCode", EventCode, "ServiceName", ServiceName, "TicketOptions", TicketOptions, "TicketEncryptionType", TicketEncryptionType]), entities = mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)) -| select start_time, end_time, entities, body -| into write_ssa_detected_events(); -``` - -#### Macros -The SPL above uses the following Macros: - -Note that `detect_kerberoasting_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* service_name -* _time -* event_code -* ticket_encryption_type -* service_id -* ticket_options - - -#### How To Implement -The test data is converted from Windows Security Event logs generated from Attach Range simulation and used in SPL search and extended to SPL2 - -#### Known False Positives -Older systems that support kerberos RC4 by default NetApp may generate false positives - -#### Associated Analytic story -* [Credential Dumping](/stories/credential_dumping) - - -#### Kill Chain Phase -* Actions on Objectives - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 14.0 | 70 | 20 | Kerberoasting malware is potentially applying stolen credentials. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ | - - -Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` - - - -#### Reference - -* [Initial ESCU implementation by Jose Hernandez and Patrick Bareiss](Initial ESCU implementation by Jose Hernandez and Patrick Bareiss) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/endpoint/detect_kerberoasting.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2020-10-21-detect_snicat_sni_exfiltration.md b/docs/_posts/2020-10-21-detect_snicat_sni_exfiltration.md deleted file mode 100644 index ea3778cd01..0000000000 --- a/docs/_posts/2020-10-21-detect_snicat_sni_exfiltration.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: "Detect SNICat SNI Exfiltration" -excerpt: "Exfiltration Over C2 Channel -" -categories: - - Network -last_modified_at: 2020-10-21 -toc: true -toc_label: "" -tags: - - Exfiltration Over C2 Channel - - Exfiltration - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for commands that the SNICat tool uses in the TLS SNI field. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-10-21 -- **Author**: Shannon Davis, Splunk -- **ID**: 82d06410-134c-11eb-adc1-0242ac120002 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1041](https://attack.mitre.org/techniques/T1041/) | Exfiltration Over C2 Channel | Exfiltration | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.DS -* DE.CM -* DE.AE - - - -
-
- -
- CIS20 - -
- -* CIS 13 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`zeek_ssl` -| rex field=server_name "(?(LIST -|LS -|SIZE -|LD -|CB -|CD -|EX -|ALIVE -|EXIT -|WHERE -|finito)-[A-Za-z0-9]{16}\.)" -| stats count by src_ip dest_ip server_name snicat -| where count>0 -| table src_ip dest_ip server_name snicat -| `detect_snicat_sni_exfiltration_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [zeek_ssl](https://github.com/splunk/security_content/blob/develop/macros/zeek_ssl.yml) - -> :information_source: -> **detect_snicat_sni_exfiltration_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* server_name -* src_ip -* dest_ip - - -#### How To Implement -You must be ingesting Zeek SSL data into Splunk. Zeek data should also be getting ingested in JSON format. We are detecting when any of the predefined SNICat commands are found within the server_name (SNI) field. These commands are LIST, LS, SIZE, LD, CB, EX, ALIVE, EXIT, WHERE, and finito. You can go further once this has been detected, and run other searches to decode the SNI data to prove or disprove if any data exfiltration has taken place. - -#### Known False Positives -Unknown - -#### Associated Analytic story -* [Data Exfiltration](/stories/data_exfiltration) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.mnemonic.io/resources/blog/introducing-snicat/](https://www.mnemonic.io/resources/blog/introducing-snicat/) -* [https://github.com/mnemonic-no/SNIcat](https://github.com/mnemonic-no/SNIcat) -* [https://attack.mitre.org/techniques/T1041/](https://attack.mitre.org/techniques/T1041/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/network/detect_snicat_sni_exfiltration.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-10-28-detect_ipv6_network_infrastructure_threats.md b/docs/_posts/2020-10-28-detect_ipv6_network_infrastructure_threats.md deleted file mode 100644 index c7023ed7fd..0000000000 --- a/docs/_posts/2020-10-28-detect_ipv6_network_infrastructure_threats.md +++ /dev/null @@ -1,194 +0,0 @@ ---- -title: "Detect IPv6 Network Infrastructure Threats" -excerpt: "Hardware Additions -, Network Denial of Service -, Adversary-in-the-Middle -, ARP Cache Poisoning -" -categories: - - Network -last_modified_at: 2020-10-28 -toc: true -toc_label: "" -tags: - - Hardware Additions - - Network Denial of Service - - Adversary-in-the-Middle - - ARP Cache Poisoning - - Initial Access - - Impact - - Collection - - Credential Access - - Collection - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -By enabling IPv6 First Hop Security as a Layer 2 Security measure on the organization's network devices, we will be able to detect various attacks such as packet forging in the Infrastructure. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-10-28 -- **Author**: Mikael Bjerkeland, Splunk -- **ID**: c3be767e-7959-44c5-8976-0e9c12a91ad2 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1200](https://attack.mitre.org/techniques/T1200/) | Hardware Additions | Initial Access | - -| [T1498](https://attack.mitre.org/techniques/T1498/) | Network Denial of Service | Impact | - -| [T1557](https://attack.mitre.org/techniques/T1557/) | Adversary-in-the-Middle | Collection, Credential Access | - -| [T1557.002](https://attack.mitre.org/techniques/T1557/002/) | ARP Cache Poisoning | Collection, Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance -* Delivery -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* ID.AM -* PR.DS - - - -
-
- -
- CIS20 - -
- -* CIS 1 -* CIS 11 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cisco_networks` facility="SISF" mnemonic IN ("IP_THEFT","MAC_THEFT","MAC_AND_IP_THEFT","PAK_DROP") -| eval src_interface=src_int_prefix_long+src_int_suffix -| eval dest_interface=dest_int_prefix_long+dest_int_suffix -| stats min(_time) AS firstTime max(_time) AS lastTime values(src_mac) AS src_mac values(src_vlan) AS src_vlan values(mnemonic) AS mnemonic values(vendor_explanation) AS vendor_explanation values(src_ip) AS src_ip values(dest_ip) AS dest_ip values(dest_interface) AS dest_interface values(action) AS action count BY host src_interface -| table host src_interface dest_interface src_mac src_ip dest_ip src_vlan mnemonic vendor_explanation action count -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -| `detect_ipv6_network_infrastructure_threats_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [cisco_networks](https://github.com/splunk/security_content/blob/develop/macros/cisco_networks.yml) - -> :information_source: -> **detect_ipv6_network_infrastructure_threats_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* facility -* mnemonic -* src_int_prefix_long -* src_int_suffix -* dest_int_prefix_long -* dest_int_suffix -* src_mac -* src_vlan -* vendor_explanation -* action - - -#### How To Implement -This search uses a standard SPL query on logs from Cisco Network devices. The network devices must be configured with one or more First Hop Security measures such as RA Guard, DHCP Guard and/or device tracking. See References for more information. The search also requires that the Cisco Networks Add-on for Splunk (https://splunkbase.splunk.com/app/1467) is used to parse the logs from the Cisco network devices. - -#### Known False Positives -None currently known - -#### Associated Analytic story -* [Router and Infrastructure Security](/stories/router_and_infrastructure_security) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.ciscolive.com/c/dam/r/ciscolive/emea/docs/2019/pdf/BRKSEC-3200.pdf](https://www.ciscolive.com/c/dam/r/ciscolive/emea/docs/2019/pdf/BRKSEC-3200.pdf) -* [https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/ipv6_fhsec/configuration/xe-16-12/ip6f-xe-16-12-book/ip6-ra-guard.html](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/ipv6_fhsec/configuration/xe-16-12/ip6f-xe-16-12-book/ip6-ra-guard.html) -* [https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/ipv6_fhsec/configuration/xe-16-12/ip6f-xe-16-12-book/ip6-snooping.html](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/ipv6_fhsec/configuration/xe-16-12/ip6f-xe-16-12-book/ip6-snooping.html) -* [https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/ipv6_fhsec/configuration/xe-16-12/ip6f-xe-16-12-book/ip6-dad-proxy.html](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/ipv6_fhsec/configuration/xe-16-12/ip6f-xe-16-12-book/ip6-dad-proxy.html) -* [https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/ipv6_fhsec/configuration/xe-16-12/ip6f-xe-16-12-book/ip6-nd-mcast-supp.html](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/ipv6_fhsec/configuration/xe-16-12/ip6f-xe-16-12-book/ip6-nd-mcast-supp.html) -* [https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/ipv6_fhsec/configuration/xe-16-12/ip6f-xe-16-12-book/ip6-dhcpv6-guard.html](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/ipv6_fhsec/configuration/xe-16-12/ip6f-xe-16-12-book/ip6-dhcpv6-guard.html) -* [https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/ipv6_fhsec/configuration/xe-16-12/ip6f-xe-16-12-book/ip6-src-guard.html](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/ipv6_fhsec/configuration/xe-16-12/ip6f-xe-16-12-book/ip6-src-guard.html) -* [https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/ipv6_fhsec/configuration/xe-16-12/ip6f-xe-16-12-book/ipv6-dest-guard.html](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/ipv6_fhsec/configuration/xe-16-12/ip6f-xe-16-12-book/ipv6-dest-guard.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/network/detect_ipv6_network_infrastructure_threats.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-10-28-detect_port_security_violation.md b/docs/_posts/2020-10-28-detect_port_security_violation.md deleted file mode 100644 index f4b280451b..0000000000 --- a/docs/_posts/2020-10-28-detect_port_security_violation.md +++ /dev/null @@ -1,183 +0,0 @@ ---- -title: "Detect Port Security Violation" -excerpt: "Hardware Additions -, Network Denial of Service -, Adversary-in-the-Middle -, ARP Cache Poisoning -" -categories: - - Network -last_modified_at: 2020-10-28 -toc: true -toc_label: "" -tags: - - Hardware Additions - - Network Denial of Service - - Adversary-in-the-Middle - - ARP Cache Poisoning - - Initial Access - - Impact - - Collection - - Credential Access - - Collection - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -By enabling Port Security on a Cisco switch you can restrict input to an interface by limiting and identifying MAC addresses of the workstations that are allowed to access the port. When you assign secure MAC addresses to a secure port, the port does not forward packets with source addresses outside the group of defined addresses. If you limit the number of secure MAC addresses to one and assign a single secure MAC address, the workstation attached to that port is assured the full bandwidth of the port. If a port is configured as a secure port and the maximum number of secure MAC addresses is reached, when the MAC address of a workstation attempting to access the port is different from any of the identified secure MAC addresses, a security violation occurs. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-10-28 -- **Author**: Mikael Bjerkeland, Splunk -- **ID**: 2de3d5b8-a4fa-45c5-8540-6d071c194d24 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1200](https://attack.mitre.org/techniques/T1200/) | Hardware Additions | Initial Access | - -| [T1498](https://attack.mitre.org/techniques/T1498/) | Network Denial of Service | Impact | - -| [T1557](https://attack.mitre.org/techniques/T1557/) | Adversary-in-the-Middle | Collection, Credential Access | - -| [T1557.002](https://attack.mitre.org/techniques/T1557/002/) | ARP Cache Poisoning | Collection, Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance -* Delivery -* Exploitation -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* ID.AM -* PR.DS - - - -
-
- -
- CIS20 - -
- -* CIS 1 -* CIS 11 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cisco_networks` (facility="PM" mnemonic="ERR_DISABLE" disable_cause="psecure-violation") OR (facility="PORT_SECURITY" mnemonic="PSECURE_VIOLATION" OR mnemonic="PSECURE_VIOLATION_VLAN") -| eval src_interface=src_int_prefix_long+src_int_suffix -| stats min(_time) AS firstTime max(_time) AS lastTime values(disable_cause) AS disable_cause values(src_mac) AS src_mac values(src_vlan) AS src_vlan values(action) AS action count by host src_interface -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_port_security_violation_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [cisco_networks](https://github.com/splunk/security_content/blob/develop/macros/cisco_networks.yml) - -> :information_source: -> **detect_port_security_violation_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* facility -* mnemonic -* disable_cause -* src_int_prefix_long -* src_int_suffix -* src_mac -* src_vlan -* action -* host -* src_interface - - -#### How To Implement -This search uses a standard SPL query on logs from Cisco Network devices. The network devices must be configured with Port Security and Error Disable for this to work (see https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst4500/12-2/25ew/configuration/guide/conf/port_sec.html) and log with a severity level of minimum "5 - notification". The search also requires that the Cisco Networks Add-on for Splunk (https://splunkbase.splunk.com/app/1467) is used to parse the logs from the Cisco network devices. - -#### Known False Positives -This search might be prone to high false positives if you have malfunctioning devices connected to your ethernet ports or if end users periodically connect physical devices to the network. - -#### Associated Analytic story -* [Router and Infrastructure Security](/stories/router_and_infrastructure_security) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/network/detect_port_security_violation.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-10-28-detect_software_download_to_network_device.md b/docs/_posts/2020-10-28-detect_software_download_to_network_device.md deleted file mode 100644 index 11f87c2188..0000000000 --- a/docs/_posts/2020-10-28-detect_software_download_to_network_device.md +++ /dev/null @@ -1,167 +0,0 @@ ---- -title: "Detect Software Download To Network Device" -excerpt: "TFTP Boot -, Pre-OS Boot -" -categories: - - Network -last_modified_at: 2020-10-28 -toc: true -toc_label: "" -tags: - - TFTP Boot - - Pre-OS Boot - - Defense Evasion - - Persistence - - Defense Evasion - - Persistence - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Network_Traffic ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -Adversaries may abuse netbooting to load an unauthorized network device operating system from a Trivial File Transfer Protocol (TFTP) server. TFTP boot (netbooting) is commonly used by network administrators to load configuration-controlled network device images from a centralized management server. Netbooting is one option in the boot sequence and can be used to centralize, manage, and control device images. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Network_Traffic](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkTraffic) -- **Last Updated**: 2020-10-28 -- **Author**: Mikael Bjerkeland, Splunk -- **ID**: cc590c66-f65f-48f2-986a-4797244762f8 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1542.005](https://attack.mitre.org/techniques/T1542/005/) | TFTP Boot | Defense Evasion, Persistence | - -| [T1542](https://attack.mitre.org/techniques/T1542/) | Pre-OS Boot | Defense Evasion, Persistence | - -
-
- - -
- Kill Chain Phase - -
- -* Delivery - - -
-
- - -
- NIST - -
- -* ID.AM -* PR.DS - - - -
-
- -
- CIS20 - -
- -* CIS 1 -* CIS 11 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Network_Traffic where (All_Traffic.transport=udp AND All_Traffic.dest_port=69) OR (All_Traffic.transport=tcp AND All_Traffic.dest_port=21) OR (All_Traffic.transport=tcp AND All_Traffic.dest_port=22) AND All_Traffic.dest_category!=common_software_repo_destination AND All_Traffic.src_category=network OR All_Traffic.src_category=router OR All_Traffic.src_category=switch by All_Traffic.src All_Traffic.dest All_Traffic.dest_port -| `drop_dm_object_name("All_Traffic")` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_software_download_to_network_device_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **detect_software_download_to_network_device_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* All_Traffic.transport -* All_Traffic.dest_port -* All_Traffic.dest_category -* All_Traffic.src_category -* All_Traffic.src -* All_Traffic.dest - - -#### How To Implement -This search looks for Network Traffic events to TFTP, FTP or SSH/SCP ports from network devices. Make sure to tag any network devices as network, router or switch in order for this detection to work. If the TFTP traffic doesn't traverse a firewall nor packet inspection, these events will not be logged. This is typically an issue if the TFTP server is on the same subnet as the network device. There is also a chance of the network device loading software using a DHCP assigned IP address (netboot) which is not in the Asset inventory. - -#### Known False Positives -This search will also report any legitimate attempts of software downloads to network devices as well as outbound SSH sessions from network devices. - -#### Associated Analytic story -* [Router and Infrastructure Security](/stories/router_and_infrastructure_security) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/network/detect_software_download_to_network_device.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-10-28-detect_traffic_mirroring.md b/docs/_posts/2020-10-28-detect_traffic_mirroring.md deleted file mode 100644 index 5275e8e08a..0000000000 --- a/docs/_posts/2020-10-28-detect_traffic_mirroring.md +++ /dev/null @@ -1,171 +0,0 @@ ---- -title: "Detect Traffic Mirroring" -excerpt: "Hardware Additions -, Automated Exfiltration -, Network Denial of Service -, Traffic Duplication -" -categories: - - Network -last_modified_at: 2020-10-28 -toc: true -toc_label: "" -tags: - - Hardware Additions - - Automated Exfiltration - - Network Denial of Service - - Traffic Duplication - - Initial Access - - Exfiltration - - Impact - - Exfiltration - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -Adversaries may leverage traffic mirroring in order to automate data exfiltration over compromised network infrastructure. Traffic mirroring is a native feature for some network devices and used for network analysis and may be configured to duplicate traffic and forward to one or more destinations for analysis by a network analyzer or other monitoring device. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-10-28 -- **Author**: Mikael Bjerkeland, Splunk -- **ID**: 42b3b753-5925-49c5-9742-36fa40a73990 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1200](https://attack.mitre.org/techniques/T1200/) | Hardware Additions | Initial Access | - -| [T1020](https://attack.mitre.org/techniques/T1020/) | Automated Exfiltration | Exfiltration | - -| [T1498](https://attack.mitre.org/techniques/T1498/) | Network Denial of Service | Impact | - -| [T1020.001](https://attack.mitre.org/techniques/T1020/001/) | Traffic Duplication | Exfiltration | - -
-
- - -
- Kill Chain Phase - -
- -* Delivery -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* ID.AM -* PR.DS - - - -
-
- -
- CIS20 - -
- -* CIS 1 -* CIS 11 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cisco_networks` (facility="MIRROR" mnemonic="ETH_SPAN_SESSION_UP") OR (facility="SPAN" mnemonic="SESSION_UP") OR (facility="SPAN" mnemonic="PKTCAP_START") OR (mnemonic="CFGLOG_LOGGEDCMD" command="monitor session*") -| stats min(_time) AS firstTime max(_time) AS lastTime count BY host facility mnemonic -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -| `detect_traffic_mirroring_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [cisco_networks](https://github.com/splunk/security_content/blob/develop/macros/cisco_networks.yml) - -> :information_source: -> **detect_traffic_mirroring_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* facility -* mnemonic -* host - - -#### How To Implement -This search uses a standard SPL query on logs from Cisco Network devices. The network devices must log with a severity level of minimum "5 - notification". The search also requires that the Cisco Networks Add-on for Splunk (https://splunkbase.splunk.com/app/1467) is used to parse the logs from the Cisco network devices and that the devices have been configured according to the documentation of the Cisco Networks Add-on. Also note that an attacker may disable logging from the device prior to enabling traffic mirroring. - -#### Known False Positives -This search will return false positives for any legitimate traffic captures by network administrators. - -#### Associated Analytic story -* [Router and Infrastructure Security](/stories/router_and_infrastructure_security) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/network/detect_traffic_mirroring.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-11-06-ryuk_test_files_detected.md b/docs/_posts/2020-11-06-ryuk_test_files_detected.md deleted file mode 100644 index 30d6f15c08..0000000000 --- a/docs/_posts/2020-11-06-ryuk_test_files_detected.md +++ /dev/null @@ -1,157 +0,0 @@ ---- -title: "Ryuk Test Files Detected" -excerpt: "Data Encrypted for Impact -" -categories: - - Endpoint -last_modified_at: 2020-11-06 -toc: true -toc_label: "" -tags: - - Data Encrypted for Impact - - Impact - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The search looks for files that contain the key word *Ryuk* under any folder in the C drive, which is consistent with Ryuk propagation. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2020-11-06 -- **Author**: Rod Soto, Jose Hernandez, Splunk -- **ID**: 57d44d70-28d9-4ed1-acf5-1c80ae2bbce3 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1486](https://attack.mitre.org/techniques/T1486/) | Data Encrypted for Impact | Impact | - -
-
- - -
- Kill Chain Phase - -
- -* Delivery - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem WHERE "Filesystem.file_path"=C:\\*Ryuk* BY "Filesystem.dest", "Filesystem.user", "Filesystem.file_path" -| `drop_dm_object_name(Filesystem)` -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `ryuk_test_files_detected_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **ryuk_test_files_detected_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Filesystem.file_path -* Filesystem.dest -* Filesystem.user - - -#### How To Implement -You must be ingesting data that records the filesystem activity from your hosts to populate the Endpoint Filesystem data-model object. If you are using Sysmon, you will need a Splunk Universal Forwarder on each endpoint from which you want to collect data. - -#### Known False Positives -If there are files with this keywoord as file names it might trigger false possitives, please make use of our filters to tune out potential FPs. - -#### Associated Analytic story -* [Ryuk Ransomware](/stories/ryuk_ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 70.0 | 70 | 100 | A creation of ryuk test file $file_path$ in host $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ryuk/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ryuk/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/ryuk_test_files_detected.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-11-06-windows_connhost_exe_started_forcefully.md b/docs/_posts/2020-11-06-windows_connhost_exe_started_forcefully.md deleted file mode 100644 index aad62e03e2..0000000000 --- a/docs/_posts/2020-11-06-windows_connhost_exe_started_forcefully.md +++ /dev/null @@ -1,150 +0,0 @@ ---- -title: "Windows connhost exe started forcefully" -excerpt: "Windows Command Shell -" -categories: - - Deprecated -last_modified_at: 2020-11-06 -toc: true -toc_label: "" -tags: - - Windows Command Shell - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The search looks for the Console Window Host process (connhost.exe) executed using the force flag -ForceV1. This is not regular behavior in the Windows OS and is often seen executed by the Ryuk Ransomware. DEPRECATED This event is actually seen in the windows 10 client of attack_range_local. After further testing we realized this is not specific to Ryuk. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-11-06 -- **Author**: Rod Soto, Jose Hernandez, Splunk -- **ID**: c114aaca-68ee-41c2-ad8c-32bf21db8769 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059.003](https://attack.mitre.org/techniques/T1059/003/) | Windows Command Shell | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Delivery - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes WHERE Processes.process="*C:\\Windows\\system32\\conhost.exe* 0xffffffff *-ForceV1*" by Processes.user Processes.process_name Processes.process Processes.dest -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_connhost_exe_started_forcefully_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_connhost_exe_started_forcefully_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -You must be ingesting data that records the process-system activity from your hosts to populate the Endpoint Processes data-model object. If you are using Sysmon, you will need a Splunk Universal Forwarder on each endpoint from which you want to collect data. - -#### Known False Positives -This process should not be ran forcefully, we have not see any false positives for this detection - -#### Associated Analytic story -* [Ryuk Ransomware](/stories/ryuk_ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/windows_connhost_exe_started_forcefully.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-11-06-windows_security_account_manager_stopped.md b/docs/_posts/2020-11-06-windows_security_account_manager_stopped.md deleted file mode 100644 index 8863ecb9c6..0000000000 --- a/docs/_posts/2020-11-06-windows_security_account_manager_stopped.md +++ /dev/null @@ -1,158 +0,0 @@ ---- -title: "Windows Security Account Manager Stopped" -excerpt: "Service Stop -" -categories: - - Endpoint -last_modified_at: 2020-11-06 -toc: true -toc_label: "" -tags: - - Service Stop - - Impact - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The search looks for a Windows Security Account Manager (SAM) was stopped via command-line. This is consistent with Ryuk infections across a fleet of endpoints. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2020-11-06 -- **Author**: Rod Soto, Jose Hernandez, Splunk -- **ID**: 69c12d59-d951-431e-ab77-ec426b8d65e6 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1489](https://attack.mitre.org/techniques/T1489/) | Service Stop | Impact | - -
-
- - -
- Kill Chain Phase - -
- -* Delivery - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes WHERE ("Processes.process_name"="net*.exe" "Processes.process"="*stop \"samss\"*") BY "Processes.dest", "Processes.user", "Processes.process" -| `drop_dm_object_name(Processes)` -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `windows_security_account_manager_stopped_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_security_account_manager_stopped_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process_name -* Processes.process -* Processes.dest -* Processes.user - - -#### How To Implement -You must be ingesting data that records the process-system activity from your hosts to populate the Endpoint Processes data-model object. If you are using Sysmon, you will need a Splunk Universal Forwarder on each endpoint from which you want to collect data. - -#### Known False Positives -SAM is a critical windows service, stopping it would cause major issues on an endpoint this makes false positive rare. AlthoughNo false positives have been identified. - -#### Associated Analytic story -* [Ryuk Ransomware](/stories/ryuk_ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 70.0 | 70 | 100 | The Windows Security Account Manager (SAM) was stopped via cli by $user$ on $dest$ by this command: $processs$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ryuk/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ryuk/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_security_account_manager_stopped.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-11-09-common_ransomware_extensions.md b/docs/_posts/2020-11-09-common_ransomware_extensions.md deleted file mode 100644 index dc37dca253..0000000000 --- a/docs/_posts/2020-11-09-common_ransomware_extensions.md +++ /dev/null @@ -1,168 +0,0 @@ ---- -title: "Common Ransomware Extensions" -excerpt: "Data Destruction -" -categories: - - Endpoint -last_modified_at: 2020-11-09 -toc: true -toc_label: "" -tags: - - Data Destruction - - Impact - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The search looks for file modifications with extensions commonly used by Ransomware - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2020-11-09 -- **Author**: David Dorsey, Splunk -- **ID**: a9e5c5db-db11-43ca-86a8-c852d1b2c0ec - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1485](https://attack.mitre.org/techniques/T1485/) | Data Destruction | Impact | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Filesystem.user) as user values(Filesystem.dest) as dest values(Filesystem.file_path) as file_path from datamodel=Endpoint.Filesystem by Filesystem.file_name -| `drop_dm_object_name(Filesystem)` -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| rex field=file_name "(?\.[^\.]+)$" -| `ransomware_extensions` -| `common_ransomware_extensions_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [ransomware_extensions](https://github.com/splunk/security_content/blob/develop/macros/ransomware_extensions.yml) - -> :information_source: -> **common_ransomware_extensions_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Filesystem.user -* Filesystem.dest -* Filesystem.file_path -* Filesystem.file_name - - -#### How To Implement -You must be ingesting data that records the filesystem activity from your hosts to populate the Endpoint file-system data model node. If you are using Sysmon, you will need a Splunk Universal Forwarder on each endpoint from which you want to collect data.\ -This search produces fields (`query`,`query_length`,`count`) that are not yet supported by ES Incident Review and therefore cannot be viewed when a notable event is raised. These fields contribute additional context to the notable. To see the additional metadata, add the following fields, if not already present, to Incident Review - Event Attributes (Configure > Incident Management > Incident Review Settings > Add New Entry):\\n1. **Label:** Name, **Field:** Name\ -1. \ -1. **Label:** File Extension, **Field:** file_extension\ -Detailed documentation on how to create a new field within Incident Review may be found here: `https://docs.splunk.com/Documentation/ES/5.3.0/Admin/Customizenotables#Add_a_field_to_the_notable_event_details` - -#### Known False Positives -It is possible for a legitimate file with these extensions to be created. If this is a true ransomware attack, there will be a large number of files created with these extensions. - -#### Associated Analytic story -* [SamSam Ransomware](/stories/samsam_ransomware) -* [Ryuk Ransomware](/stories/ryuk_ransomware) -* [Ransomware](/stories/ransomware) -* [Clop Ransomware](/stories/clop_ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 90.0 | 90 | 100 | A file - $file_name$ was written to disk on endpoint $dest$ by user $user$, this is indicative of a known ransomware file extension and should be reviewed immediately. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/ransomware_extensions/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/ransomware_extensions/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/common_ransomware_extensions.yml) \| *version*: **4** \ No newline at end of file diff --git a/docs/_posts/2020-11-09-common_ransomware_notes.md b/docs/_posts/2020-11-09-common_ransomware_notes.md deleted file mode 100644 index 02e4d5a45d..0000000000 --- a/docs/_posts/2020-11-09-common_ransomware_notes.md +++ /dev/null @@ -1,163 +0,0 @@ ---- -title: "Common Ransomware Notes" -excerpt: "Data Destruction -" -categories: - - Endpoint -last_modified_at: 2020-11-09 -toc: true -toc_label: "" -tags: - - Data Destruction - - Impact - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The search looks for files created with names matching those typically used in ransomware notes that tell the victim how to get their data back. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2020-11-09 -- **Author**: David Dorsey, Splunk -- **ID**: ada0f478-84a8-4641-a3f1-d82362d6bd71 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1485](https://attack.mitre.org/techniques/T1485/) | Data Destruction | Impact | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Filesystem.user) as user values(Filesystem.dest) as dest values(Filesystem.file_path) as file_path from datamodel=Endpoint.Filesystem by Filesystem.file_name -| `drop_dm_object_name(Filesystem)` -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `ransomware_notes` -| `common_ransomware_notes_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [ransomware_notes](https://github.com/splunk/security_content/blob/develop/macros/ransomware_notes.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **common_ransomware_notes_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Filesystem.user -* Filesystem.dest -* Filesystem.file_path -* Filesystem.file_name - - -#### How To Implement -You must be ingesting data that records file-system activity from your hosts to populate the Endpoint Filesystem data-model node. This is typically populated via endpoint detection-and-response product, such as Carbon Black, or via other endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report file-system reads and writes. - -#### Known False Positives -It's possible that a legitimate file could be created with the same name used by ransomware note files. - -#### Associated Analytic story -* [SamSam Ransomware](/stories/samsam_ransomware) -* [Ransomware](/stories/ransomware) -* [Ryuk Ransomware](/stories/ryuk_ransomware) -* [Clop Ransomware](/stories/clop_ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 90.0 | 90 | 100 | A file - $file_name$ was written to disk on endpoint $dest$ by user $user$, this is indicative of a known ransomware note file and should be reviewed immediately. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/ransomware_notes/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/ransomware_notes/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/common_ransomware_notes.yml) \| *version*: **4** \ No newline at end of file diff --git a/docs/_posts/2020-11-09-deleting_shadow_copies.md b/docs/_posts/2020-11-09-deleting_shadow_copies.md deleted file mode 100644 index f6b57fe6ab..0000000000 --- a/docs/_posts/2020-11-09-deleting_shadow_copies.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: "Deleting Shadow Copies" -excerpt: "Inhibit System Recovery -" -categories: - - Endpoint -last_modified_at: 2020-11-09 -toc: true -toc_label: "" -tags: - - Inhibit System Recovery - - Impact - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The vssadmin.exe utility is used to interact with the Volume Shadow Copy Service. Wmic is an interface to the Windows Management Instrumentation. This search looks for either of these tools being used to delete shadow copies. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2020-11-09 -- **Author**: David Dorsey, Splunk -- **ID**: b89919ed-ee5f-492c-b139-95dbb162039e - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1490](https://attack.mitre.org/techniques/T1490/) | Inhibit System Recovery | Impact | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM -* PR.IP - - - -
-
- -
- CIS20 - -
- -* CIS 8 -* CIS 10 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count values(Processes.process) as process values(Processes.parent_process) as parent_process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name=vssadmin.exe OR Processes.process_name=wmic.exe) Processes.process=*delete* Processes.process=*shadow* by Processes.user Processes.process_name Processes.parent_process_name Processes.dest -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `deleting_shadow_copies_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **deleting_shadow_copies_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -You must be ingesting endpoint data that tracks process activity, including parent-child relationships from your endpoints to populate the Endpoint data model in the Processes node. The command-line arguments are mapped to the "process" field in the Endpoint data model. - -#### Known False Positives -vssadmin.exe and wmic.exe are standard applications shipped with modern versions of windows. They may be used by administrators to legitimately delete old backup copies, although this is typically rare. - -#### Associated Analytic story -* [Windows Log Manipulation](/stories/windows_log_manipulation) -* [SamSam Ransomware](/stories/samsam_ransomware) -* [Ransomware](/stories/ransomware) -* [Clop Ransomware](/stories/clop_ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 81.0 | 90 | 90 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to delete shadow copies. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1490/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1490/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/deleting_shadow_copies.yml) \| *version*: **4** \ No newline at end of file diff --git a/docs/_posts/2020-11-09-detect_excessive_account_lockouts_from_endpoint.md b/docs/_posts/2020-11-09-detect_excessive_account_lockouts_from_endpoint.md deleted file mode 100644 index 2deda244e4..0000000000 --- a/docs/_posts/2020-11-09-detect_excessive_account_lockouts_from_endpoint.md +++ /dev/null @@ -1,175 +0,0 @@ ---- -title: "Detect Excessive Account Lockouts From Endpoint" -excerpt: "Valid Accounts -, Domain Accounts -" -categories: - - Endpoint -last_modified_at: 2020-11-09 -toc: true -toc_label: "" -tags: - - Valid Accounts - - Domain Accounts - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Change ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search identifies endpoints that have caused a relatively high number of account lockouts in a short period. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Change](https://docs.splunk.com/Documentation/CIM/latest/User/Change) -- **Last Updated**: 2020-11-09 -- **Author**: David Dorsey, Splunk -- **ID**: c026e3dd-7e18-4abb-8f41-929e836efe74 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -| [T1078.002](https://attack.mitre.org/techniques/T1078/002/) | Domain Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* PR.IP - - - -
-
- -
- CIS20 - -
- -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(All_Changes.user) as user from datamodel=Change.All_Changes where nodename=All_Changes.Account_Management All_Changes.result="lockout" by All_Changes.dest All_Changes.result -|`drop_dm_object_name("All_Changes")` -|`drop_dm_object_name("Account_Management")` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| search count > 5 -| `detect_excessive_account_lockouts_from_endpoint_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **detect_excessive_account_lockouts_from_endpoint_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* All_Changes.user -* nodename -* All_Changes.result -* All_Changes.dest - - -#### How To Implement -You must ingest your Windows security event logs in the `Change` datamodel under the nodename is `Account_Management`, for this search to execute successfully. Please consider updating the cron schedule and the count of lockouts you want to monitor, according to your environment. \ - **Splunk>Phantom Playbook Integration**\ -If Splunk>Phantom is also configured in your environment, a Playbook called "Excessive Account Lockouts Enrichment and Response" can be configured to run when any results are found by this detection search. The Playbook executes the Contextual and Investigative searches in this Story, conducts additional information gathering on Windows endpoints, and takes a response action to shut down the affected endpoint. To use this integration, install the Phantom App for Splunk `https://splunkbase.splunk.com/app/3411/`, add the correct hostname to the "Phantom Instance" field in the Adaptive Response Actions when configuring this detection search, and set the corresponding Playbook to active. \ -(Playbook Link:`https://my.phantom.us/4.1/playbook/excessive-account-lockouts-enrichment-and-response/`).\ - - -#### Known False Positives -It's possible that a widely used system, such as a kiosk, could cause a large number of account lockouts. - -#### Associated Analytic story -* [Account Monitoring and Controls](/stories/account_monitoring_and_controls) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 36.0 | 60 | 60 | Multiple accounts have been locked out. Review $dest$ and results related to $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078.002/account_lockout/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078.002/account_lockout/windows-security.log) -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078.002/account_lockout/windows-system.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078.002/account_lockout/windows-system.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml) \| *version*: **5** \ No newline at end of file diff --git a/docs/_posts/2020-11-10-detect_processes_used_for_system_network_configuration_discovery.md b/docs/_posts/2020-11-10-detect_processes_used_for_system_network_configuration_discovery.md deleted file mode 100644 index f3728f515c..0000000000 --- a/docs/_posts/2020-11-10-detect_processes_used_for_system_network_configuration_discovery.md +++ /dev/null @@ -1,172 +0,0 @@ ---- -title: "Detect processes used for System Network Configuration Discovery" -excerpt: "System Network Configuration Discovery -" -categories: - - Endpoint -last_modified_at: 2020-11-10 -toc: true -toc_label: "" -tags: - - System Network Configuration Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for fast execution of processes used for system network configuration discovery on the endpoint. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2020-11-10 -- **Author**: Bhavin Patel, Splunk -- **ID**: a51bfe1a-94f0-48cc-b1e4-16ae10145893 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1016](https://attack.mitre.org/techniques/T1016/) | System Network Configuration Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Installation -* Command & Control -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* ID.AM -* PR.DS - - - -
-
- -
- CIS20 - -
- -* CIS 2 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count values(Processes.process) as process values(Processes.parent_process) as parent_process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where NOT Processes.user IN ("","unknown") by Processes.dest Processes.process_name Processes.user _time -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `drop_dm_object_name(Processes)` -| search `system_network_configuration_discovery_tools` -| transaction dest connected=false maxpause=5m -|where eventcount>=5 -| table firstTime lastTime dest user process_name process parent_process eventcount -| `detect_processes_used_for_system_network_configuration_discovery_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [system_network_configuration_discovery_tools](https://github.com/splunk/security_content/blob/develop/macros/system_network_configuration_discovery_tools.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **detect_processes_used_for_system_network_configuration_discovery_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -You must be ingesting data that records registry activity from your hosts to populate the Endpoint data model in the processes node. This is typically populated via endpoint detection-and-response product, such as Carbon Black, or endpoint data sources, such as Sysmon. The data used for this search is usually generated via logs that report reads and writes to the registry or that are populated via Windows event logs, after enabling process tracking in your Windows audit settings. - -#### Known False Positives -It is uncommon for normal users to execute a series of commands used for network discovery. System administrators often use scripts to execute these commands. These can generate false positives. - -#### Associated Analytic story -* [Unusual Processes](/stories/unusual_processes) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 32.0 | 40 | 80 | An instance of $parent_process_name$ spawning multiple $process_name$ was identified on endpoint $dest$ by user $user$ typically not a normal behavior of the process. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1016/discovery_commands/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1016/discovery_commands/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2020-11-10-detect_prohibited_applications_spawning_cmd_exe.md b/docs/_posts/2020-11-10-detect_prohibited_applications_spawning_cmd_exe.md deleted file mode 100644 index e8b58d02a8..0000000000 --- a/docs/_posts/2020-11-10-detect_prohibited_applications_spawning_cmd_exe.md +++ /dev/null @@ -1,176 +0,0 @@ ---- -title: "Detect Prohibited Applications Spawning cmd exe" -excerpt: "Command and Scripting Interpreter -, Windows Command Shell -" -categories: - - Endpoint -last_modified_at: 2020-11-10 -toc: true -toc_label: "" -tags: - - Command and Scripting Interpreter - - Windows Command Shell - - Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for executions of cmd.exe spawned by a process that is often abused by attackers and that does not typically launch cmd.exe. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2020-11-10 -- **Author**: Bhavin Patel, Splunk -- **ID**: dcfd6b40-42f9-469d-a433-2e53f7486664 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -| [T1059.003](https://attack.mitre.org/techniques/T1059/003/) | Windows Command Shell | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_cmd` by Processes.parent_process_name Processes.process_name Processes.original_file_name Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -|search [`prohibited_apps_launching_cmd`] -| `detect_prohibited_applications_spawning_cmd_exe_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [prohibited_apps_launching_cmd](https://github.com/splunk/security_content/blob/develop/macros/prohibited_apps_launching_cmd.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [process_cmd](https://github.com/splunk/security_content/blob/develop/macros/process_cmd.yml) - -> :information_source: -> **detect_prohibited_applications_spawning_cmd_exe_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -You must be ingesting data that records process activity from your hosts and populates the Endpoint data model with the resultant dataset. This search includes a lookup file, `prohibited_apps_launching_cmd.csv`, that contains a list of processes that should not be spawning cmd.exe. You can modify this lookup to better suit your environment. To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -There are circumstances where an application may legitimately execute and interact with the Windows command-line interface. Investigate and modify the lookup file, as appropriate. - -#### Associated Analytic story -* [Suspicious Command-Line Executions](/stories/suspicious_command-line_executions) -* [Suspicious MSHTA Activity](/stories/suspicious_mshta_activity) -* [Suspicious Zoom Child Processes](/stories/suspicious_zoom_child_processes) -* [NOBELIUM Group](/stories/nobelium_group) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ running prohibited applications. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.003/powershell_spawn_cmd/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.003/powershell_spawn_cmd/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml) \| *version*: **6** \ No newline at end of file diff --git a/docs/_posts/2020-11-18-disabling_remote_user_account_control.md b/docs/_posts/2020-11-18-disabling_remote_user_account_control.md deleted file mode 100644 index 3755196466..0000000000 --- a/docs/_posts/2020-11-18-disabling_remote_user_account_control.md +++ /dev/null @@ -1,168 +0,0 @@ ---- -title: "Disabling Remote User Account Control" -excerpt: "Bypass User Account Control -, Abuse Elevation Control Mechanism -" -categories: - - Endpoint -last_modified_at: 2020-11-18 -toc: true -toc_label: "" -tags: - - Bypass User Account Control - - Abuse Elevation Control Mechanism - - Defense Evasion - - Privilege Escalation - - Defense Evasion - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The search looks for modifications to registry keys that control the enforcement of Windows User Account Control (UAC). - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2020-11-18 -- **Author**: David Dorsey, Patrick Bareiss, Splunk -- **ID**: bbc644bc-37df-4e1a-9c88-ec9a53e2038c - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1548.002](https://attack.mitre.org/techniques/T1548/002/) | Bypass User Account Control | Defense Evasion, Privilege Escalation | - -| [T1548](https://attack.mitre.org/techniques/T1548/) | Abuse Elevation Control Mechanism | Defense Evasion, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path=*HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\EnableLUA* Registry.registry_value_data="0x00000000" by Registry.dest, Registry.registry_key_name Registry.user Registry.registry_path Registry.registry_value_data Registry.action -| `drop_dm_object_name(Registry)` -| `disabling_remote_user_account_control_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **disabling_remote_user_account_control_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.registry_path -* Registry.registry_value_name -* Registry.dest -* Registry.registry_key_name -* Registry.user -* Registry.action - - -#### How To Implement -To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black, or via other endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report registry modifications. - -#### Known False Positives -This registry key may be modified via administrators to implement a change in system policy. This type of change should be a very rare occurrence. - -#### Associated Analytic story -* [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics) -* [Suspicious Windows Registry Activities](/stories/suspicious_windows_registry_activities) -* [Remcos](/stories/remcos) -* [Windows Registry Abuse](/stories/windows_registry_abuse) -* [Azorult](/stories/azorult) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 42.0 | 70 | 60 | The Windows registry keys that control the enforcement of Windows User Account Control (UAC) were modified on $dest$ by $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.002/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.002/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disabling_remote_user_account_control.yml) \| *version*: **4** \ No newline at end of file diff --git a/docs/_posts/2020-11-18-execution_of_file_with_multiple_extensions.md b/docs/_posts/2020-11-18-execution_of_file_with_multiple_extensions.md deleted file mode 100644 index 83b2b703c9..0000000000 --- a/docs/_posts/2020-11-18-execution_of_file_with_multiple_extensions.md +++ /dev/null @@ -1,166 +0,0 @@ ---- -title: "Execution of File with Multiple Extensions" -excerpt: "Masquerading -, Rename System Utilities -" -categories: - - Endpoint -last_modified_at: 2020-11-18 -toc: true -toc_label: "" -tags: - - Masquerading - - Rename System Utilities - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for processes launched from files that have double extensions in the file name. This is typically done to obscure the "real" file extension and make it appear as though the file being accessed is a data file, as opposed to executable content. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2020-11-18 -- **Author**: Rico Valdez, Splunk -- **ID**: b06a555e-dce0-417d-a2eb-28a5d8d66ef7 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1036](https://attack.mitre.org/techniques/T1036/) | Masquerading | Defense Evasion | - -| [T1036.003](https://attack.mitre.org/techniques/T1036/003/) | Rename System Utilities | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.CM -* PR.PT -* PR.IP - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process = *.doc.exe OR Processes.process = *.htm.exe OR Processes.process = *.html.exe OR Processes.process = *.txt.exe OR Processes.process = *.pdf.exe OR Processes.process = *.doc.exe by Processes.dest Processes.user Processes.process Processes.parent_process -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `drop_dm_object_name(Processes)` -| `execution_of_file_with_multiple_extensions_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **execution_of_file_with_multiple_extensions_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process -* Processes.dest -* Processes.user -* Processes.parent_process - - -#### How To Implement -To successfully implement this search, you must be ingesting data that records process activity from your hosts to populate the endpoint data model in the processes node. - -#### Known False Positives -None identified. - -#### Associated Analytic story -* [Windows File Extension and Association Abuse](/stories/windows_file_extension_and_association_abuse) -* [Masquerading - Rename System Utilities](/stories/masquerading_-_rename_system_utilities) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 56.0 | 80 | 70 | process $process$ have double extensions in the file name is executed on $dest$ by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036.003/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036.003/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2020-11-19-execution_of_file_with_spaces_before_extension.md b/docs/_posts/2020-11-19-execution_of_file_with_spaces_before_extension.md deleted file mode 100644 index 5850ce8104..0000000000 --- a/docs/_posts/2020-11-19-execution_of_file_with_spaces_before_extension.md +++ /dev/null @@ -1,159 +0,0 @@ ---- -title: "Execution of File With Spaces Before Extension" -excerpt: "Rename System Utilities -" -categories: - - Deprecated -last_modified_at: 2020-11-19 -toc: true -toc_label: "" -tags: - - Rename System Utilities - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for processes launched from files with at least five spaces in the name before the extension. This is typically done to obfuscate the file extension by pushing it outside of the default view. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2020-11-19 -- **Author**: Rico Valdez, Splunk -- **ID**: ab0353e6-a956-420b-b724-a8b4846d5d5a - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1036.003](https://attack.mitre.org/techniques/T1036/003/) | Rename System Utilities | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.CM -* PR.PT -* PR.IP - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count values(Processes.process_path) as process_path min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process = "* .*" by Processes.dest Processes.user Processes.process Processes.process_name -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `drop_dm_object_name(Processes)` -| `execution_of_file_with_spaces_before_extension_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **execution_of_file_with_spaces_before_extension_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process_path -* Processes.process -* Processes.dest -* Processes.user -* Processes.process_name - - -#### How To Implement -To successfully implement this search, you must be ingesting data that records process activity from your hosts to populate the endpoint data model in the processes node. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -None identified. - -#### Associated Analytic story -* [Windows File Extension and Association Abuse](/stories/windows_file_extension_and_association_abuse) -* [Masquerading - Rename System Utilities](/stories/masquerading_-_rename_system_utilities) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2020-11-23-processes_created_by_netsh.md b/docs/_posts/2020-11-23-processes_created_by_netsh.md deleted file mode 100644 index 7b7f79645c..0000000000 --- a/docs/_posts/2020-11-23-processes_created_by_netsh.md +++ /dev/null @@ -1,151 +0,0 @@ ---- -title: "Processes created by netsh" -excerpt: "Disable or Modify System Firewall -" -categories: - - Deprecated -last_modified_at: 2020-11-23 -toc: true -toc_label: "" -tags: - - Disable or Modify System Firewall - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for processes launching netsh.exe to execute various commands via the netsh command-line utility. Netsh.exe is a command-line scripting utility that allows you to, either locally or remotely, display or modify the network configuration of a computer that is currently running. Netsh can be used as a persistence proxy technique to execute a helper .dll when netsh.exe is executed. In this search, we are looking for processes spawned by netsh.exe that are executing commands via the command line. Deprecated because we have another detection of the same type. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2020-11-23 -- **Author**: Bhavin Patel, Splunk -- **ID**: b89919ed-fe5f-492c-b139-95dbb162041e - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.004](https://attack.mitre.org/techniques/T1562/004/) | Disable or Modify System Firewall | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=netsh.exe by Processes.user Processes.dest Processes.parent_process Processes.parent_process_name Processes.process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `processes_created_by_netsh_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **processes_created_by_netsh_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -To successfully implement this search, you must be ingesting logs with the process name, command-line arguments, and parent processes from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -It is unusual for netsh.exe to have any child processes in most environments. It makes sense to investigate the child process and verify whether the process spawned is legitimate. We explicitely exclude "C:\Program Files\rempl\sedlauncher.exe" process path since it is a legitimate process by Mircosoft. - -#### Associated Analytic story -* [Netsh Abuse](/stories/netsh_abuse) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/processes_created_by_netsh.yml) \| *version*: **5** \ No newline at end of file diff --git a/docs/_posts/2020-11-23-shim_database_installation_with_suspicious_parameters.md b/docs/_posts/2020-11-23-shim_database_installation_with_suspicious_parameters.md deleted file mode 100644 index e2c9aaaf5c..0000000000 --- a/docs/_posts/2020-11-23-shim_database_installation_with_suspicious_parameters.md +++ /dev/null @@ -1,164 +0,0 @@ ---- -title: "Shim Database Installation With Suspicious Parameters" -excerpt: "Application Shimming -, Event Triggered Execution -" -categories: - - Endpoint -last_modified_at: 2020-11-23 -toc: true -toc_label: "" -tags: - - Application Shimming - - Event Triggered Execution - - Persistence - - Privilege Escalation - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search detects the process execution and arguments required to silently create a shim database. The sdbinst.exe application is used to install shim database files (.sdb). A shim is a small library which transparently intercepts an API, changes the parameters passed, handles the operation itself, or redirects the operation elsewhere. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2020-11-23 -- **Author**: David Dorsey, Splunk -- **ID**: 404620de-46d8-48b6-90cc-8a8d7b0876a3 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1546.011](https://attack.mitre.org/techniques/T1546/011/) | Application Shimming | Persistence, Privilege Escalation | - -| [T1546](https://attack.mitre.org/techniques/T1546/) | Event Triggered Execution | Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = sdbinst.exe by Processes.process_name Processes.parent_process_name Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `shim_database_installation_with_suspicious_parameters_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **shim_database_installation_with_suspicious_parameters_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process_name -* Processes.parent_process_name -* Processes.dest -* Processes.user - - -#### How To Implement -You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. - -#### Known False Positives -None identified - -#### Associated Analytic story -* [Windows Persistence Techniques](/stories/windows_persistence_techniques) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 63.0 | 70 | 90 | A process $process_name$ that possible create a shim db silently in host $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.011/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.011/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml) \| *version*: **4** \ No newline at end of file diff --git a/docs/_posts/2020-11-26-reg_exe_manipulating_windows_services_registry_keys.md b/docs/_posts/2020-11-26-reg_exe_manipulating_windows_services_registry_keys.md deleted file mode 100644 index 14d83a388f..0000000000 --- a/docs/_posts/2020-11-26-reg_exe_manipulating_windows_services_registry_keys.md +++ /dev/null @@ -1,176 +0,0 @@ ---- -title: "Reg exe Manipulating Windows Services Registry Keys" -excerpt: "Services Registry Permissions Weakness -, Hijack Execution Flow -" -categories: - - Endpoint -last_modified_at: 2020-11-26 -toc: true -toc_label: "" -tags: - - Services Registry Permissions Weakness - - Hijack Execution Flow - - Defense Evasion - - Persistence - - Privilege Escalation - - Defense Evasion - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The search looks for reg.exe modifying registry keys that define Windows services and their configurations. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2020-11-26 -- **Author**: Rico Valdez, Splunk -- **ID**: 8470d755-0c13-45b3-bd63-387a373c10cf - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1574.011](https://attack.mitre.org/techniques/T1574/011/) | Services Registry Permissions Weakness | Defense Evasion, Persistence, Privilege Escalation | - -| [T1574](https://attack.mitre.org/techniques/T1574/) | Hijack Execution Flow | Defense Evasion, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Installation - - -
-
- - -
- NIST - -
- -* PR.IP -* PR.PT -* PR.AC -* PR.AT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Processes.process_name) as process_name values(Processes.parent_process_name) as parent_process_name values(Processes.user) as user FROM datamodel=Endpoint.Processes where Processes.process_name=reg.exe Processes.process=*reg* Processes.process=*add* Processes.process=*Services* by Processes.process_id Processes.dest Processes.process -| `drop_dm_object_name("Processes")` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `reg_exe_manipulating_windows_services_registry_keys_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **reg_exe_manipulating_windows_services_registry_keys_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process_name -* Processes.parent_process_name -* Processes.user -* Processes.process -* Processes.process_id -* Processes.dest - - -#### How To Implement -To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. - -#### Known False Positives -It is unusual for a service to be created or modified by directly manipulating the registry. However, there may be legitimate instances of this behavior. It is important to validate and investigate, as appropriate. - -#### Associated Analytic story -* [Windows Service Abuse](/stories/windows_service_abuse) -* [Windows Persistence Techniques](/stories/windows_persistence_techniques) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 45.0 | 75 | 60 | A reg.exe process $process_name$ with commandline $process$ in host $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1574.011/change_registry_path_service/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1574.011/change_registry_path_service/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml) \| *version*: **5** \ No newline at end of file diff --git a/docs/_posts/2020-12-07-schtasks_used_for_forcing_a_reboot.md b/docs/_posts/2020-12-07-schtasks_used_for_forcing_a_reboot.md deleted file mode 100644 index bf5a4d23b9..0000000000 --- a/docs/_posts/2020-12-07-schtasks_used_for_forcing_a_reboot.md +++ /dev/null @@ -1,168 +0,0 @@ ---- -title: "Schtasks used for forcing a reboot" -excerpt: "Scheduled Task -, Scheduled Task/Job -" -categories: - - Endpoint -last_modified_at: 2020-12-07 -toc: true -toc_label: "" -tags: - - Scheduled Task - - Scheduled Task/Job - - Execution - - Persistence - - Privilege Escalation - - Execution - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for flags passed to schtasks.exe on the command-line that indicate that a forced reboot of system is scheduled. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2020-12-07 -- **Author**: Bhavin Patel, Splunk -- **ID**: 1297fb80-f42a-4b4a-9c8a-88c066437cf6 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1053.005](https://attack.mitre.org/techniques/T1053/005/) | Scheduled Task | Execution, Persistence, Privilege Escalation | - -| [T1053](https://attack.mitre.org/techniques/T1053/) | Scheduled Task/Job | Execution, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.IP - - - -
-
- -
- CIS20 - -
- -* CIS 3 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=schtasks.exe Processes.process="*shutdown*" Processes.process="*/create *" by Processes.process_name Processes.parent_process_name Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `schtasks_used_for_forcing_a_reboot_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **schtasks_used_for_forcing_a_reboot_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process -* Processes.process_name -* Processes.parent_process_name -* Processes.dest -* Processes.user - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Administrators may create jobs on systems forcing reboots to perform updates, maintenance, etc. - -#### Associated Analytic story -* [Windows Persistence Techniques](/stories/windows_persistence_techniques) -* [Ransomware](/stories/ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 56.0 | 70 | 80 | A schedule task process $process_name$ with force reboot commandline $process$ in host $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/schtask_shutdown/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/schtask_shutdown/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml) \| *version*: **4** \ No newline at end of file diff --git a/docs/_posts/2020-12-08-shim_database_file_creation.md b/docs/_posts/2020-12-08-shim_database_file_creation.md deleted file mode 100644 index 499b7a4006..0000000000 --- a/docs/_posts/2020-12-08-shim_database_file_creation.md +++ /dev/null @@ -1,164 +0,0 @@ ---- -title: "Shim Database File Creation" -excerpt: "Application Shimming -, Event Triggered Execution -" -categories: - - Endpoint -last_modified_at: 2020-12-08 -toc: true -toc_label: "" -tags: - - Application Shimming - - Event Triggered Execution - - Persistence - - Privilege Escalation - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for shim database files being written to default directories. The sdbinst.exe application is used to install shim database files (.sdb). According to Microsoft, a shim is a small library that transparently intercepts an API, changes the parameters passed, handles the operation itself, or redirects the operation elsewhere. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2020-12-08 -- **Author**: David Dorsey, Splunk -- **ID**: 6e4c4588-ba2f-42fa-97e6-9f6f548eaa33 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1546.011](https://attack.mitre.org/techniques/T1546/011/) | Application Shimming | Persistence, Privilege Escalation | - -| [T1546](https://attack.mitre.org/techniques/T1546/) | Event Triggered Execution | Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count values(Filesystem.action) values(Filesystem.file_hash) as file_hash values(Filesystem.file_path) as file_path min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_path=*Windows\\AppPatch\\Custom* by Filesystem.file_name Filesystem.dest -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -|`drop_dm_object_name(Filesystem)` -| `shim_database_file_creation_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **shim_database_file_creation_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Filesystem.file_hash -* Filesystem.file_path -* Filesystem.file_name -* Filesystem.dest - - -#### How To Implement -You must be ingesting data that records the filesystem activity from your hosts to populate the Endpoint file-system data model node. If you are using Sysmon, you will need a Splunk Universal Forwarder on each endpoint from which you want to collect data. - -#### Known False Positives -Because legitimate shim files are created and used all the time, this event, in itself, is not suspicious. However, if there are other correlating events, it may warrant further investigation. - -#### Associated Analytic story -* [Windows Persistence Techniques](/stories/windows_persistence_techniques) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 56.0 | 70 | 80 | A process that possibly write shim database in $file_path$ in host $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.011/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.011/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/shim_database_file_creation.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2020-12-08-single_letter_process_on_endpoint.md b/docs/_posts/2020-12-08-single_letter_process_on_endpoint.md deleted file mode 100644 index 545bc9c5ad..0000000000 --- a/docs/_posts/2020-12-08-single_letter_process_on_endpoint.md +++ /dev/null @@ -1,166 +0,0 @@ ---- -title: "Single Letter Process On Endpoint" -excerpt: "User Execution -, Malicious File -" -categories: - - Endpoint -last_modified_at: 2020-12-08 -toc: true -toc_label: "" -tags: - - User Execution - - Malicious File - - Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for process names that consist only of a single letter. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2020-12-08 -- **Author**: David Dorsey, Splunk -- **ID**: a4214f0b-e01c-41bc-8cc4-d2b71e3056b4 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1204](https://attack.mitre.org/techniques/T1204/) | User Execution | Execution | - -| [T1204.002](https://attack.mitre.org/techniques/T1204/002/) | Malicious File | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* ID.AM -* PR.DS - - - -
-
- -
- CIS20 - -
- -* CIS 2 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes by Processes.dest, Processes.user, Processes.process, Processes.process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| eval process_name_length = len(process_name), endExe = if(substr(process_name, -4) == ".exe", 1, 0) -| search process_name_length=5 AND endExe=1 -| table count, firstTime, lastTime, dest, user, process, process_name -| `single_letter_process_on_endpoint_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **single_letter_process_on_endpoint_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.process -* Processes.process_name - - -#### How To Implement -You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. - -#### Known False Positives -Single-letter executables are not always malicious. Investigate this activity with your normal incident-response process. - -#### Associated Analytic story -* [DHS Report TA18-074A](/stories/dhs_report_ta18-074a) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 63.0 | 70 | 90 | A suspicious process $process_name$ with single letter in host $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1204.002/single_letter_exe/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1204.002/single_letter_exe/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/single_letter_process_on_endpoint.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2020-12-08-system_processes_run_from_unexpected_locations.md b/docs/_posts/2020-12-08-system_processes_run_from_unexpected_locations.md deleted file mode 100644 index 6f18cf8b5a..0000000000 --- a/docs/_posts/2020-12-08-system_processes_run_from_unexpected_locations.md +++ /dev/null @@ -1,177 +0,0 @@ ---- -title: "System Processes Run From Unexpected Locations" -excerpt: "Masquerading -, Rename System Utilities -" -categories: - - Endpoint -last_modified_at: 2020-12-08 -toc: true -toc_label: "" -tags: - - Masquerading - - Rename System Utilities - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for system processes that typically execute from `C:\Windows\System32\` or `C:\Windows\SysWOW64`. This may indicate a malicious process that is trying to hide as a legitimate process.\ -This detection utilizes a lookup that is deduped `system32` and `syswow64` directories from Server 2016 and Windows 10.\ -During triage, review the parallel processes - what process moved the native Windows binary? identify any artifacts on disk and review. If a remote destination is contacted, what is the reputation? - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2020-12-08 -- **Author**: David Dorsey, Michael Haag, Splunk -- **ID**: a34aae96-ccf8-4aef-952c-3ea21444444d - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1036](https://attack.mitre.org/techniques/T1036/) | Masquerading | Defense Evasion | - -| [T1036.003](https://attack.mitre.org/techniques/T1036/003/) | Rename System Utilities | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes where Processes.process_path !="C:\\Windows\\System32*" Processes.process_path !="C:\\Windows\\SysWOW64*" by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.process_hash -| `drop_dm_object_name("Processes")` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `is_windows_system_file` -| `system_processes_run_from_unexpected_locations_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [is_windows_system_file](https://github.com/splunk/security_content/blob/develop/macros/is_windows_system_file.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **system_processes_run_from_unexpected_locations_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process_path -* Processes.user -* Processes.dest -* Processes.process_name -* Processes.process_id -* Processes.parent_process_name -* Processes.process_hash - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -This detection may require tuning based on third party applications utilizing native Windows binaries in non-standard paths. - -#### Associated Analytic story -* [Suspicious Command-Line Executions](/stories/suspicious_command-line_executions) -* [Unusual Processes](/stories/unusual_processes) -* [Ransomware](/stories/ransomware) -* [Masquerading - Rename System Utilities](/stories/masquerading_-_rename_system_utilities) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | System process running from unexpected location on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1036.003/T1036.003.yaml](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1036.003/T1036.003.yaml) -* [https://attack.mitre.org/techniques/T1036/003/](https://attack.mitre.org/techniques/T1036/003/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036.003/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036.003/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml) \| *version*: **6** \ No newline at end of file diff --git a/docs/_posts/2020-12-08-unusually_long_command_line.md b/docs/_posts/2020-12-08-unusually_long_command_line.md deleted file mode 100644 index a6874e39d2..0000000000 --- a/docs/_posts/2020-12-08-unusually_long_command_line.md +++ /dev/null @@ -1,159 +0,0 @@ ---- -title: "Unusually Long Command Line" -excerpt: "" -categories: - - Endpoint -last_modified_at: 2020-12-08 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -Command lines that are extremely long may be indicative of malicious activity on your hosts. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-12-08 -- **Author**: David Dorsey, Splunk -- **ID**: c77162d3-f93c-45cc-80c8-22f6a4264e7f - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes by Processes.user Processes.dest Processes.process_name Processes.process -| `drop_dm_object_name("Processes")` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| eval processlen=len(process) -| eventstats stdev(processlen) as stdev, avg(processlen) as avg by dest -| stats max(processlen) as maxlen, values(stdev) as stdevperhost, values(avg) as avgperhost by dest, user, process_name, process -| `unusually_long_command_line_filter` -|eval threshold = 3 -| where maxlen > ((threshold*stdevperhost) + avgperhost) -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **unusually_long_command_line_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.user -* Processes.dest -* Processes.process_name -* Processes.process - - -#### How To Implement -You must be ingesting endpoint data that tracks process activity, including parent-child relationships, from your endpoints to populate the Endpoint data model in the Processes node. The command-line arguments are mapped to the process field in the Endpoint data model. - -#### Known False Positives -Some legitimate applications start with long command lines. - -#### Associated Analytic story -* [Suspicious Command-Line Executions](/stories/suspicious_command-line_executions) -* [Unusual Processes](/stories/unusual_processes) -* [Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns](/stories/possible_backdoor_activity_associated_with_mudcarp_espionage_campaigns) -* [Ransomware](/stories/ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 42.0 | 70 | 60 | Unusually long command line $Processes.process_name$ on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036.003/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036.003/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/endpoint/unusually_long_command_line.yml) \| *version*: **5** \ No newline at end of file diff --git a/docs/_posts/2020-12-08-wmi_permanent_event_subscription_-_sysmon.md b/docs/_posts/2020-12-08-wmi_permanent_event_subscription_-_sysmon.md deleted file mode 100644 index ab0558ca46..0000000000 --- a/docs/_posts/2020-12-08-wmi_permanent_event_subscription_-_sysmon.md +++ /dev/null @@ -1,179 +0,0 @@ ---- -title: "WMI Permanent Event Subscription - Sysmon" -excerpt: "Windows Management Instrumentation Event Subscription -, Event Triggered Execution -" -categories: - - Endpoint -last_modified_at: 2020-12-08 -toc: true -toc_label: "" -tags: - - Windows Management Instrumentation Event Subscription - - Event Triggered Execution - - Persistence - - Privilege Escalation - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for the creation of WMI permanent event subscriptions. The following analytic identifies the use of WMI Event Subscription to establish persistence or perform privilege escalation. WMI can be used to install event filters, providers, consumers, and bindings that execute code when a defined event occurs. WMI subscription execution is proxied by the WMI Provider Host process (WmiPrvSe.exe) and thus may result in elevated SYSTEM privileges. This analytic is restricted by commonly added process execution and a path. If the volume is low enough, remove the values and flag on any new subscriptions.\ -All event subscriptions have three components \ -1. Filter - WQL Query for the events we want. EventID = 19 \ -1. Consumer - An action to take upon triggering the filter. EventID = 20 \ -1. Binding - Registers a filter to a consumer. EventID = 21 \ -Monitor for the creation of new WMI EventFilter, EventConsumer, and FilterToConsumerBinding. It may be pertinent to review all 3 to identify the flow of execution. In addition, EventCode 4104 may assist with any other PowerShell script usage that registered the subscription. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-12-08 -- **Author**: Rico Valdez, Michael Haag, Splunk -- **ID**: ad05aae6-3b2a-4f73-af97-57bd26cee3b9 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1546.003](https://attack.mitre.org/techniques/T1546/003/) | Windows Management Instrumentation Event Subscription | Persistence, Privilege Escalation | - -| [T1546](https://attack.mitre.org/techniques/T1546/) | Event Triggered Execution | Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* PR.AT -* PR.AC -* PR.IP - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventCode=21 -| rename host as dest -| table _time, dest, user, Operation, EventType, Query, Consumer, Filter -| `wmi_permanent_event_subscription___sysmon_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **wmi_permanent_event_subscription_-_sysmon_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* host -* user -* Operation -* EventType -* Query -* Consumer -* Filter - - -#### How To Implement -To successfully implement this search, you must be collecting Sysmon data using Sysmon version 6.1 or greater and have Sysmon configured to generate alerts for WMI activity (eventID= 19, 20, 21). In addition, you must have at least version 6.0.4 of the Sysmon TA installed to properly parse the fields. - -#### Known False Positives -Although unlikely, administrators may use event subscriptions for legitimate purposes. - -#### Associated Analytic story -* [Suspicious WMI Use](/stories/suspicious_wmi_use) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 30.0 | 30 | 100 | User $user$ on $host$ executed the following suspicious WMI query: $Query$. Filter: $filter$. Consumer: $Consumer$. EventCode: $EventCode$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1546.003/T1546.003.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1546.003/T1546.003.md) -* [https://www.eideon.com/2018-03-02-THL03-WMIBackdoors/](https://www.eideon.com/2018-03-02-THL03-WMIBackdoors/) -* [https://github.com/trustedsec/SysmonCommunityGuide/blob/master/chapters/WMI-events.md](https://github.com/trustedsec/SysmonCommunityGuide/blob/master/chapters/WMI-events.md) -* [https://in.security/2019/04/03/an-intro-into-abusing-and-identifying-wmi-event-subscriptions-for-persistence/](https://in.security/2019/04/03/an-intro-into-abusing-and-identifying-wmi-event-subscriptions-for-persistence/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.003/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.003/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2020-12-14-sunburst_correlation_dll_and_network_event.md b/docs/_posts/2020-12-14-sunburst_correlation_dll_and_network_event.md deleted file mode 100644 index 97b7a140ca..0000000000 --- a/docs/_posts/2020-12-14-sunburst_correlation_dll_and_network_event.md +++ /dev/null @@ -1,160 +0,0 @@ ---- -title: "Sunburst Correlation DLL and Network Event" -excerpt: "Exploitation for Client Execution -" -categories: - - Endpoint -last_modified_at: 2020-12-14 -toc: true -toc_label: "" -tags: - - Exploitation for Client Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The malware sunburst will load the malicious dll by SolarWinds.BusinessLayerHost.exe. After a period of 12-14 days, the malware will attempt to resolve a subdomain of avsvmcloud.com. This detections will correlate both events. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-12-14 -- **Author**: Patrick Bareiss, Splunk -- **ID**: 701a8740-e8db-40df-9190-5516d3819787 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1203](https://attack.mitre.org/techniques/T1203/) | Exploitation for Client Execution | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 6 -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -(`sysmon` EventCode=7 ImageLoaded=*SolarWinds.Orion.Core.BusinessLayer.dll) OR (`sysmon` EventCode=22 QueryName=*avsvmcloud.com) -| eventstats dc(EventCode) AS dc_events -| where dc_events=2 -| stats min(_time) as firstTime max(_time) as lastTime values(ImageLoaded) AS ImageLoaded values(QueryName) AS QueryName by host -| rename host as dest -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `sunburst_correlation_dll_and_network_event_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **sunburst_correlation_dll_and_network_event_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* ImageLoaded -* QueryName - - -#### How To Implement -This detection relies on sysmon logs with the Event ID 7, Driver loaded. Please tune your sysmon config that you DriverLoad event for SolarWinds.Orion.Core.BusinessLayer.dll is captured by Sysmon. Additionally, you need sysmon logs for Event ID 22, DNS Query. We suggest to run this detection at least once a day over the last 14 days. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [NOBELIUM Group](/stories/nobelium_group) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.mandiant.com/resources/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor](https://www.mandiant.com/resources/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/endpoint/sunburst_correlation_dll_and_network_event.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-12-15-o365_suspicious_rights_delegation.md b/docs/_posts/2020-12-15-o365_suspicious_rights_delegation.md deleted file mode 100644 index ee30a723f2..0000000000 --- a/docs/_posts/2020-12-15-o365_suspicious_rights_delegation.md +++ /dev/null @@ -1,162 +0,0 @@ ---- -title: "O365 Suspicious Rights Delegation" -excerpt: "Remote Email Collection -, Email Collection -" -categories: - - Cloud -last_modified_at: 2020-12-15 -toc: true -toc_label: "" -tags: - - Remote Email Collection - - Email Collection - - Collection - - Collection - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search detects the assignment of rights to accesss content from another mailbox. This is usually only assigned to a service account. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-12-15 -- **Author**: Patrick Bareiss, Splunk -- **ID**: b25d2973-303e-47c8-bacd-52b61604c6a7 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1114.002](https://attack.mitre.org/techniques/T1114/002/) | Remote Email Collection | Collection | - -| [T1114](https://attack.mitre.org/techniques/T1114/) | Email Collection | Collection | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.DP -* DE.AE - - - -
-
- -
- CIS20 - -
- -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`o365_management_activity` Operation=Add-MailboxPermission -| spath input=Parameters -| rename User AS src_user, Identity AS dest_user -| search AccessRights=FullAccess OR AccessRights=SendAs OR AccessRights=SendOnBehalf -| stats count earliest(_time) as firstTime latest(_time) as lastTime by user src_user dest_user Operation AccessRights -|`security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -|`o365_suspicious_rights_delegation_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [o365_management_activity](https://github.com/splunk/security_content/blob/develop/macros/o365_management_activity.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **o365_suspicious_rights_delegation_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Operation -* Parameters - - -#### How To Implement -You must install splunk Microsoft Office 365 add-on. This search works with o365:management:activity - -#### Known False Positives -Service Accounts - -#### Associated Analytic story -* [Office 365 Detections](/stories/office_365_detections) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 48.0 | 80 | 60 | User $user$ has delegated suspicious rights $AccessRights$ to user $dest_user$ that allow access to sensitive | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1114.002/suspicious_rights_delegation/suspicious_rights_delegation.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1114.002/suspicious_rights_delegation/suspicious_rights_delegation.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/o365_suspicious_rights_delegation.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-12-16-high_number_of_login_failures_from_a_single_source.md b/docs/_posts/2020-12-16-high_number_of_login_failures_from_a_single_source.md deleted file mode 100644 index 8996475b29..0000000000 --- a/docs/_posts/2020-12-16-high_number_of_login_failures_from_a_single_source.md +++ /dev/null @@ -1,164 +0,0 @@ ---- -title: "High Number of Login Failures from a single source" -excerpt: "Password Guessing -, Brute Force -" -categories: - - Cloud -last_modified_at: 2020-12-16 -toc: true -toc_label: "" -tags: - - Password Guessing - - Brute Force - - Credential Access - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search will detect more than 5 login failures in Office365 Azure Active Directory from a single source IP address. Please adjust the threshold value of 5 as suited for your environment. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-12-16 -- **Author**: Bhavin Patel, Splunk -- **ID**: 7f398cfb-918d-41f4-8db8-2e2474e02222 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1110.001](https://attack.mitre.org/techniques/T1110/001/) | Password Guessing | Credential Access | - -| [T1110](https://attack.mitre.org/techniques/T1110/) | Brute Force | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.DP -* DE.AE - - - -
-
- -
- CIS20 - -
- -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`o365_management_activity` Operation=UserLoginFailed record_type=AzureActiveDirectoryStsLogon app=AzureActiveDirectory -| stats count dc(user) as accounts_locked values(user) as user values(LogonError) as LogonError values(authentication_method) as authentication_method values(signature) as signature values(UserAgent) as UserAgent by src_ip record_type Operation app -| search accounts_locked >= 5 -| `high_number_of_login_failures_from_a_single_source_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [o365_management_activity](https://github.com/splunk/security_content/blob/develop/macros/o365_management_activity.yml) - -> :information_source: -> **high_number_of_login_failures_from_a_single_source_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Operation -* record_type -* app -* user -* LogonError -* authentication_method -* signature -* UserAgent -* src_ip -* record_type - - -#### How To Implement - - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Office 365 Detections](/stories/office_365_detections) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/cloud/high_number_of_login_failures_from_a_single_source.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-12-16-o365_pst_export_alert.md b/docs/_posts/2020-12-16-o365_pst_export_alert.md deleted file mode 100644 index 4037093153..0000000000 --- a/docs/_posts/2020-12-16-o365_pst_export_alert.md +++ /dev/null @@ -1,157 +0,0 @@ ---- -title: "O365 PST export alert" -excerpt: "Email Collection -" -categories: - - Cloud -last_modified_at: 2020-12-16 -toc: true -toc_label: "" -tags: - - Email Collection - - Collection - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search detects when a user has performed an Ediscovery search or exported a PST file from the search. This PST file usually has sensitive information including email body content - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-12-16 -- **Author**: Rod Soto, Splunk -- **ID**: 5f694cc4-a678-4a60-9410-bffca1b647dc - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1114](https://attack.mitre.org/techniques/T1114/) | Email Collection | Collection | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`o365_management_activity` Category=ThreatManagement Name="eDiscovery search started or exported" -| stats count earliest(_time) as firstTime latest(_time) as lastTime by Source Severity AlertEntityId Operation Name -|`security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -| `o365_pst_export_alert_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [o365_management_activity](https://github.com/splunk/security_content/blob/develop/macros/o365_management_activity.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **o365_pst_export_alert_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Category -* Name -* Source -* Severity -* AlertEntityId -* Operation - - -#### How To Implement -You must install splunk Microsoft Office 365 add-on. This search works with o365:management:activity - -#### Known False Positives -PST export can be done for legitimate purposes but due to the sensitive nature of its content it must be monitored. - -#### Associated Analytic story -* [Office 365 Detections](/stories/office_365_detections) -* [Data Exfiltration](/stories/data_exfiltration) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 48.0 | 80 | 60 | User $Source$ has exported a PST file from the search using this operation- $Operation$ with a severity of $Severity$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1114/](https://attack.mitre.org/techniques/T1114/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1114/o365_export_pst_file/o365_export_pst_file.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1114/o365_export_pst_file/o365_export_pst_file.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/o365_pst_export_alert.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-12-16-o365_suspicious_admin_email_forwarding.md b/docs/_posts/2020-12-16-o365_suspicious_admin_email_forwarding.md deleted file mode 100644 index 24a14ff406..0000000000 --- a/docs/_posts/2020-12-16-o365_suspicious_admin_email_forwarding.md +++ /dev/null @@ -1,164 +0,0 @@ ---- -title: "O365 Suspicious Admin Email Forwarding" -excerpt: "Email Forwarding Rule -, Email Collection -" -categories: - - Cloud -last_modified_at: 2020-12-16 -toc: true -toc_label: "" -tags: - - Email Forwarding Rule - - Email Collection - - Collection - - Collection - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search detects when an admin configured a forwarding rule for multiple mailboxes to the same destination. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-12-16 -- **Author**: Patrick Bareiss, Splunk -- **ID**: 7f398cfb-918d-41f4-8db8-2e2474e02c28 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1114.003](https://attack.mitre.org/techniques/T1114/003/) | Email Forwarding Rule | Collection | - -| [T1114](https://attack.mitre.org/techniques/T1114/) | Email Collection | Collection | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.DP -* DE.AE - - - -
-
- -
- CIS20 - -
- -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`o365_management_activity` Operation=Set-Mailbox -| spath input=Parameters -| rename Identity AS src_user -| search ForwardingAddress=* -| stats dc(src_user) AS count_src_user earliest(_time) as firstTime latest(_time) as lastTime values(src_user) AS src_user values(user) AS user by ForwardingAddress -| where count_src_user > 1 -|`security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -|`o365_suspicious_admin_email_forwarding_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [o365_management_activity](https://github.com/splunk/security_content/blob/develop/macros/o365_management_activity.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **o365_suspicious_admin_email_forwarding_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Operation -* Parameters - - -#### How To Implement -You must install splunk Microsoft Office 365 add-on. This search works with o365:management:activity - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Office 365 Detections](/stories/office_365_detections) -* [Data Exfiltration](/stories/data_exfiltration) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 48.0 | 80 | 60 | User $user$ has configured a forwarding rule for multiple mailboxes to the same destination $ForwardingAddress$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1114.003/o365_email_forwarding_rule/o365_email_forwarding_rule.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1114.003/o365_email_forwarding_rule/o365_email_forwarding_rule.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-12-16-o365_suspicious_user_email_forwarding.md b/docs/_posts/2020-12-16-o365_suspicious_user_email_forwarding.md deleted file mode 100644 index 46ed9198f8..0000000000 --- a/docs/_posts/2020-12-16-o365_suspicious_user_email_forwarding.md +++ /dev/null @@ -1,164 +0,0 @@ ---- -title: "O365 Suspicious User Email Forwarding" -excerpt: "Email Forwarding Rule -, Email Collection -" -categories: - - Cloud -last_modified_at: 2020-12-16 -toc: true -toc_label: "" -tags: - - Email Forwarding Rule - - Email Collection - - Collection - - Collection - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search detects when multiple user configured a forwarding rule to the same destination. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2020-12-16 -- **Author**: Patrick Bareiss, Splunk -- **ID**: f8dfe015-dbb3-4569-ba75-b13787e06aa4 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1114.003](https://attack.mitre.org/techniques/T1114/003/) | Email Forwarding Rule | Collection | - -| [T1114](https://attack.mitre.org/techniques/T1114/) | Email Collection | Collection | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.DP -* DE.AE - - - -
-
- -
- CIS20 - -
- -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`o365_management_activity` Operation=Set-Mailbox -| spath input=Parameters -| rename Identity AS src_user -| search ForwardingSmtpAddress=* -| stats dc(src_user) AS count_src_user earliest(_time) as firstTime latest(_time) as lastTime values(src_user) AS src_user values(user) AS user by ForwardingSmtpAddress -| where count_src_user > 1 -|`security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -|`o365_suspicious_user_email_forwarding_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [o365_management_activity](https://github.com/splunk/security_content/blob/develop/macros/o365_management_activity.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **o365_suspicious_user_email_forwarding_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Operation -* Parameters - - -#### How To Implement -You must install splunk Microsoft Office 365 add-on. This search works with o365:management:activity - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Office 365 Detections](/stories/office_365_detections) -* [Data Exfiltration](/stories/data_exfiltration) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 48.0 | 80 | 60 | User $user$ configured multiple users $src_user$ with a count of $count_src_user$, a forwarding rule to same destination $ForwardingSmtpAddress$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1114.003/o365_email_forwarding_rule/o365_email_forwarding_rule.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1114.003/o365_email_forwarding_rule/o365_email_forwarding_rule.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-12-21-bcdedit_failure_recovery_modification.md b/docs/_posts/2020-12-21-bcdedit_failure_recovery_modification.md deleted file mode 100644 index 9a0522dffa..0000000000 --- a/docs/_posts/2020-12-21-bcdedit_failure_recovery_modification.md +++ /dev/null @@ -1,162 +0,0 @@ ---- -title: "BCDEdit Failure Recovery Modification" -excerpt: "Inhibit System Recovery -" -categories: - - Endpoint -last_modified_at: 2020-12-21 -toc: true -toc_label: "" -tags: - - Inhibit System Recovery - - Impact - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for flags passed to bcdedit.exe modifications to the built-in Windows error recovery boot configurations. This is typically used by ransomware to prevent recovery. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2020-12-21 -- **Author**: Michael Haag, Splunk -- **ID**: 809b31d2-5462-11eb-ae93-0242ac130002 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1490](https://attack.mitre.org/techniques/T1490/) | Inhibit System Recovery | Impact | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.IP - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = bcdedit.exe Processes.process="*recoveryenabled*" (Processes.process="* no*") by Processes.process_name Processes.process Processes.parent_process_name Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `bcdedit_failure_recovery_modification_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **bcdedit_failure_recovery_modification_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process_name -* Processes.process -* Processes.parent_process_name -* Processes.dest -* Processes.user - - -#### How To Implement -You must be ingesting endpoint data that tracks process activity, including parent-child relationships from your endpoints to populate the Endpoint data model in the Processes node. Tune based on parent process names. - -#### Known False Positives -Administrators may modify the boot configuration. - -#### Associated Analytic story -* [Ryuk Ransomware](/stories/ryuk_ransomware) -* [Ransomware](/stories/ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 100 | 80 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting disable the ability to recover the endpoint. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1490/T1490.md#atomic-test-4---windows---disable-windows-recovery-console-repair](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1490/T1490.md#atomic-test-4---windows---disable-windows-recovery-console-repair) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1490/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1490/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/bcdedit_failure_recovery_modification.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-01-06-supernova_webshell.md b/docs/_posts/2021-01-06-supernova_webshell.md deleted file mode 100644 index 51781a2d96..0000000000 --- a/docs/_posts/2021-01-06-supernova_webshell.md +++ /dev/null @@ -1,164 +0,0 @@ ---- -title: "Supernova Webshell" -excerpt: "Web Shell -" -categories: - - Web -last_modified_at: 2021-01-06 -toc: true -toc_label: "" -tags: - - Web Shell - - Persistence - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Web ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search aims to detect the Supernova webshell used in the SUNBURST attack. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Web](https://docs.splunk.com/Documentation/CIM/latest/User/Web) -- **Last Updated**: 2021-01-06 -- **Author**: John Stoner, Splunk -- **ID**: 2ec08a09-9ff1-4dac-b59f-1efd57972ec1 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1505.003](https://attack.mitre.org/techniques/T1505/003/) | Web Shell | Persistence | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* PR.DS -* ID.RA -* PR.PT -* PR.IP -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 4 -* CIS 13 -* CIS 18 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count from datamodel=Web.Web where web.url=*logoimagehandler.ashx*codes* OR Web.url=*logoimagehandler.ashx*clazz* OR Web.url=*logoimagehandler.ashx*method* OR Web.url=*logoimagehandler.ashx*args* by Web.src Web.dest Web.url Web.vendor_product Web.user Web.http_user_agent _time span=1s -| `supernova_webshell_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **supernova_webshell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Web.url -* Web.src -* Web.dest -* Web.vendor_product -* Web.user -* Web.http_user_agent - - -#### How To Implement -To successfully implement this search, you need to be monitoring web traffic to your Solarwinds Orion. The logs should be ingested into splunk and populating/mapped to the Web data model. - -#### Known False Positives -There might be false positives associted with this detection since items like args as a web argument is pretty generic. - -#### Associated Analytic story -* [NOBELIUM Group](/stories/nobelium_group) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.splunk.com/en_us/blog/security/detecting-supernova-malware-solarwinds-continued.html](https://www.splunk.com/en_us/blog/security/detecting-supernova-malware-solarwinds-continued.html) -* [https://www.guidepointsecurity.com/blog/supernova-solarwinds-net-webshell-analysis/](https://www.guidepointsecurity.com/blog/supernova-solarwinds-net-webshell-analysis/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/web/supernova_webshell.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-01-11-aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.md b/docs/_posts/2021-01-11-aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.md deleted file mode 100644 index a3cca683c2..0000000000 --- a/docs/_posts/2021-01-11-aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.md +++ /dev/null @@ -1,165 +0,0 @@ ---- -title: "AWS Detect Users creating keys with encrypt policy without MFA" -excerpt: "Data Encrypted for Impact -" -categories: - - Cloud -last_modified_at: 2021-01-11 -toc: true -toc_label: "" -tags: - - Data Encrypted for Impact - - Impact - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search provides detection of KMS keys where action kms:Encrypt is accessible for everyone (also outside of your organization). This is an indicator that your account is compromised and the attacker uses the encryption key to compromise another company. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-01-11 -- **Author**: Rod Soto, Patrick Bareiss Splunk -- **ID**: c79c164f-4b21-4847-98f9-cf6a9f49179e - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1486](https://attack.mitre.org/techniques/T1486/) | Data Encrypted for Impact | Impact | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cloudtrail` eventName=CreateKey OR eventName=PutKeyPolicy -| spath input=requestParameters.policy output=key_policy_statements path=Statement{} -| mvexpand key_policy_statements -| spath input=key_policy_statements output=key_policy_action_1 path=Action -| spath input=key_policy_statements output=key_policy_action_2 path=Action{} -| eval key_policy_action=mvappend(key_policy_action_1, key_policy_action_2) -| spath input=key_policy_statements output=key_policy_principal path=Principal.AWS -| search key_policy_action="kms:Encrypt" AND key_policy_principal="*" -| stats count min(_time) as firstTime max(_time) as lastTime by eventName eventSource eventID awsRegion userIdentity.principalId -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -|`aws_detect_users_creating_keys_with_encrypt_policy_without_mfa_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) - -> :information_source: -> **aws_detect_users_creating_keys_with_encrypt_policy_without_mfa_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* eventName -* eventSource -* eventID -* awsRegion -* requestParameters.policy -* userIdentity.principalId - - -#### How To Implement -You must install splunk AWS add on and Splunk App for AWS. This search works with AWS CloudTrail logs - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Ransomware Cloud](/stories/ransomware_cloud) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | AWS account is potentially compromised and user $userIdentity.principalId$ is trying to compromise other accounts. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://rhinosecuritylabs.com/aws/s3-ransomware-part-1-attack-vector/](https://rhinosecuritylabs.com/aws/s3-ransomware-part-1-attack-vector/) -* [https://github.com/d1vious/git-wild-hunt](https://github.com/d1vious/git-wild-hunt) -* [https://www.youtube.com/watch?v=PgzNib37g0M](https://www.youtube.com/watch?v=PgzNib37g0M) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1486/aws_kms_key/aws_cloudtrail_events.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1486/aws_kms_key/aws_cloudtrail_events.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-01-11-aws_detect_users_with_kms_keys_performing_encryption_s3.md b/docs/_posts/2021-01-11-aws_detect_users_with_kms_keys_performing_encryption_s3.md deleted file mode 100644 index c0a423f76c..0000000000 --- a/docs/_posts/2021-01-11-aws_detect_users_with_kms_keys_performing_encryption_s3.md +++ /dev/null @@ -1,160 +0,0 @@ ---- -title: "AWS Detect Users with KMS keys performing encryption S3" -excerpt: "Data Encrypted for Impact -" -categories: - - Cloud -last_modified_at: 2021-01-11 -toc: true -toc_label: "" -tags: - - Data Encrypted for Impact - - Impact - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search provides detection of users with KMS keys performing encryption specifically against S3 buckets. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-01-11 -- **Author**: Rod Soto, Patrick Bareiss Splunk -- **ID**: 884a5f59-eec7-4f4a-948b-dbde18225fdc - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1486](https://attack.mitre.org/techniques/T1486/) | Data Encrypted for Impact | Impact | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cloudtrail` eventName=CopyObject requestParameters.x-amz-server-side-encryption="aws:kms" -| rename requestParameters.bucketName AS bucket_name, requestParameters.x-amz-copy-source AS src_file, requestParameters.key AS dest_file -| stats count min(_time) as firstTime max(_time) as lastTime values(src_file) AS src_file values(dest_file) AS dest_file values(userAgent) AS userAgent values(region) AS region values(src) AS src by user -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -|`aws_detect_users_with_kms_keys_performing_encryption_s3_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) - -> :information_source: -> **aws_detect_users_with_kms_keys_performing_encryption_s3_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* eventName -* requestParameters.x-amz-server-side-encryption -* requestParameters.bucketName -* requestParameters.x-amz-copy-source -* requestParameters.key -* userAgent -* region - - -#### How To Implement -You must install splunk AWS add on and Splunk App for AWS. This search works with AWS CloudTrail logs - -#### Known False Positives -bucket with S3 encryption - -#### Associated Analytic story -* [Ransomware Cloud](/stories/ransomware_cloud) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | User $user$ with KMS keys is performing encryption, against S3 buckets on these files $dest_file$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://rhinosecuritylabs.com/aws/s3-ransomware-part-1-attack-vector/](https://rhinosecuritylabs.com/aws/s3-ransomware-part-1-attack-vector/) -* [https://github.com/d1vious/git-wild-hunt](https://github.com/d1vious/git-wild-hunt) -* [https://www.youtube.com/watch?v=PgzNib37g0M](https://www.youtube.com/watch?v=PgzNib37g0M) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1486/s3_file_encryption/aws_cloudtrail_events.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1486/s3_file_encryption/aws_cloudtrail_events.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-01-11-aws_network_access_control_list_created_with_all_open_ports.md b/docs/_posts/2021-01-11-aws_network_access_control_list_created_with_all_open_ports.md deleted file mode 100644 index 738b9292e8..0000000000 --- a/docs/_posts/2021-01-11-aws_network_access_control_list_created_with_all_open_ports.md +++ /dev/null @@ -1,171 +0,0 @@ ---- -title: "AWS Network Access Control List Created with All Open Ports" -excerpt: "Disable or Modify Cloud Firewall -, Impair Defenses -" -categories: - - Cloud -last_modified_at: 2021-01-11 -toc: true -toc_label: "" -tags: - - Disable or Modify Cloud Firewall - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The search looks for AWS CloudTrail events to detect if any network ACLs were created with all the ports open to a specified CIDR. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-01-11 -- **Author**: Bhavin Patel, Patrick Bareiss, Splunk -- **ID**: ada0f478-84a8-4641-a3f1-d82362d6bd75 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.007](https://attack.mitre.org/techniques/T1562/007/) | Disable or Modify Cloud Firewall | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.DP -* DE.AE - - - -
-
- -
- CIS20 - -
- -* CIS 11 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cloudtrail` eventName=CreateNetworkAclEntry OR eventName=ReplaceNetworkAclEntry requestParameters.ruleAction=allow requestParameters.egress=false requestParameters.aclProtocol=-1 -| append [search `cloudtrail` eventName=CreateNetworkAclEntry OR eventName=ReplaceNetworkAclEntry requestParameters.ruleAction=allow requestParameters.egress=false requestParameters.aclProtocol!=-1 -| eval port_range='requestParameters.portRange.to' - 'requestParameters.portRange.from' -| where port_range>1024] -| fillnull -| stats count min(_time) as firstTime max(_time) as lastTime by userName userIdentity.principalId eventName requestParameters.ruleAction requestParameters.egress requestParameters.aclProtocol requestParameters.portRange.to requestParameters.portRange.from src userAgent requestParameters.cidrBlock -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `aws_network_access_control_list_created_with_all_open_ports_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) - -> :information_source: -> **aws_network_access_control_list_created_with_all_open_ports_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* eventName -* requestParameters.ruleAction -* requestParameters.egress -* requestParameters.aclProtocol -* requestParameters.portRange.to -* requestParameters.portRange.from -* requestParameters.cidrBlock -* userName -* userIdentity.principalId -* userAgent - - -#### How To Implement -You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS, version 4.4.0 or later, and configure your AWS CloudTrail inputs. - -#### Known False Positives -It's possible that an admin has created this ACL with all ports open for some legitimate purpose however, this should be scoped and not allowed in production environment. - -#### Associated Analytic story -* [AWS Network ACL Activity](/stories/aws_network_acl_activity) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 48.0 | 60 | 80 | User $user_arn$ has created network ACLs with all the ports open to a specified CIDR $requestParameters.cidrBlock$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.007/aws_create_acl/aws_cloudtrail_events.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.007/aws_create_acl/aws_cloudtrail_events.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-01-12-aws_network_access_control_list_deleted.md b/docs/_posts/2021-01-12-aws_network_access_control_list_deleted.md deleted file mode 100644 index 338cc3e6db..0000000000 --- a/docs/_posts/2021-01-12-aws_network_access_control_list_deleted.md +++ /dev/null @@ -1,164 +0,0 @@ ---- -title: "AWS Network Access Control List Deleted" -excerpt: "Disable or Modify Cloud Firewall -, Impair Defenses -" -categories: - - Cloud -last_modified_at: 2021-01-12 -toc: true -toc_label: "" -tags: - - Disable or Modify Cloud Firewall - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -Enforcing network-access controls is one of the defensive mechanisms used by cloud administrators to restrict access to a cloud instance. After the attacker has gained control of the AWS console by compromising an admin account, they can delete a network ACL and gain access to the instance from anywhere. This search will query the AWS CloudTrail logs to detect users deleting network ACLs. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-01-12 -- **Author**: Bhavin Patel, Patrick Bareiss, Splunk -- **ID**: ada0f478-84a8-4641-a3f1-d82362d6fd75 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.007](https://attack.mitre.org/techniques/T1562/007/) | Disable or Modify Cloud Firewall | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.DP -* DE.AE - - - -
-
- -
- CIS20 - -
- -* CIS 11 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cloudtrail` eventName=DeleteNetworkAclEntry requestParameters.egress=false -| fillnull -| stats count min(_time) as firstTime max(_time) as lastTime by userName userIdentity.principalId eventName requestParameters.egress src userAgent -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `aws_network_access_control_list_deleted_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) - -> :information_source: -> **aws_network_access_control_list_deleted_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* eventName -* requestParameters.egress -* userName -* userIdentity.principalId -* src -* userAgent - - -#### How To Implement -You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your AWS CloudTrail inputs. - -#### Known False Positives -It's possible that a user has legitimately deleted a network ACL. - -#### Associated Analytic story -* [AWS Network ACL Activity](/stories/aws_network_acl_activity) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 5.0 | 10 | 50 | User $user_arn$ from $src$ has sucessfully deleted network ACLs entry (eventName= $eventName$), such that the instance is accessible from anywhere | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.007/aws_delete_acl/aws_cloudtrail_events.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.007/aws_delete_acl/aws_cloudtrail_events.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/aws_network_access_control_list_deleted.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-01-12-suspicious_microsoft_workflow_compiler_usage.md b/docs/_posts/2021-01-12-suspicious_microsoft_workflow_compiler_usage.md deleted file mode 100644 index a9eda9f12e..0000000000 --- a/docs/_posts/2021-01-12-suspicious_microsoft_workflow_compiler_usage.md +++ /dev/null @@ -1,171 +0,0 @@ ---- -title: "Suspicious microsoft workflow compiler usage" -excerpt: "Trusted Developer Utilities Proxy Execution -" -categories: - - Endpoint -last_modified_at: 2021-01-12 -toc: true -toc_label: "" -tags: - - Trusted Developer Utilities Proxy Execution - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies microsoft.workflow.compiler.exe usage. microsoft.workflow.compiler.exe is natively found in C:\Windows\Microsoft.NET\Framework64\v4.0.30319 and is rarely utilized. When investigating, identify the executed code on disk and review. It is not a commonly used process by many applications. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-01-12 -- **Author**: Michael Haag, Splunk -- **ID**: 9bbc62e8-55d8-11eb-ae93-0242ac130002 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1127](https://attack.mitre.org/techniques/T1127/) | Trusted Developer Utilities Proxy Execution | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_microsoftworkflowcompiler` by Processes.dest Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `suspicious_microsoft_workflow_compiler_usage_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_microsoftworkflowcompiler](https://github.com/splunk/security_content/blob/develop/macros/process_microsoftworkflowcompiler.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **suspicious_microsoft_workflow_compiler_usage_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Although unlikely, limited instances have been identified coming from native Microsoft utilities similar to SCCM. - -#### Associated Analytic story -* [Trusted Developer Utilities Proxy Execution](/stories/trusted_developer_utilities_proxy_execution) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 35.0 | 70 | 50 | Suspicious microsoft.workflow.compiler.exe process ran on $dest$ by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://lolbas-project.github.io/lolbas/Binaries/Msbuild/](https://lolbas-project.github.io/lolbas/Binaries/Msbuild/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218/T1218.md#atomic-test-6---microsoftworkflowcompilerexe-payload-execution](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218/T1218.md#atomic-test-6---microsoftworkflowcompilerexe-payload-execution) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_usage.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-01-12-suspicious_msbuild_path.md b/docs/_posts/2021-01-12-suspicious_msbuild_path.md deleted file mode 100644 index fa4f0bbd18..0000000000 --- a/docs/_posts/2021-01-12-suspicious_msbuild_path.md +++ /dev/null @@ -1,134 +0,0 @@ ---- -title: "Suspicious msbuild path" -excerpt: "Masquerading -, Trusted Developer Utilities Proxy Execution -, Rename System Utilities -, MSBuild -" -categories: - - Endpoint -last_modified_at: 2021-01-12 -toc: true -toc_label: "" -tags: - - Masquerading - - Trusted Developer Utilities Proxy Execution - - Rename System Utilities - - MSBuild - - Defense Evasion - - Defense Evasion - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies msbuild.exe executing from a non-standard path. Msbuild.exe is natively found in C:\Windows\Microsoft.NET\Framework\v4.0.30319 and C:\Windows\Microsoft.NET\Framework64\v4.0.30319. Instances of Visual Studio will run a copy of msbuild.exe. A moved instance of MSBuild is suspicious, however there are instances of build applications that will move or use a copy of MSBuild. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/object-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-01-12 -- **Author**: Michael Haag, Splunk -- **ID**: f5198224-551c-11eb-ae93-0242ac130002 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1036](https://attack.mitre.org/techniques/T1036/) | Masquerading | Defense Evasion | - -| [T1127](https://attack.mitre.org/techniques/T1127/) | Trusted Developer Utilities Proxy Execution | Defense Evasion | - -| [T1036.003](https://attack.mitre.org/techniques/T1036/003/) | Rename System Utilities | Defense Evasion | - -| [T1127.001](https://attack.mitre.org/techniques/T1127/001/) | MSBuild | Defense Evasion | - -#### Search - -``` - -| tstats `security_content_summariesonly` count values(Processes.process_name) as process_name values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_msbuild` AND (Processes.process_path!=c:\\windows\\microsoft.net\\framework*\\v*\\*) by Processes.dest Processes.original_file_name Processes.parent_process Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `suspicious_msbuild_path_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [process_msbuild](https://github.com/splunk/security_content/blob/develop/macros/process_msbuild.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -Note that `suspicious_msbuild_path_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Some legitimate applications may use a moved copy of msbuild.exe, triggering a false positive. Baselining of MSBuild.exe usage is recommended to better understand it's path usage. Visual Studio runs an instance out of a path that will need to be filtered on. - -#### Associated Analytic story -* [Trusted Developer Utilities Proxy Execution MSBuild](/stories/trusted_developer_utilities_proxy_execution_msbuild) -* [Cobalt Strike](/stories/cobalt_strike) -* [Masquerading - Rename System Utilities](/stories/masquerading_-_rename_system_utilities) -* [Living Off The Land](/stories/living_off_the_land) - - -#### Kill Chain Phase -* Exploitation - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | Msbuild.exe ran from an uncommon path on $dest$ execyted by $user$ | - - - - -#### Reference - -* [https://lolbas-project.github.io/lolbas/Binaries/Msbuild/](https://lolbas-project.github.io/lolbas/Binaries/Msbuild/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1127.001/T1127.001.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1127.001/T1127.001.md) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127.001/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127.001/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/suspicious_msbuild_path.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-01-12-suspicious_msbuild_rename.md b/docs/_posts/2021-01-12-suspicious_msbuild_rename.md deleted file mode 100644 index d8e42916be..0000000000 --- a/docs/_posts/2021-01-12-suspicious_msbuild_rename.md +++ /dev/null @@ -1,185 +0,0 @@ ---- -title: "Suspicious MSBuild Rename" -excerpt: "Masquerading -, Trusted Developer Utilities Proxy Execution -, Rename System Utilities -, MSBuild -" -categories: - - Endpoint -last_modified_at: 2021-01-12 -toc: true -toc_label: "" -tags: - - Masquerading - - Trusted Developer Utilities Proxy Execution - - Rename System Utilities - - MSBuild - - Defense Evasion - - Defense Evasion - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies renamed instances of msbuild.exe executing. Msbuild.exe is natively found in C:\Windows\Microsoft.NET\Framework\v4.0.30319 and C:\Windows\Microsoft.NET\Framework64\v4.0.30319. During investigation, identify the code executed and what is executing a renamed instance of MSBuild. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-01-12 -- **Author**: Michael Haag, Splunk -- **ID**: 4006adac-5937-11eb-ae93-0242ac130002 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1036](https://attack.mitre.org/techniques/T1036/) | Masquerading | Defense Evasion | - -| [T1127](https://attack.mitre.org/techniques/T1127/) | Trusted Developer Utilities Proxy Execution | Defense Evasion | - -| [T1036.003](https://attack.mitre.org/techniques/T1036/003/) | Rename System Utilities | Defense Evasion | - -| [T1127.001](https://attack.mitre.org/techniques/T1127/001/) | MSBuild | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_msbuild` by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.original_file_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `suspicious_msbuild_rename_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [process_msbuild](https://github.com/splunk/security_content/blob/develop/macros/process_msbuild.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -Note that **suspicious_msbuild_rename_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Although unlikely, some legitimate applications may use a moved copy of msbuild, triggering a false positive. - -#### Associated Analytic story -* [Trusted Developer Utilities Proxy Execution MSBuild](/stories/trusted_developer_utilities_proxy_execution_msbuild) -* [Cobalt Strike](/stories/cobalt_strike) -* [Masquerading - Rename System Utilities](/stories/masquerading_-_rename_system_utilities) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 63.0 | 70 | 90 | Suspicious renamed msbuild.exe binary ran on $dest$ by $user$ | - - -#### Reference - -* [https://lolbas-project.github.io/lolbas/Binaries/Msbuild/](https://lolbas-project.github.io/lolbas/Binaries/Msbuild/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1127.001/T1127.001.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1127.001/T1127.001.md) -* [https://github.com/infosecn1nja/MaliciousMacroMSBuild/](https://github.com/infosecn1nja/MaliciousMacroMSBuild/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127.001/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127.001/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/suspicious_msbuild_rename.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-01-12-suspicious_msbuild_spawn.md b/docs/_posts/2021-01-12-suspicious_msbuild_spawn.md deleted file mode 100644 index 2981f697b7..0000000000 --- a/docs/_posts/2021-01-12-suspicious_msbuild_spawn.md +++ /dev/null @@ -1,176 +0,0 @@ ---- -title: "Suspicious MSBuild Spawn" -excerpt: "Trusted Developer Utilities Proxy Execution -, MSBuild -" -categories: - - Endpoint -last_modified_at: 2021-01-12 -toc: true -toc_label: "" -tags: - - Trusted Developer Utilities Proxy Execution - - MSBuild - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies wmiprvse.exe spawning msbuild.exe. This behavior is indicative of a COM object being utilized to spawn msbuild from wmiprvse.exe. It is common for MSBuild.exe to be spawned from devenv.exe while using Visual Studio. In this instance, there will be command line arguments and file paths. In a malicious instance, MSBuild.exe will spawn from non-standard processes and have no command line arguments. For example, MSBuild.exe spawning from explorer.exe, powershell.exe is far less common and should be investigated. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-01-12 -- **Author**: Michael Haag, Splunk -- **ID**: a115fba6-5514-11eb-ae93-0242ac130002 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1127](https://attack.mitre.org/techniques/T1127/) | Trusted Developer Utilities Proxy Execution | Defense Evasion | - -| [T1127.001](https://attack.mitre.org/techniques/T1127/001/) | MSBuild | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count values(Processes.process_name) as process_name values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=wmiprvse.exe AND `process_msbuild` by Processes.dest Processes.parent_process Processes.original_file_name Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `suspicious_msbuild_spawn_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_msbuild](https://github.com/splunk/security_content/blob/develop/macros/process_msbuild.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **suspicious_msbuild_spawn_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Although unlikely, some legitimate applications may exhibit this behavior, triggering a false positive. - -#### Associated Analytic story -* [Trusted Developer Utilities Proxy Execution MSBuild](/stories/trusted_developer_utilities_proxy_execution_msbuild) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 42.0 | 70 | 60 | Suspicious msbuild.exe process executed on $dest$ by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://lolbas-project.github.io/lolbas/Binaries/Msbuild/](https://lolbas-project.github.io/lolbas/Binaries/Msbuild/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1127.001/T1127.001.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1127.001/T1127.001.md) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127.001/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127.001/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/suspicious_msbuild_spawn.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-01-12-suspicious_mshta_child_process.md b/docs/_posts/2021-01-12-suspicious_mshta_child_process.md deleted file mode 100644 index f837ac19d1..0000000000 --- a/docs/_posts/2021-01-12-suspicious_mshta_child_process.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: "Suspicious mshta child process" -excerpt: "System Binary Proxy Execution -, Mshta -" -categories: - - Endpoint -last_modified_at: 2021-01-12 -toc: true -toc_label: "" -tags: - - System Binary Proxy Execution - - Mshta - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies child processes spawning from "mshta.exe". The search will return the first time and last time these command-line arguments were used for these executions, as well as the target system, the user, parent process "mshta.exe" and its child process. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-01-12 -- **Author**: Michael Haag, Splunk -- **ID**: 60023bb6-5500-11eb-ae93-0242ac130002 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218](https://attack.mitre.org/techniques/T1218/) | System Binary Proxy Execution | Defense Evasion | - -| [T1218.005](https://attack.mitre.org/techniques/T1218/005/) | Mshta | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count values(Processes.process_name) as process_name values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=mshta.exe AND (Processes.process_name=powershell.exe OR Processes.process_name=colorcpl.exe OR Processes.process_name=msbuild.exe OR Processes.process_name=microsoft.workflow.compiler.exe OR Processes.process_name=searchprotocolhost.exe OR Processes.process_name=scrcons.exe OR Processes.process_name=cscript.exe OR Processes.process_name=wscript.exe OR Processes.process_name=powershell.exe OR Processes.process_name=cmd.exe) by Processes.dest Processes.parent_process Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `suspicious_mshta_child_process_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **suspicious_mshta_child_process_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process_name -* Processes.process -* Processes.parent_process_name -* Processes.dest -* Processes.parent_process -* Processes.user - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -Although unlikely, some legitimate applications may exhibit this behavior, triggering a false positive. - -#### Associated Analytic story -* [Suspicious MSHTA Activity](/stories/suspicious_mshta_activity) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 40.0 | 50 | 80 | suspicious mshta child process detected on host $dest$ by user $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/redcanaryco/AtomicTestHarnesses](https://github.com/redcanaryco/AtomicTestHarnesses) -* [https://redcanary.com/blog/introducing-atomictestharnesses/](https://redcanary.com/blog/introducing-atomictestharnesses/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.005/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.005/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/suspicious_mshta_child_process.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-01-14-detect_hosts_connecting_to_dynamic_domain_providers.md b/docs/_posts/2021-01-14-detect_hosts_connecting_to_dynamic_domain_providers.md deleted file mode 100644 index acb9fc9e9c..0000000000 --- a/docs/_posts/2021-01-14-detect_hosts_connecting_to_dynamic_domain_providers.md +++ /dev/null @@ -1,174 +0,0 @@ ---- -title: "Detect hosts connecting to dynamic domain providers" -excerpt: "Drive-by Compromise -" -categories: - - Network -last_modified_at: 2021-01-14 -toc: true -toc_label: "" -tags: - - Drive-by Compromise - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Network_Resolution ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -Malicious actors often abuse legitimate Dynamic DNS services to host malicious payloads or interactive command and control nodes. Attackers will automate domain resolution changes by routing dynamic domains to countless IP addresses to circumvent firewall blocks, block lists as well as frustrate a network defenders analytic and investigative processes. This search will look for DNS queries made from within your infrastructure to suspicious dynamic domains. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Network_Resolution](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkResolution) -- **Last Updated**: 2021-01-14 -- **Author**: Bhavin Patel, Splunk -- **ID**: a1e761ac-1344-4dbd-88b2-3f34c912d359 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1189](https://attack.mitre.org/techniques/T1189/) | Drive-by Compromise | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Command & Control -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.DS -* PR.PT -* DE.AE -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 -* CIS 12 -* CIS 13 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count values(DNS.answer) as answer min(_time) as firstTime from datamodel=Network_Resolution by DNS.query host -| `drop_dm_object_name("DNS")` -| `security_content_ctime(firstTime)` -| `dynamic_dns_providers` -| `detect_hosts_connecting_to_dynamic_domain_providers_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [dynamic_dns_providers](https://github.com/splunk/security_content/blob/develop/macros/dynamic_dns_providers.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **detect_hosts_connecting_to_dynamic_domain_providers_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* DNS.answer -* DNS.query -* host - - -#### How To Implement -First, you'll need to ingest data from your DNS operations. This can be done by ingesting logs from your server or data, collected passively by Splunk Stream or a similar solution. Specifically, data that contains the domain that is being queried and the IP of the host originating the request must be populating the `Network_Resolution` data model. This search also leverages a lookup file, `dynamic_dns_providers_default.csv`, which contains a non-exhaustive list of Dynamic DNS providers. Please consider updating the local lookup periodically by adding new domains to the list of `dynamic_dns_providers_local.csv`.\ -This search produces fields (query, answer, isDynDNS) that are not yet supported by ES Incident Review and therefore cannot be viewed when a notable event is raised. These fields contribute additional context to the notable event. To see the additional metadata, add the following fields, if not already present, to Incident Review. Event Attributes (Configure > Incident Management > Incident Review Settings > Add New Entry):\\n1. **Label:** DNS Query, **Field:** query\ -1. \ -1. **Label:** DNS Answer, **Field:** answer\ -1. \ -1. **Label:** IsDynamicDNS, **Field:** isDynDNS\ -Detailed documentation on how to create a new field within Incident Review may be found here: `https://docs.splunk.com/Documentation/ES/5.3.0/Admin/Customizenotables#Add_a_field_to_the_notable_event_details` - -#### Known False Positives -Some users and applications may leverage Dynamic DNS to reach out to some domains on the Internet since dynamic DNS by itself is not malicious, however this activity must be verified. - -#### Associated Analytic story -* [Data Protection](/stories/data_protection) -* [Prohibited Traffic Allowed or Protocol Mismatch](/stories/prohibited_traffic_allowed_or_protocol_mismatch) -* [DNS Hijacking](/stories/dns_hijacking) -* [Suspicious DNS Traffic](/stories/suspicious_dns_traffic) -* [Dynamic DNS](/stories/dynamic_dns) -* [Command and Control](/stories/command_and_control) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 56.0 | 70 | 80 | A dns query $query$ from your infra connecting to suspicious domain in host $host$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1189/dyn_dns_site/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1189/dyn_dns_site/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2021-01-19-malicious_powershell_process_-_multiple_suspicious_command-line_arguments.md b/docs/_posts/2021-01-19-malicious_powershell_process_-_multiple_suspicious_command-line_arguments.md deleted file mode 100644 index 6935cf6776..0000000000 --- a/docs/_posts/2021-01-19-malicious_powershell_process_-_multiple_suspicious_command-line_arguments.md +++ /dev/null @@ -1,98 +0,0 @@ ---- -title: "Malicious PowerShell Process - Multiple Suspicious Command-Line Arguments" -excerpt: "PowerShell -" -categories: - - Deprecated -last_modified_at: 2021-01-19 -toc: true -toc_label: "" -tags: - - PowerShell - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for PowerShell processes started with a base64 encoded command-line passed to it, with parameters to modify the execution policy for the process, and those that prevent the display of an interactive prompt to the user. This combination of command-line options is suspicious because it overrides the default PowerShell execution policy, attempts to hide itself from the user, and passes an encoded script to be run on the command-line. Deprecated because almost the same as Malicious PowerShell Process - Encoded Command - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/object-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-01-19 -- **Author**: David Dorsey, Splunk -- **ID**: 2cdb91d2-542c-497f-b252-be495e71f38c - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | - -#### Search - -``` - -| tstats `security_content_summariesonly` count values(Processes.process) as process values(Processes.parent_process) as parent_process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=powershell.exe by Processes.user Processes.process_name Processes.parent_process_name Processes.dest -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| search (process=*-EncodedCommand* OR process=*-enc*) process=*-Exec* -| `malicious_powershell_process___multiple_suspicious_command_line_arguments_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -Note that `malicious_powershell_process_-_multiple_suspicious_command-line_arguments_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. - -#### Known False Positives -Legitimate process can have this combination of command-line options, but it's not common. - -#### Associated Analytic story -* [Malicious PowerShell](/stories/malicious_powershell) - - -#### Kill Chain Phase -* Command & Control -* Actions on Objectives - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - - - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/malicious_powershell_process_-_multiple_suspicious_command-line_arguments.yml) \| *version*: **6** \ No newline at end of file diff --git a/docs/_posts/2021-01-19-malicious_powershell_process_with_obfuscation_techniques.md b/docs/_posts/2021-01-19-malicious_powershell_process_with_obfuscation_techniques.md deleted file mode 100644 index d264511cc0..0000000000 --- a/docs/_posts/2021-01-19-malicious_powershell_process_with_obfuscation_techniques.md +++ /dev/null @@ -1,178 +0,0 @@ ---- -title: "Malicious PowerShell Process With Obfuscation Techniques" -excerpt: "Command and Scripting Interpreter -, PowerShell -" -categories: - - Endpoint -last_modified_at: 2021-01-19 -toc: true -toc_label: "" -tags: - - Command and Scripting Interpreter - - PowerShell - - Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for PowerShell processes launched with arguments that have characters indicative of obfuscation on the command-line. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-01-19 -- **Author**: David Dorsey, Splunk -- **ID**: cde75cf6-3c7a-4dd6-af01-27cdb4511fd4 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -| [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Command & Control -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM -* PR.IP - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 7 -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count values(Processes.process) as process values(Processes.parent_process) as parent_process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_powershell` by Processes.user Processes.process_name Processes.original_file_name Processes.parent_process_name Processes.dest Processes.process -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| eval num_obfuscation = (mvcount(split(process,"`"))-1) + (mvcount(split(process, "^"))-1) + (mvcount(split(process, "'"))-1) -| `malicious_powershell_process_with_obfuscation_techniques_filter` -| search num_obfuscation > 10 -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml) - -> :information_source: -> **malicious_powershell_process_with_obfuscation_techniques_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -These characters might be legitimately on the command-line, but it is not common. - -#### Associated Analytic story -* [Hermetic Wiper](/stories/hermetic_wiper) -* [Malicious PowerShell](/stories/malicious_powershell) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 42.0 | 70 | 60 | Powershell.exe running with potential obfuscated arguments on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/obfuscated_powershell/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/obfuscated_powershell/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml) \| *version*: **5** \ No newline at end of file diff --git a/docs/_posts/2021-01-19-suspicious_powershell_command-line_arguments.md b/docs/_posts/2021-01-19-suspicious_powershell_command-line_arguments.md deleted file mode 100644 index f48bcf3d8c..0000000000 --- a/docs/_posts/2021-01-19-suspicious_powershell_command-line_arguments.md +++ /dev/null @@ -1,157 +0,0 @@ ---- -title: "Suspicious Powershell Command-Line Arguments" -excerpt: "PowerShell -" -categories: - - Deprecated -last_modified_at: 2021-01-19 -toc: true -toc_label: "" -tags: - - PowerShell - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for PowerShell processes started with a base64 encoded command-line passed to it, with parameters to modify the execution policy for the process, and those that prevent the display of an interactive prompt to the user. This combination of command-line options is suspicious because it overrides the default PowerShell execution policy, attempts to hide itself from the user, and passes an encoded script to be run on the command-line. Deprecated because almost the same as Malicious PowerShell Process - Encoded Command - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-01-19 -- **Author**: David Dorsey, Splunk -- **ID**: 2cdb91d2-542c-497f-b252-be495e71f38c - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Command & Control -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM -* PR.IP - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 7 -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count values(Processes.process) as process values(Processes.parent_process) as parent_process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=powershell.exe by Processes.user Processes.process_name Processes.parent_process_name Processes.dest -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| search (process=*-EncodedCommand* OR process=*-enc*) process=*-Exec* -| `suspicious_powershell_command_line_arguments_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **suspicious_powershell_command-line_arguments_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. - -#### Known False Positives -Legitimate process can have this combination of command-line options, but it's not common. - -#### Associated Analytic story -* [Malicious PowerShell](/stories/malicious_powershell) -* [Hermetic Wiper](/stories/hermetic_wiper) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/suspicious_powershell_command_line_arguments.yml) \| *version*: **6** \ No newline at end of file diff --git a/docs/_posts/2021-01-20-detect_rundll32_inline_hta_execution.md b/docs/_posts/2021-01-20-detect_rundll32_inline_hta_execution.md deleted file mode 100644 index 9dd8f0fe7a..0000000000 --- a/docs/_posts/2021-01-20-detect_rundll32_inline_hta_execution.md +++ /dev/null @@ -1,178 +0,0 @@ ---- -title: "Detect Rundll32 Inline HTA Execution" -excerpt: "System Binary Proxy Execution -, Mshta -" -categories: - - Endpoint -last_modified_at: 2021-01-20 -toc: true -toc_label: "" -tags: - - System Binary Proxy Execution - - Mshta - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies "rundll32.exe" execution with inline protocol handlers. "JavaScript", "VBScript", and "About" are the only supported options when invoking HTA content directly on the command-line. This type of behavior is commonly observed with fileless malware or application whitelisting bypass techniques. The search will return the first time and last time these command-line arguments were used for these executions, as well as the target system, the user, process "rundll32.exe" and its parent process. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-01-20 -- **Author**: Michael Haag, Splunk -- **ID**: 91c79f14-5b41-11eb-ae93-0242ac130002 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218](https://attack.mitre.org/techniques/T1218/) | System Binary Proxy Execution | Defense Evasion | - -| [T1218.005](https://attack.mitre.org/techniques/T1218/005/) | Mshta | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count values(Processes.process) as process values(Processes.parent_process) as parent_process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_rundll32` (Processes.process=*vbscript* OR Processes.process=*javascript* OR Processes.process=*about*) by Processes.user Processes.process_name Processes.parent_process_name Processes.original_file_name Processes.dest -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_rundll32_inline_hta_execution_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [process_rundll32](https://github.com/splunk/security_content/blob/develop/macros/process_rundll32.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **detect_rundll32_inline_hta_execution_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Although unlikely, some legitimate applications may exhibit this behavior, triggering a false positive. - -#### Associated Analytic story -* [Suspicious MSHTA Activity](/stories/suspicious_mshta_activity) -* [NOBELIUM Group](/stories/nobelium_group) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 56.0 | 70 | 80 | Suspicious rundll32.exe inline HTA execution on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/redcanaryco/AtomicTestHarnesses](https://github.com/redcanaryco/AtomicTestHarnesses) -* [https://redcanary.com/blog/introducing-atomictestharnesses/](https://redcanary.com/blog/introducing-atomictestharnesses/) -* [https://docs.microsoft.com/en-us/windows/win32/search/-search-3x-wds-extidx-prot-implementing](https://docs.microsoft.com/en-us/windows/win32/search/-search-3x-wds-extidx-prot-implementing) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.005/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.005/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-01-20-suspicious_mshta_spawn.md b/docs/_posts/2021-01-20-suspicious_mshta_spawn.md deleted file mode 100644 index 7c5c6ff72c..0000000000 --- a/docs/_posts/2021-01-20-suspicious_mshta_spawn.md +++ /dev/null @@ -1,177 +0,0 @@ ---- -title: "Suspicious mshta spawn" -excerpt: "System Binary Proxy Execution -, Mshta -" -categories: - - Endpoint -last_modified_at: 2021-01-20 -toc: true -toc_label: "" -tags: - - System Binary Proxy Execution - - Mshta - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies wmiprvse.exe spawning mshta.exe. This behavior is indicative of a DCOM object being utilized to spawn mshta from wmiprvse.exe or svchost.exe. In this instance, adversaries may use LethalHTA that will spawn mshta.exe from svchost.exe. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-01-20 -- **Author**: Michael Haag, Splunk -- **ID**: 4d33a488-5b5f-11eb-ae93-0242ac130002 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218](https://attack.mitre.org/techniques/T1218/) | System Binary Proxy Execution | Defense Evasion | - -| [T1218.005](https://attack.mitre.org/techniques/T1218/005/) | Mshta | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count values(Processes.process_name) as process_name values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.parent_process_name=svchost.exe OR Processes.parent_process_name=wmiprvse.exe) AND `process_mshta` by Processes.dest Processes.parent_process Processes.user Processes.original_file_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `suspicious_mshta_spawn_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_mshta](https://github.com/splunk/security_content/blob/develop/macros/process_mshta.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **suspicious_mshta_spawn_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Although unlikely, some legitimate applications may exhibit this behavior, triggering a false positive. - -#### Associated Analytic story -* [Suspicious MSHTA Activity](/stories/suspicious_mshta_activity) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 42.0 | 70 | 60 | mshta.exe spawned by wmiprvse.exe on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://codewhitesec.blogspot.com/2018/07/lethalhta.html](https://codewhitesec.blogspot.com/2018/07/lethalhta.html) -* [https://github.com/redcanaryco/AtomicTestHarnesses](https://github.com/redcanaryco/AtomicTestHarnesses) -* [https://redcanary.com/blog/introducing-atomictestharnesses/](https://redcanary.com/blog/introducing-atomictestharnesses/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.005/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.005/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/suspicious_mshta_spawn.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-01-22-wbadmin_delete_system_backups.md b/docs/_posts/2021-01-22-wbadmin_delete_system_backups.md deleted file mode 100644 index 1a8acc8dc0..0000000000 --- a/docs/_posts/2021-01-22-wbadmin_delete_system_backups.md +++ /dev/null @@ -1,165 +0,0 @@ ---- -title: "WBAdmin Delete System Backups" -excerpt: "Inhibit System Recovery -" -categories: - - Endpoint -last_modified_at: 2021-01-22 -toc: true -toc_label: "" -tags: - - Inhibit System Recovery - - Impact - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for flags passed to wbadmin.exe (Windows Backup Administrator Tool) that delete backup files. This is typically used by ransomware to prevent recovery. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-01-22 -- **Author**: Michael Haag, Splunk -- **ID**: cd5aed7e-5cea-11eb-ae93-0242ac130002 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1490](https://attack.mitre.org/techniques/T1490/) | Inhibit System Recovery | Impact | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.IP - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=wbadmin.exe Processes.process="*delete*" AND (Processes.process="*catalog*" OR Processes.process="*systemstatebackup*") by Processes.process_name Processes.process Processes.parent_process_name Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `wbadmin_delete_system_backups_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **wbadmin_delete_system_backups_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process_name -* Processes.process -* Processes.parent_process_name -* Processes.dest -* Processes.user - - -#### How To Implement -You must be ingesting endpoint data that tracks process activity, including parent-child relationships from your endpoints to populate the Endpoint data model in the Processes node. Tune based on parent process names. - -#### Known False Positives -Administrators may modify the boot configuration. - -#### Associated Analytic story -* [Ryuk Ransomware](/stories/ryuk_ransomware) -* [Ransomware](/stories/ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | System backups deletion on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1490/T1490.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1490/T1490.md) -* [https://thedfirreport.com/2020/10/08/ryuks-return/](https://thedfirreport.com/2020/10/08/ryuks-return/) -* [https://attack.mitre.org/techniques/T1490/](https://attack.mitre.org/techniques/T1490/) -* [https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/wbadmin](https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/wbadmin) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1490/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1490/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/wbadmin_delete_system_backups.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-01-25-nltest_domain_trust_discovery.md b/docs/_posts/2021-01-25-nltest_domain_trust_discovery.md deleted file mode 100644 index 37096e6cd7..0000000000 --- a/docs/_posts/2021-01-25-nltest_domain_trust_discovery.md +++ /dev/null @@ -1,169 +0,0 @@ ---- -title: "NLTest Domain Trust Discovery" -excerpt: "Domain Trust Discovery -" -categories: - - Endpoint -last_modified_at: 2021-01-25 -toc: true -toc_label: "" -tags: - - Domain Trust Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for the execution of `nltest.exe` with command-line arguments utilized to query for Domain Trust information. Two arguments `/domain trusts`, returns a list of trusted domains, and `/all_trusts`, returns all trusted domains. Red Teams and adversaries alike use NLTest.exe to enumerate the current domain to assist with further understanding where to pivot next. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-01-25 -- **Author**: Michael Haag, Splunk -- **ID**: c3e05466-5f22-11eb-ae93-0242ac130002 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1482](https://attack.mitre.org/techniques/T1482/) | Domain Trust Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name=nltest.exe OR Processes.process_name!=nltest.exe) (Processes.process=*/domain_trusts* OR Processes.process=*/all_trusts*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `nltest_domain_trust_discovery_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -Note that **nltest_domain_trust_discovery_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process_name -* Processes.process -* Processes.dest -* Processes.user -* Processes.parent_process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Administrators may use nltest for troubleshooting purposes, otherwise, rarely used. - -#### Associated Analytic story -* [Ryuk Ransomware](/stories/ryuk_ransomware) -* [Domain Trust Discovery](/stories/domain_trust_discovery) -* [IcedID](/stories/icedid) -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | Domain trust discovery execution on $dest$ | - - -#### Reference - -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1482/T1482.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1482/T1482.md) -* [https://malware.news/t/lets-learn-trickbot-implements-network-collector-module-leveraging-cmd-wmi-ldap/19104](https://malware.news/t/lets-learn-trickbot-implements-network-collector-module-leveraging-cmd-wmi-ldap/19104) -* [https://attack.mitre.org/techniques/T1482/](https://attack.mitre.org/techniques/T1482/) -* [https://www.owasp.org/images/4/4b/Red_Team_Operating_in_a_Modern_Environment.pdf](https://www.owasp.org/images/4/4b/Red_Team_Operating_in_a_Modern_Environment.pdf) -* [https://ss64.com/nt/nltest.html](https://ss64.com/nt/nltest.html) -* [https://redcanary.com/threat-detection-report/techniques/domain-trust-discovery/](https://redcanary.com/threat-detection-report/techniques/domain-trust-discovery/) -* [https://thedfirreport.com/2020/10/08/ryuks-return/](https://thedfirreport.com/2020/10/08/ryuks-return/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1482/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1482/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/nltest_domain_trust_discovery.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-01-26-aws_saml_access_by_provider_user_and_principal.md b/docs/_posts/2021-01-26-aws_saml_access_by_provider_user_and_principal.md deleted file mode 100644 index 10e272bfee..0000000000 --- a/docs/_posts/2021-01-26-aws_saml_access_by_provider_user_and_principal.md +++ /dev/null @@ -1,164 +0,0 @@ ---- -title: "AWS SAML Access by Provider User and Principal" -excerpt: "Valid Accounts -" -categories: - - Cloud -last_modified_at: 2021-01-26 -toc: true -toc_label: "" -tags: - - Valid Accounts - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search provides specific SAML access from specific Service Provider, user and targeted principal at AWS. This search provides specific information to detect abnormal access or potential credential hijack or forgery, specially in federated environments using SAML protocol inside the perimeter or cloud provider. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-01-26 -- **Author**: Rod Soto, Splunk -- **ID**: bbe23980-6019-11eb-ae93-0242ac130002 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cloudtrail` eventName=Assumerolewithsaml -| stats count min(_time) as firstTime max(_time) as lastTime by requestParameters.principalArn requestParameters.roleArn requestParameters.roleSessionName recipientAccountId responseElements.issuer sourceIPAddress userAgent -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -|`aws_saml_access_by_provider_user_and_principal_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) - -> :information_source: -> **aws_saml_access_by_provider_user_and_principal_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* eventName -* requestParameters.principalArn -* requestParameters.roleArn -* requestParameters.roleSessionName -* recipientAccountId -* responseElements.issuer -* sourceIPAddress -* userAgent - - -#### How To Implement -You must install splunk AWS add on and Splunk App for AWS. This search works with AWS CloudTrail logs - -#### Known False Positives -Attacks using a Golden SAML or SAML assertion hijacks or forgeries are very difficult to detect as accessing cloud providers with these assertions looks exactly like normal access, however things such as source IP sourceIPAddress user, and principal targeted at receiving cloud provider along with endpoint credential access and abuse detection searches can provide the necessary context to detect these attacks. - -#### Associated Analytic story -* [Cloud Federated Credential Abuse](/stories/cloud_federated_credential_abuse) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 64.0 | 80 | 80 | From IP address $sourceIPAddress$, user agent $userAgent$ has trigged an event $eventName$ for account ID $recipientAccountId$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.cisa.gov/uscert/ncas/alerts/aa21-008a](https://www.cisa.gov/uscert/ncas/alerts/aa21-008a) -* [https://www.splunk.com/en_us/blog/security/a-golden-saml-journey-solarwinds-continued.html](https://www.splunk.com/en_us/blog/security/a-golden-saml-journey-solarwinds-continued.html) -* [https://www.fireeye.com/content/dam/fireeye-www/blog/pdfs/wp-m-unc2452-2021-000343-01.pdf](https://www.fireeye.com/content/dam/fireeye-www/blog/pdfs/wp-m-unc2452-2021-000343-01.pdf) -* [https://www.cyberark.com/resources/threat-research-blog/golden-saml-newly-discovered-attack-technique-forges-authentication-to-cloud-apps](https://www.cyberark.com/resources/threat-research-blog/golden-saml-newly-discovered-attack-technique-forges-authentication-to-cloud-apps) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/assume_role_with_saml/assume_role_with_saml.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/assume_role_with_saml/assume_role_with_saml.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-01-26-aws_saml_update_identity_provider.md b/docs/_posts/2021-01-26-aws_saml_update_identity_provider.md deleted file mode 100644 index 6f97ccba4f..0000000000 --- a/docs/_posts/2021-01-26-aws_saml_update_identity_provider.md +++ /dev/null @@ -1,163 +0,0 @@ ---- -title: "AWS SAML Update identity provider" -excerpt: "Valid Accounts -" -categories: - - Cloud -last_modified_at: 2021-01-26 -toc: true -toc_label: "" -tags: - - Valid Accounts - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search provides detection of updates to SAML provider in AWS. Updates to SAML provider need to be monitored closely as they may indicate possible perimeter compromise of federated credentials, or backdoor access from another cloud provider set by attacker. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-01-26 -- **Author**: Rod Soto, Splunk -- **ID**: 2f0604c6-6030-11eb-ae93-0242ac130002 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cloudtrail` eventName=UpdateSAMLProvider -| stats count min(_time) as firstTime max(_time) as lastTime by eventType eventName requestParameters.sAMLProviderArn userIdentity.sessionContext.sessionIssuer.arn sourceIPAddress userIdentity.accessKeyId userIdentity.principalId -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -|`aws_saml_update_identity_provider_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) - -> :information_source: -> **aws_saml_update_identity_provider_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* eventName -* eventType -* requestParameters.sAMLProviderArn -* userIdentity.sessionContext.sessionIssuer.arn -* sourceIPAddress -* userIdentity.accessKeyId -* userIdentity.principalId - - -#### How To Implement -You must install splunk AWS add on and Splunk App for AWS. This search works with AWS CloudTrail logs. - -#### Known False Positives -Updating a SAML provider or creating a new one may not necessarily be malicious however it needs to be closely monitored. - -#### Associated Analytic story -* [Cloud Federated Credential Abuse](/stories/cloud_federated_credential_abuse) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 64.0 | 80 | 80 | User $userIdentity.principalId$ from IP address $sourceIPAddress$ has trigged an event $eventName$ to update the SAML provider to $requestParameters.sAMLProviderArn$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.cisa.gov/uscert/ncas/alerts/aa21-008a](https://www.cisa.gov/uscert/ncas/alerts/aa21-008a) -* [https://www.splunk.com/en_us/blog/security/a-golden-saml-journey-solarwinds-continued.html](https://www.splunk.com/en_us/blog/security/a-golden-saml-journey-solarwinds-continued.html) -* [https://www.fireeye.com/content/dam/fireeye-www/blog/pdfs/wp-m-unc2452-2021-000343-01.pdf](https://www.fireeye.com/content/dam/fireeye-www/blog/pdfs/wp-m-unc2452-2021-000343-01.pdf) -* [https://www.cyberark.com/resources/threat-research-blog/golden-saml-newly-discovered-attack-technique-forges-authentication-to-cloud-apps](https://www.cyberark.com/resources/threat-research-blog/golden-saml-newly-discovered-attack-technique-forges-authentication-to-cloud-apps) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/update_saml_provider/update_saml_provider.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/update_saml_provider/update_saml_provider.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/aws_saml_update_identity_provider.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-01-26-certutil_exe_certificate_extraction.md b/docs/_posts/2021-01-26-certutil_exe_certificate_extraction.md deleted file mode 100644 index ec35fb3d93..0000000000 --- a/docs/_posts/2021-01-26-certutil_exe_certificate_extraction.md +++ /dev/null @@ -1,153 +0,0 @@ ---- -title: "Certutil exe certificate extraction" -excerpt: "" -categories: - - Endpoint -last_modified_at: 2021-01-26 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for arguments to certutil.exe indicating the manipulation or extraction of Certificate. This certificate can then be used to sign new authentication tokens specially inside Federated environments such as Windows ADFS. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-01-26 -- **Author**: Rod Soto, Splunk -- **ID**: 337a46be-600f-11eb-ae93-0242ac130002 - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Installation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=certutil.exe Processes.process = "*-exportPFX*" by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `certutil_exe_certificate_extraction_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **certutil_exe_certificate_extraction_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Unless there are specific use cases, manipulating or exporting certificates using certutil is uncommon. Extraction of certificate has been observed during attacks such as Golden SAML and other campaigns targeting Federated services. - -#### Associated Analytic story -* [Windows Persistence Techniques](/stories/windows_persistence_techniques) -* [Cloud Federated Credential Abuse](/stories/cloud_federated_credential_abuse) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 63.0 | 90 | 70 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting export a certificate. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/certutil_exe_certificate_extraction/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/certutil_exe_certificate_extraction/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/certutil_exe_certificate_extraction.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-01-26-detect_spike_in_aws_security_hub_alerts_for_ec2_instance.md b/docs/_posts/2021-01-26-detect_spike_in_aws_security_hub_alerts_for_ec2_instance.md deleted file mode 100644 index 4a121c7f70..0000000000 --- a/docs/_posts/2021-01-26-detect_spike_in_aws_security_hub_alerts_for_ec2_instance.md +++ /dev/null @@ -1,153 +0,0 @@ ---- -title: "Detect Spike in AWS Security Hub Alerts for EC2 Instance" -excerpt: "" -categories: - - Cloud -last_modified_at: 2021-01-26 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for a spike in number of of AWS security Hub alerts for an EC2 instance in 4 hours intervals - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-01-26 -- **Author**: Bhavin Patel, Splunk -- **ID**: 2a9b80d3-6340-4345-b5ad-290bf5d0d222 - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.DP - - - -
-
- -
- CIS20 - -
- -* CIS 13 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`aws_securityhub_finding` "Resources{}.Type"=AWSEC2Instance -| bucket span=4h _time -| stats count AS alerts values(Title) as Title values(Types{}) as Types values(vendor_account) as vendor_account values(vendor_region) as vendor_region values(severity) as severity by _time dest -| eventstats avg(alerts) as total_alerts_avg, stdev(alerts) as total_alerts_stdev -| eval threshold_value = 3 -| eval isOutlier=if(alerts > total_alerts_avg+(total_alerts_stdev * threshold_value), 1, 0) -| search isOutlier=1 -| table _time dest alerts Title Types vendor_account vendor_region severity isOutlier total_alerts_avg -| `detect_spike_in_aws_security_hub_alerts_for_ec2_instance_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [aws_securityhub_finding](https://github.com/splunk/security_content/blob/develop/macros/aws_securityhub_finding.yml) - -> :information_source: -> **detect_spike_in_aws_security_hub_alerts_for_ec2_instance_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Resources{}.Type -* Title -* Types{} -* vendor_account -* vendor_region -* severity -* dest - - -#### How To Implement -You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your Security Hub inputs. The threshold_value should be tuned to your environment and schedule these searches according to the bucket span interval. - -#### Known False Positives -None - -#### Associated Analytic story -* [AWS Security Hub Alerts](/stories/aws_security_hub_alerts) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | Spike in AWS security Hub alerts with title $Title$ for EC2 instance $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/security_hub_ec2_spike/security_hub_ec2_spike.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/security_hub_ec2_spike/security_hub_ec2_spike.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/detect_spike_in_aws_security_hub_alerts_for_ec2_instance.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2021-01-26-detect_spike_in_aws_security_hub_alerts_for_user.md b/docs/_posts/2021-01-26-detect_spike_in_aws_security_hub_alerts_for_user.md deleted file mode 100644 index d93a66ab22..0000000000 --- a/docs/_posts/2021-01-26-detect_spike_in_aws_security_hub_alerts_for_user.md +++ /dev/null @@ -1,150 +0,0 @@ ---- -title: "Detect Spike in AWS Security Hub Alerts for User" -excerpt: "" -categories: - - Cloud -last_modified_at: 2021-01-26 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for a spike in number of of AWS security Hub alerts for an AWS IAM User in 4 hours intervals. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-01-26 -- **Author**: Bhavin Patel, Splunk -- **ID**: 2a9b80d3-6220-4345-b5ad-290bf5d0d222 - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.DP -* DE.AE - - - -
-
- -
- CIS20 - -
- -* CIS 13 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`aws_securityhub_finding` "findings{}.Resources{}.Type"= AwsIamUser -| rename findings{}.Resources{}.Id as user -| bucket span=4h _time -| stats count AS alerts by _time user -| eventstats avg(alerts) as total_launched_avg, stdev(alerts) as total_launched_stdev -| eval threshold_value = 2 -| eval isOutlier=if(alerts > total_launched_avg+(total_launched_stdev * threshold_value), 1, 0) -| search isOutlier=1 -| table _time user alerts -|`detect_spike_in_aws_security_hub_alerts_for_user_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [aws_securityhub_finding](https://github.com/splunk/security_content/blob/develop/macros/aws_securityhub_finding.yml) - -> :information_source: -> **detect_spike_in_aws_security_hub_alerts_for_user_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* findings{}.Resources{}.Type -* indings{}.Resources{}.Id -* user - - -#### How To Implement -You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your Security Hub inputs. The threshold_value should be tuned to your environment and schedule these searches according to the bucket span interval. - -#### Known False Positives -None - -#### Associated Analytic story -* [AWS Security Hub Alerts](/stories/aws_security_hub_alerts) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/cloud/detect_spike_in_aws_security_hub_alerts_for_user.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2021-01-26-o365_add_app_role_assignment_grant_user.md b/docs/_posts/2021-01-26-o365_add_app_role_assignment_grant_user.md deleted file mode 100644 index aa6b09ec66..0000000000 --- a/docs/_posts/2021-01-26-o365_add_app_role_assignment_grant_user.md +++ /dev/null @@ -1,164 +0,0 @@ ---- -title: "O365 Add App Role Assignment Grant User" -excerpt: "Cloud Account -, Create Account -" -categories: - - Cloud -last_modified_at: 2021-01-26 -toc: true -toc_label: "" -tags: - - Cloud Account - - Create Account - - Persistence - - Persistence - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search detects the creation of a new Federation setting by alerting about an specific event related to its creation. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-01-26 -- **Author**: Rod Soto, Splunk -- **ID**: b2c81cc6-6040-11eb-ae93-0242ac130002 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1136.003](https://attack.mitre.org/techniques/T1136/003/) | Cloud Account | Persistence | - -| [T1136](https://attack.mitre.org/techniques/T1136/) | Create Account | Persistence | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`o365_management_activity` Workload=AzureActiveDirectory Operation="Add app role assignment grant to user." -| stats count min(_time) as firstTime max(_time) as lastTime values(Actor{}.ID) as Actor.ID values(Actor{}.Type) as Actor.Type by ActorIpAddress dest ResultStatus -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `o365_add_app_role_assignment_grant_user_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [o365_management_activity](https://github.com/splunk/security_content/blob/develop/macros/o365_management_activity.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **o365_add_app_role_assignment_grant_user_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Workload -* Operation -* Actor{}.ID -* Actor{}.Type -* ActorIpAddress -* dest -* ResultStatus - - -#### How To Implement -You must install splunk Microsoft Office 365 add-on. This search works with o365:management:activity - -#### Known False Positives -The creation of a new Federation is not necessarily malicious, however this events need to be followed closely, as it may indicate federated credential abuse or backdoor via federated identities at a different cloud provider. - -#### Associated Analytic story -* [Office 365 Detections](/stories/office_365_detections) -* [Cloud Federated Credential Abuse](/stories/cloud_federated_credential_abuse) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 18.0 | 30 | 60 | User $Actor.ID$ has created a new federation setting on $dest$ from IP Address $ActorIpAddress$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.fireeye.com/content/dam/fireeye-www/blog/pdfs/wp-m-unc2452-2021-000343-01.pdf](https://www.fireeye.com/content/dam/fireeye-www/blog/pdfs/wp-m-unc2452-2021-000343-01.pdf) -* [https://www.cisa.gov/uscert/ncas/alerts/aa21-008a](https://www.cisa.gov/uscert/ncas/alerts/aa21-008a) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.003/o365_new_federation/o365_new_federation.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.003/o365_new_federation/o365_new_federation.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/o365_add_app_role_assignment_grant_user.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-01-26-o365_excessive_sso_logon_errors.md b/docs/_posts/2021-01-26-o365_excessive_sso_logon_errors.md deleted file mode 100644 index d5a0cd0982..0000000000 --- a/docs/_posts/2021-01-26-o365_excessive_sso_logon_errors.md +++ /dev/null @@ -1,159 +0,0 @@ ---- -title: "O365 Excessive SSO logon errors" -excerpt: "Modify Authentication Process -" -categories: - - Cloud -last_modified_at: 2021-01-26 -toc: true -toc_label: "" -tags: - - Modify Authentication Process - - Credential Access - - Defense Evasion - - Persistence - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search detects accounts with high number of Single Sign ON (SSO) logon errors. Excessive logon errors may indicate attempts to bruteforce of password or single sign on token hijack or reuse. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-01-26 -- **Author**: Rod Soto, Splunk -- **ID**: 8158ccc4-6038-11eb-ae93-0242ac130002 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1556](https://attack.mitre.org/techniques/T1556/) | Modify Authentication Process | Credential Access, Defense Evasion, Persistence | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`o365_management_activity` Workload=AzureActiveDirectory LogonError=SsoArtifactInvalidOrExpired -| stats count min(_time) as firstTime max(_time) as lastTime by LogonError ActorIpAddress UserAgent UserId -| where count > 5 -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `o365_excessive_sso_logon_errors_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [o365_management_activity](https://github.com/splunk/security_content/blob/develop/macros/o365_management_activity.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **o365_excessive_sso_logon_errors_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Workload -* LogonError -* ActorIpAddress -* UserAgent -* UserId - - -#### How To Implement -You must install splunk Microsoft Office 365 add-on. This search works with o365:management:activity - -#### Known False Positives -Logon errors may not be malicious in nature however it may indicate attempts to reuse a token or password obtained via credential access attack. - -#### Associated Analytic story -* [Office 365 Detections](/stories/office_365_detections) -* [Cloud Federated Credential Abuse](/stories/cloud_federated_credential_abuse) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 64.0 | 80 | 80 | User $UserId$ has caused excessive number of SSO logon errors from $ActorIpAddress$ using UserAgent $UserAgent$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://stealthbits.com/blog/bypassing-mfa-with-pass-the-cookie/](https://stealthbits.com/blog/bypassing-mfa-with-pass-the-cookie/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1556/o365_sso_logon_errors/o365_sso_logon_errors.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1556/o365_sso_logon_errors/o365_sso_logon_errors.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/o365_excessive_sso_logon_errors.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-01-26-o365_new_federated_domain_added.md b/docs/_posts/2021-01-26-o365_new_federated_domain_added.md deleted file mode 100644 index 2fb2c1f106..0000000000 --- a/docs/_posts/2021-01-26-o365_new_federated_domain_added.md +++ /dev/null @@ -1,168 +0,0 @@ ---- -title: "O365 New Federated Domain Added" -excerpt: "Cloud Account -, Create Account -" -categories: - - Cloud -last_modified_at: 2021-01-26 -toc: true -toc_label: "" -tags: - - Cloud Account - - Create Account - - Persistence - - Persistence - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search detects the addition of a new Federated domain. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-01-26 -- **Author**: Rod Soto, Splunk -- **ID**: e155876a-6048-11eb-ae93-0242ac130002 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1136.003](https://attack.mitre.org/techniques/T1136/003/) | Cloud Account | Persistence | - -| [T1136](https://attack.mitre.org/techniques/T1136/) | Create Account | Persistence | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`o365_management_activity` Workload=Exchange Operation="Add-FederatedDomain" -| stats count min(_time) as firstTime max(_time) as lastTime values(Parameters{}.Value) as Parameters.Value by ObjectId Operation OrganizationName OriginatingServer UserId UserKey -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `o365_new_federated_domain_added_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [o365_management_activity](https://github.com/splunk/security_content/blob/develop/macros/o365_management_activity.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **o365_new_federated_domain_added_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Workload -* Operation -* Parameters{}.Value -* ObjectId -* OrganizationName -* OriginatingServer -* UserId -* UserKey - - -#### How To Implement -You must install splunk Microsoft Office 365 add-on. This search works with o365:management:activity. - -#### Known False Positives -The creation of a new Federated domain is not necessarily malicious, however these events need to be followed closely, as it may indicate federated credential abuse or backdoor via federated identities at a similar or different cloud provider. - -#### Associated Analytic story -* [Office 365 Detections](/stories/office_365_detections) -* [Cloud Federated Credential Abuse](/stories/cloud_federated_credential_abuse) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 64.0 | 80 | 80 | User $UserId$ has added a new federated domaain $Parameters.Value$ for $OrganizationName$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.fireeye.com/content/dam/fireeye-www/blog/pdfs/wp-m-unc2452-2021-000343-01.pdf](https://www.fireeye.com/content/dam/fireeye-www/blog/pdfs/wp-m-unc2452-2021-000343-01.pdf) -* [https://www.cisa.gov/uscert/ncas/alerts/aa21-008a](https://www.cisa.gov/uscert/ncas/alerts/aa21-008a) -* [https://www.splunk.com/en_us/blog/security/a-golden-saml-journey-solarwinds-continued.html](https://www.splunk.com/en_us/blog/security/a-golden-saml-journey-solarwinds-continued.html) -* [https://blog.sygnia.co/detection-and-hunting-of-golden-saml-attack?hsLang=en](https://blog.sygnia.co/detection-and-hunting-of-golden-saml-attack?hsLang=en) -* [https://o365blog.com/post/aadbackdoor/](https://o365blog.com/post/aadbackdoor/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.003/o365_new_federated_domain/o365_new_federated_domain.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.003/o365_new_federated_domain/o365_new_federated_domain.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/o365_new_federated_domain_added.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-01-26-revil_registry_entry.md b/docs/_posts/2021-01-26-revil_registry_entry.md deleted file mode 100644 index 443d184024..0000000000 --- a/docs/_posts/2021-01-26-revil_registry_entry.md +++ /dev/null @@ -1,164 +0,0 @@ ---- -title: "Revil Registry Entry" -excerpt: "Modify Registry -" -categories: - - Endpoint -last_modified_at: 2021-01-26 -toc: true -toc_label: "" -tags: - - Modify Registry - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic identifies suspicious modification in registry entry to keep some malware data during its infection. This technique seen in several apt implant, malware and ransomware like REVIL where it keep some information like the random generated file extension it uses for all the encrypted files and ransomware notes file name in the compromised host. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-01-26 -- **Author**: Teoderick Contreras, Splunk -- **ID**: e3d3f57a-c381-11eb-9e35-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1112](https://attack.mitre.org/techniques/T1112/) | Modify Registry | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry where (Registry.registry_path="*\\SOFTWARE\\WOW6432Node\\Facebook_Assistant\\*" OR Registry.registry_path="*\\SOFTWARE\\WOW6432Node\\BlackLivesMatter*") by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid -| `drop_dm_object_name(Registry)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] -| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data -| `revil_registry_entry_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **revil_registry_entry_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.dest -* Registry.user -* Registry.registry_value_name -* Registry.registry_path -* Registry.registry_key_name - - -#### How To Implement -to successfully implement this search, you need to be ingesting logs with the Image, TargetObject registry key, registry Details from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Ransomware](/stories/ransomware) -* [Revil Ransomware](/stories/revil_ransomware) -* [Windows Registry Abuse](/stories/windows_registry_abuse) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 60.0 | 60 | 100 | A registry entry $registry_path$ with registry value $registry_value_name$ and $registry_value_name$ related to revil ransomware in host $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://krebsonsecurity.com/2021/05/a-closer-look-at-the-darkside-ransomware-gang/](https://krebsonsecurity.com/2021/05/a-closer-look-at-the-darkside-ransomware-gang/) -* [https://www.mcafee.com/blogs/other-blogs/mcafee-labs/mcafee-atr-analyzes-sodinokibi-aka-revil-ransomware-as-a-service-what-the-code-tells-us/](https://www.mcafee.com/blogs/other-blogs/mcafee-labs/mcafee-atr-analyzes-sodinokibi-aka-revil-ransomware-as-a-service-what-the-code-tells-us/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/revil/inf1/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/revil/inf1/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/revil_registry_entry.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-01-27-detect_baron_samedit_cve-2021-3156.md b/docs/_posts/2021-01-27-detect_baron_samedit_cve-2021-3156.md deleted file mode 100644 index a8d7b373eb..0000000000 --- a/docs/_posts/2021-01-27-detect_baron_samedit_cve-2021-3156.md +++ /dev/null @@ -1,154 +0,0 @@ ---- -title: "Detect Baron Samedit CVE-2021-3156" -excerpt: "Exploitation for Privilege Escalation -" -categories: - - Endpoint -last_modified_at: 2021-01-27 -toc: true -toc_label: "" -tags: - - Exploitation for Privilege Escalation - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2021-3156 ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search detects the heap-based buffer overflow of sudoedit - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-01-27 -- **Author**: Shannon Davis, Splunk -- **ID**: 93fbec4e-0375-440c-8db3-4508eca470c4 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1068](https://attack.mitre.org/techniques/T1068/) | Exploitation for Privilege Escalation | Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 -* CIS 12 -* CIS 16 - - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2021-3156](https://nvd.nist.gov/vuln/detail/CVE-2021-3156) | Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character. | 7.2 | - - - -
-
- -#### Search - -``` -`linux_hosts` -| search "sudoedit -s \\" -| `detect_baron_samedit_cve_2021_3156_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [linux_hosts](https://github.com/splunk/security_content/blob/develop/macros/linux_hosts.yml) - -> :information_source: -> **detect_baron_samedit_cve-2021-3156_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -Splunk Universal Forwarder running on Linux systems, capturing logs from the /var/log directory. The vulnerability is exposed when a non privledged user tries passing in a single \ character at the end of the command while using the shell and edit flags. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Baron Samedit CVE-2021-3156](/stories/baron_samedit_cve-2021-3156) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/endpoint/detect_baron_samedit_cve_2021_3156.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-01-28-detect_baron_samedit_cve-2021-3156_via_osquery.md b/docs/_posts/2021-01-28-detect_baron_samedit_cve-2021-3156_via_osquery.md deleted file mode 100644 index 7ec2bb2591..0000000000 --- a/docs/_posts/2021-01-28-detect_baron_samedit_cve-2021-3156_via_osquery.md +++ /dev/null @@ -1,155 +0,0 @@ ---- -title: "Detect Baron Samedit CVE-2021-3156 via OSQuery" -excerpt: "Exploitation for Privilege Escalation -" -categories: - - Endpoint -last_modified_at: 2021-01-28 -toc: true -toc_label: "" -tags: - - Exploitation for Privilege Escalation - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2021-3156 ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search detects the heap-based buffer overflow of sudoedit - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-01-28 -- **Author**: Shannon Davis, Splunk -- **ID**: 1de31d5d-8fa6-4ee0-af89-17069134118a - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1068](https://attack.mitre.org/techniques/T1068/) | Exploitation for Privilege Escalation | Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 -* CIS 12 -* CIS 16 - - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2021-3156](https://nvd.nist.gov/vuln/detail/CVE-2021-3156) | Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character. | 7.2 | - - - -
-
- -#### Search - -``` -`osquery_process` -| search "columns.cmdline"="sudoedit -s \\*" -| `detect_baron_samedit_cve_2021_3156_via_osquery_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [osquery_process](https://github.com/splunk/security_content/blob/develop/macros/osquery_process.yml) - -> :information_source: -> **detect_baron_samedit_cve-2021-3156_via_osquery_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* columns.cmdline - - -#### How To Implement -OSQuery installed and configured to pick up process events (info at https://osquery.io) as well as using the Splunk OSQuery Add-on https://splunkbase.splunk.com/app/4402. The vulnerability is exposed when a non privledged user tries passing in a single \ character at the end of the command while using the shell and edit flags. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Baron Samedit CVE-2021-3156](/stories/baron_samedit_cve-2021-3156) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/endpoint/detect_baron_samedit_cve_2021_3156_via_osquery.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-01-28-detect_regsvr32_application_control_bypass.md b/docs/_posts/2021-01-28-detect_regsvr32_application_control_bypass.md deleted file mode 100644 index 6c37af2788..0000000000 --- a/docs/_posts/2021-01-28-detect_regsvr32_application_control_bypass.md +++ /dev/null @@ -1,180 +0,0 @@ ---- -title: "Detect Regsvr32 Application Control Bypass" -excerpt: "System Binary Proxy Execution -, Regsvr32 -" -categories: - - Endpoint -last_modified_at: 2021-01-28 -toc: true -toc_label: "" -tags: - - System Binary Proxy Execution - - Regsvr32 - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -Adversaries may abuse Regsvr32.exe to proxy execution of malicious code. Regsvr32.exe is a command-line program used to register and unregister object linking and embedding controls, including dynamic link libraries (DLLs), on Windows systems. Regsvr32.exe is also a Microsoft signed binary.This variation of the technique is often referred to as a "Squiblydoo" attack. \ -Upon investigating, look for network connections to remote destinations (internal or external). Be cautious to modify the query to look for "scrobj.dll", the ".dll" is not required to load scrobj. "scrobj.dll" will be loaded by "regsvr32.exe" upon execution. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-01-28 -- **Author**: Michael Haag, Splunk -- **ID**: 070e9b80-6252-11eb-ae93-0242ac130002 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218](https://attack.mitre.org/techniques/T1218/) | System Binary Proxy Execution | Defense Evasion | - -| [T1218.010](https://attack.mitre.org/techniques/T1218/010/) | Regsvr32 | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_regsvr32` Processes.process=*scrobj* by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.original_file_name Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_regsvr32_application_control_bypass_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [process_regsvr32](https://github.com/splunk/security_content/blob/develop/macros/process_regsvr32.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **detect_regsvr32_application_control_bypass_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Limited false positives related to third party software registering .DLL's. - -#### Associated Analytic story -* [Suspicious Regsvr32 Activity](/stories/suspicious_regsvr32_activity) -* [Cobalt Strike](/stories/cobalt_strike) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ in an attempt to bypass detection and preventative controls was identified on endpoint $dest$ by user $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1218/010/](https://attack.mitre.org/techniques/T1218/010/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.010/T1218.010.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.010/T1218.010.md) -* [https://lolbas-project.github.io/lolbas/Binaries/Regsvr32/](https://lolbas-project.github.io/lolbas/Binaries/Regsvr32/) -* [https://support.microsoft.com/en-us/topic/how-to-use-the-regsvr32-tool-and-troubleshoot-regsvr32-error-messages-a98d960a-7392-e6fe-d90a-3f4e0cb543e5](https://support.microsoft.com/en-us/topic/how-to-use-the-regsvr32-tool-and-troubleshoot-regsvr32-error-messages-a98d960a-7392-e6fe-d90a-3f4e0cb543e5) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.010/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.010/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-01-28-ntdsutil_export_ntds.md b/docs/_posts/2021-01-28-ntdsutil_export_ntds.md deleted file mode 100644 index c02bb291a8..0000000000 --- a/docs/_posts/2021-01-28-ntdsutil_export_ntds.md +++ /dev/null @@ -1,176 +0,0 @@ ---- -title: "Ntdsutil Export NTDS" -excerpt: "NTDS -, OS Credential Dumping -" -categories: - - Endpoint -last_modified_at: 2021-01-28 -toc: true -toc_label: "" -tags: - - NTDS - - OS Credential Dumping - - Credential Access - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -Monitor for signs that Ntdsutil is being used to Extract Active Directory database - NTDS.dit, typically used for offline password cracking. It may be used in normal circumstances with no command line arguments or shorthand variations of more common arguments. Ntdsutil.exe is typically seen run on a Windows Server. Typical command used to dump ntds.dit \ -ntdsutil "ac i ntds" "ifm" "create full C:\Temp" q q \ -This technique uses "Install from Media" (IFM), which will extract a copy of the Active Directory database. A successful export of the Active Directory database will yield a file modification named ntds.dit to the destination. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-01-28 -- **Author**: Michael Haag, Patrick Bareiss, Splunk -- **ID**: da63bc76-61ae-11eb-ae93-0242ac130002 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1003.003](https://attack.mitre.org/techniques/T1003/003/) | NTDS | Credential Access | - -| [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name=ntdsutil.exe Processes.process=*ntds* Processes.process=*create*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `ntdsutil_export_ntds_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **ntdsutil_export_ntds_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process_name -* Processes.process -* Processes.dest -* Processes.user -* Processes.parent_process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -You must be ingesting endpoint data that tracks process activity, including parent-child relationships from your endpoints, to populate the Endpoint data model in the Processes node. The command-line arguments are mapped to the "process" field in the Endpoint data model. - -#### Known False Positives -Highly possible Server Administrators will troubleshoot with ntdsutil.exe, generating false positives. - -#### Associated Analytic story -* [Credential Dumping](/stories/credential_dumping) -* [HAFNIUM Group](/stories/hafnium_group) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 50.0 | 100 | 50 | Active Directory NTDS export on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1003.003/T1003.003.md#atomic-test-3---dump-active-directory-database-with-ntdsutil](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1003.003/T1003.003.md#atomic-test-3---dump-active-directory-database-with-ntdsutil) -* [https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-R2-and-2012/cc753343(v=ws.11)](https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-R2-and-2012/cc753343(v=ws.11)) -* [https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf](https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf) -* [https://strontic.github.io/xcyclopedia/library/vss_ps.dll-97B15BDAE9777F454C9A6BA25E938DB3.html](https://strontic.github.io/xcyclopedia/library/vss_ps.dll-97B15BDAE9777F454C9A6BA25E938DB3.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.003/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.003/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/ntdsutil_export_ntds.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-01-28-suspicious_regsvr32_register_suspicious_path.md b/docs/_posts/2021-01-28-suspicious_regsvr32_register_suspicious_path.md deleted file mode 100644 index f9cf1a3efd..0000000000 --- a/docs/_posts/2021-01-28-suspicious_regsvr32_register_suspicious_path.md +++ /dev/null @@ -1,180 +0,0 @@ ---- -title: "Suspicious Regsvr32 Register Suspicious Path" -excerpt: "System Binary Proxy Execution -, Regsvr32 -" -categories: - - Endpoint -last_modified_at: 2021-01-28 -toc: true -toc_label: "" -tags: - - System Binary Proxy Execution - - Regsvr32 - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -Adversaries may abuse Regsvr32.exe to proxy execution of malicious code by using non-standard file extensions to load malciious DLLs. Upon investigating, look for network connections to remote destinations (internal or external). Review additional parrallel processes and child processes for additional activity. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-01-28 -- **Author**: Michael Haag, Splunk -- **ID**: 62732736-6250-11eb-ae93-0242ac130002 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218](https://attack.mitre.org/techniques/T1218/) | System Binary Proxy Execution | Defense Evasion | - -| [T1218.010](https://attack.mitre.org/techniques/T1218/010/) | Regsvr32 | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_regsvr32` (Processes.process=*appdata* OR Processes.process=*programdata* OR Processes.process=*windows\temp*) (Processes.process!=*.dll Processes.process!=*.ax Processes.process!=*.ocx) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.original_file_name Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `suspicious_regsvr32_register_suspicious_path_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [process_regsvr32](https://github.com/splunk/security_content/blob/develop/macros/process_regsvr32.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **suspicious_regsvr32_register_suspicious_path_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -You must be ingesting endpoint data that tracks process activity, including parent-child relationships from your endpoints, to populate the Endpoint data model in the Processes node. The command-line arguments are mapped to the "process" field in the Endpoint data model. Tune the query by filtering additional extensions found to be used by legitimate processes. To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Limited false positives with the query restricted to specified paths. Add more world writeable paths as tuning continues. - -#### Associated Analytic story -* [Suspicious Regsvr32 Activity](/stories/suspicious_regsvr32_activity) -* [Iceid](/stories/iceid) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 35.0 | 70 | 50 | Suspicious $Processes.process_path.file_path$ process potentially loading malicious code | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1218/010/](https://attack.mitre.org/techniques/T1218/010/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.010/T1218.010.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.010/T1218.010.md) -* [https://lolbas-project.github.io/lolbas/Binaries/Regsvr32/](https://lolbas-project.github.io/lolbas/Binaries/Regsvr32/) -* [https://support.microsoft.com/en-us/topic/how-to-use-the-regsvr32-tool-and-troubleshoot-regsvr32-error-messages-a98d960a-7392-e6fe-d90a-3f4e0cb543e5](https://support.microsoft.com/en-us/topic/how-to-use-the-regsvr32-tool-and-troubleshoot-regsvr32-error-messages-a98d960a-7392-e6fe-d90a-3f4e0cb543e5) -* [https://any.run/report/f29a7d2ecd3585e1e4208e44bcc7156ab5388725f1d29d03e7699da0d4598e7c/0826458b-5367-45cf-b841-c95a33a01718](https://any.run/report/f29a7d2ecd3585e1e4208e44bcc7156ab5388725f1d29d03e7699da0d4598e7c/0826458b-5367-45cf-b841-c95a33a01718) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.010/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.010/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-01-29-detect_baron_samedit_cve-2021-3156_segfault.md b/docs/_posts/2021-01-29-detect_baron_samedit_cve-2021-3156_segfault.md deleted file mode 100644 index 156896e442..0000000000 --- a/docs/_posts/2021-01-29-detect_baron_samedit_cve-2021-3156_segfault.md +++ /dev/null @@ -1,157 +0,0 @@ ---- -title: "Detect Baron Samedit CVE-2021-3156 Segfault" -excerpt: "Exploitation for Privilege Escalation -" -categories: - - Endpoint -last_modified_at: 2021-01-29 -toc: true -toc_label: "" -tags: - - Exploitation for Privilege Escalation - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2021-3156 ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search detects the heap-based buffer overflow of sudoedit - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-01-29 -- **Author**: Shannon Davis, Splunk -- **ID**: 10f2bae0-bbe6-4984-808c-37dc1c67980d - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1068](https://attack.mitre.org/techniques/T1068/) | Exploitation for Privilege Escalation | Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 -* CIS 12 -* CIS 16 - - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2021-3156](https://nvd.nist.gov/vuln/detail/CVE-2021-3156) | Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character. | 7.2 | - - - -
-
- -#### Search - -``` -`linux_hosts` -| search sudoedit segfault -| stats count min(_time) as firstTime max(_time) as lastTime by host -| search count > 5 -| `detect_baron_samedit_cve_2021_3156_segfault_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [linux_hosts](https://github.com/splunk/security_content/blob/develop/macros/linux_hosts.yml) - -> :information_source: -> **detect_baron_samedit_cve-2021-3156_segfault_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* host - - -#### How To Implement -Splunk Universal Forwarder running on Linux systems (tested on Centos and Ubuntu), where segfaults are being logged. This also captures instances where the exploit has been compiled into a binary. The detection looks for greater than 5 instances of sudoedit combined with segfault over your search time period on a single host - -#### Known False Positives -If sudoedit is throwing segfaults for other reasons this will pick those up too. - -#### Associated Analytic story -* [Baron Samedit CVE-2021-3156](/stories/baron_samedit_cve-2021-3156) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/endpoint/detect_baron_samedit_cve_2021_3156_segfault.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-02-01-dump_lsass_via_procdump_rename.md b/docs/_posts/2021-02-01-dump_lsass_via_procdump_rename.md deleted file mode 100644 index f790f144d3..0000000000 --- a/docs/_posts/2021-02-01-dump_lsass_via_procdump_rename.md +++ /dev/null @@ -1,167 +0,0 @@ ---- -title: "Dump LSASS via procdump Rename" -excerpt: "LSASS Memory -" -categories: - - Deprecated -last_modified_at: 2021-02-01 -toc: true -toc_label: "" -tags: - - LSASS Memory - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -Detect a renamed instance of procdump.exe dumping the lsass process. This query looks for both -mm and -ma usage. -mm will produce a mini dump file and -ma will write a dump file with all process memory. Both are highly suspect and should be reviewed. Modify the query as needed.\ -During triage, confirm this is procdump.exe executing. If it is the first time a Sysinternals utility has been ran, it is possible there will be a -accepteula on the command line. Review other endpoint data sources for cross process (injection) into lsass.exe. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-02-01 -- **Author**: Michael Haag, Splunk -- **ID**: 21276daa-663d-11eb-ae93-0242ac130002 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1003.001](https://attack.mitre.org/techniques/T1003/001/) | LSASS Memory | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` OriginalFileName=procdump process_name!=procdump*.exe EventID=1 (CommandLine=*-ma* OR CommandLine=*-mm*) CommandLine=*lsass* -| rename Computer as dest -| stats count min(_time) as firstTime max(_time) as lastTime by dest, parent_process_name, process_name, OriginalFileName, CommandLine -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `dump_lsass_via_procdump_rename_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **dump_lsass_via_procdump_rename_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* OriginalFileName -* process_name -* EventID -* CommandLine -* Computer -* parent_process_name - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -None identified. - -#### Associated Analytic story -* [Credential Dumping](/stories/credential_dumping) -* [HAFNIUM Group](/stories/hafnium_group) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | The following $process_name$ has been identified as renamed, spawning from $parent_process_name$ on $dest$, attempting to dump lsass.exe. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1003/001/](https://attack.mitre.org/techniques/T1003/001/) -* [https://docs.microsoft.com/en-us/sysinternals/downloads/procdump](https://docs.microsoft.com/en-us/sysinternals/downloads/procdump) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1003.001/T1003.001.md#atomic-test-2---dump-lsassexe-memory-using-procdump](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1003.001/T1003.001.md#atomic-test-2---dump-lsassexe-memory-using-procdump) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.001/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.001/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_advpack.md b/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_advpack.md deleted file mode 100644 index 4009f62681..0000000000 --- a/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_advpack.md +++ /dev/null @@ -1,179 +0,0 @@ ---- -title: "Detect Rundll32 Application Control Bypass - advpack" -excerpt: "System Binary Proxy Execution -, Rundll32 -" -categories: - - Endpoint -last_modified_at: 2021-02-04 -toc: true -toc_label: "" -tags: - - System Binary Proxy Execution - - Rundll32 - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies rundll32.exe loading advpack.dll and ieadvpack.dll by calling the LaunchINFSection function on the command line. This particular technique will load script code from a file. Upon a successful execution, the following module loads may occur - clr.dll, jscript.dll and scrobj.dll. During investigation, identify script content origination. Generally, a child process will spawn from rundll32.exe, but that may be bypassed based on script code contents. Rundll32.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. During investigation, review any network connections and obtain the script content executed. It's possible other files are on disk. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-02-04 -- **Author**: Michael Haag, Splunk -- **ID**: 4aefadfe-9abd-4bf8-b3fd-867e9ef95bf8 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218](https://attack.mitre.org/techniques/T1218/) | System Binary Proxy Execution | Defense Evasion | - -| [T1218.011](https://attack.mitre.org/techniques/T1218/011/) | Rundll32 | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_rundll32` Processes.process=*advpack* by Processes.dest Processes.user Processes.parent_process_name Processes.original_file_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_rundll32_application_control_bypass___advpack_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [process_rundll32](https://github.com/splunk/security_content/blob/develop/macros/process_rundll32.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **detect_rundll32_application_control_bypass_-_advpack_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Although unlikely, some legitimate applications may use advpack.dll or ieadvpack.dll, triggering a false positive. - -#### Associated Analytic story -* [Suspicious Rundll32 Activity](/stories/suspicious_rundll32_activity) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ loading advpack.dll and ieadvpack.dll by calling the LaunchINFSection function on the command line was identified on endpoint $dest$ by user $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1218/011/](https://attack.mitre.org/techniques/T1218/011/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.011/T1218.011.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.011/T1218.011.md) -* [https://lolbas-project.github.io/lolbas/Binaries/Rundll32/](https://lolbas-project.github.io/lolbas/Binaries/Rundll32/) -* [https://lolbas-project.github.io/lolbas/Libraries/Advpack/](https://lolbas-project.github.io/lolbas/Libraries/Advpack/) -* [https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/](https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.011/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.011/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_setupapi.md b/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_setupapi.md deleted file mode 100644 index 5d9e885e5e..0000000000 --- a/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_setupapi.md +++ /dev/null @@ -1,179 +0,0 @@ ---- -title: "Detect Rundll32 Application Control Bypass - setupapi" -excerpt: "System Binary Proxy Execution -, Rundll32 -" -categories: - - Endpoint -last_modified_at: 2021-02-04 -toc: true -toc_label: "" -tags: - - System Binary Proxy Execution - - Rundll32 - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies rundll32.exe loading setupapi.dll and iesetupapi.dll by calling the LaunchINFSection function on the command line. This particular technique will load script code from a file. Upon a successful execution, the following module loads may occur - clr.dll, jscript.dll and scrobj.dll. During investigation, identify script content origination. Generally, a child process will spawn from rundll32.exe, but that may be bypassed based on script code contents. Rundll32.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. During investigation, review any network connections and obtain the script content executed. It's possible other files are on disk. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-02-04 -- **Author**: Michael Haag, Splunk -- **ID**: 61e7b44a-6088-4f26-b788-9a96ba13b37a - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218](https://attack.mitre.org/techniques/T1218/) | System Binary Proxy Execution | Defense Evasion | - -| [T1218.011](https://attack.mitre.org/techniques/T1218/011/) | Rundll32 | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_rundll32` Processes.process=*setupapi* by Processes.dest Processes.user Processes.parent_process_name Processes.original_file_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_rundll32_application_control_bypass___setupapi_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [process_rundll32](https://github.com/splunk/security_content/blob/develop/macros/process_rundll32.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **detect_rundll32_application_control_bypass_-_setupapi_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Although unlikely, some legitimate applications may use setupapi triggering a false positive. - -#### Associated Analytic story -* [Suspicious Rundll32 Activity](/stories/suspicious_rundll32_activity) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ loading setupapi.dll and iesetupapi.dll by calling the LaunchINFSection function on the command line was identified on endpoint $dest$ by user $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1218/011/](https://attack.mitre.org/techniques/T1218/011/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.011/T1218.011.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.011/T1218.011.md) -* [https://lolbas-project.github.io/lolbas/Binaries/Rundll32/](https://lolbas-project.github.io/lolbas/Binaries/Rundll32/) -* [https://lolbas-project.github.io/lolbas/Libraries/Setupapi/](https://lolbas-project.github.io/lolbas/Libraries/Setupapi/) -* [https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/](https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.011/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.011/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_syssetup.md b/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_syssetup.md deleted file mode 100644 index ed46a9baab..0000000000 --- a/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_syssetup.md +++ /dev/null @@ -1,179 +0,0 @@ ---- -title: "Detect Rundll32 Application Control Bypass - syssetup" -excerpt: "System Binary Proxy Execution -, Rundll32 -" -categories: - - Endpoint -last_modified_at: 2021-02-04 -toc: true -toc_label: "" -tags: - - System Binary Proxy Execution - - Rundll32 - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies rundll32.exe loading syssetup.dll by calling the LaunchINFSection function on the command line. This particular technique will load script code from a file. Upon a successful execution, the following module loads may occur - clr.dll, jscript.dll and scrobj.dll. During investigation, identify script content origination. Generally, a child process will spawn from rundll32.exe, but that may be bypassed based on script code contents. Rundll32.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. During investigation, review any network connections and obtain the script content executed. It's possible other files are on disk. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-02-04 -- **Author**: Michael Haag, Splunk -- **ID**: 71b9bf37-cde1-45fb-b899-1b0aa6fa1183 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218](https://attack.mitre.org/techniques/T1218/) | System Binary Proxy Execution | Defense Evasion | - -| [T1218.011](https://attack.mitre.org/techniques/T1218/011/) | Rundll32 | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_rundll32` Processes.process=*syssetup* by Processes.dest Processes.user Processes.parent_process_name Processes.original_file_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_rundll32_application_control_bypass___syssetup_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [process_rundll32](https://github.com/splunk/security_content/blob/develop/macros/process_rundll32.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **detect_rundll32_application_control_bypass_-_syssetup_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Although unlikely, some legitimate applications may use syssetup.dll, triggering a false positive. - -#### Associated Analytic story -* [Suspicious Rundll32 Activity](/stories/suspicious_rundll32_activity) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ loading syssetup.dll by calling the LaunchINFSection function on the command line was identified on endpoint $dest$ by user $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1218/011/](https://attack.mitre.org/techniques/T1218/011/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.011/T1218.011.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.011/T1218.011.md) -* [https://lolbas-project.github.io/lolbas/Binaries/Rundll32/](https://lolbas-project.github.io/lolbas/Binaries/Rundll32/) -* [https://lolbas-project.github.io/lolbas/Libraries/Syssetup/](https://lolbas-project.github.io/lolbas/Libraries/Syssetup/) -* [https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/](https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.011/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.011/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-02-04-suspicious_rundll32_startw.md b/docs/_posts/2021-02-04-suspicious_rundll32_startw.md deleted file mode 100644 index ffe1328049..0000000000 --- a/docs/_posts/2021-02-04-suspicious_rundll32_startw.md +++ /dev/null @@ -1,180 +0,0 @@ ---- -title: "Suspicious Rundll32 StartW" -excerpt: "System Binary Proxy Execution -, Rundll32 -" -categories: - - Endpoint -last_modified_at: 2021-02-04 -toc: true -toc_label: "" -tags: - - System Binary Proxy Execution - - Rundll32 - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies rundll32.exe executing a DLL function name, Start and StartW, on the command line that is commonly observed with Cobalt Strike x86 and x64 DLL payloads. Rundll32.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. Typically, the DLL will be written and loaded from a world writeable path or user location. In most instances it will not have a valid certificate (Unsigned). During investigation, review the parent process and other parallel application execution. Capture and triage the DLL in question. In the instance of Cobalt Strike, rundll32.exe is the default process it opens and injects shellcode into. This default process can be changed, but typically is not. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-02-04 -- **Author**: Michael Haag, Splunk -- **ID**: 9319dda5-73f2-4d43-a85a-67ce961bddb7 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218](https://attack.mitre.org/techniques/T1218/) | System Binary Proxy Execution | Defense Evasion | - -| [T1218.011](https://attack.mitre.org/techniques/T1218/011/) | Rundll32 | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_rundll32` Processes.process=*start* by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.original_file_name Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `suspicious_rundll32_startw_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [process_rundll32](https://github.com/splunk/security_content/blob/develop/macros/process_rundll32.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **suspicious_rundll32_startw_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Although unlikely, some legitimate applications may use Start as a function and call it via the command line. Filter as needed. - -#### Associated Analytic story -* [Suspicious Rundll32 Activity](/stories/suspicious_rundll32_activity) -* [Cobalt Strike](/stories/cobalt_strike) -* [Trickbot](/stories/trickbot) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 35.0 | 70 | 50 | rundll32.exe running with suspicious parameters on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1218/011/](https://attack.mitre.org/techniques/T1218/011/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.011/T1218.011.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.011/T1218.011.md) -* [https://hstechdocs.helpsystems.com/manuals/cobaltstrike/current/userguide/index.htm#cshid=1036](https://hstechdocs.helpsystems.com/manuals/cobaltstrike/current/userguide/index.htm#cshid=1036) -* [https://lolbas-project.github.io/lolbas/Binaries/Rundll32/](https://lolbas-project.github.io/lolbas/Binaries/Rundll32/) -* [https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/](https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.011/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.011/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/suspicious_rundll32_startw.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2021-02-09-suspicious_rundll32_dllregisterserver.md b/docs/_posts/2021-02-09-suspicious_rundll32_dllregisterserver.md deleted file mode 100644 index 4cececf02b..0000000000 --- a/docs/_posts/2021-02-09-suspicious_rundll32_dllregisterserver.md +++ /dev/null @@ -1,181 +0,0 @@ ---- -title: "Suspicious Rundll32 dllregisterserver" -excerpt: "System Binary Proxy Execution -, Rundll32 -" -categories: - - Endpoint -last_modified_at: 2021-02-09 -toc: true -toc_label: "" -tags: - - System Binary Proxy Execution - - Rundll32 - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies rundll32.exe using dllregisterserver on the command line to load a DLL. When a DLL is registered, the DllRegisterServer method entry point in the DLL is invoked. This is typically seen when a DLL is being registered on the system. Not every instance is considered malicious, but it will capture malicious use of it. During investigation, review the parent process and parrellel processes executing. Capture the DLL being loaded and inspect further. Rundll32.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-02-09 -- **Author**: Michael Haag, Splunk -- **ID**: 8c00a385-9b86-4ac0-8932-c9ec3713b159 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218](https://attack.mitre.org/techniques/T1218/) | System Binary Proxy Execution | Defense Evasion | - -| [T1218.011](https://attack.mitre.org/techniques/T1218/011/) | Rundll32 | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_rundll32` Processes.process=*dllregisterserver* by Processes.dest Processes.user Processes.parent_process Processes.original_file_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `suspicious_rundll32_dllregisterserver_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [process_rundll32](https://github.com/splunk/security_content/blob/develop/macros/process_rundll32.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **suspicious_rundll32_dllregisterserver_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -This is likely to produce false positives and will require some filtering. Tune the query by adding command line paths to known good DLLs, or filtering based on parent process names. - -#### Associated Analytic story -* [Suspicious Rundll32 Activity](/stories/suspicious_rundll32_activity) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 35.0 | 70 | 50 | $Processes.process_path.file_path$ process potentially loading malicious code | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1218/011/](https://attack.mitre.org/techniques/T1218/011/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.011/T1218.011.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.011/T1218.011.md) -* [https://lolbas-project.github.io/lolbas/Binaries/Rundll32/](https://lolbas-project.github.io/lolbas/Binaries/Rundll32/) -* [https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/seedworm-apt-iran-middle-east](https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/seedworm-apt-iran-middle-east) -* [https://github.com/pan-unit42/tweets/blob/master/2020-12-10-IOCs-from-Ursnif-infection-with-Delf-variant.txt](https://github.com/pan-unit42/tweets/blob/master/2020-12-10-IOCs-from-Ursnif-infection-with-Delf-variant.txt) -* [https://www.crowdstrike.com/blog/duck-hunting-with-falcon-complete-qakbot-zip-based-campaign/](https://www.crowdstrike.com/blog/duck-hunting-with-falcon-complete-qakbot-zip-based-campaign/) -* [https://docs.microsoft.com/en-us/windows/win32/api/olectl/nf-olectl-dllregisterserver?redirectedfrom=MSDN](https://docs.microsoft.com/en-us/windows/win32/api/olectl/nf-olectl-dllregisterserver?redirectedfrom=MSDN) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.011/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.011/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-02-11-detect_html_help_spawn_child_process.md b/docs/_posts/2021-02-11-detect_html_help_spawn_child_process.md deleted file mode 100644 index 331d8cd804..0000000000 --- a/docs/_posts/2021-02-11-detect_html_help_spawn_child_process.md +++ /dev/null @@ -1,178 +0,0 @@ ---- -title: "Detect HTML Help Spawn Child Process" -excerpt: "System Binary Proxy Execution -, Compiled HTML File -" -categories: - - Endpoint -last_modified_at: 2021-02-11 -toc: true -toc_label: "" -tags: - - System Binary Proxy Execution - - Compiled HTML File - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies hh.exe (HTML Help) execution of a Compiled HTML Help (CHM) that spawns a child process. This particular technique will load Windows script code from a compiled help file. CHM files may contain nearly any file type embedded, but only execute html/htm. Upon a successful execution, the following script engines may be used for execution - JScript, VBScript, VBScript.Encode, JScript.Encode, JScript.Compact. Analyst may identify vbscript.dll or jscript.dll loading into hh.exe upon execution. The "htm" and "html" file extensions were the only extensions observed to be supported for the execution of Shortcut commands or WSH script code. During investigation, identify script content origination. Review child process events and investigate further. hh.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-02-11 -- **Author**: Michael Haag, Splunk -- **ID**: 723716de-ee55-4cd4-9759-c44e7e55ba4b - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218](https://attack.mitre.org/techniques/T1218/) | System Binary Proxy Execution | Defense Evasion | - -| [T1218.001](https://attack.mitre.org/techniques/T1218/001/) | Compiled HTML File | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=hh.exe by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_html_help_spawn_child_process_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **detect_html_help_spawn_child_process_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Although unlikely, some legitimate applications (ex. web browsers) may spawn a child process. Filter as needed. - -#### Associated Analytic story -* [Suspicious Compiled HTML Activity](/stories/suspicious_compiled_html_activity) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ spawning a child process, typically not normal behavior. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1218/001/](https://attack.mitre.org/techniques/T1218/001/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.001/T1218.001.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.001/T1218.001.md) -* [https://lolbas-project.github.io/lolbas/Binaries/Hh/](https://lolbas-project.github.io/lolbas/Binaries/Hh/) -* [https://gist.github.com/mgeeky/cce31c8602a144d8f2172a73d510e0e7](https://gist.github.com/mgeeky/cce31c8602a144d8f2172a73d510e0e7) -* [https://web.archive.org/web/20220119133748/https://cyberforensicator.com/2019/01/20/silence-dissecting-malicious-chm-files-and-performing-forensic-analysis/](https://web.archive.org/web/20220119133748/https://cyberforensicator.com/2019/01/20/silence-dissecting-malicious-chm-files-and-performing-forensic-analysis/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.001/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.001/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/detect_html_help_spawn_child_process.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-02-12-detect_regasm_spawning_a_process.md b/docs/_posts/2021-02-12-detect_regasm_spawning_a_process.md deleted file mode 100644 index f85e76b088..0000000000 --- a/docs/_posts/2021-02-12-detect_regasm_spawning_a_process.md +++ /dev/null @@ -1,173 +0,0 @@ ---- -title: "Detect Regasm Spawning a Process" -excerpt: "System Binary Proxy Execution -, Regsvcs/Regasm -" -categories: - - Endpoint -last_modified_at: 2021-02-12 -toc: true -toc_label: "" -tags: - - System Binary Proxy Execution - - Regsvcs/Regasm - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies regasm.exe spawning a process. This particular technique has been used in the wild to bypass application control products. Regasm.exe and Regsvcs.exe are signed by Microsoft. Spawning of a child process is rare from either process and should be investigated further. During investigation, identify and retrieve the content being loaded. Review parallel processes for additional suspicious behavior. Gather any other file modifications and review accordingly. regsvcs.exe and regasm.exe are natively found in C:\Windows\Microsoft.NET\Framework\v*\regasm|regsvcs.exe and C:\Windows\Microsoft.NET\Framework64\v*\regasm|regsvcs.exe. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-02-12 -- **Author**: Michael Haag, Splunk -- **ID**: 72170ec5-f7d2-42f5-aefb-2b8be6aad15f - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218](https://attack.mitre.org/techniques/T1218/) | System Binary Proxy Execution | Defense Evasion | - -| [T1218.009](https://attack.mitre.org/techniques/T1218/009/) | Regsvcs/Regasm | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=regasm.exe by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_regasm_spawning_a_process_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **detect_regasm_spawning_a_process_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.parent_process_name -* Processes.dest -* Processes.user -* Processes.parent_process -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Although unlikely, limited instances of regasm.exe or regsvcs.exe may cause a false positive. Filter based endpoint usage, command line arguments, or process lineage. - -#### Associated Analytic story -* [Suspicious Regsvcs Regasm Activity](/stories/suspicious_regsvcs_regasm_activity) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 64.0 | 80 | 80 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ spawning a child process, typically not normal behavior for $parent_process_name$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1218/009/](https://attack.mitre.org/techniques/T1218/009/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.009/T1218.009.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.009/T1218.009.md) -* [https://lolbas-project.github.io/lolbas/Binaries/Regsvcs/](https://lolbas-project.github.io/lolbas/Binaries/Regsvcs/) -* [https://lolbas-project.github.io/lolbas/Binaries/Regasm/](https://lolbas-project.github.io/lolbas/Binaries/Regasm/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.009/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.009/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/detect_regasm_spawning_a_process.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-02-12-detect_regsvcs_spawning_a_process.md b/docs/_posts/2021-02-12-detect_regsvcs_spawning_a_process.md deleted file mode 100644 index 078a873546..0000000000 --- a/docs/_posts/2021-02-12-detect_regsvcs_spawning_a_process.md +++ /dev/null @@ -1,173 +0,0 @@ ---- -title: "Detect Regsvcs Spawning a Process" -excerpt: "System Binary Proxy Execution -, Regsvcs/Regasm -" -categories: - - Endpoint -last_modified_at: 2021-02-12 -toc: true -toc_label: "" -tags: - - System Binary Proxy Execution - - Regsvcs/Regasm - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies regsvcs.exe spawning a process. This particular technique has been used in the wild to bypass application control products. Regasm.exe and Regsvcs.exe are signed by Microsoft. Spawning of a child process is rare from either process and should be investigated further. During investigation, identify and retrieve the content being loaded. Review parallel processes for additional suspicious behavior. Gather any other file modifications and review accordingly. regsvcs.exe and regasm.exe are natively found in C:\Windows\Microsoft.NET\Framework\v*\regasm|regsvcs.exe and C:\Windows\Microsoft.NET\Framework64\v*\regasm|regsvcs.exe. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-02-12 -- **Author**: Michael Haag, Splunk -- **ID**: bc477b57-5c21-4ab6-9c33-668772e7f114 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218](https://attack.mitre.org/techniques/T1218/) | System Binary Proxy Execution | Defense Evasion | - -| [T1218.009](https://attack.mitre.org/techniques/T1218/009/) | Regsvcs/Regasm | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=regsvcs.exe by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_regsvcs_spawning_a_process_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **detect_regsvcs_spawning_a_process_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.parent_process_name -* Processes.dest -* Processes.user -* Processes.parent_process -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Although unlikely, limited instances of regasm.exe or regsvcs.exe may cause a false positive. Filter based endpoint usage, command line arguments, or process lineage. - -#### Associated Analytic story -* [Suspicious Regsvcs Regasm Activity](/stories/suspicious_regsvcs_regasm_activity) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 64.0 | 80 | 80 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ typically not normal for this process. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1218/009/](https://attack.mitre.org/techniques/T1218/009/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.009/T1218.009.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.009/T1218.009.md) -* [https://lolbas-project.github.io/lolbas/Binaries/Regsvcs/](https://lolbas-project.github.io/lolbas/Binaries/Regsvcs/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.009/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.009/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/detect_regsvcs_spawning_a_process.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-02-22-aws_create_policy_version_to_allow_all_resources.md b/docs/_posts/2021-02-22-aws_create_policy_version_to_allow_all_resources.md deleted file mode 100644 index 5fddfe8ebe..0000000000 --- a/docs/_posts/2021-02-22-aws_create_policy_version_to_allow_all_resources.md +++ /dev/null @@ -1,172 +0,0 @@ ---- -title: "AWS Create Policy Version to allow all resources" -excerpt: "Cloud Accounts -, Valid Accounts -" -categories: - - Cloud -last_modified_at: 2021-02-22 -toc: true -toc_label: "" -tags: - - Cloud Accounts - - Valid Accounts - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for AWS CloudTrail events where a user created a policy version that allows them to access any resource in their account - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-02-22 -- **Author**: Bhavin Patel, Splunk -- **ID**: 2a9b80d3-6340-4345-b5ad-212bf3d0dac4 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1078.004](https://attack.mitre.org/techniques/T1078/004/) | Cloud Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.DS -* PR.AC -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 13 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cloudtrail` eventName=CreatePolicyVersion eventSource = iam.amazonaws.com errorCode = success -| spath input=requestParameters.policyDocument output=key_policy_statements path=Statement{} -| mvexpand key_policy_statements -| spath input=key_policy_statements output=key_policy_action_1 path=Action -| search key_policy_action_1 = "*" -| stats count min(_time) as firstTime max(_time) as lastTime values(key_policy_statements) as policy_added by eventName eventSource aws_account_id errorCode userAgent eventID awsRegion userIdentity.principalId user_arn -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -|`aws_create_policy_version_to_allow_all_resources_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) - -Note that **aws_create_policy_version_to_allow_all_resources_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* eventName -* userAgent -* errorCode -* requestParameters.userName - - -#### How To Implement -You must install splunk AWS add on and Splunk App for AWS. This search works with AWS CloudTrail logs. - -#### Known False Positives -While this search has no known false positives, it is possible that an AWS admin has legitimately created a policy to allow a user to access all resources. That said, AWS strongly advises against granting full control to all AWS resources - -#### Associated Analytic story -* [AWS IAM Privilege Escalation](/stories/aws_iam_privilege_escalation) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | User $user$ created a policy version that allows them to access any resource in their account | - - -#### Reference - -* [https://labs.bishopfox.com/tech-blog/privilege-escalation-in-aws](https://labs.bishopfox.com/tech-blog/privilege-escalation-in-aws) -* [https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation-part-2/](https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation-part-2/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_create_policy_version/aws_cloudtrail_events.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_create_policy_version/aws_cloudtrail_events.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-02-22-cobalt_strike_named_pipes.md b/docs/_posts/2021-02-22-cobalt_strike_named_pipes.md deleted file mode 100644 index af133f7b4a..0000000000 --- a/docs/_posts/2021-02-22-cobalt_strike_named_pipes.md +++ /dev/null @@ -1,167 +0,0 @@ ---- -title: "Cobalt Strike Named Pipes" -excerpt: "Process Injection -" -categories: - - Endpoint -last_modified_at: 2021-02-22 -toc: true -toc_label: "" -tags: - - Process Injection - - Defense Evasion - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the use of default or publicly known named pipes used with Cobalt Strike. A named pipe is a named, one-way or duplex pipe for communication between the pipe server and one or more pipe clients. Cobalt Strike uses named pipes in many ways and has default values used with the Artifact Kit and Malleable C2 Profiles. The following query assists with identifying these default named pipes. Each EDR product presents named pipes a little different. Consider taking the values and generating a query based on the product of choice. \ -Upon triage, review the process performing the named pipe. If it is explorer.exe, It is possible it was injected into by another process. Review recent parallel processes to identify suspicious patterns or behaviors. A parallel process may have a network connection, review and follow the connection back to identify any file modifications. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-02-22 -- **Author**: Michael Haag, Splunk -- **ID**: 5876d429-0240-4709-8b93-ea8330b411b5 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1055](https://attack.mitre.org/techniques/T1055/) | Process Injection | Defense Evasion, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventID=17 OR EventID=18 PipeName IN (\\msagent_*, \\wkssvc*, \\DserNamePipe*, \\srvsvc_*, \\mojo.*, \\postex_*, \\status_*, \\MSSE-*, \\spoolss_*, \\win_svc*, \\ntsvcs*, \\winsock*, \\UIA_PIPE*) -| stats count min(_time) as firstTime max(_time) as lastTime by Computer, process_name, process_id process_path, PipeName -| rename Computer as dest -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `cobalt_strike_named_pipes_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -Note that **cobalt_strike_named_pipes_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventID -* PipeName -* Computer -* process_name -* process_path -* process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -The idea of using named pipes with Cobalt Strike is to blend in. Therefore, some of the named pipes identified and added may cause false positives. Filter by process name or pipe name to reduce false positives. - -#### Associated Analytic story -* [Cobalt Strike](/stories/cobalt_strike) -* [Trickbot](/stories/trickbot) -* [DarkSide Ransomware](/stories/darkside_ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 72.0 | 80 | 90 | An instance of $process_name$ was identified on endpoint $Computer$ by user $user$ accessing known suspicious named pipes related to Cobalt Strike. | - - -#### Reference - -* [https://attack.mitre.org/techniques/T1218/009/](https://attack.mitre.org/techniques/T1218/009/) -* [https://docs.microsoft.com/en-us/windows/win32/ipc/named-pipes](https://docs.microsoft.com/en-us/windows/win32/ipc/named-pipes) -* [https://www.cobaltstrike.com/help-smb-beacon](https://www.cobaltstrike.com/help-smb-beacon) -* [https://blog.cobaltstrike.com/2021/02/09/learn-pipe-fitting-for-all-of-your-offense-projects/](https://blog.cobaltstrike.com/2021/02/09/learn-pipe-fitting-for-all-of-your-offense-projects/) -* [https://gist.github.com/MHaggis/6c600e524045a6d49c35291a21e10752](https://gist.github.com/MHaggis/6c600e524045a6d49c35291a21e10752) -* [https://www.mandiant.com/resources/shining-a-light-on-darkside-ransomware-operations](https://www.mandiant.com/resources/shining-a-light-on-darkside-ransomware-operations) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/cobalt_strike_named_pipes.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-02-22-suspicious_curl_network_connection.md b/docs/_posts/2021-02-22-suspicious_curl_network_connection.md deleted file mode 100644 index 27ede70c64..0000000000 --- a/docs/_posts/2021-02-22-suspicious_curl_network_connection.md +++ /dev/null @@ -1,161 +0,0 @@ ---- -title: "Suspicious Curl Network Connection" -excerpt: "Ingress Tool Transfer -" -categories: - - Endpoint -last_modified_at: 2021-02-22 -toc: true -toc_label: "" -tags: - - Ingress Tool Transfer - - Command And Control - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the use of a curl contacting suspicious remote domains to checkin to command and control servers or download further implants. In the context of Silver Sparrow, curl is identified contacting s3.amazonaws.com. This particular behavior is common with MacOS adware-malicious software. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-02-22 -- **Author**: Michael Haag, Splunk -- **ID**: 3f613dc0-21f2-4063-93b1-5d3c15eef22f - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1105](https://attack.mitre.org/techniques/T1105/) | Ingress Tool Transfer | Command And Control | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=curl Processes.process=s3.amazonaws.com by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `suspicious_curl_network_connection_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **suspicious_curl_network_connection_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process_name -* Processes.process -* Processes.dest -* Processes.user -* Processes.parent_process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Unknown. Filter as needed. - -#### Associated Analytic story -* [Silver Sparrow](/stories/silver_sparrow) -* [Ingress Tool Transfer](/stories/ingress_tool_transfer) -* [Linux Living Off The Land](/stories/linux_living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://redcanary.com/blog/clipping-silver-sparrows-wings/](https://redcanary.com/blog/clipping-silver-sparrows-wings/) -* [https://www.marcosantadev.com/manage-plist-files-plistbuddy/](https://www.marcosantadev.com/manage-plist-files-plistbuddy/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/endpoint/suspicious_curl_network_connection.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-02-22-suspicious_plistbuddy_usage.md b/docs/_posts/2021-02-22-suspicious_plistbuddy_usage.md deleted file mode 100644 index 6b7c13d843..0000000000 --- a/docs/_posts/2021-02-22-suspicious_plistbuddy_usage.md +++ /dev/null @@ -1,172 +0,0 @@ ---- -title: "Suspicious PlistBuddy Usage" -excerpt: "Launch Agent -, Create or Modify System Process -" -categories: - - Endpoint -last_modified_at: 2021-02-22 -toc: true -toc_label: "" -tags: - - Launch Agent - - Create or Modify System Process - - Persistence - - Privilege Escalation - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the use of a native MacOS utility, PlistBuddy, creating or modifying a properly list (.plist) file. In the instance of Silver Sparrow, the following commands were executed:\ -- PlistBuddy -c "Add :Label string init_verx" ~/Library/Launchagents/init_verx.plist \ -- PlistBuddy -c "Add :RunAtLoad bool true" ~/Library/Launchagents/init_verx.plist \ -- PlistBuddy -c "Add :StartInterval integer 3600" ~/Library/Launchagents/init_verx.plist \ -- PlistBuddy -c "Add :ProgramArguments array" ~/Library/Launchagents/init_verx.plist \ -- PlistBuddy -c "Add :ProgramArguments:0 string /bin/sh" ~/Library/Launchagents/init_verx.plist \ -- PlistBuddy -c "Add :ProgramArguments:1 string -c" ~/Library/Launchagents/init_verx.plist \ -Upon triage, capture the property list file being written to disk and review for further indicators. Contain the endpoint and triage further. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-02-22 -- **Author**: Michael Haag, Splunk -- **ID**: c3194009-e0eb-4f84-87a9-4070f8688f00 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1543.001](https://attack.mitre.org/techniques/T1543/001/) | Launch Agent | Persistence, Privilege Escalation | - -| [T1543](https://attack.mitre.org/techniques/T1543/) | Create or Modify System Process | Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=PlistBuddy (Processes.process=*LaunchAgents* OR Processes.process=*RunAtLoad* OR Processes.process=*true*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `suspicious_plistbuddy_usage_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **suspicious_plistbuddy_usage_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process_name -* Processes.process -* Processes.dest -* Processes.user -* Processes.parent_process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Some legitimate applications may use PlistBuddy to create or modify property lists and possibly generate false positives. Review the property list being modified or created to confirm. - -#### Associated Analytic story -* [Silver Sparrow](/stories/silver_sparrow) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.marcosantadev.com/manage-plist-files-plistbuddy/](https://www.marcosantadev.com/manage-plist-files-plistbuddy/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/endpoint/suspicious_plistbuddy_usage.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-02-22-suspicious_plistbuddy_usage_via_osquery.md b/docs/_posts/2021-02-22-suspicious_plistbuddy_usage_via_osquery.md deleted file mode 100644 index e0f26e95cb..0000000000 --- a/docs/_posts/2021-02-22-suspicious_plistbuddy_usage_via_osquery.md +++ /dev/null @@ -1,160 +0,0 @@ ---- -title: "Suspicious PlistBuddy Usage via OSquery" -excerpt: "Launch Agent -, Create or Modify System Process -" -categories: - - Endpoint -last_modified_at: 2021-02-22 -toc: true -toc_label: "" -tags: - - Launch Agent - - Create or Modify System Process - - Persistence - - Privilege Escalation - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the use of a native MacOS utility, PlistBuddy, creating or modifying a properly list (.plist) file. In the instance of Silver Sparrow, the following commands were executed:\ -- PlistBuddy -c "Add :Label string init_verx" ~/Library/Launchagents/init_verx.plist \ -- PlistBuddy -c "Add :RunAtLoad bool true" ~/Library/Launchagents/init_verx.plist \ -- PlistBuddy -c "Add :StartInterval integer 3600" ~/Library/Launchagents/init_verx.plist \ -- PlistBuddy -c "Add :ProgramArguments array" ~/Library/Launchagents/init_verx.plist \ -- PlistBuddy -c "Add :ProgramArguments:0 string /bin/sh" ~/Library/Launchagents/init_verx.plist \ -- PlistBuddy -c "Add :ProgramArguments:1 string -c" ~/Library/Launchagents/init_verx.plist \ -Upon triage, capture the property list file being written to disk and review for further indicators. Contain the endpoint and triage further. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-02-22 -- **Author**: Michael Haag, Splunk -- **ID**: 20ba6c32-c733-4a32-b64e-2688cf231399 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1543.001](https://attack.mitre.org/techniques/T1543/001/) | Launch Agent | Persistence, Privilege Escalation | - -| [T1543](https://attack.mitre.org/techniques/T1543/) | Create or Modify System Process | Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`osquery_process` "columns.cmdline"="*LaunchAgents*" OR "columns.cmdline"="*RunAtLoad*" OR "columns.cmdline"="*true*" -| `suspicious_plistbuddy_usage_via_osquery_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [osquery_process](https://github.com/splunk/security_content/blob/develop/macros/osquery_process.yml) - -> :information_source: -> **suspicious_plistbuddy_usage_via_osquery_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* columns.cmdline - - -#### How To Implement -OSQuery must be installed and configured to pick up process events (info at https://osquery.io) as well as using the Splunk OSQuery Add-on https://splunkbase.splunk.com/app/4402. Modify the macro and validate fields are correct. - -#### Known False Positives -Some legitimate applications may use PlistBuddy to create or modify property lists and possibly generate false positives. Review the property list being modified or created to confirm. - -#### Associated Analytic story -* [Silver Sparrow](/stories/silver_sparrow) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.marcosantadev.com/manage-plist-files-plistbuddy/](https://www.marcosantadev.com/manage-plist-files-plistbuddy/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/endpoint/suspicious_plistbuddy_usage_via_osquery.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-02-22-suspicious_sqlite3_lsquarantine_behavior.md b/docs/_posts/2021-02-22-suspicious_sqlite3_lsquarantine_behavior.md deleted file mode 100644 index 2a90b73471..0000000000 --- a/docs/_posts/2021-02-22-suspicious_sqlite3_lsquarantine_behavior.md +++ /dev/null @@ -1,159 +0,0 @@ ---- -title: "Suspicious SQLite3 LSQuarantine Behavior" -excerpt: "Data Staged -" -categories: - - Endpoint -last_modified_at: 2021-02-22 -toc: true -toc_label: "" -tags: - - Data Staged - - Collection - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the use of a SQLite3 querying the MacOS preferences to identify the original URL the pkg was downloaded from. This particular behavior is common with MacOS adware-malicious software. Upon triage, review other processes in parallel for suspicious activity. Identify any recent package installations. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-02-22 -- **Author**: Michael Haag, Splunk -- **ID**: e1997b2e-655f-4561-82fd-aeba8e1c1a86 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1074](https://attack.mitre.org/techniques/T1074/) | Data Staged | Collection | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=sqlite3 Processes.process=*LSQuarantine* by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `suspicious_sqlite3_lsquarantine_behavior_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **suspicious_sqlite3_lsquarantine_behavior_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process_name -* Processes.process -* Processes.dest -* Processes.user -* Processes.parent_process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Unknown. - -#### Associated Analytic story -* [Silver Sparrow](/stories/silver_sparrow) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://redcanary.com/blog/clipping-silver-sparrows-wings/](https://redcanary.com/blog/clipping-silver-sparrows-wings/) -* [https://www.marcosantadev.com/manage-plist-files-plistbuddy/](https://www.marcosantadev.com/manage-plist-files-plistbuddy/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/endpoint/suspicious_sqlite3_lsquarantine_behavior.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-03-01-any_powershell_downloadfile.md b/docs/_posts/2021-03-01-any_powershell_downloadfile.md deleted file mode 100644 index 6d9666dc77..0000000000 --- a/docs/_posts/2021-03-01-any_powershell_downloadfile.md +++ /dev/null @@ -1,175 +0,0 @@ ---- -title: "Any Powershell DownloadFile" -excerpt: "Command and Scripting Interpreter -, PowerShell -" -categories: - - Endpoint -last_modified_at: 2021-03-01 -toc: true -toc_label: "" -tags: - - Command and Scripting Interpreter - - PowerShell - - Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2021-44228 - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the use of PowerShell downloading a file using `DownloadFile` method. This particular method is utilized in many different PowerShell frameworks to download files and output to disk. Identify the source (IP/domain) and destination file and triage appropriately. If AMSI logging or PowerShell transaction logs are available, review for further details of the implant. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-03-01 -- **Author**: Michael Haag, Splunk -- **ID**: 1a93b7ea-7af7-11eb-adb5-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -| [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2021-44228](https://nvd.nist.gov/vuln/detail/CVE-2021-44228) | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects. | 9.3 | - - - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_powershell` Processes.process=*DownloadFile* by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `any_powershell_downloadfile_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -Note that **any_powershell_downloadfile_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -False positives may be present and filtering will need to occur by parent process or command line argument. It may be required to modify this query to an EDR product for more granular coverage. - -#### Associated Analytic story -* [Malicious PowerShell](/stories/malicious_powershell) -* [Ingress Tool Transfer](/stories/ingress_tool_transfer) -* [Log4Shell CVE-2021-44228](/stories/log4shell_cve-2021-44228) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 56.0 | 80 | 70 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$. This behavior identifies the use of DownloadFile within PowerShell. | - - -#### Reference - -* [https://docs.microsoft.com/en-us/dotnet/api/system.net.webclient.downloadfile?view=net-5.0](https://docs.microsoft.com/en-us/dotnet/api/system.net.webclient.downloadfile?view=net-5.0) -* [https://blog.malwarebytes.com/malwarebytes-news/2021/02/lazyscripter-from-empire-to-double-rat/](https://blog.malwarebytes.com/malwarebytes-news/2021/02/lazyscripter-from-empire-to-double-rat/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1059.001/T1059.001.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1059.001/T1059.001.md) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/any_powershell_downloadfile.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-03-01-any_powershell_downloadstring.md b/docs/_posts/2021-03-01-any_powershell_downloadstring.md deleted file mode 100644 index 91eb4a0cef..0000000000 --- a/docs/_posts/2021-03-01-any_powershell_downloadstring.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: "Any Powershell DownloadString" -excerpt: "Command and Scripting Interpreter -, PowerShell -" -categories: - - Endpoint -last_modified_at: 2021-03-01 -toc: true -toc_label: "" -tags: - - Command and Scripting Interpreter - - PowerShell - - Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the use of PowerShell downloading a file using `DownloadString` method. This particular method is utilized in many different PowerShell frameworks to download files and output to disk. Identify the source (IP/domain) and destination file and triage appropriately. If AMSI logging or PowerShell transaction logs are available, review for further details of the implant. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-03-01 -- **Author**: Michael Haag, Splunk -- **ID**: 4d015ef2-7adf-11eb-95da-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -| [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_powershell` Processes.process=*.DownloadString* by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `any_powershell_downloadstring_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -Note that **any_powershell_downloadstring_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -False positives may be present and filtering will need to occur by parent process or command line argument. It may be required to modify this query to an EDR product for more granular coverage. - -#### Associated Analytic story -* [Malicious PowerShell](/stories/malicious_powershell) -* [HAFNIUM Group](/stories/hafnium_group) -* [Ingress Tool Transfer](/stories/ingress_tool_transfer) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 56.0 | 80 | 70 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$. This behavior identifies the use of DownloadString within PowerShell. | - - -#### Reference - -* [https://docs.microsoft.com/en-us/dotnet/api/system.net.webclient.downloadstring?view=net-5.0](https://docs.microsoft.com/en-us/dotnet/api/system.net.webclient.downloadstring?view=net-5.0) -* [https://blog.malwarebytes.com/malwarebytes-news/2021/02/lazyscripter-from-empire-to-double-rat/](https://blog.malwarebytes.com/malwarebytes-news/2021/02/lazyscripter-from-empire-to-double-rat/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1059.001/T1059.001.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1059.001/T1059.001.md) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/any_powershell_downloadstring.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-03-01-fodhelper_uac_bypass.md b/docs/_posts/2021-03-01-fodhelper_uac_bypass.md deleted file mode 100644 index 592926edfb..0000000000 --- a/docs/_posts/2021-03-01-fodhelper_uac_bypass.md +++ /dev/null @@ -1,180 +0,0 @@ ---- -title: "FodHelper UAC Bypass" -excerpt: "Modify Registry -, Bypass User Account Control -, Abuse Elevation Control Mechanism -" -categories: - - Endpoint -last_modified_at: 2021-03-01 -toc: true -toc_label: "" -tags: - - Modify Registry - - Bypass User Account Control - - Abuse Elevation Control Mechanism - - Defense Evasion - - Defense Evasion - - Privilege Escalation - - Defense Evasion - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -Fodhelper.exe has a known UAC bypass as it attempts to look for specific registry keys upon execution, that do not exist. Therefore, an attacker can write its malicious commands in these registry keys to be executed by fodhelper.exe with the highest privilege. \ -1. `HKCU:\Software\Classes\ms-settings\shell\open\command`\ -1. `HKCU:\Software\Classes\ms-settings\shell\open\command\DelegateExecute`\ -1. `HKCU:\Software\Classes\ms-settings\shell\open\command\(default)`\ -Upon triage, fodhelper.exe will have a child process and read access will occur on the registry keys. Isolate the endpoint and review parallel processes for additional behavior. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-03-01 -- **Author**: Michael Haag, Splunk -- **ID**: 909f8fd8-7ac8-11eb-a1f3-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1112](https://attack.mitre.org/techniques/T1112/) | Modify Registry | Defense Evasion | - -| [T1548.002](https://attack.mitre.org/techniques/T1548/002/) | Bypass User Account Control | Defense Evasion, Privilege Escalation | - -| [T1548](https://attack.mitre.org/techniques/T1548/) | Abuse Elevation Control Mechanism | Defense Evasion, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=fodhelper.exe by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `fodhelper_uac_bypass_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **fodhelper_uac_bypass_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.parent_process_name -* Processes.dest -* Processes.user -* Processes.parent_process -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Limited to no false positives are expected. - -#### Associated Analytic story -* [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics) -* [IcedID](/stories/icedid) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 81.0 | 90 | 90 | Suspcious registy keys added by process fodhelper.exe (process_id- $process_id), with a parent_process of $parent_process_name$ that has been executed on $dest$ by $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://blog.malwarebytes.com/malwarebytes-news/2021/02/lazyscripter-from-empire-to-double-rat/](https://blog.malwarebytes.com/malwarebytes-news/2021/02/lazyscripter-from-empire-to-double-rat/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1548.002/T1548.002.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1548.002/T1548.002.md) -* [https://github.com/gushmazuko/WinBypass/blob/master/FodhelperBypass.ps1](https://github.com/gushmazuko/WinBypass/blob/master/FodhelperBypass.ps1) -* [https://attack.mitre.org/techniques/T1548/002/](https://attack.mitre.org/techniques/T1548/002/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.002/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.002/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/fodhelper_uac_bypass.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-03-01-ryuk_wake_on_lan_command.md b/docs/_posts/2021-03-01-ryuk_wake_on_lan_command.md deleted file mode 100644 index 9050ba0148..0000000000 --- a/docs/_posts/2021-03-01-ryuk_wake_on_lan_command.md +++ /dev/null @@ -1,167 +0,0 @@ ---- -title: "Ryuk Wake on LAN Command" -excerpt: "Command and Scripting Interpreter -, Windows Command Shell -" -categories: - - Endpoint -last_modified_at: 2021-03-01 -toc: true -toc_label: "" -tags: - - Command and Scripting Interpreter - - Windows Command Shell - - Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This Splunk query identifies the use of Wake-on-LAN utilized by Ryuk ransomware. The Ryuk Ransomware uses the Wake-on-Lan feature to turn on powered off devices on a compromised network to have greater success encrypting them. This is a high fidelity indicator of Ryuk ransomware executing on an endpoint. Upon triage, isolate the endpoint. Additional file modification events will be within the users profile (\appdata\roaming) and in public directories (users\public\). Review all Scheduled Tasks on the isolated endpoint and across the fleet. Suspicious Scheduled Tasks will include a path to a unknown binary and those endpoints should be isolated until triaged. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-03-01 -- **Author**: Michael Haag, Splunk -- **ID**: 538d0152-7aaa-11eb-beaa-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -| [T1059.003](https://attack.mitre.org/techniques/T1059/003/) | Windows Command Shell | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process="*8 LAN*" OR Processes.process="*9 REP*") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `ryuk_wake_on_lan_command_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **ryuk_wake_on_lan_command_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process -* Processes.dest -* Processes.user -* Processes.parent_process -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Limited to no known false positives. - -#### Associated Analytic story -* [Ryuk Ransomware](/stories/ryuk_ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 63.0 | 70 | 90 | A process $process_name$ with wake on LAN commandline $process$ in host $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.bleepingcomputer.com/news/security/ryuk-ransomware-uses-wake-on-lan-to-encrypt-offline-devices/](https://www.bleepingcomputer.com/news/security/ryuk-ransomware-uses-wake-on-lan-to-encrypt-offline-devices/) -* [https://www.bleepingcomputer.com/news/security/ryuk-ransomware-now-self-spreads-to-other-windows-lan-devices/](https://www.bleepingcomputer.com/news/security/ryuk-ransomware-now-self-spreads-to-other-windows-lan-devices/) -* [https://www.cert.ssi.gouv.fr/uploads/CERTFR-2021-CTI-006.pdf](https://www.cert.ssi.gouv.fr/uploads/CERTFR-2021-CTI-006.pdf) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.003/ryuk/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.003/ryuk/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/ryuk_wake_on_lan_command.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-03-01-suspicious_scheduled_task_from_public_directory.md b/docs/_posts/2021-03-01-suspicious_scheduled_task_from_public_directory.md deleted file mode 100644 index 5dd5e0a279..0000000000 --- a/docs/_posts/2021-03-01-suspicious_scheduled_task_from_public_directory.md +++ /dev/null @@ -1,173 +0,0 @@ ---- -title: "Suspicious Scheduled Task from Public Directory" -excerpt: "Scheduled Task -, Scheduled Task/Job -" -categories: - - Endpoint -last_modified_at: 2021-03-01 -toc: true -toc_label: "" -tags: - - Scheduled Task - - Scheduled Task/Job - - Execution - - Persistence - - Privilege Escalation - - Execution - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following detection identifies Scheduled Tasks registering (creating a new task) a binary or script to run from a public directory which includes users\public, \programdata\ and \windows\temp. Upon triage, review the binary or script in the command line for legitimacy, whether an approved binary/script or not. In addition, capture the binary or script in question and analyze for further behaviors. Identify the source and contain the endpoint. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-03-01 -- **Author**: Michael Haag, Splunk -- **ID**: 7feb7972-7ac3-11eb-bac8-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1053.005](https://attack.mitre.org/techniques/T1053/005/) | Scheduled Task | Execution, Persistence, Privilege Escalation | - -| [T1053](https://attack.mitre.org/techniques/T1053/) | Scheduled Task/Job | Execution, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=schtasks.exe (Processes.process=*\\users\\public\\* OR Processes.process=*\\programdata\\* OR Processes.process=*windows\\temp*) Processes.process=*/create* by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `suspicious_scheduled_task_from_public_directory_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **suspicious_scheduled_task_from_public_directory_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process_name -* Processes.process -* Processes.dest -* Processes.user -* Processes.parent_process -* Processes.process_name -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Limited false positives may be present. Filter as needed by parent process or command line argument. - -#### Associated Analytic story -* [Ransomware](/stories/ransomware) -* [Ryuk Ransomware](/stories/ryuk_ransomware) -* [Windows Persistence Techniques](/stories/windows_persistence_techniques) -* [Living Off The Land](/stories/living_off_the_land) -* [Azorult](/stories/azorult) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 35.0 | 70 | 50 | Suspicious scheduled task registered on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1053/005/](https://attack.mitre.org/techniques/T1053/005/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/schtasks/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/schtasks/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-03-02-aws_setdefaultpolicyversion.md b/docs/_posts/2021-03-02-aws_setdefaultpolicyversion.md deleted file mode 100644 index 3c9f85d4ee..0000000000 --- a/docs/_posts/2021-03-02-aws_setdefaultpolicyversion.md +++ /dev/null @@ -1,173 +0,0 @@ ---- -title: "AWS SetDefaultPolicyVersion" -excerpt: "Cloud Accounts -, Valid Accounts -" -categories: - - Cloud -last_modified_at: 2021-03-02 -toc: true -toc_label: "" -tags: - - Cloud Accounts - - Valid Accounts - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for AWS CloudTrail events where a user has set a default policy versions. Attackers have been know to use this technique for Privilege Escalation in case the previous versions of the policy had permissions to access more resources than the current version of the policy - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-03-02 -- **Author**: Bhavin Patel, Splunk -- **ID**: 2a9b80d3-6340-4345-11ad-212bf3d0dac4 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1078.004](https://attack.mitre.org/techniques/T1078/004/) | Cloud Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.DS -* PR.AC -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 13 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cloudtrail` eventName=SetDefaultPolicyVersion eventSource = iam.amazonaws.com -| stats count min(_time) as firstTime max(_time) as lastTime values(requestParameters.policyArn) as policy_arn by src requestParameters.versionId eventName eventSource aws_account_id errorCode userAgent eventID awsRegion userIdentity.principalId user_arn -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `aws_setdefaultpolicyversion_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) - -> :information_source: -> **aws_setdefaultpolicyversion_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* eventName -* userAgent -* errorCode -* requestParameters.userName -* eventSource - - -#### How To Implement -You must install splunk AWS add on and Splunk App for AWS. This search works with AWS CloudTrail logs. - -#### Known False Positives -While this search has no known false positives, it is possible that an AWS admin has legitimately set a default policy to allow a user to access all resources. That said, AWS strongly advises against granting full control to all AWS resources - -#### Associated Analytic story -* [AWS IAM Privilege Escalation](/stories/aws_iam_privilege_escalation) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 30.0 | 50 | 60 | From IP address $sourceIPAddress$, user agent $userAgent$ has trigged an event $eventName$ for updating the the default policy version | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://bishopfox.com/blog/privilege-escalation-in-aws](https://bishopfox.com/blog/privilege-escalation-in-aws) -* [https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation-part-2/](https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation-part-2/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_setdefaultpolicyversion/aws_cloudtrail_events.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_setdefaultpolicyversion/aws_cloudtrail_events.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/aws_setdefaultpolicyversion.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-03-02-unified_messaging_service_spawning_a_process.md b/docs/_posts/2021-03-02-unified_messaging_service_spawning_a_process.md deleted file mode 100644 index 6c19456715..0000000000 --- a/docs/_posts/2021-03-02-unified_messaging_service_spawning_a_process.md +++ /dev/null @@ -1,166 +0,0 @@ ---- -title: "Unified Messaging Service Spawning a Process" -excerpt: "Exploit Public-Facing Application -" -categories: - - Endpoint -last_modified_at: 2021-03-02 -toc: true -toc_label: "" -tags: - - Exploit Public-Facing Application - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2021-26857 - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This detection identifies Microsoft Exchange Server's Unified Messaging services, umworkerprocess.exe and umservice.exe, spawning a child process, indicating possible exploitation of CVE-2021-26857 vulnerability. The query filters out werfault.exe and wermgr.exe mostly due to potential false positives, however, if there is an excessive amount of "wermgr.exe" or "WerFault.exe" failures, it may be due to the active exploitation. During triage, identify any additional suspicious parallel processes. Identify any recent out of place file modifications. Review Exchange logs following Microsofts guide. To contain, perform egress filtering or restrict public access to Exchange. In final, patch the vulnerablity and monitor. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-03-02 -- **Author**: Michael Haag, Splunk -- **ID**: f1126df0-7bd5-11eb-988f-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1190](https://attack.mitre.org/techniques/T1190/) | Exploit Public-Facing Application | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2021-26857](https://nvd.nist.gov/vuln/detail/CVE-2021-26857) | Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-26412, CVE-2021-26854, CVE-2021-26855, CVE-2021-26858, CVE-2021-27065, CVE-2021-27078. | 6.8 | - - - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name="umworkerprocess.exe" OR Processes.parent_process_name="UMService.exe" (Processes.process_name!="wermgr.exe" OR Processes.process_name!="werfault.exe") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `unified_messaging_service_spawning_a_process_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **unified_messaging_service_spawning_a_process_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process_name -* Processes.process -* Processes.dest -* Processes.user -* Processes.parent_process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -Unknown. Tune out child processes as needed to limit volume of false positives. - -#### Associated Analytic story -* [HAFNIUM Group](/stories/hafnium_group) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 56.0 | 70 | 80 | Possible CVE-2021-26857 exploitation on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.volexity.com/blog/2021/03/02/active-exploitation-of-microsoft-exchange-zero-day-vulnerabilities/](https://www.volexity.com/blog/2021/03/02/active-exploitation-of-microsoft-exchange-zero-day-vulnerabilities/) -* [https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/](https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/) -* [https://www.rapid7.com/blog/post/2021/03/03/rapid7s-insightidr-enables-detection-and-response-to-microsoft-exchange-0-day/](https://www.rapid7.com/blog/post/2021/03/03/rapid7s-insightidr-enables-detection-and-response-to-microsoft-exchange-0-day/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1505.003/windows-sysmon_umservices.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1505.003/windows-sysmon_umservices.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-03-02-windows_disableantispyware_registry.md b/docs/_posts/2021-03-02-windows_disableantispyware_registry.md deleted file mode 100644 index 5bd04bc753..0000000000 --- a/docs/_posts/2021-03-02-windows_disableantispyware_registry.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: "Windows DisableAntiSpyware Registry" -excerpt: "Disable or Modify Tools -, Impair Defenses -" -categories: - - Endpoint -last_modified_at: 2021-03-02 -toc: true -toc_label: "" -tags: - - Disable or Modify Tools - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The search looks for the Registry Key DisableAntiSpyware set to disable. This is consistent with Ryuk infections across a fleet of endpoints. This particular behavior is typically executed when an ransomware actor gains access to an endpoint and beings to perform execution. Usually, a batch (.bat) will be executed and multiple registry and scheduled task modifications will occur. During triage, review parallel processes and identify any further file modifications. Endpoint should be isolated. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-03-02 -- **Author**: Rod Soto, Jose Hernandez, Michael Haag, Splunk -- **ID**: 23150a40-9301-4195-b802-5bb4f43067fb - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Delivery - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_value_name="DisableAntiSpyware" AND Registry.registry_value_data="0x00000001" by Registry.dest Registry.user Registry.registry_path Registry.registry_value_data -| `drop_dm_object_name(Registry)` -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `windows_disableantispyware_registry_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_disableantispyware_registry_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.registry_key_name -* Registry.registry_value_name -* Registry.dest -* Registry.user -* Registry.registry_path - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. - -#### Known False Positives -It is unusual to turn this feature off a Windows system since it is a default security control, although it is not rare for some policies to disable it. Although no false positives have been identified, use the provided filter macro to tune the search. - -#### Associated Analytic story -* [Ryuk Ransomware](/stories/ryuk_ransomware) -* [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics) -* [Windows Registry Abuse](/stories/windows_registry_abuse) -* [Azorult](/stories/azorult) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 24.0 | 30 | 80 | Windows DisableAntiSpyware registry key set to 'disabled' on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://blog.malwarebytes.com/malwarebytes-news/2021/02/lazyscripter-from-empire-to-double-rat/](https://blog.malwarebytes.com/malwarebytes-news/2021/02/lazyscripter-from-empire-to-double-rat/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_disableantispyware_registry.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-03-03-nishang_powershelltcponeline.md b/docs/_posts/2021-03-03-nishang_powershelltcponeline.md deleted file mode 100644 index fe914f3b97..0000000000 --- a/docs/_posts/2021-03-03-nishang_powershelltcponeline.md +++ /dev/null @@ -1,172 +0,0 @@ ---- -title: "Nishang PowershellTCPOneLine" -excerpt: "Command and Scripting Interpreter -, PowerShell -" -categories: - - Endpoint -last_modified_at: 2021-03-03 -toc: true -toc_label: "" -tags: - - Command and Scripting Interpreter - - PowerShell - - Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This query detects the Nishang Invoke-PowerShellTCPOneLine utility that spawns a call back to a remote command and control server. This is a powershell oneliner. In addition, this will capture on the command-line additional utilities used by Nishang. Triage the endpoint and identify any parallel processes that look suspicious. Review the reputation of the remote IP or domain contacted by the powershell process. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-03-03 -- **Author**: Michael Haag, Splunk -- **ID**: 1a382c6c-7c2e-11eb-ac69-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -| [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_powershell` (Processes.process=*Net.Sockets.TCPClient* AND Processes.process=*System.Text.ASCIIEncoding*) by Processes.dest Processes.user Processes.parent_process Processes.original_file_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `nishang_powershelltcponeline_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml) - -> :information_source: -> **nishang_powershelltcponeline_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Limited false positives may be present. Filter as needed based on initial analysis. - -#### Associated Analytic story -* [HAFNIUM Group](/stories/hafnium_group) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 42.0 | 70 | 60 | Possible Nishang Invoke-PowerShellTCPOneLine behavior on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/samratashok/nishang/blob/master/Shells/Invoke-PowerShellTcpOneLine.ps1](https://github.com/samratashok/nishang/blob/master/Shells/Invoke-PowerShellTcpOneLine.ps1) -* [https://www.volexity.com/blog/2021/03/02/active-exploitation-of-microsoft-exchange-zero-day-vulnerabilities/](https://www.volexity.com/blog/2021/03/02/active-exploitation-of-microsoft-exchange-zero-day-vulnerabilities/) -* [https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/](https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/) -* [https://www.rapid7.com/blog/post/2021/03/03/rapid7s-insightidr-enables-detection-and-response-to-microsoft-exchange-0-day/](https://www.rapid7.com/blog/post/2021/03/03/rapid7s-insightidr-enables-detection-and-response-to-microsoft-exchange-0-day/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/nishang_powershelltcponeline.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-03-03-w3wp_spawning_shell.md b/docs/_posts/2021-03-03-w3wp_spawning_shell.md deleted file mode 100644 index 7e2da03840..0000000000 --- a/docs/_posts/2021-03-03-w3wp_spawning_shell.md +++ /dev/null @@ -1,184 +0,0 @@ ---- -title: "W3WP Spawning Shell" -excerpt: "Server Software Component -, Web Shell -" -categories: - - Endpoint -last_modified_at: 2021-03-03 -toc: true -toc_label: "" -tags: - - Server Software Component - - Web Shell - - Persistence - - Persistence - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2021-34473 - - CVE-2021-34523 - - CVE-2021-31207 - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This query identifies a shell, PowerShell.exe or Cmd.exe, spawning from W3WP.exe, or IIS. In addition to IIS logs, this behavior with an EDR product will capture potential webshell activity, similar to the HAFNIUM Group abusing CVEs, on publicly available Exchange mail servers. During triage, review the parent process and child process of the shell being spawned. Review the command-line arguments and any file modifications that may occur. Identify additional parallel process, child processes, that may highlight further commands executed. After triaging, work to contain the threat and patch the system that is vulnerable. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-03-03 -- **Author**: Michael Haag, Splunk -- **ID**: 0f03423c-7c6a-11eb-bc47-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1505](https://attack.mitre.org/techniques/T1505/) | Server Software Component | Persistence | - -| [T1505.003](https://attack.mitre.org/techniques/T1505/003/) | Web Shell | Persistence | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2021-34473](https://nvd.nist.gov/vuln/detail/CVE-2021-34473) | Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-31196, CVE-2021-31206. | 10.0 | -| [CVE-2021-34523](https://nvd.nist.gov/vuln/detail/CVE-2021-34523) | Microsoft Exchange Server Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-33768, CVE-2021-34470. | 7.5 | -| [CVE-2021-31207](https://nvd.nist.gov/vuln/detail/CVE-2021-31207) | Microsoft Exchange Server Security Feature Bypass Vulnerability | 6.5 | - - - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count values(Processes.process_name) as process_name values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=w3wp.exe AND `process_cmd` OR `process_powershell` by Processes.dest Processes.parent_process Processes.original_file_name Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `w3wp_spawning_shell_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [process_cmd](https://github.com/splunk/security_content/blob/develop/macros/process_cmd.yml) - -> :information_source: -> **w3wp_spawning_shell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Baseline your environment before production. It is possible build systems using IIS will spawn cmd.exe to perform a software build. Filter as needed. - -#### Associated Analytic story -* [Hermetic Wiper](/stories/hermetic_wiper) -* [HAFNIUM Group](/stories/hafnium_group) -* [ProxyShell](/stories/proxyshell) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 56.0 | 70 | 80 | Possible Web Shell execution on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.microsoft.com/security/blog/2020/02/04/ghost-in-the-shell-investigating-web-shell-attacks/](https://www.microsoft.com/security/blog/2020/02/04/ghost-in-the-shell-investigating-web-shell-attacks/) -* [https://www.zerodayinitiative.com/blog/2021/8/17/from-pwn2own-2021-a-new-attack-surface-on-microsoft-exchange-proxyshell](https://www.zerodayinitiative.com/blog/2021/8/17/from-pwn2own-2021-a-new-attack-surface-on-microsoft-exchange-proxyshell) -* [https://www.youtube.com/watch?v=FC6iHw258RI](https://www.youtube.com/watch?v=FC6iHw258RI) -* [https://www.huntress.com/blog/rapid-response-microsoft-exchange-servers-still-vulnerable-to-proxyshell-exploit#what-should-you-do](https://www.huntress.com/blog/rapid-response-microsoft-exchange-servers-still-vulnerable-to-proxyshell-exploit#what-should-you-do) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1505.003/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1505.003/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/w3wp_spawning_shell.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-03-12-ransomware_notes_bulk_creation.md b/docs/_posts/2021-03-12-ransomware_notes_bulk_creation.md deleted file mode 100644 index 05dc65a75a..0000000000 --- a/docs/_posts/2021-03-12-ransomware_notes_bulk_creation.md +++ /dev/null @@ -1,162 +0,0 @@ ---- -title: "Ransomware Notes bulk creation" -excerpt: "Data Encrypted for Impact -" -categories: - - Endpoint -last_modified_at: 2021-03-12 -toc: true -toc_label: "" -tags: - - Data Encrypted for Impact - - Impact - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytics identifies a big number of instance of ransomware notes (filetype e.g .txt, .html, .hta) file creation to the infected machine. This behavior is a good sensor if the ransomware note filename is quite new for security industry or the ransomware note filename is not in your ransomware lookup table list for monitoring. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-03-12 -- **Author**: Teoderick Contreras -- **ID**: eff7919a-8330-11eb-83f8-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1486](https://attack.mitre.org/techniques/T1486/) | Data Encrypted for Impact | Impact | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventCode=11 file_name IN ("*\.txt","*\.html","*\.hta") -|bin _time span=10s -| stats min(_time) as firstTime max(_time) as lastTime dc(TargetFilename) as unique_readme_path_count values(TargetFilename) as list_of_readme_path by Computer Image file_name -| where unique_readme_path_count >= 15 -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `ransomware_notes_bulk_creation_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **ransomware_notes_bulk_creation_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* EventCode -* file_name -* _time -* TargetFilename -* Computer -* Image -* user - - -#### How To Implement -You must be ingesting data that records the filesystem activity from your hosts to populate the Endpoint file-system data model node. If you are using Sysmon, you will need a Splunk Universal Forwarder on each endpoint from which you want to collect data. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Clop Ransomware](/stories/clop_ransomware) -* [DarkSide Ransomware](/stories/darkside_ransomware) -* [BlackMatter Ransomware](/stories/blackmatter_ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 81.0 | 90 | 90 | A high frequency file creation of $file_name$ in different file path in host $Computer$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.mandiant.com/resources/fin11-email-campaigns-precursor-for-ransomware-data-theft](https://www.mandiant.com/resources/fin11-email-campaigns-precursor-for-ransomware-data-theft) -* [https://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html](https://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_a/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_a/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/ransomware_notes_bulk_creation.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-03-12-resize_shadowstorage_volume.md b/docs/_posts/2021-03-12-resize_shadowstorage_volume.md deleted file mode 100644 index 9f9fd5b333..0000000000 --- a/docs/_posts/2021-03-12-resize_shadowstorage_volume.md +++ /dev/null @@ -1,162 +0,0 @@ ---- -title: "Resize ShadowStorage volume" -excerpt: "Inhibit System Recovery -" -categories: - - Endpoint -last_modified_at: 2021-03-12 -toc: true -toc_label: "" -tags: - - Inhibit System Recovery - - Impact - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytics identifies the resizing of shadowstorage by ransomware malware to avoid the shadow volumes being made again. this technique is an alternative by ransomware attacker than deleting the shadowstorage which is known alert in defensive team. one example of ransomware that use this technique is CLOP ransomware where it drops a .bat file that will resize the shadowstorage to minimum size as much as possible - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-03-12 -- **Author**: Teoderick Contreras -- **ID**: bc760ca6-8336-11eb-bcbb-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1490](https://attack.mitre.org/techniques/T1490/) | Inhibit System Recovery | Impact | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` values(Processes.process) as cmdline values(Processes.parent_process_name) as parent_process values(Processes.process_name) as process_name min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name = "cmd.exe" OR Processes.parent_process_name = "powershell.exe" OR Processes.parent_process_name = "powershell_ise.exe" OR Processes.parent_process_name = "wmic.exe" Processes.process_name = "vssadmin.exe" Processes.process="*resize*" Processes.process="*shadowstorage*" Processes.process="*/maxsize*" by Processes.parent_process_name Processes.parent_process Processes.process_name Processes.process Processes.dest Processes.user Processes.process_id Processes.process_guid -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -| `resize_shadowstorage_volume_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **resize_shadowstorage_volume_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* Processes.process -* Process.parent_process_name -* _time -* Processes.process_name -* Processes.parent_process -* Processes.dest -* Processes.user - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -network admin can resize the shadowstorage for valid purposes. - -#### Associated Analytic story -* [Clop Ransomware](/stories/clop_ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 72.0 | 80 | 90 | A process $parent_process_name$ attempt to resize shadow copy with commandline $process$ in host $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.mandiant.com/resources/fin11-email-campaigns-precursor-for-ransomware-data-theft](https://www.mandiant.com/resources/fin11-email-campaigns-precursor-for-ransomware-data-theft) -* [https://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html](https://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1490/T1490.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1490/T1490.md) -* [https://redcanary.com/blog/blackbyte-ransomware/](https://redcanary.com/blog/blackbyte-ransomware/) -* [https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/vssadmin-resize-shadowstorage](https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/vssadmin-resize-shadowstorage) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_a/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_a/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/resize_shadowstorage_volume.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-03-16-high_process_termination_frequency.md b/docs/_posts/2021-03-16-high_process_termination_frequency.md deleted file mode 100644 index 83a596b564..0000000000 --- a/docs/_posts/2021-03-16-high_process_termination_frequency.md +++ /dev/null @@ -1,158 +0,0 @@ ---- -title: "High Process Termination Frequency" -excerpt: "Data Encrypted for Impact -" -categories: - - Endpoint -last_modified_at: 2021-03-16 -toc: true -toc_label: "" -tags: - - Data Encrypted for Impact - - Impact - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytics are designed to indentify a high frequency of process termination on a machine which is a common behavior of ransomware malware before encrypting files. This technique is designed to avoid an exception error while accessing (docs, images, database and etc..) in the infected machine for encryption. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-03-16 -- **Author**: Teoderick Contreras -- **ID**: 17cd75b2-8666-11eb-9ab4-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1486](https://attack.mitre.org/techniques/T1486/) | Data Encrypted for Impact | Impact | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventCode=5 -|bin _time span=3s -|stats values(Image) as proc_terminated min(_time) as firstTime max(_time) as lastTime count by Computer EventCode ProcessID -| where count >= 15 -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `high_process_termination_frequency_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **high_process_termination_frequency_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* EventCode -* Image -* Computer -* _time -* ProcessID - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the Image (process full path of terminated process) from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -admin or user tool that can terminate multiple process. - -#### Associated Analytic story -* [Clop Ransomware](/stories/clop_ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 72.0 | 90 | 80 | High frequency process termination (more than 15 processes within 3s) detected on host $Computer$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.mandiant.com/resources/fin11-email-campaigns-precursor-for-ransomware-data-theft](https://www.mandiant.com/resources/fin11-email-campaigns-precursor-for-ransomware-data-theft) -* [https://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html](https://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_a/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_a/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/high_process_termination_frequency.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-03-16-windows_high_file_deletion_frequency.md b/docs/_posts/2021-03-16-windows_high_file_deletion_frequency.md deleted file mode 100644 index 1de6dea794..0000000000 --- a/docs/_posts/2021-03-16-windows_high_file_deletion_frequency.md +++ /dev/null @@ -1,162 +0,0 @@ ---- -title: "Windows High File Deletion Frequency" -excerpt: "Data Destruction -" -categories: - - Endpoint -last_modified_at: 2021-03-16 -toc: true -toc_label: "" -tags: - - Data Destruction - - Impact - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for high frequency of file deletion relative to process name and process id. These events usually happen when the ransomware tries to encrypt the files with the ransomware file extensions and sysmon treat the original files to be deleted as soon it was replace as encrypted data. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-03-16 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 45b125c4-866f-11eb-a95a-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1485](https://attack.mitre.org/techniques/T1485/) | Data Destruction | Impact | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventCode=23 TargetFilename IN ("*.cmd", "*.ini","*.gif", "*.jpg", "*.jpeg", "*.db", "*.ps1", "*.doc*", "*.xls*", "*.ppt*", "*.bmp","*.zip", "*.rar", "*.7z", "*.chm", "*.png", "*.log", "*.vbs", "*.js", "*.vhd", "*.bak", "*.wbcat", "*.bkf" , "*.backup*", "*.dsk", "*.win") -| stats values(TargetFilename) as deleted_files min(_time) as firstTime max(_time) as lastTime count by Computer user EventCode Image ProcessID -|where count >=100 -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_high_file_deletion_frequency_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **windows_high_file_deletion_frequency_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* EventCode -* TargetFilename -* Computer -* user -* Image -* ProcessID -* _time - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the deleted target file name, process name and process id from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -user may delete bunch of pictures or files in a folder. - -#### Associated Analytic story -* [Clop Ransomware](/stories/clop_ransomware) -* [WhisperGate](/stories/whispergate) -* [DarkCrystal RAT](/stories/darkcrystal_rat) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 72.0 | 90 | 80 | High frequency file deletion activity detected on host $Computer$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.mandiant.com/resources/fin11-email-campaigns-precursor-for-ransomware-data-theft](https://www.mandiant.com/resources/fin11-email-campaigns-precursor-for-ransomware-data-theft) -* [https://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html](https://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html) -* [https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/](https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_a/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_a/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_high_file_deletion_frequency.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-03-17-clop_common_exec_parameter.md b/docs/_posts/2021-03-17-clop_common_exec_parameter.md deleted file mode 100644 index 95b4806b3e..0000000000 --- a/docs/_posts/2021-03-17-clop_common_exec_parameter.md +++ /dev/null @@ -1,164 +0,0 @@ ---- -title: "Clop Common Exec Parameter" -excerpt: "User Execution -" -categories: - - Endpoint -last_modified_at: 2021-03-17 -toc: true -toc_label: "" -tags: - - User Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytics are designed to identifies some CLOP ransomware variant that using arguments to execute its main code or feature of its code. In this variant if the parameter is "runrun", CLOP ransomware will try to encrypt files in network shares and if it is "temp.dat", it will try to read from some stream pipe or file start encrypting files within the infected local machines. This technique can be also identified as an anti-sandbox technique to make its code non-responsive since it is waiting for some parameter to execute properly. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-03-17 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 5a8a2a72-8322-11eb-9ee9-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1204](https://attack.mitre.org/techniques/T1204/) | User Execution | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` values(Processes.process) as cmdline values(Processes.parent_process_name) as parent_process values(Processes.process_name) count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name != "*temp.dat*" Processes.process = "*runrun*" OR Processes.process = "*temp.dat*" by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `clop_common_exec_parameter_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **clop_common_exec_parameter_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Operators can execute third party tools using these parameters. - -#### Associated Analytic story -* [Clop Ransomware](/stories/clop_ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 100.0 | 100 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting using arguments to execute its main code or feature of its code related to Clop ransomware. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.mandiant.com/resources/fin11-email-campaigns-precursor-for-ransomware-data-theft](https://www.mandiant.com/resources/fin11-email-campaigns-precursor-for-ransomware-data-theft) -* [https://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html](https://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_b/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_b/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/clop_common_exec_parameter.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-03-17-clop_ransomware_known_service_name.md b/docs/_posts/2021-03-17-clop_ransomware_known_service_name.md deleted file mode 100644 index ad22032eb1..0000000000 --- a/docs/_posts/2021-03-17-clop_ransomware_known_service_name.md +++ /dev/null @@ -1,159 +0,0 @@ ---- -title: "Clop Ransomware Known Service Name" -excerpt: "Create or Modify System Process -" -categories: - - Endpoint -last_modified_at: 2021-03-17 -toc: true -toc_label: "" -tags: - - Create or Modify System Process - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This detection is to identify the common service name created by the CLOP ransomware as part of its persistence and high privilege code execution in the infected machine. Ussually CLOP ransomware use StartServiceCtrlDispatcherW API in creating this service entry. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-03-17 -- **Author**: Teoderick Contreras -- **ID**: 07e08a12-870c-11eb-b5f9-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1543](https://attack.mitre.org/techniques/T1543/) | Create or Modify System Process | Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`wineventlog_system` EventCode=7045 Service_Name IN ("SecurityCenterIBM", "WinCheckDRVs") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Service_File_Name Service_Name Service_Start_Type Service_Type -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `clop_ransomware_known_service_name_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [wineventlog_system](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_system.yml) - -> :information_source: -> **clop_ransomware_known_service_name_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* EventCode -* cmdline -* _time -* parent_process_name -* process_name -* OriginalFileName -* process_path - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the Service name, Service File Name Service Start type, and Service Type from your endpoints. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Clop Ransomware](/stories/clop_ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 100.0 | 100 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ executing known Clop Ransomware service names. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.mandiant.com/resources/fin11-email-campaigns-precursor-for-ransomware-data-theft](https://www.mandiant.com/resources/fin11-email-campaigns-precursor-for-ransomware-data-theft) -* [https://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html](https://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_a/windows-system.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_a/windows-system.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/clop_ransomware_known_service_name.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-03-23-certutil_with_decode_argument.md b/docs/_posts/2021-03-23-certutil_with_decode_argument.md deleted file mode 100644 index b7495a6ba1..0000000000 --- a/docs/_posts/2021-03-23-certutil_with_decode_argument.md +++ /dev/null @@ -1,168 +0,0 @@ ---- -title: "CertUtil With Decode Argument" -excerpt: "Deobfuscate/Decode Files or Information -" -categories: - - Endpoint -last_modified_at: 2021-03-23 -toc: true -toc_label: "" -tags: - - Deobfuscate/Decode Files or Information - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -CertUtil.exe may be used to `encode` and `decode` a file, including PE and script code. Encoding will convert a file to base64 with `-----BEGIN CERTIFICATE-----` and `-----END CERTIFICATE-----` tags. Malicious usage will include decoding a encoded file that was downloaded. Once decoded, it will be loaded by a parallel process. Note that there are two additional command switches that may be used - `encodehex` and `decodehex`. Similarly, the file will be encoded in HEX and later decoded for further execution. During triage, identify the source of the file being decoded. Review its contents or execution behavior for further analysis. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-03-23 -- **Author**: Michael Haag, Splunk -- **ID**: bfe94226-8c10-11eb-a4b3-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1140](https://attack.mitre.org/techniques/T1140/) | Deobfuscate/Decode Files or Information | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_certutil` Processes.process=*decode* by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `certutil_with_decode_argument_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_certutil](https://github.com/splunk/security_content/blob/develop/macros/process_certutil.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **certutil_with_decode_argument_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Typically seen used to `encode` files, but it is possible to see legitimate use of `decode`. Filter based on parent-child relationship, file paths, endpoint or user. - -#### Associated Analytic story -* [Deobfuscate-Decode Files or Information](/stories/deobfuscate-decode_files_or_information) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 40.0 | 50 | 80 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to decode a file. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1140/](https://attack.mitre.org/techniques/T1140/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1140/T1140.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1140/T1140.md) -* [https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/certutil](https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/certutil) -* [https://www.bleepingcomputer.com/news/security/certutilexe-could-allow-attackers-to-download-malware-while-bypassing-av/](https://www.bleepingcomputer.com/news/security/certutilexe-could-allow-attackers-to-download-malware-while-bypassing-av/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1140/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1140/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/certutil_with_decode_argument.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-03-29-powershell_start-bitstransfer.md b/docs/_posts/2021-03-29-powershell_start-bitstransfer.md deleted file mode 100644 index 5583fced4f..0000000000 --- a/docs/_posts/2021-03-29-powershell_start-bitstransfer.md +++ /dev/null @@ -1,166 +0,0 @@ ---- -title: "PowerShell Start-BitsTransfer" -excerpt: "BITS Jobs -" -categories: - - Endpoint -last_modified_at: 2021-03-29 -toc: true -toc_label: "" -tags: - - BITS Jobs - - Defense Evasion - - Persistence - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -Start-BitsTransfer is the PowerShell "version" of BitsAdmin.exe. Similar functionality is present. This technique variation is not as commonly used by adversaries, but has been abused in the past. Lesser known uses include the ability to set the `-TransferType` to `Upload` for exfiltration of files. In an instance where `Upload` is used, it is highly possible files will be archived. During triage, review parallel processes and process lineage. Capture any files on disk and review. For the remote domain or IP, what is the reputation? - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-03-29 -- **Author**: Michael Haag, Splunk -- **ID**: 39e2605a-90d8-11eb-899e-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1197](https://attack.mitre.org/techniques/T1197/) | BITS Jobs | Defense Evasion, Persistence | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_powershell` Processes.process=*start-bitstransfer* by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.original_file_name Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `powershell_start_bitstransfer_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml) - -> :information_source: -> **powershell_start-bitstransfer_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Limited false positives. It is possible administrators will utilize Start-BitsTransfer for administrative tasks, otherwise filter based parent process or command-line arguments. - -#### Associated Analytic story -* [BITS Jobs](/stories/bits_jobs) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 56.0 | 70 | 80 | A suspicious process $process_name$ with commandline $process$ that are related to bittransfer functionality in host $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://isc.sans.edu/diary/Investigating+Microsoft+BITS+Activity/23281](https://isc.sans.edu/diary/Investigating+Microsoft+BITS+Activity/23281) -* [https://docs.microsoft.com/en-us/windows/win32/bits/using-windows-powershell-to-create-bits-transfer-jobs](https://docs.microsoft.com/en-us/windows/win32/bits/using-windows-powershell-to-create-bits-transfer-jobs) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1197/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1197/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/powershell_start_bitstransfer.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-03-31-aws_iam_successful_group_deletion.md b/docs/_posts/2021-03-31-aws_iam_successful_group_deletion.md deleted file mode 100644 index c36f3c3426..0000000000 --- a/docs/_posts/2021-03-31-aws_iam_successful_group_deletion.md +++ /dev/null @@ -1,165 +0,0 @@ ---- -title: "AWS IAM Successful Group Deletion" -excerpt: "Cloud Groups -, Account Manipulation -, Permission Groups Discovery -" -categories: - - Cloud -last_modified_at: 2021-03-31 -toc: true -toc_label: "" -tags: - - Cloud Groups - - Account Manipulation - - Permission Groups Discovery - - Discovery - - Persistence - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following query uses IAM events to track the success of a group being deleted on AWS. This is typically not indicative of malicious behavior, but a precurser to additional events thay may unfold. Review parallel IAM events - recently added users, new groups and so forth. Inversely, review failed attempts in a similar manner. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-03-31 -- **Author**: Michael Haag, Splunk -- **ID**: e776d06c-9267-11eb-819b-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1069.003](https://attack.mitre.org/techniques/T1069/003/) | Cloud Groups | Discovery | - -| [T1098](https://attack.mitre.org/techniques/T1098/) | Account Manipulation | Persistence | - -| [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cloudtrail` eventSource=iam.amazonaws.com eventName=DeleteGroup errorCode=success (userAgent!=*.amazonaws.com) -| stats count min(_time) as firstTime max(_time) as lastTime values(requestParameters.groupName) as group_deleted by src eventName eventSource errorCode user_agent awsRegion userIdentity.principalId user_arn -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `aws_iam_successful_group_deletion_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) - -> :information_source: -> **aws_iam_successful_group_deletion_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* eventName -* userAgent -* errorCode -* requestParameters.groupName - - -#### How To Implement -The Splunk AWS Add-on and Splunk App for AWS is required to utilize this data. The search requires AWS Cloudtrail logs. - -#### Known False Positives -This detection will require tuning to provide high fidelity detection capabilties. Tune based on src addresses (corporate offices, VPN terminations) or by groups of users. Not every user with AWS access should have permission to delete groups (least privilege). - -#### Associated Analytic story -* [AWS IAM Privilege Escalation](/stories/aws_iam_privilege_escalation) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 5.0 | 10 | 50 | User $user_arn$ has sucessfully deleted mulitple groups $group_deleted$ from $src$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://awscli.amazonaws.com/v2/documentation/api/latest/reference/iam/delete-group.html](https://awscli.amazonaws.com/v2/documentation/api/latest/reference/iam/delete-group.html) -* [https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeleteGroup.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeleteGroup.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/aws_iam_successful_group_deletion/aws_iam_successful_group_deletion.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/aws_iam_successful_group_deletion/aws_iam_successful_group_deletion.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/aws_iam_successful_group_deletion.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-03-31-disabling_firewall_with_netsh.md b/docs/_posts/2021-03-31-disabling_firewall_with_netsh.md deleted file mode 100644 index f10537d8e5..0000000000 --- a/docs/_posts/2021-03-31-disabling_firewall_with_netsh.md +++ /dev/null @@ -1,171 +0,0 @@ ---- -title: "Disabling Firewall with Netsh" -excerpt: "Disable or Modify Tools -, Impair Defenses -" -categories: - - Endpoint -last_modified_at: 2021-03-31 -toc: true -toc_label: "" -tags: - - Disable or Modify Tools - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to identifies suspicious firewall disabling using netsh application. this technique is commonly seen in malware that tries to communicate or download its component or other payload to its C2 server. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-03-31 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 6860a62c-9203-11eb-9e05-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_netsh` Processes.process= "*firewall*" (Processes.process= "*off*" OR Processes.process= "*disable*") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `disabling_firewall_with_netsh_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_netsh](https://github.com/splunk/security_content/blob/develop/macros/process_netsh.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **disabling_firewall_with_netsh_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -admin may disable firewall during testing or fixing network problem. - -#### Associated Analytic story -* [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | The Windows Firewall was disabled on $dest$ by $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://tccontre.blogspot.com/2020/01/remcos-rat-evading-windows-defender-av.html](https://tccontre.blogspot.com/2020/01/remcos-rat-evading-windows-defender-av.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-security.log) -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-system.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-system.log) -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disabling_firewall_with_netsh.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-03-31-dsquery_domain_discovery.md b/docs/_posts/2021-03-31-dsquery_domain_discovery.md deleted file mode 100644 index b076a89e3a..0000000000 --- a/docs/_posts/2021-03-31-dsquery_domain_discovery.md +++ /dev/null @@ -1,168 +0,0 @@ ---- -title: "DSQuery Domain Discovery" -excerpt: "Domain Trust Discovery -" -categories: - - Endpoint -last_modified_at: 2021-03-31 -toc: true -toc_label: "" -tags: - - Domain Trust Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies "dsquery.exe" execution with arguments looking for `TrustedDomain` query directly on the command-line. This is typically indicative of an Administrator or adversary perform domain trust discovery. Note that this query does not identify any other variations of "Dsquery.exe" usage.\ -Within this detection, it is assumed `dsquery.exe` is not moved or renamed.\ -The search will return the first time and last time these command-line arguments were used for these executions, as well as the target system, the user, process "dsquery.exe" and its parent process.\ -DSQuery.exe is natively found in `C:\Windows\system32` and `C:\Windows\syswow64` and only on Server operating system.\ -The following DLL(s) are loaded when DSQuery.exe is launched `dsquery.dll`. If found loaded by another process, it is possible dsquery is running within that process context in memory.\ -In addition to trust discovery, review parallel processes for additional behaviors performed. Identify the parent process and capture any files (batch files, for example) being used. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-03-31 -- **Author**: Michael Haag, Splunk -- **ID**: cc316032-924a-11eb-91a2-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1482](https://attack.mitre.org/techniques/T1482/) | Domain Trust Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=dsquery.exe Processes.process=*trustedDomain* by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `dsquery_domain_discovery_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **dsquery_domain_discovery_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Limited false positives. If there is a true false positive, filter based on command-line or parent process. - -#### Associated Analytic story -* [Domain Trust Discovery](/stories/domain_trust_discovery) -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 72.0 | 80 | 90 | An instance of $parent_process_name$ spawning $process_name$ was identified performing domain discovery on endpoint $dest$ by user $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1482/T1482.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1482/T1482.md) -* [https://blog.harmj0y.net/redteaming/a-guide-to-attacking-domain-trusts/](https://blog.harmj0y.net/redteaming/a-guide-to-attacking-domain-trusts/) -* [https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-R2-and-2012/cc732952(v=ws.11)](https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-R2-and-2012/cc732952(v=ws.11)) -* [https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-R2-and-2012/cc754232(v=ws.11)](https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-R2-and-2012/cc754232(v=ws.11)) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1482/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1482/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/dsquery_domain_discovery.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-04-01-aws_iam_assume_role_policy_brute_force.md b/docs/_posts/2021-04-01-aws_iam_assume_role_policy_brute_force.md deleted file mode 100644 index b60136f69f..0000000000 --- a/docs/_posts/2021-04-01-aws_iam_assume_role_policy_brute_force.md +++ /dev/null @@ -1,162 +0,0 @@ ---- -title: "AWS IAM Assume Role Policy Brute Force" -excerpt: "Cloud Infrastructure Discovery -, Brute Force -" -categories: - - Cloud -last_modified_at: 2021-04-01 -toc: true -toc_label: "" -tags: - - Cloud Infrastructure Discovery - - Brute Force - - Discovery - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following detection identifies any malformed policy document exceptions with a status of `failure`. A malformed policy document exception occurs in instances where roles are attempted to be assumed, or brute forced. In a brute force attempt, using a tool like CloudSploit or Pacu, an attempt will look like `arn:aws:iam::111111111111:role/aws-service-role/rds.amazonaws.com/AWSServiceRoleForRDS`. Meaning, when an adversary is attempting to identify a role name, multiple failures will occur. This detection focuses on the errors of a remote attempt that is failing. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-04-01 -- **Author**: Michael Haag, Splunk -- **ID**: f19e09b0-9308-11eb-b7ec-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1580](https://attack.mitre.org/techniques/T1580/) | Cloud Infrastructure Discovery | Discovery | - -| [T1110](https://attack.mitre.org/techniques/T1110/) | Brute Force | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cloudtrail` (errorCode=MalformedPolicyDocumentException) status=failure (userAgent!=*.amazonaws.com) -| stats count min(_time) as firstTime max(_time) as lastTime values(requestParameters.policyName) as policy_name by src eventName eventSource aws_account_id errorCode requestParameters.policyDocument userAgent eventID awsRegion userIdentity.principalId user_arn -| where count >= 2 -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `aws_iam_assume_role_policy_brute_force_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) - -> :information_source: -> **aws_iam_assume_role_policy_brute_force_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* eventName -* userAgent -* errorCode -* requestParameters.policyName - - -#### How To Implement -The Splunk AWS Add-on and Splunk App for AWS is required to utilize this data. The search requires AWS Cloudtrail logs. Set the `where count` greater than a value to identify suspicious activity in your environment. - -#### Known False Positives -This detection will require tuning to provide high fidelity detection capabilties. Tune based on src addresses (corporate offices, VPN terminations) or by groups of users. - -#### Associated Analytic story -* [AWS IAM Privilege Escalation](/stories/aws_iam_privilege_escalation) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 28.0 | 40 | 70 | User $user_arn$ has caused multiple failures with errorCode $errorCode$, which potentially means adversary is attempting to identify a role name. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.praetorian.com/blog/aws-iam-assume-role-vulnerabilities/](https://www.praetorian.com/blog/aws-iam-assume-role-vulnerabilities/) -* [https://rhinosecuritylabs.com/aws/assume-worst-aws-assume-role-enumeration/](https://rhinosecuritylabs.com/aws/assume-worst-aws-assume-role-enumeration/) -* [https://www.elastic.co/guide/en/security/current/aws-iam-brute-force-of-assume-role-policy.html](https://www.elastic.co/guide/en/security/current/aws-iam-brute-force-of-assume-role-policy.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1580/aws_iam_assume_role_policy_brute_force/aws_iam_assume_role_policy_brute_force.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1580/aws_iam_assume_role_policy_brute_force/aws_iam_assume_role_policy_brute_force.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-04-01-aws_iam_delete_policy.md b/docs/_posts/2021-04-01-aws_iam_delete_policy.md deleted file mode 100644 index 4a24129392..0000000000 --- a/docs/_posts/2021-04-01-aws_iam_delete_policy.md +++ /dev/null @@ -1,155 +0,0 @@ ---- -title: "AWS IAM Delete Policy" -excerpt: "Account Manipulation -" -categories: - - Cloud -last_modified_at: 2021-04-01 -toc: true -toc_label: "" -tags: - - Account Manipulation - - Persistence - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following detection identifes when a policy is deleted on AWS. This does not identify whether successful or failed, but the error messages tell a story of suspicious attempts. There is a specific process to follow when deleting a policy. First, detach the policy from all users, groups, and roles that the policy is attached to, using DetachUserPolicy , DetachGroupPolicy , or DetachRolePolicy. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-04-01 -- **Author**: Michael Haag, Splunk -- **ID**: ec3a9362-92fe-11eb-99d0-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1098](https://attack.mitre.org/techniques/T1098/) | Account Manipulation | Persistence | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cloudtrail` eventName=DeletePolicy (userAgent!=*.amazonaws.com) -| stats count min(_time) as firstTime max(_time) as lastTime values(requestParameters.policyArn) as policyArn by src eventName eventSource aws_account_id errorCode errorMessage userAgent eventID awsRegion userIdentity.principalId userIdentity.arn -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `aws_iam_delete_policy_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) - -> :information_source: -> **aws_iam_delete_policy_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* eventName -* userAgent -* errorCode -* requestParameters.policyArn - - -#### How To Implement -The Splunk AWS Add-on and Splunk App for AWS is required to utilize this data. The search requires AWS Cloudtrail logs. - -#### Known False Positives -This detection will require tuning to provide high fidelity detection capabilties. Tune based on src addresses (corporate offices, VPN terminations) or by groups of users. Not every user with AWS access should have permission to delete policies (least privilege). In addition, this may be saved seperately and tuned for failed or success attempts only. - -#### Associated Analytic story -* [AWS IAM Privilege Escalation](/stories/aws_iam_privilege_escalation) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 10.0 | 20 | 50 | User $user_arn$ has deleted AWS Policies from IP address $src$ by executing the following command $eventName$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeletePolicy.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeletePolicy.html) -* [https://docs.aws.amazon.com/cli/latest/reference/iam/delete-policy.html](https://docs.aws.amazon.com/cli/latest/reference/iam/delete-policy.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/aws_iam_delete_policy/aws_iam_delete_policy.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/aws_iam_delete_policy/aws_iam_delete_policy.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/aws_iam_delete_policy.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-04-01-aws_iam_failure_group_deletion.md b/docs/_posts/2021-04-01-aws_iam_failure_group_deletion.md deleted file mode 100644 index 213ebb88ad..0000000000 --- a/docs/_posts/2021-04-01-aws_iam_failure_group_deletion.md +++ /dev/null @@ -1,155 +0,0 @@ ---- -title: "AWS IAM Failure Group Deletion" -excerpt: "Account Manipulation -" -categories: - - Cloud -last_modified_at: 2021-04-01 -toc: true -toc_label: "" -tags: - - Account Manipulation - - Persistence - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This detection identifies failure attempts to delete groups. We want to identify when a group is attempting to be deleted, but either access is denied, there is a conflict or there is no group. This is indicative of administrators performing an action, but also could be suspicious behavior occurring. Review parallel IAM events - recently added users, new groups and so forth. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-04-01 -- **Author**: Michael Haag, Splunk -- **ID**: 723b861a-92eb-11eb-93b8-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1098](https://attack.mitre.org/techniques/T1098/) | Account Manipulation | Persistence | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cloudtrail` eventSource=iam.amazonaws.com eventName=DeleteGroup errorCode IN (NoSuchEntityException,DeleteConflictException, AccessDenied) (userAgent!=*.amazonaws.com) -| stats count min(_time) as firstTime max(_time) as lastTime values(requestParameters.groupName) as group_name by src eventName eventSource aws_account_id errorCode errorMessage userAgent eventID awsRegion userIdentity.principalId user_arn -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `aws_iam_failure_group_deletion_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) - -> :information_source: -> **aws_iam_failure_group_deletion_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* eventName -* userAgent -* errorCode -* requestParameters.groupName - - -#### How To Implement -The Splunk AWS Add-on and Splunk App for AWS is required to utilize this data. The search requires AWS Cloudtrail logs. - -#### Known False Positives -This detection will require tuning to provide high fidelity detection capabilties. Tune based on src addresses (corporate offices, VPN terminations) or by groups of users. Not every user with AWS access should have permission to delete groups (least privilege). - -#### Associated Analytic story -* [AWS IAM Privilege Escalation](/stories/aws_iam_privilege_escalation) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 5.0 | 10 | 50 | User $user_arn$ has had mulitple failures while attempting to delete groups from $src$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://awscli.amazonaws.com/v2/documentation/api/latest/reference/iam/delete-group.html](https://awscli.amazonaws.com/v2/documentation/api/latest/reference/iam/delete-group.html) -* [https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeleteGroup.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeleteGroup.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/aws_iam_failure_group_deletion/aws_iam_failure_group_deletion.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/aws_iam_failure_group_deletion/aws_iam_failure_group_deletion.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/aws_iam_failure_group_deletion.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-04-07-malicious_powershell_executed_as_a_service.md b/docs/_posts/2021-04-07-malicious_powershell_executed_as_a_service.md deleted file mode 100644 index ebd16db17c..0000000000 --- a/docs/_posts/2021-04-07-malicious_powershell_executed_as_a_service.md +++ /dev/null @@ -1,174 +0,0 @@ ---- -title: "Malicious Powershell Executed As A Service" -excerpt: "System Services -, Service Execution -" -categories: - - Endpoint -last_modified_at: 2021-04-07 -toc: true -toc_label: "" -tags: - - System Services - - Service Execution - - Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This detection is to identify the abuse the Windows SC.exe to execute malicious commands or payloads via PowerShell. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-04-07 -- **Author**: Ryan Becwar -- **ID**: 8e204dfd-cae0-4ea8-a61d-e972a1ff2ff8 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1569](https://attack.mitre.org/techniques/T1569/) | System Services | Execution | - -| [T1569.002](https://attack.mitre.org/techniques/T1569/002/) | Service Execution | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - `wineventlog_system` EventCode=7045 -| eval l_Service_File_Name=lower(Service_File_Name) -| regex l_Service_File_Name="powershell[.\s] -|powershell_ise[.\s] -|pwsh[.\s] -|psexec[.\s]" -| regex l_Service_File_Name="-nop[rofile\s]+ -|-w[indowstyle]*\s+hid[den]* -|-noe[xit\s]+ -|-enc[odedcommand\s]+" -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Service_File_Name Service_Name Service_Start_Type Service_Type Service_Account user -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `malicious_powershell_executed_as_a_service_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [wineventlog_system](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_system.yml) - -> :information_source: -> **malicious_powershell_executed_as_a_service_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* EventCode -* Service_File_Name -* Service_Type -* _time -* Service_Name -* Service_Start_Type -* Service_Account -* user - - -#### How To Implement -To successfully implement this search, you need to be ingesting Windows System logs with the Service name, Service File Name Service Start type, and Service Type from your endpoints. - -#### Known False Positives -Creating a hidden powershell service is rare and could key off of those instances. - -#### Associated Analytic story -* [Malicious Powershell](/stories/malicious_powershell) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 72.0 | 90 | 80 | Identifies the abuse the Windows SC.exe to execute malicious powerShell as a service $Service_File_Name$ by $user$ on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.fireeye.com/content/dam/fireeye-www/blog/pdfs/dosfuscation-report.pdf](https://www.fireeye.com/content/dam/fireeye-www/blog/pdfs/dosfuscation-report.pdf) -* [http://az4n6.blogspot.com/2017/](http://az4n6.blogspot.com/2017/) -* [https://www.danielbohannon.com/blog-1/2017/3/12/powershell-execution-argument-obfuscation-how-it-can-make-detection-easier](https://www.danielbohannon.com/blog-1/2017/3/12/powershell-execution-argument-obfuscation-how-it-can-make-detection-easier) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1569.002/atomic_red_team/windows-system.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1569.002/atomic_red_team/windows-system.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-04-08-multiple_users_failing_to_authenticate_from_host_using_kerberos.md b/docs/_posts/2021-04-08-multiple_users_failing_to_authenticate_from_host_using_kerberos.md deleted file mode 100644 index 03972fab52..0000000000 --- a/docs/_posts/2021-04-08-multiple_users_failing_to_authenticate_from_host_using_kerberos.md +++ /dev/null @@ -1,167 +0,0 @@ ---- -title: "Multiple Users Failing To Authenticate From Host Using Kerberos" -excerpt: "Password Spraying -, Brute Force -" -categories: - - Endpoint -last_modified_at: 2021-04-08 -toc: true -toc_label: "" -tags: - - Password Spraying - - Brute Force - - Credential Access - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies one source endpoint failing to authenticate with multiple valid users using the Kerberos protocol. This behavior could represent an adversary performing a Password Spraying attack against an Active Directory environment using Kerberos to obtain initial access or elevate privileges. Event 4771 is generated when the Key Distribution Center fails to issue a Kerberos Ticket Granting Ticket (TGT). Failure code 0x18 stands for `wrong password provided` (the attempted user is a legitimate domain user).\ -The detection calculates the standard deviation for each host and leverages the 3-sigma statistical rule to identify an unusual number of users. To customize this analytic, users can try different combinations of the `bucket` span time and the calculation of the `upperBound` field. This logic can be used for real time security monitoring as well as threat hunting exercises.\ -This detection will only trigger on domain controllers, not on member servers or workstations.\ -The analytics returned fields allow analysts to investigate the event further by providing fields like source ip and attempted user accounts. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-04-08 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 3a91a212-98a9-11eb-b86a-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1110.003](https://attack.mitre.org/techniques/T1110/003/) | Password Spraying | Credential Access | - -| [T1110](https://attack.mitre.org/techniques/T1110/) | Brute Force | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`wineventlog_security` EventCode=4771 Failure_Code=0x18 Account_Name!="*$" -| bucket span=2m _time -| stats dc(Account_Name) AS unique_accounts values(Account_Name) as tried_accounts by _time, Client_Address -| eventstats avg(unique_accounts) as comp_avg , stdev(unique_accounts) as comp_std by Client_Address -| eval upperBound=(comp_avg+comp_std*3) -| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0) -| search isOutlier=1 -| `multiple_users_failing_to_authenticate_from_host_using_kerberos_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) - -> :information_source: -> **multiple_users_failing_to_authenticate_from_host_using_kerberos_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Result_Code -* Account_Name -* Client_Address - - -#### How To Implement -To successfully implement this search, you need to be ingesting Domain Controller and Kerberos events. The Advanced Security Audit policy setting `Audit Kerberos Authentication Service` within `Account Logon` needs to be enabled. - -#### Known False Positives -A host failing to authenticate with multiple valid domain users is not a common behavior for legitimate systems. Possible false positive scenarios include but are not limited to vulnerability scanners, missconfigured systems and multi-user systems like Citrix farms. - -#### Associated Analytic story -* [Active Directory Password Spraying](/stories/active_directory_password_spraying) -* [Active Directory Kerberos Attacks](/stories/active_directory_kerberos_attacks) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | Potential Kerberos based password spraying attack from $Client_Address$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1110/003/](https://attack.mitre.org/techniques/T1110/003/) -* [https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/dn319109(v=ws.11)](https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/dn319109(v=ws.11)) -* [https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4771](https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4771) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_valid_users_kerberos/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_valid_users_kerberos/windows-security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-04-08-winevent_scheduled_task_created_within_public_path.md b/docs/_posts/2021-04-08-winevent_scheduled_task_created_within_public_path.md deleted file mode 100644 index 8298ca7fc7..0000000000 --- a/docs/_posts/2021-04-08-winevent_scheduled_task_created_within_public_path.md +++ /dev/null @@ -1,178 +0,0 @@ ---- -title: "WinEvent Scheduled Task Created Within Public Path" -excerpt: "Scheduled Task -, Scheduled Task/Job -" -categories: - - Endpoint -last_modified_at: 2021-04-08 -toc: true -toc_label: "" -tags: - - Scheduled Task - - Scheduled Task/Job - - Execution - - Persistence - - Privilege Escalation - - Execution - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following query utilizes Windows Security EventCode 4698, `A scheduled task was created`, to identify suspicious tasks registered on Windows either via schtasks.exe OR TaskService with a command to be executed from a user writeable file path.\ -The search will return the first time and last time the task was registered, as well as the `Command` to be executed, `Task Name`, `Author`, `Enabled`, and whether it is `Hidden` or not.\ -schtasks.exe is natively found in `C:\Windows\system32` and `C:\Windows\syswow64`.\ -The following DLL(s) are loaded when schtasks.exe or TaskService is launched -`taskschd.dll`. If found loaded by another process, it is possible a scheduled task is being registered within that process context in memory.\ -Upon triage, identify the task scheduled source. Was it schtasks.exe or was it via TaskService. Review the job created and the Command to be executed. Capture any artifacts on disk and review. Identify any parallel processes within the same timeframe to identify source. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-04-08 -- **Author**: Michael Haag, Splunk -- **ID**: 5d9c6eee-988c-11eb-8253-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1053.005](https://attack.mitre.org/techniques/T1053/005/) | Scheduled Task | Execution, Persistence, Privilege Escalation | - -| [T1053](https://attack.mitre.org/techniques/T1053/) | Scheduled Task/Job | Execution, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`wineventlog_security` EventCode=4698 -| xmlkv Message -| search Command IN ("*\\users\\public\\*", "*\\programdata\\*", "*\\temp\\*", "*\\Windows\\Tasks\\*", "*\\appdata\\*", "*\\perflogs\\*") -| stats count min(_time) as firstTime max(_time) as lastTime by dest, Task_Name, Command, Author, Enabled, Hidden -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `winevent_scheduled_task_created_within_public_path_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **winevent_scheduled_task_created_within_public_path_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* dest -* Task_Name -* Description -* Command - - -#### How To Implement -To successfully implement this search, you need to be ingesting Windows Security Event Logs with 4698 EventCode enabled. The Windows TA is also required. - -#### Known False Positives -False positives are possible if legitimate applications are allowed to register tasks in public paths. Filter as needed based on paths that are used legitimately. - -#### Associated Analytic story -* [Windows Persistence Techniques](/stories/windows_persistence_techniques) -* [Ransomware](/stories/ransomware) -* [Ryuk Ransomware](/stories/ryuk_ransomware) -* [IcedID](/stories/icedid) -* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) -* [Industroyer2](/stories/industroyer2) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 70.0 | 70 | 100 | A windows scheduled task was created (task name=$Task_Name$) on $dest$ by the following command: $Command$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://research.checkpoint.com/2021/irans-apt34-returns-with-an-updated-arsenal/](https://research.checkpoint.com/2021/irans-apt34-returns-with-an-updated-arsenal/) -* [https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=4698](https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=4698) -* [https://redcanary.com/threat-detection-report/techniques/scheduled-task-job/](https://redcanary.com/threat-detection-report/techniques/scheduled-task-job/) -* [https://docs.microsoft.com/en-us/windows/win32/taskschd/time-trigger-example--scripting-?redirectedfrom=MSDN](https://docs.microsoft.com/en-us/windows/win32/taskschd/time-trigger-example--scripting-?redirectedfrom=MSDN) -* [https://app.any.run/tasks/e26f1b2e-befa-483b-91d2-e18636e2faf3/](https://app.any.run/tasks/e26f1b2e-befa-483b-91d2-e18636e2faf3/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/taskschedule/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/taskschedule/windows-security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-04-12-excel_spawning_powershell.md b/docs/_posts/2021-04-12-excel_spawning_powershell.md deleted file mode 100644 index a7a8420e93..0000000000 --- a/docs/_posts/2021-04-12-excel_spawning_powershell.md +++ /dev/null @@ -1,169 +0,0 @@ ---- -title: "Excel Spawning PowerShell" -excerpt: "Security Account Manager -, OS Credential Dumping -" -categories: - - Endpoint -last_modified_at: 2021-04-12 -toc: true -toc_label: "" -tags: - - Security Account Manager - - OS Credential Dumping - - Credential Access - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following detection identifies Microsoft Excel spawning PowerShell. Typically, this is not common behavior and not default with Excel.exe. Excel.exe will generally be found in the following path `C:\Program Files\Microsoft Office\root\Office16` (version will vary). PowerShell spawning from Excel.exe is common for a spearphishing attachment and is actively used. Albeit, the command executed will most likely be encoded and captured via another detection. During triage, review parallel processes and identify any files that may have been written. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-04-12 -- **Author**: Michael Haag, Splunk -- **ID**: 42d40a22-9be3-11eb-8f08-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1003.002](https://attack.mitre.org/techniques/T1003/002/) | Security Account Manager | Credential Access | - -| [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count values(Processes.process) min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name="excel.exe" `process_powershell` by Processes.parent_process Processes.process_name Processes.user Processes.dest Processes.original_file_name -| `drop_dm_object_name("Processes")` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -| `excel_spawning_powershell_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml) - -> :information_source: -> **excel_spawning_powershell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -False positives should be limited, but if any are present, filter as needed. - -#### Associated Analytic story -* [Spearphishing Attachments](/stories/spearphishing_attachments) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$, indicating potential suspicious macro execution. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://redcanary.com/threat-detection-report/techniques/powershell/](https://redcanary.com/threat-detection-report/techniques/powershell/) -* [https://attack.mitre.org/techniques/T1566/001/](https://attack.mitre.org/techniques/T1566/001/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/excel_spawning_powershell.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-04-12-excel_spawning_windows_script_host.md b/docs/_posts/2021-04-12-excel_spawning_windows_script_host.md deleted file mode 100644 index 881449035a..0000000000 --- a/docs/_posts/2021-04-12-excel_spawning_windows_script_host.md +++ /dev/null @@ -1,164 +0,0 @@ ---- -title: "Excel Spawning Windows Script Host" -excerpt: "Security Account Manager -, OS Credential Dumping -" -categories: - - Endpoint -last_modified_at: 2021-04-12 -toc: true -toc_label: "" -tags: - - Security Account Manager - - OS Credential Dumping - - Credential Access - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following detection identifies Microsoft Excel spawning Windows Script Host - `cscript.exe` or `wscript.exe`. Typically, this is not common behavior and not default with Excel.exe. Excel.exe will generally be found in the following path `C:\Program Files\Microsoft Office\root\Office16` (version will vary). `cscript.exe` or `wscript.exe` default location is `c:\windows\system32\` or c:windows\syswow64`. `cscript.exe` or `wscript.exe` spawning from Excel.exe is common for a spearphishing attachment and is actively used. Albeit, the command-line executed will most likely be obfuscated and captured via another detection. During triage, review parallel processes and identify any files that may have been written. Review the reputation of the remote destination and block accordingly. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-04-12 -- **Author**: Michael Haag, Splunk -- **ID**: 57fe880a-9be3-11eb-9bf3-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1003.002](https://attack.mitre.org/techniques/T1003/002/) | Security Account Manager | Credential Access | - -| [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count values(Processes.process) min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name="excel.exe" Processes.process_name IN ("cscript.exe", "wscript.exe") by Processes.parent_process Processes.process_name Processes.user Processes.dest -| `drop_dm_object_name("Processes")` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -| `excel_spawning_windows_script_host_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **excel_spawning_windows_script_host_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* process_name -* process_id -* parent_process_name -* dest -* user -* parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -False positives should be limited, but if any are present, filter as needed. In some instances, `cscript.exe` is used for legitimate business practices. - -#### Associated Analytic story -* [Spearphishing Attachments](/stories/spearphishing_attachments) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$, indicating potential suspicious macro execution. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://app.any.run/tasks/8ecfbc29-03d0-421c-a5bf-3905d29192a2/](https://app.any.run/tasks/8ecfbc29-03d0-421c-a5bf-3905d29192a2/) -* [https://attack.mitre.org/techniques/T1566/001/](https://attack.mitre.org/techniques/T1566/001/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/excel_spawning_windows_script_host.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-04-12-winevent_scheduled_task_created_to_spawn_shell.md b/docs/_posts/2021-04-12-winevent_scheduled_task_created_to_spawn_shell.md deleted file mode 100644 index 5ff4bdb821..0000000000 --- a/docs/_posts/2021-04-12-winevent_scheduled_task_created_to_spawn_shell.md +++ /dev/null @@ -1,174 +0,0 @@ ---- -title: "WinEvent Scheduled Task Created to Spawn Shell" -excerpt: "Scheduled Task -, Scheduled Task/Job -" -categories: - - Endpoint -last_modified_at: 2021-04-12 -toc: true -toc_label: "" -tags: - - Scheduled Task - - Scheduled Task/Job - - Execution - - Persistence - - Privilege Escalation - - Execution - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following query utilizes Windows Security EventCode 4698, `A scheduled task was created`, to identify suspicious tasks registered on Windows either via schtasks.exe OR TaskService with a command to be executed with a native Windows shell (PowerShell, Cmd, Wscript, Cscript).\ -The search will return the first time and last time the task was registered, as well as the `Command` to be executed, `Task Name`, `Author`, `Enabled`, and whether it is `Hidden` or not.\ -schtasks.exe is natively found in `C:\Windows\system32` and `C:\Windows\syswow64`.\ -The following DLL(s) are loaded when schtasks.exe or TaskService is launched -`taskschd.dll`. If found loaded by another process, it is possible a scheduled task is being registered within that process context in memory.\ -Upon triage, identify the task scheduled source. Was it schtasks.exe or via TaskService? Review the job created and the Command to be executed. Capture any artifacts on disk and review. Identify any parallel processes within the same timeframe to identify source. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-04-12 -- **Author**: Michael Haag, Splunk -- **ID**: 203ef0ea-9bd8-11eb-8201-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1053.005](https://attack.mitre.org/techniques/T1053/005/) | Scheduled Task | Execution, Persistence, Privilege Escalation | - -| [T1053](https://attack.mitre.org/techniques/T1053/) | Scheduled Task/Job | Execution, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`wineventlog_security` EventCode=4698 -| xmlkv Message -| search Command IN ("*powershell.exe*", "*wscript.exe*", "*cscript.exe*", "*cmd.exe*", "*sh.exe*", "*ksh.exe*", "*zsh.exe*", "*bash.exe*", "*scrcons.exe*", "*pwsh.exe*") -| stats count min(_time) as firstTime max(_time) as lastTime by dest, Task_Name, Command, Author, Enabled, Hidden -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `winevent_scheduled_task_created_to_spawn_shell_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **winevent_scheduled_task_created_to_spawn_shell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* dest -* Task_Name -* Description -* Command - - -#### How To Implement -To successfully implement this search, you need to be ingesting Windows Security Event Logs with 4698 EventCode enabled. The Windows TA is also required. - -#### Known False Positives -False positives are possible if legitimate applications are allowed to register tasks that call a shell to be spawned. Filter as needed based on command-line or processes that are used legitimately. - -#### Associated Analytic story -* [Windows Persistence Techniques](/stories/windows_persistence_techniques) -* [Ransomware](/stories/ransomware) -* [Ryuk Ransomware](/stories/ryuk_ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 70.0 | 70 | 100 | A windows scheduled task was created (task name=$Task_Name$) on $dest$ by the following command: $Command$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://research.checkpoint.com/2021/irans-apt34-returns-with-an-updated-arsenal/](https://research.checkpoint.com/2021/irans-apt34-returns-with-an-updated-arsenal/) -* [https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=4698](https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=4698) -* [https://redcanary.com/threat-detection-report/techniques/scheduled-task-job/](https://redcanary.com/threat-detection-report/techniques/scheduled-task-job/) -* [https://docs.microsoft.com/en-us/windows/win32/taskschd/time-trigger-example--scripting-?redirectedfrom=MSDN](https://docs.microsoft.com/en-us/windows/win32/taskschd/time-trigger-example--scripting-?redirectedfrom=MSDN) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/atomic_red_team/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/atomic_red_team/windows-security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-04-12-winword_spawning_powershell.md b/docs/_posts/2021-04-12-winword_spawning_powershell.md deleted file mode 100644 index 043a43314d..0000000000 --- a/docs/_posts/2021-04-12-winword_spawning_powershell.md +++ /dev/null @@ -1,173 +0,0 @@ ---- -title: "Winword Spawning PowerShell" -excerpt: "Phishing -, Spearphishing Attachment -" -categories: - - Endpoint -last_modified_at: 2021-04-12 -toc: true -toc_label: "" -tags: - - Phishing - - Spearphishing Attachment - - Initial Access - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following detection identifies Microsoft Word spawning PowerShell. Typically, this is not common behavior and not default with winword.exe. Winword.exe will generally be found in the following path `C:\Program Files\Microsoft Office\root\Office16` (version will vary). PowerShell spawning from winword.exe is common for a spearphishing attachment and is actively used. Albeit, the command executed will most likely be encoded and captured via another detection. During triage, review parallel processes and identify any files that may have been written. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-04-12 -- **Author**: Michael Haag, Splunk -- **ID**: b2c950b8-9be2-11eb-8658-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | - -| [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name="winword.exe" `process_powershell` by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `winword_spawning_powershell_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml) - -> :information_source: -> **winword_spawning_powershell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -False positives should be limited, but if any are present, filter as needed. - -#### Associated Analytic story -* [Spearphishing Attachments](/stories/spearphishing_attachments) -* [DarkCrystal RAT](/stories/darkcrystal_rat) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 70.0 | 70 | 100 | $parent_process_name$ on $dest$ by $user$ launched the following powershell process: $process_name$ which is very common in spearphishing attacks | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://redcanary.com/threat-detection-report/techniques/powershell/](https://redcanary.com/threat-detection-report/techniques/powershell/) -* [https://attack.mitre.org/techniques/T1566/001/](https://attack.mitre.org/techniques/T1566/001/) -* [https://app.any.run/tasks/b79fa381-f35c-4b3e-8d02-507e7ee7342f/](https://app.any.run/tasks/b79fa381-f35c-4b3e-8d02-507e7ee7342f/) -* [https://app.any.run/tasks/181ac90b-0898-4631-8701-b778a30610ad/](https://app.any.run/tasks/181ac90b-0898-4631-8701-b778a30610ad/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/winword_spawning_powershell.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-04-12-winword_spawning_windows_script_host.md b/docs/_posts/2021-04-12-winword_spawning_windows_script_host.md deleted file mode 100644 index 1b841987af..0000000000 --- a/docs/_posts/2021-04-12-winword_spawning_windows_script_host.md +++ /dev/null @@ -1,163 +0,0 @@ ---- -title: "Winword Spawning Windows Script Host" -excerpt: "Phishing -, Spearphishing Attachment -" -categories: - - Endpoint -last_modified_at: 2021-04-12 -toc: true -toc_label: "" -tags: - - Phishing - - Spearphishing Attachment - - Initial Access - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following detection identifies Microsoft Winword.exe spawning Windows Script Host - `cscript.exe` or `wscript.exe`. Typically, this is not common behavior and not default with Winword.exe. Winword.exe will generally be found in the following path `C:\Program Files\Microsoft Office\root\Office16` (version will vary). `cscript.exe` or `wscript.exe` default location is `c:\windows\system32\` or c:windows\syswow64\`. `cscript.exe` or `wscript.exe` spawning from Winword.exe is common for a spearphishing attachment and is actively used. Albeit, the command-line executed will most likely be obfuscated and captured via another detection. During triage, review parallel processes and identify any files that may have been written. Review the reputation of the remote destination and block accordingly. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-04-12 -- **Author**: Michael Haag, Splunk -- **ID**: 637e1b5c-9be1-11eb-9c32-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | - -| [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name="winword.exe" Processes.process_name IN ("cscript.exe", "wscript.exe") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `winword_spawning_windows_script_host_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **winword_spawning_windows_script_host_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* process_name -* process_id -* parent_process_name -* dest -* user -* parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -There will be limited false positives and it will be different for every environment. Tune by child process or command-line as needed. - -#### Associated Analytic story -* [Spearphishing Attachments](/stories/spearphishing_attachments) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 70.0 | 70 | 100 | User $user$ on $dest$ spawned Windows Script Host from Winword.exe | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1566/001/](https://attack.mitre.org/techniques/T1566/001/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_wsh.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_wsh.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/winword_spawning_windows_script_host.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-04-13-aws_excessive_security_scanning.md b/docs/_posts/2021-04-13-aws_excessive_security_scanning.md deleted file mode 100644 index af0757675b..0000000000 --- a/docs/_posts/2021-04-13-aws_excessive_security_scanning.md +++ /dev/null @@ -1,162 +0,0 @@ ---- -title: "AWS Excessive Security Scanning" -excerpt: "Cloud Service Discovery -" -categories: - - Cloud -last_modified_at: 2021-04-13 -toc: true -toc_label: "" -tags: - - Cloud Service Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for AWS CloudTrail events and analyse the amount of eventNames which starts with Describe by a single user. This indicates that this user scans the configuration of your AWS cloud environment. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-04-13 -- **Author**: Patrick Bareiss, Splunk -- **ID**: 1fdd164a-def8-4762-83a9-9ffe24e74d5a - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1526](https://attack.mitre.org/techniques/T1526/) | Cloud Service Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.DS -* PR.AC -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 13 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cloudtrail` eventName=Describe* OR eventName=List* OR eventName=Get* -| stats dc(eventName) as dc_events min(_time) as firstTime max(_time) as lastTime values(eventName) as eventName values(src) as src values(userAgent) as userAgent by user userIdentity.arn -| where dc_events > 50 -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -|`aws_excessive_security_scanning_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) - -> :information_source: -> **aws_excessive_security_scanning_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* eventName -* src -* userAgent -* user -* userIdentity.arn - - -#### How To Implement -You must install splunk AWS add on and Splunk App for AWS. This search works with AWS CloudTrail logs. - -#### Known False Positives -While this search has no known false positives. - -#### Associated Analytic story -* [AWS User Monitoring](/stories/aws_user_monitoring) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 18.0 | 30 | 60 | user $user$ has excessive number of api calls $dc_events$ from these IP addresses $src$, violating the threshold of 50, using the following commands $command$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/aquasecurity/cloudsploit](https://github.com/aquasecurity/cloudsploit) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1526/aws_security_scanner/aws_security_scanner.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1526/aws_security_scanner/aws_security_scanner.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/aws_excessive_security_scanning.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-04-13-multiple_users_attempting_to_authenticate_using_explicit_credentials.md b/docs/_posts/2021-04-13-multiple_users_attempting_to_authenticate_using_explicit_credentials.md deleted file mode 100644 index 9df5b65a14..0000000000 --- a/docs/_posts/2021-04-13-multiple_users_attempting_to_authenticate_using_explicit_credentials.md +++ /dev/null @@ -1,119 +0,0 @@ ---- -title: "Multiple Users Attempting To Authenticate Using Explicit Credentials" -excerpt: "Password Spraying -, Brute Force -" -categories: - - Endpoint -last_modified_at: 2021-04-13 -toc: true -toc_label: "" -tags: - - Password Spraying - - Brute Force - - Credential Access - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies a source user failing to authenticate with multiple users using explicit credentials on a host. This behavior could represent an adversary performing a Password Spraying attack against an Active Directory environment to obtain initial access or elevate privileges. Event 4648 is generated when a process attempts an account logon by explicitly specifying that accounts credentials. This event generates on domain controllers, member servers, and workstations.\ -The detection calculates the standard deviation for each host and leverages the 3-sigma statistical rule to identify an unusual number of users. To customize this analytic, users can try different combinations of the `bucket` span time and the calculation of the `upperBound` field. This logic can be used for real time security monitoring as well as threat hunting exercises.\ -This detection will trigger on the potenfially malicious host, perhaps controlled via a trojan or operated by an insider threat, from where a password spraying attack is being executed.\ -The analytics returned fields allow analysts to investigate the event further by providing fields like source account, attempted user accounts and the endpoint were the behavior was identified. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/object-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: -- **Last Updated**: 2021-04-13 -- **Author**: Mauricio Velazco, Splunk -- **ID**: e61918fa-9ca4-11eb-836c-acde48001122 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1110.003](https://attack.mitre.org/techniques/T1110/003/) | Password Spraying | Credential Access | - -| [T1110](https://attack.mitre.org/techniques/T1110/) | Brute Force | Credential Access | - -#### Search - -``` - `wineventlog_security` EventCode=4648 -| bucket span=2m _time -| eval Source_Account = mvindex(Account_Name, 0) -| eval Destination_Account = mvindex(Account_Name, 1) -| search Source_Account != "*$" Source_Account !="-" Destination_Account !="*$" -| stats dc(Destination_Account) AS unique_accounts values(Destination_Account) as tried_account by _time, ComputerName, Source_Account -| eventstats avg(unique_accounts) as comp_avg , stdev(unique_accounts) as comp_std by ComputerName -| eval upperBound=(comp_avg+comp_std*3) -| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0) -| search isOutlier=1 -| `multiple_users_attempting_to_authenticate_using_explicit_credentials_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) - -Note that `multiple_users_attempting_to_authenticate_using_explicit_credentials_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Security_ID -* Account_Name -* ComputerName - - -#### How To Implement -To successfully implement this search, you need to be ingesting Windows Event Logs from domain controllers as well as member servers and workstations. The Advanced Security Audit policy setting `Audit Logon` within `Logon/Logoff` needs to be enabled. - -#### Known False Positives -A source user failing attempting to authenticate multiple users on a host is not a common behavior for regular systems. Some applications, however, may exhibit this behavior in which case sets of users hosts can be added to an allow list. Possible false positive scenarios include systems where several users connect to like Mail servers, identity providers, remote desktop services, Citrix, etc. - -#### Associated Analytic story -* [Active Directory Password Spraying](/stories/active_directory_password_spraying) - - -#### Kill Chain Phase -* Exploitation - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | Potential password spraying attack from $ComputerName$ | - - - - -#### Reference - -* [https://attack.mitre.org/techniques/T1110/003/](https://attack.mitre.org/techniques/T1110/003/) -* [https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4648](https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4648) -* [https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/basic-audit-logon-events](https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/basic-audit-logon-events) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_explicit_credential_spray/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_explicit_credential_spray/windows-security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-04-13-multiple_users_failing_to_authenticate_from_host_using_ntlm.md b/docs/_posts/2021-04-13-multiple_users_failing_to_authenticate_from_host_using_ntlm.md deleted file mode 100644 index ee94ae6d32..0000000000 --- a/docs/_posts/2021-04-13-multiple_users_failing_to_authenticate_from_host_using_ntlm.md +++ /dev/null @@ -1,166 +0,0 @@ ---- -title: "Multiple Users Failing To Authenticate From Host Using NTLM" -excerpt: "Password Spraying -, Brute Force -" -categories: - - Endpoint -last_modified_at: 2021-04-13 -toc: true -toc_label: "" -tags: - - Password Spraying - - Brute Force - - Credential Access - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies one source endpoint failing to authenticate with multiple valid users using the NTLM protocol. This behavior could represent an adversary performing a Password Spraying attack against an Active Directory environment using NTLM to obtain initial access or elevate privileges. Event 4776 is generated on the computer that is authoritative for the provided credentials. For domain accounts, the domain controller is authoritative. For local accounts, the local computer is authoritative. Error code 0xC000006A means: misspelled or bad password (the attempted user is a legitimate domain user).\ -The detection calculates the standard deviation for each host and leverages the 3-sigma statistical rule to identify an unusual number of users. To customize this analytic, users can try different combinations of the `bucket` span time and the calculation of the `upperBound` field. This logic can be used for real time security monitoring as well as threat hunting exercises.\ -This detection will only trigger on domain controllers, not on member servers or workstations.\ -The analytics returned fields allow analysts to investigate the event further by providing fields like source workstation name and attempted user accounts. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-04-13 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 7ed272a4-9c77-11eb-af22-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1110.003](https://attack.mitre.org/techniques/T1110/003/) | Password Spraying | Credential Access | - -| [T1110](https://attack.mitre.org/techniques/T1110/) | Brute Force | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - `wineventlog_security` EventCode=4776 Logon_Account!="*$" 0xC000006A action=failure -| bucket span=2m _time -| stats dc(Logon_Account) AS unique_accounts values(Logon_Account) as tried_accounts by _time, Source_Workstation -| eventstats avg(unique_accounts) as comp_avg , stdev(unique_accounts) as comp_std by Source_Workstation -| eval upperBound=(comp_avg+comp_std*3) -| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0) -| search isOutlier=1 -| `multiple_users_failing_to_authenticate_from_host_using_ntlm_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) - -> :information_source: -> **multiple_users_failing_to_authenticate_from_host_using_ntlm_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* action -* Logon_Account -* Source_Workstation - - -#### How To Implement -To successfully implement this search, you need to be ingesting Domain Controller events. The Advanced Security Audit policy setting `Audit Credential Validation` within `Account Logon` needs to be enabled. - -#### Known False Positives -A host failing to authenticate with multiple valid domain users is not a common behavior for legitimate systems. Possible false positive scenarios include but are not limited to vulnerability scanners and missconfigured systems. If this detection triggers on a host other than a Domain Controller, the behavior could represent a password spraying attack against the host's local accounts. - -#### Associated Analytic story -* [Active Directory Password Spraying](/stories/active_directory_password_spraying) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | Potential NTLM based password spraying attack from $Source_Workstation$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1110/003/](https://attack.mitre.org/techniques/T1110/003/) -* [https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-credential-validation](https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-credential-validation) -* [https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4776](https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4776) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_valid_users_ntlm/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_valid_users_ntlm/windows-security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-04-13-multiple_users_failing_to_authenticate_from_process.md b/docs/_posts/2021-04-13-multiple_users_failing_to_authenticate_from_process.md deleted file mode 100644 index c6dacc87f6..0000000000 --- a/docs/_posts/2021-04-13-multiple_users_failing_to_authenticate_from_process.md +++ /dev/null @@ -1,172 +0,0 @@ ---- -title: "Multiple Users Failing To Authenticate From Process" -excerpt: "Password Spraying -, Brute Force -" -categories: - - Endpoint -last_modified_at: 2021-04-13 -toc: true -toc_label: "" -tags: - - Password Spraying - - Brute Force - - Credential Access - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies a source process name failing to authenticate with multiple users. This behavior could represent an adversary performing a Password Spraying attack against an Active Directory environment to obtain initial access or elevate privileges. Event 4625 generates on domain controllers, member servers, and workstations when an account fails to logon. Logon Type 2 describes an iteractive logon attempt.\ -The detection calculates the standard deviation for each host and leverages the 3-sigma statistical rule to identify an unusual number of users. To customize this analytic, users can try different combinations of the `bucket` span time and the calculation of the `upperBound` field. This logic can be used for real time security monitoring as well as threat hunting exercises.\ -This detection will trigger on the potenfially malicious host, perhaps controlled via a trojan or operated by an insider threat, from where a password spraying attack is being executed. This could be a domain controller as well as a member server or workstation.\ -The analytics returned fields allow analysts to investigate the event further by providing fields like source process name, source account and attempted user accounts. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-04-13 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 9015385a-9c84-11eb-bef2-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1110.003](https://attack.mitre.org/techniques/T1110/003/) | Password Spraying | Credential Access | - -| [T1110](https://attack.mitre.org/techniques/T1110/) | Brute Force | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - `wineventlog_security` EventCode=4625 Logon_Type=2 Caller_Process_Name!="-" -| bucket span=2m _time -| eval Source_Account = mvindex(Account_Name, 0) -| eval Destination_Account = mvindex(Account_Name, 1) -| stats dc(Destination_Account) AS unique_accounts values(Account_Name) as tried_accounts by _time, Caller_Process_Name, Source_Account, ComputerName -| eventstats avg(unique_accounts) as comp_avg , stdev(unique_accounts) as comp_std by Caller_Process_Name, Source_Account, ComputerName -| eval upperBound=(comp_avg+comp_std*3) -| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0) -| search isOutlier=1 -| `multiple_users_failing_to_authenticate_from_process_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) - -> :information_source: -> **multiple_users_failing_to_authenticate_from_process_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Logon_Type -* Caller_Process_Name -* Security_ID -* Account_Name -* ComputerName - - -#### How To Implement -To successfully implement this search, you need to be ingesting Windows Event Logs from domain controllers aas well as member servers and workstations. The Advanced Security Audit policy setting `Audit Logon` within `Logon/Logoff` needs to be enabled. - -#### Known False Positives -A process failing to authenticate with multiple users is not a common behavior for legitimate user sessions. Possible false positive scenarios include but are not limited to vulnerability scanners and missconfigured systems. - -#### Associated Analytic story -* [Active Directory Password Spraying](/stories/active_directory_password_spraying) -* [Insider Threat](/stories/insider_threat) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | Potential password spraying attack from $ComputerName$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1110/003/](https://attack.mitre.org/techniques/T1110/003/) -* [https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4625](https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4625) -* [https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=4625](https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=4625) -* [https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/basic-audit-logon-events](https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/basic-audit-logon-events) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_multiple_users_from_process/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_multiple_users_from_process/windows-security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-04-13-multiple_users_remotely_failing_to_authenticate_from_host.md b/docs/_posts/2021-04-13-multiple_users_remotely_failing_to_authenticate_from_host.md deleted file mode 100644 index fcaf6e161c..0000000000 --- a/docs/_posts/2021-04-13-multiple_users_remotely_failing_to_authenticate_from_host.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: "Multiple Users Remotely Failing To Authenticate From Host" -excerpt: "Password Spraying -, Brute Force -" -categories: - - Endpoint -last_modified_at: 2021-04-13 -toc: true -toc_label: "" -tags: - - Password Spraying - - Brute Force - - Credential Access - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies a source host failing to authenticate against a remote host with multiple users. This behavior could represent an adversary performing a Password Spraying attack against an Active Directory environment to obtain initial access or elevate privileges. Event 4625 documents each and every failed attempt to logon to the local computer. This event generates on domain controllers, member servers, and workstations. Logon Type 3 describes an remote authentication attempt.\ -The detection calculates the standard deviation for each host and leverages the 3-sigma statistical rule to identify an unusual number of users. To customize this analytic, users can try different combinations of the `bucket` span time and the calculation of the `upperBound` field. This logic can be used for real time security monitoring as well as threat hunting exercises.\ -This detection will trigger on the host that is the target of the password spraying attack. This could be a domain controller as well as a member server or workstation.\ -The analytics returned fields allow analysts to investigate the event further by providing fields like source process name, source account and attempted user accounts. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-04-13 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 80f9d53e-9ca1-11eb-b0d6-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1110.003](https://attack.mitre.org/techniques/T1110/003/) | Password Spraying | Credential Access | - -| [T1110](https://attack.mitre.org/techniques/T1110/) | Brute Force | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - `wineventlog_security` EventCode=4625 Logon_Type=3 Source_Network_Address!="-" -| bucket span=2m _time -| eval Destination_Account = mvindex(Account_Name, 1) -| stats dc(Destination_Account) AS unique_accounts values(Destination_Account) as tried_accounts by _time, Source_Network_Address, ComputerName -| eventstats avg(unique_accounts) as comp_avg , stdev(unique_accounts) as comp_std by Source_Network_Address, ComputerName -| eval upperBound=(comp_avg+comp_std*3) -| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0) -| search isOutlier=1 -| `multiple_users_remotely_failing_to_authenticate_from_host_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) - -> :information_source: -> **multiple_users_remotely_failing_to_authenticate_from_host_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Logon_Type -* Security_ID -* Account_Name -* ComputerName -* Source_Network_Address - - -#### How To Implement -To successfully implement this search, you need to be ingesting Windows Event Logs from domain controllers as as well as member servers and workstations. The Advanced Security Audit policy setting `Audit Logon` within `Logon/Logoff` needs to be enabled. - -#### Known False Positives -A host failing to authenticate with multiple valid users against a remote host is not a common behavior for legitimate systems. Possible false positive scenarios include but are not limited to vulnerability scanners, remote administration tools, missconfigyred systems, etc. - -#### Associated Analytic story -* [Active Directory Password Spraying](/stories/active_directory_password_spraying) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | Potential password spraying attack on $ComputerName$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1110/003/](https://attack.mitre.org/techniques/T1110/003/) -* [https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4625](https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4625) -* [https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=4625](https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=4625) -* [https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/basic-audit-logon-events](https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/basic-audit-logon-events) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_remote_spray/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_remote_spray/windows-security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-04-13-office_application_spawn_rundll32_process.md b/docs/_posts/2021-04-13-office_application_spawn_rundll32_process.md deleted file mode 100644 index 75a6897250..0000000000 --- a/docs/_posts/2021-04-13-office_application_spawn_rundll32_process.md +++ /dev/null @@ -1,171 +0,0 @@ ---- -title: "Office Application Spawn rundll32 process" -excerpt: "Phishing -, Spearphishing Attachment -" -categories: - - Endpoint -last_modified_at: 2021-04-13 -toc: true -toc_label: "" -tags: - - Phishing - - Spearphishing Attachment - - Initial Access - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -this detection was designed to identifies suspicious spawned process of known MS office application due to macro or malicious code. this technique can be seen in so many malware like trickbot that used MS office as its weapon or attack vector to initially infect the machines. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-04-13 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 958751e4-9c5f-11eb-b103-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | - -| [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.parent_process_name = "winword.exe" OR Processes.parent_process_name = "excel.exe" OR Processes.parent_process_name = "powerpnt.exe") AND `process_rundll32` by Processes.parent_process Processes.process_name Processes.process_id Processes.process_guid Processes.process Processes.user Processes.dest -| `drop_dm_object_name("Processes")` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -| `office_application_spawn_rundll32_process_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [process_rundll32](https://github.com/splunk/security_content/blob/develop/macros/process_rundll32.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **office_application_spawn_rundll32_process_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Spearphishing Attachments](/stories/spearphishing_attachments) -* [Trickbot](/stories/trickbot) -* [IcedID](/stories/icedid) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 63.0 | 70 | 90 | Office application spawning rundll32.exe on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://any.run/malware-trends/trickbot](https://any.run/malware-trends/trickbot) -* [https://any.run/report/47561b4e949041eff0a0f4693c59c81726591779fe21183ae9185b5eb6a69847/aba3722a-b373-4dae-8273-8730fb40cdbe](https://any.run/report/47561b4e949041eff0a0f4693c59c81726591779fe21183ae9185b5eb6a69847/aba3722a-b373-4dae-8273-8730fb40cdbe) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/datasets/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/datasets/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/office_application_spawn_rundll32_process.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-04-13-windows_users_authenticate_using_explicit_credentials.md b/docs/_posts/2021-04-13-windows_users_authenticate_using_explicit_credentials.md deleted file mode 100644 index eeeff83e47..0000000000 --- a/docs/_posts/2021-04-13-windows_users_authenticate_using_explicit_credentials.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: "Windows Users Authenticate Using Explicit Credentials" -excerpt: "Password Spraying -, Brute Force -" -categories: - - Endpoint -last_modified_at: 2021-04-13 -toc: true -toc_label: "" -tags: - - Password Spraying - - Brute Force - - Credential Access - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies a source user failing to authenticate with multiple users using explicit credentials on a host. This behavior could represent an adversary performing a Password Spraying attack against an Active Directory environment to obtain initial access or elevate privileges. Event 4648 is generated when a process attempts an account logon by explicitly specifying that accounts credentials. This event generates on domain controllers, member servers, and workstations.\ -The detection calculates the standard deviation for each host and leverages the 3-sigma statistical rule to identify an unusual number of users. To customize this analytic, users can try different combinations of the `bucket` span time and the calculation of the `upperBound` field. This logic can be used for real time security monitoring as well as threat hunting exercises.\ -This detection will trigger on the potenfially malicious host, perhaps controlled via a trojan or operated by an insider threat, from where a password spraying attack is being executed.\ -The analytics returned fields allow analysts to investigate the event further by providing fields like source account, attempted user accounts and the endpoint were the behavior was identified. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-04-13 -- **Author**: Mauricio Velazco, Splunk -- **ID**: e61918fa-9ca4-11eb-836c-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1110.003](https://attack.mitre.org/techniques/T1110/003/) | Password Spraying | Credential Access | - -| [T1110](https://attack.mitre.org/techniques/T1110/) | Brute Force | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - `wineventlog_security` EventCode=4648 -| bucket span=2m _time -| eval Source_Account = mvindex(Account_Name, 0) -| eval Destination_Account = mvindex(Account_Name, 1) -| search Source_Account != "*$" Source_Account !="-" Destination_Account !="*$" -| stats dc(Destination_Account) AS unique_accounts values(Destination_Account) as tried_account by _time, ComputerName, Source_Account -| eventstats avg(unique_accounts) as comp_avg , stdev(unique_accounts) as comp_std by ComputerName -| eval upperBound=(comp_avg+comp_std*3) -| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0) -| search isOutlier=1 -| `windows_users_authenticate_using_explicit_credentials_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) - -> :information_source: -> **windows_users_authenticate_using_explicit_credentials_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Security_ID -* Account_Name -* ComputerName - - -#### How To Implement -To successfully implement this search, you need to be ingesting Windows Event Logs from domain controllers as well as member servers and workstations. The Advanced Security Audit policy setting `Audit Logon` within `Logon/Logoff` needs to be enabled. - -#### Known False Positives -A source user failing attempting to authenticate multiple users on a host is not a common behavior for regular systems. Some applications, however, may exhibit this behavior in which case sets of users hosts can be added to an allow list. Possible false positive scenarios include systems where several users connect to like Mail servers, identity providers, remote desktop services, Citrix, etc. - -#### Associated Analytic story -* [Active Directory Password Spraying](/stories/active_directory_password_spraying) -* [Insider Threat](/stories/insider_threat) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | Potential password spraying attack from $ComputerName$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1110/003/](https://attack.mitre.org/techniques/T1110/003/) -* [https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4648](https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4648) -* [https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/basic-audit-logon-events](https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/basic-audit-logon-events) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_explicit_credential_spray/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_explicit_credential_spray/windows-security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_users_authenticate_using_explicit_credentials.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-04-14-multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.md b/docs/_posts/2021-04-14-multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.md deleted file mode 100644 index 0b3334caad..0000000000 --- a/docs/_posts/2021-04-14-multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.md +++ /dev/null @@ -1,115 +0,0 @@ ---- -title: "Multiple Disabled Users Failing To Authenticate From Host Using Kerberos" -excerpt: "Password Spraying -, Brute Force -" -categories: - - Endpoint -last_modified_at: 2021-04-14 -toc: true -toc_label: "" -tags: - - Password Spraying - - Brute Force - - Credential Access - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies one source endpoint failing to authenticate with multiple disabled domain users using the Kerberos protocol. This behavior could represent an adversary performing a Password Spraying attack against an Active Directory environment using Kerberos to obtain initial access or elevate privileges. As attackers progress in a breach, mistakes will be made. In certain scenarios, adversaries may execute a password spraying attack against disabled users. Event 4768 is generated every time the Key Distribution Center issues a Kerberos Ticket Granting Ticket (TGT). Failure code `0x12` stands for `clients credentials have been revoked` (account disabled, expired or locked out).\ -The detection calculates the standard deviation for each host and leverages the 3-sigma statistical rule to identify an unusual number of users. To customize this analytic, users can try different combinations of the `bucket` span time and the calculation of the `upperBound` field. This logic can be used for real time security monitoring as well as threat hunting exercises.\ -This detection will only trigger on domain controllers, not on member servers or workstations.\ -The analytics returned fields allow analysts to investigate the event further by providing fields like source ip and attempted user accounts. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/object-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: -- **Last Updated**: 2021-04-14 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 98f22d82-9d62-11eb-9fcf-acde48001122 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1110.003](https://attack.mitre.org/techniques/T1110/003/) | Password Spraying | Credential Access | - -| [T1110](https://attack.mitre.org/techniques/T1110/) | Brute Force | Credential Access | - -#### Search - -``` -`wineventlog_security` EventCode=4768 Account_Name!="*$" Result_Code=0x12 -| bucket span=2m _time -| stats dc(Account_Name) AS unique_accounts values(Account_Name) as tried_accounts by _time, Client_Address -| eventstats avg(unique_accounts) as comp_avg , stdev(unique_accounts) as comp_std by Client_Address -| eval upperBound=(comp_avg+comp_std*3) -| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0) -| search isOutlier=1 -| `multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) - -Note that `multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Result_Code -* Account_Name -* Client_Address - - -#### How To Implement -To successfully implement this search, you need to be ingesting Domain Controller and Kerberos events. The Advanced Security Audit policy setting `Audit Kerberos Authentication Service` within `Account Logon` needs to be enabled. - -#### Known False Positives -A host failing to authenticate with multiple disabled domain users is not a common behavior for legitimate systems. Possible false positive scenarios include but are not limited to vulnerability scanners, multi-user systems missconfigured systems. - -#### Associated Analytic story -* [Active Directory Password Spraying](/stories/active_directory_password_spraying) -* [Active Directory Kerberos Attacks](/stories/active_directory_kerberos_attacks) - - -#### Kill Chain Phase -* Exploitation - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | Potential Kerberos based password spraying attack from $Client_Address$ | - - - - -#### Reference - -* [https://attack.mitre.org/techniques/T1110/003/](https://attack.mitre.org/techniques/T1110/003/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_disabled_users_kerberos/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_disabled_users_kerberos/windows-security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-04-14-multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.md b/docs/_posts/2021-04-14-multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.md deleted file mode 100644 index 9fa8e3e7f8..0000000000 --- a/docs/_posts/2021-04-14-multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.md +++ /dev/null @@ -1,115 +0,0 @@ ---- -title: "Multiple Invalid Users Failing To Authenticate From Host Using Kerberos" -excerpt: "Password Spraying -, Brute Force -" -categories: - - Endpoint -last_modified_at: 2021-04-14 -toc: true -toc_label: "" -tags: - - Password Spraying - - Brute Force - - Credential Access - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies one source endpoint failing to authenticate with multiple invalid domain users using the Kerberos protocol. This behavior could represent an adversary performing a Password Spraying attack against an Active Directory environment using Kerberos to obtain initial access or elevate privileges. As attackers progress in a breach, mistakes will be made. In certain scenarios, adversaries may execute a password spraying attack using an invalid list of users. Event 4768 is generated every time the Key Distribution Center issues a Kerberos Ticket Granting Ticket (TGT). Failure code 0x6 stands for `client not found in Kerberos database` (the attempted user is not a valid domain user).\ -The detection calculates the standard deviation for each host and leverages the 3-sigma statistical rule to identify an unusual number of users. To customize this analytic, users can try different combinations of the `bucket` span time and the calculation of the `upperBound` field. This logic can be used for real time security monitoring as well as threat hunting exercises.\ -This detection will only trigger on domain controllers, not on member servers or workstations.\ -The analytics returned fields allow analysts to investigate the event further by providing fields like source ip and attempted user accounts. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/object-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: -- **Last Updated**: 2021-04-14 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 001266a6-9d5b-11eb-829b-acde48001122 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1110.003](https://attack.mitre.org/techniques/T1110/003/) | Password Spraying | Credential Access | - -| [T1110](https://attack.mitre.org/techniques/T1110/) | Brute Force | Credential Access | - -#### Search - -``` -`wineventlog_security` EventCode=4768 Result_Code=0x6 Account_Name!="*$" -| bucket span=2m _time -| stats dc(Account_Name) AS unique_accounts values(Account_Name) as tried_accounts by _time, Client_Address -| eventstats avg(unique_accounts) as comp_avg , stdev(unique_accounts) as comp_std by Client_Address -| eval upperBound=(comp_avg+comp_std*3) -| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0) -| search isOutlier=1 -| `multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) - -Note that `multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Result_Code -* Account_Name -* Client_Address - - -#### How To Implement -To successfully implement this search, you need to be ingesting Domain Controller and Kerberos events. The Advanced Security Audit policy setting `Audit Kerberos Authentication Service` within `Account Logon` needs to be enabled. - -#### Known False Positives -A host failing to authenticate with multiple invalid domain users is not a common behavior for legitimate systems. Possible false positive scenarios include but are not limited to vulnerability scanners, multi-user systems and missconfigured systems. - -#### Associated Analytic story -* [Active Directory Password Spraying](/stories/active_directory_password_spraying) -* [Active Directory Kerberos Attacks](/stories/active_directory_kerberos_attacks) - - -#### Kill Chain Phase -* Exploitation - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | Potential Kerberos based password spraying attack from $Client_Address$ | - - - - -#### Reference - -* [https://attack.mitre.org/techniques/T1110/003/](https://attack.mitre.org/techniques/T1110/003/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_invalid_users_kerberos/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_invalid_users_kerberos/windows-security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-04-14-office_document_creating_schedule_task.md b/docs/_posts/2021-04-14-office_document_creating_schedule_task.md deleted file mode 100644 index bef8758516..0000000000 --- a/docs/_posts/2021-04-14-office_document_creating_schedule_task.md +++ /dev/null @@ -1,165 +0,0 @@ ---- -title: "Office Document Creating Schedule Task" -excerpt: "Phishing -, Spearphishing Attachment -" -categories: - - Endpoint -last_modified_at: 2021-04-14 -toc: true -toc_label: "" -tags: - - Phishing - - Spearphishing Attachment - - Initial Access - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -this search detects a potential malicious office document that create schedule task entry through macro VBA api or through loading taskschd.dll. This technique was seen in so many malicious macro malware that create persistence , beaconing using task schedule malware entry The search will return the first time and last time the task was registered, as well as the `Command` to be executed, `Task Name`, `Author`, `Enabled`, and whether it is `Hidden` or not. schtasks.exe is natively found in `C:\Windows\system32` and `C:\Windows\syswow64`. The following DLL(s) are loaded when schtasks.exe or TaskService is launched -`taskschd.dll`. If found loaded by another process, it's possible a scheduled task is being registered within that process context in memory. Upon triage, identify the task scheduled source. Was it schtasks.exe or via TaskService? Review the job created and the Command to be executed. Capture any artifacts on disk and review. Identify any parallel processes within the same timeframe to identify source.' - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-04-14 -- **Author**: Teoderick Contreras, Splunk -- **ID**: cc8b7b74-9d0f-11eb-8342-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | - -| [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventCode=7 process_name IN ("WINWORD.EXE", "EXCEL.EXE", "POWERPNT.EXE") ImageLoaded = "*\\taskschd.dll" -| stats min(_time) as firstTime max(_time) as lastTime values(ImageLoaded) as AllImageLoaded count by Computer EventCode Image process_name ProcessId ProcessGuid -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `office_document_creating_schedule_task_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **office_document_creating_schedule_task_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* ImageLoaded -* AllImageLoaded -* Computer -* EventCode -* Image -* process_name -* ProcessId -* ProcessGuid -* _time - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name and ImageLoaded (Like sysmon EventCode 7) from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Also be sure to include those monitored dll to your own sysmon config. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Spearphishing Attachments](/stories/spearphishing_attachments) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | Office document creating a schedule task on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://research.checkpoint.com/2021/irans-apt34-returns-with-an-updated-arsenal/](https://research.checkpoint.com/2021/irans-apt34-returns-with-an-updated-arsenal/) -* [https://redcanary.com/threat-detection-report/techniques/scheduled-task-job/](https://redcanary.com/threat-detection-report/techniques/scheduled-task-job/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/datasets/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/datasets/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/office_document_creating_schedule_task.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-04-14-office_document_executing_macro_code.md b/docs/_posts/2021-04-14-office_document_executing_macro_code.md deleted file mode 100644 index eae4be613d..0000000000 --- a/docs/_posts/2021-04-14-office_document_executing_macro_code.md +++ /dev/null @@ -1,167 +0,0 @@ ---- -title: "Office Document Executing Macro Code" -excerpt: "Phishing -, Spearphishing Attachment -" -categories: - - Endpoint -last_modified_at: 2021-04-14 -toc: true -toc_label: "" -tags: - - Phishing - - Spearphishing Attachment - - Initial Access - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -this detection was designed to identifies suspicious office documents that using macro code. Macro code is known to be one of the prevalent weaponization or attack vector of threat actor. This malicious macro code is embed to a office document as an attachment that may execute malicious payload, download malware payload or other malware component. It is really good practice to disable macro by default to avoid automatically execute macro code while opening or closing a office document files. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-04-14 -- **Author**: Teoderick Contreras, Splunk -- **ID**: b12c89bc-9d06-11eb-a592-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | - -| [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventCode=7 parent_process_name IN ("WINWORD.EXE", "EXCEL.EXE", "POWERPNT.EXE") ImageLoaded IN ("*\\VBE7INTL.DLL","*\\VBE7.DLL", "*\\VBEUI.DLL") -| stats min(_time) as firstTime max(_time) as lastTime values(ImageLoaded) as AllImageLoaded count by Computer EventCode Image process_name ProcessId ProcessGuid -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `office_document_executing_macro_code_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **office_document_executing_macro_code_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* ImageLoaded -* AllImageLoaded -* Computer -* EventCode -* Image -* process_name -* ProcessId -* ProcessGuid -* _time - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name and ImageLoaded (Like sysmon EventCode 7) from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Also be sure to include those monitored dll to your own sysmon config. - -#### Known False Positives -Normal Office Document macro use for automation - -#### Associated Analytic story -* [Spearphishing Attachments](/stories/spearphishing_attachments) -* [Trickbot](/stories/trickbot) -* [IcedID](/stories/icedid) -* [DarkCrystal RAT](/stories/darkcrystal_rat) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 35.0 | 70 | 50 | Office document executing a macro on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.joesandbox.com/analysis/386500/0/html](https://www.joesandbox.com/analysis/386500/0/html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/datasets/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/datasets/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/office_document_executing_macro_code.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-04-14-windows_disabled_users_failing_to_authenticate_kerberos.md b/docs/_posts/2021-04-14-windows_disabled_users_failing_to_authenticate_kerberos.md deleted file mode 100644 index ea94b25366..0000000000 --- a/docs/_posts/2021-04-14-windows_disabled_users_failing_to_authenticate_kerberos.md +++ /dev/null @@ -1,165 +0,0 @@ ---- -title: "Windows Disabled Users Failing To Authenticate Kerberos" -excerpt: "Password Spraying -, Brute Force -" -categories: - - Endpoint -last_modified_at: 2021-04-14 -toc: true -toc_label: "" -tags: - - Password Spraying - - Brute Force - - Credential Access - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies one source endpoint failing to authenticate with multiple disabled domain users using the Kerberos protocol. This behavior could represent an adversary performing a Password Spraying attack against an Active Directory environment using Kerberos to obtain initial access or elevate privileges. As attackers progress in a breach, mistakes will be made. In certain scenarios, adversaries may execute a password spraying attack against disabled users. Event 4768 is generated every time the Key Distribution Center issues a Kerberos Ticket Granting Ticket (TGT). Failure code `0x12` stands for `clients credentials have been revoked` (account disabled, expired or locked out).\ -The detection calculates the standard deviation for each host and leverages the 3-sigma statistical rule to identify an unusual number of users. To customize this analytic, users can try different combinations of the `bucket` span time and the calculation of the `upperBound` field. This logic can be used for real time security monitoring as well as threat hunting exercises.\ -This detection will only trigger on domain controllers, not on member servers or workstations.\ -The analytics returned fields allow analysts to investigate the event further by providing fields like source ip and attempted user accounts. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-04-14 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 98f22d82-9d62-11eb-9fcf-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1110.003](https://attack.mitre.org/techniques/T1110/003/) | Password Spraying | Credential Access | - -| [T1110](https://attack.mitre.org/techniques/T1110/) | Brute Force | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`wineventlog_security` EventCode=4768 Account_Name!="*$" Result_Code=0x12 -| bucket span=2m _time -| stats dc(Account_Name) AS unique_accounts values(Account_Name) as tried_accounts by _time, Client_Address -| eventstats avg(unique_accounts) as comp_avg , stdev(unique_accounts) as comp_std by Client_Address -| eval upperBound=(comp_avg+comp_std*3) -| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0) -| search isOutlier=1 -| `windows_disabled_users_failing_to_authenticate_kerberos_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) - -> :information_source: -> **windows_disabled_users_failing_to_authenticate_kerberos_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Result_Code -* Account_Name -* Client_Address - - -#### How To Implement -To successfully implement this search, you need to be ingesting Domain Controller and Kerberos events. The Advanced Security Audit policy setting `Audit Kerberos Authentication Service` within `Account Logon` needs to be enabled. - -#### Known False Positives -A host failing to authenticate with multiple disabled domain users is not a common behavior for legitimate systems. Possible false positive scenarios include but are not limited to vulnerability scanners, multi-user systems missconfigured systems. - -#### Associated Analytic story -* [Active Directory Password Spraying](/stories/active_directory_password_spraying) -* [Active Directory Kerberos Attacks](/stories/active_directory_kerberos_attacks) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | Potential Kerberos based password spraying attack from $Client_Address$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1110/003/](https://attack.mitre.org/techniques/T1110/003/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_disabled_users_kerberos/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_disabled_users_kerberos/windows-security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_disabled_users_failing_to_authenticate_kerberos.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-04-14-windows_invalid_users_failed_authentication_via_kerberos.md b/docs/_posts/2021-04-14-windows_invalid_users_failed_authentication_via_kerberos.md deleted file mode 100644 index 565416e454..0000000000 --- a/docs/_posts/2021-04-14-windows_invalid_users_failed_authentication_via_kerberos.md +++ /dev/null @@ -1,165 +0,0 @@ ---- -title: "Windows Invalid Users Failed Authentication via Kerberos" -excerpt: "Password Spraying -, Brute Force -" -categories: - - Endpoint -last_modified_at: 2021-04-14 -toc: true -toc_label: "" -tags: - - Password Spraying - - Brute Force - - Credential Access - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies one source endpoint failing to authenticate with multiple invalid domain users using the Kerberos protocol. This behavior could represent an adversary performing a Password Spraying attack against an Active Directory environment using Kerberos to obtain initial access or elevate privileges. As attackers progress in a breach, mistakes will be made. In certain scenarios, adversaries may execute a password spraying attack using an invalid list of users. Event 4768 is generated every time the Key Distribution Center issues a Kerberos Ticket Granting Ticket (TGT). Failure code 0x6 stands for `client not found in Kerberos database` (the attempted user is not a valid domain user).\ -The detection calculates the standard deviation for each host and leverages the 3-sigma statistical rule to identify an unusual number of users. To customize this analytic, users can try different combinations of the `bucket` span time and the calculation of the `upperBound` field. This logic can be used for real time security monitoring as well as threat hunting exercises.\ -This detection will only trigger on domain controllers, not on member servers or workstations.\ -The analytics returned fields allow analysts to investigate the event further by providing fields like source ip and attempted user accounts. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-04-14 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 001266a6-9d5b-11eb-829b-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1110.003](https://attack.mitre.org/techniques/T1110/003/) | Password Spraying | Credential Access | - -| [T1110](https://attack.mitre.org/techniques/T1110/) | Brute Force | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`wineventlog_security` EventCode=4768 Result_Code=0x6 Account_Name!="*$" -| bucket span=2m _time -| stats dc(Account_Name) AS unique_accounts values(Account_Name) as tried_accounts by _time, Client_Address -| eventstats avg(unique_accounts) as comp_avg , stdev(unique_accounts) as comp_std by Client_Address -| eval upperBound=(comp_avg+comp_std*3) -| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0) -| search isOutlier=1 -| `windows_invalid_users_failed_authentication_via_kerberos_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) - -> :information_source: -> **windows_invalid_users_failed_authentication_via_kerberos_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Result_Code -* Account_Name -* Client_Address - - -#### How To Implement -To successfully implement this search, you need to be ingesting Domain Controller and Kerberos events. The Advanced Security Audit policy setting `Audit Kerberos Authentication Service` within `Account Logon` needs to be enabled. - -#### Known False Positives -A host failing to authenticate with multiple invalid domain users is not a common behavior for legitimate systems. Possible false positive scenarios include but are not limited to vulnerability scanners, multi-user systems and missconfigured systems. - -#### Associated Analytic story -* [Active Directory Password Spraying](/stories/active_directory_password_spraying) -* [Active Directory Kerberos Attacks](/stories/active_directory_kerberos_attacks) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | Potential Kerberos based password spraying attack from $Client_Address$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1110/003/](https://attack.mitre.org/techniques/T1110/003/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_invalid_users_kerberos/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_invalid_users_kerberos/windows-security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_invalid_users_failed_authentication_via_kerberos.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-04-15-dns_exfiltration_using_nslookup_app.md b/docs/_posts/2021-04-15-dns_exfiltration_using_nslookup_app.md deleted file mode 100644 index 4f941e1c9b..0000000000 --- a/docs/_posts/2021-04-15-dns_exfiltration_using_nslookup_app.md +++ /dev/null @@ -1,168 +0,0 @@ ---- -title: "DNS Exfiltration Using Nslookup App" -excerpt: "Exfiltration Over Alternative Protocol -" -categories: - - Endpoint -last_modified_at: 2021-04-15 -toc: true -toc_label: "" -tags: - - Exfiltration Over Alternative Protocol - - Exfiltration - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -this search is to detect potential DNS exfiltration using nslookup application. This technique are seen in couple of malware and APT group to exfiltrated collected data in a infected machine or infected network. This detection is looking for unique use of nslookup where it tries to use specific record type, TXT, A, AAAA, that are commonly used by attacker and also the retry parameter which is designed to query C2 DNS multiple tries. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-04-15 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 2452e632-9e0d-11eb-bacd-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1048](https://attack.mitre.org/techniques/T1048/) | Exfiltration Over Alternative Protocol | Exfiltration | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` values(Processes.process) as process values(Processes.process_id) as process_id values(Processes.parent_process) as parent_process count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = "nslookup.exe" Processes.process = "*-querytype=*" OR Processes.process="*-qt=*" OR Processes.process="*-q=*" OR Processes.process="-type=*" OR Processes.process="*-retry=*" by Processes.dest Processes.user Processes.process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `dns_exfiltration_using_nslookup_app_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **dns_exfiltration_using_nslookup_app_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances of nslookup.exe may be used. - -#### Known False Positives -admin nslookup usage - -#### Associated Analytic story -* [Suspicious DNS Traffic](/stories/suspicious_dns_traffic) -* [Dynamic DNS](/stories/dynamic_dns) -* [Data Exfiltration](/stories/data_exfiltration) -* [Command and Control](/stories/command_and_control) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 72.0 | 90 | 80 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ performing activity related to DNS exfiltration. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.mandiant.com/resources/fin7-spear-phishing-campaign-targets-personnel-involved-sec-filings](https://www.mandiant.com/resources/fin7-spear-phishing-campaign-targets-personnel-involved-sec-filings) -* [https://www.varonis.com/blog/dns-tunneling](https://www.varonis.com/blog/dns-tunneling) -* [https://www.microsoft.com/security/blog/2021/01/20/deep-dive-into-the-solorigate-second-stage-activation-from-sunburst-to-teardrop-and-raindrop/](https://www.microsoft.com/security/blog/2021/01/20/deep-dive-into-the-solorigate-second-stage-activation-from-sunburst-to-teardrop-and-raindrop/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1048.003/nslookup_exfil/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1048.003/nslookup_exfil/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/dns_exfiltration_using_nslookup_app.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-04-15-multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.md b/docs/_posts/2021-04-15-multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.md deleted file mode 100644 index f2c1f657ff..0000000000 --- a/docs/_posts/2021-04-15-multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.md +++ /dev/null @@ -1,166 +0,0 @@ ---- -title: "Multiple Invalid Users Failing To Authenticate From Host Using NTLM" -excerpt: "Password Spraying -, Brute Force -" -categories: - - Endpoint -last_modified_at: 2021-04-15 -toc: true -toc_label: "" -tags: - - Password Spraying - - Brute Force - - Credential Access - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies one source endpoint failing to authenticate with multiple invalid users using the NTLM protocol. This behavior could represent an adversary performing a Password Spraying attack against an Active Directory environment using NTLM to obtain initial access or elevate privileges. As attackers progress in a breach, mistakes will be made. In certain scenarios, adversaries may execute a password spraying attack using an invalid list of users. Event 4776 is generated on the computer that is authoritative for the provided credentials. For domain accounts, the domain controller is authoritative. For local accounts, the local computer is authoritative. Error code 0xC0000064 stands for `The username you typed does not exist` (the attempted user is a legitimate domain user).\ -The detection calculates the standard deviation for each host and leverages the 3-sigma statistical rule to identify an unusual number of users. To customize this analytic, users can try different combinations of the `bucket` span time and the calculation of the `upperBound` field. This logic can be used for real time security monitoring as well as threat hunting exercises.\ -This detection will only trigger on domain controllers, not on member servers or workstations.\ -The analytics returned fields allow analysts to investigate the event further by providing fields like source workstation name and attempted user accounts. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-04-15 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 57ad5a64-9df7-11eb-a290-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1110.003](https://attack.mitre.org/techniques/T1110/003/) | Password Spraying | Credential Access | - -| [T1110](https://attack.mitre.org/techniques/T1110/) | Brute Force | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - `wineventlog_security` EventCode=4776 Logon_Account!="*$" 0xC0000064 action=failure -| bucket span=2m _time -| stats dc(Logon_Account) AS unique_accounts values(Logon_Account) as tried_accounts by _time, Source_Workstation -| eventstats avg(unique_accounts) as comp_avg , stdev(unique_accounts) as comp_std by Source_Workstation -| eval upperBound=(comp_avg+comp_std*3) -| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0) -| search isOutlier=1 -| `multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) - -> :information_source: -> **multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* action -* Logon_Account -* Source_Workstation - - -#### How To Implement -To successfully implement this search, you need to be ingesting Domain Controller events. The Advanced Security Audit policy setting `Audit Credential Validation' within `Account Logon` needs to be enabled. - -#### Known False Positives -A host failing to authenticate with multiple invalid domain users is not a common behavior for legitimate systems. Possible false positive scenarios include but are not limited to vulnerability scanners and missconfigured systems. If this detection triggers on a host other than a Domain Controller, the behavior could represent a password spraying attack against the host's local accounts. - -#### Associated Analytic story -* [Active Directory Password Spraying](/stories/active_directory_password_spraying) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | Potential NTLM based password spraying attack from $Source_Workstation$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1110/003/](https://attack.mitre.org/techniques/T1110/003/) -* [https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-credential-validation](https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-credential-validation) -* [https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4776](https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4776) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_invalid_users_ntlm/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_invalid_users_ntlm/windows-security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-04-19-gpupdate_with_no_command_line_arguments_with_network.md b/docs/_posts/2021-04-19-gpupdate_with_no_command_line_arguments_with_network.md deleted file mode 100644 index 379e0c481a..0000000000 --- a/docs/_posts/2021-04-19-gpupdate_with_no_command_line_arguments_with_network.md +++ /dev/null @@ -1,116 +0,0 @@ ---- -title: "GPUpdate with no Command Line Arguments with Network" -excerpt: "Process Injection -" -categories: - - Endpoint -last_modified_at: 2021-04-19 -toc: true -toc_label: "" -tags: - - Process Injection - - Defense Evasion - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies gpupdate.exe with no command line arguments and with a network connection. It is unusual for gpupdate.exe to execute with no command line arguments present. This particular behavior is common with malicious software, including Cobalt Strike. During investigation, triage any network connections and parallel processes. Identify any suspicious module loads related to credential dumping or file writes. gpupdate.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/object-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-04-19 -- **Author**: Michael Haag, Splunk -- **ID**: 2c853856-a140-11eb-a5b5-acde48001122 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1055](https://attack.mitre.org/techniques/T1055/) | Process Injection | Defense Evasion, Privilege Escalation | - -#### Search - -``` - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name=gpupdate.exe by _time span=1h Processes.process_guid Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| regex process="(gpupdate\.exe.{0,4}$)" -| join process_guid [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Ports where Ports.dest_port !="0" by Ports.process_guid Ports.dest Ports.dest_port -| `drop_dm_object_name(Ports)` -| rename dest as connection_to_CNC] -| table _time dest parent_process_name process_name process_path process process_guid connection_to_CNC dest_port -| `gpupdate_with_no_command_line_arguments_with_network_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -Note that `gpupdate_with_no_command_line_arguments_with_network_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventID -* process_name -* process_id -* parent_process_name -* dest_port -* process_path - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Limited false positives may be present in small environments. Tuning may be required based on parent process. - -#### Associated Analytic story -* [Cobalt Strike](/stories/cobalt_strike) - - -#### Kill Chain Phase -* Exploitation - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 81.0 | 90 | 90 | Process gpupdate.exe with parent_process $parent_process_name$ is executed on $dest$ by user $user$, followed by an outbound network connection to $connection_to_CNC$ on port $dest_port$. This behaviour is seen with cobaltstrike. | - - - - -#### Reference - -* [https://raw.githubusercontent.com/xx0hcd/Malleable-C2-Profiles/0ef8cf4556e26f6d4190c56ba697c2159faa5822/crimeware/trick_ryuk.profile](https://raw.githubusercontent.com/xx0hcd/Malleable-C2-Profiles/0ef8cf4556e26f6d4190c56ba697c2159faa5822/crimeware/trick_ryuk.profile) -* [https://blog.cobaltstrike.com/2021/02/09/learn-pipe-fitting-for-all-of-your-offense-projects/](https://blog.cobaltstrike.com/2021/02/09/learn-pipe-fitting-for-all-of-your-offense-projects/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-04-19-powershell_remote_thread_to_known_windows_process.md b/docs/_posts/2021-04-19-powershell_remote_thread_to_known_windows_process.md deleted file mode 100644 index 000c69e486..0000000000 --- a/docs/_posts/2021-04-19-powershell_remote_thread_to_known_windows_process.md +++ /dev/null @@ -1,162 +0,0 @@ ---- -title: "Powershell Remote Thread To Known Windows Process" -excerpt: "Process Injection -" -categories: - - Endpoint -last_modified_at: 2021-04-19 -toc: true -toc_label: "" -tags: - - Process Injection - - Defense Evasion - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -this search is designed to detect suspicious powershell process that tries to inject code and to known/critical windows process and execute it using CreateRemoteThread. This technique is seen in several malware like trickbot and offensive tooling like cobaltstrike where it load a shellcode to svchost.exe to execute reverse shell to c2 and download another payload - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-04-19 -- **Author**: Teoderick Contreras, Splunk -- **ID**: ec102cb2-a0f5-11eb-9b38-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1055](https://attack.mitre.org/techniques/T1055/) | Process Injection | Defense Evasion, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventCode = 8 process_name IN ("powershell_ise.exe", "powershell.exe") TargetImage IN ("*\\svchost.exe","*\\csrss.exe" "*\\gpupdate.exe", "*\\explorer.exe","*\\services.exe","*\\winlogon.exe","*\\smss.exe","*\\wininit.exe","*\\userinit.exe","*\\spoolsv.exe","*\\taskhost.exe") -| stats min(_time) as firstTime max(_time) as lastTime count by SourceImage process_name SourceProcessId SourceProcessGuid TargetImage TargetProcessId NewThreadId StartAddress Computer EventCode -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `powershell_remote_thread_to_known_windows_process_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **powershell_remote_thread_to_known_windows_process_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* SourceImage -* process_name -* SourceProcessId -* SourceProcessGuid -* TargetImage -* TargetProcessId -* NewThreadId -* StartAddress -* Computer -* EventCode - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, Create Remote thread from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances of create remote thread may be used. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Trickbot](/stories/trickbot) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 63.0 | 70 | 90 | A suspicious powershell process $process_name$ that tries to create a remote thread on target process $TargetImage$ with eventcode $EventCode$ in host $Computer$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://thedfirreport.com/2021/01/11/trickbot-still-alive-and-well/](https://thedfirreport.com/2021/01/11/trickbot-still-alive-and-well/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/trickbot/infection/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/trickbot/infection/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-04-19-schedule_task_with_http_command_arguments.md b/docs/_posts/2021-04-19-schedule_task_with_http_command_arguments.md deleted file mode 100644 index b297562c89..0000000000 --- a/docs/_posts/2021-04-19-schedule_task_with_http_command_arguments.md +++ /dev/null @@ -1,163 +0,0 @@ ---- -title: "Schedule Task with HTTP Command Arguments" -excerpt: "Scheduled Task/Job -" -categories: - - Endpoint -last_modified_at: 2021-04-19 -toc: true -toc_label: "" -tags: - - Scheduled Task/Job - - Execution - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following query utilizes Windows Security EventCode 4698, `A scheduled task was created`, to identify suspicious tasks registered on Windows either via schtasks.exe OR TaskService with an arguments "HTTP" string that are unique entry of malware or attack that uses lolbin to download other file or payload to the infected machine. The search will return the first time and last time the task was registered, as well as the `Command` to be executed, `Task Name`, `Author`, `Enabled`, and whether it is `Hidden` or not. schtasks.exe is natively found in `C:\Windows\system32` and `C:\Windows\syswow64`. The following DLL(s) are loaded when schtasks.exe or TaskService is launched -`taskschd.dll`. If found loaded by another process, it is possible a scheduled task is being registered within that process context in memory. Upon triage, identify the task scheduled source. Was it schtasks.exe or via TaskService? Review the job created and the Command to be executed. Capture any artifacts on disk and review. Identify any parallel processes within the same timeframe to identify source.' - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-04-19 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 523c2684-a101-11eb-916b-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1053](https://attack.mitre.org/techniques/T1053/) | Scheduled Task/Job | Execution, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`wineventlog_security` EventCode=4698 -| xmlkv Message -| search Arguments IN ("*http*") -| stats count min(_time) as firstTime max(_time) as lastTime by dest, Task_Name, Command, Author, Enabled, Hidden, Arguments -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `schedule_task_with_http_command_arguments_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **schedule_task_with_http_command_arguments_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* dest -* Task_Name -* Command -* Author -* Enabled -* Hidden -* Arguments - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the task schedule (Exa. Security Log EventCode 4698) endpoints. Tune and filter known instances of Task schedule used in your environment. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Windows Persistence Techniques](/stories/windows_persistence_techniques) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 63.0 | 70 | 90 | A schedule task process commandline arguments $Arguments$ with http string on it in host $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://app.any.run/tasks/92d7ef61-bfd7-4c92-bc15-322172b4ebec/](https://app.any.run/tasks/92d7ef61-bfd7-4c92-bc15-322172b4ebec/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/tasksched/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/tasksched/windows-security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/schedule_task_with_http_command_arguments.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-04-19-schedule_task_with_rundll32_command_trigger.md b/docs/_posts/2021-04-19-schedule_task_with_rundll32_command_trigger.md deleted file mode 100644 index 2831b2bc73..0000000000 --- a/docs/_posts/2021-04-19-schedule_task_with_rundll32_command_trigger.md +++ /dev/null @@ -1,166 +0,0 @@ ---- -title: "Schedule Task with Rundll32 Command Trigger" -excerpt: "Scheduled Task/Job -" -categories: - - Endpoint -last_modified_at: 2021-04-19 -toc: true -toc_label: "" -tags: - - Scheduled Task/Job - - Execution - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following query utilizes Windows Security EventCode 4698, `A scheduled task was created`, to identify suspicious tasks registered on Windows either via schtasks.exe OR TaskService with a command to be executed with a Rundll32. This technique is common in new trickbot that uses rundll32 to load is trickbot downloader. The search will return the first time and last time the task was registered, as well as the `Command` to be executed, `Task Name`, `Author`, `Enabled`, and whether it is `Hidden` or not. schtasks.exe is natively found in `C:\Windows\system32` and `C:\Windows\syswow64`. The following DLL(s) are loaded when schtasks.exe or TaskService is launched -`taskschd.dll`. If found loaded by another process, it is possible a scheduled task is being registered within that process context in memory. Upon triage, identify the task scheduled source. Was it schtasks.exe or via TaskService? Review the job created and the Command to be executed. Capture any artifacts on disk and review. Identify any parallel processes within the same timeframe to identify source.' - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-04-19 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 75b00fd8-a0ff-11eb-8b31-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1053](https://attack.mitre.org/techniques/T1053/) | Scheduled Task/Job | Execution, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`wineventlog_security` EventCode=4698 -| xmlkv Message -| search Command IN ("*rundll32*") -| stats count min(_time) as firstTime max(_time) as lastTime by dest, Task_Name, Command, Author, Enabled, Hidden, Arguments -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `schedule_task_with_rundll32_command_trigger_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **schedule_task_with_rundll32_command_trigger_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* dest -* Task_Name -* Command -* Author -* Enabled -* Hidden -* Arguments - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the task schedule (Exa. Security Log EventCode 4698) endpoints. Tune and filter known instances of Task schedule used in your environment. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Windows Persistence Techniques](/stories/windows_persistence_techniques) -* [Trickbot](/stories/trickbot) -* [IcedID](/stories/icedid) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 70.0 | 70 | 100 | A schedule task process commandline rundll32 arguments $Arguments$ in host $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://labs.vipre.com/trickbot-and-its-modules/](https://labs.vipre.com/trickbot-and-its-modules/) -* [https://whitehat.eu/incident-response-case-study-featuring-ryuk-and-trickbot-part-2/](https://whitehat.eu/incident-response-case-study-featuring-ryuk-and-trickbot-part-2/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/trickbot/tasksched/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/trickbot/tasksched/windows-security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/schedule_task_with_rundll32_command_trigger.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-04-19-wermgr_process_connecting_to_ip_check_web_services.md b/docs/_posts/2021-04-19-wermgr_process_connecting_to_ip_check_web_services.md deleted file mode 100644 index b78947071f..0000000000 --- a/docs/_posts/2021-04-19-wermgr_process_connecting_to_ip_check_web_services.md +++ /dev/null @@ -1,165 +0,0 @@ ---- -title: "Wermgr Process Connecting To IP Check Web Services" -excerpt: "Gather Victim Network Information -, IP Addresses -" -categories: - - Endpoint -last_modified_at: 2021-04-19 -toc: true -toc_label: "" -tags: - - Gather Victim Network Information - - IP Addresses - - Reconnaissance - - Reconnaissance - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -this search is designed to detect suspicious wermgr.exe process that tries to connect to known IP web services. This technique is know for trickbot and other trojan spy malware to recon the infected machine and look for its ip address without so much finger print on the commandline process. Since wermgr.exe is designed for error handling process of windows it is really suspicious that this process is trying to connect to this IP web services cause that maybe cause of some malicious code injection. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-04-19 -- **Author**: Teoderick Contreras, Splunk -- **ID**: ed313326-a0f9-11eb-a89c-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1590](https://attack.mitre.org/techniques/T1590/) | Gather Victim Network Information | Reconnaissance | - -| [T1590.005](https://attack.mitre.org/techniques/T1590/005/) | IP Addresses | Reconnaissance | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventCode =22 process_name = wermgr.exe QueryName IN ("*wtfismyip.com", "*checkip.amazonaws.com", "*ipecho.net", "*ipinfo.io", "*api.ipify.org", "*icanhazip.com", "*ip.anysrc.com","*api.ip.sb", "ident.me", "www.myexternalip.com", "*zen.spamhaus.org", "*cbl.abuseat.org", "*b.barracudacentral.org","*dnsbl-1.uceprotect.net", "*spam.dnsbl.sorbs.net") -| stats min(_time) as firstTime max(_time) as lastTime count by process_path process_name process_id QueryName QueryStatus QueryResults Computer EventCode -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `wermgr_process_connecting_to_ip_check_web_services_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **wermgr_process_connecting_to_ip_check_web_services_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* process_path -* process_name -* process_id -* QueryName -* QueryStatus -* QueryResults -* Computer -* EventCode - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, dns query name process path , and query ststus from your endpoints like EventCode 22. If you are using Sysmon, you must have at least version 12 of the Sysmon TA. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Trickbot](/stories/trickbot) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 56.0 | 70 | 80 | Wermgr.exe process connecting IP location web services on $ComputerName$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://labs.vipre.com/trickbot-and-its-modules/](https://labs.vipre.com/trickbot-and-its-modules/) -* [https://blog.whitehat.eu/2019/05/incident-trickbot-ryuk-2.html](https://blog.whitehat.eu/2019/05/incident-trickbot-ryuk-2.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/trickbot/infection/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/trickbot/infection/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-04-19-wermgr_process_create_executable_file.md b/docs/_posts/2021-04-19-wermgr_process_create_executable_file.md deleted file mode 100644 index c2c705791c..0000000000 --- a/docs/_posts/2021-04-19-wermgr_process_create_executable_file.md +++ /dev/null @@ -1,158 +0,0 @@ ---- -title: "Wermgr Process Create Executable File" -excerpt: "Obfuscated Files or Information -" -categories: - - Endpoint -last_modified_at: 2021-04-19 -toc: true -toc_label: "" -tags: - - Obfuscated Files or Information - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -this search is designed to detect potential malicious wermgr.exe process that drops or create executable file. Since wermgr.exe is an application trigger when error encountered in a process, it is really un ussual to this process to drop executable file. This technique is commonly seen in trickbot malware where it injects it code to this process to execute it malicious behavior like downloading other payload - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-04-19 -- **Author**: Teoderick Contreras, Splunk -- **ID**: ab3bcce0-a105-11eb-973c-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1027](https://attack.mitre.org/techniques/T1027/) | Obfuscated Files or Information | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventCode=11 process_name = "wermgr.exe" TargetFilename = "*.exe" -| stats min(_time) as firstTime max(_time) as lastTime count by Image TargetFilename process_name dest EventCode ProcessId -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `wermgr_process_create_executable_file_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **wermgr_process_create_executable_file_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Image -* TargetFilename -* process_name -* dest -* EventCode -* ProcessId - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances of wermgr.exe may be used. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Trickbot](/stories/trickbot) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 56.0 | 70 | 80 | Wermgr.exe writing executable files on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://labs.vipre.com/trickbot-and-its-modules/](https://labs.vipre.com/trickbot-and-its-modules/) -* [https://whitehat.eu/incident-response-case-study-featuring-ryuk-and-trickbot-part-2/](https://whitehat.eu/incident-response-case-study-featuring-ryuk-and-trickbot-part-2/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/trickbot/infection/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/trickbot/infection/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/wermgr_process_create_executable_file.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-04-19-wermgr_process_spawned_cmd_or_powershell_process.md b/docs/_posts/2021-04-19-wermgr_process_spawned_cmd_or_powershell_process.md deleted file mode 100644 index 4ca443cc29..0000000000 --- a/docs/_posts/2021-04-19-wermgr_process_spawned_cmd_or_powershell_process.md +++ /dev/null @@ -1,166 +0,0 @@ ---- -title: "Wermgr Process Spawned CMD Or Powershell Process" -excerpt: "Command and Scripting Interpreter -" -categories: - - Endpoint -last_modified_at: 2021-04-19 -toc: true -toc_label: "" -tags: - - Command and Scripting Interpreter - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is designed to detect suspicious cmd and powershell process spawned by wermgr.exe process. This suspicious behavior are commonly seen in code injection technique technique like trickbot to execute a shellcode, dll modules to run malicious behavior. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-04-19 -- **Author**: Teoderick Contreras, Splunk -- **ID**: e8fc95bc-a107-11eb-a978-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` values(Processes.process) as cmdline min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name = "wermgr.exe" `process_cmd` OR `process_powershell` by Processes.parent_process_name Processes.original_file_name Processes.parent_process_id Processes.process_name Processes.process Processes.process_id Processes.process_guid Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `wermgr_process_spawned_cmd_or_powershell_process_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [process_cmd](https://github.com/splunk/security_content/blob/develop/macros/process_cmd.yml) - -> :information_source: -> **wermgr_process_spawned_cmd_or_powershell_process_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Trickbot](/stories/trickbot) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 56.0 | 70 | 80 | Wermgr.exe spawning suspicious processes on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://labs.vipre.com/trickbot-and-its-modules/](https://labs.vipre.com/trickbot-and-its-modules/) -* [https://whitehat.eu/incident-response-case-study-featuring-ryuk-and-trickbot-part-2/](https://whitehat.eu/incident-response-case-study-featuring-ryuk-and-trickbot-part-2/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/trickbot/infection/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/trickbot/infection/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-04-21-excessive_usage_of_nslookup_app.md b/docs/_posts/2021-04-21-excessive_usage_of_nslookup_app.md deleted file mode 100644 index 1220889852..0000000000 --- a/docs/_posts/2021-04-21-excessive_usage_of_nslookup_app.md +++ /dev/null @@ -1,164 +0,0 @@ ---- -title: "Excessive Usage of NSLOOKUP App" -excerpt: "Exfiltration Over Alternative Protocol -" -categories: - - Endpoint -last_modified_at: 2021-04-21 -toc: true -toc_label: "" -tags: - - Exfiltration Over Alternative Protocol - - Exfiltration - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect potential DNS exfiltration using nslookup application. This technique are seen in couple of malware and APT group to exfiltrated collected data in a infected machine or infected network. This detection is looking for unique use of nslookup where it tries to use specific record type (TXT, A, AAAA) that are commonly used by attacker and also the retry parameter which is designed to query C2 DNS multiple tries. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-04-21 -- **Author**: Teoderick Contreras, Stanislav Miskovic, Splunk -- **ID**: 0a69fdaa-a2b8-11eb-b16d-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1048](https://attack.mitre.org/techniques/T1048/) | Exfiltration Over Alternative Protocol | Exfiltration | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventCode = 1 process_name = "nslookup.exe" -| bucket _time span=15m -| stats count as numNsLookup by Computer, _time -| eventstats avg(numNsLookup) as avgNsLookup, stdev(numNsLookup) as stdNsLookup, count as numSlots by Computer -| eval upperThreshold=(avgNsLookup + stdNsLookup *3) -| eval isOutlier=if(avgNsLookup > 20 and avgNsLookup >= upperThreshold, 1, 0) -| search isOutlier=1 -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `excessive_usage_of_nslookup_app_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **excessive_usage_of_nslookup_app_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Computer -* process_name -* EventCode - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances of nslookup.exe may be used. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Suspicious DNS Traffic](/stories/suspicious_dns_traffic) -* [Dynamic DNS](/stories/dynamic_dns) -* [Data Exfiltration](/stories/data_exfiltration) -* [Command and Control](/stories/command_and_control) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 28.0 | 40 | 70 | Excessive usage of nslookup.exe has been detected on $Computer$. This detection is triggered as as it violates the dynamic threshold | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.fireeye.com/blog/threat-research/2017/03/fin7_spear_phishing.html](https://www.fireeye.com/blog/threat-research/2017/03/fin7_spear_phishing.html) -* [https://www.varonis.com/blog/dns-tunneling/](https://www.varonis.com/blog/dns-tunneling/) -* [https://www.microsoft.com/security/blog/2021/01/20/deep-dive-into-the-solorigate-second-stage-activation-from-sunburst-to-teardrop-and-raindrop/](https://www.microsoft.com/security/blog/2021/01/20/deep-dive-into-the-solorigate-second-stage-activation-from-sunburst-to-teardrop-and-raindrop/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1048.003/nslookup_exfil/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1048.003/nslookup_exfil/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/excessive_usage_of_nslookup_app.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-04-21-multiple_archive_files_http_post_traffic.md b/docs/_posts/2021-04-21-multiple_archive_files_http_post_traffic.md deleted file mode 100644 index b431df4985..0000000000 --- a/docs/_posts/2021-04-21-multiple_archive_files_http_post_traffic.md +++ /dev/null @@ -1,171 +0,0 @@ ---- -title: "Multiple Archive Files Http Post Traffic" -excerpt: "Exfiltration Over Unencrypted Non-C2 Protocol -, Exfiltration Over Alternative Protocol -" -categories: - - Network -last_modified_at: 2021-04-21 -toc: true -toc_label: "" -tags: - - Exfiltration Over Unencrypted Non-C2 Protocol - - Exfiltration Over Alternative Protocol - - Exfiltration - - Exfiltration - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Network_Traffic ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is designed to detect high frequency of archive files data exfiltration through HTTP POST method protocol. This are one of the common techniques used by APT or trojan spy after doing the data collection like screenshot, recording, sensitive data to the infected machines. The attacker may execute archiving command to the collected data, save it a temp folder with a hidden attribute then send it to its C2 through HTTP POST. Sometimes adversaries will rename the archive files or encode/encrypt to cover their tracks. This detection can detect a renamed archive files transfer to HTTP POST since it checks the request body header. Unfortunately this detection cannot support archive that was encrypted or encoded before doing the exfiltration. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Network_Traffic](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkTraffic) -- **Last Updated**: 2021-04-21 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 4477f3ea-a28f-11eb-b762-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1048.003](https://attack.mitre.org/techniques/T1048/003/) | Exfiltration Over Unencrypted Non-C2 Protocol | Exfiltration | - -| [T1048](https://attack.mitre.org/techniques/T1048/) | Exfiltration Over Alternative Protocol | Exfiltration | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`stream_http` http_method=POST -|eval archive_hdr1=substr(form_data,1,2) -| eval archive_hdr2 = substr(form_data,1,4) -|stats values(form_data) as http_request_body min(_time) as firstTime max(_time) as lastTime count by http_method http_user_agent uri_path url bytes_in bytes_out archive_hdr1 archive_hdr2 -|where count >20 AND (archive_hdr1 = "7z" OR archive_hdr1 = "PK" OR archive_hdr2="Rar!") -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `multiple_archive_files_http_post_traffic_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [stream_http](https://github.com/splunk/security_content/blob/develop/macros/stream_http.yml) - -> :information_source: -> **multiple_archive_files_http_post_traffic_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* http_method -* http_user_agent -* uri_path -* url -* bytes_in -* bytes_out -* archive_hdr1 -* archive_hdr2 -* form_data - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the stream HTTP logs or network logs that catch network traffic. Make sure that the http-request-body, payload, or request field is enabled in stream http configuration. - -#### Known False Positives -Normal archive transfer via HTTP protocol may trip this detection. - -#### Associated Analytic story -* [Data Exfiltration](/stories/data_exfiltration) -* [Command and Control](/stories/command_and_control) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | A http post $http_method$ sending packet with possible archive bytes header 4form_data$ in uri path $uri_path$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1560/001/](https://attack.mitre.org/techniques/T1560/001/) -* [https://www.mandiant.com/resources/apt39-iranian-cyber-espionage-group-focused-on-personal-information](https://www.mandiant.com/resources/apt39-iranian-cyber-espionage-group-focused-on-personal-information) -* [https://www.microsoft.com/security/blog/2021/01/20/deep-dive-into-the-solorigate-second-stage-activation-from-sunburst-to-teardrop-and-raindrop/](https://www.microsoft.com/security/blog/2021/01/20/deep-dive-into-the-solorigate-second-stage-activation-from-sunburst-to-teardrop-and-raindrop/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1048.003/archive_http_post/stream_http_events.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1048.003/archive_http_post/stream_http_events.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/network/multiple_archive_files_http_post_traffic.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-04-22-anomalous_usage_of_7zip.md b/docs/_posts/2021-04-22-anomalous_usage_of_7zip.md deleted file mode 100644 index 7d58b841d5..0000000000 --- a/docs/_posts/2021-04-22-anomalous_usage_of_7zip.md +++ /dev/null @@ -1,169 +0,0 @@ ---- -title: "Anomalous usage of 7zip" -excerpt: "Archive via Utility -, Archive Collected Data -" -categories: - - Endpoint -last_modified_at: 2021-04-22 -toc: true -toc_label: "" -tags: - - Archive via Utility - - Archive Collected Data - - Collection - - Collection - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following detection identifies a 7z.exe spawned from `Rundll32.exe` or `Dllhost.exe`. It is assumed that the adversary has brought in `7z.exe` and `7z.dll`. It has been observed where an adversary will rename `7z.exe`. Additional coverage may be required to identify the behavior of renamed instances of `7z.exe`. During triage, identify the source of injection into `Rundll32.exe` or `Dllhost.exe`. Capture any files written to disk and analyze as needed. Review parallel processes for additional behaviors. Typically, archiving files will result in exfiltration. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-04-22 -- **Author**: Michael Haag, Teoderick Contreras, Splunk -- **ID**: 9364ee8e-a39a-11eb-8f1d-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1560.001](https://attack.mitre.org/techniques/T1560/001/) | Archive via Utility | Collection | - -| [T1560](https://attack.mitre.org/techniques/T1560/) | Archive Collected Data | Collection | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name IN ("rundll32.exe", "dllhost.exe") Processes.process_name=*7z* by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `anomalous_usage_of_7zip_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **anomalous_usage_of_7zip_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process_name -* Processes.process -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.process_name -* Processes.parent_process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -False positives should be limited as this behavior is not normal for `rundll32.exe` or `dllhost.exe` to spawn and run 7zip. - -#### Associated Analytic story -* [Cobalt Strike](/stories/cobalt_strike) -* [NOBELIUM Group](/stories/nobelium_group) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 64.0 | 80 | 80 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$. This behavior is indicative of suspicious loading of 7zip. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1560/001/](https://attack.mitre.org/techniques/T1560/001/) -* [https://www.microsoft.com/security/blog/2021/01/20/deep-dive-into-the-solorigate-second-stage-activation-from-sunburst-to-teardrop-and-raindrop/](https://www.microsoft.com/security/blog/2021/01/20/deep-dive-into-the-solorigate-second-stage-activation-from-sunburst-to-teardrop-and-raindrop/) -* [https://thedfirreport.com/2021/01/31/bazar-no-ryuk/](https://thedfirreport.com/2021/01/31/bazar-no-ryuk/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1560.001/archive_utility/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1560.001/archive_utility/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/anomalous_usage_of_7zip.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-04-22-office_product_spawning_rundll32_with_no_dll.md b/docs/_posts/2021-04-22-office_product_spawning_rundll32_with_no_dll.md deleted file mode 100644 index e0ae691ef6..0000000000 --- a/docs/_posts/2021-04-22-office_product_spawning_rundll32_with_no_dll.md +++ /dev/null @@ -1,171 +0,0 @@ ---- -title: "Office Product Spawning Rundll32 with no DLL" -excerpt: "Phishing -, Spearphishing Attachment -" -categories: - - Endpoint -last_modified_at: 2021-04-22 -toc: true -toc_label: "" -tags: - - Phishing - - Spearphishing Attachment - - Initial Access - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following detection identifies the latest behavior utilized by IcedID malware family. This detection identifies any Windows Office Product spawning `rundll32.exe` without a `.dll` file extension. In malicious instances, the command-line of `rundll32.exe` will look like `rundll32 ..\oepddl.igk2,DllRegisterServer`. In addition, Threat Research has released a detection identifying the use of `DllRegisterServer` on the command-line of `rundll32.exe`. In this instance, we narrow our detection down to the Office suite as a parent process. During triage, review all file modifications. Capture and analyze the `DLL` that was dropped to disk. The Office Product will have reached out to a remote destination, capture and block the IPs or domain. Review additional parallel processes for further activity. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-04-22 -- **Author**: Michael Haag, Splunk -- **ID**: c661f6be-a38c-11eb-be57-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | - -| [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name IN ("winword.exe","excel.exe","powerpnt.exe","mspub.exe","visio.exe") `process_rundll32` (Processes.process!=*.dll*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `office_product_spawning_rundll32_with_no_dll_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [process_rundll32](https://github.com/splunk/security_content/blob/develop/macros/process_rundll32.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **office_product_spawning_rundll32_with_no_dll_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -False positives should be limited, but if any are present, filter as needed. - -#### Associated Analytic story -* [Spearphishing Attachments](/stories/spearphishing_attachments) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 63.0 | 70 | 90 | office parent process $parent_process_name$ will execute a suspicious child process $process_name$ with process id $process_id$ and no dll commandline $process$ in host $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.joesandbox.com/analysis/395471/0/html](https://www.joesandbox.com/analysis/395471/0/html) -* [https://app.any.run/tasks/cef4b8ba-023c-4b3b-b2ef-6486a44f6ed9/](https://app.any.run/tasks/cef4b8ba-023c-4b3b-b2ef-6486a44f6ed9/) -* [https://any.run/malware-trends/icedid](https://any.run/malware-trends/icedid) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_icedid.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_icedid.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-04-22-plain_http_post_exfiltrated_data.md b/docs/_posts/2021-04-22-plain_http_post_exfiltrated_data.md deleted file mode 100644 index 2f4662d6e8..0000000000 --- a/docs/_posts/2021-04-22-plain_http_post_exfiltrated_data.md +++ /dev/null @@ -1,163 +0,0 @@ ---- -title: "Plain HTTP POST Exfiltrated Data" -excerpt: "Exfiltration Over Unencrypted Non-C2 Protocol -, Exfiltration Over Alternative Protocol -" -categories: - - Network -last_modified_at: 2021-04-22 -toc: true -toc_label: "" -tags: - - Exfiltration Over Unencrypted Non-C2 Protocol - - Exfiltration Over Alternative Protocol - - Exfiltration - - Exfiltration - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Network_Traffic ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect potential plain HTTP POST method data exfiltration. This network traffic is commonly used by trickbot, trojanspy, keylogger or APT adversary where arguments or commands are sent in plain text to the remote C2 server using HTTP POST method as part of data exfiltration. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Network_Traffic](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkTraffic) -- **Last Updated**: 2021-04-22 -- **Author**: Teoderick Contreras, Splunk -- **ID**: e2b36208-a364-11eb-8909-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1048.003](https://attack.mitre.org/techniques/T1048/003/) | Exfiltration Over Unencrypted Non-C2 Protocol | Exfiltration | - -| [T1048](https://attack.mitre.org/techniques/T1048/) | Exfiltration Over Alternative Protocol | Exfiltration | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`stream_http` http_method=POST form_data IN ("*wermgr.exe*","*svchost.exe*", "*name=\"proclist\"*","*ipconfig*", "*name=\"sysinfo\"*", "*net view*") -|stats values(form_data) as http_request_body min(_time) as firstTime max(_time) as lastTime count by http_method http_user_agent uri_path url bytes_in bytes_out -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `plain_http_post_exfiltrated_data_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [stream_http](https://github.com/splunk/security_content/blob/develop/macros/stream_http.yml) - -> :information_source: -> **plain_http_post_exfiltrated_data_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* http_method -* http_user_agent -* uri_path -* url -* bytes_in -* bytes_out - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the stream HTTP logs or network logs that catch network traffic. Make sure that the http-request-body, payload, or request field is enabled. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Data Exfiltration](/stories/data_exfiltration) -* [Command and Control](/stories/command_and_control) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 63.0 | 70 | 90 | A http post $http_method$ sending packet with plain text of information $form_data$ in uri path $uri_path$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://blog.talosintelligence.com/2020/03/trickbot-primer.html](https://blog.talosintelligence.com/2020/03/trickbot-primer.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1048.003/plain_exfil_data/stream_http_events.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1048.003/plain_exfil_data/stream_http_events.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/network/plain_http_post_exfiltrated_data.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-04-22-winword_spawning_cmd.md b/docs/_posts/2021-04-22-winword_spawning_cmd.md deleted file mode 100644 index b2ee8054fa..0000000000 --- a/docs/_posts/2021-04-22-winword_spawning_cmd.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: "Winword Spawning Cmd" -excerpt: "Phishing -, Spearphishing Attachment -" -categories: - - Endpoint -last_modified_at: 2021-04-22 -toc: true -toc_label: "" -tags: - - Phishing - - Spearphishing Attachment - - Initial Access - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following detection identifies Microsoft Word spawning `cmd.exe`. Typically, this is not common behavior and not default with winword.exe. Winword.exe will generally be found in the following path `C:\Program Files\Microsoft Office\root\Office16` (version will vary). Cmd.exe spawning from winword.exe is common for a spearphishing attachment and is actively used. Albeit, the command-line will indicate what is being executed. During triage, review parallel processes and identify any files that may have been written. It is possible that COM is utilized to trampoline the child process to `explorer.exe` or `wmiprvse.exe`. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-04-22 -- **Author**: Michael Haag, Splunk -- **ID**: 6fcbaedc-a37b-11eb-956b-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | - -| [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=winword.exe `process_cmd` by Processes.dest Processes.user Processes.parent_process Processes.original_file_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `winword_spawning_cmd_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [process_cmd](https://github.com/splunk/security_content/blob/develop/macros/process_cmd.yml) - -> :information_source: -> **winword_spawning_cmd_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -False positives should be limited, but if any are present, filter as needed. - -#### Associated Analytic story -* [Spearphishing Attachments](/stories/spearphishing_attachments) -* [DarkCrystal RAT](/stories/darkcrystal_rat) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 70.0 | 70 | 100 | $parent_process_name$ on $dest$ by $user$ launched command: $process_name$ which is very common in spearphishing attacks. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://app.any.run/tasks/73af0064-a785-4c0a-ab0d-cde593fe16ef/](https://app.any.run/tasks/73af0064-a785-4c0a-ab0d-cde593fe16ef/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/winword_spawning_cmd.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-04-26-office_product_spawning_bitsadmin.md b/docs/_posts/2021-04-26-office_product_spawning_bitsadmin.md deleted file mode 100644 index 83ac9784e0..0000000000 --- a/docs/_posts/2021-04-26-office_product_spawning_bitsadmin.md +++ /dev/null @@ -1,169 +0,0 @@ ---- -title: "Office Product Spawning BITSAdmin" -excerpt: "Phishing -, Spearphishing Attachment -" -categories: - - Endpoint -last_modified_at: 2021-04-26 -toc: true -toc_label: "" -tags: - - Phishing - - Spearphishing Attachment - - Initial Access - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following detection identifies the latest behavior utilized by different malware families (including TA551, IcedID). This detection identifies any Windows Office Product spawning `bitsadmin.exe`. In malicious instances, the command-line of `bitsadmin.exe` will contain a URL to a remote destination or similar command-line arguments as transfer, Download, priority, Foreground. In addition, Threat Research has released a detections identifying suspicious use of `bitsadmin.exe`. In this instance, we narrow our detection down to the Office suite as a parent process. During triage, review all file modifications. Capture and analyze any artifacts on disk. The Office Product, or `bitsadmin.exe` will have reached out to a remote destination, capture and block the IPs or domain. Review additional parallel processes for further activity. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-04-26 -- **Author**: Michael Haag, Splunk -- **ID**: e8c591f4-a6d7-11eb-8cf7-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | - -| [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name IN ("winword.exe","excel.exe","powerpnt.exe","mspub.exe","visio.exe") `process_bitsadmin` by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `office_product_spawning_bitsadmin_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [process_bitsadmin](https://github.com/splunk/security_content/blob/develop/macros/process_bitsadmin.yml) - -> :information_source: -> **office_product_spawning_bitsadmin_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -No false positives known. Filter as needed. - -#### Associated Analytic story -* [Spearphishing Attachments](/stories/spearphishing_attachments) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 63.0 | 70 | 90 | office parent process $parent_process_name$ will execute a suspicious child process $process_name$ with process id $process_id$ in host $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1197/T1197.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1197/T1197.md) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_macros.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_macros.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/office_product_spawning_bitsadmin.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-04-26-office_product_spawning_certutil.md b/docs/_posts/2021-04-26-office_product_spawning_certutil.md deleted file mode 100644 index aee81a0e17..0000000000 --- a/docs/_posts/2021-04-26-office_product_spawning_certutil.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: "Office Product Spawning CertUtil" -excerpt: "Phishing -, Spearphishing Attachment -" -categories: - - Endpoint -last_modified_at: 2021-04-26 -toc: true -toc_label: "" -tags: - - Phishing - - Spearphishing Attachment - - Initial Access - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following detection identifies the latest behavior utilized by different malware families (including TA551, IcedID). This detection identifies any Windows Office Product spawning `certutil.exe`. In malicious instances, the command-line of `certutil.exe` will contain a URL to a remote destination. In addition, Threat Research has released a detections identifying suspicious use of `certutil.exe`. In this instance, we narrow our detection down to the Office suite as a parent process. During triage, review all file modifications. Capture and analyze any artifacts on disk. The Office Product, or `certutil.exe` will have reached out to a remote destination, capture and block the IPs or domain. Review additional parallel processes for further activity. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-04-26 -- **Author**: Michael Haag, Splunk -- **ID**: 6925fe72-a6d5-11eb-9e17-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | - -| [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name IN ("winword.exe","excel.exe","powerpnt.exe","mspub.exe","visio.exe") `process_certutil` by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `office_product_spawning_certutil_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_certutil](https://github.com/splunk/security_content/blob/develop/macros/process_certutil.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **office_product_spawning_certutil_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -No false positives known. Filter as needed. - -#### Associated Analytic story -* [Spearphishing Attachments](/stories/spearphishing_attachments) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 63.0 | 70 | 90 | office parent process $parent_process_name$ will execute a suspicious child process $process_name$ with process id $process_id$ in host $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://redcanary.com/threat-detection-report/threats/TA551/](https://redcanary.com/threat-detection-report/threats/TA551/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1105/T1105.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1105/T1105.md) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_macros.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_macros.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/office_product_spawning_certutil.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-04-26-office_product_spawning_mshta.md b/docs/_posts/2021-04-26-office_product_spawning_mshta.md deleted file mode 100644 index 23dc5d2084..0000000000 --- a/docs/_posts/2021-04-26-office_product_spawning_mshta.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: "Office Product Spawning MSHTA" -excerpt: "Phishing -, Spearphishing Attachment -" -categories: - - Endpoint -last_modified_at: 2021-04-26 -toc: true -toc_label: "" -tags: - - Phishing - - Spearphishing Attachment - - Initial Access - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following detection identifies the latest behavior utilized by different malware families (including TA551, IcedID). This detection identifies any Windows Office Product spawning `mshta.exe`. In malicious instances, the command-line of `mshta.exe` will contain the `hta` file locally, or a URL to the remote destination. In addition, Threat Research has released a detections identifying suspicious use of `mshta.exe`. In this instance, we narrow our detection down to the Office suite as a parent process. During triage, review all file modifications. Capture and analyze any artifacts on disk. The Office Product, or `mshta.exe` will have reached out to a remote destination, capture and block the IPs or domain. Review additional parallel processes for further activity. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-04-26 -- **Author**: Michael Haag, Splunk -- **ID**: 6078fa20-a6d2-11eb-b662-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | - -| [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name IN ("winword.exe","excel.exe","powerpnt.exe","mspub.exe","visio.exe") `process_mshta` by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `office_product_spawning_mshta_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_mshta](https://github.com/splunk/security_content/blob/develop/macros/process_mshta.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **office_product_spawning_mshta_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -No false positives known. Filter as needed. - -#### Associated Analytic story -* [Spearphishing Attachments](/stories/spearphishing_attachments) -* [IcedID](/stories/icedid) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 63.0 | 70 | 90 | office parent process $parent_process_name$ will execute a suspicious child process $process_name$ with process id $process_id$ in host $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://redcanary.com/threat-detection-report/threats/TA551/](https://redcanary.com/threat-detection-report/threats/TA551/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_macros.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_macros.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/office_product_spawning_mshta.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-04-26-trickbot_named_pipe.md b/docs/_posts/2021-04-26-trickbot_named_pipe.md deleted file mode 100644 index 5eb7a599ed..0000000000 --- a/docs/_posts/2021-04-26-trickbot_named_pipe.md +++ /dev/null @@ -1,160 +0,0 @@ ---- -title: "Trickbot Named Pipe" -excerpt: "Process Injection -" -categories: - - Endpoint -last_modified_at: 2021-04-26 -toc: true -toc_label: "" -tags: - - Process Injection - - Defense Evasion - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -this search is to detect potential trickbot infection through the create/connected named pipe to the system. This technique is used by trickbot to communicate to its c2 to post or get command during infection. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-04-26 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 1804b0a4-a682-11eb-8f68-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1055](https://attack.mitre.org/techniques/T1055/) | Process Injection | Defense Evasion, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventCode IN (17,18) PipeName="\\pipe\\*lacesomepipe" -| stats min(_time) as firstTime max(_time) as lastTime count by Computer user_id EventCode PipeName signature Image process_id -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `trickbot_named_pipe_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **trickbot_named_pipe_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Computer -* user_id -* EventCode -* PipeName -* signature -* Image -* process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name and pipename from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. . - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Trickbot](/stories/trickbot) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 42.0 | 70 | 60 | Possible Trickbot namedpipe created on $Computer$ by $Image$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://labs.vipre.com/trickbot-and-its-modules/](https://labs.vipre.com/trickbot-and-its-modules/) -* [https://whitehat.eu/incident-response-case-study-featuring-ryuk-and-trickbot-part-2/](https://whitehat.eu/incident-response-case-study-featuring-ryuk-and-trickbot-part-2/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/trickbot/namedpipe/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/trickbot/namedpipe/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/trickbot_named_pipe.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-04-29-icacls_deny_command.md b/docs/_posts/2021-04-29-icacls_deny_command.md deleted file mode 100644 index 5bed11167c..0000000000 --- a/docs/_posts/2021-04-29-icacls_deny_command.md +++ /dev/null @@ -1,159 +0,0 @@ ---- -title: "Icacls Deny Command" -excerpt: "File and Directory Permissions Modification -" -categories: - - Endpoint -last_modified_at: 2021-04-29 -toc: true -toc_label: "" -tags: - - File and Directory Permissions Modification - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic identifies a potential adversary that changes the security permission of a specific file or directory. This technique is commonly seen in APT tradecraft or coinminer scripts. This behavior is meant to evade detection and prevent access to their component files. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-04-29 -- **Author**: Teoderick Contreras, Splunk -- **ID**: cf8d753e-a8fe-11eb-8f58-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1222](https://attack.mitre.org/techniques/T1222/) | File and Directory Permissions Modification | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` values(Processes.process) as process values(Processes.process_id) as process_id count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = "icacls.exe" OR Processes.process_name = "cacls.exe" OR Processes.process_name = "xcacls.exe" AND Processes.process = "*/deny*" by Processes.parent_process_name Processes.process_name Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `icacls_deny_command_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **icacls_deny_command_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.parent_process_name -* Processes.process_name -* Processes.dest -* Processes.user -* Processes.process_id -* Processes.process - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed icacls.exe may be used. - -#### Known False Positives -Unknown. It is possible some administrative scripts use ICacls. Filter as needed. - -#### Associated Analytic story -* [XMRig](/stories/xmrig) -* [Azorult](/stories/azorult) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 72.0 | 90 | 80 | Process name $process_name$ with deny argument executed by $user$ to change security permission of a specific file or directory on host $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/](https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/icacls_deny_command.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-04-29-suspicious_driver_loaded_path.md b/docs/_posts/2021-04-29-suspicious_driver_loaded_path.md deleted file mode 100644 index ff1e142ac3..0000000000 --- a/docs/_posts/2021-04-29-suspicious_driver_loaded_path.md +++ /dev/null @@ -1,165 +0,0 @@ ---- -title: "Suspicious Driver Loaded Path" -excerpt: "Windows Service -, Create or Modify System Process -" -categories: - - Endpoint -last_modified_at: 2021-04-29 -toc: true -toc_label: "" -tags: - - Windows Service - - Create or Modify System Process - - Persistence - - Privilege Escalation - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic will detect suspicious driver loaded paths. This technique is commonly used by malicious software like coin miners (xmrig) to register its malicious driver from notable directories where executable or drivers do not commonly exist. During triage, validate this driver is for legitimate business use. Review the metadata and certificate information. Unsigned drivers from non-standard paths is not normal, but occurs. In addition, review driver loads into `ntoskrnl.exe` for possible other drivers of interest. Long tail analyze drivers by path (outside of default, and in default) for further review. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-04-29 -- **Author**: Teoderick Contreras, Splunk -- **ID**: f880acd4-a8f1-11eb-a53b-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1543.003](https://attack.mitre.org/techniques/T1543/003/) | Windows Service | Persistence, Privilege Escalation | - -| [T1543](https://attack.mitre.org/techniques/T1543/) | Create or Modify System Process | Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventCode=6 ImageLoaded = "*.sys" NOT (ImageLoaded IN("*\\WINDOWS\\inf","*\\WINDOWS\\System32\\drivers\\*", "*\\WINDOWS\\System32\\DriverStore\\FileRepository\\*")) -| stats min(_time) as firstTime max(_time) as lastTime count by Computer ImageLoaded Hashes IMPHASH Signature Signed -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `suspicious_driver_loaded_path_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **suspicious_driver_loaded_path_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Computer -* ImageLoaded -* Hashes -* IMPHASH -* Signature -* Signed - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the driver loaded and Signature from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -Limited false positives will be present. Some applications do load drivers - -#### Associated Analytic story -* [XMRig](/stories/xmrig) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 63.0 | 70 | 90 | Suspicious driver $ImageLoaded$ on $Computer$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.trendmicro.com/vinfo/hk/threat-encyclopedia/malware/trojan.ps1.powtran.a/](https://www.trendmicro.com/vinfo/hk/threat-encyclopedia/malware/trojan.ps1.powtran.a/) -* [https://redcanary.com/blog/tracking-driver-inventory-to-expose-rootkits/](https://redcanary.com/blog/tracking-driver-inventory-to-expose-rootkits/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/suspicious_driver_loaded_path.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-04-29-xmrig_driver_loaded.md b/docs/_posts/2021-04-29-xmrig_driver_loaded.md deleted file mode 100644 index 7046351428..0000000000 --- a/docs/_posts/2021-04-29-xmrig_driver_loaded.md +++ /dev/null @@ -1,164 +0,0 @@ ---- -title: "XMRIG Driver Loaded" -excerpt: "Windows Service -, Create or Modify System Process -" -categories: - - Endpoint -last_modified_at: 2021-04-29 -toc: true -toc_label: "" -tags: - - Windows Service - - Create or Modify System Process - - Persistence - - Privilege Escalation - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic identifies XMRIG coinminer driver installation on the system. The XMRIG driver name by default is `WinRing0x64.sys`. This cpu miner is an open source project that is commonly abused by adversaries to infect and mine bitcoin. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-04-29 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 90080fa6-a8df-11eb-91e4-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1543.003](https://attack.mitre.org/techniques/T1543/003/) | Windows Service | Persistence, Privilege Escalation | - -| [T1543](https://attack.mitre.org/techniques/T1543/) | Create or Modify System Process | Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventCode=6 Signature="Noriyuki MIYAZAKI" OR ImageLoaded= "*\\WinRing0x64.sys" -| stats min(_time) as firstTime max(_time) as lastTime count by Computer ImageLoaded Hashes IMPHASH Signature Signed -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `xmrig_driver_loaded_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **xmrig_driver_loaded_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Computer -* ImageLoaded -* Hashes -* IMPHASH -* Signature -* Signed - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the driver loaded and Signature from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -False positives should be limited. - -#### Associated Analytic story -* [XMRig](/stories/xmrig) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | A driver $ImageLoaded$ related to xmrig crytominer loaded in host $Computer$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.trendmicro.com/vinfo/hk/threat-encyclopedia/malware/trojan.ps1.powtran.a/](https://www.trendmicro.com/vinfo/hk/threat-encyclopedia/malware/trojan.ps1.powtran.a/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/xmrig_driver_loaded.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-05-04-deleting_of_net_users.md b/docs/_posts/2021-05-04-deleting_of_net_users.md deleted file mode 100644 index 696ce71d06..0000000000 --- a/docs/_posts/2021-05-04-deleting_of_net_users.md +++ /dev/null @@ -1,164 +0,0 @@ ---- -title: "Deleting Of Net Users" -excerpt: "Account Access Removal -" -categories: - - Endpoint -last_modified_at: 2021-05-04 -toc: true -toc_label: "" -tags: - - Account Access Removal - - Impact - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic will detect a suspicious net.exe/net1.exe command-line to delete a user on a system. This technique may be use by an administrator for legitimate purposes, however this behavior has been used in the wild to impair some user or deleting adversaries tracks created during its lateral movement additional systems. During triage, review parallel processes for additional behavior. Identify any other user accounts created before or after. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-05-04 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 1c8c6f66-acce-11eb-aafb-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1531](https://attack.mitre.org/techniques/T1531/) | Account Access Removal | Impact | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` values(Processes.process) as process values(Processes.parent_process) as parent_process values(Processes.process_id) as process_id count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_net` AND Processes.process="*user*" AND Processes.process="*/delete*" by Processes.process_name Processes.original_file_name Processes.dest Processes.user Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `deleting_of_net_users_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_net](https://github.com/splunk/security_content/blob/develop/macros/process_net.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **deleting_of_net_users_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -System administrators or scripts may delete user accounts via this technique. Filter as needed. - -#### Associated Analytic story -* [XMRig](/stories/xmrig) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to delete accounts. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/](https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/deleting_of_net_users.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-05-04-disabling_net_user_account.md b/docs/_posts/2021-05-04-disabling_net_user_account.md deleted file mode 100644 index f1a0878aad..0000000000 --- a/docs/_posts/2021-05-04-disabling_net_user_account.md +++ /dev/null @@ -1,164 +0,0 @@ ---- -title: "Disabling Net User Account" -excerpt: "Account Access Removal -" -categories: - - Endpoint -last_modified_at: 2021-05-04 -toc: true -toc_label: "" -tags: - - Account Access Removal - - Impact - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic will identify a suspicious command-line that disables a user account using the `net.exe` utility native to Windows. This technique may used by the adversaries to interrupt availability of such users to do their malicious act. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-05-04 -- **Author**: Teoderick Contreras, Splunk -- **ID**: c0325326-acd6-11eb-98c2-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1531](https://attack.mitre.org/techniques/T1531/) | Account Access Removal | Impact | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` values(Processes.process) as process values(Processes.parent_process) as parent_process values(Processes.process_id) as process_id count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_net` AND Processes.process="*user*" AND Processes.process="*/active:no*" by Processes.process_name Processes.original_file_name Processes.dest Processes.user Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `disabling_net_user_account_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_net](https://github.com/splunk/security_content/blob/develop/macros/process_net.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **disabling_net_user_account_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [XMRig](/stories/xmrig) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 42.0 | 70 | 60 | An instance of $parent_process_name$ spawning $process_name$ was identified disabling a user account on endpoint $dest$ by user $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/](https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disabling_net_user_account.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-05-04-excessive_attempt_to_disable_services.md b/docs/_posts/2021-05-04-excessive_attempt_to_disable_services.md deleted file mode 100644 index 5ca072aeea..0000000000 --- a/docs/_posts/2021-05-04-excessive_attempt_to_disable_services.md +++ /dev/null @@ -1,160 +0,0 @@ ---- -title: "Excessive Attempt To Disable Services" -excerpt: "Service Stop -" -categories: - - Endpoint -last_modified_at: 2021-05-04 -toc: true -toc_label: "" -tags: - - Service Stop - - Impact - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic will identify suspicious series of command-line to disable several services. This technique is seen where the adversary attempts to disable security app services or other malware services to complete the objective on the compromised system. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-05-04 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 8fa2a0f0-acd9-11eb-8994-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1489](https://attack.mitre.org/techniques/T1489/) | Service Stop | Impact | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` values(Processes.process) as process values(Processes.process_id) as process_id count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = "sc.exe" AND Processes.process="*config*" OR Processes.process="*Disabled*" by Processes.process_name Processes.parent_process_name Processes.dest Processes.user _time span=1m -| where count >=4 -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `excessive_attempt_to_disable_services_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **excessive_attempt_to_disable_services_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process -* Processes.process_id -* Processes.process_name -* Processes.parent_process_name -* Processes.dest -* Processes.user - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed sc.exe may be used. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [XMRig](/stories/xmrig) -* [Azorult](/stories/azorult) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | An excessive amount of $process_name$ was executed on $dest$ attempting to disable services. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/](https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/excessive_attempt_to_disable_services.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-05-04-excessive_service_stop_attempt.md b/docs/_posts/2021-05-04-excessive_service_stop_attempt.md deleted file mode 100644 index 95aba44e11..0000000000 --- a/docs/_posts/2021-05-04-excessive_service_stop_attempt.md +++ /dev/null @@ -1,166 +0,0 @@ ---- -title: "Excessive Service Stop Attempt" -excerpt: "Service Stop -" -categories: - - Endpoint -last_modified_at: 2021-05-04 -toc: true -toc_label: "" -tags: - - Service Stop - - Impact - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic identifies suspicious series of attempt to kill multiple services on a system using either `net.exe` or `sc.exe`. This technique is use by adversaries to terminate security services or other related services to continue there objective and evade detections. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-05-04 -- **Author**: Teoderick Contreras, Splunk -- **ID**: ae8d3f4a-acd7-11eb-8846-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1489](https://attack.mitre.org/techniques/T1489/) | Service Stop | Impact | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` values(Processes.process) as process values(Processes.process_id) as process_id count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_net` OR Processes.process_name = "sc.exe" OR Processes.process_name = "net1.exe" AND Processes.process="*stop*" OR Processes.process="*delete*" by Processes.process_name Processes.original_file_name Processes.parent_process_name Processes.dest Processes.user _time span=1m -| where count >=5 -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `excessive_service_stop_attempt_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_net](https://github.com/splunk/security_content/blob/develop/macros/process_net.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **excessive_service_stop_attempt_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [XMRig](/stories/xmrig) -* [Ransomware](/stories/ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | An excessive amount of $process_name$ was executed on $dest$ attempting to disable services. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/](https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/excessive_service_stop_attempt.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-05-04-excessive_usage_of_taskkill.md b/docs/_posts/2021-05-04-excessive_usage_of_taskkill.md deleted file mode 100644 index 33f149cc00..0000000000 --- a/docs/_posts/2021-05-04-excessive_usage_of_taskkill.md +++ /dev/null @@ -1,165 +0,0 @@ ---- -title: "Excessive Usage Of Taskkill" -excerpt: "Disable or Modify Tools -, Impair Defenses -" -categories: - - Endpoint -last_modified_at: 2021-05-04 -toc: true -toc_label: "" -tags: - - Disable or Modify Tools - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic identifies excessive usage of `taskkill.exe` application. This application is commonly used by adversaries to evade detections by killing security product processes or even other processes to evade detection. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-05-04 -- **Author**: Teoderick Contreras, Splunk -- **ID**: fe5bca48-accb-11eb-a67c-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` values(Processes.process) as process values(Processes.process_id) as process_id count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = "taskkill.exe" by Processes.parent_process_name Processes.process_name Processes.dest Processes.user _time span=1m -| where count >=10 -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `excessive_usage_of_taskkill_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **excessive_usage_of_taskkill_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.parent_process_name -* Processes.process_name -* Processes.dest -* Processes.user -* Processes.process -* Processes.process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed taskkill.exe may be used. - -#### Known False Positives -Unknown. Filter as needed. - -#### Associated Analytic story -* [XMRig](/stories/xmrig) -* [Azorult](/stories/azorult) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 28.0 | 40 | 70 | Excessive usage of taskkill.exe with process id $process_id$ (more than 10 within 1m) has been detected on $dest$ with a parent process of $parent_process_name$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/](https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/excessive_usage_of_taskkill.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-05-04-icacls_grant_command.md b/docs/_posts/2021-05-04-icacls_grant_command.md deleted file mode 100644 index 01c62fcfba..0000000000 --- a/docs/_posts/2021-05-04-icacls_grant_command.md +++ /dev/null @@ -1,159 +0,0 @@ ---- -title: "ICACLS Grant Command" -excerpt: "File and Directory Permissions Modification -" -categories: - - Endpoint -last_modified_at: 2021-05-04 -toc: true -toc_label: "" -tags: - - File and Directory Permissions Modification - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic identifies potential adversaries that modify the security permission of a specific file or directory. This technique is commonly seen in APT tradecraft and coinminer scripts to evade detections and restrict access to their component files. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-05-04 -- **Author**: Teoderick Contreras, Splunk -- **ID**: b1b1e316-accc-11eb-a9b4-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1222](https://attack.mitre.org/techniques/T1222/) | File and Directory Permissions Modification | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` values(Processes.process) as process values(Processes.process_id) as process_id count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = "icacls.exe" OR Processes.process_name = "cacls.exe" OR Processes.process_name = "xcacls.exe" AND Processes.process = "*/grant*" by Processes.parent_process_name Processes.process_name Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `icacls_grant_command_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **icacls_grant_command_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.parent_process_name -* Processes.process_name -* Processes.dest -* Processes.user -* Processes.process_id -* Processes.process - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed icacls.exe may be used. - -#### Known False Positives -Unknown. Filter as needed. - -#### Associated Analytic story -* [XMRig](/stories/xmrig) -* [Ransomware](/stories/ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | Process name $process_name$ with grant argument executed by $user$ to change security permission of a specific file or directory on host $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/](https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/icacls_grant_command.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-05-04-modify_acl_permission_to_files_or_folder.md b/docs/_posts/2021-05-04-modify_acl_permission_to_files_or_folder.md deleted file mode 100644 index 2f16ecbb28..0000000000 --- a/docs/_posts/2021-05-04-modify_acl_permission_to_files_or_folder.md +++ /dev/null @@ -1,109 +0,0 @@ ---- -title: "Modify ACL permission To Files Or Folder" -excerpt: "File and Directory Permissions Modification -" -categories: - - Endpoint -last_modified_at: 2021-05-04 -toc: true -toc_label: "" -tags: - - File and Directory Permissions Modification - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic identifies suspicious modification of ACL permission to a files or folder to make it available to everyone. This technique may be used by the adversary to evade ACLs or protected files access. This changes is commonly configured by the file or directory owner with appropriate permission. This behavior is a good indicator if this command seen on a machine utilized by an account with no permission to do so. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/object-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-05-04 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 7e8458cc-acca-11eb-9e3f-acde48001122 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1222](https://attack.mitre.org/techniques/T1222/) | File and Directory Permissions Modification | Defense Evasion | - -#### Search - -``` - -| tstats `security_content_summariesonly` values(Processes.process) as process values(Processes.process_id) as process_id count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = "cacls.exe" OR Processes.process_name = "icacls.exe" OR Processes.process_name = "xcacls.exe" AND (Processes.process = "*/G everyone:*" OR Processes.process = "*/G SYSTEM:*") by Processes.parent_process_name Processes.process_name Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `modify_acl_permission_to_files_or_folder_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -Note that `modify_acl_permission_to_files_or_folder_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.parent_process_name -* Processes.process_name -* Processes.dest -* Processes.user -* Processes.process -* Processes.process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed cacls.exe may be used. - -#### Known False Positives -administrators may use this command. Filter as needed. - -#### Associated Analytic story -* [XMRig](/stories/xmrig) - - -#### Kill Chain Phase -* Exploitation - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 32.0 | 40 | 80 | Suspicious ACL permission modification on $dest$ | - - - - -#### Reference - -* [https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/](https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-05-04-process_kill_base_on_file_path.md b/docs/_posts/2021-05-04-process_kill_base_on_file_path.md deleted file mode 100644 index bbecb9975f..0000000000 --- a/docs/_posts/2021-05-04-process_kill_base_on_file_path.md +++ /dev/null @@ -1,169 +0,0 @@ ---- -title: "Process Kill Base On File Path" -excerpt: "Disable or Modify Tools -, Impair Defenses -" -categories: - - Endpoint -last_modified_at: 2021-05-04 -toc: true -toc_label: "" -tags: - - Disable or Modify Tools - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the use of `wmic.exe` using `delete` to remove a executable path. This is typically ran via a batch file during beginning stages of an adversary setting up for mining on an endpoint. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-05-04 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 5ffaa42c-acdb-11eb-9ad3-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` values(Processes.process) as process values(Processes.process_id) as process_id count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_wmic` AND Processes.process="*process*" AND Processes.process="*executablepath*" AND Processes.process="*delete*" by Processes.parent_process_name Processes.process_name Processes.original_file_name Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `process_kill_base_on_file_path_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [process_wmic](https://github.com/splunk/security_content/blob/develop/macros/process_wmic.yml) - -> :information_source: -> **process_kill_base_on_file_path_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Unknown. - -#### Associated Analytic story -* [XMRig](/stories/xmrig) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 56.0 | 70 | 80 | A process $process_name$ attempt to kill process by its file path using commandline $process$ in host $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/](https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/process_kill_base_on_file_path.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-05-05-suspicious_process_file_path.md b/docs/_posts/2021-05-05-suspicious_process_file_path.md deleted file mode 100644 index 2fbb5278a8..0000000000 --- a/docs/_posts/2021-05-05-suspicious_process_file_path.md +++ /dev/null @@ -1,168 +0,0 @@ ---- -title: "Suspicious Process File Path" -excerpt: "Create or Modify System Process -" -categories: - - Endpoint -last_modified_at: 2021-05-05 -toc: true -toc_label: "" -tags: - - Create or Modify System Process - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic will detect a suspicious process running in a file path where a process is not commonly seen and is most commonly used by malicious software. This behavior has been used by adversaries where they drop and run an exe in a path that is accessible without admin privileges. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-05-05 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 9be25988-ad82-11eb-a14f-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1543](https://attack.mitre.org/techniques/T1543/) | Create or Modify System Process | Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count values(Processes.process_name) as process_name values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_path = "*\\windows\\fonts\\*" OR Processes.process_path = "*\\windows\\temp\\*" OR Processes.process_path = "*\\users\\public\\*" OR Processes.process_path = "*\\windows\\debug\\*" OR Processes.process_path.file_path = "*\\Users\\Administrator\\Music\\*" OR Processes.process_path.file_path = "*\\Windows\\servicing\\*" OR Processes.process_path.file_path = "*\\Users\\Default\\*" OR Processes.process_path.file_path = "*Recycle.bin*" OR Processes.process_path = "*\\Windows\\Media\\*" OR Processes.process_path = "\\Windows\\repair\\*" OR Processes.process_path = "*\\temp\\*" OR Processes.process_path = "*\\PerfLogs\\*" by Processes.parent_process_name Processes.parent_process Processes.process_path Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `suspicious_process_file_path_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **suspicious_process_file_path_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process_name -* Processes.process -* Processes.parent_process_name -* Processes.parent_process -* Processes.process_path -* Processes.dest -* Processes.user - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Administrators may allow execution of specific binaries in non-standard paths. Filter as needed. - -#### Associated Analytic story -* [Data Destruction](/stories/data_destruction) -* [Double Zero Destructor](/stories/double_zero_destructor) -* [XMRig](/stories/xmrig) -* [Remcos](/stories/remcos) -* [WhisperGate](/stories/whispergate) -* [Hermetic Wiper](/stories/hermetic_wiper) -* [Industroyer2](/stories/industroyer2) -* [DarkCrystal RAT](/stories/darkcrystal_rat) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 35.0 | 70 | 50 | Suspicioues process $Processes.process_path.file_path$ running from suspicious location | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.trendmicro.com/vinfo/hk/threat-encyclopedia/malware/trojan.ps1.powtran.a/](https://www.trendmicro.com/vinfo/hk/threat-encyclopedia/malware/trojan.ps1.powtran.a/) -* [https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/](https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/suspicious_process_file_path.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-05-06-download_files_using_telegram.md b/docs/_posts/2021-05-06-download_files_using_telegram.md deleted file mode 100644 index 43eaa37a0b..0000000000 --- a/docs/_posts/2021-05-06-download_files_using_telegram.md +++ /dev/null @@ -1,157 +0,0 @@ ---- -title: "Download Files Using Telegram" -excerpt: "Ingress Tool Transfer -" -categories: - - Endpoint -last_modified_at: 2021-05-06 -toc: true -toc_label: "" -tags: - - Ingress Tool Transfer - - Command And Control - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic will identify a suspicious download by the Telegram application on a Windows system. This behavior was identified on a honeypot where the adversary gained access, installed Telegram and followed through with downloading different network scanners (port, bruteforcer, masscan) to the system and later used to mapped the whole network and further move laterally. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-05-06 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 58194e28-ae5e-11eb-8912-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1105](https://attack.mitre.org/techniques/T1105/) | Ingress Tool Transfer | Command And Control | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventCode= 15 process_name = "telegram.exe" TargetFilename = "*:Zone.Identifier" -|stats count min(_time) as firstTime max(_time) as lastTime by Computer EventCode Image process_id TargetFilename Hash -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `download_files_using_telegram_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **download_files_using_telegram_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Computer -* EventCode -* Image -* process_id -* TargetFilename -* Hash - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name and TargetFilename from your endpoints or Events that monitor filestream events which is happened when process download something. (EventCode 15) If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -normal download of file in telegram app. (if it was a common app in network) - -#### Associated Analytic story -* [XMRig](/stories/xmrig) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | Suspicious files were downloaded with the Telegram application on $dest$ by $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/](https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/minergate/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/minergate/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/download_files_using_telegram.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-05-06-enumerate_users_local_group_using_telegram.md b/docs/_posts/2021-05-06-enumerate_users_local_group_using_telegram.md deleted file mode 100644 index 2283e7d33e..0000000000 --- a/docs/_posts/2021-05-06-enumerate_users_local_group_using_telegram.md +++ /dev/null @@ -1,161 +0,0 @@ ---- -title: "Enumerate Users Local Group Using Telegram" -excerpt: "Account Discovery -" -categories: - - Endpoint -last_modified_at: 2021-05-06 -toc: true -toc_label: "" -tags: - - Account Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic will detect a suspicious Telegram process enumerating all network users in a local group. This technique was seen in a Monero infected honeypot to mapped all the users on the compromised system. EventCode 4798 is generated when a process enumerates a user's security-enabled local groups on a computer or device. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-05-06 -- **Author**: Teoderick Contreras, Splunk -- **ID**: fcd74532-ae54-11eb-a5ab-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`wineventlog_security` EventCode=4798 Process_Name = "*\\telegram.exe" -| stats count min(_time) as firstTime max(_time) as lastTime by ComputerName EventCode Process_Name Process_ID Account_Name Account_Domain Logon_ID Security_ID Message -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `enumerate_users_local_group_using_telegram_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **enumerate_users_local_group_using_telegram_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* ComputerName -* EventCode -* Process_Name -* Process_ID -* Account_Name -* Account_Domain -* Logon_ID -* Security_ID -* Message - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the Task Schedule (Exa. Security Log EventCode 4798) endpoints. Tune and filter known instances of process like logonUI used in your environment. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [XMRig](/stories/xmrig) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | The Telegram application has been identified enumerating local groups on $ComputerName$ by $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/](https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/) -* [https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4798](https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4798) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/minergate/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/minergate/windows-security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-05-06-excessive_usage_of_net_app.md b/docs/_posts/2021-05-06-excessive_usage_of_net_app.md deleted file mode 100644 index 6fd3ea4bce..0000000000 --- a/docs/_posts/2021-05-06-excessive_usage_of_net_app.md +++ /dev/null @@ -1,167 +0,0 @@ ---- -title: "Excessive Usage Of Net App" -excerpt: "Account Access Removal -" -categories: - - Endpoint -last_modified_at: 2021-05-06 -toc: true -toc_label: "" -tags: - - Account Access Removal - - Impact - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic identifies excessive usage of `net.exe` or `net1.exe` within a bucket of time (1 minute). This behavior was seen in a Monero incident where the adversary attempts to create many users, delete and disable users as part of its malicious behavior. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-05-06 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 45e52536-ae42-11eb-b5c6-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1531](https://attack.mitre.org/techniques/T1531/) | Account Access Removal | Impact | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` values(Processes.process) as process values(Processes.process_id) as process_id count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_net` by Processes.process_name Processes.parent_process_name Processes.original_file_name Processes.dest Processes.user _time span=1m -| where count >=10 -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `excessive_usage_of_net_app_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_net](https://github.com/splunk/security_content/blob/develop/macros/process_net.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **excessive_usage_of_net_app_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -unknown. Filter as needed. Modify the time span as needed. - -#### Associated Analytic story -* [XMRig](/stories/xmrig) -* [Ransomware](/stories/ransomware) -* [Azorult](/stories/azorult) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 28.0 | 40 | 70 | Excessive usage of net1.exe or net.exe within 1m, with command line $process$ has been detected on $dest$ by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/](https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/excessive_usage_of_net_app.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-05-06-executables_or_script_creation_in_suspicious_path.md b/docs/_posts/2021-05-06-executables_or_script_creation_in_suspicious_path.md deleted file mode 100644 index c6c40096fe..0000000000 --- a/docs/_posts/2021-05-06-executables_or_script_creation_in_suspicious_path.md +++ /dev/null @@ -1,166 +0,0 @@ ---- -title: "Executables Or Script Creation In Suspicious Path" -excerpt: "Masquerading -" -categories: - - Endpoint -last_modified_at: 2021-05-06 -toc: true -toc_label: "" -tags: - - Masquerading - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic will identify suspicious executable or scripts (known file extensions) in list of suspicious file path in Windows. This technique is used by adversaries to evade detection. The suspicious file path are known paths used in the wild and are not common to have executable or scripts. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-05-06 -- **Author**: Teoderick Contreras, Splunk -- **ID**: a7e3f0f0-ae42-11eb-b245-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1036](https://attack.mitre.org/techniques/T1036/) | Masquerading | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -|tstats `security_content_summariesonly` values(Filesystem.file_path) as file_path count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Filesystem where (Filesystem.file_name = *.exe OR Filesystem.file_name = *.dll OR Filesystem.file_name = *.sys OR Filesystem.file_name = *.com OR Filesystem.file_name = *.vbs OR Filesystem.file_name = *.vbe OR Filesystem.file_name = *.js OR Filesystem.file_name = *.ps1 OR Filesystem.file_name = *.bat OR Filesystem.file_name = *.cmd OR Filesystem.file_name = *.pif) AND ( Filesystem.file_path = *\\windows\\fonts\\* OR Filesystem.file_path = *\\windows\\temp\\* OR Filesystem.file_path = *\\users\\public\\* OR Filesystem.file_path = *\\windows\\debug\\* OR Filesystem.file_path = *\\Users\\Administrator\\Music\\* OR Filesystem.file_path = *\\Windows\\servicing\\* OR Filesystem.file_path = *\\Users\\Default\\* OR Filesystem.file_path = *Recycle.bin* OR Filesystem.file_path = *\\Windows\\Media\\* OR Filesystem.file_path = *\\Windows\\repair\\* OR Filesystem.file_path = *\\AppData\\Local\\Temp* OR Filesystem.file_path = *\\PerfLogs\\*) by Filesystem.file_create_time Filesystem.process_id Filesystem.file_name Filesystem.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `executables_or_script_creation_in_suspicious_path_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **executables_or_script_creation_in_suspicious_path_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Filesystem.file_path -* Filesystem.file_create_time -* Filesystem.process_id -* Filesystem.file_name -* Filesystem.user - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the Filesystem responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Filesystem` node. - -#### Known False Positives -Administrators may allow creation of script or exe in the paths specified. Filter as needed. - -#### Associated Analytic story -* [Double Zero Destructor](/stories/double_zero_destructor) -* [Data Destruction](/stories/data_destruction) -* [XMRig](/stories/xmrig) -* [Remcos](/stories/remcos) -* [WhisperGate](/stories/whispergate) -* [Hermetic Wiper](/stories/hermetic_wiper) -* [Industroyer2](/stories/industroyer2) -* [Azorult](/stories/azorult) -* [DarkCrystal RAT](/stories/darkcrystal_rat) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 56.0 | 80 | 70 | Suspicious executable or scripts with file name $file_name$, $file_path$ and process_id $process_id$ executed in suspicious file path in Windows by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/](https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/) -* [https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/](https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-05-07-excessive_usage_of_cacls_app.md b/docs/_posts/2021-05-07-excessive_usage_of_cacls_app.md deleted file mode 100644 index 39668c135d..0000000000 --- a/docs/_posts/2021-05-07-excessive_usage_of_cacls_app.md +++ /dev/null @@ -1,160 +0,0 @@ ---- -title: "Excessive Usage Of Cacls App" -excerpt: "File and Directory Permissions Modification -" -categories: - - Endpoint -last_modified_at: 2021-05-07 -toc: true -toc_label: "" -tags: - - File and Directory Permissions Modification - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies excessive usage of `cacls.exe`, `xcacls.exe` or `icacls.exe` application to change file or folder permission. This behavior is commonly seen where the adversary attempts to impair some users from deleting or accessing its malware components or artifact from the compromised system. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-05-07 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 0bdf6092-af17-11eb-939a-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1222](https://attack.mitre.org/techniques/T1222/) | File and Directory Permissions Modification | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` values(Processes.process) as process values(Processes.process_id) as process_id values(Processes.process_name) as process_name count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = "cacls.exe" OR Processes.process_name = "icacls.exe" OR Processes.process_name = "XCACLS.exe" by Processes.parent_process_name Processes.parent_process Processes.dest Processes.user _time span=1m -| where count >=10 -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `excessive_usage_of_cacls_app_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **excessive_usage_of_cacls_app_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process -* Processes.process_id -* Processes.process_name -* Processes.parent_process_name -* Processes.dest -* Processes.user - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Administrators or administrative scripts may use this application. Filter as needed. - -#### Associated Analytic story -* [XMRig](/stories/xmrig) -* [Azorult](/stories/azorult) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | An excessive amount of $process_name$ was executed on $dest$ attempting to modify permissions. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/](https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/excessive_usage_of_cacls_app.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-05-07-schtasks_run_task_on_demand.md b/docs/_posts/2021-05-07-schtasks_run_task_on_demand.md deleted file mode 100644 index 9e8d148a76..0000000000 --- a/docs/_posts/2021-05-07-schtasks_run_task_on_demand.md +++ /dev/null @@ -1,161 +0,0 @@ ---- -title: "Schtasks Run Task On Demand" -excerpt: "Scheduled Task/Job -" -categories: - - Endpoint -last_modified_at: 2021-05-07 -toc: true -toc_label: "" -tags: - - Scheduled Task/Job - - Execution - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic identifies an on demand run of a Windows Schedule Task through shell or command-line. This technique has been used by adversaries that force to run their created Schedule Task as their persistence mechanism or for lateral movement as part of their malicious attack to the compromised machine. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-05-07 -- **Author**: Teoderick Contreras, Splunk -- **ID**: bb37061e-af1f-11eb-a159-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1053](https://attack.mitre.org/techniques/T1053/) | Scheduled Task/Job | Execution, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` values(Processes.process) as process values(Processes.process_id) as process_id count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = "schtasks.exe" Processes.process = "*/run*" by Processes.process_name Processes.parent_process_name Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `schtasks_run_task_on_demand_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **schtasks_run_task_on_demand_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process -* Processes.process_id -* Processes.process_name -* Processes.parent_process_name -* Processes.dest -* Processes.user - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed schtasks.exe may be used. - -#### Known False Positives -Administrators may use to debug Schedule Task entries. Filter as needed. - -#### Associated Analytic story -* [XMRig](/stories/xmrig) -* [Industroyer2](/stories/industroyer2) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 48.0 | 60 | 80 | A "on demand" execution of schedule task process $process_name$ using commandline $process$ in host $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/](https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/schtasks_run_task_on_demand.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-05-12-delete_shadowcopy_with_powershell.md b/docs/_posts/2021-05-12-delete_shadowcopy_with_powershell.md deleted file mode 100644 index d129b3c343..0000000000 --- a/docs/_posts/2021-05-12-delete_shadowcopy_with_powershell.md +++ /dev/null @@ -1,158 +0,0 @@ ---- -title: "Delete ShadowCopy With PowerShell" -excerpt: "Inhibit System Recovery -" -categories: - - Endpoint -last_modified_at: 2021-05-12 -toc: true -toc_label: "" -tags: - - Inhibit System Recovery - - Impact - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This following analytic detects PowerShell command to delete shadow copy using the WMIC PowerShell module. This technique was seen used by a recent adversary to deploy DarkSide Ransomware where it executed a child process of PowerShell to execute a hex encoded command to delete shadow copy. This hex encoded command was able to be decrypted by PowerShell log. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-05-12 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 5ee2bcd0-b2ff-11eb-bb34-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1490](https://attack.mitre.org/techniques/T1490/) | Inhibit System Recovery | Impact | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 Message= "*ShadowCopy*" (Message = "*Delete*" OR Message = "*Remove*") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `delete_shadowcopy_with_powershell_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **delete_shadowcopy_with_powershell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Message -* ComputerName -* User - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the powershell logs from your endpoints. make sure you enable needed registry to monitor this event. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [DarkSide Ransomware](/stories/darkside_ransomware) -* [Ransomware](/stories/ransomware) -* [Revil Ransomware](/stories/revil_ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 81.0 | 90 | 90 | An attempt to delete ShadowCopy was performed using PowerShell on $ComputerName$ by $User$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.mandiant.com/resources/shining-a-light-on-darkside-ransomware-operations](https://www.mandiant.com/resources/shining-a-light-on-darkside-ransomware-operations) -* [https://www.techtarget.com/searchwindowsserver/tutorial/Set-up-PowerShell-script-block-logging-for-added-security](https://www.techtarget.com/searchwindowsserver/tutorial/Set-up-PowerShell-script-block-logging-for-added-security) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/revil/inf1/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/revil/inf1/windows-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/delete_shadowcopy_with_powershell.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-05-13-cmlua_or_cmstplua_uac_bypass.md b/docs/_posts/2021-05-13-cmlua_or_cmstplua_uac_bypass.md deleted file mode 100644 index 64ff8b9995..0000000000 --- a/docs/_posts/2021-05-13-cmlua_or_cmstplua_uac_bypass.md +++ /dev/null @@ -1,164 +0,0 @@ ---- -title: "CMLUA Or CMSTPLUA UAC Bypass" -excerpt: "System Binary Proxy Execution -, CMSTP -" -categories: - - Endpoint -last_modified_at: 2021-05-13 -toc: true -toc_label: "" -tags: - - System Binary Proxy Execution - - CMSTP - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic detects a potential process using COM Object like CMLUA or CMSTPLUA to bypass UAC. This technique has been used by ransomware adversaries to gain administrative privileges to its running process. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-05-13 -- **Author**: Teoderick Contreras, Splunk -- **ID**: f87b5062-b405-11eb-a889-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218](https://attack.mitre.org/techniques/T1218/) | System Binary Proxy Execution | Defense Evasion | - -| [T1218.003](https://attack.mitre.org/techniques/T1218/003/) | CMSTP | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventCode=7 ImageLoaded IN ("*\\CMLUA.dll", "*\\CMSTPLUA.dll", "*\\CMLUAUTIL.dll") NOT(process_name IN("CMSTP.exe", "CMMGR32.exe")) NOT(Image IN("*\\windows\\*", "*\\program files*")) -| stats count min(_time) as firstTime max(_time) as lastTime by Image ImageLoaded process_name Computer EventCode Signed ProcessId -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `cmlua_or_cmstplua_uac_bypass_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **cmlua_or_cmstplua_uac_bypass_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Image -* ImageLoaded -* process_name -* Computer -* EventCode -* Signed -* ProcessId - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name and imageloaded executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -Legitimate windows application that are not on the list loading this dll. Filter as needed. - -#### Associated Analytic story -* [DarkSide Ransomware](/stories/darkside_ransomware) -* [Ransomware](/stories/ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | The following module $ImageLoaded$ was loaded by a non-standard application on endpoint $Computer$ by user $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1218/003/](https://attack.mitre.org/techniques/T1218/003/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/darkside_cmstp_com/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/darkside_cmstp_com/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-05-13-slui_runas_elevated.md b/docs/_posts/2021-05-13-slui_runas_elevated.md deleted file mode 100644 index 9467a16fca..0000000000 --- a/docs/_posts/2021-05-13-slui_runas_elevated.md +++ /dev/null @@ -1,171 +0,0 @@ ---- -title: "SLUI RunAs Elevated" -excerpt: "Bypass User Account Control -, Abuse Elevation Control Mechanism -" -categories: - - Endpoint -last_modified_at: 2021-05-13 -toc: true -toc_label: "" -tags: - - Bypass User Account Control - - Abuse Elevation Control Mechanism - - Defense Evasion - - Privilege Escalation - - Defense Evasion - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the Microsoft Software Licensing User Interface Tool, `slui.exe`, elevating access using the `-verb runas` function. This particular bypass utilizes a registry key/value. Identified by two sources, the registry keys are `HKCU\Software\Classes\exefile\shell` and `HKCU\Software\Classes\launcher.Systemsettings\Shell\open\command`. To simulate this behavior, multiple POC are available. The analytic identifies the use of `runas` by `slui.exe`. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-05-13 -- **Author**: Michael Haag, Splunk -- **ID**: 8d124810-b3e4-11eb-96c7-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1548.002](https://attack.mitre.org/techniques/T1548/002/) | Bypass User Account Control | Defense Evasion, Privilege Escalation | - -| [T1548](https://attack.mitre.org/techniques/T1548/) | Abuse Elevation Control Mechanism | Defense Evasion, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=slui.exe (Processes.process=*-verb* Processes.process=*runas*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `slui_runas_elevated_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **slui_runas_elevated_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Limited false positives should be present as this is not commonly used by legitimate applications. - -#### Associated Analytic story -* [DarkSide Ransomware](/stories/darkside_ransomware) -* [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 63.0 | 70 | 90 | A slui process $process_name$ with elevated commandline $process$ in host $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.exploit-db.com/exploits/46998](https://www.exploit-db.com/exploits/46998) -* [https://mattharr0ey.medium.com/privilege-escalation-uac-bypass-in-changepk-c40b92818d1b](https://mattharr0ey.medium.com/privilege-escalation-uac-bypass-in-changepk-c40b92818d1b) -* [https://gist.github.com/r00t-3xp10it/0c92cd554d3156fd74f6c25660ccc466](https://gist.github.com/r00t-3xp10it/0c92cd554d3156fd74f6c25660ccc466) -* [https://www.rapid7.com/db/modules/exploit/windows/local/bypassuac_sluihijack/](https://www.rapid7.com/db/modules/exploit/windows/local/bypassuac_sluihijack/) -* [https://www.mandiant.com/resources/shining-a-light-on-darkside-ransomware-operations](https://www.mandiant.com/resources/shining-a-light-on-darkside-ransomware-operations) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.002/slui/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.002/slui/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/slui_runas_elevated.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-05-13-slui_spawning_a_process.md b/docs/_posts/2021-05-13-slui_spawning_a_process.md deleted file mode 100644 index ae5608e181..0000000000 --- a/docs/_posts/2021-05-13-slui_spawning_a_process.md +++ /dev/null @@ -1,169 +0,0 @@ ---- -title: "SLUI Spawning a Process" -excerpt: "Bypass User Account Control -, Abuse Elevation Control Mechanism -" -categories: - - Endpoint -last_modified_at: 2021-05-13 -toc: true -toc_label: "" -tags: - - Bypass User Account Control - - Abuse Elevation Control Mechanism - - Defense Evasion - - Privilege Escalation - - Defense Evasion - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the Microsoft Software Licensing User Interface Tool, `slui.exe`, spawning a child process. This behavior is associated with publicly known UAC bypass. `slui.exe` is commonly associated with software updates and is most often spawned by `svchost.exe`. The `slui.exe` process should not have child processes, and any processes spawning from it will be running with elevated privileges. During triage, review the child process and additional parallel processes. Identify any file modifications that may have lead to the bypass. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-05-13 -- **Author**: Michael Haag, Splunk -- **ID**: 879c4330-b3e0-11eb-b1b1-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1548.002](https://attack.mitre.org/techniques/T1548/002/) | Bypass User Account Control | Defense Evasion, Privilege Escalation | - -| [T1548](https://attack.mitre.org/techniques/T1548/) | Abuse Elevation Control Mechanism | Defense Evasion, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=slui.exe by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `slui_spawning_a_process_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **slui_spawning_a_process_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Certain applications may spawn from `slui.exe` that are legitimate. Filtering will be needed to ensure proper monitoring. - -#### Associated Analytic story -* [DarkSide Ransomware](/stories/darkside_ransomware) -* [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 63.0 | 70 | 90 | A slui process $parent_process_name$ spawning child process $process_name$ in host $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.exploit-db.com/exploits/46998](https://www.exploit-db.com/exploits/46998) -* [https://www.rapid7.com/db/modules/exploit/windows/local/bypassuac_sluihijack/](https://www.rapid7.com/db/modules/exploit/windows/local/bypassuac_sluihijack/) -* [https://www.mandiant.com/resources/shining-a-light-on-darkside-ransomware-operations](https://www.mandiant.com/resources/shining-a-light-on-darkside-ransomware-operations) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.002/slui/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.002/slui/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/slui_spawning_a_process.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-05-18-services_escalate_exe.md b/docs/_posts/2021-05-18-services_escalate_exe.md deleted file mode 100644 index 611bdb3994..0000000000 --- a/docs/_posts/2021-05-18-services_escalate_exe.md +++ /dev/null @@ -1,162 +0,0 @@ ---- -title: "Services Escalate Exe" -excerpt: "Abuse Elevation Control Mechanism -" -categories: - - Endpoint -last_modified_at: 2021-05-18 -toc: true -toc_label: "" -tags: - - Abuse Elevation Control Mechanism - - Defense Evasion - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the use of `svc-exe` with Cobalt Strike. The behavior typically follows after an adversary has already gained initial access and is escalating privileges. Using `svc-exe`, a randomly named binary will be downloaded from the remote Teamserver and placed on disk within `C:\Windows\400619a.exe`. Following, the binary will be added to the registry under key `HKLM\System\CurrentControlSet\Services\400619a\` with multiple keys and values added to look like a legitimate service. Upon loading, `services.exe` will spawn the randomly named binary from `\\127.0.0.1\ADMIN$\400619a.exe`. The process lineage is completed with `400619a.exe` spawning rundll32.exe, which is the default `spawnto_` value for Cobalt Strike. The `spawnto_` value is arbitrary and may be any process on disk (typically system32/syswow64 binary). The `spawnto_` process will also contain a network connection. During triage, review parallel procesess and identify any additional file modifications. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-05-18 -- **Author**: Michael Haag, Splunk -- **ID**: c448488c-b7ec-11eb-8253-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1548](https://attack.mitre.org/techniques/T1548/) | Abuse Elevation Control Mechanism | Defense Evasion, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=services.exe Processes.process_path=*admin$* by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `services_escalate_exe_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **services_escalate_exe_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you will need to ensure that DNS data is populating the Network_Resolution data model. - -#### Known False Positives -False positives should be limited as `services.exe` should never spawn a process from `ADMIN$`. Filter as needed. - -#### Associated Analytic story -* [Cobalt Strike](/stories/cobalt_strike) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 76.0 | 80 | 95 | A service process $parent_process_name$ with process path $process_path$ in host $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://thedfirreport.com/2021/03/29/sodinokibi-aka-revil-ransomware/](https://thedfirreport.com/2021/03/29/sodinokibi-aka-revil-ransomware/) -* [https://attack.mitre.org/techniques/T1548/](https://attack.mitre.org/techniques/T1548/) -* [https://hstechdocs.helpsystems.com/manuals/cobaltstrike/current/userguide/index.htm#cshid=1085](https://hstechdocs.helpsystems.com/manuals/cobaltstrike/current/userguide/index.htm#cshid=1085) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/services_escalate_exe.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-05-19-allow_inbound_traffic_in_firewall_rule.md b/docs/_posts/2021-05-19-allow_inbound_traffic_in_firewall_rule.md deleted file mode 100644 index 9f0639ec6f..0000000000 --- a/docs/_posts/2021-05-19-allow_inbound_traffic_in_firewall_rule.md +++ /dev/null @@ -1,160 +0,0 @@ ---- -title: "Allow Inbound Traffic In Firewall Rule" -excerpt: "Remote Desktop Protocol -, Remote Services -" -categories: - - Endpoint -last_modified_at: 2021-05-19 -toc: true -toc_label: "" -tags: - - Remote Desktop Protocol - - Remote Services - - Lateral Movement - - Lateral Movement - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies suspicious PowerShell command to allow inbound traffic inbound to a specific local port within the public profile. This technique was seen in some attacker want to have a remote access to a machine by allowing the traffic in firewall rule. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-05-19 -- **Author**: Teoderick Contreras, Splunk -- **ID**: a5d85486-b89c-11eb-8267-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1021.001](https://attack.mitre.org/techniques/T1021/001/) | Remote Desktop Protocol | Lateral Movement | - -| [T1021](https://attack.mitre.org/techniques/T1021/) | Remote Services | Lateral Movement | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 Message = "*firewall*" Message = "*Inbound*" Message = "*Allow*" Message = "*-LocalPort*" -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `allow_inbound_traffic_in_firewall_rule_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **allow_inbound_traffic_in_firewall_rule_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Message -* ComputerName -* User - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the powershell logs from your endpoints. make sure you enable needed registry to monitor this event. - -#### Known False Positives -administrator may allow inbound traffic in certain network or machine. - -#### Associated Analytic story -* [Prohibited Traffic Allowed or Protocol Mismatch](/stories/prohibited_traffic_allowed_or_protocol_mismatch) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 3.0 | 10 | 30 | Suspicious firewall modification detected on endpoint $ComputerName$ by user $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://docs.microsoft.com/en-us/powershell/module/netsecurity/new-netfirewallrule?view=windowsserver2019-ps](https://docs.microsoft.com/en-us/powershell/module/netsecurity/new-netfirewallrule?view=windowsserver2019-ps) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/casper/datasets1/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/casper/datasets1/windows-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-05-19-mailsniper_invoke_functions.md b/docs/_posts/2021-05-19-mailsniper_invoke_functions.md deleted file mode 100644 index e5e1267fc9..0000000000 --- a/docs/_posts/2021-05-19-mailsniper_invoke_functions.md +++ /dev/null @@ -1,160 +0,0 @@ ---- -title: "Mailsniper Invoke functions" -excerpt: "Email Collection -, Local Email Collection -" -categories: - - Endpoint -last_modified_at: 2021-05-19 -toc: true -toc_label: "" -tags: - - Email Collection - - Local Email Collection - - Collection - - Collection - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect known mailsniper.ps1 functions executed in a machine. This technique was seen in some attacker to harvest some sensitive e-mail in a compromised exchange server. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-05-19 -- **Author**: Teoderick Contreras, Splunk -- **ID**: a36972c8-b894-11eb-9f78-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1114](https://attack.mitre.org/techniques/T1114/) | Email Collection | Collection | - -| [T1114.001](https://attack.mitre.org/techniques/T1114/001/) | Local Email Collection | Collection | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 Message IN ("*Invoke-GlobalO365MailSearch*", "*Invoke-GlobalMailSearch*", "*Invoke-SelfSearch*", "*Invoke-PasswordSprayOWA*", "*Invoke-PasswordSprayEWS*","*Invoke-DomainHarvestOWA*", "*Invoke-UsernameHarvestOWA*","*Invoke-OpenInboxFinder*","*Invoke-InjectGEventAPI*","*Invoke-InjectGEvent*","*Invoke-SearchGmail*", "*Invoke-MonitorCredSniper*", "*Invoke-AddGmailRule*","*Invoke-PasswordSprayEAS*","*Invoke-UsernameHarvestEAS*") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `mailsniper_invoke_functions_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **mailsniper_invoke_functions_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Message -* ComputerName -* User - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the powershell logs from your endpoints. make sure you enable needed registry to monitor this event. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Data Exfiltration](/stories/data_exfiltration) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 72.0 | 90 | 80 | mailsniper.ps1 functions $Message$ executed on a $ComputerName$ by user $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.blackhillsinfosec.com/introducing-mailsniper-a-tool-for-searching-every-users-email-for-sensitive-data/](https://www.blackhillsinfosec.com/introducing-mailsniper-a-tool-for-searching-every-users-email-for-sensitive-data/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/casper/datasets1/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/casper/datasets1/windows-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/mailsniper_invoke_functions.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-05-20-cmd_echo_pipe_-_escalation.md b/docs/_posts/2021-05-20-cmd_echo_pipe_-_escalation.md deleted file mode 100644 index 1ed5f0e08d..0000000000 --- a/docs/_posts/2021-05-20-cmd_echo_pipe_-_escalation.md +++ /dev/null @@ -1,182 +0,0 @@ ---- -title: "CMD Echo Pipe - Escalation" -excerpt: "Command and Scripting Interpreter -, Windows Command Shell -, Windows Service -, Create or Modify System Process -" -categories: - - Endpoint -last_modified_at: 2021-05-20 -toc: true -toc_label: "" -tags: - - Command and Scripting Interpreter - - Windows Command Shell - - Windows Service - - Create or Modify System Process - - Execution - - Execution - - Persistence - - Privilege Escalation - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic identifies a common behavior by Cobalt Strike and other frameworks where the adversary will escalate privileges, either via `jump` (Cobalt Strike PTH) or `getsystem`, using named-pipe impersonation. A suspicious event will look like `cmd.exe /c echo 4sgryt3436 > \\.\Pipe\5erg53`. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-05-20 -- **Author**: Michael Haag, Splunk -- **ID**: eb277ba0-b96b-11eb-b00e-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -| [T1059.003](https://attack.mitre.org/techniques/T1059/003/) | Windows Command Shell | Execution | - -| [T1543.003](https://attack.mitre.org/techniques/T1543/003/) | Windows Service | Persistence, Privilege Escalation | - -| [T1543](https://attack.mitre.org/techniques/T1543/) | Create or Modify System Process | Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_cmd` OR Processes.process=*%comspec%* (Processes.process=*echo* AND Processes.process=*pipe*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `cmd_echo_pipe___escalation_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [process_cmd](https://github.com/splunk/security_content/blob/develop/macros/process_cmd.yml) - -> :information_source: -> **cmd_echo_pipe_-_escalation_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Unknown. It is possible filtering may be required to ensure fidelity. - -#### Associated Analytic story -* [Cobalt Strike](/stories/cobalt_strike) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 64.0 | 80 | 80 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ potentially performing privilege escalation using named pipes related to Cobalt Strike and other frameworks. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://redcanary.com/threat-detection-report/threats/cobalt-strike/](https://redcanary.com/threat-detection-report/threats/cobalt-strike/) -* [https://github.com/rapid7/meterpreter/blob/master/source/extensions/priv/server/elevate/namedpipe.c](https://github.com/rapid7/meterpreter/blob/master/source/extensions/priv/server/elevate/namedpipe.c) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/cmd_echo_pipe___escalation.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-05-21-winrm_spawning_a_process.md b/docs/_posts/2021-05-21-winrm_spawning_a_process.md deleted file mode 100644 index 60c4fd6778..0000000000 --- a/docs/_posts/2021-05-21-winrm_spawning_a_process.md +++ /dev/null @@ -1,166 +0,0 @@ ---- -title: "WinRM Spawning a Process" -excerpt: "Exploit Public-Facing Application -" -categories: - - Endpoint -last_modified_at: 2021-05-21 -toc: true -toc_label: "" -tags: - - Exploit Public-Facing Application - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2021-31166 - - Endpoint ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies suspicious processes spawning from WinRM (wsmprovhost.exe). This analytic is related to potential exploitation of CVE-2021-31166. which is a kernel-mode device driver http.sys vulnerability. Current proof of concept code will blue-screen the operating system. However, http.sys used by many different Windows processes, including WinRM. In this case, identifying suspicious process create (child processes) from `wsmprovhost.exe` is what this analytic is identifying. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-05-21 -- **Author**: Drew Church, Michael Haag, Splunk -- **ID**: a081836a-ba4d-11eb-8593-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1190](https://attack.mitre.org/techniques/T1190/) | Exploit Public-Facing Application | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation -* Actions on Objectives - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2021-31166](https://nvd.nist.gov/vuln/detail/CVE-2021-31166) | HTTP Protocol Stack Remote Code Execution Vulnerability | 7.5 | - - - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=wsmprovhost.exe Processes.process_name IN ("cmd.exe","sh.exe","bash.exe","powershell.exe","pwsh.exe","schtasks.exe","certutil.exe","whoami.exe","bitsadmin.exe","scp.exe") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `winrm_spawning_a_process_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **winrm_spawning_a_process_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Unknown. Add new processes or filter as needed. It is possible system management software may spawn processes from `wsmprovhost.exe`. - -#### Associated Analytic story -* [Unusual Processes](/stories/unusual_processes) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/SigmaHQ/sigma/blob/9b7fb0c0f3af2e53ed483e29e0d0f88ccf1c08ca/rules/windows/process_access/win_susp_shell_spawn_from_winrm.yml](https://github.com/SigmaHQ/sigma/blob/9b7fb0c0f3af2e53ed483e29e0d0f88ccf1c08ca/rules/windows/process_access/win_susp_shell_spawn_from_winrm.yml) -* [https://www.zerodayinitiative.com/blog/2021/5/17/cve-2021-31166-a-wormable-code-execution-bug-in-httpsys](https://www.zerodayinitiative.com/blog/2021/5/17/cve-2021-31166-a-wormable-code-execution-bug-in-httpsys) -* [https://github.com/0vercl0k/CVE-2021-31166/blob/main/cve-2021-31166.py](https://github.com/0vercl0k/CVE-2021-31166/blob/main/cve-2021-31166.py) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/endpoint/winrm_spawning_a_process.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-05-26-secretdumps_offline_ntds_dumping_tool.md b/docs/_posts/2021-05-26-secretdumps_offline_ntds_dumping_tool.md deleted file mode 100644 index 42ee811fe0..0000000000 --- a/docs/_posts/2021-05-26-secretdumps_offline_ntds_dumping_tool.md +++ /dev/null @@ -1,165 +0,0 @@ ---- -title: "SecretDumps Offline NTDS Dumping Tool" -excerpt: "NTDS -, OS Credential Dumping -" -categories: - - Endpoint -last_modified_at: 2021-05-26 -toc: true -toc_label: "" -tags: - - NTDS - - OS Credential Dumping - - Credential Access - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic detects a potential usage of secretsdump.py tool for dumping credentials (ntlm hash) from a copy of ntds.dit and SAM.Security,SYSTEM registrry hive. This technique was seen in some attacker that dump ntlm hashes offline after having a copy of ntds.dit and SAM/SYSTEM/SECURITY registry hive. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-05-26 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 5672819c-be09-11eb-bbfb-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1003.003](https://attack.mitre.org/techniques/T1003/003/) | NTDS | Credential Access | - -| [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = "python*.exe" Processes.process = "*.py*" Processes.process = "*-ntds*" (Processes.process = "*-system*" OR Processes.process = "*-sam*" OR Processes.process = "*-security*" OR Processes.process = "*-bootkey*") by Processes.process_name Processes.process Processes.parent_process_name Processes.parent_process Processes.dest Processes.user Processes.process_id Processes.process_guid -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `secretdumps_offline_ntds_dumping_tool_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **secretdumps_offline_ntds_dumping_tool_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process_name -* Processes.process -* Processes.parent_process_name -* Processes.parent_process -* Processes.dest -* Processes.user -* Processes.process_id -* Processes.process_guid - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Credential Dumping](/stories/credential_dumping) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | A secretdump process $process_name$ with secretdump commandline $process$ to dump credentials in host $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/SecureAuthCorp/impacket/blob/master/examples/secretsdump.py](https://github.com/SecureAuthCorp/impacket/blob/master/examples/secretsdump.py) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/casper/datasets1/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/casper/datasets1/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-05-27-detect_sharphound_file_modifications.md b/docs/_posts/2021-05-27-detect_sharphound_file_modifications.md deleted file mode 100644 index f6da8244e1..0000000000 --- a/docs/_posts/2021-05-27-detect_sharphound_file_modifications.md +++ /dev/null @@ -1,192 +0,0 @@ ---- -title: "Detect SharpHound File Modifications" -excerpt: "Domain Account -, Local Groups -, Domain Trust Discovery -, Local Account -, Account Discovery -, Domain Groups -, Permission Groups Discovery -" -categories: - - Endpoint -last_modified_at: 2021-05-27 -toc: true -toc_label: "" -tags: - - Domain Account - - Local Groups - - Domain Trust Discovery - - Local Account - - Account Discovery - - Domain Groups - - Permission Groups Discovery - - Discovery - - Discovery - - Discovery - - Discovery - - Discovery - - Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -SharpHound is used as a reconnaissance collector, ingestor, for BloodHound. SharpHound will query the domain controller and begin gathering all the data related to the domain and trusts. For output, it will drop a .zip file upon completion following a typical pattern that is often not changed. This analytic focuses on the default file name scheme. Note that this may be evaded with different parameters within SharpHound, but that depends on the operator. `-randomizefilenames` and `-encryptzip` are two examples. In addition, executing SharpHound via .exe or .ps1 without any command-line arguments will still perform activity and dump output to the default filename. Example default filename `20210601181553_BloodHound.zip`. SharpHound creates multiple temp files following the same pattern `20210601182121_computers.json`, `domains.json`, `gpos.json`, `ous.json` and `users.json`. Tuning may be required, or remove these json's entirely if it is too noisy. During traige, review parallel processes for further suspicious behavior. Typically, the process executing the `.ps1` ingestor will be PowerShell. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-05-27 -- **Author**: Michael Haag, Splunk -- **ID**: 42b4b438-beed-11eb-ba1d-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery | - -| [T1069.001](https://attack.mitre.org/techniques/T1069/001/) | Local Groups | Discovery | - -| [T1482](https://attack.mitre.org/techniques/T1482/) | Domain Trust Discovery | Discovery | - -| [T1087.001](https://attack.mitre.org/techniques/T1087/001/) | Local Account | Discovery | - -| [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - -| [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery | - -| [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Filesystem where Filesystem.file_name IN ("*bloodhound.zip", "*_computers.json", "*_gpos.json", "*_domains.json", "*_users.json", "*_groups.json") by Filesystem.file_create_time Filesystem.process_id Filesystem.file_name Filesystem.file_path Filesystem.dest -| `drop_dm_object_name(Filesystem)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_sharphound_file_modifications_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **detect_sharphound_file_modifications_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* file_path -* dest -* file_name -* process_id -* file_create_time - - -#### How To Implement -To successfully implement this search you need to be ingesting information on file modifications that include the name of the process, and file, responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Filesystem` node. - -#### Known False Positives -False positives should be limited as the analytic is specific to a filename with extension .zip. Filter as needed. - -#### Associated Analytic story -* [Discovery Techniques](/stories/discovery_techniques) -* [Ransomware](/stories/ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 24.0 | 30 | 80 | Potential SharpHound file modifications identified on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/software/S0521/](https://attack.mitre.org/software/S0521/) -* [https://thedfirreport.com/?s=bloodhound](https://thedfirreport.com/?s=bloodhound) -* [https://github.com/BloodHoundAD/BloodHound/tree/master/Collectors](https://github.com/BloodHoundAD/BloodHound/tree/master/Collectors) -* [https://github.com/BloodHoundAD/SharpHound3](https://github.com/BloodHoundAD/SharpHound3) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1059.001/T1059.001.md#atomic-test-2---run-bloodhound-from-local-disk](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1059.001/T1059.001.md#atomic-test-2---run-bloodhound-from-local-disk) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/sharphound/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/sharphound/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/detect_sharphound_file_modifications.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-05-27-detect_sharphound_usage.md b/docs/_posts/2021-05-27-detect_sharphound_usage.md deleted file mode 100644 index 3fe7723c86..0000000000 --- a/docs/_posts/2021-05-27-detect_sharphound_usage.md +++ /dev/null @@ -1,198 +0,0 @@ ---- -title: "Detect SharpHound Usage" -excerpt: "Domain Account -, Local Groups -, Domain Trust Discovery -, Local Account -, Account Discovery -, Domain Groups -, Permission Groups Discovery -" -categories: - - Endpoint -last_modified_at: 2021-05-27 -toc: true -toc_label: "" -tags: - - Domain Account - - Local Groups - - Domain Trust Discovery - - Local Account - - Account Discovery - - Domain Groups - - Permission Groups Discovery - - Discovery - - Discovery - - Discovery - - Discovery - - Discovery - - Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies SharpHound binary usage by using the original filena,e. In addition to renaming the PE, other coverage is available to detect command-line arguments. This particular analytic looks for the original_file_name of `SharpHound.exe` and the process name. It is possible older instances of SharpHound.exe have different original filenames. Dependent upon the operator, the code may be re-compiled and the attributes removed or changed to anything else. During triage, review the metadata of the binary in question. Review parallel processes for suspicious behavior. Identify the source of this binary. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-05-27 -- **Author**: Michael Haag, Splunk -- **ID**: dd04b29a-beed-11eb-87bc-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery | - -| [T1069.001](https://attack.mitre.org/techniques/T1069/001/) | Local Groups | Discovery | - -| [T1482](https://attack.mitre.org/techniques/T1482/) | Domain Trust Discovery | Discovery | - -| [T1087.001](https://attack.mitre.org/techniques/T1087/001/) | Local Account | Discovery | - -| [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - -| [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery | - -| [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name=sharphound.exe OR Processes.original_file_name=SharpHound.exe) by Processes.dest Processes.user Processes.parent_process_name Processes.original_file_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_sharphound_usage_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **detect_sharphound_usage_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -False positives should be limited as this is specific to a file attribute not used by anything else. Filter as needed. - -#### Associated Analytic story -* [Discovery Techniques](/stories/discovery_techniques) -* [Ransomware](/stories/ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 24.0 | 30 | 80 | Potential SharpHound binary identified on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/software/S0521/](https://attack.mitre.org/software/S0521/) -* [https://thedfirreport.com/?s=bloodhound](https://thedfirreport.com/?s=bloodhound) -* [https://github.com/BloodHoundAD/BloodHound/tree/master/Collectors](https://github.com/BloodHoundAD/BloodHound/tree/master/Collectors) -* [https://github.com/BloodHoundAD/SharpHound3](https://github.com/BloodHoundAD/SharpHound3) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1059.001/T1059.001.md#atomic-test-2---run-bloodhound-from-local-disk](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1059.001/T1059.001.md#atomic-test-2---run-bloodhound-from-local-disk) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/sharphound/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/sharphound/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/detect_sharphound_usage.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-06-01-detect_azurehound_command-line_arguments.md b/docs/_posts/2021-06-01-detect_azurehound_command-line_arguments.md deleted file mode 100644 index 93e1e6b5cc..0000000000 --- a/docs/_posts/2021-06-01-detect_azurehound_command-line_arguments.md +++ /dev/null @@ -1,196 +0,0 @@ ---- -title: "Detect AzureHound Command-Line Arguments" -excerpt: "Domain Account -, Local Groups -, Domain Trust Discovery -, Local Account -, Account Discovery -, Domain Groups -, Permission Groups Discovery -" -categories: - - Endpoint -last_modified_at: 2021-06-01 -toc: true -toc_label: "" -tags: - - Domain Account - - Local Groups - - Domain Trust Discovery - - Local Account - - Account Discovery - - Domain Groups - - Permission Groups Discovery - - Discovery - - Discovery - - Discovery - - Discovery - - Discovery - - Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the common command-line argument used by AzureHound `Invoke-AzureHound`. Being the script is FOSS, function names may be modified, but these changes are dependent upon the operator. In most instances the defaults are used. This analytic works to identify the common command-line attributes used. It does not cover the entirety of every argument in order to avoid false positives. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-06-01 -- **Author**: Michael Haag, Splunk -- **ID**: 26f02e96-c300-11eb-b611-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery | - -| [T1069.001](https://attack.mitre.org/techniques/T1069/001/) | Local Groups | Discovery | - -| [T1482](https://attack.mitre.org/techniques/T1482/) | Domain Trust Discovery | Discovery | - -| [T1087.001](https://attack.mitre.org/techniques/T1087/001/) | Local Account | Discovery | - -| [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - -| [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery | - -| [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process IN ("*invoke-azurehound*") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_azurehound_command_line_arguments_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **detect_azurehound_command-line_arguments_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Unknown. - -#### Associated Analytic story -* [Discovery Techniques](/stories/discovery_techniques) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ using AzureHound to enumerate AzureAD. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/software/S0521/](https://attack.mitre.org/software/S0521/) -* [https://github.com/BloodHoundAD/BloodHound/tree/master/Collectors](https://github.com/BloodHoundAD/BloodHound/tree/master/Collectors) -* [https://posts.specterops.io/introducing-bloodhound-4-0-the-azure-update-9b2b26c5e350](https://posts.specterops.io/introducing-bloodhound-4-0-the-azure-update-9b2b26c5e350) -* [https://github.com/BloodHoundAD/BloodHound/blob/master/Collectors/AzureHound.ps1](https://github.com/BloodHoundAD/BloodHound/blob/master/Collectors/AzureHound.ps1) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/sharphound/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/sharphound/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-06-01-detect_azurehound_file_modifications.md b/docs/_posts/2021-06-01-detect_azurehound_file_modifications.md deleted file mode 100644 index b9c6d7610e..0000000000 --- a/docs/_posts/2021-06-01-detect_azurehound_file_modifications.md +++ /dev/null @@ -1,188 +0,0 @@ ---- -title: "Detect AzureHound File Modifications" -excerpt: "Domain Account -, Local Groups -, Domain Trust Discovery -, Local Account -, Account Discovery -, Domain Groups -, Permission Groups Discovery -" -categories: - - Endpoint -last_modified_at: 2021-06-01 -toc: true -toc_label: "" -tags: - - Domain Account - - Local Groups - - Domain Trust Discovery - - Local Account - - Account Discovery - - Domain Groups - - Permission Groups Discovery - - Discovery - - Discovery - - Discovery - - Discovery - - Discovery - - Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic is similar to SharpHound file modifications, but this instance covers the use of Invoke-AzureHound. AzureHound is the SharpHound equivilent but for Azure. It's possible this may never be seen in an environment as most attackers may execute this tool remotely. Once execution is complete, a zip file with a similar name will drop `20210601090751-azurecollection.zip`. In addition to the zip, multiple .json files will be written to disk, which are in the zip. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-06-01 -- **Author**: Michael Haag, Splunk -- **ID**: 1c34549e-c31b-11eb-996b-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery | - -| [T1069.001](https://attack.mitre.org/techniques/T1069/001/) | Local Groups | Discovery | - -| [T1482](https://attack.mitre.org/techniques/T1482/) | Domain Trust Discovery | Discovery | - -| [T1087.001](https://attack.mitre.org/techniques/T1087/001/) | Local Account | Discovery | - -| [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - -| [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery | - -| [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Filesystem where Filesystem.file_name IN ("*-azurecollection.zip", "*-azprivroleadminrights.json", "*-azglobaladminrights.json", "*-azcloudappadmins.json", "*-azapplicationadmins.json") by Filesystem.file_create_time Filesystem.process_id Filesystem.file_name Filesystem.file_path Filesystem.dest -| `drop_dm_object_name(Filesystem)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_azurehound_file_modifications_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **detect_azurehound_file_modifications_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* file_path -* dest -* file_name -* process_id -* file_create_time - - -#### How To Implement -To successfully implement this search you need to be ingesting information on file modifications that include the name of the process, and file, responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Filesystem` node. - -#### Known False Positives -False positives should be limited as the analytic is specific to a filename with extension .zip. Filter as needed. - -#### Associated Analytic story -* [Discovery Techniques](/stories/discovery_techniques) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 63.0 | 70 | 90 | A file - $file_name$ was written to disk that is related to AzureHound, a AzureAD enumeration utility, has occurred on endpoint $dest$ by user $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://posts.specterops.io/introducing-bloodhound-4-0-the-azure-update-9b2b26c5e350](https://posts.specterops.io/introducing-bloodhound-4-0-the-azure-update-9b2b26c5e350) -* [https://raw.githubusercontent.com/BloodHoundAD/BloodHound/master/Collectors/AzureHound.ps1](https://raw.githubusercontent.com/BloodHoundAD/BloodHound/master/Collectors/AzureHound.ps1) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/sharphound/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/sharphound/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/detect_azurehound_file_modifications.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-06-01-detect_sharphound_command-line_arguments.md b/docs/_posts/2021-06-01-detect_sharphound_command-line_arguments.md deleted file mode 100644 index efc68eb9c4..0000000000 --- a/docs/_posts/2021-06-01-detect_sharphound_command-line_arguments.md +++ /dev/null @@ -1,194 +0,0 @@ ---- -title: "Detect SharpHound Command-Line Arguments" -excerpt: "Domain Account -, Local Groups -, Domain Trust Discovery -, Local Account -, Account Discovery -, Domain Groups -, Permission Groups Discovery -" -categories: - - Endpoint -last_modified_at: 2021-06-01 -toc: true -toc_label: "" -tags: - - Domain Account - - Local Groups - - Domain Trust Discovery - - Local Account - - Account Discovery - - Domain Groups - - Permission Groups Discovery - - Discovery - - Discovery - - Discovery - - Discovery - - Discovery - - Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies common command-line arguments used by SharpHound `-collectionMethod` and `invoke-bloodhound`. Being the script is FOSS, function names may be modified, but these changes are dependent upon the operator. In most instances the defaults are used. This analytic works to identify the common command-line attributes used. It does not cover the entirety of every argument in order to avoid false positives. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-06-01 -- **Author**: Michael Haag, Splunk -- **ID**: a0bdd2f6-c2ff-11eb-b918-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery | - -| [T1069.001](https://attack.mitre.org/techniques/T1069/001/) | Local Groups | Discovery | - -| [T1482](https://attack.mitre.org/techniques/T1482/) | Domain Trust Discovery | Discovery | - -| [T1087.001](https://attack.mitre.org/techniques/T1087/001/) | Local Account | Discovery | - -| [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - -| [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery | - -| [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process IN ("*-collectionMethod*","*invoke-bloodhound*") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_sharphound_command_line_arguments_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **detect_sharphound_command-line_arguments_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -False positives should be limited as the arguments used are specific to SharpHound. Filter as needed or add more command-line arguments as needed. - -#### Associated Analytic story -* [Discovery Techniques](/stories/discovery_techniques) -* [Ransomware](/stories/ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 24.0 | 30 | 80 | Possible SharpHound command-Line arguments identified on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/software/S0521/](https://attack.mitre.org/software/S0521/) -* [https://thedfirreport.com/?s=bloodhound](https://thedfirreport.com/?s=bloodhound) -* [https://github.com/BloodHoundAD/BloodHound/tree/master/Collectors](https://github.com/BloodHoundAD/BloodHound/tree/master/Collectors) -* [https://github.com/BloodHoundAD/SharpHound3](https://github.com/BloodHoundAD/SharpHound3) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1059.001/T1059.001.md#atomic-test-2---run-bloodhound-from-local-disk](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1059.001/T1059.001.md#atomic-test-2---run-bloodhound-from-local-disk) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/sharphound/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/sharphound/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-06-02-conti_common_exec_parameter.md b/docs/_posts/2021-06-02-conti_common_exec_parameter.md deleted file mode 100644 index 316ee41a9b..0000000000 --- a/docs/_posts/2021-06-02-conti_common_exec_parameter.md +++ /dev/null @@ -1,163 +0,0 @@ ---- -title: "Conti Common Exec parameter" -excerpt: "User Execution -" -categories: - - Endpoint -last_modified_at: 2021-06-02 -toc: true -toc_label: "" -tags: - - User Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search detects the suspicious commandline argument of revil ransomware to encrypt specific or all local drive and network shares of the compromised machine or host. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-06-02 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 624919bc-c382-11eb-adcc-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1204](https://attack.mitre.org/techniques/T1204/) | User Execution | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process = "*-m local*" OR Processes.process = "*-m net*" OR Processes.process = "*-m all*" OR Processes.process = "*-nomutex*" by Processes.process_name Processes.process Processes.parent_process_name Processes.parent_process Processes.dest Processes.user Processes.process_id Processes.process_guid -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `conti_common_exec_parameter_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **conti_common_exec_parameter_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -3rd party tool may have commandline parameter that can trigger this detection. - -#### Associated Analytic story -* [Ransomware](/stories/ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 64.0 | 80 | 80 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ executing specific Conti Ransomware related parameters. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://malpedia.caad.fkie.fraunhofer.de/details/win.conti](https://malpedia.caad.fkie.fraunhofer.de/details/win.conti) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/conti/inf1/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/conti/inf1/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/conti_common_exec_parameter.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-06-02-modification_of_wallpaper.md b/docs/_posts/2021-06-02-modification_of_wallpaper.md deleted file mode 100644 index bb4baa84c7..0000000000 --- a/docs/_posts/2021-06-02-modification_of_wallpaper.md +++ /dev/null @@ -1,163 +0,0 @@ ---- -title: "Modification Of Wallpaper" -excerpt: "Defacement -" -categories: - - Endpoint -last_modified_at: 2021-06-02 -toc: true -toc_label: "" -tags: - - Defacement - - Impact - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic identifies suspicious modification of registry to deface or change the wallpaper of a compromised machines as part of its payload. This technique was commonly seen in ransomware like REVIL where it create a bitmap file contain a note that the machine was compromised and make it as a wallpaper. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-06-02 -- **Author**: Teoderick Contreras, Splunk -- **ID**: accb0712-c381-11eb-8e5b-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1491](https://attack.mitre.org/techniques/T1491/) | Defacement | Impact | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventCode =13 (TargetObject= "*\\Control Panel\\Desktop\\Wallpaper" AND Image != "*\\explorer.exe") OR (TargetObject= "*\\Control Panel\\Desktop\\Wallpaper" AND Details = "*\\temp\\*") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Image TargetObject Details Computer process_guid process_id user_id -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `modification_of_wallpaper_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **modification_of_wallpaper_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Image -* TargetObject -* Details -* Computer -* process_guid -* process_id -* user_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the Image, TargetObject registry key, registry Details from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -3rd party tool may used to changed the wallpaper of the machine - -#### Associated Analytic story -* [Ransomware](/stories/ransomware) -* [Revil Ransomware](/stories/revil_ransomware) -* [BlackMatter Ransomware](/stories/blackmatter_ransomware) -* [Windows Registry Abuse](/stories/windows_registry_abuse) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 54.0 | 60 | 90 | Wallpaper modification on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://krebsonsecurity.com/2021/05/a-closer-look-at-the-darkside-ransomware-gang/](https://krebsonsecurity.com/2021/05/a-closer-look-at-the-darkside-ransomware-gang/) -* [https://www.mcafee.com/blogs/other-blogs/mcafee-labs/mcafee-atr-analyzes-sodinokibi-aka-revil-ransomware-as-a-service-what-the-code-tells-us/](https://www.mcafee.com/blogs/other-blogs/mcafee-labs/mcafee-atr-analyzes-sodinokibi-aka-revil-ransomware-as-a-service-what-the-code-tells-us/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/revil/inf1/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/revil/inf1/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/modification_of_wallpaper.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-06-02-revil_common_exec_parameter.md b/docs/_posts/2021-06-02-revil_common_exec_parameter.md deleted file mode 100644 index 333cfb289a..0000000000 --- a/docs/_posts/2021-06-02-revil_common_exec_parameter.md +++ /dev/null @@ -1,162 +0,0 @@ ---- -title: "Revil Common Exec Parameter" -excerpt: "User Execution -" -categories: - - Endpoint -last_modified_at: 2021-06-02 -toc: true -toc_label: "" -tags: - - User Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic identifies suspicious commandline parameter that are commonly used by REVIL ransomware to encrypts the compromise machine. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-06-02 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 85facebe-c382-11eb-9c3e-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1204](https://attack.mitre.org/techniques/T1204/) | User Execution | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process = "* -nolan *" OR Processes.process = "* -nolocal *" OR Processes.process = "* -fast *" OR Processes.process = "* -full *" by Processes.process_name Processes.process Processes.parent_process_name Processes.parent_process Processes.dest Processes.user Processes.process_id Processes.process_guid -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `revil_common_exec_parameter_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **revil_common_exec_parameter_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process_name -* Processes.process -* Processes.parent_process_name -* Processes.parent_process -* Processes.dest -* Processes.user -* Processes.process_id -* Processes.process_guid - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -third party tool may have same command line parameters as revil ransomware. - -#### Associated Analytic story -* [Ransomware](/stories/ransomware) -* [Revil Ransomware](/stories/revil_ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 54.0 | 60 | 90 | A process $process_name$ with commandline $process$ related to revil ransomware in host $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://krebsonsecurity.com/2021/05/a-closer-look-at-the-darkside-ransomware-gang/](https://krebsonsecurity.com/2021/05/a-closer-look-at-the-darkside-ransomware-gang/) -* [https://www.mcafee.com/blogs/other-blogs/mcafee-labs/mcafee-atr-analyzes-sodinokibi-aka-revil-ransomware-as-a-service-what-the-code-tells-us/](https://www.mcafee.com/blogs/other-blogs/mcafee-labs/mcafee-atr-analyzes-sodinokibi-aka-revil-ransomware-as-a-service-what-the-code-tells-us/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/revil/inf1/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/revil/inf1/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/revil_common_exec_parameter.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-06-02-wbemprox_com_object_execution.md b/docs/_posts/2021-06-02-wbemprox_com_object_execution.md deleted file mode 100644 index aa6d560171..0000000000 --- a/docs/_posts/2021-06-02-wbemprox_com_object_execution.md +++ /dev/null @@ -1,167 +0,0 @@ ---- -title: "Wbemprox COM Object Execution" -excerpt: "System Binary Proxy Execution -, CMSTP -" -categories: - - Endpoint -last_modified_at: 2021-06-02 -toc: true -toc_label: "" -tags: - - System Binary Proxy Execution - - CMSTP - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -this search is designed to detect potential malicious process loading COM object to wbemprox.dll, - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-06-02 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 9d911ce0-c3be-11eb-b177-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218](https://attack.mitre.org/techniques/T1218/) | System Binary Proxy Execution | Defense Evasion | - -| [T1218.003](https://attack.mitre.org/techniques/T1218/003/) | CMSTP | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventCode=7 ImageLoaded IN ("*\\fastprox.dll", "*\\wbemprox.dll", "*\\wbemcomn.dll") NOT (process_name IN ("wmiprvse.exe", "WmiApSrv.exe", "unsecapp.exe")) NOT(Image IN("*\\windows\\*","*\\program files*", "*\\wbem\\*")) -| stats count min(_time) as firstTime max(_time) as lastTime by Image ImageLoaded process_name Computer EventCode Signed ProcessId Hashes IMPHASH -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `wbemprox_com_object_execution_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **wbemprox_com_object_execution_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Image -* ImageLoaded -* process_name -* Computer -* EventCode -* Signed -* ProcessId -* Hashes -* IMPHASH - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name and imageloaded executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -legitimate process that are not in the exception list may trigger this event. - -#### Associated Analytic story -* [Ransomware](/stories/ransomware) -* [Revil Ransomware](/stories/revil_ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 35.0 | 70 | 50 | Suspicious COM Object Execution on $Computer$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://krebsonsecurity.com/2021/05/a-closer-look-at-the-darkside-ransomware-gang/](https://krebsonsecurity.com/2021/05/a-closer-look-at-the-darkside-ransomware-gang/) -* [https://www.mcafee.com/blogs/other-blogs/mcafee-labs/mcafee-atr-analyzes-sodinokibi-aka-revil-ransomware-as-a-service-what-the-code-tells-us/](https://www.mcafee.com/blogs/other-blogs/mcafee-labs/mcafee-atr-analyzes-sodinokibi-aka-revil-ransomware-as-a-service-what-the-code-tells-us/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/revil/inf2/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/revil/inf2/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/wbemprox_com_object_execution.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-06-04-known_services_killed_by_ransomware.md b/docs/_posts/2021-06-04-known_services_killed_by_ransomware.md deleted file mode 100644 index e87879902a..0000000000 --- a/docs/_posts/2021-06-04-known_services_killed_by_ransomware.md +++ /dev/null @@ -1,157 +0,0 @@ ---- -title: "Known Services Killed by Ransomware" -excerpt: "Inhibit System Recovery -" -categories: - - Endpoint -last_modified_at: 2021-06-04 -toc: true -toc_label: "" -tags: - - Inhibit System Recovery - - Impact - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search detects a suspicioous termination of known services killed by ransomware before encrypting files in a compromised machine. This technique is commonly seen in most of ransomware now a days to avoid exception error while accessing the targetted files it wants to encrypts because of the open handle of those services to the targetted file. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-06-04 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 3070f8e0-c528-11eb-b2a0-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1490](https://attack.mitre.org/techniques/T1490/) | Inhibit System Recovery | Impact | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`wineventlog_system` EventCode=7036 Message IN ("*Volume Shadow Copy*","*VSS*", "*backup*", "*sophos*", "*sql*", "*memtas*", "*mepocs*", "*veeam*", "*svc$*") Message="*service entered the stopped state*" -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message dest Type -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `known_services_killed_by_ransomware_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [wineventlog_system](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_system.yml) - -> :information_source: -> **known_services_killed_by_ransomware_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Message -* dest -* Type - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the 7036 EventCode ScManager in System audit Logs from your endpoints. - -#### Known False Positives -Admin activities or installing related updates may do a sudden stop to list of services we monitor. - -#### Associated Analytic story -* [Ransomware](/stories/ransomware) -* [BlackMatter Ransomware](/stories/blackmatter_ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 72.0 | 90 | 80 | Known services $Message$ terminated by a potential ransomware on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://krebsonsecurity.com/2021/05/a-closer-look-at-the-darkside-ransomware-gang/](https://krebsonsecurity.com/2021/05/a-closer-look-at-the-darkside-ransomware-gang/) -* [https://www.mcafee.com/blogs/other-blogs/mcafee-labs/mcafee-atr-analyzes-sodinokibi-aka-revil-ransomware-as-a-service-what-the-code-tells-us/](https://www.mcafee.com/blogs/other-blogs/mcafee-labs/mcafee-atr-analyzes-sodinokibi-aka-revil-ransomware-as-a-service-what-the-code-tells-us/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/revil/inf3/windows-system.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/revil/inf3/windows-system.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/known_services_killed_by_ransomware.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-06-07-excessive_number_of_taskhost_processes.md b/docs/_posts/2021-06-07-excessive_number_of_taskhost_processes.md deleted file mode 100644 index 21bfada3a3..0000000000 --- a/docs/_posts/2021-06-07-excessive_number_of_taskhost_processes.md +++ /dev/null @@ -1,161 +0,0 @@ ---- -title: "Excessive number of taskhost processes" -excerpt: "Command and Scripting Interpreter -" -categories: - - Endpoint -last_modified_at: 2021-06-07 -toc: true -toc_label: "" -tags: - - Command and Scripting Interpreter - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This detection targets behaviors observed in post exploit kits like Meterpreter and Koadic that are run in memory. We have observed that these tools must invoke an excessive number of taskhost.exe and taskhostex.exe processes to complete various actions (discovery, lateral movement, etc.). It is extremely uncommon in the course of normal operations to see so many distinct taskhost and taskhostex processes running concurrently in a short time frame. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Microsoft Windows](https://splunkbase.splunk.com/app/742) -- **Last Updated**: 2021-06-07 -- **Author**: Michael Hart -- **ID**: f443dac2-c7cf-11eb-ab51-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` values(Processes.process_id) as process_ids min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes WHERE Processes.process_name = "taskhost.exe" OR Processes.process_name = "taskhostex.exe" BY Processes.dest Processes.process_name _time span=1h -| `drop_dm_object_name(Processes)` -| eval pid_count=mvcount(process_ids) -| eval taskhost_count_=if(process_name == "taskhost.exe", pid_count, 0) -| eval taskhostex_count_=if(process_name == "taskhostex.exe", pid_count, 0) -| stats sum(taskhost_count_) as taskhost_count, sum(taskhostex_count_) as taskhostex_count by _time, dest, firstTime, lastTime -| where taskhost_count > 10 and taskhostex_count > 10 -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `excessive_number_of_taskhost_processes_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **excessive_number_of_taskhost_processes_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process_id -* Processes.process_name -* Processes.dest -* Processes.user - - -#### How To Implement -To successfully implement this search you need to be ingesting events related to processes on the endpoints that include the name of the process and process id into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Administrators, administrative actions or certain applications may run many instances of taskhost and taskhostex concurrently. Filter as needed. - -#### Associated Analytic story -* [Meterpreter](/stories/meterpreter) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 56.0 | 80 | 70 | An excessive amount of $process_name$ was executed on $dest$ indicative of suspicious behavior. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/software/S0250/](https://attack.mitre.org/software/S0250/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059/meterpreter/taskhost_processes/logExcessiveTaskHost.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059/meterpreter/taskhost_processes/logExcessiveTaskHost.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-06-08-powershell_fileless_process_injection_via_getprocaddress.md b/docs/_posts/2021-06-08-powershell_fileless_process_injection_via_getprocaddress.md deleted file mode 100644 index 98ba72fb42..0000000000 --- a/docs/_posts/2021-06-08-powershell_fileless_process_injection_via_getprocaddress.md +++ /dev/null @@ -1,173 +0,0 @@ ---- -title: "Powershell Fileless Process Injection via GetProcAddress" -excerpt: "Command and Scripting Interpreter -, Process Injection -, PowerShell -" -categories: - - Endpoint -last_modified_at: 2021-06-08 -toc: true -toc_label: "" -tags: - - Command and Scripting Interpreter - - Process Injection - - PowerShell - - Execution - - Defense Evasion - - Privilege Escalation - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify suspicious PowerShell execution. Script Block Logging captures the command sent to PowerShell, the full command to be executed. Upon enabling, logs will output to Windows event logs. Dependent upon volume, enable no critical endpoints or all. \ -This analytic identifies `GetProcAddress` in the script block. This is not normal to be used by most PowerShell scripts and is typically unsafe/malicious. Many attack toolkits use GetProcAddress to obtain code execution. \ -In use, `$var_gpa = $var_unsafe_native_methods.GetMethod(GetProcAddress` and later referenced/executed elsewhere. \ -During triage, review parallel processes using an EDR product or 4688 events. It will be important to understand the timeline of events around this activity. Review the entire logged PowerShell script block. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-06-08 -- **Author**: Michael Haag, Splunk -- **ID**: a26d9db4-c883-11eb-9d75-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -| [T1055](https://attack.mitre.org/techniques/T1055/) | Process Injection | Defense Evasion, Privilege Escalation | - -| [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 Message=*getprocaddress* -| stats count min(_time) as firstTime max(_time) as lastTime by OpCode ComputerName User EventCode Message -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `powershell_fileless_process_injection_via_getprocaddress_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **powershell_fileless_process_injection_via_getprocaddress_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Message -* OpCode -* ComputerName -* User -* EventCode - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -Limited false positives. Filter as needed. - -#### Associated Analytic story -* [Hermetic Wiper](/stories/hermetic_wiper) -* [Malicious PowerShell](/stories/malicious_powershell) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 48.0 | 60 | 80 | A suspicious powershell script contains GetProcAddress API in $Message$ with EventCode $EventCode$ in host $ComputerName$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.](https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.) -* [https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63](https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63) -* [https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf](https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf) -* [https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/](https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/windows-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-06-08-powershell_fileless_script_contains_base64_encoded_content.md b/docs/_posts/2021-06-08-powershell_fileless_script_contains_base64_encoded_content.md deleted file mode 100644 index c538fe2b26..0000000000 --- a/docs/_posts/2021-06-08-powershell_fileless_script_contains_base64_encoded_content.md +++ /dev/null @@ -1,172 +0,0 @@ ---- -title: "Powershell Fileless Script Contains Base64 Encoded Content" -excerpt: "Command and Scripting Interpreter -, Obfuscated Files or Information -, PowerShell -" -categories: - - Endpoint -last_modified_at: 2021-06-08 -toc: true -toc_label: "" -tags: - - Command and Scripting Interpreter - - Obfuscated Files or Information - - PowerShell - - Execution - - Defense Evasion - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify suspicious PowerShell execution. Script Block Logging captures the command sent to PowerShell, the full command to be executed. Upon enabling, logs will output to Windows event logs. Dependent upon volume, enable on critical endpoints or all. \ -This analytic identifies `FromBase64String` within the script block. A typical malicious instance will include additional code. \ -Command example - `[Byte[]]$var_code = [System.Convert]::FromBase64String(38uqIyMjQ6rG....` \ -During triage, review parallel processes using an EDR product or 4688 events. It will be important to understand the timeline of events around this activity. Review the entire logged PowerShell script block. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-06-08 -- **Author**: Michael Haag, Splunk -- **ID**: 8acbc04c-c882-11eb-b060-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -| [T1027](https://attack.mitre.org/techniques/T1027/) | Obfuscated Files or Information | Defense Evasion | - -| [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 Message=*frombase64string* -| stats count min(_time) as firstTime max(_time) as lastTime by OpCode ComputerName User EventCode Message -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `powershell_fileless_script_contains_base64_encoded_content_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **powershell_fileless_script_contains_base64_encoded_content_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Message -* OpCode -* ComputerName -* User -* EventCode - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -False positives should be limited. Filter as needed. - -#### Associated Analytic story -* [Hermetic Wiper](/stories/hermetic_wiper) -* [Malicious PowerShell](/stories/malicious_powershell) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 56.0 | 70 | 80 | A suspicious powershell script contains base64 command in $Message$ with EventCode $EventCode$ in host $ComputerName$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.](https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.) -* [https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63](https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63) -* [https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf](https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf) -* [https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/](https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/windows-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-06-09-detect_empire_with_powershell_script_block_logging.md b/docs/_posts/2021-06-09-detect_empire_with_powershell_script_block_logging.md deleted file mode 100644 index fa15056f8b..0000000000 --- a/docs/_posts/2021-06-09-detect_empire_with_powershell_script_block_logging.md +++ /dev/null @@ -1,167 +0,0 @@ ---- -title: "Detect Empire with PowerShell Script Block Logging" -excerpt: "Command and Scripting Interpreter -, PowerShell -" -categories: - - Endpoint -last_modified_at: 2021-06-09 -toc: true -toc_label: "" -tags: - - Command and Scripting Interpreter - - PowerShell - - Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify suspicious PowerShell execution. Script Block Logging captures the command sent to PowerShell, the full command to be executed. Upon enabling, logs will output to Windows event logs. Dependent upon volume, enable on critical endpoints or all. \ -This analytic identifies the common PowerShell stager used by PowerShell-Empire. Each stager that may use PowerShell all uses the same pattern. The initial HTTP will be base64 encoded and use `system.net.webclient`. Note that some obfuscation may evade the analytic. \ -During triage, review parallel processes using an EDR product or 4688 events. It will be important to understand the timeline of events around this activity. Review the entire logged PowerShell script block. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-06-09 -- **Author**: Michael Haag, Splunk -- **ID**: bc1dc6b8-c954-11eb-bade-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -| [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 (Message=*system.net.webclient* AND Message=*frombase64string*) -| stats count min(_time) as firstTime max(_time) as lastTime by OpCode ComputerName User EventCode Message -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_empire_with_powershell_script_block_logging_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **detect_empire_with_powershell_script_block_logging_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Message -* OpCode -* ComputerName -* User -* EventCode - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -False positives may only pertain to it not being related to Empire, but another framework. Filter as needed if any applications use the same pattern. - -#### Associated Analytic story -* [Hermetic Wiper](/stories/hermetic_wiper) -* [Malicious PowerShell](/stories/malicious_powershell) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 81.0 | 90 | 90 | The following behavior was identified and typically related to PowerShell-Empire on $ComputerName$ by $User$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.](https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.) -* [https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63](https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63) -* [https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf](https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf) -* [https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/](https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/) -* [https://github.com/BC-SECURITY/Empire](https://github.com/BC-SECURITY/Empire) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/windows-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-06-09-detect_mimikatz_with_powershell_script_block_logging.md b/docs/_posts/2021-06-09-detect_mimikatz_with_powershell_script_block_logging.md deleted file mode 100644 index b7dc1c284f..0000000000 --- a/docs/_posts/2021-06-09-detect_mimikatz_with_powershell_script_block_logging.md +++ /dev/null @@ -1,161 +0,0 @@ ---- -title: "Detect Mimikatz With PowerShell Script Block Logging" -excerpt: "OS Credential Dumping -" -categories: - - Endpoint -last_modified_at: 2021-06-09 -toc: true -toc_label: "" -tags: - - OS Credential Dumping - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify suspicious PowerShell execution. Script Block Logging captures the command sent to PowerShell, the full command to be executed. Upon enabling, logs will output to Windows event logs. Dependent upon volume, enable no critical endpoints or all. \ -This analytic identifies common Mimikatz functions that may be identified in the script block, including `mimikatz`. This will catch the most basic use cases for Pass the Ticket, Pass the Hash and `-DumprCreds`. \ -During triage, review parallel processes using an EDR product or 4688 events. It will be important to understand the timeline of events around this activity. Review the entire logged PowerShell script block. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-06-09 -- **Author**: Michael Haag, Splunk -- **ID**: 8148c29c-c952-11eb-9255-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 Message IN (*mimikatz*, *-dumpcr*, *sekurlsa::pth*, *kerberos::ptt*, *kerberos::golden*) -| stats count min(_time) as firstTime max(_time) as lastTime by OpCode ComputerName User EventCode Message -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_mimikatz_with_powershell_script_block_logging_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **detect_mimikatz_with_powershell_script_block_logging_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Message -* OpCode -* ComputerName -* User -* EventCode - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -False positives should be limited as the commands being identifies are quite specific to EventCode 4104 and Mimikatz. Filter as needed. - -#### Associated Analytic story -* [Hermetic Wiper](/stories/hermetic_wiper) -* [Malicious PowerShell](/stories/malicious_powershell) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 90.0 | 90 | 100 | The following behavior was identified and typically related to MimiKatz being loaded within the context of PowerShell on $ComputerName$ by $User$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.](https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.) -* [https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63](https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63) -* [https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf](https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf) -* [https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/](https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/windows-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-06-09-unloading_amsi_via_reflection.md b/docs/_posts/2021-06-09-unloading_amsi_via_reflection.md deleted file mode 100644 index b3fe0480ab..0000000000 --- a/docs/_posts/2021-06-09-unloading_amsi_via_reflection.md +++ /dev/null @@ -1,171 +0,0 @@ ---- -title: "Unloading AMSI via Reflection" -excerpt: "Impair Defenses -, PowerShell -, Command and Scripting Interpreter -" -categories: - - Endpoint -last_modified_at: 2021-06-09 -toc: true -toc_label: "" -tags: - - Impair Defenses - - PowerShell - - Command and Scripting Interpreter - - Defense Evasion - - Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify suspicious PowerShell execution. Script Block Logging captures the command sent to PowerShell, the full command to be executed. Upon enabling, logs will output to Windows event logs. Dependent upon volume, enable on critical endpoints or all. \ -This analytic identifies the behavior of AMSI being tampered with. Implemented natively in many frameworks, the command will look similar to `SEtValuE($Null,(New-OBJEct COLlECtionS.GenerIC.HAshSEt{[StrINg]))}$ReF=[ReF].AsSeMbLY.GeTTyPe("System.Management.Automation.Amsi"+"Utils")` taken from Powershell-Empire. \ -During triage, review parallel processes using an EDR product or 4688 events. It will be important to understand the timeline of events around this activity. Review the entire logged PowerShell script block. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-06-09 -- **Author**: Michael Haag, Splunk -- **ID**: a21e3484-c94d-11eb-b55b-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -| [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | - -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 ScriptBlockText = *system.management.automation.amsi* -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode ScriptBlockText Computer user_id -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `unloading_amsi_via_reflection_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **unloading_amsi_via_reflection_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* ScriptBlockText -* Opcode -* Computer -* UserID -* EventCode - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -Potential for some third party applications to disable AMSI upon invocation. Filter as needed. - -#### Associated Analytic story -* [Hermetic Wiper](/stories/hermetic_wiper) -* [Malicious PowerShell](/stories/malicious_powershell) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | Possible AMSI Unloading via Reflection using PowerShell on $Computer$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.](https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.) -* [https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63](https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63) -* [https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf](https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf) -* [https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/](https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/windows-powershell-xml.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/windows-powershell-xml.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/unloading_amsi_via_reflection.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-06-10-clear_unallocated_sector_using_cipher_app.md b/docs/_posts/2021-06-10-clear_unallocated_sector_using_cipher_app.md deleted file mode 100644 index 262e1b6bf6..0000000000 --- a/docs/_posts/2021-06-10-clear_unallocated_sector_using_cipher_app.md +++ /dev/null @@ -1,169 +0,0 @@ ---- -title: "Clear Unallocated Sector Using Cipher App" -excerpt: "File Deletion -, Indicator Removal on Host -" -categories: - - Endpoint -last_modified_at: 2021-06-10 -toc: true -toc_label: "" -tags: - - File Deletion - - Indicator Removal on Host - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -this search is to detect execution of `cipher.exe` to clear the unallocated sectors of a specific disk. This technique was seen in some ransomware to make it impossible to forensically recover deleted files. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-06-10 -- **Author**: Teoderick Contreras, Splunk -- **ID**: cd80a6ac-c9d9-11eb-8839-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1070.004](https://attack.mitre.org/techniques/T1070/004/) | File Deletion | Defense Evasion | - -| [T1070](https://attack.mitre.org/techniques/T1070/) | Indicator Removal on Host | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = "cipher.exe" Processes.process = "*/w:*" by Processes.parent_process_name Processes.parent_process Processes.process_name Processes.process Processes.dest Processes.user Processes.process_id Processes.process_guid -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `clear_unallocated_sector_using_cipher_app_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **clear_unallocated_sector_using_cipher_app_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -administrator may execute this app to manage disk - -#### Associated Analytic story -* [Ransomware](/stories/ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 90.0 | 100 | 90 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to clear the unallocated sectors of a specific disk. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://unit42.paloaltonetworks.com/vatet-pyxie-defray777/3/](https://unit42.paloaltonetworks.com/vatet-pyxie-defray777/3/) -* [https://www.sophos.com/en-us/medialibrary/PDFs/technical-papers/sophoslabs-ransomware-behavior-report.pdf](https://www.sophos.com/en-us/medialibrary/PDFs/technical-papers/sophoslabs-ransomware-behavior-report.pdf) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/data1/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/data1/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-06-10-disable_logs_using_wevtutil.md b/docs/_posts/2021-06-10-disable_logs_using_wevtutil.md deleted file mode 100644 index 0ea696d65d..0000000000 --- a/docs/_posts/2021-06-10-disable_logs_using_wevtutil.md +++ /dev/null @@ -1,165 +0,0 @@ ---- -title: "Disable Logs Using WevtUtil" -excerpt: "Indicator Removal on Host -, Clear Windows Event Logs -" -categories: - - Endpoint -last_modified_at: 2021-06-10 -toc: true -toc_label: "" -tags: - - Indicator Removal on Host - - Clear Windows Event Logs - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect execution of wevtutil.exe to disable logs. This technique was seen in several ransomware to disable the event logs to evade alerts and detections. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-06-10 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 236e7c8e-c9d9-11eb-a824-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1070](https://attack.mitre.org/techniques/T1070/) | Indicator Removal on Host | Defense Evasion | - -| [T1070.001](https://attack.mitre.org/techniques/T1070/001/) | Clear Windows Event Logs | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = "wevtutil.exe" Processes.process = "*sl*" Processes.process = "*/e:false*" by Processes.parent_process_name Processes.parent_process Processes.process_name Processes.process Processes.dest Processes.user Processes.process_id Processes.process_guid -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `disable_logs_using_wevtutil_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **disable_logs_using_wevtutil_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.parent_process_name -* Processes.parent_process -* Processes.process_name -* Processes.process -* Processes.dest -* Processes.user -* Processes.process_id -* Processes.process_guid - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -network operator may disable audit event logs for debugging purposes. - -#### Associated Analytic story -* [Ransomware](/stories/ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 24.0 | 30 | 80 | WevtUtil.exe used to disable Event Logging on $dest | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.bleepingcomputer.com/news/security/new-ransom-x-ransomware-used-in-texas-txdot-cyberattack/](https://www.bleepingcomputer.com/news/security/new-ransom-x-ransomware-used-in-texas-txdot-cyberattack/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/data1/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/data1/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disable_logs_using_wevtutil.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-06-10-permission_modification_using_takeown_app.md b/docs/_posts/2021-06-10-permission_modification_using_takeown_app.md deleted file mode 100644 index d895f70a46..0000000000 --- a/docs/_posts/2021-06-10-permission_modification_using_takeown_app.md +++ /dev/null @@ -1,160 +0,0 @@ ---- -title: "Permission Modification using Takeown App" -excerpt: "File and Directory Permissions Modification -" -categories: - - Endpoint -last_modified_at: 2021-06-10 -toc: true -toc_label: "" -tags: - - File and Directory Permissions Modification - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect a modification of file or directory permission using takeown.exe windows app. This technique was seen in some ransomware that take the ownership of a folder or files to encrypt or delete it. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-06-10 -- **Author**: Teoderick Contreras, Splunk -- **ID**: fa7ca5c6-c9d8-11eb-bce9-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1222](https://attack.mitre.org/techniques/T1222/) | File and Directory Permissions Modification | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = "takeown.exe" Processes.process = "*/f*" by Processes.parent_process_name Processes.parent_process Processes.process_name Processes.process Processes.dest Processes.user Processes.process_id Processes.process_guid -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `permission_modification_using_takeown_app_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **permission_modification_using_takeown_app_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.parent_process_name -* Processes.parent_process -* Processes.process_name -* Processes.process -* Processes.dest -* Processes.user -* Processes.process_id -* Processes.process_guid - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -takeown.exe is a normal windows application that may used by network operator. - -#### Associated Analytic story -* [Ransomware](/stories/ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 56.0 | 70 | 80 | A suspicious of execution of $process_name$ with process id $process_id$ and commandline $process$ to modify permission of directory or files in host $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://research.nccgroup.com/2020/06/23/wastedlocker-a-new-ransomware-variant-developed-by-the-evil-corp-group/](https://research.nccgroup.com/2020/06/23/wastedlocker-a-new-ransomware-variant-developed-by-the-evil-corp-group/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/data1/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/data1/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/permission_modification_using_takeown_app.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-06-10-powershell_creating_thread_mutex.md b/docs/_posts/2021-06-10-powershell_creating_thread_mutex.md deleted file mode 100644 index 6c6cf0c524..0000000000 --- a/docs/_posts/2021-06-10-powershell_creating_thread_mutex.md +++ /dev/null @@ -1,163 +0,0 @@ ---- -title: "Powershell Creating Thread Mutex" -excerpt: "Obfuscated Files or Information -, Indicator Removal from Tools -" -categories: - - Endpoint -last_modified_at: 2021-06-10 -toc: true -toc_label: "" -tags: - - Obfuscated Files or Information - - Indicator Removal from Tools - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies suspicious PowerShell script execution via EventCode 4104 that is using the `mutex` function. This function is commonly seen in some obfuscated PowerShell scripts to make sure that only one instance of there process is running on a compromise machine. During triage, review parallel processes within the same timeframe. Review the full script block to identify other related artifacts. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-06-10 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 637557ec-ca08-11eb-bd0a-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1027](https://attack.mitre.org/techniques/T1027/) | Obfuscated Files or Information | Defense Evasion | - -| [T1027.005](https://attack.mitre.org/techniques/T1027/005/) | Indicator Removal from Tools | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 Message = "*Threading.Mutex*" -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `powershell_creating_thread_mutex_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **powershell_creating_thread_mutex_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Message -* ComputerName -* User - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -powershell developer may used this function in their script for instance checking too. - -#### Associated Analytic story -* [Malicious PowerShell](/stories/malicious_powershell) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 40.0 | 50 | 80 | A suspicious powershell script contains Thread Mutex in $Message$ with EventCode $EventCode$ in host $ComputerName$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://isc.sans.edu/forums/diary/Some+Powershell+Malicious+Code/22988/](https://isc.sans.edu/forums/diary/Some+Powershell+Malicious+Code/22988/) -* [https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.](https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.) -* [https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63](https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63) -* [https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf](https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf) -* [https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/](https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/pwsh/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/pwsh/windows-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/powershell_creating_thread_mutex.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-06-10-powershell_domain_enumeration.md b/docs/_posts/2021-06-10-powershell_domain_enumeration.md deleted file mode 100644 index ddf93250e3..0000000000 --- a/docs/_posts/2021-06-10-powershell_domain_enumeration.md +++ /dev/null @@ -1,164 +0,0 @@ ---- -title: "PowerShell Domain Enumeration" -excerpt: "Command and Scripting Interpreter -, PowerShell -" -categories: - - Endpoint -last_modified_at: 2021-06-10 -toc: true -toc_label: "" -tags: - - Command and Scripting Interpreter - - PowerShell - - Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify suspicious PowerShell execution. Script Block Logging captures the command sent to PowerShell, the full command to be executed. Upon enabling, logs will output to Windows event logs. Dependent upon volume, enable on critical endpoints or all. \ -This analytic identifies specific PowerShell modules typically used to enumerate an organizations domain or users. \ -During triage, review parallel processes using an EDR product or 4688 events. It will be important to understand the timeline of events around this activity. Review the entire logged PowerShell script block. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-06-10 -- **Author**: Michael Haag, Splunk -- **ID**: e1866ce2-ca22-11eb-8e44-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -| [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 Message IN (*get-netdomaintrust*, *get-netforesttrust*, *get-addomain*, *get-adgroupmember*, *get-domainuser*) -| stats count min(_time) as firstTime max(_time) as lastTime by ComputerName EventCode Message -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `powershell_domain_enumeration_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **powershell_domain_enumeration_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Message -* ComputerName -* EventCode - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -It is possible there will be false positives, filter as needed. - -#### Associated Analytic story -* [Hermetic Wiper](/stories/hermetic_wiper) -* [Malicious PowerShell](/stories/malicious_powershell) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 42.0 | 60 | 70 | A suspicious powershell script contains domain enumeration command in $Message$ with EventCode $EventCode$ in host $ComputerName$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.](https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.) -* [https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63](https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63) -* [https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf](https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf) -* [https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/](https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/windows-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/powershell_domain_enumeration.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-06-10-powershell_loading_dotnet_into_memory_via_reflection.md b/docs/_posts/2021-06-10-powershell_loading_dotnet_into_memory_via_reflection.md deleted file mode 100644 index 22736ee8b4..0000000000 --- a/docs/_posts/2021-06-10-powershell_loading_dotnet_into_memory_via_reflection.md +++ /dev/null @@ -1,167 +0,0 @@ ---- -title: "PowerShell Loading DotNET into Memory via Reflection" -excerpt: "Command and Scripting Interpreter -, PowerShell -" -categories: - - Endpoint -last_modified_at: 2021-06-10 -toc: true -toc_label: "" -tags: - - Command and Scripting Interpreter - - PowerShell - - Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify suspicious PowerShell execution. Script Block Logging captures the command sent to PowerShell, the full command to be executed. Upon enabling, logs will output to Windows event logs. Dependent upon volume, enable no critical endpoints or all. \ -This analytic identifies the use of PowerShell loading .net assembly via reflection. This is commonly found in malicious PowerShell usage, including Empire and Cobalt Strike. In addition, the `load(` value may be modifed by removing `(` and it will identify more events to review. \ -During triage, review parallel processes using an EDR product or 4688 events. It will be important to understand the timeline of events around this activity. Review the entire logged PowerShell script block. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-06-10 -- **Author**: Michael Haag, Splunk -- **ID**: 85bc3f30-ca28-11eb-bd21-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -| [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 Message IN ("*[system.reflection.assembly]::load(*","*[reflection.assembly]*") -| stats count min(_time) as firstTime max(_time) as lastTime by OpCode ComputerName User EventCode Message -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `powershell_loading_dotnet_into_memory_via_reflection_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **powershell_loading_dotnet_into_memory_via_reflection_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Message -* OpCode -* ComputerName -* User -* EventCode - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -False positives should be limited as day to day scripts do not use this method. - -#### Associated Analytic story -* [Hermetic Wiper](/stories/hermetic_wiper) -* [Malicious PowerShell](/stories/malicious_powershell) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 56.0 | 70 | 80 | A suspicious powershell script contains reflective class assembly command in $Message$ to load .net code in memory with EventCode $EventCode$ in host $ComputerName$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://docs.microsoft.com/en-us/dotnet/api/system.reflection.assembly?view=net-5.0](https://docs.microsoft.com/en-us/dotnet/api/system.reflection.assembly?view=net-5.0) -* [https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.](https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.) -* [https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63](https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63) -* [https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf](https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf) -* [https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/](https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/windows-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_reflection.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-06-10-powershell_loading_dotnet_into_memory_via_system_reflection_assembly.md b/docs/_posts/2021-06-10-powershell_loading_dotnet_into_memory_via_system_reflection_assembly.md deleted file mode 100644 index 9ea3e9fd84..0000000000 --- a/docs/_posts/2021-06-10-powershell_loading_dotnet_into_memory_via_system_reflection_assembly.md +++ /dev/null @@ -1,116 +0,0 @@ ---- -title: "PowerShell Loading DotNET into Memory via System Reflection Assembly" -excerpt: "Command and Scripting Interpreter -, PowerShell -" -categories: - - Endpoint -last_modified_at: 2021-06-10 -toc: true -toc_label: "" -tags: - - Command and Scripting Interpreter - - PowerShell - - Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify suspicious PowerShell execution. Script Block Logging captures the command sent to PowerShell, the full command to be executed. Upon enabling, logs will output to Windows event logs. Dependent upon volume, enable no critical endpoints or all. \ -This analytic identifies the use of PowerShell loading .net assembly via reflection. This is commonly found in malicious PowerShell usage, including Empire and Cobalt Strike. In addition, the `load(` value may be modifed by removing `(` and it will identify more events to review. \ -During triage, review parallel processes using an EDR product or 4688 events. It will be important to understand the timeline of events around this activity. Review the entire logged PowerShell script block. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/object-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: -- **Last Updated**: 2021-06-10 -- **Author**: Michael Haag, Splunk -- **ID**: 85bc3f30-ca28-11eb-bd21-acde48001122 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -| [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | - -#### Search - -``` -`powershell` EventCode=4104 Message IN ("*[system.reflection.assembly]::load(*","*[reflection.assembly]*") -| stats count min(_time) as firstTime max(_time) as lastTime by OpCode ComputerName User EventCode Message -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `powershell_loading_dotnet_into_memory_via_system_reflection_assembly_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -Note that `powershell_loading_dotnet_into_memory_via_system_reflection_assembly_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Message -* OpCode -* ComputerName -* User -* EventCode - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -False positives should be limited as day to day scripts do not use this method. - -#### Associated Analytic story -* [Malicious PowerShell](/stories/malicious_powershell) - - -#### Kill Chain Phase -* Exploitation - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 56.0 | 70 | 80 | A suspicious powershell script contains reflective class assembly command in $Message$ to load .net code in memory with EventCode $EventCode$ in host $ComputerName$ | - - - - -#### Reference - -* [https://docs.microsoft.com/en-us/dotnet/api/system.reflection.assembly?view=net-5.0](https://docs.microsoft.com/en-us/dotnet/api/system.reflection.assembly?view=net-5.0) -* [https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.](https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.) -* [https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63](https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63) -* [https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf](https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf) -* [https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/](https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/windows-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-06-10-powershell_processing_stream_of_data.md b/docs/_posts/2021-06-10-powershell_processing_stream_of_data.md deleted file mode 100644 index 4653bf74ad..0000000000 --- a/docs/_posts/2021-06-10-powershell_processing_stream_of_data.md +++ /dev/null @@ -1,165 +0,0 @@ ---- -title: "Powershell Processing Stream Of Data" -excerpt: "Command and Scripting Interpreter -, PowerShell -" -categories: - - Endpoint -last_modified_at: 2021-06-10 -toc: true -toc_label: "" -tags: - - Command and Scripting Interpreter - - PowerShell - - Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies suspicious PowerShell script execution via EventCode 4104 that is processing compressed stream data. This is typically found in obfuscated PowerShell or PowerShell executing embedded .NET or binary files that are stream flattened and will be deflated durnig execution. During triage, review parallel processes within the same timeframe. Review the full script block to identify other related artifacts. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-06-10 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 0d718b52-c9f1-11eb-bc61-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -| [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 Message = "*IO.Compression.*" OR Message = "*IO.StreamReader*" OR Message = "*]::Decompress*" -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `powershell_processing_stream_of_data_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **powershell_processing_stream_of_data_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Message -* ComputerName -* User -* Score - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -powershell may used this function to process compressed data. - -#### Associated Analytic story -* [Hermetic Wiper](/stories/hermetic_wiper) -* [Malicious PowerShell](/stories/malicious_powershell) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 40.0 | 50 | 80 | A suspicious powershell script contains stream command in $Message$ commonly for processing compressed or to decompressed binary file with EventCode $EventCode$ in host $ComputerName$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://medium.com/@ahmedjouini99/deobfuscating-emotets-powershell-payload-e39fb116f7b9](https://medium.com/@ahmedjouini99/deobfuscating-emotets-powershell-payload-e39fb116f7b9) -* [https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell](https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell) -* [https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63](https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63) -* [https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf](https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf) -* [https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/](https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/pwsh/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/pwsh/windows-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/powershell_processing_stream_of_data.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-06-10-powershell_using_memory_as_backing_store.md b/docs/_posts/2021-06-10-powershell_using_memory_as_backing_store.md deleted file mode 100644 index e14b1e2669..0000000000 --- a/docs/_posts/2021-06-10-powershell_using_memory_as_backing_store.md +++ /dev/null @@ -1,155 +0,0 @@ ---- -title: "Powershell Using memory As Backing Store" -excerpt: "Deobfuscate/Decode Files or Information -" -categories: - - Endpoint -last_modified_at: 2021-06-10 -toc: true -toc_label: "" -tags: - - Deobfuscate/Decode Files or Information - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies suspicious PowerShell script execution via EventCode 4104 that is using memory stream as new object backstore. The malicious PowerShell script will contain stream flate data and will be decompressed in memory to run or drop the actual payload. During triage, review parallel processes within the same timeframe. Review the full script block to identify other related artifacts. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-06-10 -- **Author**: Teoderick Contreras, Splunk -- **ID**: c396a0c4-c9f2-11eb-b4f5-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1140](https://attack.mitre.org/techniques/T1140/) | Deobfuscate/Decode Files or Information | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 Message = "*New-Object IO.MemoryStream*" -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `powershell_using_memory_as_backing_store_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -Note that **powershell_using_memory_as_backing_store_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Message -* ComputerName -* User - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -powershell may used this function to store out object into memory. - -#### Associated Analytic story -* [Hermetic Wiper](/stories/hermetic_wiper) -* [Malicious PowerShell](/stories/malicious_powershell) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 40.0 | 50 | 80 | A suspicious powershell script contains memorystream command in $Message$ as new object backstore with EventCode $EventCode$ in host $ComputerName$ | - - -#### Reference - -* [https://www.carbonblack.com/blog/decoding-malicious-powershell-streams/](https://www.carbonblack.com/blog/decoding-malicious-powershell-streams/) -* [https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.](https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.) -* [https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63](https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63) -* [https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf](https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf) -* [https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/](https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/pwsh/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/pwsh/windows-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-06-10-prevent_automatic_repair_mode_using_bcdedit.md b/docs/_posts/2021-06-10-prevent_automatic_repair_mode_using_bcdedit.md deleted file mode 100644 index 63c2fafb1b..0000000000 --- a/docs/_posts/2021-06-10-prevent_automatic_repair_mode_using_bcdedit.md +++ /dev/null @@ -1,160 +0,0 @@ ---- -title: "Prevent Automatic Repair Mode using Bcdedit" -excerpt: "Inhibit System Recovery -" -categories: - - Endpoint -last_modified_at: 2021-06-10 -toc: true -toc_label: "" -tags: - - Inhibit System Recovery - - Impact - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect a suspicious bcdedit.exe execution to ignore all failures. This technique was used by ransomware to prevent the compromise machine automatically boot in repair mode. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-06-10 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 7742aa92-c9d9-11eb-bbfc-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1490](https://attack.mitre.org/techniques/T1490/) | Inhibit System Recovery | Impact | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = "bcdedit.exe" Processes.process = "*bootstatuspolicy*" Processes.process = "*ignoreallfailures*" by Processes.parent_process_name Processes.parent_process Processes.process_name Processes.process Processes.dest Processes.user Processes.process_id Processes.process_guid -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `prevent_automatic_repair_mode_using_bcdedit_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **prevent_automatic_repair_mode_using_bcdedit_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.parent_process_name -* Processes.parent_process -* Processes.process_name -* Processes.process -* Processes.dest -* Processes.user -* Processes.process_id -* Processes.process_guid - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed bcdedit.exe may be used. - -#### Known False Positives -Administrators may modify the boot configuration ignore failure during testing and debugging. - -#### Associated Analytic story -* [Ransomware](/stories/ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 56.0 | 70 | 80 | A suspicious process $process_name$ with process id $process_id$ contains commandline $process$ to ignore all bcdedit execution failure in host $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://jsac.jpcert.or.jp/archive/2020/pdf/JSAC2020_1_tamada-yamazaki-nakatsuru_en.pdf](https://jsac.jpcert.or.jp/archive/2020/pdf/JSAC2020_1_tamada-yamazaki-nakatsuru_en.pdf) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/data1/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/data1/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-06-10-recon_avproduct_through_pwh_or_wmi.md b/docs/_posts/2021-06-10-recon_avproduct_through_pwh_or_wmi.md deleted file mode 100644 index 8188e12a0a..0000000000 --- a/docs/_posts/2021-06-10-recon_avproduct_through_pwh_or_wmi.md +++ /dev/null @@ -1,156 +0,0 @@ ---- -title: "Recon AVProduct Through Pwh or WMI" -excerpt: "Gather Victim Host Information -" -categories: - - Endpoint -last_modified_at: 2021-06-10 -toc: true -toc_label: "" -tags: - - Gather Victim Host Information - - Reconnaissance - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies suspicious PowerShell script execution via EventCode 4104 performing checks to identify anti-virus products installed on the endpoint. This technique is commonly found in malware and APT events where the adversary will map all running security applications or services. During triage, review parallel processes within the same timeframe. Review the full script block to identify other related artifacts. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-06-10 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 28077620-c9f6-11eb-8785-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1592](https://attack.mitre.org/techniques/T1592/) | Gather Victim Host Information | Reconnaissance | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 (Message = "*SELECT*" OR Message = "*WMIC*") AND (Message = "*AntiVirusProduct*" OR Message = "*AntiSpywareProduct*") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `recon_avproduct_through_pwh_or_wmi_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -Note that **recon_avproduct_through_pwh_or_wmi_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Message -* ComputerName -* User - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -network administrator may used this command for checking purposes - -#### Associated Analytic story -* [Hermetic Wiper](/stories/hermetic_wiper) -* [Ransomware](/stories/ransomware) -* [Malicious PowerShell](/stories/malicious_powershell) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 56.0 | 70 | 80 | A suspicious powershell script contains AV recon command in $Message$ with EventCode $EventCode$ in host $ComputerName$ | - - -#### Reference - -* [https://news.sophos.com/en-us/2020/05/12/maze-ransomware-1-year-counting/](https://news.sophos.com/en-us/2020/05/12/maze-ransomware-1-year-counting/) -* [https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.](https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.) -* [https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63](https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63) -* [https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf](https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf) -* [https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/](https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/pwsh/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/pwsh/windows-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/recon_avproduct_through_pwh_or_wmi.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-06-10-recon_using_wmi_class.md b/docs/_posts/2021-06-10-recon_using_wmi_class.md deleted file mode 100644 index 4c8d730be6..0000000000 --- a/docs/_posts/2021-06-10-recon_using_wmi_class.md +++ /dev/null @@ -1,161 +0,0 @@ ---- -title: "Recon Using WMI Class" -excerpt: "Gather Victim Host Information -" -categories: - - Endpoint -last_modified_at: 2021-06-10 -toc: true -toc_label: "" -tags: - - Gather Victim Host Information - - Reconnaissance - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies suspicious PowerShell via EventCode 4104, where WMI is performing an event query looking for running processes or running services. This technique is commonly found where the adversary will identify services and system information on the compromised machine. During triage, review parallel processes within the same timeframe. Review the full script block to identify other related artifacts. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-06-10 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 018c1972-ca07-11eb-9473-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1592](https://attack.mitre.org/techniques/T1592/) | Gather Victim Host Information | Reconnaissance | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 (Message= "*SELECT*" OR Message= "*Get-WmiObject*") AND (Message= "*Win32_Bios*" OR Message= "*Win32_OperatingSystem*" OR Message= "*Win32_Processor*" OR Message= "*Win32_ComputerSystem*" OR Message= "*Win32_ComputerSystemProduct*" OR Message= "*Win32_ShadowCopy*") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `recon_using_wmi_class_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **recon_using_wmi_class_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Message -* ComputerName -* User - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -network administrator may used this command for checking purposes - -#### Associated Analytic story -* [Hermetic Wiper](/stories/hermetic_wiper) -* [Malicious PowerShell](/stories/malicious_powershell) -* [Industroyer2](/stories/industroyer2) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 60.0 | 75 | 80 | A suspicious powershell script contains host recon command in $Message$ with EventCode $EventCode$ in host $ComputerName$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://news.sophos.com/en-us/2020/05/12/maze-ransomware-1-year-counting/](https://news.sophos.com/en-us/2020/05/12/maze-ransomware-1-year-counting/) -* [https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.](https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.) -* [https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63](https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63) -* [https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf](https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf) -* [https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/](https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/) -* [https://www.welivesecurity.com/2022/04/12/industroyer2-industroyer-reloaded/](https://www.welivesecurity.com/2022/04/12/industroyer2-industroyer-reloaded/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/pwsh/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/pwsh/windows-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/recon_using_wmi_class.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-06-14-wmi_recon_running_process_or_services.md b/docs/_posts/2021-06-14-wmi_recon_running_process_or_services.md deleted file mode 100644 index 9dbb5f7e29..0000000000 --- a/docs/_posts/2021-06-14-wmi_recon_running_process_or_services.md +++ /dev/null @@ -1,158 +0,0 @@ ---- -title: "WMI Recon Running Process Or Services" -excerpt: "Gather Victim Host Information -" -categories: - - Endpoint -last_modified_at: 2021-06-14 -toc: true -toc_label: "" -tags: - - Gather Victim Host Information - - Reconnaissance - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies suspicious PowerShell script execution via EventCode 4104, where WMI is performing an event query looking for running processes or running services. This technique is commonly found in malware and APT events where the adversary will map all running security applications or services on the compromised machine. During triage, review parallel processes within the same timeframe. Review the full script block to identify other related artifacts. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-06-14 -- **Author**: Teoderick Contreras, Splunk -- **ID**: b5cd5526-cce7-11eb-b3bd-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1592](https://attack.mitre.org/techniques/T1592/) | Gather Victim Host Information | Reconnaissance | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 Message= "*SELECT*" AND (Message="*Win32_Process*" OR Message="*Win32_Service*") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `wmi_recon_running_process_or_services_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **wmi_recon_running_process_or_services_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Message -* ComputerName -* User - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -network administrator may used this command for checking purposes - -#### Associated Analytic story -* [Hermetic Wiper](/stories/hermetic_wiper) -* [Malicious PowerShell](/stories/malicious_powershell) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 30.0 | 30 | 100 | Suspicious powerShell script execution by $user$ on $ComputerName$ via EventCode 4104, where WMI is performing an event query looking for running processes or running services | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://news.sophos.com/en-us/2020/05/12/maze-ransomware-1-year-counting/](https://news.sophos.com/en-us/2020/05/12/maze-ransomware-1-year-counting/) -* [https://www.eideon.com/2018-03-02-THL03-WMIBackdoors/](https://www.eideon.com/2018-03-02-THL03-WMIBackdoors/) -* [https://github.com/trustedsec/SysmonCommunityGuide/blob/master/chapters/WMI-events.md](https://github.com/trustedsec/SysmonCommunityGuide/blob/master/chapters/WMI-events.md) -* [https://in.security/2019/04/03/an-intro-into-abusing-and-identifying-wmi-event-subscriptions-for-persistence/](https://in.security/2019/04/03/an-intro-into-abusing-and-identifying-wmi-event-subscriptions-for-persistence/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/pwsh/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/pwsh/windows-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/wmi_recon_running_process_or_services.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-06-15-wevtutil_usage_to_clear_logs.md b/docs/_posts/2021-06-15-wevtutil_usage_to_clear_logs.md deleted file mode 100644 index ac0a37a013..0000000000 --- a/docs/_posts/2021-06-15-wevtutil_usage_to_clear_logs.md +++ /dev/null @@ -1,112 +0,0 @@ ---- -title: "WevtUtil Usage To Clear Logs" -excerpt: "Indicator Removal on Host, Clear Windows Event Logs" -categories: - - Endpoint -last_modified_at: 2021-06-15 -toc: true -toc_label: "" -tags: - - Indicator Removal on Host - - Defense Evasion - - Clear Windows Event Logs - - Defense Evasion - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -The wevtutil.exe application is the windows event log utility. This searches for wevtutil.exe with parameters for clearing the application, security, setup, powershell, sysmon, or system event logs. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2021-06-15 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 5438113c-cdd9-11eb-93b8-acde48001122 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1070](https://attack.mitre.org/techniques/T1070/) | Indicator Removal on Host | Defense Evasion | - -| [T1070.001](https://attack.mitre.org/techniques/T1070/001/) | Clear Windows Event Logs | Defense Evasion | - -#### Search - -``` - -| from read_ssa_enriched_events() -| where "Endpoint_Processes" IN(_datamodels) -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line IS NOT NULL AND like(cmd_line, "% cl %") AND (match_regex(cmd_line, /(?i)security/)=true OR match_regex(cmd_line, /(?i)system/)=true OR match_regex(cmd_line, /(?i)sysmon/)=true OR match_regex(cmd_line, /(?i)application/)=true OR match_regex(cmd_line, /(?i)setup/)=true OR match_regex(cmd_line, /(?i)powershell/)=true) AND process_name="wevtutil.exe" -| eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)) -| eval body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) -| into write_ssa_detected_events(); -``` - -#### Macros -The SPL above uses the following Macros: - -Note that `wevtutil_usage_to_clear_logs_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* dest_device_id -* process_name -* parent_process_name -* process_path -* dest_user_id -* process - - -#### How To Implement -You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. - -#### Known False Positives -The wevtutil.exe application is a legitimate Windows event log utility. Administrators may use it to manage Windows event logs. - -#### Associated Analytic story -* [Windows Log Manipulation](/stories/windows_log_manipulation) -* [Ransomware](/stories/ransomware) -* [Clop Ransomware](/stories/clop_ransomware) - - -#### Kill Chain Phase -* Exploitation - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 63.0 | 70 | 90 | A wevtutil process $process_name$ with commandline $cmd_line$ to clear event logs in host $dest_device_id$ | - - -Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` - - - -#### Reference - -* [https://www.splunk.com/en_us/blog/security/detecting-clop-ransomware.html](https://www.splunk.com/en_us/blog/security/detecting-clop-ransomware.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070.001/ssa_wevtutil/clear_evt.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070.001/ssa_wevtutil/clear_evt.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/wevtutil_usage_to_clear_logs.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-06-15-wevtutil_usage_to_disable_logs.md b/docs/_posts/2021-06-15-wevtutil_usage_to_disable_logs.md deleted file mode 100644 index 908ec247b7..0000000000 --- a/docs/_posts/2021-06-15-wevtutil_usage_to_disable_logs.md +++ /dev/null @@ -1,111 +0,0 @@ ---- -title: "Wevtutil Usage To Disable Logs" -excerpt: "Indicator Removal on Host, Clear Windows Event Logs" -categories: - - Endpoint -last_modified_at: 2021-06-15 -toc: true -toc_label: "" -tags: - - Indicator Removal on Host - - Defense Evasion - - Clear Windows Event Logs - - Defense Evasion - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect execution of wevtutil.exe to disable logs. This technique was seen in several ransomware to disable the event logs to evade alerts and detections in compromised host. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2021-06-15 -- **Author**: Teoderick Contreras, Splunk -- **ID**: a4bdc944-cdd9-11eb-ac97-acde48001122 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1070](https://attack.mitre.org/techniques/T1070/) | Indicator Removal on Host | Defense Evasion | - -| [T1070.001](https://attack.mitre.org/techniques/T1070/001/) | Clear Windows Event Logs | Defense Evasion | - -#### Search - -``` - -| from read_ssa_enriched_events() -| where "Endpoint_Processes" IN(_datamodels) -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line IS NOT NULL AND like(cmd_line, "% sl %") AND like(cmd_line, "%/e:false%") AND process_name="wevtutil.exe" -| eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)) -| eval body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) -| into write_ssa_detected_events(); -``` - -#### Macros -The SPL above uses the following Macros: - -Note that `wevtutil_usage_to_disable_logs_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* dest_device_id -* process_name -* parent_process_name -* process_path -* dest_user_id -* process - - -#### How To Implement -You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. - -#### Known False Positives -network operator may disable audit event logs for debugging purposes. - -#### Associated Analytic story -* [Windows Log Manipulation](/stories/windows_log_manipulation) -* [Ransomware](/stories/ransomware) - - -#### Kill Chain Phase -* Exploitation - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 63.0 | 70 | 90 | A wevtutil process $process_name$ with commandline $cmd_line$ to disable event logs in host $dest_device_id$ | - - -Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` - - - -#### Reference - -* [https://www.bleepingcomputer.com/news/security/new-ransom-x-ransomware-used-in-texas-txdot-cyberattack/](https://www.bleepingcomputer.com/news/security/new-ransom-x-ransomware-used-in-texas-txdot-cyberattack/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070.001/ssa_wevtutil/disable_evt.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070.001/ssa_wevtutil/disable_evt.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/wevtutil_usage_to_disable_logs.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-06-16-detect_wmi_event_subscription_persistence.md b/docs/_posts/2021-06-16-detect_wmi_event_subscription_persistence.md deleted file mode 100644 index e75f0eb6fd..0000000000 --- a/docs/_posts/2021-06-16-detect_wmi_event_subscription_persistence.md +++ /dev/null @@ -1,168 +0,0 @@ ---- -title: "Detect WMI Event Subscription Persistence" -excerpt: "Windows Management Instrumentation Event Subscription -, Event Triggered Execution -" -categories: - - Endpoint -last_modified_at: 2021-06-16 -toc: true -toc_label: "" -tags: - - Windows Management Instrumentation Event Subscription - - Event Triggered Execution - - Persistence - - Privilege Escalation - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the use of WMI Event Subscription to establish persistence or perform privilege escalation. WMI can be used to install event filters, providers, consumers, and bindings that execute code when a defined event occurs. WMI subscription execution is proxied by the WMI Provider Host process (WmiPrvSe.exe) and thus may result in elevated SYSTEM privileges. This analytic is restricted by commonly added process execution and a path. If the volume is low enough, remove the values and flag on any new subscriptions.\ -All event subscriptions have three components \ -1. Filter - WQL Query for the events we want. EventID equals 19 \ -1. Consumer - An action to take upon triggering the filter. EventID equals 20 \ -1. Binding - Registers a filter to a consumer. EventID equals 21 \ -Monitor for the creation of new WMI EventFilter, EventConsumer, and FilterToConsumerBinding. It may be pertinent to review all 3 to identify the flow of execution. In addition, EventCode 4104 may assist with any other PowerShell script usage that registered the subscription. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-06-16 -- **Author**: Michael Haag, Splunk -- **ID**: 01d9a0c2-cece-11eb-ab46-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1546.003](https://attack.mitre.org/techniques/T1546/003/) | Windows Management Instrumentation Event Subscription | Persistence, Privilege Escalation | - -| [T1546](https://attack.mitre.org/techniques/T1546/) | Event Triggered Execution | Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventID=20 -| stats count min(_time) as firstTime max(_time) as lastTime by Computer User Destination -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_wmi_event_subscription_persistence_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **detect_wmi_event_subscription_persistence_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Destination -* Computer -* User - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with that provide WMI Event Subscription from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA and have enabled EventID 19, 20 and 21. Tune and filter known good to limit the volume. - -#### Known False Positives -It is possible some applications will create a consumer and may be required to be filtered. For tuning, add any additional LOLBin's for further depth of coverage. - -#### Associated Analytic story -* [Suspicious WMI Use](/stories/suspicious_wmi_use) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 63.0 | 70 | 90 | Possible malicious WMI Subscription created on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1546.003/T1546.003.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1546.003/T1546.003.md) -* [https://www.eideon.com/2018-03-02-THL03-WMIBackdoors/](https://www.eideon.com/2018-03-02-THL03-WMIBackdoors/) -* [https://github.com/trustedsec/SysmonCommunityGuide/blob/master/chapters/WMI-events.md](https://github.com/trustedsec/SysmonCommunityGuide/blob/master/chapters/WMI-events.md) -* [https://in.security/2019/04/03/an-intro-into-abusing-and-identifying-wmi-event-subscriptions-for-persistence/](https://in.security/2019/04/03/an-intro-into-abusing-and-identifying-wmi-event-subscriptions-for-persistence/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.003/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.003/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-06-17-suspicious_event_log_service_behavior.md b/docs/_posts/2021-06-17-suspicious_event_log_service_behavior.md deleted file mode 100644 index f638d3f37f..0000000000 --- a/docs/_posts/2021-06-17-suspicious_event_log_service_behavior.md +++ /dev/null @@ -1,172 +0,0 @@ ---- -title: "Suspicious Event Log Service Behavior" -excerpt: "Indicator Removal on Host -, Clear Windows Event Logs -" -categories: - - Endpoint -last_modified_at: 2021-06-17 -toc: true -toc_label: "" -tags: - - Indicator Removal on Host - - Clear Windows Event Logs - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes Windows Event ID 1100 to identify when Windows event log service is shutdown. Note that this is a voluminous analytic that will require tuning or restricted to specific endpoints based on criticality. This event generates every time Windows Event Log service has shut down. It also generates during normal system shutdown. During triage, based on time of day and user, determine if this was planned. If not planned, follow through with reviewing parallel alerts and other data sources to determine what else may have occurred. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-06-17 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 2b85aa3d-f5f6-4c2e-a081-a09f6e1c2e40 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1070](https://attack.mitre.org/techniques/T1070/) | Indicator Removal on Host | Defense Evasion | - -| [T1070.001](https://attack.mitre.org/techniques/T1070/001/) | Clear Windows Event Logs | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.DP -* PR.IP -* PR.AC -* PR.AT -* DE.AE - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 6 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -(`wineventlog_security` EventCode=1100) -| stats count min(_time) as firstTime max(_time) as lastTime by dest Message EventCode -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `suspicious_event_log_service_behavior_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **suspicious_event_log_service_behavior_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* dest - - -#### How To Implement -To successfully implement this search, you need to be ingesting Windows event logs from your hosts. In addition, the Splunk Windows TA is needed. - -#### Known False Positives -It is possible the Event Logging service gets shut down due to system errors or legitimately administration tasks. Filter as needed. - -#### Associated Analytic story -* [Windows Log Manipulation](/stories/windows_log_manipulation) -* [Ransomware](/stories/ransomware) -* [Clop Ransomware](/stories/clop_ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 9.0 | 30 | 30 | The Windows Event Log Service shutdown on $ComputerName$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-1100](https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-1100) -* [https://www.ired.team/offensive-security/defense-evasion/disabling-windows-event-logs-by-suspending-eventlog-service-threads](https://www.ired.team/offensive-security/defense-evasion/disabling-windows-event-logs-by-suspending-eventlog-service-threads) -* [https://attack.mitre.org/techniques/T1070/001/](https://attack.mitre.org/techniques/T1070/001/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1070.001/T1070.001.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1070.001/T1070.001.md) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070.001/atomic_red_team/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070.001/atomic_red_team/windows-security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/suspicious_event_log_service_behavior.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-06-22-execute_javascript_with_jscript_com_clsid.md b/docs/_posts/2021-06-22-execute_javascript_with_jscript_com_clsid.md deleted file mode 100644 index f41f7f15d2..0000000000 --- a/docs/_posts/2021-06-22-execute_javascript_with_jscript_com_clsid.md +++ /dev/null @@ -1,164 +0,0 @@ ---- -title: "Execute Javascript With Jscript COM CLSID" -excerpt: "Command and Scripting Interpreter -, Visual Basic -" -categories: - - Endpoint -last_modified_at: 2021-06-22 -toc: true -toc_label: "" -tags: - - Command and Scripting Interpreter - - Visual Basic - - Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic will identify suspicious process of cscript.exe where it tries to execute javascript using jscript.encode CLSID (COM OBJ). This technique was seen in ransomware (reddot ransomware) where it execute javascript with this com object with combination of amsi disabling technique. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-06-22 -- **Author**: Teoderick Contreras, Splunk -- **ID**: dc64d064-d346-11eb-8588-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -| [T1059.005](https://attack.mitre.org/techniques/T1059/005/) | Visual Basic | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = "cscript.exe" Processes.process="*-e:{F414C262-6AC0-11CF-B6D1-00AA00BBBB58}*" by Processes.parent_process_name Processes.process_name Processes.process Processes.parent_process Processes.process_id Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `execute_javascript_with_jscript_com_clsid_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **execute_javascript_with_jscript_com_clsid_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.parent_process_name -* Processes.process_name -* Processes.process -* Processes.parent_process -* Processes.process_id -* Processes.dest -* Processes.user - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the Filesystem responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Filesystem` node. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Ransomware](/stories/ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 56.0 | 80 | 70 | Suspicious process of cscript.exe with a parent process $parent_process_name$ where it tries to execute javascript using jscript.encode CLSID (COM OBJ), detected on $dest$ by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://app.any.run/tasks/c0f98850-af65-4352-9746-fbebadee4f05/](https://app.any.run/tasks/c0f98850-af65-4352-9746-fbebadee4f05/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/data2/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/data2/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-06-22-powershell_enable_smb1protocol_feature.md b/docs/_posts/2021-06-22-powershell_enable_smb1protocol_feature.md deleted file mode 100644 index 85426be232..0000000000 --- a/docs/_posts/2021-06-22-powershell_enable_smb1protocol_feature.md +++ /dev/null @@ -1,162 +0,0 @@ ---- -title: "Powershell Enable SMB1Protocol Feature" -excerpt: "Obfuscated Files or Information -, Indicator Removal from Tools -" -categories: - - Endpoint -last_modified_at: 2021-06-22 -toc: true -toc_label: "" -tags: - - Obfuscated Files or Information - - Indicator Removal from Tools - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect a suspicious enabling of smb1protocol through "powershell.exe". This technique was seen in some ransomware (like reddot) where it enable smb share to do the lateral movement and encrypt other files within the compromise network system. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-06-22 -- **Author**: Teoderick Contreras, Splunk -- **ID**: afed80b2-d34b-11eb-a952-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1027](https://attack.mitre.org/techniques/T1027/) | Obfuscated Files or Information | Defense Evasion | - -| [T1027.005](https://attack.mitre.org/techniques/T1027/005/) | Indicator Removal from Tools | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 Message = "*Enable-WindowsOptionalFeature*" Message = "*SMB1Protocol*" -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `powershell_enable_smb1protocol_feature_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **powershell_enable_smb1protocol_feature_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Message -* ComputerName -* User - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the powershell logs from your endpoints. make sure you enable needed registry to monitor this event. - -#### Known False Positives -network operator may enable or disable this windows feature. - -#### Associated Analytic story -* [Hermetic Wiper](/stories/hermetic_wiper) -* [Malicious PowerShell](/stories/malicious_powershell) -* [Ransomware](/stories/ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | Powershell Enable SMB1Protocol Feature | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://app.any.run/tasks/c0f98850-af65-4352-9746-fbebadee4f05/](https://app.any.run/tasks/c0f98850-af65-4352-9746-fbebadee4f05/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/data2/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/data2/windows-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-06-22-recursive_delete_of_directory_in_batch_cmd.md b/docs/_posts/2021-06-22-recursive_delete_of_directory_in_batch_cmd.md deleted file mode 100644 index a11edd86b5..0000000000 --- a/docs/_posts/2021-06-22-recursive_delete_of_directory_in_batch_cmd.md +++ /dev/null @@ -1,169 +0,0 @@ ---- -title: "Recursive Delete of Directory In Batch CMD" -excerpt: "File Deletion -, Indicator Removal on Host -" -categories: - - Endpoint -last_modified_at: 2021-06-22 -toc: true -toc_label: "" -tags: - - File Deletion - - Indicator Removal on Host - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect a suspicious commandline designed to delete files or directory recursive using batch command. This technique was seen in ransomware (reddot) where it it tries to delete the files in recycle bin to impaire user from recovering deleted files. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-06-22 -- **Author**: Teoderick Contreras, Splunk -- **ID**: ba570b3a-d356-11eb-8358-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1070.004](https://attack.mitre.org/techniques/T1070/004/) | File Deletion | Defense Evasion | - -| [T1070](https://attack.mitre.org/techniques/T1070/) | Indicator Removal on Host | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_cmd` Processes.process=*/c* Processes.process=* rd * Processes.process="*/s*" Processes.process="*/q*" by Processes.user Processes.process_name Processes.parent_process_name Processes.parent_process Processes.process Processes.process_id Processes.dest -|`drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `recursive_delete_of_directory_in_batch_cmd_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [process_cmd](https://github.com/splunk/security_content/blob/develop/macros/process_cmd.yml) - -> :information_source: -> **recursive_delete_of_directory_in_batch_cmd_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -network operator may use this batch command to delete recursively a directory or files within directory - -#### Associated Analytic story -* [Ransomware](/stories/ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | Recursive Delete of Directory In Batch CMD | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://app.any.run/tasks/c0f98850-af65-4352-9746-fbebadee4f05/](https://app.any.run/tasks/c0f98850-af65-4352-9746-fbebadee4f05/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/data2/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/data2/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-06-23-allow_file_and_printing_sharing_in_firewall.md b/docs/_posts/2021-06-23-allow_file_and_printing_sharing_in_firewall.md deleted file mode 100644 index bd7d3c9fd1..0000000000 --- a/docs/_posts/2021-06-23-allow_file_and_printing_sharing_in_firewall.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: "Allow File And Printing Sharing In Firewall" -excerpt: "Disable or Modify Cloud Firewall -, Impair Defenses -" -categories: - - Endpoint -last_modified_at: 2021-06-23 -toc: true -toc_label: "" -tags: - - Disable or Modify Cloud Firewall - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect a suspicious modification of firewall to allow file and printer sharing. This technique was seen in ransomware to be able to discover more machine connected to the compromised host to encrypt more files - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-06-23 -- **Author**: Teoderick Contreras, Splunk -- **ID**: ce27646e-d411-11eb-8a00-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.007](https://attack.mitre.org/techniques/T1562/007/) | Disable or Modify Cloud Firewall | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_netsh` Processes.process= "*firewall*" Processes.process= "*group=\"File and Printer Sharing\"*" Processes.process="*enable=Yes*" by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.parent_process_name Processes.original_file_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `allow_file_and_printing_sharing_in_firewall_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_netsh](https://github.com/splunk/security_content/blob/develop/macros/process_netsh.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **allow_file_and_printing_sharing_in_firewall_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -network admin may modify this firewall feature that may cause this rule to be triggered. - -#### Associated Analytic story -* [Ransomware](/stories/ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://community.fortinet.com:443/t5/FortiEDR/How-FortiEDR-detects-and-blocks-Revil-Ransomware-aka-sodinokibi/ta-p/189638?externalID=FD52469](https://community.fortinet.com:443/t5/FortiEDR/How-FortiEDR-detects-and-blocks-Revil-Ransomware-aka-sodinokibi/ta-p/189638?externalID=FD52469) -* [https://app.any.run/tasks/c0f98850-af65-4352-9746-fbebadee4f05/](https://app.any.run/tasks/c0f98850-af65-4352-9746-fbebadee4f05/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/data2/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/data2/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-06-23-allow_network_discovery_in_firewall.md b/docs/_posts/2021-06-23-allow_network_discovery_in_firewall.md deleted file mode 100644 index d1aafee343..0000000000 --- a/docs/_posts/2021-06-23-allow_network_discovery_in_firewall.md +++ /dev/null @@ -1,171 +0,0 @@ ---- -title: "Allow Network Discovery In Firewall" -excerpt: "Disable or Modify Cloud Firewall -, Impair Defenses -" -categories: - - Endpoint -last_modified_at: 2021-06-23 -toc: true -toc_label: "" -tags: - - Disable or Modify Cloud Firewall - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect a suspicious modification to the firewall to allow network discovery on a machine. This technique was seen in couple of ransomware (revil, reddot) to discover other machine connected to the compromised host to encrypt more files. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-06-23 -- **Author**: Teoderick Contreras, Splunk -- **ID**: ccd6a38c-d40b-11eb-85a5-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.007](https://attack.mitre.org/techniques/T1562/007/) | Disable or Modify Cloud Firewall | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_netsh` Processes.process= "*firewall*" Processes.process= "*group=\"Network Discovery\"*" Processes.process="*enable*" Processes.process="*Yes*" by Processes.dest Processes.user Processes.parent_process Processes.original_file_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `allow_network_discovery_in_firewall_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_netsh](https://github.com/splunk/security_content/blob/develop/macros/process_netsh.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **allow_network_discovery_in_firewall_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -network admin may modify this firewall feature that may cause this rule to be triggered. - -#### Associated Analytic story -* [Ransomware](/stories/ransomware) -* [Revil Ransomware](/stories/revil_ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://community.fortinet.com:443/t5/FortiEDR/How-FortiEDR-detects-and-blocks-Revil-Ransomware-aka-sodinokibi/ta-p/189638?externalID=FD52469](https://community.fortinet.com:443/t5/FortiEDR/How-FortiEDR-detects-and-blocks-Revil-Ransomware-aka-sodinokibi/ta-p/189638?externalID=FD52469) -* [https://app.any.run/tasks/c0f98850-af65-4352-9746-fbebadee4f05/](https://app.any.run/tasks/c0f98850-af65-4352-9746-fbebadee4f05/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/data2/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/data2/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/allow_network_discovery_in_firewall.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-06-24-excessive_usage_of_sc_service_utility.md b/docs/_posts/2021-06-24-excessive_usage_of_sc_service_utility.md deleted file mode 100644 index a425090e69..0000000000 --- a/docs/_posts/2021-06-24-excessive_usage_of_sc_service_utility.md +++ /dev/null @@ -1,165 +0,0 @@ ---- -title: "Excessive Usage Of SC Service Utility" -excerpt: "System Services -, Service Execution -" -categories: - - Endpoint -last_modified_at: 2021-06-24 -toc: true -toc_label: "" -tags: - - System Services - - Service Execution - - Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect a suspicious excessive usage of sc.exe in a host machine. This technique was seen in several ransomware , xmrig and other malware to create, modify, delete or disable a service may related to security application or to gain privilege escalation. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-06-24 -- **Author**: Teoderick Contreras, Splunk -- **ID**: cb6b339e-d4c6-11eb-a026-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1569](https://attack.mitre.org/techniques/T1569/) | System Services | Execution | - -| [T1569.002](https://attack.mitre.org/techniques/T1569/002/) | Service Execution | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventCode = 1 process_name = "sc.exe" -| bucket _time span=15m -| stats values(process) as process count as numScExe by Computer, _time -| eventstats avg(numScExe) as avgScExe, stdev(numScExe) as stdScExe, count as numSlots by Computer -| eval upperThreshold=(avgScExe + stdScExe *3) -| eval isOutlier=if(avgScExe > 5 and avgScExe >= upperThreshold, 1, 0) -| search isOutlier=1 -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `excessive_usage_of_sc_service_utility_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **excessive_usage_of_sc_service_utility_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* process_name -* process - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed taskkill.exe may be used. - -#### Known False Positives -excessive execution of sc.exe is quite suspicious since it can modify or execute app in high privilege permission. - -#### Associated Analytic story -* [Ransomware](/stories/ransomware) -* [Azorult](/stories/azorult) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | Excessive Usage Of SC Service Utility | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://app.any.run/tasks/c0f98850-af65-4352-9746-fbebadee4f05/](https://app.any.run/tasks/c0f98850-af65-4352-9746-fbebadee4f05/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/data2/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/data2/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-06-25-excessive_number_of_service_control_start_as_disabled.md b/docs/_posts/2021-06-25-excessive_number_of_service_control_start_as_disabled.md deleted file mode 100644 index ef62d7eafc..0000000000 --- a/docs/_posts/2021-06-25-excessive_number_of_service_control_start_as_disabled.md +++ /dev/null @@ -1,166 +0,0 @@ ---- -title: "Excessive number of service control start as disabled" -excerpt: "Disable or Modify Tools -, Impair Defenses -" -categories: - - Endpoint -last_modified_at: 2021-06-25 -toc: true -toc_label: "" -tags: - - Disable or Modify Tools - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This detection targets behaviors observed when threat actors have used sc.exe to modify services. We observed malware in a honey pot spawning numerous sc.exe processes in a short period of time, presumably to impair defenses, possibly to block others from compromising the same machine. This detection will alert when we see both an excessive number of sc.exe processes launched with specific commandline arguments to disable the start of certain services. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-06-25 -- **Author**: Michael Hart, Splunk -- **ID**: 77592bec-d5cc-11eb-9e60-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` distinct_count(Processes.process) as distinct_cmdlines values(Processes.process_id) as process_ids min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes WHERE Processes.process_name = "sc.exe" AND Processes.process="*start= disabled*" by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.parent_process_id, _time span=30m -| where distinct_cmdlines >= 8 -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `excessive_number_of_service_control_start_as_disabled_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **excessive_number_of_service_control_start_as_disabled_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must be ingesting logs with both the process name and command line from your endpoints. The complete process name with command-line arguments are mapped to the "process" field in the Endpoint data model. - -#### Known False Positives -Legitimate programs and administrators will execute sc.exe with the start disabled flag. It is possible, but unlikely from the telemetry of normal Windows operation we observed, that sc.exe will be called more than seven times in a short period of time. - -#### Associated Analytic story -* [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | An excessive amount of $process_name$ was executed on $dest$ attempting to disable services. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/sc-create](https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/sc-create) -* [https://attack.mitre.org/techniques/T1562/001/](https://attack.mitre.org/techniques/T1562/001/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/sc_service_start_disabled/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/sc_service_start_disabled/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-07-01-print_spooler_adding_a_printer_driver.md b/docs/_posts/2021-07-01-print_spooler_adding_a_printer_driver.md deleted file mode 100644 index 608519e66a..0000000000 --- a/docs/_posts/2021-07-01-print_spooler_adding_a_printer_driver.md +++ /dev/null @@ -1,174 +0,0 @@ ---- -title: "Print Spooler Adding A Printer Driver" -excerpt: "Print Processors -, Boot or Logon Autostart Execution -" -categories: - - Endpoint -last_modified_at: 2021-07-01 -toc: true -toc_label: "" -tags: - - Print Processors - - Boot or Logon Autostart Execution - - Persistence - - Privilege Escalation - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2021-34527 - - CVE-2021-1675 - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies new printer drivers being load by utilizing the Windows PrintService operational logs, EventCode 316. This was identified during our testing of CVE-2021-34527 previously (CVE-2021-1675) or PrintNightmare. \ -Within the proof of concept code, the following event will occur - "Printer driver 1234 for Windows x64 Version-3 was added or updated. Files:- UNIDRV.DLL, kernelbase.dll, evil.dll. No user action is required." \ -During triage, isolate the endpoint and review for source of exploitation. Capture any additional file modification events and review the source of where the exploitation began. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-07-01 -- **Author**: Mauricio Velazco, Michael Haag, Teoderick Contreras, Splunk -- **ID**: 313681a2-da8e-11eb-adad-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1547.012](https://attack.mitre.org/techniques/T1547/012/) | Print Processors | Persistence, Privilege Escalation | - -| [T1547](https://attack.mitre.org/techniques/T1547/) | Boot or Logon Autostart Execution | Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2021-34527](https://nvd.nist.gov/vuln/detail/CVE-2021-34527) | Windows Print Spooler Remote Code Execution Vulnerability | 9.0 | -| [CVE-2021-1675](https://nvd.nist.gov/vuln/detail/CVE-2021-1675) | Windows Print Spooler Elevation of Privilege Vulnerability | 9.3 | - - - -
-
- -#### Search - -``` -`printservice` EventCode=316 category = "Adding a printer driver" Message = "*kernelbase.dll,*" Message = "*UNIDRV.DLL,*" Message = "*.DLL.*" -| stats count min(_time) as firstTime max(_time) as lastTime by OpCode EventCode ComputerName Message -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `print_spooler_adding_a_printer_driver_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [printservice](https://github.com/splunk/security_content/blob/develop/macros/printservice.yml) - -> :information_source: -> **print_spooler_adding_a_printer_driver_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* OpCode -* EventCode -* ComputerName -* Message - - -#### How To Implement -You will need to ensure PrintService Admin and Operational logs are being logged to Splunk from critical or all systems. - -#### Known False Positives -Unknown. This may require filtering. - -#### Associated Analytic story -* [PrintNightmare CVE-2021-34527](/stories/printnightmare_cve-2021-34527) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 72.0 | 80 | 90 | Suspicious print driver was loaded on endpoint $ComputerName$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://twitter.com/MalwareJake/status/1410421445608476679?s=20](https://twitter.com/MalwareJake/status/1410421445608476679?s=20) -* [https://www.truesec.com/hub/blog/fix-for-printnightmare-cve-2021-1675-exploit-to-keep-your-print-servers-running-while-a-patch-is-not-available](https://www.truesec.com/hub/blog/fix-for-printnightmare-cve-2021-1675-exploit-to-keep-your-print-servers-running-while-a-patch-is-not-available) -* [https://www.truesec.com/hub/blog/exploitable-critical-rce-vulnerability-allows-regular-users-to-fully-compromise-active-directory-printnightmare-cve-2021-1675](https://www.truesec.com/hub/blog/exploitable-critical-rce-vulnerability-allows-regular-users-to-fully-compromise-active-directory-printnightmare-cve-2021-1675) -* [https://www.reddit.com/r/msp/comments/ob6y02/critical_vulnerability_printnightmare_exposes](https://www.reddit.com/r/msp/comments/ob6y02/critical_vulnerability_printnightmare_exposes) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.012/printnightmare/windows-printservice_operational.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.012/printnightmare/windows-printservice_operational.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/print_spooler_adding_a_printer_driver.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-07-01-print_spooler_failed_to_load_a_plug-in.md b/docs/_posts/2021-07-01-print_spooler_failed_to_load_a_plug-in.md deleted file mode 100644 index 420a89ebda..0000000000 --- a/docs/_posts/2021-07-01-print_spooler_failed_to_load_a_plug-in.md +++ /dev/null @@ -1,171 +0,0 @@ ---- -title: "Print Spooler Failed to Load a Plug-in" -excerpt: "Print Processors -, Boot or Logon Autostart Execution -" -categories: - - Endpoint -last_modified_at: 2021-07-01 -toc: true -toc_label: "" -tags: - - Print Processors - - Boot or Logon Autostart Execution - - Persistence - - Privilege Escalation - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2021-34527 - - CVE-2021-1675 - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies driver load errors utilizing the Windows PrintService Admin logs. This was identified during our testing of CVE-2021-34527 previously (CVE-2021-1675) or PrintNightmare. \ -Within the proof of concept code, the following error will occur - "The print spooler failed to load a plug-in module C:\Windows\system32\spool\DRIVERS\x64\3\meterpreter.dll, error code 0x45A. See the event user data for context information." \ -The analytic is based on file path and failure to load the plug-in. \ -During triage, isolate the endpoint and review for source of exploitation. Capture any additional file modification events. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-07-01 -- **Author**: Mauricio Velazco, Michael Haag, Splunk -- **ID**: 1adc9548-da7c-11eb-8f13-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1547.012](https://attack.mitre.org/techniques/T1547/012/) | Print Processors | Persistence, Privilege Escalation | - -| [T1547](https://attack.mitre.org/techniques/T1547/) | Boot or Logon Autostart Execution | Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2021-34527](https://nvd.nist.gov/vuln/detail/CVE-2021-34527) | Windows Print Spooler Remote Code Execution Vulnerability | 9.0 | -| [CVE-2021-1675](https://nvd.nist.gov/vuln/detail/CVE-2021-1675) | Windows Print Spooler Elevation of Privilege Vulnerability | 9.3 | - - - -
-
- -#### Search - -``` -`printservice` ((ErrorCode="0x45A" (EventCode="808" OR EventCode="4909")) OR ("The print spooler failed to load a plug-in module" OR "\\drivers\\x64\\")) -| stats count min(_time) as firstTime max(_time) as lastTime by OpCode EventCode ComputerName Message -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `print_spooler_failed_to_load_a_plug_in_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [printservice](https://github.com/splunk/security_content/blob/develop/macros/printservice.yml) - -> :information_source: -> **print_spooler_failed_to_load_a_plug-in_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* OpCode -* EventCode -* ComputerName -* Message - - -#### How To Implement -You will need to ensure PrintService Admin and Operational logs are being logged to Splunk from critical or all systems. - -#### Known False Positives -False positives are unknown and filtering may be required. - -#### Associated Analytic story -* [PrintNightmare CVE-2021-34527](/stories/printnightmare_cve-2021-34527) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 72.0 | 80 | 90 | Suspicious printer spooler errors have occured on endpoint $ComputerName$ with EventCode $EventCode$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.truesec.com/hub/blog/fix-for-printnightmare-cve-2021-1675-exploit-to-keep-your-print-servers-running-while-a-patch-is-not-available](https://www.truesec.com/hub/blog/fix-for-printnightmare-cve-2021-1675-exploit-to-keep-your-print-servers-running-while-a-patch-is-not-available) -* [https://www.truesec.com/hub/blog/exploitable-critical-rce-vulnerability-allows-regular-users-to-fully-compromise-active-directory-printnightmare-cve-2021-1675](https://www.truesec.com/hub/blog/exploitable-critical-rce-vulnerability-allows-regular-users-to-fully-compromise-active-directory-printnightmare-cve-2021-1675) -* [https://www.reddit.com/r/msp/comments/ob6y02/critical_vulnerability_printnightmare_exposes](https://www.reddit.com/r/msp/comments/ob6y02/critical_vulnerability_printnightmare_exposes) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/print_spooler_failed_to_load_a_plug_in.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-07-01-spoolsv_spawning_rundll32.md b/docs/_posts/2021-07-01-spoolsv_spawning_rundll32.md deleted file mode 100644 index afc087cf40..0000000000 --- a/docs/_posts/2021-07-01-spoolsv_spawning_rundll32.md +++ /dev/null @@ -1,178 +0,0 @@ ---- -title: "Spoolsv Spawning Rundll32" -excerpt: "Print Processors -, Boot or Logon Autostart Execution -" -categories: - - Endpoint -last_modified_at: 2021-07-01 -toc: true -toc_label: "" -tags: - - Print Processors - - Boot or Logon Autostart Execution - - Persistence - - Privilege Escalation - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2021-34527 - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies a suspicious child process, `rundll32.exe`, with no command-line arguments being spawned from `spoolsv.exe`. This was identified during our testing of CVE-2021-34527 previously (CVE-2021-1675) or PrintNightmare. Typically, this is not normal behavior for `spoolsv.exe` to spawn a process. During triage, isolate the endpoint and review for source of exploitation. Capture any additional file modification events. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-07-01 -- **Author**: Mauricio Velazco, Michael Haag, Splunk -- **ID**: 15d905f6-da6b-11eb-ab82-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1547.012](https://attack.mitre.org/techniques/T1547/012/) | Print Processors | Persistence, Privilege Escalation | - -| [T1547](https://attack.mitre.org/techniques/T1547/) | Boot or Logon Autostart Execution | Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2021-34527](https://nvd.nist.gov/vuln/detail/CVE-2021-34527) | Windows Print Spooler Remote Code Execution Vulnerability | 9.0 | - - - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=spoolsv.exe `process_rundll32` by Processes.dest Processes.user Processes.parent_process Processes.original_file_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `spoolsv_spawning_rundll32_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [process_rundll32](https://github.com/splunk/security_content/blob/develop/macros/process_rundll32.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **spoolsv_spawning_rundll32_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Limited false positives have been identified. There are limited instances where `rundll32.exe` may be spawned by a legitimate print driver. - -#### Associated Analytic story -* [PrintNightmare CVE-2021-34527](/stories/printnightmare_cve-2021-34527) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 72.0 | 80 | 90 | $parent_process$ has spawned $process_name$ on endpoint $ComputerName$. This behavior is suspicious and related to PrintNightmare. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.truesec.com/hub/blog/fix-for-printnightmare-cve-2021-1675-exploit-to-keep-your-print-servers-running-while-a-patch-is-not-available](https://www.truesec.com/hub/blog/fix-for-printnightmare-cve-2021-1675-exploit-to-keep-your-print-servers-running-while-a-patch-is-not-available) -* [https://www.truesec.com/hub/blog/exploitable-critical-rce-vulnerability-allows-regular-users-to-fully-compromise-active-directory-printnightmare-cve-2021-1675](https://www.truesec.com/hub/blog/exploitable-critical-rce-vulnerability-allows-regular-users-to-fully-compromise-active-directory-printnightmare-cve-2021-1675) -* [https://www.reddit.com/r/msp/comments/ob6y02/critical_vulnerability_printnightmare_exposes](https://www.reddit.com/r/msp/comments/ob6y02/critical_vulnerability_printnightmare_exposes) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.012/printnightmare/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.012/printnightmare/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/spoolsv_spawning_rundll32.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-07-01-spoolsv_suspicious_loaded_modules.md b/docs/_posts/2021-07-01-spoolsv_suspicious_loaded_modules.md deleted file mode 100644 index bbc1985d5b..0000000000 --- a/docs/_posts/2021-07-01-spoolsv_suspicious_loaded_modules.md +++ /dev/null @@ -1,168 +0,0 @@ ---- -title: "Spoolsv Suspicious Loaded Modules" -excerpt: "Print Processors -, Boot or Logon Autostart Execution -" -categories: - - Endpoint -last_modified_at: 2021-07-01 -toc: true -toc_label: "" -tags: - - Print Processors - - Boot or Logon Autostart Execution - - Persistence - - Privilege Escalation - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2021-34527 - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect suspicious loading of dll in specific path relative to printnightmare exploitation. In this search we try to detect the loaded modules made by spoolsv.exe after the exploitation. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-07-01 -- **Author**: Mauricio Velazco, Michael Haag, Teoderick Contreras, Splunk -- **ID**: a5e451f8-da81-11eb-b245-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1547.012](https://attack.mitre.org/techniques/T1547/012/) | Print Processors | Persistence, Privilege Escalation | - -| [T1547](https://attack.mitre.org/techniques/T1547/) | Boot or Logon Autostart Execution | Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2021-34527](https://nvd.nist.gov/vuln/detail/CVE-2021-34527) | Windows Print Spooler Remote Code Execution Vulnerability | 9.0 | - - - -
-
- -#### Search - -``` -`sysmon` EventCode=7 Image ="*\\spoolsv.exe" ImageLoaded="*\\Windows\\System32\\spool\\drivers\\x64\\*" ImageLoaded = "*.dll" -| stats dc(ImageLoaded) as countImgloaded values(ImageLoaded) as ImgLoaded count min(_time) as firstTime max(_time) as lastTime by Image Computer ProcessId EventCode -| where countImgloaded >= 3 -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `spoolsv_suspicious_loaded_modules_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **spoolsv_suspicious_loaded_modules_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Image -* Computer -* EventCode -* ImageLoaded - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name and imageloaded executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [PrintNightmare CVE-2021-34527](/stories/printnightmare_cve-2021-34527) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 72.0 | 80 | 90 | $Image$ with process id $process_id$ has loaded a driver from $ImageLoaded$ on endpoint $Computer$. This behavior is suspicious and related to PrintNightmare. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://raw.githubusercontent.com/hieuttmmo/sigma/dceb13fe3f1821b119ae495b41e24438bd97e3d0/rules/windows/image_load/sysmon_cve_2021_1675_print_nightmare.yml](https://raw.githubusercontent.com/hieuttmmo/sigma/dceb13fe3f1821b119ae495b41e24438bd97e3d0/rules/windows/image_load/sysmon_cve_2021_1675_print_nightmare.yml) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.012/printnightmare/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.012/printnightmare/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/spoolsv_suspicious_loaded_modules.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-07-01-spoolsv_suspicious_process_access.md b/docs/_posts/2021-07-01-spoolsv_suspicious_process_access.md deleted file mode 100644 index 1b43ca5a8e..0000000000 --- a/docs/_posts/2021-07-01-spoolsv_suspicious_process_access.md +++ /dev/null @@ -1,164 +0,0 @@ ---- -title: "Spoolsv Suspicious Process Access" -excerpt: "Exploitation for Privilege Escalation -" -categories: - - Endpoint -last_modified_at: 2021-07-01 -toc: true -toc_label: "" -tags: - - Exploitation for Privilege Escalation - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2021-34527 - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic identifies a suspicious behavior related to PrintNightmare, or CVE-2021-34527 previously (CVE-2021-1675), to gain privilege escalation on the vulnerable machine. This exploit attacks a critical Windows Print Spooler Vulnerability to elevate privilege. This detection is to look for suspicious process access made by the spoolsv.exe that may related to the attack. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-07-01 -- **Author**: Mauricio Velazco, Michael Haag, Teoderick Contreras, Splunk -- **ID**: 799b606e-da81-11eb-93f8-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1068](https://attack.mitre.org/techniques/T1068/) | Exploitation for Privilege Escalation | Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2021-34527](https://nvd.nist.gov/vuln/detail/CVE-2021-34527) | Windows Print Spooler Remote Code Execution Vulnerability | 9.0 | - - - -
-
- -#### Search - -``` -`sysmon` EventCode=10 SourceImage = "*\\spoolsv.exe" CallTrace = "*\\Windows\\system32\\spool\\DRIVERS\\x64\\*" TargetImage IN ("*\\rundll32.exe", "*\\spoolsv.exe") GrantedAccess = 0x1fffff -| stats count min(_time) as firstTime max(_time) as lastTime by Computer SourceImage TargetImage GrantedAccess CallTrace EventCode ProcessID -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `spoolsv_suspicious_process_access_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **spoolsv_suspicious_process_access_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* SourceImage -* TargetImage -* GrantedAccess -* CallTrace -* EventCode - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with process access event where SourceImage, TargetImage, GrantedAccess and CallTrace executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances of spoolsv.exe. - -#### Known False Positives -Unknown. Filter as needed. - -#### Associated Analytic story -* [PrintNightmare CVE-2021-34527](/stories/printnightmare_cve-2021-34527) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 72.0 | 80 | 90 | $SourceImage$ was GrantedAccess open access to $TargetImage$ on endpoint $Computer$. This behavior is suspicious and related to PrintNightmare. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/cube0x0/impacket/commit/73b9466c17761384ece11e1028ec6689abad6818](https://github.com/cube0x0/impacket/commit/73b9466c17761384ece11e1028ec6689abad6818) -* [https://www.truesec.com/hub/blog/fix-for-printnightmare-cve-2021-1675-exploit-to-keep-your-print-servers-running-while-a-patch-is-not-available](https://www.truesec.com/hub/blog/fix-for-printnightmare-cve-2021-1675-exploit-to-keep-your-print-servers-running-while-a-patch-is-not-available) -* [https://www.truesec.com/hub/blog/exploitable-critical-rce-vulnerability-allows-regular-users-to-fully-compromise-active-directory-printnightmare-cve-2021-1675](https://www.truesec.com/hub/blog/exploitable-critical-rce-vulnerability-allows-regular-users-to-fully-compromise-active-directory-printnightmare-cve-2021-1675) -* [https://www.reddit.com/r/msp/comments/ob6y02/critical_vulnerability_printnightmare_exposes](https://www.reddit.com/r/msp/comments/ob6y02/critical_vulnerability_printnightmare_exposes) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.012/printnightmare/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.012/printnightmare/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/spoolsv_suspicious_process_access.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-07-01-spoolsv_writing_a_dll.md b/docs/_posts/2021-07-01-spoolsv_writing_a_dll.md deleted file mode 100644 index cbc7c60c62..0000000000 --- a/docs/_posts/2021-07-01-spoolsv_writing_a_dll.md +++ /dev/null @@ -1,177 +0,0 @@ ---- -title: "Spoolsv Writing a DLL" -excerpt: "Print Processors -, Boot or Logon Autostart Execution -" -categories: - - Endpoint -last_modified_at: 2021-07-01 -toc: true -toc_label: "" -tags: - - Print Processors - - Boot or Logon Autostart Execution - - Persistence - - Privilege Escalation - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2021-34527 - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies a `.dll` being written by `spoolsv.exe`. This was identified during our testing of CVE-2021-34527 previously (CVE-2021-1675) or PrintNightmare. Typically, this is not normal behavior for `spoolsv.exe` to write a `.dll`. Current POC code used will write the suspicious DLL to disk within a path of `\spool\drivers\x64\`. During triage, isolate the endpoint and review for source of exploitation. Capture any additional file modification events. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-07-01 -- **Author**: Mauricio Velazco, Michael Haag, Splunk -- **ID**: d5bf5cf2-da71-11eb-92c2-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1547.012](https://attack.mitre.org/techniques/T1547/012/) | Print Processors | Persistence, Privilege Escalation | - -| [T1547](https://attack.mitre.org/techniques/T1547/) | Boot or Logon Autostart Execution | Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2021-34527](https://nvd.nist.gov/vuln/detail/CVE-2021-34527) | Windows Print Spooler Remote Code Execution Vulnerability | 9.0 | - - - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name=spoolsv.exe by _time Processes.process_id Processes.process_name Processes.dest -| `drop_dm_object_name(Processes)` -| join process_guid, _time [ -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_path="*\\spool\\drivers\\x64\\*" Filesystem.file_name="*.dll" by _time Filesystem.dest Filesystem.file_create_time Filesystem.file_name Filesystem.file_path -| `drop_dm_object_name(Filesystem)` -| fields _time dest file_create_time file_name file_path process_name process_path process] -| dedup file_create_time -| table dest file_create_time, file_name, file_path, process_name -| `spoolsv_writing_a_dll_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **spoolsv_writing_a_dll_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Filesystem.dest -* Filesystem.file_create_time -* Filesystem.file_name -* Filesystem.file_path -* Processes.process_name -* Processes.process_id -* Processes.process_name -* Processes.dest - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node and `Filesystem` node. - -#### Known False Positives -Unknown. - -#### Associated Analytic story -* [PrintNightmare CVE-2021-34527](/stories/printnightmare_cve-2021-34527) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 72.0 | 80 | 90 | $process_name$ has been identified writing dll's to $file_path$ on endpoint $dest$. This behavior is suspicious and related to PrintNightmare. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.truesec.com/hub/blog/fix-for-printnightmare-cve-2021-1675-exploit-to-keep-your-print-servers-running-while-a-patch-is-not-available](https://www.truesec.com/hub/blog/fix-for-printnightmare-cve-2021-1675-exploit-to-keep-your-print-servers-running-while-a-patch-is-not-available) -* [https://www.truesec.com/hub/blog/exploitable-critical-rce-vulnerability-allows-regular-users-to-fully-compromise-active-directory-printnightmare-cve-2021-1675](https://www.truesec.com/hub/blog/exploitable-critical-rce-vulnerability-allows-regular-users-to-fully-compromise-active-directory-printnightmare-cve-2021-1675) -* [https://www.reddit.com/r/msp/comments/ob6y02/critical_vulnerability_printnightmare_exposes](https://www.reddit.com/r/msp/comments/ob6y02/critical_vulnerability_printnightmare_exposes) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.012/printnightmare/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.012/printnightmare/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/spoolsv_writing_a_dll.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-07-01-spoolsv_writing_a_dll_-_sysmon.md b/docs/_posts/2021-07-01-spoolsv_writing_a_dll_-_sysmon.md deleted file mode 100644 index 28dfef2479..0000000000 --- a/docs/_posts/2021-07-01-spoolsv_writing_a_dll_-_sysmon.md +++ /dev/null @@ -1,172 +0,0 @@ ---- -title: "Spoolsv Writing a DLL - Sysmon" -excerpt: "Print Processors -, Boot or Logon Autostart Execution -" -categories: - - Endpoint -last_modified_at: 2021-07-01 -toc: true -toc_label: "" -tags: - - Print Processors - - Boot or Logon Autostart Execution - - Persistence - - Privilege Escalation - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2021-34527 - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies a `.dll` being written by `spoolsv.exe`. This was identified during our testing of CVE-2021-34527 previously(CVE-2021-1675) or PrintNightmare. Typically, this is not normal behavior for `spoolsv.exe` to write a `.dll`. Current POC code used will write the suspicious DLL to disk within a path of `\spool\drivers\x64\`. During triage, isolate the endpoint and review for source of exploitation. Capture any additional file modification events. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-07-01 -- **Author**: Mauricio Velazco, Michael Haag, Splunk -- **ID**: 347fd388-da87-11eb-836d-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1547.012](https://attack.mitre.org/techniques/T1547/012/) | Print Processors | Persistence, Privilege Escalation | - -| [T1547](https://attack.mitre.org/techniques/T1547/) | Boot or Logon Autostart Execution | Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2021-34527](https://nvd.nist.gov/vuln/detail/CVE-2021-34527) | Windows Print Spooler Remote Code Execution Vulnerability | 9.0 | - - - -
-
- -#### Search - -``` -`sysmon` EventID=11 process_name=spoolsv.exe file_path="*\\spool\\drivers\\x64\\*" file_name=*.dll -| stats count min(_time) as firstTime max(_time) as lastTime by dest, UserID, process_name, file_path, file_name, TargetFilename, process_id -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `spoolsv_writing_a_dll___sysmon_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **spoolsv_writing_a_dll_-_sysmon_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* dest -* UserID -* process_name -* file_path -* file_name -* TargetFilename - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed rundll32.exe may be used. - -#### Known False Positives -Limited false positives. Filter as needed. - -#### Associated Analytic story -* [PrintNightmare CVE-2021-34527](/stories/printnightmare_cve-2021-34527) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 72.0 | 80 | 90 | $process_name$ has been identified writing dll's to $file_path$ on endpoint $dest$. This behavior is suspicious and related to PrintNightmare. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/cube0x0/impacket/commit/73b9466c17761384ece11e1028ec6689abad6818](https://github.com/cube0x0/impacket/commit/73b9466c17761384ece11e1028ec6689abad6818) -* [https://www.truesec.com/hub/blog/fix-for-printnightmare-cve-2021-1675-exploit-to-keep-your-print-servers-running-while-a-patch-is-not-available](https://www.truesec.com/hub/blog/fix-for-printnightmare-cve-2021-1675-exploit-to-keep-your-print-servers-running-while-a-patch-is-not-available) -* [https://www.truesec.com/hub/blog/exploitable-critical-rce-vulnerability-allows-regular-users-to-fully-compromise-active-directory-printnightmare-cve-2021-1675](https://www.truesec.com/hub/blog/exploitable-critical-rce-vulnerability-allows-regular-users-to-fully-compromise-active-directory-printnightmare-cve-2021-1675) -* [https://www.reddit.com/r/msp/comments/ob6y02/critical_vulnerability_printnightmare_exposes](https://www.reddit.com/r/msp/comments/ob6y02/critical_vulnerability_printnightmare_exposes) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.012/printnightmare/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.012/printnightmare/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/spoolsv_writing_a_dll___sysmon.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-07-05-msmpeng_application_dll_side_loading.md b/docs/_posts/2021-07-05-msmpeng_application_dll_side_loading.md deleted file mode 100644 index d736ada874..0000000000 --- a/docs/_posts/2021-07-05-msmpeng_application_dll_side_loading.md +++ /dev/null @@ -1,167 +0,0 @@ ---- -title: "Msmpeng Application DLL Side Loading" -excerpt: "DLL Side-Loading -, Hijack Execution Flow -" -categories: - - Endpoint -last_modified_at: 2021-07-05 -toc: true -toc_label: "" -tags: - - DLL Side-Loading - - Hijack Execution Flow - - Defense Evasion - - Persistence - - Privilege Escalation - - Defense Evasion - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect a suspicious creation of msmpeng.exe or mpsvc.dll in non default windows defender folder. This technique was seen couple days ago with revil ransomware in Kaseya Supply chain. The approach is to drop an old version of msmpeng.exe to load the actual payload name as mspvc.dll which will load the revil ransomware to the compromise machine - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-07-05 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 8bb3f280-dd9b-11eb-84d5-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1574.002](https://attack.mitre.org/techniques/T1574/002/) | DLL Side-Loading | Defense Evasion, Persistence, Privilege Escalation | - -| [T1574](https://attack.mitre.org/techniques/T1574/) | Hijack Execution Flow | Defense Evasion, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -|tstats `security_content_summariesonly` values(Filesystem.file_path) as file_path count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Filesystem where (Filesystem.file_name = "msmpeng.exe" OR Filesystem.file_name = "mpsvc.dll") AND Filesystem.file_path != "*\\Program Files\\windows defender\\*" by Filesystem.file_create_time Filesystem.process_id Filesystem.file_name Filesystem.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `msmpeng_application_dll_side_loading_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **msmpeng_application_dll_side_loading_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Filesystem.file_create_time -* Filesystem.process_id -* Filesystem.file_name -* Filesystem.user -* Filesystem.file_path - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the Filesystem responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Filesystem` node. - -#### Known False Positives -quite minimal false positive expected. - -#### Associated Analytic story -* [Ransomware](/stories/ransomware) -* [Revil Ransomware](/stories/revil_ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://community.sophos.com/b/security-blog/posts/active-ransomware-attack-on-kaseya-customers](https://community.sophos.com/b/security-blog/posts/active-ransomware-attack-on-kaseya-customers) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets//malware/revil/msmpeng_side/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets//malware/revil/msmpeng_side/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-07-05-powershell_disable_security_monitoring.md b/docs/_posts/2021-07-05-powershell_disable_security_monitoring.md deleted file mode 100644 index 1bcde7cce2..0000000000 --- a/docs/_posts/2021-07-05-powershell_disable_security_monitoring.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: "Powershell Disable Security Monitoring" -excerpt: "Disable or Modify Tools -, Impair Defenses -" -categories: - - Endpoint -last_modified_at: 2021-07-05 -toc: true -toc_label: "" -tags: - - Disable or Modify Tools - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to identifies a modification in registry to disable the windows denfender real time behavior monitoring. This event or technique is commonly seen in RAT, bot, or Trojan to disable AV to evade detections. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-07-05 -- **Author**: Michael Haag, Splunk -- **ID**: c148a894-dd93-11eb-bf2a-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_powershell` Processes.process="*set-mppreference*" AND Processes.process IN ("*disablerealtimemonitoring*","*disableioavprotection*","*disableintrusionpreventionsystem*","*disablescriptscanning*","*disableblockatfirstseen*") by Processes.dest Processes.user Processes.parent_process Processes.original_file_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `powershell_disable_security_monitoring_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **powershell_disable_security_monitoring_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Limited false positives. However, tune based on scripts that may perform this action. - -#### Associated Analytic story -* [Ransomware](/stories/ransomware) -* [Revil Ransomware](/stories/revil_ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1562.001/T1562.001.md#atomic-test-15---tamper-with-windows-defender-atp-powershell](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1562.001/T1562.001.md#atomic-test-15---tamper-with-windows-defender-atp-powershell) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/pwh_defender_disabling/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/pwh_defender_disabling/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/powershell_disable_security_monitoring.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-07-12-uac_bypass_mmc_load_unsigned_dll.md b/docs/_posts/2021-07-12-uac_bypass_mmc_load_unsigned_dll.md deleted file mode 100644 index c8832363f7..0000000000 --- a/docs/_posts/2021-07-12-uac_bypass_mmc_load_unsigned_dll.md +++ /dev/null @@ -1,171 +0,0 @@ ---- -title: "UAC Bypass MMC Load Unsigned Dll" -excerpt: "Bypass User Account Control -, Abuse Elevation Control Mechanism -, MMC -" -categories: - - Endpoint -last_modified_at: 2021-07-12 -toc: true -toc_label: "" -tags: - - Bypass User Account Control - - Abuse Elevation Control Mechanism - - MMC - - Defense Evasion - - Privilege Escalation - - Defense Evasion - - Privilege Escalation - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect a suspicious loaded unsigned dll by MMC.exe application. This technique is commonly seen in attacker that tries to bypassed UAC feature or gain privilege escalation. This is done by modifying some CLSID registry that will trigger the mmc.exe to load the dll path - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-07-12 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 7f04349c-e30d-11eb-bc7f-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1548.002](https://attack.mitre.org/techniques/T1548/002/) | Bypass User Account Control | Defense Evasion, Privilege Escalation | - -| [T1548](https://attack.mitre.org/techniques/T1548/) | Abuse Elevation Control Mechanism | Defense Evasion, Privilege Escalation | - -| [T1218.014](https://attack.mitre.org/techniques/T1218/014/) | MMC | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventCode=7 ImageLoaded = "*.dll" Image = "*\\mmc.exe" Signed=false Company != "Microsoft Corporation" -| stats count min(_time) as firstTime max(_time) as lastTime by Image ImageLoaded Signed ProcessId OriginalFileName Computer EventCode Company -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `uac_bypass_mmc_load_unsigned_dll_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **uac_bypass_mmc_load_unsigned_dll_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Image -* ImageLoaded -* Signed -* ProcessId -* OriginalFileName -* Computer -* EventCode -* Company - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name and imageloaded executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -unknown. all of the dll loaded by mmc.exe is microsoft signed dll. - -#### Associated Analytic story -* [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 63.0 | 70 | 90 | Suspicious unsigned $ImageLoaded$ loaded by $Image$ on endpoint $Computer$ with EventCode $EventCode$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://offsec.almond.consulting/UAC-bypass-dotnet.html](https://offsec.almond.consulting/UAC-bypass-dotnet.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/uac_bypass/windows-sysmon2.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/uac_bypass/windows-sysmon2.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-07-13-cloud_compute_instance_created_by_previously_unseen_user.md b/docs/_posts/2021-07-13-cloud_compute_instance_created_by_previously_unseen_user.md deleted file mode 100644 index 9c8e890bd2..0000000000 --- a/docs/_posts/2021-07-13-cloud_compute_instance_created_by_previously_unseen_user.md +++ /dev/null @@ -1,178 +0,0 @@ ---- -title: "Cloud Compute Instance Created By Previously Unseen User" -excerpt: "Cloud Accounts -, Valid Accounts -" -categories: - - Cloud -last_modified_at: 2021-07-13 -toc: true -toc_label: "" -tags: - - Cloud Accounts - - Valid Accounts - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Change ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for cloud compute instances created by users who have not created them before. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Change](https://docs.splunk.com/Documentation/CIM/latest/User/Change)- **Datasource**: [Splunk Add-on for Amazon Kinesis Firehose](https://splunkbase.splunk.com/app/3719) -- **Last Updated**: 2021-07-13 -- **Author**: Rico Valdez, Splunk -- **ID**: 37a0ec8d-827e-4d6d-8025-cedf31f3a149 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1078.004](https://attack.mitre.org/techniques/T1078/004/) | Cloud Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* ID.AM - - - -
-
- -
- CIS20 - -
- -* CIS 1 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count earliest(_time) as firstTime, latest(_time) as lastTime values(All_Changes.object) as dest from datamodel=Change where All_Changes.action=created by All_Changes.user All_Changes.vendor_region -| `drop_dm_object_name("All_Changes")` -| lookup previously_seen_cloud_compute_creations_by_user user as user OUTPUTNEW firstTimeSeen, enough_data -| eventstats max(enough_data) as enough_data -| where enough_data=1 -| eval firstTimeSeenUser=min(firstTimeSeen) -| where isnull(firstTimeSeenUser) OR firstTimeSeenUser > relative_time(now(), "-24h@h") -| table firstTime, user, dest, count vendor_region -| `security_content_ctime(firstTime)` -| `cloud_compute_instance_created_by_previously_unseen_user_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **cloud_compute_instance_created_by_previously_unseen_user_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Lookups -The SPL above uses the following Lookups: - -* [previously_seen_cloud_compute_creations_by_user](https://github.com/splunk/security_content/blob/develop/lookups/previously_seen_cloud_compute_creations_by_user.yml) with [data](https://github.com/splunk/security_content/tree/develop/lookups/previously_seen_cloud_compute_creations_by_user.csv) - -#### Required field -* _time -* All_Changes.object -* All_Changes.action -* All_Changes.user -* All_Changes.vendor_region - - -#### How To Implement -You must be ingesting the appropriate cloud-infrastructure logs Run the "Previously Seen Cloud Compute Creations By User" support search to create of baseline of previously seen users. - -#### Known False Positives -It's possible that a user will start to create compute instances for the first time, for any number of reasons. Verify with the user launching instances that this is the intended behavior. - -#### Associated Analytic story -* [Cloud Cryptomining](/stories/cloud_cryptomining) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 18.0 | 30 | 60 | User $user$ is creating a new instance $dest$ for the first time | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-07-19-aws_createaccesskey.md b/docs/_posts/2021-07-19-aws_createaccesskey.md deleted file mode 100644 index b423035ff6..0000000000 --- a/docs/_posts/2021-07-19-aws_createaccesskey.md +++ /dev/null @@ -1,111 +0,0 @@ ---- -title: "AWS CreateAccessKey" -excerpt: "Cloud Account -, Create Account -" -categories: - - Cloud -last_modified_at: 2021-07-19 -toc: true -toc_label: "" -tags: - - Cloud Account - - Create Account - - Persistence - - Persistence - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for AWS CloudTrail events where a user A who has already permission to create access keys, makes an API call to create access keys for another user B. Attackers have been know to use this technique for Privilege Escalation in case new victim(user B) has more permissions than old victim(user B) - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/object-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: -- **Last Updated**: 2021-07-19 -- **Author**: Bhavin Patel, Splunk -- **ID**: 2a9b80d3-6340-4345-11ad-212bf3d0d111 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1136.003](https://attack.mitre.org/techniques/T1136/003/) | Cloud Account | Persistence | - -| [T1136](https://attack.mitre.org/techniques/T1136/) | Create Account | Persistence | - -#### Search - -``` -`cloudtrail` eventName = CreateAccessKey userAgent !=console.amazonaws.com errorCode = success -| search userIdentity.userName!=requestParameters.userName -| stats count min(_time) as firstTime max(_time) as lastTime by requestParameters.userName src eventName eventSource aws_account_id errorCode userAgent eventID awsRegion userIdentity.principalId user_arn -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -|`aws_createaccesskey_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -Note that `aws_createaccesskey_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* eventName -* userAgent -* errorCode -* requestParameters.userName - - -#### How To Implement -You must install splunk AWS add on and Splunk App for AWS. This search works with AWS CloudTrail logs. - -#### Known False Positives -While this search has no known false positives, it is possible that an AWS admin has legitimately created keys for another user. - -#### Associated Analytic story -* [AWS IAM Privilege Escalation](/stories/aws_iam_privilege_escalation) - - -#### Kill Chain Phase -* Actions on Objectives - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 63.0 | 70 | 90 | User $user_arn$ is attempting to create access keys for $requestParameters.userName$ from this IP $src$ | - - - - -#### Reference - -* [https://labs.bishopfox.com/tech-blog/privilege-escalation-in-aws](https://labs.bishopfox.com/tech-blog/privilege-escalation-in-aws) -* [https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation-part-2/](https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation-part-2/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_createaccesskey/aws_cloudtrail_events.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_createaccesskey/aws_cloudtrail_events.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/aws_createaccesskey.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-07-19-aws_createloginprofile.md b/docs/_posts/2021-07-19-aws_createloginprofile.md deleted file mode 100644 index b2e2c7f42c..0000000000 --- a/docs/_posts/2021-07-19-aws_createloginprofile.md +++ /dev/null @@ -1,171 +0,0 @@ ---- -title: "AWS CreateLoginProfile" -excerpt: "Cloud Account -, Create Account -" -categories: - - Cloud -last_modified_at: 2021-07-19 -toc: true -toc_label: "" -tags: - - Cloud Account - - Create Account - - Persistence - - Persistence - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for AWS CloudTrail events where a user A(victim A) creates a login profile for user B, followed by a AWS Console login event from user B from the same src_ip as user B. This correlated event can be indicative of privilege escalation since both events happened from the same src_ip - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-07-19 -- **Author**: Bhavin Patel, Splunk -- **ID**: 2a9b80d3-6340-4345-11ad-212bf444d111 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1136.003](https://attack.mitre.org/techniques/T1136/003/) | Cloud Account | Persistence | - -| [T1136](https://attack.mitre.org/techniques/T1136/) | Create Account | Persistence | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.DS -* PR.AC -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 13 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cloudtrail` eventName = CreateLoginProfile -| rename requestParameters.userName as new_login_profile -| table src_ip eventName new_login_profile userIdentity.userName -| join new_login_profile src_ip [ -| search `cloudtrail` eventName = ConsoleLogin -| rename userIdentity.userName as new_login_profile -| stats count values(eventName) min(_time) as firstTime max(_time) as lastTime by eventSource aws_account_id errorCode userAgent eventID awsRegion userIdentity.principalId user_arn new_login_profile src_ip -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)`] -| `aws_createloginprofile_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) - -> :information_source: -> **aws_createloginprofile_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* eventName -* userAgent -* errorCode -* requestParameters.userName - - -#### How To Implement -You must install splunk AWS add on and Splunk App for AWS. This search works with AWS CloudTrail logs. - -#### Known False Positives -While this search has no known false positives, it is possible that an AWS admin has legitimately created a login profile for another user. - -#### Associated Analytic story -* [AWS IAM Privilege Escalation](/stories/aws_iam_privilege_escalation) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 72.0 | 90 | 80 | User $user_arn$ is attempting to create a login profile for $requestParameters.userName$ and did a console login from this IP $src_ip$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://bishopfox.com/blog/privilege-escalation-in-aws](https://bishopfox.com/blog/privilege-escalation-in-aws) -* [https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation-part-2/](https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation-part-2/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_createloginprofile/aws_cloudtrail_events.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_createloginprofile/aws_cloudtrail_events.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/aws_createloginprofile.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-07-19-aws_updateloginprofile.md b/docs/_posts/2021-07-19-aws_updateloginprofile.md deleted file mode 100644 index 724ad761bf..0000000000 --- a/docs/_posts/2021-07-19-aws_updateloginprofile.md +++ /dev/null @@ -1,111 +0,0 @@ ---- -title: "AWS UpdateLoginProfile" -excerpt: "Cloud Account -, Create Account -" -categories: - - Cloud -last_modified_at: 2021-07-19 -toc: true -toc_label: "" -tags: - - Cloud Account - - Create Account - - Persistence - - Persistence - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for AWS CloudTrail events where a user A who has already permission to update login profile, makes an API call to update login profile for another user B . Attackers have been know to use this technique for Privilege Escalation in case new victim(user B) has more permissions than old victim(user B) - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/object-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: -- **Last Updated**: 2021-07-19 -- **Author**: Bhavin Patel, Splunk -- **ID**: 2a9b80d3-6a40-4115-11ad-212bf3d0d111 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1136.003](https://attack.mitre.org/techniques/T1136/003/) | Cloud Account | Persistence | - -| [T1136](https://attack.mitre.org/techniques/T1136/) | Create Account | Persistence | - -#### Search - -``` -`cloudtrail` eventName = UpdateLoginProfile userAgent !=console.amazonaws.com errorCode = success -| search userIdentity.userName!=requestParameters.userName -| stats count min(_time) as firstTime max(_time) as lastTime by requestParameters.userName src eventName eventSource aws_account_id errorCode userAgent eventID awsRegion userIdentity.userName user_arn -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -|`aws_updateloginprofile_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -Note that `aws_updateloginprofile_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* eventName -* userAgent -* errorCode -* requestParameters.userName - - -#### How To Implement -You must install splunk AWS add on and Splunk App for AWS. This search works with AWS CloudTrail logs. - -#### Known False Positives -While this search has no known false positives, it is possible that an AWS admin has legitimately created keys for another user. - -#### Associated Analytic story -* [AWS IAM Privilege Escalation](/stories/aws_iam_privilege_escalation) - - -#### Kill Chain Phase -* Actions on Objectives - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 30.0 | 50 | 60 | From IP address $sourceIPAddress$, user agent $userAgent$ has trigged an event $eventName$ for updating the existing login profile, potentially giving user $user_arn$ more access privilleges | - - - - -#### Reference - -* [https://labs.bishopfox.com/tech-blog/privilege-escalation-in-aws](https://labs.bishopfox.com/tech-blog/privilege-escalation-in-aws) -* [https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation-part-2/](https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation-part-2/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_updateloginprofile/aws_cloudtrail_events.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_updateloginprofile/aws_cloudtrail_events.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/aws_updateloginprofile.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-07-19-detect_new_open_s3_buckets.md b/docs/_posts/2021-07-19-detect_new_open_s3_buckets.md deleted file mode 100644 index 6c3e88a3a7..0000000000 --- a/docs/_posts/2021-07-19-detect_new_open_s3_buckets.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: "Detect New Open S3 buckets" -excerpt: "Data from Cloud Storage Object -" -categories: - - Cloud -last_modified_at: 2021-07-19 -toc: true -toc_label: "" -tags: - - Data from Cloud Storage Object - - Collection - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for AWS CloudTrail events where a user has created an open/public S3 bucket. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-07-19 -- **Author**: Bhavin Patel, Patrick Bareiss, Splunk -- **ID**: 2a9b80d3-6340-4345-b5ad-290bf3d0dac4 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1530](https://attack.mitre.org/techniques/T1530/) | Data from Cloud Storage Object | Collection | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.DS -* PR.AC -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 13 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cloudtrail` eventSource=s3.amazonaws.com eventName=PutBucketAcl -| rex field=_raw "(?{.+})" -| spath input=json_field output=grantees path=requestParameters.AccessControlPolicy.AccessControlList.Grant{} -| search grantees=* -| mvexpand grantees -| spath input=grantees output=uri path=Grantee.URI -| spath input=grantees output=permission path=Permission -| search uri IN ("http://acs.amazonaws.com/groups/global/AllUsers","http://acs.amazonaws.com/groups/global/AuthenticatedUsers") -| search permission IN ("READ","READ_ACP","WRITE","WRITE_ACP","FULL_CONTROL") -| rename requestParameters.bucketName AS bucketName -| stats count min(_time) as firstTime max(_time) as lastTime by user_arn userIdentity.principalId userAgent uri permission bucketName -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_new_open_s3_buckets_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) - -> :information_source: -> **detect_new_open_s3_buckets_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* eventSource -* eventName -* requestParameters.bucketName -* user_arn -* userIdentity.principalId -* userAgent -* uri -* permission - - -#### How To Implement -You must install the AWS App for Splunk. - -#### Known False Positives -While this search has no known false positives, it is possible that an AWS admin has legitimately created a public bucket for a specific purpose. That said, AWS strongly advises against granting full control to the "All Users" group. - -#### Associated Analytic story -* [Suspicious AWS S3 Activities](/stories/suspicious_aws_s3_activities) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 48.0 | 60 | 80 | User $user_arn$ has created an open/public bucket $bucketName$ with the following permissions $permission$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1530/aws_s3_public_bucket/aws_cloudtrail_events.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1530/aws_s3_public_bucket/aws_cloudtrail_events.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/detect_new_open_s3_buckets.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2021-07-19-detect_new_open_s3_buckets_over_aws_cli.md b/docs/_posts/2021-07-19-detect_new_open_s3_buckets_over_aws_cli.md deleted file mode 100644 index fae0ca6e88..0000000000 --- a/docs/_posts/2021-07-19-detect_new_open_s3_buckets_over_aws_cli.md +++ /dev/null @@ -1,166 +0,0 @@ ---- -title: "Detect New Open S3 Buckets over AWS CLI" -excerpt: "Data from Cloud Storage Object -" -categories: - - Cloud -last_modified_at: 2021-07-19 -toc: true -toc_label: "" -tags: - - Data from Cloud Storage Object - - Collection - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for AWS CloudTrail events where a user has created an open/public S3 bucket over the aws cli. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-07-19 -- **Author**: Patrick Bareiss, Splunk -- **ID**: 39c61d09-8b30-4154-922b-2d0a694ecc22 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1530](https://attack.mitre.org/techniques/T1530/) | Data from Cloud Storage Object | Collection | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.DS -* PR.AC -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 13 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cloudtrail` eventSource="s3.amazonaws.com" (userAgent="[aws-cli*" OR userAgent=aws-cli* ) eventName=PutBucketAcl OR requestParameters.accessControlList.x-amz-grant-read-acp IN ("*AuthenticatedUsers","*AllUsers") OR requestParameters.accessControlList.x-amz-grant-write IN ("*AuthenticatedUsers","*AllUsers") OR requestParameters.accessControlList.x-amz-grant-write-acp IN ("*AuthenticatedUsers","*AllUsers") OR requestParameters.accessControlList.x-amz-grant-full-control IN ("*AuthenticatedUsers","*AllUsers") -| rename requestParameters.bucketName AS bucketName -| fillnull -| stats count min(_time) as firstTime max(_time) as lastTime by userIdentity.userName userIdentity.principalId userAgent bucketName requestParameters.accessControlList.x-amz-grant-read requestParameters.accessControlList.x-amz-grant-read-acp requestParameters.accessControlList.x-amz-grant-write requestParameters.accessControlList.x-amz-grant-write-acp requestParameters.accessControlList.x-amz-grant-full-control -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_new_open_s3_buckets_over_aws_cli_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) - -> :information_source: -> **detect_new_open_s3_buckets_over_aws_cli_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* eventSource -* eventName -* requestParameters.accessControlList.x-amz-grant-read-acp -* requestParameters.accessControlList.x-amz-grant-write -* requestParameters.accessControlList.x-amz-grant-write-acp -* requestParameters.accessControlList.x-amz-grant-full-control -* requestParameters.bucketName -* userIdentity.userName -* userIdentity.principalId -* userAgent -* bucketName - - -#### How To Implement - - -#### Known False Positives -While this search has no known false positives, it is possible that an AWS admin has legitimately created a public bucket for a specific purpose. That said, AWS strongly advises against granting full control to the "All Users" group. - -#### Associated Analytic story -* [Suspicious AWS S3 Activities](/stories/suspicious_aws_s3_activities) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 48.0 | 60 | 80 | User $userIdentity.userName$ has created an open/public bucket $bucketName$ using AWS CLI with the following permissions - $requestParameters.accessControlList.x-amz-grant-read$ $requestParameters.accessControlList.x-amz-grant-read-acp$ $requestParameters.accessControlList.x-amz-grant-write$ $requestParameters.accessControlList.x-amz-grant-write-acp$ $requestParameters.accessControlList.x-amz-grant-full-control$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1530/aws_s3_public_bucket/aws_cloudtrail_events.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1530/aws_s3_public_bucket/aws_cloudtrail_events.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-07-19-mshta_spawning_rundll32_or_regsvr32_process.md b/docs/_posts/2021-07-19-mshta_spawning_rundll32_or_regsvr32_process.md deleted file mode 100644 index 5ce445a8c1..0000000000 --- a/docs/_posts/2021-07-19-mshta_spawning_rundll32_or_regsvr32_process.md +++ /dev/null @@ -1,172 +0,0 @@ ---- -title: "Mshta spawning Rundll32 OR Regsvr32 Process" -excerpt: "System Binary Proxy Execution -, Mshta -" -categories: - - Endpoint -last_modified_at: 2021-07-19 -toc: true -toc_label: "" -tags: - - System Binary Proxy Execution - - Mshta - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect a suspicious mshta.exe process that spawn rundll32 or regsvr32 child process. This technique was seen in several malware nowadays like trickbot to load its initial .dll stage loader to execute and download the the actual trickbot payload. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-07-19 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 4aa5d062-e893-11eb-9eb2-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218](https://attack.mitre.org/techniques/T1218/) | System Binary Proxy Execution | Defense Evasion | - -| [T1218.005](https://attack.mitre.org/techniques/T1218/005/) | Mshta | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name = "mshta.exe" `process_rundll32` OR `process_regsvr32` by Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.process_guid Processes.user Processes.dest -| `drop_dm_object_name("Processes")` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -| `mshta_spawning_rundll32_or_regsvr32_process_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [process_rundll32](https://github.com/splunk/security_content/blob/develop/macros/process_rundll32.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_regsvr32](https://github.com/splunk/security_content/blob/develop/macros/process_regsvr32.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **mshta_spawning_rundll32_or_regsvr32_process_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -limitted. this anomaly behavior is not commonly seen in clean host. - -#### Associated Analytic story -* [Trickbot](/stories/trickbot) -* [IcedID](/stories/icedid) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 56.0 | 70 | 80 | a mshta parent process $parent_process_name$ spawn child process $process_name$ in host $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://twitter.com/cyb3rops/status/1416050325870587910?s=21](https://twitter.com/cyb3rops/status/1416050325870587910?s=21) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/trickbot/spear_phish/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/trickbot/spear_phish/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-07-19-office_product_spawn_cmd_process.md b/docs/_posts/2021-07-19-office_product_spawn_cmd_process.md deleted file mode 100644 index fa75660590..0000000000 --- a/docs/_posts/2021-07-19-office_product_spawn_cmd_process.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: "Office Product Spawn CMD Process" -excerpt: "System Binary Proxy Execution -, Mshta -" -categories: - - Endpoint -last_modified_at: 2021-07-19 -toc: true -toc_label: "" -tags: - - System Binary Proxy Execution - - Mshta - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -this search is to detect a suspicious office product process that spawn cmd child process. This is commonly seen in a ms office product having macro to execute shell command to download or execute malicious lolbin relative to its malicious code. This is seen in trickbot spear phishing doc where it execute shell cmd to run mshta payload. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-07-19 -- **Author**: Teoderick Contreras, Splunk -- **ID**: b8b19420-e892-11eb-9244-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218](https://attack.mitre.org/techniques/T1218/) | System Binary Proxy Execution | Defense Evasion | - -| [T1218.005](https://attack.mitre.org/techniques/T1218/005/) | Mshta | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.parent_process_name = "winword.exe" OR Processes.parent_process_name= "excel.exe" OR Processes.parent_process_name = "powerpnt.exe") `process_cmd` by Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.process_guid Processes.user Processes.dest Processes.original_file_name -| `drop_dm_object_name("Processes")` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -| `office_product_spawn_cmd_process_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [process_cmd](https://github.com/splunk/security_content/blob/develop/macros/process_cmd.yml) - -> :information_source: -> **office_product_spawn_cmd_process_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -IT or network admin may create an document automation that will run shell script. - -#### Associated Analytic story -* [Trickbot](/stories/trickbot) -* [DarkCrystal RAT](/stories/darkcrystal_rat) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 56.0 | 70 | 80 | an office product parent process $parent_process_name$ spawn child process $process_name$ in host $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://twitter.com/cyb3rops/status/1416050325870587910?s=21](https://twitter.com/cyb3rops/status/1416050325870587910?s=21) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/trickbot/spear_phish/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/trickbot/spear_phish/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/office_product_spawn_cmd_process.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-07-20-detect_shared_ec2_snapshot.md b/docs/_posts/2021-07-20-detect_shared_ec2_snapshot.md deleted file mode 100644 index 257563c8b2..0000000000 --- a/docs/_posts/2021-07-20-detect_shared_ec2_snapshot.md +++ /dev/null @@ -1,165 +0,0 @@ ---- -title: "Detect shared ec2 snapshot" -excerpt: "Transfer Data to Cloud Account -" -categories: - - Cloud -last_modified_at: 2021-07-20 -toc: true -toc_label: "" -tags: - - Transfer Data to Cloud Account - - Exfiltration - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes AWS CloudTrail events to identify when an EC2 snapshot permissions are modified to be shared with a different AWS account. This method is used by adversaries to exfiltrate the EC2 snapshot. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-07-20 -- **Author**: Bhavin Patel, Splunk -- **ID**: 2a9b80d3-6340-4345-b5ad-290bf3d222c4 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1537](https://attack.mitre.org/techniques/T1537/) | Transfer Data to Cloud Account | Exfiltration | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.DS -* PR.AC -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 13 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cloudtrail` eventName=ModifySnapshotAttribute -| rename requestParameters.createVolumePermission.add.items{}.userId as requested_account_id -| search requested_account_id != NULL -| eval match=if(requested_account_id==aws_account_id,"Match","No Match") -| table _time user_arn src_ip requestParameters.attributeType requested_account_id aws_account_id match vendor_region user_agent -| where match = "No Match" -| `detect_shared_ec2_snapshot_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) - -> :information_source: -> **detect_shared_ec2_snapshot_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* eventName -* user_arn -* src_ip -* requestParameters.attributeType -* aws_account_id -* vendor_region -* user_agent - - -#### How To Implement -You must install splunk AWS add on and Splunk App for AWS. This search works with AWS CloudTrail logs. - -#### Known False Positives -It is possible that an AWS admin has legitimately shared a snapshot with others for a specific purpose. - -#### Associated Analytic story -* [Suspicious Cloud Instance Activities](/stories/suspicious_cloud_instance_activities) -* [Data Exfiltration](/stories/data_exfiltration) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 48.0 | 60 | 80 | AWS EC2 snapshot from account $aws_account_id$ is shared with $requested_account_id$ by user $user_arn$ from $src_ip$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://labs.nettitude.com/blog/how-to-exfiltrate-aws-ec2-data/](https://labs.nettitude.com/blog/how-to-exfiltrate-aws-ec2-data/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1537/aws_snapshot_exfil/aws_cloudtrail_events.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1537/aws_snapshot_exfil/aws_cloudtrail_events.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/detect_shared_ec2_snapshot.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-07-21-detect_copy_of_shadowcopy_with_script_block_logging.md b/docs/_posts/2021-07-21-detect_copy_of_shadowcopy_with_script_block_logging.md deleted file mode 100644 index ba50bfd6fb..0000000000 --- a/docs/_posts/2021-07-21-detect_copy_of_shadowcopy_with_script_block_logging.md +++ /dev/null @@ -1,169 +0,0 @@ ---- -title: "Detect Copy of ShadowCopy with Script Block Logging" -excerpt: "Security Account Manager -, OS Credential Dumping -" -categories: - - Endpoint -last_modified_at: 2021-07-21 -toc: true -toc_label: "" -tags: - - Security Account Manager - - OS Credential Dumping - - Credential Access - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2021-36934 ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify suspicious PowerShell execution. Script Block Logging captures the command sent to PowerShell, the full command to be executed. Upon enabling, logs will output to Windows event logs. Dependent upon volume, enable on critical endpoints or all. \ -This analytic identifies `copy` or `[System.IO.File]::Copy` being used to capture the SAM, SYSTEM or SECURITY hives identified in script block. This will catch the most basic use cases for credentials being taken for offline cracking. \ -During triage, review parallel processes using an EDR product or 4688 events. It will be important to understand the timeline of events around this activity. Review the entire logged PowerShell script block. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-07-21 -- **Author**: Michael Haag, Splunk -- **ID**: 9251299c-ea5b-11eb-a8de-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1003.002](https://attack.mitre.org/techniques/T1003/002/) | Security Account Manager | Credential Access | - -| [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2021-36934](https://nvd.nist.gov/vuln/detail/CVE-2021-36934) | Windows Elevation of Privilege Vulnerability | 4.6 | - - - -
-
- -#### Search - -``` -`powershell` EventCode=4104 Message IN ("*copy*","*[System.IO.File]::Copy*") AND Message IN ("*System32\\config\\SAM*", "*System32\\config\\SYSTEM*","*System32\\config\\SECURITY*") -| stats count min(_time) as firstTime max(_time) as lastTime by OpCode ComputerName User EventCode Message -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_copy_of_shadowcopy_with_script_block_logging_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **detect_copy_of_shadowcopy_with_script_block_logging_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Message -* OpCode -* ComputerName -* User -* EventCode - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -Limited false positives as the scope is limited to SAM, SYSTEM and SECURITY hives. - -#### Associated Analytic story -* [Credential Dumping](/stories/credential_dumping) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | PowerShell was identified running a script to capture the SAM hive on endpoint $ComputerName$ by user $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36934](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36934) -* [https://github.com/GossiTheDog/HiveNightmare](https://github.com/GossiTheDog/HiveNightmare) -* [https://github.com/JumpsecLabs/Guidance-Advice/tree/main/SAM_Permissions](https://github.com/JumpsecLabs/Guidance-Advice/tree/main/SAM_Permissions) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.002/serioussam/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.002/serioussam/windows-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-07-23-sam_database_file_access_attempt.md b/docs/_posts/2021-07-23-sam_database_file_access_attempt.md deleted file mode 100644 index d9c2d32959..0000000000 --- a/docs/_posts/2021-07-23-sam_database_file_access_attempt.md +++ /dev/null @@ -1,164 +0,0 @@ ---- -title: "SAM Database File Access Attempt" -excerpt: "Security Account Manager -, OS Credential Dumping -" -categories: - - Endpoint -last_modified_at: 2021-07-23 -toc: true -toc_label: "" -tags: - - Security Account Manager - - OS Credential Dumping - - Credential Access - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2021-36934 - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies access to SAM, SYSTEM or SECURITY databases' within the file path of `windows\system32\config` using Windows Security EventCode 4663. This particular behavior is related to credential access, an attempt to either use a Shadow Copy or recent CVE-2021-36934 to access the SAM database. The Security Account Manager (SAM) is a database file in Windows XP, Windows Vista, Windows 7, 8.1 and 10 that stores users' passwords. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-07-23 -- **Author**: Michael Haag, Mauricio Velazco, Splunk -- **ID**: 57551656-ebdb-11eb-afdf-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1003.002](https://attack.mitre.org/techniques/T1003/002/) | Security Account Manager | Credential Access | - -| [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2021-36934](https://nvd.nist.gov/vuln/detail/CVE-2021-36934) | Windows Elevation of Privilege Vulnerability | 4.6 | - - - -
-
- -#### Search - -``` -`wineventlog_security` (EventCode=4663) process_name!=*\\dllhost.exe Object_Name IN ("*\\Windows\\System32\\config\\SAM*","*\\Windows\\System32\\config\\SYSTEM*","*\\Windows\\System32\\config\\SECURITY*") -| stats values(Accesses) count by process_name Object_Name dest user -| `sam_database_file_access_attempt_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) - -> :information_source: -> **sam_database_file_access_attempt_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* process_name -* Object_Name -* dest -* user - - -#### How To Implement -To successfully implement this search, you must ingest Windows Security Event logs and track event code 4663. For 4663, enable "Audit Object Access" in Group Policy. Then check the two boxes listed for both "Success" and "Failure." - -#### Known False Positives -Natively, `dllhost.exe` will access the files. Every environment will have additional native processes that do as well. Filter by process_name. As an aside, one can remove process_name entirely and add `Object_Name=*ShadowCopy*`. - -#### Associated Analytic story -* [Credential Dumping](/stories/credential_dumping) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | The following process $process_name$ accessed the object $Object_Name$ attempting to gain access to credentials on $dest$ by user $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=4663](https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=4663) -* [https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4663](https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4663) -* [https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36934](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36934) -* [https://github.com/GossiTheDog/HiveNightmare](https://github.com/GossiTheDog/HiveNightmare) -* [https://github.com/JumpsecLabs/Guidance-Advice/tree/main/SAM_Permissions](https://github.com/JumpsecLabs/Guidance-Advice/tree/main/SAM_Permissions) -* [https://en.wikipedia.org/wiki/Security_Account_Manager](https://en.wikipedia.org/wiki/Security_Account_Manager) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/sam_database_file_access_attempt.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-07-26-rundll32_createremotethread_in_browser.md b/docs/_posts/2021-07-26-rundll32_createremotethread_in_browser.md deleted file mode 100644 index 7ee60a9e83..0000000000 --- a/docs/_posts/2021-07-26-rundll32_createremotethread_in_browser.md +++ /dev/null @@ -1,160 +0,0 @@ ---- -title: "Rundll32 CreateRemoteThread In Browser" -excerpt: "Process Injection -" -categories: - - Endpoint -last_modified_at: 2021-07-26 -toc: true -toc_label: "" -tags: - - Process Injection - - Defense Evasion - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic identifies the suspicious Remote Thread execution of rundll32.exe process to "firefox.exe" and "chrome.exe" browser. This technique was seen in IcedID malware where it hooks the browser to parse banking information as user used the targetted browser process. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-07-26 -- **Author**: Teoderick Contreras, Splunk -- **ID**: f8a22586-ee2d-11eb-a193-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1055](https://attack.mitre.org/techniques/T1055/) | Process Injection | Defense Evasion, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventCode=8 SourceImage = "*\\rundll32.exe" TargetImage IN ("*\\firefox.exe", "*\\chrome.exe", "*\\iexplore.exe","*\\microsoftedgecp.exe") -| stats count min(_time) as firstTime max(_time) as lastTime by SourceImage TargetImage TargetProcessId SourceProcessId StartAddress EventCode Computer -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `rundll32_createremotethread_in_browser_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **rundll32_createremotethread_in_browser_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* SourceImage -* TargetImage -* TargetProcessId -* SourceProcessId -* StartAddress -* EventCode -* Computer - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the SourceImage, TargetImage, and EventCode executions from your endpoints related to create remote thread or injecting codes. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [IcedID](/stories/icedid) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 70.0 | 70 | 100 | rundl32 process $SourceImage$ create a remote thread to browser process $TargetImage$ in host $Computer$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.joesandbox.com/analysis/380662/0/html](https://www.joesandbox.com/analysis/380662/0/html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/inf_icedid/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/inf_icedid/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-07-26-rundll32_process_creating_exe_dll_files.md b/docs/_posts/2021-07-26-rundll32_process_creating_exe_dll_files.md deleted file mode 100644 index 2fee621286..0000000000 --- a/docs/_posts/2021-07-26-rundll32_process_creating_exe_dll_files.md +++ /dev/null @@ -1,162 +0,0 @@ ---- -title: "Rundll32 Process Creating Exe Dll Files" -excerpt: "System Binary Proxy Execution -, Rundll32 -" -categories: - - Endpoint -last_modified_at: 2021-07-26 -toc: true -toc_label: "" -tags: - - System Binary Proxy Execution - - Rundll32 - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect a suspicious rundll32 process that drops executable (.exe or .dll) files. this behavior seen in rundll32 process of IcedID that tries to drop copy of itself in temp folder or download executable drop it either appdata or programdata as part of its execution. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-07-26 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 6338266a-ee2a-11eb-bf68-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218](https://attack.mitre.org/techniques/T1218/) | System Binary Proxy Execution | Defense Evasion | - -| [T1218.011](https://attack.mitre.org/techniques/T1218/011/) | Rundll32 | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventCode=11 process_name="rundll32.exe" TargetFilename IN ("*.exe", "*.dll",) -| stats count min(_time) as firstTime max(_time) as lastTime by Image TargetFilename ProcessGuid dest user_id -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `rundll32_process_creating_exe_dll_files_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **rundll32_process_creating_exe_dll_files_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Image -* TargetFilename -* ProcessGuid -* dest -* user_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, TargetFilename, and eventcode 11 executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed rundll32.exe may be used. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [IcedID](/stories/icedid) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | rundll32 process $process_name$ drops a file $TargetFilename$ in host $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://any.run/malware-trends/icedid](https://any.run/malware-trends/icedid) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/inf_icedid/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/inf_icedid/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-07-26-suspicious_icedid_rundll32_cmdline.md b/docs/_posts/2021-07-26-suspicious_icedid_rundll32_cmdline.md deleted file mode 100644 index fa9fa4b335..0000000000 --- a/docs/_posts/2021-07-26-suspicious_icedid_rundll32_cmdline.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: "Suspicious IcedID Rundll32 Cmdline" -excerpt: "System Binary Proxy Execution -, Rundll32 -" -categories: - - Endpoint -last_modified_at: 2021-07-26 -toc: true -toc_label: "" -tags: - - System Binary Proxy Execution - - Rundll32 - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect a suspicious rundll32.exe commandline to execute dll file. This technique was seen in IcedID malware to load its payload dll with the following parameter to load encrypted dll payload which is the license.dat. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-07-26 -- **Author**: Teoderick Contreras, Splunk -- **ID**: bed761f8-ee29-11eb-8bf3-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218](https://attack.mitre.org/techniques/T1218/) | System Binary Proxy Execution | Defense Evasion | - -| [T1218.011](https://attack.mitre.org/techniques/T1218/011/) | Rundll32 | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_rundll32` Processes.process=*/i:* by Processes.process_name Processes.process Processes.parent_process_name Processes.parent_process Processes.process_id Processes.parent_process_id Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `suspicious_icedid_rundll32_cmdline_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [process_rundll32](https://github.com/splunk/security_content/blob/develop/macros/process_rundll32.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **suspicious_icedid_rundll32_cmdline_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -limitted. this parameter is not commonly used by windows application but can be used by the network operator. - -#### Associated Analytic story -* [IcedID](/stories/icedid) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 56.0 | 70 | 80 | rundll32 process $process_name$ with commandline $process$ in host $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://threatpost.com/icedid-banking-trojan-surges-emotet/165314/](https://threatpost.com/icedid-banking-trojan-surges-emotet/165314/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/inf_icedid/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/inf_icedid/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-07-26-suspicious_rundll32_plugininit.md b/docs/_posts/2021-07-26-suspicious_rundll32_plugininit.md deleted file mode 100644 index 14846a2e0e..0000000000 --- a/docs/_posts/2021-07-26-suspicious_rundll32_plugininit.md +++ /dev/null @@ -1,169 +0,0 @@ ---- -title: "Suspicious Rundll32 PluginInit" -excerpt: "System Binary Proxy Execution -, Rundll32 -" -categories: - - Endpoint -last_modified_at: 2021-07-26 -toc: true -toc_label: "" -tags: - - System Binary Proxy Execution - - Rundll32 - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect a suspicious rundll32.exe process with plugininit parameter. This technique is commonly seen in IceID malware to execute its initial dll stager to download another payload to the compromised machine. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-07-26 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 92d51712-ee29-11eb-b1ae-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218](https://attack.mitre.org/techniques/T1218/) | System Binary Proxy Execution | Defense Evasion | - -| [T1218.011](https://attack.mitre.org/techniques/T1218/011/) | Rundll32 | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_rundll32` Processes.process=*PluginInit* by Processes.process_name Processes.process Processes.parent_process_name Processes.original_file_name Processes.parent_process Processes.process_id Processes.parent_process_id Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `suspicious_rundll32_plugininit_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [process_rundll32](https://github.com/splunk/security_content/blob/develop/macros/process_rundll32.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **suspicious_rundll32_plugininit_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -third party application may used this dll export name to execute function. - -#### Associated Analytic story -* [IcedID](/stories/icedid) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 42.0 | 60 | 70 | rundll32 process $process_name$ with commandline $process$ in host $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://threatpost.com/icedid-banking-trojan-surges-emotet/165314/](https://threatpost.com/icedid-banking-trojan-surges-emotet/165314/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/inf_icedid/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/inf_icedid/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/suspicious_rundll32_plugininit.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-07-27-chcp_command_execution.md b/docs/_posts/2021-07-27-chcp_command_execution.md deleted file mode 100644 index 247e12d47f..0000000000 --- a/docs/_posts/2021-07-27-chcp_command_execution.md +++ /dev/null @@ -1,162 +0,0 @@ ---- -title: "CHCP Command Execution" -excerpt: "Command and Scripting Interpreter -" -categories: - - Endpoint -last_modified_at: 2021-07-27 -toc: true -toc_label: "" -tags: - - Command and Scripting Interpreter - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect execution of chcp.exe application. this utility is used to change the active code page of the console. This technique was seen in icedid malware to know the locale region/language/country of the compromise host. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-07-27 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 21d236ec-eec1-11eb-b23e-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=chcp.com Processes.parent_process_name = cmd.exe Processes.parent_process=*/c* by Processes.process_name Processes.process Processes.parent_process_name Processes.parent_process Processes.process_id Processes.parent_process_id Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `chcp_command_execution_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **chcp_command_execution_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* process_name -* process -* parent_process_name -* parent_process -* process_id -* parent_process_id -* dest -* user - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed chcp.com may be used. - -#### Known False Positives -other tools or script may used this to change code page to UTF-* or others - -#### Associated Analytic story -* [IcedID](/stories/icedid) -* [Azorult](/stories/azorult) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 9.0 | 30 | 30 | parent process $parent_process_name$ spawning chcp process $process_name$ with parent command line $parent_process$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://ss64.com/nt/chcp.html](https://ss64.com/nt/chcp.html) -* [https://twitter.com/tccontre18/status/1419941156633329665?s=20](https://twitter.com/tccontre18/status/1419941156633329665?s=20) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/simulated_icedid/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/simulated_icedid/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/chcp_command_execution.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-07-27-regsvr32_with_known_silent_switch_cmdline.md b/docs/_posts/2021-07-27-regsvr32_with_known_silent_switch_cmdline.md deleted file mode 100644 index a70a85e8c3..0000000000 --- a/docs/_posts/2021-07-27-regsvr32_with_known_silent_switch_cmdline.md +++ /dev/null @@ -1,175 +0,0 @@ ---- -title: "Regsvr32 with Known Silent Switch Cmdline" -excerpt: "System Binary Proxy Execution -, Regsvr32 -" -categories: - - Endpoint -last_modified_at: 2021-07-27 -toc: true -toc_label: "" -tags: - - System Binary Proxy Execution - - Regsvr32 - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies Regsvr32.exe utilizing the silent switch to load DLLs. This technique has most recently been seen in IcedID campaigns to load its initial dll that will download the 2nd stage loader that will download and decrypt the config payload. The switch type may be either a hyphen `-` or forward slash `/`. This behavior is typically found with `-s`, and it is possible there are more switch types that may be used. \ During triage, review parallel processes and capture any artifacts that may have landed on disk. Isolate and contain the endpoint as necessary. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-07-27 -- **Author**: Teoderick Contreras, Splunk -- **ID**: c9ef7dc4-eeaf-11eb-b2b6-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218](https://attack.mitre.org/techniques/T1218/) | System Binary Proxy Execution | Defense Evasion | - -| [T1218.010](https://attack.mitre.org/techniques/T1218/010/) | Regsvr32 | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_regsvr32` by Processes.user Processes.process_name Processes.process Processes.parent_process_name Processes.original_file_name Processes.dest Processes.process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| where match(process,"(?i)[\- -|\/][Ss]{1}") -| `regsvr32_with_known_silent_switch_cmdline_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [process_regsvr32](https://github.com/splunk/security_content/blob/develop/macros/process_regsvr32.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **regsvr32_with_known_silent_switch_cmdline_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -minimal. but network operator can use this application to load dll. - -#### Associated Analytic story -* [IcedID](/stories/icedid) -* [Suspicious Regsvr32 Activity](/stories/suspicious_regsvr32_activity) -* [Remcos](/stories/remcos) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 56.0 | 70 | 80 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to load a DLL using the silent parameter. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://app.any.run/tasks/56680cba-2bbc-4b34-8633-5f7878ddf858/](https://app.any.run/tasks/56680cba-2bbc-4b34-8633-5f7878ddf858/) -* [https://regexr.com/699e2](https://regexr.com/699e2) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/inf_icedid/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/inf_icedid/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/regsvr32_with_known_silent_switch_cmdline.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-07-29-rundll32_create_remote_thread_to_a_process.md b/docs/_posts/2021-07-29-rundll32_create_remote_thread_to_a_process.md deleted file mode 100644 index fdf4ec8c06..0000000000 --- a/docs/_posts/2021-07-29-rundll32_create_remote_thread_to_a_process.md +++ /dev/null @@ -1,160 +0,0 @@ ---- -title: "Rundll32 Create Remote Thread To A Process" -excerpt: "Process Injection -" -categories: - - Endpoint -last_modified_at: 2021-07-29 -toc: true -toc_label: "" -tags: - - Process Injection - - Defense Evasion - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic identifies the suspicious Remote Thread execution of rundll32.exe process to cmd.exe process. This technique was seen in IcedID malware to execute its malicious code in normal process for defense evasion and to steal sensitive information the the compromised host. browser process. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-07-29 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 2dbeee3a-f067-11eb-96c0-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1055](https://attack.mitre.org/techniques/T1055/) | Process Injection | Defense Evasion, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventCode=8 SourceImage = "*\\rundll32.exe" TargetImage = "*.exe" -| stats count min(_time) as firstTime max(_time) as lastTime by SourceImage TargetImage TargetProcessId SourceProcessId StartAddress EventCode Computer -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `rundll32_create_remote_thread_to_a_process_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **rundll32_create_remote_thread_to_a_process_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* SourceImage -* TargetImage -* TargetProcessId -* SourceProcessId -* StartAddress -* EventCode -* Computer - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the SourceImage, TargetImage, and EventCode executions from your endpoints related to create remote thread or injecting codes. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [IcedID](/stories/icedid) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 56.0 | 70 | 80 | rundl32 process $SourceImage$ create a remote thread to process $TargetImage$ in host $Computer$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.joesandbox.com/analysis/380662/0/html](https://www.joesandbox.com/analysis/380662/0/html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/inf_icedid/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/inf_icedid/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-07-30-drop_icedid_license_dat.md b/docs/_posts/2021-07-30-drop_icedid_license_dat.md deleted file mode 100644 index 77dd7cbdcb..0000000000 --- a/docs/_posts/2021-07-30-drop_icedid_license_dat.md +++ /dev/null @@ -1,156 +0,0 @@ ---- -title: "Drop IcedID License dat" -excerpt: "User Execution -, Malicious File -" -categories: - - Endpoint -last_modified_at: 2021-07-30 -toc: true -toc_label: "" -tags: - - User Execution - - Malicious File - - Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect dropping a suspicious file named as "license.dat" in %appdata%. This behavior seen in latest IcedID malware that contain the actual core bot that will be injected in other process to do banking stealing. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-07-30 -- **Author**: Teoderick Contreras, Splunk -- **ID**: b7a045fc-f14a-11eb-8e79-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1204](https://attack.mitre.org/techniques/T1204/) | User Execution | Execution | - -| [T1204.002](https://attack.mitre.org/techniques/T1204/002/) | Malicious File | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventCode= 11 TargetFilename = "*\\license.dat" AND (TargetFilename="*\\appdata\\*" OR TargetFilename="*\\programdata\\*") -|stats count min(_time) as firstTime max(_time) as lastTime by TargetFilename EventCode process_id process_name Computer -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `drop_icedid_license_dat_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **drop_icedid_license_dat_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [IcedID](/stories/icedid) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 63.0 | 70 | 90 | process $SourceImage$ create a file $TargetImage$ in host $Computer$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.cisecurity.org/insights/white-papers/security-primer-icedid](https://www.cisecurity.org/insights/white-papers/security-primer-icedid) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/simulated_icedid/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/simulated_icedid/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/drop_icedid_license_dat.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-07-30-icedid_exfiltrated_archived_file_creation.md b/docs/_posts/2021-07-30-icedid_exfiltrated_archived_file_creation.md deleted file mode 100644 index 785cda45b1..0000000000 --- a/docs/_posts/2021-07-30-icedid_exfiltrated_archived_file_creation.md +++ /dev/null @@ -1,161 +0,0 @@ ---- -title: "IcedID Exfiltrated Archived File Creation" -excerpt: "Archive via Utility -, Archive Collected Data -" -categories: - - Endpoint -last_modified_at: 2021-07-30 -toc: true -toc_label: "" -tags: - - Archive via Utility - - Archive Collected Data - - Collection - - Collection - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect a suspicious file creation namely passff.tar and cookie.tar. This files are possible archived of stolen browser information like history and cookies in a compromised machine with IcedID. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-07-30 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 0db4da70-f14b-11eb-8043-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1560.001](https://attack.mitre.org/techniques/T1560/001/) | Archive via Utility | Collection | - -| [T1560](https://attack.mitre.org/techniques/T1560/) | Archive Collected Data | Collection | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventCode= 11 (TargetFilename = "*\\passff.tar" OR TargetFilename = "*\\cookie.tar") -|stats count min(_time) as firstTime max(_time) as lastTime by TargetFilename EventCode process_id process_name Computer -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `icedid_exfiltrated_archived_file_creation_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **icedid_exfiltrated_archived_file_creation_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* TargetFilename -* EventCode -* process_id -* process_name -* Computer - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [IcedID](/stories/icedid) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 72.0 | 80 | 90 | process $SourceImage$ create a file $TargetImage$ in host $Computer$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.cisecurity.org/insights/white-papers/security-primer-icedid](https://www.cisecurity.org/insights/white-papers/security-primer-icedid) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/simulated_icedid/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/simulated_icedid/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-07-30-office_application_spawn_regsvr32_process.md b/docs/_posts/2021-07-30-office_application_spawn_regsvr32_process.md deleted file mode 100644 index d478b8a1dc..0000000000 --- a/docs/_posts/2021-07-30-office_application_spawn_regsvr32_process.md +++ /dev/null @@ -1,169 +0,0 @@ ---- -title: "Office Application Spawn Regsvr32 process" -excerpt: "Phishing -, Spearphishing Attachment -" -categories: - - Endpoint -last_modified_at: 2021-07-30 -toc: true -toc_label: "" -tags: - - Phishing - - Spearphishing Attachment - - Initial Access - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -this detection was designed to identifies suspicious spawned process of known MS office application due to macro or malicious code. this technique can be seen in so many malware like IcedID that used MS office as its weapon or attack vector to initially infect the machines. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-07-30 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 2d9fc90c-f11f-11eb-9300-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | - -| [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.parent_process_name = "winword.exe" OR Processes.parent_process_name = "excel.exe" OR Processes.parent_process_name = "powerpnt.exe" OR Processes.parent_process_name = "outlook.exe") `process_regsvr32` by Processes.parent_process_name Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.process_guid Processes.user Processes.dest -| `drop_dm_object_name("Processes")` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -| `office_application_spawn_regsvr32_process_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [process_regsvr32](https://github.com/splunk/security_content/blob/develop/macros/process_regsvr32.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **office_application_spawn_regsvr32_process_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [IcedID](/stories/icedid) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 63.0 | 70 | 90 | Office application spawning regsvr32.exe on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.joesandbox.com/analysis/380662/0/html](https://www.joesandbox.com/analysis/380662/0/html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/phish_icedid/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/phish_icedid/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-08-03-sqlite_module_in_temp_folder.md b/docs/_posts/2021-08-03-sqlite_module_in_temp_folder.md deleted file mode 100644 index ce3d5c295e..0000000000 --- a/docs/_posts/2021-08-03-sqlite_module_in_temp_folder.md +++ /dev/null @@ -1,156 +0,0 @@ ---- -title: "Sqlite Module In Temp Folder" -excerpt: "Data from Local System -" -categories: - - Endpoint -last_modified_at: 2021-08-03 -toc: true -toc_label: "" -tags: - - Data from Local System - - Collection - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect a suspicious file creation of sqlite3.dll in %temp% folder. This behavior was seen in IcedID malware where it download sqlite module to parse browser database like for chrome or firefox to stole browser information related to bank, credit card or credentials. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-08-03 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 0f216a38-f45f-11eb-b09c-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1005](https://attack.mitre.org/techniques/T1005/) | Data from Local System | Collection | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventCode=11 (TargetFilename = "*\\sqlite32.dll" OR TargetFilename = "*\\sqlite64.dll") (TargetFilename = "*\\temp\\*") -|stats count min(_time) as firstTime max(_time) as lastTime by process_name TargetFilename EventCode ProcessId Image -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `sqlite_module_in_temp_folder_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **sqlite_module_in_temp_folder_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* process_name -* TargetFilename -* EventCode -* ProcessId -* Image - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [IcedID](/stories/icedid) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 9.0 | 30 | 30 | process $SourceImage$ create a file $TargetImage$ in host $Computer$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.cisecurity.org/insights/white-papers/security-primer-icedid](https://www.cisecurity.org/insights/white-papers/security-primer-icedid) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/simulated_icedid/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/simulated_icedid/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/sqlite_module_in_temp_folder.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-04-create_remote_thread_in_shell_application.md b/docs/_posts/2021-08-04-create_remote_thread_in_shell_application.md deleted file mode 100644 index bf0db94672..0000000000 --- a/docs/_posts/2021-08-04-create_remote_thread_in_shell_application.md +++ /dev/null @@ -1,159 +0,0 @@ ---- -title: "Create Remote Thread In Shell Application" -excerpt: "Process Injection -" -categories: - - Endpoint -last_modified_at: 2021-08-04 -toc: true -toc_label: "" -tags: - - Process Injection - - Defense Evasion - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect suspicious process injection in command shell. This technique was seen in IcedID where it execute cmd.exe process to inject its shellcode as part of its execution as banking trojan. It is really uncommon to have a create remote thread execution in the following application. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-08-04 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 10399c1e-f51e-11eb-b920-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1055](https://attack.mitre.org/techniques/T1055/) | Process Injection | Defense Evasion, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventCode=8 TargetImage IN ("*\\cmd.exe", "*\\powershell*") -| stats count min(_time) as firstTime max(_time) as lastTime by TargetImage TargetProcessId SourceProcessId EventCode StartAddress SourceImage Computer -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `create_remote_thread_in_shell_application_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **create_remote_thread_in_shell_application_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* SourceImage -* TargetImage -* TargetProcessId -* SourceProcessId -* StartAddress -* EventCode -* Computer - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [IcedID](/stories/icedid) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 70.0 | 70 | 100 | process $SourceImage$ create a remote thread to shell app process $TargetImage$ in host $Computer$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://thedfirreport.com/2021/07/19/icedid-and-cobalt-strike-vs-antivirus/](https://thedfirreport.com/2021/07/19/icedid-and-cobalt-strike-vs-antivirus/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/simulated_icedid/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/simulated_icedid/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/create_remote_thread_in_shell_application.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-09-rundll32_lockworkstation.md b/docs/_posts/2021-08-09-rundll32_lockworkstation.md deleted file mode 100644 index 5058d1066c..0000000000 --- a/docs/_posts/2021-08-09-rundll32_lockworkstation.md +++ /dev/null @@ -1,165 +0,0 @@ ---- -title: "Rundll32 LockWorkStation" -excerpt: "System Binary Proxy Execution -, Rundll32 -" -categories: - - Endpoint -last_modified_at: 2021-08-09 -toc: true -toc_label: "" -tags: - - System Binary Proxy Execution - - Rundll32 - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect a suspicious rundll32 commandline to lock the workstation through command line. This technique was seen in CONTI leak tooling and script as part of its defense evasion. This technique is not a common practice to lock a screen and maybe a good indicator of compromise. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-08-09 -- **Author**: Teoderick Contreras, Splunk -- **ID**: fa90f372-f91d-11eb-816c-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218](https://attack.mitre.org/techniques/T1218/) | System Binary Proxy Execution | Defense Evasion | - -| [T1218.011](https://attack.mitre.org/techniques/T1218/011/) | Rundll32 | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=rundll32.exe Processes.process= "*user32.dll,LockWorkStation*" by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `rundll32_lockworkstation_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **rundll32_lockworkstation_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process -* Processes.parent_process_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed rundll32.exe may be used. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Ransomware](/stories/ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | process $process_name$ with cmdline $process$ in host $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://threadreaderapp.com/thread/1423361119926816776.html](https://threadreaderapp.com/thread/1423361119926816776.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/conti/conti_leak/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/conti/conti_leak/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/rundll32_lockworkstation.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-08-09-uninstall_app_using_msiexec.md b/docs/_posts/2021-08-09-uninstall_app_using_msiexec.md deleted file mode 100644 index 9da25e52ad..0000000000 --- a/docs/_posts/2021-08-09-uninstall_app_using_msiexec.md +++ /dev/null @@ -1,165 +0,0 @@ ---- -title: "Uninstall App Using MsiExec" -excerpt: "Msiexec -, System Binary Proxy Execution -" -categories: - - Endpoint -last_modified_at: 2021-08-09 -toc: true -toc_label: "" -tags: - - Msiexec - - System Binary Proxy Execution - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect a suspicious un-installation of application using msiexec. This technique was seen in conti leak tool and script where it tries to uninstall AV product using this commandline. This commandline to uninstall product is not a common practice in enterprise network. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-08-09 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 1fca2b28-f922-11eb-b2dd-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218.007](https://attack.mitre.org/techniques/T1218/007/) | Msiexec | Defense Evasion | - -| [T1218](https://attack.mitre.org/techniques/T1218/) | System Binary Proxy Execution | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=msiexec.exe Processes.process= "* /qn *" Processes.process= "*/X*" Processes.process= "*REBOOT=*" by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `uninstall_app_using_msiexec_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **uninstall_app_using_msiexec_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process -* Processes.parent_process_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -unknown. - -#### Associated Analytic story -* [Ransomware](/stories/ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 30.0 | 50 | 60 | process $process_name$ with a cmdline $process$ in host $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://threadreaderapp.com/thread/1423361119926816776.html](https://threadreaderapp.com/thread/1423361119926816776.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/conti/conti_leak/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/conti/conti_leak/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/uninstall_app_using_msiexec.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-10-powershell_execute_com_object.md b/docs/_posts/2021-08-10-powershell_execute_com_object.md deleted file mode 100644 index 58528eb6fd..0000000000 --- a/docs/_posts/2021-08-10-powershell_execute_com_object.md +++ /dev/null @@ -1,156 +0,0 @@ ---- -title: "Powershell Execute COM Object" -excerpt: "Component Object Model Hijacking -, Event Triggered Execution -" -categories: - - Endpoint -last_modified_at: 2021-08-10 -toc: true -toc_label: "" -tags: - - Component Object Model Hijacking - - Event Triggered Execution - - Persistence - - Privilege Escalation - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect a COM CLSID execution through powershell. This technique was seen in several adversaries and malware like ransomware conti where it has a feature to execute command using COM Object. This technique may use by network operator at some cases but a good indicator if some application want to gain privilege escalation or bypass uac. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-08-10 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 65711630-f9bf-11eb-8d72-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1546.015](https://attack.mitre.org/techniques/T1546/015/) | Component Object Model Hijacking | Persistence, Privilege Escalation | - -| [T1546](https://attack.mitre.org/techniques/T1546/) | Event Triggered Execution | Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 Message = "*CreateInstance([type]::GetTypeFromCLSID*" OR Message = "*CreateInstance([Type]::GetTypeFromProgID*" -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `powershell_execute_com_object_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -Note that **powershell_execute_com_object_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -network operrator may use this command. - -#### Associated Analytic story -* [Hermetic Wiper](/stories/hermetic_wiper) -* [Malicious PowerShell](/stories/malicious_powershell) -* [Ransomware](/stories/ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 5.0 | 10 | 50 | A suspicious powershell script contains COM CLSID command in $Message$ with EventCode $EventCode$ in host $ComputerName$ | - - -#### Reference - -* [https://threadreaderapp.com/thread/1423361119926816776.html](https://threadreaderapp.com/thread/1423361119926816776.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/conti/conti_leak/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/conti/conti_leak/windows-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/powershell_execute_com_object.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-11-fsutil_zeroing_file.md b/docs/_posts/2021-08-11-fsutil_zeroing_file.md deleted file mode 100644 index d250310e6a..0000000000 --- a/docs/_posts/2021-08-11-fsutil_zeroing_file.md +++ /dev/null @@ -1,158 +0,0 @@ ---- -title: "Fsutil Zeroing File" -excerpt: "Indicator Removal on Host -" -categories: - - Endpoint -last_modified_at: 2021-08-11 -toc: true -toc_label: "" -tags: - - Indicator Removal on Host - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect a suspicious fsutil process to zeroing a target file. This technique was seen in lockbit ransomware where it tries to zero out its malware path as part of its defense evasion after encrypting the compromised host. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-08-11 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 4e5e024e-fabb-11eb-8b8f-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1070](https://attack.mitre.org/techniques/T1070/) | Indicator Removal on Host | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count values(Processes.process) as process values(Processes.parent_process) as parent_process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=fsutil.exe Processes.process="*setzerodata*" by Processes.user Processes.process_name Processes.parent_process_name Processes.dest Processes.process Processes.parent_process -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `fsutil_zeroing_file_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **fsutil_zeroing_file_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.user -* Processes.process_name -* Processes.parent_process_name -* Processes.dest -* Processes.process -* Processes.parent_process - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Ransomware](/stories/ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 54.0 | 60 | 90 | Possible file data deletion on $dest$ using $process$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://app.any.run/tasks/e0ac072d-58c9-4f53-8a3b-3e491c7ac5db/](https://app.any.run/tasks/e0ac072d-58c9-4f53-8a3b-3e491c7ac5db/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070/fsutil_file_zero/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070/fsutil_file_zero/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/fsutil_zeroing_file.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-13-uac_bypass_with_colorui_com_object.md b/docs/_posts/2021-08-13-uac_bypass_with_colorui_com_object.md deleted file mode 100644 index 65a9387f53..0000000000 --- a/docs/_posts/2021-08-13-uac_bypass_with_colorui_com_object.md +++ /dev/null @@ -1,163 +0,0 @@ ---- -title: "UAC Bypass With Colorui COM Object" -excerpt: "System Binary Proxy Execution -, CMSTP -" -categories: - - Endpoint -last_modified_at: 2021-08-13 -toc: true -toc_label: "" -tags: - - System Binary Proxy Execution - - CMSTP - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect a possible uac bypass using the colorui.dll COM Object. this technique was seen in so many malware and ransomware like lockbit where it make use of the colorui.dll COM CLSID to bypass UAC. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-08-13 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 2bcccd20-fc2b-11eb-8d22-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218](https://attack.mitre.org/techniques/T1218/) | System Binary Proxy Execution | Defense Evasion | - -| [T1218.003](https://attack.mitre.org/techniques/T1218/003/) | CMSTP | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventCode=7 ImageLoaded="*\\colorui.dll" process_name != "colorcpl.exe" NOT(Image IN("*\\windows\\*", "*\\program files*")) -| stats count min(_time) as firstTime max(_time) as lastTime by Image ImageLoaded process_name Computer EventCode Signed ProcessId -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `uac_bypass_with_colorui_com_object_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **uac_bypass_with_colorui_com_object_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Image -* ImageLoaded -* process_name -* Computer -* EventCode -* Signed -* ProcessId - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -not so common. but 3rd part app may load this dll. - -#### Associated Analytic story -* [Ransomware](/stories/ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 48.0 | 60 | 80 | The following module $ImageLoaded$ was loaded by a non-standard application on endpoint $Computer$ by user $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://news.sophos.com/en-us/2020/04/24/lockbit-ransomware-borrows-tricks-to-keep-up-with-revil-and-maze/](https://news.sophos.com/en-us/2020/04/24/lockbit-ransomware-borrows-tricks-to-keep-up-with-revil-and-maze/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.015/uac_colorui/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.015/uac_colorui/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-16-gsuite_drive_share_in_external_email.md b/docs/_posts/2021-08-16-gsuite_drive_share_in_external_email.md deleted file mode 100644 index 1bb1a670db..0000000000 --- a/docs/_posts/2021-08-16-gsuite_drive_share_in_external_email.md +++ /dev/null @@ -1,169 +0,0 @@ ---- -title: "Gsuite Drive Share In External Email" -excerpt: "Exfiltration to Cloud Storage -, Exfiltration Over Web Service -" -categories: - - Cloud -last_modified_at: 2021-08-16 -toc: true -toc_label: "" -tags: - - Exfiltration to Cloud Storage - - Exfiltration Over Web Service - - Exfiltration - - Exfiltration - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect suspicious google drive or google docs files shared outside or externally. This behavior might be a good hunting query to monitor exfitration of data made by an attacker or insider to a targetted machine. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-08-16 -- **Author**: Teoderick Contreras, Splunk -- **ID**: f6ee02d6-fea0-11eb-b2c2-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1567.002](https://attack.mitre.org/techniques/T1567/002/) | Exfiltration to Cloud Storage | Exfiltration | - -| [T1567](https://attack.mitre.org/techniques/T1567/) | Exfiltration Over Web Service | Exfiltration | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`gsuite_drive` NOT (email IN("", "null")) -| rex field=parameters.owner "[^@]+@(?[^@]+)" -| rex field=email "[^@]+@(?[^@]+)" -| where src_domain = "internal_test_email.com" and not dest_domain = "internal_test_email.com" -| eval phase="plan" -| eval severity="low" -| stats values(parameters.doc_title) as doc_title, values(parameters.doc_type) as doc_types, values(email) as dst_email_list, values(parameters.visibility) as visibility, values(parameters.doc_id) as doc_id, count min(_time) as firstTime max(_time) as lastTime by parameters.owner ip_address phase severity -| rename parameters.owner as user ip_address as src_ip -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `gsuite_drive_share_in_external_email_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [gsuite_drive](https://github.com/splunk/security_content/blob/develop/macros/gsuite_drive.yml) - -> :information_source: -> **gsuite_drive_share_in_external_email_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* parameters.doc_title -* src_domain -* dest_domain -* email -* parameters.visibility -* parameters.owner -* parameters.doc_type - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs related to gsuite having the file attachment metadata like file type, file extension, source email, destination email, num of attachment and etc. In order for the search to work for your environment, please edit the query to use your company specific email domain instead of `internal_test_email.com`. - -#### Known False Positives -network admin or normal user may share files to customer and external team. - -#### Associated Analytic story -* [Dev Sec Ops](/stories/dev_sec_ops) -* [Insider Threat](/stories/insider_threat) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 72.0 | 80 | 90 | suspicious share gdrive from $parameters.owner$ to $email$ namely as $parameters.doc_title$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.redhat.com/en/topics/devops/what-is-devsecops](https://www.redhat.com/en/topics/devops/what-is-devsecops) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1567.002/gsuite_share_drive/gdrive_share_external.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1567.002/gsuite_share_drive/gdrive_share_external.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/gsuite_drive_share_in_external_email.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-16-gsuite_email_suspicious_attachment.md b/docs/_posts/2021-08-16-gsuite_email_suspicious_attachment.md deleted file mode 100644 index 3c41a25ed8..0000000000 --- a/docs/_posts/2021-08-16-gsuite_email_suspicious_attachment.md +++ /dev/null @@ -1,165 +0,0 @@ ---- -title: "GSuite Email Suspicious Attachment" -excerpt: "Spearphishing Attachment -, Phishing -" -categories: - - Cloud -last_modified_at: 2021-08-16 -toc: true -toc_label: "" -tags: - - Spearphishing Attachment - - Phishing - - Initial Access - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect a suspicious attachment file extension in Gsuite email that may related to spear phishing attack. This file type is commonly used by malware to lure user to click on it to execute malicious code to compromised targetted machine. But this search can also catch some normal files related to this file type that maybe send by employee or network admin. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-08-16 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 6d663014-fe92-11eb-ab07-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | - -| [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`gsuite_gmail` "attachment{}.file_extension_type" IN ("pl", "py", "rb", "sh", "bat", "exe", "dll", "cpl", "com", "js", "vbs", "ps1", "reg","swf", "cmd", "go") -| eval phase="plan" -| eval severity="medium" -| stats count min(_time) as firstTime max(_time) as lastTime values(attachment{}.file_extension_type) as email_attachments, values(attachment{}.sha256) as attachment_sha256, values(payload_size) as payload_size by destination{}.service num_message_attachments subject destination{}.address source.address phase severity -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `gsuite_email_suspicious_attachment_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [gsuite_gmail](https://github.com/splunk/security_content/blob/develop/macros/gsuite_gmail.yml) - -> :information_source: -> **gsuite_email_suspicious_attachment_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* attachment{}.file_extension_type -* attachment{}.sha256 -* destination{}.service -* num_message_attachments -* payload_size -* subject -* destination{}.address -* source.address - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs related to gsuite having the file attachment metadata like file type, file extension, source email, destination email, num of attachment and etc. - -#### Known False Positives -network admin and normal user may send this file attachment as part of their day to day work. having a good protocol in attaching this file type to an e-mail may reduce the risk of having a spear phishing attack. - -#### Associated Analytic story -* [Dev Sec Ops](/stories/dev_sec_ops) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | suspicious email from $source.address$ to $destination{}.address$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.redhat.com/en/topics/devops/what-is-devsecops](https://www.redhat.com/en/topics/devops/what-is-devsecops) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/gsuite_susp_attachment_ext/gsuite_gmail_file_ext.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/gsuite_susp_attachment_ext/gsuite_gmail_file_ext.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/gsuite_email_suspicious_attachment.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-17-7zip_commandline_to_smb_share_path.md b/docs/_posts/2021-08-17-7zip_commandline_to_smb_share_path.md deleted file mode 100644 index e9fe2ca201..0000000000 --- a/docs/_posts/2021-08-17-7zip_commandline_to_smb_share_path.md +++ /dev/null @@ -1,165 +0,0 @@ ---- -title: "7zip CommandLine To SMB Share Path" -excerpt: "Archive via Utility -, Archive Collected Data -" -categories: - - Endpoint -last_modified_at: 2021-08-17 -toc: true -toc_label: "" -tags: - - Archive via Utility - - Archive Collected Data - - Collection - - Collection - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect a suspicious 7z process with commandline pointing to SMB network share. This technique was seen in CONTI LEAK tools where it use 7z to archive a sensitive files and place it in network share tmp folder. This search is a good hunting query that may give analyst a hint why specific user try to archive a file pointing to SMB user which is un usual. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-08-17 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 01d29b48-ff6f-11eb-b81e-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1560.001](https://attack.mitre.org/techniques/T1560/001/) | Archive via Utility | Collection | - -| [T1560](https://attack.mitre.org/techniques/T1560/) | Archive Collected Data | Collection | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name ="7z.exe" OR Processes.process_name = "7za.exe" OR Processes.original_file_name = "7z.exe" OR Processes.original_file_name = "7za.exe") AND (Processes.process="*\\C$\\*" OR Processes.process="*\\Admin$\\*" OR Processes.process="*\\IPC$\\*") by Processes.original_file_name Processes.parent_process_name Processes.parent_process Processes.process_name Processes.process Processes.parent_process_id Processes.process_id Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `7zip_commandline_to_smb_share_path_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **7zip_commandline_to_smb_share_path_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process -* Processes.parent_process_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed 7z.exe may be used. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Ransomware](/stories/ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | archive process $process_name$ with suspicious cmdline $process$ in host $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://threadreaderapp.com/thread/1423361119926816776.html](https://threadreaderapp.com/thread/1423361119926816776.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/conti/conti_leak/windows-sysmon_7z.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/conti/conti_leak/windows-sysmon_7z.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-17-aws_ecr_container_scanning_findings_high.md b/docs/_posts/2021-08-17-aws_ecr_container_scanning_findings_high.md deleted file mode 100644 index 00bccf02c8..0000000000 --- a/docs/_posts/2021-08-17-aws_ecr_container_scanning_findings_high.md +++ /dev/null @@ -1,174 +0,0 @@ ---- -title: "AWS ECR Container Scanning Findings High" -excerpt: "Malicious Image -, User Execution -" -categories: - - Cloud -last_modified_at: 2021-08-17 -toc: true -toc_label: "" -tags: - - Malicious Image - - User Execution - - Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for AWS CloudTrail events from AWS Elastic Container Service (ECR). You need to activate image scanning in order to get the event DescribeImageScanFindings with the results. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-08-17 -- **Author**: Patrick Bareiss, Splunk -- **ID**: 62721bd2-1d82-4623-b6e6-aac170014423 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1204.003](https://attack.mitre.org/techniques/T1204/003/) | Malicious Image | Execution | - -| [T1204](https://attack.mitre.org/techniques/T1204/) | User Execution | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.DS -* PR.AC -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 13 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cloudtrail` eventSource=ecr.amazonaws.com eventName=DescribeImageScanFindings -| spath path=responseElements.imageScanFindings.findings{} output=findings -| mvexpand findings -| spath input=findings -| search severity=HIGH -| rename name as finding_name, description as finding_description, requestParameters.imageId.imageDigest as imageDigest, requestParameters.repositoryName as image -| eval finding = finding_name.", ".finding_description -| eval phase="release" -| eval severity="high" -| stats min(_time) as firstTime max(_time) as lastTime by awsRegion, eventName, eventSource, imageDigest, image, user, userName, src_ip, finding, phase, severity -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `aws_ecr_container_scanning_findings_high_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) - -> :information_source: -> **aws_ecr_container_scanning_findings_high_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* eventSource -* eventName -* responseElements.imageScanFindings.findings{} -* awsRegion -* requestParameters.imageId.imageDigest -* requestParameters.repositoryName -* user -* userName -* src_ip - - -#### How To Implement -You must install splunk AWS add on and Splunk App for AWS. This search works with AWS CloudTrail logs. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Dev Sec Ops](/stories/dev_sec_ops) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 70.0 | 70 | 100 | Vulnerabilities with severity high found in image $image$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://docs.aws.amazon.com/AmazonECR/latest/userguide/image-scanning.html](https://docs.aws.amazon.com/AmazonECR/latest/userguide/image-scanning.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/aws_ecr_container_scanning_findings_high.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-17-aws_ecr_container_scanning_findings_low_informational_unknown.md b/docs/_posts/2021-08-17-aws_ecr_container_scanning_findings_low_informational_unknown.md deleted file mode 100644 index d96bb8f419..0000000000 --- a/docs/_posts/2021-08-17-aws_ecr_container_scanning_findings_low_informational_unknown.md +++ /dev/null @@ -1,174 +0,0 @@ ---- -title: "AWS ECR Container Scanning Findings Low Informational Unknown" -excerpt: "Malicious Image -, User Execution -" -categories: - - Cloud -last_modified_at: 2021-08-17 -toc: true -toc_label: "" -tags: - - Malicious Image - - User Execution - - Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for AWS CloudTrail events from AWS Elastic Container Service (ECR). You need to activate image scanning in order to get the event DescribeImageScanFindings with the results. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-08-17 -- **Author**: Patrick Bareiss, Splunk -- **ID**: cbc95e44-7c22-443f-88fd-0424478f5589 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1204.003](https://attack.mitre.org/techniques/T1204/003/) | Malicious Image | Execution | - -| [T1204](https://attack.mitre.org/techniques/T1204/) | User Execution | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.DS -* PR.AC -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 13 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cloudtrail` eventSource=ecr.amazonaws.com eventName=DescribeImageScanFindings -| spath path=responseElements.imageScanFindings.findings{} output=findings -| mvexpand findings -| spath input=findings -| search severity IN (LOW, INFORMATIONAL, UNKNWON) -| rename name as finding_name, description as finding_description, requestParameters.imageId.imageDigest as imageDigest, requestParameters.repositoryName as repositoryName -| eval finding = finding_name.", ".finding_description -| eval phase="release" -| eval severity="low" -| stats min(_time) as firstTime max(_time) as lastTime by awsRegion, eventName, eventSource, imageDigest, repositoryName, user, userName, src_ip, finding, phase, severity -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `aws_ecr_container_scanning_findings_low_informational_unknown_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) - -> :information_source: -> **aws_ecr_container_scanning_findings_low_informational_unknown_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* eventSource -* eventName -* responseElements.imageScanFindings.findings{} -* awsRegion -* requestParameters.imageId.imageDigest -* requestParameters.repositoryName -* user -* userName -* src_ip - - -#### How To Implement -You must install splunk AWS add on and Splunk App for AWS. This search works with AWS CloudTrail logs. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Dev Sec Ops](/stories/dev_sec_ops) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 7.0 | 10 | 70 | Vulnerabilities with severity high found in repository $repositoryName$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://docs.aws.amazon.com/AmazonECR/latest/userguide/image-scanning.html](https://docs.aws.amazon.com/AmazonECR/latest/userguide/image-scanning.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-17-aws_ecr_container_scanning_findings_medium.md b/docs/_posts/2021-08-17-aws_ecr_container_scanning_findings_medium.md deleted file mode 100644 index 096fcc5bea..0000000000 --- a/docs/_posts/2021-08-17-aws_ecr_container_scanning_findings_medium.md +++ /dev/null @@ -1,174 +0,0 @@ ---- -title: "AWS ECR Container Scanning Findings Medium" -excerpt: "Malicious Image -, User Execution -" -categories: - - Cloud -last_modified_at: 2021-08-17 -toc: true -toc_label: "" -tags: - - Malicious Image - - User Execution - - Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for AWS CloudTrail events from AWS Elastic Container Service (ECR). You need to activate image scanning in order to get the event DescribeImageScanFindings with the results. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-08-17 -- **Author**: Patrick Bareiss, Splunk -- **ID**: 0b80e2c8-c746-4ddb-89eb-9efd892220cf - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1204.003](https://attack.mitre.org/techniques/T1204/003/) | Malicious Image | Execution | - -| [T1204](https://attack.mitre.org/techniques/T1204/) | User Execution | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.DS -* PR.AC -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 13 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cloudtrail` eventSource=ecr.amazonaws.com eventName=DescribeImageScanFindings -| spath path=responseElements.imageScanFindings.findings{} output=findings -| mvexpand findings -| spath input=findings -| search severity=MEDIUM -| rename name as finding_name, description as finding_description, requestParameters.imageId.imageDigest as imageDigest, requestParameters.repositoryName as image -| eval finding = finding_name.", ".finding_description -| eval phase="release" -| eval severity="medium" -| stats min(_time) as firstTime max(_time) as lastTime by awsRegion, eventName, eventSource, imageDigest, image, userName, src_ip, finding, phase, severity -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `aws_ecr_container_scanning_findings_medium_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) - -> :information_source: -> **aws_ecr_container_scanning_findings_medium_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* eventSource -* eventName -* responseElements.imageScanFindings.findings{} -* awsRegion -* requestParameters.imageId.imageDigest -* requestParameters.repositoryName -* user -* userName -* src_ip - - -#### How To Implement -You must install splunk AWS add on and Splunk App for AWS. This search works with AWS CloudTrail logs. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Dev Sec Ops](/stories/dev_sec_ops) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 21.0 | 30 | 70 | Vulnerabilities with severity high found in image $image$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://docs.aws.amazon.com/AmazonECR/latest/userguide/image-scanning.html](https://docs.aws.amazon.com/AmazonECR/latest/userguide/image-scanning.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/aws_ecr_container_scanning_findings_medium.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-17-gsuite_outbound_email_with_attachment_to_external_domain.md b/docs/_posts/2021-08-17-gsuite_outbound_email_with_attachment_to_external_domain.md deleted file mode 100644 index a5d581a73a..0000000000 --- a/docs/_posts/2021-08-17-gsuite_outbound_email_with_attachment_to_external_domain.md +++ /dev/null @@ -1,163 +0,0 @@ ---- -title: "Gsuite Outbound Email With Attachment To External Domain" -excerpt: "Exfiltration Over Unencrypted Non-C2 Protocol -, Exfiltration Over Alternative Protocol -" -categories: - - Cloud -last_modified_at: 2021-08-17 -toc: true -toc_label: "" -tags: - - Exfiltration Over Unencrypted Non-C2 Protocol - - Exfiltration Over Alternative Protocol - - Exfiltration - - Exfiltration - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect a suspicious outbound e-mail from internal email to external email domain. This can be a good hunting query to monitor insider or outbound email traffic for not common domain e-mail. The idea is to parse the domain of destination email check if there is a minimum outbound traffic < 20 with attachment. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-08-17 -- **Author**: Teoderick Contreras, Stanislav Miskovic, Splunk -- **ID**: dc4dc3a8-ff54-11eb-8bf7-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1048.003](https://attack.mitre.org/techniques/T1048/003/) | Exfiltration Over Unencrypted Non-C2 Protocol | Exfiltration | - -| [T1048](https://attack.mitre.org/techniques/T1048/) | Exfiltration Over Alternative Protocol | Exfiltration | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`gsuite_gmail` num_message_attachments > 0 -| rex field=source.from_header_address "[^@]+@(?[^@]+)" -| rex field=destination{}.address "[^@]+@(?[^@]+)" -| where source_domain="internal_test_email.com" and not dest_domain="internal_test_email.com" -| eval phase="plan" -| eval severity="low" -| stats values(subject) as subject, values(source.from_header_address) as src_domain_list, count as numEvents, dc(source.from_header_address) as numSrcAddresses, min(_time) as firstTime max(_time) as lastTime by dest_domain phase severity -| where numSrcAddresses < 20 -|sort - numSrcAddresses -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `gsuite_outbound_email_with_attachment_to_external_domain_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [gsuite_gmail](https://github.com/splunk/security_content/blob/develop/macros/gsuite_gmail.yml) - -> :information_source: -> **gsuite_outbound_email_with_attachment_to_external_domain_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs related to gsuite having the file attachment metadata like file type, file extension, source email, destination email, num of attachment and etc. - -#### Known False Positives -network admin and normal user may send this file attachment as part of their day to day work. having a good protocol in attaching this file type to an e-mail may reduce the risk of having a spear phishing attack. - -#### Associated Analytic story -* [Dev Sec Ops](/stories/dev_sec_ops) -* [Insider Threat](/stories/insider_threat) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 9.0 | 30 | 30 | suspicious email from $source.address$ to $destination{}.address$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.redhat.com/en/topics/devops/what-is-devsecops](https://www.redhat.com/en/topics/devops/what-is-devsecops) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/gsuite_outbound_email_to_external/gsuite_external_domain.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/gsuite_outbound_email_to_external/gsuite_external_domain.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-18-esentutl_sam_copy.md b/docs/_posts/2021-08-18-esentutl_sam_copy.md deleted file mode 100644 index fcb09a3843..0000000000 --- a/docs/_posts/2021-08-18-esentutl_sam_copy.md +++ /dev/null @@ -1,168 +0,0 @@ ---- -title: "Esentutl SAM Copy" -excerpt: "Security Account Manager -, OS Credential Dumping -" -categories: - - Endpoint -last_modified_at: 2021-08-18 -toc: true -toc_label: "" -tags: - - Security Account Manager - - OS Credential Dumping - - Credential Access - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the process - `esentutl.exe` - being used to capture credentials stored in ntds.dit or the SAM file on disk. During triage, review parallel processes and determine if legitimate activity. Upon determination of illegitimate activity, take further action to isolate and contain the threat. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-08-18 -- **Author**: Michael Haag, Splunk -- **ID**: d372f928-ce4f-11eb-a762-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1003.002](https://attack.mitre.org/techniques/T1003/002/) | Security Account Manager | Credential Access | - -| [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_esentutl` Processes.process IN ("*ntds*", "*SAM*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `esentutl_sam_copy_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_esentutl](https://github.com/splunk/security_content/blob/develop/macros/process_esentutl.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **esentutl_sam_copy_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -False positives should be limited. Filter as needed. - -#### Associated Analytic story -* [Credential Dumping](/stories/credential_dumping) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user user$ attempting to capture credentials for offline cracking or observability. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/redcanaryco/atomic-red-team/blob/6a570c2a4630cf0c2bd41a2e8375b5d5ab92f700/atomics/T1003.002/T1003.002.md](https://github.com/redcanaryco/atomic-red-team/blob/6a570c2a4630cf0c2bd41a2e8375b5d5ab92f700/atomics/T1003.002/T1003.002.md) -* [https://attack.mitre.org/software/S0404/](https://attack.mitre.org/software/S0404/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/esentutl_sam_copy.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-18-powershell_4104_hunting.md b/docs/_posts/2021-08-18-powershell_4104_hunting.md deleted file mode 100644 index 07a15a9f19..0000000000 --- a/docs/_posts/2021-08-18-powershell_4104_hunting.md +++ /dev/null @@ -1,333 +0,0 @@ ---- -title: "PowerShell 4104 Hunting" -excerpt: "Command and Scripting Interpreter -, PowerShell -" -categories: - - Endpoint -last_modified_at: 2021-08-18 -toc: true -toc_label: "" -tags: - - Command and Scripting Interpreter - - PowerShell - - Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following Hunting analytic assists with identifying suspicious PowerShell execution using Script Block Logging, or EventCode 4104. This analytic is not meant to be ran hourly, but occasionally to identify malicious or suspicious PowerShell. This analytic is a combination of work completed by Alex Teixeira and Splunk Threat Research Team. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-08-18 -- **Author**: Michael Haag, Splunk -- **ID**: d6f2b006-0041-11ec-8885-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -| [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 -| eval DoIt = if(match(Message,"(?i)(\$doit)"), "4", 0) -| eval enccom=if(match(Message,"[A-Za-z0-9+\/]{44,}([A-Za-z0-9+\/]{4} -|[A-Za-z0-9+\/]{3}= -|[A-Za-z0-9+\/]{2}==)") OR match(Message, "(?i)[-]e(nc*o*d*e*d*c*o*m*m*a*n*d*)*\s+[^-]"),4,0) -| eval suspcmdlet=if(match(Message, "(?i)Add-Exfiltration -|Add-Persistence -|Add-RegBackdoor -|Add-ScrnSaveBackdoor -|Check-VM -|Do-Exfiltration -|Enabled-DuplicateToken -|Exploit-Jboss -|Find-Fruit -|Find-GPOLocation -|Find-TrustedDocuments -|Get-ApplicationHost -|Get-ChromeDump -|Get-ClipboardContents -|Get-FoxDump -|Get-GPPPassword -|Get-IndexedItem -|Get-Keystrokes -|LSASecret -|Get-PassHash -|Get-RegAlwaysInstallElevated -|Get-RegAutoLogon -|Get-RickAstley -|Get-Screenshot -|Get-SecurityPackages -|Get-ServiceFilePermission -|Get-ServicePermission -|Get-ServiceUnquoted -|Get-SiteListPassword -|Get-System -|Get-TimedScreenshot -|Get-UnattendedInstallFile -|Get-Unconstrained -|Get-VaultCredential -|Get-VulnAutoRun -|Get-VulnSchTask -|Gupt-Backdoor -|HTTP-Login -|Install-SSP -|Install-ServiceBinary -|Invoke-ACLScanner -|Invoke-ADSBackdoor -|Invoke-ARPScan -|Invoke-AllChecks -|Invoke-BackdoorLNK -|Invoke-BypassUAC -|Invoke-CredentialInjection -|Invoke-DCSync -|Invoke-DllInjection -|Invoke-DowngradeAccount -|Invoke-EgressCheck -|Invoke-Inveigh -|Invoke-InveighRelay -|Invoke-Mimikittenz -|Invoke-NetRipper -|Invoke-NinjaCopy -|Invoke-PSInject -|Invoke-Paranoia -|Invoke-PortScan -|Invoke-PoshRat -|Invoke-PostExfil -|Invoke-PowerDump -|Invoke-PowerShellTCP -|Invoke-PsExec -|Invoke-PsUaCme -|Invoke-ReflectivePEInjection -|Invoke-ReverseDNSLookup -|Invoke-RunAs -|Invoke-SMBScanner -|Invoke-SSHCommand -|Invoke-Service -|Invoke-Shellcode -|Invoke-Tater -|Invoke-ThunderStruck -|Invoke-Token -|Invoke-UserHunter -|Invoke-VoiceTroll -|Invoke-WScriptBypassUAC -|Invoke-WinEnum -|MailRaider -|New-HoneyHash -|Out-Minidump -|Port-Scan -|PowerBreach -|PowerUp -|PowerView -|Remove-Update -|Set-MacAttribute -|Set-Wallpaper -|Show-TargetScreen -|Start-CaptureServer -|VolumeShadowCopyTools -|NEEEEWWW -|(Computer -|User)Property -|CachedRDPConnection -|get-net\S+ -|invoke-\S+hunter -|Install-Service -|get-\S+(credent -|password) -|remoteps -|Kerberos.*(policy -|ticket) -|netfirewall -|Uninstall-Windows -|Verb\s+Runas -|AmsiBypass -|nishang -|Invoke-Interceptor -|EXEonRemote -|NetworkRelay -|PowerShelludp -|PowerShellIcmp -|CreateShortcut -|copy-vss -|invoke-dll -|invoke-mass -|out-shortcut -|Invoke-ShellCommand"),1,0) -| eval base64 = if(match(lower(Message),"frombase64"), "4", 0) -| eval empire=if(match(lower(Message),"system.net.webclient") AND match(lower(Message), "frombase64string") ,5,0) -| eval mimikatz=if(match(lower(Message),"mimikatz") OR match(lower(Message), "-dumpcr") OR match(lower(Message), "SEKURLSA::Pth") OR match(lower(Message), "kerberos::ptt") OR match(lower(Message), "kerberos::golden") ,5,0) -| eval iex = if(match(lower(Message),"iex"), "2", 0) -| eval webclient=if(match(lower(Message),"http") OR match(lower(Message),"web(client -|request)") OR match(lower(Message),"socket") OR match(lower(Message),"download(file -|string)") OR match(lower(Message),"bitstransfer") OR match(lower(Message),"internetexplorer.application") OR match(lower(Message),"xmlhttp"),5,0) -| eval get = if(match(lower(Message),"get-"), "1", 0) -| eval rundll32 = if(match(lower(Message),"rundll32"), "4", 0) -| eval suspkeywrd=if(match(Message, "(?i)(bitstransfer -|mimik -|metasp -|AssemblyBuilderAccess -|Reflection\.Assembly -|shellcode -|injection -|cnvert -|shell\.application -|start-process -|Rc4ByteStream -|System\.Security\.Cryptography -|lsass\.exe -|localadmin -|LastLoggedOn -|hijack -|BackupPrivilege -|ngrok -|comsvcs -|backdoor -|brute.?force -|Port.?Scan -|Exfiltration -|exploit -|DisableRealtimeMonitoring -|beacon)"),1,0) -| eval syswow64 = if(match(lower(Message),"syswow64"), "3", 0) -| eval httplocal = if(match(lower(Message),"http://127.0.0.1"), "4", 0) -| eval reflection = if(match(lower(Message),"reflection"), "1", 0) -| eval invokewmi=if(match(lower(Message), "(?i)(wmiobject -|WMIMethod -|RemoteWMI -|PowerShellWmi -|wmicommand)"),5,0) -| eval downgrade=if(match(Message, "(?i)([-]ve*r*s*i*o*n*\s+2)") OR match(lower(Message),"powershell -version"),3,0) -| eval compressed=if(match(Message, "(?i)GZipStream -|::Decompress -|IO.Compression -|write-zip -|(expand -|compress)-Archive"),5,0) -| eval invokecmd = if(match(lower(Message),"invoke-command"), "4", 0) -| addtotals fieldname=Score DoIt, enccom, suspcmdlet, suspkeywrd, compressed, downgrade, mimikatz, iex, empire, rundll32, webclient, syswow64, httplocal, reflection, invokewmi, invokecmd, base64, get -| stats values(Score) by DoIt, enccom, compressed, downgrade, iex, mimikatz, rundll32, empire, webclient, syswow64, httplocal, reflection, invokewmi, invokecmd, base64, get, suspcmdlet, suspkeywrd -| `powershell_4104_hunting_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **powershell_4104_hunting_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Message - - -#### How To Implement -The following Hunting analytic requires PowerShell operational logs to be imported. Modify the powershell macro as needed to match the sourcetype or add index. This analytic is specific to 4104, or PowerShell Script Block Logging. - -#### Known False Positives -Limited false positives. May filter as needed. - -#### Associated Analytic story -* [Hermetic Wiper](/stories/hermetic_wiper) -* [Malicious PowerShell](/stories/malicious_powershell) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ executing suspicious commands. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/inodee/threathunting-spl/blob/master/hunt-queries/powershell_qualifiers.md](https://github.com/inodee/threathunting-spl/blob/master/hunt-queries/powershell_qualifiers.md) -* [https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell](https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell) -* [https://github.com/marcurdy/dfir-toolset/blob/master/Powershell%20Blueteam.txt](https://github.com/marcurdy/dfir-toolset/blob/master/Powershell%20Blueteam.txt) -* [https://devblogs.microsoft.com/powershell/powershell-the-blue-team/](https://devblogs.microsoft.com/powershell/powershell-the-blue-team/) -* [https://docs.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_logging?view=powershell-5.1](https://docs.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_logging?view=powershell-5.1) -* [https://www.mandiant.com/resources/greater-visibilityt](https://www.mandiant.com/resources/greater-visibilityt) -* [https://hurricanelabs.com/splunk-tutorials/how-to-use-powershell-transcription-logs-in-splunk/](https://hurricanelabs.com/splunk-tutorials/how-to-use-powershell-transcription-logs-in-splunk/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/powershell_4104_hunting.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-19-aws_ecr_container_upload_outside_business_hours.md b/docs/_posts/2021-08-19-aws_ecr_container_upload_outside_business_hours.md deleted file mode 100644 index 6fc836489c..0000000000 --- a/docs/_posts/2021-08-19-aws_ecr_container_upload_outside_business_hours.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: "AWS ECR Container Upload Outside Business Hours" -excerpt: "Malicious Image -, User Execution -" -categories: - - Cloud -last_modified_at: 2021-08-19 -toc: true -toc_label: "" -tags: - - Malicious Image - - User Execution - - Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for AWS CloudTrail events from AWS Elastic Container Service (ECR). A upload of a new container is normally done during business hours. When done outside business hours, we want to take a look into it. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-08-19 -- **Author**: Patrick Bareiss, Splunk -- **ID**: d4c4d4eb-3994-41ca-a25e-a82d64e125bb - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1204.003](https://attack.mitre.org/techniques/T1204/003/) | Malicious Image | Execution | - -| [T1204](https://attack.mitre.org/techniques/T1204/) | User Execution | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.DS -* PR.AC -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 13 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cloudtrail` eventSource=ecr.amazonaws.com eventName=PutImage date_hour>=20 OR date_hour<8 NOT (date_wday=saturday OR date_wday=sunday) -| rename requestParameters.* as * -| rename repositoryName AS image -| eval phase="release" -| eval severity="medium" -| stats min(_time) as firstTime max(_time) as lastTime by awsRegion, eventName, eventSource, user, userName, src_ip, imageTag, registryId, image, phase, severity -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `aws_ecr_container_upload_outside_business_hours_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) - -> :information_source: -> **aws_ecr_container_upload_outside_business_hours_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* eventSource -* eventName -* awsRegion -* requestParameters.imageTag -* requestParameters.registryId -* requestParameters.repositoryName -* user -* userName -* src_ip - - -#### How To Implement -You must install splunk AWS add on and Splunk App for AWS. This search works with AWS CloudTrail logs. - -#### Known False Positives -When your development is spreaded in different time zones, applying this rule can be difficult. - -#### Associated Analytic story -* [Dev Sec Ops](/stories/dev_sec_ops) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | Container uploaded outside business hours from $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1204/003/](https://attack.mitre.org/techniques/T1204/003/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/aws_ecr_container_upload_outside_business_hours.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-19-aws_ecr_container_upload_unknown_user.md b/docs/_posts/2021-08-19-aws_ecr_container_upload_unknown_user.md deleted file mode 100644 index cc02548366..0000000000 --- a/docs/_posts/2021-08-19-aws_ecr_container_upload_unknown_user.md +++ /dev/null @@ -1,171 +0,0 @@ ---- -title: "AWS ECR Container Upload Unknown User" -excerpt: "Malicious Image -, User Execution -" -categories: - - Cloud -last_modified_at: 2021-08-19 -toc: true -toc_label: "" -tags: - - Malicious Image - - User Execution - - Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for AWS CloudTrail events from AWS Elastic Container Service (ECR). A upload of a new container is normally done from only a few known users. When the user was never seen before, we should have a closer look into the event. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-08-19 -- **Author**: Patrick Bareiss, Splunk -- **ID**: 300688e4-365c-4486-a065-7c884462b31d - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1204.003](https://attack.mitre.org/techniques/T1204/003/) | Malicious Image | Execution | - -| [T1204](https://attack.mitre.org/techniques/T1204/) | User Execution | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.DS -* PR.AC -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 13 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cloudtrail` eventSource=ecr.amazonaws.com eventName=PutImage NOT `aws_ecr_users` -| rename requestParameters.* as * -| rename repositoryName AS image -| eval phase="release" -| eval severity="high" -| stats min(_time) as firstTime max(_time) as lastTime by awsRegion, eventName, eventSource, user, userName, src_ip, imageTag, registryId, image, phase, severity -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `aws_ecr_container_upload_unknown_user_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) -* [aws_ecr_users](https://github.com/splunk/security_content/blob/develop/macros/aws_ecr_users.yml) - -> :information_source: -> **aws_ecr_container_upload_unknown_user_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* eventSource -* eventName -* awsRegion -* requestParameters.imageTag -* requestParameters.registryId -* requestParameters.repositoryName -* user -* userName -* src_ip - - -#### How To Implement -You must install splunk AWS add on and Splunk App for AWS. This search works with AWS CloudTrail logs. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Dev Sec Ops](/stories/dev_sec_ops) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | Container uploaded from unknown user $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1204/003/](https://attack.mitre.org/techniques/T1204/003/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/aws_ecr_container_upload_unknown_user.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-19-gsuite_email_suspicious_subject_with_attachment.md b/docs/_posts/2021-08-19-gsuite_email_suspicious_subject_with_attachment.md deleted file mode 100644 index f70e2c6197..0000000000 --- a/docs/_posts/2021-08-19-gsuite_email_suspicious_subject_with_attachment.md +++ /dev/null @@ -1,161 +0,0 @@ ---- -title: "Gsuite Email Suspicious Subject With Attachment" -excerpt: "Spearphishing Attachment -, Phishing -" -categories: - - Cloud -last_modified_at: 2021-08-19 -toc: true -toc_label: "" -tags: - - Spearphishing Attachment - - Phishing - - Initial Access - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect a gsuite email contains suspicious subject having known file type used in spear phishing. This technique is a common and effective entry vector of attacker to compromise a network by luring the user to click or execute the suspicious attachment send from external email account because of the effective social engineering of subject related to delivery, bank and so on. On the other hand this detection may catch a normal email traffic related to legitimate transaction so better to check the email sender, spelling and etc. avoid click link or opening the attachment if you are not expecting this type of e-mail. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-08-19 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 8ef3971e-00f2-11ec-b54f-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | - -| [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`gsuite_gmail` num_message_attachments > 0 subject IN ("*dhl*", "* ups *", "*delivery*", "*parcel*", "*label*", "*invoice*", "*postal*", "* fedex *", "* usps *", "* express *", "*shipment*", "*Banking/Tax*","*shipment*", "*new order*") attachment{}.file_extension_type IN ("doc", "docx", "xls", "xlsx", "ppt", "pptx", "pdf", "zip", "rar", "html","htm","hta") -| rex field=source.from_header_address "[^@]+@(?[^@]+)" -| rex field=destination{}.address "[^@]+@(?[^@]+)" -| where not source_domain="internal_test_email.com" and dest_domain="internal_test_email.com" -| eval phase="plan" -| eval severity="medium" -| stats count min(_time) as firstTime max(_time) as lastTime values(attachment{}.file_extension_type) as email_attachments, values(attachment{}.sha256) as attachment_sha256, values(payload_size) as payload_size by destination{}.service num_message_attachments subject destination{}.address source.address phase severity -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `gsuite_email_suspicious_subject_with_attachment_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [gsuite_gmail](https://github.com/splunk/security_content/blob/develop/macros/gsuite_gmail.yml) - -> :information_source: -> **gsuite_email_suspicious_subject_with_attachment_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs related to gsuite having the file attachment metadata like file type, file extension, source email, destination email, num of attachment and etc. - -#### Known False Positives -normal user or normal transaction may contain the subject and file type attachment that this detection try to search. - -#### Associated Analytic story -* [Dev Sec Ops](/stories/dev_sec_ops) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | suspicious email from $source.address$ to $destination{}.address$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.redhat.com/en/topics/devops/what-is-devsecops](https://www.redhat.com/en/topics/devops/what-is-devsecops) -* [https://www.mandiant.com/resources/top-words-used-in-spear-phishing-attacks](https://www.mandiant.com/resources/top-words-used-in-spear-phishing-attacks) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/gsuite_susp_subj/gsuite_susp_subj_attach.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/gsuite_susp_subj/gsuite_susp_subj_attach.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-19-protocols_passing_authentication_in_cleartext.md b/docs/_posts/2021-08-19-protocols_passing_authentication_in_cleartext.md deleted file mode 100644 index cd7873937d..0000000000 --- a/docs/_posts/2021-08-19-protocols_passing_authentication_in_cleartext.md +++ /dev/null @@ -1,159 +0,0 @@ ---- -title: "Protocols passing authentication in cleartext" -excerpt: "" -categories: - - Network -last_modified_at: 2021-08-19 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Network_Traffic ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies cleartext protocols at risk of leaking sensitive information. Currently, this consists of legacy protocols such as telnet (port 23), POP3 (port 110), IMAP (port 143), and non-anonymous FTP (port 21) sessions. While some of these protocols may be used over SSL, they typically are found on different assigned ports in those instances. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Network_Traffic](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkTraffic) -- **Last Updated**: 2021-08-19 -- **Author**: Rico Valdez, Splunk -- **ID**: 6923cd64-17a0-453c-b945-81ac2d8c6db9 - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.AE -* PR.AC -* PR.DS - - - -
-
- -
- CIS20 - -
- -* CIS 9 -* CIS 14 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Network_Traffic where All_Traffic.action!=blocked AND All_Traffic.transport="tcp" AND (All_Traffic.dest_port="23" OR All_Traffic.dest_port="143" OR All_Traffic.dest_port="110" OR (All_Traffic.dest_port="21" AND All_Traffic.user != "anonymous")) by All_Traffic.user All_Traffic.src All_Traffic.dest All_Traffic.dest_port -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `drop_dm_object_name("All_Traffic")` -| `protocols_passing_authentication_in_cleartext_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **protocols_passing_authentication_in_cleartext_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* All_Traffic.transport -* All_Traffic.dest_port -* All_Traffic.user -* All_Traffic.src -* All_Traffic.dest -* All_Traffic.action - - -#### How To Implement -This search requires you to be ingesting your network traffic, and populating the Network_Traffic data model. For more accurate result it's better to limit destination to organization private and public IP range, like All_Traffic.dest IN(192.168.0.0/16,172.16.0.0/12,10.0.0.0/8, x.x.x.x/22) - -#### Known False Positives -Some networks may use kerberized FTP or telnet servers, however, this is rare. - -#### Associated Analytic story -* [Use of Cleartext Protocols](/stories/use_of_cleartext_protocols) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.rackaid.com/blog/secure-your-email-and-file-transfers/](https://www.rackaid.com/blog/secure-your-email-and-file-transfers/) -* [https://www.infosecmatter.com/capture-passwords-using-wireshark/](https://www.infosecmatter.com/capture-passwords-using-wireshark/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/network/protocols_passing_authentication_in_cleartext.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2021-08-20-github_commit_changes_in_master.md b/docs/_posts/2021-08-20-github_commit_changes_in_master.md deleted file mode 100644 index b176886222..0000000000 --- a/docs/_posts/2021-08-20-github_commit_changes_in_master.md +++ /dev/null @@ -1,151 +0,0 @@ ---- -title: "Github Commit Changes In Master" -excerpt: "Trusted Relationship -" -categories: - - Cloud -last_modified_at: 2021-08-20 -toc: true -toc_label: "" -tags: - - Trusted Relationship - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect a pushed or commit to master or main branch. This is to avoid unwanted modification to master without a review to the changes. Ideally in terms of devsecops the changes made in a branch and do a PR for review. of course in some cases admin of the project may did a changes directly to master branch - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-08-20 -- **Author**: Teoderick Contreras, Splunk -- **ID**: c9d2bfe2-019f-11ec-a8eb-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1199](https://attack.mitre.org/techniques/T1199/) | Trusted Relationship | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`github` branches{}.name = main OR branches{}.name = master -| stats count min(_time) as firstTime max(_time) as lastTime by commit.commit.author.email commit.author.login commit.commit.message repository.pushed_at commit.commit.committer.date repository.full_name -| rename commit.author.login as user, repository.full_name as repository -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `github_commit_changes_in_master_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [github](https://github.com/splunk/security_content/blob/develop/macros/github.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **github_commit_changes_in_master_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs related to github logs having the fork, commit, push metadata that can be use to monitor the changes in a github project. - -#### Known False Positives -admin can do changes directly to master branch - -#### Associated Analytic story -* [Dev Sec Ops](/stories/dev_sec_ops) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 9.0 | 30 | 30 | suspicious commit by $commit.commit.author.email$ to main branch | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.redhat.com/en/topics/devops/what-is-devsecops](https://www.redhat.com/en/topics/devops/what-is-devsecops) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1199/github_push_master/github_push_master.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1199/github_push_master/github_push_master.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/github_commit_changes_in_master.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-20-kubernetes_nginx_ingress_lfi.md b/docs/_posts/2021-08-20-kubernetes_nginx_ingress_lfi.md deleted file mode 100644 index ac0fc91be6..0000000000 --- a/docs/_posts/2021-08-20-kubernetes_nginx_ingress_lfi.md +++ /dev/null @@ -1,169 +0,0 @@ ---- -title: "Kubernetes Nginx Ingress LFI" -excerpt: "Exploitation for Credential Access -" -categories: - - Cloud -last_modified_at: 2021-08-20 -toc: true -toc_label: "" -tags: - - Exploitation for Credential Access - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search uses the Kubernetes logs from a nginx ingress controller to detect local file inclusion attacks. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-08-20 -- **Author**: Patrick Bareiss, Splunk -- **ID**: 0f83244b-425b-4528-83db-7a88c5f66e48 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1212](https://attack.mitre.org/techniques/T1212/) | Exploitation for Credential Access | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.DS -* PR.AC -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 13 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`kubernetes_container_controller` -| rex field=_raw "^(?\S+)\s+-\s+-\s+\[(?[^\]]*)\]\s\"(?[^\"]*)\"\s(?\S*)\s(?\S*)\s\"(?[^\"]*)\"\s\"(?[^\"]*)\"\s(?\S*)\s(?\S*)\s\[(?[^\]]*)\]\s\[(?[^\]]*)\]\s(?\S*)\s(?\S*)\s(?\S*)\s(?\S*)\s(?\S*)" -| lookup local_file_inclusion_paths local_file_inclusion_paths AS request OUTPUT lfi_path -| search lfi_path=yes -| rename remote_addr AS src_ip, upstream_status as status, proxy_upstream_name as proxy -| rex field=request "^(?\S+)\s(?\S+)\s" -| eval phase="operate" -| eval severity="high" -| stats count min(_time) as firstTime max(_time) as lastTime by src_ip, status, url, http_method, host, http_user_agent, proxy, phase, severity -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `kubernetes_nginx_ingress_lfi_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [kubernetes_container_controller](https://github.com/splunk/security_content/blob/develop/macros/kubernetes_container_controller.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **kubernetes_nginx_ingress_lfi_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Lookups -The SPL above uses the following Lookups: - -* [local_file_inclusion_paths](https://github.com/splunk/security_content/blob/develop/lookups/local_file_inclusion_paths.yml) with [data](https://github.com/splunk/security_content/tree/develop/lookups/local_file_inclusion_paths.csv) - -#### Required field -* raw - - -#### How To Implement -You must ingest Kubernetes logs through Splunk Connect for Kubernetes. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Dev Sec Ops](/stories/dev_sec_ops) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | Local File Inclusion Attack detected on $host$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/splunk/splunk-connect-for-kubernetes](https://github.com/splunk/splunk-connect-for-kubernetes) -* [https://www.offensive-security.com/metasploit-unleashed/file-inclusion-vulnerabilities/](https://www.offensive-security.com/metasploit-unleashed/file-inclusion-vulnerabilities/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1212/kubernetes_nginx_lfi_attack/kubernetes_nginx_lfi_attack.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1212/kubernetes_nginx_lfi_attack/kubernetes_nginx_lfi_attack.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/kubernetes_nginx_ingress_lfi.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-23-getlocaluser_with_powershell.md b/docs/_posts/2021-08-23-getlocaluser_with_powershell.md deleted file mode 100644 index 55b0cd8cf1..0000000000 --- a/docs/_posts/2021-08-23-getlocaluser_with_powershell.md +++ /dev/null @@ -1,157 +0,0 @@ ---- -title: "GetLocalUser with PowerShell" -excerpt: "Account Discovery -, Local Account -" -categories: - - Endpoint -last_modified_at: 2021-08-23 -toc: true -toc_label: "" -tags: - - Account Discovery - - Local Account - - Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for the execution of `powershell.exe` with command-line arguments utilized to query for local users. The `Get-LocalUser` commandlet is used to return a list of all local users. Red Teams and adversaries may leverage this commandlet to enumerate users for situational awareness and Active Directory Discovery. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-08-23 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 85fae8fa-0427-11ec-8b78-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - -| [T1087.001](https://attack.mitre.org/techniques/T1087/001/) | Local Account | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="powershell.exe") (Processes.process=*Get-LocalUser*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `getlocaluser_with_powershell_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **getlocaluser_with_powershell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Administrators or power users may use this PowerShell commandlet for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | Local user discovery enumeration using PowerShell on $dest$ by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1087/001/](https://attack.mitre.org/techniques/T1087/001/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.001/AD_discovery/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.001/AD_discovery/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/getlocaluser_with_powershell.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-23-getlocaluser_with_powershell_script_block.md b/docs/_posts/2021-08-23-getlocaluser_with_powershell_script_block.md deleted file mode 100644 index 3b1b485d3a..0000000000 --- a/docs/_posts/2021-08-23-getlocaluser_with_powershell_script_block.md +++ /dev/null @@ -1,150 +0,0 @@ ---- -title: "GetLocalUser with PowerShell Script Block" -excerpt: "Account Discovery -, Local Account -" -categories: - - Endpoint -last_modified_at: 2021-08-23 -toc: true -toc_label: "" -tags: - - Account Discovery - - Local Account - - Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-LocalUser` commandlet. The `Get-LocalUser` commandlet is used to return a list of all local users. Red Teams and adversaries may leverage this commandlet to enumerate users for situational awareness and Active Directory Discovery. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-08-23 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 2e891cbe-0426-11ec-9c9c-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - -| [T1087.001](https://attack.mitre.org/techniques/T1087/001/) | Local Account | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 (Message = "*Get-LocalUser*") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `getlocaluser_with_powershell_script_block_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -Note that **getlocaluser_with_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -Administrators or power users may use this PowerShell commandlet for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | Local user discovery enumeration using PowerShell on $dest$ by $user$ | - - -#### Reference - -* [https://attack.mitre.org/techniques/T1087/001/](https://attack.mitre.org/techniques/T1087/001/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.001/AD_discovery/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.001/AD_discovery/windows-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-23-getwmiobject_user_account_with_powershell.md b/docs/_posts/2021-08-23-getwmiobject_user_account_with_powershell.md deleted file mode 100644 index 65ed551ddb..0000000000 --- a/docs/_posts/2021-08-23-getwmiobject_user_account_with_powershell.md +++ /dev/null @@ -1,157 +0,0 @@ ---- -title: "GetWmiObject User Account with PowerShell" -excerpt: "Account Discovery -, Local Account -" -categories: - - Endpoint -last_modified_at: 2021-08-23 -toc: true -toc_label: "" -tags: - - Account Discovery - - Local Account - - Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for the execution of `powershell.exe` with command-line arguments utilized to query local users. The `Get-WmiObject` commandlet combined with the `Win32_UserAccount` parameter is used to return a list of all local users. Red Teams and adversaries may leverage this commandlet to enumerate users for situational awareness and Active Directory Discovery. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-08-23 -- **Author**: Mauricio Velazco, Splunk -- **ID**: b44f6ac6-0429-11ec-87e9-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - -| [T1087.001](https://attack.mitre.org/techniques/T1087/001/) | Local Account | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="powershell.exe") (Processes.process=*Get-WmiObject* AND Processes.process=*Win32_UserAccount*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `getwmiobject_user_account_with_powershell_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **getwmiobject_user_account_with_powershell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Administrators or power users may use this PowerShell commandlet for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | Local user discovery enumeration using PowerShell on $dest$ by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1087/001/](https://attack.mitre.org/techniques/T1087/001/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.001/AD_discovery/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.001/AD_discovery/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-23-getwmiobject_user_account_with_powershell_script_block.md b/docs/_posts/2021-08-23-getwmiobject_user_account_with_powershell_script_block.md deleted file mode 100644 index 6a544a3ab2..0000000000 --- a/docs/_posts/2021-08-23-getwmiobject_user_account_with_powershell_script_block.md +++ /dev/null @@ -1,154 +0,0 @@ ---- -title: "GetWmiObject User Account with PowerShell Script Block" -excerpt: "Account Discovery -, Local Account -" -categories: - - Endpoint -last_modified_at: 2021-08-23 -toc: true -toc_label: "" -tags: - - Account Discovery - - Local Account - - Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-WmiObject` commandlet used with specific parameters. The `Win32_UserAccount` parameter is used to return a list of all local users. Red Teams and adversaries may leverage this commandlet to enumerate users for situational awareness and Active Directory Discovery. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-08-23 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 640b0eda-0429-11ec-accd-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - -| [T1087.001](https://attack.mitre.org/techniques/T1087/001/) | Local Account | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 (Message="*Get-WmiObject*" AND Message="*Win32_UserAccount*") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `getwmiobject_user_account_with_powershell_script_block_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **getwmiobject_user_account_with_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -Administrators or power users may use this PowerShell commandlet for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | Local user discovery enumeration using PowerShell on $dest$ by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1087/001/](https://attack.mitre.org/techniques/T1087/001/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.001/AD_discovery/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.001/AD_discovery/windows-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-23-gsuite_email_with_known_abuse_web_service_link.md b/docs/_posts/2021-08-23-gsuite_email_with_known_abuse_web_service_link.md deleted file mode 100644 index b9eae53195..0000000000 --- a/docs/_posts/2021-08-23-gsuite_email_with_known_abuse_web_service_link.md +++ /dev/null @@ -1,160 +0,0 @@ ---- -title: "Gsuite Email With Known Abuse Web Service Link" -excerpt: "Spearphishing Attachment -, Phishing -" -categories: - - Cloud -last_modified_at: 2021-08-23 -toc: true -toc_label: "" -tags: - - Spearphishing Attachment - - Phishing - - Initial Access - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytics is to detect a gmail containing a link that are known to be abused by malware or attacker like pastebin, telegram and discord to deliver malicious payload. This event can encounter some normal email traffic within organization and external email that normally using this application and services. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-08-23 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 8630aa22-042b-11ec-af39-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | - -| [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`gsuite_gmail` "link_domain{}" IN ("*pastebin.com*", "*discord*", "*telegram*","t.me") -| rex field=source.from_header_address "[^@]+@(?[^@]+)" -| rex field=destination{}.address "[^@]+@(?[^@]+)" -| where not source_domain="internal_test_email.com" and dest_domain="internal_test_email.com" -| eval phase="plan" -| eval severity="low" -|stats values(link_domain{}) as link_domains min(_time) as firstTime max(_time) as lastTime count by is_spam source.address source.from_header_address subject destination{}.address phase severity -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `gsuite_email_with_known_abuse_web_service_link_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [gsuite_gmail](https://github.com/splunk/security_content/blob/develop/macros/gsuite_gmail.yml) - -> :information_source: -> **gsuite_email_with_known_abuse_web_service_link_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs related to gsuite having the file attachment metadata like file type, file extension, source email, destination email, num of attachment and etc. - -#### Known False Positives -normal email contains this link that are known application within the organization or network can be catched by this detection. - -#### Associated Analytic story -* [Dev Sec Ops](/stories/dev_sec_ops) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | suspicious email from $source.address$ to $destination{}.address$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://news.sophos.com/en-us/2021/07/22/malware-increasingly-targets-discord-for-abuse/](https://news.sophos.com/en-us/2021/07/22/malware-increasingly-targets-discord-for-abuse/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/gsuite_susp_url/gsuite_susp_url.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/gsuite_susp_url/gsuite_susp_url.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-23-gsuite_suspicious_shared_file_name.md b/docs/_posts/2021-08-23-gsuite_suspicious_shared_file_name.md deleted file mode 100644 index 222f8bb9a1..0000000000 --- a/docs/_posts/2021-08-23-gsuite_suspicious_shared_file_name.md +++ /dev/null @@ -1,169 +0,0 @@ ---- -title: "Gsuite Suspicious Shared File Name" -excerpt: "Spearphishing Attachment -, Phishing -" -categories: - - Cloud -last_modified_at: 2021-08-23 -toc: true -toc_label: "" -tags: - - Spearphishing Attachment - - Phishing - - Initial Access - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect a shared file in google drive with suspicious file name that are commonly used by spear phishing campaign. This technique is very popular to lure the user by running a malicious document or click a malicious link within the shared file that will redirected to malicious website. This detection can also catch some normal email communication between organization and its external customer. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-08-23 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 07eed200-03f5-11ec-98fb-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | - -| [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`gsuite_drive` parameters.owner_is_team_drive=false "parameters.doc_title" IN ("*dhl*", "* ups *", "*delivery*", "*parcel*", "*label*", "*invoice*", "*postal*", "*fedex*", "* usps *", "* express *", "*shipment*", "*Banking/Tax*","*shipment*", "*new order*") parameters.doc_type IN ("document","pdf", "msexcel", "msword", "spreadsheet", "presentation") -| rex field=parameters.owner "[^@]+@(?[^@]+)" -| rex field=parameters.target_user "[^@]+@(?[^@]+)" -| where not source_domain="internal_test_email.com" and dest_domain="internal_test_email.com" -| eval phase="plan" -| eval severity="low" -| stats count min(_time) as firstTime max(_time) as lastTime by email parameters.owner parameters.target_user parameters.doc_title parameters.doc_type phase severity -| rename parameters.target_user AS user -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `gsuite_suspicious_shared_file_name_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [gsuite_drive](https://github.com/splunk/security_content/blob/develop/macros/gsuite_drive.yml) - -> :information_source: -> **gsuite_suspicious_shared_file_name_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* parameters.doc_title -* src_domain -* dest_domain -* email -* parameters.visibility -* parameters.owner -* parameters.doc_type - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs related to gsuite having the file attachment metadata like file type, file extension, source email, destination email, num of attachment and etc. In order for the search to work for your environment, please edit the query to use your company specific email domain instead of `internal_test_email.com`. - -#### Known False Positives -normal user or normal transaction may contain the subject and file type attachment that this detection try to search - -#### Associated Analytic story -* [Dev Sec Ops](/stories/dev_sec_ops) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 21.0 | 30 | 70 | suspicious share gdrive from $parameters.owner$ to $email$ namely as $parameters.doc_title$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.redhat.com/en/topics/devops/what-is-devsecops](https://www.redhat.com/en/topics/devops/what-is-devsecops) -* [https://www.mandiant.com/resources/top-words-used-in-spear-phishing-attacks](https://www.mandiant.com/resources/top-words-used-in-spear-phishing-attacks) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/gdrive_susp_file_share/gdrive_susp_attach.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/gdrive_susp_file_share/gdrive_susp_attach.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-23-kubernetes_nginx_ingress_rfi.md b/docs/_posts/2021-08-23-kubernetes_nginx_ingress_rfi.md deleted file mode 100644 index 68cf946c0f..0000000000 --- a/docs/_posts/2021-08-23-kubernetes_nginx_ingress_rfi.md +++ /dev/null @@ -1,164 +0,0 @@ ---- -title: "Kubernetes Nginx Ingress RFI" -excerpt: "Exploitation for Credential Access -" -categories: - - Cloud -last_modified_at: 2021-08-23 -toc: true -toc_label: "" -tags: - - Exploitation for Credential Access - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search uses the Kubernetes logs from a nginx ingress controller to detect remote file inclusion attacks. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-08-23 -- **Author**: Patrick Bareiss, Splunk -- **ID**: fc5531ae-62fd-4de6-9c36-b4afdae8ca95 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1212](https://attack.mitre.org/techniques/T1212/) | Exploitation for Credential Access | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.DS -* PR.AC -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 13 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`kubernetes_container_controller` -| rex field=_raw "^(?\S+)\s+-\s+-\s+\[(?[^\]]*)\]\s\"(?[^\"]*)\"\s(?\S*)\s(?\S*)\s\"(?[^\"]*)\"\s\"(?[^\"]*)\"\s(?\S*)\s(?\S*)\s\[(?[^\]]*)\]\s\[(?[^\]]*)\]\s(?\S*)\s(?\S*)\s(?\S*)\s(?\S*)\s(?\S*)" -| rex field=request "^(?\S+)?\s(?\S+)\s" -| rex field=url "(?\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})" -| search dest_ip=* -| rename remote_addr AS src_ip, upstream_status as status, proxy_upstream_name as proxy -| eval phase="operate" -| eval severity="medium" -| stats count min(_time) as firstTime max(_time) as lastTime by src_ip, dest_ip status, url, http_method, host, http_user_agent, proxy, phase, severity -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `kubernetes_nginx_ingress_rfi_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [kubernetes_container_controller](https://github.com/splunk/security_content/blob/develop/macros/kubernetes_container_controller.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **kubernetes_nginx_ingress_rfi_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* raw - - -#### How To Implement -You must ingest Kubernetes logs through Splunk Connect for Kubernetes. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Dev Sec Ops](/stories/dev_sec_ops) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | Remote File Inclusion Attack detected on $host$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/splunk/splunk-connect-for-kubernetes](https://github.com/splunk/splunk-connect-for-kubernetes) -* [https://www.invicti.com/blog/web-security/remote-file-inclusion-vulnerability/](https://www.invicti.com/blog/web-security/remote-file-inclusion-vulnerability/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1212/kuberntest_nginx_rfi_attack/kubernetes_nginx_rfi_attack.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1212/kuberntest_nginx_rfi_attack/kubernetes_nginx_rfi_attack.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/kubernetes_nginx_ingress_rfi.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-24-adsisearcher_account_discovery.md b/docs/_posts/2021-08-24-adsisearcher_account_discovery.md deleted file mode 100644 index 5f2ea3159e..0000000000 --- a/docs/_posts/2021-08-24-adsisearcher_account_discovery.md +++ /dev/null @@ -1,162 +0,0 @@ ---- -title: "AdsiSearcher Account Discovery" -excerpt: "Domain Account -, Account Discovery -" -categories: - - Endpoint -last_modified_at: 2021-08-24 -toc: true -toc_label: "" -tags: - - Domain Account - - Account Discovery - - Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the `[Adsisearcher]` type accelerator being used to query Active Directory for domain groups. Red Teams and adversaries may leverage `[Adsisearcher]` to enumerate domain users for situational awareness and Active Directory Discovery. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-08-24 -- **Author**: Teoderick Contreras, Mauricio Velazco, Splunk -- **ID**: de7fcadc-04f3-11ec-a241-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery | - -| [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 Message = "*[adsisearcher]*" Message = "*objectcategory=user*" Message = "*.findAll()*" -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `adsisearcher_account_discovery_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **adsisearcher_account_discovery_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Message -* ComputerName -* User - - -#### How To Implement -The following Hunting analytic requires PowerShell operational logs to be imported. Modify the powershell macro as needed to match the sourcetype or add index. This analytic is specific to 4104, or PowerShell Script Block Logging. - -#### Known False Positives -Administrators or power users may use this command for troubleshooting. - -#### Associated Analytic story -* [Industroyer2](/stories/industroyer2) -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | powershell process having commandline $Message$ for user enumeration | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1087/002/](https://attack.mitre.org/techniques/T1087/002/) -* [https://www.blackhillsinfosec.com/red-blue-purple/](https://www.blackhillsinfosec.com/red-blue-purple/) -* [https://devblogs.microsoft.com/scripting/use-the-powershell-adsisearcher-type-accelerator-to-search-active-directory/](https://devblogs.microsoft.com/scripting/use-the-powershell-adsisearcher-type-accelerator-to-search-active-directory/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/AD_discovery/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/AD_discovery/windows-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/adsisearcher_account_discovery.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-24-domain_account_discovery_with_dsquery.md b/docs/_posts/2021-08-24-domain_account_discovery_with_dsquery.md deleted file mode 100644 index 6161794c2a..0000000000 --- a/docs/_posts/2021-08-24-domain_account_discovery_with_dsquery.md +++ /dev/null @@ -1,166 +0,0 @@ ---- -title: "Domain Account Discovery with Dsquery" -excerpt: "Domain Account -, Account Discovery -" -categories: - - Endpoint -last_modified_at: 2021-08-24 -toc: true -toc_label: "" -tags: - - Domain Account - - Account Discovery - - Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for the execution of `dsquery.exe` with command-line arguments utilized to discover domain users. The `user` argument returns a list of all users registered in the domain. Red Teams and adversaries alike engage in remote system discovery for situational awareness and Active Directory Discovery. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-08-24 -- **Author**: Teoderick Contreras, Mauricio Velazco, Splunk -- **ID**: b1a8ce04-04c2-11ec-bea7-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery | - -| [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name="dsquery.exe" AND Processes.process = "*user*" by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `domain_account_discovery_with_dsquery_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **domain_account_discovery_with_dsquery_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id -* Processes.parent_process_name - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -Administrators or power users may use this command for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | an instance of process $process_name$ with commandline $process$ in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://jpcertcc.github.io/ToolAnalysisResultSheet/details/dsquery.htm](https://jpcertcc.github.io/ToolAnalysisResultSheet/details/dsquery.htm) -* [https://attack.mitre.org/techniques/T1087/002/](https://attack.mitre.org/techniques/T1087/002/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/AD_discovery/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/AD_discovery/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-24-domain_account_discovery_with_net_app.md b/docs/_posts/2021-08-24-domain_account_discovery_with_net_app.md deleted file mode 100644 index e7c336bbb4..0000000000 --- a/docs/_posts/2021-08-24-domain_account_discovery_with_net_app.md +++ /dev/null @@ -1,167 +0,0 @@ ---- -title: "Domain Account Discovery With Net App" -excerpt: "Domain Account -, Account Discovery -" -categories: - - Endpoint -last_modified_at: 2021-08-24 -toc: true -toc_label: "" -tags: - - Domain Account - - Account Discovery - - Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for the execution of `net.exe` or `net1.exe` with command-line arguments utilized to query for domain users. Red Teams and adversaries alike may use net.exe to enumerate domain users for situational awareness and Active Directory Discovery. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-08-24 -- **Author**: Teoderick Contreras, Mauricio Velazco, Splunk -- **ID**: 98f6a534-04c2-11ec-96b2-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery | - -| [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_net` AND Processes.process = "* user*" AND Processes.process = "*/do*" by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `domain_account_discovery_with_net_app_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_net](https://github.com/splunk/security_content/blob/develop/macros/process_net.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **domain_account_discovery_with_net_app_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id -* Processes.parent_process_name - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -Administrators or power users may use this command for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | an instance of process $process_name$ with commandline $process$ in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://docs.microsoft.com/en-us/defender-for-identity/playbook-domain-dominance](https://docs.microsoft.com/en-us/defender-for-identity/playbook-domain-dominance) -* [https://attack.mitre.org/techniques/T1087/002/](https://attack.mitre.org/techniques/T1087/002/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/AD_discovery/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/AD_discovery/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/domain_account_discovery_with_net_app.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-24-domain_account_discovery_with_wmic.md b/docs/_posts/2021-08-24-domain_account_discovery_with_wmic.md deleted file mode 100644 index 0f8edcb217..0000000000 --- a/docs/_posts/2021-08-24-domain_account_discovery_with_wmic.md +++ /dev/null @@ -1,165 +0,0 @@ ---- -title: "Domain Account Discovery with Wmic" -excerpt: "Domain Account -, Account Discovery -" -categories: - - Endpoint -last_modified_at: 2021-08-24 -toc: true -toc_label: "" -tags: - - Domain Account - - Account Discovery - - Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for the execution of `wmic.exe` with command-line arguments utilized to query for domain users. Red Teams and adversaries alike use wmic.exe to enumerate domain users for situational awareness and Active Directory Discovery. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-08-24 -- **Author**: Teoderick Contreras, Mauricio Velazco, Splunk -- **ID**: 383572e0-04c5-11ec-bdcc-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery | - -| [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name="wmic.exe" AND Processes.process = "*/NAMESPACE:\\\\root\\directory\\ldap*" AND Processes.process = "*ds_user*" AND Processes.process = "*GET*" AND Processes.process = "*ds_samaccountname*" by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `domain_account_discovery_with_wmic_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **domain_account_discovery_with_wmic_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id -* Processes.parent_process_name - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -Administrators or power users may use this command for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | an instance of process $process_name$ with commandline $process$ in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1087/002/](https://attack.mitre.org/techniques/T1087/002/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/AD_discovery/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/AD_discovery/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/domain_account_discovery_with_wmic.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-24-get-domaintrust_with_powershell.md b/docs/_posts/2021-08-24-get-domaintrust_with_powershell.md deleted file mode 100644 index 1abdd8c065..0000000000 --- a/docs/_posts/2021-08-24-get-domaintrust_with_powershell.md +++ /dev/null @@ -1,163 +0,0 @@ ---- -title: "Get-DomainTrust with PowerShell" -excerpt: "Domain Trust Discovery -" -categories: - - Endpoint -last_modified_at: 2021-08-24 -toc: true -toc_label: "" -tags: - - Domain Trust Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic identifies Get-DomainTrust from PowerView in order to gather domain trust information. Typically, this is utilized within a script being executed and used to enumerate the domain trust information. This grants the adversary an understanding of how large or small the domain is. During triage, review parallel processes using an EDR product or 4688 events. It will be important to understand the timeline of events around this activity. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-08-24 -- **Author**: Michael Haag, Splunk -- **ID**: 4fa7f846-054a-11ec-a836-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1482](https://attack.mitre.org/techniques/T1482/) | Domain Trust Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process=*get-domaintrust* by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `get_domaintrust_with_powershell_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **get-domaintrust_with_powershell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Limited false positives as this requires an active Administrator or adversary to bring in, import, and execute. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 12.0 | 30 | 40 | Suspicious PowerShell Get-DomainTrust was identified on endpoint $dest$ by user $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://blog.harmj0y.net/redteaming/a-guide-to-attacking-domain-trusts/](https://blog.harmj0y.net/redteaming/a-guide-to-attacking-domain-trusts/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1482/discovery/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1482/discovery/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/get_domaintrust_with_powershell.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-24-get-domaintrust_with_powershell_script_block.md b/docs/_posts/2021-08-24-get-domaintrust_with_powershell_script_block.md deleted file mode 100644 index 8ee95a2b0b..0000000000 --- a/docs/_posts/2021-08-24-get-domaintrust_with_powershell_script_block.md +++ /dev/null @@ -1,162 +0,0 @@ ---- -title: "Get-DomainTrust with PowerShell Script Block" -excerpt: "Domain Trust Discovery -" -categories: - - Endpoint -last_modified_at: 2021-08-24 -toc: true -toc_label: "" -tags: - - Domain Trust Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify suspicious PowerShell execution. Script Block Logging captures the command sent to PowerShell, the full command to be executed. Upon enabling, logs will output to Windows event logs. Dependent upon volume, enable on critical endpoints or all. \ -This analytic identifies Get-DomainTrust from PowerView in order to gather domain trust information. \ -During triage, review parallel processes using an EDR product or 4688 events. It will be important to understand the timeline of events around this activity. Review the entire logged PowerShell script block. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-08-24 -- **Author**: Michael Haag, Splunk -- **ID**: 89275e7e-0548-11ec-bf75-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1482](https://attack.mitre.org/techniques/T1482/) | Domain Trust Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 Message = "*get-foresttrust*" -| stats count min(_time) as firstTime max(_time) as lastTime by Message ComputerName User EventCode -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `get_domaintrust_with_powershell_script_block_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **get-domaintrust_with_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Message -* Path -* OpCode -* ComputerName -* User - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -It is possible certain system management frameworks utilize this command to gather trust information. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 12.0 | 30 | 40 | Suspicious PowerShell Get-DomainTrust was identified on endpoint $ComputerName$ by user $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://blog.harmj0y.net/redteaming/a-guide-to-attacking-domain-trusts/](https://blog.harmj0y.net/redteaming/a-guide-to-attacking-domain-trusts/) -* [https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.](https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.) -* [https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63](https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63) -* [https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf](https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf) -* [https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/](https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1482/discovery/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1482/discovery/windows-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-24-get_aduser_with_powershell.md b/docs/_posts/2021-08-24-get_aduser_with_powershell.md deleted file mode 100644 index 99d7a6b93d..0000000000 --- a/docs/_posts/2021-08-24-get_aduser_with_powershell.md +++ /dev/null @@ -1,167 +0,0 @@ ---- -title: "Get ADUser with PowerShell" -excerpt: "Domain Account -, Account Discovery -" -categories: - - Endpoint -last_modified_at: 2021-08-24 -toc: true -toc_label: "" -tags: - - Domain Account - - Account Discovery - - Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for the execution of `powershell.exe` with command-line arguments utilized to enumerate domain users. The `Get-AdUser' commandlet returns a list of all domain users. Red Teams and adversaries alike may use this commandlet to identify remote systems for situational awareness and Active Directory Discovery. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-08-24 -- **Author**: Teoderick Contreras, Mauricio Velazco, Splunk -- **ID**: 0b6ee3f4-04e3-11ec-a87d-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery | - -| [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="cmd.exe" OR Processes.process_name="powershell*") AND Processes.process = "*Get-ADUser*" AND Processes.process = "*-filter*" by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `get_aduser_with_powershell_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **get_aduser_with_powershell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id -* Processes.parent_process_name - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -Administrators or power users may use this command for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | an instance of process $process_name$ with commandline $process$ in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.blackhillsinfosec.com/red-blue-purple/](https://www.blackhillsinfosec.com/red-blue-purple/) -* [https://attack.mitre.org/techniques/T1087/002/](https://attack.mitre.org/techniques/T1087/002/) -* [https://docs.microsoft.com/en-us/powershell/module/activedirectory/get-aduser?view=windowsserver2019-ps](https://docs.microsoft.com/en-us/powershell/module/activedirectory/get-aduser?view=windowsserver2019-ps) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/AD_discovery/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/AD_discovery/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/get_aduser_with_powershell.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-24-get_aduser_with_powershell_script_block.md b/docs/_posts/2021-08-24-get_aduser_with_powershell_script_block.md deleted file mode 100644 index 983227c015..0000000000 --- a/docs/_posts/2021-08-24-get_aduser_with_powershell_script_block.md +++ /dev/null @@ -1,161 +0,0 @@ ---- -title: "Get ADUser with PowerShell Script Block" -excerpt: "Domain Account -, Account Discovery -" -categories: - - Endpoint -last_modified_at: 2021-08-24 -toc: true -toc_label: "" -tags: - - Domain Account - - Account Discovery - - Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-AdGUser` commandlet. The `Get-AdUser` commandlet is used to return a list of all domain users. Red Teams and adversaries may leverage this commandlet to enumerate domain groups for situational awareness and Active Directory Discovery. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-08-24 -- **Author**: Teoderick Contreras, Mauricio Velazco, Splunk -- **ID**: 21432e40-04f4-11ec-b7e6-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery | - -| [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 Message = "*get-aduser*" Message = "*-filter*" -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `get_aduser_with_powershell_script_block_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **get_aduser_with_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Message -* ComputerName -* User - - -#### How To Implement -The following Hunting analytic requires PowerShell operational logs to be imported. Modify the powershell macro as needed to match the sourcetype or add index. This analytic is specific to 4104, or PowerShell Script Block Logging. - -#### Known False Positives -Administrators or power users may use this command for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | powershell process having commandline $Message$ for user enumeration | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.blackhillsinfosec.com/red-blue-purple/](https://www.blackhillsinfosec.com/red-blue-purple/) -* [https://attack.mitre.org/techniques/T1087/002/](https://attack.mitre.org/techniques/T1087/002/) -* [https://docs.microsoft.com/en-us/powershell/module/activedirectory/get-aduser?view=windowsserver2019-ps](https://docs.microsoft.com/en-us/powershell/module/activedirectory/get-aduser?view=windowsserver2019-ps) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/AD_discovery/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/AD_discovery/windows-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-24-get_domainuser_with_powershell.md b/docs/_posts/2021-08-24-get_domainuser_with_powershell.md deleted file mode 100644 index 5e3ccc9ec7..0000000000 --- a/docs/_posts/2021-08-24-get_domainuser_with_powershell.md +++ /dev/null @@ -1,165 +0,0 @@ ---- -title: "Get DomainUser with PowerShell" -excerpt: "Domain Account -, Account Discovery -" -categories: - - Endpoint -last_modified_at: 2021-08-24 -toc: true -toc_label: "" -tags: - - Domain Account - - Account Discovery - - Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for the execution of `powershell.exe` with command-line arguments utilized to enumerate domain users. `Get-DomainUser` is part of PowerView, a PowerShell tool used to perform enumeration on Windows domains. Red Teams and adversaries alike may leverage PowerView to enumerate domain users for situational awareness and Active Directory Discovery. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-08-24 -- **Author**: Teoderick Contreras, Mauricio Velazco, Splunk -- **ID**: 9a5a41d6-04e7-11ec-923c-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery | - -| [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="cmd.exe" OR Processes.process_name="powershell*") AND Processes.process = "*Get-DomainUser*" by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `get_domainuser_with_powershell_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **get_domainuser_with_powershell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id -* Processes.parent_process_name - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -Administrators or power users may use this command for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | an instance of process $process_name$ with commandline $process$ in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://powersploit.readthedocs.io/en/latest/Recon/Get-DomainUser/](https://powersploit.readthedocs.io/en/latest/Recon/Get-DomainUser/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/AD_discovery/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/AD_discovery/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/get_domainuser_with_powershell.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-24-get_domainuser_with_powershell_script_block.md b/docs/_posts/2021-08-24-get_domainuser_with_powershell_script_block.md deleted file mode 100644 index 6f526d8776..0000000000 --- a/docs/_posts/2021-08-24-get_domainuser_with_powershell_script_block.md +++ /dev/null @@ -1,155 +0,0 @@ ---- -title: "Get DomainUser with PowerShell Script Block" -excerpt: "Domain Account -, Account Discovery -" -categories: - - Endpoint -last_modified_at: 2021-08-24 -toc: true -toc_label: "" -tags: - - Domain Account - - Account Discovery - - Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-DomainUser` commandlet. `GetDomainUser` is part of PowerView, a PowerShell tool used to perform enumeration on Windows domains. Red Teams and adversaries alike may use PowerView to enumerate domain users for situational awareness and Active Directory Discovery. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-08-24 -- **Author**: Teoderick Contreras, Mauricio Velazco, Splunk -- **ID**: 61994268-04f4-11ec-865c-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery | - -| [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 Message = "*Get-DomainUser*" -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `get_domainuser_with_powershell_script_block_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -Note that **get_domainuser_with_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Message -* ComputerName -* User - - -#### How To Implement -The following Hunting analytic requires PowerShell operational logs to be imported. Modify the powershell macro as needed to match the sourcetype or add index. This analytic is specific to 4104, or PowerShell Script Block Logging. - -#### Known False Positives -Administrators or power users may use this command for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | powershell process having commandline $Message$ for user enumeration | - - -#### Reference - -* [https://powersploit.readthedocs.io/en/latest/Recon/Get-DomainUser/](https://powersploit.readthedocs.io/en/latest/Recon/Get-DomainUser/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/AD_discovery/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/AD_discovery/windows-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-24-getwmiobject_ds_user_with_powershell.md b/docs/_posts/2021-08-24-getwmiobject_ds_user_with_powershell.md deleted file mode 100644 index 12ffa406ce..0000000000 --- a/docs/_posts/2021-08-24-getwmiobject_ds_user_with_powershell.md +++ /dev/null @@ -1,165 +0,0 @@ ---- -title: "GetWmiObject DS User with PowerShell" -excerpt: "Domain Account -, Account Discovery -" -categories: - - Endpoint -last_modified_at: 2021-08-24 -toc: true -toc_label: "" -tags: - - Domain Account - - Account Discovery - - Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for the execution of `powershell.exe` with command-line arguments utilized to query for domain users. The `Get-WmiObject` commandlet combined with the `-class ds_user` parameter can be used to return the full list of users in a Windows domain. Red Teams and adversaries alike may leverage WMI in this case, using PowerShell, to enumerate domain users for situational awareness and Active Directory Discovery. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-08-24 -- **Author**: Teoderick Contreras, Mauricio Velazco, Splunk -- **ID**: 22d3b118-04df-11ec-8fa3-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery | - -| [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="cmd.exe" OR Processes.process_name="powershell*") AND Processes.process = "*get-wmiobject*" AND Processes.process = "*ds_user*" AND Processes.process = "*root\\directory\\ldap*" AND Processes.process = "*-namespace*" by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `getwmiobject_ds_user_with_powershell_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **getwmiobject_ds_user_with_powershell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id -* Processes.parent_process_name - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -Administrators or power users may use this command for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | an instance of process $process_name$ with commandline $process$ in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://jpcertcc.github.io/ToolAnalysisResultSheet/details/dsquery.htm](https://jpcertcc.github.io/ToolAnalysisResultSheet/details/dsquery.htm) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/AD_discovery/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/AD_discovery/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-24-getwmiobject_ds_user_with_powershell_script_block.md b/docs/_posts/2021-08-24-getwmiobject_ds_user_with_powershell_script_block.md deleted file mode 100644 index c090f4f54a..0000000000 --- a/docs/_posts/2021-08-24-getwmiobject_ds_user_with_powershell_script_block.md +++ /dev/null @@ -1,160 +0,0 @@ ---- -title: "GetWmiObject DS User with PowerShell Script Block" -excerpt: "Domain Account -, Account Discovery -" -categories: - - Endpoint -last_modified_at: 2021-08-24 -toc: true -toc_label: "" -tags: - - Domain Account - - Account Discovery - - Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-WmiObject` commandlet. The `DS_User` class parameter leverages WMI to query for all domain users. Red Teams and adversaries may leverage this commandlet to enumerate domain users for situational awareness and Active Directory Discovery. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-08-24 -- **Author**: Teoderick Contreras, Mauricio Velazco, Splunk -- **ID**: fabd364e-04f3-11ec-b34b-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery | - -| [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 Message = "*get-wmiobject*" Message = "*ds_user*" Message = "*-namespace*" Message = "*root\\directory\\ldap*" -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `getwmiobject_ds_user_with_powershell_script_block_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **getwmiobject_ds_user_with_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Message -* ComputerName -* User - - -#### How To Implement -he following Hunting analytic requires PowerShell operational logs to be imported. Modify the powershell macro as needed to match the sourcetype or add index. This analytic is specific to 4104, or PowerShell Script Block Logging. - -#### Known False Positives -Administrators or power users may use this command for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | powershell process having commandline $Message$ for user enumeration | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.blackhillsinfosec.com/red-blue-purple/](https://www.blackhillsinfosec.com/red-blue-purple/) -* [https://docs.microsoft.com/en-us/windows/win32/wmisdk/describing-the-ldap-namespace](https://docs.microsoft.com/en-us/windows/win32/wmisdk/describing-the-ldap-namespace) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/AD_discovery/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/AD_discovery/windows-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-24-kubernetes_scanner_image_pulling.md b/docs/_posts/2021-08-24-kubernetes_scanner_image_pulling.md deleted file mode 100644 index d63185fdba..0000000000 --- a/docs/_posts/2021-08-24-kubernetes_scanner_image_pulling.md +++ /dev/null @@ -1,167 +0,0 @@ ---- -title: "Kubernetes Scanner Image Pulling" -excerpt: "Cloud Service Discovery -" -categories: - - Cloud -last_modified_at: 2021-08-24 -toc: true -toc_label: "" -tags: - - Cloud Service Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search uses the Kubernetes logs from Splunk Connect from Kubernetes to detect Kubernetes Security Scanner. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-08-24 -- **Author**: Patrick Bareiss, Splunk -- **ID**: 4890cd6b-0112-4974-a272-c5c153aee551 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1526](https://attack.mitre.org/techniques/T1526/) | Cloud Service Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.DS -* PR.AC -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 13 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`kube_objects_events` object.message IN ("Pulling image *kube-hunter*", "Pulling image *kube-bench*", "Pulling image *kube-recon*", "Pulling image *kube-recon*") -| rename object.* AS * -| rename involvedObject.* AS * -| rename source.host AS host -| eval phase="operate" -| eval severity="high" -| stats min(_time) as firstTime max(_time) as lastTime count by host, name, namespace, kind, reason, message, phase, severity -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `kubernetes_scanner_image_pulling_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [kube_objects_events](https://github.com/splunk/security_content/blob/develop/macros/kube_objects_events.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **kubernetes_scanner_image_pulling_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* object.message -* source.host -* object.involvedObject.name -* object.involvedObject.namespace -* object.involvedObject.kind -* object.message -* object.reason - - -#### How To Implement -You must ingest Kubernetes logs through Splunk Connect for Kubernetes. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Dev Sec Ops](/stories/dev_sec_ops) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 81.0 | 90 | 90 | Kubernetes Scanner image pulled on host $host$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/splunk/splunk-connect-for-kubernetes](https://github.com/splunk/splunk-connect-for-kubernetes) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1526/kubernetes_kube_hunter/kubernetes_kube_hunter.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1526/kubernetes_kube_hunter/kubernetes_kube_hunter.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/kubernetes_scanner_image_pulling.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-25-domain_group_discovery_with_adsisearcher.md b/docs/_posts/2021-08-25-domain_group_discovery_with_adsisearcher.md deleted file mode 100644 index 1d73972dff..0000000000 --- a/docs/_posts/2021-08-25-domain_group_discovery_with_adsisearcher.md +++ /dev/null @@ -1,159 +0,0 @@ ---- -title: "Domain Group Discovery with Adsisearcher" -excerpt: "Permission Groups Discovery -, Domain Groups -" -categories: - - Endpoint -last_modified_at: 2021-08-25 -toc: true -toc_label: "" -tags: - - Permission Groups Discovery - - Domain Groups - - Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the `[Adsisearcher]` type accelerator being used to query Active Directory for domain groups. Red Teams and adversaries may leverage `[Adsisearcher]` to enumerate domain groups for situational awareness and Active Directory Discovery. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-08-25 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 089c862f-5f83-49b5-b1c8-7e4ff66560c7 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | - -| [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 (Message = "*[adsisearcher]*" AND Message = "*(objectcategory=group)*" AND Message = "*findAll()*") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `domain_group_discovery_with_adsisearcher_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **domain_group_discovery_with_adsisearcher_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Message -* ComputerName -* User - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -Administrators or power users may use Adsisearcher for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 18.0 | 30 | 60 | Domain group discovery enumeration using PowerShell on $dest$ by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1069/002/](https://attack.mitre.org/techniques/T1069/002/) -* [https://devblogs.microsoft.com/scripting/use-the-powershell-adsisearcher-type-accelerator-to-search-active-directory/](https://devblogs.microsoft.com/scripting/use-the-powershell-adsisearcher-type-accelerator-to-search-active-directory/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.002/AD_discovery/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.002/AD_discovery/windows-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-25-domain_group_discovery_with_net.md b/docs/_posts/2021-08-25-domain_group_discovery_with_net.md deleted file mode 100644 index aa06e4111a..0000000000 --- a/docs/_posts/2021-08-25-domain_group_discovery_with_net.md +++ /dev/null @@ -1,167 +0,0 @@ ---- -title: "Domain Group Discovery With Net" -excerpt: "Permission Groups Discovery -, Domain Groups -" -categories: - - Endpoint -last_modified_at: 2021-08-25 -toc: true -toc_label: "" -tags: - - Permission Groups Discovery - - Domain Groups - - Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for the execution of `net.exe` with command-line arguments utilized to query for domain groups. The argument `group /domain`, returns a list of all domain groups. Red Teams and adversaries alike use net.exe to enumerate domain groups for situational awareness and Active Directory Discovery. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-08-25 -- **Author**: Mauricio Velazco, Splunk -- **ID**: f2f14ac7-fa81-471a-80d5-7eb65c3c7349 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | - -| [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="net.exe" OR Processes.process_name="net1.exe") (Processes.process=*group* AND Processes.process=*/do*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `domain_group_discovery_with_net_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **domain_group_discovery_with_net_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Administrators or power users may use this command for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | Domain group discovery enumeration on $dest$ by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1069/002/](https://attack.mitre.org/techniques/T1069/002/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.002/AD_discovery/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.002/AD_discovery/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/domain_group_discovery_with_net.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-25-domain_group_discovery_with_wmic.md b/docs/_posts/2021-08-25-domain_group_discovery_with_wmic.md deleted file mode 100644 index 53315ed956..0000000000 --- a/docs/_posts/2021-08-25-domain_group_discovery_with_wmic.md +++ /dev/null @@ -1,167 +0,0 @@ ---- -title: "Domain Group Discovery With Wmic" -excerpt: "Permission Groups Discovery -, Domain Groups -" -categories: - - Endpoint -last_modified_at: 2021-08-25 -toc: true -toc_label: "" -tags: - - Permission Groups Discovery - - Domain Groups - - Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for the execution of `wmic.exe` with command-line arguments utilized to query for domain groups. The arguments utilized in this command return a list of all domain groups. Red Teams and adversaries alike use wmic.exe to enumerate domain groups for situational awareness and Active Directory Discovery. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-08-25 -- **Author**: Mauricio Velazco, Splunk -- **ID**: a87736a6-95cd-4728-8689-3c64d5026b3e - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | - -| [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="wmic.exe") (Processes.process=*/NAMESPACE:\\\\root\\directory\\ldap* AND Processes.process=*ds_group* AND Processes.process="*GET ds_samaccountname*") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `domain_group_discovery_with_wmic_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **domain_group_discovery_with_wmic_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Administrators or power users may use this command for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | Domain group discovery enumeration on $dest$ by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1069/002/](https://attack.mitre.org/techniques/T1069/002/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.002/AD_discovery/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.002/AD_discovery/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/domain_group_discovery_with_wmic.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-25-elevated_group_discovery_with_net.md b/docs/_posts/2021-08-25-elevated_group_discovery_with_net.md deleted file mode 100644 index eb3df3262c..0000000000 --- a/docs/_posts/2021-08-25-elevated_group_discovery_with_net.md +++ /dev/null @@ -1,169 +0,0 @@ ---- -title: "Elevated Group Discovery With Net" -excerpt: "Permission Groups Discovery -, Domain Groups -" -categories: - - Endpoint -last_modified_at: 2021-08-25 -toc: true -toc_label: "" -tags: - - Permission Groups Discovery - - Domain Groups - - Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for the execution of `net.exe` or `net1.exe` with command-line arguments utilized to query for specific elevated domain groups. Red Teams and adversaries alike use net.exe to enumerate elevated domain groups for situational awareness and Active Directory Discovery to identify high privileged users. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-08-25 -- **Author**: Mauricio Velazco, Splunk -- **ID**: a23a0e20-0b1b-4a07-82e5-ec5f70811e7a - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | - -| [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="net.exe" OR Processes.process_name="net1.exe") (Processes.process="*group*" AND Processes.process="*/do*") (Processes.process="*Domain Admins*" OR Processes.process="*Enterprise Admins*" OR Processes.process="*Schema Admins*" OR Processes.process="*Account Operators*" OR Processes.process="*Server Operators*" OR Processes.process="*Protected Users*" OR Processes.process="*Dns Admins*") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `elevated_group_discovery_with_net_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **elevated_group_discovery_with_net_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Administrators or power users may use this command for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 21.0 | 30 | 70 | Elevated domain group discovery enumeration on $dest$ by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1069/002/](https://attack.mitre.org/techniques/T1069/002/) -* [https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/plan/security-best-practices/appendix-b--privileged-accounts-and-groups-in-active-directory](https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/plan/security-best-practices/appendix-b--privileged-accounts-and-groups-in-active-directory) -* [https://adsecurity.org/?p=3658](https://adsecurity.org/?p=3658) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.002/AD_discovery/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.002/AD_discovery/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/elevated_group_discovery_with_net.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-25-elevated_group_discovery_with_powerview.md b/docs/_posts/2021-08-25-elevated_group_discovery_with_powerview.md deleted file mode 100644 index 98c721908f..0000000000 --- a/docs/_posts/2021-08-25-elevated_group_discovery_with_powerview.md +++ /dev/null @@ -1,161 +0,0 @@ ---- -title: "Elevated Group Discovery with PowerView" -excerpt: "Permission Groups Discovery -, Domain Groups -" -categories: - - Endpoint -last_modified_at: 2021-08-25 -toc: true -toc_label: "" -tags: - - Permission Groups Discovery - - Domain Groups - - Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-DomainGroupMember` commandlet. `Get-DomainGroupMember` is part of PowerView, a PowerShell tool used to perform enumeration on Windows domains. As the name suggests, `Get-DomainGroupMember` is used to list the members of an specific domain group. Red Teams and adversaries alike use PowerView to enumerate elevated domain groups for situational awareness and Active Directory Discovery to identify high privileged users. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-08-25 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 10d62950-0de5-4199-a710-cff9ea79b413 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | - -| [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 (Message = "*Get-DomainGroupMember*") AND Message IN ("*Domain Admins*","*Enterprise Admins*", "*Schema Admins*", "*Account Operators*" , "*Server Operators*", "*Protected Users*", "*Dns Admins*") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `elevated_group_discovery_with_powerview_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **elevated_group_discovery_with_powerview_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Message -* ComputerName -* User - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -Administrators or power users may use this PowerView for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 21.0 | 30 | 70 | Elevated group discovery using PowerView on $dest$ by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1069/002/](https://attack.mitre.org/techniques/T1069/002/) -* [https://powersploit.readthedocs.io/en/latest/Recon/Get-DomainGroupMember/](https://powersploit.readthedocs.io/en/latest/Recon/Get-DomainGroupMember/) -* [https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/plan/security-best-practices/appendix-b--privileged-accounts-and-groups-in-active-directory](https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/plan/security-best-practices/appendix-b--privileged-accounts-and-groups-in-active-directory) -* [https://attack.mitre.org/techniques/T1069/002/](https://attack.mitre.org/techniques/T1069/002/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.002/AD_discovery/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.002/AD_discovery/windows-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-25-elevated_group_discovery_with_wmic.md b/docs/_posts/2021-08-25-elevated_group_discovery_with_wmic.md deleted file mode 100644 index 289891f3b1..0000000000 --- a/docs/_posts/2021-08-25-elevated_group_discovery_with_wmic.md +++ /dev/null @@ -1,169 +0,0 @@ ---- -title: "Elevated Group Discovery With Wmic" -excerpt: "Permission Groups Discovery -, Domain Groups -" -categories: - - Endpoint -last_modified_at: 2021-08-25 -toc: true -toc_label: "" -tags: - - Permission Groups Discovery - - Domain Groups - - Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for the execution of `wmic.exe` with command-line arguments utilized to query for specific domain groups. Red Teams and adversaries alike use net.exe to enumerate elevated domain groups for situational awareness and Active Directory Discovery to identify high privileged users. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-08-25 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 3f6bbf22-093e-4cb4-9641-83f47b8444b6 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | - -| [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="wmic.exe") (Processes.process=*/NAMESPACE:\\\\root\\directory\\ldap*) (Processes.process="*Domain Admins*" OR Processes.process="*Enterprise Admins*" OR Processes.process="*Schema Admins*" OR Processes.process="*Account Operators*" OR Processes.process="*Server Operators*" OR Processes.process="*Protected Users*" OR Processes.process="*Dns Admins*") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `elevated_group_discovery_with_wmic_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **elevated_group_discovery_with_wmic_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Administrators or power users may use this command for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 21.0 | 30 | 70 | Elevated domain group discovery enumeration on $dest$ by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1069/002/](https://attack.mitre.org/techniques/T1069/002/) -* [https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/plan/security-best-practices/appendix-b--privileged-accounts-and-groups-in-active-directory](https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/plan/security-best-practices/appendix-b--privileged-accounts-and-groups-in-active-directory) -* [https://adsecurity.org/?p=3658](https://adsecurity.org/?p=3658) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.002/AD_discovery/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.002/AD_discovery/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-25-getadgroup_with_powershell.md b/docs/_posts/2021-08-25-getadgroup_with_powershell.md deleted file mode 100644 index 78d29754ca..0000000000 --- a/docs/_posts/2021-08-25-getadgroup_with_powershell.md +++ /dev/null @@ -1,168 +0,0 @@ ---- -title: "GetAdGroup with PowerShell" -excerpt: "Permission Groups Discovery -, Domain Groups -" -categories: - - Endpoint -last_modified_at: 2021-08-25 -toc: true -toc_label: "" -tags: - - Permission Groups Discovery - - Domain Groups - - Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for the execution of `powershell.exe` with command-line arguments utilized to query for domain groups. The `Get-AdGroup` commandlnet is used to return a list of all groups available in a Windows Domain. Red Teams and adversaries alike may leverage this commandlet to enumerate domain groups for situational awareness and Active Directory Discovery. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-08-25 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 872e3063-0fc4-4e68-b2f3-f2b99184a708 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | - -| [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="powershell.exe") (Processes.process=*Get-AdGroup*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `getadgroup_with_powershell_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **getadgroup_with_powershell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Administrators or power users may use this command for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | Domain group discovery enumeration on $dest$ by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1069/002/](https://attack.mitre.org/techniques/T1069/002/) -* [https://docs.microsoft.com/en-us/powershell/module/activedirectory/get-adgroup?view=windowsserver2019-ps](https://docs.microsoft.com/en-us/powershell/module/activedirectory/get-adgroup?view=windowsserver2019-ps) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.002/AD_discovery/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.002/AD_discovery/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/getadgroup_with_powershell.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-25-getadgroup_with_powershell_script_block.md b/docs/_posts/2021-08-25-getadgroup_with_powershell_script_block.md deleted file mode 100644 index 6bce78d975..0000000000 --- a/docs/_posts/2021-08-25-getadgroup_with_powershell_script_block.md +++ /dev/null @@ -1,155 +0,0 @@ ---- -title: "GetAdGroup with PowerShell Script Block" -excerpt: "Permission Groups Discovery -, Domain Groups -" -categories: - - Endpoint -last_modified_at: 2021-08-25 -toc: true -toc_label: "" -tags: - - Permission Groups Discovery - - Domain Groups - - Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-AdGroup` commandlet. The `Get-AdGroup` commandlet is used to return a list of all domain groups. Red Teams and adversaries may leverage this commandlet to enumerate domain groups for situational awareness and Active Directory Discovery. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-08-25 -- **Author**: Mauricio Velazco, Splunk -- **ID**: e4c73d68-794b-468d-b4d0-dac1772bbae7 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | - -| [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 (Message = "*Get-ADGroup*") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `getadgroup_with_powershell_script_block_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -Note that **getadgroup_with_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Message -* ComputerName -* User - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -Administrators or power users may use this PowerShell commandlet for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | Domain group discovery enumeration using PowerShell on $dest$ by $user$ | - - -#### Reference - -* [https://attack.mitre.org/techniques/T1069/002/](https://attack.mitre.org/techniques/T1069/002/) -* [https://docs.microsoft.com/en-us/powershell/module/activedirectory/get-adgroup?view=windowsserver2019-ps](https://docs.microsoft.com/en-us/powershell/module/activedirectory/get-adgroup?view=windowsserver2019-ps) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.002/AD_discovery/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.002/AD_discovery/windows-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-25-getdomaingroup_with_powershell.md b/docs/_posts/2021-08-25-getdomaingroup_with_powershell.md deleted file mode 100644 index bd53c4c7a6..0000000000 --- a/docs/_posts/2021-08-25-getdomaingroup_with_powershell.md +++ /dev/null @@ -1,168 +0,0 @@ ---- -title: "GetDomainGroup with PowerShell" -excerpt: "Permission Groups Discovery -, Domain Groups -" -categories: - - Endpoint -last_modified_at: 2021-08-25 -toc: true -toc_label: "" -tags: - - Permission Groups Discovery - - Domain Groups - - Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for the execution of `powershell.exe` with command-line arguments utilized to query for domain groups. `Get-DomainGroup` is part of PowerView, a PowerShell tool used to perform enumeration on Windows domains. Red Teams and adversaries alike may leverage PowerView to enumerate domain groups for situational awareness and Active Directory Discovery. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-08-25 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 93c94be3-bead-4a60-860f-77ca3fe59903 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | - -| [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="powershell.exe") (Processes.process=*Get-DomainGroup*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `getdomaingroup_with_powershell_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **getdomaingroup_with_powershell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Administrators or power users may use this command for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | Domain group discovery with PowerView on $dest$ by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1069/002/](https://attack.mitre.org/techniques/T1069/002/) -* [https://powersploit.readthedocs.io/en/latest/Recon/Get-DomainGroup/](https://powersploit.readthedocs.io/en/latest/Recon/Get-DomainGroup/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.002/AD_discovery/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.002/AD_discovery/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/getdomaingroup_with_powershell.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-25-getnettcpconnection_with_powershell.md b/docs/_posts/2021-08-25-getnettcpconnection_with_powershell.md deleted file mode 100644 index ad340cae7a..0000000000 --- a/docs/_posts/2021-08-25-getnettcpconnection_with_powershell.md +++ /dev/null @@ -1,163 +0,0 @@ ---- -title: "GetNetTcpconnection with PowerShell" -excerpt: "System Network Connections Discovery -" -categories: - - Endpoint -last_modified_at: 2021-08-25 -toc: true -toc_label: "" -tags: - - System Network Connections Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for the execution of `powershell.exe` with command-line utilized to get a listing of network connections on a compromised system. The `Get-NetTcpConnection` commandlet lists the current TCP connections. Red Teams and adversaries alike may use this commandlet for situational awareness and Active Directory Discovery. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-08-25 -- **Author**: Mauricio Velazco, Splunk -- **ID**: e02af35c-1de5-4afe-b4be-f45aba57272b - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1049](https://attack.mitre.org/techniques/T1049/) | System Network Connections Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="powershell.exe") (Processes.process=*Get-NetTcpConnection*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `getnettcpconnection_with_powershell_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **getnettcpconnection_with_powershell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Administrators or power users may use this command for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | Network Connection discovery on $dest$ by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1049/](https://attack.mitre.org/techniques/T1049/) -* [https://docs.microsoft.com/en-us/powershell/module/nettcpip/get-nettcpconnection?view=windowsserver2019-ps](https://docs.microsoft.com/en-us/powershell/module/nettcpip/get-nettcpconnection?view=windowsserver2019-ps) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1049/AD_discovery/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1049/AD_discovery/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/getnettcpconnection_with_powershell.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-25-getwmiobject_ds_group_with_powershell.md b/docs/_posts/2021-08-25-getwmiobject_ds_group_with_powershell.md deleted file mode 100644 index 4ec21d1676..0000000000 --- a/docs/_posts/2021-08-25-getwmiobject_ds_group_with_powershell.md +++ /dev/null @@ -1,168 +0,0 @@ ---- -title: "GetWmiObject Ds Group with PowerShell" -excerpt: "Permission Groups Discovery -, Domain Groups -" -categories: - - Endpoint -last_modified_at: 2021-08-25 -toc: true -toc_label: "" -tags: - - Permission Groups Discovery - - Domain Groups - - Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for the execution of `powershell.exe` with command-line arguments utilized to query for domain groups. The `Get-WmiObject` commandlet combined with the `-class ds_group` parameter can be used to return the full list of groups in a Windows domain. Red Teams and adversaries alike may leverage WMI in this case, using PowerShell, to enumerate domain groups for situational awareness and Active Directory Discovery. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-08-25 -- **Author**: Mauricio Velazco, Splunk -- **ID**: df275a44-4527-443b-b884-7600e066e3eb - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | - -| [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="powershell.exe") (Processes.process=*Get-WmiObject* AND Processes.process="*namespace root\\directory\\ldap*" AND Processes.process="*class ds_group*") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `getwmiobject_ds_group_with_powershell_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **getwmiobject_ds_group_with_powershell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Administrators or power users may use this command for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | Domain group discovery enumeration on $dest$ by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1069/002/](https://attack.mitre.org/techniques/T1069/002/) -* [https://docs.microsoft.com/en-us/powershell/module/microsoft.powershell.management/get-wmiobject?view=powershell-5.1](https://docs.microsoft.com/en-us/powershell/module/microsoft.powershell.management/get-wmiobject?view=powershell-5.1) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.002/AD_discovery/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.002/AD_discovery/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-25-getwmiobject_ds_group_with_powershell_script_block.md b/docs/_posts/2021-08-25-getwmiobject_ds_group_with_powershell_script_block.md deleted file mode 100644 index 52ea5b8660..0000000000 --- a/docs/_posts/2021-08-25-getwmiobject_ds_group_with_powershell_script_block.md +++ /dev/null @@ -1,159 +0,0 @@ ---- -title: "GetWmiObject Ds Group with PowerShell Script Block" -excerpt: "Permission Groups Discovery -, Domain Groups -" -categories: - - Endpoint -last_modified_at: 2021-08-25 -toc: true -toc_label: "" -tags: - - Permission Groups Discovery - - Domain Groups - - Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-WmiObject` commandlet used with specific parameters . The `DS_Group` parameter leverages WMI to query for all domain groups. Red Teams and adversaries may leverage this commandlet to enumerate domain groups for situational awareness and Active Directory Discovery. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-08-25 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 67740bd3-1506-469c-b91d-effc322cc6e5 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | - -| [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 (Message=*Get-WmiObject* AND Message="*namespace root\\directory\\ldap*" AND Message="*class ds_group*") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `getwmiobject_ds_group_with_powershell_script_block_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **getwmiobject_ds_group_with_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Message -* ComputerName -* User - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -Administrators or power users may use this PowerShell commandlet for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | Domain group discovery enumeration using PowerShell on $dest$ by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1069/002/](https://attack.mitre.org/techniques/T1069/002/) -* [https://docs.microsoft.com/en-us/powershell/module/microsoft.powershell.management/get-wmiobject?view=powershell-5.1](https://docs.microsoft.com/en-us/powershell/module/microsoft.powershell.management/get-wmiobject?view=powershell-5.1) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.002/AD_discovery/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.002/AD_discovery/windows-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-26-get_addefaultdomainpasswordpolicy_with_powershell.md b/docs/_posts/2021-08-26-get_addefaultdomainpasswordpolicy_with_powershell.md deleted file mode 100644 index b95ef0b2e8..0000000000 --- a/docs/_posts/2021-08-26-get_addefaultdomainpasswordpolicy_with_powershell.md +++ /dev/null @@ -1,162 +0,0 @@ ---- -title: "Get ADDefaultDomainPasswordPolicy with Powershell" -excerpt: "Password Policy Discovery -" -categories: - - Endpoint -last_modified_at: 2021-08-26 -toc: true -toc_label: "" -tags: - - Password Policy Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for the execution of `powershell.exe` executing the Get-ADDefaultDomainPasswordPolicy commandlet used to obtain the password policy in a Windows domain. Red Teams and adversaries alike may use PowerShell to enumerate domain policies for situational awareness and Active Directory Discovery. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-08-26 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 36e46ebe-065a-11ec-b4c7-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1201](https://attack.mitre.org/techniques/T1201/) | Password Policy Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="cmd.exe" OR Processes.process_name="powershell*") AND Processes.process = "*Get-ADDefaultDomainPasswordPolicy*" by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `get_addefaultdomainpasswordpolicy_with_powershell_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **get_addefaultdomainpasswordpolicy_with_powershell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id -* Processes.parent_process_name - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed rundll32.exe may be used. - -#### Known False Positives -Administrators or power users may use this command for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 9.0 | 30 | 30 | an instance of process $process_name$ with commandline $process$ in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/S1ckB0y1337/Active-Directory-Exploitation-Cheat-Sheet](https://github.com/S1ckB0y1337/Active-Directory-Exploitation-Cheat-Sheet) -* [https://attack.mitre.org/techniques/T1201/](https://attack.mitre.org/techniques/T1201/) -* [https://docs.microsoft.com/en-us/powershell/module/activedirectory/get-addefaultdomainpasswordpolicy?view=windowsserver2019-ps](https://docs.microsoft.com/en-us/powershell/module/activedirectory/get-addefaultdomainpasswordpolicy?view=windowsserver2019-ps) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1201/pwd_policy_discovery/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1201/pwd_policy_discovery/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-26-get_addefaultdomainpasswordpolicy_with_powershell_script_block.md b/docs/_posts/2021-08-26-get_addefaultdomainpasswordpolicy_with_powershell_script_block.md deleted file mode 100644 index 7304dc73dd..0000000000 --- a/docs/_posts/2021-08-26-get_addefaultdomainpasswordpolicy_with_powershell_script_block.md +++ /dev/null @@ -1,152 +0,0 @@ ---- -title: "Get ADDefaultDomainPasswordPolicy with Powershell Script Block" -excerpt: "Password Policy Discovery -" -categories: - - Endpoint -last_modified_at: 2021-08-26 -toc: true -toc_label: "" -tags: - - Password Policy Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-ADDefaultDomainPasswordPolicy` commandlet used to obtain the password policy in a Windows domain. Red Teams and adversaries alike may use PowerShell to enumerate domain policies for situational awareness and Active Directory Discovery. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-08-26 -- **Author**: Teoderick Contreras, Mauricio Velazco, Splunk -- **ID**: 1ff7ccc8-065a-11ec-91e4-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1201](https://attack.mitre.org/techniques/T1201/) | Password Policy Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 Message ="*Get-ADDefaultDomainPasswordPolicy*" -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `get_addefaultdomainpasswordpolicy_with_powershell_script_block_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -Note that **get_addefaultdomainpasswordpolicy_with_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Message -* ComputerName -* User - - -#### How To Implement -The following Hunting analytic requires PowerShell operational logs to be imported. Modify the powershell macro as needed to match the sourcetype or add index. This analytic is specific to 4104, or PowerShell Script Block Logging. - -#### Known False Positives -Administrators or power users may use this command for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 9.0 | 30 | 30 | powershell process having commandline $Message$ to query domain password policy | - - -#### Reference - -* [https://github.com/S1ckB0y1337/Active-Directory-Exploitation-Cheat-Sheet](https://github.com/S1ckB0y1337/Active-Directory-Exploitation-Cheat-Sheet) -* [https://attack.mitre.org/techniques/T1201/](https://attack.mitre.org/techniques/T1201/) -* [https://docs.microsoft.com/en-us/powershell/module/activedirectory/get-addefaultdomainpasswordpolicy?view=windowsserver2019-ps](https://docs.microsoft.com/en-us/powershell/module/activedirectory/get-addefaultdomainpasswordpolicy?view=windowsserver2019-ps) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1201/pwd_policy_discovery/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1201/pwd_policy_discovery/windows-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-26-get_aduserresultantpasswordpolicy_with_powershell.md b/docs/_posts/2021-08-26-get_aduserresultantpasswordpolicy_with_powershell.md deleted file mode 100644 index 2e9ec509b7..0000000000 --- a/docs/_posts/2021-08-26-get_aduserresultantpasswordpolicy_with_powershell.md +++ /dev/null @@ -1,162 +0,0 @@ ---- -title: "Get ADUserResultantPasswordPolicy with Powershell" -excerpt: "Password Policy Discovery -" -categories: - - Endpoint -last_modified_at: 2021-08-26 -toc: true -toc_label: "" -tags: - - Password Policy Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for the execution of `powershell.exe` executing the Get ADUserResultantPasswordPolicy commandlet used to obtain the password policy in a Windows domain. Red Teams and adversaries alike may use PowerShell to enumerate domain policies for situational awareness and Active Directory Discovery. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-08-26 -- **Author**: Teoderick Contreras, Mauricio Velazco, Splunk -- **ID**: 8b5ef342-065a-11ec-b0fc-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1201](https://attack.mitre.org/techniques/T1201/) | Password Policy Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="cmd.exe" OR Processes.process_name="powershell*") AND Processes.process = "*Get-ADUserResultantPasswordPolicy*" by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `get_aduserresultantpasswordpolicy_with_powershell_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **get_aduserresultantpasswordpolicy_with_powershell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id -* Processes.parent_process_name - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed rundll32.exe may be used. - -#### Known False Positives -Administrators or power users may use this command for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | an instance of process $process_name$ with commandline $process$ in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/S1ckB0y1337/Active-Directory-Exploitation-Cheat-Sheet](https://github.com/S1ckB0y1337/Active-Directory-Exploitation-Cheat-Sheet) -* [https://attack.mitre.org/techniques/T1201/](https://attack.mitre.org/techniques/T1201/) -* [https://docs.microsoft.com/en-us/powershell/module/activedirectory/get-aduserresultantpasswordpolicy?view=windowsserver2019-ps](https://docs.microsoft.com/en-us/powershell/module/activedirectory/get-aduserresultantpasswordpolicy?view=windowsserver2019-ps) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1201/pwd_policy_discovery/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1201/pwd_policy_discovery/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-26-get_aduserresultantpasswordpolicy_with_powershell_script_block.md b/docs/_posts/2021-08-26-get_aduserresultantpasswordpolicy_with_powershell_script_block.md deleted file mode 100644 index ff79a04102..0000000000 --- a/docs/_posts/2021-08-26-get_aduserresultantpasswordpolicy_with_powershell_script_block.md +++ /dev/null @@ -1,156 +0,0 @@ ---- -title: "Get ADUserResultantPasswordPolicy with Powershell Script Block" -excerpt: "Password Policy Discovery -" -categories: - - Endpoint -last_modified_at: 2021-08-26 -toc: true -toc_label: "" -tags: - - Password Policy Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-ADUserResultantPasswordPolicy` commandlet used to obtain the password policy in a Windows domain. Red Teams and adversaries alike may use PowerShell to enumerate domain policies for situational awareness and Active Directory Discovery. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-08-26 -- **Author**: Teoderick Contreras, MAuricio Velazco, Splunk -- **ID**: 737e1eb0-065a-11ec-921a-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1201](https://attack.mitre.org/techniques/T1201/) | Password Policy Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 Message ="*Get-ADUserResultantPasswordPolicy*" -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `get_aduserresultantpasswordpolicy_with_powershell_script_block_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **get_aduserresultantpasswordpolicy_with_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Message -* ComputerName -* User - - -#### How To Implement -The following Hunting analytic requires PowerShell operational logs to be imported. Modify the powershell macro as needed to match the sourcetype or add index. This analytic is specific to 4104, or PowerShell Script Block Logging. - -#### Known False Positives -Administrators or power users may use this command for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 9.0 | 30 | 30 | powershell process having commandline $Message$ to query domain user password policy. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/S1ckB0y1337/Active-Directory-Exploitation-Cheat-Sheet](https://github.com/S1ckB0y1337/Active-Directory-Exploitation-Cheat-Sheet) -* [https://attack.mitre.org/techniques/T1201/](https://attack.mitre.org/techniques/T1201/) -* [https://docs.microsoft.com/en-us/powershell/module/activedirectory/get-aduserresultantpasswordpolicy?view=windowsserver2019-ps](https://docs.microsoft.com/en-us/powershell/module/activedirectory/get-aduserresultantpasswordpolicy?view=windowsserver2019-ps) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1201/pwd_policy_discovery/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1201/pwd_policy_discovery/windows-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-26-get_domainpolicy_with_powershell.md b/docs/_posts/2021-08-26-get_domainpolicy_with_powershell.md deleted file mode 100644 index 68210802d9..0000000000 --- a/docs/_posts/2021-08-26-get_domainpolicy_with_powershell.md +++ /dev/null @@ -1,162 +0,0 @@ ---- -title: "Get DomainPolicy with Powershell" -excerpt: "Password Policy Discovery -" -categories: - - Endpoint -last_modified_at: 2021-08-26 -toc: true -toc_label: "" -tags: - - Password Policy Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for the execution of `powershell.exe` executing the `Get-DomainPolicy` commandlet used to obtain the password policy in a Windows domain. Red Teams and adversaries alike may use PowerShell to enumerate domain policies for situational awareness and Active Directory Discovery. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-08-26 -- **Author**: Teoderick Contreras, Mauricio Velazco, Splunk -- **ID**: b8f9947e-065a-11ec-aafb-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1201](https://attack.mitre.org/techniques/T1201/) | Password Policy Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="cmd.exe" OR Processes.process_name="powershell*") AND Processes.process = "*Get-DomainPolicy*" by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `get_domainpolicy_with_powershell_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **get_domainpolicy_with_powershell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id -* Processes.parent_process_name - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed rundll32.exe may be used. - -#### Known False Positives -Administrators or power users may use this command for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 30.0 | 50 | 60 | an instance of process $process_name$ with commandline $process$ in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/S1ckB0y1337/Active-Directory-Exploitation-Cheat-Sheet](https://github.com/S1ckB0y1337/Active-Directory-Exploitation-Cheat-Sheet) -* [https://powersploit.readthedocs.io/en/latest/Recon/Get-DomainPolicy/](https://powersploit.readthedocs.io/en/latest/Recon/Get-DomainPolicy/) -* [https://attack.mitre.org/techniques/T1201/](https://attack.mitre.org/techniques/T1201/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1201/pwd_policy_discovery/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1201/pwd_policy_discovery/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/get_domainpolicy_with_powershell.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-26-get_domainpolicy_with_powershell_script_block.md b/docs/_posts/2021-08-26-get_domainpolicy_with_powershell_script_block.md deleted file mode 100644 index ee64ac4113..0000000000 --- a/docs/_posts/2021-08-26-get_domainpolicy_with_powershell_script_block.md +++ /dev/null @@ -1,156 +0,0 @@ ---- -title: "Get DomainPolicy with Powershell Script Block" -excerpt: "Password Policy Discovery -" -categories: - - Endpoint -last_modified_at: 2021-08-26 -toc: true -toc_label: "" -tags: - - Password Policy Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get DomainPolicy` commandlet used to obtain the password policy in a Windows domain. Red Teams and adversaries alike may use PowerShell to enumerate domain policies for situational awareness and Active Directory Discovery. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-08-26 -- **Author**: Teoderick Contreras, Splunk -- **ID**: a360d2b2-065a-11ec-b0bf-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1201](https://attack.mitre.org/techniques/T1201/) | Password Policy Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 Message ="*Get-DomainPolicy*" -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `get_domainpolicy_with_powershell_script_block_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **get_domainpolicy_with_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Message -* ComputerName -* User - - -#### How To Implement -The following Hunting analytic requires PowerShell operational logs to be imported. Modify the powershell macro as needed to match the sourcetype or add index. This analytic is specific to 4104, or PowerShell Script Block Logging. - -#### Known False Positives -Administrators or power users may use this command for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 30.0 | 50 | 60 | powershell process having commandline $Message$ to query domain policy. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/S1ckB0y1337/Active-Directory-Exploitation-Cheat-Sheet](https://github.com/S1ckB0y1337/Active-Directory-Exploitation-Cheat-Sheet) -* [https://powersploit.readthedocs.io/en/latest/Recon/Get-DomainPolicy/](https://powersploit.readthedocs.io/en/latest/Recon/Get-DomainPolicy/) -* [https://attack.mitre.org/techniques/T1201/](https://attack.mitre.org/techniques/T1201/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1201/pwd_policy_discovery/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1201/pwd_policy_discovery/windows-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-26-getdomaingroup_with_powershell_script_block.md b/docs/_posts/2021-08-26-getdomaingroup_with_powershell_script_block.md deleted file mode 100644 index 545ab393fc..0000000000 --- a/docs/_posts/2021-08-26-getdomaingroup_with_powershell_script_block.md +++ /dev/null @@ -1,159 +0,0 @@ ---- -title: "GetDomainGroup with PowerShell Script Block" -excerpt: "Permission Groups Discovery -, Domain Groups -" -categories: - - Endpoint -last_modified_at: 2021-08-26 -toc: true -toc_label: "" -tags: - - Permission Groups Discovery - - Domain Groups - - Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-DomainGroup` commandlet. `Get-DomainGroup` is part of PowerView, a PowerShell tool used to perform enumeration on Windows domains. As the name suggests, `Get-DomainGroup` is used to query domain groups. Red Teams and adversaries may leverage this function to enumerate domain groups for situational awareness and Active Directory Discovery. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-08-26 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 09725404-a44f-4ed3-9efa-8ed5d69e4c53 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | - -| [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 (Message = "*Get-DomainGroup*") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `getdomaingroup_with_powershell_script_block_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **getdomaingroup_with_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Message -* ComputerName -* User - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -Administrators or power users may use this PowerView functions for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | Domain group discovery enumeration using PowerView on $dest$ by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1069/002/](https://attack.mitre.org/techniques/T1069/002/) -* [https://powersploit.readthedocs.io/en/latest/Recon/Get-DomainGroup/](https://powersploit.readthedocs.io/en/latest/Recon/Get-DomainGroup/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.002/AD_discovery/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.002/AD_discovery/windows-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-26-password_policy_discovery_with_net.md b/docs/_posts/2021-08-26-password_policy_discovery_with_net.md deleted file mode 100644 index 7f195b6c3d..0000000000 --- a/docs/_posts/2021-08-26-password_policy_discovery_with_net.md +++ /dev/null @@ -1,160 +0,0 @@ ---- -title: "Password Policy Discovery with Net" -excerpt: "Password Policy Discovery -" -categories: - - Endpoint -last_modified_at: 2021-08-26 -toc: true -toc_label: "" -tags: - - Password Policy Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for the execution of `net.exe` or `net1.exe` with command line arguments used to obtain the domain password policy. Red Teams and adversaries may leverage `net.exe` for situational awareness and Active Directory Discovery. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-08-26 -- **Author**: Teoderick Contreras, Mauricio Velazco, Splunk -- **ID**: 09336538-065a-11ec-8665-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1201](https://attack.mitre.org/techniques/T1201/) | Password Policy Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="net.exe" OR Processes.process_name="net1.exe") AND Processes.process = "*accounts*" AND Processes.process = "*/domain*" by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `password_policy_discovery_with_net_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **password_policy_discovery_with_net_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id -* Processes.parent_process_name - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed rundll32.exe may be used. - -#### Known False Positives -Administrators or power users may use this command for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 9.0 | 30 | 30 | an instance of process $process_name$ with commandline $process$ in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/S1ckB0y1337/Active-Directory-Exploitation-Cheat-Sheet](https://github.com/S1ckB0y1337/Active-Directory-Exploitation-Cheat-Sheet) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1201/pwd_policy_discovery/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1201/pwd_policy_discovery/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/password_policy_discovery_with_net.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-26-process_creating_lnk_file_in_suspicious_location.md b/docs/_posts/2021-08-26-process_creating_lnk_file_in_suspicious_location.md deleted file mode 100644 index b15a922a25..0000000000 --- a/docs/_posts/2021-08-26-process_creating_lnk_file_in_suspicious_location.md +++ /dev/null @@ -1,179 +0,0 @@ ---- -title: "Process Creating LNK file in Suspicious Location" -excerpt: "Phishing -, Spearphishing Link -" -categories: - - Endpoint -last_modified_at: 2021-08-26 -toc: true -toc_label: "" -tags: - - Phishing - - Spearphishing Link - - Initial Access - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for a process launching an `*.lnk` file under `C:\User*` or `*\Local\Temp\*`. This is common behavior used by various spear phishing tools. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-08-26 -- **Author**: Jose Hernandez, Splunk -- **ID**: 5d814af1-1041-47b5-a9ac-d754e82e9a26 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | - -| [T1566.002](https://attack.mitre.org/techniques/T1566/002/) | Spearphishing Link | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Installation -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* ID.AM -* PR.DS - - - -
-
- -
- CIS20 - -
- -* CIS 7 -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_name="*.lnk" AND (Filesystem.file_path="C:\\User\\*" OR Filesystem.file_path="*\\Temp\\*") by _time span=1h Filesystem.process_guid Filesystem.file_name Filesystem.file_path Filesystem.file_hash Filesystem.user -| `drop_dm_object_name(Filesystem)` -| rename process_guid as lnk_guid -| join lnk_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name=* by _time span=1h Processes.parent_process_guid Processes.process_id Processes.process_name Processes.dest Processes.process_path Processes.process -| `drop_dm_object_name(Processes)` -| rename parent_process_guid as lnk_guid -| fields _time lnk_guid process_id dest process_name process_path process] -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| table firstTime, lastTime, lnk_guid, process_id, user, dest, file_name, file_path, process_name, process, process_path, file_hash -| `process_creating_lnk_file_in_suspicious_location_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **process_creating_lnk_file_in_suspicious_location_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Filesystem.file_name -* Filesystem.file_path -* Filesystem.process_id -* Filesystem.file_name -* Filesystem.file_path -* Filesystem.file_hash -* Filesystem.user - - -#### How To Implement -You must be ingesting data that records filesystem and process activity from your hosts to populate the Endpoint data model. This is typically populated via endpoint detection-and-response product, such as Carbon Black, or endpoint data sources, such as Sysmon. - -#### Known False Positives -This detection should yield little or no false positive results. It is uncommon for LNK files to be executed from temporary or user directories. - -#### Associated Analytic story -* [Spearphishing Attachments](/stories/spearphishing_attachments) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 63.0 | 70 | 90 | A process $process_name$ that launching .lnk file in $file_path$ in host $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1566/001/](https://attack.mitre.org/techniques/T1566/001/) -* [https://www.trendmicro.com/en_us/research/17/e/rising-trend-attackers-using-lnk-files-download-malware.html](https://www.trendmicro.com/en_us/research/17/e/rising-trend-attackers-using-lnk-files-download-malware.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.002/lnk_file_temp_folder/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.002/lnk_file_temp_folder/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml) \| *version*: **5** \ No newline at end of file diff --git a/docs/_posts/2021-08-27-exchange_powershell_abuse_via_ssrf.md b/docs/_posts/2021-08-27-exchange_powershell_abuse_via_ssrf.md deleted file mode 100644 index 27495bc909..0000000000 --- a/docs/_posts/2021-08-27-exchange_powershell_abuse_via_ssrf.md +++ /dev/null @@ -1,163 +0,0 @@ ---- -title: "Exchange PowerShell Abuse via SSRF" -excerpt: "Exploit Public-Facing Application -" -categories: - - Endpoint -last_modified_at: 2021-08-27 -toc: true -toc_label: "" -tags: - - Exploit Public-Facing Application - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic identifies suspicious behavior related to ProxyShell against on-premise Microsoft Exchange servers. \ -Modification of this analytic is requried to ensure fields are mapped accordingly. \ -A suspicious event will have `PowerShell`, the method `POST` and `autodiscover.json`. This is indicative of accessing PowerShell on the back end of Exchange with SSRF. \ -An event will look similar to `POST /autodiscover/autodiscover.json a=dsxvu@fnsso.flq/powershell/?X-Rps-CAT=VgEAVAdXaW5kb3d...` (abbreviated) \ -Review the source attempting to perform this activity against your environment. In addition, review PowerShell logs and access recently granted to Exchange roles. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-08-27 -- **Author**: Michael Haag, Splunk -- **ID**: 29228ab4-0762-11ec-94aa-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1190](https://attack.mitre.org/techniques/T1190/) | Exploit Public-Facing Application | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| `exchange` c_uri="*//autodiscover.json*" cs_uri_query="*PowerShell*" cs_method="POST" -| stats count min(_time) as firstTime max(_time) as lastTime by dest, cs_uri_query, cs_method, c_uri -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `exchange_powershell_abuse_via_ssrf_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [exchange](https://github.com/splunk/security_content/blob/develop/macros/exchange.yml) - -> :information_source: -> **exchange_powershell_abuse_via_ssrf_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* dest -* cs_uri_query -* cs_method -* c_uri - - -#### How To Implement -The following analytic requires on-premise Exchange to be logging to Splunk using the TA - https://splunkbase.splunk.com/app/3225. Ensure logs are parsed correctly, or tune the analytic for your environment. - -#### Known False Positives -Limited false positives, however, tune as needed. - -#### Associated Analytic story -* [ProxyShell](/stories/proxyshell) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | Activity related to ProxyShell has been identified on $dest$. Review events and take action accordingly. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/GossiTheDog/ThreatHunting/blob/master/AzureSentinel/Exchange-Powershell-via-SSRF](https://github.com/GossiTheDog/ThreatHunting/blob/master/AzureSentinel/Exchange-Powershell-via-SSRF) -* [https://blog.orange.tw/2021/08/proxylogon-a-new-attack-surface-on-ms-exchange-part-1.html](https://blog.orange.tw/2021/08/proxylogon-a-new-attack-surface-on-ms-exchange-part-1.html) -* [https://peterjson.medium.com/reproducing-the-proxyshell-pwn2own-exploit-49743a4ea9a1](https://peterjson.medium.com/reproducing-the-proxyshell-pwn2own-exploit-49743a4ea9a1) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/exchange-events.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/exchange-events.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/endpoint/exchange_powershell_abuse_via_ssrf.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-27-exchange_powershell_module_usage.md b/docs/_posts/2021-08-27-exchange_powershell_module_usage.md deleted file mode 100644 index 38f8098ad8..0000000000 --- a/docs/_posts/2021-08-27-exchange_powershell_module_usage.md +++ /dev/null @@ -1,168 +0,0 @@ ---- -title: "Exchange PowerShell Module Usage" -excerpt: "Command and Scripting Interpreter -, PowerShell -" -categories: - - Endpoint -last_modified_at: 2021-08-27 -toc: true -toc_label: "" -tags: - - Command and Scripting Interpreter - - PowerShell - - Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the usage of Exchange PowerShell modules that were recently used for a proof of concept related to ProxyShell. Currently, there is no active data shared or data we could re-produce relate to this part of the ProxyShell chain of exploits. \ -Inherently, the usage of the modules is not malicious, but reviewing parallel processes, and user, of the session will assist with determining the intent. \ -Module - New-MailboxExportRequest will begin the process of exporting contents of a primary mailbox or archive to a .pst file. \ -Module - New-managementroleassignment can assign a management role to a management role group, management role assignment policy, user, or universal security group (USG). - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-08-27 -- **Author**: Michael Haag -- **ID**: 2d10095e-05ae-11ec-8fdf-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -| [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 Message IN ("*New-MailboxExportRequest*", "*New-ManagementRoleAssignment*") -| stats count min(_time) as firstTime max(_time) as lastTime by Path Message OpCode ComputerName User EventCode -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `exchange_powershell_module_usage_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **exchange_powershell_module_usage_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Path -* Message -* OpCode -* ComputerName -* User -* EventCode - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -Administrators or power users may use this PowerShell commandlet for troubleshooting. - -#### Associated Analytic story -* [ProxyShell](/stories/proxyshell) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | Local user discovery enumeration using PowerShell on $dest$ by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://docs.microsoft.com/en-us/powershell/module/exchange/new-mailboxexportrequest?view=exchange-ps](https://docs.microsoft.com/en-us/powershell/module/exchange/new-mailboxexportrequest?view=exchange-ps) -* [https://docs.microsoft.com/en-us/powershell/module/exchange/new-managementroleassignment?view=exchange-ps](https://docs.microsoft.com/en-us/powershell/module/exchange/new-managementroleassignment?view=exchange-ps) -* [https://blog.orange.tw/2021/08/proxyshell-a-new-attack-surface-on-ms-exchange-part-3.html](https://blog.orange.tw/2021/08/proxyshell-a-new-attack-surface-on-ms-exchange-part-3.html) -* [https://www.zerodayinitiative.com/blog/2021/8/17/from-pwn2own-2021-a-new-attack-surface-on-microsoft-exchange-proxyshell](https://www.zerodayinitiative.com/blog/2021/8/17/from-pwn2own-2021-a-new-attack-surface-on-microsoft-exchange-proxyshell) -* [https://thedfirreport.com/2021/11/15/exchange-exploit-leads-to-domain-wide-ransomware/](https://thedfirreport.com/2021/11/15/exchange-exploit-leads-to-domain-wide-ransomware/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/endpoint/exchange_powershell_module_usage.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-30-domain_controller_discovery_with_nltest.md b/docs/_posts/2021-08-30-domain_controller_discovery_with_nltest.md deleted file mode 100644 index a7a7709f4a..0000000000 --- a/docs/_posts/2021-08-30-domain_controller_discovery_with_nltest.md +++ /dev/null @@ -1,162 +0,0 @@ ---- -title: "Domain Controller Discovery with Nltest" -excerpt: "Remote System Discovery -" -categories: - - Endpoint -last_modified_at: 2021-08-30 -toc: true -toc_label: "" -tags: - - Remote System Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for the execution of `nltest.exe` with command-line arguments utilized to discover remote systems. The arguments `/dclist:` and '/dsgetdc:', can be used to return a list of all domain controllers. Red Teams and adversaries alike may use nltest.exe to identify domain controllers in a Windows Domain for situational awareness and Active Directory Discovery. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-08-30 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 41243735-89a7-4c83-bcdd-570aa78f00a1 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1018](https://attack.mitre.org/techniques/T1018/) | Remote System Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="nltest.exe") (Processes.process="*/dclist:*" OR Processes.process="*/dsgetdc:*") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `domain_controller_discovery_with_nltest_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **domain_controller_discovery_with_nltest_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Administrators or power users may use this command for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 21.0 | 30 | 70 | Domain controller discovery on $dest$ by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1018/](https://attack.mitre.org/techniques/T1018/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/AD_discovery/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/AD_discovery/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-30-remote_system_discovery_with_net.md b/docs/_posts/2021-08-30-remote_system_discovery_with_net.md deleted file mode 100644 index 933e997068..0000000000 --- a/docs/_posts/2021-08-30-remote_system_discovery_with_net.md +++ /dev/null @@ -1,162 +0,0 @@ ---- -title: "Remote System Discovery with Net" -excerpt: "Remote System Discovery -" -categories: - - Endpoint -last_modified_at: 2021-08-30 -toc: true -toc_label: "" -tags: - - Remote System Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for the execution of `net.exe` or `net1.exe` with command-line arguments utilized to discover remote systems. The argument `domain computers /domain` returns a list of all domain computers. Red Teams and adversaries alike use net.exe to identify remote systems for situational awareness and Active Directory Discovery. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-08-30 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 9df16706-04a2-41e2-bbfe-9b38b34409d3 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1018](https://attack.mitre.org/techniques/T1018/) | Remote System Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="net.exe" OR Processes.process_name="net1.exe") (Processes.process="*domain computers*" AND Processes.process=*/do*) OR (Processes.process="*view*" AND Processes.process=*/do*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `remote_system_discovery_with_net_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **remote_system_discovery_with_net_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Administrators or power users may use this command for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | Remote system discovery enumeration on $dest$ by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1018/](https://attack.mitre.org/techniques/T1018/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/AD_discovery/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/AD_discovery/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/remote_system_discovery_with_net.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-31-petitpotam_network_share_access_request.md b/docs/_posts/2021-08-31-petitpotam_network_share_access_request.md deleted file mode 100644 index 74fd24e098..0000000000 --- a/docs/_posts/2021-08-31-petitpotam_network_share_access_request.md +++ /dev/null @@ -1,166 +0,0 @@ ---- -title: "PetitPotam Network Share Access Request" -excerpt: "Forced Authentication -" -categories: - - Endpoint -last_modified_at: 2021-08-31 -toc: true -toc_label: "" -tags: - - Forced Authentication - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2021-36942 ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes Windows Event Code 5145, "A network share object was checked to see whether client can be granted desired access". During our research into PetitPotam, CVE-2021-36942, we identified the ocurrence of this event on the target host with specific values. \ -To enable 5145 events via Group Policy - Computer Configuration->Polices->Windows Settings->Security Settings->Advanced Audit Policy Configuration. Expand this node, go to Object Access (Audit Polices->Object Access), then select the Setting Audit Detailed File Share Audit \ -It is possible this is not enabled by default and may need to be reviewed and enabled. \ -During triage, review parallel security events to identify further suspicious activity. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-08-31 -- **Author**: Michael Haag, Mauricio Velazco, Splunk -- **ID**: 95b8061a-0a67-11ec-85ec-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1187](https://attack.mitre.org/techniques/T1187/) | Forced Authentication | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2021-36942](https://nvd.nist.gov/vuln/detail/CVE-2021-36942) | Windows LSA Spoofing Vulnerability | 5.0 | - - - -
-
- -#### Search - -``` -`wineventlog_security` Account_Name="ANONYMOUS LOGON" EventCode=5145 Relative_Target_Name=lsarpc -| stats count min(_time) as firstTime max(_time) as lastTime by dest, Security_ID, Share_Name, Source_Address, Accesses, Message -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `petitpotam_network_share_access_request_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **petitpotam_network_share_access_request_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* dest -* Security_ID -* Share_Name -* Source_Address -* Accesses -* Message - - -#### How To Implement -Windows Event Code 5145 is required to utilize this analytic and it may not be enabled in most environments. - -#### Known False Positives -False positives have been limited when the Anonymous Logon is used for Account Name. - -#### Associated Analytic story -* [PetitPotam NTLM Relay on Active Directory Certificate Services](/stories/petitpotam_ntlm_relay_on_active_directory_certificate_services) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 56.0 | 80 | 70 | A remote host is enumerating a $dest$ to identify permissions. This is a precursor event to CVE-2021-36942, PetitPotam. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1187/](https://attack.mitre.org/techniques/T1187/) -* [https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5145](https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5145) -* [https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-5145](https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-5145) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1187/petitpotam/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1187/petitpotam/windows-security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/petitpotam_network_share_access_request.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-31-petitpotam_suspicious_kerberos_tgt_request.md b/docs/_posts/2021-08-31-petitpotam_suspicious_kerberos_tgt_request.md deleted file mode 100644 index 097e4595bc..0000000000 --- a/docs/_posts/2021-08-31-petitpotam_suspicious_kerberos_tgt_request.md +++ /dev/null @@ -1,162 +0,0 @@ ---- -title: "PetitPotam Suspicious Kerberos TGT Request" -excerpt: "OS Credential Dumping -" -categories: - - Endpoint -last_modified_at: 2021-08-31 -toc: true -toc_label: "" -tags: - - OS Credential Dumping - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2021-36942 ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifes Event Code 4768, A `Kerberos authentication ticket (TGT) was requested`, successfull occurs. This behavior has been identified to assist with detecting PetitPotam, CVE-2021-36942. Once an attacer obtains a computer certificate by abusing Active Directory Certificate Services in combination with PetitPotam, the next step would be to leverage the certificate for malicious purposes. One way of doing this is to request a Kerberos Ticket Granting Ticket using a tool like Rubeus. This request will generate a 4768 event with some unusual fields depending on the environment. This analytic will require tuning, we recommend filtering Account_Name to Domain Controllers for your environment. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-08-31 -- **Author**: Michael Haag, Mauricio Velazco, Splunk -- **ID**: e3ef244e-0a67-11ec-abf2-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2021-36942](https://nvd.nist.gov/vuln/detail/CVE-2021-36942) | Windows LSA Spoofing Vulnerability | 5.0 | - - - -
-
- -#### Search - -``` -`wineventlog_security` EventCode=4768 Client_Address!="::1" Certificate_Thumbprint!="" Account_Name=*$ -| stats count min(_time) as firstTime max(_time) as lastTime by dest, Account_Name, Client_Address, action, Message -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `petitpotam_suspicious_kerberos_tgt_request_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **petitpotam_suspicious_kerberos_tgt_request_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* dest -* Account_Name -* Client_Address -* action -* Message - - -#### How To Implement -The following analytic requires Event Code 4768. Ensure that it is logging no Domain Controllers and appearing in Splunk. - -#### Known False Positives -False positives are possible if the environment is using certificates for authentication. - -#### Associated Analytic story -* [PetitPotam NTLM Relay on Active Directory Certificate Services](/stories/petitpotam_ntlm_relay_on_active_directory_certificate_services) -* [Active Directory Kerberos Attacks](/stories/active_directory_kerberos_attacks) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 56.0 | 80 | 70 | A Kerberos TGT was requested in a non-standard manner against $dest$, potentially related to CVE-2021-36942, PetitPotam. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4768](https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4768) -* [https://isc.sans.edu/forums/diary/Active+Directory+Certificate+Services+ADCS+PKI+domain+admin+vulnerability/27668/](https://isc.sans.edu/forums/diary/Active+Directory+Certificate+Services+ADCS+PKI+domain+admin+vulnerability/27668/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1187/petitpotam/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1187/petitpotam/windows-security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-08-31-remote_system_discovery_with_dsquery.md b/docs/_posts/2021-08-31-remote_system_discovery_with_dsquery.md deleted file mode 100644 index 1526c5c5e8..0000000000 --- a/docs/_posts/2021-08-31-remote_system_discovery_with_dsquery.md +++ /dev/null @@ -1,163 +0,0 @@ ---- -title: "Remote System Discovery with Dsquery" -excerpt: "Remote System Discovery -" -categories: - - Endpoint -last_modified_at: 2021-08-31 -toc: true -toc_label: "" -tags: - - Remote System Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for the execution of `dsquery.exe` with command-line arguments utilized to discover remote systems. The `computer` argument returns a list of all computers registered in the domain. Red Teams and adversaries alike engage in remote system discovery for situational awareness and Active Directory Discovery. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-08-31 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 9fb562f4-42f8-4139-8e11-a82edf7ed718 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1018](https://attack.mitre.org/techniques/T1018/) | Remote System Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="dsquery.exe") (Processes.process="*computer*") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `remote_system_discovery_with_dsquery_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **remote_system_discovery_with_dsquery_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Administrators or power users may use this command for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | Remote system discovery enumeration on $dest$ by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1018/](https://attack.mitre.org/techniques/T1018/) -* [https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/cc732952(v=ws.11)](https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/cc732952(v=ws.11)) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/AD_discovery/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/AD_discovery/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-01-circle_ci_disable_security_step.md b/docs/_posts/2021-09-01-circle_ci_disable_security_step.md deleted file mode 100644 index 9e27a6d39f..0000000000 --- a/docs/_posts/2021-09-01-circle_ci_disable_security_step.md +++ /dev/null @@ -1,169 +0,0 @@ ---- -title: "Circle CI Disable Security Step" -excerpt: "Compromise Client Software Binary -" -categories: - - Cloud -last_modified_at: 2021-09-01 -toc: true -toc_label: "" -tags: - - Compromise Client Software Binary - - Persistence - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for disable security step in CircleCI pipeline. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-09-01 -- **Author**: Patrick Bareiss, Splunk -- **ID**: 72cb9de9-e98b-4ac9-80b2-5331bba6ea97 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1554](https://attack.mitre.org/techniques/T1554/) | Compromise Client Software Binary | Persistence | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.DS -* PR.AC -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 13 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`circleci` -| rename workflows.job_id AS job_id -| join job_id [ -| search `circleci` -| stats values(name) as step_names count by job_id job_name ] -| stats count by step_names job_id job_name vcs.committer_name vcs.subject vcs.url owners{} -| rename vcs.* as * , owners{} as user -| lookup mandatory_step_for_job job_name OUTPUTNEW step_name AS mandatory_step -| search mandatory_step=* -| eval mandatory_step_executed=if(like(step_names, "%".mandatory_step."%"), 1, 0) -| where mandatory_step_executed=0 -| rex field=url "(?[^\/]*\/[^\/]*)$" -| eval phase="build" -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `circle_ci_disable_security_step_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [circleci](https://github.com/splunk/security_content/blob/develop/macros/circleci.yml) - -> :information_source: -> **circle_ci_disable_security_step_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Lookups -The SPL above uses the following Lookups: - -* [mandatory_step_for_job](https://github.com/splunk/security_content/blob/develop/lookups/mandatory_step_for_job.yml) with [data](https://github.com/splunk/security_content/tree/develop/lookups/mandatory_step_for_job.csv) - -#### Required field -* _times - - -#### How To Implement -You must index CircleCI logs. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Dev Sec Ops](/stories/dev_sec_ops) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 72.0 | 80 | 90 | disable security step $mandatory_step$ in job $job_name$ from user $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1554/circle_ci_disable_security_step/circle_ci_disable_security_step.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1554/circle_ci_disable_security_step/circle_ci_disable_security_step.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/circle_ci_disable_security_step.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-01-domain_controller_discovery_with_wmic.md b/docs/_posts/2021-09-01-domain_controller_discovery_with_wmic.md deleted file mode 100644 index 6158e6df76..0000000000 --- a/docs/_posts/2021-09-01-domain_controller_discovery_with_wmic.md +++ /dev/null @@ -1,162 +0,0 @@ ---- -title: "Domain Controller Discovery with Wmic" -excerpt: "Remote System Discovery -" -categories: - - Endpoint -last_modified_at: 2021-09-01 -toc: true -toc_label: "" -tags: - - Remote System Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for the execution of `wmic.exe` with command-line arguments utilized to discover remote systems. The arguments utilized in this command line return a list of all domain controllers in a Windows domain. Red Teams and adversaries alike use *.exe to identify remote systems for situational awareness and Active Directory Discovery. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-09-01 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 64c7adaa-48ee-483c-b0d6-7175bc65e6cc - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1018](https://attack.mitre.org/techniques/T1018/) | Remote System Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="wmic.exe") (Processes.process="" OR Processes.process="*DomainControllerAddress*") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `domain_controller_discovery_with_wmic_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **domain_controller_discovery_with_wmic_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Administrators or power users may use this command for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 21.0 | 30 | 70 | Domain controller discovery on $dest$ by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1018/](https://attack.mitre.org/techniques/T1018/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/AD_discovery/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/AD_discovery/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-01-domain_group_discovery_with_dsquery.md b/docs/_posts/2021-09-01-domain_group_discovery_with_dsquery.md deleted file mode 100644 index 9534f2d6fd..0000000000 --- a/docs/_posts/2021-09-01-domain_group_discovery_with_dsquery.md +++ /dev/null @@ -1,167 +0,0 @@ ---- -title: "Domain Group Discovery With Dsquery" -excerpt: "Permission Groups Discovery -, Domain Groups -" -categories: - - Endpoint -last_modified_at: 2021-09-01 -toc: true -toc_label: "" -tags: - - Permission Groups Discovery - - Domain Groups - - Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for the execution of `dsquery.exe` with command-line arguments utilized to query for domain groups. The argument `group`, returns a list of all domain groups. Red Teams and adversaries alike use may leverage dsquery.exe to enumerate domain groups for situational awareness and Active Directory Discovery. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-09-01 -- **Author**: Mauricio Velazco, Splunk -- **ID**: f0c9d62f-a232-4edd-b17e-bc409fb133d4 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | - -| [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="dsquery.exe") (Processes.process="*group*") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `domain_group_discovery_with_dsquery_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **domain_group_discovery_with_dsquery_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Administrators or power users may use this command for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | Domain group discovery enumeration on $dest$ by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1069/002/](https://attack.mitre.org/techniques/T1069/002/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.002/AD_discovery/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.002/AD_discovery/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-01-getadcomputer_with_powershell_script_block.md b/docs/_posts/2021-09-01-getadcomputer_with_powershell_script_block.md deleted file mode 100644 index 9f6011c46d..0000000000 --- a/docs/_posts/2021-09-01-getadcomputer_with_powershell_script_block.md +++ /dev/null @@ -1,154 +0,0 @@ ---- -title: "GetAdComputer with PowerShell Script Block" -excerpt: "Remote System Discovery -" -categories: - - Endpoint -last_modified_at: 2021-09-01 -toc: true -toc_label: "" -tags: - - Remote System Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-AdGroup` commandlet. The `Get-AdGroup` commandlet is used to return a list of all domain computers. Red Teams and adversaries may leverage this commandlet to enumerate domain computers for situational awareness and Active Directory Discovery. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-09-01 -- **Author**: Mauricio Velazco, Splunk -- **ID**: a9a1da02-8e27-4bf7-a348-f4389c9da487 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1018](https://attack.mitre.org/techniques/T1018/) | Remote System Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 (Message = "*Get-AdComputer*") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `getadcomputer_with_powershell_script_block_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **getadcomputer_with_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Message -* ComputerName -* User - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -Administrators or power users may use this PowerShell commandlet for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | Remote system discovery enumeration on $dest$ by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1018/](https://attack.mitre.org/techniques/T1018/) -* [https://docs.microsoft.com/en-us/powershell/module/activedirectory/get-adgroup?view=windowsserver2019-ps](https://docs.microsoft.com/en-us/powershell/module/activedirectory/get-adgroup?view=windowsserver2019-ps) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/AD_discovery/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/AD_discovery/windows-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-01-getwmiobject_ds_computer_with_powershell_script_block.md b/docs/_posts/2021-09-01-getwmiobject_ds_computer_with_powershell_script_block.md deleted file mode 100644 index 9ef16fa75a..0000000000 --- a/docs/_posts/2021-09-01-getwmiobject_ds_computer_with_powershell_script_block.md +++ /dev/null @@ -1,154 +0,0 @@ ---- -title: "GetWmiObject Ds Computer with PowerShell Script Block" -excerpt: "Remote System Discovery -" -categories: - - Endpoint -last_modified_at: 2021-09-01 -toc: true -toc_label: "" -tags: - - Remote System Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-WmiObject` commandlet. The `DS_Computer` class parameter leverages WMI to query for all domain computers. Red Teams and adversaries may leverage this commandlet to enumerate domain computers for situational awareness and Active Directory Discovery. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-09-01 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 29b99201-723c-4118-847a-db2b3d3fb8ea - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1018](https://attack.mitre.org/techniques/T1018/) | Remote System Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 (Message=*Get-WmiObject* AND Message="*namespace root\\directory\\ldap*" AND Message="*class ds_computer*") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `getwmiobject_ds_computer_with_powershell_script_block_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **getwmiobject_ds_computer_with_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Message -* ComputerName -* User - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -Administrators or power users may use this PowerShell commandlet for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | Remote system discovery enumeration on $dest$ by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1018/](https://attack.mitre.org/techniques/T1018/) -* [https://docs.microsoft.com/en-us/powershell/module/microsoft.powershell.management/get-wmiobject?view=powershell-5.1](https://docs.microsoft.com/en-us/powershell/module/microsoft.powershell.management/get-wmiobject?view=powershell-5.1) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/AD_discovery/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/AD_discovery/windows-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-01-github_commit_in_develop.md b/docs/_posts/2021-09-01-github_commit_in_develop.md deleted file mode 100644 index 2eef99dca3..0000000000 --- a/docs/_posts/2021-09-01-github_commit_in_develop.md +++ /dev/null @@ -1,151 +0,0 @@ ---- -title: "Github Commit In Develop" -excerpt: "Trusted Relationship -" -categories: - - Cloud -last_modified_at: 2021-09-01 -toc: true -toc_label: "" -tags: - - Trusted Relationship - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect a pushed or commit to develop branch. This is to avoid unwanted modification to develop without a review to the changes. Ideally in terms of devsecops the changes made in a branch and do a PR for review. of course in some cases admin of the project may did a changes directly to master branch - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-09-01 -- **Author**: Teoderick Contreras, Splunk -- **ID**: f3030cb6-0b02-11ec-8f22-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1199](https://attack.mitre.org/techniques/T1199/) | Trusted Relationship | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`github` branches{}.name = main OR branches{}.name = develop -| stats count min(_time) as firstTime max(_time) as lastTime by commit.author.html_url commit.commit.author.email commit.author.login commit.commit.message repository.pushed_at commit.commit.committer.date -| eval phase="code" -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `github_commit_in_develop_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [github](https://github.com/splunk/security_content/blob/develop/macros/github.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **github_commit_in_develop_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs related to github logs having the fork, commit, push metadata that can be use to monitor the changes in a github project. - -#### Known False Positives -admin can do changes directly to develop branch - -#### Associated Analytic story -* [Dev Sec Ops](/stories/dev_sec_ops) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 9.0 | 30 | 30 | suspicious commit by $commit.commit.author.email$ to develop branch | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.redhat.com/en/topics/devops/what-is-devsecops](https://www.redhat.com/en/topics/devops/what-is-devsecops) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1199/github_push_master/github_push_develop.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1199/github_push_master/github_push_develop.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/github_commit_in_develop.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-01-github_dependabot_alert.md b/docs/_posts/2021-09-01-github_dependabot_alert.md deleted file mode 100644 index fd2a212384..0000000000 --- a/docs/_posts/2021-09-01-github_dependabot_alert.md +++ /dev/null @@ -1,174 +0,0 @@ ---- -title: "GitHub Dependabot Alert" -excerpt: "Compromise Software Dependencies and Development Tools -, Supply Chain Compromise -" -categories: - - Cloud -last_modified_at: 2021-09-01 -toc: true -toc_label: "" -tags: - - Compromise Software Dependencies and Development Tools - - Supply Chain Compromise - - Initial Access - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for Dependabot Alerts in Github logs. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-09-01 -- **Author**: Patrick Bareiss, Splunk -- **ID**: 05032b04-4469-4034-9df7-05f607d75cba - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1195.001](https://attack.mitre.org/techniques/T1195/001/) | Compromise Software Dependencies and Development Tools | Initial Access | - -| [T1195](https://attack.mitre.org/techniques/T1195/) | Supply Chain Compromise | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.DS -* PR.AC -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 13 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`github` alert.id=* action=create -| rename repository.full_name as repository, repository.html_url as repository_url sender.login as user -| stats min(_time) as firstTime max(_time) as lastTime by action alert.affected_package_name alert.affected_range alert.created_at alert.external_identifier alert.external_reference alert.fixed_in alert.severity repository repository_url user -| eval phase="code" -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `github_dependabot_alert_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [github](https://github.com/splunk/security_content/blob/develop/macros/github.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **github_dependabot_alert_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* alert.id -* repository.full_name -* repository.html_url -* action -* alert.affected_package_name -* alert.affected_range -* alert.created_at -* alert.external_identifier -* alert.external_reference -* alert.fixed_in -* alert.severity - - -#### How To Implement -You must index GitHub logs. You can follow the url in reference to onboard GitHub logs. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Dev Sec Ops](/stories/dev_sec_ops) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 27.0 | 30 | 90 | Vulnerabilities found in packages used by GitHub repository $repository$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.splunk.com/en_us/blog/tips-and-tricks/getting-github-data-with-webhooks.html](https://www.splunk.com/en_us/blog/tips-and-tricks/getting-github-data-with-webhooks.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1195.001/github_security_advisor_alert/github_security_advisor_alert.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1195.001/github_security_advisor_alert/github_security_advisor_alert.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/github_dependabot_alert.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-01-github_pull_request_from_unknown_user.md b/docs/_posts/2021-09-01-github_pull_request_from_unknown_user.md deleted file mode 100644 index 986599f6e5..0000000000 --- a/docs/_posts/2021-09-01-github_pull_request_from_unknown_user.md +++ /dev/null @@ -1,176 +0,0 @@ ---- -title: "GitHub Pull Request from Unknown User" -excerpt: "Compromise Software Dependencies and Development Tools -, Supply Chain Compromise -" -categories: - - Cloud -last_modified_at: 2021-09-01 -toc: true -toc_label: "" -tags: - - Compromise Software Dependencies and Development Tools - - Supply Chain Compromise - - Initial Access - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for Pull Request from unknown user. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-09-01 -- **Author**: Patrick Bareiss, Splunk -- **ID**: 9d7b9100-8878-4404-914e-ca5e551a641e - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1195.001](https://attack.mitre.org/techniques/T1195/001/) | Compromise Software Dependencies and Development Tools | Initial Access | - -| [T1195](https://attack.mitre.org/techniques/T1195/) | Supply Chain Compromise | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.DS -* PR.AC -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 13 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`github` check_suite.pull_requests{}.id=* -| stats count by check_suite.head_commit.author.name repository.full_name check_suite.pull_requests{}.head.ref check_suite.head_commit.message -| rename check_suite.head_commit.author.name as user repository.full_name as repository check_suite.pull_requests{}.head.ref as ref_head check_suite.head_commit.message as commit_message -| search NOT `github_known_users` -| eval phase="code" -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `github_pull_request_from_unknown_user_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [github](https://github.com/splunk/security_content/blob/develop/macros/github.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [github_known_users](https://github.com/splunk/security_content/blob/develop/macros/github_known_users.yml) - -> :information_source: -> **github_pull_request_from_unknown_user_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* alert.id -* repository.full_name -* repository.html_url -* action -* alert.affected_package_name -* alert.affected_range -* alert.created_at -* alert.external_identifier -* alert.external_reference -* alert.fixed_in -* alert.severity - - -#### How To Implement -You must index GitHub logs. You can follow the url in reference to onboard GitHub logs. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Dev Sec Ops](/stories/dev_sec_ops) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 27.0 | 30 | 90 | Vulnerabilities found in packages used by GitHub repository $repository$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.splunk.com/en_us/blog/tips-and-tricks/getting-github-data-with-webhooks.html](https://www.splunk.com/en_us/blog/tips-and-tricks/getting-github-data-with-webhooks.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1195.001/github_pull_request/github_pull_request.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1195.001/github_pull_request/github_pull_request.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/github_pull_request_from_unknown_user.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-01-remote_system_discovery_with_adsisearcher.md b/docs/_posts/2021-09-01-remote_system_discovery_with_adsisearcher.md deleted file mode 100644 index f62c1c6ce5..0000000000 --- a/docs/_posts/2021-09-01-remote_system_discovery_with_adsisearcher.md +++ /dev/null @@ -1,154 +0,0 @@ ---- -title: "Remote System Discovery with Adsisearcher" -excerpt: "Remote System Discovery -" -categories: - - Endpoint -last_modified_at: 2021-09-01 -toc: true -toc_label: "" -tags: - - Remote System Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the `[Adsisearcher]` type accelerator being used to query Active Directory for domain computers. Red Teams and adversaries may leverage `[Adsisearcher]` to enumerate domain computers for situational awareness and Active Directory Discovery. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-09-01 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 70803451-0047-4e12-9d63-77fa7eb8649c - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1018](https://attack.mitre.org/techniques/T1018/) | Remote System Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 (Message = "*[adsisearcher]*" AND Message = "*objectclass=computer*" AND Message = "*findAll()*") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `remote_system_discovery_with_adsisearcher_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **remote_system_discovery_with_adsisearcher_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Message -* ComputerName -* User - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -Administrators or power users may use Adsisearcher for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | Remote system discovery enumeration on $dest$ by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1018/](https://attack.mitre.org/techniques/T1018/) -* [https://devblogs.microsoft.com/scripting/use-the-powershell-adsisearcher-type-accelerator-to-search-active-directory/](https://devblogs.microsoft.com/scripting/use-the-powershell-adsisearcher-type-accelerator-to-search-active-directory/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/AD_discovery/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/AD_discovery/windows-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-01-remote_system_discovery_with_wmic.md b/docs/_posts/2021-09-01-remote_system_discovery_with_wmic.md deleted file mode 100644 index d2cbc9336e..0000000000 --- a/docs/_posts/2021-09-01-remote_system_discovery_with_wmic.md +++ /dev/null @@ -1,163 +0,0 @@ ---- -title: "Remote System Discovery with Wmic" -excerpt: "Remote System Discovery -" -categories: - - Endpoint -last_modified_at: 2021-09-01 -toc: true -toc_label: "" -tags: - - Remote System Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for the execution of `wmic.exe` with command-line arguments utilized to discover remote systems. The arguments utilized in this command return a list of all the systems registered in the domain. Red Teams and adversaries alike may leverage WMI and wmic.exe to identify remote systems for situational awareness and Active Directory Discovery. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-09-01 -- **Author**: Mauricio Velazco, Splunk -- **ID**: d82eced3-b1dc-42ab-859e-a2fc98827359 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1018](https://attack.mitre.org/techniques/T1018/) | Remote System Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="wmic.exe") (Processes.process=*/NAMESPACE:\\\\root\\directory\\ldap* AND Processes.process=*ds_computer* AND Processes.process="*GET ds_samaccountname*") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `remote_system_discovery_with_wmic_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **remote_system_discovery_with_wmic_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Administrators or power users may use this command for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | Remote system discovery enumeration on $dest$ by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1018/](https://attack.mitre.org/techniques/T1018/) -* [https://docs.microsoft.com/en-us/windows/win32/wmisdk/wmic](https://docs.microsoft.com/en-us/windows/win32/wmisdk/wmic) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/AD_discovery/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/AD_discovery/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/remote_system_discovery_with_wmic.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-02-circle_ci_disable_security_job.md b/docs/_posts/2021-09-02-circle_ci_disable_security_job.md deleted file mode 100644 index 735373a9e4..0000000000 --- a/docs/_posts/2021-09-02-circle_ci_disable_security_job.md +++ /dev/null @@ -1,165 +0,0 @@ ---- -title: "Circle CI Disable Security Job" -excerpt: "Compromise Client Software Binary -" -categories: - - Cloud -last_modified_at: 2021-09-02 -toc: true -toc_label: "" -tags: - - Compromise Client Software Binary - - Persistence - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for disable security job in CircleCI pipeline. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-09-02 -- **Author**: Patrick Bareiss, Splunk -- **ID**: 4a2fdd41-c578-4cd4-9ef7-980e352517f2 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1554](https://attack.mitre.org/techniques/T1554/) | Compromise Client Software Binary | Persistence | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.DS -* PR.AC -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 13 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`circleci` -| rename vcs.committer_name as user vcs.subject as commit_message vcs.url as url workflows.* as * -| stats values(job_name) as job_names by workflow_id workflow_name user commit_message url branch -| lookup mandatory_job_for_workflow workflow_name OUTPUTNEW job_name AS mandatory_job -| search mandatory_job=* -| eval mandatory_job_executed=if(like(job_names, "%".mandatory_job."%"), 1, 0) -| where mandatory_job_executed=0 -| eval phase="build" -| rex field=url "(?[^\/]*\/[^\/]*)$" -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `circle_ci_disable_security_job_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [circleci](https://github.com/splunk/security_content/blob/develop/macros/circleci.yml) - -> :information_source: -> **circle_ci_disable_security_job_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Lookups -The SPL above uses the following Lookups: - -* [mandatory_job_for_workflow](https://github.com/splunk/security_content/blob/develop/lookups/mandatory_job_for_workflow.yml) with [data](https://github.com/splunk/security_content/tree/develop/lookups/mandatory_job_for_workflow.csv) - -#### Required field -* _times - - -#### How To Implement -You must index CircleCI logs. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Dev Sec Ops](/stories/dev_sec_ops) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 72.0 | 80 | 90 | disable security job $mandatory_job$ in workflow $workflow_name$ from user $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1554/circle_ci_disable_security_job/circle_ci_disable_security_job.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1554/circle_ci_disable_security_job/circle_ci_disable_security_job.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/circle_ci_disable_security_job.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-02-get-foresttrust_with_powershell.md b/docs/_posts/2021-09-02-get-foresttrust_with_powershell.md deleted file mode 100644 index dfa36ed572..0000000000 --- a/docs/_posts/2021-09-02-get-foresttrust_with_powershell.md +++ /dev/null @@ -1,163 +0,0 @@ ---- -title: "Get-ForestTrust with PowerShell" -excerpt: "Domain Trust Discovery -" -categories: - - Endpoint -last_modified_at: 2021-09-02 -toc: true -toc_label: "" -tags: - - Domain Trust Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic identifies Get-ForestTrust from PowerSploit in order to gather domain trust information. Typically, this is utilized within a script being executed and used to enumerate the domain trust information. This grants the adversary an understanding of how large or small the domain is. During triage, review parallel processes using an EDR product or 4688 events. It will be important to understand the timeline of events around this activity. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-09-02 -- **Author**: Michael Haag, Splunk -- **ID**: 584f4884-0bf1-11ec-a5ec-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1482](https://attack.mitre.org/techniques/T1482/) | Domain Trust Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=powershell.exe OR Processes.process_name=cmd.exe Processes.process=*get-foresttrust* by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `get_foresttrust_with_powershell_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **get-foresttrust_with_powershell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Limited false positives as this requires an active Administrator or adversary to bring in, import, and execute. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 12.0 | 30 | 40 | Suspicious PowerShell Get-ForestTrust was identified on endpoint $dest$ by user $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://powersploit.readthedocs.io/en/latest/Recon/Get-ForestTrust/](https://powersploit.readthedocs.io/en/latest/Recon/Get-ForestTrust/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1482/discovery/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1482/discovery/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/get_foresttrust_with_powershell.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-02-get-foresttrust_with_powershell_script_block.md b/docs/_posts/2021-09-02-get-foresttrust_with_powershell_script_block.md deleted file mode 100644 index 6004b1416c..0000000000 --- a/docs/_posts/2021-09-02-get-foresttrust_with_powershell_script_block.md +++ /dev/null @@ -1,158 +0,0 @@ ---- -title: "Get-ForestTrust with PowerShell Script Block" -excerpt: "Domain Trust Discovery -" -categories: - - Endpoint -last_modified_at: 2021-09-02 -toc: true -toc_label: "" -tags: - - Domain Trust Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify suspicious PowerShell execution. Script Block Logging captures the command sent to PowerShell, the full command to be executed. Upon enabling, logs will output to Windows event logs. Dependent upon volume, enable on critical endpoints or all. \ -This analytic identifies Get-ForestTrust from PowerSploit in order to gather domain trust information. \ -During triage, review parallel processes using an EDR product or 4688 events. It will be important to understand the timeline of events around this activity. Review the entire logged PowerShell script block. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-09-02 -- **Author**: Michael Haag, Splunk -- **ID**: 70fac80e-0bf1-11ec-9ba0-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1482](https://attack.mitre.org/techniques/T1482/) | Domain Trust Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 ScriptBlockText = "*get-foresttrust*" -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode ScriptBlockText Computer user_id -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `get_foresttrust_with_powershell_script_block_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **get-foresttrust_with_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Message -* Path -* OpCode -* ComputerName -* User - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -False positives may be present. Tune as needed. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 12.0 | 30 | 40 | Suspicious PowerShell Get-ForestTrust was identified on endpoint $ComputerName$ by user $User$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://powersploit.readthedocs.io/en/latest/Recon/Get-ForestTrust/](https://powersploit.readthedocs.io/en/latest/Recon/Get-ForestTrust/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1482/discovery/windows-powershell-xml.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1482/discovery/windows-powershell-xml.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-02-getdomaincomputer_with_powershell_script_block.md b/docs/_posts/2021-09-02-getdomaincomputer_with_powershell_script_block.md deleted file mode 100644 index f35dfdad93..0000000000 --- a/docs/_posts/2021-09-02-getdomaincomputer_with_powershell_script_block.md +++ /dev/null @@ -1,154 +0,0 @@ ---- -title: "GetDomainComputer with PowerShell Script Block" -excerpt: "Remote System Discovery -" -categories: - - Endpoint -last_modified_at: 2021-09-02 -toc: true -toc_label: "" -tags: - - Remote System Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-DomainComputer` commandlet. `GetDomainComputer` is part of PowerView, a PowerShell tool used to perform enumeration on Windows domains. Red Teams and adversaries alike may use PowerView to enumerate domain computers for situational awareness and Active Directory Discovery. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-09-02 -- **Author**: Mauricio Velazco, Splunk -- **ID**: f64da023-b988-4775-8d57-38e512beb56e - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1018](https://attack.mitre.org/techniques/T1018/) | Remote System Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 (Message = "*Get-DomainComputer*") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `getdomaincomputer_with_powershell_script_block_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **getdomaincomputer_with_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Message -* ComputerName -* User - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -Administrators or power users may use PowerView for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 24.0 | 30 | 80 | Remote system discovery with PowerView on $dest$ by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1018/](https://attack.mitre.org/techniques/T1018/) -* [https://powersploit.readthedocs.io/en/latest/Recon/Get-DomainComputer/](https://powersploit.readthedocs.io/en/latest/Recon/Get-DomainComputer/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/AD_discovery/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/AD_discovery/windows-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-02-getdomaincontroller_with_powershell_script_block.md b/docs/_posts/2021-09-02-getdomaincontroller_with_powershell_script_block.md deleted file mode 100644 index 6438259673..0000000000 --- a/docs/_posts/2021-09-02-getdomaincontroller_with_powershell_script_block.md +++ /dev/null @@ -1,154 +0,0 @@ ---- -title: "GetDomainController with PowerShell Script Block" -excerpt: "Remote System Discovery -" -categories: - - Endpoint -last_modified_at: 2021-09-02 -toc: true -toc_label: "" -tags: - - Remote System Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-DomainController` commandlet. `Get-DomainController` is part of PowerView, a PowerShell tool used to perform enumeration on Windows domains. Red Teams and adversaries alike may use PowerView to enumerate domain computers for situational awareness and Active Directory Discovery. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-09-02 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 676b600a-a94d-4951-b346-11329431e6c1 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1018](https://attack.mitre.org/techniques/T1018/) | Remote System Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 (Message = "*Get-DomainController*") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `getdomaincontroller_with_powershell_script_block_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **getdomaincontroller_with_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Message -* ComputerName -* User - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -Administrators or power users may use this PowerShell commandlet for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 24.0 | 30 | 80 | Remote system discovery with PowerView on $dest$ by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1018/](https://attack.mitre.org/techniques/T1018/) -* [https://powersploit.readthedocs.io/en/latest/Recon/Get-DomainController/](https://powersploit.readthedocs.io/en/latest/Recon/Get-DomainController/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/AD_discovery/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/AD_discovery/windows-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-06-bcdedit_command_back_to_normal_mode_boot.md b/docs/_posts/2021-09-06-bcdedit_command_back_to_normal_mode_boot.md deleted file mode 100644 index ac2289bd7c..0000000000 --- a/docs/_posts/2021-09-06-bcdedit_command_back_to_normal_mode_boot.md +++ /dev/null @@ -1,158 +0,0 @@ ---- -title: "Bcdedit Command Back To Normal Mode Boot" -excerpt: "Inhibit System Recovery -" -categories: - - Endpoint -last_modified_at: 2021-09-06 -toc: true -toc_label: "" -tags: - - Inhibit System Recovery - - Impact - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect a suspicious bcdedit commandline to configure the host from safe mode back to normal boot configuration. This technique was seen in blackMatter ransomware where it force the compromised host to boot in safe mode to continue its encryption and bring back to normal boot using bcdedit deletevalue command. This TTP can be a good alert for host that booted from safe mode forcefully since it need to modify the boot configuration to bring it back to normal. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-09-06 -- **Author**: Teoderick Contreras, Splunk -- **ID**: dc7a8004-0f18-11ec-8c54-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1490](https://attack.mitre.org/techniques/T1490/) | Inhibit System Recovery | Impact | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = bcdedit.exe Processes.process="*/deletevalue*" Processes.process="*{current}*" Processes.process="*safeboot*" by Processes.process_name Processes.process Processes.parent_process_name Processes.dest Processes.user -|`drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `bcdedit_command_back_to_normal_mode_boot_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **bcdedit_command_back_to_normal_mode_boot_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process_name -* Processes.process -* Processes.parent_process_name -* Processes.parent_process -* Processes.dest -* Processes.user - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed rundll32.exe may be used. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [BlackMatter Ransomware](/stories/blackmatter_ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 35.0 | 50 | 70 | bcdedit process with commandline $process$ to bring back to normal boot configuration the $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://news.sophos.com/en-us/2021/08/09/blackmatter-ransomware-emerges-from-the-shadow-of-darkside/](https://news.sophos.com/en-us/2021/08/09/blackmatter-ransomware-emerges-from-the-shadow-of-darkside/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1552.002/autoadminlogon/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1552.002/autoadminlogon/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/bcdedit_command_back_to_normal_mode_boot.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-06-change_to_safe_mode_with_network_config.md b/docs/_posts/2021-09-06-change_to_safe_mode_with_network_config.md deleted file mode 100644 index fda1a61b06..0000000000 --- a/docs/_posts/2021-09-06-change_to_safe_mode_with_network_config.md +++ /dev/null @@ -1,158 +0,0 @@ ---- -title: "Change To Safe Mode With Network Config" -excerpt: "Inhibit System Recovery -" -categories: - - Endpoint -last_modified_at: 2021-09-06 -toc: true -toc_label: "" -tags: - - Inhibit System Recovery - - Impact - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect a suspicious bcdedit commandline to configure the host to boot in safe mode with network config. This technique was seen in blackMatter ransomware where it force the compromised host to boot in safe mode to continue its encryption and bring back to normal boot using bcdedit deletevalue command. This TTP can be a good alert for host that booted from safe mode forcefully since it need to modify the boot configuration to bring it back to normal. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-09-06 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 81f1dce0-0f18-11ec-a5d7-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1490](https://attack.mitre.org/techniques/T1490/) | Inhibit System Recovery | Impact | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = bcdedit.exe Processes.process="*/set*" Processes.process="*{current}*" Processes.process="*safeboot*" Processes.process="*network*" by Processes.process_name Processes.process Processes.parent_process_name Processes.dest Processes.user -|`drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `change_to_safe_mode_with_network_config_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **change_to_safe_mode_with_network_config_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process_name -* Processes.process -* Processes.parent_process_name -* Processes.parent_process -* Processes.dest -* Processes.user - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed rundll32.exe may be used. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [BlackMatter Ransomware](/stories/blackmatter_ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | bcdedit process with commandline $process$ to force safemode boot the $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://news.sophos.com/en-us/2021/08/09/blackmatter-ransomware-emerges-from-the-shadow-of-darkside/](https://news.sophos.com/en-us/2021/08/09/blackmatter-ransomware-emerges-from-the-shadow-of-darkside/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1552.002/autoadminlogon/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1552.002/autoadminlogon/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/change_to_safe_mode_with_network_config.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-06-correlation_by_repository_and_risk.md b/docs/_posts/2021-09-06-correlation_by_repository_and_risk.md deleted file mode 100644 index 8cd918eff2..0000000000 --- a/docs/_posts/2021-09-06-correlation_by_repository_and_risk.md +++ /dev/null @@ -1,155 +0,0 @@ ---- -title: "Correlation by Repository and Risk" -excerpt: "Malicious Image -, User Execution -" -categories: - - Cloud -last_modified_at: 2021-09-06 -toc: true -toc_label: "" -tags: - - Malicious Image - - User Execution - - Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search correlations detections by repository and risk_score - -- **Type**: [Correlation](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-09-06 -- **Author**: Patrick Bareiss, Splunk -- **ID**: 8da9fdd9-6a1b-4ae0-8a34-8c25e6be9687 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1204.003](https://attack.mitre.org/techniques/T1204/003/) | Malicious Image | Execution | - -| [T1204](https://attack.mitre.org/techniques/T1204/) | User Execution | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.DS -* PR.AC -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 13 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`signals` -| fillnull -| stats sum(risk_score) as risk_score values(source) as signals values(user) as user by repository -| sort - risk_score -| where risk_score > 80 -| `correlation_by_repository_and_risk_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [signals](https://github.com/splunk/security_content/blob/develop/macros/signals.yml) - -> :information_source: -> **correlation_by_repository_and_risk_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -For Dev Sec Ops POC - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Dev Sec Ops](/stories/dev_sec_ops) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 70.0 | 70 | 100 | Correlation triggered for user $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/correlation_by_repository_and_risk.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-06-correlation_by_user_and_risk.md b/docs/_posts/2021-09-06-correlation_by_user_and_risk.md deleted file mode 100644 index 8fc54dfbb0..0000000000 --- a/docs/_posts/2021-09-06-correlation_by_user_and_risk.md +++ /dev/null @@ -1,155 +0,0 @@ ---- -title: "Correlation by User and Risk" -excerpt: "Malicious Image -, User Execution -" -categories: - - Cloud -last_modified_at: 2021-09-06 -toc: true -toc_label: "" -tags: - - Malicious Image - - User Execution - - Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search correlations detections by user and risk_score - -- **Type**: [Correlation](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-09-06 -- **Author**: Patrick Bareiss, Splunk -- **ID**: 610e12dc-b6fa-4541-825e-4a0b3b6f6773 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1204.003](https://attack.mitre.org/techniques/T1204/003/) | Malicious Image | Execution | - -| [T1204](https://attack.mitre.org/techniques/T1204/) | User Execution | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.DS -* PR.AC -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 13 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`signals` -| fillnull -| stats sum(risk_score) as risk_score values(source) as signals values(repository) as repository by user -| sort - risk_score -| where risk_score > 80 -| `correlation_by_user_and_risk_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [signals](https://github.com/splunk/security_content/blob/develop/macros/signals.yml) - -> :information_source: -> **correlation_by_user_and_risk_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -For Dev Sec Ops POC - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Dev Sec Ops](/stories/dev_sec_ops) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 70.0 | 70 | 100 | Correlation triggered for user $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/correlation_by_user_and_risk.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-07-getadcomputer_with_powershell.md b/docs/_posts/2021-09-07-getadcomputer_with_powershell.md deleted file mode 100644 index 90bf4429ed..0000000000 --- a/docs/_posts/2021-09-07-getadcomputer_with_powershell.md +++ /dev/null @@ -1,162 +0,0 @@ ---- -title: "GetAdComputer with PowerShell" -excerpt: "Remote System Discovery -" -categories: - - Endpoint -last_modified_at: 2021-09-07 -toc: true -toc_label: "" -tags: - - Remote System Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for the execution of `powershell.exe` with command-line arguments utilized to discover remote systems. The `Get-AdComputer' commandlet returns a list of all domain computers. Red Teams and adversaries alike may use this commandlet to identify remote systems for situational awareness and Active Directory Discovery. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-09-07 -- **Author**: Mauricio Velazco, Splunk -- **ID**: c5a31f80-5888-4d81-9f78-1cc65026316e - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1018](https://attack.mitre.org/techniques/T1018/) | Remote System Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="powershell.exe") (Processes.process=*Get-AdComputer*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `getadcomputer_with_powershell_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **getadcomputer_with_powershell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Administrators or power users may use this command for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | Remote system discovery enumeration on $dest$ by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1018/](https://attack.mitre.org/techniques/T1018/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/AD_discovery/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/AD_discovery/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/getadcomputer_with_powershell.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-07-getdomaincomputer_with_powershell.md b/docs/_posts/2021-09-07-getdomaincomputer_with_powershell.md deleted file mode 100644 index 713fbc5000..0000000000 --- a/docs/_posts/2021-09-07-getdomaincomputer_with_powershell.md +++ /dev/null @@ -1,162 +0,0 @@ ---- -title: "GetDomainComputer with PowerShell" -excerpt: "Remote System Discovery -" -categories: - - Endpoint -last_modified_at: 2021-09-07 -toc: true -toc_label: "" -tags: - - Remote System Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for the execution of `powershell.exe` with command-line arguments utilized to discover remote systems. `Get-DomainComputer` is part of PowerView, a PowerShell tool used to perform enumeration on Windows domains. Red Teams and adversaries alike may leverage PowerView to enumerate domain groups for situational awareness and Active Directory Discovery. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-09-07 -- **Author**: Mauricio Velazco, Splunk -- **ID**: ed550c19-712e-43f6-bd19-6f58f61b3a5e - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1018](https://attack.mitre.org/techniques/T1018/) | Remote System Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="powershell.exe") (Processes.process=*Get-DomainComputer*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `getdomaincomputer_with_powershell_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **getdomaincomputer_with_powershell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Administrators or power users may use PowerView for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 24.0 | 30 | 80 | Remote system discovery enumeration on $dest$ by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1018/](https://attack.mitre.org/techniques/T1018/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/AD_discovery/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/AD_discovery/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/getdomaincomputer_with_powershell.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-07-getdomaincontroller_with_powershell.md b/docs/_posts/2021-09-07-getdomaincontroller_with_powershell.md deleted file mode 100644 index d908a9d014..0000000000 --- a/docs/_posts/2021-09-07-getdomaincontroller_with_powershell.md +++ /dev/null @@ -1,163 +0,0 @@ ---- -title: "GetDomainController with PowerShell" -excerpt: "Remote System Discovery -" -categories: - - Endpoint -last_modified_at: 2021-09-07 -toc: true -toc_label: "" -tags: - - Remote System Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for the execution of `powershell.exe` with command-line arguments utilized to discover remote systems. `Get-DomainController` is part of PowerView, a PowerShell tool used to perform enumeration on Windows domains. Red Teams and adversaries alike may leverage PowerView to enumerate domain groups for situational awareness and Active Directory Discovery. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-09-07 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 868ee0e4-52ab-484a-833a-6d85b7c028d0 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1018](https://attack.mitre.org/techniques/T1018/) | Remote System Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="powershell.exe") (Processes.process=*Get-DomainController*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `getdomaincontroller_with_powershell_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **getdomaincontroller_with_powershell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Administrators or power users may use PowerView for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 24.0 | 30 | 80 | Remote system discovery using PowerView on $dest$ by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1018/](https://attack.mitre.org/techniques/T1018/) -* [https://powersploit.readthedocs.io/en/latest/Recon/Get-DomainController/](https://powersploit.readthedocs.io/en/latest/Recon/Get-DomainController/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/AD_discovery/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/AD_discovery/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/getdomaincontroller_with_powershell.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-07-getwmiobject_ds_computer_with_powershell.md b/docs/_posts/2021-09-07-getwmiobject_ds_computer_with_powershell.md deleted file mode 100644 index fb7d6d46cf..0000000000 --- a/docs/_posts/2021-09-07-getwmiobject_ds_computer_with_powershell.md +++ /dev/null @@ -1,162 +0,0 @@ ---- -title: "GetWmiObject Ds Computer with PowerShell" -excerpt: "Remote System Discovery -" -categories: - - Endpoint -last_modified_at: 2021-09-07 -toc: true -toc_label: "" -tags: - - Remote System Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for the execution of `powershell.exe` with command-line arguments utilized to discover remote systems. The `Get-WmiObject` commandlet combined with the `DS_Computer` parameter can be used to return a list of all domain computers. Red Teams and adversaries alike may leverage WMI in this case, using PowerShell, to enumerate domain groups for situational awareness and Active Directory Discovery. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-09-07 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 7141122c-3bc2-4aaa-ab3b-7a85a0bbefc3 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1018](https://attack.mitre.org/techniques/T1018/) | Remote System Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="powershell.exe") (Processes.process=*Get-WmiObject* AND Processes.process="*namespace root\\directory\\ldap*" AND Processes.process="*class ds_computer*") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `getwmiobject_ds_computer_with_powershell_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **getwmiobject_ds_computer_with_powershell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Administrators or power users may use this command for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 21.0 | 30 | 70 | Remote system discovery enumeration using WMI on $dest$ by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1018/](https://attack.mitre.org/techniques/T1018/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/AD_discovery/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/AD_discovery/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-07-schcache_change_by_app_connect_and_create_adsi_object.md b/docs/_posts/2021-09-07-schcache_change_by_app_connect_and_create_adsi_object.md deleted file mode 100644 index 5f1e7fe3f7..0000000000 --- a/docs/_posts/2021-09-07-schcache_change_by_app_connect_and_create_adsi_object.md +++ /dev/null @@ -1,163 +0,0 @@ ---- -title: "SchCache Change By App Connect And Create ADSI Object" -excerpt: "Domain Account -, Account Discovery -" -categories: - - Endpoint -last_modified_at: 2021-09-07 -toc: true -toc_label: "" -tags: - - Domain Account - - Account Discovery - - Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to detect an application try to connect and create ADSI Object to do LDAP query. Every time an application connects to the directory and attempts to create an ADSI object, the Active Directory Schema is checked for changes. If it has changed since the last connection, the schema is downloaded and stored in a cache on the local computer either in %LOCALAPPDATA%\Microsoft\Windows\SchCache or %systemroot%\SchCache. We found this a good anomaly use case to detect suspicious application like blackmatter ransomware that use ADS object api to execute ldap query. having a good list of ldap or normal AD query tool used within the network is a good start to reduce the noise. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-09-07 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 991eb510-0fc6-11ec-82d3-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery | - -| [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventCode=11 TargetFilename = "*\\Windows\\SchCache\\*" TargetFilename = "*.sch*" NOT (Image IN ("*\\Windows\\system32\\mmc.exe")) -|stats count min(_time) as firstTime max(_time) as lastTime by Image TargetFilename EventCode process_id process_name Computer -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `schcache_change_by_app_connect_and_create_adsi_object_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **schcache_change_by_app_connect_and_create_adsi_object_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Image -* TargetFilename -* EventCode -* process_id -* process_name -* Computer - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -normal application like mmc.exe and other ldap query tool may trigger this detections. - -#### Associated Analytic story -* [blackMatter ransomware](/stories/blackmatter_ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | process $Image$ create a file $TargetFilename$ in host $Computer$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://docs.microsoft.com/en-us/windows/win32/adsi/adsi-and-uac](https://docs.microsoft.com/en-us/windows/win32/adsi/adsi-and-uac) -* [https://news.sophos.com/en-us/2021/08/09/blackmatter-ransomware-emerges-from-the-shadow-of-darkside/](https://news.sophos.com/en-us/2021/08/09/blackmatter-ransomware-emerges-from-the-shadow-of-darkside/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/blackmatter_schcache/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/blackmatter_schcache/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-07-system_information_discovery_detection.md b/docs/_posts/2021-09-07-system_information_discovery_detection.md deleted file mode 100644 index 8508ab29a4..0000000000 --- a/docs/_posts/2021-09-07-system_information_discovery_detection.md +++ /dev/null @@ -1,164 +0,0 @@ ---- -title: "System Information Discovery Detection" -excerpt: "System Information Discovery -" -categories: - - Endpoint -last_modified_at: 2021-09-07 -toc: true -toc_label: "" -tags: - - System Information Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -Detect system information discovery techniques used by attackers to understand configurations of the system to further exploit it. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-09-07 -- **Author**: Patrick Bareiss, Splunk -- **ID**: 8e99f89e-ae58-4ebc-bf52-ae0b1a277e72 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1082](https://attack.mitre.org/techniques/T1082/) | System Information Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 6 -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process="*wmic* qfe*" OR Processes.process=*systeminfo* OR Processes.process=*hostname*) by Processes.user Processes.process_name Processes.process Processes.dest Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| eventstats dc(process) as dc_processes_by_dest by dest -| where dc_processes_by_dest > 2 -| stats values(process) as process min(firstTime) as firstTime max(lastTime) as lastTime by user, dest parent_process_name -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `system_information_discovery_detection_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **system_information_discovery_detection_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process -* Processes.user -* Processes.process_name -* Processes.dest - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Administrators debugging servers - -#### Associated Analytic story -* [Discovery Techniques](/stories/discovery_techniques) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | Potential system information discovery behavior on $dest$ by $User$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://web.archive.org/web/20210119205146/https://oscp.infosecsanyam.in/priv-escalation/windows-priv-escalation](https://web.archive.org/web/20210119205146/https://oscp.infosecsanyam.in/priv-escalation/windows-priv-escalation) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1082/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1082/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/system_information_discovery_detection.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-09-08-control_loading_from_world_writable_directory.md b/docs/_posts/2021-09-08-control_loading_from_world_writable_directory.md deleted file mode 100644 index 594531298f..0000000000 --- a/docs/_posts/2021-09-08-control_loading_from_world_writable_directory.md +++ /dev/null @@ -1,177 +0,0 @@ ---- -title: "Control Loading from World Writable Directory" -excerpt: "System Binary Proxy Execution -, Control Panel -" -categories: - - Endpoint -last_modified_at: 2021-09-08 -toc: true -toc_label: "" -tags: - - System Binary Proxy Execution - - Control Panel - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2021-40444 - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following detection identifies control.exe loading either a .cpl or .inf from a writable directory. This is related to CVE-2021-40444. During triage, review parallel processes, parent and child, for further suspicious behaviors. In addition, capture file modifications and analyze. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-09-08 -- **Author**: Michael Haag, Splunk -- **ID**: 10423ac4-10c9-11ec-8dc4-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218](https://attack.mitre.org/techniques/T1218/) | System Binary Proxy Execution | Defense Evasion | - -| [T1218.002](https://attack.mitre.org/techniques/T1218/002/) | Control Panel | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2021-40444](https://nvd.nist.gov/vuln/detail/CVE-2021-40444) | Microsoft MSHTML Remote Code Execution Vulnerability | 6.8 | - - - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name=control.exe OR Processes.original_file_name=CONTROL.EXE) AND Processes.process IN ("*\\appdata\\*", "*\\windows\\temp\\*", "*\\programdata\\*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.original_file_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `control_loading_from_world_writable_directory_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **control_loading_from_world_writable_directory_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Limited false positives will be present as control.exe does not natively load from writable paths as defined. One may add .cpl or .inf to the command-line if there is any false positives. Tune as needed. - -#### Associated Analytic story -* [Microsoft MSHTML Remote Code Execution CVE-2021-40444](/stories/microsoft_mshtml_remote_code_execution_cve-2021-40444) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to load a suspicious file from disk. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://strontic.github.io/xcyclopedia/library/rundll32.exe-111474C61232202B5B588D2B512CBB25.html](https://strontic.github.io/xcyclopedia/library/rundll32.exe-111474C61232202B5B588D2B512CBB25.html) -* [https://app.any.run/tasks/36c14029-9df8-439c-bba0-45f2643b0c70/](https://app.any.run/tasks/36c14029-9df8-439c-bba0-45f2643b0c70/) -* [https://attack.mitre.org/techniques/T1218/011/](https://attack.mitre.org/techniques/T1218/011/) -* [https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40444](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40444) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.002/T1218.002.yaml](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.002/T1218.002.yaml) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.002/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.002/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/control_loading_from_world_writable_directory.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-08-create_local_admin_accounts_using_net_exe.md b/docs/_posts/2021-09-08-create_local_admin_accounts_using_net_exe.md deleted file mode 100644 index 5681350cc9..0000000000 --- a/docs/_posts/2021-09-08-create_local_admin_accounts_using_net_exe.md +++ /dev/null @@ -1,173 +0,0 @@ ---- -title: "Create local admin accounts using net exe" -excerpt: "Local Account -, Create Account -" -categories: - - Endpoint -last_modified_at: 2021-09-08 -toc: true -toc_label: "" -tags: - - Local Account - - Create Account - - Persistence - - Persistence - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for the creation of local administrator accounts using net.exe . - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-09-08 -- **Author**: Bhavin Patel, Splunk -- **ID**: b89919ed-fe5f-492c-b139-151bb162040e - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1136.001](https://attack.mitre.org/techniques/T1136/001/) | Local Account | Persistence | - -| [T1136](https://attack.mitre.org/techniques/T1136/) | Create Account | Persistence | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count values(Processes.user) as user values(Processes.parent_process) as parent_process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name=net.exe OR Processes.process_name=net1.exe) AND Processes.process=*/add* AND (Processes.process=*administrators* OR Processes.process=*administratoren* OR Processes.process=*administrateurs* OR Processes.process=*administrador* OR Processes.process=*amministratori* OR Processes.process=*administratorer*) by Processes.process Processes.process_name Processes.dest -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `create_local_admin_accounts_using_net_exe_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **create_local_admin_accounts_using_net_exe_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. - -#### Known False Positives -Administrators often leverage net.exe to create admin accounts. - -#### Associated Analytic story -* [DHS Report TA18-074A](/stories/dhs_report_ta18-074a) -* [Azorult](/stories/azorult) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 30.0 | 50 | 60 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to add a user to the local Administrators group. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.001/atomic_red_team/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.001/atomic_red_team/windows-security.log) -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.001/atomic_red_team/windows-system.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.001/atomic_red_team/windows-system.log) -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.001/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.001/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml) \| *version*: **6** \ No newline at end of file diff --git a/docs/_posts/2021-09-08-office_spawning_control.md b/docs/_posts/2021-09-08-office_spawning_control.md deleted file mode 100644 index c8c05e9d02..0000000000 --- a/docs/_posts/2021-09-08-office_spawning_control.md +++ /dev/null @@ -1,178 +0,0 @@ ---- -title: "Office Spawning Control" -excerpt: "Phishing -, Spearphishing Attachment -" -categories: - - Endpoint -last_modified_at: 2021-09-08 -toc: true -toc_label: "" -tags: - - Phishing - - Spearphishing Attachment - - Initial Access - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2021-40444 - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following detection identifies control.exe spawning from an office product. This detection identifies any Windows Office Product spawning `control.exe`. In malicious instances, the command-line of `control.exe` will contain a file path to a .cpl or .inf, related to CVE-2021-40444. In this instance, we narrow our detection down to the Office suite as a parent process. During triage, review all file modifications. Capture and analyze any artifacts on disk. review parallel and child processes to identify further suspicious behavior - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-09-08 -- **Author**: Michael Haag, Splunk -- **ID**: 053e027c-10c7-11ec-8437-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | - -| [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2021-40444](https://nvd.nist.gov/vuln/detail/CVE-2021-40444) | Microsoft MSHTML Remote Code Execution Vulnerability | 6.8 | - - - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name IN ("winword.exe","excel.exe","powerpnt.exe","mspub.exe","visio.exe","wordpad.exe","wordview.exe") Processes.process_name=control.exe by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `office_spawning_control_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **office_spawning_control_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Limited false positives should be present. - -#### Associated Analytic story -* [Spearphishing Attachments](/stories/spearphishing_attachments) -* [Microsoft MSHTML Remote Code Execution CVE-2021-40444](/stories/microsoft_mshtml_remote_code_execution_cve-2021-40444) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ clicking a suspicious attachment. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://strontic.github.io/xcyclopedia/library/control.exe-1F13E714A0FEA8887707DFF49287996F.html](https://strontic.github.io/xcyclopedia/library/control.exe-1F13E714A0FEA8887707DFF49287996F.html) -* [https://app.any.run/tasks/36c14029-9df8-439c-bba0-45f2643b0c70/](https://app.any.run/tasks/36c14029-9df8-439c-bba0-45f2643b0c70/) -* [https://attack.mitre.org/techniques/T1218/011/](https://attack.mitre.org/techniques/T1218/011/) -* [https://www.echotrail.io/insights/search/control.exe/](https://www.echotrail.io/insights/search/control.exe/) -* [https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40444](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40444) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.002/T1218.002.yaml](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.002/T1218.002.yaml) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_control.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_control.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/office_spawning_control.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-08-rundll32_control_rundll_hunt.md b/docs/_posts/2021-09-08-rundll32_control_rundll_hunt.md deleted file mode 100644 index a6cbdb54f1..0000000000 --- a/docs/_posts/2021-09-08-rundll32_control_rundll_hunt.md +++ /dev/null @@ -1,180 +0,0 @@ ---- -title: "Rundll32 Control RunDLL Hunt" -excerpt: "System Binary Proxy Execution -, Rundll32 -" -categories: - - Endpoint -last_modified_at: 2021-09-08 -toc: true -toc_label: "" -tags: - - System Binary Proxy Execution - - Rundll32 - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2021-40444 - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following hunting detection identifies rundll32.exe with `control_rundll` within the command-line, loading a .cpl or another file type. Developed in relation to CVE-2021-40444. Rundll32.exe can also be used to execute Control Panel Item files (.cpl) through the undocumented shell32.dll functions Control_RunDLL and Control_RunDLLAsUser. Double-clicking a .cpl file also causes rundll32.exe to execute. \ This is written to be a bit more broad by not including .cpl. \ During triage, review parallel processes to identify any further suspicious behavior. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-09-08 -- **Author**: Michael Haag, Splunk -- **ID**: c8e7ced0-10c5-11ec-8b03-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218](https://attack.mitre.org/techniques/T1218/) | System Binary Proxy Execution | Defense Evasion | - -| [T1218.011](https://attack.mitre.org/techniques/T1218/011/) | Rundll32 | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2021-40444](https://nvd.nist.gov/vuln/detail/CVE-2021-40444) | Microsoft MSHTML Remote Code Execution Vulnerability | 6.8 | - - - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_rundll32` Processes.process=*Control_RunDLL* by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.original_file_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `rundll32_control_rundll_hunt_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [process_rundll32](https://github.com/splunk/security_content/blob/develop/macros/process_rundll32.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **rundll32_control_rundll_hunt_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -This is a hunting detection, meant to provide a understanding of how voluminous control_rundll is within the environment. - -#### Associated Analytic story -* [Suspicious Rundll32 Activity](/stories/suspicious_rundll32_activity) -* [Microsoft MSHTML Remote Code Execution CVE-2021-40444](/stories/microsoft_mshtml_remote_code_execution_cve-2021-40444) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to load a suspicious file from disk. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://strontic.github.io/xcyclopedia/library/rundll32.exe-111474C61232202B5B588D2B512CBB25.html](https://strontic.github.io/xcyclopedia/library/rundll32.exe-111474C61232202B5B588D2B512CBB25.html) -* [https://app.any.run/tasks/36c14029-9df8-439c-bba0-45f2643b0c70/](https://app.any.run/tasks/36c14029-9df8-439c-bba0-45f2643b0c70/) -* [https://attack.mitre.org/techniques/T1218/011/](https://attack.mitre.org/techniques/T1218/011/) -* [https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40444](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40444) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.002/T1218.002.yaml](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.002/T1218.002.yaml) -* [https://redcanary.com/blog/intelligence-insights-december-2021/](https://redcanary.com/blog/intelligence-insights-december-2021/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.002/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.002/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/rundll32_control_rundll_hunt.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-08-rundll32_control_rundll_world_writable_directory.md b/docs/_posts/2021-09-08-rundll32_control_rundll_world_writable_directory.md deleted file mode 100644 index d74d500fcd..0000000000 --- a/docs/_posts/2021-09-08-rundll32_control_rundll_world_writable_directory.md +++ /dev/null @@ -1,180 +0,0 @@ ---- -title: "Rundll32 Control RunDLL World Writable Directory" -excerpt: "System Binary Proxy Execution -, Rundll32 -" -categories: - - Endpoint -last_modified_at: 2021-09-08 -toc: true -toc_label: "" -tags: - - System Binary Proxy Execution - - Rundll32 - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2021-40444 - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following detection identifies rundll32.exe with `control_rundll` within the command-line, loading a .cpl or another file type from windows\temp, programdata, or appdata. Developed in relation to CVE-2021-40444. Rundll32.exe can also be used to execute Control Panel Item files (.cpl) through the undocumented shell32.dll functions Control_RunDLL and Control_RunDLLAsUser. Double-clicking a .cpl file also causes rundll32.exe to execute. This is written to be a bit more broad by not including .cpl. The paths are specified, add more as needed. During triage, review parallel processes to identify any further suspicious behavior. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-09-08 -- **Author**: Michael Haag, Splunk -- **ID**: 1adffe86-10c3-11ec-8ce6-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218](https://attack.mitre.org/techniques/T1218/) | System Binary Proxy Execution | Defense Evasion | - -| [T1218.011](https://attack.mitre.org/techniques/T1218/011/) | Rundll32 | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2021-40444](https://nvd.nist.gov/vuln/detail/CVE-2021-40444) | Microsoft MSHTML Remote Code Execution Vulnerability | 6.8 | - - - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_rundll32` Processes.process=*Control_RunDLL* AND Processes.process IN ("*\\appdata\\*", "*\\windows\\temp\\*", "*\\programdata\\*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.original_file_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `rundll32_control_rundll_world_writable_directory_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [process_rundll32](https://github.com/splunk/security_content/blob/develop/macros/process_rundll32.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **rundll32_control_rundll_world_writable_directory_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -This may be tuned, or a new one related, by adding .cpl to command-line. However, it's important to look for both. Tune/filter as needed. - -#### Associated Analytic story -* [Suspicious Rundll32 Activity](/stories/suspicious_rundll32_activity) -* [Microsoft MSHTML Remote Code Execution CVE-2021-40444](/stories/microsoft_mshtml_remote_code_execution_cve-2021-40444) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to load a suspicious file from disk. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://strontic.github.io/xcyclopedia/library/rundll32.exe-111474C61232202B5B588D2B512CBB25.html](https://strontic.github.io/xcyclopedia/library/rundll32.exe-111474C61232202B5B588D2B512CBB25.html) -* [https://app.any.run/tasks/36c14029-9df8-439c-bba0-45f2643b0c70/](https://app.any.run/tasks/36c14029-9df8-439c-bba0-45f2643b0c70/) -* [https://attack.mitre.org/techniques/T1218/011/](https://attack.mitre.org/techniques/T1218/011/) -* [https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40444](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40444) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.002/T1218.002.yaml](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.002/T1218.002.yaml) -* [https://redcanary.com/blog/intelligence-insights-december-2021/](https://redcanary.com/blog/intelligence-insights-december-2021/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.002/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.002/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-09-extraction_of_registry_hives.md b/docs/_posts/2021-09-09-extraction_of_registry_hives.md deleted file mode 100644 index f34dcadfbc..0000000000 --- a/docs/_posts/2021-09-09-extraction_of_registry_hives.md +++ /dev/null @@ -1,171 +0,0 @@ ---- -title: "Extraction of Registry Hives" -excerpt: "Security Account Manager -, OS Credential Dumping -" -categories: - - Endpoint -last_modified_at: 2021-09-09 -toc: true -toc_label: "" -tags: - - Security Account Manager - - OS Credential Dumping - - Credential Access - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the use of `reg.exe` exporting Windows Registry hives containing credentials. Adversaries may use this technique to export registry hives for offline credential access attacks. Typically found executed from a untrusted process or script. Upon execution, a file will be written to disk. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-09-09 -- **Author**: Michael Haag, Splunk -- **ID**: 8bbb7d58-b360-11eb-ba21-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1003.002](https://attack.mitre.org/techniques/T1003/002/) | Security Account Manager | Credential Access | - -| [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_reg` (Processes.process=*save* OR Processes.process=*export*) AND (Processes.process="*\sam *" OR Processes.process="*\system *" OR Processes.process="*\security *") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `extraction_of_registry_hives_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [process_reg](https://github.com/splunk/security_content/blob/develop/macros/process_reg.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **extraction_of_registry_hives_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -It is possible some agent based products will generate false positives. Filter as needed. - -#### Associated Analytic story -* [DarkSide Ransomware](/stories/darkside_ransomware) -* [Credential Dumping](/stories/credential_dumping) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 56.0 | 80 | 70 | Suspicious use of `reg.exe` exporting Windows Registry hives containing credentials executed on $dest$ by user $user$, with a parent process of $parent_process_id$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.mandiant.com/resources/shining-a-light-on-darkside-ransomware-operations](https://www.mandiant.com/resources/shining-a-light-on-darkside-ransomware-operations) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1003.002/T1003.002.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1003.002/T1003.002.md) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.002/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.002/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/extraction_of_registry_hives.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-09-09-mshtml_module_load_in_office_product.md b/docs/_posts/2021-09-09-mshtml_module_load_in_office_product.md deleted file mode 100644 index 283e5188e6..0000000000 --- a/docs/_posts/2021-09-09-mshtml_module_load_in_office_product.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: "MSHTML Module Load in Office Product" -excerpt: "Phishing -, Spearphishing Attachment -" -categories: - - Endpoint -last_modified_at: 2021-09-09 -toc: true -toc_label: "" -tags: - - Phishing - - Spearphishing Attachment - - Initial Access - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2021-40444 - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following detection identifies the module load of mshtml.dll into an Office product. This behavior has been related to CVE-2021-40444, whereas the malicious document will load ActiveX, which activates the MSHTML component. The vulnerability resides in the MSHTML component. During triage, identify parallel processes and capture any file modifications for analysis. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-09-09 -- **Author**: Michael Haag, Splunk -- **ID**: 5f1c168e-118b-11ec-84ff-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | - -| [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2021-40444](https://nvd.nist.gov/vuln/detail/CVE-2021-40444) | Microsoft MSHTML Remote Code Execution Vulnerability | 6.8 | - - - -
-
- -#### Search - -``` -`sysmon` EventID=7 process_name IN ("winword.exe","excel.exe","powerpnt.exe","mspub.exe","visio.exe","wordpad.exe","wordview.exe") ImageLoaded IN ("*\\mshtml.dll", "*\\Microsoft.mshtml.dll","*\\IE.Interop.MSHTML.dll","*\\MshtmlDac.dll","*\\MshtmlDed.dll","*\\MshtmlDer.dll") -| stats count min(_time) as firstTime max(_time) as lastTime by Computer, process_name, ImageLoaded, OriginalFileName, process_id -| rename Computer as dest -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `mshtml_module_load_in_office_product_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **mshtml_module_load_in_office_product_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* ImageLoaded -* process_name -* OriginalFileName -* process_id -* dest - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process names and image loads from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -Limited false positives will be present, however, tune as necessary. - -#### Associated Analytic story -* [Spearphishing Attachments](/stories/spearphishing_attachments) -* [Microsoft MSHTML Remote Code Execution CVE-2021-40444](/stories/microsoft_mshtml_remote_code_execution_cve-2021-40444) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | An instance of $process_name$ was identified on endpoint $dest$ loading mshtml.dll. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://app.any.run/tasks/36c14029-9df8-439c-bba0-45f2643b0c70/](https://app.any.run/tasks/36c14029-9df8-439c-bba0-45f2643b0c70/) -* [https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40444](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40444) -* [https://strontic.github.io/xcyclopedia/index-dll](https://strontic.github.io/xcyclopedia/index-dll) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_mshtml.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_mshtml.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/mshtml_module_load_in_office_product.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-10-getnettcpconnection_with_powershell_script_block.md b/docs/_posts/2021-09-10-getnettcpconnection_with_powershell_script_block.md deleted file mode 100644 index 9cbc7d7180..0000000000 --- a/docs/_posts/2021-09-10-getnettcpconnection_with_powershell_script_block.md +++ /dev/null @@ -1,154 +0,0 @@ ---- -title: "GetNetTcpconnection with PowerShell Script Block" -excerpt: "System Network Connections Discovery -" -categories: - - Endpoint -last_modified_at: 2021-09-10 -toc: true -toc_label: "" -tags: - - System Network Connections Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-NetTcpconnection ` commandlet. This commandlet is used to return a listing of network connections on a compromised system. Red Teams and adversaries alike may use this commandlet for situational awareness and Active Directory Discovery. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-09-10 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 091712ff-b02a-4d43-82ed-34765515d95d - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1049](https://attack.mitre.org/techniques/T1049/) | System Network Connections Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 (Message = "*Get-NetTcpconnection*") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `getnettcpconnection_with_powershell_script_block_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **getnettcpconnection_with_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Message -* ComputerName -* User - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -Administrators or power users may use this PowerShell commandlet for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | Network Connection discovery on $dest$ by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1049/](https://attack.mitre.org/techniques/T1049/) -* [https://docs.microsoft.com/en-us/powershell/module/nettcpip/get-nettcpconnection?view=windowsserver2019-ps](https://docs.microsoft.com/en-us/powershell/module/nettcpip/get-nettcpconnection?view=windowsserver2019-ps) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1049/AD_discovery/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1049/AD_discovery/windows-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-10-network_connection_discovery_with_arp.md b/docs/_posts/2021-09-10-network_connection_discovery_with_arp.md deleted file mode 100644 index c89ce7ea75..0000000000 --- a/docs/_posts/2021-09-10-network_connection_discovery_with_arp.md +++ /dev/null @@ -1,162 +0,0 @@ ---- -title: "Network Connection Discovery With Arp" -excerpt: "System Network Connections Discovery -" -categories: - - Endpoint -last_modified_at: 2021-09-10 -toc: true -toc_label: "" -tags: - - System Network Connections Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for the execution of `arp.exe` utilized to get a listing of network connections on a compromised system. Red Teams and adversaries alike may use arp.exe for situational awareness and Active Directory Discovery. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-09-10 -- **Author**: Mauricio Velazco, Splunk -- **ID**: ae008c0f-83bd-4ed4-9350-98d4328e15d2 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1049](https://attack.mitre.org/techniques/T1049/) | System Network Connections Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="arp.exe") (Processes.process=*-a*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `network_connection_discovery_with_arp_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **network_connection_discovery_with_arp_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Administrators or power users may use this command for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | Network Connection discovery on $dest$ by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1049/](https://attack.mitre.org/techniques/T1049/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1049/AD_discovery/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1049/AD_discovery/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/network_connection_discovery_with_arp.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-10-network_connection_discovery_with_net.md b/docs/_posts/2021-09-10-network_connection_discovery_with_net.md deleted file mode 100644 index 4c0494e90a..0000000000 --- a/docs/_posts/2021-09-10-network_connection_discovery_with_net.md +++ /dev/null @@ -1,163 +0,0 @@ ---- -title: "Network Connection Discovery With Net" -excerpt: "System Network Connections Discovery -" -categories: - - Endpoint -last_modified_at: 2021-09-10 -toc: true -toc_label: "" -tags: - - System Network Connections Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for the execution of `net.exe` with command-line arguments utilized to get a listing of network connections on a compromised system. Red Teams and adversaries alike may use net.exe for situational awareness and Active Directory Discovery. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-09-10 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 640337e5-6e41-4b7f-af06-9d9eab5e1e2d - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1049](https://attack.mitre.org/techniques/T1049/) | System Network Connections Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="net.exe" OR Processes.process_name="net1.exe") (Processes.process=*use*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `network_connection_discovery_with_net_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **network_connection_discovery_with_net_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Administrators or power users may use this command for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) -* [Azorult](/stories/azorult) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | Network Connection discovery on $dest$ by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1049/](https://attack.mitre.org/techniques/T1049/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1049/AD_discovery/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1049/AD_discovery/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/network_connection_discovery_with_net.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-10-network_connection_discovery_with_netstat.md b/docs/_posts/2021-09-10-network_connection_discovery_with_netstat.md deleted file mode 100644 index 02afe963b8..0000000000 --- a/docs/_posts/2021-09-10-network_connection_discovery_with_netstat.md +++ /dev/null @@ -1,162 +0,0 @@ ---- -title: "Network Connection Discovery With Netstat" -excerpt: "System Network Connections Discovery -" -categories: - - Endpoint -last_modified_at: 2021-09-10 -toc: true -toc_label: "" -tags: - - System Network Connections Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for the execution of `netstat.exe` with command-line arguments utilized to get a listing of network connections on a compromised system. Red Teams and adversaries alike may use netstat.exe for situational awareness and Active Directory Discovery. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-09-10 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 2cf5cc25-f39a-436d-a790-4857e5995ede - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1049](https://attack.mitre.org/techniques/T1049/) | System Network Connections Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="netstat.exe") (Processes.process=*-a*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `network_connection_discovery_with_netstat_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **network_connection_discovery_with_netstat_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Administrators or power users may use this command for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | Network Connection discovery on $dest$ by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1049/](https://attack.mitre.org/techniques/T1049/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1049/AD_discovery/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1049/AD_discovery/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/network_connection_discovery_with_netstat.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-10-office_product_writing_cab_or_inf.md b/docs/_posts/2021-09-10-office_product_writing_cab_or_inf.md deleted file mode 100644 index 285f6b2960..0000000000 --- a/docs/_posts/2021-09-10-office_product_writing_cab_or_inf.md +++ /dev/null @@ -1,175 +0,0 @@ ---- -title: "Office Product Writing cab or inf" -excerpt: "Phishing -, Spearphishing Attachment -" -categories: - - Endpoint -last_modified_at: 2021-09-10 -toc: true -toc_label: "" -tags: - - Phishing - - Spearphishing Attachment - - Initial Access - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2021-40444 - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies behavior related to CVE-2021-40444. Whereas the malicious document will load ActiveX and download the remote payload (.inf, .cab). During triage, review parallel processes and further activity on endpoint to identify additional patterns. Retrieve the file modifications and analyze further. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-09-10 -- **Author**: Michael Haag, Splunk -- **ID**: f48cd1d4-125a-11ec-a447-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | - -| [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2021-40444](https://nvd.nist.gov/vuln/detail/CVE-2021-40444) | Microsoft MSHTML Remote Code Execution Vulnerability | 6.8 | - - - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name IN ("winword.exe","excel.exe","powerpnt.exe","mspub.exe","visio.exe","wordpad.exe","wordview.exe") by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest -| `drop_dm_object_name(Processes)` -| join process_guid, _time [ -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_name IN ("*.inf","*.cab") by _time span=1h Filesystem.dest Filesystem.file_create_time Filesystem.file_name Filesystem.file_path -| `drop_dm_object_name(Filesystem)` -| fields _time dest file_create_time file_name file_path process_name process_path process] -| dedup file_create_time -| table dest, process_name, process, file_create_time, file_name, file_path -| `office_product_writing_cab_or_inf_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **office_product_writing_cab_or_inf_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* dest -* process_name -* process -* file_create_time -* file_name -* file_path - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node and `Filesystem` node. - -#### Known False Positives -The query is structured in a way that `action` (read, create) is not defined. Review the results of this query, filter, and tune as necessary. It may be necessary to generate this query specific to your endpoint product. - -#### Associated Analytic story -* [Spearphishing Attachments](/stories/spearphishing_attachments) -* [Microsoft MSHTML Remote Code Execution CVE-2021-40444](/stories/microsoft_mshtml_remote_code_execution_cve-2021-40444) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | An instance of $process_name$ was identified on $dest$ writing an inf or cab file to this. This is not typical of $process_name$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://twitter.com/vxunderground/status/1436326057179860992?s=20](https://twitter.com/vxunderground/status/1436326057179860992?s=20) -* [https://app.any.run/tasks/36c14029-9df8-439c-bba0-45f2643b0c70/](https://app.any.run/tasks/36c14029-9df8-439c-bba0-45f2643b0c70/) -* [https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40444](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40444) -* [https://twitter.com/RonnyTNL/status/1436334640617373699?s=20](https://twitter.com/RonnyTNL/status/1436334640617373699?s=20) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_cabinf.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_cabinf.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/office_product_writing_cab_or_inf.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-13-getcurrent_user_with_powershell.md b/docs/_posts/2021-09-13-getcurrent_user_with_powershell.md deleted file mode 100644 index 7e6072e5ca..0000000000 --- a/docs/_posts/2021-09-13-getcurrent_user_with_powershell.md +++ /dev/null @@ -1,163 +0,0 @@ ---- -title: "GetCurrent User with PowerShell" -excerpt: "System Owner/User Discovery -" -categories: - - Endpoint -last_modified_at: 2021-09-13 -toc: true -toc_label: "" -tags: - - System Owner/User Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for the execution of `powerhsell.exe` with command-line arguments that execute the `GetCurrent` method of the WindowsIdentity .NET class. This method returns an object that represents the current Windows user. Red Teams and adversaries may leverage this method to identify the logged user on a compromised endpoint for situational awareness and Active Directory Discovery. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-09-13 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 7eb9c3d5-c98c-4088-acc5-8240bad15379 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1033](https://attack.mitre.org/techniques/T1033/) | System Owner/User Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="powershell.exe") (Processes.process=*System.Security.Principal.WindowsIdentity* OR Processes.process=*GetCurrent()*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `getcurrent_user_with_powershell_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **getcurrent_user_with_powershell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Administrators or power users may use this command for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | System user discovery on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1033/](https://attack.mitre.org/techniques/T1033/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1033/AD_discovery/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1033/AD_discovery/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/getcurrent_user_with_powershell.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-13-getcurrent_user_with_powershell_script_block.md b/docs/_posts/2021-09-13-getcurrent_user_with_powershell_script_block.md deleted file mode 100644 index c9b55ec456..0000000000 --- a/docs/_posts/2021-09-13-getcurrent_user_with_powershell_script_block.md +++ /dev/null @@ -1,152 +0,0 @@ ---- -title: "GetCurrent User with PowerShell Script Block" -excerpt: "System Owner/User Discovery -" -categories: - - Endpoint -last_modified_at: 2021-09-13 -toc: true -toc_label: "" -tags: - - System Owner/User Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `GetCurrent` method of the WindowsIdentity .NET class. This method returns an object that represents the current Windows user. Red Teams and adversaries may leverage this method to identify the logged user on a compromised endpoint for situational awareness and Active Directory Discovery. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-09-13 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 80879283-c30f-44f7-8471-d1381f6d437a - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1033](https://attack.mitre.org/techniques/T1033/) | System Owner/User Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 (Message = "*[System.Security.Principal.WindowsIdentity]*" AND Message = "*GetCurrent()*") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `getcurrent_user_with_powershell_script_block_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -Note that **getcurrent_user_with_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Path -* Message -* OpCode -* ComputerName -* User -* EventCode - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -Administrators or power users may use this PowerShell commandlet for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | System user discovery on $dest$ | - - -#### Reference - -* [https://attack.mitre.org/techniques/T1033/](https://attack.mitre.org/techniques/T1033/) -* [https://docs.microsoft.com/en-us/dotnet/api/system.security.principal.windowsidentity.getcurrent?view=net-5.0](https://docs.microsoft.com/en-us/dotnet/api/system.security.principal.windowsidentity.getcurrent?view=net-5.0) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1033/AD_discovery/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1033/AD_discovery/windows-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-13-jscript_execution_using_cscript_app.md b/docs/_posts/2021-09-13-jscript_execution_using_cscript_app.md deleted file mode 100644 index 3fcf5e264c..0000000000 --- a/docs/_posts/2021-09-13-jscript_execution_using_cscript_app.md +++ /dev/null @@ -1,166 +0,0 @@ ---- -title: "Jscript Execution Using Cscript App" -excerpt: "Command and Scripting Interpreter -, JavaScript -" -categories: - - Endpoint -last_modified_at: 2021-09-13 -toc: true -toc_label: "" -tags: - - Command and Scripting Interpreter - - JavaScript - - Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect a execution of jscript using cscript process. Commonly when a user run jscript file it was executed by wscript.exe application. This technique was seen in FIN7 js implant to execute its malicious script using cscript process. This behavior is uncommon and a good artifacts to check further anomalies within the network - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-09-13 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 002f1e24-146e-11ec-a470-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -| [T1059.007](https://attack.mitre.org/techniques/T1059/007/) | JavaScript | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.parent_process_name = "cscript.exe" AND Processes.parent_process = "*//e:jscript*") OR (Processes.process_name = "cscript.exe" AND Processes.process = "*//e:jscript*") by Processes.parent_process_name Processes.parent_process Processes.process_name Processes.process_id Processes.process Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `jscript_execution_using_cscript_app_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **jscript_execution_using_cscript_app_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.parent_process_name -* Processes.parent_process -* Processes.process_name -* Processes.process_id -* Processes.process -* Processes.dest -* Processes.user - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [FIN7](/stories/fin7) -* [Remcos](/stories/remcos) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | Process name $process_name$ with commandline $process$ to execute jscript in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.mandiant.com/resources/fin7-pursuing-an-enigmatic-and-evasive-global-criminal-operation](https://www.mandiant.com/resources/fin7-pursuing-an-enigmatic-and-evasive-global-criminal-operation) -* [https://attack.mitre.org/groups/G0046/](https://attack.mitre.org/groups/G0046/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/fin7/fin7_macro_js_1/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/fin7/fin7_macro_js_1/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/jscript_execution_using_cscript_app.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-13-ms_scripting_process_loading_ldap_module.md b/docs/_posts/2021-09-13-ms_scripting_process_loading_ldap_module.md deleted file mode 100644 index aa61d94c40..0000000000 --- a/docs/_posts/2021-09-13-ms_scripting_process_loading_ldap_module.md +++ /dev/null @@ -1,164 +0,0 @@ ---- -title: "MS Scripting Process Loading Ldap Module" -excerpt: "Command and Scripting Interpreter -, JavaScript -" -categories: - - Endpoint -last_modified_at: 2021-09-13 -toc: true -toc_label: "" -tags: - - Command and Scripting Interpreter - - JavaScript - - Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect a suspicious MS scripting process such as wscript.exe or cscript.exe that loading ldap module to process ldap query. This behavior was seen in FIN7 implant where it uses javascript to execute ldap query to parse host information that will send to its C2 server. this anomaly detections is a good initial step to hunt further a suspicious ldap query or ldap related events to the host that may give you good information regarding ldap or AD information processing or might be a attacker. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-09-13 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 0b0c40dc-14a6-11ec-b267-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -| [T1059.007](https://attack.mitre.org/techniques/T1059/007/) | JavaScript | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventCode =7 Image IN ("*\\wscript.exe", "*\\cscript.exe") ImageLoaded IN ("*\\Wldap32.dll", "*\\adsldp.dll", "*\\adsldpc.dll") -| stats min(_time) as firstTime max(_time) as lastTime count by Image EventCode process_name ProcessId ProcessGuid Computer ImageLoaded -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `ms_scripting_process_loading_ldap_module_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **ms_scripting_process_loading_ldap_module_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Image -* EventCode -* process_name -* ProcessId -* ProcessGuid -* Computer -* ImageLoaded - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed rundll32.exe may be used. - -#### Known False Positives -automation scripting language may used by network operator to do ldap query. - -#### Associated Analytic story -* [FIN7](/stories/fin7) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 9.0 | 30 | 30 | $process_name$ loading ldap modules $ImageLoaded$ in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.mandiant.com/resources/fin7-pursuing-an-enigmatic-and-evasive-global-criminal-operation](https://www.mandiant.com/resources/fin7-pursuing-an-enigmatic-and-evasive-global-criminal-operation) -* [https://attack.mitre.org/groups/G0046/](https://attack.mitre.org/groups/G0046/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/fin7/fin7_js_2/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/fin7/fin7_js_2/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-13-ms_scripting_process_loading_wmi_module.md b/docs/_posts/2021-09-13-ms_scripting_process_loading_wmi_module.md deleted file mode 100644 index 663b1aeade..0000000000 --- a/docs/_posts/2021-09-13-ms_scripting_process_loading_wmi_module.md +++ /dev/null @@ -1,164 +0,0 @@ ---- -title: "MS Scripting Process Loading WMI Module" -excerpt: "Command and Scripting Interpreter -, JavaScript -" -categories: - - Endpoint -last_modified_at: 2021-09-13 -toc: true -toc_label: "" -tags: - - Command and Scripting Interpreter - - JavaScript - - Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect a suspicious MS scripting process such as wscript.exe or cscript.exe that loading wmi module to process wmi query. This behavior was seen in FIN7 implant where it uses javascript to execute wmi query to parse host information that will send to its C2 server. this anomaly detections is a good initial step to hunt further a suspicious wmi query or wmi related events to the host that may give you good information regarding process that are commonly using wmi query or modules or might be an attacker using this technique. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-09-13 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 2eba3d36-14a6-11ec-a682-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -| [T1059.007](https://attack.mitre.org/techniques/T1059/007/) | JavaScript | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventCode =7 Image IN ("*\\wscript.exe", "*\\cscript.exe") ImageLoaded IN ("*\\fastprox.dll", "*\\wbemdisp.dll", "*\\wbemprox.dll", "*\\wbemsvc.dll" , "*\\wmiutils.dll", "*\\wbemcomn.dll") -| stats min(_time) as firstTime max(_time) as lastTime count by Image EventCode process_name ProcessId ProcessGuid Computer ImageLoaded -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `ms_scripting_process_loading_wmi_module_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **ms_scripting_process_loading_wmi_module_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Image -* EventCode -* process_name -* ProcessId -* ProcessGuid -* Computer -* ImageLoaded - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed rundll32.exe may be used. - -#### Known False Positives -automation scripting language may used by network operator to do ldap query. - -#### Associated Analytic story -* [FIN7](/stories/fin7) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 9.0 | 30 | 30 | $process_name$ loading wmi modules $ImageLoaded$ in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.mandiant.com/resources/fin7-pursuing-an-enigmatic-and-evasive-global-criminal-operation](https://www.mandiant.com/resources/fin7-pursuing-an-enigmatic-and-evasive-global-criminal-operation) -* [https://attack.mitre.org/groups/G0046/](https://attack.mitre.org/groups/G0046/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/fin7/fin7_js_2/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/fin7/fin7_js_2/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-13-office_application_drop_executable.md b/docs/_posts/2021-09-13-office_application_drop_executable.md deleted file mode 100644 index ad8861de56..0000000000 --- a/docs/_posts/2021-09-13-office_application_drop_executable.md +++ /dev/null @@ -1,168 +0,0 @@ ---- -title: "Office Application Drop Executable" -excerpt: "Phishing -, Spearphishing Attachment -" -categories: - - Endpoint -last_modified_at: 2021-09-13 -toc: true -toc_label: "" -tags: - - Phishing - - Spearphishing Attachment - - Initial Access - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect a suspicious MS office application that drop or create executables or script in the host. This behavior is commonly seen in spear phishing office attachment where it drop malicious files or script to compromised the host. It might be some normal macro may drop script or tools as part of automation but still this behavior is reallly suspicious and not commonly seen in normal office application - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-09-13 -- **Author**: Teoderick Contreras, Michael Haag Splunk -- **ID**: 73ce70c4-146d-11ec-9184-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | - -| [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name IN ("winword.exe","excel.exe","powerpnt.exe","mspub.exe","visio.exe","wordpad.exe","wordview.exe") by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_name IN ("*.exe","*.dll","*.pif","*.scr","*.js","*.vbs","*.vbe","*.ps1") by _time span=1h Filesystem.dest Filesystem.file_create_time Filesystem.file_name Filesystem.process_guid Filesystem.file_path -| `drop_dm_object_name(Filesystem)` -| rename process_guid as proc_guid -| fields _time dest file_create_time file_name file_path process_name process_path process proc_guid] -| dedup file_create_time -| table dest, process_name, process, file_create_time, file_name, file_path, proc_guid -| `office_application_drop_executable_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **office_application_drop_executable_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Image -* TargetFilename -* ProcessGuid -* dest -* user_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed rundll32.exe may be used. - -#### Known False Positives -office macro for automation may do this behavior - -#### Associated Analytic story -* [FIN7](/stories/fin7) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 64.0 | 80 | 80 | process $process_name$ drops a file $TargetFilename$ in host $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.mandiant.com/resources/fin7-pursuing-an-enigmatic-and-evasive-global-criminal-operation](https://www.mandiant.com/resources/fin7-pursuing-an-enigmatic-and-evasive-global-criminal-operation) -* [https://attack.mitre.org/groups/G0046/](https://attack.mitre.org/groups/G0046/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/fin7/fin7_macro_js_1/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/fin7/fin7_macro_js_1/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/office_application_drop_executable.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-13-system_user_discovery_with_query.md b/docs/_posts/2021-09-13-system_user_discovery_with_query.md deleted file mode 100644 index 3d5f542883..0000000000 --- a/docs/_posts/2021-09-13-system_user_discovery_with_query.md +++ /dev/null @@ -1,163 +0,0 @@ ---- -title: "System User Discovery With Query" -excerpt: "System Owner/User Discovery -" -categories: - - Endpoint -last_modified_at: 2021-09-13 -toc: true -toc_label: "" -tags: - - System Owner/User Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for the execution of `query.exe` with command-line arguments utilized to discover the logged user. Red Teams and adversaries alike may leverage `query.exe` to identify system users on a compromised endpoint for situational awareness and Active Directory Discovery. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-09-13 -- **Author**: Mauricio Velazco, Splunk -- **ID**: ad03bfcf-8a91-4bc2-a500-112993deba87 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1033](https://attack.mitre.org/techniques/T1033/) | System Owner/User Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="query.exe") (Processes.process=*user*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `system_user_discovery_with_query_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **system_user_discovery_with_query_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Administrators or power users may use this command for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | System user discovery on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1033/](https://attack.mitre.org/techniques/T1033/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1033/AD_discovery/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1033/AD_discovery/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/system_user_discovery_with_query.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-13-system_user_discovery_with_whoami.md b/docs/_posts/2021-09-13-system_user_discovery_with_whoami.md deleted file mode 100644 index 6c269f5979..0000000000 --- a/docs/_posts/2021-09-13-system_user_discovery_with_whoami.md +++ /dev/null @@ -1,163 +0,0 @@ ---- -title: "System User Discovery With Whoami" -excerpt: "System Owner/User Discovery -" -categories: - - Endpoint -last_modified_at: 2021-09-13 -toc: true -toc_label: "" -tags: - - System Owner/User Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for the execution of `whoami.exe` without any arguments. This windows native binary prints out the current logged user. Red Teams and adversaries alike may leverage `whoami.exe` to identify system users on a compromised endpoint for situational awareness and Active Directory Discovery. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-09-13 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 894fc43e-6f50-47d5-a68b-ee9ee23e18f4 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1033](https://attack.mitre.org/techniques/T1033/) | System Owner/User Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="whoami.exe") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `system_user_discovery_with_whoami_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **system_user_discovery_with_whoami_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Administrators or power users may use this command for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | System user discovery on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1033/](https://attack.mitre.org/techniques/T1033/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1033/AD_discovery/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1033/AD_discovery/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/system_user_discovery_with_whoami.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-13-user_discovery_with_env_vars_powershell.md b/docs/_posts/2021-09-13-user_discovery_with_env_vars_powershell.md deleted file mode 100644 index 52e651933e..0000000000 --- a/docs/_posts/2021-09-13-user_discovery_with_env_vars_powershell.md +++ /dev/null @@ -1,163 +0,0 @@ ---- -title: "User Discovery With Env Vars PowerShell" -excerpt: "System Owner/User Discovery -" -categories: - - Endpoint -last_modified_at: 2021-09-13 -toc: true -toc_label: "" -tags: - - System Owner/User Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for the execution of `powershell.exe` with command-line arguments that leverage PowerShell environment variables to identify the current logged user. Red Teams and adversaries may leverage this method to identify the logged user on a compromised endpoint for situational awareness and Active Directory Discovery. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-09-13 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 0cdf318b-a0dd-47d7-b257-c621c0247de8 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1033](https://attack.mitre.org/techniques/T1033/) | System Owner/User Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="powershell.exe") (Processes.process="*$env:UserName*" OR Processes.process="*[System.Environment]::UserName*") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `user_discovery_with_env_vars_powershell_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **user_discovery_with_env_vars_powershell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Administrators or power users may use this command for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | System user discovery on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1033/](https://attack.mitre.org/techniques/T1033/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1033/AD_discovery/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1033/AD_discovery/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/user_discovery_with_env_vars_powershell.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-13-user_discovery_with_env_vars_powershell_script_block.md b/docs/_posts/2021-09-13-user_discovery_with_env_vars_powershell_script_block.md deleted file mode 100644 index 97b7343e2b..0000000000 --- a/docs/_posts/2021-09-13-user_discovery_with_env_vars_powershell_script_block.md +++ /dev/null @@ -1,151 +0,0 @@ ---- -title: "User Discovery With Env Vars PowerShell Script Block" -excerpt: "System Owner/User Discovery -" -categories: - - Endpoint -last_modified_at: 2021-09-13 -toc: true -toc_label: "" -tags: - - System Owner/User Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the use of PowerShell environment variables to identify the current logged user. Red Teams and adversaries may leverage this method to identify the logged user on a compromised endpoint for situational awareness and Active Directory Discovery. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-09-13 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 77f41d9e-b8be-47e3-ab35-5776f5ec1d20 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1033](https://attack.mitre.org/techniques/T1033/) | System Owner/User Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 (Message = "*$env:UserName*" OR Message = "*[System.Environment]::UserName*") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `user_discovery_with_env_vars_powershell_script_block_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -Note that **user_discovery_with_env_vars_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Path -* Message -* OpCode -* ComputerName -* User -* EventCode - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -Administrators or power users may use this PowerShell commandlet for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | System user discovery on $dest$ | - - -#### Reference - -* [https://attack.mitre.org/techniques/T1033/](https://attack.mitre.org/techniques/T1033/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1033/AD_discovery/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1033/AD_discovery/windows-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-13-xsl_script_execution_with_wmic.md b/docs/_posts/2021-09-13-xsl_script_execution_with_wmic.md deleted file mode 100644 index a7fcdc4bf3..0000000000 --- a/docs/_posts/2021-09-13-xsl_script_execution_with_wmic.md +++ /dev/null @@ -1,164 +0,0 @@ ---- -title: "XSL Script Execution With WMIC" -excerpt: "XSL Script Processing -" -categories: - - Endpoint -last_modified_at: 2021-09-13 -toc: true -toc_label: "" -tags: - - XSL Script Processing - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect a suspicious wmic.exe process or renamed wmic process to execute malicious xsl file. This technique was seen in FIN7 to execute its malicous jscript using the .xsl as the loader with the help of wmic.exe process. This TTP is really a good indicator for you to hunt further for FIN7 or other attacker that known to used this technique. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-09-13 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 004e32e2-146d-11ec-a83f-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1220](https://attack.mitre.org/techniques/T1220/) | XSL Script Processing | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_wmic` Processes.process = "*os get*" Processes.process="*/format:*" Processes.process = "*.xsl*" by Processes.parent_process_name Processes.parent_process Processes.process_name Processes.process_id Processes.process Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `xsl_script_execution_with_wmic_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [process_wmic](https://github.com/splunk/security_content/blob/develop/macros/process_wmic.yml) - -> :information_source: -> **xsl_script_execution_with_wmic_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.parent_process_name -* Processes.parent_process -* Processes.process_name -* Processes.process_id -* Processes.process -* Processes.dest -* Processes.user - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [FIN7](/stories/fin7) -* [Suspicious WMI Use](/stories/suspicious_wmi_use) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ utilizing wmic to load a XSL script. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.mandiant.com/resources/fin7-pursuing-an-enigmatic-and-evasive-global-criminal-operation](https://www.mandiant.com/resources/fin7-pursuing-an-enigmatic-and-evasive-global-criminal-operation) -* [https://attack.mitre.org/groups/G0046/](https://attack.mitre.org/groups/G0046/) -* [https://web.archive.org/web/20190814201250/https://subt0x11.blogspot.com/2018/04/wmicexe-whitelisting-bypass-hacking.html](https://web.archive.org/web/20190814201250/https://subt0x11.blogspot.com/2018/04/wmicexe-whitelisting-bypass-hacking.html) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1220/T1220.md#atomic-test-3---wmic-bypass-using-local-xsl-file](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1220/T1220.md#atomic-test-3---wmic-bypass-using-local-xsl-file) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/fin7/fin7_macro_js_1/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/fin7/fin7_macro_js_1/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/xsl_script_execution_with_wmic.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-14-cmdline_tool_not_executed_in_cmd_shell.md b/docs/_posts/2021-09-14-cmdline_tool_not_executed_in_cmd_shell.md deleted file mode 100644 index 0df0d7499b..0000000000 --- a/docs/_posts/2021-09-14-cmdline_tool_not_executed_in_cmd_shell.md +++ /dev/null @@ -1,169 +0,0 @@ ---- -title: "Cmdline Tool Not Executed In CMD Shell" -excerpt: "Command and Scripting Interpreter -, JavaScript -" -categories: - - Endpoint -last_modified_at: 2021-09-14 -toc: true -toc_label: "" -tags: - - Command and Scripting Interpreter - - JavaScript - - Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-09-14 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 6c3f7dd8-153c-11ec-ac2d-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -| [T1059.007](https://attack.mitre.org/techniques/T1059/007/) | JavaScript | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name = "ipconfig.exe" OR Processes.process_name = "systeminfo.exe") AND NOT (Processes.parent_process_name = "cmd.exe" OR Processes.parent_process_name = "powershell*" OR Processes.parent_process_name="pwsh.exe" OR Processes.parent_process_name = "explorer.exe") by Processes.parent_process_name Processes.parent_process Processes.process_name Processes.original_file_name Processes.process_id Processes.process Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `cmdline_tool_not_executed_in_cmd_shell_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **cmdline_tool_not_executed_in_cmd_shell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -A network operator or systems administrator may utilize an automated host discovery application that may generate false positives. Filter as needed. - -#### Associated Analytic story -* [FIN7](/stories/fin7) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 56.0 | 70 | 80 | A non-standard parent process $parent_process_name$ spawned child process $process_name$ to execute command-line tool on $dest$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.mandiant.com/resources/fin7-pursuing-an-enigmatic-and-evasive-global-criminal-operation](https://www.mandiant.com/resources/fin7-pursuing-an-enigmatic-and-evasive-global-criminal-operation) -* [https://attack.mitre.org/groups/G0046/](https://attack.mitre.org/groups/G0046/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/fin7/jssloader/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/fin7/jssloader/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-14-get_wmiobject_group_discovery.md b/docs/_posts/2021-09-14-get_wmiobject_group_discovery.md deleted file mode 100644 index 0c112c1c9b..0000000000 --- a/docs/_posts/2021-09-14-get_wmiobject_group_discovery.md +++ /dev/null @@ -1,169 +0,0 @@ ---- -title: "Get WMIObject Group Discovery" -excerpt: "Permission Groups Discovery -, Local Groups -" -categories: - - Endpoint -last_modified_at: 2021-09-14 -toc: true -toc_label: "" -tags: - - Permission Groups Discovery - - Local Groups - - Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following hunting analytic identifies the use of `Get-WMIObject Win32_Group` being used with PowerShell to identify local groups on the endpoint. \ Typically, by itself, is not malicious but may raise suspicion based on time of day, endpoint and username. \ During triage, review parallel processes and identify any further suspicious behavior. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-09-14 -- **Author**: Michael Haag, Splunk -- **ID**: 5434f670-155d-11ec-8cca-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | - -| [T1069.001](https://attack.mitre.org/techniques/T1069/001/) | Local Groups | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name=powershell.exe OR processes.process_name=cmd.exe) (Processes.process="*Get-WMIObject*" AND Processes.process="*Win32_Group*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.original_file_name Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `get_wmiobject_group_discovery_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **get_wmiobject_group_discovery_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -False positives may be present. Tune as needed. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | System group discovery on $dest$ by $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1069/001/](https://attack.mitre.org/techniques/T1069/001/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1069.001/T1069.001.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1069.001/T1069.001.md) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.001/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.001/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/get_wmiobject_group_discovery.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-14-get_wmiobject_group_discovery_with_script_block_logging.md b/docs/_posts/2021-09-14-get_wmiobject_group_discovery_with_script_block_logging.md deleted file mode 100644 index d831dda2a3..0000000000 --- a/docs/_posts/2021-09-14-get_wmiobject_group_discovery_with_script_block_logging.md +++ /dev/null @@ -1,162 +0,0 @@ ---- -title: "Get WMIObject Group Discovery with Script Block Logging" -excerpt: "Permission Groups Discovery -, Local Groups -" -categories: - - Endpoint -last_modified_at: 2021-09-14 -toc: true -toc_label: "" -tags: - - Permission Groups Discovery - - Local Groups - - Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify suspicious PowerShell execution. Script Block Logging captures the command sent to PowerShell, the full command to be executed. Upon enabling, logs will output to Windows event logs. Dependent upon volume, enable on critical endpoints or all. \ -This analytic identifies the usage of `Get-WMIObject Win32_Group`, which is typically used as a way to identify groups on the endpoint. Typically, by itself, is not malicious but may raise suspicion based on time of day, endpoint and username. \ -During triage, review parallel processes using an EDR product or 4688 events. It will be important to understand the timeline of events around this activity. Review the entire logged PowerShell script block. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-09-14 -- **Author**: Michael Haag, Splunk -- **ID**: 69df7f7c-155d-11ec-a055-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | - -| [T1069.001](https://attack.mitre.org/techniques/T1069/001/) | Local Groups | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 Message = "*Get-WMIObject*" AND Message = "*Win32_Group*" -| stats count min(_time) as firstTime max(_time) as lastTime by Message OpCode ComputerName User EventCode -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `get_wmiobject_group_discovery_with_script_block_logging_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -Note that **get_wmiobject_group_discovery_with_script_block_logging_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Message -* ComputerName -* User - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -False positives may be present. Tune as needed. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | System group discovery enumeration on $dest$ by $user$. | - - -#### Reference - -* [https://www.splunk.com/en_us/blog/security/powershell-detections-threat-research-release-august-2021.html](https://www.splunk.com/en_us/blog/security/powershell-detections-threat-research-release-august-2021.html) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1069.001/T1069.001.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1069.001/T1069.001.md) -* [https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.](https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.) -* [https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63](https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63) -* [https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf](https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf) -* [https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/](https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.001/atomic_red_team/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.001/atomic_red_team/windows-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-14-net_localgroup_discovery.md b/docs/_posts/2021-09-14-net_localgroup_discovery.md deleted file mode 100644 index cae36a82be..0000000000 --- a/docs/_posts/2021-09-14-net_localgroup_discovery.md +++ /dev/null @@ -1,171 +0,0 @@ ---- -title: "Net Localgroup Discovery" -excerpt: "Permission Groups Discovery -, Local Groups -" -categories: - - Endpoint -last_modified_at: 2021-09-14 -toc: true -toc_label: "" -tags: - - Permission Groups Discovery - - Local Groups - - Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following hunting analytic will identify the use of localgroup discovery using `net localgroup`. During triage, review parallel processes and identify any further suspicious behavior. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-09-14 -- **Author**: Michael Haag, Splunk -- **ID**: 54f5201e-155b-11ec-a6e2-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | - -| [T1069.001](https://attack.mitre.org/techniques/T1069/001/) | Local Groups | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=net.exe OR Processes.process_name=net1.exe (Processes.process="*localgroup*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.original_file_name Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `net_localgroup_discovery_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **net_localgroup_discovery_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -False positives may be present. Tune as needed. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) -* [Windows Discovery Techniques](/stories/windows_discovery_techniques) -* [Azorult](/stories/azorult) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | Local group discovery on $dest$ by $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1069/001/](https://attack.mitre.org/techniques/T1069/001/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1069.001/T1069.001.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1069.001/T1069.001.md) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.001/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.001/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/net_localgroup_discovery.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-14-powershell_get_localgroup_discovery.md b/docs/_posts/2021-09-14-powershell_get_localgroup_discovery.md deleted file mode 100644 index d1cfcb3cc0..0000000000 --- a/docs/_posts/2021-09-14-powershell_get_localgroup_discovery.md +++ /dev/null @@ -1,169 +0,0 @@ ---- -title: "PowerShell Get LocalGroup Discovery" -excerpt: "Permission Groups Discovery -, Local Groups -" -categories: - - Endpoint -last_modified_at: 2021-09-14 -toc: true -toc_label: "" -tags: - - Permission Groups Discovery - - Local Groups - - Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following hunting analytic identifies the use of `get-localgroup` being used with PowerShell to identify local groups on the endpoint. During triage, review parallel processes and identify any further suspicious behavior. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-09-14 -- **Author**: Michael Haag, Splunk -- **ID**: b71adfcc-155b-11ec-9413-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | - -| [T1069.001](https://attack.mitre.org/techniques/T1069/001/) | Local Groups | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name=powershell.exe OR Processes.process_name=cmd.exe) (Processes.process="*get-localgroup*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `powershell_get_localgroup_discovery_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **powershell_get_localgroup_discovery_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -False positives may be present. Tune as needed. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | Local group discovery on $dest$ by $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1069/001/](https://attack.mitre.org/techniques/T1069/001/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1069.001/T1069.001.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1069.001/T1069.001.md) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.001/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.001/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/powershell_get_localgroup_discovery.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-14-powershell_get_localgroup_discovery_with_script_block_logging.md b/docs/_posts/2021-09-14-powershell_get_localgroup_discovery_with_script_block_logging.md deleted file mode 100644 index 96189c8f79..0000000000 --- a/docs/_posts/2021-09-14-powershell_get_localgroup_discovery_with_script_block_logging.md +++ /dev/null @@ -1,166 +0,0 @@ ---- -title: "Powershell Get LocalGroup Discovery with Script Block Logging" -excerpt: "Permission Groups Discovery -, Local Groups -" -categories: - - Endpoint -last_modified_at: 2021-09-14 -toc: true -toc_label: "" -tags: - - Permission Groups Discovery - - Local Groups - - Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify suspicious PowerShell execution. Script Block Logging captures the command sent to PowerShell, the full command to be executed. Upon enabling, logs will output to Windows event logs. Dependent upon volume, enable on critical endpoints or all. \ -This analytic identifies PowerShell cmdlet - `get-localgroup` being ran. Typically, by itself, is not malicious but may raise suspicion based on time of day, endpoint and username. \ -During triage, review parallel processes using an EDR product or 4688 events. It will be important to understand the timeline of events around this activity. Review the entire logged PowerShell script block. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-09-14 -- **Author**: Michael Haag, Splunk -- **ID**: d7c6ad22-155c-11ec-bb64-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | - -| [T1069.001](https://attack.mitre.org/techniques/T1069/001/) | Local Groups | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 Message = "*get-localgroup*" -| stats count min(_time) as firstTime max(_time) as lastTime by Message OpCode ComputerName User EventCode -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `powershell_get_localgroup_discovery_with_script_block_logging_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **powershell_get_localgroup_discovery_with_script_block_logging_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Message -* ComputerName -* User - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -False positives may be present. Tune as needed. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | Local group discovery on $dest$ by $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.splunk.com/en_us/blog/security/powershell-detections-threat-research-release-august-2021.html](https://www.splunk.com/en_us/blog/security/powershell-detections-threat-research-release-august-2021.html) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1069.001/T1069.001.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1069.001/T1069.001.md) -* [https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell](https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell) -* [https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63](https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63) -* [https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf](https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf) -* [https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/](https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.001/atomic_red_team/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.001/atomic_red_team/windows-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-14-wmic_group_discovery.md b/docs/_posts/2021-09-14-wmic_group_discovery.md deleted file mode 100644 index 4934e04504..0000000000 --- a/docs/_posts/2021-09-14-wmic_group_discovery.md +++ /dev/null @@ -1,171 +0,0 @@ ---- -title: "Wmic Group Discovery" -excerpt: "Permission Groups Discovery -, Local Groups -" -categories: - - Endpoint -last_modified_at: 2021-09-14 -toc: true -toc_label: "" -tags: - - Permission Groups Discovery - - Local Groups - - Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following hunting analytic identifies the use of `wmic.exe` enumerating local groups on the endpoint. \ -Typically, by itself, is not malicious but may raise suspicion based on time of day, endpoint and username. \ -During triage, review parallel processes and identify any further suspicious behavior. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-09-14 -- **Author**: Michael Haag, Splunk -- **ID**: 83317b08-155b-11ec-8e00-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | - -| [T1069.001](https://attack.mitre.org/techniques/T1069/001/) | Local Groups | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=wmic.exe (Processes.process="*group get name*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.original_file_name Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `wmic_group_discovery_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **wmic_group_discovery_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Administrators or power users may use this command for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | Local group discovery on $dest$ by $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1069/001/](https://attack.mitre.org/techniques/T1069/001/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1069.001/T1069.001.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1069.001/T1069.001.md) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.001/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.001/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/wmic_group_discovery.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-15-check_elevated_cmd_using_whoami.md b/docs/_posts/2021-09-15-check_elevated_cmd_using_whoami.md deleted file mode 100644 index 694618f1b7..0000000000 --- a/docs/_posts/2021-09-15-check_elevated_cmd_using_whoami.md +++ /dev/null @@ -1,156 +0,0 @@ ---- -title: "Check Elevated CMD using whoami" -excerpt: "System Owner/User Discovery -" -categories: - - Endpoint -last_modified_at: 2021-09-15 -toc: true -toc_label: "" -tags: - - System Owner/User Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect a suspicious whoami execution to check if the cmd or shell instance process is with elevated privileges. This technique was seen in FIN7 js implant where it execute this as part of its data collection to the infected machine to check if the running shell cmd process is elevated or not. This TTP is really a good alert for known attacker that recon on the targetted host. This command is not so commonly executed by a normal user or even an admin to check if a process is elevated. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-09-15 -- **Author**: Teoderick Contreras, Splunk -- **ID**: a9079b18-1633-11ec-859c-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1033](https://attack.mitre.org/techniques/T1033/) | System Owner/User Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process = "*whoami*" Processes.process = "*/group*" Processes.process = "* find *" Processes.process = "*12288*" by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `check_elevated_cmd_using_whoami_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **check_elevated_cmd_using_whoami_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.parent_process_name -* Processes.parent_process -* Processes.process_name -* Processes.process_id -* Processes.process -* Processes.dest -* Processes.user - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed rundll32.exe may be used. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [FIN7](/stories/fin7) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 56.0 | 70 | 80 | Process name $process_name$ with commandline $process$ in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/fin7/fin7_js_2/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/fin7/fin7_js_2/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-15-non_chrome_process_accessing_chrome_default_dir.md b/docs/_posts/2021-09-15-non_chrome_process_accessing_chrome_default_dir.md deleted file mode 100644 index 9f48a1bb5b..0000000000 --- a/docs/_posts/2021-09-15-non_chrome_process_accessing_chrome_default_dir.md +++ /dev/null @@ -1,163 +0,0 @@ ---- -title: "Non Chrome Process Accessing Chrome Default Dir" -excerpt: "Credentials from Password Stores -, Credentials from Web Browsers -" -categories: - - Endpoint -last_modified_at: 2021-09-15 -toc: true -toc_label: "" -tags: - - Credentials from Password Stores - - Credentials from Web Browsers - - Credential Access - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect an anomaly event of non-chrome process accessing the files in chrome user default folder. This folder contains all the sqlite database of the chrome browser related to users login, history, cookies and etc. Most of the RAT, trojan spy as well as FIN7 jssloader try to parse the those sqlite database to collect information on the compromised host. This SACL Event (4663) need to be enabled to tthe firefox profile directory to be eable to use this. Since you monitoring this access to the folder a noise coming from firefox need to be filter and also sqlite db browser and explorer .exe to make this detection more stable. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-09-15 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 81263de4-160a-11ec-944f-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1555](https://attack.mitre.org/techniques/T1555/) | Credentials from Password Stores | Credential Access | - -| [T1555.003](https://attack.mitre.org/techniques/T1555/003/) | Credentials from Web Browsers | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`wineventlog_security` EventCode=4663 NOT (process_name IN ("*\\chrome.exe", "*\\explorer.exe", "*sql*")) Object_Name="*\\Google\\Chrome\\User Data\\Default*" -| stats count min(_time) as firstTime max(_time) as lastTime by Object_Name Object_Type process_name Access_Mask Accesses process_id EventCode dest user -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `non_chrome_process_accessing_chrome_default_dir_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **non_chrome_process_accessing_chrome_default_dir_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Object_Name -* Object_Type -* process_name -* Access_Mask -* Accesses -* process_id -* EventCode -* dest -* user - - -#### How To Implement -To successfully implement this search, you must ingest Windows Security Event logs and track event code 4663. For 4663, enable "Audit Object Access" in Group Policy. Then check the two boxes listed for both "Success" and "Failure." - -#### Known False Positives -other browser not listed related to firefox may catch by this rule. - -#### Associated Analytic story -* [FIN7](/stories/fin7) -* [Remcos](/stories/remcos) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 35.0 | 50 | 70 | a non firefox browser process $process_name$ accessing $Object_Name$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/fin7/fin7_sacl/security2.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/fin7/fin7_sacl/security2.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-15-non_firefox_process_access_firefox_profile_dir.md b/docs/_posts/2021-09-15-non_firefox_process_access_firefox_profile_dir.md deleted file mode 100644 index 8ea599e012..0000000000 --- a/docs/_posts/2021-09-15-non_firefox_process_access_firefox_profile_dir.md +++ /dev/null @@ -1,164 +0,0 @@ ---- -title: "Non Firefox Process Access Firefox Profile Dir" -excerpt: "Credentials from Password Stores -, Credentials from Web Browsers -" -categories: - - Endpoint -last_modified_at: 2021-09-15 -toc: true -toc_label: "" -tags: - - Credentials from Password Stores - - Credentials from Web Browsers - - Credential Access - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect an anomaly event of non-firefox process accessing the files in profile folder. This folder contains all the sqlite database of the firefox browser related to users login, history, cookies and etc. Most of the RAT, trojan spy as well as FIN7 jssloader try to parse the those sqlite database to collect information on the compromised host. This SACL Event (4663) need to be enabled to tthe firefox profile directory to be eable to use this. Since you monitoring this access to the folder a noise coming from firefox need to be filter and also sqlite db browser and explorer .exe to make this detection more stable. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-09-15 -- **Author**: Teoderick Contreras, Splunk -- **ID**: e6fc13b0-1609-11ec-b533-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1555](https://attack.mitre.org/techniques/T1555/) | Credentials from Password Stores | Credential Access | - -| [T1555.003](https://attack.mitre.org/techniques/T1555/003/) | Credentials from Web Browsers | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`wineventlog_security` EventCode=4663 NOT (process_name IN ("*\\firefox.exe", "*\\explorer.exe", "*sql*")) Object_Name="*\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles*" -| stats count min(_time) as firstTime max(_time) as lastTime by Object_Name Object_Type process_name Access_Mask Accesses process_id EventCode dest user -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `non_firefox_process_access_firefox_profile_dir_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **non_firefox_process_access_firefox_profile_dir_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Object_Name -* Object_Type -* process_name -* Access_Mask -* Accesses -* process_id -* EventCode -* dest -* user - - -#### How To Implement -To successfully implement this search, you must ingest Windows Security Event logs and track event code 4663. For 4663, enable "Audit Object Access" in Group Policy. Then check the two boxes listed for both "Success" and "Failure." - -#### Known False Positives -other browser not listed related to firefox may catch by this rule. - -#### Associated Analytic story -* [FIN7](/stories/fin7) -* [Remcos](/stories/remcos) -* [Azorult](/stories/azorult) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 35.0 | 50 | 70 | a non firefox browser process $process_name$ accessing $Object_Name$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/fin7/fin7_sacl/security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/fin7/fin7_sacl/security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-16-account_discovery_with_net_app.md b/docs/_posts/2021-09-16-account_discovery_with_net_app.md deleted file mode 100644 index 2c66cec6fb..0000000000 --- a/docs/_posts/2021-09-16-account_discovery_with_net_app.md +++ /dev/null @@ -1,173 +0,0 @@ ---- -title: "Account Discovery With Net App" -excerpt: "Domain Account -, Account Discovery -" -categories: - - Endpoint -last_modified_at: 2021-09-16 -toc: true -toc_label: "" -tags: - - Domain Account - - Account Discovery - - Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -this search is to detect a potential account discovery series of command used by several malware or attack to recon the target machine. This technique is also seen in some note worthy malware like trickbot where it runs a cmd process, or even drop its module that will execute the said series of net command. This series of command are good correlation search and indicator of attacker recon if seen in the machines within a none technical user or department (HR, finance, ceo and etc) network. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-09-16 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 339805ce-ac30-11eb-b87d-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery | - -| [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` values(Processes.process) as process values(Processes.parent_process) as parent_process values(Processes.process_id) as process_id count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_net` AND (Processes.process="*user*" OR Processes.process="*config*" OR Processes.process="*view /all*") by Processes.process_name Processes.dest Processes.user Processes.parent_process_name -| where count >=5 -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `account_discovery_with_net_app_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_net](https://github.com/splunk/security_content/blob/develop/macros/process_net.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **account_discovery_with_net_app_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.. - -#### Known False Positives -admin or power user may used this series of command. - -#### Associated Analytic story -* [Trickbot](/stories/trickbot) -* [IcedID](/stories/icedid) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 5.0 | 10 | 50 | Suspicious $process_name$ usage detected on endpoint $dest$ by user $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://labs.vipre.com/trickbot-and-its-modules/](https://labs.vipre.com/trickbot-and-its-modules/) -* [https://whitehat.eu/incident-response-case-study-featuring-ryuk-and-trickbot-part-2/](https://whitehat.eu/incident-response-case-study-featuring-ryuk-and-trickbot-part-2/) -* [https://app.any.run/tasks/48414a33-3d66-4a46-afe5-c2003bb55ccf/](https://app.any.run/tasks/48414a33-3d66-4a46-afe5-c2003bb55ccf/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/trickbot/infection/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/trickbot/infection/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/account_discovery_with_net_app.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2021-09-16-attempt_to_add_certificate_to_untrusted_store.md b/docs/_posts/2021-09-16-attempt_to_add_certificate_to_untrusted_store.md deleted file mode 100644 index 54672494fe..0000000000 --- a/docs/_posts/2021-09-16-attempt_to_add_certificate_to_untrusted_store.md +++ /dev/null @@ -1,175 +0,0 @@ ---- -title: "Attempt To Add Certificate To Untrusted Store" -excerpt: "Install Root Certificate -, Subvert Trust Controls -" -categories: - - Endpoint -last_modified_at: 2021-09-16 -toc: true -toc_label: "" -tags: - - Install Root Certificate - - Subvert Trust Controls - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -Attempt To Add Certificate To Untrusted Store - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-09-16 -- **Author**: Patrick Bareiss, Rico Valdez, Splunk -- **ID**: 6bc5243e-ef36-45dc-9b12-f4a6be131159 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1553.004](https://attack.mitre.org/techniques/T1553/004/) | Install Root Certificate | Defense Evasion | - -| [T1553](https://attack.mitre.org/techniques/T1553/) | Subvert Trust Controls | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Installation -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM -* PR.IP - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime values(Processes.process) as process max(_time) as lastTime from datamodel=Endpoint.Processes where `process_certutil` (Processes.process=*-addstore*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name("Processes")` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -| `attempt_to_add_certificate_to_untrusted_store_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_certutil](https://github.com/splunk/security_content/blob/develop/macros/process_certutil.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **attempt_to_add_certificate_to_untrusted_store_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.process_name -* Processes.process -* Processes.parent_process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. - -#### Known False Positives -There may be legitimate reasons for administrators to add a certificate to the untrusted certificate store. In such cases, this will typically be done on a large number of systems. - -#### Associated Analytic story -* [Disabling Security Tools](/stories/disabling_security_tools) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 35.0 | 70 | 50 | An instance of $parent_process_name$ spawning $process_name$ was identified attempting to add a certificate to the store on endpoint $dest$ by user $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1553.004/T1553.004.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1553.004/T1553.004.md) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1553.004/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1553.004/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml) \| *version*: **7** \ No newline at end of file diff --git a/docs/_posts/2021-09-16-attempted_credential_dump_from_registry_via_reg_exe.md b/docs/_posts/2021-09-16-attempted_credential_dump_from_registry_via_reg_exe.md deleted file mode 100644 index beb83a8095..0000000000 --- a/docs/_posts/2021-09-16-attempted_credential_dump_from_registry_via_reg_exe.md +++ /dev/null @@ -1,179 +0,0 @@ ---- -title: "Attempted Credential Dump From Registry via Reg exe" -excerpt: "Security Account Manager -, OS Credential Dumping -" -categories: - - Endpoint -last_modified_at: 2021-09-16 -toc: true -toc_label: "" -tags: - - Security Account Manager - - OS Credential Dumping - - Credential Access - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -Monitor for execution of reg.exe with parameters specifying an export of keys that contain hashed credentials that attackers may try to crack offline. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-09-16 -- **Author**: Patrick Bareiss, Splunk -- **ID**: e9fb4a59-c5fb-440a-9f24-191fbc6b2911 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1003.002](https://attack.mitre.org/techniques/T1003/002/) | Security Account Manager | Credential Access | - -| [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_reg` OR `process_cmd` Processes.process=*save* (Processes.process=*HKEY_LOCAL_MACHINE\\Security* OR Processes.process=*HKEY_LOCAL_MACHINE\\SAM* OR Processes.process=*HKEY_LOCAL_MACHINE\\System* OR Processes.process=*HKLM\\Security* OR Processes.process=*HKLM\\System* OR Processes.process=*HKLM\\SAM*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `attempted_credential_dump_from_registry_via_reg_exe_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [process_reg](https://github.com/splunk/security_content/blob/develop/macros/process_reg.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [process_cmd](https://github.com/splunk/security_content/blob/develop/macros/process_cmd.yml) - -> :information_source: -> **attempted_credential_dump_from_registry_via_reg_exe_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -None identified. - -#### Associated Analytic story -* [Credential Dumping](/stories/credential_dumping) -* [DarkSide Ransomware](/stories/darkside_ransomware) -* [Windows Registry Abuse](/stories/windows_registry_abuse) -* [Industroyer2](/stories/industroyer2) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 90.0 | 90 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to export the registry keys. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1003.002/T1003.002.md#atomic-test-1---registry-dump-of-sam-creds-and-secrets](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1003.002/T1003.002.md#atomic-test-1---registry-dump-of-sam-creds-and-secrets) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.002/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.002/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml) \| *version*: **6** \ No newline at end of file diff --git a/docs/_posts/2021-09-16-batch_file_write_to_system32.md b/docs/_posts/2021-09-16-batch_file_write_to_system32.md deleted file mode 100644 index 160222e305..0000000000 --- a/docs/_posts/2021-09-16-batch_file_write_to_system32.md +++ /dev/null @@ -1,169 +0,0 @@ ---- -title: "Batch File Write to System32" -excerpt: "User Execution -, Malicious File -" -categories: - - Endpoint -last_modified_at: 2021-09-16 -toc: true -toc_label: "" -tags: - - User Execution - - Malicious File - - Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The search looks for a batch file (.bat) written to the Windows system directory tree. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-09-16 -- **Author**: Michael Haag, Rico Valdez, Splunk -- **ID**: 503d17cb-9eab-4cf8-a20e-01d5c6987ae3 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1204](https://attack.mitre.org/techniques/T1204/) | User Execution | Execution | - -| [T1204.002](https://attack.mitre.org/techniques/T1204/002/) | Malicious File | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Delivery - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name=* by _time span=1h Processes.process_id Processes.process_name Processes.dest -| `drop_dm_object_name(Processes)` -| join process_guid, _time [ -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_path IN ("*\\system32\\*", "*\\syswow64\\*") Filesystem.file_name="*.bat" by _time span=1h Filesystem.dest Filesystem.file_create_time Filesystem.file_name Filesystem.file_path -| `drop_dm_object_name(Filesystem)` -| fields _time dest file_create_time file_name file_path process_name process_path process] -| dedup file_create_time -| table dest file_create_time, file_name, file_path, process_name -| `batch_file_write_to_system32_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **batch_file_write_to_system32_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Filesystem.dest -* Filesystem.file_name -* Filesystem.user -* Filesystem.file_path -* Processes.process_id -* Processes.process_name -* Processes.dest - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -It is possible for this search to generate a notable event for a batch file write to a path that includes the string "system32", but is not the actual Windows system directory. As such, you should confirm the path of the batch file identified by the search. In addition, a false positive may be generated by an administrator copying a legitimate batch file in this directory tree. You should confirm that the activity is legitimate and modify the search to add exclusions, as necessary. - -#### Associated Analytic story -* [SamSam Ransomware](/stories/samsam_ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 63.0 | 70 | 90 | A file - $file_name$ was written to system32 has occurred on endpoint $dest$ by user $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1204.002/batch_file_in_system32/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1204.002/batch_file_in_system32/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/batch_file_write_to_system32.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-09-16-bits_job_persistence.md b/docs/_posts/2021-09-16-bits_job_persistence.md deleted file mode 100644 index 1de2af652c..0000000000 --- a/docs/_posts/2021-09-16-bits_job_persistence.md +++ /dev/null @@ -1,169 +0,0 @@ ---- -title: "BITS Job Persistence" -excerpt: "BITS Jobs -" -categories: - - Endpoint -last_modified_at: 2021-09-16 -toc: true -toc_label: "" -tags: - - BITS Jobs - - Defense Evasion - - Persistence - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following query identifies Microsoft Background Intelligent Transfer Service utility `bitsadmin.exe` scheduling a BITS job to persist on an endpoint. The query identifies the parameters used to create, resume or add a file to a BITS job. Typically seen combined in a oneliner or ran in sequence. If identified, review the BITS job created and capture any files written to disk. It is possible for BITS to be used to upload files and this may require further network data analysis to identify. You can use `bitsadmin /list /verbose` to list out the jobs during investigation. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-09-16 -- **Author**: Michael Haag, Splunk -- **ID**: e97a5ffe-90bf-11eb-928a-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1197](https://attack.mitre.org/techniques/T1197/) | BITS Jobs | Defense Evasion, Persistence | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_bitsadmin` Processes.process IN (*create*, *addfile*, *setnotifyflags*, *setnotifycmdline*, *setminretrydelay*, *setcustomheaders*, *resume* ) by Processes.dest Processes.user Processes.original_file_name Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `bits_job_persistence_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [process_bitsadmin](https://github.com/splunk/security_content/blob/develop/macros/process_bitsadmin.yml) - -> :information_source: -> **bits_job_persistence_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Limited false positives will be present. Typically, applications will use `BitsAdmin.exe`. Any filtering should be done based on command-line arguments (legitimate applications) or parent process. - -#### Associated Analytic story -* [BITS Jobs](/stories/bits_jobs) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 56.0 | 70 | 80 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to persist using BITS. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1197/](https://attack.mitre.org/techniques/T1197/) -* [https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/bitsadmin](https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/bitsadmin) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1197/T1197.md#atomic-test-3---persist-download--execute](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1197/T1197.md#atomic-test-3---persist-download--execute) -* [https://lolbas-project.github.io/lolbas/Binaries/Bitsadmin/](https://lolbas-project.github.io/lolbas/Binaries/Bitsadmin/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1197/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1197/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/bits_job_persistence.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-09-16-bitsadmin_download_file.md b/docs/_posts/2021-09-16-bitsadmin_download_file.md deleted file mode 100644 index d2c8c7bf2d..0000000000 --- a/docs/_posts/2021-09-16-bitsadmin_download_file.md +++ /dev/null @@ -1,176 +0,0 @@ ---- -title: "BITSAdmin Download File" -excerpt: "BITS Jobs -, Ingress Tool Transfer -" -categories: - - Endpoint -last_modified_at: 2021-09-16 -toc: true -toc_label: "" -tags: - - BITS Jobs - - Ingress Tool Transfer - - Defense Evasion - - Persistence - - Command And Control - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following query identifies Microsoft Background Intelligent Transfer Service utility `bitsadmin.exe` using the `transfer` parameter to download a remote object. In addition, look for `download` or `upload` on the command-line, the switches are not required to perform a transfer. Capture any files downloaded. Review the reputation of the IP or domain used. Typically once executed, a follow on command will be used to execute the dropped file. Note that the network connection or file modification events related will not spawn or create from `bitsadmin.exe`, but the artifacts will appear in a parallel process of `svchost.exe` with a command-line similar to `svchost.exe -k netsvcs -s BITS`. It's important to review all parallel and child processes to capture any behaviors and artifacts. In some suspicious and malicious instances, BITS jobs will be created. You can use `bitsadmin /list /verbose` to list out the jobs during investigation. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-09-16 -- **Author**: Michael Haag, Splunk -- **ID**: 80630ff4-8e4c-11eb-aab5-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1197](https://attack.mitre.org/techniques/T1197/) | BITS Jobs | Defense Evasion, Persistence | - -| [T1105](https://attack.mitre.org/techniques/T1105/) | Ingress Tool Transfer | Command And Control | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_bitsadmin` Processes.process=*transfer* by Processes.dest Processes.user Processes.parent_process Processes.original_file_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `bitsadmin_download_file_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [process_bitsadmin](https://github.com/splunk/security_content/blob/develop/macros/process_bitsadmin.yml) - -> :information_source: -> **bitsadmin_download_file_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Limited false positives, however it may be required to filter based on parent process name or network connection. - -#### Associated Analytic story -* [Ingress Tool Transfer](/stories/ingress_tool_transfer) -* [BITS Jobs](/stories/bits_jobs) -* [DarkSide Ransomware](/stories/darkside_ransomware) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to download a file. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/redcanaryco/atomic-red-team/blob/8eb52117b748d378325f7719554a896e37bccec7/atomics/T1105/T1105.md#atomic-test-9---windows---bitsadmin-bits-download](https://github.com/redcanaryco/atomic-red-team/blob/8eb52117b748d378325f7719554a896e37bccec7/atomics/T1105/T1105.md#atomic-test-9---windows---bitsadmin-bits-download) -* [https://github.com/redcanaryco/atomic-red-team/blob/bc705cb7aaa5f26f2d96585fac8e4c7052df0ff9/atomics/T1197/T1197.md](https://github.com/redcanaryco/atomic-red-team/blob/bc705cb7aaa5f26f2d96585fac8e4c7052df0ff9/atomics/T1197/T1197.md) -* [https://docs.microsoft.com/en-us/windows/win32/bits/bitsadmin-tool](https://docs.microsoft.com/en-us/windows/win32/bits/bitsadmin-tool) -* [https://thedfirreport.com/2021/03/29/sodinokibi-aka-revil-ransomware/](https://thedfirreport.com/2021/03/29/sodinokibi-aka-revil-ransomware/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1197/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1197/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/bitsadmin_download_file.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-09-16-creation_of_shadow_copy_with_wmic_and_powershell.md b/docs/_posts/2021-09-16-creation_of_shadow_copy_with_wmic_and_powershell.md deleted file mode 100644 index abb3e468f1..0000000000 --- a/docs/_posts/2021-09-16-creation_of_shadow_copy_with_wmic_and_powershell.md +++ /dev/null @@ -1,176 +0,0 @@ ---- -title: "Creation of Shadow Copy with wmic and powershell" -excerpt: "NTDS -, OS Credential Dumping -" -categories: - - Endpoint -last_modified_at: 2021-09-16 -toc: true -toc_label: "" -tags: - - NTDS - - OS Credential Dumping - - Credential Access - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search detects the use of wmic and Powershell to create a shadow copy. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-09-16 -- **Author**: Patrick Bareiss, Splunk -- **ID**: 2ed8b538-d284-449a-be1d-82ad1dbd186b - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1003.003](https://attack.mitre.org/techniques/T1003/003/) | NTDS | Credential Access | - -| [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_wmic` OR `process_powershell` Processes.process=*shadowcopy* Processes.process=*create* by Processes.user Processes.process_name Processes.original_file_name Processes.process Processes.dest -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `creation_of_shadow_copy_with_wmic_and_powershell_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [process_wmic](https://github.com/splunk/security_content/blob/develop/macros/process_wmic.yml) - -> :information_source: -> **creation_of_shadow_copy_with_wmic_and_powershell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Legtimate administrator usage of wmic to create a shadow copy. - -#### Associated Analytic story -* [Credential Dumping](/stories/credential_dumping) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 81.0 | 90 | 90 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to create a shadow copy to perform offline password cracking. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf](https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.003/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.003/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2021-09-16-credential_dumping_via_copy_command_from_shadow_copy.md b/docs/_posts/2021-09-16-credential_dumping_via_copy_command_from_shadow_copy.md deleted file mode 100644 index f6f060195b..0000000000 --- a/docs/_posts/2021-09-16-credential_dumping_via_copy_command_from_shadow_copy.md +++ /dev/null @@ -1,174 +0,0 @@ ---- -title: "Credential Dumping via Copy Command from Shadow Copy" -excerpt: "NTDS -, OS Credential Dumping -" -categories: - - Endpoint -last_modified_at: 2021-09-16 -toc: true -toc_label: "" -tags: - - NTDS - - OS Credential Dumping - - Credential Access - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search detects credential dumping using copy command from a shadow copy. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-09-16 -- **Author**: Patrick Bareiss, Splunk -- **ID**: d8c406fe-23d2-45f3-a983-1abe7b83ff3b - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1003.003](https://attack.mitre.org/techniques/T1003/003/) | NTDS | Credential Access | - -| [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_cmd` (Processes.process=*\\system32\\config\\sam* OR Processes.process=*\\system32\\config\\security* OR Processes.process=*\\system32\\config\\system* OR Processes.process=*\\windows\\ntds\\ntds.dit*) by Processes.dest Processes.user Processes.process_name Processes.process Processes.parent_process Processes.original_file_name Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `credential_dumping_via_copy_command_from_shadow_copy_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [process_cmd](https://github.com/splunk/security_content/blob/develop/macros/process_cmd.yml) - -> :information_source: -> **credential_dumping_via_copy_command_from_shadow_copy_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Credential Dumping](/stories/credential_dumping) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 81.0 | 90 | 90 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to copy SAM and NTDS.dit for offline password cracking. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf](https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.003/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.003/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-09-16-credential_dumping_via_symlink_to_shadow_copy.md b/docs/_posts/2021-09-16-credential_dumping_via_symlink_to_shadow_copy.md deleted file mode 100644 index d6a564ecf3..0000000000 --- a/docs/_posts/2021-09-16-credential_dumping_via_symlink_to_shadow_copy.md +++ /dev/null @@ -1,174 +0,0 @@ ---- -title: "Credential Dumping via Symlink to Shadow Copy" -excerpt: "NTDS -, OS Credential Dumping -" -categories: - - Endpoint -last_modified_at: 2021-09-16 -toc: true -toc_label: "" -tags: - - NTDS - - OS Credential Dumping - - Credential Access - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search detects the creation of a symlink to a shadow copy. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-09-16 -- **Author**: Patrick Bareiss, Splunk -- **ID**: c5eac648-fae0-4263-91a6-773df1f4c903 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1003.003](https://attack.mitre.org/techniques/T1003/003/) | NTDS | Credential Access | - -| [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_cmd` Processes.process=*mklink* Processes.process=*HarddiskVolumeShadowCopy* by Processes.dest Processes.user Processes.process_name Processes.process Processes.parent_process Processes.original_file_name Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `credential_dumping_via_symlink_to_shadow_copy_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [process_cmd](https://github.com/splunk/security_content/blob/develop/macros/process_cmd.yml) - -> :information_source: -> **credential_dumping_via_symlink_to_shadow_copy_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Credential Dumping](/stories/credential_dumping) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 81.0 | 90 | 90 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to create symlink to a shadow copy to grab credentials. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf](https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.003/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.003/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-09-16-detect_html_help_renamed.md b/docs/_posts/2021-09-16-detect_html_help_renamed.md deleted file mode 100644 index 460d449fd2..0000000000 --- a/docs/_posts/2021-09-16-detect_html_help_renamed.md +++ /dev/null @@ -1,173 +0,0 @@ ---- -title: "Detect HTML Help Renamed" -excerpt: "Signed Binary Proxy Execution -, Compiled HTML File -" -categories: - - Endpoint -last_modified_at: 2021-09-16 -toc: true -toc_label: "" -tags: - - Signed Binary Proxy Execution - - Compiled HTML File - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies a renamed instance of hh.exe (HTML Help) executing a Compiled HTML Help (CHM). This particular technique will load Windows script code from a compiled help file. CHM files may contain nearly any file type embedded, but only execute html/htm. Upon a successful execution, the following script engines may be used for execution - JScript, VBScript, VBScript.Encode, JScript.Encode, JScript.Compact. Analyst may identify vbscript.dll or jscript.dll loading into hh.exe upon execution. The "htm" and "html" file extensions were the only extensions observed to be supported for the execution of Shortcut commands or WSH script code. During investigation, identify script content origination. Validate it is the legitimate version of hh.exe by reviewing the PE metadata. hh.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-09-16 -- **Author**: Michael Haag, Splunk -- **ID**: 62fed254-513b-460e-953d-79771493a9f3 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | - -| [T1218.001](https://attack.mitre.org/techniques/T1218/001/) | Compiled HTML File | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_hh` by Processes.dest Processes.user Processes.parent_process_name Processes.original_file_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_html_help_renamed_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [process_hh](https://github.com/splunk/security_content/blob/develop/macros/process_hh.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -Note that **detect_html_help_renamed_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Although unlikely a renamed instance of hh.exe will be used legitimately, filter as needed. - -#### Associated Analytic story -* [Suspicious Compiled HTML Activity](/stories/suspicious_compiled_html_activity) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | The following $process_name$ has been identified as renamed, spawning from $parent_process_name$. | - - -#### Reference - -* [https://attack.mitre.org/techniques/T1218/001/](https://attack.mitre.org/techniques/T1218/001/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.001/T1218.001.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.001/T1218.001.md) -* [https://lolbas-project.github.io/lolbas/Binaries/Hh/](https://lolbas-project.github.io/lolbas/Binaries/Hh/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.001/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.001/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/detect_html_help_renamed.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2021-09-16-detect_html_help_url_in_command_line.md b/docs/_posts/2021-09-16-detect_html_help_url_in_command_line.md deleted file mode 100644 index fc5d25d403..0000000000 --- a/docs/_posts/2021-09-16-detect_html_help_url_in_command_line.md +++ /dev/null @@ -1,180 +0,0 @@ ---- -title: "Detect HTML Help URL in Command Line" -excerpt: "System Binary Proxy Execution -, Compiled HTML File -" -categories: - - Endpoint -last_modified_at: 2021-09-16 -toc: true -toc_label: "" -tags: - - System Binary Proxy Execution - - Compiled HTML File - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies hh.exe (HTML Help) execution of a Compiled HTML Help (CHM) file from a remote url. This particular technique will load Windows script code from a compiled help file. CHM files may contain nearly any file type embedded, but only execute html/htm. Upon a successful execution, the following script engines may be used for execution - JScript, VBScript, VBScript.Encode, JScript.Encode, JScript.Compact. Analyst may identify vbscript.dll or jscript.dll loading into hh.exe upon execution. The "htm" and "html" file extensions were the only extensions observed to be supported for the execution of Shortcut commands or WSH script code. During investigation, identify script content origination. Review reputation of remote IP and domain. Some instances, it is worth decompiling the .chm file to review its original contents. hh.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-09-16 -- **Author**: Michael Haag, Splunk -- **ID**: 8c5835b9-39d9-438b-817c-95f14c69a31e - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218](https://attack.mitre.org/techniques/T1218/) | System Binary Proxy Execution | Defense Evasion | - -| [T1218.001](https://attack.mitre.org/techniques/T1218/001/) | Compiled HTML File | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_hh` Processes.process=*http* by Processes.dest Processes.user Processes.parent_process Processes.original_file_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_html_help_url_in_command_line_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_hh](https://github.com/splunk/security_content/blob/develop/macros/process_hh.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **detect_html_help_url_in_command_line_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Although unlikely, some legitimate applications may retrieve a CHM remotely, filter as needed. - -#### Associated Analytic story -* [Suspicious Compiled HTML Activity](/stories/suspicious_compiled_html_activity) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 90.0 | 90 | 100 | An instance of $parent_proces_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ contacting a remote destination to potentally download a malicious payload. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1218/001/](https://attack.mitre.org/techniques/T1218/001/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.001/T1218.001.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.001/T1218.001.md) -* [https://lolbas-project.github.io/lolbas/Binaries/Hh/](https://lolbas-project.github.io/lolbas/Binaries/Hh/) -* [https://blog.sevagas.com/?Hacking-around-HTA-files](https://blog.sevagas.com/?Hacking-around-HTA-files) -* [https://gist.github.com/mgeeky/cce31c8602a144d8f2172a73d510e0e7](https://gist.github.com/mgeeky/cce31c8602a144d8f2172a73d510e0e7) -* [https://web.archive.org/web/20220119133748/https://cyberforensicator.com/2019/01/20/silence-dissecting-malicious-chm-files-and-performing-forensic-analysis/](https://web.archive.org/web/20220119133748/https://cyberforensicator.com/2019/01/20/silence-dissecting-malicious-chm-files-and-performing-forensic-analysis/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.001/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.001/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/detect_html_help_url_in_command_line.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-09-16-detect_html_help_using_infotech_storage_handlers.md b/docs/_posts/2021-09-16-detect_html_help_using_infotech_storage_handlers.md deleted file mode 100644 index c9b2ff2744..0000000000 --- a/docs/_posts/2021-09-16-detect_html_help_using_infotech_storage_handlers.md +++ /dev/null @@ -1,180 +0,0 @@ ---- -title: "Detect HTML Help Using InfoTech Storage Handlers" -excerpt: "System Binary Proxy Execution -, Compiled HTML File -" -categories: - - Endpoint -last_modified_at: 2021-09-16 -toc: true -toc_label: "" -tags: - - System Binary Proxy Execution - - Compiled HTML File - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies hh.exe (HTML Help) execution of a Compiled HTML Help (CHM) file using InfoTech Storage Handlers. This particular technique will load Windows script code from a compiled help file, using InfoTech Storage Handlers. itss.dll will load upon execution. Three InfoTech Storage handlers are supported - ms-its, its, mk:@MSITStore. ITSS may be used to launch a specific html/htm file from within a CHM file. CHM files may contain nearly any file type embedded. Upon a successful execution, the following script engines may be used for execution - JScript, VBScript, VBScript.Encode, JScript.Encode, JScript.Compact. Analyst may identify vbscript.dll or jscript.dll loading into hh.exe upon execution. The "htm" and "html" file extensions were the only extensions observed to be supported for the execution of Shortcut commands or WSH script code. During investigation, identify script content origination. hh.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-09-16 -- **Author**: Michael Haag, Splunk -- **ID**: 0b2eefa5-5508-450d-b970-3dd2fb761aec - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218](https://attack.mitre.org/techniques/T1218/) | System Binary Proxy Execution | Defense Evasion | - -| [T1218.001](https://attack.mitre.org/techniques/T1218/001/) | Compiled HTML File | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_hh` Processes.process IN ("*its:*", "*mk:@MSITStore:*") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_html_help_using_infotech_storage_handlers_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_hh](https://github.com/splunk/security_content/blob/develop/macros/process_hh.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **detect_html_help_using_infotech_storage_handlers_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -It is rare to see instances of InfoTech Storage Handlers being used, but it does happen in some legitimate instances. Filter as needed. - -#### Associated Analytic story -* [Suspicious Compiled HTML Activity](/stories/suspicious_compiled_html_activity) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 72.0 | 80 | 90 | $process_name$ has been identified using Infotech Storage Handlers to load a specific file within a CHM on $dest$ under user $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1218/001/](https://attack.mitre.org/techniques/T1218/001/) -* [https://www.kb.cert.org/vuls/id/851869](https://www.kb.cert.org/vuls/id/851869) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.001/T1218.001.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.001/T1218.001.md) -* [https://lolbas-project.github.io/lolbas/Binaries/Hh/](https://lolbas-project.github.io/lolbas/Binaries/Hh/) -* [https://gist.github.com/mgeeky/cce31c8602a144d8f2172a73d510e0e7](https://gist.github.com/mgeeky/cce31c8602a144d8f2172a73d510e0e7) -* [https://web.archive.org/web/20220119133748/https://cyberforensicator.com/2019/01/20/silence-dissecting-malicious-chm-files-and-performing-forensic-analysis/](https://web.archive.org/web/20220119133748/https://cyberforensicator.com/2019/01/20/silence-dissecting-malicious-chm-files-and-performing-forensic-analysis/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.001/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.001/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-09-16-detect_mshta_inline_hta_execution.md b/docs/_posts/2021-09-16-detect_mshta_inline_hta_execution.md deleted file mode 100644 index 917308ab5f..0000000000 --- a/docs/_posts/2021-09-16-detect_mshta_inline_hta_execution.md +++ /dev/null @@ -1,177 +0,0 @@ ---- -title: "Detect mshta inline hta execution" -excerpt: "System Binary Proxy Execution -, Mshta -" -categories: - - Endpoint -last_modified_at: 2021-09-16 -toc: true -toc_label: "" -tags: - - System Binary Proxy Execution - - Mshta - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies "mshta.exe" execution with inline protocol handlers. "JavaScript", "VBScript", and "About" are the only supported options when invoking HTA content directly on the command-line. The search will return the first time and last time these command-line arguments were used for these executions, as well as the target system, the user, process "mshta.exe" and its parent process. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-09-16 -- **Author**: Bhavin Patel, Michael Haag, Splunk -- **ID**: a0873b32-5b68-11eb-ae93-0242ac130002 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218](https://attack.mitre.org/techniques/T1218/) | System Binary Proxy Execution | Defense Evasion | - -| [T1218.005](https://attack.mitre.org/techniques/T1218/005/) | Mshta | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count values(Processes.process) as process values(Processes.parent_process) as parent_process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_mshta` (Processes.process=*vbscript* OR Processes.process=*javascript* OR Processes.process=*about*) by Processes.user Processes.process_name Processes.original_file_name Processes.parent_process_name Processes.dest -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_mshta_inline_hta_execution_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_mshta](https://github.com/splunk/security_content/blob/develop/macros/process_mshta.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **detect_mshta_inline_hta_execution_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Although unlikely, some legitimate applications may exhibit this behavior, triggering a false positive. - -#### Associated Analytic story -* [Suspicious MSHTA Activity](/stories/suspicious_mshta_activity) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 90.0 | 90 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ executing with inline HTA, indicative of defense evasion. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/redcanaryco/AtomicTestHarnesses](https://github.com/redcanaryco/AtomicTestHarnesses) -* [https://redcanary.com/blog/introducing-atomictestharnesses/](https://redcanary.com/blog/introducing-atomictestharnesses/) -* [https://docs.microsoft.com/en-us/windows/win32/search/-search-3x-wds-extidx-prot-implementing](https://docs.microsoft.com/en-us/windows/win32/search/-search-3x-wds-extidx-prot-implementing) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.005/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.005/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml) \| *version*: **6** \ No newline at end of file diff --git a/docs/_posts/2021-09-16-detect_mshta_renamed.md b/docs/_posts/2021-09-16-detect_mshta_renamed.md deleted file mode 100644 index 05ffb568a6..0000000000 --- a/docs/_posts/2021-09-16-detect_mshta_renamed.md +++ /dev/null @@ -1,172 +0,0 @@ ---- -title: "Detect mshta renamed" -excerpt: "Signed Binary Proxy Execution -, Mshta -" -categories: - - Endpoint -last_modified_at: 2021-09-16 -toc: true -toc_label: "" -tags: - - Signed Binary Proxy Execution - - Mshta - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies renamed instances of mshta.exe executing. Mshta.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. This analytic utilizes the internal name of the PE to identify if is the legitimate mshta binary. Further analysis should be performed to review the executed content and validation it is the real mshta. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-09-16 -- **Author**: Michael Haag, Splunk -- **ID**: 8f45fcf0-5b68-11eb-ae93-0242ac130002 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | - -| [T1218.005](https://attack.mitre.org/techniques/T1218/005/) | Mshta | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_mshta` by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.original_file_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_mshta_renamed_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [process_mshta](https://github.com/splunk/security_content/blob/develop/macros/process_mshta.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -Note that **detect_mshta_renamed_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Although unlikely, some legitimate applications may use a moved copy of mshta.exe, but never renamed, triggering a false positive. - -#### Associated Analytic story -* [Suspicious MSHTA Activity](/stories/suspicious_mshta_activity) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | The following $process_name$ has been identified as renamed, spawning from $parent_process_name$. | - - -#### Reference - -* [https://github.com/redcanaryco/AtomicTestHarnesses](https://github.com/redcanaryco/AtomicTestHarnesses) -* [https://redcanary.com/blog/introducing-atomictestharnesses/](https://redcanary.com/blog/introducing-atomictestharnesses/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.005/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.005/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/detect_mshta_renamed.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-09-16-detect_mshta_url_in_command_line.md b/docs/_posts/2021-09-16-detect_mshta_url_in_command_line.md deleted file mode 100644 index 6d3b9fd3f3..0000000000 --- a/docs/_posts/2021-09-16-detect_mshta_url_in_command_line.md +++ /dev/null @@ -1,177 +0,0 @@ ---- -title: "Detect MSHTA Url in Command Line" -excerpt: "System Binary Proxy Execution -, Mshta -" -categories: - - Endpoint -last_modified_at: 2021-09-16 -toc: true -toc_label: "" -tags: - - System Binary Proxy Execution - - Mshta - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic identifies when Microsoft HTML Application Host (mshta.exe) utility is used to make remote http connections. Adversaries may use mshta.exe to proxy the download and execution of remote .hta files. The analytic identifies command line arguments of http and https being used. This technique is commonly used by malicious software to bypass preventative controls. The search will return the first time and last time these command-line arguments were used for these executions, as well as the target system, the user, process "rundll32.exe" and its parent process. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-09-16 -- **Author**: Michael Haag, Splunk -- **ID**: 9b3af1e6-5b68-11eb-ae93-0242ac130002 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218](https://attack.mitre.org/techniques/T1218/) | System Binary Proxy Execution | Defense Evasion | - -| [T1218.005](https://attack.mitre.org/techniques/T1218/005/) | Mshta | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count values(Processes.process) as process values(Processes.parent_process) as parent_process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_mshta` (Processes.process="*http://*" OR Processes.process="*https://*") by Processes.user Processes.process_name Processes.parent_process_name Processes.original_file_name Processes.dest -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_mshta_url_in_command_line_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_mshta](https://github.com/splunk/security_content/blob/develop/macros/process_mshta.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **detect_mshta_url_in_command_line_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -It is possible legitimate applications may perform this behavior and will need to be filtered. - -#### Associated Analytic story -* [Suspicious MSHTA Activity](/stories/suspicious_mshta_activity) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $est$ by user $user$ attempting to access a remote destination to download an additional payload. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/redcanaryco/AtomicTestHarnesses](https://github.com/redcanaryco/AtomicTestHarnesses) -* [https://redcanary.com/blog/introducing-atomictestharnesses/](https://redcanary.com/blog/introducing-atomictestharnesses/) -* [https://docs.microsoft.com/en-us/windows/win32/search/-search-3x-wds-extidx-prot-implementing](https://docs.microsoft.com/en-us/windows/win32/search/-search-3x-wds-extidx-prot-implementing) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.005/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.005/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/detect_mshta_url_in_command_line.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-09-16-detect_psexec_with_accepteula_flag.md b/docs/_posts/2021-09-16-detect_psexec_with_accepteula_flag.md deleted file mode 100644 index 1dea81ca3d..0000000000 --- a/docs/_posts/2021-09-16-detect_psexec_with_accepteula_flag.md +++ /dev/null @@ -1,175 +0,0 @@ ---- -title: "Detect PsExec With accepteula Flag" -excerpt: "Remote Services -, SMB/Windows Admin Shares -" -categories: - - Endpoint -last_modified_at: 2021-09-16 -toc: true -toc_label: "" -tags: - - Remote Services - - SMB/Windows Admin Shares - - Lateral Movement - - Lateral Movement - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for events where `PsExec.exe` is run with the `accepteula` flag in the command line. PsExec is a built-in Windows utility that enables you to execute processes on other systems. It is fully interactive for console applications. This tool is widely used for launching interactive command prompts on remote systems. Threat actors leverage this extensively for executing code on compromised systems. If an attacker is running PsExec for the first time, they will be prompted to accept the end-user license agreement (EULA), which can be passed as the argument `accepteula` within the command line. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-09-16 -- **Author**: Bhavin Patel, Splunk -- **ID**: 27c3a83d-cada-47c6-9042-67baf19d2574 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1021](https://attack.mitre.org/techniques/T1021/) | Remote Services | Lateral Movement | - -| [T1021.002](https://attack.mitre.org/techniques/T1021/002/) | SMB/Windows Admin Shares | Lateral Movement | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_psexec` Processes.process=*accepteula* by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_psexec_with_accepteula_flag_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [process_psexec](https://github.com/splunk/security_content/blob/develop/macros/process_psexec.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **detect_psexec_with_accepteula_flag_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Administrators can leverage PsExec for accessing remote systems and might pass `accepteula` as an argument if they are running this tool for the first time. However, it is not likely that you'd see multiple occurrences of this event on a machine - -#### Associated Analytic story -* [SamSam Ransomware](/stories/samsam_ransomware) -* [DHS Report TA18-074A](/stories/dhs_report_ta18-074a) -* [HAFNIUM Group](/stories/hafnium_group) -* [DarkSide Ransomware](/stories/darkside_ransomware) -* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 35.0 | 50 | 70 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ running the utility for possibly the first time. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021.002/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021.002/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml) \| *version*: **4** \ No newline at end of file diff --git a/docs/_posts/2021-09-16-detect_renamed_7-zip.md b/docs/_posts/2021-09-16-detect_renamed_7-zip.md deleted file mode 100644 index 2aa3a5d738..0000000000 --- a/docs/_posts/2021-09-16-detect_renamed_7-zip.md +++ /dev/null @@ -1,168 +0,0 @@ ---- -title: "Detect Renamed 7-Zip" -excerpt: "Archive via Utility -, Archive Collected Data -" -categories: - - Endpoint -last_modified_at: 2021-09-16 -toc: true -toc_label: "" -tags: - - Archive via Utility - - Archive Collected Data - - Collection - - Collection - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies renamed 7-Zip usage using Sysmon. At this stage of an attack, review parallel processes and file modifications for data that is staged or potentially have been exfiltrated. This analytic utilizes the OriginalFileName to capture the renamed process. During triage, validate this is the legitimate version of `7zip` by reviewing the PE metadata. In addition, review parallel processes for further suspicious behavior. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-09-16 -- **Author**: Michael Haag, Splunk -- **ID**: 4057291a-b8cf-11eb-95fe-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1560.001](https://attack.mitre.org/techniques/T1560/001/) | Archive via Utility | Collection | - -| [T1560](https://attack.mitre.org/techniques/T1560/) | Archive Collected Data | Collection | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.original_file_name=7z*.exe AND Processes.process_name!=7z*.exe) by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.original_file_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_renamed_7_zip_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **detect_renamed_7-zip_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Limited false positives, however this analytic will need to be modified for each environment if Sysmon is not used. - -#### Associated Analytic story -* [Collection and Staging](/stories/collection_and_staging) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 27.0 | 30 | 90 | The following $process_name$ has been identified as renamed, spawning from $parent_process_name$ on $dest$ by $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1560.001/T1560.001.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1560.001/T1560.001.md) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1560.001/archive_utility/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1560.001/archive_utility/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/detect_renamed_7_zip.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-09-16-detect_renamed_psexec.md b/docs/_posts/2021-09-16-detect_renamed_psexec.md deleted file mode 100644 index 4c17b45fc1..0000000000 --- a/docs/_posts/2021-09-16-detect_renamed_psexec.md +++ /dev/null @@ -1,171 +0,0 @@ ---- -title: "Detect Renamed PSExec" -excerpt: "System Services -, Service Execution -" -categories: - - Endpoint -last_modified_at: 2021-09-16 -toc: true -toc_label: "" -tags: - - System Services - - Service Execution - - Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies renamed instances of `PsExec.exe` being utilized on an endpoint. Most instances, it is highly probable to capture `Psexec.exe` or other SysInternal utility usage with the command-line argument of `-accepteula`. During triage, validate this is the legitimate version of `PsExec` by reviewing the PE metadata. In addition, review parallel processes for further suspicious behavior. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-09-16 -- **Author**: Michael Haag, Splunk -- **ID**: 683e6196-b8e8-11eb-9a79-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1569](https://attack.mitre.org/techniques/T1569/) | System Services | Execution | - -| [T1569.002](https://attack.mitre.org/techniques/T1569/002/) | Service Execution | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_psexec` by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.original_file_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_renamed_psexec_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_psexec](https://github.com/splunk/security_content/blob/develop/macros/process_psexec.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -Note that **detect_renamed_psexec_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Limited false positives should be present. It is possible some third party applications may use older versions of PsExec, filter as needed. - -#### Associated Analytic story -* [SamSam Ransomware](/stories/samsam_ransomware) -* [DHS Report TA18-074A](/stories/dhs_report_ta18-074a) -* [HAFNIUM Group](/stories/hafnium_group) -* [DarkSide Ransomware](/stories/darkside_ransomware) -* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 27.0 | 30 | 90 | The following $process_name$ has been identified as renamed, spawning from $parent_process_name$ on $dest$ by $user$. | - - -#### Reference - -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1569.002/T1569.002.yaml](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1569.002/T1569.002.yaml) -* [https://redcanary.com/blog/threat-hunting-psexec-lateral-movement/](https://redcanary.com/blog/threat-hunting-psexec-lateral-movement/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1569.002/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1569.002/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/detect_renamed_psexec.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2021-09-16-detect_renamed_rclone.md b/docs/_posts/2021-09-16-detect_renamed_rclone.md deleted file mode 100644 index 88e57e0dc8..0000000000 --- a/docs/_posts/2021-09-16-detect_renamed_rclone.md +++ /dev/null @@ -1,166 +0,0 @@ ---- -title: "Detect Renamed RClone" -excerpt: "Automated Exfiltration -" -categories: - - Endpoint -last_modified_at: 2021-09-16 -toc: true -toc_label: "" -tags: - - Automated Exfiltration - - Exfiltration - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the usage of `rclone.exe`, renamed, being used to exfiltrate data to a remote destination. RClone has been used by multiple ransomware groups to exfiltrate data. In many instances, it will be downloaded from the legitimate site and executed accordingly. During triage, isolate the endpoint and begin to review parallel processes for additional behavior. At this stage, the adversary may have staged data to be exfiltrated. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-09-16 -- **Author**: Michael Haag, Splunk -- **ID**: 6dca1124-b3ec-11eb-9328-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1020](https://attack.mitre.org/techniques/T1020/) | Automated Exfiltration | Exfiltration | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.original_file_name=rclone.exe AND Processes.process_name!=rclone.exe) by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.original_file_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_renamed_rclone_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **detect_renamed_rclone_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -False positives should be limited as this analytic identifies renamed instances of `rclone.exe`. Filter as needed if there is a legitimate business use case. - -#### Associated Analytic story -* [DarkSide Ransomware](/stories/darkside_ransomware) -* [Ransomware](/stories/ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 27.0 | 30 | 90 | The following $process_name$ has been identified as renamed, spawning from $parent_process_name$ on $dest$ by $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://redcanary.com/blog/rclone-mega-extortion/](https://redcanary.com/blog/rclone-mega-extortion/) -* [https://www.mandiant.com/resources/shining-a-light-on-darkside-ransomware-operations](https://www.mandiant.com/resources/shining-a-light-on-darkside-ransomware-operations) -* [https://thedfirreport.com/2021/03/29/sodinokibi-aka-revil-ransomware/](https://thedfirreport.com/2021/03/29/sodinokibi-aka-revil-ransomware/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1020/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1020/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/detect_renamed_rclone.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-09-16-detect_renamed_winrar.md b/docs/_posts/2021-09-16-detect_renamed_winrar.md deleted file mode 100644 index e0a0dee5d6..0000000000 --- a/docs/_posts/2021-09-16-detect_renamed_winrar.md +++ /dev/null @@ -1,168 +0,0 @@ ---- -title: "Detect Renamed WinRAR" -excerpt: "Archive via Utility -, Archive Collected Data -" -categories: - - Endpoint -last_modified_at: 2021-09-16 -toc: true -toc_label: "" -tags: - - Archive via Utility - - Archive Collected Data - - Collection - - Collection - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analtyic identifies renamed instances of `WinRAR.exe`. In most cases, it is not common for WinRAR to be used renamed, however it is common to be installed by a third party application and executed from a non-standard path. During triage, validate additional metadata from the binary that this is `WinRAR`. Review parallel processes and file modifications. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-09-16 -- **Author**: Michael Haag, Splunk -- **ID**: 1b7bfb2c-b8e6-11eb-99ac-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1560.001](https://attack.mitre.org/techniques/T1560/001/) | Archive via Utility | Collection | - -| [T1560](https://attack.mitre.org/techniques/T1560/) | Archive Collected Data | Collection | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.original_file_name=WinRAR.exe (Processes.process_name!=rar.exe OR Processes.process_name!=winrar.exe) by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.original_file_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_renamed_winrar_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **detect_renamed_winrar_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Unknown. It is possible third party applications use renamed instances of WinRAR. - -#### Associated Analytic story -* [Collection and Staging](/stories/collection_and_staging) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 27.0 | 30 | 90 | The following $process_name$ has been identified as renamed, spawning from $parent_process_name$ on $dest$ by $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1560.001/T1560.001.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1560.001/T1560.001.md) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1560.001/archive_utility/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1560.001/archive_utility/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/detect_renamed_winrar.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2021-09-16-dump_lsass_via_procdump.md b/docs/_posts/2021-09-16-dump_lsass_via_procdump.md deleted file mode 100644 index afd7962ebb..0000000000 --- a/docs/_posts/2021-09-16-dump_lsass_via_procdump.md +++ /dev/null @@ -1,175 +0,0 @@ ---- -title: "Dump LSASS via procdump" -excerpt: "LSASS Memory -, OS Credential Dumping -" -categories: - - Endpoint -last_modified_at: 2021-09-16 -toc: true -toc_label: "" -tags: - - LSASS Memory - - OS Credential Dumping - - Credential Access - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -Detect procdump.exe dumping the lsass process. This query looks for both -mm and -ma usage. -mm will produce a mini dump file and -ma will write a dump file with all process memory. Both are highly suspect and should be reviewed. This query does not monitor for the internal name (original_file_name=procdump) of the PE or look for procdump64.exe. Modify the query as needed.\ -During triage, confirm this is procdump.exe executing. If it is the first time a Sysinternals utility has been ran, it is possible there will be a -accepteula on the command line. Review other endpoint data sources for cross process (injection) into lsass.exe. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-09-16 -- **Author**: Michael Haag, Splunk -- **ID**: 3742ebfe-64c2-11eb-ae93-0242ac130002 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1003.001](https://attack.mitre.org/techniques/T1003/001/) | LSASS Memory | Credential Access | - -| [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_procdump` (Processes.process=*-ma* OR Processes.process=*-mm*) Processes.process=*lsass* by Processes.user Processes.process_name Processes.process Processes.original_file_name Processes.dest -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `dump_lsass_via_procdump_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [process_procdump](https://github.com/splunk/security_content/blob/develop/macros/process_procdump.yml) - -> :information_source: -> **dump_lsass_via_procdump_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -None identified. - -#### Associated Analytic story -* [Credential Dumping](/stories/credential_dumping) -* [HAFNIUM Group](/stories/hafnium_group) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified attempting to dump lsass.exe on endpoint $dest$ by user $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1003/001/](https://attack.mitre.org/techniques/T1003/001/) -* [https://docs.microsoft.com/en-us/sysinternals/downloads/procdump](https://docs.microsoft.com/en-us/sysinternals/downloads/procdump) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1003.001/T1003.001.md#atomic-test-2---dump-lsassexe-memory-using-procdump](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1003.001/T1003.001.md#atomic-test-2---dump-lsassexe-memory-using-procdump) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.001/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.001/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/dump_lsass_via_procdump.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-09-16-local_account_discovery_with_net.md b/docs/_posts/2021-09-16-local_account_discovery_with_net.md deleted file mode 100644 index 53d906c803..0000000000 --- a/docs/_posts/2021-09-16-local_account_discovery_with_net.md +++ /dev/null @@ -1,158 +0,0 @@ ---- -title: "Local Account Discovery with Net" -excerpt: "Account Discovery -, Local Account -" -categories: - - Endpoint -last_modified_at: 2021-09-16 -toc: true -toc_label: "" -tags: - - Account Discovery - - Local Account - - Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for the execution of `net.exe` or `net1.exe` with command-line arguments utilized to query for local users. The two arguments `user` and 'users', return a list of all local users. Red Teams and adversaries alike use net.exe to enumerate users for situational awareness and Active Directory Discovery. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-09-16 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 5d0d4830-0133-11ec-bae3-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - -| [T1087.001](https://attack.mitre.org/techniques/T1087/001/) | Local Account | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_net` (Processes.process=*user OR Processes.process=*users) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `local_account_discovery_with_net_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_net](https://github.com/splunk/security_content/blob/develop/macros/process_net.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **local_account_discovery_with_net_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Administrators or power users may use this command for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | Local user discovery enumeration on $dest$ by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1087/001/](https://attack.mitre.org/techniques/T1087/001/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.001/AD_discovery/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.001/AD_discovery/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/local_account_discovery_with_net.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-09-16-local_account_discovery_with_wmic.md b/docs/_posts/2021-09-16-local_account_discovery_with_wmic.md deleted file mode 100644 index 34a3d5138b..0000000000 --- a/docs/_posts/2021-09-16-local_account_discovery_with_wmic.md +++ /dev/null @@ -1,158 +0,0 @@ ---- -title: "Local Account Discovery With Wmic" -excerpt: "Account Discovery -, Local Account -" -categories: - - Endpoint -last_modified_at: 2021-09-16 -toc: true -toc_label: "" -tags: - - Account Discovery - - Local Account - - Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for the execution of `wmic.exe` with command-line arguments utilized to query for local users. The argument `useraccount` is used to leverage WMI to return a list of all local users. Red Teams and adversaries alike use net.exe to enumerate users for situational awareness and Active Directory Discovery. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-09-16 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 4902d7aa-0134-11ec-9d65-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - -| [T1087.001](https://attack.mitre.org/techniques/T1087/001/) | Local Account | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_wmic` (Processes.process=*useraccount*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `local_account_discovery_with_wmic_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [process_wmic](https://github.com/splunk/security_content/blob/develop/macros/process_wmic.yml) - -> :information_source: -> **local_account_discovery_with_wmic_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Administrators or power users may use this command for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | Local user discovery enumeration on $dest$ by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1087/001/](https://attack.mitre.org/techniques/T1087/001/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.001/AD_discovery/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.001/AD_discovery/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/local_account_discovery_with_wmic.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-09-16-office_product_spawning_wmic.md b/docs/_posts/2021-09-16-office_product_spawning_wmic.md deleted file mode 100644 index eed2b96620..0000000000 --- a/docs/_posts/2021-09-16-office_product_spawning_wmic.md +++ /dev/null @@ -1,172 +0,0 @@ ---- -title: "Office Product Spawning Wmic" -excerpt: "Phishing -, Spearphishing Attachment -" -categories: - - Endpoint -last_modified_at: 2021-09-16 -toc: true -toc_label: "" -tags: - - Phishing - - Spearphishing Attachment - - Initial Access - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following detection identifies the latest behavior utilized by Ursnif malware family. This detection identifies any Windows Office Product spawning `wmic.exe`. In malicious instances, the command-line of `wmic.exe` will contain `wmic process call create`. In addition, Threat Research has released a detection identifying the use of `wmic process call create` on the command-line of `wmic.exe`. In this instance, we narrow our detection down to the Office suite as a parent process. During triage, review all file modifications. Capture and analyze any artifacts on disk. The Office Product, or `wmic.exe` will have reached out to a remote destination, capture and block the IPs or domain. Review additional parallel processes for further activity. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-09-16 -- **Author**: Michael Haag, Splunk -- **ID**: ffc236d6-a6c9-11eb-95f1-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | - -| [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name IN ("winword.exe","excel.exe","powerpnt.exe","mspub.exe","visio.exe") `process_wmic` by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `office_product_spawning_wmic_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [process_wmic](https://github.com/splunk/security_content/blob/develop/macros/process_wmic.yml) - -> :information_source: -> **office_product_spawning_wmic_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -No false positives known. Filter as needed. - -#### Associated Analytic story -* [Spearphishing Attachments](/stories/spearphishing_attachments) -* [FIN7](/stories/fin7) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 63.0 | 70 | 90 | office parent process $parent_process_name$ will execute a suspicious child process $process_name$ with process id $process_id$ in host $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://app.any.run/tasks/fb894ab8-a966-4b72-920b-935f41756afd/](https://app.any.run/tasks/fb894ab8-a966-4b72-920b-935f41756afd/) -* [https://attack.mitre.org/techniques/T1047/](https://attack.mitre.org/techniques/T1047/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1047/T1047.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1047/T1047.md) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_macros.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_macros.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/office_product_spawning_wmic.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2021-09-16-processes_launching_netsh.md b/docs/_posts/2021-09-16-processes_launching_netsh.md deleted file mode 100644 index f65a13f3a8..0000000000 --- a/docs/_posts/2021-09-16-processes_launching_netsh.md +++ /dev/null @@ -1,169 +0,0 @@ ---- -title: "Processes launching netsh" -excerpt: "Disable or Modify System Firewall -, Impair Defenses -" -categories: - - Endpoint -last_modified_at: 2021-09-16 -toc: true -toc_label: "" -tags: - - Disable or Modify System Firewall - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for processes launching netsh.exe. Netsh is a command-line scripting utility that allows you to, either locally or remotely, display or modify the network configuration of a computer that is currently running. Netsh can be used as a persistence proxy technique to execute a helper DLL when netsh.exe is executed. In this search, we are looking for processes spawned by netsh.exe and executing commands via the command line. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-09-16 -- **Author**: Michael Haag, Josef Kuepker, Splunk -- **ID**: b89919ed-fe5f-492c-b139-95dbb162040e - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.004](https://attack.mitre.org/techniques/T1562/004/) | Disable or Modify System Firewall | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count values(Processes.process) AS Processes.process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_netsh` by Processes.parent_process_name Processes.parent_process Processes.original_file_name Processes.process_name Processes.user Processes.dest -|`drop_dm_object_name("Processes")` -|`security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -|`processes_launching_netsh_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_netsh](https://github.com/splunk/security_content/blob/develop/macros/process_netsh.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **processes_launching_netsh_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process -* Processes.parent_process_name -* Processes.parent_process -* Processes.process_name -* Processes.user -* Processes.dest - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Some VPN applications are known to launch netsh.exe. Outside of these instances, it is unusual for an executable to launch netsh.exe and run commands. - -#### Associated Analytic story -* [Netsh Abuse](/stories/netsh_abuse) -* [Disabling Security Tools](/stories/disabling_security_tools) -* [DHS Report TA18-074A](/stories/dhs_report_ta18-074a) -* [Azorult](/stories/azorult) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 42.0 | 60 | 70 | A process $process_name$ that tries to execute netsh commandline $process$ in host $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.004/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.004/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/processes_launching_netsh.yml) \| *version*: **4** \ No newline at end of file diff --git a/docs/_posts/2021-09-20-detect_regasm_with_no_command_line_arguments.md b/docs/_posts/2021-09-20-detect_regasm_with_no_command_line_arguments.md deleted file mode 100644 index b1070ff4b5..0000000000 --- a/docs/_posts/2021-09-20-detect_regasm_with_no_command_line_arguments.md +++ /dev/null @@ -1,122 +0,0 @@ ---- -title: "Detect Regasm with no Command Line Arguments" -excerpt: "Signed Binary Proxy Execution -, Regsvcs/Regasm -" -categories: - - Endpoint -last_modified_at: 2021-09-20 -toc: true -toc_label: "" -tags: - - Signed Binary Proxy Execution - - Regsvcs/Regasm - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies regasm.exe with no command line arguments. This particular behavior occurs when another process injects into regasm.exe, no command line arguments will be present. During investigation, identify any network connections and parallel processes. Identify any suspicious module loads related to credential dumping or file writes. Regasm.exe are natively found in `C:\Windows\Microsoft.NET\Framework\v*\regasm|regsvcs.exe` and `C:\Windows\Microsoft.NET\Framework64\v*\regasm|regsvcs.exe`. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/object-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-09-20 -- **Author**: Michael Haag, Splunk -- **ID**: c3bc1430-04e7-4178-835f-047d8e6e97df - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | - -| [T1218.009](https://attack.mitre.org/techniques/T1218/009/) | Regsvcs/Regasm | Defense Evasion | - -#### Search - -``` - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where `process_regasm` by _time span=1h Processes.process_id Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| regex process="(regasm\.exe.{0,4}$)" -| `detect_regasm_with_no_command_line_arguments_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [process_regasm](https://github.com/splunk/security_content/blob/develop/macros/process_regasm.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -Note that `detect_regasm_with_no_command_line_arguments_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Although unlikely, limited instances of regasm.exe or may cause a false positive. Filter based endpoint usage, command line arguments, or process lineage. - -#### Associated Analytic story -* [Suspicious Regsvcs Regasm Activity](/stories/suspicious_regsvcs_regasm_activity) - - -#### Kill Chain Phase -* Actions on Objectives - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | The process $process_name$ was spawned by $parent_process_name$ without any command-line arguments on $dest$ by $user$. | - - - - -#### Reference - -* [https://attack.mitre.org/techniques/T1218/009/](https://attack.mitre.org/techniques/T1218/009/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.009/T1218.009.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.009/T1218.009.md) -* [https://lolbas-project.github.io/lolbas/Binaries/Regasm/](https://lolbas-project.github.io/lolbas/Binaries/Regasm/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.009/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.009/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/detect_regasm_with_no_command_line_arguments.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-09-20-detect_regsvcs_with_no_command_line_arguments.md b/docs/_posts/2021-09-20-detect_regsvcs_with_no_command_line_arguments.md deleted file mode 100644 index 88d4ee0479..0000000000 --- a/docs/_posts/2021-09-20-detect_regsvcs_with_no_command_line_arguments.md +++ /dev/null @@ -1,122 +0,0 @@ ---- -title: "Detect Regsvcs with No Command Line Arguments" -excerpt: "Signed Binary Proxy Execution -, Regsvcs/Regasm -" -categories: - - Endpoint -last_modified_at: 2021-09-20 -toc: true -toc_label: "" -tags: - - Signed Binary Proxy Execution - - Regsvcs/Regasm - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies regsvcs.exe with no command line arguments. This particular behavior occurs when another process injects into regsvcs.exe, no command line arguments will be present. During investigation, identify any network connections and parallel processes. Identify any suspicious module loads related to credential dumping or file writes. Regasm.exe are natively found in C:\Windows\Microsoft.NET\Framework\v*\regasm|regsvcs.exe and C:\Windows\Microsoft.NET\Framework64\v*\regasm|regsvcs.exe. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/object-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-09-20 -- **Author**: Michael Haag, Splunk -- **ID**: 6b74d578-a02e-4e94-a0d1-39440d0bf254 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | - -| [T1218.009](https://attack.mitre.org/techniques/T1218/009/) | Regsvcs/Regasm | Defense Evasion | - -#### Search - -``` - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where `process_regsvcs` by _time span=1h Processes.process_id Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| regex process="(regsvcs\.exe.{0,4}$)" -| `detect_regsvcs_with_no_command_line_arguments_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [process_regsvcs](https://github.com/splunk/security_content/blob/develop/macros/process_regsvcs.yml) - -Note that `detect_regsvcs_with_no_command_line_arguments_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Although unlikely, limited instances of regsvcs.exe may cause a false positive. Filter based endpoint usage, command line arguments, or process lineage. - -#### Associated Analytic story -* [Suspicious Regsvcs Regasm Activity](/stories/suspicious_regsvcs_regasm_activity) - - -#### Kill Chain Phase -* Actions on Objectives - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | The process $process_name$ was spawned by $parent_process_name$ without any command-line arguments on $dest$ by $user$. | - - - - -#### Reference - -* [https://attack.mitre.org/techniques/T1218/009/](https://attack.mitre.org/techniques/T1218/009/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.009/T1218.009.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.009/T1218.009.md) -* [https://lolbas-project.github.io/lolbas/Binaries/Regsvcs/](https://lolbas-project.github.io/lolbas/Binaries/Regsvcs/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.009/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.009/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/detect_regsvcs_with_no_command_line_arguments.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-09-20-office_document_spawned_child_process_to_download.md b/docs/_posts/2021-09-20-office_document_spawned_child_process_to_download.md deleted file mode 100644 index 5a3740eb78..0000000000 --- a/docs/_posts/2021-09-20-office_document_spawned_child_process_to_download.md +++ /dev/null @@ -1,168 +0,0 @@ ---- -title: "Office Document Spawned Child Process To Download" -excerpt: "Phishing -, Spearphishing Attachment -" -categories: - - Endpoint -last_modified_at: 2021-09-20 -toc: true -toc_label: "" -tags: - - Phishing - - Spearphishing Attachment - - Initial Access - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect potential malicious office document executing lolbin child process to download payload or other malware. Since most of the attacker abused the capability of office document to execute living on land application to blend it to the normal noise in the infected machine to cover its track. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-09-20 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 6fed27d2-9ec7-11eb-8fe4-aa665a019aa3 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | - -| [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name IN ("winword.exe","excel.exe","powerpnt.exe","mspub.exe","visio.exe") Processes.process IN ("*http:*","*https:*") NOT (Processes.original_file_name IN("firefox.exe", "chrome.exe","iexplore.exe","msedge.exe")) by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.original_file_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `office_document_spawned_child_process_to_download_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **office_document_spawned_child_process_to_download_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances office application and browser may be used. - -#### Known False Positives -Default browser not in the filter list. - -#### Associated Analytic story -* [Spearphishing Attachments](/stories/spearphishing_attachments) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 35.0 | 70 | 50 | Office document spawning suspicious child process on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://app.any.run/tasks/92d7ef61-bfd7-4c92-bc15-322172b4ebec/](https://app.any.run/tasks/92d7ef61-bfd7-4c92-bc15-322172b4ebec/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/datasets2/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/datasets2/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2021-09-20-suspicious_dllhost_no_command_line_arguments.md b/docs/_posts/2021-09-20-suspicious_dllhost_no_command_line_arguments.md deleted file mode 100644 index f847ccddab..0000000000 --- a/docs/_posts/2021-09-20-suspicious_dllhost_no_command_line_arguments.md +++ /dev/null @@ -1,117 +0,0 @@ ---- -title: "Suspicious DLLHost no Command Line Arguments" -excerpt: "Process Injection -" -categories: - - Endpoint -last_modified_at: 2021-09-20 -toc: true -toc_label: "" -tags: - - Process Injection - - Defense Evasion - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies DLLHost.exe with no command line arguments. It is unusual for DLLHost.exe to execute with no command line arguments present. This particular behavior is common with malicious software, including Cobalt Strike. During investigation, identify any network connections and parallel processes. Identify any suspicious module loads related to credential dumping or file writes. DLLHost.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/object-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-09-20 -- **Author**: Michael Haag, Splunk -- **ID**: ff61e98c-0337-4593-a78f-72a676c56f26 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1055](https://attack.mitre.org/techniques/T1055/) | Process Injection | Defense Evasion, Privilege Escalation | - -#### Search - -``` - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where `process_dllhost` by _time span=1h Processes.process_id Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| regex process="(dllhost\.exe.{0,4}$)" -| `suspicious_dllhost_no_command_line_arguments_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [process_dllhost](https://github.com/splunk/security_content/blob/develop/macros/process_dllhost.yml) - -Note that `suspicious_dllhost_no_command_line_arguments_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Limited false positives may be present in small environments. Tuning may be required based on parent process. - -#### Associated Analytic story -* [Cobalt Strike](/stories/cobalt_strike) - - -#### Kill Chain Phase -* Exploitation - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | Suspicious dllhost.exe process with no command line arguments executed on $dest$ by $user$ | - - - - -#### Reference - -* [https://raw.githubusercontent.com/threatexpress/malleable-c2/c3385e481159a759f79b8acfe11acf240893b830/jquery-c2.4.2.profile](https://raw.githubusercontent.com/threatexpress/malleable-c2/c3385e481159a759f79b8acfe11acf240893b830/jquery-c2.4.2.profile) -* [https://blog.cobaltstrike.com/2021/02/09/learn-pipe-fitting-for-all-of-your-offense-projects/](https://blog.cobaltstrike.com/2021/02/09/learn-pipe-fitting-for-all-of-your-offense-projects/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-09-20-suspicious_gpupdate_no_command_line_arguments.md b/docs/_posts/2021-09-20-suspicious_gpupdate_no_command_line_arguments.md deleted file mode 100644 index 206d088f94..0000000000 --- a/docs/_posts/2021-09-20-suspicious_gpupdate_no_command_line_arguments.md +++ /dev/null @@ -1,117 +0,0 @@ ---- -title: "Suspicious GPUpdate no Command Line Arguments" -excerpt: "Process Injection -" -categories: - - Endpoint -last_modified_at: 2021-09-20 -toc: true -toc_label: "" -tags: - - Process Injection - - Defense Evasion - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies gpupdate.exe with no command line arguments. It is unusual for gpupdate.exe to execute with no command line arguments present. This particular behavior is common with malicious software, including Cobalt Strike. During investigation, identify any network connections and parallel processes. Identify any suspicious module loads related to credential dumping or file writes. gpupdate.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/object-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-09-20 -- **Author**: Michael Haag, Splunk -- **ID**: f308490a-473a-40ef-ae64-dd7a6eba284a - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1055](https://attack.mitre.org/techniques/T1055/) | Process Injection | Defense Evasion, Privilege Escalation | - -#### Search - -``` - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where `process_gpupdate` by _time span=1h Processes.process_id Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| regex process="(gpupdate\.exe.{0,4}$)" -| `suspicious_gpupdate_no_command_line_arguments_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_gpupdate](https://github.com/splunk/security_content/blob/develop/macros/process_gpupdate.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -Note that `suspicious_gpupdate_no_command_line_arguments_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -Limited false positives may be present in small environments. Tuning may be required based on parent process. - -#### Associated Analytic story -* [Cobalt Strike](/stories/cobalt_strike) - - -#### Kill Chain Phase -* Exploitation - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | Suspicious gpupdate.exe process with no command line arguments executed on $dest$ by $user$ | - - - - -#### Reference - -* [https://raw.githubusercontent.com/xx0hcd/Malleable-C2-Profiles/0ef8cf4556e26f6d4190c56ba697c2159faa5822/crimeware/trick_ryuk.profile](https://raw.githubusercontent.com/xx0hcd/Malleable-C2-Profiles/0ef8cf4556e26f6d4190c56ba697c2159faa5822/crimeware/trick_ryuk.profile) -* [https://blog.cobaltstrike.com/2021/02/09/learn-pipe-fitting-for-all-of-your-offense-projects/](https://blog.cobaltstrike.com/2021/02/09/learn-pipe-fitting-for-all-of-your-offense-projects/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-09-20-suspicious_microsoft_workflow_compiler_rename.md b/docs/_posts/2021-09-20-suspicious_microsoft_workflow_compiler_rename.md deleted file mode 100644 index d00fa64fff..0000000000 --- a/docs/_posts/2021-09-20-suspicious_microsoft_workflow_compiler_rename.md +++ /dev/null @@ -1,179 +0,0 @@ ---- -title: "Suspicious microsoft workflow compiler rename" -excerpt: "Masquerading -, Trusted Developer Utilities Proxy Execution -, Rename System Utilities -" -categories: - - Endpoint -last_modified_at: 2021-09-20 -toc: true -toc_label: "" -tags: - - Masquerading - - Trusted Developer Utilities Proxy Execution - - Rename System Utilities - - Defense Evasion - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies a renamed instance of microsoft.workflow.compiler.exe. Microsoft.workflow.compiler.exe is natively found in C:\Windows\Microsoft.NET\Framework64\v4.0.30319 and is rarely utilized. When investigating, identify the executed code on disk and review. A spawned child process from microsoft.workflow.compiler.exe is uncommon. In any instance, microsoft.workflow.compiler.exe spawning from an Office product or any living off the land binary is highly suspect. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-09-20 -- **Author**: Michael Haag, Splunk -- **ID**: f0db4464-55d9-11eb-ae93-0242ac130002 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1036](https://attack.mitre.org/techniques/T1036/) | Masquerading | Defense Evasion | - -| [T1127](https://attack.mitre.org/techniques/T1127/) | Trusted Developer Utilities Proxy Execution | Defense Evasion | - -| [T1036.003](https://attack.mitre.org/techniques/T1036/003/) | Rename System Utilities | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_microsoftworkflowcompiler` by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.original_file_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `suspicious_microsoft_workflow_compiler_rename_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [process_microsoftworkflowcompiler](https://github.com/splunk/security_content/blob/develop/macros/process_microsoftworkflowcompiler.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -Note that **suspicious_microsoft_workflow_compiler_rename_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Although unlikely, some legitimate applications may use a moved copy of microsoft.workflow.compiler.exe, triggering a false positive. - -#### Associated Analytic story -* [Trusted Developer Utilities Proxy Execution](/stories/trusted_developer_utilities_proxy_execution) -* [Cobalt Strike](/stories/cobalt_strike) -* [Masquerading - Rename System Utilities](/stories/masquerading_-_rename_system_utilities) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 63.0 | 70 | 90 | Suspicious renamed microsoft.workflow.compiler.exe binary ran on $dest$ by $user$ | - - -#### Reference - -* [https://lolbas-project.github.io/lolbas/Binaries/Microsoft.Workflow.Compiler/](https://lolbas-project.github.io/lolbas/Binaries/Microsoft.Workflow.Compiler/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218/T1218.md#atomic-test-6---microsoftworkflowcompilerexe-payload-execution](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218/T1218.md#atomic-test-6---microsoftworkflowcompilerexe-payload-execution) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2021-09-20-suspicious_rundll32_no_command_line_arguments.md b/docs/_posts/2021-09-20-suspicious_rundll32_no_command_line_arguments.md deleted file mode 100644 index 06d1499832..0000000000 --- a/docs/_posts/2021-09-20-suspicious_rundll32_no_command_line_arguments.md +++ /dev/null @@ -1,132 +0,0 @@ ---- -title: "Suspicious Rundll32 no Command Line Arguments" -excerpt: "Signed Binary Proxy Execution -, Rundll32 -" -categories: - - Endpoint -last_modified_at: 2021-09-20 -toc: true -toc_label: "" -tags: - - Signed Binary Proxy Execution - - Rundll32 - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2021-34527 - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies rundll32.exe with no command line arguments. It is unusual for rundll32.exe to execute with no command line arguments present. This particular behavior is common with malicious software, including Cobalt Strike. During investigation, identify any network connections and parallel processes. Identify any suspicious module loads related to credential dumping or file writes. Rundll32.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/object-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-09-20 -- **Author**: Michael Haag, Splunk -- **ID**: e451bd16-e4c5-4109-8eb1-c4c6ecf048b4 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | - -| [T1218.011](https://attack.mitre.org/techniques/T1218/011/) | Rundll32 | Defense Evasion | - -#### Search - -``` - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where `process_rundll32` by _time span=1h Processes.process_id Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| regex process="(rundll32\.exe.{0,4}$)" -| `suspicious_rundll32_no_command_line_arguments_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [process_rundll32](https://github.com/splunk/security_content/blob/develop/macros/process_rundll32.yml) - -Note that `suspicious_rundll32_no_command_line_arguments_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Although unlikely, some legitimate applications may use a moved copy of rundll32, triggering a false positive. - -#### Associated Analytic story -* [Suspicious Rundll32 Activity](/stories/suspicious_rundll32_activity) -* [Cobalt Strike](/stories/cobalt_strike) -* [PrintNightmare CVE-2021-34527](/stories/printnightmare_cve-2021-34527) - - -#### Kill Chain Phase -* Actions on Objectives - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | Suspicious rundll32.exe process with no command line arguments executed on $dest$ by $user$ | - - -#### CVE - -| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2021-34527](https://nvd.nist.gov/vuln/detail/CVE-2021-34527) | Windows Print Spooler Remote Code Execution Vulnerability | 9.0 | - - - -#### Reference - -* [https://attack.mitre.org/techniques/T1218/011/](https://attack.mitre.org/techniques/T1218/011/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.011/T1218.011.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.011/T1218.011.md) -* [https://lolbas-project.github.io/lolbas/Binaries/Rundll32](https://lolbas-project.github.io/lolbas/Binaries/Rundll32) -* [https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/](https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.011/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.011/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/suspicious_rundll32_no_command_line_arguments.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-09-20-suspicious_searchprotocolhost_no_command_line_arguments.md b/docs/_posts/2021-09-20-suspicious_searchprotocolhost_no_command_line_arguments.md deleted file mode 100644 index 03b8c7fe7b..0000000000 --- a/docs/_posts/2021-09-20-suspicious_searchprotocolhost_no_command_line_arguments.md +++ /dev/null @@ -1,115 +0,0 @@ ---- -title: "Suspicious SearchProtocolHost no Command Line Arguments" -excerpt: "Process Injection -" -categories: - - Endpoint -last_modified_at: 2021-09-20 -toc: true -toc_label: "" -tags: - - Process Injection - - Defense Evasion - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies searchprotocolhost.exe with no command line arguments. It is unusual for searchprotocolhost.exe to execute with no command line arguments present. This particular behavior is common with malicious software, including Cobalt Strike. During investigation, identify any network connections and parallel processes. Identify any suspicious module loads related to credential dumping or file writes. searchprotocolhost.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/object-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-09-20 -- **Author**: Michael Haag, Splunk -- **ID**: f52d2db8-31f9-4aa7-a176-25779effe55c - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1055](https://attack.mitre.org/techniques/T1055/) | Process Injection | Defense Evasion, Privilege Escalation | - -#### Search - -``` - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name=searchprotocolhost.exe by _time span=1h Processes.process_id Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| regex process="(searchprotocolhost\.exe.{0,4}$)" -| `suspicious_searchprotocolhost_no_command_line_arguments_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -Note that `suspicious_searchprotocolhost_no_command_line_arguments_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Limited false positives may be present in small environments. Tuning may be required based on parent process. - -#### Associated Analytic story -* [Cobalt Strike](/stories/cobalt_strike) - - -#### Kill Chain Phase -* Exploitation - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | Suspicious searchprotocolhost.exe process with no command line arguments executed on $dest$ by $user$ | - - - - -#### Reference - -* [https://github.com/fireeye/red_team_tool_countermeasures/blob/master/rules/PGF/supplemental/hxioc/SUSPICIOUS%20EXECUTION%20OF%20SEARCHPROTOCOLHOST%20(METHODOLOGY).ioc](https://github.com/fireeye/red_team_tool_countermeasures/blob/master/rules/PGF/supplemental/hxioc/SUSPICIOUS%20EXECUTION%20OF%20SEARCHPROTOCOLHOST%20(METHODOLOGY).ioc) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-09-21-remcos_rat_file_creation_in_remcos_folder.md b/docs/_posts/2021-09-21-remcos_rat_file_creation_in_remcos_folder.md deleted file mode 100644 index 9f36797a90..0000000000 --- a/docs/_posts/2021-09-21-remcos_rat_file_creation_in_remcos_folder.md +++ /dev/null @@ -1,157 +0,0 @@ ---- -title: "Remcos RAT File Creation in Remcos Folder" -excerpt: "Screen Capture -" -categories: - - Endpoint -last_modified_at: 2021-09-21 -toc: true -toc_label: "" -tags: - - Screen Capture - - Collection - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect file creation in remcos folder in appdata which is the keylog and clipboard logs that will be send to its c2 server. This is really a good TTP indicator that there is a remcos rat in the system that do keylogging, clipboard grabbing and audio recording. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-09-21 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 25ae862a-1ac3-11ec-94a1-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1113](https://attack.mitre.org/techniques/T1113/) | Screen Capture | Collection | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -|tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_name IN ("*.dat") Filesystem.file_path = "*\\remcos\\*" by _time Filesystem.file_name Filesystem.file_path Filesystem.dest Filesystem.file_create_time -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `remcos_rat_file_creation_in_remcos_folder_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **remcos_rat_file_creation_in_remcos_folder_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* dest -* file_create_time -* file_name -* file_path - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Remcos](/stories/remcos) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 100.0 | 100 | 100 | file $file_name$ created in $file_path$ of $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://success.trendmicro.com/dcx/s/solution/1123281-remcos-malware-information?language=en_US](https://success.trendmicro.com/dcx/s/solution/1123281-remcos-malware-information?language=en_US) -* [https://blog.malwarebytes.com/threat-intelligence/2021/07/remcos-rat-delivered-via-visual-basic/](https://blog.malwarebytes.com/threat-intelligence/2021/07/remcos-rat-delivered-via-visual-basic/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos_agent/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos_agent/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-21-suspicious_image_creation_in_appdata_folder.md b/docs/_posts/2021-09-21-suspicious_image_creation_in_appdata_folder.md deleted file mode 100644 index 370ef4905d..0000000000 --- a/docs/_posts/2021-09-21-suspicious_image_creation_in_appdata_folder.md +++ /dev/null @@ -1,161 +0,0 @@ ---- -title: "Suspicious Image Creation In Appdata Folder" -excerpt: "Screen Capture -" -categories: - - Endpoint -last_modified_at: 2021-09-21 -toc: true -toc_label: "" -tags: - - Screen Capture - - Collection - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect a suspicious creation of image in appdata folder made by process that also has a file reference in appdata folder. This technique was seen in remcos rat that capture screenshot of the compromised machine and place it in the appdata and will be send to its C2 server. This TTP is really a good indicator to check that process because it is in suspicious folder path and image files are not commonly created by user in this folder path. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-09-21 -- **Author**: Teoderick Contreras, Splunk -- **ID**: f6f904c4-1ac0-11ec-806b-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1113](https://attack.mitre.org/techniques/T1113/) | Screen Capture | Collection | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name=*.exe Processes.process_path="*\\appdata\\Roaming\\*" by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest -| `drop_dm_object_name(Processes)` -| join process_guid, _time [ -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_name IN ("*.png","*.jpg","*.bmp","*.gif","*.tiff") Filesystem.file_path = "*\\appdata\\Roaming\\*" by _time span=1h Filesystem.dest Filesystem.file_create_time Filesystem.file_name Filesystem.file_path -| `drop_dm_object_name(Filesystem)` -| fields _time dest file_create_time file_name file_path process_name process_path process] -| `suspicious_image_creation_in_appdata_folder_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **suspicious_image_creation_in_appdata_folder_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* dest -* file_create_time -* file_name -* file_path -* process_name -* process_path -* process - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Remcos](/stories/remcos) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | process $process_name$ creating image file $file_path$ in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://success.trendmicro.com/dcx/s/solution/1123281-remcos-malware-information?language=en_US](https://success.trendmicro.com/dcx/s/solution/1123281-remcos-malware-information?language=en_US) -* [https://blog.malwarebytes.com/threat-intelligence/2021/07/remcos-rat-delivered-via-visual-basic/](https://blog.malwarebytes.com/threat-intelligence/2021/07/remcos-rat-delivered-via-visual-basic/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos_agent/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos_agent/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-21-suspicious_wav_file_in_appdata_folder.md b/docs/_posts/2021-09-21-suspicious_wav_file_in_appdata_folder.md deleted file mode 100644 index c9d6643b26..0000000000 --- a/docs/_posts/2021-09-21-suspicious_wav_file_in_appdata_folder.md +++ /dev/null @@ -1,161 +0,0 @@ ---- -title: "Suspicious WAV file in Appdata Folder" -excerpt: "Screen Capture -" -categories: - - Endpoint -last_modified_at: 2021-09-21 -toc: true -toc_label: "" -tags: - - Screen Capture - - Collection - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to detect a suspicious creation of .wav file in appdata folder. This behavior was seen in Remcos RAT malware where it put the audio recording in the appdata\audio folde as part of data collection. this recording can be send to its C2 server as part of its exfiltration to the compromised machine. creation of wav files in this folder path is not a ussual disk place used by user to save audio format file. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-09-21 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 5be109e6-1ac5-11ec-b421-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1113](https://attack.mitre.org/techniques/T1113/) | Screen Capture | Collection | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name=*.exe Processes.process_path="*\\appdata\\Roaming\\*" by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest -| `drop_dm_object_name(Processes)` -| join process_guid, _time [ -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_name IN ("*.wav") Filesystem.file_path = "*\\appdata\\Roaming\\*" by _time span=1h Filesystem.dest Filesystem.file_create_time Filesystem.file_name Filesystem.file_path -| `drop_dm_object_name(Filesystem)` -| fields file_name file_path process_name process_path process dest file_create_time _time ] -| `suspicious_wav_file_in_appdata_folder_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **suspicious_wav_file_in_appdata_folder_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* dest -* file_create_time -* file_name -* file_path -* process_name -* process_path -* process - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, file_name, file_path and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Remcos](/stories/remcos) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | process $process_name$ creating image file $file_path$ in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://success.trendmicro.com/dcx/s/solution/1123281-remcos-malware-information?language=en_US](https://success.trendmicro.com/dcx/s/solution/1123281-remcos-malware-information?language=en_US) -* [https://blog.malwarebytes.com/threat-intelligence/2021/07/remcos-rat-delivered-via-visual-basic/](https://blog.malwarebytes.com/threat-intelligence/2021/07/remcos-rat-delivered-via-visual-basic/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos_agent/sysmon_wav.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos_agent/sysmon_wav.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-27-change_default_file_association.md b/docs/_posts/2021-09-27-change_default_file_association.md deleted file mode 100644 index cb7c02689c..0000000000 --- a/docs/_posts/2021-09-27-change_default_file_association.md +++ /dev/null @@ -1,167 +0,0 @@ ---- -title: "Change Default File Association" -excerpt: "Change Default File Association -, Event Triggered Execution -" -categories: - - Endpoint -last_modified_at: 2021-09-27 -toc: true -toc_label: "" -tags: - - Change Default File Association - - Event Triggered Execution - - Persistence - - Privilege Escalation - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is developed to detect suspicious registry modification to change the default file association of windows to malicious payload. This techninique was seen in some APT where it modify the default process to run file association, like .txt to notepad.exe. Instead notepad.exe it will point to a Script or other payload that will load malicious command to the compromised host. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-09-27 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 462d17d8-1f71-11ec-ad07-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1546.001](https://attack.mitre.org/techniques/T1546/001/) | Change Default File Association | Persistence, Privilege Escalation | - -| [T1546](https://attack.mitre.org/techniques/T1546/) | Event Triggered Execution | Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path ="*\\shell\\open\\command\\*" Registry.registry_path = "*HKCR\\*" by Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `drop_dm_object_name(Registry)` -| `change_default_file_association_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **change_default_file_association_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.dest -* Registry.user -* Registry.registry_path -* Registry.registry_key_name -* Registry.registry_value_name - - -#### How To Implement -To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Windows Persistence Techniques](/stories/windows_persistence_techniques) -* [Windows Privilege Escalation](/stories/windows_privilege_escalation) -* [Windows Registry Abuse](/stories/windows_registry_abuse) -* [Hermetic Wiper](/stories/hermetic_wiper) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | modified/added/deleted registry entry $Registry.registry_path$ in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/privilege-escalation/untitled-3/accessibility-features](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/privilege-escalation/untitled-3/accessibility-features) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.001/txtfile_reg/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.001/txtfile_reg/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/change_default_file_association.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-27-logon_script_event_trigger_execution.md b/docs/_posts/2021-09-27-logon_script_event_trigger_execution.md deleted file mode 100644 index 65c5eeab70..0000000000 --- a/docs/_posts/2021-09-27-logon_script_event_trigger_execution.md +++ /dev/null @@ -1,166 +0,0 @@ ---- -title: "Logon Script Event Trigger Execution" -excerpt: "Boot or Logon Initialization Scripts -, Logon Script (Windows) -" -categories: - - Endpoint -last_modified_at: 2021-09-27 -toc: true -toc_label: "" -tags: - - Boot or Logon Initialization Scripts - - Logon Script (Windows) - - Persistence - - Privilege Escalation - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect a suspicious modification of registry entry to persist and gain privilege escalation upon booting up of compromised host. This technique was seen in several APT and malware where it modify UserInitMprLogonScript registry entry to its malicious payload to be executed upon boot up of the machine. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-09-27 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 4c38c264-1f74-11ec-b5fa-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1037](https://attack.mitre.org/techniques/T1037/) | Boot or Logon Initialization Scripts | Persistence, Privilege Escalation | - -| [T1037.001](https://attack.mitre.org/techniques/T1037/001/) | Logon Script (Windows) | Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path IN ("*\\Environment\\UserInitMprLogonScript") by Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `drop_dm_object_name(Registry)` -| `logon_script_event_trigger_execution_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **logon_script_event_trigger_execution_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.dest -* Registry.user -* Registry.registry_path -* Registry.registry_key_name -* Registry.registry_value_name - - -#### How To Implement -To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Windows Persistence Techniques](/stories/windows_persistence_techniques) -* [Windows Privilege Escalation](/stories/windows_privilege_escalation) -* [Hermetic Wiper](/stories/hermetic_wiper) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | modified/added/deleted registry entry $Registry.registry_path$ in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1037/001/](https://attack.mitre.org/techniques/T1037/001/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1037.001/logonscript_reg/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1037.001/logonscript_reg/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/logon_script_event_trigger_execution.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-27-screensaver_event_trigger_execution.md b/docs/_posts/2021-09-27-screensaver_event_trigger_execution.md deleted file mode 100644 index b84ed3e5c4..0000000000 --- a/docs/_posts/2021-09-27-screensaver_event_trigger_execution.md +++ /dev/null @@ -1,168 +0,0 @@ ---- -title: "Screensaver Event Trigger Execution" -excerpt: "Event Triggered Execution -, Screensaver -" -categories: - - Endpoint -last_modified_at: 2021-09-27 -toc: true -toc_label: "" -tags: - - Event Triggered Execution - - Screensaver - - Persistence - - Privilege Escalation - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is developed to detect possible event trigger execution through screensaver registry entry modification for persistence or privilege escalation. This technique was seen in several APT and malware where they put the malicious payload path to the SCRNSAVE.EXE registry key to redirect the execution to their malicious payload path. This TTP is a good indicator that some attacker may modify this entry for their persistence and privilege escalation. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-09-27 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 58cea3ec-1f6d-11ec-8560-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1546](https://attack.mitre.org/techniques/T1546/) | Event Triggered Execution | Persistence, Privilege Escalation | - -| [T1546.002](https://attack.mitre.org/techniques/T1546/002/) | Screensaver | Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where (Registry.registry_path="*\\Control Panel\\Desktop\\SCRNSAVE.EXE*") by Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `drop_dm_object_name(Registry)` -| `screensaver_event_trigger_execution_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **screensaver_event_trigger_execution_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.dest -* Registry.user -* Registry.registry_path -* Registry.registry_key_name -* Registry.registry_value_name - - -#### How To Implement -To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Windows Persistence Techniques](/stories/windows_persistence_techniques) -* [Windows Privilege Escalation](/stories/windows_privilege_escalation) -* [Windows Registry Abuse](/stories/windows_registry_abuse) -* [Hermetic Wiper](/stories/hermetic_wiper) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 72.0 | 80 | 90 | modified/added/deleted registry entry $Registry.registry_path$ in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1546/002/](https://attack.mitre.org/techniques/T1546/002/) -* [https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/privilege-escalation/untitled-3/screensaver](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/privilege-escalation/untitled-3/screensaver) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.002/scrnsave_reg/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.002/scrnsave_reg/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/screensaver_event_trigger_execution.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-28-print_processor_registry_autostart.md b/docs/_posts/2021-09-28-print_processor_registry_autostart.md deleted file mode 100644 index d0cbefcb3b..0000000000 --- a/docs/_posts/2021-09-28-print_processor_registry_autostart.md +++ /dev/null @@ -1,169 +0,0 @@ ---- -title: "Print Processor Registry Autostart" -excerpt: "Print Processors -, Boot or Logon Autostart Execution -" -categories: - - Endpoint -last_modified_at: 2021-09-28 -toc: true -toc_label: "" -tags: - - Print Processors - - Boot or Logon Autostart Execution - - Persistence - - Privilege Escalation - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to detect a suspicious modification or new registry entry regarding print processor. This registry is known to be abuse by turla or other APT to gain persistence and privilege escalation to the compromised machine. This is done by adding the malicious dll payload on the new created key in this registry that will be executed as it restarted the spoolsv.exe process and services. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-09-28 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 1f5b68aa-2037-11ec-898e-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1547.012](https://attack.mitre.org/techniques/T1547/012/) | Print Processors | Persistence, Privilege Escalation | - -| [T1547](https://attack.mitre.org/techniques/T1547/) | Boot or Logon Autostart Execution | Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path ="*\\Control\\Print\\Environments\\Windows x64\\Print Processors*" by Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `drop_dm_object_name(Registry)` -| `print_processor_registry_autostart_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **print_processor_registry_autostart_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.dest -* Registry.user -* Registry.registry_path -* Registry.registry_key_name -* Registry.registry_value_name - - -#### How To Implement -To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. - -#### Known False Positives -possible new printer installation may add driver component on this registry. - -#### Associated Analytic story -* [Windows Persistence Techniques](/stories/windows_persistence_techniques) -* [Windows Privilege Escalation](/stories/windows_privilege_escalation) -* [Hermetic Wiper](/stories/hermetic_wiper) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | modified/added/deleted registry entry $Registry.registry_path$ in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1547/012/](https://attack.mitre.org/techniques/T1547/012/) -* [https://www.welivesecurity.com/2020/05/21/no-game-over-winnti-group/](https://www.welivesecurity.com/2020/05/21/no-game-over-winnti-group/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.012/print_reg/sysmon_print.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.012/print_reg/sysmon_print.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/endpoint/print_processor_registry_autostart.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-29-verclsid_clsid_execution.md b/docs/_posts/2021-09-29-verclsid_clsid_execution.md deleted file mode 100644 index 5ed0df7318..0000000000 --- a/docs/_posts/2021-09-29-verclsid_clsid_execution.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: "Verclsid CLSID Execution" -excerpt: "Verclsid -, System Binary Proxy Execution -" -categories: - - Endpoint -last_modified_at: 2021-09-29 -toc: true -toc_label: "" -tags: - - Verclsid - - System Binary Proxy Execution - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to detect a possible abuse of verclsid to execute malicious file through generate CLSID. This process is a normal application of windows to verify the CLSID COM object before it is instantiated by Windows Explorer. This hunting query can be a good pivot point to analyze what is he CLSID or COM object pointing too to check if it is a valid application or not. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-09-29 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 61e9a56a-20fa-11ec-8ba3-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218.012](https://attack.mitre.org/techniques/T1218/012/) | Verclsid | Defense Evasion | - -| [T1218](https://attack.mitre.org/techniques/T1218/) | System Binary Proxy Execution | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` values(Processes.process) as process values(Processes.parent_process) as parent_process values(Processes.process_id) as process_id count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_verclsid` AND Processes.process="*/S*" Processes.process="*/C*" AND Processes.process="*{*" AND Processes.process="*}*" by Processes.process_name Processes.original_file_name Processes.dest Processes.user Processes.parent_process_name Processes.parent_process -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `verclsid_clsid_execution_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_verclsid](https://github.com/splunk/security_content/blob/develop/macros/process_verclsid.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **verclsid_clsid_execution_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -windows can used this application for its normal COM object validation. - -#### Associated Analytic story -* [Unusual Processes](/stories/unusual_processes) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | process $process_name$ to execute possible clsid commandline $process$ in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://gist.github.com/NickTyrer/0598b60112eaafe6d07789f7964290d5](https://gist.github.com/NickTyrer/0598b60112eaafe6d07789f7964290d5) -* [https://bohops.com/2018/08/18/abusing-the-com-registry-structure-part-2-loading-techniques-for-evasion-and-persistence/](https://bohops.com/2018/08/18/abusing-the-com-registry-structure-part-2-loading-techniques-for-evasion-and-persistence/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.012/verclsid_exec/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.012/verclsid_exec/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/verclsid_clsid_execution.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-10-01-vbscript_execution_using_wscript_app.md b/docs/_posts/2021-10-01-vbscript_execution_using_wscript_app.md deleted file mode 100644 index e3c8f76556..0000000000 --- a/docs/_posts/2021-10-01-vbscript_execution_using_wscript_app.md +++ /dev/null @@ -1,169 +0,0 @@ ---- -title: "Vbscript Execution Using Wscript App" -excerpt: "Visual Basic -, Command and Scripting Interpreter -" -categories: - - Endpoint -last_modified_at: 2021-10-01 -toc: true -toc_label: "" -tags: - - Visual Basic - - Command and Scripting Interpreter - - Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to detect a suspicious wscript commandline to execute vbscript. This technique was seen in several malware to execute malicious vbs file using wscript application. commonly vbs script is associated to cscript process and this can be a technique to evade process parent child detections or even some av script emulation system. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-10-01 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 35159940-228f-11ec-8a49-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059.005](https://attack.mitre.org/techniques/T1059/005/) | Visual Basic | Execution | - -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.parent_process_name = "wscript.exe" AND Processes.parent_process = "*//e:vbscript*") OR (Processes.process_name = "wscript.exe" AND Processes.process = "*//e:vbscript*") by Processes.parent_process_name Processes.parent_process Processes.process_name Processes.process_id Processes.process Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `vbscript_execution_using_wscript_app_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **vbscript_execution_using_wscript_app_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [FIN7](/stories/fin7) -* [Remcos](/stories/remcos) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | Process name $process_name$ with commandline $process$ to execute vbsscript | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.joesandbox.com/analysis/369332/0/html](https://www.joesandbox.com/analysis/369332/0/html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.005/vbs_wscript/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.005/vbs_wscript/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-10-04-msbuild_suspicious_spawned_by_script_process.md b/docs/_posts/2021-10-04-msbuild_suspicious_spawned_by_script_process.md deleted file mode 100644 index 8ae8f4edaf..0000000000 --- a/docs/_posts/2021-10-04-msbuild_suspicious_spawned_by_script_process.md +++ /dev/null @@ -1,164 +0,0 @@ ---- -title: "MSBuild Suspicious Spawned By Script Process" -excerpt: "MSBuild -, Trusted Developer Utilities Proxy Execution -" -categories: - - Endpoint -last_modified_at: 2021-10-04 -toc: true -toc_label: "" -tags: - - MSBuild - - Trusted Developer Utilities Proxy Execution - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to detect a suspicious child process of MSBuild spawned by Windows Script Host - cscript or wscript. This behavior or event are commonly seen and used by malware or adversaries to execute malicious msbuild process using malicious script in the compromised host. During triage, review parallel processes and identify any file modifications. MSBuild may load a script from the same path without having command-line arguments. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-10-04 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 213b3148-24ea-11ec-93a2-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1127.001](https://attack.mitre.org/techniques/T1127/001/) | MSBuild | Defense Evasion | - -| [T1127](https://attack.mitre.org/techniques/T1127/) | Trusted Developer Utilities Proxy Execution | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count values(Processes.process_name) as process_name values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name IN ("wscript.exe", "cscript.exe") AND `process_msbuild` by Processes.dest Processes.parent_process Processes.parent_process_name Processes.process_name Processes.original_file_name Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `msbuild_suspicious_spawned_by_script_process_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_msbuild](https://github.com/splunk/security_content/blob/develop/macros/process_msbuild.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **msbuild_suspicious_spawned_by_script_process_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.parent_process -* Processes.parent_process_name -* Processes.process_name -* Processes.original_file_name -* Processes.user - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -False positives should be limited as developers do not spawn MSBuild via a WSH. - -#### Associated Analytic story -* [Trusted Developer Utilities Proxy Execution MSBuild](/stories/trusted_developer_utilities_proxy_execution_msbuild) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | Msbuild.exe process spawned by $parent_process_name$ on $dest$ executed by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://app.any.run/tasks/dc93ee63-050c-4ff8-b07e-8277af9ab939/](https://app.any.run/tasks/dc93ee63-050c-4ff8-b07e-8277af9ab939/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127.001/regsvr32_silent/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127.001/regsvr32_silent/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/msbuild_suspicious_spawned_by_script_process.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-10-04-regsvr32_silent_and_install_param_dll_loading.md b/docs/_posts/2021-10-04-regsvr32_silent_and_install_param_dll_loading.md deleted file mode 100644 index c924c644b1..0000000000 --- a/docs/_posts/2021-10-04-regsvr32_silent_and_install_param_dll_loading.md +++ /dev/null @@ -1,176 +0,0 @@ ---- -title: "Regsvr32 Silent and Install Param Dll Loading" -excerpt: "System Binary Proxy Execution -, Regsvr32 -" -categories: - - Endpoint -last_modified_at: 2021-10-04 -toc: true -toc_label: "" -tags: - - System Binary Proxy Execution - - Regsvr32 - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to detect a loading of dll using regsvr32 application with silent parameter and dllinstall execution. This technique was seen in several RAT malware similar to remcos, njrat and adversaries to load their malicious DLL on the compromised machine. This TTP may executed by normal 3rd party application so it is better to pivot by the parent process, parent command-line and command-line of the file that execute this regsvr32. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-10-04 -- **Author**: Teoderick Contreras, Splunk -- **ID**: f421c250-24e7-11ec-bc43-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218](https://attack.mitre.org/techniques/T1218/) | System Binary Proxy Execution | Defense Evasion | - -| [T1218.010](https://attack.mitre.org/techniques/T1218/010/) | Regsvr32 | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_regsvr32` AND Processes.process="*/i*" by Processes.dest Processes.parent_process Processes.process Processes.parent_process_name Processes.process_name Processes.original_file_name Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| where match(process,"(?i)[\- -|\/][Ss]{1}") -| `regsvr32_silent_and_install_param_dll_loading_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [process_regsvr32](https://github.com/splunk/security_content/blob/develop/macros/process_regsvr32.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **regsvr32_silent_and_install_param_dll_loading_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Other third part application may used this parameter but not so common in base windows environment. - -#### Associated Analytic story -* [Data Destruction](/stories/data_destruction) -* [Suspicious Regsvr32 Activity](/stories/suspicious_regsvr32_activity) -* [Remcos](/stories/remcos) -* [Hermetic Wiper](/stories/hermetic_wiper) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 36.0 | 60 | 60 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to load a DLL using the silent and dllinstall parameter. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://app.any.run/tasks/dc93ee63-050c-4ff8-b07e-8277af9ab939/](https://app.any.run/tasks/dc93ee63-050c-4ff8-b07e-8277af9ab939/) -* [https://attack.mitre.org/techniques/T1218/010/](https://attack.mitre.org/techniques/T1218/010/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.005/vbs_wscript/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.005/vbs_wscript/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/regsvr32_silent_and_install_param_dll_loading.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-10-05-detect_exchange_web_shell.md b/docs/_posts/2021-10-05-detect_exchange_web_shell.md deleted file mode 100644 index e35e09eb0c..0000000000 --- a/docs/_posts/2021-10-05-detect_exchange_web_shell.md +++ /dev/null @@ -1,174 +0,0 @@ ---- -title: "Detect Exchange Web Shell" -excerpt: "Server Software Component -, Web Shell -, Exploit Public-Facing Application -" -categories: - - Endpoint -last_modified_at: 2021-10-05 -toc: true -toc_label: "" -tags: - - Server Software Component - - Web Shell - - Exploit Public-Facing Application - - Persistence - - Persistence - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following query identifies suspicious .aspx created in 3 paths identified by Microsoft as known drop locations for Exchange exploitation related to HAFNIUM group and recently disclosed vulnerablity named ProxyShell. Paths include: `\HttpProxy\owa\auth\`, `\inetpub\wwwroot\aspnet_client\`, and `\HttpProxy\OAB\`. Upon triage, the suspicious .aspx file will likely look obvious on the surface. inspect the contents for script code inside. Identify additional log sources, IIS included, to review source and other potential exploitation. It is often the case that a particular threat is only applicable to a specific subset of systems in your environment. Typically analytics to detect those threats are written without the benefit of being able to only target those systems as well. Writing analytics against all systems when those behaviors are limited to identifiable subsets of those systems is suboptimal. Consider the case ProxyShell vulnerability on Microsoft Exchange Servers. With asset information, a hunter can limit their analytics to systems that have been identified as Exchange servers. A hunter may start with the theory that the exchange server is communicating with new systems that it has not previously. If this theory is run against all publicly facing systems, the amount of noise it will generate will likely render this theory untenable. However, using the asset information to limit this analytic to just the Exchange servers will reduce the noise allowing the hunter to focus only on the systems where this behavioral change is relevant. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-10-05 -- **Author**: Michael Haag, Shannon Davis, David Dorsey, Splunk -- **ID**: 8c14eeee-2af1-4a4b-bda8-228da0f4862a - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1505](https://attack.mitre.org/techniques/T1505/) | Server Software Component | Persistence | - -| [T1505.003](https://attack.mitre.org/techniques/T1505/003/) | Web Shell | Persistence | - -| [T1190](https://attack.mitre.org/techniques/T1190/) | Exploit Public-Facing Application | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name=System by _time span=1h Processes.process_id Processes.process_name Processes.dest -| `drop_dm_object_name(Processes)` -| join process_guid, _time [ -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_path IN ("*\\HttpProxy\\owa\\auth\\*", "*\\inetpub\\wwwroot\\aspnet_client\\*", "*\\HttpProxy\\OAB\\*") Filesystem.file_name="*.aspx" by _time span=1h Filesystem.dest Filesystem.file_create_time Filesystem.file_name Filesystem.file_path -| `drop_dm_object_name(Filesystem)` -| fields _time dest file_create_time file_name file_path process_name process_path process] -| dedup file_create_time -| table dest file_create_time, file_name, file_path, process_name -| `detect_exchange_web_shell_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **detect_exchange_web_shell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Filesystem.file_path -* Filesystem.process_id -* Filesystem.file_name -* Filesystem.file_hash -* Filesystem.user - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node and `Filesystem` node. - -#### Known False Positives -The query is structured in a way that `action` (read, create) is not defined. Review the results of this query, filter, and tune as necessary. It may be necessary to generate this query specific to your endpoint product. - -#### Associated Analytic story -* [HAFNIUM Group](/stories/hafnium_group) -* [ProxyShell](/stories/proxyshell) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 81.0 | 90 | 90 | A file - $file_name$ was written to disk that is related to IIS exploitation previously performed by HAFNIUM. Review further file modifications on endpoint $dest$ by user $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Sample%20Data/Feeds/MSTICIoCs-ExchangeServerVulnerabilitiesDisclosedMarch2021.csv](https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Sample%20Data/Feeds/MSTICIoCs-ExchangeServerVulnerabilitiesDisclosedMarch2021.csv) -* [https://www.zerodayinitiative.com/blog/2021/8/17/from-pwn2own-2021-a-new-attack-surface-on-microsoft-exchange-proxyshell](https://www.zerodayinitiative.com/blog/2021/8/17/from-pwn2own-2021-a-new-attack-surface-on-microsoft-exchange-proxyshell) -* [https://www.youtube.com/watch?v=FC6iHw258RI](https://www.youtube.com/watch?v=FC6iHw258RI) -* [https://www.huntress.com/blog/rapid-response-microsoft-exchange-servers-still-vulnerable-to-proxyshell-exploit#what-should-you-do](https://www.huntress.com/blog/rapid-response-microsoft-exchange-servers-still-vulnerable-to-proxyshell-exploit#what-should-you-do) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1505.003/windows-sysmon_proxylogon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1505.003/windows-sysmon_proxylogon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/detect_exchange_web_shell.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2021-10-05-malicious_inprocserver32_modification.md b/docs/_posts/2021-10-05-malicious_inprocserver32_modification.md deleted file mode 100644 index f72b3e29df..0000000000 --- a/docs/_posts/2021-10-05-malicious_inprocserver32_modification.md +++ /dev/null @@ -1,171 +0,0 @@ ---- -title: "Malicious InProcServer32 Modification" -excerpt: "Regsvr32 -, Modify Registry -" -categories: - - Endpoint -last_modified_at: 2021-10-05 -toc: true -toc_label: "" -tags: - - Regsvr32 - - Modify Registry - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies a process modifying the registry with a known malicious CLSID under InProcServer32. Most COM classes are registered with the operating system and are identified by a GUID that represents the Class Identifier (CLSID) within the registry (usually under HKLM\\Software\\Classes\\CLSID or HKCU\\Software\\Classes\\CLSID). Behind the implementation of a COM class is the server (some binary) that is referenced within registry keys under the CLSID. The LocalServer32 key represents a path to an executable (exe) implementation, and the InprocServer32 key represents a path to a dynamic link library (DLL) implementation (Bohops). During triage, review parallel processes for suspicious activity. Pivot on the process GUID to see the full timeline of events. Analyze the value and look for file modifications. Being this is looking for inprocserver32, a DLL found in the value will most likely be loaded by a parallel process. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-10-05 -- **Author**: Michael Haag, Splunk -- **ID**: 127c8d08-25ff-11ec-9223-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218.010](https://attack.mitre.org/techniques/T1218/010/) | Regsvr32 | Defense Evasion | - -| [T1112](https://attack.mitre.org/techniques/T1112/) | Modify Registry | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time Processes.process_id Processes.process_name Processes.dest Processes.process_guid Processes.user -| `drop_dm_object_name(Processes)` -| join process_guid [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry where Registry.registry_path= "*\\CLSID\\{89565275-A714-4a43-912E-978B935EDCCC}\\InProcServer32\\(Default)" by Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.dest Registry.process_guid Registry.user -| `drop_dm_object_name(Registry)` -| fields _time dest registry_path registry_key_name registry_value_name process_name process_path process process_guid user] -| stats count min(_time) as firstTime max(_time) as lastTime by dest, process_name registry_path registry_key_name registry_value_name user -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `malicious_inprocserver32_modification_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **malicious_inprocserver32_modification_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* dest -* process_name -* registry_path -* registry_key_name -* registry_value_name -* user - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -False positives should be limited, filter as needed. In our test case, Remcos used regsvr32.exe to modify the registry. It may be required, dependent upon the EDR tool producing registry events, to remove (Default) from the command-line. - -#### Associated Analytic story -* [Suspicious Regsvr32 Activity](/stories/suspicious_regsvr32_activity) -* [Remcos](/stories/remcos) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | The $process_name$ was identified on endpoint $dest$ modifying the registry with a known malicious clsid under InProcServer32. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://bohops.com/2018/06/28/abusing-com-registry-structure-clsid-localserver32-inprocserver32/](https://bohops.com/2018/06/28/abusing-com-registry-structure-clsid-localserver32-inprocserver32/) -* [https://tria.ge/210929-ap75vsddan](https://tria.ge/210929-ap75vsddan) -* [https://www.virustotal.com/gui/file/cb77b93150cb0f7fe65ce8a7e2a5781e727419451355a7736db84109fa215a89](https://www.virustotal.com/gui/file/cb77b93150cb0f7fe65ce8a7e2a5781e727419451355a7736db84109fa215a89) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/malicious_inprocserver32_modification.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-10-05-process_writing_dynamicwrapperx.md b/docs/_posts/2021-10-05-process_writing_dynamicwrapperx.md deleted file mode 100644 index f42d4979d5..0000000000 --- a/docs/_posts/2021-10-05-process_writing_dynamicwrapperx.md +++ /dev/null @@ -1,172 +0,0 @@ ---- -title: "Process Writing DynamicWrapperX" -excerpt: "Command and Scripting Interpreter -, Component Object Model -" -categories: - - Endpoint -last_modified_at: 2021-10-05 -toc: true -toc_label: "" -tags: - - Command and Scripting Interpreter - - Component Object Model - - Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -DynamicWrapperX is an ActiveX component that can be used in a script to call Windows API functions, but it requires the dynwrapx.dll to be installed and registered. With that, a binary writing dynwrapx.dll to disk and registering it into the registry is highly suspect. Why is it needed? In most malicious instances, it will be written to disk at a non-standard location. During triage, review parallel processes and pivot on the process_guid. Review the registry for any suspicious modifications meant to load dynwrapx.dll. Identify any suspicious module loads of dynwrapx.dll. This will identify the process that will invoke vbs/wscript/cscript. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-10-05 -- **Author**: Michael Haag, Splunk -- **ID**: b0a078e4-2601-11ec-9aec-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -| [T1559.001](https://attack.mitre.org/techniques/T1559/001/) | Component Object Model | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time Processes.process_id Processes.process_name Processes.dest Processes.process_guid Processes.user -| `drop_dm_object_name(Processes)` -| join process_guid [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Filesystem where Filesystem.file_name="dynwrapx.dll" by _time Filesystem.dest Filesystem.file_create_time Filesystem.file_name Filesystem.file_path Filesystem.process_guid Filesystem.user -| `drop_dm_object_name(Filesystem)` -| fields _time process_guid file_path file_name file_create_time user dest process_name] -| stats count min(_time) as firstTime max(_time) as lastTime by dest process_name process_guid file_name file_path file_create_time user -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `process_writing_dynamicwrapperx_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **process_writing_dynamicwrapperx_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* dest -* process_name -* process_guid -* file_name -* file_path -* file_create_time user - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` and `Filesystem` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -False positives should be limited, however it is possible to filter by Processes.process_name and specific processes (ex. wscript.exe). Filter as needed. This may need modification based on EDR telemetry and how it brings in registry data. For example, removal of (Default). - -#### Associated Analytic story -* [Remcos](/stories/remcos) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | An instance of $process_name$ was identified on endpoint $dest$ downloading the DynamicWrapperX dll. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://blog.f-secure.com/hunting-for-koadic-a-com-based-rootkit/](https://blog.f-secure.com/hunting-for-koadic-a-com-based-rootkit/) -* [https://www.script-coding.com/dynwrapx_eng.html](https://www.script-coding.com/dynwrapx_eng.html) -* [https://bohops.com/2018/06/28/abusing-com-registry-structure-clsid-localserver32-inprocserver32/](https://bohops.com/2018/06/28/abusing-com-registry-structure-clsid-localserver32-inprocserver32/) -* [https://tria.ge/210929-ap75vsddan](https://tria.ge/210929-ap75vsddan) -* [https://www.virustotal.com/gui/file/cb77b93150cb0f7fe65ce8a7e2a5781e727419451355a7736db84109fa215a89](https://www.virustotal.com/gui/file/cb77b93150cb0f7fe65ce8a7e2a5781e727419451355a7736db84109fa215a89) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/process_writing_dynamicwrapperx.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-10-05-rundll32_shimcache_flush.md b/docs/_posts/2021-10-05-rundll32_shimcache_flush.md deleted file mode 100644 index f51ec23ad7..0000000000 --- a/docs/_posts/2021-10-05-rundll32_shimcache_flush.md +++ /dev/null @@ -1,165 +0,0 @@ ---- -title: "Rundll32 Shimcache Flush" -excerpt: "Modify Registry -" -categories: - - Endpoint -last_modified_at: 2021-10-05 -toc: true -toc_label: "" -tags: - - Modify Registry - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to detect a suspicious rundll32 commandline to clear shim cache. This technique is a anti-forensic technique to clear the cache taht are one important artifacts in terms of digital forensic during attacks or incident. This TTP is a good indicator that someone tries to evade some tools and clear foothold on the machine. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-10-05 -- **Author**: Teoderick Contreras, Splunk -- **ID**: a913718a-25b6-11ec-96d3-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1112](https://attack.mitre.org/techniques/T1112/) | Modify Registry | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_rundll32` AND Processes.process = "*apphelp.dll,ShimFlushCache*" by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.original_file_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `rundll32_shimcache_flush_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [process_rundll32](https://github.com/splunk/security_content/blob/develop/macros/process_rundll32.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **rundll32_shimcache_flush_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Unusual Processes](/stories/unusual_processes) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | rundll32 process execute $process$ to clear shim cache in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://blueteamops.medium.com/shimcache-flush-89daff28d15e](https://blueteamops.medium.com/shimcache-flush-89daff28d15e) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1112/shimcache_flush/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1112/shimcache_flush/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/rundll32_shimcache_flush.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-10-05-suspicious_copy_on_system32.md b/docs/_posts/2021-10-05-suspicious_copy_on_system32.md deleted file mode 100644 index e139502ae5..0000000000 --- a/docs/_posts/2021-10-05-suspicious_copy_on_system32.md +++ /dev/null @@ -1,169 +0,0 @@ ---- -title: "Suspicious Copy on System32" -excerpt: "Rename System Utilities -, Masquerading -" -categories: - - Endpoint -last_modified_at: 2021-10-05 -toc: true -toc_label: "" -tags: - - Rename System Utilities - - Masquerading - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to detect a suspicious copy of file from systemroot folder of the windows OS. This technique is commonly used by APT or other malware as part of execution (LOLBIN) to run its malicious code using the available legitimate tool in OS. this type of event may seen or may execute of normal user in some instance but this is really a anomaly that needs to be check within the network. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-10-05 -- **Author**: Teoderick Contreras, Splunk -- **ID**: ce633e56-25b2-11ec-9e76-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1036.003](https://attack.mitre.org/techniques/T1036/003/) | Rename System Utilities | Defense Evasion | - -| [T1036](https://attack.mitre.org/techniques/T1036/) | Masquerading | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name IN("cmd.exe", "powershell*","pwsh.exe", "sqlps.exe", "sqltoolsps.exe", "powershell_ise.exe") AND `process_copy` AND Processes.process IN("*\\Windows\\System32\*", "*\\Windows\\SysWow64\\*") AND Processes.process = "*copy*" by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `suspicious_copy_on_system32_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_copy](https://github.com/splunk/security_content/blob/develop/macros/process_copy.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **suspicious_copy_on_system32_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -every user may do this event but very un-ussual. - -#### Associated Analytic story -* [Unusual Processes](/stories/unusual_processes) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 63.0 | 70 | 90 | execution of copy exe to copy file from $process$ in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.hybrid-analysis.com/sample/8da5b75b6380a41eee3a399c43dfe0d99eeefaa1fd21027a07b1ecaa4cd96fdd?environmentId=120](https://www.hybrid-analysis.com/sample/8da5b75b6380a41eee3a399c43dfe0d99eeefaa1fd21027a07b1ecaa4cd96fdd?environmentId=120) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036.003/copy_sysmon/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036.003/copy_sysmon/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/suspicious_copy_on_system32.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-10-05-winhlp32_spawning_a_process.md b/docs/_posts/2021-10-05-winhlp32_spawning_a_process.md deleted file mode 100644 index 0fbefce559..0000000000 --- a/docs/_posts/2021-10-05-winhlp32_spawning_a_process.md +++ /dev/null @@ -1,166 +0,0 @@ ---- -title: "Winhlp32 Spawning a Process" -excerpt: "Process Injection -" -categories: - - Endpoint -last_modified_at: 2021-10-05 -toc: true -toc_label: "" -tags: - - Process Injection - - Defense Evasion - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies winhlp32.exe, found natively in `c:\windows\`, spawning a child process that loads a file out of appdata, programdata, or temp. Winhlp32.exe has a rocky past in that multiple vulnerabilities were found and added to MetaSploit. WinHlp32.exe is required to display 32-bit Help files that have the ".hlp" file name extension. This particular instance is related to a Remcos sample where dynwrapx.dll is added to the registry under inprocserver32, and later module loaded by winhlp32.exe to spawn wscript.exe and load a vbs or file from disk. During triage, review parallel processes to identify further suspicious behavior. Review module loads for unsuspecting unsigned modules. Capture any file modifications and analyze. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-10-05 -- **Author**: Michael Haag, Splunk -- **ID**: d17dae9e-2618-11ec-b9f5-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1055](https://attack.mitre.org/techniques/T1055/) | Process Injection | Defense Evasion, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=winhlp32.exe Processes.process IN ("*\\appdata\\*","*\\programdata\\*", "*\\temp\\*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `winhlp32_spawning_a_process_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **winhlp32_spawning_a_process_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -False positives should be limited as winhlp32.exe is typically not used with the latest flavors of Windows OS. However, filter as needed. - -#### Associated Analytic story -* [Remcos](/stories/remcos) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$, and is not typical activity for this process. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.exploit-db.com/exploits/16541](https://www.exploit-db.com/exploits/16541) -* [https://tria.ge/210929-ap75vsddan](https://tria.ge/210929-ap75vsddan) -* [https://www.virustotal.com/gui/file/cb77b93150cb0f7fe65ce8a7e2a5781e727419451355a7736db84109fa215a89](https://www.virustotal.com/gui/file/cb77b93150cb0f7fe65ce8a7e2a5781e727419451355a7736db84109fa215a89) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/winhlp32_spawning_a_process.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-10-06-dns_query_length_with_high_standard_deviation.md b/docs/_posts/2021-10-06-dns_query_length_with_high_standard_deviation.md deleted file mode 100644 index cc36c5840d..0000000000 --- a/docs/_posts/2021-10-06-dns_query_length_with_high_standard_deviation.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: "DNS Query Length With High Standard Deviation" -excerpt: "Exfiltration Over Unencrypted Non-C2 Protocol -, Exfiltration Over Alternative Protocol -" -categories: - - Network -last_modified_at: 2021-10-06 -toc: true -toc_label: "" -tags: - - Exfiltration Over Unencrypted Non-C2 Protocol - - Exfiltration Over Alternative Protocol - - Exfiltration - - Exfiltration - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Network_Resolution ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search allows you to identify DNS requests and compute the standard deviation on the length of the names being resolved, then filter on two times the standard deviation to show you those queries that are unusually large for your environment. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Network_Resolution](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkResolution)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-10-06 -- **Author**: Bhavin Patel, Splunk -- **ID**: 1a67f15a-f4ff-4170-84e9-08cf6f75d6f5 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1048.003](https://attack.mitre.org/techniques/T1048/003/) | Exfiltration Over Unencrypted Non-C2 Protocol | Exfiltration | - -| [T1048](https://attack.mitre.org/techniques/T1048/) | Exfiltration Over Alternative Protocol | Exfiltration | - -
-
- - -
- Kill Chain Phase - -
- -* Command & Control - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.AE -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 -* CIS 12 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count from datamodel=Network_Resolution where NOT DNS.message_type IN("Pointer","PTR") by DNS.query -| `drop_dm_object_name("DNS")` -| eval tlds=split(query,".") -| eval tld=mvindex(tlds,-1) -| eval tld_len=len(tld) -| search tld_len<=24 -| eval query_length = len(query) -| table query query_length record_type count -| eventstats stdev(query_length) AS stdev avg(query_length) AS avg p50(query_length) AS p50 -| where query_length>(avg+stdev*2) -| eval z_score=(query_length-avg)/stdev -| `dns_query_length_with_high_standard_deviation_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **dns_query_length_with_high_standard_deviation_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* DNS.query - - -#### How To Implement -To successfully implement this search, you will need to ensure that DNS data is populating the Network_Resolution data model. - -#### Known False Positives -It's possible there can be long domain names that are legitimate. - -#### Associated Analytic story -* [Hidden Cobra Malware](/stories/hidden_cobra_malware) -* [Suspicious DNS Traffic](/stories/suspicious_dns_traffic) -* [Command and Control](/stories/command_and_control) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 56.0 | 70 | 80 | A dns query $query$ with 2 time standard deviation of name len of the dns query in host $host$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1048.003/long_dns_queries/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1048.003/long_dns_queries/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/network/dns_query_length_with_high_standard_deviation.yml) \| *version*: **4** \ No newline at end of file diff --git a/docs/_posts/2021-10-06-sdelete_application_execution.md b/docs/_posts/2021-10-06-sdelete_application_execution.md deleted file mode 100644 index 0cd61d1772..0000000000 --- a/docs/_posts/2021-10-06-sdelete_application_execution.md +++ /dev/null @@ -1,174 +0,0 @@ ---- -title: "Sdelete Application Execution" -excerpt: "Data Destruction -, File Deletion -, Indicator Removal on Host -" -categories: - - Endpoint -last_modified_at: 2021-10-06 -toc: true -toc_label: "" -tags: - - Data Destruction - - File Deletion - - Indicator Removal on Host - - Impact - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to detect the execution of sdelete.exe application sysinternal tools. This tool is one of the most use tool of malware and adversaries to remove or clear their tracks and artifact in the targetted host. This tool is designed to delete securely a file in file system that remove the forensic evidence on the machine. A good TTP query to check why user execute this application which is not a common practice. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-10-06 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 31702fc0-2682-11ec-85c3-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1485](https://attack.mitre.org/techniques/T1485/) | Data Destruction | Impact | - -| [T1070.004](https://attack.mitre.org/techniques/T1070/004/) | File Deletion | Defense Evasion | - -| [T1070](https://attack.mitre.org/techniques/T1070/) | Indicator Removal on Host | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` values(Processes.process) as process values(Processes.parent_process) as parent_process values(Processes.process_id) as process_id count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_sdelete` by Processes.process_name Processes.original_file_name Processes.dest Processes.user Processes.parent_process_name Processes.parent_process -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `sdelete_application_execution_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_sdelete](https://github.com/splunk/security_content/blob/develop/macros/process_sdelete.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **sdelete_application_execution_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -user may execute and use this application - -#### Associated Analytic story -* [Masquerading - Rename System Utilities](/stories/masquerading_-_rename_system_utilities) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | sdelete process $process_name$ executed in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://app.any.run/tasks/956f50be-2c13-465a-ac00-6224c14c5f89/](https://app.any.run/tasks/956f50be-2c13-465a-ac00-6224c14c5f89/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/sdelete/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/sdelete/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/sdelete_application_execution.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-10-06-wscript_or_cscript_suspicious_child_process.md b/docs/_posts/2021-10-06-wscript_or_cscript_suspicious_child_process.md deleted file mode 100644 index 238d194fdd..0000000000 --- a/docs/_posts/2021-10-06-wscript_or_cscript_suspicious_child_process.md +++ /dev/null @@ -1,186 +0,0 @@ ---- -title: "Wscript Or Cscript Suspicious Child Process" -excerpt: "Process Injection -, Create or Modify System Process -, Parent PID Spoofing -, Access Token Manipulation -" -categories: - - Endpoint -last_modified_at: 2021-10-06 -toc: true -toc_label: "" -tags: - - Process Injection - - Create or Modify System Process - - Parent PID Spoofing - - Access Token Manipulation - - Defense Evasion - - Privilege Escalation - - Persistence - - Privilege Escalation - - Defense Evasion - - Privilege Escalation - - Defense Evasion - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic identifies a suspicious spawned process by WScript or CScript process. This technique was a common technique used by adversaries and malware to execute different LOLBIN, other scripts like PowerShell or spawn a suspended process to inject its code as a defense evasion. This TTP may detect some normal script that using several application tool that are in the list of the child process it detects but a good pivot and indicator that a script is may execute suspicious code. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-10-06 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 1f35e1da-267b-11ec-90a9-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1055](https://attack.mitre.org/techniques/T1055/) | Process Injection | Defense Evasion, Privilege Escalation | - -| [T1543](https://attack.mitre.org/techniques/T1543/) | Create or Modify System Process | Persistence, Privilege Escalation | - -| [T1134.004](https://attack.mitre.org/techniques/T1134/004/) | Parent PID Spoofing | Defense Evasion, Privilege Escalation | - -| [T1134](https://attack.mitre.org/techniques/T1134/) | Access Token Manipulation | Defense Evasion, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name IN ("cscript.exe", "wscript.exe") Processes.process_name IN ("regsvr32.exe", "rundll32.exe","winhlp32.exe","certutil.exe","msbuild.exe","cmd.exe","powershell*","wmic.exe","mshta.exe") by Processes.dest Processes.user Processes.parent_process_name Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `wscript_or_cscript_suspicious_child_process_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **wscript_or_cscript_suspicious_child_process_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -Administrators may create vbs or js script that use several tool as part of its execution. Filter as needed. - -#### Associated Analytic story -* [FIN7](/stories/fin7) -* [Remcos](/stories/remcos) -* [Unusual Processes](/stories/unusual_processes) -* [WhisperGate](/stories/whispergate) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | wscript or cscript parent process spawned $process_name$ in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.hybrid-analysis.com/sample/8da5b75b6380a41eee3a399c43dfe0d99eeefaa1fd21027a07b1ecaa4cd96fdd?environmentId=120](https://www.hybrid-analysis.com/sample/8da5b75b6380a41eee3a399c43dfe0d99eeefaa1fd21027a07b1ecaa4cd96fdd?environmentId=120) -* [https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/](https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.005/vbs_wscript/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.005/vbs_wscript/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-10-11-suspicious_wevtutil_usage.md b/docs/_posts/2021-10-11-suspicious_wevtutil_usage.md deleted file mode 100644 index 762e377e0f..0000000000 --- a/docs/_posts/2021-10-11-suspicious_wevtutil_usage.md +++ /dev/null @@ -1,175 +0,0 @@ ---- -title: "Suspicious wevtutil Usage" -excerpt: "Clear Windows Event Logs -, Indicator Removal on Host -" -categories: - - Endpoint -last_modified_at: 2021-10-11 -toc: true -toc_label: "" -tags: - - Clear Windows Event Logs - - Indicator Removal on Host - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The wevtutil.exe application is the windows event log utility. This searches for wevtutil.exe with parameters for clearing the application, security, setup, trace or system event logs. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-10-11 -- **Author**: David Dorsey, Michael Haag, Splunk -- **ID**: 2827c0fd-e1be-4868-ae25-59d28e0f9d4f - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1070.001](https://attack.mitre.org/techniques/T1070/001/) | Clear Windows Event Logs | Defense Evasion | - -| [T1070](https://attack.mitre.org/techniques/T1070/) | Indicator Removal on Host | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.DP -* PR.IP -* PR.PT -* PR.AC -* PR.AT -* DE.AE - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 6 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=wevtutil.exe Processes.process IN ("* cl *", "*clear-log*") (Processes.process="*System*" OR Processes.process="*Security*" OR Processes.process="*Setup*" OR Processes.process="*Application*" OR Processes.process="*trace*") by Processes.process_name Processes.parent_process_name Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -| `suspicious_wevtutil_usage_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **suspicious_wevtutil_usage_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process -* Processes.process_name -* Processes.parent_process_name -* Processes.dest -* Processes.user - - -#### How To Implement -You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. - -#### Known False Positives -The wevtutil.exe application is a legitimate Windows event log utility. Administrators may use it to manage Windows event logs. - -#### Associated Analytic story -* [Windows Log Manipulation](/stories/windows_log_manipulation) -* [Ransomware](/stories/ransomware) -* [Clop Ransomware](/stories/clop_ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 28.0 | 40 | 70 | Wevtutil.exe being used to clear Event Logs on $dest$ by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1070.001/T1070.001.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1070.001/T1070.001.md) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070.001/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070.001/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/suspicious_wevtutil_usage.yml) \| *version*: **4** \ No newline at end of file diff --git a/docs/_posts/2021-10-13-dllhost_with_no_command_line_arguments_with_network.md b/docs/_posts/2021-10-13-dllhost_with_no_command_line_arguments_with_network.md deleted file mode 100644 index 3d680dce61..0000000000 --- a/docs/_posts/2021-10-13-dllhost_with_no_command_line_arguments_with_network.md +++ /dev/null @@ -1,116 +0,0 @@ ---- -title: "DLLHost with no Command Line Arguments with Network" -excerpt: "Process Injection -" -categories: - - Endpoint -last_modified_at: 2021-10-13 -toc: true -toc_label: "" -tags: - - Process Injection - - Defense Evasion - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies DLLHost.exe with no command line arguments with a network connection. It is unusual for DLLHost.exe to execute with no command line arguments present. This particular behavior is common with malicious software, including Cobalt Strike. During investigation, triage any network connections and parallel processes. Identify any suspicious module loads related to credential dumping or file writes. DLLHost.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/object-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-10-13 -- **Author**: Michael Haag, Splunk -- **ID**: f1c07594-a141-11eb-8407-acde48001122 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1055](https://attack.mitre.org/techniques/T1055/) | Process Injection | Defense Evasion, Privilege Escalation | - -#### Search - -``` - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name=dllhost.exe by _time span=1h Processes.process_guid Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| regex process="(dllhost\.exe.{0,4}$)" -| join process_guid [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Ports where Ports.dest_port !="0" by Ports.process_guid Ports.dest Ports.dest_port -| `drop_dm_object_name(Ports)` -| rename dest as connection_to_CNC] -| table _time dest parent_process_name process_name process_path process process_guid connection_to_CNC dest_port -| `dllhost_with_no_command_line_arguments_with_network_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -Note that `dllhost_with_no_command_line_arguments_with_network_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventID -* process_name -* process_id -* parent_process_name -* dest_port -* process_path - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` and `port` node. - -#### Known False Positives -Although unlikely, some legitimate third party applications may use a moved copy of dllhost, triggering a false positive. - -#### Associated Analytic story -* [Cobalt Strike](/stories/cobalt_strike) - - -#### Kill Chain Phase -* Exploitation - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | The process $process_name$ was spawned by $parent_image$ without any command-line arguments on $dest$ by $user$. | - - - - -#### Reference - -* [https://raw.githubusercontent.com/threatexpress/malleable-c2/c3385e481159a759f79b8acfe11acf240893b830/jquery-c2.4.2.profile](https://raw.githubusercontent.com/threatexpress/malleable-c2/c3385e481159a759f79b8acfe11acf240893b830/jquery-c2.4.2.profile) -* [https://blog.cobaltstrike.com/2021/02/09/learn-pipe-fitting-for-all-of-your-offense-projects/](https://blog.cobaltstrike.com/2021/02/09/learn-pipe-fitting-for-all-of-your-offense-projects/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon_dllhost.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon_dllhost.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-10-13-rundll32_with_no_command_line_arguments_with_network.md b/docs/_posts/2021-10-13-rundll32_with_no_command_line_arguments_with_network.md deleted file mode 100644 index 26471b9f0a..0000000000 --- a/docs/_posts/2021-10-13-rundll32_with_no_command_line_arguments_with_network.md +++ /dev/null @@ -1,137 +0,0 @@ ---- -title: "Rundll32 with no Command Line Arguments with Network" -excerpt: "Signed Binary Proxy Execution -, Rundll32 -" -categories: - - Endpoint -last_modified_at: 2021-10-13 -toc: true -toc_label: "" -tags: - - Signed Binary Proxy Execution - - Rundll32 - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2021-34527 - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies rundll32.exe with no command line arguments and performing a network connection. It is unusual for rundll32.exe to execute with no command line arguments present. This particular behavior is common with malicious software, including Cobalt Strike. During investigation, triage any network connections and parallel processes. Identify any suspicious module loads related to credential dumping or file writes. Rundll32.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/object-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-10-13 -- **Author**: Michael Haag, Splunk -- **ID**: 35307032-a12d-11eb-835f-acde48001122 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | - -| [T1218.011](https://attack.mitre.org/techniques/T1218/011/) | Rundll32 | Defense Evasion | - -#### Search - -``` - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where `process_rundll32` by _time span=1h Processes.process_guid Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name Processes.original_file_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| regex process="(rundll32\.exe.{0,4}$)" -| join process_guid [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Ports where Ports.dest_port !="0" by Ports.process_guid Ports.dest Ports.dest_port -| `drop_dm_object_name(Ports)` -| rename dest as connection_to_CNC] -| table _time dest parent_process_name process_name process_path process process_guid connection_to_CNC dest_port -| `rundll32_with_no_command_line_arguments_with_network_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [process_rundll32](https://github.com/splunk/security_content/blob/develop/macros/process_rundll32.yml) - -Note that `rundll32_with_no_command_line_arguments_with_network_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` and `port` node. To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Although unlikely, some legitimate applications may use a moved copy of rundll32, triggering a false positive. - -#### Associated Analytic story -* [Suspicious Rundll32 Activity](/stories/suspicious_rundll32_activity) -* [Cobalt Strike](/stories/cobalt_strike) -* [PrintNightmare CVE-2021-34527](/stories/printnightmare_cve-2021-34527) - - -#### Kill Chain Phase -* Exploitation - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 70.0 | 70 | 100 | A rundll32 process $process_name$ with no commandline argument like this process commandline $process$ in host $dest$ | - - -#### CVE - -| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2021-34527](https://nvd.nist.gov/vuln/detail/CVE-2021-34527) | Windows Print Spooler Remote Code Execution Vulnerability | 9.0 | - - - -#### Reference - -* [https://attack.mitre.org/techniques/T1218/011/](https://attack.mitre.org/techniques/T1218/011/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.011/T1218.011.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.011/T1218.011.md) -* [https://lolbas-project.github.io/lolbas/Binaries/Rundll32](https://lolbas-project.github.io/lolbas/Binaries/Rundll32) -* [https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/](https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2021-10-13-searchprotocolhost_with_no_command_line_with_network.md b/docs/_posts/2021-10-13-searchprotocolhost_with_no_command_line_with_network.md deleted file mode 100644 index d458de8592..0000000000 --- a/docs/_posts/2021-10-13-searchprotocolhost_with_no_command_line_with_network.md +++ /dev/null @@ -1,114 +0,0 @@ ---- -title: "SearchProtocolHost with no Command Line with Network" -excerpt: "Process Injection -" -categories: - - Endpoint -last_modified_at: 2021-10-13 -toc: true -toc_label: "" -tags: - - Process Injection - - Defense Evasion - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies searchprotocolhost.exe with no command line arguments and with a network connection. It is unusual for searchprotocolhost.exe to execute with no command line arguments present. This particular behavior is common with malicious software, including Cobalt Strike. During investigation, identify any network connections and parallel processes. Identify any suspicious module loads related to credential dumping or file writes. searchprotocolhost.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/object-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-10-13 -- **Author**: Michael Haag, Splunk -- **ID**: b690df8c-a145-11eb-a38b-acde48001122 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1055](https://attack.mitre.org/techniques/T1055/) | Process Injection | Defense Evasion, Privilege Escalation | - -#### Search - -``` - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name=searchprotocolhost.exe by _time span=1h Processes.process_guid Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| regex process="(searchprotocolhost\.exe.{0,4}$)" -| join process_guid [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Ports where Ports.dest_port !="0" by Ports.process_guid Ports.dest Ports.dest_port -| `drop_dm_object_name(Ports)` -| rename dest as connection_to_CNC] -| table _time dest parent_process_name process_name process_path process process_guid connection_to_CNC dest_port -| `searchprotocolhost_with_no_command_line_with_network_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -Note that `searchprotocolhost_with_no_command_line_with_network_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* process_name -* process_id -* parent_process_name -* dest_port -* process_path - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` and `ports` node. - -#### Known False Positives -Limited false positives may be present in small environments. Tuning may be required based on parent process. - -#### Associated Analytic story -* [Cobalt Strike](/stories/cobalt_strike) - - -#### Kill Chain Phase -* Exploitation - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 70.0 | 70 | 100 | A searchprotocolhost.exe process $process_name$ with no commandline in host $dest$ | - - - - -#### Reference - -* [https://github.com/fireeye/red_team_tool_countermeasures/blob/master/rules/PGF/supplemental/hxioc/SUSPICIOUS%20EXECUTION%20OF%20SEARCHPROTOCOLHOST%20(METHODOLOGY).ioc](https://github.com/fireeye/red_team_tool_countermeasures/blob/master/rules/PGF/supplemental/hxioc/SUSPICIOUS%20EXECUTION%20OF%20SEARCHPROTOCOLHOST%20(METHODOLOGY).ioc) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon_searchprotocolhost.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon_searchprotocolhost.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-10-14-serviceprincipalnames_discovery_with_powershell.md b/docs/_posts/2021-10-14-serviceprincipalnames_discovery_with_powershell.md deleted file mode 100644 index 7943fe80d2..0000000000 --- a/docs/_posts/2021-10-14-serviceprincipalnames_discovery_with_powershell.md +++ /dev/null @@ -1,179 +0,0 @@ ---- -title: "ServicePrincipalNames Discovery with PowerShell" -excerpt: "Kerberoasting -" -categories: - - Endpoint -last_modified_at: 2021-10-14 -toc: true -toc_label: "" -tags: - - Kerberoasting - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies `powershell.exe` usage, using Script Block Logging EventCode 4104, related to querying the domain for Service Principle Names. typically, this is a precursor activity related to kerberoasting or the silver ticket attack. \ -What is a ServicePrincipleName? \ -A service principal name (SPN) is a unique identifier of a service instance. SPNs are used by Kerberos authentication to associate a service instance with a service logon account. This allows a client application to request that the service authenticate an account even if the client does not have the account name.\ -The following analytic identifies the use of KerberosRequestorSecurityToken class within the script block. Using .NET System.IdentityModel.Tokens.KerberosRequestorSecurityToken class in PowerShell is the equivelant of using setspn.exe. \ -During triage, review parallel processes for further suspicious activity. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-10-14 -- **Author**: Michael Haag, Splunk -- **ID**: 13243068-2d38-11ec-8908-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1558.003](https://attack.mitre.org/techniques/T1558/003/) | Kerberoasting | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 Message="*KerberosRequestorSecurityToken*" -| stats count min(_time) as firstTime max(_time) as lastTime by Message OpCode ComputerName User EventCode -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `serviceprincipalnames_discovery_with_powershell_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **serviceprincipalnames_discovery_with_powershell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -False positives should be limited, however filter as needed. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) -* [Active Directory Kerberos Attacks](/stories/active_directory_kerberos_attacks) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to identify service principle names. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://docs.microsoft.com/en-us/windows/win32/ad/service-principal-names](https://docs.microsoft.com/en-us/windows/win32/ad/service-principal-names) -* [https://docs.microsoft.com/en-us/dotnet/api/system.identitymodel.tokens.kerberosrequestorsecuritytoken?view=netframework-4.8](https://docs.microsoft.com/en-us/dotnet/api/system.identitymodel.tokens.kerberosrequestorsecuritytoken?view=netframework-4.8) -* [https://www.ired.team/offensive-security-experiments/active-directory-kerberos-abuse/t1208-kerberoasting](https://www.ired.team/offensive-security-experiments/active-directory-kerberos-abuse/t1208-kerberoasting) -* [https://strontic.github.io/xcyclopedia/library/setspn.exe-5C184D581524245DAD7A0A02B51FD2C2.html](https://strontic.github.io/xcyclopedia/library/setspn.exe-5C184D581524245DAD7A0A02B51FD2C2.html) -* [https://attack.mitre.org/techniques/T1558/003/](https://attack.mitre.org/techniques/T1558/003/) -* [https://social.technet.microsoft.com/wiki/contents/articles/717.service-principal-names-spn-setspn-syntax.aspx](https://social.technet.microsoft.com/wiki/contents/articles/717.service-principal-names-spn-setspn-syntax.aspx) -* [https://web.archive.org/web/20220212163642/https://www.harmj0y.net/blog/powershell/kerberoasting-without-mimikatz/](https://web.archive.org/web/20220212163642/https://www.harmj0y.net/blog/powershell/kerberoasting-without-mimikatz/) -* [https://blog.zsec.uk/paving-2-da-wholeset/](https://blog.zsec.uk/paving-2-da-wholeset/) -* [https://msitpros.com/?p=3113](https://msitpros.com/?p=3113) -* [https://adsecurity.org/?p=3466](https://adsecurity.org/?p=3466) -* [https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.](https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.) -* [https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63](https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63) -* [https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf](https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf) -* [https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/](https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1558.003/atomic_red_team/windows-powershell_kerberos.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1558.003/atomic_red_team/windows-powershell_kerberos.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/serviceprincipalnames_discovery_with_powershell.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-10-14-serviceprincipalnames_discovery_with_setspn.md b/docs/_posts/2021-10-14-serviceprincipalnames_discovery_with_setspn.md deleted file mode 100644 index 3ead2144b5..0000000000 --- a/docs/_posts/2021-10-14-serviceprincipalnames_discovery_with_setspn.md +++ /dev/null @@ -1,180 +0,0 @@ ---- -title: "ServicePrincipalNames Discovery with SetSPN" -excerpt: "Kerberoasting -" -categories: - - Endpoint -last_modified_at: 2021-10-14 -toc: true -toc_label: "" -tags: - - Kerberoasting - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies `setspn.exe` usage related to querying the domain for Service Principle Names. typically, this is a precursor activity related to kerberoasting or the silver ticket attack. \ -What is a ServicePrincipleName? \ -A service principal name (SPN) is a unique identifier of a service instance. SPNs are used by Kerberos authentication to associate a service instance with a service logon account. This allows a client application to request that the service authenticate an account even if the client does not have the account name.\ -Example usage includes the following \ -1. setspn -T offense -Q */* 1. setspn -T attackrange.local -F -Q MSSQLSvc/* 1. setspn -Q */* > allspns.txt 1. setspn -q \ -Values \ -1. -F = perform queries at the forest, rather than domain level 1. -T = perform query on the specified domain or forest (when -F is also used) 1. -Q = query for existence of SPN \ -During triage, review parallel processes for further suspicious activity. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-10-14 -- **Author**: Michael Haag, Splunk -- **ID**: ae8b3efc-2d2e-11ec-8b57-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1558.003](https://attack.mitre.org/techniques/T1558/003/) | Kerberoasting | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_setspn` (Processes.process="*-t*" AND Processes.process="*-f*") OR (Processes.process="*-q*" AND Processes.process="**/**") OR (Processes.process="*-q*") OR (Processes.process="*-s*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `serviceprincipalnames_discovery_with_setspn_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_setspn](https://github.com/splunk/security_content/blob/develop/macros/process_setspn.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **serviceprincipalnames_discovery_with_setspn_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -False positives may be caused by Administrators resetting SPNs or querying for SPNs. Filter as needed. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) -* [Active Directory Kerberos Attacks](/stories/active_directory_kerberos_attacks) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to identify service principle names. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://docs.microsoft.com/en-us/windows/win32/ad/service-principal-names](https://docs.microsoft.com/en-us/windows/win32/ad/service-principal-names) -* [https://www.ired.team/offensive-security-experiments/active-directory-kerberos-abuse/t1208-kerberoasting](https://www.ired.team/offensive-security-experiments/active-directory-kerberos-abuse/t1208-kerberoasting) -* [https://strontic.github.io/xcyclopedia/library/setspn.exe-5C184D581524245DAD7A0A02B51FD2C2.html](https://strontic.github.io/xcyclopedia/library/setspn.exe-5C184D581524245DAD7A0A02B51FD2C2.html) -* [https://attack.mitre.org/techniques/T1558/003/](https://attack.mitre.org/techniques/T1558/003/) -* [https://social.technet.microsoft.com/wiki/contents/articles/717.service-principal-names-spn-setspn-syntax.aspx](https://social.technet.microsoft.com/wiki/contents/articles/717.service-principal-names-spn-setspn-syntax.aspx) -* [https://web.archive.org/web/20220212163642/https://www.harmj0y.net/blog/powershell/kerberoasting-without-mimikatz/](https://web.archive.org/web/20220212163642/https://www.harmj0y.net/blog/powershell/kerberoasting-without-mimikatz/) -* [https://blog.zsec.uk/paving-2-da-wholeset/](https://blog.zsec.uk/paving-2-da-wholeset/) -* [https://msitpros.com/?p=3113](https://msitpros.com/?p=3113) -* [https://adsecurity.org/?p=3466](https://adsecurity.org/?p=3466) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1558.003/atomic_red_team/windows-sysmon_setspn.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1558.003/atomic_red_team/windows-sysmon_setspn.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/serviceprincipalnames_discovery_with_setspn.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-10-18-disable_schedule_task.md b/docs/_posts/2021-10-18-disable_schedule_task.md deleted file mode 100644 index 1b4cfa60ad..0000000000 --- a/docs/_posts/2021-10-18-disable_schedule_task.md +++ /dev/null @@ -1,162 +0,0 @@ ---- -title: "Disable Schedule Task" -excerpt: "Disable or Modify Tools -, Impair Defenses -" -categories: - - Endpoint -last_modified_at: 2021-10-18 -toc: true -toc_label: "" -tags: - - Disable or Modify Tools - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to detect a suspicious commandline to disable existing schedule task. This technique is used by adversaries or commodity malware like IceID to disable security application (AV products) in the targetted host to evade detections. This TTP is a good pivot to check further why and what other process run before and after this detection. check which process execute the commandline and what task is disabled. parent child process is quite valuable in this scenario too. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-10-18 -- **Author**: Teoderick Contreras, Splunk -- **ID**: db596056-3019-11ec-a9ff-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=schtasks.exe Processes.process=*/change* Processes.process=*/disable* by Processes.user Processes.process_name Processes.process Processes.parent_process_name Processes.parent_process Processes.dest -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `disable_schedule_task_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **disable_schedule_task_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.user -* Processes.process_name -* Processes.parent_process_name -* Processes.dest - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -admin may disable problematic schedule task - -#### Associated Analytic story -* [IcedID](/stories/icedid) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 56.0 | 70 | 80 | schtask process with commandline $process$ to disable schedule task in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/](https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/disable_schtask/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/disable_schtask/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disable_schedule_task.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-10-19-windows_curl_download_to_suspicious_path.md b/docs/_posts/2021-10-19-windows_curl_download_to_suspicious_path.md deleted file mode 100644 index 22720e91d1..0000000000 --- a/docs/_posts/2021-10-19-windows_curl_download_to_suspicious_path.md +++ /dev/null @@ -1,169 +0,0 @@ ---- -title: "Windows Curl Download to Suspicious Path" -excerpt: "Ingress Tool Transfer -" -categories: - - Endpoint -last_modified_at: 2021-10-19 -toc: true -toc_label: "" -tags: - - Ingress Tool Transfer - - Command And Control - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the use of Windows Curl.exe downloading a file to a suspicious location. \ --O or --output is used when a file is to be downloaded and placed in a specified location. \ -During triage, review parallel processes for further behavior. In addition, identify if the download was successful. If a file was downloaded, capture and analyze. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-10-19 -- **Author**: Michael Haag, Splunk -- **ID**: c32f091e-30db-11ec-8738-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1105](https://attack.mitre.org/techniques/T1105/) | Ingress Tool Transfer | Command And Control | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_curl` Processes.process IN ("*-O *","*--output*") Processes.process IN ("*\\appdata\\*","*\\programdata\\*","*\\public\\*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_curl_download_to_suspicious_path_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [process_curl](https://github.com/splunk/security_content/blob/develop/macros/process_curl.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_curl_download_to_suspicious_path_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -It is possible Administrators or super users will use Curl for legitimate purposes. Filter as needed. - -#### Associated Analytic story -* [IceID](/stories/iceid) -* [Ingress Tool Transfer](/stories/ingress_tool_transfer) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ to download a file to a suspicious directory. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/](https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/) -* [https://attack.mitre.org/techniques/T1105/](https://attack.mitre.org/techniques/T1105/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1105/T1105.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1105/T1105.md) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1105/atomic_red_team/windows-sysmon_curl.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1105/atomic_red_team/windows-sysmon_curl.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_curl_download_to_suspicious_path.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-10-19-winevent_windows_task_scheduler_event_action_started.md b/docs/_posts/2021-10-19-winevent_windows_task_scheduler_event_action_started.md deleted file mode 100644 index d893b1bbd3..0000000000 --- a/docs/_posts/2021-10-19-winevent_windows_task_scheduler_event_action_started.md +++ /dev/null @@ -1,162 +0,0 @@ ---- -title: "WinEvent Windows Task Scheduler Event Action Started" -excerpt: "Scheduled Task -" -categories: - - Endpoint -last_modified_at: 2021-10-19 -toc: true -toc_label: "" -tags: - - Scheduled Task - - Execution - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following hunting analytic assists with identifying suspicious tasks that have been registered and ran in Windows using EventID 200 (action run) and 201 (action completed). It is recommended to filter based on ActionName by specifying specific paths not used in your environment. After some basic tuning, this may be effective in capturing evasive ways to register tasks on Windows. Review parallel events related to tasks being scheduled. EventID 106 will generate when a new task is generated, however, that does not mean it ran. Capture any files on disk and analyze. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-10-19 -- **Author**: Michael Haag, Splunk -- **ID**: b3632472-310b-11ec-9aab-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1053.005](https://attack.mitre.org/techniques/T1053/005/) | Scheduled Task | Execution, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`wineventlog_task_scheduler` EventCode IN ("200","201") -| rename ComputerName as dest -| stats count min(_time) as firstTime max(_time) as lastTime by Message dest EventCode category -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `winevent_windows_task_scheduler_event_action_started_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [wineventlog_task_scheduler](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_task_scheduler.yml) - -> :information_source: -> **winevent_windows_task_scheduler_event_action_started_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* TaskName -* ActionName -* EventID -* dest -* ProcessID - - -#### How To Implement -Task Scheduler logs are required to be collected. Enable logging with inputs.conf by adding a stanza for [WinEventLog://Microsoft-Windows-TaskScheduler/Operational] and renderXml=false. Note, not translating it in XML may require a proper extraction of specific items in the Message. - -#### Known False Positives -False positives will be present. Filter based on ActionName paths or specify keywords of interest. - -#### Associated Analytic story -* [IcedID](/stories/icedid) -* [Windows Persistence Techniques](/stories/windows_persistence_techniques) -* [Industroyer2](/stories/industroyer2) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | A Scheduled Task was scheduled and ran on $dest$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1053.005/T1053.005.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1053.005/T1053.005.md) -* [https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/](https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/windows_taskschedule/windows-taskschedule.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/windows_taskschedule/windows-taskschedule.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/winevent_windows_task_scheduler_event_action_started.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-10-20-wmic_noninteractive_app_uninstallation.md b/docs/_posts/2021-10-20-wmic_noninteractive_app_uninstallation.md deleted file mode 100644 index 34f97c1258..0000000000 --- a/docs/_posts/2021-10-20-wmic_noninteractive_app_uninstallation.md +++ /dev/null @@ -1,168 +0,0 @@ ---- -title: "Wmic NonInteractive App Uninstallation" -excerpt: "Disable or Modify Tools -, Impair Defenses -" -categories: - - Endpoint -last_modified_at: 2021-10-20 -toc: true -toc_label: "" -tags: - - Disable or Modify Tools - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to detect a suspicious wmic commandlined that uninstall application non interactively. This technique was seen in IceID to uninstall av products to the compromised host to bypassed and evade detections. This Hunting query maybe a good indicator that some process tries to uninstall application using wmic which is not a common behavior. This approach may seen in some script or third part appication to uninstall their application but it is a good thing to check what it uninstall and why. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-10-20 -- **Author**: Teoderick Contreras, Splunk -- **ID**: bff0e7a0-317f-11ec-ab4e-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=wmic.exe Processes.process="* product *" Processes.process="*where name*" Processes.process="*call uninstall*" Processes.process="*/nointeractive*" by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.original_file_name Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `wmic_noninteractive_app_uninstallation_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **wmic_noninteractive_app_uninstallation_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -third party application may use this approach to uninstall there application - -#### Associated Analytic story -* [IceID](/stories/iceid) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | wmic $process$ with commandline $process$ in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/](https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/disable_av/sysmon2.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/disable_av/sysmon2.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-10-24-gdrive_suspicious_file_sharing.md b/docs/_posts/2021-10-24-gdrive_suspicious_file_sharing.md deleted file mode 100644 index 985dd92032..0000000000 --- a/docs/_posts/2021-10-24-gdrive_suspicious_file_sharing.md +++ /dev/null @@ -1,158 +0,0 @@ ---- -title: "Gdrive suspicious file sharing" -excerpt: "Phishing -" -categories: - - Cloud -last_modified_at: 2021-10-24 -toc: true -toc_label: "" -tags: - - Phishing - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search can help the detection of compromised accounts or internal users sharing potentially malicious/classified documents with users outside your organization via GSuite file sharing . - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-10-24 -- **Author**: Rod Soto, Teoderick Contreras -- **ID**: a7131dae-34e3-11ec-a2de-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`gsuite_drive` name=change_user_access -| rename parameters.* as * -| search email = "*@yourdomain.com" target_user != "*@yourdomain.com" -| stats count values(owner) as owner values(target_user) as target values(doc_type) as doc_type values(doc_title) as doc_title dc(target_user) as distinct_target by src_ip email -| where distinct_target > 50 -| `gdrive_suspicious_file_sharing_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [gsuite_drive](https://github.com/splunk/security_content/blob/develop/macros/gsuite_drive.yml) - -> :information_source: -> **gdrive_suspicious_file_sharing_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* src_ip -* parameters.owner -* parameters.target_user -* parameters.doc_title -* parameters.doc_type - - -#### How To Implement -Need to implement Gsuite logging targeting Google suite drive activity. In order for the search to work for your environment please update `yourdomain.com` value in the query with the domain relavant for your organization. - -#### Known False Positives -This is an anomaly search, you must specify your domain in the parameters so it either filters outside domains or focus on internal domains. This search may also help investigate compromise of accounts. By looking at for example source ip addresses, document titles and abnormal number of shares and shared target users. - -#### Associated Analytic story -* [Spearphishing Attachments](/stories/spearphishing_attachments) -* [Data Exfiltration](/stories/data_exfiltration) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.splunk.com/en_us/blog/security/investigating-gsuite-phishing-attacks-with-splunk.html](https://www.splunk.com/en_us/blog/security/investigating-gsuite-phishing-attacks-with-splunk.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [[]]([]) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/cloud/gdrive_suspicious_file_sharing.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-10-24-gsuite_suspicious_calendar_invite.md b/docs/_posts/2021-10-24-gsuite_suspicious_calendar_invite.md deleted file mode 100644 index 6993e039ef..0000000000 --- a/docs/_posts/2021-10-24-gsuite_suspicious_calendar_invite.md +++ /dev/null @@ -1,158 +0,0 @@ ---- -title: "Gsuite suspicious calendar invite" -excerpt: "Phishing -" -categories: - - Cloud -last_modified_at: 2021-10-24 -toc: true -toc_label: "" -tags: - - Phishing - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search can help the detection of compromised accounts or internal users sending suspcious calendar invites via GSuite calendar. These invites may contain malicious links or attachments. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-10-24 -- **Author**: Rod Soto, Teoderick Contreras -- **ID**: 03cdd68a-34fb-11ec-9bd3-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`gsuite_calendar` -|bin span=5m _time -|rename parameters.* as * -|search target_calendar_id!=null email="*yourdomain.com" -| stats count values(target_calendar_id) values(event_title) values(event_guest) by email _time -| where count >100 -| `gsuite_suspicious_calendar_invite_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [gsuite_calendar](https://github.com/splunk/security_content/blob/develop/macros/gsuite_calendar.yml) - -> :information_source: -> **gsuite_suspicious_calendar_invite_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* email -* parameters.event_title -* parameters.target_calendar_id -* parameters.event_title - - -#### How To Implement -In order to successfully implement this search, you need to be ingesting logs related to gsuite (gsuite:calendar:json) having the file sharing metadata like file type, source owner, destination target user, description, etc. This search can also be made more specific by selecting specific emails, subdomains timeframe, organizational units, targeted user, etc. In order for the search to work for your environment please update `yourdomain.com` value in the query with the domain relavant for your organization. - -#### Known False Positives -This search will also produce normal activity statistics. Fields such as email, ip address, name, parameters.organizer_calendar_id, parameters.target_calendar_id and parameters.event_title may give away phishing intent.For more specific results use email parameter. - -#### Associated Analytic story -* [Spearphishing Attachments](/stories/spearphishing_attachments) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.techrepublic.com/article/how-to-avoid-the-dreaded-google-calendar-malicious-invite-issue/](https://www.techrepublic.com/article/how-to-avoid-the-dreaded-google-calendar-malicious-invite-issue/) -* [https://gcn.com/cybersecurity/2012/09/the-20-most-common-words-in-phishing-attacks/280956/](https://gcn.com/cybersecurity/2012/09/the-20-most-common-words-in-phishing-attacks/280956/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [[]]([]) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/cloud/gsuite_suspicious_calendar_invite.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-11-03-windows_adfind_exe.md b/docs/_posts/2021-11-03-windows_adfind_exe.md deleted file mode 100644 index f998e017cf..0000000000 --- a/docs/_posts/2021-11-03-windows_adfind_exe.md +++ /dev/null @@ -1,166 +0,0 @@ ---- -title: "Windows AdFind Exe" -excerpt: "Remote System Discovery -" -categories: - - Endpoint -last_modified_at: 2021-11-03 -toc: true -toc_label: "" -tags: - - Remote System Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for the execution of `adfind.exe` with command-line arguments that it uses by default. Specifically the filter or search functions. It also considers the arguments necessary like objectcategory, see readme for more details: https://www.joeware.net/freetools/tools/adfind/usage.htm. This has been seen used before by Wizard Spider, FIN6 and actors whom also launched SUNBURST. AdFind.exe is usually used a recon tool to enumare a domain controller. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-11-03 -- **Author**: Jose Hernandez, Bhavin Patel, Splunk -- **ID**: bd3b0187-189b-46c0-be45-f52da2bae67f - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1018](https://attack.mitre.org/techniques/T1018/) | Remote System Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process="* -f *" OR Processes.process="* -b *") AND (Processes.process=*objectcategory* OR Processes.process="* -gcb *" OR Processes.process="* -sc *") by Processes.dest Processes.user Processes.process_name Processes.process Processes.parent_process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_adfind_exe_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_adfind_exe_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process -* Processes.dest -* Processes.user -* Processes.process_name -* Processes.parent_process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -administrators rarely use adfind, usually not used for legitimate reasons - -#### Associated Analytic story -* [NOBELIUM Group](/stories/nobelium_group) -* [Domain Trust Discovery](/stories/domain_trust_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | Windows AdFind Exe | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.volexity.com/blog/2020/12/14/dark-halo-leverages-solarwinds-compromise-to-breach-organizations/](https://www.volexity.com/blog/2020/12/14/dark-halo-leverages-solarwinds-compromise-to-breach-organizations/) -* [https://www.mandiant.com/resources/a-nasty-trick-from-credential-theft-malware-to-business-disruption](https://www.mandiant.com/resources/a-nasty-trick-from-credential-theft-malware-to-business-disruption) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_adfind_exe.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-11-04-attacker_tools_on_endpoint.md b/docs/_posts/2021-11-04-attacker_tools_on_endpoint.md deleted file mode 100644 index fd0857c133..0000000000 --- a/docs/_posts/2021-11-04-attacker_tools_on_endpoint.md +++ /dev/null @@ -1,184 +0,0 @@ ---- -title: "Attacker Tools On Endpoint" -excerpt: "Match Legitimate Name or Location -, Masquerading -, OS Credential Dumping -, Active Scanning -" -categories: - - Endpoint -last_modified_at: 2021-11-04 -toc: true -toc_label: "" -tags: - - Match Legitimate Name or Location - - Masquerading - - OS Credential Dumping - - Active Scanning - - Defense Evasion - - Defense Evasion - - Credential Access - - Reconnaissance - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for execution of commonly used attacker tools on an endpoint. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-11-04 -- **Author**: Bhavin Patel, Splunk -- **ID**: a51bfe1a-94f0-48cc-b4e4-16a110145893 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1036.005](https://attack.mitre.org/techniques/T1036/005/) | Match Legitimate Name or Location | Defense Evasion | - -| [T1036](https://attack.mitre.org/techniques/T1036/) | Masquerading | Defense Evasion | - -| [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - -| [T1595](https://attack.mitre.org/techniques/T1595/) | Active Scanning | Reconnaissance | - -
-
- - -
- Kill Chain Phase - -
- -* Installation -* Command & Control -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* ID.AM -* PR.DS - - - -
-
- -
- CIS20 - -
- -* CIS 2 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Processes.process) as process values(Processes.parent_process) as parent_process from datamodel=Endpoint.Processes where Processes.dest!=unknown Processes.user!=unknown by Processes.dest Processes.user Processes.process_name Processes.process -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `drop_dm_object_name(Processes)` -| lookup attacker_tools attacker_tool_names AS process_name OUTPUT description -| search description !=false -| `attacker_tools_on_endpoint_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **attacker_tools_on_endpoint_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Lookups -The SPL above uses the following Lookups: - -* [attacker_tools](https://github.com/splunk/security_content/blob/develop/lookups/attacker_tools.yml) with [data](https://github.com/splunk/security_content/tree/develop/lookups/attacker_tools.csv) - -#### Required field -* Processes.dest -* Processes.user -* Processes.process_name -* Processes.parent_process - - -#### How To Implement -To successfully implement this search, you must be ingesting data that records process activity from your hosts to populate the endpoint data model in the processes node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is usually generated via logs that report process tracking in your Windows audit settings. - -#### Known False Positives -Some administrator activity can be potentially triggered, please add those users to the filter macro. - -#### Associated Analytic story -* [Monitor for Unauthorized Software](/stories/monitor_for_unauthorized_software) -* [XMRig](/stories/xmrig) -* [SamSam Ransomware](/stories/samsam_ransomware) -* [Unusual Processes](/stories/unusual_processes) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 64.0 | 80 | 80 | An attacker tool $process_name$,listed in attacker_tools.csv is executed on host $dest$ by User $user$. This process $process_name$ is known to do- $description$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1595/attacker_scan_tools/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1595/attacker_scan_tools/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/attacker_tools_on_endpoint.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-11-05-potential_pass_the_token_or_hash_observed_by_an_event_collecting_device.md b/docs/_posts/2021-11-05-potential_pass_the_token_or_hash_observed_by_an_event_collecting_device.md deleted file mode 100644 index 4fdff5f2e4..0000000000 --- a/docs/_posts/2021-11-05-potential_pass_the_token_or_hash_observed_by_an_event_collecting_device.md +++ /dev/null @@ -1,119 +0,0 @@ ---- -title: "Potential Pass the Token or Hash Observed by an Event Collecting Device" -excerpt: "Use Alternate Authentication Material, Pass the Hash" -categories: - - Endpoint -last_modified_at: 2021-11-05 -toc: true -toc_label: "" -tags: - - Use Alternate Authentication Material - - Defense Evasion - - Lateral Movement - - Pass the Hash - - Defense Evasion - - Lateral Movement - - Splunk Behavioral Analytics - - Authentication ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This detection identifies potential Pass the Token or Pass the Hash credential stealing. We detect the main side effect of these attacks, which is a transition from the dominant Kerberos logins to rare NTLM logins for a given user, as reported by an event-collecting device (i.e., a specific domain controller or an endpoint destination). - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Authentication](https://docs.splunk.com/Documentation/CIM/latest/User/Authentication) -- **Last Updated**: 2021-11-05 -- **Author**: Stanislav Miskovic, Splunk -- **ID**: 1058ba3e-a698-49bc-a1e5-7cedece4ea87 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1550](https://attack.mitre.org/techniques/T1550/) | Use Alternate Authentication Material | Defense Evasion, Lateral Movement | - -| [T1550.002](https://attack.mitre.org/techniques/T1550/002/) | Pass the Hash | Defense Evasion, Lateral Movement | - -#### Search - -``` - -| from read_ssa_enriched_events() -| where "Authentication" IN(_datamodels) - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), dest_user= lower(ucast(map_get(input_event, "dest_user_primary_artifact"), "string", null)), dest_user_id= ucast(map_get(input_event, "dest_user_id"), "string", null), origin_device_id= ucast(map_get(input_event, "origin_device_id"), "string", null), signature_id= lower(ucast(map_get(input_event, "signature_id"), "string", null)), authentication_method= lower(ucast(map_get(input_event, "authentication_method"), "string", null)), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where signature_id = "4624" AND (authentication_method="ntlmssp" OR authentication_method="kerberos") AND dest_user_id != null AND origin_device_id != null - -| eval isKerberos=if(authentication_method == "kerberos", 1, 0), isNtlm=if(authentication_method == "ntlmssp", 1, 0), timeNTLM=if(isNtlm > 0, timestamp, null) - -| stats sum(isKerberos) as totalKerberos, sum(isNtlm) as totalNtlm, min(timestamp) as startTime, min(timeNTLM) as startNTLMTime, max(timestamp) as endTime, max(timeNTLM) as endNTLMTime by dest_user_id, dest_user, origin_device_id, span(timestamp, 86400s) - -| where NOT dest_user="-" AND totalKerberos > 0 AND totalNtlm > 0 AND endTime - startTime > 1800000 AND (totalKerberos > 10 * totalNtlm AND totalKerberos > 50) AND (endTime - startTime) > 3 * (endNTLMTime - startNTLMTime) - -| eval start_time=startNTLMTime, end_time=endNTLMTime, entities=mvappend(dest_user_id, origin_device_id), body=create_map(["event_id", event_id, "total_kerberos", totalKerberos, "total_ntlm", totalNtlm, "analysis_start_time", startTime, "analysis_end_time", endTime, "detection_start_time", startNTLMTime, "detection_end_time", endNTLMTime]) - -| into write_ssa_detected_events(); -``` - -#### Macros -The SPL above uses the following Macros: - -Note that `potential_pass_the_token_or_hash_observed_by_an_event_collecting_device_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* signature_id -* dest_user -* dest_user_id -* origin_device_id -* authentication_method - - -#### How To Implement -You must be ingesting Windows Security logs from devices of interest - at least from domain controllers. Please make sure that event ID 4624 is being logged. - -#### Known False Positives -Environments in which NTLM is used extremely rarely and for benign purposes (such as a rare use of SMB shares). - -#### Associated Analytic story -* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) - - -#### Kill Chain Phase -* Lateral Movement - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 64.0 | 80 | 80 | Potential lateral movement and credential stealing via Pass the Token or Pass the Hash techniques. Operation is performed via credentials of the account $dest_user_id$ and observed by the logging device $origin_device_id$ | - - -Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` - - - -#### Reference - -* [https://attack.mitre.org/techniques/T1550/002/](https://attack.mitre.org/techniques/T1550/002/) -* [https://www.offensive-security.com/metasploit-unleashed/psexec-pass-hash/](https://www.offensive-security.com/metasploit-unleashed/psexec-pass-hash/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/potential_pass_the_token_or_hash_observed_by_an_event_collecting_device.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-11-10-windows_curl_upload_to_remote_destination.md b/docs/_posts/2021-11-10-windows_curl_upload_to_remote_destination.md deleted file mode 100644 index fe5471fb42..0000000000 --- a/docs/_posts/2021-11-10-windows_curl_upload_to_remote_destination.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: "Windows Curl Upload to Remote Destination" -excerpt: "Ingress Tool Transfer -" -categories: - - Endpoint -last_modified_at: 2021-11-10 -toc: true -toc_label: "" -tags: - - Ingress Tool Transfer - - Command And Control - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the use of Windows Curl.exe uploading a file to a remote destination. \ -`-T` or `--upload-file` is used when a file is to be uploaded to a remotge destination. \ -`-d` or `--data` POST is the HTTP method that was invented to send data to a receiving web application, and it is, for example, how most common HTML forms on the web work. \ -HTTP multipart formposts are done with `-F`, but this appears to not be compatible with the Windows version of Curl. Will update if identified adversary tradecraft. \ -Adversaries may use one of the three methods based on the remote destination and what they are attempting to upload (zip vs txt). During triage, review parallel processes for further behavior. In addition, identify if the upload was successful in network logs. If a file was uploaded, isolate the endpoint and review. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-11-10 -- **Author**: Michael Haag, Splunk -- **ID**: 42f8f1a2-4228-11ec-aade-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1105](https://attack.mitre.org/techniques/T1105/) | Ingress Tool Transfer | Command And Control | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_curl` Processes.process IN ("*-T *","*--upload-file *", "*-d *", "*--data *", "*-F *") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_curl_upload_to_remote_destination_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [process_curl](https://github.com/splunk/security_content/blob/develop/macros/process_curl.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_curl_upload_to_remote_destination_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -False positives may be limited to source control applications and may be required to be filtered out. - -#### Associated Analytic story -* [Ingress Tool Transfer](/stories/ingress_tool_transfer) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ uploading a file to a remote destination. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://everything.curl.dev/usingcurl/uploads](https://everything.curl.dev/usingcurl/uploads) -* [https://techcommunity.microsoft.com/t5/containers/tar-and-curl-come-to-windows/ba-p/382409](https://techcommunity.microsoft.com/t5/containers/tar-and-curl-come-to-windows/ba-p/382409) -* [https://twitter.com/d1r4c/status/1279042657508081664?s=20](https://twitter.com/d1r4c/status/1279042657508081664?s=20) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1105/atomic_red_team/windows-sysmon_curl_upload.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1105/atomic_red_team/windows-sysmon_curl_upload.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_curl_upload_to_remote_destination.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-11-10-windows_service_creation_on_remote_endpoint.md b/docs/_posts/2021-11-10-windows_service_creation_on_remote_endpoint.md deleted file mode 100644 index be55e557b9..0000000000 --- a/docs/_posts/2021-11-10-windows_service_creation_on_remote_endpoint.md +++ /dev/null @@ -1,172 +0,0 @@ ---- -title: "Windows Service Creation on Remote Endpoint" -excerpt: "Create or Modify System Process -, Windows Service -" -categories: - - Endpoint -last_modified_at: 2021-11-10 -toc: true -toc_label: "" -tags: - - Create or Modify System Process - - Windows Service - - Persistence - - Privilege Escalation - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for the execution of `sc.exe` with command-line arguments utilized to create a Windows Service on a remote endpoint. Red Teams and adversaries alike may abuse the Service Control Manager for lateral movement and remote code execution. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-11-10 -- **Author**: Mauricio Velazco, Splunk -- **ID**: e0eea4fa-4274-11ec-882b-3e22fbd008af - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1543](https://attack.mitre.org/techniques/T1543/) | Create or Modify System Process | Persistence, Privilege Escalation | - -| [T1543.003](https://attack.mitre.org/techniques/T1543/003/) | Windows Service | Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name=sc.exe OR Processes.original_file_name=sc.exe) (Processes.process=*\\\\* AND Processes.process=*create* AND Processes.process=*binpath*) by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_service_creation_on_remote_endpoint_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_service_creation_on_remote_endpoint_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. - -#### Known False Positives -Administrators may create Windows Services on remote systems, but this activity is usually limited to a small set of hosts or users. - -#### Associated Analytic story -* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 54.0 | 90 | 60 | A Windows Service was created on a remote endpoint from $dest | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://docs.microsoft.com/en-us/windows/win32/services/service-control-manager](https://docs.microsoft.com/en-us/windows/win32/services/service-control-manager) -* [https://docs.microsoft.com/en-us/windows/win32/services/controlling-a-service-using-sc](https://docs.microsoft.com/en-us/windows/win32/services/controlling-a-service-using-sc) -* [https://attack.mitre.org/techniques/T1543/003/](https://attack.mitre.org/techniques/T1543/003/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1543.003/lateral_movement/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1543.003/lateral_movement/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_service_creation_on_remote_endpoint.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-11-10-windows_service_initiation_on_remote_endpoint.md b/docs/_posts/2021-11-10-windows_service_initiation_on_remote_endpoint.md deleted file mode 100644 index 30f8951fe7..0000000000 --- a/docs/_posts/2021-11-10-windows_service_initiation_on_remote_endpoint.md +++ /dev/null @@ -1,171 +0,0 @@ ---- -title: "Windows Service Initiation on Remote Endpoint" -excerpt: "Create or Modify System Process -, Windows Service -" -categories: - - Endpoint -last_modified_at: 2021-11-10 -toc: true -toc_label: "" -tags: - - Create or Modify System Process - - Windows Service - - Persistence - - Privilege Escalation - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for the execution of `sc.exe` with command-line arguments utilized to start a Windows Service on a remote endpoint. Red Teams and adversaries alike may abuse the Service Control Manager for lateral movement and remote code execution. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-11-10 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 3f519894-4276-11ec-ab02-3e22fbd008af - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1543](https://attack.mitre.org/techniques/T1543/) | Create or Modify System Process | Persistence, Privilege Escalation | - -| [T1543.003](https://attack.mitre.org/techniques/T1543/003/) | Windows Service | Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name=sc.exe OR Processes.original_file_name=sc.exe) (Processes.process=*\\\\* AND Processes.process=*start*) by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_service_initiation_on_remote_endpoint_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_service_initiation_on_remote_endpoint_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. - -#### Known False Positives -Administrators may start Windows Services on remote systems, but this activity is usually limited to a small set of hosts or users. - -#### Associated Analytic story -* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 54.0 | 90 | 60 | A Windows Service was started on a remote endpoint from $dest | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://docs.microsoft.com/en-us/windows/win32/services/controlling-a-service-using-sc](https://docs.microsoft.com/en-us/windows/win32/services/controlling-a-service-using-sc) -* [https://attack.mitre.org/techniques/T1543/003/](https://attack.mitre.org/techniques/T1543/003/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1543.003/lateral_movement/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1543.003/lateral_movement/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_service_initiation_on_remote_endpoint.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-11-11-remote_process_instantiation_via_winrm_and_winrs.md b/docs/_posts/2021-11-11-remote_process_instantiation_via_winrm_and_winrs.md deleted file mode 100644 index 4adbe759e9..0000000000 --- a/docs/_posts/2021-11-11-remote_process_instantiation_via_winrm_and_winrs.md +++ /dev/null @@ -1,169 +0,0 @@ ---- -title: "Remote Process Instantiation via WinRM and Winrs" -excerpt: "Remote Services -, Windows Remote Management -" -categories: - - Endpoint -last_modified_at: 2021-11-11 -toc: true -toc_label: "" -tags: - - Remote Services - - Windows Remote Management - - Lateral Movement - - Lateral Movement - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for the execution of `winrs.exe` with command-line arguments utilized to start a process on a remote endpoint. Red Teams and adversaries alike may abuse the WinRM protocol and this binary for lateral movement and remote code execution. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-11-11 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 0dd296a2-4338-11ec-ba02-3e22fbd008af - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1021](https://attack.mitre.org/techniques/T1021/) | Remote Services | Lateral Movement | - -| [T1021.006](https://attack.mitre.org/techniques/T1021/006/) | Windows Remote Management | Lateral Movement | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name=winrs.exe OR Processes.original_file_name=winrs.exe) (Processes.process="*-r:*" OR Processes.process="*-remote:*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `remote_process_instantiation_via_winrm_and_winrs_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **remote_process_instantiation_via_winrm_and_winrs_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. - -#### Known False Positives -Administrators may leverage WinRM and WinRs to start a process on remote systems, but this activity is usually limited to a small set of hosts or users. - -#### Associated Analytic story -* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 54.0 | 90 | 60 | A process was started on a remote endpoint from $dest | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/winrs](https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/winrs) -* [https://attack.mitre.org/techniques/T1021/006/](https://attack.mitre.org/techniques/T1021/006/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021.006/lateral_movement/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021.006/lateral_movement/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/remote_process_instantiation_via_winrm_and_winrs.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-11-11-scheduled_task_creation_on_remote_endpoint_using_at.md b/docs/_posts/2021-11-11-scheduled_task_creation_on_remote_endpoint_using_at.md deleted file mode 100644 index 9efa6c3b0c..0000000000 --- a/docs/_posts/2021-11-11-scheduled_task_creation_on_remote_endpoint_using_at.md +++ /dev/null @@ -1,174 +0,0 @@ ---- -title: "Scheduled Task Creation on Remote Endpoint using At" -excerpt: "Scheduled Task/Job -, At -" -categories: - - Endpoint -last_modified_at: 2021-11-11 -toc: true -toc_label: "" -tags: - - Scheduled Task/Job - - At - - Execution - - Persistence - - Privilege Escalation - - Execution - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for the execution of `at.exe` with command-line arguments utilized to create a Scheduled Task on a remote endpoint. Red Teams and adversaries alike may abuse the Task Scheduler for lateral movement and remote code execution. The `at.exe` binary internally leverages the AT protocol which was deprecated starting with Windows 8 and Windows Server 2012 but may still work on previous versions of Windows. Furthermore, attackers may enable this protocol on demand by changing a sytem registry key. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-11-11 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 4be54858-432f-11ec-8209-3e22fbd008af - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1053](https://attack.mitre.org/techniques/T1053/) | Scheduled Task/Job | Execution, Persistence, Privilege Escalation | - -| [T1053.002](https://attack.mitre.org/techniques/T1053/002/) | At | Execution, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name=at.exe OR Processes.original_file_name=at.exe) (Processes.process=*\\\\*) by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `scheduled_task_creation_on_remote_endpoint_using_at_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **scheduled_task_creation_on_remote_endpoint_using_at_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. - -#### Known False Positives -Administrators may create scheduled tasks on remote systems, but this activity is usually limited to a small set of hosts or users. - -#### Associated Analytic story -* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 54.0 | 90 | 60 | A Windows Scheduled Task was created on a remote endpoint from $dest | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/at](https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/at) -* [https://docs.microsoft.com/en-us/windows/win32/cimwin32prov/win32-scheduledjob?redirectedfrom=MSDN](https://docs.microsoft.com/en-us/windows/win32/cimwin32prov/win32-scheduledjob?redirectedfrom=MSDN) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.002/lateral_movement/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.002/lateral_movement/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/scheduled_task_creation_on_remote_endpoint_using_at.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-11-11-scheduled_task_initiation_on_remote_endpoint.md b/docs/_posts/2021-11-11-scheduled_task_initiation_on_remote_endpoint.md deleted file mode 100644 index 8f7eb63971..0000000000 --- a/docs/_posts/2021-11-11-scheduled_task_initiation_on_remote_endpoint.md +++ /dev/null @@ -1,174 +0,0 @@ ---- -title: "Scheduled Task Initiation on Remote Endpoint" -excerpt: "Scheduled Task/Job -, Scheduled Task -" -categories: - - Endpoint -last_modified_at: 2021-11-11 -toc: true -toc_label: "" -tags: - - Scheduled Task/Job - - Scheduled Task - - Execution - - Persistence - - Privilege Escalation - - Execution - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for the execution of `schtasks.exe` with command-line arguments utilized to start a Scheduled Task on a remote endpoint. Red Teams and adversaries alike may abuse the Task Scheduler for lateral movement and remote code execution. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-11-11 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 95cf4608-4302-11ec-8194-3e22fbd008af - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1053](https://attack.mitre.org/techniques/T1053/) | Scheduled Task/Job | Execution, Persistence, Privilege Escalation | - -| [T1053.005](https://attack.mitre.org/techniques/T1053/005/) | Scheduled Task | Execution, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name=schtasks.exe OR Processes.original_file_name=schtasks.exe) (Processes.process=*/s* AND Processes.process=*/run*) by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `scheduled_task_initiation_on_remote_endpoint_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **scheduled_task_initiation_on_remote_endpoint_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. - -#### Known False Positives -Administrators may start scheduled tasks on remote systems, but this activity is usually limited to a small set of hosts or users. - -#### Associated Analytic story -* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 54.0 | 90 | 60 | A Windows Scheduled Task was ran on a remote endpoint from $dest | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/schtasks](https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/schtasks) -* [https://attack.mitre.org/techniques/T1053/005/](https://attack.mitre.org/techniques/T1053/005/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/lateral_movement/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/lateral_movement/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/scheduled_task_initiation_on_remote_endpoint.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-11-11-schtasks_scheduling_job_on_remote_system.md b/docs/_posts/2021-11-11-schtasks_scheduling_job_on_remote_system.md deleted file mode 100644 index 1ec5ea7c58..0000000000 --- a/docs/_posts/2021-11-11-schtasks_scheduling_job_on_remote_system.md +++ /dev/null @@ -1,165 +0,0 @@ ---- -title: "Schtasks scheduling job on remote system" -excerpt: "Scheduled Task -, Scheduled Task/Job -" -categories: - - Endpoint -last_modified_at: 2021-11-11 -toc: true -toc_label: "" -tags: - - Scheduled Task - - Scheduled Task/Job - - Execution - - Persistence - - Privilege Escalation - - Execution - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for the execution of `schtasks.exe` with command-line arguments utilized to create a Scheduled Task on a remote endpoint. Red Teams and adversaries alike may abuse the Task Scheduler for lateral movement and remote code execution. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-11-11 -- **Author**: David Dorsey, Mauricio Velazco, Splunk -- **ID**: 1297fb80-f42a-4b4a-9c8a-88c066237cf6 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1053.005](https://attack.mitre.org/techniques/T1053/005/) | Scheduled Task | Execution, Persistence, Privilege Escalation | - -| [T1053](https://attack.mitre.org/techniques/T1053/) | Scheduled Task/Job | Execution, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.IP - - - -
-
- -
- CIS20 - -
- -* CIS 3 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name = schtasks.exe OR Processes.original_file_name=schtasks.exe) (Processes.process="*/create*" AND Processes.process="*/s*") by Processes.process_name Processes.process Processes.parent_process_name Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `schtasks_scheduling_job_on_remote_system_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -Note that **schtasks_scheduling_job_on_remote_system_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process_name -* Processes.process -* Processes.parent_process_name -* Processes.dest -* Processes.user - - -#### How To Implement -You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. - -#### Known False Positives -Administrators may create scheduled tasks on remote systems, but this activity is usually limited to a small set of hosts or users. It is important to validate and investigate as appropriate. - -#### Associated Analytic story -* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) -* [NOBELIUM Group](/stories/nobelium_group) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 63.0 | 70 | 90 | A schedule task process $process_name$ with remote job commandline $process$ in host $dest$ | - - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml) \| *version*: **5** \ No newline at end of file diff --git a/docs/_posts/2021-11-11-wmic_xsl_execution_via_url.md b/docs/_posts/2021-11-11-wmic_xsl_execution_via_url.md deleted file mode 100644 index 3e2d9784e0..0000000000 --- a/docs/_posts/2021-11-11-wmic_xsl_execution_via_url.md +++ /dev/null @@ -1,166 +0,0 @@ ---- -title: "WMIC XSL Execution via URL" -excerpt: "XSL Script Processing -" -categories: - - Endpoint -last_modified_at: 2021-11-11 -toc: true -toc_label: "" -tags: - - XSL Script Processing - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies `wmic.exe` loading a remote XSL (eXtensible Stylesheet Language) script. This originally was identified by Casey Smith, dubbed Squiblytwo, as an application control bypass. Many adversaries will utilize this technique to invoke JScript or VBScript within an XSL file. This technique can also execute local/remote scripts and, similar to its Regsvr32 "Squiblydoo" counterpart, leverages a trusted, built-in Windows tool. Adversaries may abuse any alias in Windows Management Instrumentation provided they utilize the /FORMAT switch. Upon identifying a suspicious execution, review for confirmed network connnection and script download. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-11-11 -- **Author**: Michael Haag, Splunk -- **ID**: 787e9dd0-4328-11ec-a029-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1220](https://attack.mitre.org/techniques/T1220/) | XSL Script Processing | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_wmic` Processes.process IN ("*http://*", "*https://*") Processes.process="*/format:*" by Processes.parent_process_name Processes.original_file_name Processes.parent_process Processes.process_name Processes.process_id Processes.process Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `wmic_xsl_execution_via_url_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [process_wmic](https://github.com/splunk/security_content/blob/develop/macros/process_wmic.yml) - -> :information_source: -> **wmic_xsl_execution_via_url_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -False positives are limited as legitimate applications typically do not download files or xsl using WMIC. Filter as needed. - -#### Associated Analytic story -* [Suspicious WMI Use](/stories/suspicious_wmi_use) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ utilizing wmic to download a remote XSL script. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1220/T1220.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1220/T1220.md) -* [https://web.archive.org/web/20190814201250/https://subt0x11.blogspot.com/2018/04/wmicexe-whitelisting-bypass-hacking.html](https://web.archive.org/web/20190814201250/https://subt0x11.blogspot.com/2018/04/wmicexe-whitelisting-bypass-hacking.html) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1220/T1220.md#atomic-test-4---wmic-bypass-using-remote-xsl-file](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1220/T1220.md#atomic-test-4---wmic-bypass-using-remote-xsl-file) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1220/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1220/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/wmic_xsl_execution_via_url.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-11-12-aws_iam_accessdenied_discovery_events.md b/docs/_posts/2021-11-12-aws_iam_accessdenied_discovery_events.md deleted file mode 100644 index 0d1451a1db..0000000000 --- a/docs/_posts/2021-11-12-aws_iam_accessdenied_discovery_events.md +++ /dev/null @@ -1,157 +0,0 @@ ---- -title: "AWS IAM AccessDenied Discovery Events" -excerpt: "Cloud Infrastructure Discovery -" -categories: - - Cloud -last_modified_at: 2021-11-12 -toc: true -toc_label: "" -tags: - - Cloud Infrastructure Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following detection identifies excessive AccessDenied events within an hour timeframe. It is possible that an access key to AWS may have been stolen and is being misused to perform discovery events. In these instances, the access is not available with the key stolen therefore these events will be generated. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-11-12 -- **Author**: Michael Haag, Splunk -- **ID**: 3e1f1568-9633-11eb-a69c-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1580](https://attack.mitre.org/techniques/T1580/) | Cloud Infrastructure Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cloudtrail` (errorCode = "AccessDenied") user_type=IAMUser (userAgent!=*.amazonaws.com) -| bucket _time span=1h -| stats count as failures min(_time) as firstTime max(_time) as lastTime, dc(eventName) as methods, dc(eventSource) as sources by src_ip, userIdentity.arn, _time -| where failures >= 5 and methods >= 1 and sources >= 1 -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `aws_iam_accessdenied_discovery_events_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) - -> :information_source: -> **aws_iam_accessdenied_discovery_events_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* eventName -* eventSource -* userAgent -* errorCode -* userIdentity.type - - -#### How To Implement -The Splunk AWS Add-on and Splunk App for AWS is required to utilize this data. The search requires AWS Cloudtrail logs. - -#### Known False Positives -It is possible to start this detection will need to be tuned by source IP or user. In addition, change the count values to an upper threshold to restrict false positives. - -#### Associated Analytic story -* [Suspicious Cloud User Activities](/stories/suspicious_cloud_user_activities) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 10.0 | 20 | 50 | User $userIdentity.arn$ is seen to perform excessive number of discovery related api calls- $failures$, within an hour where the access was denied. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://aws.amazon.com/premiumsupport/knowledge-center/troubleshoot-iam-permission-errors/](https://aws.amazon.com/premiumsupport/knowledge-center/troubleshoot-iam-permission-errors/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1580/aws_iam_accessdenied_discovery_events/aws_iam_accessdenied_discovery_events.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1580/aws_iam_accessdenied_discovery_events/aws_iam_accessdenied_discovery_events.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/aws_iam_accessdenied_discovery_events.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-11-12-csc_net_on_the_fly_compilation.md b/docs/_posts/2021-11-12-csc_net_on_the_fly_compilation.md deleted file mode 100644 index 52abb47d1e..0000000000 --- a/docs/_posts/2021-11-12-csc_net_on_the_fly_compilation.md +++ /dev/null @@ -1,167 +0,0 @@ ---- -title: "CSC Net On The Fly Compilation" -excerpt: "Compile After Delivery -, Obfuscated Files or Information -" -categories: - - Endpoint -last_modified_at: 2021-11-12 -toc: true -toc_label: "" -tags: - - Compile After Delivery - - Obfuscated Files or Information - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -this analytic is to detect a suspicious compile before delivery approach of .net compiler csc.exe. This technique was seen in several adversaries, malware and even in red teams to take advantage the csc.exe .net compiler tool to compile on the fly a malicious .net code to evade detection from security product. This is a good hunting query to check further the file or process created after this event and check the file path that passed to csc.exe which is the .net code. Aside from that, powershell is capable of using this compiler in executing .net code in a powershell script so filter on that case is needed. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-11-12 -- **Author**: Teoderick Contreras, Splunk -- **ID**: ea73128a-43ab-11ec-9753-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1027.004](https://attack.mitre.org/techniques/T1027/004/) | Compile After Delivery | Defense Evasion | - -| [T1027](https://attack.mitre.org/techniques/T1027/) | Obfuscated Files or Information | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_csc` Processes.process = "*/noconfig*" Processes.process = "*/fullpaths*" Processes.process = "*@*" by Processes.dest Processes.user Processes.parent_process_name Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `csc_net_on_the_fly_compilation_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_csc](https://github.com/splunk/security_content/blob/develop/macros/process_csc.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **csc_net_on_the_fly_compilation_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -A network operator or systems administrator may utilize an automated powershell script taht execute .net code that may generate false positive. filter is needed. - -#### Associated Analytic story -* [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | csc.exe with commandline $process$ to compile .net code on $dest$ by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://app.any.run/tasks/ad4c3cda-41f2-4401-8dba-56cc2d245488/](https://app.any.run/tasks/ad4c3cda-41f2-4401-8dba-56cc2d245488/) -* [https://tccontre.blogspot.com/2019/06/maicious-macro-that-compile-c-code-as.html](https://tccontre.blogspot.com/2019/06/maicious-macro-that-compile-c-code-as.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/vilsel/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/vilsel/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/csc_net_on_the_fly_compilation.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-11-12-firewall_allowed_program_enable.md b/docs/_posts/2021-11-12-firewall_allowed_program_enable.md deleted file mode 100644 index a40ceb6936..0000000000 --- a/docs/_posts/2021-11-12-firewall_allowed_program_enable.md +++ /dev/null @@ -1,166 +0,0 @@ ---- -title: "Firewall Allowed Program Enable" -excerpt: "Disable or Modify System Firewall -, Impair Defenses -" -categories: - - Endpoint -last_modified_at: 2021-11-12 -toc: true -toc_label: "" -tags: - - Disable or Modify System Firewall - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic detects a potential suspicious modification of firewall rule allowing to execute specific application. This technique was identified when an adversary and red teams to bypassed firewall file execution restriction in a targetted host. Take note that this event or command can run by administrator during testing or allowing legitimate tool or application. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-11-12 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 9a8f63a8-43ac-11ec-904c-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.004](https://attack.mitre.org/techniques/T1562/004/) | Disable or Modify System Firewall | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process = "*firewall*" Processes.process = "*allow*" Processes.process = "*add*" Processes.process = "*ENABLE*" by Processes.dest Processes.user Processes.parent_process_name Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `firewall_allowed_program_enable_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **firewall_allowed_program_enable_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -A network operator or systems administrator may utilize an automated or manual execution of this firewall rule that may generate false positives. Filter as needed. - -#### Associated Analytic story -* [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics) -* [Azorult](/stories/azorult) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | firewall allowed program commandline $process$ of $process_name$ on $dest$ by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://app.any.run/tasks/ad4c3cda-41f2-4401-8dba-56cc2d245488/](https://app.any.run/tasks/ad4c3cda-41f2-4401-8dba-56cc2d245488/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/vilsel/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/vilsel/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/firewall_allowed_program_enable.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-11-12-network_discovery_using_route_windows_app.md b/docs/_posts/2021-11-12-network_discovery_using_route_windows_app.md deleted file mode 100644 index 9d9050df1a..0000000000 --- a/docs/_posts/2021-11-12-network_discovery_using_route_windows_app.md +++ /dev/null @@ -1,166 +0,0 @@ ---- -title: "Network Discovery Using Route Windows App" -excerpt: "System Network Configuration Discovery -, Internet Connection Discovery -" -categories: - - Endpoint -last_modified_at: 2021-11-12 -toc: true -toc_label: "" -tags: - - System Network Configuration Discovery - - Internet Connection Discovery - - Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic look for a spawned process of route.exe windows application. Adversaries and red teams alike abuse this application the recon or do a network discovery on a target host. but one possible false positive might be an automated tool used by a system administator or a powershell script in amazon ec2 config services. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-11-12 -- **Author**: Teoderick Contreras, Splunk -- **ID**: dd83407e-439f-11ec-ab8e-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1016](https://attack.mitre.org/techniques/T1016/) | System Network Configuration Discovery | Discovery | - -| [T1016.001](https://attack.mitre.org/techniques/T1016/001/) | Internet Connection Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_route` by Processes.dest Processes.user Processes.parent_process_name Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `network_discovery_using_route_windows_app_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_route](https://github.com/splunk/security_content/blob/develop/macros/process_route.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **network_discovery_using_route_windows_app_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -A network operator or systems administrator may utilize an automated host discovery application that may generate false positives or an amazon ec2 script that uses this application. Filter as needed. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 9.0 | 30 | 30 | Network Connection discovery on $dest$ by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://app.any.run/tasks/ad4c3cda-41f2-4401-8dba-56cc2d245488/](https://app.any.run/tasks/ad4c3cda-41f2-4401-8dba-56cc2d245488/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/vilsel/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/vilsel/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/network_discovery_using_route_windows_app.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-11-12-remote_process_instantiation_via_wmi.md b/docs/_posts/2021-11-12-remote_process_instantiation_via_wmi.md deleted file mode 100644 index 59357aa8f6..0000000000 --- a/docs/_posts/2021-11-12-remote_process_instantiation_via_wmi.md +++ /dev/null @@ -1,175 +0,0 @@ ---- -title: "Remote Process Instantiation via WMI" -excerpt: "Windows Management Instrumentation -" -categories: - - Endpoint -last_modified_at: 2021-11-12 -toc: true -toc_label: "" -tags: - - Windows Management Instrumentation - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic identifies wmic.exe being launched with parameters to spawn a process on a remote system. Red Teams and adversaries alike may abuse WMI and this binary for lateral movement and remote code execution. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-11-12 -- **Author**: Rico Valdez, Mauricio Velazco, Splunk -- **ID**: d25d2c3d-d9d8-40ec-8fdf-e86fe155a3da - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1047](https://attack.mitre.org/techniques/T1047/) | Windows Management Instrumentation | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* PR.AT -* PR.AC -* PR.IP - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_wmic` (Processes.process="*/node:*" AND Processes.process="*process*" AND Processes.process="*call*" AND Processes.process="*create*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `remote_process_instantiation_via_wmi_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [process_wmic](https://github.com/splunk/security_content/blob/develop/macros/process_wmic.yml) - -> :information_source: -> **remote_process_instantiation_via_wmi_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -The wmic.exe utility is a benign Windows application. It may be used legitimately by Administrators with these parameters for remote system administration, but it's relatively uncommon. - -#### Associated Analytic story -* [Ransomware](/stories/ransomware) -* [Suspicious WMI Use](/stories/suspicious_wmi_use) -* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | A wmic.exe process $process$ contain process spawn commandline $process$ in host $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1047/](https://attack.mitre.org/techniques/T1047/) -* [https://docs.microsoft.com/en-us/windows/win32/cimwin32prov/create-method-in-class-win32-process](https://docs.microsoft.com/en-us/windows/win32/cimwin32prov/create-method-in-class-win32-process) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1047/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1047/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml) \| *version*: **7** \ No newline at end of file diff --git a/docs/_posts/2021-11-12-runas_execution_in_commandline.md b/docs/_posts/2021-11-12-runas_execution_in_commandline.md deleted file mode 100644 index fd8c7b566e..0000000000 --- a/docs/_posts/2021-11-12-runas_execution_in_commandline.md +++ /dev/null @@ -1,169 +0,0 @@ ---- -title: "Runas Execution in CommandLine" -excerpt: "Access Token Manipulation -, Token Impersonation/Theft -" -categories: - - Endpoint -last_modified_at: 2021-11-12 -toc: true -toc_label: "" -tags: - - Access Token Manipulation - - Token Impersonation/Theft - - Defense Evasion - - Privilege Escalation - - Defense Evasion - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic look for a spawned runas.exe process with a administrator user option parameter. This parameter was abused by adversaries, malware author or even red teams to gain elevated privileges in target host. This is a good hunting query to figure out privilege escalation tactics that may used for different stages like lateral movement but take note that administrator may use this command in purpose so its better to see other event context before and after this analytic. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-11-12 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 4807e716-43a4-11ec-a0e7-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1134](https://attack.mitre.org/techniques/T1134/) | Access Token Manipulation | Defense Evasion, Privilege Escalation | - -| [T1134.001](https://attack.mitre.org/techniques/T1134/001/) | Token Impersonation/Theft | Defense Evasion, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_runas` AND Processes.process = "*/user:*" AND Processes.process = "*admin*" by Processes.dest Processes.user Processes.parent_process_name Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `runas_execution_in_commandline_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [process_runas](https://github.com/splunk/security_content/blob/develop/macros/process_runas.yml) - -> :information_source: -> **runas_execution_in_commandline_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -A network operator or systems administrator may utilize an automated or manual execute this command that may generate false positives. filter is needed. - -#### Associated Analytic story -* [Windows Privilege Escalation](/stories/windows_privilege_escalation) -* [Hermetic Wiper](/stories/hermetic_wiper) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | elevated process using runas on $dest$ by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://app.any.run/tasks/ad4c3cda-41f2-4401-8dba-56cc2d245488/](https://app.any.run/tasks/ad4c3cda-41f2-4401-8dba-56cc2d245488/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/vilsel/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/vilsel/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/runas_execution_in_commandline.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-11-12-windows_installutil_credential_theft.md b/docs/_posts/2021-11-12-windows_installutil_credential_theft.md deleted file mode 100644 index baa1e11f26..0000000000 --- a/docs/_posts/2021-11-12-windows_installutil_credential_theft.md +++ /dev/null @@ -1,171 +0,0 @@ ---- -title: "Windows InstallUtil Credential Theft" -excerpt: "InstallUtil -, System Binary Proxy Execution -" -categories: - - Endpoint -last_modified_at: 2021-11-12 -toc: true -toc_label: "" -tags: - - InstallUtil - - System Binary Proxy Execution - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the Windows InstallUtil.exe binary loading `vaultcli.dll` and Samlib.dll`. This technique may be used to execute code to bypassing application control and capture credentials by utilizing a tool like MimiKatz. \ -When `InstallUtil.exe` is used in a malicous manner, the path to an executable on the filesystem is typically specified. Take note of the parent process. In a suspicious instance, this will be spawned from a non-standard process like `Cmd.exe`, `PowerShell.exe` or `Explorer.exe`. \ -If used by a developer, typically this will be found with multiple command-line switches/arguments and spawn from Visual Studio. \ -During triage review resulting network connections, file modifications, and parallel processes. Capture any artifacts and review further. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-11-12 -- **Author**: Michael Haag, Splunk -- **ID**: ccfeddec-43ec-11ec-b494-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218.004](https://attack.mitre.org/techniques/T1218/004/) | InstallUtil | Defense Evasion | - -| [T1218](https://attack.mitre.org/techniques/T1218/) | System Binary Proxy Execution | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventCode=7 process_name=installutil.exe ImageLoaded IN ("*\\samlib.dll", "*\\vaultcli.dll") -| stats count min(_time) as firstTime max(_time) as lastTime by Computer, process_name, ImageLoaded, OriginalFileName, process_id -| rename Computer as dest -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_installutil_credential_theft_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **windows_installutil_credential_theft_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and module loads from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -Typically this will not trigger as by it's very nature InstallUtil does not need credentials. Filter as needed. - -#### Associated Analytic story -* [Signed Binary Proxy Execution InstallUtil](/stories/signed_binary_proxy_execution_installutil) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ loading samlib.dll and vaultcli.dll to potentially capture credentials in memory. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://gist.github.com/xorrior/bbac3919ca2aef8d924bdf3b16cce3d0](https://gist.github.com/xorrior/bbac3919ca2aef8d924bdf3b16cce3d0) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.004/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.004/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_installutil_credential_theft.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-11-12-windows_installutil_remote_network_connection.md b/docs/_posts/2021-11-12-windows_installutil_remote_network_connection.md deleted file mode 100644 index 20d85dc167..0000000000 --- a/docs/_posts/2021-11-12-windows_installutil_remote_network_connection.md +++ /dev/null @@ -1,130 +0,0 @@ ---- -title: "Windows InstallUtil Remote Network Connection" -excerpt: "InstallUtil -, Signed Binary Proxy Execution -" -categories: - - Endpoint -last_modified_at: 2021-11-12 -toc: true -toc_label: "" -tags: - - InstallUtil - - Signed Binary Proxy Execution - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the Windows InstallUtil.exe binary making a remote network connection. This technique may be used to download and execute code while bypassing application control. \ -When `InstallUtil.exe` is used in a malicous manner, the path to an executable on the filesystem is typically specified. Take note of the parent process. In a suspicious instance, this will be spawned from a non-standard process like `Cmd.exe`, `PowerShell.exe` or `Explorer.exe`. \ -If used by a developer, typically this will be found with multiple command-line switches/arguments and spawn from Visual Studio. \ -During triage review resulting network connections, file modifications, and parallel processes. Capture any artifacts and review further. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/object-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-11-12 -- **Author**: Michael Haag, Splunk -- **ID**: 4fbf9270-43da-11ec-9486-acde48001122 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218.004](https://attack.mitre.org/techniques/T1218/004/) | InstallUtil | Defense Evasion | - -| [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | - -#### Search - -``` - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where `process_installutil` by _time span=1h Processes.process_guid Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name Processes.original_file_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| join process_guid [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Ports where Ports.dest_port !="0" by Ports.process_guid Ports.dest Ports.dest_port -| `drop_dm_object_name(Ports)` -| rename dest as connection_to_CNC] -| table _time dest parent_process_name process_name process_path process process_guid connection_to_CNC dest_port -| `windows_installutil_remote_network_connection_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [process_installutil](https://github.com/splunk/security_content/blob/develop/macros/process_installutil.yml) - -Note that `windows_installutil_remote_network_connection_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id -* Ports.process_guid -* Ports.dest -* Ports.dest_port - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` and `Ports` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Limited false positives should be present as InstallUtil is not typically used to download remote files. Filter as needed based on Developers requirements. - -#### Associated Analytic story -* [Signed Binary Proxy Execution InstallUtil](/stories/signed_binary_proxy_execution_installutil) - - -#### Kill Chain Phase -* Exploitation - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ generating a remote download. | - - - - -#### Reference - -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.004/T1218.004.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.004/T1218.004.md) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.004/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.004/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_installutil_remote_network_connection.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-11-12-windows_installutil_uninstall_option.md b/docs/_posts/2021-11-12-windows_installutil_uninstall_option.md deleted file mode 100644 index 55bc046bbd..0000000000 --- a/docs/_posts/2021-11-12-windows_installutil_uninstall_option.md +++ /dev/null @@ -1,176 +0,0 @@ ---- -title: "Windows InstallUtil Uninstall Option" -excerpt: "InstallUtil -, System Binary Proxy Execution -" -categories: - - Endpoint -last_modified_at: 2021-11-12 -toc: true -toc_label: "" -tags: - - InstallUtil - - System Binary Proxy Execution - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the Windows InstallUtil.exe binary. This will execute code while bypassing application control using the `/u` (uninstall) switch. \ -InstallUtil uses the functions install and uninstall within the System.Configuration.Install namespace to process .net assembly. Install function requires admin privileges, however, uninstall function can be run as an unprivileged user.\ -When `InstallUtil.exe` is used in a malicous manner, the path to an executable on the filesystem is typically specified. Take note of the parent process. In a suspicious instance, this will be spawned from a non-standard process like `Cmd.exe`, `PowerShell.exe` or `Explorer.exe`. \ -If used by a developer, typically this will be found with multiple command-line switches/arguments and spawn from Visual Studio. \ -During triage review resulting network connections, file modifications, and parallel processes. Capture any artifacts and review further. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-11-12 -- **Author**: Michael Haag, Splunk -- **ID**: cfa7b9ac-43f0-11ec-9b48-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218.004](https://attack.mitre.org/techniques/T1218/004/) | InstallUtil | Defense Evasion | - -| [T1218](https://attack.mitre.org/techniques/T1218/) | System Binary Proxy Execution | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_installutil` Processes.process IN ("*/u*", "*uninstall*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_installutil_uninstall_option_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [process_installutil](https://github.com/splunk/security_content/blob/develop/macros/process_installutil.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_installutil_uninstall_option_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Limited false positives should be present. Filter as needed by parent process or application. - -#### Associated Analytic story -* [Signed Binary Proxy Execution InstallUtil](/stories/signed_binary_proxy_execution_installutil) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ performing an uninstall. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_12](https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_12) -* [https://github.com/api0cradle/UltimateAppLockerByPassList/blob/master/md/Installutil.exe.md](https://github.com/api0cradle/UltimateAppLockerByPassList/blob/master/md/Installutil.exe.md) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.004/T1218.004.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.004/T1218.004.md) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.004/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.004/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_installutil_uninstall_option.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-11-12-windows_installutil_uninstall_option_with_network.md b/docs/_posts/2021-11-12-windows_installutil_uninstall_option_with_network.md deleted file mode 100644 index be6ffdda71..0000000000 --- a/docs/_posts/2021-11-12-windows_installutil_uninstall_option_with_network.md +++ /dev/null @@ -1,133 +0,0 @@ ---- -title: "Windows InstallUtil Uninstall Option with Network" -excerpt: "InstallUtil -, Signed Binary Proxy Execution -" -categories: - - Endpoint -last_modified_at: 2021-11-12 -toc: true -toc_label: "" -tags: - - InstallUtil - - Signed Binary Proxy Execution - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the Windows InstallUtil.exe binary making a remote network connection. This technique may be used to download and execute code while bypassing application control using the `/u` (uninstall) switch. \ -InstallUtil uses the functions install and uninstall within the System.Configuration.Install namespace to process .net assembly. Install function requires admin privileges, however, uninstall function can be run as an unprivileged user.\ -When `InstallUtil.exe` is used in a malicous manner, the path to an executable on the filesystem is typically specified. Take note of the parent process. In a suspicious instance, this will be spawned from a non-standard process like `Cmd.exe`, `PowerShell.exe` or `Explorer.exe`. \ -If used by a developer, typically this will be found with multiple command-line switches/arguments and spawn from Visual Studio. \ -During triage review resulting network connections, file modifications, and parallel processes. Capture any artifacts and review further. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/object-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-11-12 -- **Author**: Michael Haag, Splunk -- **ID**: 1a52c836-43ef-11ec-a36c-acde48001122 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218.004](https://attack.mitre.org/techniques/T1218/004/) | InstallUtil | Defense Evasion | - -| [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | - -#### Search - -``` - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where `process_installutil` Processes.process IN ("*/u*", "*uninstall*") by _time span=1h Processes.process_guid Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| join process_guid [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Ports where Ports.dest_port !="0" by Ports.process_guid Ports.dest Ports.dest_port -| `drop_dm_object_name(Ports)` -| rename dest as connection_to_CNC] -| table _time dest parent_process_name process_name original_file_name process_path process process_guid connection_to_CNC dest_port -| `windows_installutil_uninstall_option_with_network_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [process_installutil](https://github.com/splunk/security_content/blob/develop/macros/process_installutil.yml) - -Note that `windows_installutil_uninstall_option_with_network_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id -* Ports.process_guid -* Ports.dest -* Ports.dest_port - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` and `Ports` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Limited false positives should be present as InstallUtil is not typically used to download remote files. Filter as needed based on Developers requirements. - -#### Associated Analytic story -* [Signed Binary Proxy Execution InstallUtil](/stories/signed_binary_proxy_execution_installutil) - - -#### Kill Chain Phase -* Exploitation - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ performing an uninstall. | - - - - -#### Reference - -* [https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_12](https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_12) -* [https://github.com/api0cradle/UltimateAppLockerByPassList/blob/master/md/Installutil.exe.md](https://github.com/api0cradle/UltimateAppLockerByPassList/blob/master/md/Installutil.exe.md) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.004/T1218.004.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.004/T1218.004.md) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.004/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.004/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_installutil_uninstall_option_with_network.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-11-12-windows_installutil_url_in_command_line.md b/docs/_posts/2021-11-12-windows_installutil_url_in_command_line.md deleted file mode 100644 index c2736e0ce1..0000000000 --- a/docs/_posts/2021-11-12-windows_installutil_url_in_command_line.md +++ /dev/null @@ -1,174 +0,0 @@ ---- -title: "Windows InstallUtil URL in Command Line" -excerpt: "InstallUtil -, System Binary Proxy Execution -" -categories: - - Endpoint -last_modified_at: 2021-11-12 -toc: true -toc_label: "" -tags: - - InstallUtil - - System Binary Proxy Execution - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the Windows InstallUtil.exe binary passing a HTTP request on the command-line. This technique may be used to download and execute code while bypassing application control. \ -When `InstallUtil.exe` is used in a malicous manner, the path to an executable on the filesystem is typically specified. Take note of the parent process. In a suspicious instance, this will be spawned from a non-standard process like `Cmd.exe`, `PowerShell.exe` or `Explorer.exe`. \ -If used by a developer, typically this will be found with multiple command-line switches/arguments and spawn from Visual Studio. \ -During triage review resulting network connections, file modifications, and parallel processes. Capture any artifacts and review further. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-11-12 -- **Author**: Michael Haag, Splunk -- **ID**: 28e06670-43df-11ec-a569-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218.004](https://attack.mitre.org/techniques/T1218/004/) | InstallUtil | Defense Evasion | - -| [T1218](https://attack.mitre.org/techniques/T1218/) | System Binary Proxy Execution | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_installutil` Processes.process IN ("*http://*","*https://*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_installutil_url_in_command_line_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [process_installutil](https://github.com/splunk/security_content/blob/develop/macros/process_installutil.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_installutil_url_in_command_line_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Limited false positives should be present as InstallUtil is not typically used to download remote files. Filter as needed based on Developers requirements. - -#### Associated Analytic story -* [Signed Binary Proxy Execution InstallUtil](/stories/signed_binary_proxy_execution_installutil) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ passing a URL on the command-line. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.004/T1218.004.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.004/T1218.004.md) -* [https://gist.github.com/DanielRTeixeira/0fd06ec8f041f34a32bf5623c6dd479d](https://gist.github.com/DanielRTeixeira/0fd06ec8f041f34a32bf5623c6dd479d) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.004/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.004/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_installutil_url_in_command_line.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-11-15-remote_process_instantiation_via_dcom_and_powershell.md b/docs/_posts/2021-11-15-remote_process_instantiation_via_dcom_and_powershell.md deleted file mode 100644 index 37b92ca050..0000000000 --- a/docs/_posts/2021-11-15-remote_process_instantiation_via_dcom_and_powershell.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: "Remote Process Instantiation via DCOM and PowerShell" -excerpt: "Remote Services -, Distributed Component Object Model -" -categories: - - Endpoint -last_modified_at: 2021-11-15 -toc: true -toc_label: "" -tags: - - Remote Services - - Distributed Component Object Model - - Lateral Movement - - Lateral Movement - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for the execution of `powershell.exe` with arguments utilized to start a process on a remote endpoint by abusing the DCOM protocol. Specifically, this search looks for the abuse of ShellExecute and ExecuteShellCommand. Red Teams and adversaries alike may abuse DCOM and `powershell.exe` for lateral movement and remote code execution. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-11-15 -- **Author**: Mauricio Velazco, Splunk -- **ID**: d4f42098-4680-11ec-ad07-3e22fbd008af - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1021](https://attack.mitre.org/techniques/T1021/) | Remote Services | Lateral Movement | - -| [T1021.003](https://attack.mitre.org/techniques/T1021/003/) | Distributed Component Object Model | Lateral Movement | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_powershell` (Processes.process="*Document.ActiveView.ExecuteShellCommand*" OR Processes.process="*Document.Application.ShellExecute*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `remote_process_instantiation_via_dcom_and_powershell_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml) - -> :information_source: -> **remote_process_instantiation_via_dcom_and_powershell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. - -#### Known False Positives -Administrators may leverage DCOM to start a process on remote systems, but this activity is usually limited to a small set of hosts or users. - -#### Associated Analytic story -* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 63.0 | 90 | 70 | A process was started on a remote endpoint from $dest by abusing DCOM using PowerShell.exe | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1021/003/](https://attack.mitre.org/techniques/T1021/003/) -* [https://www.cybereason.com/blog/dcom-lateral-movement-techniques](https://www.cybereason.com/blog/dcom-lateral-movement-techniques) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021.003/lateral_movement/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021.003/lateral_movement/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/remote_process_instantiation_via_dcom_and_powershell.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-11-15-remote_process_instantiation_via_dcom_and_powershell_script_block.md b/docs/_posts/2021-11-15-remote_process_instantiation_via_dcom_and_powershell_script_block.md deleted file mode 100644 index b6b7d0635b..0000000000 --- a/docs/_posts/2021-11-15-remote_process_instantiation_via_dcom_and_powershell_script_block.md +++ /dev/null @@ -1,155 +0,0 @@ ---- -title: "Remote Process Instantiation via DCOM and PowerShell Script Block" -excerpt: "Remote Services -, Distributed Component Object Model -" -categories: - - Endpoint -last_modified_at: 2021-11-15 -toc: true -toc_label: "" -tags: - - Remote Services - - Distributed Component Object Model - - Lateral Movement - - Lateral Movement - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of PowerShell with arguments utilized to start a process on a remote endpoint by abusing the DCOM protocol. Specifically, this search looks for the abuse of ShellExecute and ExecuteShellCommand. Red Teams and adversaries alike may abuse DCOM for lateral movement and remote code execution. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-11-15 -- **Author**: Mauricio Velazco, Splunk -- **ID**: fa1c3040-4680-11ec-a618-3e22fbd008af - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1021](https://attack.mitre.org/techniques/T1021/) | Remote Services | Lateral Movement | - -| [T1021.003](https://attack.mitre.org/techniques/T1021/003/) | Distributed Component Object Model | Lateral Movement | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 (Message="*Document.Application.ShellExecute*" OR Message="*Document.ActiveView.ExecuteShellCommand*") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `remote_process_instantiation_via_dcom_and_powershell_script_block_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -Note that **remote_process_instantiation_via_dcom_and_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Message -* ComputerName -* User - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup instructions can be found https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -Administrators may leverage DCOM to start a process on remote systems, but this activity is usually limited to a small set of hosts or users. - -#### Associated Analytic story -* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 63.0 | 90 | 70 | A process was started on a remote endpoint from $ComputerName by abusing WMI using PowerShell.exe | - - -#### Reference - -* [https://attack.mitre.org/techniques/T1021/003/](https://attack.mitre.org/techniques/T1021/003/) -* [https://www.cybereason.com/blog/dcom-lateral-movement-techniques](https://www.cybereason.com/blog/dcom-lateral-movement-techniques) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021.003/lateral_movement/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021.003/lateral_movement/windows-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/remote_process_instantiation_via_dcom_and_powershell_script_block.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-11-15-remote_process_instantiation_via_wmi_and_powershell.md b/docs/_posts/2021-11-15-remote_process_instantiation_via_wmi_and_powershell.md deleted file mode 100644 index 133e5e5ae1..0000000000 --- a/docs/_posts/2021-11-15-remote_process_instantiation_via_wmi_and_powershell.md +++ /dev/null @@ -1,165 +0,0 @@ ---- -title: "Remote Process Instantiation via WMI and PowerShell" -excerpt: "Windows Management Instrumentation -" -categories: - - Endpoint -last_modified_at: 2021-11-15 -toc: true -toc_label: "" -tags: - - Windows Management Instrumentation - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for the execution of `powershell.exe` leveraging the `Invoke-WmiMethod` commandlet complemented with arguments utilized to start a process on a remote endpoint by abusing WMI. Red Teams and adversaries alike may abuse WMI and `powershell.exe` for lateral movement and remote code execution. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-11-15 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 112638b4-4634-11ec-b9ab-3e22fbd008af - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1047](https://attack.mitre.org/techniques/T1047/) | Windows Management Instrumentation | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_powershell` (Processes.process="*Invoke-WmiMethod*" AND Processes.process="*-CN*" AND Processes.process="*-Class Win32_Process*" AND Processes.process="*-Name create*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `remote_process_instantiation_via_wmi_and_powershell_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml) - -> :information_source: -> **remote_process_instantiation_via_wmi_and_powershell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. - -#### Known False Positives -Administrators may leverage WWMI and powershell.exe to start a process on remote systems, but this activity is usually limited to a small set of hosts or users. - -#### Associated Analytic story -* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 63.0 | 90 | 70 | A process was started on a remote endpoint from $dest by abusing WMI using PowerShell.exe | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1047/](https://attack.mitre.org/techniques/T1047/) -* [https://docs.microsoft.com/en-us/powershell/module/microsoft.powershell.management/invoke-wmimethod?view=powershell-5.1](https://docs.microsoft.com/en-us/powershell/module/microsoft.powershell.management/invoke-wmimethod?view=powershell-5.1) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1047/lateral_movement/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1047/lateral_movement/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/remote_process_instantiation_via_wmi_and_powershell.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-11-15-remote_process_instantiation_via_wmi_and_powershell_script_block.md b/docs/_posts/2021-11-15-remote_process_instantiation_via_wmi_and_powershell_script_block.md deleted file mode 100644 index 7b124d8434..0000000000 --- a/docs/_posts/2021-11-15-remote_process_instantiation_via_wmi_and_powershell_script_block.md +++ /dev/null @@ -1,154 +0,0 @@ ---- -title: "Remote Process Instantiation via WMI and PowerShell Script Block" -excerpt: "Windows Management Instrumentation -" -categories: - - Endpoint -last_modified_at: 2021-11-15 -toc: true -toc_label: "" -tags: - - Windows Management Instrumentation - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Invoke-WmiMethod` commandlet with arguments utilized to start a process on a remote endpoint by abusing WMI. Red Teams and adversaries alike may abuse WMI and this commandlet for lateral movement and remote code execution. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-11-15 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 2a048c14-4634-11ec-a618-3e22fbd008af - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1047](https://attack.mitre.org/techniques/T1047/) | Windows Management Instrumentation | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 (Message="*Invoke-WmiMethod*" AND Message="*-CN*" AND Message="*-Class Win32_Process*" AND Message="*-Name create*") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `remote_process_instantiation_via_wmi_and_powershell_script_block_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **remote_process_instantiation_via_wmi_and_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Message -* ComputerName -* User - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup instructions can be found https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -Administrators may leverage WWMI and powershell.exe to start a process on remote systems, but this activity is usually limited to a small set of hosts or users. - -#### Associated Analytic story -* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 63.0 | 90 | 70 | A process was started on a remote endpoint from $ComputerName by abusing WMI using PowerShell.exe | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1047/](https://attack.mitre.org/techniques/T1047/) -* [https://docs.microsoft.com/en-us/powershell/module/microsoft.powershell.management/invoke-wmimethod?view=powershell-5.1](https://docs.microsoft.com/en-us/powershell/module/microsoft.powershell.management/invoke-wmimethod?view=powershell-5.1) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1047/lateral_movement/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1047/lateral_movement/windows-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/remote_process_instantiation_via_wmi_and_powershell_script_block.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-11-15-sdelete_application_execution.md b/docs/_posts/2021-11-15-sdelete_application_execution.md deleted file mode 100644 index 982e127ff0..0000000000 --- a/docs/_posts/2021-11-15-sdelete_application_execution.md +++ /dev/null @@ -1,116 +0,0 @@ ---- -title: "Sdelete Application Execution" -excerpt: "Data Destruction, File Deletion, Indicator Removal on Host" -categories: - - Endpoint -last_modified_at: 2021-11-15 -toc: true -toc_label: "" -tags: - - Data Destruction - - Impact - - File Deletion - - Defense Evasion - - Indicator Removal on Host - - Defense Evasion - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic will detect the execution of sdelete.exe attempting to delete potentially important files that may related to adversary or insider threats to destroy evidence or information sabotage. Sdelete is a SysInternals utility meant to securely delete files on disk. This tool is commonly used to clear tracks and artifact on the targeted host. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2021-11-15 -- **Author**: Teoderick Contreras, Splunk -- **ID**: fcc52b9a-4616-11ec-8454-acde48001122 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1485](https://attack.mitre.org/techniques/T1485/) | Data Destruction | Impact | - -| [T1070.004](https://attack.mitre.org/techniques/T1070/004/) | File Deletion | Defense Evasion | - -| [T1070](https://attack.mitre.org/techniques/T1070/) | Indicator Removal on Host | Defense Evasion | - -#### Search - -``` - -| from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event,"_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), parent_cmd_line=ucast(map_get(input_event, "parent_process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line IS NOT NULL AND process_name IS NOT NULL AND like(process_name, "%sdelete%") AND (like (cmd_line, "%-c %") OR like (cmd_line, "%-f %")OR like (cmd_line, "%-p %") OR like (cmd_line, "%-r %") OR like (cmd_line, "%-q %") OR like (cmd_line, "%-s %") OR like (cmd_line, "%-z %") OR like (cmd_line, "%/accepteula%") OR like (cmd_line, "%-nobanner%")OR like (cmd_line, "%.doc%")OR like (cmd_line, "%.xls%") OR like (cmd_line, "%.ppt%")OR like (cmd_line, "%.rtf%") OR like (cmd_line, "%.pdf%") OR like (cmd_line, "%.key%")OR like (cmd_line, "%.log%") OR like (cmd_line, "%.txt%") OR like (cmd_line, "%.jpg%") OR like (cmd_line, "%.png%") OR like (cmd_line, "%.gif%") OR like (cmd_line, "%.bmp%") OR like (cmd_line, "%.7z%") OR like (cmd_line, "%.zip%") OR like (cmd_line, "%.rar%") OR like (cmd_line, "%.tar%") OR like (cmd_line, "%.gz%") OR like (cmd_line, "%.xls%")) -| eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "process_path", process_path, "parent_process_name", parent_process_name, "parent_cmd_line", parent_cmd_line]) -| into write_ssa_detected_events(); -``` - -#### Macros -The SPL above uses the following Macros: - -Note that `sdelete_application_execution_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* dest -* user -* parent_process_name -* parent_process -* process_name -* process -* process_id -* process_path -* cmd_line - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -False positives should be limited, filter as needed. - -#### Associated Analytic story -* [Information Sabotage](/stories/information_sabotage) - - -#### Kill Chain Phase -* Exploitation - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 42.0 | 60 | 70 | Sdelete process $process_name$ executed on $dest_device_id$ attempting to permanently delete files by $dest_user_id$. | - - -Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` - - - -#### Reference - -* [https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/](https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1485/T1485.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1485/T1485.md) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/sdelete/security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/sdelete/security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/sdelete_application_execution.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-11-15-windows_diskcryptor_usage.md b/docs/_posts/2021-11-15-windows_diskcryptor_usage.md deleted file mode 100644 index 9d36129ad0..0000000000 --- a/docs/_posts/2021-11-15-windows_diskcryptor_usage.md +++ /dev/null @@ -1,164 +0,0 @@ ---- -title: "Windows DiskCryptor Usage" -excerpt: "Data Encrypted for Impact -" -categories: - - Endpoint -last_modified_at: 2021-11-15 -toc: true -toc_label: "" -tags: - - Data Encrypted for Impact - - Impact - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies DiskCryptor process name of dcrypt.exe or internal name dcinst.exe. This utility has been utilized by adversaries to encrypt disks manually during an operation. In addition, during install, a dcrypt.sys driver is installed and requires a reboot in order to take effect. There are no command-line arguments used. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-11-15 -- **Author**: Michael Haag, Splunk -- **ID**: d56fe0c8-4650-11ec-a8fa-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1486](https://attack.mitre.org/techniques/T1486/) | Data Encrypted for Impact | Impact | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="dcrypt.exe" OR Processes.original_file_name=dcinst.exe) by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_diskcryptor_usage_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_diskcryptor_usage_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -It is possible false positives may be present based on the internal name dcinst.exe, filter as needed. It may be worthy to alert on the service name. - -#### Associated Analytic story -* [Ransomware](/stories/ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 35.0 | 70 | 50 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to encrypt disks. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://thedfirreport.com/2021/11/15/exchange-exploit-leads-to-domain-wide-ransomware/](https://thedfirreport.com/2021/11/15/exchange-exploit-leads-to-domain-wide-ransomware/) -* [https://github.com/DavidXanatos/DiskCryptor](https://github.com/DavidXanatos/DiskCryptor) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1486/dcrypt/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1486/dcrypt/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_diskcryptor_usage.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-11-16-high_frequency_copy_of_files_in_network_share.md b/docs/_posts/2021-11-16-high_frequency_copy_of_files_in_network_share.md deleted file mode 100644 index 98131b04cf..0000000000 --- a/docs/_posts/2021-11-16-high_frequency_copy_of_files_in_network_share.md +++ /dev/null @@ -1,162 +0,0 @@ ---- -title: "High Frequency Copy Of Files In Network Share" -excerpt: "Transfer Data to Cloud Account -" -categories: - - Endpoint -last_modified_at: 2021-11-16 -toc: true -toc_label: "" -tags: - - Transfer Data to Cloud Account - - Exfiltration - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to detect a suspicious high frequency copying/moving of files in network share as part of information sabotage. This anomaly event can be a good indicator of insider trying to sabotage data by transfering classified or internal files within network share to exfitrate it after or to lure evidence of insider attack to other user. This behavior may catch several noise if network share is a common place for classified or internal document processing. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-11-16 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 40925f12-4709-11ec-bb43-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1537](https://attack.mitre.org/techniques/T1537/) | Transfer Data to Cloud Account | Exfiltration | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`wineventlog_security` EventCode=5145 Relative_Target_Name IN ("*.doc","*.docx","*.xls","*.xlsx","*.ppt","*.pptx","*.log","*.txt","*.db","*.7z","*.zip","*.rar","*.tar","*.gz","*.jpg","*.gif","*.png","*.bmp","*.pdf","*.rtf","*.key") Object_Type=File Share_Name IN ("\\\\*\\C$","\\\\*\\IPC$","\\\\*\\admin$") Access_Mask= "0x2" -| bucket _time span=5m -| stats values(Relative_Target_Name) as valRelativeTargetName, values(Share_Name) as valShareName, values(Object_Type) as valObjectType, values(Access_Mask) as valAccessmask, values(src_port) as valSrcPort, values(Source_Address) as valSrcAddress count as numShareName by dest, _time, EventCode, user -| eventstats avg(numShareName) as avgShareName, stdev(numShareName) as stdShareName, count as numSlots by dest, _time, EventCode, user -| eval upperThreshold=(avgShareName + stdShareName *3) -| eval isOutlier=if(avgShareName > 20 and avgShareName >= upperThreshold, 1, 0) -| search isOutlier=1 -| `high_frequency_copy_of_files_in_network_share_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) - -> :information_source: -> **high_frequency_copy_of_files_in_network_share_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Share_Name -* Relative_Target_Name -* Object_Type -* Access_Mask -* user -* src_port -* Source_Address - - -#### How To Implement -o successfully implement this search, you need to be ingesting Windows Security Event Logs with 5145 EventCode enabled. The Windows TA is also required. Also enable the object Audit access success/failure in your group policy. - -#### Known False Positives -this behavior may seen in normal transfer of file within network if network share is common place for sharing documents. - -#### Associated Analytic story -* [Information Sabotage](/stories/information_sabotage) -* [Insider Threat](/stories/insider_threat) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 9.0 | 30 | 30 | high frequency copy of document in network share $Share_Name$ from $Source_Address$ by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1537/](https://attack.mitre.org/techniques/T1537/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1537/high_copy_files_in_net_share/security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1537/high_copy_files_in_net_share/security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/high_frequency_copy_of_files_in_network_share.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-11-16-remote_process_instantiation_via_winrm_and_powershell.md b/docs/_posts/2021-11-16-remote_process_instantiation_via_winrm_and_powershell.md deleted file mode 100644 index d611b7f432..0000000000 --- a/docs/_posts/2021-11-16-remote_process_instantiation_via_winrm_and_powershell.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: "Remote Process Instantiation via WinRM and PowerShell" -excerpt: "Remote Services -, Windows Remote Management -" -categories: - - Endpoint -last_modified_at: 2021-11-16 -toc: true -toc_label: "" -tags: - - Remote Services - - Windows Remote Management - - Lateral Movement - - Lateral Movement - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for the execution of `powershell.exe` with arguments utilized to start a process on a remote endpoint by abusing the WinRM protocol. Specifically, this search looks for the abuse of the `Invoke-Command` commandlet. Red Teams and adversaries alike may abuse WinRM and `powershell.exe` for lateral movement and remote code execution. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-11-16 -- **Author**: Mauricio Velazco, Splunk -- **ID**: ba24cda8-4716-11ec-8009-3e22fbd008af - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1021](https://attack.mitre.org/techniques/T1021/) | Remote Services | Lateral Movement | - -| [T1021.006](https://attack.mitre.org/techniques/T1021/006/) | Windows Remote Management | Lateral Movement | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_powershell` (Processes.process="*Invoke-Command*" AND Processes.process="*-ComputerName*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `remote_process_instantiation_via_winrm_and_powershell_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml) - -> :information_source: -> **remote_process_instantiation_via_winrm_and_powershell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. - -#### Known False Positives -Administrators may leverage WinRM and `Invoke-Command` to start a process on remote systems for system administration or automation use cases. However, this activity is usually limited to a small set of hosts or users. - -#### Associated Analytic story -* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 45.0 | 90 | 50 | A process was started on a remote endpoint from $dest by abusing WinRM using PowerShell.exe | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1021/006/](https://attack.mitre.org/techniques/T1021/006/) -* [https://pentestlab.blog/2018/05/15/lateral-movement-winrm/](https://pentestlab.blog/2018/05/15/lateral-movement-winrm/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021.006/lateral_movement_psh/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021.006/lateral_movement_psh/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/remote_process_instantiation_via_winrm_and_powershell.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-11-16-remote_process_instantiation_via_winrm_and_powershell_script_block.md b/docs/_posts/2021-11-16-remote_process_instantiation_via_winrm_and_powershell_script_block.md deleted file mode 100644 index 461370826c..0000000000 --- a/docs/_posts/2021-11-16-remote_process_instantiation_via_winrm_and_powershell_script_block.md +++ /dev/null @@ -1,155 +0,0 @@ ---- -title: "Remote Process Instantiation via WinRM and PowerShell Script Block" -excerpt: "Remote Services -, Windows Remote Management -" -categories: - - Endpoint -last_modified_at: 2021-11-16 -toc: true -toc_label: "" -tags: - - Remote Services - - Windows Remote Management - - Lateral Movement - - Lateral Movement - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of PowerShell with arguments utilized to start a process on a remote endpoint by abusing the WinRM protocol. Specifically, this search looks for the abuse of the `Invoke-Command` commandlet. Red Teams and adversaries alike may abuse WinRM for lateral movement and remote code execution. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-11-16 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 7d4c618e-4716-11ec-951c-3e22fbd008af - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1021](https://attack.mitre.org/techniques/T1021/) | Remote Services | Lateral Movement | - -| [T1021.006](https://attack.mitre.org/techniques/T1021/006/) | Windows Remote Management | Lateral Movement | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 (Message="*Invoke-Command*" AND Message="*-ComputerName*") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `remote_process_instantiation_via_winrm_and_powershell_script_block_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -Note that **remote_process_instantiation_via_winrm_and_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Message -* ComputerName -* User - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup instructions can be found https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -Administrators may leverage WinRM and `Invoke-Command` to start a process on remote systems for system administration or automation use cases. This activity is usually limited to a small set of hosts or users. In certain environments, tuning may not be possible. - -#### Associated Analytic story -* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 45.0 | 90 | 50 | A process was started on a remote endpoint from $ComputerName by abusing WinRM using PowerShell.exe | - - -#### Reference - -* [https://attack.mitre.org/techniques/T1021/006/](https://attack.mitre.org/techniques/T1021/006/) -* [https://pentestlab.blog/2018/05/15/lateral-movement-winrm/](https://pentestlab.blog/2018/05/15/lateral-movement-winrm/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021.006/lateral_movement_psh/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021.006/lateral_movement_psh/windows-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/remote_process_instantiation_via_winrm_and_powershell_script_block.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-11-17-windows_dism_remove_defender.md b/docs/_posts/2021-11-17-windows_dism_remove_defender.md deleted file mode 100644 index 407e0e576c..0000000000 --- a/docs/_posts/2021-11-17-windows_dism_remove_defender.md +++ /dev/null @@ -1,168 +0,0 @@ ---- -title: "Windows DISM Remove Defender" -excerpt: "Disable or Modify Tools -, Impair Defenses -" -categories: - - Endpoint -last_modified_at: 2021-11-17 -toc: true -toc_label: "" -tags: - - Disable or Modify Tools - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the use of the Windows Disk Image Utility, `dism.exe`, to remove Windows Defender. Adversaries may use `dism.exe` to disable Defender before completing their objective. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-11-17 -- **Author**: Michael Haag, Splunk -- **ID**: 8567da9e-47f0-11ec-99a9-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=dism.exe (Processes.process="*/online*" AND Processes.process="*/disable-feature*" AND Processes.process="*Windows-Defender*" AND Processes.process="*/remove*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_dism_remove_defender_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_dism_remove_defender_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Some legitimate administrative tools leverage `dism.exe` to manipulate packages and features of the operating system. Filter as needed. - -#### Associated Analytic story -* [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to disable Windows Defender. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://thedfirreport.com/2020/11/23/pysa-mespinoza-ransomware/](https://thedfirreport.com/2020/11/23/pysa-mespinoza-ransomware/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/atomic_red_team/windows-sysmon_dism.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/atomic_red_team/windows-sysmon_dism.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_dism_remove_defender.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-11-18-executable_file_written_in_administrative_smb_share.md b/docs/_posts/2021-11-18-executable_file_written_in_administrative_smb_share.md deleted file mode 100644 index 98e16c7643..0000000000 --- a/docs/_posts/2021-11-18-executable_file_written_in_administrative_smb_share.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: "Executable File Written in Administrative SMB Share" -excerpt: "Remote Services -, SMB/Windows Admin Shares -" -categories: - - Endpoint -last_modified_at: 2021-11-18 -toc: true -toc_label: "" -tags: - - Remote Services - - SMB/Windows Admin Shares - - Lateral Movement - - Lateral Movement - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies executable files (.exe or .dll) being written to Windows administrative SMB shares (Admin$, IPC$, C$). This represents suspicious behavior as its commonly used by tools like like PsExec/PaExec and others to stage service binaries before creating and starting a Windows service on remote endpoints. Red Teams and adversaries alike may abuse administrative shares for lateral movement and remote code execution. The Trickbot malware family also implements this behavior to try to infect other machines in the infected network. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-11-18 -- **Author**: Teoderick Contreras, Mauricio Velazco, Splunk -- **ID**: f63c34fe-a435-11eb-935a-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1021](https://attack.mitre.org/techniques/T1021/) | Remote Services | Lateral Movement | - -| [T1021.002](https://attack.mitre.org/techniques/T1021/002/) | SMB/Windows Admin Shares | Lateral Movement | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`wineventlog_security` EventCode=5145 Relative_Target_Name IN ("*.exe","*.dll") Object_Type=File Share_Name IN ("\\\\*\\C$","\\\\*\\IPC$","\\\\*\\admin$") Access_Mask= "0x2" -| stats min(_time) as firstTime max(_time) as lastTime count by EventCode Share_Name Relative_Target_Name Object_Type Access_Mask user src_port Source_Address -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `executable_file_written_in_administrative_smb_share_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **executable_file_written_in_administrative_smb_share_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Share_Name -* Relative_Target_Name -* Object_Type -* Access_Mask -* user -* src_port -* Source_Address - - -#### How To Implement -To successfully implement this search, you need to be ingesting Windows Security Event Logs with 5145 EventCode enabled. The Windows TA is also required. Also enable the object Audit access success/failure in your group policy. - -#### Known False Positives -System Administrators may use looks like PsExec for troubleshooting or administrations tasks. However, this will typically come only from certain users and certain systems that can be added to an allow list. - -#### Associated Analytic story -* [Data Destruction](/stories/data_destruction) -* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) -* [Trickbot](/stories/trickbot) -* [Hermetic Wiper](/stories/hermetic_wiper) -* [Industroyer2](/stories/industroyer2) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 70.0 | 70 | 100 | $user$ dropped or created an executable file in known sensitive SMB share. Share name=$Share_Name$, Target name=$Relative_Target_Name$, and Access mask=$Access_Mask$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1021/002/](https://attack.mitre.org/techniques/T1021/002/) -* [https://www.rapid7.com/blog/post/2013/03/09/psexec-demystified/](https://www.rapid7.com/blog/post/2013/03/09/psexec-demystified/) -* [https://labs.vipre.com/trickbot-and-its-modules/](https://labs.vipre.com/trickbot-and-its-modules/) -* [https://whitehat.eu/incident-response-case-study-featuring-ryuk-and-trickbot-part-2/](https://whitehat.eu/incident-response-case-study-featuring-ryuk-and-trickbot-part-2/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/trickbot/exe_smbshare/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/trickbot/exe_smbshare/windows-security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/executable_file_written_in_administrative_smb_share.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-11-18-loading_of_dynwrapx_module.md b/docs/_posts/2021-11-18-loading_of_dynwrapx_module.md deleted file mode 100644 index ab844da06b..0000000000 --- a/docs/_posts/2021-11-18-loading_of_dynwrapx_module.md +++ /dev/null @@ -1,171 +0,0 @@ ---- -title: "Loading Of Dynwrapx Module" -excerpt: "Process Injection -, Dynamic-link Library Injection -" -categories: - - Endpoint -last_modified_at: 2021-11-18 -toc: true -toc_label: "" -tags: - - Process Injection - - Dynamic-link Library Injection - - Defense Evasion - - Privilege Escalation - - Defense Evasion - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -DynamicWrapperX is an ActiveX component that can be used in a script to call Windows API functions, but it requires the dynwrapx.dll to be installed and registered. With that, registering or loading dynwrapx.dll to a host is highly suspicious. In most instances when it is used maliciously, the best way to triage is to review parallel processes and pivot on the process_guid. Review the registry for any suspicious modifications meant to load dynwrapx.dll. Identify any suspicious module loads of dynwrapx.dll. This detection will return and identify the processes that invoke vbs/wscript/cscript. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-11-18 -- **Author**: Teoderick Contreras, Splunk -- **ID**: eac5e8ba-4857-11ec-9371-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1055](https://attack.mitre.org/techniques/T1055/) | Process Injection | Defense Evasion, Privilege Escalation | - -| [T1055.001](https://attack.mitre.org/techniques/T1055/001/) | Dynamic-link Library Injection | Defense Evasion, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventCode=7 (ImageLoaded = "*\\dynwrapx.dll" OR OriginalFileName = "dynwrapx.dll" OR Product = "DynamicWrapperX") -| stats count min(_time) as firstTime max(_time) as lastTime by Image ImageLoaded OriginalFileName Product process_name Computer EventCode Signed ProcessId -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `loading_of_dynwrapx_module_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **loading_of_dynwrapx_module_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Image -* ImageLoaded -* OriginalFileName -* Product -* process_name -* Computer -* EventCode -* Signed -* ProcessId - - -#### How To Implement -To successfully implement this search you need to be ingesting information on processes that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` and `Filesystem` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -False positives should be limited, however it is possible to filter by Processes.process_name and specific processes (ex. wscript.exe). Filter as needed. This may need modification based on EDR telemetry and how it brings in registry data. For example, removal of (Default). - -#### Associated Analytic story -* [Remcos](/stories/remcos) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | dynwrapx.dll loaded by process $process_name$ on $Computer$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://blog.f-secure.com/hunting-for-koadic-a-com-based-rootkit/](https://blog.f-secure.com/hunting-for-koadic-a-com-based-rootkit/) -* [https://www.script-coding.com/dynwrapx_eng.html](https://www.script-coding.com/dynwrapx_eng.html) -* [https://bohops.com/2018/06/28/abusing-com-registry-structure-clsid-localserver32-inprocserver32/](https://bohops.com/2018/06/28/abusing-com-registry-structure-clsid-localserver32-inprocserver32/) -* [https://tria.ge/210929-ap75vsddan](https://tria.ge/210929-ap75vsddan) -* [https://www.virustotal.com/gui/file/cb77b93150cb0f7fe65ce8a7e2a5781e727419451355a7736db84109fa215a89](https://www.virustotal.com/gui/file/cb77b93150cb0f7fe65ce8a7e2a5781e727419451355a7736db84109fa215a89) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos_dynwrapx/sysmon_dynwraper.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos_dynwrapx/sysmon_dynwraper.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/loading_of_dynwrapx_module.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-11-19-system_info_gathering_using_dxdiag_application.md b/docs/_posts/2021-11-19-system_info_gathering_using_dxdiag_application.md deleted file mode 100644 index f2e189df34..0000000000 --- a/docs/_posts/2021-11-19-system_info_gathering_using_dxdiag_application.md +++ /dev/null @@ -1,164 +0,0 @@ ---- -title: "System Info Gathering Using Dxdiag Application" -excerpt: "Gather Victim Host Information -" -categories: - - Endpoint -last_modified_at: 2021-11-19 -toc: true -toc_label: "" -tags: - - Gather Victim Host Information - - Reconnaissance - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to detect a suspicious dxdiag.exe process command-line execution. Dxdiag is used to collect the system info of the target host. This technique has been used by Remcos RATS, various actors, and other malware to collect information as part of the recon or collection phase of an attack. This behavior should rarely be seen in a corporate network, but this command line can be used by a network administrator to audit host machine specifications. Thus in some rare cases, this detection will contain false positives in its results. To triage further, analyze what commands were passed after it pipes out the result to a file for further processing. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-11-19 -- **Author**: Teoderick Contreras, Splunk -- **ID**: f92d74f2-4921-11ec-b685-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1592](https://attack.mitre.org/techniques/T1592/) | Gather Victim Host Information | Reconnaissance | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_dxdiag` AND Processes.process = "* /t *" by Processes.dest Processes.user Processes.parent_process_name Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `system_info_gathering_using_dxdiag_application_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [process_dxdiag](https://github.com/splunk/security_content/blob/develop/macros/process_dxdiag.yml) - -> :information_source: -> **system_info_gathering_using_dxdiag_application_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` and `Filesystem` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -This commandline can be used by a network administrator to audit host machine specifications. Thus, a filter is needed. - -#### Associated Analytic story -* [Remcos](/stories/remcos) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | dxdiag.exe process with commandline $process$ on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://app.any.run/tasks/df0baf9f-8baf-4c32-a452-16562ecb19be/](https://app.any.run/tasks/df0baf9f-8baf-4c32-a452-16562ecb19be/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/t1592/host_info_dxdiag/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/t1592/host_info_dxdiag/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/system_info_gathering_using_dxdiag_application.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-11-22-anomalous_usage_of_archive_tools.md b/docs/_posts/2021-11-22-anomalous_usage_of_archive_tools.md deleted file mode 100644 index 4a75f7bfb1..0000000000 --- a/docs/_posts/2021-11-22-anomalous_usage_of_archive_tools.md +++ /dev/null @@ -1,111 +0,0 @@ ---- -title: "Anomalous usage of Archive Tools" -excerpt: "Archive via Utility, Archive Collected Data" -categories: - - Endpoint -last_modified_at: 2021-11-22 -toc: true -toc_label: "" -tags: - - Archive via Utility - - Collection - - Archive Collected Data - - Collection - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -The following detection identifies the usage of archive tools from the command line. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2021-11-22 -- **Author**: Patrick Bareiss, Splunk -- **ID**: 63614a58-10e2-4c6c-ae81-ea1113681439 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1560.001](https://attack.mitre.org/techniques/T1560/001/) | Archive via Utility | Collection | - -| [T1560](https://attack.mitre.org/techniques/T1560/) | Archive Collected Data | Collection | - -#### Search - -``` - -| from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event,"_time"), "string", null)), process=lower(ucast(map_get(input_event, "process"), "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), parent_process=ucast(map_get(input_event, "parent_process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where process_name IS NOT NULL AND parent_process_name IS NOT NULL -| where like(process_name, "7z%") OR process_name="WinRAR.exe" OR like(process_name, "winzip%") -| where like(parent_process_name, "%cmd.exe") OR like(parent_process_name, "%powershell.exe") -| eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) -| into write_ssa_detected_events(); -``` - -#### Macros -The SPL above uses the following Macros: - -Note that `anomalous_usage_of_archive_tools_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process_name -* Processes.process -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -False positives can be ligitmate usage of archive tools from the command line. - -#### Associated Analytic story -* [Cobalt Strike](/stories/cobalt_strike) -* [NOBELIUM Group](/stories/nobelium_group) - - -#### Kill Chain Phase -* Actions on Objective - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 42.0 | 70 | 60 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$. This behavior is indicative of suspicious loading of 7zip. | - - -Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` - - - -#### Reference - -* [https://attack.mitre.org/techniques/T1560/001/](https://attack.mitre.org/techniques/T1560/001/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1560.001/archive_tools/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1560.001/archive_tools/windows-security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/anomalous_usage_of_archive_tools.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-11-22-possible_browser_pass_view_parameter.md b/docs/_posts/2021-11-22-possible_browser_pass_view_parameter.md deleted file mode 100644 index a240857b3c..0000000000 --- a/docs/_posts/2021-11-22-possible_browser_pass_view_parameter.md +++ /dev/null @@ -1,169 +0,0 @@ ---- -title: "Possible Browser Pass View Parameter" -excerpt: "Credentials from Web Browsers -, Credentials from Password Stores -" -categories: - - Endpoint -last_modified_at: 2021-11-22 -toc: true -toc_label: "" -tags: - - Credentials from Web Browsers - - Credentials from Password Stores - - Credential Access - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic will detect if a suspicious process contains a commandline parameter related to a web browser credential dumper. This technique is used by Remcos RAT malware which uses the Nirsoft webbrowserpassview.exe application to dump web browser credentials. Remcos uses the "/stext" command line to dump the credentials in text format. This Hunting query is a good indicator of hosts suffering from possible Remcos RAT infection. Since the hunting query is based on the parameter command and the possible path where it will save the text credential information, it may catch normal tools that are using the same command and behavior. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-11-22 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 8ba484e8-4b97-11ec-b19a-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1555.003](https://attack.mitre.org/techniques/T1555/003/) | Credentials from Web Browsers | Credential Access | - -| [T1555](https://attack.mitre.org/techniques/T1555/) | Credentials from Password Stores | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process IN ("*/stext *", "*/shtml *", "*/LoadPasswordsIE*", "*/LoadPasswordsFirefox*", "*/LoadPasswordsChrome*", "*/LoadPasswordsOpera*", "*/LoadPasswordsSafari*" , "*/UseOperaPasswordFile*", "*/OperaPasswordFile*","*/stab*", "*/scomma*", "*/stabular*", "*/shtml*", "*/sverhtml*", "*/sxml*", "*/skeepass*" ) AND Processes.process IN ("*\\temp\\*", "*\\users\\public\\*", "*\\programdata\\*") by Processes.dest Processes.user Processes.parent_process_name Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.original_file_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `possible_browser_pass_view_parameter_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **possible_browser_pass_view_parameter_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -False positive is quite limited. Filter is needed - -#### Associated Analytic story -* [Remcos](/stories/remcos) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 16.0 | 40 | 40 | suspicious process $process_name$ contains commandline $process$ on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.nirsoft.net/utils/web_browser_password.html](https://www.nirsoft.net/utils/web_browser_password.html) -* [https://app.any.run/tasks/df0baf9f-8baf-4c32-a452-16562ecb19be/](https://app.any.run/tasks/df0baf9f-8baf-4c32-a452-16562ecb19be/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1555/web_browser_pass_view/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1555/web_browser_pass_view/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/possible_browser_pass_view_parameter.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-11-22-services_lolbas_execution_process_spawn.md b/docs/_posts/2021-11-22-services_lolbas_execution_process_spawn.md deleted file mode 100644 index f1d26ef0d2..0000000000 --- a/docs/_posts/2021-11-22-services_lolbas_execution_process_spawn.md +++ /dev/null @@ -1,173 +0,0 @@ ---- -title: "Services LOLBAS Execution Process Spawn" -excerpt: "Create or Modify System Process -, Windows Service -" -categories: - - Endpoint -last_modified_at: 2021-11-22 -toc: true -toc_label: "" -tags: - - Create or Modify System Process - - Windows Service - - Persistence - - Privilege Escalation - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies `services.exe` spawning a LOLBAS execution process. When adversaries execute code on remote endpoints abusing the Service Control Manager and creating a remote malicious service, the executed command is spawned as a child process of `services.exe`. The LOLBAS project documents Windows native binaries that can be abused by threat actors to perform tasks like executing malicious code. Looking for child processes of services.exe that are part of the LOLBAS project can help defenders identify lateral movement activity. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-11-22 -- **Author**: Mauricio Velazco, Splunk -- **ID**: ba9e1954-4c04-11ec-8b74-3e22fbd008af - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1543](https://attack.mitre.org/techniques/T1543/) | Create or Modify System Process | Persistence, Privilege Escalation | - -| [T1543.003](https://attack.mitre.org/techniques/T1543/003/) | Windows Service | Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.parent_process_name=services.exe) (Processes.process_name IN ("Regsvcs.exe", "Ftp.exe", "OfflineScannerShell.exe", "Rasautou.exe", "Schtasks.exe", "Xwizard.exe", "Dllhost.exe", "Pnputil.exe", "Atbroker.exe", "Pcwrun.exe", "Ttdinject.exe","Mshta.exe", "Bitsadmin.exe", "Certoc.exe", "Ieexec.exe", "Microsoft.Workflow.Compiler.exe", "Runscripthelper.exe", "Forfiles.exe", "Msbuild.exe", "Register-cimprovider.exe", "Tttracer.exe", "Ie4uinit.exe", "Bash.exe", "Hh.exe", "SettingSyncHost.exe", "Cmstp.exe", "Mmc.exe", "Stordiag.exe", "Scriptrunner.exe", "Odbcconf.exe", "Extexport.exe", "Msdt.exe", "WorkFolders.exe", "Diskshadow.exe", "Mavinject.exe", "Regasm.exe", "Gpscript.exe", "Rundll32.exe", "Regsvr32.exe", "Msiexec.exe", "Wuauclt.exe", "Presentationhost.exe", "Wmic.exe", "Runonce.exe", "Syncappvpublishingserver.exe", "Verclsid.exe", "Infdefaultinstall.exe", "Explorer.exe", "Installutil.exe", "Netsh.exe", "Wab.exe", "Dnscmd.exe", "At.exe", "Pcalua.exe", "Msconfig.exe")) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `services_lolbas_execution_process_spawn_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **services_lolbas_execution_process_spawn_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. - -#### Known False Positives -Legitimate applications may trigger this behavior, filter as needed. - -#### Associated Analytic story -* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 54.0 | 90 | 60 | Services.exe spawned a LOLBAS process on $dest | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1543/003/](https://attack.mitre.org/techniques/T1543/003/) -* [https://pentestlab.blog/2020/07/21/lateral-movement-services/](https://pentestlab.blog/2020/07/21/lateral-movement-services/) -* [https://lolbas-project.github.io/](https://lolbas-project.github.io/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1543.003/lateral_movement_lolbas/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1543.003/lateral_movement_lolbas/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/services_lolbas_execution_process_spawn.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-11-22-svchost_lolbas_execution_process_spawn.md b/docs/_posts/2021-11-22-svchost_lolbas_execution_process_spawn.md deleted file mode 100644 index 49d8668e14..0000000000 --- a/docs/_posts/2021-11-22-svchost_lolbas_execution_process_spawn.md +++ /dev/null @@ -1,175 +0,0 @@ ---- -title: "Svchost LOLBAS Execution Process Spawn" -excerpt: "Scheduled Task/Job -, Scheduled Task -" -categories: - - Endpoint -last_modified_at: 2021-11-22 -toc: true -toc_label: "" -tags: - - Scheduled Task/Job - - Scheduled Task - - Execution - - Persistence - - Privilege Escalation - - Execution - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies `svchost.exe` spawning a LOLBAS execution process. When adversaries execute code on remote endpoints abusing the Task Scheduler and creating a malicious remote scheduled task, the executed command is spawned as a child process of `svchost.exe`. The LOLBAS project documents Windows native binaries that can be abused by threat actors to perform tasks like executing malicious code. Looking for child processes of svchost.exe that are part of the LOLBAS project can help defenders identify lateral movement activity. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-11-22 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 09e5c72a-4c0d-11ec-aa29-3e22fbd008af - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1053](https://attack.mitre.org/techniques/T1053/) | Scheduled Task/Job | Execution, Persistence, Privilege Escalation | - -| [T1053.005](https://attack.mitre.org/techniques/T1053/005/) | Scheduled Task | Execution, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.parent_process_name=svchost.exe) (Processes.process_name IN ("Regsvcs.exe", "Ftp.exe", "OfflineScannerShell.exe", "Rasautou.exe", "Schtasks.exe", "Xwizard.exe", "Pnputil.exe", "Atbroker.exe", "Pcwrun.exe", "Ttdinject.exe","Mshta.exe", "Bitsadmin.exe", "Certoc.exe", "Ieexec.exe", "Microsoft.Workflow.Compiler.exe", "Runscripthelper.exe", "Forfiles.exe", "Msbuild.exe", "Register-cimprovider.exe", "Tttracer.exe", "Ie4uinit.exe", "Bash.exe", "Hh.exe", "SettingSyncHost.exe", "Cmstp.exe", "Stordiag.exe", "Scriptrunner.exe", "Odbcconf.exe", "Extexport.exe", "Msdt.exe", "WorkFolders.exe", "Diskshadow.exe", "Mavinject.exe", "Regasm.exe", "Gpscript.exe", "Regsvr32.exe", "Msiexec.exe", "Wuauclt.exe", "Presentationhost.exe", "Wmic.exe", "Runonce.exe", "Syncappvpublishingserver.exe", "Verclsid.exe", "Infdefaultinstall.exe", "Installutil.exe", "Netsh.exe", "Wab.exe", "Dnscmd.exe", "At.exe", "Pcalua.exe", "Msconfig.exe")) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `svchost_lolbas_execution_process_spawn_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **svchost_lolbas_execution_process_spawn_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. - -#### Known False Positives -Legitimate applications may trigger this behavior, filter as needed. - -#### Associated Analytic story -* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 54.0 | 90 | 60 | Svchost.exe spawned a LOLBAS process on $dest | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1053/005/](https://attack.mitre.org/techniques/T1053/005/) -* [https://www.ired.team/offensive-security/persistence/t1053-schtask](https://www.ired.team/offensive-security/persistence/t1053-schtask) -* [https://lolbas-project.github.io/](https://lolbas-project.github.io/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/lateral_movement_lolbas/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/lateral_movement_lolbas/windows-security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/svchost_lolbas_execution_process_spawn.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-11-22-windows_service_created_with_suspicious_service_path.md b/docs/_posts/2021-11-22-windows_service_created_with_suspicious_service_path.md deleted file mode 100644 index dedb5d334c..0000000000 --- a/docs/_posts/2021-11-22-windows_service_created_with_suspicious_service_path.md +++ /dev/null @@ -1,162 +0,0 @@ ---- -title: "Windows Service Created With Suspicious Service Path" -excerpt: "System Services -, Service Execution -" -categories: - - Endpoint -last_modified_at: 2021-11-22 -toc: true -toc_label: "" -tags: - - System Services - - Service Execution - - Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytc uses Windows Event Id 7045, `New Service Was Installed`, to identify the creation of a Windows Service where the service binary path path is located in a non-common Service folder in Windows. Red Teams and adversaries alike may create malicious Services for lateral movement or remote code execution as well as persistence and execution. The Clop ransomware has also been seen in the wild abusing Windows services. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-11-22 -- **Author**: Teoderick Contreras, Mauricio Velazco, Splunk -- **ID**: 429141be-8311-11eb-adb6-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1569](https://attack.mitre.org/techniques/T1569/) | System Services | Execution | - -| [T1569.002](https://attack.mitre.org/techniques/T1569/002/) | Service Execution | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - `wineventlog_system` EventCode=7045 Service_File_Name = "*\.exe" NOT (Service_File_Name IN ("C:\\Windows\\*", "C:\\Program File*", "C:\\Programdata\\*", "%systemroot%\\*")) -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Service_File_Name Service_Name Service_Start_Type Service_Type -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_service_created_with_suspicious_service_path_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [wineventlog_system](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_system.yml) - -> :information_source: -> **windows_service_created_with_suspicious_service_path_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* EventCode -* Service_File_Name -* Service_Type -* _time -* Service_Name -* Service_Start_Type - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the Service name, Service File Name Service Start type, and Service Type from your endpoints. - -#### Known False Positives -Legitimate applications may install services with uncommon services paths. - -#### Associated Analytic story -* [Clop Ransomware](/stories/clop_ransomware) -* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 56.0 | 70 | 80 | A service $Service_File_Name$ was created from a non-standard path using $Service_Name$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.mandiant.com/resources/fin11-email-campaigns-precursor-for-ransomware-data-theft](https://www.mandiant.com/resources/fin11-email-campaigns-precursor-for-ransomware-data-theft) -* [https://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html](https://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_a/windows-system.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_a/windows-system.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_service_created_with_suspicious_service_path.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-11-22-windows_service_created_within_public_path.md b/docs/_posts/2021-11-22-windows_service_created_within_public_path.md deleted file mode 100644 index ddf621fad7..0000000000 --- a/docs/_posts/2021-11-22-windows_service_created_within_public_path.md +++ /dev/null @@ -1,163 +0,0 @@ ---- -title: "Windows Service Created Within Public Path" -excerpt: "Create or Modify System Process -, Windows Service -" -categories: - - Endpoint -last_modified_at: 2021-11-22 -toc: true -toc_label: "" -tags: - - Create or Modify System Process - - Windows Service - - Persistence - - Privilege Escalation - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytc uses Windows Event Id 7045, `New Service Was Installed`, to identify the creation of a Windows Service where the service binary path is located in public paths. This behavior could represent the installation of a malicious service. Red Teams and adversaries alike may create malicious Services for lateral movement or remote code execution - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-11-22 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 3abb2eda-4bb8-11ec-9ae4-3e22fbd008af - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1543](https://attack.mitre.org/techniques/T1543/) | Create or Modify System Process | Persistence, Privilege Escalation | - -| [T1543.003](https://attack.mitre.org/techniques/T1543/003/) | Windows Service | Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`wineventlog_system` EventCode=7045 Service_File_Name = "*\.exe" NOT (Service_File_Name IN ("C:\\Windows\\*", "C:\\Program File*", "C:\\Programdata\\*", "%systemroot%\\*")) -| stats count min(_time) as firstTime max(_time) as lastTime by ComputerName EventCode Service_File_Name Service_Name Service_Start_Type Service_Type -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_service_created_within_public_path_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [wineventlog_system](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_system.yml) - -> :information_source: -> **windows_service_created_within_public_path_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* EventCode -* Service_File_Name -* Service_Type -* _time -* Service_Name -* Service_Start_Type - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the Service name, Service File Name Service Start type, and Service Type from your endpoints. - -#### Known False Positives -Legitimate applications may install services with uncommon services paths. - -#### Associated Analytic story -* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 54.0 | 90 | 60 | A Windows Service $Service_File_Name$ with a public path was created on $ComputerName | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://docs.microsoft.com/en-us/windows/win32/services/service-control-manager](https://docs.microsoft.com/en-us/windows/win32/services/service-control-manager) -* [https://pentestlab.blog/2020/07/21/lateral-movement-services/](https://pentestlab.blog/2020/07/21/lateral-movement-services/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1543.003/lateral_movement_suspicious_path/windows-system.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1543.003/lateral_movement_suspicious_path/windows-system.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_service_created_within_public_path.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-11-22-wmiprsve_lolbas_execution_process_spawn.md b/docs/_posts/2021-11-22-wmiprsve_lolbas_execution_process_spawn.md deleted file mode 100644 index 479ec8abb8..0000000000 --- a/docs/_posts/2021-11-22-wmiprsve_lolbas_execution_process_spawn.md +++ /dev/null @@ -1,165 +0,0 @@ ---- -title: "Wmiprsve LOLBAS Execution Process Spawn" -excerpt: "Windows Management Instrumentation -" -categories: - - Endpoint -last_modified_at: 2021-11-22 -toc: true -toc_label: "" -tags: - - Windows Management Instrumentation - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies `wmiprsve.exe` spawning a LOLBAS execution process. When adversaries execute code on remote endpoints abusing Windows Management Instrumentation (WMI), the executed command is spawned as a child process of `wmiprvse.exe`. The LOLBAS project documents Windows native binaries that can be abused by threat actors to perform tasks like executing malicious code. Looking for child processes of wmiprvse.exe that are part of the LOLBAS project can help defenders identify lateral movement activity. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-11-22 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 95a455f0-4c04-11ec-b8ac-3e22fbd008af - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1047](https://attack.mitre.org/techniques/T1047/) | Windows Management Instrumentation | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.parent_process_name=wmiprvse.exe) (Processes.process_name IN ("Regsvcs.exe", "Ftp.exe", "OfflineScannerShell.exe", "Rasautou.exe", "Schtasks.exe", "Xwizard.exe", "Dllhost.exe", "Pnputil.exe", "Atbroker.exe", "Pcwrun.exe", "Ttdinject.exe","Mshta.exe", "Bitsadmin.exe", "Certoc.exe", "Ieexec.exe", "Microsoft.Workflow.Compiler.exe", "Runscripthelper.exe", "Forfiles.exe", "Msbuild.exe", "Register-cimprovider.exe", "Tttracer.exe", "Ie4uinit.exe", "Bash.exe", "Hh.exe", "SettingSyncHost.exe", "Cmstp.exe", "Mmc.exe", "Stordiag.exe", "Scriptrunner.exe", "Odbcconf.exe", "Extexport.exe", "Msdt.exe", "WorkFolders.exe", "Diskshadow.exe", "Mavinject.exe", "Regasm.exe", "Gpscript.exe", "Rundll32.exe", "Regsvr32.exe", "Msiexec.exe", "Wuauclt.exe", "Presentationhost.exe", "Wmic.exe", "Runonce.exe", "Syncappvpublishingserver.exe", "Verclsid.exe", "Infdefaultinstall.exe", "Explorer.exe", "Installutil.exe", "Netsh.exe", "Wab.exe", "Dnscmd.exe", "At.exe", "Pcalua.exe", "Msconfig.exe")) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `wmiprsve_lolbas_execution_process_spawn_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **wmiprsve_lolbas_execution_process_spawn_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. - -#### Known False Positives -Legitimate applications may trigger this behavior, filter as needed. - -#### Associated Analytic story -* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 54.0 | 90 | 60 | Wmiprsve.exe spawned a LOLBAS process on $dest$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1047/](https://attack.mitre.org/techniques/T1047/) -* [https://www.ired.team/offensive-security/lateral-movement/t1047-wmi-for-lateral-movement](https://www.ired.team/offensive-security/lateral-movement/t1047-wmi-for-lateral-movement) -* [https://lolbas-project.github.io/](https://lolbas-project.github.io/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1047/lateral_movement_lolbas/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1047/lateral_movement_lolbas/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/wmiprsve_lolbas_execution_process_spawn.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-11-22-wsmprovhost_lolbas_execution_process_spawn.md b/docs/_posts/2021-11-22-wsmprovhost_lolbas_execution_process_spawn.md deleted file mode 100644 index cc5641f5df..0000000000 --- a/docs/_posts/2021-11-22-wsmprovhost_lolbas_execution_process_spawn.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: "Wsmprovhost LOLBAS Execution Process Spawn" -excerpt: "Remote Services -, Windows Remote Management -" -categories: - - Endpoint -last_modified_at: 2021-11-22 -toc: true -toc_label: "" -tags: - - Remote Services - - Windows Remote Management - - Lateral Movement - - Lateral Movement - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies `Wsmprovhost.exe` spawning a LOLBAS execution process. When adversaries execute code on remote endpoints abusing the Windows Remote Management (WinRm) protocol, the executed command is spawned as a child processs of `Wsmprovhost.exe`. The LOLBAS project documents Windows native binaries that can be abused by threat actors to perform tasks like executing malicious code. Looking for child processes of Wsmprovhost.exe that are part of the LOLBAS project can help defenders identify lateral movement activity. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-11-22 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 2eed004c-4c0d-11ec-93e8-3e22fbd008af - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1021](https://attack.mitre.org/techniques/T1021/) | Remote Services | Lateral Movement | - -| [T1021.006](https://attack.mitre.org/techniques/T1021/006/) | Windows Remote Management | Lateral Movement | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.parent_process_name=wsmprovhost.exe) (Processes.process_name IN ("Regsvcs.exe", "Ftp.exe", "OfflineScannerShell.exe", "Rasautou.exe", "Schtasks.exe", "Xwizard.exe", "Dllhost.exe", "Pnputil.exe", "Atbroker.exe", "Pcwrun.exe", "Ttdinject.exe","Mshta.exe", "Bitsadmin.exe", "Certoc.exe", "Ieexec.exe", "Microsoft.Workflow.Compiler.exe", "Runscripthelper.exe", "Forfiles.exe", "Msbuild.exe", "Register-cimprovider.exe", "Tttracer.exe", "Ie4uinit.exe", "Bash.exe", "Hh.exe", "SettingSyncHost.exe", "Cmstp.exe", "Mmc.exe", "Stordiag.exe", "Scriptrunner.exe", "Odbcconf.exe", "Extexport.exe", "Msdt.exe", "WorkFolders.exe", "Diskshadow.exe", "Mavinject.exe", "Regasm.exe", "Gpscript.exe", "Rundll32.exe", "Regsvr32.exe", "Msiexec.exe", "Wuauclt.exe", "Presentationhost.exe", "Wmic.exe", "Runonce.exe", "Syncappvpublishingserver.exe", "Verclsid.exe", "Infdefaultinstall.exe", "Explorer.exe", "Installutil.exe", "Netsh.exe", "Wab.exe", "Dnscmd.exe", "At.exe", "Pcalua.exe", "Msconfig.exe")) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `wsmprovhost_lolbas_execution_process_spawn_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **wsmprovhost_lolbas_execution_process_spawn_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. - -#### Known False Positives -Legitimate applications may trigger this behavior, filter as needed. - -#### Associated Analytic story -* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 54.0 | 90 | 60 | Wsmprovhost.exe spawned a LOLBAS process on $dest$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1021/006/](https://attack.mitre.org/techniques/T1021/006/) -* [https://lolbas-project.github.io/](https://lolbas-project.github.io/) -* [https://pentestlab.blog/2018/05/15/lateral-movement-winrm/](https://pentestlab.blog/2018/05/15/lateral-movement-winrm/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021.006/lateral_movement_lolbas/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021.006/lateral_movement_lolbas/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/wsmprovhost_lolbas_execution_process_spawn.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-11-23-mmc_lolbas_execution_process_spawn.md b/docs/_posts/2021-11-23-mmc_lolbas_execution_process_spawn.md deleted file mode 100644 index 7b21a8c296..0000000000 --- a/docs/_posts/2021-11-23-mmc_lolbas_execution_process_spawn.md +++ /dev/null @@ -1,176 +0,0 @@ ---- -title: "Mmc LOLBAS Execution Process Spawn" -excerpt: "Remote Services -, Distributed Component Object Model -, MMC -" -categories: - - Endpoint -last_modified_at: 2021-11-23 -toc: true -toc_label: "" -tags: - - Remote Services - - Distributed Component Object Model - - MMC - - Lateral Movement - - Lateral Movement - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies `mmc.exe` spawning a LOLBAS execution process. When adversaries execute code on remote endpoints abusing the DCOM protocol and the MMC20 COM object, the executed command is spawned as a child processs of `mmc.exe`. The LOLBAS project documents Windows native binaries that can be abused by threat actors to perform tasks like executing malicious code. Looking for child processes of mmc.exe that are part of the LOLBAS project can help defenders identify lateral movement activity. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-11-23 -- **Author**: Mauricio Velazco, Splunk -- **ID**: f6601940-4c74-11ec-b9b7-3e22fbd008af - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1021](https://attack.mitre.org/techniques/T1021/) | Remote Services | Lateral Movement | - -| [T1021.003](https://attack.mitre.org/techniques/T1021/003/) | Distributed Component Object Model | Lateral Movement | - -| [T1218.014](https://attack.mitre.org/techniques/T1218/014/) | MMC | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.parent_process_name=mmc.exe) (Processes.process_name IN ("Regsvcs.exe", "Ftp.exe", "OfflineScannerShell.exe", "Rasautou.exe", "Schtasks.exe", "Xwizard.exe", "Dllhost.exe", "Pnputil.exe", "Atbroker.exe", "Pcwrun.exe", "Ttdinject.exe","Mshta.exe", "Bitsadmin.exe", "Certoc.exe", "Ieexec.exe", "Microsoft.Workflow.Compiler.exe", "Runscripthelper.exe", "Forfiles.exe", "Msbuild.exe", "Register-cimprovider.exe", "Tttracer.exe", "Ie4uinit.exe", "Bash.exe", "Hh.exe", "SettingSyncHost.exe", "Cmstp.exe", "Mmc.exe", "Stordiag.exe", "Scriptrunner.exe", "Odbcconf.exe", "Extexport.exe", "Msdt.exe", "WorkFolders.exe", "Diskshadow.exe", "Mavinject.exe", "Regasm.exe", "Gpscript.exe", "Rundll32.exe", "Regsvr32.exe", "Msiexec.exe", "Wuauclt.exe", "Presentationhost.exe", "Wmic.exe", "Runonce.exe", "Syncappvpublishingserver.exe", "Verclsid.exe", "Infdefaultinstall.exe", "Explorer.exe", "Installutil.exe", "Netsh.exe", "Wab.exe", "Dnscmd.exe", "At.exe", "Pcalua.exe", "Msconfig.exe")) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `mmc_lolbas_execution_process_spawn_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **mmc_lolbas_execution_process_spawn_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. - -#### Known False Positives -Legitimate applications may trigger this behavior, filter as needed. - -#### Associated Analytic story -* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 54.0 | 90 | 60 | Mmc.exe spawned a LOLBAS process on $dest$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1021/003/](https://attack.mitre.org/techniques/T1021/003/) -* [https://www.cybereason.com/blog/dcom-lateral-movement-techniques](https://www.cybereason.com/blog/dcom-lateral-movement-techniques) -* [https://lolbas-project.github.io/](https://lolbas-project.github.io/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021.003/lateral_movement_lolbas/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021.003/lateral_movement_lolbas/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/mmc_lolbas_execution_process_spawn.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-11-24-attempt_to_delete_services.md b/docs/_posts/2021-11-24-attempt_to_delete_services.md deleted file mode 100644 index 20ebd11f9a..0000000000 --- a/docs/_posts/2021-11-24-attempt_to_delete_services.md +++ /dev/null @@ -1,117 +0,0 @@ ---- -title: "Attempt To Delete Services" -excerpt: "Service Stop, Create or Modify System Process, Windows Service" -categories: - - Endpoint -last_modified_at: 2021-11-24 -toc: true -toc_label: "" -tags: - - Service Stop - - Impact - - Create or Modify System Process - - Persistence - - Privilege Escalation - - Windows Service - - Persistence - - Privilege Escalation - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies Windows Service Control, `sc.exe`, attempting to delete a service. This is typically identified in parallel with other instances of service enumeration of attempts to stop a service and then delete it. Adversaries utilize this technique to terminate security services or other related services to continue there objective and evade detections. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2021-11-24 -- **Author**: Teoderick Contreras, splunk -- **ID**: a0c8c292-d01a-11eb-aa18-acde48001122 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1489](https://attack.mitre.org/techniques/T1489/) | Service Stop | Impact | - -| [T1543](https://attack.mitre.org/techniques/T1543/) | Create or Modify System Process | Persistence, Privilege Escalation | - -| [T1543.003](https://attack.mitre.org/techniques/T1543/003/) | Windows Service | Persistence, Privilege Escalation | - -#### Search - -``` - -| from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line IS NOT NULL AND like(cmd_line, "%delete%") AND process_name = "sc.exe" -| eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) -| into write_ssa_detected_events(); -``` - -#### Macros -The SPL above uses the following Macros: - -Note that `attempt_to_delete_services_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* dest_device_id -* process_name -* parent_process_name -* process_path -* dest_user_id -* process -* cmd_line - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -It is possible administrative scripts may start/stop/delete services. Filter as needed. - -#### Associated Analytic story -* [XMRig](/stories/xmrig) -* [Ransomware](/stories/ransomware) - - -#### Kill Chain Phase -* Exploitation - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 36.0 | 60 | 60 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$ attempting to delete a service. | - - -Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` - - - -#### Reference - -* [https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/](https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1543.003/T1543.003.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1543.003/T1543.003.md) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/ssa_data1/sc_del.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/ssa_data1/sc_del.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/attempt_to_delete_services.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2021-11-24-attempt_to_disable_services.md b/docs/_posts/2021-11-24-attempt_to_disable_services.md deleted file mode 100644 index 273b5a26d8..0000000000 --- a/docs/_posts/2021-11-24-attempt_to_disable_services.md +++ /dev/null @@ -1,108 +0,0 @@ ---- -title: "Attempt To Disable Services" -excerpt: "Service Stop" -categories: - - Endpoint -last_modified_at: 2021-11-24 -toc: true -toc_label: "" -tags: - - Service Stop - - Impact - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies Windows Service Control, `sc.exe`, attempting to disable a service. This is typically identified in parallel with other instances of service enumeration of attempts to stop a service and then disable it. Adversaries utilize this technique to terminate security services or other related services to continue there objective and evade detections. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2021-11-24 -- **Author**: Teoderick Contreras, Splunk -- **ID**: afb31de4-d023-11eb-98d5-acde48001122 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1489](https://attack.mitre.org/techniques/T1489/) | Service Stop | Impact | - -#### Search - -``` - -| from read_ssa_enriched_events() -| eval _datamodels=ucast(map_get(input_event, "_datamodels"), "collection", []), body={} -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line IS NOT NULL AND like(cmd_line, "%disabled%") AND like(cmd_line, "%config%") AND process_name="sc.exe" -| eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) -| into write_ssa_detected_events(); -``` - -#### Macros -The SPL above uses the following Macros: - -Note that `attempt_to_disable_services_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* dest_device_id -* process_name -* parent_process_name -* process_path -* dest_user_id -* process - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -It is possible administrative scripts may start/stop/delete services. Filter as needed. - -#### Associated Analytic story -* [XMRig](/stories/xmrig) -* [Ransomware](/stories/ransomware) - - -#### Kill Chain Phase -* Exploitation - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 36.0 | 60 | 60 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$ attempting to disable a service. | - - -Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` - - - -#### Reference - -* [https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/](https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/) -* [https://app.any.run/tasks/c0f98850-af65-4352-9746-fbebadee4f05/](https://app.any.run/tasks/c0f98850-af65-4352-9746-fbebadee4f05/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1562.001/T1562.001.md#atomic-test-14---disable-arbitrary-security-windows-service](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1562.001/T1562.001.md#atomic-test-14---disable-arbitrary-security-windows-service) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/ssa_data1/sc_disable.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/ssa_data1/sc_disable.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/attempt_to_disable_services.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2021-11-25-add_or_set_windows_defender_exclusion.md b/docs/_posts/2021-11-25-add_or_set_windows_defender_exclusion.md deleted file mode 100644 index c4f1f46cc0..0000000000 --- a/docs/_posts/2021-11-25-add_or_set_windows_defender_exclusion.md +++ /dev/null @@ -1,172 +0,0 @@ ---- -title: "Add or Set Windows Defender Exclusion" -excerpt: "Disable or Modify Tools -, Impair Defenses -" -categories: - - Endpoint -last_modified_at: 2021-11-25 -toc: true -toc_label: "" -tags: - - Disable or Modify Tools - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic will identify a suspicious process command-line related to Windows Defender exclusion feature. This command is abused by adversaries, malware authors and red teams to bypass Windows Defender Antivirus products by excluding folder path, file path, process and extensions. From its real time or schedule scan to execute their malicious code. This is a good indicator for defense evasion and to look further for events after this behavior. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-11-25 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 773b66fe-4dd9-11ec-8289-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process = "*Add-MpPreference *" OR Processes.process = "*Set-MpPreference *") AND Processes.process="*-exclusion*" by Processes.dest Processes.user Processes.parent_process Processes.parent_process_name Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `add_or_set_windows_defender_exclusion_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **add_or_set_windows_defender_exclusion_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. - -#### Known False Positives -Admin or user may choose to use this windows features. Filter as needed. - -#### Associated Analytic story -* [Remcos](/stories/remcos) -* [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics) -* [WhisperGate](/stories/whispergate) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 64.0 | 80 | 80 | exclusion command $process$ executed on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://tccontre.blogspot.com/2020/01/remcos-rat-evading-windows-defender-av.html](https://tccontre.blogspot.com/2020/01/remcos-rat-evading-windows-defender-av.html) -* [https://app.any.run/tasks/cf1245de-06a7-4366-8209-8e3006f2bfe5/](https://app.any.run/tasks/cf1245de-06a7-4366-8209-8e3006f2bfe5/) -* [https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/](https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/defender_exclusion_sysmon/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/defender_exclusion_sysmon/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-11-25-powershell_windows_defender_exclusion_commands.md b/docs/_posts/2021-11-25-powershell_windows_defender_exclusion_commands.md deleted file mode 100644 index 9d367f82a9..0000000000 --- a/docs/_posts/2021-11-25-powershell_windows_defender_exclusion_commands.md +++ /dev/null @@ -1,164 +0,0 @@ ---- -title: "Powershell Windows Defender Exclusion Commands" -excerpt: "Disable or Modify Tools -, Impair Defenses -" -categories: - - Endpoint -last_modified_at: 2021-11-25 -toc: true -toc_label: "" -tags: - - Disable or Modify Tools - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic will detect a suspicious process commandline related to windows defender exclusion feature. This command is abused by adversaries, malware author and red teams to bypassed Windows Defender Anti-Virus product by excluding folder path, file path, process, extensions and etc. from its real time or schedule scan to execute their malicious code. This is a good indicator for defense evasion and to look further for events after this behavior. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-11-25 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 907ac95c-4dd9-11ec-ba2c-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 (Message = "*Add-MpPreference *" OR Message = "*Set-MpPreference *") AND Message = "*-exclusion*" -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `powershell_windows_defender_exclusion_commands_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **powershell_windows_defender_exclusion_commands_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Message -* ComputerName -* User - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. - -#### Known False Positives -admin or user may choose to use this windows features. - -#### Associated Analytic story -* [Remcos](/stories/remcos) -* [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics) -* [WhisperGate](/stories/whispergate) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 64.0 | 80 | 80 | exclusion command $Message$ executed on $ComputerName$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://tccontre.blogspot.com/2020/01/remcos-rat-evading-windows-defender-av.html](https://tccontre.blogspot.com/2020/01/remcos-rat-evading-windows-defender-av.html) -* [https://app.any.run/tasks/cf1245de-06a7-4366-8209-8e3006f2bfe5/](https://app.any.run/tasks/cf1245de-06a7-4366-8209-8e3006f2bfe5/) -* [https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/](https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/defender_exclusion_powershell/powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/defender_exclusion_powershell/powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-11-25-windows_defender_exclusion_registry_entry.md b/docs/_posts/2021-11-25-windows_defender_exclusion_registry_entry.md deleted file mode 100644 index a3e9f131d9..0000000000 --- a/docs/_posts/2021-11-25-windows_defender_exclusion_registry_entry.md +++ /dev/null @@ -1,171 +0,0 @@ ---- -title: "Windows Defender Exclusion Registry Entry" -excerpt: "Disable or Modify Tools -, Impair Defenses -" -categories: - - Endpoint -last_modified_at: 2021-11-25 -toc: true -toc_label: "" -tags: - - Disable or Modify Tools - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic will detect a suspicious process that modify a registry related to windows defender exclusion feature. This registry is abused by adversaries, malware author and red teams to bypassed Windows Defender Anti-Virus product by excluding folder path, file path, process, extensions and etc. from its real time or schedule scan to execute their malicious code. This is a good indicator for a defense evasion and to look further for events after this behavior. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-11-25 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 13395a44-4dd9-11ec-9df7-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path = "*\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Exclusions\\*" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid -| `drop_dm_object_name(Registry)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] -| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data -| `windows_defender_exclusion_registry_entry_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_defender_exclusion_registry_entry_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.registry_key_name -* Registry.registry_path -* Registry.user -* Registry.dest -* Registry.registry_value_name -* Registry.registry_value_data - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. - -#### Known False Positives -admin or user may choose to use this windows features. - -#### Associated Analytic story -* [Remcos](/stories/remcos) -* [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics) -* [Azorult](/stories/azorult) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 64.0 | 80 | 80 | exclusion registry $registry_path$ modified or added on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://tccontre.blogspot.com/2020/01/remcos-rat-evading-windows-defender-av.html](https://tccontre.blogspot.com/2020/01/remcos-rat-evading-windows-defender-av.html) -* [https://app.any.run/tasks/cf1245de-06a7-4366-8209-8e3006f2bfe5/](https://app.any.run/tasks/cf1245de-06a7-4366-8209-8e3006f2bfe5/) -* [https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/](https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/defender_exclusion_sysmon/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/defender_exclusion_sysmon/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-11-29-attempted_credential_dump_from_registry_via_reg_exe.md b/docs/_posts/2021-11-29-attempted_credential_dump_from_registry_via_reg_exe.md deleted file mode 100644 index 7f140e4ff3..0000000000 --- a/docs/_posts/2021-11-29-attempted_credential_dump_from_registry_via_reg_exe.md +++ /dev/null @@ -1,109 +0,0 @@ ---- -title: "Attempted Credential Dump From Registry via Reg exe" -excerpt: "OS Credential Dumping, Security Account Manager" -categories: - - Endpoint -last_modified_at: 2021-11-29 -toc: true -toc_label: "" -tags: - - OS Credential Dumping - - Credential Access - - Security Account Manager - - Credential Access - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the use of `reg.exe` attempting to export Windows registry keys that contain hashed credentials. Adversaries will utilize this technique to capture and perform offline password cracking. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2021-11-29 -- **Author**: Jose Hernandez, Splunk -- **ID**: 14038953-e5f2-4daf-acff-5452062baf03 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - -| [T1003.002](https://attack.mitre.org/techniques/T1003/002/) | Security Account Manager | Credential Access | - -#### Search - -``` - -| from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)) -| eval process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), dest_user_id=ucast(map_get(input_event, "dest_user_id"), "string", null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where process_name="cmd.exe" OR process_name="reg.exe" -| where cmd_line != null AND match_regex(cmd_line, /(?i)save\s+/)=true AND ( match_regex(cmd_line, /(?i)HKLM\\Security/)=true OR match_regex(cmd_line, /(?i)HKLM\\SAM/)=true OR match_regex(cmd_line, /(?i)HKLM\\System/)=true OR match_regex(cmd_line, /(?i)HKEY_LOCAL_MACHINE\\Security/)=true OR match_regex(cmd_line, /(?i)HKEY_LOCAL_MACHINE\\SAM/)=true OR match_regex(cmd_line, /(?i)HKEY_LOCAL_MACHINE\\System/)=true ) -| eval start_time = timestamp, end_time = timestamp, entities = mvappend(dest_device_id, dest_user_id), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name]) -| into write_ssa_detected_events(); -``` - -#### Macros -The SPL above uses the following Macros: - -Note that `attempted_credential_dump_from_registry_via_reg_exe_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* process_name -* _time -* dest_device_id -* dest_user_id -* process -* cmd_line - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -None identified. - -#### Associated Analytic story -* [Credential Dumping](/stories/credential_dumping) - - -#### Kill Chain Phase -* Actions on Objectives - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 63.0 | 70 | 90 | An attempt to save registry keys storing credentials has been performed on $dest_device_id$ by $dest_user_id$ via process $process_name$. | - - -Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` - - - -#### Reference - -* [https://github.com/splunk/security_content/blob/55a17c65f9f56c2220000b62701765422b46125d/detections/attempted_credential_dump_from_registry_via_reg_exe.yml](https://github.com/splunk/security_content/blob/55a17c65f9f56c2220000b62701765422b46125d/detections/attempted_credential_dump_from_registry_via_reg_exe.yml) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1003.002/T1003.002.md#atomic-test-1---registry-dump-of-sam-creds-and-secrets](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1003.002/T1003.002.md#atomic-test-1---registry-dump-of-sam-creds-and-secrets) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-11-29-deny_permission_using_cacls_utility.md b/docs/_posts/2021-11-29-deny_permission_using_cacls_utility.md deleted file mode 100644 index aad5d24494..0000000000 --- a/docs/_posts/2021-11-29-deny_permission_using_cacls_utility.md +++ /dev/null @@ -1,105 +0,0 @@ ---- -title: "Deny Permission using Cacls Utility" -excerpt: "File and Directory Permissions Modification" -categories: - - Endpoint -last_modified_at: 2021-11-29 -toc: true -toc_label: "" -tags: - - File and Directory Permissions Modification - - Defense Evasion - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the use of `cacls.exe`, `icacls.exe` or `xcacls.exe` placing the deny permission on a file or directory. Adversaries perform this behavior to prevent responders from reviewing or gaining access to adversary files on disk. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2021-11-29 -- **Author**: Teoderick Contreras, Splunk -- **ID**: b76eae28-cd25-11eb-9c92-acde48001122 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1222](https://attack.mitre.org/techniques/T1222/) | File and Directory Permissions Modification | Defense Evasion | - -#### Search - -``` - -| from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line IS NOT NULL AND match_regex(cmd_line, /(?i)deny/)=true AND (process_name="cacls.exe" OR process_name="xcacls.exe" OR process_name="icacls.exe") -| eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) -| into write_ssa_detected_events(); -``` - -#### Macros -The SPL above uses the following Macros: - -Note that `deny_permission_using_cacls_utility_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* dest_device_id -* process_name -* parent_process_name -* process_path -* dest_user_id -* process -* cmd_line - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed icacls.exe may be used. - -#### Known False Positives -System administrators may use cacls utilities but this is not a common practice. Filter as needed. - -#### Associated Analytic story -* [XMRig](/stories/xmrig) - - -#### Kill Chain Phase -* Exploitation - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 35.0 | 50 | 70 | A cacls process $process_name$ with commandline $cmd_line$ try to deny a permission of a file or directory in host $dest_device_id$ | - - -Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` - - - -#### Reference - -* [https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/](https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.001/ssa_cacls/all_icalc.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.001/ssa_cacls/all_icalc.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/deny_permission_using_cacls_utility.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2021-11-29-detect_dump_lsass_memory_using_comsvcs.md b/docs/_posts/2021-11-29-detect_dump_lsass_memory_using_comsvcs.md deleted file mode 100644 index 6887c2bd67..0000000000 --- a/docs/_posts/2021-11-29-detect_dump_lsass_memory_using_comsvcs.md +++ /dev/null @@ -1,107 +0,0 @@ ---- -title: "Detect Dump LSASS Memory using comsvcs" -excerpt: "NTDS, OS Credential Dumping" -categories: - - Endpoint -last_modified_at: 2021-11-29 -toc: true -toc_label: "" -tags: - - NTDS - - Credential Access - - OS Credential Dumping - - Credential Access - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies credential dumping using comsvcs.dll with `regsvr32.exe`. This technique is common with adversaries who would like to dump the memory of lsass.exe and perform offline password cracking. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2021-11-29 -- **Author**: Jose Hernandez, Splunk -- **ID**: 76bb9e35-f314-4c3d-a385-83c72a13ce4e - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1003.003](https://attack.mitre.org/techniques/T1003/003/) | NTDS | Credential Access | - -| [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - -#### Search - -``` - -| from read_ssa_enriched_events() -| eval tenant=ucast(map_get(input_event, "_tenant"), "string", null), machine=ucast(map_get(input_event, "dest_device_id"), "string", null), process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), process=lower(ucast(map_get(input_event, "process"), "string", null)), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where process IS NOT NULL AND process_name IS NOT NULL AND process_name LIKE "%rundll32.exe%" AND match_regex(process, /(?i)comsvcs.dll[,\s]+MiniDump/)=true -| eval start_time = timestamp, end_time = timestamp, entities = mvappend(machine), body=create_map(["event_id", event_id, "process_name", process_name, "process", process]) -| into write_ssa_detected_events(); -``` - -#### Macros -The SPL above uses the following Macros: - -Note that `detect_dump_lsass_memory_using_comsvcs_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* process_name -* _tenant -* _time -* dest_device_id -* process - - -#### How To Implement -You must be ingesting endpoint data that tracks process activity, including Windows command line logging. You can see how we test this with [Event Code 4688](https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=4688a) on the [attack_range](https://github.com/splunk/attack_range/blob/develop/ansible/roles/windows_common/tasks/windows-enable-4688-cmd-line-audit.yml). - -#### Known False Positives -False positives should be limited, filter as needed. - -#### Associated Analytic story -* [Credential Dumping](/stories/credential_dumping) - - -#### Kill Chain Phase -* Actions on Objectives - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 70.0 | 70 | 100 | A dump of lsass.exe was attempted using comsvcs.dll on endpoint $dest_device_id$ by user $dest_device_user$. | - - -Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` - - - -#### Reference - -* [https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf](https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1003.001/T1003.001.md#atomic-test-3---dump-lsassexe-memory-using-comsvcsdll](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1003.001/T1003.001.md#atomic-test-3---dump-lsassexe-memory-using-comsvcsdll) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.001/atomic_red_team/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.001/atomic_red_team/windows-security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/detect_dump_lsass_memory_using_comsvcs.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-11-29-detect_rclone_command-line_usage.md b/docs/_posts/2021-11-29-detect_rclone_command-line_usage.md deleted file mode 100644 index d15ca639fd..0000000000 --- a/docs/_posts/2021-11-29-detect_rclone_command-line_usage.md +++ /dev/null @@ -1,165 +0,0 @@ ---- -title: "Detect RClone Command-Line Usage" -excerpt: "Automated Exfiltration -" -categories: - - Endpoint -last_modified_at: 2021-11-29 -toc: true -toc_label: "" -tags: - - Automated Exfiltration - - Exfiltration - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic identifies commonly used command-line arguments used by `rclone.exe` to initiate a file transfer. Some arguments were negated as they are specific to the configuration used by adversaries. In particular, an adversary may list the files or directories of the remote file share using `ls` or `lsd`, which is not indicative of malicious behavior. During triage, at this stage of a ransomware event, exfiltration is about to occur or has already. Isolate the endpoint and continue investigating by review file modifications and parallel processes. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-11-29 -- **Author**: Michael Haag, Splunk -- **ID**: 32e0baea-b3f1-11eb-a2ce-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1020](https://attack.mitre.org/techniques/T1020/) | Automated Exfiltration | Exfiltration | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_rclone` Processes.process IN ("*copy*", "*mega*", "*pcloud*", "*ftp*", "*--config*", "*--progress*", "*--no-check-certificate*", "*--ignore-existing*", "*--auto-confirm*", "*--transfers*", "*--multi-thread-streams*") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_rclone_command_line_usage_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [process_rclone](https://github.com/splunk/security_content/blob/develop/macros/process_rclone.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **detect_rclone_command-line_usage_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id -* Processes.original_file_name - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -False positives should be limited as this is restricted to the Rclone process name. Filter or tune the analytic as needed. - -#### Associated Analytic story -* [DarkSide Ransomware](/stories/darkside_ransomware) -* [Ransomware](/stories/ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 35.0 | 50 | 70 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to connect to a remote cloud service to move files or folders. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://redcanary.com/blog/rclone-mega-extortion/](https://redcanary.com/blog/rclone-mega-extortion/) -* [https://www.mandiant.com/resources/shining-a-light-on-darkside-ransomware-operations](https://www.mandiant.com/resources/shining-a-light-on-darkside-ransomware-operations) -* [https://thedfirreport.com/2021/03/29/sodinokibi-aka-revil-ransomware/](https://thedfirreport.com/2021/03/29/sodinokibi-aka-revil-ransomware/) -* [https://thedfirreport.com/2021/11/29/continuing-the-bazar-ransomware-story/](https://thedfirreport.com/2021/11/29/continuing-the-bazar-ransomware-story/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1020/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1020/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/detect_rclone_command_line_usage.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-11-29-possible_lateral_movement_powershell_spawn.md b/docs/_posts/2021-11-29-possible_lateral_movement_powershell_spawn.md deleted file mode 100644 index 86a012dfd6..0000000000 --- a/docs/_posts/2021-11-29-possible_lateral_movement_powershell_spawn.md +++ /dev/null @@ -1,207 +0,0 @@ ---- -title: "Possible Lateral Movement PowerShell Spawn" -excerpt: "Remote Services -, Distributed Component Object Model -, Windows Remote Management -, Windows Management Instrumentation -, Scheduled Task -, Windows Service -, PowerShell -, MMC -" -categories: - - Endpoint -last_modified_at: 2021-11-29 -toc: true -toc_label: "" -tags: - - Remote Services - - Distributed Component Object Model - - Windows Remote Management - - Windows Management Instrumentation - - Scheduled Task - - Windows Service - - PowerShell - - MMC - - Lateral Movement - - Lateral Movement - - Lateral Movement - - Execution - - Execution - - Persistence - - Privilege Escalation - - Persistence - - Privilege Escalation - - Execution - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic assists with identifying a PowerShell process spawned as a child or grand child process of commonly abused processes during lateral movement techniques including `services.exe`, `wmiprsve.exe`, `svchost.exe`, `wsmprovhost.exe` and `mmc.exe`. Legitimate Windows features such as the Service Control Manager, Windows Management Instrumentation, Task Scheduler, Windows Remote Management and the DCOM protocol can be abused to start a process on a remote endpoint. Looking for PowerShell spawned out of this processes may reveal a lateral movement attack. Red Teams and adversaries alike may abuse these services during a breach for lateral movement and remote code execution. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-11-29 -- **Author**: Mauricio Velazco, Splunk -- **ID**: cb909b3e-512b-11ec-aa31-3e22fbd008af - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1021](https://attack.mitre.org/techniques/T1021/) | Remote Services | Lateral Movement | - -| [T1021.003](https://attack.mitre.org/techniques/T1021/003/) | Distributed Component Object Model | Lateral Movement | - -| [T1021.006](https://attack.mitre.org/techniques/T1021/006/) | Windows Remote Management | Lateral Movement | - -| [T1047](https://attack.mitre.org/techniques/T1047/) | Windows Management Instrumentation | Execution | - -| [T1053.005](https://attack.mitre.org/techniques/T1053/005/) | Scheduled Task | Execution, Persistence, Privilege Escalation | - -| [T1543.003](https://attack.mitre.org/techniques/T1543/003/) | Windows Service | Persistence, Privilege Escalation | - -| [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | - -| [T1218.014](https://attack.mitre.org/techniques/T1218/014/) | MMC | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.parent_process_name=wmiprvse.exe OR Processes.parent_process_name=services.exe OR Processes.parent_process_name=svchost.exe OR Processes.parent_process_name=wsmprovhost.exe OR Processes.parent_process_name=mmc.exe) (Processes.process_name=powershell.exe OR (Processes.process_name=cmd.exe AND Processes.process=*powershell.exe*) OR Processes.process_name=pwsh.exe OR (Processes.process_name=cmd.exe AND Processes.process=*pwsh.exe*)) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `possible_lateral_movement_powershell_spawn_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **possible_lateral_movement_powershell_spawn_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. - -#### Known False Positives -Legitimate applications may spawn PowerShell as a child process of the the identified processes. Filter as needed. - -#### Associated Analytic story -* [Hermetic Wiper](/stories/hermetic_wiper) -* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) -* [Malicious PowerShell](/stories/malicious_powershell) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 45.0 | 90 | 50 | A PowerShell process was spawned as a child process of typically abused processes on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1021/003/](https://attack.mitre.org/techniques/T1021/003/) -* [https://attack.mitre.org/techniques/T1021/006/](https://attack.mitre.org/techniques/T1021/006/) -* [https://attack.mitre.org/techniques/T1047/](https://attack.mitre.org/techniques/T1047/) -* [https://attack.mitre.org/techniques/T1053/005/](https://attack.mitre.org/techniques/T1053/005/) -* [https://attack.mitre.org/techniques/T1543/003/](https://attack.mitre.org/techniques/T1543/003/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1543.003/lateral_movement_powershell/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1543.003/lateral_movement_powershell/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/possible_lateral_movement_powershell_spawn.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-11-29-randomly_generated_scheduled_task_name.md b/docs/_posts/2021-11-29-randomly_generated_scheduled_task_name.md deleted file mode 100644 index 7b680ce19e..0000000000 --- a/docs/_posts/2021-11-29-randomly_generated_scheduled_task_name.md +++ /dev/null @@ -1,164 +0,0 @@ ---- -title: "Randomly Generated Scheduled Task Name" -excerpt: "Scheduled Task/Job -, Scheduled Task -" -categories: - - Endpoint -last_modified_at: 2021-11-29 -toc: true -toc_label: "" -tags: - - Scheduled Task/Job - - Scheduled Task - - Execution - - Persistence - - Privilege Escalation - - Execution - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following hunting analytic leverages Event ID 4698, `A scheduled task was created`, to identify the creation of a Scheduled Task with a suspicious, high entropy, Task Name. To achieve this, this analytic also leverages the `ut_shannon` function from the URL ToolBox Splunk application. Red teams and adversaries alike may abuse the Task Scheduler to create and start a remote Scheduled Task and obtain remote code execution. To achieve this goal, tools like Impacket or Crapmapexec, typically create a Scheduled Task with a random task name on the victim host. This hunting analytic may help defenders identify Scheduled Tasks created as part of a lateral movement attack. The entropy threshold `ut_shannon > 3` should be customized by users. The Command field can be used to determine if the task has malicious intent or not. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-11-29 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 9d22a780-5165-11ec-ad4f-3e22fbd008af - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1053](https://attack.mitre.org/techniques/T1053/) | Scheduled Task/Job | Execution, Persistence, Privilege Escalation | - -| [T1053.005](https://attack.mitre.org/techniques/T1053/005/) | Scheduled Task | Execution, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - `wineventlog_security` EventCode=4698 -| xmlkv Message -| lookup ut_shannon_lookup word as Task_Name -| where ut_shannon > 3 -| table _time, dest, Task_Name, ut_shannon, Command, Author, Enabled, Hidden -| `randomly_generated_scheduled_task_name_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) - -> :information_source: -> **randomly_generated_scheduled_task_name_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* dest -* Task_Name -* Description -* Command - - -#### How To Implement -To successfully implement this search, you need to be ingesting Windows Security Event Logs with 4698 EventCode enabled. The Windows TA as well as the URL ToolBox application are also required. - -#### Known False Positives -Legitimate applications may use random Scheduled Task names. - -#### Associated Analytic story -* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 45.0 | 90 | 50 | A windows scheduled task with a suspicious task name was created on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1053/005/](https://attack.mitre.org/techniques/T1053/005/) -* [https://splunkbase.splunk.com/app/2734/](https://splunkbase.splunk.com/app/2734/) -* [https://en.wikipedia.org/wiki/Entropy_(information_theory)](https://en.wikipedia.org/wiki/Entropy_(information_theory)) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/endpoint/randomly_generated_scheduled_task_name.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-11-29-randomly_generated_windows_service_name.md b/docs/_posts/2021-11-29-randomly_generated_windows_service_name.md deleted file mode 100644 index 8c0118f01d..0000000000 --- a/docs/_posts/2021-11-29-randomly_generated_windows_service_name.md +++ /dev/null @@ -1,161 +0,0 @@ ---- -title: "Randomly Generated Windows Service Name" -excerpt: "Create or Modify System Process -, Windows Service -" -categories: - - Endpoint -last_modified_at: 2021-11-29 -toc: true -toc_label: "" -tags: - - Create or Modify System Process - - Windows Service - - Persistence - - Privilege Escalation - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following hunting analytic leverages Event ID 7045, `A new service was installed in the system`, to identify the installation of a Windows Service with a suspicious, high entropy, Service Name. To achieve this, this analytic also leverages the `ut_shannon` function from the URL ToolBox Splunk application. Red teams and adversaries alike may abuse the Service Control Manager to create and start a remote Windows Service and obtain remote code execution. To achieve this goal, some tools like Metasploit, Cobalt Strike and Impacket, typically create a Windows Service with a random service name on the victim host. This hunting analytic may help defenders identify Windows Services installed as part of a lateral movement attack. The entropy threshold `ut_shannon > 3` should be customized by users. The Service_File_Name field can be used to determine if the Windows Service has malicious intent or not. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-11-29 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 2032a95a-5165-11ec-a2c3-3e22fbd008af - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1543](https://attack.mitre.org/techniques/T1543/) | Create or Modify System Process | Persistence, Privilege Escalation | - -| [T1543.003](https://attack.mitre.org/techniques/T1543/003/) | Windows Service | Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - `wineventlog_system` EventCode=7045 -| lookup ut_shannon_lookup word as Service_Name -| where ut_shannon > 3 -| table EventCode ComputerName Service_Name ut_shannon Service_Start_Type Service_Type Service_File_Name -| `randomly_generated_windows_service_name_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [wineventlog_system](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_system.yml) - -> :information_source: -> **randomly_generated_windows_service_name_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* ComputerName -* Service_File_Name -* Service_Type -* Service_Name -* Service_Start_Type - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the Service name, Service File Name Service Start type, and Service Type from your endpoints. The Windows TA as well as the URL ToolBox application are also required. - -#### Known False Positives -Legitimate applications may use random Windows Service names. - -#### Associated Analytic story -* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 45.0 | 90 | 50 | A Windows Service with a suspicious service name was installed on $ComputerName$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1543/003/](https://attack.mitre.org/techniques/T1543/003/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/endpoint/randomly_generated_windows_service_name.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-11-30-delete_a_net_user.md b/docs/_posts/2021-11-30-delete_a_net_user.md deleted file mode 100644 index e900f9596a..0000000000 --- a/docs/_posts/2021-11-30-delete_a_net_user.md +++ /dev/null @@ -1,107 +0,0 @@ ---- -title: "Delete A Net User" -excerpt: "Account Access Removal" -categories: - - Endpoint -last_modified_at: 2021-11-30 -toc: true -toc_label: "" -tags: - - Account Access Removal - - Impact - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic will detect a suspicious net.exe/net1.exe command-line to delete a user on a system. This technique may be use by an administrator for legitimate purposes, however this behavior has been used in the wild to impair some user or deleting adversaries tracks created during its lateral movement additional systems. During triage, review parallel processes for additional behavior. Identify any other user accounts created before or after. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2021-11-30 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 8776d79c-d26e-11eb-9a56-acde48001122 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1531](https://attack.mitre.org/techniques/T1531/) | Account Access Removal | Impact | - -#### Search - -``` - -| from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line IS NOT NULL AND like(cmd_line, "%/delete%") AND (process_name="net1.exe" OR process_name="net.exe") -| eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) -| into write_ssa_detected_events(); -``` - -#### Macros -The SPL above uses the following Macros: - -Note that `delete_a_net_user_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* dest_device_id -* process_name -* parent_process_name -* process_path -* dest_user_id -* process -* cmd_line - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed net.exe may be used. - -#### Known False Positives -System administrators or scripts may delete user accounts via this technique. Filter as needed. - -#### Associated Analytic story -* [XMRig](/stories/xmrig) -* [Ransomware](/stories/ransomware) - - -#### Kill Chain Phase -* Exploitation - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$ attempting to delete a user account. | - - -Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` - - - -#### Reference - -* [https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/](https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/ssa_data1/net_user_del.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/ssa_data1/net_user_del.log) -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1531/atomic_red_team/security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1531/atomic_red_team/security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/delete_a_net_user.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2021-11-30-disable_net_user_account.md b/docs/_posts/2021-11-30-disable_net_user_account.md deleted file mode 100644 index 338948cfad..0000000000 --- a/docs/_posts/2021-11-30-disable_net_user_account.md +++ /dev/null @@ -1,113 +0,0 @@ ---- -title: "Disable Net User Account" -excerpt: "Service Stop, Valid Accounts" -categories: - - Endpoint -last_modified_at: 2021-11-30 -toc: true -toc_label: "" -tags: - - Service Stop - - Impact - - Valid Accounts - - Defense Evasion - - Persistence - - Privilege Escalation - - Initial Access - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic will identify a suspicious command-line that disables a user account using the native `net.exe` or `net1.exe` utility to Windows. This technique may used by the adversaries to interrupt availability of accounts and continue the impact against the organization. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2021-11-30 -- **Author**: Teoderick Contreras, Splunk -- **ID**: ba858b08-d26c-11eb-af9b-acde48001122 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1489](https://attack.mitre.org/techniques/T1489/) | Service Stop | Impact | - -| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - -#### Search - -``` - -| from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line IS NOT NULL AND like(cmd_line, "%/active:no%") AND like(cmd_line, "%user%") AND (process_name="net1.exe" OR process_name="net.exe") -| eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) -| into write_ssa_detected_events(); -``` - -#### Macros -The SPL above uses the following Macros: - -Note that `disable_net_user_account_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* dest_device_id -* process_name -* parent_process_name -* process_path -* dest_user_id -* process -* cmd_line - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed net.exe/net1.exe may be used. - -#### Known False Positives -System administrators or automated scripts may disable an account but not a common practice. Filter as needed. - -#### Associated Analytic story -* [XMRig](/stories/xmrig) -* [Ransomware](/stories/ransomware) - - -#### Kill Chain Phase -* Exploitation - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$ attempting to disable accounts. | - - -Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` - - - -#### Reference - -* [https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/](https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/ssa_data1/net_user_dis.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/ssa_data1/net_user_dis.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disable_net_user_account.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2021-11-30-first_time_seen_command_line_argument.md b/docs/_posts/2021-11-30-first_time_seen_command_line_argument.md deleted file mode 100644 index 772947375d..0000000000 --- a/docs/_posts/2021-11-30-first_time_seen_command_line_argument.md +++ /dev/null @@ -1,112 +0,0 @@ ---- -title: "First time seen command line argument" -excerpt: "Command and Scripting Interpreter, Indirect Command Execution" -categories: - - Endpoint -last_modified_at: 2021-11-30 -toc: true -toc_label: "" -tags: - - Command and Scripting Interpreter - - Execution - - Indirect Command Execution - - Defense Evasion - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - -### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for command-line arguments that use a `/c` parameter to execute a command that has not previously been seen. This is an implementation on SPL2 of the rule `First time seen command line argument` by @bpatel. 'The following analytic identifies first time seen command-line arguments on a single endpoint. The analytic looks for arguments instantiated by `cmd.exe /c` and the associated command-line. Adversaries automate or spawn multiple processes using this method, this analytic may assist with identifying the first time it's been found on this endpoint.' - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2021-11-30 -- **Author**: Ignacio Bermudez Corrales, Splunk -- **ID**: fc0edc95-ff2b-48b0-9f6f-63da3789fd23 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -| [T1202](https://attack.mitre.org/techniques/T1202/) | Indirect Command Execution | Defense Evasion | - -#### Search - -``` - -| from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)) -| eval dest_user_id=ucast(map_get(input_event, "dest_user_id"), "string", null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), "string", null), process_name=ucast(map_get(input_event, "process_name"), "string", null), cmd_line=ucast(map_get(input_event, "process"), "string", null), cmd_line_norm=lower(cmd_line), cmd_line_norm=replace(cmd_line_norm, /[0-9a-f]{8}-[0-9a-f]{4}-[1-5][0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}/, "GUID"), cmd_line_norm=replace(cmd_line_norm, /(?<=\s)+\\[^:]*(?=\\.*\.\w{3}(\s -|$)+)/, "\\PATH"), /* replaces " \\Something\\Something\\command.ext" => "PATH\\command.ext" */ cmd_line_norm=replace(cmd_line_norm, /\w:\\[^:]*(?=\\.*\.\w{3}(\s -|$)+)/, "\\PATH"), /* replaces "C:\\Something\\Something\\command.ext" => "PATH\\command.ext" */ cmd_line_norm=replace(cmd_line_norm, /\d+/, "N"), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where process_name="cmd.exe" AND match_regex(ucast(cmd_line, "string", ""), /.* \/[cC] .*/)=true -| select process_name, cmd_line, cmd_line_norm, timestamp, dest_device_id, dest_user_id -| first_time_event input_columns=["cmd_line_norm"] -| where first_time_cmd_line_norm -| eval start_time = timestamp, end_time = timestamp, entities = mvappend(dest_device_id, dest_user_id), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name]) -| into write_ssa_detected_events(); -``` - -#### Macros -The SPL above uses the following Macros: - -Note that `first_time_seen_command_line_argument_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* process_name -* _time -* dest_device_id -* dest_user_id -* process -* cmd_line - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -Legitimate programs use command-line arguments to execute. Verify the command-line arguments to check what command/program is being executed. Filtering will be needed. - -#### Associated Analytic story -* [Unusual Processes](/stories/unusual_processes) - - -#### Kill Chain Phase -* Command and Control -* Actions on Objectives - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 30.0 | 50 | 60 | A process $process_name$ ha been identified in the environment with a command-line $cmd_line$ not previously seen before on host $dest_device_id$ | - - -Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` - - - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/endpoint/first_time_seen_command_line_argument.yml) \| *version*: **4** \ No newline at end of file diff --git a/docs/_posts/2021-11-30-grant_permission_using_cacls_utility.md b/docs/_posts/2021-11-30-grant_permission_using_cacls_utility.md deleted file mode 100644 index 82e83d9b3e..0000000000 --- a/docs/_posts/2021-11-30-grant_permission_using_cacls_utility.md +++ /dev/null @@ -1,105 +0,0 @@ ---- -title: "Grant Permission Using Cacls Utility" -excerpt: "File and Directory Permissions Modification" -categories: - - Endpoint -last_modified_at: 2021-11-30 -toc: true -toc_label: "" -tags: - - File and Directory Permissions Modification - - Defense Evasion - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the use of `cacls.exe`, `icacls.exe` or `xcacls.exe` placing the grant permission on a file or directory. Adversaries perform this behavior to allow components of their files to run, however it allows responders to review or gaining access to adversary files on disk. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2021-11-30 -- **Author**: Teoderick Contreras, Splunk -- **ID**: c6da561a-cd29-11eb-ae65-acde48001122 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1222](https://attack.mitre.org/techniques/T1222/) | File and Directory Permissions Modification | Defense Evasion | - -#### Search - -``` - -| from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line IS NOT NULL AND match_regex(cmd_line, /(?i)grant/)=true AND (process_name="cacls.exe" OR process_name="xcacls.exe" OR process_name="icacls.exe") -| eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) -| into write_ssa_detected_events(); -``` - -#### Macros -The SPL above uses the following Macros: - -Note that `grant_permission_using_cacls_utility_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* dest_device_id -* process_name -* parent_process_name -* process_path -* dest_user_id -* process -* cmd_line - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed icacls.exe may be used. - -#### Known False Positives -System administrators may use cacls utilities but this is not a common practice. Filter as needed. - -#### Associated Analytic story -* [XMRig](/stories/xmrig) - - -#### Kill Chain Phase -* Exploitation - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 35.0 | 50 | 70 | A cacls process $process_name$ with commandline $cmd_line$ try to grant user a permission to a file or directory in host $dest_device_id$ | - - -Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` - - - -#### Reference - -* [https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/](https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.001/ssa_cacls/all_icalc.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.001/ssa_cacls/all_icalc.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/grant_permission_using_cacls_utility.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2021-11-30-modify_acls_permission_of_files_or_folders.md b/docs/_posts/2021-11-30-modify_acls_permission_of_files_or_folders.md deleted file mode 100644 index 85e019e720..0000000000 --- a/docs/_posts/2021-11-30-modify_acls_permission_of_files_or_folders.md +++ /dev/null @@ -1,105 +0,0 @@ ---- -title: "Modify ACLs Permission Of Files Or Folders" -excerpt: "File and Directory Permissions Modification" -categories: - - Endpoint -last_modified_at: 2021-11-30 -toc: true -toc_label: "" -tags: - - File and Directory Permissions Modification - - Defense Evasion - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic identifies suspicious modification of ACL permission to a files or folder to make it available to everyone or to a specific user. This technique may be used by the adversary to evade ACLs or protected files access. This changes is commonly configured by the file or directory owner with appropriate permission. This behavior raises suspicion if this command is seen on an endpoint utilized by an account with no permission to do so. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2021-11-30 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 9ae9a48a-cdbe-11eb-875a-acde48001122 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1222](https://attack.mitre.org/techniques/T1222/) | File and Directory Permissions Modification | Defense Evasion | - -#### Search - -``` - -| from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line IS NOT NULL AND like(cmd_line, "%/G%") AND (match_regex(cmd_line, /(?i)everyone:/)=true OR match_regex(cmd_line, /(?i)SYSTEM:/)=true) AND (process_name="cacls.exe" OR process_name="xcacls.exe" OR process_name="icacls.exe") -| eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) -| into write_ssa_detected_events(); -``` - -#### Macros -The SPL above uses the following Macros: - -Note that `modify_acls_permission_of_files_or_folders_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* dest_device_id -* process_name -* parent_process_name -* process_path -* dest_user_id -* process -* cmd_line - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed cacls.exe may be used. - -#### Known False Positives -System administrators may use this windows utility. filter is needed. - -#### Associated Analytic story -* [XMRig](/stories/xmrig) - - -#### Kill Chain Phase -* Exploitation - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 35.0 | 50 | 70 | A cacls process $process_name$ with commandline $cmd_line$ try to modify a permission of a file or directory in host $dest_device_id$ | - - -Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` - - - -#### Reference - -* [https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/](https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.001/ssa_cacls/all_icalc.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.001/ssa_cacls/all_icalc.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/modify_acls_permission_of_files_or_folders.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-11-30-potential_pass_the_token_or_hash_observed_at_the_destination_device.md b/docs/_posts/2021-11-30-potential_pass_the_token_or_hash_observed_at_the_destination_device.md deleted file mode 100644 index cb904cf6c1..0000000000 --- a/docs/_posts/2021-11-30-potential_pass_the_token_or_hash_observed_at_the_destination_device.md +++ /dev/null @@ -1,119 +0,0 @@ ---- -title: "Potential Pass the Token or Hash Observed at the Destination Device" -excerpt: "Use Alternate Authentication Material, Pass the Hash" -categories: - - Endpoint -last_modified_at: 2021-11-30 -toc: true -toc_label: "" -tags: - - Use Alternate Authentication Material - - Defense Evasion - - Lateral Movement - - Pass the Hash - - Defense Evasion - - Lateral Movement - - Splunk Behavioral Analytics - - Authentication ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This detection identifies potential Pass the Token or Pass the Hash credential stealing. We detect the main side effect of these attacks, which is a transition from the dominant Kerberos logins to rare NTLM logins for a given user, as reported by a detination device. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Authentication](https://docs.splunk.com/Documentation/CIM/latest/User/Authentication) -- **Last Updated**: 2021-11-30 -- **Author**: Stanislav Miskovic, Splunk -- **ID**: 82e76b80-5cdb-4899-9b43-85dbe777b36d - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1550](https://attack.mitre.org/techniques/T1550/) | Use Alternate Authentication Material | Defense Evasion, Lateral Movement | - -| [T1550.002](https://attack.mitre.org/techniques/T1550/002/) | Pass the Hash | Defense Evasion, Lateral Movement | - -#### Search - -``` - -| from read_ssa_enriched_events() -| where "Authentication" IN(_datamodels) -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), dest_user=lower(ucast(map_get(input_event, "dest_user_primary_artifact"), "string", null)), dest_user_id= ucast(map_get(input_event, "dest_user_id"), "string", null), dest_device_id= ucast(map_get(input_event, "dest_device_id"), "string", null), signature_id= lower(ucast(map_get(input_event, "signature_id"), "string", null)), authentication_method= lower(ucast(map_get(input_event, "authentication_method"), "string", null)), event_id=ucast(map_get(input_event, "event_id"), "string", null) - -| where signature_id = "4624" AND (authentication_method="ntlmssp" OR authentication_method="kerberos") AND dest_user_id != null AND dest_device_id != null - -| eval isKerberos=if(authentication_method == "kerberos", 1, 0), isNtlm=if(authentication_method == "ntlmssp", 1, 0), timeNTLM=if(isNtlm > 0, timestamp, null) - -| stats sum(isKerberos) as totalKerberos, sum(isNtlm) as totalNtlm, min(timestamp) as startTime, min(timeNTLM) as startNTLMTime, max(timestamp) as endTime, max(timeNTLM) as endNTLMTime by dest_user_id, dest_user, dest_device_id, span(timestamp, 86400s) - -| where NOT dest_user="-" AND totalKerberos > 0 AND totalNtlm > 0 AND endTime - startTime > 1800000 AND (totalKerberos > 10 * totalNtlm AND totalKerberos > 50) AND (endTime - startTime) > 3 * (endNTLMTime - startNTLMTime) - -| eval start_time=ucast(startNTLMTime, "long", null), end_time=ucast(endNTLMTime, "long", null), entities=mvappend(dest_user_id, dest_device_id), body=create_map(["event_id", event_id, "total_kerberos", totalKerberos, "total_ntlm", totalNtlm, "analysis_start_time", startTime, "analysis_end_time", endTime, "pth_start_time", startNTLMTime, "pth_end_time", endNTLMTime]) - -| into write_ssa_detected_events(); -``` - -#### Macros -The SPL above uses the following Macros: - -Note that `potential_pass_the_token_or_hash_observed_at_the_destination_device_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* signature_id -* dest_user -* dest_user_id -* dest_device_id -* authentication_method - - -#### How To Implement -You must be ingesting Windows Security logs from endpoint devices, i.e., destinations of interest. Please make sure that event ID 4624 is being logged. - -#### Known False Positives -Environments in which NTLM is used extremely rarely and for benign purposes (such as a rare use of SMB shares). - -#### Associated Analytic story -* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) - - -#### Kill Chain Phase -* Lateral Movement - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 72.0 | 80 | 90 | Potential lateral movement and credential stealing via Pass the Token or Pass the Hash techniques. Operation is performed via credentials of the account $dest_user_id$ and observed by the destination device $dest_device_id$ | - - -Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` - - - -#### Reference - -* [https://attack.mitre.org/techniques/T1550/002/](https://attack.mitre.org/techniques/T1550/002/) -* [https://www.offensive-security.com/metasploit-unleashed/psexec-pass-hash/](https://www.offensive-security.com/metasploit-unleashed/psexec-pass-hash/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/potential_pass_the_token_or_hash_observed_at_the_destination_device.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2021-11-30-rare_parent-child_process_relationship.md b/docs/_posts/2021-11-30-rare_parent-child_process_relationship.md deleted file mode 100644 index c0f55a8d7b..0000000000 --- a/docs/_posts/2021-11-30-rare_parent-child_process_relationship.md +++ /dev/null @@ -1,121 +0,0 @@ ---- -title: "Rare Parent-Child Process Relationship" -excerpt: "Exploitation for Client Execution, Command and Scripting Interpreter, Scheduled Task/Job, Software Deployment Tools" -categories: - - Endpoint -last_modified_at: 2021-11-30 -toc: true -toc_label: "" -tags: - - Exploitation for Client Execution - - Execution - - Command and Scripting Interpreter - - Execution - - Scheduled Task/Job - - Execution - - Persistence - - Privilege Escalation - - Software Deployment Tools - - Execution - - Lateral Movement - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - -### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -An attacker may use LOLBAS tools spawned from vulnerable applications not typically used by system administrators. This analytic leverages the Splunk Streaming ML DSP plugin to find rare parent/child relationships. The list of application has been extracted from https://github.com/LOLBAS-Project/LOLBAS/tree/master/yml/OSBinaries - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2021-11-30 -- **Author**: Peter Gael, Splunk; Ignacio Bermudez Corrales, Splunk -- **ID**: cf090c78-bcc6-11eb-8529-0242ac130003 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1203](https://attack.mitre.org/techniques/T1203/) | Exploitation for Client Execution | Execution | - -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -| [T1053](https://attack.mitre.org/techniques/T1053/) | Scheduled Task/Job | Execution, Persistence, Privilege Escalation | - -| [T1072](https://attack.mitre.org/techniques/T1072/) | Software Deployment Tools | Execution, Lateral Movement | - -#### Search - -``` - -| from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)) -| eval parent_process=lower(ucast(map_get(input_event, "parent_process_name"), "string", null)), parent_process_name=mvindex(split(parent_process, "\\"), -1), process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), dest_user_id=ucast(map_get(input_event, "dest_user_id"), "string", null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where parent_process_name!=null -| select parent_process_name, process_name, cmd_line, timestamp, dest_device_id, dest_user_id -| conditional_anomaly conditional="parent_process_name" target="process_name" -| where (process_name="powershell.exe" OR process_name="regsvcs.exe" OR process_name="ftp.exe" OR process_name="dfsvc.exe" OR process_name="rasautou.exe" OR process_name="schtasks.exe" OR process_name="xwizard.exe" OR process_name="findstr.exe" OR process_name="esentutl.exe" OR process_name="cscript.exe" OR process_name="reg.exe" OR process_name="csc.exe" OR process_name="atbroker.exe" OR process_name="print.exe" OR process_name="pcwrun.exe" OR process_name="vbc.exe" OR process_name="rpcping.exe" OR process_name="wsreset.exe" OR process_name="ilasm.exe" OR process_name="certutil.exe" OR process_name="replace.exe" OR process_name="mshta.exe" OR process_name="bitsadmin.exe" OR process_name="wscript.exe" OR process_name="ieexec.exe" OR process_name="cmd.exe" OR process_name="microsoft.workflow.compiler.exe" OR process_name="runscripthelper.exe" OR process_name="makecab.exe" OR process_name="forfiles.exe" OR process_name="desktopimgdownldr.exe" OR process_name="control.exe" OR process_name="msbuild.exe" OR process_name="register-cimprovider.exe" OR process_name="tttracer.exe" OR process_name="ie4uinit.exe" OR process_name="sc.exe" OR process_name="bash.exe" OR process_name="hh.exe" OR process_name="cmstp.exe" OR process_name="mmc.exe" OR process_name="jsc.exe" OR process_name="scriptrunner.exe" OR process_name="odbcconf.exe" OR process_name="extexport.exe" OR process_name="msdt.exe" OR process_name="diskshadow.exe" OR process_name="extrac32.exe" OR process_name="eventvwr.exe" OR process_name="mavinject.exe" OR process_name="regasm.exe" OR process_name="gpscript.exe" OR process_name="rundll32.exe" OR process_name="regsvr32.exe" OR process_name="regedit.exe" OR process_name="msiexec.exe" OR process_name="gfxdownloadwrapper.exe" OR process_name="presentationhost.exe" OR process_name="regini.exe" OR process_name="wmic.exe" OR process_name="runonce.exe" OR process_name="syncappvpublishingserver.exe" OR process_name="verclsid.exe" OR process_name="psr.exe" OR process_name="infdefaultinstall.exe" OR process_name="explorer.exe" OR process_name="expand.exe" OR process_name="installutil.exe" OR process_name="netsh.exe" OR process_name="wab.exe" OR process_name="dnscmd.exe" OR process_name="at.exe" OR process_name="pcalua.exe" OR process_name="cmdkey.exe" OR process_name="msconfig.exe") -| eval input = (-1)*log(output) -| adaptive_threshold algorithm="gaussian" threshold=0.001 window=604800000L -| where label AND input > mean -| eval start_time = timestamp, end_time = timestamp, entities = mvappend(dest_device_id, dest_user_id), body = create_map(["process_name", process_name, "parent_process_name", parent_process_name, "input", input, "mean", mean, "variance", variance, "output", output, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); -``` - -#### Macros -The SPL above uses the following Macros: - -Note that `rare_parent-child_process_relationship_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* process -* process_name -* parent_process_name -* _time -* dest_device_id -* dest_user_id -* cmd_line - - -#### How To Implement -Collect endpoint data such as sysmon or 4688 events. - -#### Known False Positives -Some custom tools used by administrators could be used rarely to launch remotely applications. This might trigger false positives at the beginning when it has not collected yet enough data to construct the baseline. - -#### Associated Analytic story -* [Unusual Processes](/stories/unusual_processes) - - -#### Kill Chain Phase -* Exploitation - - - - -Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` - - - -#### Reference - -* [https://github.com/LOLBAS-Project/LOLBAS/tree/master/yml/OSBinaries](https://github.com/LOLBAS-Project/LOLBAS/tree/master/yml/OSBinaries) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/endpoint/rare_parent-child_process_relationship.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-11-30-resize_shadowstorage_volume.md b/docs/_posts/2021-11-30-resize_shadowstorage_volume.md deleted file mode 100644 index ce8824c5ba..0000000000 --- a/docs/_posts/2021-11-30-resize_shadowstorage_volume.md +++ /dev/null @@ -1,107 +0,0 @@ ---- -title: "Resize Shadowstorage Volume" -excerpt: "Service Stop" -categories: - - Endpoint -last_modified_at: 2021-11-30 -toc: true -toc_label: "" -tags: - - Service Stop - - Impact - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the resizing of shadowstorage using vssadmin.exe to avoid the shadow volumes being made again. This technique is typically found used by adversaries during a ransomware event and a precursor to deleting the shadowstorage. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2021-11-30 -- **Author**: Teoderick Contreras, Splunk -- **ID**: dbc30554-d27e-11eb-9e5e-acde48001122 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1489](https://attack.mitre.org/techniques/T1489/) | Service Stop | Impact | - -#### Search - -``` - -| from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line IS NOT NULL AND like(cmd_line, "%resize%") AND like(cmd_line, "%shadowstorage%") AND like(cmd_line, "%maxsize%") AND process_name="vssadmin.exe" -| eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) -| into write_ssa_detected_events(); -``` - -#### Macros -The SPL above uses the following Macros: - -Note that `resize_shadowstorage_volume_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* dest_device_id -* process_name -* parent_process_name -* process_path -* dest_user_id -* process -* cmd_line - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -System administrators may resize the shadowstorage for valid purposes. Filter as needed. - -#### Associated Analytic story -* [Clop Ransomware](/stories/clop_ransomware) -* [Ransomware](/stories/ransomware) - - -#### Kill Chain Phase -* Exploitation - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 64.0 | 80 | 80 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$ attempting to create a shadow copy to perform offline password cracking. | - - -Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` - - - -#### Reference - -* [https://www.fireeye.com/blog/threat-research/2020/10/fin11-email-campaigns-precursor-for-ransomware-data-theft.html](https://www.fireeye.com/blog/threat-research/2020/10/fin11-email-campaigns-precursor-for-ransomware-data-theft.html) -* [https://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html](https://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/ssa_data1/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/ssa_data1/windows-security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/resize_shadowstorage_volume.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2021-12-01-unusual_number_of_computer_service_tickets_requested.md b/docs/_posts/2021-12-01-unusual_number_of_computer_service_tickets_requested.md deleted file mode 100644 index 3cf570d475..0000000000 --- a/docs/_posts/2021-12-01-unusual_number_of_computer_service_tickets_requested.md +++ /dev/null @@ -1,161 +0,0 @@ ---- -title: "Unusual Number of Computer Service Tickets Requested" -excerpt: "Valid Accounts -" -categories: - - Endpoint -last_modified_at: 2021-12-01 -toc: true -toc_label: "" -tags: - - Valid Accounts - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following hunting analytic leverages Event ID 4769, `A Kerberos service ticket was requested`, to identify an unusual number of computer service ticket requests from one source. When a domain joined endpoint connects to a remote endpoint, it first will request a Kerberos Ticket with the computer name as the Service Name. An endpoint requesting a large number of computer service tickets for different endpoints could represent malicious behavior like lateral movement, malware staging, reconnaissance, etc.\ -The detection calculates the standard deviation for each host and leverages the 3-sigma statistical rule to identify an unusual number of service requests. To customize this analytic, users can try different combinations of the `bucket` span time, the calculation of the `upperBound` field as well as the Outlier calculation. This logic can be used for real time security monitoring as well as threat hunting exercises.\ - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-12-01 -- **Author**: Mauricio Velazco, Splunk -- **ID**: ac3b81c0-52f4-11ec-ac44-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - `wineventlog_security` EventCode=4769 Service_Name="*$" Account_Name!="*$*" -| bucket span=2m _time -| stats dc(Service_Name) AS unique_targets values(Service_Name) as host_targets by _time, Client_Address, Account_Name -| eventstats avg(unique_targets) as comp_avg , stdev(unique_targets) as comp_std by Client_Address, Account_Name -| eval upperBound=(comp_avg+comp_std*3) -| eval isOutlier=if(unique_targets >10 and unique_targets >= upperBound, 1, 0) -| `unusual_number_of_computer_service_tickets_requested_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) - -> :information_source: -> **unusual_number_of_computer_service_tickets_requested_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Ticket_Options -* Ticket_Encryption_Type -* dest -* service -* service_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting Domain Controller and Kerberos events. The Advanced Security Audit policy setting `Audit Kerberos Authentication Service` within `Account Logon` needs to be enabled. - -#### Known False Positives -An single endpoint requesting a large number of computer service tickets is not common behavior. Possible false positive scenarios include but are not limited to vulnerability scanners, administration systeams and missconfigured systems. - -#### Associated Analytic story -* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) -* [Active Directory Kerberos Attacks](/stories/active_directory_kerberos_attacks) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 42.0 | 70 | 60 | | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1078/](https://attack.mitre.org/techniques/T1078/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/endpoint/unusual_number_of_computer_service_tickets_requested.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-01-unusual_number_of_remote_endpoint_authentication_events.md b/docs/_posts/2021-12-01-unusual_number_of_remote_endpoint_authentication_events.md deleted file mode 100644 index f3bc05c48a..0000000000 --- a/docs/_posts/2021-12-01-unusual_number_of_remote_endpoint_authentication_events.md +++ /dev/null @@ -1,161 +0,0 @@ ---- -title: "Unusual Number of Remote Endpoint Authentication Events" -excerpt: "Valid Accounts -" -categories: - - Endpoint -last_modified_at: 2021-12-01 -toc: true -toc_label: "" -tags: - - Valid Accounts - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following hunting analytic leverages Event ID 4624, `An account was successfully logged on`, to identify an unusual number of remote authentication attempts coming from one source. An endpoint authenticating to a large number of remote endpoints could represent malicious behavior like lateral movement, malware staging, reconnaissance, etc.\ -The detection calculates the standard deviation for each host and leverages the 3-sigma statistical rule to identify an unusual high number of authentication events. To customize this analytic, users can try different combinations of the `bucket` span time, the calculation of the `upperBound` field as well as the Outlier calculation. This logic can be used for real time security monitoring as well as threat hunting exercises.\ - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-12-01 -- **Author**: Mauricio Velazco, Splunk -- **ID**: acb5dc74-5324-11ec-a36d-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - `wineventlog_security` EventCode=4624 Logon_Type=3 Account_Name!="*$" -| eval Source_Account = mvindex(Account_Name, 1) -| bucket span=2m _time -| stats dc(ComputerName) AS unique_targets values(ComputerName) as target_hosts by _time, Source_Network_Address, Source_Account -| eventstats avg(unique_targets) as comp_avg , stdev(unique_targets) as comp_std by Source_Network_Address, Source_Account -| eval upperBound=(comp_avg+comp_std*3) -| eval isOutlier=if(unique_targets >10 and unique_targets >= upperBound, 1, 0) -| `unusual_number_of_remote_endpoint_authentication_events_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) - -> :information_source: -> **unusual_number_of_remote_endpoint_authentication_events_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Logon_Type -* Caller_Process_Name -* Security_ID -* Account_Name -* ComputerName - - -#### How To Implement -To successfully implement this search, you need to be ingesting Windows Event Logs from domain controllers aas well as member servers and workstations. The Advanced Security Audit policy setting `Audit Logon` within `Logon/Logoff` needs to be enabled. - -#### Known False Positives -An single endpoint authenticating to a large number of hosts is not common behavior. Possible false positive scenarios include but are not limited to vulnerability scanners, jump servers and missconfigured systems. - -#### Associated Analytic story -* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 42.0 | 70 | 60 | | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1078/](https://attack.mitre.org/techniques/T1078/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/endpoint/unusual_number_of_remote_endpoint_authentication_events.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-03-detect_rclone_command-line_usage.md b/docs/_posts/2021-12-03-detect_rclone_command-line_usage.md deleted file mode 100644 index f6d9b3b970..0000000000 --- a/docs/_posts/2021-12-03-detect_rclone_command-line_usage.md +++ /dev/null @@ -1,111 +0,0 @@ ---- -title: "Detect RClone Command-Line Usage" -excerpt: "Automated Exfiltration" -categories: - - Endpoint -last_modified_at: 2021-12-03 -toc: true -toc_label: "" -tags: - - Automated Exfiltration - - Exfiltration - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic identifies commonly used command-line arguments used by `rclone.exe` to initiate a file transfer. Some arguments were negated as they are specific to the configuration used by adversaries. In particular, an adversary may list the files or directories of the remote file share using `ls` or `lsd`, which is not indicative of malicious behavior. During triage, at this stage of a ransomware event, exfiltration is about to occur or has already. Isolate the endpoint and continue investigating by review file modifications and parallel processes. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2021-12-03 -- **Author**: Michael Haag, Splunk -- **ID**: e8b74268-5454-11ec-a799-acde48001122 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1020](https://attack.mitre.org/techniques/T1020/) | Automated Exfiltration | Exfiltration | - -#### Search - -``` - -| from read_ssa_enriched_events() -| where "Endpoint_Processes" IN(_datamodels) -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line IS NOT NULL AND process_name IS NOT NULL AND process_name="rclone.exe" AND (like (cmd_line, "%copy%") OR like (cmd_line, "%mega%")OR like (cmd_line, "%pcloud%") OR like (cmd_line, "%ftp%") OR like (cmd_line, "%--config%") OR like (cmd_line, "%--progress%") OR like (cmd_line, "%--no-check-certificate%") OR like (cmd_line, "%--ignore-existing%") OR like (cmd_line, "%--auto-confirm%") OR like (cmd_line, "%--transfers%") OR like (cmd_line, "%--multi-thread-streams%")) -| eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)) -| eval body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) -| into write_ssa_detected_events(); -``` - -#### Macros -The SPL above uses the following Macros: - -Note that `detect_rclone_command-line_usage_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* dest_device_id -* process_name -* parent_process_name -* process_path -* dest_user_id -* process -* cmd_line - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint_Processess` datamodel. - -#### Known False Positives -False positives should be limited as this is restricted to the Rclone process name. Filter or tune the analytic as needed. - -#### Associated Analytic story -* [DarkSide Ransomware](/stories/darkside_ransomware) -* [Ransomware](/stories/ransomware) - - -#### Kill Chain Phase -* Exfiltration - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 35.0 | 50 | 70 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$ attempting to connect to a remote cloud service to move files or folders. | - - -Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` - - - -#### Reference - -* [https://redcanary.com/blog/rclone-mega-extortion/](https://redcanary.com/blog/rclone-mega-extortion/) -* [https://www.mandiant.com/resources/shining-a-light-on-darkside-ransomware-operations](https://www.mandiant.com/resources/shining-a-light-on-darkside-ransomware-operations) -* [https://thedfirreport.com/2021/03/29/sodinokibi-aka-revil-ransomware/](https://thedfirreport.com/2021/03/29/sodinokibi-aka-revil-ransomware/) -* [https://thedfirreport.com/2021/11/29/continuing-the-bazar-ransomware-story/](https://thedfirreport.com/2021/11/29/continuing-the-bazar-ransomware-story/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1020/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1020/windows-security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/detect_rclone_command-line_usage.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-03-short_lived_scheduled_task.md b/docs/_posts/2021-12-03-short_lived_scheduled_task.md deleted file mode 100644 index 0f5a5570f9..0000000000 --- a/docs/_posts/2021-12-03-short_lived_scheduled_task.md +++ /dev/null @@ -1,160 +0,0 @@ ---- -title: "Short Lived Scheduled Task" -excerpt: "Scheduled Task -" -categories: - - Endpoint -last_modified_at: 2021-12-03 -toc: true -toc_label: "" -tags: - - Scheduled Task - - Execution - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic leverages Windows Security EventCode 4698, `A scheduled task was created` and Windows Security EventCode 4699, `A scheduled task was deleted` to identify scheduled tasks created and deleted in less than 30 seconds. This behavior may represent a lateral movement attack abusing the Task Scheduler to obtain code execution. Red Teams and adversaries alike may abuse the Task Scheduler for lateral movement and remote code execution. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-12-03 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 6fa31414-546e-11ec-adfa-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1053.005](https://attack.mitre.org/techniques/T1053/005/) | Scheduled Task | Execution, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - `wineventlog_security` EventCode=4698 OR EventCode=4699 -| xmlkv Message -| transaction Task_Name startswith=(EventCode=4698) endswith=(EventCode=4699) -| eval short_lived=case((duration<30),"TRUE") -| search short_lived = TRUE -| table _time, ComputerName, Account_Name, Command, Task_Name, short_lived -| `short_lived_scheduled_task_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) - -> :information_source: -> **short_lived_scheduled_task_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* dest -* ComputerName -* Account_Name -* Task_Name -* Description -* Command - - -#### How To Implement -To successfully implement this search, you need to be ingesting Windows Security Event Logs with 4698 EventCode enabled. The Windows TA is also required. - -#### Known False Positives -Although uncommon, legitimate applications may create and delete a Scheduled Task within 30 seconds. Filter as needed. - -#### Associated Analytic story -* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 81.0 | 90 | 90 | A windows scheduled task was created and deleted in 30 seconds on $ComputerName$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1053/005/](https://attack.mitre.org/techniques/T1053/005/) -* [https://docs.microsoft.com/en-us/windows/win32/taskschd/about-the-task-scheduler](https://docs.microsoft.com/en-us/windows/win32/taskschd/about-the-task-scheduler) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/lateral_movement/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/lateral_movement/windows-security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/short_lived_scheduled_task.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-03-windows_curl_upload_to_remote_destination.md b/docs/_posts/2021-12-03-windows_curl_upload_to_remote_destination.md deleted file mode 100644 index da10ee9932..0000000000 --- a/docs/_posts/2021-12-03-windows_curl_upload_to_remote_destination.md +++ /dev/null @@ -1,115 +0,0 @@ ---- -title: "Windows Curl Upload to Remote Destination" -excerpt: "Ingress Tool Transfer" -categories: - - Endpoint -last_modified_at: 2021-12-03 -toc: true -toc_label: "" -tags: - - Ingress Tool Transfer - - Command & Control - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the use of Windows Curl.exe uploading a file to a remote destination. \ -`-T` or `--upload-file` is used when a file is to be uploaded to a remotge destination. \ -`-d` or `--data` POST is the HTTP method that was invented to send data to a receiving web application, and it is, for example, how most common HTML forms on the web work. \ -HTTP multipart formposts are done with `-F`, but this appears to not be compatible with the Windows version of Curl. Will update if identified adversary tradecraft. \ -Adversaries may use one of the three methods based on the remote destination and what they are attempting to upload (zip vs txt). During triage, review parallel processes for further behavior. In addition, identify if the upload was successful in network logs. If a file was uploaded, isolate the endpoint and review. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2021-12-03 -- **Author**: Michael Haag, Splunk -- **ID**: cc8d046a-543b-11ec-b864-acde48001122 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1105](https://attack.mitre.org/techniques/T1105/) | Ingress Tool Transfer | Command And Control | - -#### Search - -``` - -| from read_ssa_enriched_events() -| where "Endpoint_Processes" IN(_datamodels) -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) - -| where cmd_line IS NOT NULL AND process_name IS NOT NULL AND process_name="curl.exe" AND (like (cmd_line, "%-T %") OR like (cmd_line, "%--upload-file %")OR like (cmd_line, "%-d %") OR like (cmd_line, "%--data %") OR like (cmd_line, "%-F %")) - -| eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)) -| eval body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) -| into write_ssa_detected_events(); -``` - -#### Macros -The SPL above uses the following Macros: - -Note that `windows_curl_upload_to_remote_destination_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* dest_device_id -* process_name -* parent_process_name -* process_path -* dest_user_id -* process -* cmd_line - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint_Processess` datamodel. - -#### Known False Positives -False positives may be limited to source control applications and may be required to be filtered out. - -#### Associated Analytic story -* [Ingress Tool Transfer](/stories/ingress_tool_transfer) - - -#### Kill Chain Phase -* Exfiltration - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$ uploading a file to a remote destination. | - - -Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` - - - -#### Reference - -* [https://everything.curl.dev/usingcurl/uploads](https://everything.curl.dev/usingcurl/uploads) -* [https://techcommunity.microsoft.com/t5/containers/tar-and-curl-come-to-windows/ba-p/382409](https://techcommunity.microsoft.com/t5/containers/tar-and-curl-come-to-windows/ba-p/382409) -* [https://twitter.com/d1r4c/status/1279042657508081664?s=20](https://twitter.com/d1r4c/status/1279042657508081664?s=20) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1105/atomic_red_team/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1105/atomic_red_team/windows-security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_curl_upload_to_remote_destination.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-06-suspicious_linux_discovery_commands.md b/docs/_posts/2021-12-06-suspicious_linux_discovery_commands.md deleted file mode 100644 index f70a9508fb..0000000000 --- a/docs/_posts/2021-12-06-suspicious_linux_discovery_commands.md +++ /dev/null @@ -1,165 +0,0 @@ ---- -title: "Suspicious Linux Discovery Commands" -excerpt: "Unix Shell -" -categories: - - Endpoint -last_modified_at: 2021-12-06 -toc: true -toc_label: "" -tags: - - Unix Shell - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search, detects execution of suspicious bash commands from various commonly leveraged bash scripts like (AutoSUID, LinEnum, LinPeas) to perform discovery of possible paths of privilege execution, password files, vulnerable directories, executables and file permissions on a Linux host.\ -The search logic specifically looks for high number of distinct commands run in a short period of time. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-12-06 -- **Author**: Bhavin Patel, Splunk -- **ID**: 0edd5112-56c9-11ec-b990-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059.004](https://attack.mitre.org/techniques/T1059/004/) | Unix Shell | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count values(Processes.process) values(Processes.process_name) values(Processes.parent_process_name) dc(Processes.process) as distinct_commands dc(Processes.process_name) as distinct_process_names min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where [ -|inputlookup linux_tool_discovery_process.csv -| rename process as Processes.process -|table Processes.process] by _time span=5m Processes.user Processes.dest -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| where distinct_commands > 40 AND distinct_process_names > 3 -| `suspicious_linux_discovery_commands_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **suspicious_linux_discovery_commands_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process -* Processes.parent_process_name -* Processes.user -* Processes.process_name - - -#### How To Implement -This detection search is based on Splunk add-on for Microsoft Sysmon-Linux.(https://splunkbase.splunk.com/app/6176/). Please install this add-on to parse fields correctly and execute detection search. Consider customizing the time window and threshold values according to your environment. - -#### Known False Positives -Unless an administrator is using these commands to troubleshoot or audit a system, the execution of these commands should be monitored. - -#### Associated Analytic story -* [Linux Post-Exploitation](/stories/linux_post-exploitation) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 81.0 | 90 | 90 | Suspicious Linux Discovery Commands detected on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/matrices/enterprise/linux/](https://attack.mitre.org/matrices/enterprise/linux/) -* [https://attack.mitre.org/techniques/T1059/004/](https://attack.mitre.org/techniques/T1059/004/) -* [https://github.com/IvanGlinkin/AutoSUID](https://github.com/IvanGlinkin/AutoSUID) -* [https://github.com/carlospolop/PEASS-ng/tree/master/linPEAS](https://github.com/carlospolop/PEASS-ng/tree/master/linPEAS) -* [https://github.com/rebootuser/LinEnum](https://github.com/rebootuser/LinEnum) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.004/linux_discovery_tools/sysmon_linux.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.004/linux_discovery_tools/sysmon_linux.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/suspicious_linux_discovery_commands.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-07-anomalous_usage_of_account_credentials.md b/docs/_posts/2021-12-07-anomalous_usage_of_account_credentials.md deleted file mode 100644 index 3c0d2cfbe9..0000000000 --- a/docs/_posts/2021-12-07-anomalous_usage_of_account_credentials.md +++ /dev/null @@ -1,109 +0,0 @@ ---- -title: "Anomalous Usage of Account Credentials" -excerpt: "Domain Accounts" -categories: - - Endpoint -last_modified_at: 2021-12-07 -toc: true -toc_label: "" -tags: - - Domain Accounts - - Defense Evasion - - Persistence - - Privilege Escalation - - Initial Access - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - -### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This is an anomaly generating detection looking for multiple interactive logins within a specific time period. An insider threat may attempt to steal colleagues credentials in low tech, undetectable methods, in order to gain access to additional information or to hide their own behavior. This should capture their attempted use of those credentials on a workstation. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2021-12-07 -- **Author**: Lou Stella, Splunk -- **ID**: 629cbf9e-5785-11ec-9611-acde48001122 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1078.002](https://attack.mitre.org/techniques/T1078/002/) | Domain Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - -#### Search - -``` - -| from read_ssa_enriched_events() -| eval device=ucast(map_get(input_event, "dest_device_id"), "string", null), auth_type=ucast(map_get(input_event, "authentication_type"), "string", null), timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), src_user=ucast(map_get(input_event, "dest_user_original_artifact"), "string", null), signature_id=ucast(map_get(input_event, "EventCode"), "string", null) -| where signature_id="4624" -| where auth_type="2" OR auth_type="11" -| where NOT (src_user="SYSTEM") AND NOT (src_user="ANONYMOUS LOGON") -| stats estdc(src_user) AS user_counter by device, span(timestamp, 600s, 300s) -| where user_counter>=2 -| rename window_end AS timestamp -| eval start_time=window_start, end_time=timestamp, entities=mvappend(device), body=create_map(["user_counter", user_counter, "device", device]) -| into write_ssa_detected_events(); -``` - -#### Macros -The SPL above uses the following Macros: - -Note that `anomalous_usage_of_account_credentials_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -To successfully implement this detection, you need to be ingesting logon events from workstations. - -#### Known False Positives -Shared workstations can cause false positives - -#### Associated Analytic story -* [Insider Threat](/stories/insider_threat) - - -#### Kill Chain Phase -* Privilege Escalation -* Lateral Movement - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 6.0 | 20 | 30 | Multiple interactive logins detected on $device$ | - - -Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` - - - -#### Reference - -* [https://attack.mitre.org/techniques/T1078/002/](https://attack.mitre.org/techniques/T1078/002/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078.002/account_login/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078.002/account_login/windows-security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/endpoint/anomalous_usage_of_account_credentials.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-07-bcdedit_failure_recovery_modification.md b/docs/_posts/2021-12-07-bcdedit_failure_recovery_modification.md deleted file mode 100644 index a4c08b68a6..0000000000 --- a/docs/_posts/2021-12-07-bcdedit_failure_recovery_modification.md +++ /dev/null @@ -1,106 +0,0 @@ ---- -title: "BCDEdit Failure Recovery Modification" -excerpt: "Inhibit System Recovery" -categories: - - Endpoint -last_modified_at: 2021-12-07 -toc: true -toc_label: "" -tags: - - Inhibit System Recovery - - Impact - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for flags passed to bcdedit.exe modifications to the built-in Windows error recovery boot configurations. This is typically used by ransomware to prevent recovery. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2021-12-07 -- **Author**: Michael Haag, Splunk -- **ID**: 76d79d6e-25bb-40f6-b3b2-e0a6b7e5ea13 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1490](https://attack.mitre.org/techniques/T1490/) | Inhibit System Recovery | Impact | - -#### Search - -``` - -| from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line IS NOT NULL AND process_name IS NOT NULL AND process_name="bcdedit.exe" AND (like (cmd_line, "%recoveryenabled%") AND like (cmd_line, "%no%")) -| eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) -| into write_ssa_detected_events(); -``` - -#### Macros -The SPL above uses the following Macros: - -Note that `bcdedit_failure_recovery_modification_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* dest_device_id -* process_name -* parent_process_name -* process_path -* dest_user_id -* process -* cmd_line - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint_Processess` datamodel. - -#### Known False Positives -Administrators may modify the boot configuration. - -#### Associated Analytic story -* [Ryuk Ransomware](/stories/ryuk_ransomware) -* [Ransomware](/stories/ransomware) - - -#### Kill Chain Phase -* Actions on Objectives - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 100 | 80 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$ attempting disable the ability to recover the endpoint. | - - -Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` - - - -#### Reference - -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1490/T1490.md#atomic-test-4---windows---disable-windows-recovery-console-repair](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1490/T1490.md#atomic-test-4---windows---disable-windows-recovery-console-repair) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1490/atomic_red_team/windows-security_bcdedit_wbadmin.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1490/atomic_red_team/windows-security_bcdedit_wbadmin.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/bcdedit_failure_recovery_modification.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-07-dns_exfiltration_using_nslookup_app.md b/docs/_posts/2021-12-07-dns_exfiltration_using_nslookup_app.md deleted file mode 100644 index c982c2c963..0000000000 --- a/docs/_posts/2021-12-07-dns_exfiltration_using_nslookup_app.md +++ /dev/null @@ -1,112 +0,0 @@ ---- -title: "DNS Exfiltration Using Nslookup App" -excerpt: "Exfiltration Over Alternative Protocol" -categories: - - Endpoint -last_modified_at: 2021-12-07 -toc: true -toc_label: "" -tags: - - Exfiltration Over Alternative Protocol - - Exfiltration - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect potential DNS exfiltration using nslookup application. This technique are seen in couple of malware and APT group to exfiltrated collected data in a infected machine or infected network. This detection is looking for unique use of nslookup where it tries to use specific record type, TXT, A, AAAA, that are commonly used by attacker and also the retry parameter which is designed to query C2 DNS multiple tries. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2021-12-07 -- **Author**: Michael Haag, Splunk -- **ID**: 2452e632-9e0d-11eb-34ba-acde48001122 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1048](https://attack.mitre.org/techniques/T1048/) | Exfiltration Over Alternative Protocol | Exfiltration | - -#### Search - -``` - -| from read_ssa_enriched_events() -| where "Endpoint_Processes" IN(_datamodels) -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line IS NOT NULL AND process_name IS NOT NULL AND process_name="nslookup.exe" AND (like (cmd_line, "%-querytype=%") OR like (cmd_line, "%-qt=%") OR like (cmd_line, "%-q=%") OR like (cmd_line, "%-type=%") OR like (cmd_line, "%-retry=%")) -| eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)) -| eval body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) -| into write_ssa_detected_events(); -``` - -#### Macros -The SPL above uses the following Macros: - -Note that `dns_exfiltration_using_nslookup_app_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* dest_device_id -* process_name -* parent_process_name -* process_path -* dest_user_id -* process -* cmd_line - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint_Processess` datamodel. - -#### Known False Positives -It is possible for some legitimate administrative utilities to use similar cmd_line parameters. Filter as needed. - -#### Associated Analytic story -* [Suspicious DNS Traffic](/stories/suspicious_dns_traffic) -* [Dynamic DNS](/stories/dynamic_dns) -* [Command and Control](/stories/command_and_control) -* [Data Exfiltration](/stories/data_exfiltration) - - -#### Kill Chain Phase -* Exploitation - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 72.0 | 90 | 80 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$ performing activity related to DNS exfiltration. | - - -Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` - - - -#### Reference - -* [https://www.fireeye.com/blog/threat-research/2017/03/fin7_spear_phishing.html](https://www.fireeye.com/blog/threat-research/2017/03/fin7_spear_phishing.html) -* [https://www.varonis.com/blog/dns-tunneling/](https://www.varonis.com/blog/dns-tunneling/) -* [https://www.microsoft.com/security/blog/2021/01/20/deep-dive-into-the-solorigate-second-stage-activation-from-sunburst-to-teardrop-and-raindrop/](https://www.microsoft.com/security/blog/2021/01/20/deep-dive-into-the-solorigate-second-stage-activation-from-sunburst-to-teardrop-and-raindrop/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1048.003/nslookup_exfil/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1048.003/nslookup_exfil/windows-security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/dns_exfiltration_using_nslookup_app.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-07-excessive_number_of_office_files_copied.md b/docs/_posts/2021-12-07-excessive_number_of_office_files_copied.md deleted file mode 100644 index dab2b36dee..0000000000 --- a/docs/_posts/2021-12-07-excessive_number_of_office_files_copied.md +++ /dev/null @@ -1,98 +0,0 @@ ---- -title: "Excessive Number of Office Files Copied" -excerpt: "Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol" -categories: - - Endpoint -last_modified_at: 2021-12-07 -toc: true -toc_label: "" -tags: - - Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol - - Exfiltration - - Splunk Behavioral Analytics - - Endpoint_Filesystem ---- - -### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This detection detects a high amount of office file copied. This can be an indicator for a malicious insider. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Filesystem](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointFilesystem) -- **Last Updated**: 2021-12-07 -- **Author**: Patrick Bareiss, Splunk -- **ID**: 3c6594a9-8df6-45a1-9357-d73b62083c63 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1048.003](https://attack.mitre.org/techniques/T1048/003/) | Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol | Exfiltration | - -#### Search - -``` - -| from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)) -| eval action=ucast(map_get(input_event, "action"), "string", null), process=ucast(map_get(input_event, "process"), "string", null), file_name=ucast(map_get(input_event, "file_name"), "string", null), file_path=ucast(map_get(input_event, "file_path"), "string", null), dest_user_id=ucast(map_get(input_event, "dest_user_id"), "string", null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), "string", null) -| where "Endpoint_Filesystem" IN(_datamodels) -| where action="created" -| where like(file_name, "%.doc%") OR like(file_name, "%.xls%") OR like(file_name, "%.ppt%") -| stats count(file_name) AS count BY dest_user_id, dest_device_id, span(timestamp, 10m) -| where count > 20 -| eval start_time=window_start, end_time=window_end, entities=mvappend(dest_user_id, dest_device_id), body=create_map(["count", count]) -| into write_ssa_detected_events(); -``` - -#### Macros -The SPL above uses the following Macros: - -Note that `excessive_number_of_office_files_copied_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* action -* process -* file_name -* file_path - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Filesytem` node. - -#### Known False Positives -user may copy a lot of office fies from one folder to another - -#### Associated Analytic story - - -#### Kill Chain Phase -* Exploitation - - - - -Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` - - - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1048.003/mass_file_creation/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1048.003/mass_file_creation/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/endpoint/excessive_number_of_office_files_copied.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-07-fsutil_zeroing_file.md b/docs/_posts/2021-12-07-fsutil_zeroing_file.md deleted file mode 100644 index 7017500520..0000000000 --- a/docs/_posts/2021-12-07-fsutil_zeroing_file.md +++ /dev/null @@ -1,106 +0,0 @@ ---- -title: "Fsutil Zeroing File" -excerpt: "Indicator Removal on Host" -categories: - - Endpoint -last_modified_at: 2021-12-07 -toc: true -toc_label: "" -tags: - - Indicator Removal on Host - - Defense Evasion - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect a suspicious fsutil process to zeroing a target file. This technique was seen in lockbit ransomware where it tries to zero out its malware path as part of its defense evasion after encrypting the compromised host. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2021-12-07 -- **Author**: Michael Haag, Splunk -- **ID**: f792cdc9-43ee-4429-a3c0-ffce4fed1a85 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1070](https://attack.mitre.org/techniques/T1070/) | Indicator Removal on Host | Defense Evasion | - -#### Search - -``` - -| from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line IS NOT NULL AND process_name IS NOT NULL AND process_name="fsutil.exe" AND (like (cmd_line, "%setzerodata%")) -| eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) -| into write_ssa_detected_events(); -``` - -#### Macros -The SPL above uses the following Macros: - -Note that `fsutil_zeroing_file_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* dest_device_id -* process_name -* parent_process_name -* process_path -* dest_user_id -* process -* cmd_line - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed net.exe may be used. - -#### Known False Positives -System administrators or scripts may delete user accounts via this technique. Filter as needed. - -#### Associated Analytic story -* [Ransomware](/stories/ransomware) - - -#### Kill Chain Phase -* Exploitation - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 54.0 | 60 | 90 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$ atempting to perform file deletion. | - - -Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` - - - -#### Reference - -* [https://app.any.run/tasks/e0ac072d-58c9-4f53-8a3b-3e491c7ac5db/](https://app.any.run/tasks/e0ac072d-58c9-4f53-8a3b-3e491c7ac5db/) -* [https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/fsutil-file](https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/fsutil-file) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070/fsutil_file_zero/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070/fsutil_file_zero/windows-security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/fsutil_zeroing_file.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-07-high_file_deletion_frequency.md b/docs/_posts/2021-12-07-high_file_deletion_frequency.md deleted file mode 100644 index beb291bc14..0000000000 --- a/docs/_posts/2021-12-07-high_file_deletion_frequency.md +++ /dev/null @@ -1,109 +0,0 @@ ---- -title: "High File Deletion Frequency" -excerpt: "Data Destruction" -categories: - - Endpoint -last_modified_at: 2021-12-07 -toc: true -toc_label: "" -tags: - - Data Destruction - - Impact - - Splunk Behavioral Analytics - - Endpoint_Filesystem ---- - -### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This detection detects a high amount of file deletions in a short time for specific file types. This can be an indicator for a malicious insider. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Filesystem](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointFilesystem) -- **Last Updated**: 2021-12-07 -- **Author**: Patrick Bareiss, Splunk -- **ID**: b6200efd-13bd-4336-920a-057b25bbcfaf - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1485](https://attack.mitre.org/techniques/T1485/) | Data Destruction | Impact | - -#### Search - -``` - -| from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)) -| eval action=ucast(map_get(input_event, "action"), "string", null), process=ucast(map_get(input_event, "process"), "string", null), file_name=ucast(map_get(input_event, "file_name"), "string", null), file_path=ucast(map_get(input_event, "file_path"), "string", null), dest_user_id=ucast(map_get(input_event, "dest_user_id"), "string", null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), "string", null) -| where "Endpoint_Filesystem" IN(_datamodels) -| where action="deleted" -| where like(file_name, "%.cmd") OR like(file_name, "%.ini") OR like(file_name, "%.gif") OR like(file_name, "%.jpg") OR like(file_name, "%.jpeg") OR like(file_name, "%.db") OR like(file_name, "%.doc%") OR like(file_name, "%.ps1") OR like(file_name, "%.xls%") OR like(file_name, "%.ppt%") OR like(file_name, "%.bmp") OR like(file_name, "%.zip") OR like(file_name, "%.rar") OR like(file_name, "%.7z") OR like(file_name, "%.chm") OR like(file_name, "%.png") OR like(file_name, "%.log") OR like(file_name, "%.vbs") OR like(file_name, "%.js") -| stats count(file_name) AS count BY dest_user_id, dest_device_id, span(timestamp, 10m) -| where count > 20 -| eval start_time=window_start, end_time=window_end, entities=mvappend(dest_user_id, dest_device_id), body=create_map(["count", count]) -| into write_ssa_detected_events(); -``` - -#### Macros -The SPL above uses the following Macros: - -Note that `high_file_deletion_frequency_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* action -* process -* file_name -* file_path - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Filesytem` node. - -#### Known False Positives -user may delete bunch of pictures or files in a folder. - -#### Associated Analytic story -* [Clop Ransomware](/stories/clop_ransomware) - - -#### Kill Chain Phase -* Exploitation - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 72.0 | 90 | 80 | High frequency file deletion activity detected on host $Computer$ | - - -Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` - - - -#### Reference - -* [https://www.fireeye.com/blog/threat-research/2020/10/fin11-email-campaigns-precursor-for-ransomware-data-theft.html](https://www.fireeye.com/blog/threat-research/2020/10/fin11-email-campaigns-precursor-for-ransomware-data-theft.html) -* [https://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html](https://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/excessive_file_deletions/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/excessive_file_deletions/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/endpoint/high_file_deletion_frequency.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-07-microsoft_exchange_mailbox_replication_service_writing_active_server_pages.md b/docs/_posts/2021-12-07-microsoft_exchange_mailbox_replication_service_writing_active_server_pages.md deleted file mode 100644 index 2d79e1da67..0000000000 --- a/docs/_posts/2021-12-07-microsoft_exchange_mailbox_replication_service_writing_active_server_pages.md +++ /dev/null @@ -1,128 +0,0 @@ ---- -title: "Microsoft Exchange Mailbox Replication service writing Active Server Pages" -excerpt: "Server Software Component -, Web Shell -, Exploit Public-Facing Application -" -categories: - - Endpoint -last_modified_at: 2021-12-07 -toc: true -toc_label: "" -tags: - - Server Software Component - - Web Shell - - Exploit Public-Facing Application - - Persistence - - Persistence - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - -### WARNING THIS IS A EXPERIMENTAL object -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -The following query identifies suspicious .aspx created in 3 paths identified by Microsoft as known drop locations for Exchange exploitation related to HAFNIUM group and recently disclosed vulnerablity named ProxyShell. Paths include: `\HttpProxy\owa\auth\`, `\inetpub\wwwroot\aspnet_client\`, and `\HttpProxy\OAB\`. The analytic is limited to process name MSExchangeMailboxReplication.exe, which typically does not write .aspx files to disk. Upon triage, the suspicious .aspx file will likely look obvious on the surface. inspect the contents for script code inside. Identify additional log sources, IIS included, to review source and other potential exploitation. It is often the case that a particular threat is only applicable to a specific subset of systems in your environment. Typically analytics to detect those threats are written without the benefit of being able to only target those systems as well. Writing analytics against all systems when those behaviors are limited to identifiable subsets of those systems is suboptimal. Consider the case ProxyShell vulnerability on Microsoft Exchange Servers. With asset information, a hunter can limit their analytics to systems that have been identified as Exchange servers. A hunter may start with the theory that the exchange server is communicating with new systems that it has not previously. If this theory is run against all publicly facing systems, the amount of noise it will generate will likely render this theory untenable. However, using the asset information to limit this analytic to just the Exchange servers will reduce the noise allowing the hunter to focus only on the systems where this behavioral change is relevant. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/object-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-12-07 -- **Author**: Michael Haag, Splunk -- **ID**: 985f322c-57a5-11ec-b9ac-acde48001122 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1505](https://attack.mitre.org/techniques/T1505/) | Server Software Component | Persistence | - -| [T1505.003](https://attack.mitre.org/techniques/T1505/003/) | Web Shell | Persistence | - -| [T1190](https://attack.mitre.org/techniques/T1190/) | Exploit Public-Facing Application | Initial Access | - -#### Search - -``` - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name=MSExchangeMailboxReplication.exe by _time span=1h Processes.process_id Processes.process_name Processes.process_guid Processes.dest -| `drop_dm_object_name(Processes)` -| join process_guid, _time [ -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_path IN ("*\\HttpProxy\\owa\\auth\\*", "*\\inetpub\\wwwroot\\aspnet_client\\*", "*\\HttpProxy\\OAB\\*") Filesystem.file_name="*.aspx" by _time span=1h Filesystem.dest Filesystem.file_create_time Filesystem.file_name Filesystem.file_path -| `drop_dm_object_name(Filesystem)` -| fields _time dest file_create_time file_name file_path process_name process_path process process_guid] -| dedup file_create_time -| table dest file_create_time, file_name, file_path, process_name -| `microsoft_exchange_mailbox_replication_service_writing_active_server_pages_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -Note that `microsoft_exchange_mailbox_replication_service_writing_active_server_pages_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Filesystem.file_path -* Filesystem.process_id -* Filesystem.file_name -* Filesystem.file_hash -* Filesystem.user -* Filesystem.process_guid -* Processes.process_name -* Processes.process_id -* Processes.process_name -* Processes.process_guid - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node and `Filesystem` node. - -#### Known False Positives -The query is structured in a way that `action` (read, create) is not defined. Review the results of this query, filter, and tune as necessary. It may be necessary to generate this query specific to your endpoint product. - -#### Associated Analytic story -* [ProxyShell](/stories/proxyshell) -* [Ransomware](/stories/ransomware) - - -#### Kill Chain Phase -* Exploitation - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 81.0 | 90 | 90 | A file - $file_name$ was written to disk that is related to IIS exploitation related to ProxyShell. Review further file modifications on endpoint $dest$ by user $user$. | - - - - -#### Reference - -* [https://redcanary.com/blog/blackbyte-ransomware/](https://redcanary.com/blog/blackbyte-ransomware/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1505.003/windows-sysmon_proxylogon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1505.003/windows-sysmon_proxylogon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/endpoint/microsoft_exchange_mailbox_replication_service_writing_active_server_pages.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-07-ms_exchange_mailbox_replication_service_writing_active_server_pages.md b/docs/_posts/2021-12-07-ms_exchange_mailbox_replication_service_writing_active_server_pages.md deleted file mode 100644 index b239eeaaf8..0000000000 --- a/docs/_posts/2021-12-07-ms_exchange_mailbox_replication_service_writing_active_server_pages.md +++ /dev/null @@ -1,178 +0,0 @@ ---- -title: "MS Exchange Mailbox Replication service writing Active Server Pages" -excerpt: "Server Software Component -, Web Shell -, Exploit Public-Facing Application -" -categories: - - Endpoint -last_modified_at: 2021-12-07 -toc: true -toc_label: "" -tags: - - Server Software Component - - Web Shell - - Exploit Public-Facing Application - - Persistence - - Persistence - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following query identifies suspicious .aspx created in 3 paths identified by Microsoft as known drop locations for Exchange exploitation related to HAFNIUM group and recently disclosed vulnerablity named ProxyShell. Paths include: `\HttpProxy\owa\auth\`, `\inetpub\wwwroot\aspnet_client\`, and `\HttpProxy\OAB\`. The analytic is limited to process name MSExchangeMailboxReplication.exe, which typically does not write .aspx files to disk. Upon triage, the suspicious .aspx file will likely look obvious on the surface. inspect the contents for script code inside. Identify additional log sources, IIS included, to review source and other potential exploitation. It is often the case that a particular threat is only applicable to a specific subset of systems in your environment. Typically analytics to detect those threats are written without the benefit of being able to only target those systems as well. Writing analytics against all systems when those behaviors are limited to identifiable subsets of those systems is suboptimal. Consider the case ProxyShell vulnerability on Microsoft Exchange Servers. With asset information, a hunter can limit their analytics to systems that have been identified as Exchange servers. A hunter may start with the theory that the exchange server is communicating with new systems that it has not previously. If this theory is run against all publicly facing systems, the amount of noise it will generate will likely render this theory untenable. However, using the asset information to limit this analytic to just the Exchange servers will reduce the noise allowing the hunter to focus only on the systems where this behavioral change is relevant. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-12-07 -- **Author**: Michael Haag, Splunk -- **ID**: 985f322c-57a5-11ec-b9ac-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1505](https://attack.mitre.org/techniques/T1505/) | Server Software Component | Persistence | - -| [T1505.003](https://attack.mitre.org/techniques/T1505/003/) | Web Shell | Persistence | - -| [T1190](https://attack.mitre.org/techniques/T1190/) | Exploit Public-Facing Application | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name=MSExchangeMailboxReplication.exe by _time span=1h Processes.process_id Processes.process_name Processes.process_guid Processes.dest -| `drop_dm_object_name(Processes)` -| join process_guid, _time [ -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_path IN ("*\\HttpProxy\\owa\\auth\\*", "*\\inetpub\\wwwroot\\aspnet_client\\*", "*\\HttpProxy\\OAB\\*") Filesystem.file_name="*.aspx" by _time span=1h Filesystem.dest Filesystem.file_create_time Filesystem.file_name Filesystem.file_path -| `drop_dm_object_name(Filesystem)` -| fields _time dest file_create_time file_name file_path process_name process_path process process_guid] -| dedup file_create_time -| table dest file_create_time, file_name, file_path, process_name -| `ms_exchange_mailbox_replication_service_writing_active_server_pages_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **ms_exchange_mailbox_replication_service_writing_active_server_pages_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Filesystem.file_path -* Filesystem.process_id -* Filesystem.file_name -* Filesystem.file_hash -* Filesystem.user -* Filesystem.process_guid -* Processes.process_name -* Processes.process_id -* Processes.process_name -* Processes.process_guid - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node and `Filesystem` node. - -#### Known False Positives -The query is structured in a way that `action` (read, create) is not defined. Review the results of this query, filter, and tune as necessary. It may be necessary to generate this query specific to your endpoint product. - -#### Associated Analytic story -* [ProxyShell](/stories/proxyshell) -* [Ransomware](/stories/ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 81.0 | 90 | 90 | A file - $file_name$ was written to disk that is related to IIS exploitation related to ProxyShell. Review further file modifications on endpoint $dest$ by user $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://redcanary.com/blog/blackbyte-ransomware/](https://redcanary.com/blog/blackbyte-ransomware/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1505.003/windows-sysmon_proxylogon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1505.003/windows-sysmon_proxylogon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/endpoint/ms_exchange_mailbox_replication_service_writing_active_server_pages.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-07-wbadmin_delete_system_backups.md b/docs/_posts/2021-12-07-wbadmin_delete_system_backups.md deleted file mode 100644 index 8fe8ec4e3c..0000000000 --- a/docs/_posts/2021-12-07-wbadmin_delete_system_backups.md +++ /dev/null @@ -1,109 +0,0 @@ ---- -title: "WBAdmin Delete System Backups" -excerpt: "Inhibit System Recovery" -categories: - - Endpoint -last_modified_at: 2021-12-07 -toc: true -toc_label: "" -tags: - - Inhibit System Recovery - - Impact - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for flags passed to wbadmin.exe (Windows Backup Administrator Tool) that delete backup files. This is typically used by ransomware to prevent recovery. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2021-12-07 -- **Author**: Michael Haag, Splunk -- **ID**: 71efbf52-4dbb-4c00-a520-306aa546cbb7 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1490](https://attack.mitre.org/techniques/T1490/) | Inhibit System Recovery | Impact | - -#### Search - -``` - -| from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where (cmd_line IS NOT NULL AND process_name IS NOT NULL) AND (process_name="wbadmin.exe" AND like (cmd_line, "%delete%") OR like (cmd_line, "%catalog%") OR like (cmd_line, "%systemstatebackup%")) -| eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) -| into write_ssa_detected_events(); -``` - -#### Macros -The SPL above uses the following Macros: - -Note that `wbadmin_delete_system_backups_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* dest_device_id -* process_name -* parent_process_name -* process_path -* dest_user_id -* process -* cmd_line - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint_Processess` datamodel. - -#### Known False Positives -Administrators may modify the boot configuration. - -#### Associated Analytic story -* [Ryuk Ransomware](/stories/ryuk_ransomware) -* [Ransomware](/stories/ransomware) - - -#### Kill Chain Phase -* Exploitation - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$ attempting to delete system backups. | - - -Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` - - - -#### Reference - -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1490/T1490.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1490/T1490.md) -* [https://thedfirreport.com/2020/10/08/ryuks-return/](https://thedfirreport.com/2020/10/08/ryuks-return/) -* [https://attack.mitre.org/techniques/T1490/](https://attack.mitre.org/techniques/T1490/) -* [https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/wbadmin](https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/wbadmin) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1490/atomic_red_team/windows-security_bcdedit_wbadmin.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1490/atomic_red_team/windows-security_bcdedit_wbadmin.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/wbadmin_delete_system_backups.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-07-windows_raccine_scheduled_task_deletion.md b/docs/_posts/2021-12-07-windows_raccine_scheduled_task_deletion.md deleted file mode 100644 index 2ef2e5e6e0..0000000000 --- a/docs/_posts/2021-12-07-windows_raccine_scheduled_task_deletion.md +++ /dev/null @@ -1,164 +0,0 @@ ---- -title: "Windows Raccine Scheduled Task Deletion" -excerpt: "Disable or Modify Tools -" -categories: - - Endpoint -last_modified_at: 2021-12-07 -toc: true -toc_label: "" -tags: - - Disable or Modify Tools - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the Raccine Rules Updater scheduled task being deleted. Adversaries may attempt to remove this task in order to prevent the update of Raccine. Raccine is a "ransomware vaccine" created by security researcher Florian Roth, designed to intercept and prevent precursors and active ransomware behavior. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2021-12-07 -- **Author**: Michael Haag, Splunk -- **ID**: c9f010da-57ab-11ec-82bd-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=schtasks.exe Processes.process="*delete*" AND Processes.process="*Raccine*" by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_raccine_scheduled_task_deletion_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_raccine_scheduled_task_deletion_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -False positives should be limited, however filter as needed. - -#### Associated Analytic story -* [Ransomware](/stories/ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user user$ attempting to disable Raccines scheduled task. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://redcanary.com/blog/blackbyte-ransomware/](https://redcanary.com/blog/blackbyte-ransomware/) -* [https://github.com/Neo23x0/Raccine](https://github.com/Neo23x0/Raccine) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/atomic_red_team/windows-sysmon_raccine.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/atomic_red_team/windows-sysmon_raccine.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-08-disable_defender_antivirus_registry.md b/docs/_posts/2021-12-08-disable_defender_antivirus_registry.md deleted file mode 100644 index 3511f37a66..0000000000 --- a/docs/_posts/2021-12-08-disable_defender_antivirus_registry.md +++ /dev/null @@ -1,110 +0,0 @@ ---- -title: "Disable Defender AntiVirus Registry" -excerpt: "Disable or Modify Tools, Impair Defenses" -categories: - - Endpoint -last_modified_at: 2021-12-08 -toc: true -toc_label: "" -tags: - - Disable or Modify Tools - - Defense Evasion - - Impair Defenses - - Defense Evasion - - Splunk Behavioral Analytics - - Endpoint_Registry ---- - -### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This particular behavior is typically executed when an adversaries or malware gains access to an endpoint and beings to perform execution and to evade detections. Usually, a batch (.bat) will be executed and multiple registry and scheduled task modifications will occur. During triage, review parallel processes and identify any further file modifications. Endpoint should be isolated. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Registry](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointRegistry) -- **Last Updated**: 2021-12-08 -- **Author**: Bhavin Patel, Splunk -- **ID**: aa4f115a-3024-11ec-9987-acde48001122 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -#### Search - -``` - -| from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event,"_time"), "string", null)), registry_path=lower(ucast(map_get(input_event, "registry_path"), "string", null)), registry_key_name=lower(ucast(map_get(input_event, "registry_key_name"), "string", null)), registry_value_data=ucast(map_get(input_event, "registry_value_data"), "string", null), process_guid=ucast(map_get(input_event, "process_guid"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where like(registry_path, "%\\Policies\\Microsoft\\Windows Defender%") AND registry_key_name="DisableAntiVirus" AND registry_value_data="(0x00000001)" -| eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map( [ "event_id", event_id, "registry_path", registry_path, "registry_key_name", registry_key_name, "process_guid", process_guid,"registry_value_data",registry_value_data]) -| into write_ssa_detected_events(); -``` - -#### Macros -The SPL above uses the following Macros: - -Note that `disable_defender_antivirus_registry_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.dest -* Registry.user -* Registry.registry_value_name -* Registry.registry_key_name -* Registry.registry_path -* Registry.registry_value_data - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the registry value name, registry path, and registry value data from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -Admin or user may choose to disable windows defender product - -#### Associated Analytic story -* [IceID](/stories/iceid) - - -#### Kill Chain Phase -* Exploitation - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | Modified/added/deleted registry entry $registry_path$ in $dest$ | - - -Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` - - - -#### Reference - -* [https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/](https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/disable_av/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/disable_av/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/endpoint/disable_defender_antivirus_registry.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-08-msi_module_loaded_by_non-system_binary.md b/docs/_posts/2021-12-08-msi_module_loaded_by_non-system_binary.md deleted file mode 100644 index d94c2cff62..0000000000 --- a/docs/_posts/2021-12-08-msi_module_loaded_by_non-system_binary.md +++ /dev/null @@ -1,175 +0,0 @@ ---- -title: "MSI Module Loaded by Non-System Binary" -excerpt: "DLL Side-Loading -, Hijack Execution Flow -" -categories: - - Endpoint -last_modified_at: 2021-12-08 -toc: true -toc_label: "" -tags: - - DLL Side-Loading - - Hijack Execution Flow - - Defense Evasion - - Persistence - - Privilege Escalation - - Defense Evasion - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2021-41379 ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following hunting analytic identifies `msi.dll` being loaded by a binary not located in `system32`, `syswow64`, `winsxs` or `windows` paths. This behavior is most recently related to InstallerFileTakeOver, or CVE-2021-41379, and DLL side-loading. CVE-2021-41379 requires a binary to be dropped and `msi.dll` to be loaded by it. To Successful exploitation of this issue happens in four parts \ -1. Generation of an MSI that will trigger bad behavior. \ -1. Preparing a directory for MSI installation. \ -1. Inducing an error state. \ -1. Racing to introduce a junction and a symlink to trick msiexec.exe to modify the attacker specified file. \ -In addition, `msi.dll` has been abused in DLL side-loading attacks by being loaded by non-system binaries. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-12-08 -- **Author**: Michael Haag, Splunk -- **ID**: ccb98a66-5851-11ec-b91c-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1574.002](https://attack.mitre.org/techniques/T1574/002/) | DLL Side-Loading | Defense Evasion, Persistence, Privilege Escalation | - -| [T1574](https://attack.mitre.org/techniques/T1574/) | Hijack Execution Flow | Defense Evasion, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2021-41379](https://nvd.nist.gov/vuln/detail/CVE-2021-41379) | Windows Installer Elevation of Privilege Vulnerability | 4.6 | - - - -
-
- -#### Search - -``` -`sysmon` EventCode=7 ImageLoaded="*\\msi.dll" NOT (Image IN ("*\\System32\\*","*\\syswow64\\*","*\\windows\\*", "*\\winsxs\\*")) -| stats count min(_time) as firstTime max(_time) as lastTime by Image ImageLoaded process_name Computer EventCode ProcessId -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `msi_module_loaded_by_non_system_binary_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **msi_module_loaded_by_non-system_binary_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Image -* ImageLoaded -* process_name -* Computer -* EventCode -* ProcessId - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name and imageloaded executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -It is possible some Administrative utilities will load msi.dll outside of normal system paths, filter as needed. - -#### Associated Analytic story -* [Windows Privilege Escalation](/stories/windows_privilege_escalation) -* [Hermetic Wiper](/stories/hermetic_wiper) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 56.0 | 80 | 70 | The following module $ImageLoaded$ was loaded by $Image$ outside of the normal system paths on endpoint $Computer$, potentally related to DLL side-loading. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attackerkb.com/topics/7LstI2clmF/cve-2021-41379/rapid7-analysis](https://attackerkb.com/topics/7LstI2clmF/cve-2021-41379/rapid7-analysis) -* [https://github.com/klinix5/InstallerFileTakeOver](https://github.com/klinix5/InstallerFileTakeOver) -* [https://github.com/mandiant/red_team_tool_countermeasures/blob/master/rules/PGF/supplemental/hxioc/msi.dll%20Hijack%20(Methodology).ioc](https://github.com/mandiant/red_team_tool_countermeasures/blob/master/rules/PGF/supplemental/hxioc/msi.dll%20Hijack%20(Methodology).ioc) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/msi_module_loaded_by_non_system_binary.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-10-curl_download_and_bash_execution.md b/docs/_posts/2021-12-10-curl_download_and_bash_execution.md deleted file mode 100644 index fc7d368380..0000000000 --- a/docs/_posts/2021-12-10-curl_download_and_bash_execution.md +++ /dev/null @@ -1,172 +0,0 @@ ---- -title: "Curl Download and Bash Execution" -excerpt: "Ingress Tool Transfer -" -categories: - - Endpoint -last_modified_at: 2021-12-10 -toc: true -toc_label: "" -tags: - - Ingress Tool Transfer - - Command And Control - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2021-44228 - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the use of curl on Linux or MacOS attempting to download a file from a remote source and pipe it to bash. This is typically found with coinminers and most recently with CVE-2021-44228, a vulnerability in Log4j. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-12-10 -- **Author**: Michael Haag, Splunk -- **ID**: 900bc324-59f3-11ec-9fb4-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1105](https://attack.mitre.org/techniques/T1105/) | Ingress Tool Transfer | Command And Control | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2021-44228](https://nvd.nist.gov/vuln/detail/CVE-2021-44228) | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects. | 9.3 | - - - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=curl (Processes.process="*-s *") OR (Processes.process="* -|*" AND Processes.process="*bash*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `curl_download_and_bash_execution_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **curl_download_and_bash_execution_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon for Linux, you will need to ensure mapping is occurring correctly. If the EDR is not parsing the pipe bash in the command-line, modifying the analytic will be required. Add parent process name (Processes.parent_process_name) as needed to filter. - -#### Known False Positives -False positives should be limited, however filtering may be required. - -#### Associated Analytic story -* [Ingress Tool Transfer](/stories/ingress_tool_transfer) -* [Log4Shell CVE-2021-44228](/stories/log4shell_cve-2021-44228) -* [Linux Living Off The Land](/stories/linux_living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | An instance of $process_name$ was identified on endpoint $dest$ attempting to download a remote file and run it with bash. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.huntress.com/blog/rapid-response-critical-rce-vulnerability-is-affecting-java](https://www.huntress.com/blog/rapid-response-critical-rce-vulnerability-is-affecting-java) -* [https://www.lunasec.io/docs/blog/log4j-zero-day/](https://www.lunasec.io/docs/blog/log4j-zero-day/) -* [https://gist.github.com/nathanqthai/01808c569903f41a52e7e7b575caa890](https://gist.github.com/nathanqthai/01808c569903f41a52e7e7b575caa890) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1105/atomic_red_team/linux-sysmon_curlwget.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1105/atomic_red_team/linux-sysmon_curlwget.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/curl_download_and_bash_execution.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-11-wget_download_and_bash_execution.md b/docs/_posts/2021-12-11-wget_download_and_bash_execution.md deleted file mode 100644 index 3247414e8f..0000000000 --- a/docs/_posts/2021-12-11-wget_download_and_bash_execution.md +++ /dev/null @@ -1,171 +0,0 @@ ---- -title: "Wget Download and Bash Execution" -excerpt: "Ingress Tool Transfer -" -categories: - - Endpoint -last_modified_at: 2021-12-11 -toc: true -toc_label: "" -tags: - - Ingress Tool Transfer - - Command And Control - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2021-44228 - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the use of wget on Linux or MacOS attempting to download a file from a remote source and pipe it to bash. This is typically found with coinminers and most recently with CVE-2021-44228, a vulnerability in Log4j. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-12-11 -- **Author**: Michael Haag, Splunk -- **ID**: 35682718-5a85-11ec-b8f7-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1105](https://attack.mitre.org/techniques/T1105/) | Ingress Tool Transfer | Command And Control | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2021-44228](https://nvd.nist.gov/vuln/detail/CVE-2021-44228) | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects. | 9.3 | - - - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=wget (Processes.process="*-q *" OR Processes.process="*--quiet*" AND Processes.process="*-O- *") OR (Processes.process="* -|*" AND Processes.process="*bash*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `wget_download_and_bash_execution_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **wget_download_and_bash_execution_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon for Linux, you will need to ensure mapping is occurring correctly. If the EDR is not parsing the pipe bash in the command-line, modifying the analytic will be required. Add parent process name (Processes.parent_process_name) as needed to filter. - -#### Known False Positives -False positives should be limited, however filtering may be required. - -#### Associated Analytic story -* [Ingress Tool Transfer](/stories/ingress_tool_transfer) -* [Log4Shell CVE-2021-44228](/stories/log4shell_cve-2021-44228) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | An instance of $process_name$ was identified on endpoint $dest$ attempting to download a remote file and run it with bash. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.huntress.com/blog/rapid-response-critical-rce-vulnerability-is-affecting-java](https://www.huntress.com/blog/rapid-response-critical-rce-vulnerability-is-affecting-java) -* [https://www.lunasec.io/docs/blog/log4j-zero-day/](https://www.lunasec.io/docs/blog/log4j-zero-day/) -* [https://gist.github.com/nathanqthai/01808c569903f41a52e7e7b575caa890](https://gist.github.com/nathanqthai/01808c569903f41a52e7e7b575caa890) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1105/atomic_red_team/linux-sysmon_curlwget.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1105/atomic_red_team/linux-sysmon_curlwget.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/wget_download_and_bash_execution.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-13-detect_outbound_ldap_traffic.md b/docs/_posts/2021-12-13-detect_outbound_ldap_traffic.md deleted file mode 100644 index 8da17f93fe..0000000000 --- a/docs/_posts/2021-12-13-detect_outbound_ldap_traffic.md +++ /dev/null @@ -1,174 +0,0 @@ ---- -title: "Detect Outbound LDAP Traffic" -excerpt: "Exploit Public-Facing Application -, Command and Scripting Interpreter -" -categories: - - Network -last_modified_at: 2021-12-13 -toc: true -toc_label: "" -tags: - - Exploit Public-Facing Application - - Command and Scripting Interpreter - - Initial Access - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2021-44228 - - Network_Traffic ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -Malicious actors often abuse misconfigured LDAP servers or applications that use the LDAP servers in organizations. Outbound LDAP traffic should not be allowed outbound through your perimeter firewall. This search will help determine if you have any LDAP connections to IP addresses outside of private (RFC1918) address space. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Network_Traffic](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkTraffic) -- **Last Updated**: 2021-12-13 -- **Author**: Bhavin Patel, Johan Bjerke, Splunk -- **ID**: 5e06e262-d7cd-4216-b2f8-27b437e18458 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1190](https://attack.mitre.org/techniques/T1190/) | Exploit Public-Facing Application | Initial Access | - -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Command & Control -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.DS -* PR.PT -* DE.AE -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 12 -* CIS 13 - - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2021-44228](https://nvd.nist.gov/vuln/detail/CVE-2021-44228) | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects. | 9.3 | - - - -
-
- -#### Search - -``` - -| tstats earliest(_time) as earliest_time latest(_time) as latest_time values(All_Traffic.dest_ip) as dest_ip from datamodel=Network_Traffic.All_Traffic where All_Traffic.dest_port = 389 OR All_Traffic.dest_port = 636 AND NOT (All_Traffic.dest_ip = 10.0.0.0/8 OR All_Traffic.dest_ip=192.168.0.0/16 OR All_Traffic.dest_ip = 172.16.0.0/12) by All_Traffic.src_ip All_Traffic.dest_ip -|`drop_dm_object_name("All_Traffic")` -| where src_ip != dest_ip -| `security_content_ctime(latest_time)` -| `security_content_ctime(earliest_time)` -|`detect_outbound_ldap_traffic_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **detect_outbound_ldap_traffic_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* All_Traffic.dest_ip -* All_Traffic.dest_port -* All_Traffic.src_ip - - -#### How To Implement -You must be ingesting Zeek DNS and Zeek Conn data into Splunk. Zeek data should also be getting ingested in JSON format and should be mapped to the Network Traffic datamodels that are in use for this search. - -#### Known False Positives -Unknown at this moment. Outbound LDAP traffic should not be allowed outbound through your perimeter firewall. Please check those servers to verify if the activity is legitimate. - -#### Associated Analytic story -* [Log4Shell CVE-2021-44228](/stories/log4shell_cve-2021-44228) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 56.0 | 70 | 80 | An outbound LDAP connection from $src_ip$ in your infrastructure connecting to dest ip $dest_ip$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.govcert.ch/blog/zero-day-exploit-targeting-popular-java-library-log4j/](https://www.govcert.ch/blog/zero-day-exploit-targeting-popular-java-library-log4j/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/outbound_ldap/bro_conn.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/outbound_ldap/bro_conn.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/network/detect_outbound_ldap_traffic.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-13-java_class_file_download_by_java_user_agent.md b/docs/_posts/2021-12-13-java_class_file_download_by_java_user_agent.md deleted file mode 100644 index 836cd08fa5..0000000000 --- a/docs/_posts/2021-12-13-java_class_file_download_by_java_user_agent.md +++ /dev/null @@ -1,162 +0,0 @@ ---- -title: "Java Class File download by Java User Agent" -excerpt: "Exploit Public-Facing Application -" -categories: - - Endpoint -last_modified_at: 2021-12-13 -toc: true -toc_label: "" -tags: - - Exploit Public-Facing Application - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2021-44228 - - Web ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies a Java user agent performing a GET request for a .class file from the remote site. This is potentially indicative of exploitation of the Java application and may be related to current event CVE-2021-44228 (Log4Shell). - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Web](https://docs.splunk.com/Documentation/CIM/latest/User/Web) -- **Last Updated**: 2021-12-13 -- **Author**: Michael Haag, Splunk -- **ID**: 8281ce42-5c50-11ec-82d2-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1190](https://attack.mitre.org/techniques/T1190/) | Exploit Public-Facing Application | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2021-44228](https://nvd.nist.gov/vuln/detail/CVE-2021-44228) | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects. | 9.3 | - - - -
-
- -#### Search - -``` - -| tstats count from datamodel=Web where Web.http_user_agent="*Java*" Web.http_method="GET" Web.url="*.class*" by Web.http_user_agent Web.http_method, Web.url,Web.url_length Web.src, Web.dest -| `drop_dm_object_name("Web")` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `java_class_file_download_by_java_user_agent_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **java_class_file_download_by_java_user_agent_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Web.http_method -* Web.url -* Web.url_length -* Web.src -* Web.dest -* Web.http_user_agent - - -#### How To Implement -To successfully implement this search, you need to be ingesting web or proxy logs, or ensure it is being filled by a proxy like device, into the Web Datamodel. For additional filtering, allow list private IP space or restrict by known good. - -#### Known False Positives -Filtering may be required in some instances, filter as needed. - -#### Associated Analytic story -* [Log4Shell CVE-2021-44228](/stories/log4shell_cve-2021-44228) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 40.0 | 80 | 50 | A Java user agent $http_user_agent$ was performing a $http_method$ to retrieve a remote class file. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://arstechnica.com/information-technology/2021/12/as-log4shell-wreaks-havoc-payroll-service-reports-ransomware-attack/](https://arstechnica.com/information-technology/2021/12/as-log4shell-wreaks-havoc-payroll-service-reports-ransomware-attack/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/java/java.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/java/java.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/java_class_file_download_by_java_user_agent.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-13-linux_java_spawning_shell.md b/docs/_posts/2021-12-13-linux_java_spawning_shell.md deleted file mode 100644 index a36466edd5..0000000000 --- a/docs/_posts/2021-12-13-linux_java_spawning_shell.md +++ /dev/null @@ -1,169 +0,0 @@ ---- -title: "Linux Java Spawning Shell" -excerpt: "Exploit Public-Facing Application -" -categories: - - Endpoint -last_modified_at: 2021-12-13 -toc: true -toc_label: "" -tags: - - Exploit Public-Facing Application - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2021-44228 - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the process name of Java, Apache, or Tomcat spawning a Linux shell. This is potentially indicative of exploitation of the Java application and may be related to current event CVE-2021-44228 (Log4Shell). The shells included in the macro are "sh", "ksh", "zsh", "bash", "dash", "rbash", "fish", "csh', "tcsh', "ion", "eshell". Upon triage, review parallel processes and command-line arguments to determine legitimacy. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-12-13 -- **Author**: Michael Haag, Splunk -- **ID**: 7b09db8a-5c20-11ec-9945-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1190](https://attack.mitre.org/techniques/T1190/) | Exploit Public-Facing Application | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2021-44228](https://nvd.nist.gov/vuln/detail/CVE-2021-44228) | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects. | 9.3 | - - - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=java OR Processes.parent_process_name=apache OR Processes.parent_process_name=tomcat `linux_shells` by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `linux_java_spawning_shell_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [linux_shells](https://github.com/splunk/security_content/blob/develop/macros/linux_shells.yml) - -> :information_source: -> **linux_java_spawning_shell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon for Linux, you will need to ensure mapping is occurring correctly. Ensure EDR product is mapping OS Linux to the datamodel properly. Add any additional java process names for your environment to the analytic as needed. - -#### Known False Positives -Filtering may be required on internal developer build systems or classify assets as web facing and restrict the analytic based on asset type. - -#### Associated Analytic story -* [Hermetic Wiper](/stories/hermetic_wiper) -* [Log4Shell CVE-2021-44228](/stories/log4shell_cve-2021-44228) -* [Spring4Shell CVE-2022-22965](/stories/spring4shell_cve-2022-22965) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 40.0 | 80 | 50 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ spawning a Linux shell, potentially indicative of exploitation. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://blog.netlab.360.com/ten-families-of-malicious-samples-are-spreading-using-the-log4j2-vulnerability-now/](https://blog.netlab.360.com/ten-families-of-malicious-samples-are-spreading-using-the-log4j2-vulnerability-now/) -* [https://gist.github.com/olafhartong/916ebc673ba066537740164f7e7e1d72](https://gist.github.com/olafhartong/916ebc673ba066537740164f7e7e1d72) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_java_spawning_shell.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-13-log4shell_jndi_payload_injection_attempt.md b/docs/_posts/2021-12-13-log4shell_jndi_payload_injection_attempt.md deleted file mode 100644 index e7d29b449b..0000000000 --- a/docs/_posts/2021-12-13-log4shell_jndi_payload_injection_attempt.md +++ /dev/null @@ -1,178 +0,0 @@ ---- -title: "Log4Shell JNDI Payload Injection Attempt" -excerpt: "Exploit Public-Facing Application -" -categories: - - Web -last_modified_at: 2021-12-13 -toc: true -toc_label: "" -tags: - - Exploit Public-Facing Application - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2021-44228 - - Web ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -CVE-2021-44228 Log4Shell payloads can be injected via various methods, but on of the most common vectors injection is via Web calls. Many of the vulnerable java web applications that are using log4j have a web component to them are specially targets of this injection, specifically projects like Apache Struts, Flink, Druid, and Solr. The exploit is triggered by a LDAP lookup function in the log4j package, its invocation is similar to `${jndi:ldap://PAYLOAD_INJECTED}`, when executed against vulnerable web applications the invocation can be seen in various part of web logs. Specifically it has been successfully exploited via headers like X-Forwarded-For, User-Agent, Referer, and X-Api-Version. In this detection we first limit the scope of our search to the Web Datamodel and use the `| from datamodel` function to benefit from schema accelerated searching capabilities, mainly because the second part of the detection is pretty heavy, it runs a regex across all _raw events that looks for `${jndi:ldap://` pattern across all potential web fields available to the raw data, like http headers for example. If you see results for this detection, it means that there was a attempt at a injection, which could be a reconnaissance activity or a valid expliotation attempt, but this does not exactly mean that the host was indeed successfully exploited. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Web](https://docs.splunk.com/Documentation/CIM/latest/User/Web) -- **Last Updated**: 2021-12-13 -- **Author**: Jose Hernandez -- **ID**: c184f12e-5c90-11ec-bf1f-497c9a704a72 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1190](https://attack.mitre.org/techniques/T1190/) | Exploit Public-Facing Application | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2021-44228](https://nvd.nist.gov/vuln/detail/CVE-2021-44228) | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects. | 9.3 | - - - -
-
- -#### Search - -``` - -| from datamodel Web.Web -| regex _raw="[jJnNdDiI]{4}(\: -|\%3A -|\/ -|\%2F)\w+(\:\/\/ -|\%3A\%2F\%2F)(\$\{.*?\}(\.)?)?" -| fillnull -| stats count by action, category, dest, dest_port, http_content_type, http_method, http_referrer, http_user_agent, site, src, url, url_domain, user -| `log4shell_jndi_payload_injection_attempt_filter` -``` - -#### Macros -The SPL above uses the following Macros: - -> :information_source: -> **log4shell_jndi_payload_injection_attempt_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* action -* category -* dest -* dest_port -* http_content_type -* http_method -* http_referrer -* http_user_agent -* site -* src -* url -* url_domain -* user - - -#### How To Implement -This detection requires the Web datamodel to be populated from a supported Technology Add-On like Splunk for Apache or Splunk for Nginx. - -#### Known False Positives -If there is a vulnerablility scannner looking for log4shells this will trigger, otherwise likely to have low false positives. - -#### Associated Analytic story -* [Log4Shell CVE-2021-44228](/stories/log4shell_cve-2021-44228) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 50 | 30 | CVE-2021-44228 Log4Shell triggered for host $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.lunasec.io/docs/blog/log4j-zero-day/](https://www.lunasec.io/docs/blog/log4j-zero-day/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/log4j_proxy_logs/log4j_proxy_logs.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/log4j_proxy_logs/log4j_proxy_logs.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/web/log4shell_jndi_payload_injection_attempt.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-13-log4shell_jndi_payload_injection_with_outbound_connection.md b/docs/_posts/2021-12-13-log4shell_jndi_payload_injection_with_outbound_connection.md deleted file mode 100644 index 09319deb53..0000000000 --- a/docs/_posts/2021-12-13-log4shell_jndi_payload_injection_with_outbound_connection.md +++ /dev/null @@ -1,187 +0,0 @@ ---- -title: "Log4Shell JNDI Payload Injection with Outbound Connection" -excerpt: "Exploit Public-Facing Application -" -categories: - - Web -last_modified_at: 2021-12-13 -toc: true -toc_label: "" -tags: - - Exploit Public-Facing Application - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2021-44228 - - Network_Traffic - - Web ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -CVE-2021-44228 Log4Shell payloads can be injected via various methods, but on of the most common vectors injection is via Web calls. Many of the vulnerable java web applications that are using log4j have a web component to them are specially targets of this injection, specifically projects like Apache Struts, Flink, Druid, and Solr. The exploit is triggered by a LDAP lookup function in the log4j package, its invocation is similar to `${jndi:ldap://PAYLOAD_INJECTED}`, when executed against vulnerable web applications the invocation can be seen in various part of web logs. Specifically it has been successfully exploited via headers like X-Forwarded-For, User-Agent, Referer, and X-Api-Version. In this detection we match the invocation function with a network connection to a malicious ip address. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Network_Traffic](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkTraffic), [Web](https://docs.splunk.com/Documentation/CIM/latest/User/Web) -- **Last Updated**: 2021-12-13 -- **Author**: Jose Hernandez -- **ID**: 69afee44-5c91-11ec-bf1f-497c9a704a72 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1190](https://attack.mitre.org/techniques/T1190/) | Exploit Public-Facing Application | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2021-44228](https://nvd.nist.gov/vuln/detail/CVE-2021-44228) | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects. | 9.3 | - - - -
-
- -#### Search - -``` - -| from datamodel Web.Web -| rex field=_raw max_match=0 "[jJnNdDiI]{4}(\: -|\%3A -|\/ -|\%2F)(?\w+)(\:\/\/ -|\%3A\%2F\%2F)(\$\{.*?\}(\.)?)?(?[a-zA-Z0-9\.\-\_\$]+)" -| join affected_host type=inner [ -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Network_Traffic.All_Traffic by All_Traffic.dest -| `drop_dm_object_name(All_Traffic)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| rename dest AS affected_host] -| fillnull -| stats count by action, category, dest, dest_port, http_content_type, http_method, http_referrer, http_user_agent, site, src, url, url_domain, user -| `log4shell_jndi_payload_injection_with_outbound_connection_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **log4shell_jndi_payload_injection_with_outbound_connection_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* action -* category -* dest -* dest_port -* http_content_type -* http_method -* http_referrer -* http_user_agent -* site -* src -* url -* url_domain -* user - - -#### How To Implement -This detection requires the Web datamodel to be populated from a supported Technology Add-On like Splunk for Apache or Splunk for Nginx. - -#### Known False Positives -If there is a vulnerablility scannner looking for log4shells this will trigger, otherwise likely to have low false positives. - -#### Associated Analytic story -* [Log4Shell CVE-2021-44228](/stories/log4shell_cve-2021-44228) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 50 | 30 | CVE-2021-44228 Log4Shell triggered for host $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.lunasec.io/docs/blog/log4j-zero-day/](https://www.lunasec.io/docs/blog/log4j-zero-day/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/log4j_proxy_logs/log4j_proxy_logs.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/log4j_proxy_logs/log4j_proxy_logs.log) -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/log4j_network_logs/log4j_network_logs.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/log4j_network_logs/log4j_network_logs.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/web/log4shell_jndi_payload_injection_with_outbound_connection.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-13-outbound_network_connection_from_java_using_default_ports.md b/docs/_posts/2021-12-13-outbound_network_connection_from_java_using_default_ports.md deleted file mode 100644 index 83df26299f..0000000000 --- a/docs/_posts/2021-12-13-outbound_network_connection_from_java_using_default_ports.md +++ /dev/null @@ -1,171 +0,0 @@ ---- -title: "Outbound Network Connection from Java Using Default Ports" -excerpt: "Exploit Public-Facing Application -" -categories: - - Endpoint -last_modified_at: 2021-12-13 -toc: true -toc_label: "" -tags: - - Exploit Public-Facing Application - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2021-44228 ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -A required step while exploiting the CVE-2021-44228-Log4j vulnerability is that the victim server will perform outbound connections to attacker-controlled infrastructure. This is required as part of the JNDI lookup as well as for retrieving the second stage .class payload. The following analytic identifies the Java process reaching out to default ports used by the LDAP and RMI protocols. This behavior could represent successfull exploitation. Note that adversaries can easily decide to use arbitrary ports for these protocols and potentially bypass this detection. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2021-12-13 -- **Author**: Mauricio Velazco, Splunk -- **ID**: d2c14d28-5c47-11ec-9892-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1190](https://attack.mitre.org/techniques/T1190/) | Exploit Public-Facing Application | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2021-44228](https://nvd.nist.gov/vuln/detail/CVE-2021-44228) | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects. | 9.3 | - - - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where (Processes.process_name="java.exe" OR Processes.process_name=javaw.exe OR Processes.process_name=javaw.exe) by _time Processes.process_guid Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| join process_guid [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Ports where (Ports.dest_port= 389 OR Ports.dest_port= 636 OR Ports.dest_port = 1389 OR Ports.dest_port = 1099 ) by Ports.process_guid Ports.dest Ports.dest_port -| `drop_dm_object_name(Ports)` -| rename dest as connection_to_CNC] -| table _time dest parent_process_name process_name process_path process connection_to_CNC dest_port -| `outbound_network_connection_from_java_using_default_ports_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **outbound_network_connection_from_java_using_default_ports_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process_guid -* Processes.process_name -* Processes.dest -* Processes.process_path -* Processes.process -* Processes.parent_process_name -* Ports.process_guid -* Ports.dest -* Ports.dest_port - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Legitimate Java applications may use perform outbound connections to these ports. Filter as needed - -#### Associated Analytic story -* [Log4Shell CVE-2021-44228](/stories/log4shell_cve-2021-44228) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 54.0 | 90 | 60 | Java performed outbound connections to default ports of LDAP or RMI on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.lunasec.io/docs/blog/log4j-zero-day/](https://www.lunasec.io/docs/blog/log4j-zero-day/) -* [https://www.govcert.admin.ch/blog/zero-day-exploit-targeting-popular-java-library-log4j/](https://www.govcert.admin.ch/blog/zero-day-exploit-targeting-popular-java-library-log4j/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/outbound_java/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/outbound_java/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/outbound_network_connection_from_java_using_default_ports.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-13-windows_java_spawning_shells.md b/docs/_posts/2021-12-13-windows_java_spawning_shells.md deleted file mode 100644 index e831d6cb09..0000000000 --- a/docs/_posts/2021-12-13-windows_java_spawning_shells.md +++ /dev/null @@ -1,169 +0,0 @@ ---- -title: "Windows Java Spawning Shells" -excerpt: "Exploit Public-Facing Application -" -categories: - - Endpoint -last_modified_at: 2021-12-13 -toc: true -toc_label: "" -tags: - - Exploit Public-Facing Application - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2021-44228 - - Endpoint ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the process name of java.exe and w3wp.exe spawning a Windows shell. This is potentially indicative of exploitation of the Java application and may be related to current event CVE-2021-44228 (Log4Shell). The shells included in the macro are "cmd.exe", "powershell.exe". Upon triage, review parallel processes and command-line arguments to determine legitimacy. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-12-13 -- **Author**: Michael Haag, Splunk -- **ID**: 28c81306-5c47-11ec-bfea-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1190](https://attack.mitre.org/techniques/T1190/) | Exploit Public-Facing Application | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2021-44228](https://nvd.nist.gov/vuln/detail/CVE-2021-44228) | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects. | 9.3 | - - - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=java.exe OR Processes.parent_process_name=w3wp.exe `windows_shells` by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_java_spawning_shells_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [windows_shells](https://github.com/splunk/security_content/blob/develop/macros/windows_shells.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_java_spawning_shells_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. Restrict the analytic to publicly facing endpoints to reduce false positives. Add any additional identified web application process name to the query. Add any further Windows process names to the macro (ex. LOLBins) to further expand this query. - -#### Known False Positives -Filtering may be required on internal developer build systems or classify assets as web facing and restrict the analytic based on that. - -#### Associated Analytic story -* [Log4Shell CVE-2021-44228](/stories/log4shell_cve-2021-44228) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 40.0 | 80 | 50 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ spawning a Windows shell, potentially indicative of exploitation. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://blog.netlab.360.com/ten-families-of-malicious-samples-are-spreading-using-the-log4j2-vulnerability-now/](https://blog.netlab.360.com/ten-families-of-malicious-samples-are-spreading-using-the-log4j2-vulnerability-now/) -* [https://gist.github.com/olafhartong/916ebc673ba066537740164f7e7e1d72](https://gist.github.com/olafhartong/916ebc673ba066537740164f7e7e1d72) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/endpoint/windows_java_spawning_shells.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-14-hunting_for_log4shell.md b/docs/_posts/2021-12-14-hunting_for_log4shell.md deleted file mode 100644 index 639560890c..0000000000 --- a/docs/_posts/2021-12-14-hunting_for_log4shell.md +++ /dev/null @@ -1,291 +0,0 @@ ---- -title: "Hunting for Log4Shell" -excerpt: "Exploit Public-Facing Application -" -categories: - - Endpoint -last_modified_at: 2021-12-14 -toc: true -toc_label: "" -tags: - - Exploit Public-Facing Application - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2021-44228 - - Web ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following hunting query assists with quickly assessing CVE-2021-44228, or Log4Shell, activity mapped to the Web Datamodel. This is a combination query attempting to identify, score and dashboard. Because the Log4Shell vulnerability requires the string to be in the logs, this will work to identify the activity anywhere in the HTTP headers using _raw. Modify the first line to use the same pattern matching against other log sources. Scoring is based on a simple rubric of 0-5. 5 being the best match, and less than 5 meant to identify additional patterns that will equate to a higher total score. \ -The first jndi match identifies the standard pattern of `{jndi:` \ -jndi_fastmatch is meant to identify any jndi in the logs. The score is set low and is meant to be the "base" score used later. \ -jndi_proto is a protocol match that identifies `jndi` and one of `ldap, ldaps, rmi, dns, nis, iiop, corba, nds, http, https.` \ -all_match is a very well written regex by https://gist.github.com/Schvenn that identifies nearly all patterns of this attack behavior. \ -env works to identify environment variables in the header, meant to capture `AWS_ACCESS_KEY_ID`, `AWS_SECRET_ACCESS_KEY` and `env`. \ -uri_detect is string match looking for the common uri paths currently being scanned/abused in the wild. \ -keywords matches on enumerated values that, like `$ctx:loginId`, that may be found in the header used by the adversary. \ -lookup matching is meant to catch some basic obfuscation that has been identified using upper, lower and date. \ -Scoring will then occur based on any findings. The base score is meant to be 2 , created by jndi_fastmatch. Everything else is meant to increase that score. \ -Finally, a simple table is created to show the scoring and the _raw field. Sort based on score or columns of interest. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Web](https://docs.splunk.com/Documentation/CIM/latest/User/Web) -- **Last Updated**: 2021-12-14 -- **Author**: Michael Haag, Splunk -- **ID**: 158b68fa-5d1a-11ec-aac8-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1190](https://attack.mitre.org/techniques/T1190/) | Exploit Public-Facing Application | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2021-44228](https://nvd.nist.gov/vuln/detail/CVE-2021-44228) | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects. | 9.3 | - - - -
-
- -#### Search - -``` - -| from datamodel Web.Web -| eval jndi=if(match(_raw, "(\{ -|%7B)[jJnNdDiI]{4}:"),4,0) -| eval jndi_fastmatch=if(match(_raw, "[jJnNdDiI]{4}"),2,0) -| eval jndi_proto=if(match(_raw,"(?i)jndi:(ldap[s]? -|rmi -|dns -|nis -|iiop -|corba -|nds -|http -|https):"),5,0) -| eval all_match = if(match(_raw, "(?i)(%(25){0,}20 -|\s)*(%(25){0,}24 -|\$)(%(25){0,}20 -|\s)*(%(25){0,}7B -|{)(%(25){0,}20 -|\s)*(%(25){0,}(6A -|4A) -|J)(%(25){0,}(6E -|4E) -|N)(%(25){0,}(64 -|44) -|D)(%(25){0,}(69 -|49) -|I)(%(25){0,}20 -|\s)*(%(25){0,}3A -|:)[\w\%]+(%(25){1,}3A -|:)(%(25){1,}2F -|\/)[^\n]+"),5,0) -| eval env_var = if(match(_raw, "env:") OR match(_raw, "env:AWS_ACCESS_KEY_ID") OR match(_raw, "env:AWS_SECRET_ACCESS_KEY"),5,0) -| eval uridetect = if(match(_raw, "(?i)Basic\/Command\/Base64 -|Basic\/ReverseShell -|Basic\/TomcatMemshell -|Basic\/JBossMemshell -|Basic\/WebsphereMemshell -|Basic\/SpringMemshell -|Basic\/Command -|Deserialization\/CommonsCollectionsK -|Deserialization\/CommonsBeanutils -|Deserialization\/Jre8u20\/TomcatMemshell -|Deserialization\/CVE_2020_2555\/WeblogicMemshell -|TomcatBypass -|GroovyBypass -|WebsphereBypass"),4,0) -| eval keywords = if(match(_raw,"(?i)\$\{ctx\:loginId\} -|\$\{map\:type\} -|\$\{filename\} -|\$\{date\:MM-dd-yyyy\} -|\$\{docker\:containerId\} -|\$\{docker\:containerName\} -|\$\{docker\:imageName\} -|\$\{env\:USER\} -|\$\{event\:Marker\} -|\$\{mdc\:UserId\} -|\$\{java\:runtime\} -|\$\{java\:vm\} -|\$\{java\:os\} -|\$\{jndi\:logging/context-name\} -|\$\{hostName\} -|\$\{docker\:containerId\} -|\$\{k8s\:accountName\} -|\$\{k8s\:clusterName\} -|\$\{k8s\:containerId\} -|\$\{k8s\:containerName\} -|\$\{k8s\:host\} -|\$\{k8s\:labels.app\} -|\$\{k8s\:labels.podTemplateHash\} -|\$\{k8s\:masterUrl\} -|\$\{k8s\:namespaceId\} -|\$\{k8s\:namespaceName\} -|\$\{k8s\:podId\} -|\$\{k8s\:podIp\} -|\$\{k8s\:podName\} -|\$\{k8s\:imageId\} -|\$\{k8s\:imageName\} -|\$\{log4j\:configLocation\} -|\$\{log4j\:configParentLocation\} -|\$\{spring\:spring.application.name\} -|\$\{main\:myString\} -|\$\{main\:0\} -|\$\{main\:1\} -|\$\{main\:2\} -|\$\{main\:3\} -|\$\{main\:4\} -|\$\{main\:bar\} -|\$\{name\} -|\$\{marker\} -|\$\{marker\:name\} -|\$\{spring\:profiles.active[0] -|\$\{sys\:logPath\} -|\$\{web\:rootDir\} -|\$\{sys\:user.name\}"),4,0) -| eval obf = if(match(_raw, "(\$ -|%24)[^ /]*({ -|%7b)[^ /]*(j -|%6a)[^ /]*(n -|%6e)[^ /]*(d -|%64)[^ /]*(i -|%69)[^ /]*(: -|%3a)[^ /]*(: -|%3a)[^ /]*(/ -|%2f)"),5,0) -| eval lookups = if(match(_raw, "(?i)({ -|%7b)(main -|sys -|k8s -|spring -|lower -|upper -|env -|date -|sd)"),4,0) -| addtotals fieldname=Score, jndi, jndi_proto, env_var, uridetect, all_match, jndi_fastmatch, keywords, obf, lookups -| where Score > 2 -| stats values(Score) by jndi, jndi_proto, env_var, uridetect, all_match, jndi_fastmatch, keywords, lookups, obf, _raw -| `hunting_for_log4shell_filter` -``` - -#### Macros -The SPL above uses the following Macros: - -> :information_source: -> **hunting_for_log4shell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Web.http_method -* Web.url -* Web.url_length -* Web.src -* Web.dest -* Web.http_user_agent -* _raw - - -#### How To Implement -Out of the box, the Web datamodel is required to be pre-filled. However, tested was performed against raw httpd access logs. Change the first line to any dataset to pass the regex's against. - -#### Known False Positives -It is highly possible you will find false positives, however, the base score is set to 2 for _any_ jndi found in raw logs. tune and change as needed, include any filtering. - -#### Associated Analytic story -* [Log4Shell CVE-2021-44228](/stories/log4shell_cve-2021-44228) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 40.0 | 80 | 50 | Hunting for Log4Shell exploitation has occurred. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://gist.github.com/olafhartong/916ebc673ba066537740164f7e7e1d72](https://gist.github.com/olafhartong/916ebc673ba066537740164f7e7e1d72) -* [https://gist.github.com/Neo23x0/e4c8b03ff8cdf1fa63b7d15db6e3860b#gistcomment-3994449](https://gist.github.com/Neo23x0/e4c8b03ff8cdf1fa63b7d15db6e3860b#gistcomment-3994449) -* [https://regex101.com/r/OSrm0q/1/](https://regex101.com/r/OSrm0q/1/) -* [https://github.com/Neo23x0/signature-base/blob/master/yara/expl_log4j_cve_2021_44228.yar](https://github.com/Neo23x0/signature-base/blob/master/yara/expl_log4j_cve_2021_44228.yar) -* [https://news.sophos.com/en-us/2021/12/12/log4shell-hell-anatomy-of-an-exploit-outbreak/](https://news.sophos.com/en-us/2021/12/12/log4shell-hell-anatomy-of-an-exploit-outbreak/) -* [https://gist.github.com/MHaggis/1899b8554f38c8692a9fb0ceba60b44c](https://gist.github.com/MHaggis/1899b8554f38c8692a9fb0ceba60b44c) -* [https://twitter.com/sasi2103/status/1469764719850442760?s=20](https://twitter.com/sasi2103/status/1469764719850442760?s=20) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/java/log4shell-nginx.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/java/log4shell-nginx.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/hunting_for_log4shell.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-17-linux_add_files_in_known_crontab_directories.md b/docs/_posts/2021-12-17-linux_add_files_in_known_crontab_directories.md deleted file mode 100644 index 23d9044a7e..0000000000 --- a/docs/_posts/2021-12-17-linux_add_files_in_known_crontab_directories.md +++ /dev/null @@ -1,175 +0,0 @@ ---- -title: "Linux Add Files In Known Crontab Directories" -excerpt: "Cron -, Scheduled Task/Job -" -categories: - - Endpoint -last_modified_at: 2021-12-17 -toc: true -toc_label: "" -tags: - - Cron - - Scheduled Task/Job - - Execution - - Persistence - - Privilege Escalation - - Execution - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies a suspicious file creation in known cron table directories. This event is commonly abuse by malware, adversaries and red teamers to persist on the target or compromised host. crontab or cronjob is like a schedule task in windows environment where you can create an executable or script on the known crontab directories to run it base on its schedule. This Anomaly query is a good indicator to look further what file is added and who added the file if to consider it legitimate file. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-12-17 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 023f3452-5f27-11ec-bf00-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1053.003](https://attack.mitre.org/techniques/T1053/003/) | Cron | Execution, Persistence, Privilege Escalation | - -| [T1053](https://attack.mitre.org/techniques/T1053/) | Scheduled Task/Job | Execution, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_path IN ("*/etc/cron*", "*/var/spool/cron/*") by Filesystem.dest Filesystem.file_create_time Filesystem.file_name Filesystem.process_guid Filesystem.file_path -| `drop_dm_object_name(Filesystem)` -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `linux_add_files_in_known_crontab_directories_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **linux_add_files_in_known_crontab_directories_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Filesystem.dest -* Filesystem.file_create_time -* Filesystem.file_name -* Filesystem.process_guid -* Filesystem.file_path - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the file name, file path, and process_guid executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase. - -#### Known False Positives -Administrator or network operator can create file in crontab folders for automation purposes. Please update the filter macros to remove false positives. - -#### Associated Analytic story -* [Linux Privilege Escalation](/stories/linux_privilege_escalation) -* [Linux Persistence Techniques](/stories/linux_persistence_techniques) -* [Linux Living Off The Land](/stories/linux_living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | a file $file_name$ is created in $file_path$ on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.sandflysecurity.com/blog/detecting-cronrat-malware-on-linux-instantly/](https://www.sandflysecurity.com/blog/detecting-cronrat-malware-on-linux-instantly/) -* [https://www.cyberciti.biz/faq/how-do-i-add-jobs-to-cron-under-linux-or-unix-oses/](https://www.cyberciti.biz/faq/how-do-i-add-jobs-to-cron-under-linux-or-unix-oses/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.003/cronjobs_entry/sysmon_linux.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.003/cronjobs_entry/sysmon_linux.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_add_files_in_known_crontab_directories.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-17-linux_at_allow_config_file_creation.md b/docs/_posts/2021-12-17-linux_at_allow_config_file_creation.md deleted file mode 100644 index 5831abf03f..0000000000 --- a/docs/_posts/2021-12-17-linux_at_allow_config_file_creation.md +++ /dev/null @@ -1,174 +0,0 @@ ---- -title: "Linux At Allow Config File Creation" -excerpt: "Cron -, Scheduled Task/Job -" -categories: - - Endpoint -last_modified_at: 2021-12-17 -toc: true -toc_label: "" -tags: - - Cron - - Scheduled Task/Job - - Execution - - Persistence - - Privilege Escalation - - Execution - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies a suspicious file creation of /etc/at.allow or /etc/at.deny. These 2 files are commonly abused by malware, adversaries or red teamers to persist on the targeted or compromised host. These config files can restrict or allow user to execute "at" application (another schedule task application in linux). attacker can create a user or add the compromised username to that config file to execute "at" to schedule it malicious code. This anomaly detection can be a good indicator to investigate further the entry in created config file and who created it to verify if it is a false positive. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-12-17 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 977b3082-5f3d-11ec-b954-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1053.003](https://attack.mitre.org/techniques/T1053/003/) | Cron | Execution, Persistence, Privilege Escalation | - -| [T1053](https://attack.mitre.org/techniques/T1053/) | Scheduled Task/Job | Execution, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_path IN ("*/etc/at.allow", "*/etc/at.deny") by Filesystem.dest Filesystem.file_create_time Filesystem.file_name Filesystem.process_guid Filesystem.file_path -| `drop_dm_object_name(Filesystem)` -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `linux_at_allow_config_file_creation_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **linux_at_allow_config_file_creation_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Filesystem.dest -* Filesystem.file_create_time -* Filesystem.file_name -* Filesystem.process_guid -* Filesystem.file_path - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the file name, file path, and process_guid executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase. - -#### Known False Positives -Administrator or network operator can create this file for automation purposes. Please update the filter macros to remove false positives. - -#### Associated Analytic story -* [Linux Privilege Escalation](/stories/linux_privilege_escalation) -* [Linux Persistence Techniques](/stories/linux_persistence_techniques) -* [Linux Living Off The Land](/stories/linux_living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | A file $file_name$ is created in $file_path$ on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://linuxize.com/post/at-command-in-linux/](https://linuxize.com/post/at-command-in-linux/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.001/at_execution/sysmon_linux.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.001/at_execution/sysmon_linux.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_at_allow_config_file_creation.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-17-linux_at_application_execution.md b/docs/_posts/2021-12-17-linux_at_application_execution.md deleted file mode 100644 index 87c39a4da3..0000000000 --- a/docs/_posts/2021-12-17-linux_at_application_execution.md +++ /dev/null @@ -1,172 +0,0 @@ ---- -title: "Linux At Application Execution" -excerpt: "At (Linux) -, Scheduled Task/Job -" -categories: - - Endpoint -last_modified_at: 2021-12-17 -toc: true -toc_label: "" -tags: - - At (Linux) - - Scheduled Task/Job - - Execution - - Persistence - - Privilege Escalation - - Execution - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies a suspicious process creation of At application. This process can be used by malware, adversaries and red teamers to create persistence entry to the targeted or compromised host with their malicious code. This anomaly detection can be a good indicator to investigate the event before and after this process execution, when it was executed and what schedule task it will execute. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-12-17 -- **Author**: Teoderick Contreras, Splunk -- **ID**: bf0a378e-5f3c-11ec-a6de-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1053.001](https://attack.mitre.org/techniques/T1053/001/) | At (Linux) | Execution, Persistence, Privilege Escalation | - -| [T1053](https://attack.mitre.org/techniques/T1053/) | Scheduled Task/Job | Execution, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count from datamodel=Endpoint.Processes where Processes.process_name IN ("at", "atd") OR Processes.parent_process_name IN ("at", "atd") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.process_guid -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `linux_at_application_execution_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -Note that **linux_at_application_execution_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase. - -#### Known False Positives -Administrator or network operator can use this application for automation purposes. Please update the filter macros to remove false positives. - -#### Associated Analytic story -* [Linux Privilege Escalation](/stories/linux_privilege_escalation) -* [Linux Persistence Techniques](/stories/linux_persistence_techniques) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 9.0 | 30 | 30 | At application was executed in $dest$ | - - -#### Reference - -* [https://attack.mitre.org/techniques/T1053/001/](https://attack.mitre.org/techniques/T1053/001/) -* [https://www.linkedin.com/pulse/getting-attacker-ip-address-from-malicious-linux-job-craig-rowland/](https://www.linkedin.com/pulse/getting-attacker-ip-address-from-malicious-linux-job-craig-rowland/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.001/at_execution/sysmon_linux.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.001/at_execution/sysmon_linux.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_at_application_execution.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-17-linux_edit_cron_table_parameter.md b/docs/_posts/2021-12-17-linux_edit_cron_table_parameter.md deleted file mode 100644 index 23987f7b9a..0000000000 --- a/docs/_posts/2021-12-17-linux_edit_cron_table_parameter.md +++ /dev/null @@ -1,176 +0,0 @@ ---- -title: "Linux Edit Cron Table Parameter" -excerpt: "Cron -, Scheduled Task/Job -" -categories: - - Endpoint -last_modified_at: 2021-12-17 -toc: true -toc_label: "" -tags: - - Cron - - Scheduled Task/Job - - Execution - - Persistence - - Privilege Escalation - - Execution - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies a suspicious cronjobs modification using crontab edit parameter. This commandline parameter can be abuse by malware author, adversaries, and red red teamers to add cronjob entry to their malicious code to execute to the schedule they want. This event can also be executed by administrator or normal user for automation purposes so filter is needed. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-12-17 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 0d370304-5f26-11ec-a4bb-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1053.003](https://attack.mitre.org/techniques/T1053/003/) | Cron | Execution, Persistence, Privilege Escalation | - -| [T1053](https://attack.mitre.org/techniques/T1053/) | Scheduled Task/Job | Execution, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = crontab Processes.process = "*crontab *" Processes.process = "* -e*" by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `linux_edit_cron_table_parameter_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **linux_edit_cron_table_parameter_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase. - -#### Known False Positives -Administrator or network operator can use this application for automation purposes. Please update the filter macros to remove false positives. - -#### Associated Analytic story -* [Linux Privilege Escalation](/stories/linux_privilege_escalation) -* [Linux Persistence Techniques](/stories/linux_persistence_techniques) -* [Linux Living Off The Land](/stories/linux_living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 9.0 | 30 | 30 | A possible crontab edit command $process$ executed on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1053/003/](https://attack.mitre.org/techniques/T1053/003/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.003/crontab_edit_parameter/sysmon_linux.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.003/crontab_edit_parameter/sysmon_linux.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_edit_cron_table_parameter.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-17-linux_possible_append_command_to_at_allow_config_file.md b/docs/_posts/2021-12-17-linux_possible_append_command_to_at_allow_config_file.md deleted file mode 100644 index a38a673ce5..0000000000 --- a/docs/_posts/2021-12-17-linux_possible_append_command_to_at_allow_config_file.md +++ /dev/null @@ -1,172 +0,0 @@ ---- -title: "Linux Possible Append Command To At Allow Config File" -excerpt: "At (Linux) -, Scheduled Task/Job -" -categories: - - Endpoint -last_modified_at: 2021-12-17 -toc: true -toc_label: "" -tags: - - At (Linux) - - Scheduled Task/Job - - Execution - - Persistence - - Privilege Escalation - - Execution - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for suspicious commandline that may use to append user entry to /etc/at.allow or /etc/at.deny. These 2 files are commonly abused by malware, adversaries or red teamers to persist on the targeted or compromised host. These config file can restrict user that can only execute at application (another schedule task application in linux). attacker can create a user or add the compromised username to that config file to execute at to schedule it malicious code. This anomaly detection can be a good indicator to investigate further the entry in created config file and who created it to verify if it is a false positive. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-12-17 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 7bc20606-5f40-11ec-a586-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1053.001](https://attack.mitre.org/techniques/T1053/001/) | At (Linux) | Execution, Persistence, Privilege Escalation | - -| [T1053](https://attack.mitre.org/techniques/T1053/) | Scheduled Task/Job | Execution, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count from datamodel=Endpoint.Processes where Processes.process = "*echo*" AND Processes.process IN("*/etc/at.allow", "*/etc/at.deny") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.process_guid -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `linux_possible_append_command_to_at_allow_config_file_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -Note that **linux_possible_append_command_to_at_allow_config_file_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase. - -#### Known False Positives -Administrator or network operator can use this commandline for automation purposes. Please update the filter macros to remove false positives. - -#### Associated Analytic story -* [Linux Privilege Escalation](/stories/linux_privilege_escalation) -* [Linux Persistence Techniques](/stories/linux_persistence_techniques) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 9.0 | 30 | 30 | A commandline $process$ that may modify at allow config file in $dest$ | - - -#### Reference - -* [https://linuxize.com/post/at-command-in-linux/](https://linuxize.com/post/at-command-in-linux/) -* [https://attack.mitre.org/techniques/T1053/001/](https://attack.mitre.org/techniques/T1053/001/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.001/at_execution/sysmon_linux.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.001/at_execution/sysmon_linux.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_possible_append_command_to_at_allow_config_file.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-17-linux_possible_append_cronjob_entry_on_existing_cronjob_file.md b/docs/_posts/2021-12-17-linux_possible_append_cronjob_entry_on_existing_cronjob_file.md deleted file mode 100644 index 56f293a970..0000000000 --- a/docs/_posts/2021-12-17-linux_possible_append_cronjob_entry_on_existing_cronjob_file.md +++ /dev/null @@ -1,178 +0,0 @@ ---- -title: "Linux Possible Append Cronjob Entry on Existing Cronjob File" -excerpt: "Cron -, Scheduled Task/Job -" -categories: - - Endpoint -last_modified_at: 2021-12-17 -toc: true -toc_label: "" -tags: - - Cron - - Scheduled Task/Job - - Execution - - Persistence - - Privilege Escalation - - Execution - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for possible suspicious commandline that may use to append a code to any existing cronjob files for persistence or privilege escalation. This technique is commonly abused by malware, adversaries and red teamers to automatically execute their code within a existing or sometimes in normal cronjob script file. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-12-17 -- **Author**: Teoderick Contreras, Splunk -- **ID**: b5b91200-5f27-11ec-bb4e-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1053.003](https://attack.mitre.org/techniques/T1053/003/) | Cron | Execution, Persistence, Privilege Escalation | - -| [T1053](https://attack.mitre.org/techniques/T1053/) | Scheduled Task/Job | Execution, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count from datamodel=Endpoint.Processes where Processes.process = "*echo*" AND Processes.process IN("*/etc/cron*", "*/var/spool/cron/*", "*/etc/anacrontab*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.process_guid -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `linux_possible_append_cronjob_entry_on_existing_cronjob_file_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **linux_possible_append_cronjob_entry_on_existing_cronjob_file_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase. - -#### Known False Positives -Administrator or network operator can use this commandline for automation purposes. Please update the filter macros to remove false positives. - -#### Associated Analytic story -* [Linux Privilege Escalation](/stories/linux_privilege_escalation) -* [Linux Persistence Techniques](/stories/linux_persistence_techniques) -* [Linux Living Off The Land](/stories/linux_living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | A commandline $process$ that may modify cronjob file in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1053/003/](https://attack.mitre.org/techniques/T1053/003/) -* [https://blog.aquasec.com/threat-alert-kinsing-malware-container-vulnerability](https://blog.aquasec.com/threat-alert-kinsing-malware-container-vulnerability) -* [https://www.intezer.com/blog/research/kaiji-new-chinese-linux-malware-turning-to-golang/](https://www.intezer.com/blog/research/kaiji-new-chinese-linux-malware-turning-to-golang/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.003/cronjobs_entry/sysmon_linux.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.003/cronjobs_entry/sysmon_linux.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_possible_append_cronjob_entry_on_existing_cronjob_file.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-17-linux_possible_cronjob_modification_with_editor.md b/docs/_posts/2021-12-17-linux_possible_cronjob_modification_with_editor.md deleted file mode 100644 index 03e963a396..0000000000 --- a/docs/_posts/2021-12-17-linux_possible_cronjob_modification_with_editor.md +++ /dev/null @@ -1,176 +0,0 @@ ---- -title: "Linux Possible Cronjob Modification With Editor" -excerpt: "Cron -, Scheduled Task/Job -" -categories: - - Endpoint -last_modified_at: 2021-12-17 -toc: true -toc_label: "" -tags: - - Cron - - Scheduled Task/Job - - Execution - - Persistence - - Privilege Escalation - - Execution - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for possible modification of cronjobs file using editor. This event is can be seen in normal user but can also be a good hunting indicator for unwanted user modifying cronjobs for possible persistence or privilege escalation. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-12-17 -- **Author**: Teoderick Contreras, Splunk -- **ID**: dcc89bde-5f24-11ec-87ca-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1053.003](https://attack.mitre.org/techniques/T1053/003/) | Cron | Execution, Persistence, Privilege Escalation | - -| [T1053](https://attack.mitre.org/techniques/T1053/) | Scheduled Task/Job | Execution, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name IN("nano","vim.basic") OR Processes.process IN ("*nano *", "*vi *", "*vim *")) AND Processes.process IN("*/etc/cron*", "*/var/spool/cron/*", "*/etc/anacrontab*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `linux_possible_cronjob_modification_with_editor_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **linux_possible_cronjob_modification_with_editor_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase. - -#### Known False Positives -Administrator or network operator can use this commandline for automation purposes. Please update the filter macros to remove false positives. - -#### Associated Analytic story -* [Linux Privilege Escalation](/stories/linux_privilege_escalation) -* [Linux Persistence Techniques](/stories/linux_persistence_techniques) -* [Linux Living Off The Land](/stories/linux_living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 6.0 | 20 | 30 | A commandline $process$ that may modify cronjob file using editor in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1053/003/](https://attack.mitre.org/techniques/T1053/003/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.003/cronjobs_entry/sysmon_linux.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.003/cronjobs_entry/sysmon_linux.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_possible_cronjob_modification_with_editor.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-20-clear_unallocated_sector_using_cipher_app.md b/docs/_posts/2021-12-20-clear_unallocated_sector_using_cipher_app.md deleted file mode 100644 index 60c077cd42..0000000000 --- a/docs/_posts/2021-12-20-clear_unallocated_sector_using_cipher_app.md +++ /dev/null @@ -1,115 +0,0 @@ ---- -title: "Clear Unallocated Sector Using Cipher App" -excerpt: "File Deletion, Indicator Removal on Host" -categories: - - Endpoint -last_modified_at: 2021-12-20 -toc: true -toc_label: "" -tags: - - File Deletion - - Defense Evasion - - Indicator Removal on Host - - Defense Evasion - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -this search is to detect execution of `cipher.exe` to clear the unallocated sectors of a specific disk. This technique was seen in some ransomware to make it impossible to forensically recover deleted files. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2021-12-20 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 8f907d90-6173-11ec-9c23-acde48001122 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1070.004](https://attack.mitre.org/techniques/T1070/004/) | File Deletion | Defense Evasion | - -| [T1070](https://attack.mitre.org/techniques/T1070/) | Indicator Removal on Host | Defense Evasion | - -#### Search - -``` - -| from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line IS NOT NULL AND like(cmd_line, "%/w:%") AND process_name="cipher.exe" -| eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) -| into write_ssa_detected_events(); -``` - -#### Macros -The SPL above uses the following Macros: - -Note that `clear_unallocated_sector_using_cipher_app_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -administrator may execute this app to manage disk - -#### Associated Analytic story -* [Ransomware](/stories/ransomware) -* [Information Sabotage](/stories/information_sabotage) - - -#### Kill Chain Phase -* Exploitation - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 90.0 | 90 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to clear the unallocated sectors of a specific disk. | - - -Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` - - - -#### Reference - -* [https://unit42.paloaltonetworks.com/vatet-pyxie-defray777/3/](https://unit42.paloaltonetworks.com/vatet-pyxie-defray777/3/) -* [https://www.sophos.com/en-us/medialibrary/PDFs/technical-papers/sophoslabs-ransomware-behavior-report.pdf](https://www.sophos.com/en-us/medialibrary/PDFs/technical-papers/sophoslabs-ransomware-behavior-report.pdf) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070.004/cipher/security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070.004/cipher/security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-20-hiding_files_and_directories_with_attrib_exe.md b/docs/_posts/2021-12-20-hiding_files_and_directories_with_attrib_exe.md deleted file mode 100644 index 1e044103fd..0000000000 --- a/docs/_posts/2021-12-20-hiding_files_and_directories_with_attrib_exe.md +++ /dev/null @@ -1,104 +0,0 @@ ---- -title: "Hiding Files And Directories With Attrib exe" -excerpt: "Windows File and Directory Permissions Modification, File and Directory Permissions Modification" -categories: - - Endpoint -last_modified_at: 2021-12-20 -toc: true -toc_label: "" -tags: - - Windows File and Directory Permissions Modification - - Defense Evasion - - File and Directory Permissions Modification - - Defense Evasion - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Attackers leverage an existing Windows binary, attrib.exe, to mark specific as hidden by using specific flags so that the victim does not see the file. The search looks for specific command-line arguments to detect the use of attrib.exe to hide files. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2021-12-20 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 028e4406-6176-11ec-aec2-acde48001122 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1222.001](https://attack.mitre.org/techniques/T1222/001/) | Windows File and Directory Permissions Modification | Defense Evasion | - -| [T1222](https://attack.mitre.org/techniques/T1222/) | File and Directory Permissions Modification | Defense Evasion | - -#### Search - -``` - -| from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line IS NOT NULL AND match_regex(cmd_line, /\+h/)=true AND process_name="attrib.exe" -| eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) -| into write_ssa_detected_events(); -``` - -#### Macros -The SPL above uses the following Macros: - -Note that `hiding_files_and_directories_with_attrib_exe_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. - -#### Known False Positives -Some applications and users may legitimately use attrib.exe to interact with the files. - -#### Associated Analytic story -* [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics) -* [Windows Persistence Techniques](/stories/windows_persistence_techniques) -* [Information Sabotage](/stories/information_sabotage) - - -#### Kill Chain Phase -* Exploitation - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 72.0 | 80 | 90 | Attrib.exe with +h flag to hide files on $dest$ executed by $user$ is detected. | - - -Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` - - - -#### Reference - -* [https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/attrib](https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/attrib) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.001/attrib_hidden/security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.001/attrib_hidden/security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-20-linux_file_creation_in_init_boot_directory.md b/docs/_posts/2021-12-20-linux_file_creation_in_init_boot_directory.md deleted file mode 100644 index 6f00971b99..0000000000 --- a/docs/_posts/2021-12-20-linux_file_creation_in_init_boot_directory.md +++ /dev/null @@ -1,171 +0,0 @@ ---- -title: "Linux File Creation In Init Boot Directory" -excerpt: "RC Scripts -, Boot or Logon Initialization Scripts -" -categories: - - Endpoint -last_modified_at: 2021-12-20 -toc: true -toc_label: "" -tags: - - RC Scripts - - Boot or Logon Initialization Scripts - - Persistence - - Privilege Escalation - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for suspicious file creation on init system directories for automatic execution of script or file upon boot up. This technique is commonly abuse by adversaries, malware author and red teamer to persist on the targeted or compromised host. This behavior can be executed or use by an administrator or network operator to add script files or binary files as part of a task or automation. filter is needed. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-12-20 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 97d9cfb2-61ad-11ec-bb2d-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1037.004](https://attack.mitre.org/techniques/T1037/004/) | RC Scripts | Persistence, Privilege Escalation | - -| [T1037](https://attack.mitre.org/techniques/T1037/) | Boot or Logon Initialization Scripts | Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_path IN ("*/etc/init.d/*", "*/etc/rc.d/*", "*/sbin/init.d/*", "*/etc/rc.local*") by Filesystem.dest Filesystem.file_name Filesystem.process_guid Filesystem.file_path -| `drop_dm_object_name(Filesystem)` -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `linux_file_creation_in_init_boot_directory_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **linux_file_creation_in_init_boot_directory_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Filesystem.dest -* Filesystem.file_create_time -* Filesystem.file_name -* Filesystem.process_guid -* Filesystem.file_path - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the file name, file path, and process_guid executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase - -#### Known False Positives -Administrator or network operator can create file in this folders for automation purposes. Please update the filter macros to remove false positives. - -#### Associated Analytic story -* [Linux Privilege Escalation](/stories/linux_privilege_escalation) -* [Linux Persistence Techniques](/stories/linux_persistence_techniques) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | A file $file_name$ is created in $file_path$ on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.intezer.com/blog/research/kaiji-new-chinese-linux-malware-turning-to-golang/](https://www.intezer.com/blog/research/kaiji-new-chinese-linux-malware-turning-to-golang/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.004/linux_init_profile/sysmon_linux.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.004/linux_init_profile/sysmon_linux.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_file_creation_in_init_boot_directory.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-20-linux_file_creation_in_profile_directory.md b/docs/_posts/2021-12-20-linux_file_creation_in_profile_directory.md deleted file mode 100644 index 2dbf6a99e7..0000000000 --- a/docs/_posts/2021-12-20-linux_file_creation_in_profile_directory.md +++ /dev/null @@ -1,172 +0,0 @@ ---- -title: "Linux File Creation In Profile Directory" -excerpt: "Unix Shell Configuration Modification -, Event Triggered Execution -" -categories: - - Endpoint -last_modified_at: 2021-12-20 -toc: true -toc_label: "" -tags: - - Unix Shell Configuration Modification - - Event Triggered Execution - - Persistence - - Privilege Escalation - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for suspicious file creation in /etc/profile.d directory to automatically execute scripts by shell upon boot up of a linux machine. This technique is commonly abused by adversaries, malware and red teamers as a persistence mechanism to the targeted or compromised host. This Anomaly detection is a good indicator that someone wants to run a code after boot up which can be done also by the administrator or network operator for automation purposes. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-12-20 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 46ba0082-61af-11ec-9826-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1546.004](https://attack.mitre.org/techniques/T1546/004/) | Unix Shell Configuration Modification | Persistence, Privilege Escalation | - -| [T1546](https://attack.mitre.org/techniques/T1546/) | Event Triggered Execution | Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_path IN ("*/etc/profile.d/*") by Filesystem.dest Filesystem.file_create_time Filesystem.file_name Filesystem.process_guid Filesystem.file_path -| `drop_dm_object_name(Filesystem)` -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `linux_file_creation_in_profile_directory_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **linux_file_creation_in_profile_directory_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Filesystem.dest -* Filesystem.file_create_time -* Filesystem.file_name -* Filesystem.process_guid -* Filesystem.file_path - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the file name, file path, and process_guid executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase. - -#### Known False Positives -Administrator or network operator can create file in profile.d folders for automation purposes. Please update the filter macros to remove false positives. - -#### Associated Analytic story -* [Linux Privilege Escalation](/stories/linux_privilege_escalation) -* [Linux Persistence Techniques](/stories/linux_persistence_techniques) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 56.0 | 70 | 80 | A file $file_name$ is created in $file_path$ on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1546/004/](https://attack.mitre.org/techniques/T1546/004/) -* [https://www.intezer.com/blog/research/kaiji-new-chinese-linux-malware-turning-to-golang/](https://www.intezer.com/blog/research/kaiji-new-chinese-linux-malware-turning-to-golang/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.004/linux_init_profile/sysmon_linux.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.004/linux_init_profile/sysmon_linux.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_file_creation_in_profile_directory.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-20-linux_possible_append_command_to_profile_config_file.md b/docs/_posts/2021-12-20-linux_possible_append_command_to_profile_config_file.md deleted file mode 100644 index a9fdbc8fcb..0000000000 --- a/docs/_posts/2021-12-20-linux_possible_append_command_to_profile_config_file.md +++ /dev/null @@ -1,174 +0,0 @@ ---- -title: "Linux Possible Append Command To Profile Config File" -excerpt: "Unix Shell Configuration Modification -, Event Triggered Execution -" -categories: - - Endpoint -last_modified_at: 2021-12-20 -toc: true -toc_label: "" -tags: - - Unix Shell Configuration Modification - - Event Triggered Execution - - Persistence - - Privilege Escalation - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for suspicious command-lines that can be possibly used to modify user profile files to automatically execute scripts/executables by shell upon reboot of the machine. This technique is commonly abused by adversaries, malware and red teamers as persistence mechanism to the targeted or compromised host. This Anomaly detection is a good indicator that someone wants to run code after reboot which can be done also by the administrator or network operator for automation purposes. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-12-20 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 9c94732a-61af-11ec-91e3-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1546.004](https://attack.mitre.org/techniques/T1546/004/) | Unix Shell Configuration Modification | Persistence, Privilege Escalation | - -| [T1546](https://attack.mitre.org/techniques/T1546/) | Event Triggered Execution | Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process = "*echo*" AND Processes.process IN("*~/.bashrc", "*~/.bash_profile", "*/etc/profile", "~/.bash_login", "*~/.profile", "~/.bash_logout") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.process_guid -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `linux_possible_append_command_to_profile_config_file_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **linux_possible_append_command_to_profile_config_file_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase. - -#### Known False Positives -Administrator or network operator can use this commandline for automation purposes. Please update the filter macros to remove false positives. - -#### Associated Analytic story -* [Linux Privilege Escalation](/stories/linux_privilege_escalation) -* [Linux Persistence Techniques](/stories/linux_persistence_techniques) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | a commandline $process$ that may modify profile files in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://unix.stackexchange.com/questions/129143/what-is-the-purpose-of-bashrc-and-how-does-it-work](https://unix.stackexchange.com/questions/129143/what-is-the-purpose-of-bashrc-and-how-does-it-work) -* [https://attack.mitre.org/techniques/T1546/004/](https://attack.mitre.org/techniques/T1546/004/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.004/linux_init_profile/sysmon_linux.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.004/linux_init_profile/sysmon_linux.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_possible_append_command_to_profile_config_file.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-20-linux_service_file_created_in_systemd_directory.md b/docs/_posts/2021-12-20-linux_service_file_created_in_systemd_directory.md deleted file mode 100644 index 78dfaed993..0000000000 --- a/docs/_posts/2021-12-20-linux_service_file_created_in_systemd_directory.md +++ /dev/null @@ -1,177 +0,0 @@ ---- -title: "Linux Service File Created In Systemd Directory" -excerpt: "Systemd Timers -, Scheduled Task/Job -" -categories: - - Endpoint -last_modified_at: 2021-12-20 -toc: true -toc_label: "" -tags: - - Systemd Timers - - Scheduled Task/Job - - Execution - - Persistence - - Privilege Escalation - - Execution - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for suspicious file creation in systemd timer directory in linux platform. systemd is a system and service manager for Linux distributions. From the Windows perspective, this process fulfills the duties of wininit.exe and services.exe combined. At the risk of simplifying the functionality of systemd, it initializes a Linux system and starts relevant services that are defined in service unit files. Adversaries, malware and red teamers may abuse this this feature by stashing systemd service file to persist on the targetted or compromised host. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-12-20 -- **Author**: Teoderick Contreras, Splunk -- **ID**: c7495048-61b6-11ec-9a37-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1053.006](https://attack.mitre.org/techniques/T1053/006/) | Systemd Timers | Execution, Persistence, Privilege Escalation | - -| [T1053](https://attack.mitre.org/techniques/T1053/) | Scheduled Task/Job | Execution, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_name = *.service Filesystem.file_path IN ("*/etc/systemd/system*", "*/lib/systemd/system*", "*/usr/lib/systemd/system*", "*/run/systemd/system*", "*~/.config/systemd/*", "*~/.local/share/systemd/*","*/etc/systemd/user*", "*/lib/systemd/user*", "*/usr/lib/systemd/user*", "*/run/systemd/user*") by Filesystem.dest Filesystem.file_create_time Filesystem.file_name Filesystem.process_guid Filesystem.file_path -| `drop_dm_object_name(Filesystem)` -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `linux_service_file_created_in_systemd_directory_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **linux_service_file_created_in_systemd_directory_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Filesystem.dest -* Filesystem.file_create_time -* Filesystem.file_name -* Filesystem.process_guid -* Filesystem.file_path - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the file name, file path, and process_guid executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase. - -#### Known False Positives -Administrator or network operator can create file in systemd folders for automation purposes. Please update the filter macros to remove false positives. - -#### Associated Analytic story -* [Linux Privilege Escalation](/stories/linux_privilege_escalation) -* [Linux Persistence Techniques](/stories/linux_persistence_techniques) -* [Linux Living Off The Land](/stories/linux_living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 64.0 | 80 | 80 | A service file named as $file_path$ is created in systemd folder on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1053/006/](https://attack.mitre.org/techniques/T1053/006/) -* [https://www.intezer.com/blog/research/kaiji-new-chinese-linux-malware-turning-to-golang/](https://www.intezer.com/blog/research/kaiji-new-chinese-linux-malware-turning-to-golang/) -* [https://redcanary.com/blog/attck-t1501-understanding-systemd-service-persistence/](https://redcanary.com/blog/attck-t1501-understanding-systemd-service-persistence/) -* [https://github.com/microsoft/MSTIC-Sysmon/blob/main/linux/configs/attack-based/persistence/T1053.003_Cron_Activity.xml](https://github.com/microsoft/MSTIC-Sysmon/blob/main/linux/configs/attack-based/persistence/T1053.003_Cron_Activity.xml) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.006/service_systemd/sysmon_linux.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.006/service_systemd/sysmon_linux.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_service_file_created_in_systemd_directory.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-20-linux_service_restarted.md b/docs/_posts/2021-12-20-linux_service_restarted.md deleted file mode 100644 index 00f629bd59..0000000000 --- a/docs/_posts/2021-12-20-linux_service_restarted.md +++ /dev/null @@ -1,176 +0,0 @@ ---- -title: "Linux Service Restarted" -excerpt: "Systemd Timers -, Scheduled Task/Job -" -categories: - - Endpoint -last_modified_at: 2021-12-20 -toc: true -toc_label: "" -tags: - - Systemd Timers - - Scheduled Task/Job - - Execution - - Persistence - - Privilege Escalation - - Execution - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for restarted or re-enable services in linux platform. This technique can be executed or performed using systemctl or service tool application. Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence. When Windows boots up, it starts programs or applications called services that perform background system functions. Administrator may also create a legitimated service for a specific tool or normal application as part of task or automation, in this scenario it is suggested to look for the service path of the actual script or executable that register as service and who created the service for further verification. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-12-20 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 084275ba-61b8-11ec-8d64-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1053.006](https://attack.mitre.org/techniques/T1053/006/) | Systemd Timers | Execution, Persistence, Privilege Escalation | - -| [T1053](https://attack.mitre.org/techniques/T1053/) | Scheduled Task/Job | Execution, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name IN ("systemctl", "service") OR Processes.process IN ("*systemctl *", "*service *")) Processes.process IN ("*restart*", "*reload*", "*reenable*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.process_guid -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `linux_service_restarted_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **linux_service_restarted_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and commandline executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase. - -#### Known False Positives -Administrator or network operator can use this commandline for automation purposes. Please update the filter macros to remove false positives. - -#### Associated Analytic story -* [Linux Privilege Escalation](/stories/linux_privilege_escalation) -* [Linux Persistence Techniques](/stories/linux_persistence_techniques) -* [Linux Living Off The Land](/stories/linux_living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | A commandline $process$ that may create or start a service on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1543/003/](https://attack.mitre.org/techniques/T1543/003/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.006/service_systemd/sysmon_linux.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.006/service_systemd/sysmon_linux.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_service_restarted.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-20-linux_service_started_or_enabled.md b/docs/_posts/2021-12-20-linux_service_started_or_enabled.md deleted file mode 100644 index ac79b84055..0000000000 --- a/docs/_posts/2021-12-20-linux_service_started_or_enabled.md +++ /dev/null @@ -1,176 +0,0 @@ ---- -title: "Linux Service Started Or Enabled" -excerpt: "Systemd Timers -, Scheduled Task/Job -" -categories: - - Endpoint -last_modified_at: 2021-12-20 -toc: true -toc_label: "" -tags: - - Systemd Timers - - Scheduled Task/Job - - Execution - - Persistence - - Privilege Escalation - - Execution - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for created or enable services in linux platform. This technique can be executed or performed using systemctl or service tool application. Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence. When Windows boots up, it starts programs or applications called services that perform background system functions. Administrator may also create a legitimated service for a specific tool or normal application as part of task or automation, in this scenario it is suggested to look for the service path of the actual script or executable that register as service and who created the service for further verification. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-12-20 -- **Author**: Teoderick Contreras, Splunk -- **ID**: e0428212-61b7-11ec-88a3-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1053.006](https://attack.mitre.org/techniques/T1053/006/) | Systemd Timers | Execution, Persistence, Privilege Escalation | - -| [T1053](https://attack.mitre.org/techniques/T1053/) | Scheduled Task/Job | Execution, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name IN ("systemctl", "service") OR Processes.process IN ("*systemctl *", "*service *")) Processes.process IN ("* start *", "* enable *") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.process_guid -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `linux_service_started_or_enabled_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **linux_service_started_or_enabled_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase. - -#### Known False Positives -Administrator or network operator can use this commandline for automation purposes. Please update the filter macros to remove false positives. - -#### Associated Analytic story -* [Linux Privilege Escalation](/stories/linux_privilege_escalation) -* [Linux Persistence Techniques](/stories/linux_persistence_techniques) -* [Linux Living Off The Land](/stories/linux_living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 42.0 | 60 | 70 | a commandline $process$ that may create or start a service on $dest | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1543/003/](https://attack.mitre.org/techniques/T1543/003/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.006/service_systemd/sysmon_linux.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.006/service_systemd/sysmon_linux.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_service_started_or_enabled.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-20-suspicious_computer_account_name_change.md b/docs/_posts/2021-12-20-suspicious_computer_account_name_change.md deleted file mode 100644 index d59ae2807a..0000000000 --- a/docs/_posts/2021-12-20-suspicious_computer_account_name_change.md +++ /dev/null @@ -1,173 +0,0 @@ ---- -title: "Suspicious Computer Account Name Change" -excerpt: "Valid Accounts -, Domain Accounts -" -categories: - - Endpoint -last_modified_at: 2021-12-20 -toc: true -toc_label: "" -tags: - - Valid Accounts - - Domain Accounts - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2021-42287 - - CVE-2021-42278 - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -As part of the sAMAccountName Spoofing (CVE-2021-42278) and Domain Controller Impersonation (CVE-2021-42287) exploitation chain, adversaries need to create a new computer account name and rename it to match the name of a domain controller account without the ending '$'. In Windows Active Directory environments, computer account names always end with `$`. This analytic leverages Event Id 4781, `The name of an account was changed`, to identify a computer account rename event with a suspicious name that does not terminate with `$`. This behavior could represent an exploitation attempt of CVE-2021-42278 and CVE-2021-42287 for privilege escalation. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-12-20 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 35a61ed8-61c4-11ec-bc1e-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -| [T1078.002](https://attack.mitre.org/techniques/T1078/002/) | Domain Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2021-42287](https://nvd.nist.gov/vuln/detail/CVE-2021-42287) | Active Directory Domain Services Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-42278, CVE-2021-42282, CVE-2021-42291. | 6.5 | -| [CVE-2021-42278](https://nvd.nist.gov/vuln/detail/CVE-2021-42278) | Active Directory Domain Services Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-42282, CVE-2021-42287, CVE-2021-42291. | 6.5 | - - - -
-
- -#### Search - -``` -`wineventlog_security` EventCode=4781 Old_Account_Name="*$" New_Account_Name!="*$" -| table _time, ComputerName, Account_Name, Old_Account_Name, New_Account_Name -| `suspicious_computer_account_name_change_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) - -> :information_source: -> **suspicious_computer_account_name_change_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* ComputerName -* Account_Name -* Old_Account_Name -* New_Account_Name - - -#### How To Implement -To successfully implement this search, you need to be ingesting Windows event logs from your hosts. In addition, the Splunk Windows TA is needed. - -#### Known False Positives -Renaming a computer account name to a name that not end with '$' is highly unsual and may not have any legitimate scenarios. - -#### Associated Analytic story -* [sAMAccountName Spoofing and Domain Controller Impersonation](/stories/samaccountname_spoofing_and_domain_controller_impersonation) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 70.0 | 100 | 70 | A computer account $Old_Account_Name$ was renamed with a suspicious computer name | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://exploit.ph/cve-2021-42287-cve-2021-42278-weaponisation.html](https://exploit.ph/cve-2021-42287-cve-2021-42278-weaponisation.html) -* [https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42278](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42278) -* [https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42287](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42287) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078.002/samaccountname_spoofing/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078.002/samaccountname_spoofing/windows-security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/suspicious_computer_account_name_change.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-20-suspicious_kerberos_service_ticket_request.md b/docs/_posts/2021-12-20-suspicious_kerberos_service_ticket_request.md deleted file mode 100644 index 042d4f87c1..0000000000 --- a/docs/_posts/2021-12-20-suspicious_kerberos_service_ticket_request.md +++ /dev/null @@ -1,177 +0,0 @@ ---- -title: "Suspicious Kerberos Service Ticket Request" -excerpt: "Valid Accounts -, Domain Accounts -" -categories: - - Endpoint -last_modified_at: 2021-12-20 -toc: true -toc_label: "" -tags: - - Valid Accounts - - Domain Accounts - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2021-42287 - - CVE-2021-42278 - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -As part of the sAMAccountName Spoofing (CVE-2021-42278) and Domain Controller Impersonation (CVE-2021-42287) exploitation chain, adversaries will request and obtain a Kerberos Service Ticket (TGS) with a domain controller computer account as the Service Name. This Service Ticket can be then used to take control of the domain controller on the final part of the attack. This analytic leverages Event Id 4769, `A Kerberos service ticket was requested`, to identify an unusual TGS request where the Account_Name requesting the ticket matches the Service_Name field. This behavior could represent an exploitation attempt of CVE-2021-42278 and CVE-2021-42287 for privilege escalation. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-12-20 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 8b1297bc-6204-11ec-b7c4-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -| [T1078.002](https://attack.mitre.org/techniques/T1078/002/) | Domain Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2021-42287](https://nvd.nist.gov/vuln/detail/CVE-2021-42287) | Active Directory Domain Services Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-42278, CVE-2021-42282, CVE-2021-42291. | 6.5 | -| [CVE-2021-42278](https://nvd.nist.gov/vuln/detail/CVE-2021-42278) | Active Directory Domain Services Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-42282, CVE-2021-42287, CVE-2021-42291. | 6.5 | - - - -
-
- -#### Search - -``` - `wineventlog_security` EventCode=4769 -| eval isSuspicious = if(lower(Service_Name) = lower(mvindex(split(Account_Name,"@"),0)+"$"),1,0) -| where isSuspicious = 1 -| table _time, Client_Address, Account_Name, Service_Name, Failure_Code, isSuspicious -| `suspicious_kerberos_service_ticket_request_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) - -> :information_source: -> **suspicious_kerberos_service_ticket_request_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Service_Name -* Account_Name -* Client_Address -* Failure_Code - - -#### How To Implement -To successfully implement this search, you need to be ingesting Domain Controller and Kerberos events. The Advanced Security Audit policy setting `Audit Kerberos Authentication Service` within `Account Logon` needs to be enabled. - -#### Known False Positives -We have tested this detection logic with ~2 million 4769 events and did not identify false positives. However, they may be possible in certain environments. Filter as needed. - -#### Associated Analytic story -* [sAMAccountName Spoofing and Domain Controller Impersonation](/stories/samaccountname_spoofing_and_domain_controller_impersonation) -* [Active Directory Kerberos Attacks](/stories/active_directory_kerberos_attacks) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 60.0 | 100 | 60 | A suspicious Kerberos Service Ticket was requested by $Account_Name$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://exploit.ph/cve-2021-42287-cve-2021-42278-weaponisation.html](https://exploit.ph/cve-2021-42287-cve-2021-42278-weaponisation.html) -* [https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42278](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42278) -* [https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42287](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42287) -* [https://docs.microsoft.com/en-us/openspecs/windows_protocols/ms-sfu/02636893-7a1f-4357-af9a-b672e3e3de13](https://docs.microsoft.com/en-us/openspecs/windows_protocols/ms-sfu/02636893-7a1f-4357-af9a-b672e3e3de13) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078.002/samaccountname_spoofing/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078.002/samaccountname_spoofing/windows-security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/suspicious_kerberos_service_ticket_request.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-21-linux_add_user_account.md b/docs/_posts/2021-12-21-linux_add_user_account.md deleted file mode 100644 index 9584b01ede..0000000000 --- a/docs/_posts/2021-12-21-linux_add_user_account.md +++ /dev/null @@ -1,171 +0,0 @@ ---- -title: "Linux Add User Account" -excerpt: "Local Account -, Create Account -" -categories: - - Endpoint -last_modified_at: 2021-12-21 -toc: true -toc_label: "" -tags: - - Local Account - - Create Account - - Persistence - - Persistence - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for commands to create user accounts on the linux platform. This technique is commonly abuse by adversaries, malware author and red teamers to persist on the targeted or compromised host by creating new user with an elevated privilege. This Hunting query may catch normal creation of user by administrator so filter is needed. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-12-21 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 51fbcaf2-6259-11ec-b0f3-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1136.001](https://attack.mitre.org/techniques/T1136/001/) | Local Account | Persistence | - -| [T1136](https://attack.mitre.org/techniques/T1136/) | Create Account | Persistence | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count from datamodel=Endpoint.Processes where Processes.process_name IN ("useradd", "adduser") OR Processes.process IN ("*useradd *", "*adduser *") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.process_guid -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `linux_add_user_account_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **linux_add_user_account_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase. - -#### Known False Positives -Administrator or network operator can execute this command. Please update the filter macros to remove false positives. - -#### Associated Analytic story -* [Linux Privilege Escalation](/stories/linux_privilege_escalation) -* [Linux Persistence Techniques](/stories/linux_persistence_techniques) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | A commandline $process$ that may create user account on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://linuxize.com/post/how-to-create-users-in-linux-using-the-useradd-command/](https://linuxize.com/post/how-to-create-users-in-linux-using-the-useradd-command/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.003/linux_adduser/sysmon_linux.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.003/linux_adduser/sysmon_linux.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_add_user_account.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-21-linux_change_file_owner_to_root.md b/docs/_posts/2021-12-21-linux_change_file_owner_to_root.md deleted file mode 100644 index 5c20b23e48..0000000000 --- a/docs/_posts/2021-12-21-linux_change_file_owner_to_root.md +++ /dev/null @@ -1,173 +0,0 @@ ---- -title: "Linux Change File Owner To Root" -excerpt: "Linux and Mac File and Directory Permissions Modification -, File and Directory Permissions Modification -" -categories: - - Endpoint -last_modified_at: 2021-12-21 -toc: true -toc_label: "" -tags: - - Linux and Mac File and Directory Permissions Modification - - File and Directory Permissions Modification - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for a commandline that change the file owner to root using chown utility tool. This technique is commonly abuse by adversaries, malware author and red teamers to escalate privilege to the targeted or compromised host by changing the owner of their malicious file to root. This event is not so common in corporate network except from the administrator doing normal task that needs high privilege. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-12-21 -- **Author**: Teoderick Contreras, Splunk -- **ID**: c1400ea2-6257-11ec-ad49-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1222.002](https://attack.mitre.org/techniques/T1222/002/) | Linux and Mac File and Directory Permissions Modification | Defense Evasion | - -| [T1222](https://attack.mitre.org/techniques/T1222/) | File and Directory Permissions Modification | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name = chown OR Processes.process = "*chown *") AND Processes.process = "* root *" by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.process_guid -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `linux_change_file_owner_to_root_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **linux_change_file_owner_to_root_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase. - -#### Known False Positives -Administrator or network operator can execute this command. Please update the filter macros to remove false positives. - -#### Associated Analytic story -* [Linux Privilege Escalation](/stories/linux_privilege_escalation) -* [Linux Persistence Techniques](/stories/linux_persistence_techniques) -* [Linux Living Off The Land](/stories/linux_living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 64.0 | 80 | 80 | A commandline $process$ that may change ownership to root on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://unix.stackexchange.com/questions/101073/how-to-change-permissions-from-root-user-to-all-users](https://unix.stackexchange.com/questions/101073/how-to-change-permissions-from-root-user-to-all-users) -* [https://askubuntu.com/questions/617850/changing-from-user-to-superuser](https://askubuntu.com/questions/617850/changing-from-user-to-superuser) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.001/chmod_uid/sysmon_linux.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.001/chmod_uid/sysmon_linux.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_change_file_owner_to_root.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-21-linux_nopasswd_entry_in_sudoers_file.md b/docs/_posts/2021-12-21-linux_nopasswd_entry_in_sudoers_file.md deleted file mode 100644 index 31ddc7dcaa..0000000000 --- a/docs/_posts/2021-12-21-linux_nopasswd_entry_in_sudoers_file.md +++ /dev/null @@ -1,174 +0,0 @@ ---- -title: "Linux NOPASSWD Entry In Sudoers File" -excerpt: "Sudo and Sudo Caching -, Abuse Elevation Control Mechanism -" -categories: - - Endpoint -last_modified_at: 2021-12-21 -toc: true -toc_label: "" -tags: - - Sudo and Sudo Caching - - Abuse Elevation Control Mechanism - - Defense Evasion - - Privilege Escalation - - Defense Evasion - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to look for suspicious command lines that may add entry to /etc/sudoers with NOPASSWD attribute in linux platform. This technique is commonly abuse by adversaries, malware author and red teamers to gain elevated privilege to the targeted or compromised host. /etc/sudoers file controls who can run what commands users can execute on the machines and can also control whether user need a password to execute particular commands. This file is composed of aliases (basically variables) and user specifications. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-12-21 -- **Author**: Teoderick Contreras, Splunk -- **ID**: ab1e0d52-624a-11ec-8e0b-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1548.003](https://attack.mitre.org/techniques/T1548/003/) | Sudo and Sudo Caching | Defense Evasion, Privilege Escalation | - -| [T1548](https://attack.mitre.org/techniques/T1548/) | Abuse Elevation Control Mechanism | Defense Evasion, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process = "*NOPASSWD:*" by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.process_guid -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `linux_nopasswd_entry_in_sudoers_file_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **linux_nopasswd_entry_in_sudoers_file_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase. - -#### Known False Positives -Administrator or network operator can execute this command. Please update the filter macros to remove false positives. - -#### Associated Analytic story -* [Linux Privilege Escalation](/stories/linux_privilege_escalation) -* [Linux Persistence Techniques](/stories/linux_persistence_techniques) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 64.0 | 80 | 80 | a commandline $process$ executed on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://askubuntu.com/questions/334318/sudoers-file-enable-nopasswd-for-user-all-commands](https://askubuntu.com/questions/334318/sudoers-file-enable-nopasswd-for-user-all-commands) -* [https://help.ubuntu.com/community/Sudoers](https://help.ubuntu.com/community/Sudoers) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.003/nopasswd_sudoers/sysmon_linux.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.003/nopasswd_sudoers/sysmon_linux.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_nopasswd_entry_in_sudoers_file.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-21-linux_setuid_using_chmod_utility.md b/docs/_posts/2021-12-21-linux_setuid_using_chmod_utility.md deleted file mode 100644 index bf887c7bca..0000000000 --- a/docs/_posts/2021-12-21-linux_setuid_using_chmod_utility.md +++ /dev/null @@ -1,174 +0,0 @@ ---- -title: "Linux Setuid Using Chmod Utility" -excerpt: "Setuid and Setgid -, Abuse Elevation Control Mechanism -" -categories: - - Endpoint -last_modified_at: 2021-12-21 -toc: true -toc_label: "" -tags: - - Setuid and Setgid - - Abuse Elevation Control Mechanism - - Defense Evasion - - Privilege Escalation - - Defense Evasion - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for suspicious chmod utility execution to enable SUID bit. This allows a user to temporarily gain root access, usually in order to run a program. For example, only the root account is allowed to change the password information contained in the password database; If the SUID bit appears as an s, the file's owner also has execute permission to the file; if it appears as an S, the file's owner does not have execute permission. The second specialty permission is the SGID, or set group id bit. It is similar to the SUID bit, except it can temporarily change group membership, usually to execute a program. The SGID bit is set if an s or an S appears in the group section of permissions. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-12-21 -- **Author**: Teoderick Contreras, Splunk -- **ID**: bf0304b6-6250-11ec-9d7c-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1548.001](https://attack.mitre.org/techniques/T1548/001/) | Setuid and Setgid | Defense Evasion, Privilege Escalation | - -| [T1548](https://attack.mitre.org/techniques/T1548/) | Abuse Elevation Control Mechanism | Defense Evasion, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes WHERE (Processes.process_name = chmod OR Processes.process = "*chmod *") AND Processes.process IN("* g+s *", "* u+s *", "* 4777 *", "* 4577 *") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.process_guid -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `linux_setuid_using_chmod_utility_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **linux_setuid_using_chmod_utility_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase. - -#### Known False Positives -Administrator or network operator can execute this command. Please update the filter macros to remove false positives. - -#### Associated Analytic story -* [Linux Privilege Escalation](/stories/linux_privilege_escalation) -* [Linux Persistence Techniques](/stories/linux_persistence_techniques) -* [Linux Living Off The Land](/stories/linux_living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | a commandline $process$ that may set suid or sgid on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.hackingarticles.in/linux-privilege-escalation-using-capabilities/](https://www.hackingarticles.in/linux-privilege-escalation-using-capabilities/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.001/chmod_uid/sysmon_linux.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.001/chmod_uid/sysmon_linux.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_setuid_using_chmod_utility.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-21-linux_setuid_using_setcap_utility.md b/docs/_posts/2021-12-21-linux_setuid_using_setcap_utility.md deleted file mode 100644 index 3f84cbaeda..0000000000 --- a/docs/_posts/2021-12-21-linux_setuid_using_setcap_utility.md +++ /dev/null @@ -1,173 +0,0 @@ ---- -title: "Linux Setuid Using Setcap Utility" -excerpt: "Setuid and Setgid -, Abuse Elevation Control Mechanism -" -categories: - - Endpoint -last_modified_at: 2021-12-21 -toc: true -toc_label: "" -tags: - - Setuid and Setgid - - Abuse Elevation Control Mechanism - - Defense Evasion - - Privilege Escalation - - Defense Evasion - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for suspicious setcap utility execution to enable SUID bit. This allows a user to temporarily gain root access, usually in order to run a program. For example, only the root account is allowed to change the password information contained in the password database; If the SUID bit appears as an s, the file's owner also has execute permission to the file; if it appears as an S, the file's owner does not have execute permission. The second specialty permission is the SGID, or set group id bit. It is similar to the SUID bit, except it can temporarily change group membership, usually to execute a program. The SGID bit is set if an s or an S appears in the group section of permissions. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-12-21 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 9d96022e-6250-11ec-9a19-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1548.001](https://attack.mitre.org/techniques/T1548/001/) | Setuid and Setgid | Defense Evasion, Privilege Escalation | - -| [T1548](https://attack.mitre.org/techniques/T1548/) | Abuse Elevation Control Mechanism | Defense Evasion, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name = setcap OR Processes.process = "*setcap *") AND Processes.process IN ("* cap_setuid=ep *", "* cap_setuid+ep *", "* cap_net_bind_service+p *", "* cap_net_raw+ep *", "* cap_dac_read_search+ep *") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.process_guid -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `linux_setuid_using_setcap_utility_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **linux_setuid_using_setcap_utility_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase. - -#### Known False Positives -Administrator or network operator can execute this command. Please update the filter macros to remove false positives. - -#### Associated Analytic story -* [Linux Privilege Escalation](/stories/linux_privilege_escalation) -* [Linux Persistence Techniques](/stories/linux_persistence_techniques) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | A commandline $process$ that may set suid or sgid on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.hackingarticles.in/linux-privilege-escalation-using-capabilities/](https://www.hackingarticles.in/linux-privilege-escalation-using-capabilities/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.001/linux_setcap/sysmon_linux.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.001/linux_setcap/sysmon_linux.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_setuid_using_setcap_utility.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-21-linux_visudo_utility_execution.md b/docs/_posts/2021-12-21-linux_visudo_utility_execution.md deleted file mode 100644 index 3116da0cc8..0000000000 --- a/docs/_posts/2021-12-21-linux_visudo_utility_execution.md +++ /dev/null @@ -1,173 +0,0 @@ ---- -title: "Linux Visudo Utility Execution" -excerpt: "Sudo and Sudo Caching -, Abuse Elevation Control Mechanism -" -categories: - - Endpoint -last_modified_at: 2021-12-21 -toc: true -toc_label: "" -tags: - - Sudo and Sudo Caching - - Abuse Elevation Control Mechanism - - Defense Evasion - - Privilege Escalation - - Defense Evasion - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to looks for suspicious commandline that add entry to /etc/sudoers by using visudo utility tool in linux platform. This technique may abuse by adversaries, malware author and red teamers to gain elevated privilege to targeted or compromised host. /etc/sudoers file controls who can run what commands as what users on what machines and can also control special things such as whether you need a password for particular commands. The file is composed of aliases (basically variables) and user specifications (which control who can run what). - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-12-21 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 08c41040-624c-11ec-a71f-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1548.003](https://attack.mitre.org/techniques/T1548/003/) | Sudo and Sudo Caching | Defense Evasion, Privilege Escalation | - -| [T1548](https://attack.mitre.org/techniques/T1548/) | Abuse Elevation Control Mechanism | Defense Evasion, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = visudo by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.process_guid -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `linux_visudo_utility_execution_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **linux_visudo_utility_execution_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase. - -#### Known False Positives -Administrator or network operator can execute this command. Please update the filter macros to remove false positives. - -#### Associated Analytic story -* [Linux Privilege Escalation](/stories/linux_privilege_escalation) -* [Linux Persistence Techniques](/stories/linux_persistence_techniques) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 16.0 | 40 | 40 | A commandline $process$ executed on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://askubuntu.com/questions/334318/sudoers-file-enable-nopasswd-for-user-all-commands](https://askubuntu.com/questions/334318/sudoers-file-enable-nopasswd-for-user-all-commands) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.003/visudo/sysmon_linux.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.003/visudo/sysmon_linux.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_visudo_utility_execution.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-21-suspicious_ticket_granting_ticket_request.md b/docs/_posts/2021-12-21-suspicious_ticket_granting_ticket_request.md deleted file mode 100644 index 7eda0ed77a..0000000000 --- a/docs/_posts/2021-12-21-suspicious_ticket_granting_ticket_request.md +++ /dev/null @@ -1,171 +0,0 @@ ---- -title: "Suspicious Ticket Granting Ticket Request" -excerpt: "Valid Accounts -, Domain Accounts -" -categories: - - Endpoint -last_modified_at: 2021-12-21 -toc: true -toc_label: "" -tags: - - Valid Accounts - - Domain Accounts - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -As part of the sAMAccountName Spoofing (CVE-2021-42278) and Domain Controller Impersonation (CVE-2021-42287) exploitation chain, adversaries will need to request a Kerberos Ticket Granting Ticket (TGT) on behalf of the newly created and renamed computer account. The TGT request will be preceded by a computer account name event. This analytic leverages Event Id 4781, `The name of an account was changed` and event Id 4768 `A Kerberos authentication ticket (TGT) was requested` to correlate a sequence of events where the new computer account on event id 4781 matches the request account on event id 4768. This behavior could represent an exploitation attempt of CVE-2021-42278 and CVE-2021-42287 for privilege escalation. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-12-21 -- **Author**: Mauricio Velazco, Splunk -- **ID**: d77d349e-6269-11ec-9cfe-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -| [T1078.002](https://attack.mitre.org/techniques/T1078/002/) | Domain Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - `wineventlog_security` (EventCode=4781 Old_Account_Name="*$" New_Account_Name!="*$") OR (EventCode=4768 Account_Name!="*$") -| eval RenamedComputerAccount = coalesce(New_Account_Name, mvindex(Account_Name,0)) -| transaction RenamedComputerAccount startswith=(EventCode=4781) endswith=(EventCode=4768) -| eval short_lived=case((duration<2),"TRUE") -| search short_lived = TRUE -| table _time, ComputerName, EventCode, Account_Name,RenamedComputerAccount, short_lived -|`suspicious_ticket_granting_ticket_request_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) - -> :information_source: -> **suspicious_ticket_granting_ticket_request_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Old_Account_Name -* New_Account_Name -* Account_Name -* ComputerName - - -#### How To Implement -To successfully implement this search, you need to be ingesting Domain Controller and Kerberos events. The Advanced Security Audit policy setting `Audit Kerberos Authentication Service` within `Account Logon` needs to be enabled. - -#### Known False Positives -A computer account name change event inmediately followed by a kerberos TGT request with matching fields is unsual. However, legitimate behavior may trigger it. Filter as needed. - -#### Associated Analytic story -* [sAMAccountName Spoofing and Domain Controller Impersonation](/stories/samaccountname_spoofing_and_domain_controller_impersonation) -* [Active Directory Kerberos Attacks](/stories/active_directory_kerberos_attacks) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 60.0 | 100 | 60 | A suspicious TGT was requested was requested | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://exploit.ph/cve-2021-42287-cve-2021-42278-weaponisation.html](https://exploit.ph/cve-2021-42287-cve-2021-42278-weaponisation.html) -* [https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42278](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42278) -* [https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42287](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42287) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078.002/samaccountname_spoofing/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078.002/samaccountname_spoofing/windows-security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/suspicious_ticket_granting_ticket_request.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-22-linux_file_created_in_kernel_driver_directory.md b/docs/_posts/2021-12-22-linux_file_created_in_kernel_driver_directory.md deleted file mode 100644 index a86a4f7c18..0000000000 --- a/docs/_posts/2021-12-22-linux_file_created_in_kernel_driver_directory.md +++ /dev/null @@ -1,174 +0,0 @@ ---- -title: "Linux File Created In Kernel Driver Directory" -excerpt: "Kernel Modules and Extensions -, Boot or Logon Autostart Execution -" -categories: - - Endpoint -last_modified_at: 2021-12-22 -toc: true -toc_label: "" -tags: - - Kernel Modules and Extensions - - Boot or Logon Autostart Execution - - Persistence - - Privilege Escalation - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for suspicious file creation in kernel/driver directory in linux platform. This directory is known folder for all linux kernel module available within the system. so creation of file in this directory is a good indicator that there is a possible rootkit installation in the host machine. This technique was abuse by adversaries, malware author and red teamers to gain high privileges to their malicious code such us in kernel level. Even this event is not so common administrator or legitimate 3rd party tool may install driver or linux kernel module as part of its installation. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-12-22 -- **Author**: Teoderick Contreras, Splunk -- **ID**: b85bbeec-6326-11ec-9311-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1547.006](https://attack.mitre.org/techniques/T1547/006/) | Kernel Modules and Extensions | Persistence, Privilege Escalation | - -| [T1547](https://attack.mitre.org/techniques/T1547/) | Boot or Logon Autostart Execution | Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_path IN ("*/kernel/drivers/*") by Filesystem.dest Filesystem.file_name Filesystem.process_guid Filesystem.file_path -| `drop_dm_object_name(Filesystem)` -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `linux_file_created_in_kernel_driver_directory_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **linux_file_created_in_kernel_driver_directory_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Filesystem.dest -* Filesystem.file_create_time -* Filesystem.file_name -* Filesystem.process_guid -* Filesystem.file_path - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the file name, file path, and process_guid executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase. - -#### Known False Positives -Administrator or network operator can create file in this folders for automation purposes. Please update the filter macros to remove false positives. - -#### Associated Analytic story -* [Linux Privilege Escalation](/stories/linux_privilege_escalation) -* [Linux Persistence Techniques](/stories/linux_persistence_techniques) -* [Linux Rootkit](/stories/linux_rootkit) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 72.0 | 80 | 90 | A file $file_name$ is created in $file_path$ on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://docs.fedoraproject.org/en-US/fedora/rawhide/system-administrators-guide/kernel-module-driver-configuration/Working_with_Kernel_Modules/](https://docs.fedoraproject.org/en-US/fedora/rawhide/system-administrators-guide/kernel-module-driver-configuration/Working_with_Kernel_Modules/) -* [https://security.stackexchange.com/questions/175953/how-to-load-a-malicious-lkm-at-startup](https://security.stackexchange.com/questions/175953/how-to-load-a-malicious-lkm-at-startup) -* [https://0x00sec.org/t/kernel-rootkits-getting-your-hands-dirty/1485](https://0x00sec.org/t/kernel-rootkits-getting-your-hands-dirty/1485) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.006/loading_linux_kernel_module/sysmon_linux.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.006/loading_linux_kernel_module/sysmon_linux.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_file_created_in_kernel_driver_directory.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-22-linux_insert_kernel_module_using_insmod_utility.md b/docs/_posts/2021-12-22-linux_insert_kernel_module_using_insmod_utility.md deleted file mode 100644 index fa2fdafb1a..0000000000 --- a/docs/_posts/2021-12-22-linux_insert_kernel_module_using_insmod_utility.md +++ /dev/null @@ -1,176 +0,0 @@ ---- -title: "Linux Insert Kernel Module Using Insmod Utility" -excerpt: "Kernel Modules and Extensions -, Boot or Logon Autostart Execution -" -categories: - - Endpoint -last_modified_at: 2021-12-22 -toc: true -toc_label: "" -tags: - - Kernel Modules and Extensions - - Boot or Logon Autostart Execution - - Persistence - - Privilege Escalation - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for inserting of linux kernel module using insmod utility function. This event can detect a installation of rootkit or malicious kernel module to gain elevated privileges to their malicious code and bypassed detections. This Anomaly detection is a good indicator that someone installing kernel module in a linux host either admin or adversaries. filter is needed in this scenario - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-12-22 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 18b5a1a0-6326-11ec-943a-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1547.006](https://attack.mitre.org/techniques/T1547/006/) | Kernel Modules and Extensions | Persistence, Privilege Escalation | - -| [T1547](https://attack.mitre.org/techniques/T1547/) | Boot or Logon Autostart Execution | Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name IN("kmod", "sudo") AND Processes.process = *insmod* by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.process_guid -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `linux_insert_kernel_module_using_insmod_utility_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **linux_insert_kernel_module_using_insmod_utility_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase. - -#### Known False Positives -Administrator or network operator can execute this command. Please update the filter macros to remove false positives. - -#### Associated Analytic story -* [Linux Privilege Escalation](/stories/linux_privilege_escalation) -* [Linux Persistence Techniques](/stories/linux_persistence_techniques) -* [Linux Rootkit](/stories/linux_rootkit) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 64.0 | 80 | 80 | A commandline $process$ that may install kernel module on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://docs.fedoraproject.org/en-US/fedora/rawhide/system-administrators-guide/kernel-module-driver-configuration/Working_with_Kernel_Modules/](https://docs.fedoraproject.org/en-US/fedora/rawhide/system-administrators-guide/kernel-module-driver-configuration/Working_with_Kernel_Modules/) -* [https://security.stackexchange.com/questions/175953/how-to-load-a-malicious-lkm-at-startup](https://security.stackexchange.com/questions/175953/how-to-load-a-malicious-lkm-at-startup) -* [https://0x00sec.org/t/kernel-rootkits-getting-your-hands-dirty/1485](https://0x00sec.org/t/kernel-rootkits-getting-your-hands-dirty/1485) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.006/loading_linux_kernel_module/sysmon_linux.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.006/loading_linux_kernel_module/sysmon_linux.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_insert_kernel_module_using_insmod_utility.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-22-linux_install_kernel_module_using_modprobe_utility.md b/docs/_posts/2021-12-22-linux_install_kernel_module_using_modprobe_utility.md deleted file mode 100644 index c206c91c05..0000000000 --- a/docs/_posts/2021-12-22-linux_install_kernel_module_using_modprobe_utility.md +++ /dev/null @@ -1,176 +0,0 @@ ---- -title: "Linux Install Kernel Module Using Modprobe Utility" -excerpt: "Kernel Modules and Extensions -, Boot or Logon Autostart Execution -" -categories: - - Endpoint -last_modified_at: 2021-12-22 -toc: true -toc_label: "" -tags: - - Kernel Modules and Extensions - - Boot or Logon Autostart Execution - - Persistence - - Privilege Escalation - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for possible installing a linux kernel module using modprobe utility function. This event can detect a installation of rootkit or malicious kernel module to gain elevated privileges to their malicious code and bypassed detections. This Anomaly detection is a good indicator that someone installing kernel module in a linux host either admin or adversaries. filter is needed in this scenario - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-12-22 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 387b278a-6326-11ec-aa2c-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1547.006](https://attack.mitre.org/techniques/T1547/006/) | Kernel Modules and Extensions | Persistence, Privilege Escalation | - -| [T1547](https://attack.mitre.org/techniques/T1547/) | Boot or Logon Autostart Execution | Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name IN("kmod", "sudo") AND Processes.process = *modprobe* by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.process_guid -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `linux_install_kernel_module_using_modprobe_utility_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **linux_install_kernel_module_using_modprobe_utility_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase. - -#### Known False Positives -Administrator or network operator can execute this command. Please update the filter macros to remove false positives. - -#### Associated Analytic story -* [Linux Privilege Escalation](/stories/linux_privilege_escalation) -* [Linux Persistence Techniques](/stories/linux_persistence_techniques) -* [Linux Rootkit](/stories/linux_rootkit) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 64.0 | 80 | 80 | A commandline $process$ that may install kernel module on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://docs.fedoraproject.org/en-US/fedora/rawhide/system-administrators-guide/kernel-module-driver-configuration/Working_with_Kernel_Modules/](https://docs.fedoraproject.org/en-US/fedora/rawhide/system-administrators-guide/kernel-module-driver-configuration/Working_with_Kernel_Modules/) -* [https://security.stackexchange.com/questions/175953/how-to-load-a-malicious-lkm-at-startup](https://security.stackexchange.com/questions/175953/how-to-load-a-malicious-lkm-at-startup) -* [https://0x00sec.org/t/kernel-rootkits-getting-your-hands-dirty/1485](https://0x00sec.org/t/kernel-rootkits-getting-your-hands-dirty/1485) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.006/loading_linux_kernel_module/sysmon_linux.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.006/loading_linux_kernel_module/sysmon_linux.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_install_kernel_module_using_modprobe_utility.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-22-linux_preload_hijack_library_calls.md b/docs/_posts/2021-12-22-linux_preload_hijack_library_calls.md deleted file mode 100644 index ecf91245bd..0000000000 --- a/docs/_posts/2021-12-22-linux_preload_hijack_library_calls.md +++ /dev/null @@ -1,175 +0,0 @@ ---- -title: "Linux Preload Hijack Library Calls" -excerpt: "Dynamic Linker Hijacking -, Hijack Execution Flow -" -categories: - - Endpoint -last_modified_at: 2021-12-22 -toc: true -toc_label: "" -tags: - - Dynamic Linker Hijacking - - Hijack Execution Flow - - Defense Evasion - - Persistence - - Privilege Escalation - - Defense Evasion - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to detect a suspicious command that may hijack a library function in linux platform. This technique is commonly abuse by adversaries, malware author and red teamers to gain privileges and persist on the machine. This detection pertains to loading a dll to hijack or hook a library function of specific program using LD_PRELOAD command. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-12-22 -- **Author**: Teoderick Contreras, Splunk -- **ID**: cbe2ca30-631e-11ec-8670-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1574.006](https://attack.mitre.org/techniques/T1574/006/) | Dynamic Linker Hijacking | Defense Evasion, Persistence, Privilege Escalation | - -| [T1574](https://attack.mitre.org/techniques/T1574/) | Hijack Execution Flow | Defense Evasion, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process = "*LD_PRELOAD*" by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.process_guid -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `linux_preload_hijack_library_calls_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **linux_preload_hijack_library_calls_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase - -#### Known False Positives -Administrator or network operator can execute this command. Please update the filter macros to remove false positives. - -#### Associated Analytic story -* [Linux Privilege Escalation](/stories/linux_privilege_escalation) -* [Linux Persistence Techniques](/stories/linux_persistence_techniques) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 64.0 | 80 | 80 | A commandline $process$ that may hijack library function on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://compilepeace.medium.com/memory-malware-part-0x2-writing-userland-rootkits-via-ld-preload-30121c8343d5](https://compilepeace.medium.com/memory-malware-part-0x2-writing-userland-rootkits-via-ld-preload-30121c8343d5) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1574.006/lib_hijack/sysmon_linux.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1574.006/lib_hijack/sysmon_linux.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_preload_hijack_library_calls.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-23-linux_common_process_for_elevation_control.md b/docs/_posts/2021-12-23-linux_common_process_for_elevation_control.md deleted file mode 100644 index 42458b714f..0000000000 --- a/docs/_posts/2021-12-23-linux_common_process_for_elevation_control.md +++ /dev/null @@ -1,177 +0,0 @@ ---- -title: "Linux Common Process For Elevation Control" -excerpt: "Setuid and Setgid -, Abuse Elevation Control Mechanism -" -categories: - - Endpoint -last_modified_at: 2021-12-23 -toc: true -toc_label: "" -tags: - - Setuid and Setgid - - Abuse Elevation Control Mechanism - - Defense Evasion - - Privilege Escalation - - Defense Evasion - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to look for possible elevation control access using a common known process in linux platform to change the attribute and file ownership. This technique is commonly abused by adversaries, malware author and red teamers to gain persistence or privilege escalation on the target or compromised host. This common process is used to modify file attribute, file ownership or SUID. This tools can be used in legitimate purposes so filter is needed. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-12-23 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 66ab15c0-63d0-11ec-9e70-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1548.001](https://attack.mitre.org/techniques/T1548/001/) | Setuid and Setgid | Defense Evasion, Privilege Escalation | - -| [T1548](https://attack.mitre.org/techniques/T1548/) | Abuse Elevation Control Mechanism | Defense Evasion, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name IN ("chmod", "chown", "fchmod", "fchmodat", "fchown", "fchownat", "fremovexattr", "fsetxattr", "lchown", "lremovexattr", "lsetxattr", "removexattr", "setuid", "setgid", "setreuid", "setregid", "chattr") OR Processes.process IN ("*chmod *", "*chown *", "*fchmod *", "*fchmodat *", "*fchown *", "*fchownat *", "*fremovexattr *", "*fsetxattr *", "*lchown *", "*lremovexattr *", "*lsetxattr *", "*removexattr *", "*setuid *", "*setgid *", "*setreuid *", "*setregid *", "*setcap *", "*chattr *") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.process_guid -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `linux_common_process_for_elevation_control_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **linux_common_process_for_elevation_control_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase. - -#### Known False Positives -Administrator or network operator can execute this command. Please update the filter macros to remove false positives. - -#### Associated Analytic story -* [Linux Privilege Escalation](/stories/linux_privilege_escalation) -* [Linux Persistence Techniques](/stories/linux_persistence_techniques) -* [Linux Living Off The Land](/stories/linux_living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 9.0 | 30 | 30 | A commandline $process$ with process $process_name$ on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1548/001/](https://attack.mitre.org/techniques/T1548/001/) -* [https://github.com/Neo23x0/auditd/blob/master/audit.rules#L285-L297](https://github.com/Neo23x0/auditd/blob/master/audit.rules#L285-L297) -* [https://github.com/bfuzzy1/auditd-attack/blob/master/auditd-attack/auditd-attack.rules#L269-L270](https://github.com/bfuzzy1/auditd-attack/blob/master/auditd-attack/auditd-attack.rules#L269-L270) -* [https://github.com/microsoft/MSTIC-Sysmon/blob/main/linux/configs/attack-based/privilege_escalation/T1548.001_ElevationControl_CommonProcesses.xml](https://github.com/microsoft/MSTIC-Sysmon/blob/main/linux/configs/attack-based/privilege_escalation/T1548.001_ElevationControl_CommonProcesses.xml) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.001/chmod_uid/sysmon_linux.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.001/chmod_uid/sysmon_linux.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_common_process_for_elevation_control.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-23-linux_sudoers_tmp_file_creation.md b/docs/_posts/2021-12-23-linux_sudoers_tmp_file_creation.md deleted file mode 100644 index 0087e4ed82..0000000000 --- a/docs/_posts/2021-12-23-linux_sudoers_tmp_file_creation.md +++ /dev/null @@ -1,171 +0,0 @@ ---- -title: "Linux Sudoers Tmp File Creation" -excerpt: "Sudo and Sudo Caching -, Abuse Elevation Control Mechanism -" -categories: - - Endpoint -last_modified_at: 2021-12-23 -toc: true -toc_label: "" -tags: - - Sudo and Sudo Caching - - Abuse Elevation Control Mechanism - - Defense Evasion - - Privilege Escalation - - Defense Evasion - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to looks for file creation of sudoers.tmp file cause by editing /etc/sudoers using visudo or editor in linux platform. This technique may abuse by adversaries, malware author and red teamers to gain elevated privilege to targeted or compromised host. /etc/sudoers file controls who can run what commands as what users on what machines and can also control special things such as whether you need a password for particular commands. The file is composed of aliases (basically variables) and user specifications (which control who can run what). - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-12-23 -- **Author**: Teoderick Contreras, Splunk -- **ID**: be254a5c-63e7-11ec-89da-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1548.003](https://attack.mitre.org/techniques/T1548/003/) | Sudo and Sudo Caching | Defense Evasion, Privilege Escalation | - -| [T1548](https://attack.mitre.org/techniques/T1548/) | Abuse Elevation Control Mechanism | Defense Evasion, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_path IN ("*sudoers.tmp*") by Filesystem.dest Filesystem.file_name Filesystem.process_guid Filesystem.file_path -| `drop_dm_object_name(Filesystem)` -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `linux_sudoers_tmp_file_creation_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **linux_sudoers_tmp_file_creation_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Filesystem.dest -* Filesystem.file_create_time -* Filesystem.file_name -* Filesystem.process_guid -* Filesystem.file_path - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase. - -#### Known False Positives -administrator or network operator can execute this command. Please update the filter macros to remove false positives. - -#### Associated Analytic story -* [Linux Privilege Escalation](/stories/linux_privilege_escalation) -* [Linux Persistence Techniques](/stories/linux_persistence_techniques) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 72.0 | 80 | 90 | A file $file_name$ is created in $file_path$ on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://forum.ubuntuusers.de/topic/sudo-visudo-gibt-etc-sudoers-tmp/](https://forum.ubuntuusers.de/topic/sudo-visudo-gibt-etc-sudoers-tmp/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.003/sudoers_temp/sysmon_linux.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.003/sudoers_temp/sysmon_linux.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_sudoers_tmp_file_creation.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-01-04-linux_sudo_or_su_execution.md b/docs/_posts/2022-01-04-linux_sudo_or_su_execution.md deleted file mode 100644 index 339e2ffa54..0000000000 --- a/docs/_posts/2022-01-04-linux_sudo_or_su_execution.md +++ /dev/null @@ -1,173 +0,0 @@ ---- -title: "Linux Sudo OR Su Execution" -excerpt: "Sudo and Sudo Caching -, Abuse Elevation Control Mechanism -" -categories: - - Endpoint -last_modified_at: 2022-01-04 -toc: true -toc_label: "" -tags: - - Sudo and Sudo Caching - - Abuse Elevation Control Mechanism - - Defense Evasion - - Privilege Escalation - - Defense Evasion - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to detect the execution of sudo or su command in linux operating system. The "sudo" command allows a system administrator to delegate authority to give certain users (or groups of users) the ability to run some (or all) commands as root or another user while providing an audit trail of the commands and their arguments. This command is commonly abused by adversaries, malware author and red teamers to elevate privileges to the targeted host. This command can be executed by administrator for legitimate purposes or to execute process that need admin privileges, In this scenario filter is needed. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-01-04 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 4b00f134-6d6a-11ec-a90c-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1548.003](https://attack.mitre.org/techniques/T1548/003/) | Sudo and Sudo Caching | Defense Evasion, Privilege Escalation | - -| [T1548](https://attack.mitre.org/techniques/T1548/) | Abuse Elevation Control Mechanism | Defense Evasion, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name IN ("sudo", "su") OR Processes.parent_process_name IN ("sudo", "su") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.process_guid -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `linux_sudo_or_su_execution_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **linux_sudo_or_su_execution_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase. - -#### Known False Positives -Administrator or network operator can execute this command. Please update the filter macros to remove false positives. - -#### Associated Analytic story -* [Linux Privilege Escalation](/stories/linux_privilege_escalation) -* [Linux Persistence Techniques](/stories/linux_persistence_techniques) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 9.0 | 30 | 30 | A commandline $process$ that execute sudo or su in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1548/003/](https://attack.mitre.org/techniques/T1548/003/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.003/sudo_su/sysmon_linux.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.003/sudo_su/sysmon_linux.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_sudo_or_su_execution.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-01-05-linux_doas_conf_file_creation.md b/docs/_posts/2022-01-05-linux_doas_conf_file_creation.md deleted file mode 100644 index 9eb88bf61d..0000000000 --- a/docs/_posts/2022-01-05-linux_doas_conf_file_creation.md +++ /dev/null @@ -1,172 +0,0 @@ ---- -title: "Linux Doas Conf File Creation" -excerpt: "Sudo and Sudo Caching -, Abuse Elevation Control Mechanism -" -categories: - - Endpoint -last_modified_at: 2022-01-05 -toc: true -toc_label: "" -tags: - - Sudo and Sudo Caching - - Abuse Elevation Control Mechanism - - Defense Evasion - - Privilege Escalation - - Defense Evasion - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to detect the creation of doas.conf file in linux host platform. This configuration file can be use by doas utility tool to allow or permit standard users to perform tasks as root, the same way sudo does. This tool is developed as a minimalistic alternative to sudo application. This tool can be abused advesaries, attacker or malware to gain elevated privileges to the targeted or compromised host. On the other hand this can also be executed by administrator for a certain task that needs admin rights. In this case filter is needed. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-01-05 -- **Author**: Teoderick Contreras, Splunk -- **ID**: f6343e86-6e09-11ec-9376-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1548.003](https://attack.mitre.org/techniques/T1548/003/) | Sudo and Sudo Caching | Defense Evasion, Privilege Escalation | - -| [T1548](https://attack.mitre.org/techniques/T1548/) | Abuse Elevation Control Mechanism | Defense Evasion, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_path IN ("*/etc/doas.conf") by Filesystem.dest Filesystem.file_create_time Filesystem.file_name Filesystem.process_guid Filesystem.file_path -| `drop_dm_object_name(Filesystem)` -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `linux_doas_conf_file_creation_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **linux_doas_conf_file_creation_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Filesystem.dest -* Filesystem.file_create_time -* Filesystem.file_name -* Filesystem.process_guid -* Filesystem.file_path - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase. - -#### Known False Positives -Administrator or network operator can execute this command. Please update the filter macros to remove false positives. - -#### Associated Analytic story -* [Linux Privilege Escalation](/stories/linux_privilege_escalation) -* [Linux Persistence Techniques](/stories/linux_persistence_techniques) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | A file $file_name$ is created in $file_path$ on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://wiki.gentoo.org/wiki/Doas](https://wiki.gentoo.org/wiki/Doas) -* [https://www.makeuseof.com/how-to-install-and-use-doas/](https://www.makeuseof.com/how-to-install-and-use-doas/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.003/doas/sysmon_linux.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.003/doas/sysmon_linux.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_doas_conf_file_creation.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-01-05-linux_doas_tool_execution.md b/docs/_posts/2022-01-05-linux_doas_tool_execution.md deleted file mode 100644 index a322917bc6..0000000000 --- a/docs/_posts/2022-01-05-linux_doas_tool_execution.md +++ /dev/null @@ -1,174 +0,0 @@ ---- -title: "Linux Doas Tool Execution" -excerpt: "Sudo and Sudo Caching -, Abuse Elevation Control Mechanism -" -categories: - - Endpoint -last_modified_at: 2022-01-05 -toc: true -toc_label: "" -tags: - - Sudo and Sudo Caching - - Abuse Elevation Control Mechanism - - Defense Evasion - - Privilege Escalation - - Defense Evasion - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to detect the doas tool execution in linux host platform. This utility tool allow standard users to perform tasks as root, the same way sudo does. This tool is developed as a minimalistic alternative to sudo application. This tool can be abused advesaries, attacker or malware to gain elevated privileges to the targeted or compromised host. On the other hand this can also be executed by administrator for a certain task that needs admin rights. In this case filter is needed. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-01-05 -- **Author**: Teoderick Contreras, Splunk -- **ID**: d5a62490-6e09-11ec-884e-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1548.003](https://attack.mitre.org/techniques/T1548/003/) | Sudo and Sudo Caching | Defense Evasion, Privilege Escalation | - -| [T1548](https://attack.mitre.org/techniques/T1548/) | Abuse Elevation Control Mechanism | Defense Evasion, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = "doas" by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.process_guid -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `linux_doas_tool_execution_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **linux_doas_tool_execution_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase. - -#### Known False Positives -Administrator or network operator can execute this command. Please update the filter macros to remove false positives. - -#### Associated Analytic story -* [Linux Privilege Escalation](/stories/linux_privilege_escalation) -* [Linux Persistence Techniques](/stories/linux_persistence_techniques) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | A doas $process_name$ with commandline $process$ was executed on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://wiki.gentoo.org/wiki/Doas](https://wiki.gentoo.org/wiki/Doas) -* [https://www.makeuseof.com/how-to-install-and-use-doas/](https://www.makeuseof.com/how-to-install-and-use-doas/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.003/doas_exec/sysmon_linux.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.003/doas_exec/sysmon_linux.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_doas_tool_execution.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-01-10-linux_possible_access_to_credential_files.md b/docs/_posts/2022-01-10-linux_possible_access_to_credential_files.md deleted file mode 100644 index 9050778c1c..0000000000 --- a/docs/_posts/2022-01-10-linux_possible_access_to_credential_files.md +++ /dev/null @@ -1,172 +0,0 @@ ---- -title: "Linux Possible Access To Credential Files" -excerpt: "/etc/passwd and /etc/shadow -, OS Credential Dumping -" -categories: - - Endpoint -last_modified_at: 2022-01-10 -toc: true -toc_label: "" -tags: - - /etc/passwd and /etc/shadow - - OS Credential Dumping - - Credential Access - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to detect a possible attempt to dump or access the content of /etc/passwd and /etc/shadow to enable offline credential cracking. "etc/passwd" store user information within linux OS while "etc/shadow" contain the user passwords hash. Adversaries and threat actors may attempt to access this to gain persistence and/or privilege escalation. This anomaly detection can be a good indicator of possible credential dumping technique but it might catch some normal administrator automation scripts or during credential auditing. In this scenario filter is needed. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-01-10 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 16107e0e-71fc-11ec-b862-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1003.008](https://attack.mitre.org/techniques/T1003/008/) | /etc/passwd and /etc/shadow | Credential Access | - -| [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name IN("cat", "nano*","vim*", "vi*") AND Processes.process IN("*/etc/shadow*", "*/etc/passwd*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `linux_possible_access_to_credential_files_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **linux_possible_access_to_credential_files_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase. - -#### Known False Positives -Administrator or network operator can execute this command. Please update the filter macros to remove false positives. - -#### Associated Analytic story -* [Linux Privilege Escalation](/stories/linux_privilege_escalation) -* [Linux Persistence Techniques](/stories/linux_persistence_techniques) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | A commandline $process$ executed on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://askubuntu.com/questions/445361/what-is-difference-between-etc-shadow-and-etc-passwd](https://askubuntu.com/questions/445361/what-is-difference-between-etc-shadow-and-etc-passwd) -* [https://attack.mitre.org/techniques/T1003/008/](https://attack.mitre.org/techniques/T1003/008/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.008/copy_file_stdoutpipe/sysmon_linux.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.008/copy_file_stdoutpipe/sysmon_linux.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_possible_access_to_credential_files.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-01-10-linux_possible_access_to_sudoers_file.md b/docs/_posts/2022-01-10-linux_possible_access_to_sudoers_file.md deleted file mode 100644 index 7a328f51ca..0000000000 --- a/docs/_posts/2022-01-10-linux_possible_access_to_sudoers_file.md +++ /dev/null @@ -1,174 +0,0 @@ ---- -title: "Linux Possible Access To Sudoers File" -excerpt: "Sudo and Sudo Caching -, Abuse Elevation Control Mechanism -" -categories: - - Endpoint -last_modified_at: 2022-01-10 -toc: true -toc_label: "" -tags: - - Sudo and Sudo Caching - - Abuse Elevation Control Mechanism - - Defense Evasion - - Privilege Escalation - - Defense Evasion - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to detect a possible access or modification of /etc/sudoers file. "/etc/sudoers" file controls who can run what command as what users on what machine and can also control whether a specific user need a password for particular commands. adversaries and threat actors abuse this file to gain persistence and/or privilege escalation during attack on targeted host. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-01-10 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 4479539c-71fc-11ec-b2e2-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1548.003](https://attack.mitre.org/techniques/T1548/003/) | Sudo and Sudo Caching | Defense Evasion, Privilege Escalation | - -| [T1548](https://attack.mitre.org/techniques/T1548/) | Abuse Elevation Control Mechanism | Defense Evasion, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name IN("cat", "nano*","vim*", "vi*") AND Processes.process IN("*/etc/sudoers*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `linux_possible_access_to_sudoers_file_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **linux_possible_access_to_sudoers_file_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase. - -#### Known False Positives -administrator or network operator can execute this command. Please update the filter macros to remove false positives. - -#### Associated Analytic story -* [Linux Privilege Escalation](/stories/linux_privilege_escalation) -* [Linux Persistence Techniques](/stories/linux_persistence_techniques) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | A commandline $process$ executed on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1548/003/](https://attack.mitre.org/techniques/T1548/003/) -* [https://web.archive.org/web/20210708035426/https://www.cobaltstrike.com/downloads/csmanual43.pdf](https://web.archive.org/web/20210708035426/https://www.cobaltstrike.com/downloads/csmanual43.pdf) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.008/copy_file_stdoutpipe/sysmon_linux.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.008/copy_file_stdoutpipe/sysmon_linux.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_possible_access_to_sudoers_file.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-01-11-linux_possible_access_or_modification_of_sshd_config_file.md b/docs/_posts/2022-01-11-linux_possible_access_or_modification_of_sshd_config_file.md deleted file mode 100644 index 74cdafaa0c..0000000000 --- a/docs/_posts/2022-01-11-linux_possible_access_or_modification_of_sshd_config_file.md +++ /dev/null @@ -1,173 +0,0 @@ ---- -title: "Linux Possible Access Or Modification Of sshd Config File" -excerpt: "SSH Authorized Keys -, Account Manipulation -" -categories: - - Endpoint -last_modified_at: 2022-01-11 -toc: true -toc_label: "" -tags: - - SSH Authorized Keys - - Account Manipulation - - Persistence - - Persistence - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to look for suspicious process command-line that might be accessing or modifying sshd_config. This file is the ssh configuration file that might be modify by threat actors or adversaries to redirect port connection, allow user using authorized key generated during attack. This anomaly detection might catch noise from administrator auditing or modifying ssh configuration file. In this scenario filter is needed - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-01-11 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 7a85eb24-72da-11ec-ac76-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1098.004](https://attack.mitre.org/techniques/T1098/004/) | SSH Authorized Keys | Persistence | - -| [T1098](https://attack.mitre.org/techniques/T1098/) | Account Manipulation | Persistence | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name IN("cat", "nano*","vim*", "vi*") AND Processes.process IN("*/etc/ssh/sshd_config") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `linux_possible_access_or_modification_of_sshd_config_file_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **linux_possible_access_or_modification_of_sshd_config_file_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase. - -#### Known False Positives -Administrator or network operator can use this commandline for automation purposes. Please update the filter macros to remove false positives. - -#### Associated Analytic story -* [Linux Privilege Escalation](/stories/linux_privilege_escalation) -* [Linux Persistence Techniques](/stories/linux_persistence_techniques) -* [Linux Living Off The Land](/stories/linux_living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | a commandline $process$ executed on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.hackingarticles.in/ssh-penetration-testing-port-22/](https://www.hackingarticles.in/ssh-penetration-testing-port-22/) -* [https://attack.mitre.org/techniques/T1098/004/](https://attack.mitre.org/techniques/T1098/004/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098.004/ssh_authorized_keys/sysmon_linux.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098.004/ssh_authorized_keys/sysmon_linux.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_possible_access_or_modification_of_sshd_config_file.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-01-11-linux_possible_ssh_key_file_creation.md b/docs/_posts/2022-01-11-linux_possible_ssh_key_file_creation.md deleted file mode 100644 index a4cedaeb99..0000000000 --- a/docs/_posts/2022-01-11-linux_possible_ssh_key_file_creation.md +++ /dev/null @@ -1,171 +0,0 @@ ---- -title: "Linux Possible Ssh Key File Creation" -excerpt: "SSH Authorized Keys -, Account Manipulation -" -categories: - - Endpoint -last_modified_at: 2022-01-11 -toc: true -toc_label: "" -tags: - - SSH Authorized Keys - - Account Manipulation - - Persistence - - Persistence - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to look for possible ssh key file creation on ~/.ssh/ folder. This technique is commonly abused by threat actors and adversaries to gain persistence and privilege escalation to the targeted host. by creating ssh private and public key and passing the public key to the attacker server. threat actor can access remotely the machine using openssh daemon service. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-01-11 -- **Author**: Teoderick Contreras, Splunk -- **ID**: c04ef40c-72da-11ec-8eac-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1098.004](https://attack.mitre.org/techniques/T1098/004/) | SSH Authorized Keys | Persistence | - -| [T1098](https://attack.mitre.org/techniques/T1098/) | Account Manipulation | Persistence | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_path IN ("*/.ssh*") by Filesystem.dest Filesystem.file_name Filesystem.process_guid Filesystem.file_path -| `drop_dm_object_name(Filesystem)` -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `linux_possible_ssh_key_file_creation_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **linux_possible_ssh_key_file_creation_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Filesystem.dest -* Filesystem.file_create_time -* Filesystem.file_name -* Filesystem.process_guid -* Filesystem.file_path - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the file name, file path, and process_guid executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase. - -#### Known False Positives -Administrator or network operator can create file in ~/.ssh folders for automation purposes. Please update the filter macros to remove false positives. - -#### Associated Analytic story -* [Linux Privilege Escalation](/stories/linux_privilege_escalation) -* [Linux Persistence Techniques](/stories/linux_persistence_techniques) -* [Linux Living Off The Land](/stories/linux_living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 36.0 | 60 | 60 | A file $file_name$ is created in $file_path$ on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.hackingarticles.in/ssh-penetration-testing-port-22/](https://www.hackingarticles.in/ssh-penetration-testing-port-22/) -* [https://attack.mitre.org/techniques/T1098/004/](https://attack.mitre.org/techniques/T1098/004/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098.004/ssh_authorized_keys/sysmon_linux.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098.004/ssh_authorized_keys/sysmon_linux.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_possible_ssh_key_file_creation.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-01-12-powershell_-_connect_to_internet_with_hidden_window.md b/docs/_posts/2022-01-12-powershell_-_connect_to_internet_with_hidden_window.md deleted file mode 100644 index a7e3a6be4d..0000000000 --- a/docs/_posts/2022-01-12-powershell_-_connect_to_internet_with_hidden_window.md +++ /dev/null @@ -1,190 +0,0 @@ ---- -title: "PowerShell - Connect To Internet With Hidden Window" -excerpt: "PowerShell -, Command and Scripting Interpreter -" -categories: - - Endpoint -last_modified_at: 2022-01-12 -toc: true -toc_label: "" -tags: - - PowerShell - - Command and Scripting Interpreter - - Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2021-44228 - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following hunting analytic identifies PowerShell commands utilizing the WindowStyle parameter to hide the window on the compromised endpoint. This combination of command-line options is suspicious because it is overriding the default PowerShell execution policy, attempts to hide its activity from the user, and connects to the Internet. Removed in this version of the query is New-Object. The analytic identifies all variations of WindowStyle, as PowerShell allows the ability to shorten the parameter. For example w, win, windowsty and so forth. In addition, through our research it was identified that PowerShell will interpret different command switch types beyond the hyphen. We have added endash, emdash, horizontal bar, and forward slash. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-01-12 -- **Author**: David Dorsey, Michael Haag Splunk -- **ID**: ee18ed37-0802-4268-9435-b3b91aaa18db - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | - -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Command & Control -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM -* PR.IP - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 7 -* CIS 8 - - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2021-44228](https://nvd.nist.gov/vuln/detail/CVE-2021-44228) | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects. | 9.3 | - - - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_powershell` by Processes.user Processes.process_name Processes.process Processes.parent_process_name Processes.original_file_name Processes.dest Processes.process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| where match(process,"(?i)[\- -|\/ -| -| -|]w(in*d*o*w*s*t*y*l*e*)*\s+[^-]") -| `powershell___connect_to_internet_with_hidden_window_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml) - -> :information_source: -> **powershell_-_connect_to_internet_with_hidden_window_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process -* Processes.process_name -* Processes.user -* Processes.parent_process_name -* Processes.dest - - -#### How To Implement -You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. - -#### Known False Positives -Legitimate process can have this combination of command-line options, but it's not common. - -#### Associated Analytic story -* [Hermetic Wiper](/stories/hermetic_wiper) -* [Malicious PowerShell](/stories/malicious_powershell) -* [Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns](/stories/possible_backdoor_activity_associated_with_mudcarp_espionage_campaigns) -* [HAFNIUM Group](/stories/hafnium_group) -* [Log4Shell CVE-2021-44228](/stories/log4shell_cve-2021-44228) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 81.0 | 90 | 90 | PowerShell processes $process$ started with parameters to modify the execution policy of the run, run in a hidden window, and connect to the Internet on host $dest$ executed by user $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://regexr.com/663rr](https://regexr.com/663rr) -* [https://github.com/redcanaryco/AtomicTestHarnesses/blob/master/TestHarnesses/T1059.001_PowerShell/OutPowerShellCommandLineParameter.ps1](https://github.com/redcanaryco/AtomicTestHarnesses/blob/master/TestHarnesses/T1059.001_PowerShell/OutPowerShellCommandLineParameter.ps1) -* [https://ss64.com/ps/powershell.html](https://ss64.com/ps/powershell.html) -* [https://twitter.com/M_haggis/status/1440758396534214658?s=20](https://twitter.com/M_haggis/status/1440758396534214658?s=20) -* [https://blog.netlab.360.com/ten-families-of-malicious-samples-are-spreading-using-the-log4j2-vulnerability-now/](https://blog.netlab.360.com/ten-families-of-malicious-samples-are-spreading-using-the-log4j2-vulnerability-now/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/hidden_powershell/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/hidden_powershell/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml) \| *version*: **8** \ No newline at end of file diff --git a/docs/_posts/2022-01-12-windows_hunting_system_account_targeting_lsass.md b/docs/_posts/2022-01-12-windows_hunting_system_account_targeting_lsass.md deleted file mode 100644 index 58ff38a98a..0000000000 --- a/docs/_posts/2022-01-12-windows_hunting_system_account_targeting_lsass.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: "Windows Hunting System Account Targeting Lsass" -excerpt: "LSASS Memory -, OS Credential Dumping -" -categories: - - Endpoint -last_modified_at: 2022-01-12 -toc: true -toc_label: "" -tags: - - LSASS Memory - - OS Credential Dumping - - Credential Access - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following hunting analytic identifies all processes requesting access into Lsass.exe. his behavior may be related to credential dumping or applications requiring access to credentials. Triaging this event will require understanding the GrantedAccess from the SourceImage. In addition, whether the account is privileged or not. Review the process requesting permissions and review parallel processes. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-01-12 -- **Author**: Michael Haag, Splunk -- **ID**: 1c6abb08-73d1-11ec-9ca0-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1003.001](https://attack.mitre.org/techniques/T1003/001/) | LSASS Memory | Credential Access | - -| [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.AE -* DE.CM - - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventCode=10 TargetImage=*lsass.exe -| stats count min(_time) as firstTime max(_time) as lastTime by Computer, TargetImage, GrantedAccess, SourceImage, SourceProcessId, SourceUser, TargetUser -| rename Computer as dest -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_hunting_system_account_targeting_lsass_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **windows_hunting_system_account_targeting_lsass_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Computer -* TargetImage -* GrantedAccess -* SourceImage -* SourceProcessId -* SourceUser -* TargetUser - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Enabling EventCode 10 TargetProcess lsass.exe is required. - -#### Known False Positives -False positives will occur based on GrantedAccess and SourceUser, filter based on source image as needed. - -#### Associated Analytic story -* [Credential Dumping](/stories/credential_dumping) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 64.0 | 80 | 80 | A process, $SourceImage$, has loaded $ImageLoaded$ that are typically related to credential dumping on $dest$. Review for further details. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://en.wikipedia.org/wiki/Local_Security_Authority_Subsystem_Service](https://en.wikipedia.org/wiki/Local_Security_Authority_Subsystem_Service) -* [https://docs.microsoft.com/en-us/windows/win32/api/minidumpapiset/nf-minidumpapiset-minidumpwritedump](https://docs.microsoft.com/en-us/windows/win32/api/minidumpapiset/nf-minidumpapiset-minidumpwritedump) -* [https://cyberwardog.blogspot.com/2017/03/chronicles-of-threat-hunter-hunting-for_22.html](https://cyberwardog.blogspot.com/2017/03/chronicles-of-threat-hunter-hunting-for_22.html) -* [https://raw.githubusercontent.com/PowerShellMafia/PowerSploit/master/Exfiltration/Invoke-Mimikatz.ps1](https://raw.githubusercontent.com/PowerShellMafia/PowerSploit/master/Exfiltration/Invoke-Mimikatz.ps1) -* [https://docs.microsoft.com/en-us/windows/win32/procthread/process-security-and-access-rights?redirectedfrom=MSDN](https://docs.microsoft.com/en-us/windows/win32/procthread/process-security-and-access-rights?redirectedfrom=MSDN) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.001/atomic_red_team/windows-sysmon_creddump.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.001/atomic_red_team/windows-sysmon_creddump.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_hunting_system_account_targeting_lsass.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-01-12-windows_non-system_account_targeting_lsass.md b/docs/_posts/2022-01-12-windows_non-system_account_targeting_lsass.md deleted file mode 100644 index c48ad067c4..0000000000 --- a/docs/_posts/2022-01-12-windows_non-system_account_targeting_lsass.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: "Windows Non-System Account Targeting Lsass" -excerpt: "LSASS Memory -, OS Credential Dumping -" -categories: - - Endpoint -last_modified_at: 2022-01-12 -toc: true -toc_label: "" -tags: - - LSASS Memory - - OS Credential Dumping - - Credential Access - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies non SYSTEM accounts requesting access to lsass.exe. This behavior may be related to credential dumping or applications requiring access to credentials. Triaging this event will require understanding the GrantedAccess from the SourceImage. In addition, whether the account is privileged or not. Review the process requesting permissions and review parallel processes. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-01-12 -- **Author**: Michael Haag, Splunk -- **ID**: b1ce9a72-73cf-11ec-981b-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1003.001](https://attack.mitre.org/techniques/T1003/001/) | LSASS Memory | Credential Access | - -| [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.AE -* DE.CM - - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventCode=10 TargetImage=*lsass.exe SourceUser!="NT AUTHORITY\\*" -| stats count min(_time) as firstTime max(_time) as lastTime by Computer, TargetImage, GrantedAccess, SourceImage, SourceProcessId, SourceUser, TargetUser -| rename Computer as dest -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_non_system_account_targeting_lsass_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **windows_non-system_account_targeting_lsass_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Computer -* TargetImage -* GrantedAccess -* SourceImage -* SourceProcessId -* SourceUser -* TargetUser - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Enabling EventCode 10 TargetProcess lsass.exe is required. - -#### Known False Positives -False positives will occur based on legitimate application requests, filter based on source image as needed. - -#### Associated Analytic story -* [Credential Dumping](/stories/credential_dumping) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 64.0 | 80 | 80 | A process, $SourceImage$, has loaded $ImageLoaded$ that are typically related to credential dumping on $dest$. Review for further details. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://en.wikipedia.org/wiki/Local_Security_Authority_Subsystem_Service](https://en.wikipedia.org/wiki/Local_Security_Authority_Subsystem_Service) -* [https://docs.microsoft.com/en-us/windows/win32/api/minidumpapiset/nf-minidumpapiset-minidumpwritedump](https://docs.microsoft.com/en-us/windows/win32/api/minidumpapiset/nf-minidumpapiset-minidumpwritedump) -* [https://cyberwardog.blogspot.com/2017/03/chronicles-of-threat-hunter-hunting-for_22.html](https://cyberwardog.blogspot.com/2017/03/chronicles-of-threat-hunter-hunting-for_22.html) -* [https://raw.githubusercontent.com/PowerShellMafia/PowerSploit/master/Exfiltration/Invoke-Mimikatz.ps1](https://raw.githubusercontent.com/PowerShellMafia/PowerSploit/master/Exfiltration/Invoke-Mimikatz.ps1) -* [https://docs.microsoft.com/en-us/windows/win32/procthread/process-security-and-access-rights?redirectedfrom=MSDN](https://docs.microsoft.com/en-us/windows/win32/procthread/process-security-and-access-rights?redirectedfrom=MSDN) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.001/atomic_red_team/windows-sysmon_creddump.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.001/atomic_red_team/windows-sysmon_creddump.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_non_system_account_targeting_lsass.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-01-14-potentially_malicious_code_on_commandline.md b/docs/_posts/2022-01-14-potentially_malicious_code_on_commandline.md deleted file mode 100644 index bbc1eaf197..0000000000 --- a/docs/_posts/2022-01-14-potentially_malicious_code_on_commandline.md +++ /dev/null @@ -1,166 +0,0 @@ ---- -title: "Potentially malicious code on commandline" -excerpt: "Windows Command Shell -" -categories: - - Endpoint -last_modified_at: 2022-01-14 -toc: true -toc_label: "" -tags: - - Windows Command Shell - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic uses a pretrained machine learning text classifier to detect potentially malicious commandlines. The model identifies unusual combinations of keywords found in samples of commandlines where adversaries executed powershell code, primarily for C2 communication. For example, adversaries will leverage IO capabilities such as "streamreader" and "webclient", threading capabilties such as "mutex" locks, programmatic constructs like "function" and "catch", and cryptographic operations like "computehash". Although observing one of these keywords in a commandline script is possible, combinations of keywords observed in attack data are not typically found in normal usage of the commandline. The model will output a score where all values above zero are suspicious, anything greater than one particularly so. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-01-14 -- **Author**: Michael Hart, Splunk -- **ID**: 9c53c446-757e-11ec-871d-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059.003](https://attack.mitre.org/techniques/T1059/003/) | Windows Command Shell | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel="Endpoint.Processes" by Processes.parent_process_name Processes.process_name Processes.process Processes.user Processes.dest -| `drop_dm_object_name(Processes)` -| where len(process) > 200 -| `potentially_malicious_code_on_cmdline_tokenize_score` -| apply unusual_commandline_detection -| eval score='predicted(unusual_cmdline_logits)', process=orig_process -| fields - unusual_cmdline* predicted(unusual_cmdline_logits) orig_process -| where score > 0.5 -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `potentially_malicious_code_on_commandline_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [potentially_malicious_code_on_cmdline_tokenize_score](https://github.com/splunk/security_content/blob/develop/macros/potentially_malicious_code_on_cmdline_tokenize_score.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **potentially_malicious_code_on_commandline_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process -* Processes.parent_process_name -* Processes.process_name -* Processes.parent_process -* Processes.user -* Processes.dest - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. You will also need to install the Machine Learning Toolkit version 5.3 or above to apply the pretrained model. - -#### Known False Positives -This model is an anomaly detector that identifies usage of APIs and scripting constructs that are correllated with malicious activity. These APIs and scripting constructs are part of the programming langauge and advanced scripts may generate false positives. - -#### Associated Analytic story -* [Suspicious Command-Line Executions](/stories/suspicious_command-line_executions) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 12.0 | 60 | 20 | Unusual command-line execution with hallmarks of malicious activity run by $user$ found on $dest$ with commandline $process$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1059/003/](https://attack.mitre.org/techniques/T1059/003/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1059.001/T1059.001.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1059.001/T1059.001.md) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/malicious_cmd_line_samples/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/malicious_cmd_line_samples/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-01-17-unusual_volume_of_data_download_from_internal_server_per_entity.md b/docs/_posts/2022-01-17-unusual_volume_of_data_download_from_internal_server_per_entity.md deleted file mode 100644 index aa8864d22c..0000000000 --- a/docs/_posts/2022-01-17-unusual_volume_of_data_download_from_internal_server_per_entity.md +++ /dev/null @@ -1,124 +0,0 @@ ---- -title: "Unusual Volume of Data Download from Internal Server Per Entity" -excerpt: "Data from Information Repositories, Data from Network Shared Drive" -categories: - - Network -last_modified_at: 2022-01-17 -toc: true -toc_label: "" -tags: - - Data from Information Repositories - - Collection - - Data from Network Shared Drive - - Collection - - Splunk Behavioral Analytics - - Network_Traffic ---- - -### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Insider might conduct information collection before data exfiltration, and unusual volume of data download from internal server is an indicator of such potential threat. This detection evaluates the total bytes downloaded from internal servers at specific time window per entity level, and then flagged these that are higher than 99.999% percentile as an anamaly. A behavior will be reported as long as the downloaded byte volume is unusual even though that operation is benign, which causes false positive. It is therefore advised to adjust threshold and time window based on detection performance whenever necessary. It should be noted that seasonality is not modeled in the current approach. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Network_Traffic](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkTraffic) -- **Last Updated**: 2022-01-17 -- **Author**: Xiao Lin, Splunk -- **ID**: cca028f4-77dd-11ec-bc09-acde48001122 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1213](https://attack.mitre.org/techniques/T1213/) | Data from Information Repositories | Collection | - -| [T1039](https://attack.mitre.org/techniques/T1039/) | Data from Network Shared Drive | Collection | - -#### Search - -``` - -| from read_ssa_enriched_events() -| eval sourcetype = ucast(map_get(input_event, "sourcetype"), "string", null) -| eval timestamp = parse_long(ucast(map_get(input_event, "_time"), "string", null)) -| where sourcetype == "pan:traffic" -| eval src_device_scope =ucast(map_get(input_event, "src_device_scope"), "string", null) -| eval dest_device_scope=ucast(map_get(input_event, "dest_device_scope"), "string", null) -| where src_device_scope IS NOT NULL AND dest_device_scope IS NOT NULL -| eval dest_device = ucast(map_get(input_event, "dest_device_ips"), "collection", [])[0] -| where dest_device IS NOT NULL AND dest_device_scope == "INTERNAL" -| eval src_device = ucast(map_get(input_event, "src_device_ips"), "collection", [])[0] -| where src_device IS NOT NULL AND src_device_scope == "INTERNAL" -| eval bytes_in = ucast(map_get(input_event, "bytes_in"), "integer", 0) -| eval download_bytes = cast(bytes_in, "double") -| eval tenant = ucast(map_get(input_event, "_tenant"), "string", null) -| eval event_id = ucast(map_get(input_event, "event_id"), "string", null) -| adaptive_threshold algorithm="quantile" value="download_bytes" entity="dest_device" window=86400000L -| where label AND quantile>0.99999 -| eval end_time = timestamp -| eval start_time = end_time - 86400000 -| eval body = create_map(["event_id", event_id, "tenant", tenant]) -| eval entities=mvappend(dest_device) -| into write_ssa_detected_events(); -``` - -#### Macros -The SPL above uses the following Macros: - -Note that `unusual_volume_of_data_download_from_internal_server_per_entity_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* dest_device_scope -* bytes_in -* src_device_ips - - -#### How To Implement -Ingest PAN traffic logs - -#### Known False Positives -Benign large volume data download might be flagged as (false) positive. - -#### Associated Analytic story -* [Insider Threat](/stories/insider_threat) - - -#### Kill Chain Phase -* Weaponization - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | $src_device_ip downloaded unusually amount of data from internal server within one day | - - -Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` - - - -#### Reference - -* [https://github.com/twitter/AnomalyDetection](https://github.com/twitter/AnomalyDetection) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://github.com/splunk/attack_data/blob/master/datasets/suspicious_behaviour/unusual_data_download/unusual_volume_data_download.txt](https://github.com/splunk/attack_data/blob/master/datasets/suspicious_behaviour/unusual_data_download/unusual_volume_data_download.txt) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/network/unusual_volume_of_data_download_from_internal_server_per_entity.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-01-18-cmd_carry_out_string_command_parameter.md b/docs/_posts/2022-01-18-cmd_carry_out_string_command_parameter.md deleted file mode 100644 index 9c48054f44..0000000000 --- a/docs/_posts/2022-01-18-cmd_carry_out_string_command_parameter.md +++ /dev/null @@ -1,180 +0,0 @@ ---- -title: "CMD Carry Out String Command Parameter" -excerpt: "Windows Command Shell -, Command and Scripting Interpreter -" -categories: - - Endpoint -last_modified_at: 2022-01-18 -toc: true -toc_label: "" -tags: - - Windows Command Shell - - Command and Scripting Interpreter - - Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2021-44228 - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies command-line arguments where `cmd.exe /c` is used to execute a program. `cmd /c` is used to run commands in MS-DOS and terminate after command or process completion. This technique is commonly seen in adversaries and malware to execute batch command using different shell like PowerShell or different process other than `cmd.exe`. This is a good hunting query for suspicious command-line made by a script or relative process execute it. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-01-18 -- **Author**: Teoderick Contreras, Bhavin Patel, Splunk -- **ID**: 54a6ed00-3256-11ec-b031-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059.003](https://attack.mitre.org/techniques/T1059/003/) | Windows Command Shell | Execution | - -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2021-44228](https://nvd.nist.gov/vuln/detail/CVE-2021-44228) | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects. | 9.3 | - - - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_cmd` AND Processes.process="* /c *" by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `cmd_carry_out_string_command_parameter_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [process_cmd](https://github.com/splunk/security_content/blob/develop/macros/process_cmd.yml) - -> :information_source: -> **cmd_carry_out_string_command_parameter_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.parent_process_name -* Processes.parent_process -* Processes.process_name -* Processes.process_id -* Processes.process -* Processes.dest -* Processes.user -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -False positives may be high based on legitimate scripted code in any environment. Filter as needed. - -#### Associated Analytic story -* [Data Destruction](/stories/data_destruction) -* [IcedID](/stories/icedid) -* [Log4Shell CVE-2021-44228](/stories/log4shell_cve-2021-44228) -* [WhisperGate](/stories/whispergate) -* [Hermetic Wiper](/stories/hermetic_wiper) -* [Living Off The Land](/stories/living_off_the_land) -* [Azorult](/stories/azorult) -* [DarkCrystal RAT](/stories/darkcrystal_rat) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 30.0 | 60 | 50 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting spawn a new process. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/](https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/) -* [https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/](https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/cmd_carry_str_param/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/cmd_carry_str_param/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2022-01-18-impacket_lateral_movement_commandline_parameters.md b/docs/_posts/2022-01-18-impacket_lateral_movement_commandline_parameters.md deleted file mode 100644 index bc07278512..0000000000 --- a/docs/_posts/2022-01-18-impacket_lateral_movement_commandline_parameters.md +++ /dev/null @@ -1,193 +0,0 @@ ---- -title: "Impacket Lateral Movement Commandline Parameters" -excerpt: "Remote Services -, SMB/Windows Admin Shares -, Distributed Component Object Model -, Windows Management Instrumentation -, Windows Service -" -categories: - - Endpoint -last_modified_at: 2022-01-18 -toc: true -toc_label: "" -tags: - - Remote Services - - SMB/Windows Admin Shares - - Distributed Component Object Model - - Windows Management Instrumentation - - Windows Service - - Lateral Movement - - Lateral Movement - - Lateral Movement - - Execution - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for the presence of suspicious commandline parameters typically present when using Impacket tools. Impacket is a collection of python classes meant to be used with Microsoft network protocols. There are multiple scripts that leverage impacket libraries like `wmiexec.py`, `smbexec.py`, `dcomexec.py` and `atexec.py` used to execute commands on remote endpoints. By default, these scripts leverage administrative shares and hardcoded parameters that can be used as a signature to detect its use. Red Teams and adversaries alike may leverage Impackets tools for lateral movement and remote code execution. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-01-18 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 8ce07472-496f-11ec-ab3b-3e22fbd008af - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1021](https://attack.mitre.org/techniques/T1021/) | Remote Services | Lateral Movement | - -| [T1021.002](https://attack.mitre.org/techniques/T1021/002/) | SMB/Windows Admin Shares | Lateral Movement | - -| [T1021.003](https://attack.mitre.org/techniques/T1021/003/) | Distributed Component Object Model | Lateral Movement | - -| [T1047](https://attack.mitre.org/techniques/T1047/) | Windows Management Instrumentation | Execution | - -| [T1543.003](https://attack.mitre.org/techniques/T1543/003/) | Windows Service | Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process = "*/c* \\\\127.0.0.1\\*" OR Processes.process= "*/c* 2>&1") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `impacket_lateral_movement_commandline_parameters_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **impacket_lateral_movement_commandline_parameters_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. - -#### Known False Positives -Although uncommon, Administrators may leverage Impackets tools to start a process on remote systems for system administration or automation use cases. - -#### Associated Analytic story -* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) -* [WhisperGate](/stories/whispergate) -* [Industroyer2](/stories/industroyer2) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 63.0 | 90 | 70 | Suspicious command line parameters on $dest may represent a lateral movement attack with Impackets tools | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1021/002/](https://attack.mitre.org/techniques/T1021/002/) -* [https://attack.mitre.org/techniques/T1021/003/](https://attack.mitre.org/techniques/T1021/003/) -* [https://attack.mitre.org/techniques/T1047/](https://attack.mitre.org/techniques/T1047/) -* [https://attack.mitre.org/techniques/T1053/](https://attack.mitre.org/techniques/T1053/) -* [https://attack.mitre.org/techniques/T1053/005/](https://attack.mitre.org/techniques/T1053/005/) -* [https://github.com/SecureAuthCorp/impacket](https://github.com/SecureAuthCorp/impacket) -* [https://vk9-sec.com/impacket-remote-code-execution-rce-on-windows-from-linux/](https://vk9-sec.com/impacket-remote-code-execution-rce-on-windows-from-linux/) -* [https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/](https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021.003/impacket/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021.003/impacket/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/impacket_lateral_movement_commandline_parameters.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-01-18-malicious_powershell_process_-_encoded_command.md b/docs/_posts/2022-01-18-malicious_powershell_process_-_encoded_command.md deleted file mode 100644 index b719ab44b5..0000000000 --- a/docs/_posts/2022-01-18-malicious_powershell_process_-_encoded_command.md +++ /dev/null @@ -1,184 +0,0 @@ ---- -title: "Malicious PowerShell Process - Encoded Command" -excerpt: "Obfuscated Files or Information -" -categories: - - Endpoint -last_modified_at: 2022-01-18 -toc: true -toc_label: "" -tags: - - Obfuscated Files or Information - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the use of the EncodedCommand PowerShell parameter. This is typically used by Administrators to run complex scripts, but commonly used by adversaries to hide their code. \ -The analytic identifies all variations of EncodedCommand, as PowerShell allows the ability to shorten the parameter. For example enc, enco, encod and so forth. In addition, through our research it was identified that PowerShell will interpret different command switch types beyond the hyphen. We have added endash, emdash, horizontal bar, and forward slash. \ -During triage, review parallel events to determine legitimacy. Tune as needed based on admin scripts in use. \ -Alternatively, may use regex per matching here https://regexr.com/662ov. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-01-18 -- **Author**: David Dorsey, Michael Haag, Splunk -- **ID**: c4db14d9-7909-48b4-a054-aa14d89dbb19 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1027](https://attack.mitre.org/techniques/T1027/) | Obfuscated Files or Information | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Command & Control -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM -* PR.IP - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 7 -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_powershell` by Processes.user Processes.process_name Processes.process Processes.parent_process_name Processes.original_file_name Processes.dest Processes.process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| where match(process,"(?i)[\- -|\/ -| -| -|]e(nc*o*d*e*d*c*o*m*m*a*n*d*)*\s+[^-]") -| `malicious_powershell_process___encoded_command_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml) - -> :information_source: -> **malicious_powershell_process_-_encoded_command_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process_name -* Processes.process -* Processes.user -* Processes.parent_process_name -* Processes.dest -* Processes.process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -System administrators may use this option, but it's not common. - -#### Associated Analytic story -* [Hermetic Wiper](/stories/hermetic_wiper) -* [Malicious PowerShell](/stories/malicious_powershell) -* [NOBELIUM Group](/stories/nobelium_group) -* [WhisperGate](/stories/whispergate) -* [DarkCrystal RAT](/stories/darkcrystal_rat) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 35.0 | 70 | 50 | Powershell.exe running potentially malicious encodede commands on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://regexr.com/662ov](https://regexr.com/662ov) -* [https://github.com/redcanaryco/AtomicTestHarnesses/blob/master/TestHarnesses/T1059.001_PowerShell/OutPowerShellCommandLineParameter.ps1](https://github.com/redcanaryco/AtomicTestHarnesses/blob/master/TestHarnesses/T1059.001_PowerShell/OutPowerShellCommandLineParameter.ps1) -* [https://ss64.com/ps/powershell.html](https://ss64.com/ps/powershell.html) -* [https://twitter.com/M_haggis/status/1440758396534214658?s=20](https://twitter.com/M_haggis/status/1440758396534214658?s=20) -* [https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/](https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1027/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1027/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml) \| *version*: **7** \ No newline at end of file diff --git a/docs/_posts/2022-01-18-powershell_remove_windows_defender_directory.md b/docs/_posts/2022-01-18-powershell_remove_windows_defender_directory.md deleted file mode 100644 index 79d72396a3..0000000000 --- a/docs/_posts/2022-01-18-powershell_remove_windows_defender_directory.md +++ /dev/null @@ -1,166 +0,0 @@ ---- -title: "Powershell Remove Windows Defender Directory" -excerpt: "Disable or Modify Tools -, Impair Defenses -" -categories: - - Endpoint -last_modified_at: 2022-01-18 -toc: true -toc_label: "" -tags: - - Disable or Modify Tools - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic will identify a suspicious PowerShell command used to delete the Windows Defender folder. This technique was seen used by the WhisperGate malware campaign where it used Nirsofts advancedrun.exe to gain administrative privileges to then execute a PowerShell command to delete the Windows Defender folder. This is a good indicator the offending process is trying corrupt a Windows Defender installation. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-01-18 -- **Author**: Teoderick Contreras, Splunk -- **ID**: adf47620-79fa-11ec-b248-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 Message = "*rmdir *" AND Message = "*\\Microsoft\\Windows Defender*" -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `powershell_remove_windows_defender_directory_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **powershell_remove_windows_defender_directory_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Message -* ComputerName -* User - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [WhisperGate](/stories/whispergate) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 90.0 | 100 | 90 | suspicious powershell script $Message$ was executed on the $ComputerName$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/](https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/rmdir_defender_pwsh/powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/rmdir_defender_pwsh/powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-01-18-suspicious_process_dns_query_known_abuse_web_services.md b/docs/_posts/2022-01-18-suspicious_process_dns_query_known_abuse_web_services.md deleted file mode 100644 index b4a40a14d5..0000000000 --- a/docs/_posts/2022-01-18-suspicious_process_dns_query_known_abuse_web_services.md +++ /dev/null @@ -1,164 +0,0 @@ ---- -title: "Suspicious Process DNS Query Known Abuse Web Services" -excerpt: "Visual Basic -, Command and Scripting Interpreter -" -categories: - - Endpoint -last_modified_at: 2022-01-18 -toc: true -toc_label: "" -tags: - - Visual Basic - - Command and Scripting Interpreter - - Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic detects a suspicious process making a DNS query via known, abused text-paste web services, VoIP, instant messaging, and digital distribution platforms used to download external files. This technique is abused by adversaries, malware actors, and red teams to download a malicious file on the target host. This is a good TTP indicator for possible initial access techniques. A user will experience false positives if the following instant messaging is allowed or common applications like telegram or discord are allowed in the corporate network. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-01-18 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 3cf0dc36-484d-11ec-a6bc-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059.005](https://attack.mitre.org/techniques/T1059/005/) | Visual Basic | Execution | - -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventCode=22 QueryName IN ("*pastebin*", "*discord*", "*telegram*", "*t.me*") process_name IN ("cmd.exe", "*powershell*", "pwsh.exe", "wscript.exe", "cscript.exe") -| stats count min(_time) as firstTime max(_time) as lastTime by Image QueryName QueryStatus process_name QueryResults Computer -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `suspicious_process_dns_query_known_abuse_web_services_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **suspicious_process_dns_query_known_abuse_web_services_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Image -* QueryName -* QueryStatus -* process_name -* QueryResults -* Computer - - -#### How To Implement -This detection relies on sysmon logs with the Event ID 22, DNS Query. We suggest you run this detection at least once a day over the last 14 days. - -#### Known False Positives -Noise and false positive can be seen if the following instant messaging is allowed to use within corporate network. In this case, a filter is needed. - -#### Associated Analytic story -* [Remcos](/stories/remcos) -* [WhisperGate](/stories/whispergate) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 64.0 | 80 | 80 | suspicious process $process_name$ has a dns query in $QueryName$ on $Computer$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://urlhaus.abuse.ch/url/1798923/](https://urlhaus.abuse.ch/url/1798923/) -* [https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/](https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos_pastebin_download/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos_pastebin_download/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-01-19-suspicious_process_with_discord_dns_query.md b/docs/_posts/2022-01-19-suspicious_process_with_discord_dns_query.md deleted file mode 100644 index 168f96010b..0000000000 --- a/docs/_posts/2022-01-19-suspicious_process_with_discord_dns_query.md +++ /dev/null @@ -1,171 +0,0 @@ ---- -title: "Suspicious Process With Discord DNS Query" -excerpt: "Visual Basic -, Command and Scripting Interpreter -" -categories: - - Endpoint -last_modified_at: 2022-01-19 -toc: true -toc_label: "" -tags: - - Visual Basic - - Command and Scripting Interpreter - - Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic identifies a process making a DNS query to Discord, a well known instant messaging and digital distribution platform. Discord can be abused by adversaries, as seen in the WhisperGate campaign, to host and download malicious. external files. A process resolving a Discord DNS name could be an indicator of malware trying to download files from Discord for further execution. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-01-19 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 4d4332ae-792c-11ec-89c1-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059.005](https://attack.mitre.org/techniques/T1059/005/) | Visual Basic | Execution | - -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventCode=22 QueryName IN ("*discord*") process_path != "*\\AppData\\Local\\Discord\\*" AND process_path != "*\\Program Files*" AND process_name != "discord.exe" -| stats count min(_time) as firstTime max(_time) as lastTime by Image QueryName QueryStatus process_name QueryResults Computer process_path -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `suspicious_process_with_discord_dns_query_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **suspicious_process_with_discord_dns_query_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Image -* QueryName -* QueryStatus -* process_name -* QueryResults -* Computer -* process_path - - -#### How To Implement -his detection relies on sysmon logs with the Event ID 22, DNS Query. - -#### Known False Positives -Noise and false positive can be seen if the following instant messaging is allowed to use within corporate network. In this case, a filter is needed. - -#### Associated Analytic story -* [WhisperGate](/stories/whispergate) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 64.0 | 80 | 80 | suspicious process $process_name$ has a dns query in $QueryName$ on $Computer$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/](https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/) -* [https://medium.com/s2wblog/analysis-of-destructive-malware-whispergate-targeting-ukraine-9d5d158f19f3](https://medium.com/s2wblog/analysis-of-destructive-malware-whispergate-targeting-ukraine-9d5d158f19f3) -* [https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/](https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.005/discord_dnsquery/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.005/discord_dnsquery/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-01-19-windows_dotnet_binary_in_non_standard_path.md b/docs/_posts/2022-01-19-windows_dotnet_binary_in_non_standard_path.md deleted file mode 100644 index d77807e154..0000000000 --- a/docs/_posts/2022-01-19-windows_dotnet_binary_in_non_standard_path.md +++ /dev/null @@ -1,187 +0,0 @@ ---- -title: "Windows DotNet Binary in Non Standard Path" -excerpt: "Masquerading -, Rename System Utilities -, System Binary Proxy Execution -, InstallUtil -" -categories: - - Endpoint -last_modified_at: 2022-01-19 -toc: true -toc_label: "" -tags: - - Masquerading - - Rename System Utilities - - System Binary Proxy Execution - - InstallUtil - - Defense Evasion - - Defense Evasion - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies native .net binaries within the Windows operating system that may be abused by adversaries by moving it to a new directory. The analytic identifies the .net binary by using a lookup and compares the process name and original file name (internal name). The analytic utilizes a lookup with the is_net_windows_file macro to identify the binary process name and original file name. if one or the other matches an alert will be generated. Adversaries abuse these binaries as they are native to windows and native DotNet. Note that not all SDK (post install of Windows) are captured in the lookup. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-01-19 -- **Author**: Michael Haag, Splunk -- **ID**: fddf3b56-7933-11ec-98a6-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1036](https://attack.mitre.org/techniques/T1036/) | Masquerading | Defense Evasion | - -| [T1036.003](https://attack.mitre.org/techniques/T1036/003/) | Rename System Utilities | Defense Evasion | - -| [T1218](https://attack.mitre.org/techniques/T1218/) | System Binary Proxy Execution | Defense Evasion | - -| [T1218.004](https://attack.mitre.org/techniques/T1218/004/) | InstallUtil | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes where NOT (Processes.process_path IN ("*\\Windows\\ADWS\\*","*\\Windows\\SysWOW64*", "*\\Windows\\system32*", "*\\Windows\\NetworkController\\*", "*\\Windows\\SystemApps\\*", "*\\WinSxS\\*", "*\\Windows\\Microsoft.NET\\*")) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.original_file_name Processes.process_path Processes.process_id Processes.parent_process_id -| `drop_dm_object_name("Processes")` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `is_net_windows_file` -| `windows_dotnet_binary_in_non_standard_path_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [is_net_windows_file](https://github.com/splunk/security_content/blob/develop/macros/is_net_windows_file.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_dotnet_binary_in_non_standard_path_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -False positives may be present and filtering may be required. Certain utilities will run from non-standard paths based on the third-party application in use. - -#### Associated Analytic story -* [Masquerading - Rename System Utilities](/stories/masquerading_-_rename_system_utilities) -* [Unusual Processes](/stories/unusual_processes) -* [Ransomware](/stories/ransomware) -* [Signed Binary Proxy Execution InstallUtil](/stories/signed_binary_proxy_execution_installutil) -* [WhisperGate](/stories/whispergate) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | An instance of $parent_process_name$ spawning $process_name$ from a non-standard path was identified on endpoint $dest$ by user $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1036.003/T1036.003.yaml](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1036.003/T1036.003.yaml) -* [https://attack.mitre.org/techniques/T1036/003/](https://attack.mitre.org/techniques/T1036/003/) -* [https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/](https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.004/T1218.004.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.004/T1218.004.md) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.004/atomic_red_team/windows-sysmon_installutil_path.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.004/atomic_red_team/windows-sysmon_installutil_path.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_dotnet_binary_in_non_standard_path.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-01-19-windows_installutil_in_non_standard_path.md b/docs/_posts/2022-01-19-windows_installutil_in_non_standard_path.md deleted file mode 100644 index 14da8b3f81..0000000000 --- a/docs/_posts/2022-01-19-windows_installutil_in_non_standard_path.md +++ /dev/null @@ -1,187 +0,0 @@ ---- -title: "Windows InstallUtil in Non Standard Path" -excerpt: "Masquerading -, Rename System Utilities -, System Binary Proxy Execution -, InstallUtil -" -categories: - - Endpoint -last_modified_at: 2022-01-19 -toc: true -toc_label: "" -tags: - - Masquerading - - Rename System Utilities - - System Binary Proxy Execution - - InstallUtil - - Defense Evasion - - Defense Evasion - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the Windows binary InstallUtil.exe running from a non-standard location. The analytic utilizes a macro for InstallUtil and identifies both the process_name and original_file_name. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-01-19 -- **Author**: Michael Haag, Splunk -- **ID**: dcf74b22-7933-11ec-857c-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1036](https://attack.mitre.org/techniques/T1036/) | Masquerading | Defense Evasion | - -| [T1036.003](https://attack.mitre.org/techniques/T1036/003/) | Rename System Utilities | Defense Evasion | - -| [T1218](https://attack.mitre.org/techniques/T1218/) | System Binary Proxy Execution | Defense Evasion | - -| [T1218.004](https://attack.mitre.org/techniques/T1218/004/) | InstallUtil | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes where `process_installutil` NOT (Processes.process_path IN ("*\\Windows\\ADWS\\*","*\\Windows\\SysWOW64*", "*\\Windows\\system32*", "*\\Windows\\NetworkController\\*", "*\\Windows\\SystemApps\\*", "*\\WinSxS\\*", "*\\Windows\\Microsoft.NET\\*")) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.original_file_name Processes.process_id Processes.parent_process_id Processes.process_hash -| `drop_dm_object_name("Processes")` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_installutil_in_non_standard_path_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [process_installutil](https://github.com/splunk/security_content/blob/develop/macros/process_installutil.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_installutil_in_non_standard_path_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -False positives may be present and filtering may be required. Certain utilities will run from non-standard paths based on the third-party application in use. - -#### Associated Analytic story -* [Masquerading - Rename System Utilities](/stories/masquerading_-_rename_system_utilities) -* [Unusual Processes](/stories/unusual_processes) -* [Ransomware](/stories/ransomware) -* [Signed Binary Proxy Execution InstallUtil](/stories/signed_binary_proxy_execution_installutil) -* [WhisperGate](/stories/whispergate) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | An instance of $parent_process_name$ spawning $process_name$ from a non-standard path was identified on endpoint $dest$ by user $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1036.003/T1036.003.yaml](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1036.003/T1036.003.yaml) -* [https://attack.mitre.org/techniques/T1036/003/](https://attack.mitre.org/techniques/T1036/003/) -* [https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/](https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.004/T1218.004.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.004/T1218.004.md) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.004/atomic_red_team/windows-sysmon_installutil_path.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.004/atomic_red_team/windows-sysmon_installutil_path.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_installutil_in_non_standard_path.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-01-20-excessive_file_deletion_in_windefender_folder.md b/docs/_posts/2022-01-20-excessive_file_deletion_in_windefender_folder.md deleted file mode 100644 index f0282edf5f..0000000000 --- a/docs/_posts/2022-01-20-excessive_file_deletion_in_windefender_folder.md +++ /dev/null @@ -1,164 +0,0 @@ ---- -title: "Excessive File Deletion In WinDefender Folder" -excerpt: "Data Destruction -" -categories: - - Endpoint -last_modified_at: 2022-01-20 -toc: true -toc_label: "" -tags: - - Data Destruction - - Impact - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic will identify excessive file deletion events in the Windows Defender folder. This technique was seen in the WhisperGate malware campaign in which adversaries abused Nirsofts advancedrun.exe to gain administrative privilege to then execute PowerShell commands to delete files within the Windows Defender application folder. This behavior is a good indicator the offending process is trying to corrupt a Windows Defender installation. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-01-20 -- **Author**: Teoderick Contreras, Splunk -- **ID**: b5baa09a-7a05-11ec-8da4-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1485](https://attack.mitre.org/techniques/T1485/) | Data Destruction | Impact | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventCode=23 TargetFilename = "*\\ProgramData\\Microsoft\\Windows Defender*" -| stats values(TargetFilename) as deleted_files min(_time) as firstTime max(_time) as lastTime count by user EventCode Image ProcessID Computer -|where count >=50 -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `excessive_file_deletion_in_windefender_folder_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **excessive_file_deletion_in_windefender_folder_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* TargetFilename -* Computer -* user -* Image -* ProcessID - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, TargetFilename, and ProcessID executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -Windows Defender AV updates may cause this alert. Please update the filter macros to remove false positives. - -#### Associated Analytic story -* [WhisperGate](/stories/whispergate) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | High frequency file deletion activity detected on host $Computer$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/](https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/excessive_file_del_in_windefender_dir/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/excessive_file_del_in_windefender_dir/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/excessive_file_deletion_in_windefender_folder.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-01-20-ping_sleep_batch_command.md b/docs/_posts/2022-01-20-ping_sleep_batch_command.md deleted file mode 100644 index 548baa0f37..0000000000 --- a/docs/_posts/2022-01-20-ping_sleep_batch_command.md +++ /dev/null @@ -1,177 +0,0 @@ ---- -title: "Ping Sleep Batch Command" -excerpt: "Virtualization/Sandbox Evasion -, Time Based Evasion -" -categories: - - Endpoint -last_modified_at: 2022-01-20 -toc: true -toc_label: "" -tags: - - Virtualization/Sandbox Evasion - - Time Based Evasion - - Defense Evasion - - Discovery - - Defense Evasion - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic will identify the possible execution of ping sleep batch commands. This technique was seen in several malware samples and is used to trigger sleep times without explicitly calling sleep functions or commandlets. The goal is to delay the execution of malicious code and bypass detection or sandbox analysis. This detection can be a good indicator of a process delaying its execution for malicious purposes. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-01-20 -- **Author**: Teoderick Contreras, Splunk -- **ID**: ce058d6c-79f2-11ec-b476-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1497](https://attack.mitre.org/techniques/T1497/) | Virtualization/Sandbox Evasion | Defense Evasion, Discovery | - -| [T1497.003](https://attack.mitre.org/techniques/T1497/003/) | Time Based Evasion | Defense Evasion, Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_ping` (Processes.parent_process = "*ping*" Processes.parent_process = *-n* Processes.parent_process="* Nul*"Processes.parent_process="*>*") OR (Processes.process = "*ping*" Processes.process = *-n* Processes.process="* Nul*"Processes.process="*>*") by Processes.parent_process_name Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.process_guid Processes.user Processes.dest -| `drop_dm_object_name("Processes")` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -| `ping_sleep_batch_command_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [process_ping](https://github.com/splunk/security_content/blob/develop/macros/process_ping.yml) - -> :information_source: -> **ping_sleep_batch_command_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -Administrator or network operator may execute this command. Please update the filter macros to remove false positives. - -#### Associated Analytic story -* [WhisperGate](/stories/whispergate) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 36.0 | 60 | 60 | suspicious $process$ commandline run in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/](https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1497.003/ping_sleep/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1497.003/ping_sleep/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/ping_sleep_batch_command.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-01-21-windows_nirsoft_advancedrun.md b/docs/_posts/2022-01-21-windows_nirsoft_advancedrun.md deleted file mode 100644 index 63f965312e..0000000000 --- a/docs/_posts/2022-01-21-windows_nirsoft_advancedrun.md +++ /dev/null @@ -1,166 +0,0 @@ ---- -title: "Windows NirSoft AdvancedRun" -excerpt: "Tool -" -categories: - - Endpoint -last_modified_at: 2022-01-21 -toc: true -toc_label: "" -tags: - - Tool - - Resource Development - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the use of AdvancedRun.exe. AdvancedRun.exe has similar capabilities as other remote programs like psexec. AdvancedRun may also ingest a configuration file with all settings defined and perform its activity. The analytic is written in a way to identify a renamed binary and also the common command-line arguments. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-01-21 -- **Author**: Michael Haag, Splunk -- **ID**: bb4f3090-7ae4-11ec-897f-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1588.002](https://attack.mitre.org/techniques/T1588/002/) | Tool | Resource Development | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name=advancedrun.exe OR Processes.original_file_name=advancedrun.exe) Processes.process IN ("*EXEFilename*","*/cfg*","*RunAs*", "*WindowState*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.original_file_name Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_nirsoft_advancedrun_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_nirsoft_advancedrun_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -False positives should be limited as it is specific to AdvancedRun. Filter as needed based on legitimate usage. - -#### Associated Analytic story -* [Unusual Processes](/stories/unusual_processes) -* [Ransomware](/stories/ransomware) -* [WhisperGate](/stories/whispergate) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 60.0 | 60 | 100 | An instance of advancedrun.exe, $process_name$, was spawned by $parent_process_name$ on $dest$ by $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [http://www.nirsoft.net/utils/advanced_run.html](http://www.nirsoft.net/utils/advanced_run.html) -* [https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/](https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1588.002/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1588.002/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_nirsoft_advancedrun.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-01-24-windows_nirsoft_utilities.md b/docs/_posts/2022-01-24-windows_nirsoft_utilities.md deleted file mode 100644 index c8dcd7fcfc..0000000000 --- a/docs/_posts/2022-01-24-windows_nirsoft_utilities.md +++ /dev/null @@ -1,167 +0,0 @@ ---- -title: "Windows NirSoft Utilities" -excerpt: "Tool -" -categories: - - Endpoint -last_modified_at: 2022-01-24 -toc: true -toc_label: "" -tags: - - Tool - - Resource Development - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following hunting analytic assists with identifying the proces execution of commonly used utilities from NirSoft. Potentially not adversary behavior, but worth identifying to know if the software is present and being used. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-01-24 -- **Author**: Michael Haag, Splunk -- **ID**: 5b2f4596-7d4c-11ec-88a7-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1588.002](https://attack.mitre.org/techniques/T1588/002/) | Tool | Resource Development | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.original_file_name Processes.process_path Processes.process_id Processes.parent_process_id -| `drop_dm_object_name("Processes")` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `is_nirsoft_software` -| `windows_nirsoft_utilities_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [is_nirsoft_software](https://github.com/splunk/security_content/blob/develop/macros/is_nirsoft_software.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_nirsoft_utilities_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -False positives may be present. Filtering may be required before setting to alert. - -#### Associated Analytic story -* [WhisperGate](/stories/whispergate) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ related to NiRSoft software usage. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.cisa.gov/uscert/ncas/alerts/TA18-201A](https://www.cisa.gov/uscert/ncas/alerts/TA18-201A) -* [http://www.nirsoft.net/](http://www.nirsoft.net/) -* [https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/](https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1588.002/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1588.002/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_nirsoft_utilities.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-01-26-active_setup_registry_autostart.md b/docs/_posts/2022-01-26-active_setup_registry_autostart.md deleted file mode 100644 index 1d1066b18b..0000000000 --- a/docs/_posts/2022-01-26-active_setup_registry_autostart.md +++ /dev/null @@ -1,171 +0,0 @@ ---- -title: "Active Setup Registry Autostart" -excerpt: "Active Setup -, Boot or Logon Autostart Execution -" -categories: - - Endpoint -last_modified_at: 2022-01-26 -toc: true -toc_label: "" -tags: - - Active Setup - - Boot or Logon Autostart Execution - - Persistence - - Privilege Escalation - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to detect a suspicious modification of the active setup registry for persistence and privilege escalation. This technique was seen in several malware (poisonIvy), adware and APT to gain persistence to the compromised machine upon boot up. This TTP is a good indicator to further check the process id that do the modification since modification of this registry is not commonly done. check the legitimacy of the file and process involve in this rules to check if it is a valid setup installer that creating or modifying this registry. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-01-26 -- **Author**: Teoderick Contreras, Splunk -- **ID**: f64579c0-203f-11ec-abcc-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1547.014](https://attack.mitre.org/techniques/T1547/014/) | Active Setup | Persistence, Privilege Escalation | - -| [T1547](https://attack.mitre.org/techniques/T1547/) | Boot or Logon Autostart Execution | Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry where Registry.registry_value_name= "StubPath" Registry.registry_path = "*\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components*" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid -| `drop_dm_object_name(Registry)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] -| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data -| `active_setup_registry_autostart_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **active_setup_registry_autostart_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.dest -* Registry.user -* Registry.registry_path -* Registry.registry_key_name -* Registry.registry_value_name - - -#### How To Implement -To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. - -#### Known False Positives -Active setup installer may add or modify this registry. - -#### Associated Analytic story -* [Windows Persistence Techniques](/stories/windows_persistence_techniques) -* [Windows Privilege Escalation](/stories/windows_privilege_escalation) -* [Hermetic Wiper](/stories/hermetic_wiper) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 64.0 | 80 | 80 | modified/added/deleted registry entry $Registry.registry_path$ in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Backdoor%3AWin32%2FPoisonivy.E](https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Backdoor%3AWin32%2FPoisonivy.E) -* [https://attack.mitre.org/techniques/T1547/014/](https://attack.mitre.org/techniques/T1547/014/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/t1547.014/active_setup_stubpath/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/t1547.014/active_setup_stubpath/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/active_setup_registry_autostart.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-01-26-add_defaultuser_and_password_in_registry.md b/docs/_posts/2022-01-26-add_defaultuser_and_password_in_registry.md deleted file mode 100644 index be541bc837..0000000000 --- a/docs/_posts/2022-01-26-add_defaultuser_and_password_in_registry.md +++ /dev/null @@ -1,165 +0,0 @@ ---- -title: "Add DefaultUser And Password In Registry" -excerpt: "Credentials in Registry -, Unsecured Credentials -" -categories: - - Endpoint -last_modified_at: 2022-01-26 -toc: true -toc_label: "" -tags: - - Credentials in Registry - - Unsecured Credentials - - Credential Access - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -this search is to detect a suspicious registry modification to implement auto admin logon to a host. This technique was seen in BlackMatter ransomware to automatically logon to the compromise host after triggering a safemode boot to continue encrypting the whole network. This behavior is not a common practice and really a suspicious TTP or alert need to be consider if found within then network premise. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-01-26 -- **Author**: Teoderick Contreras, Splunk -- **ID**: d4a3eb62-0f1e-11ec-a971-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1552.002](https://attack.mitre.org/techniques/T1552/002/) | Credentials in Registry | Credential Access | - -| [T1552](https://attack.mitre.org/techniques/T1552/) | Unsecured Credentials | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path= "*SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon*" AND Registry.registry_value_name= DefaultPassword OR Registry.registry_value_name= DefaultUserName by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.process_guid Registry.registry_value_data Registry.registry_key_name -| `drop_dm_object_name(Registry)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] -| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name -| `add_defaultuser_and_password_in_registry_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **add_defaultuser_and_password_in_registry_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.registry_path -* Registry.registry_key_name -* Registry.registry_value_name -* Registry.dest - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [BlackMatter Ransomware](/stories/blackmatter_ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | modified registry key $registry_key_name$ with registry value $registry_value_name$ to prepare autoadminlogon | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://news.sophos.com/en-us/2021/08/09/blackmatter-ransomware-emerges-from-the-shadow-of-darkside/](https://news.sophos.com/en-us/2021/08/09/blackmatter-ransomware-emerges-from-the-shadow-of-darkside/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1552.002/autoadminlogon/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1552.002/autoadminlogon/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-01-26-allow_inbound_traffic_by_firewall_rule_registry.md b/docs/_posts/2022-01-26-allow_inbound_traffic_by_firewall_rule_registry.md deleted file mode 100644 index 0228edccd1..0000000000 --- a/docs/_posts/2022-01-26-allow_inbound_traffic_by_firewall_rule_registry.md +++ /dev/null @@ -1,174 +0,0 @@ ---- -title: "Allow Inbound Traffic By Firewall Rule Registry" -excerpt: "Remote Desktop Protocol -, Remote Services -" -categories: - - Endpoint -last_modified_at: 2022-01-26 -toc: true -toc_label: "" -tags: - - Remote Desktop Protocol - - Remote Services - - Lateral Movement - - Lateral Movement - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic detects a potential suspicious modification of firewall rule registry allowing inbound traffic in specific port with public profile. This technique was identified when an adversary wants to grant remote access to a machine by allowing the traffic in a firewall rule. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-01-26 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 0a46537c-be02-11eb-92ca-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1021.001](https://attack.mitre.org/techniques/T1021/001/) | Remote Desktop Protocol | Lateral Movement | - -| [T1021](https://attack.mitre.org/techniques/T1021/) | Remote Services | Lateral Movement | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path= "*\\System\\CurrentControlSet\\Services\\SharedAccess\\Parameters\\FirewallPolicy\\FirewallRules\\*" Registry.registry_value_data = "* -|Action=Allow -|*" Registry.registry_value_data = "* -|Dir=In -|*" Registry.registry_value_data = "* -|Profile=Public -|*" Registry.registry_value_data = "* -|LPort=*" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.process_guid Registry.registry_key_name Registry.registry_value_data -| `drop_dm_object_name(Registry)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] -| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name -| `allow_inbound_traffic_by_firewall_rule_registry_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **allow_inbound_traffic_by_firewall_rule_registry_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.registry_path -* Registry.registry_value_name -* Registry.registry_key_name -* Registry.dest -* Registry.user - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. - -#### Known False Positives -network admin may add/remove/modify public inbound firewall rule that may cause this rule to be triggered. - -#### Associated Analytic story -* [Prohibited Traffic Allowed or Protocol Mismatch](/stories/prohibited_traffic_allowed_or_protocol_mismatch) -* [Windows Registry Abuse](/stories/windows_registry_abuse) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 3.0 | 10 | 30 | Suspicious firewall modifications were detected via the registry on endpoint $dest$ by user $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://docs.microsoft.com/en-us/powershell/module/netsecurity/new-netfirewallrule?view=windowsserver2019-ps](https://docs.microsoft.com/en-us/powershell/module/netsecurity/new-netfirewallrule?view=windowsserver2019-ps) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/casper/datasets1/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/casper/datasets1/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-01-26-allow_operation_with_consent_admin.md b/docs/_posts/2022-01-26-allow_operation_with_consent_admin.md deleted file mode 100644 index 47944116d0..0000000000 --- a/docs/_posts/2022-01-26-allow_operation_with_consent_admin.md +++ /dev/null @@ -1,164 +0,0 @@ ---- -title: "Allow Operation with Consent Admin" -excerpt: "Abuse Elevation Control Mechanism -" -categories: - - Endpoint -last_modified_at: 2022-01-26 -toc: true -toc_label: "" -tags: - - Abuse Elevation Control Mechanism - - Defense Evasion - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic identifies a potential privilege escalation attempt to perform malicious task. This registry modification is designed to allow the `Consent Admin` to perform an operation that requires elevation without consent or credentials. We also found this in some attacker to gain privilege escalation to the compromise machine. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-01-26 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 7de17d7a-c9d8-11eb-a812-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1548](https://attack.mitre.org/techniques/T1548/) | Abuse Elevation Control Mechanism | Defense Evasion, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry where Registry.registry_path= "*\\Microsoft\\Windows\\CurrentVersion\\Policies\\System*" Registry.registry_value_name = ConsentPromptBehaviorAdmin Registry.registry_value_data = "0x00000000" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.process_guid Registry.registry_key_name Registry.registry_value_data -| `drop_dm_object_name(Registry)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] -| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name -| `allow_operation_with_consent_admin_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **allow_operation_with_consent_admin_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.registry_path -* Registry.registry_key_name -* Registry.registry_value_name -* Registry.dest - - -#### How To Implement -To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Ransomware](/stories/ransomware) -* [Windows Registry Abuse](/stories/windows_registry_abuse) -* [Azorult](/stories/azorult) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | Suspicious registry modification was performed on endpoint $dest$ by user $user$. This behavior is indicative of privilege escalation. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://docs.microsoft.com/en-us/openspecs/windows_protocols/ms-gpsb/341747f5-6b5d-4d30-85fc-fa1cc04038d4](https://docs.microsoft.com/en-us/openspecs/windows_protocols/ms-gpsb/341747f5-6b5d-4d30-85fc-fa1cc04038d4) -* [https://www.trendmicro.com/vinfo/no/threat-encyclopedia/malware/Ransom.Win32.MRDEC.MRA/](https://www.trendmicro.com/vinfo/no/threat-encyclopedia/malware/Ransom.Win32.MRDEC.MRA/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/data1/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/data1/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/allow_operation_with_consent_admin.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-01-26-disable_amsi_through_registry.md b/docs/_posts/2022-01-26-disable_amsi_through_registry.md deleted file mode 100644 index ff0458821c..0000000000 --- a/docs/_posts/2022-01-26-disable_amsi_through_registry.md +++ /dev/null @@ -1,168 +0,0 @@ ---- -title: "Disable AMSI Through Registry" -excerpt: "Disable or Modify Tools -, Impair Defenses -" -categories: - - Endpoint -last_modified_at: 2022-01-26 -toc: true -toc_label: "" -tags: - - Disable or Modify Tools - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -this search is to identify modification in registry to disable AMSI windows feature to evade detections. This technique was seen in several ransomware, RAT and even APT to impaire defenses of the compromise machine and to be able to execute payload with minimal alert as much as possible. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-01-26 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 9c27ec42-d338-11eb-9044-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows Script\\Settings\\AmsiEnable" Registry.registry_value_data = "0x00000000" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid -| `drop_dm_object_name(Registry)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] -| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data -| `disable_amsi_through_registry_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **disable_amsi_through_registry_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.registry_key_name -* Registry.registry_path -* Registry.user -* Registry.dest -* Registry.registry_value_name - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. - -#### Known False Positives -network operator may disable this feature of windows but not so common. - -#### Associated Analytic story -* [Ransomware](/stories/ransomware) -* [Windows Registry Abuse](/stories/windows_registry_abuse) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | Disable AMSI Through Registry | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://blog.f-secure.com/hunting-for-amsi-bypasses/](https://blog.f-secure.com/hunting-for-amsi-bypasses/) -* [https://gist.github.com/rxwx/8955e5abf18dc258fd6b43a3a7f4dbf9](https://gist.github.com/rxwx/8955e5abf18dc258fd6b43a3a7f4dbf9) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/data2/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/data2/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disable_amsi_through_registry.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-01-26-disable_defender_antivirus_registry.md b/docs/_posts/2022-01-26-disable_defender_antivirus_registry.md deleted file mode 100644 index 9c79d1047d..0000000000 --- a/docs/_posts/2022-01-26-disable_defender_antivirus_registry.md +++ /dev/null @@ -1,168 +0,0 @@ ---- -title: "Disable Defender AntiVirus Registry" -excerpt: "Disable or Modify Tools -, Impair Defenses -" -categories: - - Endpoint -last_modified_at: 2022-01-26 -toc: true -toc_label: "" -tags: - - Disable or Modify Tools - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This particular behavior is typically executed when an adversaries or malware gains access to an endpoint and beings to perform execution and to evade detections. Usually, a batch (.bat) will be executed and multiple registry and scheduled task modifications will occur. During triage, review parallel processes and identify any further file modifications. Endpoint should be isolated. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-01-26 -- **Author**: Teoderick Contreras, Splunk -- **ID**: aa4f695a-3024-11ec-9987-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path = "*\\Policies\\Microsoft\\Windows Defender*" Registry.registry_value_name = DisableAntiVirus Registry.registry_value_data = 0x00000001 by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid -| `drop_dm_object_name(Registry)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] -| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data -| `disable_defender_antivirus_registry_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **disable_defender_antivirus_registry_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.dest -* Registry.user -* Registry.registry_value_name -* Registry.registry_key_name -* Registry.registry_path -* Registry.registry_value_data - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the registry value name, registry path, and registry value data from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -admin or user may choose to disable windows defender product - -#### Associated Analytic story -* [IceID](/stories/iceid) -* [Windows Registry Abuse](/stories/windows_registry_abuse) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | modified/added/deleted registry entry $registry_path$ in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/](https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/disable_av/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/disable_av/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disable_defender_antivirus_registry.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-01-26-disable_defender_blockatfirstseen_feature.md b/docs/_posts/2022-01-26-disable_defender_blockatfirstseen_feature.md deleted file mode 100644 index 8e3dd93cfa..0000000000 --- a/docs/_posts/2022-01-26-disable_defender_blockatfirstseen_feature.md +++ /dev/null @@ -1,169 +0,0 @@ ---- -title: "Disable Defender BlockAtFirstSeen Feature" -excerpt: "Disable or Modify Tools -, Impair Defenses -" -categories: - - Endpoint -last_modified_at: 2022-01-26 -toc: true -toc_label: "" -tags: - - Disable or Modify Tools - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to detect a suspicious modification of registry to disable windows defender feature. This technique is to bypassed or evade detection from Windows Defender AV product specially the BlockAtFirstSeen feature where it block suspicious file first seen in the host. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-01-26 -- **Author**: Teoderick Contreras -- **ID**: 2dd719ac-3021-11ec-97b4-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path = "*\\Microsoft\\Windows Defender\\SpyNet*" Registry.registry_value_name = DisableBlockAtFirstSeen Registry.registry_value_data = 0x00000001 by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid -| `drop_dm_object_name(Registry)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] -| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data -| `disable_defender_blockatfirstseen_feature_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **disable_defender_blockatfirstseen_feature_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.dest -* Registry.user -* Registry.registry_value_name -* Registry.registry_key_name -* Registry.registry_path -* Registry.registry_value_data - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the registry value name, registry path, and registry value data from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -admin or user may choose to disable windows defender product - -#### Associated Analytic story -* [IceID](/stories/iceid) -* [Windows Registry Abuse](/stories/windows_registry_abuse) -* [Azorult](/stories/azorult) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | modified/added/deleted registry entry $registry_path$ in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/](https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/disable_av/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/disable_av/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-01-26-disable_defender_enhanced_notification.md b/docs/_posts/2022-01-26-disable_defender_enhanced_notification.md deleted file mode 100644 index ec0d139879..0000000000 --- a/docs/_posts/2022-01-26-disable_defender_enhanced_notification.md +++ /dev/null @@ -1,169 +0,0 @@ ---- -title: "Disable Defender Enhanced Notification" -excerpt: "Disable or Modify Tools -, Impair Defenses -" -categories: - - Endpoint -last_modified_at: 2022-01-26 -toc: true -toc_label: "" -tags: - - Disable or Modify Tools - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to detect a suspicious modification of registry to disable windows defender feature. This technique is to bypassed or evade detection from Windows Defender AV product specially the Enhanced Notification feature wher user or admin set to show or display alerts. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-01-26 -- **Author**: Teoderick Contreras, Splunk -- **ID**: dc65678c-301f-11ec-8e30-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path = "*Microsoft\\Windows Defender\\Reporting*" Registry.registry_value_name = DisableEnhancedNotifications Registry.registry_value_data = 0x00000001 by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid -| `drop_dm_object_name(Registry)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] -| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data -| `disable_defender_enhanced_notification_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **disable_defender_enhanced_notification_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.dest -* Registry.user -* Registry.registry_value_name -* Registry.registry_key_name -* Registry.registry_path -* Registry.registry_value_data - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the registry value name, registry path, and registry value data executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -user may choose to disable windows defender AV - -#### Associated Analytic story -* [IceID](/stories/iceid) -* [Windows Registry Abuse](/stories/windows_registry_abuse) -* [Azorult](/stories/azorult) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | modified/added/deleted registry entry $registry_path$ in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/](https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/disable_av/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/disable_av/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disable_defender_enhanced_notification.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-01-26-disable_defender_mpengine_registry.md b/docs/_posts/2022-01-26-disable_defender_mpengine_registry.md deleted file mode 100644 index b660e79003..0000000000 --- a/docs/_posts/2022-01-26-disable_defender_mpengine_registry.md +++ /dev/null @@ -1,168 +0,0 @@ ---- -title: "Disable Defender MpEngine Registry" -excerpt: "Disable or Modify Tools -, Impair Defenses -" -categories: - - Endpoint -last_modified_at: 2022-01-26 -toc: true -toc_label: "" -tags: - - Disable or Modify Tools - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This particular behavior is typically executed when an adversaries or malware gains access to an endpoint and beings to perform execution and to evade detections. Usually, a batch (.bat) will be executed and multiple registry and scheduled task modifications will occur. During triage, review parallel processes and identify any further file modifications. Endpoint should be isolated. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-01-26 -- **Author**: Teoderick Contreras, Splunk -- **ID**: cc391750-3024-11ec-955a-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path = "*\\Policies\\Microsoft\\Windows Defender\\MpEngine*" Registry.registry_value_name = MpEnablePus Registry.registry_value_data = 0x00000000 by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid -| `drop_dm_object_name(Registry)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] -| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data -| `disable_defender_mpengine_registry_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **disable_defender_mpengine_registry_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.dest -* Registry.user -* Registry.registry_value_name -* Registry.registry_key_name -* Registry.registry_path -* Registry.registry_value_data - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the registry value name, registry path, and registry value data from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -admin or user may choose to disable windows defender product - -#### Associated Analytic story -* [IceID](/stories/iceid) -* [Windows Registry Abuse](/stories/windows_registry_abuse) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | modified/added/deleted registry entry $registry_path$ in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/](https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/disable_av/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/disable_av/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disable_defender_mpengine_registry.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-01-26-disable_defender_spynet_reporting.md b/docs/_posts/2022-01-26-disable_defender_spynet_reporting.md deleted file mode 100644 index ff8afa4d65..0000000000 --- a/docs/_posts/2022-01-26-disable_defender_spynet_reporting.md +++ /dev/null @@ -1,169 +0,0 @@ ---- -title: "Disable Defender Spynet Reporting" -excerpt: "Disable or Modify Tools -, Impair Defenses -" -categories: - - Endpoint -last_modified_at: 2022-01-26 -toc: true -toc_label: "" -tags: - - Disable or Modify Tools - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to detect a suspicious modification of registry to disable windows defender feature. This technique is to bypassed or evade detection from Windows Defender AV product specially the spynet reporting for its telemetry. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-01-26 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 898debf4-3021-11ec-ba7c-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path = "*\\Microsoft\\Windows Defender\\SpyNet*" Registry.registry_value_name = SpynetReporting Registry.registry_value_data = 0x00000000 by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid -| `drop_dm_object_name(Registry)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] -| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data -| `disable_defender_spynet_reporting_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **disable_defender_spynet_reporting_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.dest -* Registry.user -* Registry.registry_value_name -* Registry.registry_key_name -* Registry.registry_path -* Registry.registry_value_data - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the registry value name, registry path, and registry value data from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -admin or user may choose to disable windows defender product - -#### Associated Analytic story -* [IceID](/stories/iceid) -* [Windows Registry Abuse](/stories/windows_registry_abuse) -* [Azorult](/stories/azorult) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | modified/added/deleted registry entry $registry_path$ in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/](https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/disable_av/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/disable_av/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disable_defender_spynet_reporting.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-01-26-disable_defender_submit_samples_consent_feature.md b/docs/_posts/2022-01-26-disable_defender_submit_samples_consent_feature.md deleted file mode 100644 index d47dc7e78d..0000000000 --- a/docs/_posts/2022-01-26-disable_defender_submit_samples_consent_feature.md +++ /dev/null @@ -1,169 +0,0 @@ ---- -title: "Disable Defender Submit Samples Consent Feature" -excerpt: "Disable or Modify Tools -, Impair Defenses -" -categories: - - Endpoint -last_modified_at: 2022-01-26 -toc: true -toc_label: "" -tags: - - Disable or Modify Tools - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to detect a suspicious modification of registry to disable windows defender feature. This technique is to bypassed or evade detection from Windows Defender AV product specially the submit samples feature for further analysis.. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-01-26 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 73922ff8-3022-11ec-bf5e-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path = "*\\Microsoft\\Windows Defender\\SpyNet*" Registry.registry_value_name = SubmitSamplesConsent Registry.registry_value_data = 0x00000000 by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid -| `drop_dm_object_name(Registry)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] -| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data -| `disable_defender_submit_samples_consent_feature_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **disable_defender_submit_samples_consent_feature_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.dest -* Registry.user -* Registry.registry_value_name -* Registry.registry_key_name -* Registry.registry_path -* Registry.registry_value_data - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the registry value name, registry path, and registry value data from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -admin or user may choose to disable windows defender product - -#### Associated Analytic story -* [IceID](/stories/iceid) -* [Windows Registry Abuse](/stories/windows_registry_abuse) -* [Azorult](/stories/azorult) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | modified/added/deleted registry entry $Registry.registry_path$ in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/](https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/disable_av/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/disable_av/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-01-26-log4shell_cve-2021-44228_exploitation.md b/docs/_posts/2022-01-26-log4shell_cve-2021-44228_exploitation.md deleted file mode 100644 index 26e45f6eac..0000000000 --- a/docs/_posts/2022-01-26-log4shell_cve-2021-44228_exploitation.md +++ /dev/null @@ -1,177 +0,0 @@ ---- -title: "Log4Shell CVE-2021-44228 Exploitation" -excerpt: "Ingress Tool Transfer -, Exploit Public-Facing Application -, Command and Scripting Interpreter -" -categories: - - Endpoint -last_modified_at: 2022-01-26 -toc: true -toc_label: "" -tags: - - Ingress Tool Transfer - - Exploit Public-Facing Application - - Command and Scripting Interpreter - - Command And Control - - Initial Access - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Risk ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This correlation find exploitation of Log4Shell CVE-2021-44228 against systems using detections from Splunk Security Content Analytic Story. It does this by calculating the distinct count of MITRE ATT&CK tactics from Log4Shell detections fired. If the count is larger than 2 or more distinct MITRE ATT&CK tactics we assume high problability of exploitation. The Analytic story breaks down into 3 major phases of a Log4Shell exploitation, specifically> Initial Payload delivery eg. `${jndi:ldap://PAYLOAD_INJECTED}` Call back to malicious LDAP server eg. Exploit.class Post Exploitation Activity/Lateral Movement using Powershell or similar T1562.001 Each of these phases fall into different MITRE ATT&CK Tactics (Initial Access, Execution, Command and Control), by looking into 2 or more phases showing up in detections triggerd is how this correlation search finds exploitation. If we get a notable from this correlation search the best way to triage it is by investigating the affected systems against Log4Shell exploitation using Splunk SOAR playbooks. - -- **Type**: [Correlation](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Risk](https://docs.splunk.com/Documentation/CIM/latest/User/Risk) -- **Last Updated**: 2022-01-26 -- **Author**: Jose Hernandez, Splunk -- **ID**: 9be30d80-3a39-4df9-9102-64a467b24eac - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1105](https://attack.mitre.org/techniques/T1105/) | Ingress Tool Transfer | Command And Control | - -| [T1190](https://attack.mitre.org/techniques/T1190/) | Exploit Public-Facing Application | Initial Access | - -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Risk.All_Risk where All_Risk.analyticstories="Log4Shell CVE-2021-44228" All_Risk.risk_object_type="system" by All_Risk.risk_object All_Risk.annotations.mitre_attack.mitre_tactic source -| `drop_dm_object_name(All_Risk)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| stats values(risk_object) as affected_systems values(source) as detection_name values(annotations.mitre_attack.mitre_tactic) as tactics values(firstTime) as firstTime values(lastTime) as lastTime dc(annotations.mitre_attack.mitre_tactic) as distinct_tactics -| where distinct_tactics >= 2 -| `log4shell_cve_2021_44228_exploitation_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **log4shell_cve-2021-44228_exploitation_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* All_Risk.analyticstories -* All_Risk.risk_object_type -* All_Risk.risk_object -* All_Risk.annotations.mitre_attack.mitre_tactic -* source - - -#### How To Implement -To implement this correlation search a user needs to enable all detections in the Log4Shell Analytic Story and confirm it is generation risk events. A simple search `index=risk analyticstories="Log4Shell CVE-2021-44228"` should contain events. - -#### Known False Positives -There are no known false positive for this search, but it could contain false positives as multiple detections can trigger and not have successful exploitation. - -#### Associated Analytic story -* [Log4Shell CVE-2021-44228](/stories/log4shell_cve-2021-44228) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 63.0 | 90 | 70 | Log4Shell Exploitation detected against $affected_systems$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://research.splunk.com/stories/log4shell_cve-2021-44228/](https://research.splunk.com/stories/log4shell_cve-2021-44228/) -* [https://www.splunk.com/en_us/blog/security/simulating-detecting-and-responding-to-log4shell-with-splunk.html](https://www.splunk.com/en_us/blog/security/simulating-detecting-and-responding-to-log4shell-with-splunk.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://raw.githubusercontent.com/splunk/attack_data/master/datasets/suspicious_behaviour/log4shell_exploitation/log4shell_correlation.txt](https://raw.githubusercontent.com/splunk/attack_data/master/datasets/suspicious_behaviour/log4shell_exploitation/log4shell_correlation.txt) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/log4shell_cve_2021_44228_exploitation.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-01-26-registry_keys_used_for_persistence.md b/docs/_posts/2022-01-26-registry_keys_used_for_persistence.md deleted file mode 100644 index 802f961654..0000000000 --- a/docs/_posts/2022-01-26-registry_keys_used_for_persistence.md +++ /dev/null @@ -1,181 +0,0 @@ ---- -title: "Registry Keys Used For Persistence" -excerpt: "Registry Run Keys / Startup Folder -, Boot or Logon Autostart Execution -" -categories: - - Endpoint -last_modified_at: 2022-01-26 -toc: true -toc_label: "" -tags: - - Registry Run Keys / Startup Folder - - Boot or Logon Autostart Execution - - Persistence - - Privilege Escalation - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The search looks for modifications to registry keys that can be used to launch an application or service at system startup. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-01-26 -- **Author**: Jose Hernandez, David Dorsey, Teoderick Contreras, Rod Soto, Splunk -- **ID**: f5f6af30-7aa7-4295-bfe9-07fe87c01a4b - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1547.001](https://attack.mitre.org/techniques/T1547/001/) | Registry Run Keys / Startup Folder | Persistence, Privilege Escalation | - -| [T1547](https://attack.mitre.org/techniques/T1547/) | Boot or Logon Autostart Execution | Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM -* DE.AE - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry where (Registry.registry_path=*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnce OR Registry.registry_path=*\\currentversion\\run* OR Registry.registry_path=*\\currentVersion\\Windows\\Appinit_Dlls* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Shell* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Notify* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Userinit* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\VmApplet* OR Registry.registry_path=*\\currentversion\\policies\\explorer\\run* OR Registry.registry_path=*\\currentversion\\runservices* OR Registry.registry_path=HKLM\\SOFTWARE\\Microsoft\\Netsh\\* OR (Registry.registry_path="*Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options*" AND Registry.registry_key_name=Debugger) OR (Registry.registry_path="*\\CurrentControlSet\\Control\\Lsa" AND Registry.registry_key_name="Security Packages") OR (Registry.registry_path="*\\CurrentControlSet\\Control\\Lsa\\OSConfig" AND Registry.registry_key_name="Security Packages") OR (Registry.registry_path="*\\Microsoft\\Windows NT\\CurrentVersion\\SilentProcessExit\\*") OR (Registry.registry_path="*currentVersion\\Windows" AND Registry.registry_key_name="Load") OR (Registry.registry_path="*\\CurrentVersion" AND Registry.registry_key_name="Svchost") OR (Registry.registry_path="*\\CurrentControlSet\Control\Session Manager"AND Registry.registry_key_name="BootExecute") OR (Registry.registry_path="*\\Software\\Run" AND Registry.registry_key_name="auto_update")) by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid Registry.registry_key_name -| `drop_dm_object_name(Registry)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] -| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name -| `registry_keys_used_for_persistence_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **registry_keys_used_for_persistence_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.registry_key_name -* Registry.registry_path -* Registry.dest -* Registry.user - - -#### How To Implement -To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. - -#### Known False Positives -There are many legitimate applications that must execute on system startup and will use these registry keys to accomplish that task. - -#### Associated Analytic story -* [Suspicious Windows Registry Activities](/stories/suspicious_windows_registry_activities) -* [Suspicious MSHTA Activity](/stories/suspicious_mshta_activity) -* [DHS Report TA18-074A](/stories/dhs_report_ta18-074a) -* [Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns](/stories/possible_backdoor_activity_associated_with_mudcarp_espionage_campaigns) -* [Ransomware](/stories/ransomware) -* [Windows Persistence Techniques](/stories/windows_persistence_techniques) -* [Emotet Malware DHS Report TA18-201A ](/stories/emotet_malware__dhs_report_ta18-201a_) -* [IcedID](/stories/icedid) -* [Remcos](/stories/remcos) -* [Windows Registry Abuse](/stories/windows_registry_abuse) -* [Azorult](/stories/azorult) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 76.0 | 80 | 95 | A registry activity in $registry_path$ related to persistence in host $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.001/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.001/atomic_red_team/windows-sysmon.log) -* [https://raw.githubusercontent.com/splunk/attack_data/master/datasets/attack_techniques/T1547.001/atomic_red_team/t1547001-runonce.log](https://raw.githubusercontent.com/splunk/attack_data/master/datasets/attack_techniques/T1547.001/atomic_red_team/t1547001-runonce.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/registry_keys_used_for_persistence.yml) \| *version*: **7** \ No newline at end of file diff --git a/docs/_posts/2022-01-26-registry_keys_used_for_privilege_escalation.md b/docs/_posts/2022-01-26-registry_keys_used_for_privilege_escalation.md deleted file mode 100644 index 57cacbb521..0000000000 --- a/docs/_posts/2022-01-26-registry_keys_used_for_privilege_escalation.md +++ /dev/null @@ -1,176 +0,0 @@ ---- -title: "Registry Keys Used For Privilege Escalation" -excerpt: "Image File Execution Options Injection -, Event Triggered Execution -" -categories: - - Endpoint -last_modified_at: 2022-01-26 -toc: true -toc_label: "" -tags: - - Image File Execution Options Injection - - Event Triggered Execution - - Persistence - - Privilege Escalation - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for modifications to registry keys that can be used to elevate privileges. The registry keys under "Image File Execution Options" are used to intercept calls to an executable and can be used to attach malicious binaries to benign system binaries. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-01-26 -- **Author**: David Dorsey, Teoderick Contreras, Splunk -- **ID**: c9f4b923-f8af-4155-b697-1354f5bcbc5e - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1546.012](https://attack.mitre.org/techniques/T1546/012/) | Image File Execution Options Injection | Persistence, Privilege Escalation | - -| [T1546](https://attack.mitre.org/techniques/T1546/) | Event Triggered Execution | Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry where (Registry.registry_path="*Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options*") AND (Registry.registry_value_name=GlobalFlag OR Registry.registry_value_name=Debugger) by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid Registry.registry_key_name -| `drop_dm_object_name(Registry)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] -| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name -| `registry_keys_used_for_privilege_escalation_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **registry_keys_used_for_privilege_escalation_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.registry_path -* Registry.registry_key_name -* Registry.dest -* Registry.user - - -#### How To Implement -To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black, or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. - -#### Known False Positives -There are many legitimate applications that must execute upon system startup and will use these registry keys to accomplish that task. - -#### Associated Analytic story -* [Windows Privilege Escalation](/stories/windows_privilege_escalation) -* [Suspicious Windows Registry Activities](/stories/suspicious_windows_registry_activities) -* [Cloud Federated Credential Abuse](/stories/cloud_federated_credential_abuse) -* [Windows Registry Abuse](/stories/windows_registry_abuse) -* [Hermetic Wiper](/stories/hermetic_wiper) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 76.0 | 80 | 95 | A registry activity in $registry_path$ related to privilege escalation in host $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://blog.malwarebytes.com/101/2015/12/an-introduction-to-image-file-execution-options/](https://blog.malwarebytes.com/101/2015/12/an-introduction-to-image-file-execution-options/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.012/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.012/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml) \| *version*: **5** \ No newline at end of file diff --git a/docs/_posts/2022-01-26-remcos_client_registry_install_entry.md b/docs/_posts/2022-01-26-remcos_client_registry_install_entry.md deleted file mode 100644 index 30c9c11ef0..0000000000 --- a/docs/_posts/2022-01-26-remcos_client_registry_install_entry.md +++ /dev/null @@ -1,163 +0,0 @@ ---- -title: "Remcos client registry install entry" -excerpt: "Modify Registry -" -categories: - - Endpoint -last_modified_at: 2022-01-26 -toc: true -toc_label: "" -tags: - - Modify Registry - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search detects registry key license at host where Remcos RAT agent is installed. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-01-26 -- **Author**: Bhavin Patel, Rod Soto, Teoderick Contreras, Splunk -- **ID**: f2a1615a-1d63-11ec-97d2-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1112](https://attack.mitre.org/techniques/T1112/) | Modify Registry | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry where (Registry.registry_key_name=*\\Software\\Remcos*) by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid -| `drop_dm_object_name(Registry)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] -| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data -|`remcos_client_registry_install_entry_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **remcos_client_registry_install_entry_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.registry_path -* Registry.registry_key_name -* Registry.process_id -* Registry.dest -* Registry.user - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Remcos](/stories/remcos) -* [Windows Registry Abuse](/stories/windows_registry_abuse) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 90.0 | 90 | 100 | A registry entry $registry_path$ with registry keyname $registry_key_name$ related to Remcos RAT in host $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/software/S0332/](https://attack.mitre.org/software/S0332/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos_registry/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos_registry/sysmon.log) -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos_panel_client/remcos_registry_entry.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos_panel_client/remcos_registry_entry.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/remcos_client_registry_install_entry.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-01-26-start_up_during_safe_mode_boot.md b/docs/_posts/2022-01-26-start_up_during_safe_mode_boot.md deleted file mode 100644 index da8d3e6238..0000000000 --- a/docs/_posts/2022-01-26-start_up_during_safe_mode_boot.md +++ /dev/null @@ -1,163 +0,0 @@ ---- -title: "Start Up During Safe Mode Boot" -excerpt: "Registry Run Keys / Startup Folder -, Boot or Logon Autostart Execution -" -categories: - - Endpoint -last_modified_at: 2022-01-26 -toc: true -toc_label: "" -tags: - - Registry Run Keys / Startup Folder - - Boot or Logon Autostart Execution - - Persistence - - Privilege Escalation - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect a modification or registry add to the safeboot registry as an autostart mechanism. This technique was seen in some ransomware to automatically execute its code upon a safe mode boot. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-01-26 -- **Author**: Teoderick Contreras, Splunk -- **ID**: c6149154-c9d8-11eb-9da7-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1547.001](https://attack.mitre.org/techniques/T1547/001/) | Registry Run Keys / Startup Folder | Persistence, Privilege Escalation | - -| [T1547](https://attack.mitre.org/techniques/T1547/) | Boot or Logon Autostart Execution | Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry where Registry.registry_path="*\\System\\CurrentControlSet\\Control\\SafeBoot\\Minimal\*" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid -| `drop_dm_object_name(Registry)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] -| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data -| `start_up_during_safe_mode_boot_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -Note that **start_up_during_safe_mode_boot_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.registry_path -* Registry.registry_key_name -* Registry.registry_value_name -* Registry.dest - - -#### How To Implement -To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. - -#### Known False Positives -updated windows application needed in safe boot may used this registry - -#### Associated Analytic story -* [Ransomware](/stories/ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 42.0 | 60 | 70 | Safeboot registry $registry_path$ was added or modified with a new value $registry_value_name$ on $dest$ | - - -#### Reference - -* [https://malware.news/t/threat-analysis-unit-tau-threat-intelligence-notification-snatch-ransomware/36365](https://malware.news/t/threat-analysis-unit-tau-threat-intelligence-notification-snatch-ransomware/36365) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/data1/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/data1/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/start_up_during_safe_mode_boot.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-01-26-time_provider_persistence_registry.md b/docs/_posts/2022-01-26-time_provider_persistence_registry.md deleted file mode 100644 index 0fc3d43f90..0000000000 --- a/docs/_posts/2022-01-26-time_provider_persistence_registry.md +++ /dev/null @@ -1,172 +0,0 @@ ---- -title: "Time Provider Persistence Registry" -excerpt: "Time Providers -, Boot or Logon Autostart Execution -" -categories: - - Endpoint -last_modified_at: 2022-01-26 -toc: true -toc_label: "" -tags: - - Time Providers - - Boot or Logon Autostart Execution - - Persistence - - Privilege Escalation - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to detect a suspicious modification of time provider registry for persistence and autostart. This technique can allow the attacker to persist on the compromised host and autostart as soon as the machine boot up. This TTP can be a good indicator of suspicious behavior since this registry is not commonly modified by normal user or even an admin. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-01-26 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 5ba382c4-2105-11ec-8d8f-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1547.003](https://attack.mitre.org/techniques/T1547/003/) | Time Providers | Persistence, Privilege Escalation | - -| [T1547](https://attack.mitre.org/techniques/T1547/) | Boot or Logon Autostart Execution | Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path ="*\\CurrentControlSet\\Services\\W32Time\\TimeProviders*" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid -| `drop_dm_object_name(Registry)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] -| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data -| `time_provider_persistence_registry_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **time_provider_persistence_registry_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.dest -* Registry.user -* Registry.registry_path -* Registry.registry_key_name -* Registry.registry_value_name - - -#### How To Implement -To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Windows Persistence Techniques](/stories/windows_persistence_techniques) -* [Windows Privilege Escalation](/stories/windows_privilege_escalation) -* [Windows Registry Abuse](/stories/windows_registry_abuse) -* [Hermetic Wiper](/stories/hermetic_wiper) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | modified/added/deleted registry entry $Registry.registry_path$ in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://pentestlab.blog/2019/10/22/persistence-time-providers/](https://pentestlab.blog/2019/10/22/persistence-time-providers/) -* [https://attack.mitre.org/techniques/T1547/003/](https://attack.mitre.org/techniques/T1547/003/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.003/timeprovider_reg/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.003/timeprovider_reg/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/time_provider_persistence_registry.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-01-27-disable_etw_through_registry.md b/docs/_posts/2022-01-27-disable_etw_through_registry.md deleted file mode 100644 index 33ea75c57f..0000000000 --- a/docs/_posts/2022-01-27-disable_etw_through_registry.md +++ /dev/null @@ -1,167 +0,0 @@ ---- -title: "Disable ETW Through Registry" -excerpt: "Disable or Modify Tools -, Impair Defenses -" -categories: - - Endpoint -last_modified_at: 2022-01-27 -toc: true -toc_label: "" -tags: - - Disable or Modify Tools - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -this search is to identify modification in registry to disable ETW windows feature to evade detections. This technique was seen in several ransomware, RAT and even APT to impaire defenses of the compromise machine and to be able to execute payload with minimal alert as much as possible. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-01-27 -- **Author**: Teoderick Contreras, Splunk -- **ID**: f0eacfa4-d33f-11eb-8f9d-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\.NETFramework\\ETWEnabled" Registry.registry_value_data = "0x00000000" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid -| `drop_dm_object_name(Registry)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] -| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data -| `disable_etw_through_registry_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **disable_etw_through_registry_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.registry_key_name -* Registry.registry_path -* Registry.user -* Registry.dest -* Registry.registry_value_name - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. - -#### Known False Positives -network operator may disable this feature of windows but not so common. - -#### Associated Analytic story -* [Ransomware](/stories/ransomware) -* [Windows Registry Abuse](/stories/windows_registry_abuse) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | Disable ETW Through Registry | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://app.any.run/tasks/c0f98850-af65-4352-9746-fbebadee4f05/](https://app.any.run/tasks/c0f98850-af65-4352-9746-fbebadee4f05/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/data2/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/data2/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disable_etw_through_registry.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-01-27-disable_registry_tool.md b/docs/_posts/2022-01-27-disable_registry_tool.md deleted file mode 100644 index 10fdb2c92c..0000000000 --- a/docs/_posts/2022-01-27-disable_registry_tool.md +++ /dev/null @@ -1,169 +0,0 @@ ---- -title: "Disable Registry Tool" -excerpt: "Disable or Modify Tools -, Impair Defenses -" -categories: - - Endpoint -last_modified_at: 2022-01-27 -toc: true -toc_label: "" -tags: - - Disable or Modify Tools - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search identifies modification of registry to disable the regedit or registry tools of the windows operating system. Since registry tool is a swiss knife in analyzing registry, malware such as RAT or trojan Spy disable this application to prevent the removal of their registry entry such as persistence, file less components and defense evasion. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-01-27 -- **Author**: Teoderick Contreras, Splunk -- **ID**: cd2cf33c-9201-11eb-a10a-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\DisableRegistryTools" Registry.registry_value_data = "0x00000001" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid -| `drop_dm_object_name(Registry)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] -| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data -| `disable_registry_tool_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **disable_registry_tool_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.registry_key_name -* Registry.registry_path -* Registry.user -* Registry.dest -* Registry.registry_value_name - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. - -#### Known False Positives -admin may disable this application for non technical user. - -#### Associated Analytic story -* [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics) -* [Windows Registry Abuse](/stories/windows_registry_abuse) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 40.0 | 40 | 100 | Disabled Registry Tools on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://any.run/report/ea4ea08407d4ee72e009103a3b77e5a09412b722fdef67315ea63f22011152af/a866d7b1-c236-4f26-a391-5ae32213dfc4#registry](https://any.run/report/ea4ea08407d4ee72e009103a3b77e5a09412b722fdef67315ea63f22011152af/a866d7b1-c236-4f26-a391-5ae32213dfc4#registry) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-security.log) -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-system.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-system.log) -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disable_registry_tool.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-01-27-disable_security_logs_using_minint_registry.md b/docs/_posts/2022-01-27-disable_security_logs_using_minint_registry.md deleted file mode 100644 index df5824fc68..0000000000 --- a/docs/_posts/2022-01-27-disable_security_logs_using_minint_registry.md +++ /dev/null @@ -1,163 +0,0 @@ ---- -title: "Disable Security Logs Using MiniNt Registry" -excerpt: "Modify Registry -" -categories: - - Endpoint -last_modified_at: 2022-01-27 -toc: true -toc_label: "" -tags: - - Modify Registry - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to detect a suspicious registry modification to disable security audit logs. This technique was shared by a researcher to disable Security logs of windows by adding this registry. The Windows will think it is WinPE and will not log any event to the Security Log - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-01-27 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 39ebdc68-25b9-11ec-aec7-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1112](https://attack.mitre.org/techniques/T1112/) | Modify Registry | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry where Registry.registry_path="*\\Control\\MiniNt\\*" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid -| `drop_dm_object_name(Registry)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] -| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data -| `disable_security_logs_using_minint_registry_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **disable_security_logs_using_minint_registry_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.dest -* Registry.user -* Registry.registry_value_name -* Registry.registry_key_name -* Registry.registry_path -* Registry.registry_value_data - - -#### How To Implement -To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. - -#### Known False Positives -Unknown. - -#### Associated Analytic story -* [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics) -* [Windows Registry Abuse](/stories/windows_registry_abuse) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | modified/added/deleted registry entry $Registry.registry_path$ in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://twitter.com/0gtweet/status/1182516740955226112](https://twitter.com/0gtweet/status/1182516740955226112) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1112/minint_reg/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1112/minint_reg/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disable_security_logs_using_minint_registry.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-01-27-disable_show_hidden_files.md b/docs/_posts/2022-01-27-disable_show_hidden_files.md deleted file mode 100644 index cdd4147341..0000000000 --- a/docs/_posts/2022-01-27-disable_show_hidden_files.md +++ /dev/null @@ -1,180 +0,0 @@ ---- -title: "Disable Show Hidden Files" -excerpt: "Hidden Files and Directories -, Disable or Modify Tools -, Hide Artifacts -, Impair Defenses -" -categories: - - Endpoint -last_modified_at: 2022-01-27 -toc: true -toc_label: "" -tags: - - Hidden Files and Directories - - Disable or Modify Tools - - Hide Artifacts - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic is to identify a modification in the Windows registry to prevent users from seeing all the files with hidden attributes. This event or techniques are known on some worm and trojan spy malware that will drop hidden files on the infected machine. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-01-27 -- **Author**: Teoderick Contreras, Mauricio Velazco, Splunk -- **ID**: 6f3ccfa2-91fe-11eb-8f9b-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1564.001](https://attack.mitre.org/techniques/T1564/001/) | Hidden Files and Directories | Defense Evasion | - -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - -| [T1564](https://attack.mitre.org/techniques/T1564/) | Hide Artifacts | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where (Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Hidden" OR Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\HideFileExt" Registry.registry_value_data = "0x00000001") OR (Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowSuperHidden" Registry.registry_value_data = "0x00000000") by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid -| `drop_dm_object_name(Registry)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] -| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data -| `disable_show_hidden_files_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **disable_show_hidden_files_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.registry_key_name -* Registry.registry_path -* Registry.user -* Registry.dest -* Registry.registry_value_nam - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics) -* [Windows Registry Abuse](/stories/windows_registry_abuse) -* [Azorult](/stories/azorult) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 40.0 | 40 | 100 | Disabled 'Show Hidden Files' on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.sophos.com/en-us/threat-center/threat-analyses/viruses-and-spyware/W32~Tiotua-P/detailed-analysis](https://www.sophos.com/en-us/threat-center/threat-analyses/viruses-and-spyware/W32~Tiotua-P/detailed-analysis) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-security.log) -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-system.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-system.log) -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disable_show_hidden_files.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-01-27-disable_uac_remote_restriction.md b/docs/_posts/2022-01-27-disable_uac_remote_restriction.md deleted file mode 100644 index c6860f04ad..0000000000 --- a/docs/_posts/2022-01-27-disable_uac_remote_restriction.md +++ /dev/null @@ -1,171 +0,0 @@ ---- -title: "Disable UAC Remote Restriction" -excerpt: "Bypass User Account Control -, Abuse Elevation Control Mechanism -" -categories: - - Endpoint -last_modified_at: 2022-01-27 -toc: true -toc_label: "" -tags: - - Bypass User Account Control - - Abuse Elevation Control Mechanism - - Defense Evasion - - Privilege Escalation - - Defense Evasion - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to detect a suspicious modification of registry to disable UAC remote restriction. This technique was well documented in Microsoft page where attacker may modify this registry value to bypassed UAC feature of windows host. This is a good indicator that some tries to bypassed UAC to suspicious process or gain privilege escalation. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-01-27 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 9928b732-210e-11ec-b65e-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1548.002](https://attack.mitre.org/techniques/T1548/002/) | Bypass User Account Control | Defense Evasion, Privilege Escalation | - -| [T1548](https://attack.mitre.org/techniques/T1548/) | Abuse Elevation Control Mechanism | Defense Evasion, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*\\CurrentVersion\\Policies\\System*" Registry.registry_value_name="LocalAccountTokenFilterPolicy" Registry.registry_value_data="0x00000001" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid -| `drop_dm_object_name(Registry)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] -| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data -| `disable_uac_remote_restriction_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **disable_uac_remote_restriction_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.dest -* Registry.user -* Registry.registry_path -* Registry.registry_key_name -* Registry.registry_value_name -* Registry.registry_value_data - - -#### How To Implement -To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. - -#### Known False Positives -admin may set this policy for non-critical machine. - -#### Associated Analytic story -* [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics) -* [Suspicious Windows Registry Activities](/stories/suspicious_windows_registry_activities) -* [Windows Registry Abuse](/stories/windows_registry_abuse) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | modified/added/deleted registry entry $Registry.registry_path$ in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://docs.microsoft.com/en-us/troubleshoot/windows-server/windows-security/user-account-control-and-remote-restriction](https://docs.microsoft.com/en-us/troubleshoot/windows-server/windows-security/user-account-control-and-remote-restriction) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.002/LocalAccountTokenFilterPolicy/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.002/LocalAccountTokenFilterPolicy/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disable_uac_remote_restriction.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-01-27-disable_windows_app_hotkeys.md b/docs/_posts/2022-01-27-disable_windows_app_hotkeys.md deleted file mode 100644 index 765d1665a4..0000000000 --- a/docs/_posts/2022-01-27-disable_windows_app_hotkeys.md +++ /dev/null @@ -1,166 +0,0 @@ ---- -title: "Disable Windows App Hotkeys" -excerpt: "Disable or Modify Tools -, Impair Defenses -" -categories: - - Endpoint -last_modified_at: 2022-01-27 -toc: true -toc_label: "" -tags: - - Disable or Modify Tools - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic detects a suspicious registry modification to disable Windows hotkey (shortcut keys) for native Windows applications. This technique is commonly used to disable certain or several Windows applications like `taskmgr.exe` and `cmd.exe`. This technique is used to impair the analyst in analyzing and removing the attacker implant in compromised systems. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-01-27 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 1490f224-ad8b-11eb-8c4f-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry where Registry.registry_path="*\\Windows NT\\CurrentVersion\\Image File Execution Options\\*" AND Registry.registry_value_data= "HotKey Disabled" AND Registry.registry_value_name = "Debugger" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_key_name Registry.process_guid Registry.registry_value_data -| `drop_dm_object_name(Registry)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] -| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name -| `disable_windows_app_hotkeys_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **disable_windows_app_hotkeys_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.registry_key_name -* Registry.registry_path -* Registry.registry_value_name -* Registry.dest Registry.user - - -#### How To Implement -To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as CarbonBlack or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [XMRig](/stories/xmrig) -* [Windows Registry Abuse](/stories/windows_registry_abuse) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 40.0 | 40 | 100 | Disabled 'Windows App Hotkeys' on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/](https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/hotkey_disabled_hidden_user/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/hotkey_disabled_hidden_user/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disable_windows_app_hotkeys.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-01-27-disable_windows_behavior_monitoring.md b/docs/_posts/2022-01-27-disable_windows_behavior_monitoring.md deleted file mode 100644 index 607d2f65a0..0000000000 --- a/docs/_posts/2022-01-27-disable_windows_behavior_monitoring.md +++ /dev/null @@ -1,172 +0,0 @@ ---- -title: "Disable Windows Behavior Monitoring" -excerpt: "Disable or Modify Tools -, Impair Defenses -" -categories: - - Endpoint -last_modified_at: 2022-01-27 -toc: true -toc_label: "" -tags: - - Disable or Modify Tools - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to identifies a modification in registry to disable the windows denfender real time behavior monitoring. This event or technique is commonly seen in RAT, bot, or Trojan to disable AV to evade detections. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-01-27 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 79439cae-9200-11eb-a4d3-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableBehaviorMonitoring" OR Registry.registry_path= "*\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableOnAccessProtection" OR Registry.registry_path= "*\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableScanOnRealtimeEnable" OR Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableRealtimeMonitoring" OR Registry.registry_path= "*\\Real-Time Protection\\DisableIntrusionPreventionSystem" OR Registry.registry_path= "*\\Real-Time Protection\\DisableIOAVProtection" OR Registry.registry_path= "*\\Real-Time Protection\\DisableScriptScanning" AND Registry.registry_value_data = "0x00000001" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid -| `drop_dm_object_name(Registry)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] -| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data -| `disable_windows_behavior_monitoring_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **disable_windows_behavior_monitoring_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.registry_key_name -* Registry.registry_path -* Registry.user -* Registry.dest -* Registry.registry_value_name - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. - -#### Known False Positives -admin or user may choose to disable this windows features. - -#### Associated Analytic story -* [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics) -* [Ransomware](/stories/ransomware) -* [Revil Ransomware](/stories/revil_ransomware) -* [Windows Registry Abuse](/stories/windows_registry_abuse) -* [Azorult](/stories/azorult) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 40.0 | 40 | 100 | Windows Defender real time behavior monitoring disabled on $dest | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://tccontre.blogspot.com/2020/01/remcos-rat-evading-windows-defender-av.html](https://tccontre.blogspot.com/2020/01/remcos-rat-evading-windows-defender-av.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-security.log) -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-system.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-system.log) -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disable_windows_behavior_monitoring.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-01-27-disable_windows_smartscreen_protection.md b/docs/_posts/2022-01-27-disable_windows_smartscreen_protection.md deleted file mode 100644 index 89b192342e..0000000000 --- a/docs/_posts/2022-01-27-disable_windows_smartscreen_protection.md +++ /dev/null @@ -1,169 +0,0 @@ ---- -title: "Disable Windows SmartScreen Protection" -excerpt: "Disable or Modify Tools -, Impair Defenses -" -categories: - - Endpoint -last_modified_at: 2022-01-27 -toc: true -toc_label: "" -tags: - - Disable or Modify Tools - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following search identifies a modification of registry to disable the smartscreen protection of windows machine. This is windows feature provide an early warning system against website that might engage in phishing attack or malware distribution. This modification are seen in RAT malware to cover their tracks upon downloading other of its component or other payload. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-01-27 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 664f0fd0-91ff-11eb-a56f-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path= "*HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\SmartScreenEnabled" Registry.registry_value_data= "Off" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid -| `drop_dm_object_name(Registry)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] -| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data -| `disable_windows_smartscreen_protection_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **disable_windows_smartscreen_protection_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.registry_key_name -* Registry.registry_path -* Registry.user -* Registry.dest -* Registry.registry_value_nam - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. - -#### Known False Positives -admin or user may choose to disable this windows features. - -#### Associated Analytic story -* [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics) -* [Windows Registry Abuse](/stories/windows_registry_abuse) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | The Windows Smartscreen was disabled on $dest$ by $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://tccontre.blogspot.com/2020/01/remcos-rat-evading-windows-defender-av.html](https://tccontre.blogspot.com/2020/01/remcos-rat-evading-windows-defender-av.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-security.log) -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-system.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-system.log) -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disable_windows_smartscreen_protection.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-01-27-disabling_cmd_application.md b/docs/_posts/2022-01-27-disabling_cmd_application.md deleted file mode 100644 index 0b91cd2c7f..0000000000 --- a/docs/_posts/2022-01-27-disabling_cmd_application.md +++ /dev/null @@ -1,169 +0,0 @@ ---- -title: "Disabling CMD Application" -excerpt: "Disable or Modify Tools -, Impair Defenses -" -categories: - - Endpoint -last_modified_at: 2022-01-27 -toc: true -toc_label: "" -tags: - - Disable or Modify Tools - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -this search is to identify modification in registry to disable cmd prompt application. This technique is commonly seen in RAT, Trojan or WORM to prevent triaging or deleting there samples through cmd application which is one of the tool of analyst to traverse on directory and files. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-01-27 -- **Author**: Teoderick Contreras, Splunk -- **ID**: ff86077c-9212-11eb-a1e6-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Policies\\Microsoft\\Windows\\System\\DisableCMD" Registry.registry_value_data = "0x00000001" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_key_name Registry.process_guid Registry.registry_value_data -| `drop_dm_object_name(Registry)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] -| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name -| `disabling_cmd_application_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **disabling_cmd_application_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.registry_key_name -* Registry.registry_path -* Registry.user -* Registry.dest -* Registry.registry_value_name - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. - -#### Known False Positives -admin may disable this application for non technical user. - -#### Associated Analytic story -* [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics) -* [Windows Registry Abuse](/stories/windows_registry_abuse) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | The Windows command prompt was disabled on $dest$ by $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://any.run/report/ea4ea08407d4ee72e009103a3b77e5a09412b722fdef67315ea63f22011152af/a866d7b1-c236-4f26-a391-5ae32213dfc4#registry](https://any.run/report/ea4ea08407d4ee72e009103a3b77e5a09412b722fdef67315ea63f22011152af/a866d7b1-c236-4f26-a391-5ae32213dfc4#registry) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-security.log) -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-system.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-system.log) -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disabling_cmd_application.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-01-27-disabling_controlpanel.md b/docs/_posts/2022-01-27-disabling_controlpanel.md deleted file mode 100644 index b22b05aff6..0000000000 --- a/docs/_posts/2022-01-27-disabling_controlpanel.md +++ /dev/null @@ -1,169 +0,0 @@ ---- -title: "Disabling ControlPanel" -excerpt: "Disable or Modify Tools -, Impair Defenses -" -categories: - - Endpoint -last_modified_at: 2022-01-27 -toc: true -toc_label: "" -tags: - - Disable or Modify Tools - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -this search is to identify registry modification to disable control panel window. This technique is commonly seen in malware to prevent their artifacts , persistence removed on the infected machine. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-01-27 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 6ae0148e-9215-11eb-a94a-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoControlPanel" Registry.registry_value_data = "0x00000001" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_key_name Registry.process_guid Registry.registry_value_data -| `drop_dm_object_name(Registry)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] -| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name -| `disabling_controlpanel_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **disabling_controlpanel_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.registry_key_name -* Registry.registry_path -* Registry.user -* Registry.dest -* Registry.registry_value_name - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. - -#### Known False Positives -admin may disable this application for non technical user. - -#### Associated Analytic story -* [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics) -* [Windows Registry Abuse](/stories/windows_registry_abuse) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | The Windows Control Panel was disabled on $dest$ by $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://any.run/report/ea4ea08407d4ee72e009103a3b77e5a09412b722fdef67315ea63f22011152af/a866d7b1-c236-4f26-a391-5ae32213dfc4#registry](https://any.run/report/ea4ea08407d4ee72e009103a3b77e5a09412b722fdef67315ea63f22011152af/a866d7b1-c236-4f26-a391-5ae32213dfc4#registry) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-security.log) -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-system.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-system.log) -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disabling_controlpanel.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-01-27-windows_possible_credential_dumping.md b/docs/_posts/2022-01-27-windows_possible_credential_dumping.md deleted file mode 100644 index e89c702ca3..0000000000 --- a/docs/_posts/2022-01-27-windows_possible_credential_dumping.md +++ /dev/null @@ -1,176 +0,0 @@ ---- -title: "Windows Possible Credential Dumping" -excerpt: "LSASS Memory -, OS Credential Dumping -" -categories: - - Endpoint -last_modified_at: 2022-01-27 -toc: true -toc_label: "" -tags: - - LSASS Memory - - OS Credential Dumping - - Credential Access - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic is an enhanced version of two previous analytics that identifies common GrantedAccess permission requests and CallTrace DLLs in order to detect credential dumping. \ -GrantedAccess is the requested permissions by the SourceImage into the TargetImage. \ -CallTrace Stack trace of where open process is called. Included is the DLL and the relative virtual address of the functions in the call stack right before the open process call. \ -dbgcore.dll or dbghelp.dll are two core Windows debug DLLs that have minidump functions which provide a way for applications to produce crashdump files that contain a useful subset of the entire process context. \ -The idea behind using ntdll.dll is to blend in by using native api of ntdll.dll. For example in sekurlsa module there are many ntdll exported api, like RtlCopyMemory, used to execute this module which is related to lsass dumping. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-01-27 -- **Author**: Michael Haag, Splunk -- **ID**: e4723b92-7266-11ec-af45-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1003.001](https://attack.mitre.org/techniques/T1003/001/) | LSASS Memory | Credential Access | - -| [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.AE -* DE.CM - - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventCode=10 TargetImage=*lsass.exe GrantedAccess IN ("0x01000", "0x1010", "0x1038", "0x40", "0x1400", "0x1fffff", "0x1410", "0x143a", "0x1438", "0x1000") CallTrace IN ("*dbgcore.dll*", "*dbghelp.dll*", "*ntdll.dll*") -| stats count min(_time) as firstTime max(_time) as lastTime by Computer, TargetImage, GrantedAccess, SourceImage, SourceProcessId, SourceUser, TargetUser -| rename Computer as dest -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_possible_credential_dumping_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **windows_possible_credential_dumping_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Computer -* TargetImage -* GrantedAccess -* SourceImage -* SourceProcessId -* SourceUser -* TargetUser - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Enabling EventCode 10 TargetProcess lsass.exe is required. - -#### Known False Positives -False positives will occur based on GrantedAccess 0x1010 and 0x1400, filter based on source image as needed or remove them. Concern is Cobalt Strike usage of Mimikatz will generate 0x1010 initially, but later be caught. - -#### Associated Analytic story -* [Credential Dumping](/stories/credential_dumping) -* [Detect Zerologon Attack](/stories/detect_zerologon_attack) -* [DarkSide Ransomware](/stories/darkside_ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 64.0 | 80 | 80 | A process, $SourceImage$, has loaded $ImageLoaded$ that are typically related to credential dumping on $dest$. Review for further details. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://en.wikipedia.org/wiki/Local_Security_Authority_Subsystem_Service](https://en.wikipedia.org/wiki/Local_Security_Authority_Subsystem_Service) -* [https://docs.microsoft.com/en-us/windows/win32/api/minidumpapiset/nf-minidumpapiset-minidumpwritedump](https://docs.microsoft.com/en-us/windows/win32/api/minidumpapiset/nf-minidumpapiset-minidumpwritedump) -* [https://cyberwardog.blogspot.com/2017/03/chronicles-of-threat-hunter-hunting-for_22.html](https://cyberwardog.blogspot.com/2017/03/chronicles-of-threat-hunter-hunting-for_22.html) -* [https://raw.githubusercontent.com/PowerShellMafia/PowerSploit/master/Exfiltration/Invoke-Mimikatz.ps1](https://raw.githubusercontent.com/PowerShellMafia/PowerSploit/master/Exfiltration/Invoke-Mimikatz.ps1) -* [https://docs.microsoft.com/en-us/windows/win32/procthread/process-security-and-access-rights?redirectedfrom=MSDN](https://docs.microsoft.com/en-us/windows/win32/procthread/process-security-and-access-rights?redirectedfrom=MSDN) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.001/atomic_red_team/windows-sysmon_creddump.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.001/atomic_red_team/windows-sysmon_creddump.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_possible_credential_dumping.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-01-28-disabling_defender_services.md b/docs/_posts/2022-01-28-disabling_defender_services.md deleted file mode 100644 index 34d3839dcb..0000000000 --- a/docs/_posts/2022-01-28-disabling_defender_services.md +++ /dev/null @@ -1,168 +0,0 @@ ---- -title: "Disabling Defender Services" -excerpt: "Disable or Modify Tools -, Impair Defenses -" -categories: - - Endpoint -last_modified_at: 2022-01-28 -toc: true -toc_label: "" -tags: - - Disable or Modify Tools - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This particular behavior is typically executed when an adversaries or malware gains access to an endpoint and beings to perform execution and to evade detections. Usually, a batch (.bat) will be executed and multiple registry and scheduled task modifications will occur. During triage, review parallel processes and identify any further file modifications. Endpoint should be isolated. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-01-28 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 911eacdc-317f-11ec-ad30-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path = "*\\System\\CurrentControlSet\\Services\\*" AND (Registry.registry_path IN("*WdBoot*", "*WdFilter*", "*WdNisDrv*", "*WdNisSvc*","*WinDefend*", "*SecurityHealthService*")) AND Registry.registry_value_name = Start Registry.registry_value_data = 0x00000004 by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid -| `drop_dm_object_name(Registry)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] -| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data -| `disabling_defender_services_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **disabling_defender_services_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.dest -* Registry.user -* Registry.registry_value_name -* Registry.registry_key_name -* Registry.registry_path -* Registry.registry_value_data - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -admin or user may choose to disable windows defender product - -#### Associated Analytic story -* [IceID](/stories/iceid) -* [Windows Registry Abuse](/stories/windows_registry_abuse) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | modified/added/deleted registry entry $registry_path$ in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/](https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/disable_av/sysmon2.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/disable_av/sysmon2.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disabling_defender_services.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-01-28-disabling_folderoptions_windows_feature.md b/docs/_posts/2022-01-28-disabling_folderoptions_windows_feature.md deleted file mode 100644 index a251d8ef82..0000000000 --- a/docs/_posts/2022-01-28-disabling_folderoptions_windows_feature.md +++ /dev/null @@ -1,169 +0,0 @@ ---- -title: "Disabling FolderOptions Windows Feature" -excerpt: "Disable or Modify Tools -, Impair Defenses -" -categories: - - Endpoint -last_modified_at: 2022-01-28 -toc: true -toc_label: "" -tags: - - Disable or Modify Tools - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to identify registry modification to disable folder options feature of windows to show hidden files, file extension and etc. This technique used by malware in combination if disabling show hidden files feature to hide their files and also to hide the file extension to lure the user base on file icons or fake file extensions. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-01-28 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 83776de4-921a-11eb-868a-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoFolderOptions" Registry.registry_value_data = "0x00000001" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_key_name Registry.process_guid Registry.registry_value_data -| `drop_dm_object_name(Registry)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] -| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name -| `disabling_folderoptions_windows_feature_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **disabling_folderoptions_windows_feature_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.registry_key_name -* Registry.registry_path -* Registry.user -* Registry.dest -* Registry.registry_value_name - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. - -#### Known False Positives -admin may disable this application for non technical user. - -#### Associated Analytic story -* [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics) -* [Windows Registry Abuse](/stories/windows_registry_abuse) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | The Windows Folder Options, to hide files, was disabled on $dest$ by $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://any.run/report/ea4ea08407d4ee72e009103a3b77e5a09412b722fdef67315ea63f22011152af/a866d7b1-c236-4f26-a391-5ae32213dfc4#registry](https://any.run/report/ea4ea08407d4ee72e009103a3b77e5a09412b722fdef67315ea63f22011152af/a866d7b1-c236-4f26-a391-5ae32213dfc4#registry) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-security.log) -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-system.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-system.log) -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-01-28-disabling_norun_windows_app.md b/docs/_posts/2022-01-28-disabling_norun_windows_app.md deleted file mode 100644 index cdeac497d7..0000000000 --- a/docs/_posts/2022-01-28-disabling_norun_windows_app.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: "Disabling NoRun Windows App" -excerpt: "Disable or Modify Tools -, Impair Defenses -" -categories: - - Endpoint -last_modified_at: 2022-01-28 -toc: true -toc_label: "" -tags: - - Disable or Modify Tools - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to identify modification of registry to disable run application in window start menu. this application is known to be a helpful shortcut to windows OS user to run known application and also to execute some reg or batch script. This technique is used malware to make cleaning of its infection more harder by preventing known application run easily through run shortcut. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-01-28 -- **Author**: Teoderick Contreras, Splunk -- **ID**: de81bc46-9213-11eb-adc9-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoRun" Registry.registry_value_data = "0x00000001" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_key_name Registry.process_guid Registry.registry_value_data -| `drop_dm_object_name(Registry)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] -| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name -| `disabling_norun_windows_app_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **disabling_norun_windows_app_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.registry_key_name -* Registry.registry_path -* Registry.user -* Registry.dest -* Registry.registry_value_name - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. - -#### Known False Positives -admin may disable this application for non technical user. - -#### Associated Analytic story -* [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics) -* [Windows Registry Abuse](/stories/windows_registry_abuse) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | The Windows registry was modified to disable run application in window start menu on $dest$ by $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://any.run/report/ea4ea08407d4ee72e009103a3b77e5a09412b722fdef67315ea63f22011152af/a866d7b1-c236-4f26-a391-5ae32213dfc4#registry](https://any.run/report/ea4ea08407d4ee72e009103a3b77e5a09412b722fdef67315ea63f22011152af/a866d7b1-c236-4f26-a391-5ae32213dfc4#registry) -* [https://blog.malwarebytes.com/detections/pum-optional-norun/](https://blog.malwarebytes.com/detections/pum-optional-norun/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-security.log) -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-system.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-system.log) -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disabling_norun_windows_app.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-01-28-disabling_systemrestore_in_registry.md b/docs/_posts/2022-01-28-disabling_systemrestore_in_registry.md deleted file mode 100644 index b3678b70de..0000000000 --- a/docs/_posts/2022-01-28-disabling_systemrestore_in_registry.md +++ /dev/null @@ -1,164 +0,0 @@ ---- -title: "Disabling SystemRestore In Registry" -excerpt: "Inhibit System Recovery -" -categories: - - Endpoint -last_modified_at: 2022-01-28 -toc: true -toc_label: "" -tags: - - Inhibit System Recovery - - Impact - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following search identifies the modification of registry related in disabling the system restore of a machine. This event or behavior are seen in some RAT malware to make the restore of the infected machine difficult and keep their infection on the box. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-01-28 -- **Author**: Teoderick Contreras, Splunk -- **ID**: f4f837e2-91fb-11eb-8bf6-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1490](https://attack.mitre.org/techniques/T1490/) | Inhibit System Recovery | Impact | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\SystemRestore\\DisableSR" OR Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\SystemRestore\\DisableConfig" OR Registry.registry_path= "*\\SOFTWARE\\Policies\\Microsoft\\Windows NT\\SystemRestore\\DisableSR" OR Registry.registry_path= "*\\SOFTWARE\\Policies\\Microsoft\\Windows NT\\SystemRestore\\DisableConfig" Registry.registry_value_data = "0x00000001" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_key_name Registry.process_guid Registry.registry_value_data -| `drop_dm_object_name(Registry)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] -| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name -| `disabling_systemrestore_in_registry_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **disabling_systemrestore_in_registry_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.registry_key_name -* Registry.registry_path -* Registry.user -* Registry.dest -* Registry.registry_value_name - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. - -#### Known False Positives -in some cases admin can disable systemrestore on a machine. - -#### Associated Analytic story -* [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics) -* [Windows Registry Abuse](/stories/windows_registry_abuse) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | The Windows registry was modified to disable system restore on $dest$ by $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://tccontre.blogspot.com/2020/01/remcos-rat-evading-windows-defender-av.html](https://tccontre.blogspot.com/2020/01/remcos-rat-evading-windows-defender-av.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-security.log) -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-system.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-system.log) -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disabling_systemrestore_in_registry.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-01-28-disabling_task_manager.md b/docs/_posts/2022-01-28-disabling_task_manager.md deleted file mode 100644 index 00d2da2921..0000000000 --- a/docs/_posts/2022-01-28-disabling_task_manager.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: "Disabling Task Manager" -excerpt: "Disable or Modify Tools -, Impair Defenses -" -categories: - - Endpoint -last_modified_at: 2022-01-28 -toc: true -toc_label: "" -tags: - - Disable or Modify Tools - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to identifies modification of registry to disable the task manager of windows operating system. this event or technique are commonly seen in malware such as RAT, Trojan, TrojanSpy or worm to prevent the user to terminate their process. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-01-28 -- **Author**: Teoderick Contreras, Splunk -- **ID**: dac279bc-9202-11eb-b7fb-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\DisableTaskMgr" Registry.registry_value_data = "0x00000001" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_key_name Registry.process_guid Registry.registry_value_data -| `drop_dm_object_name(Registry)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] -| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name -| `disabling_task_manager_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **disabling_task_manager_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.registry_key_name -* Registry.registry_path -* Registry.user -* Registry.dest -* Registry.registry_value_name - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. - -#### Known False Positives -admin may disable this application for non technical user. - -#### Associated Analytic story -* [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics) -* [Windows Registry Abuse](/stories/windows_registry_abuse) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 42.0 | 70 | 60 | The Windows Task Manager was disabled on $dest$ by $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://any.run/report/ea4ea08407d4ee72e009103a3b77e5a09412b722fdef67315ea63f22011152af/a866d7b1-c236-4f26-a391-5ae32213dfc4#registry](https://any.run/report/ea4ea08407d4ee72e009103a3b77e5a09412b722fdef67315ea63f22011152af/a866d7b1-c236-4f26-a391-5ae32213dfc4#registry) -* [https://blog.talosintelligence.com/2020/05/threat-roundup-0424-0501.html](https://blog.talosintelligence.com/2020/05/threat-roundup-0424-0501.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-security.log) -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-system.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-system.log) -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disabling_task_manager.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-01-28-enable_rdp_in_other_port_number.md b/docs/_posts/2022-01-28-enable_rdp_in_other_port_number.md deleted file mode 100644 index 40eda14163..0000000000 --- a/docs/_posts/2022-01-28-enable_rdp_in_other_port_number.md +++ /dev/null @@ -1,161 +0,0 @@ ---- -title: "Enable RDP In Other Port Number" -excerpt: "Remote Services -" -categories: - - Endpoint -last_modified_at: 2022-01-28 -toc: true -toc_label: "" -tags: - - Remote Services - - Lateral Movement - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect a modification to registry to enable rdp to a machine with different port number. This technique was seen in some atttacker tries to do lateral movement and remote access to a compromised machine to gain control of it. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-01-28 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 99495452-b899-11eb-96dc-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1021](https://attack.mitre.org/techniques/T1021/) | Remote Services | Lateral Movement | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*HKLM\\SYSTEM\\CurrentControlSet\\Control\\Terminal Server\\WinStations\\RDP-Tcp*" Registry.registry_value_name = "PortNumber" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.process_guid Registry.registry_key_name -| `drop_dm_object_name(Registry)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] -| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name -| `enable_rdp_in_other_port_number_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **enable_rdp_in_other_port_number_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.registry_path -* Registry.dest -* Registry.user -* Registry.registry_value_name - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Prohibited Traffic Allowed or Protocol Mismatch](/stories/prohibited_traffic_allowed_or_protocol_mismatch) -* [Windows Registry Abuse](/stories/windows_registry_abuse) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | RDP was moved to a non-standard port on $dest$ by $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.mvps.net/docs/how-to-secure-remote-desktop-rdp/](https://www.mvps.net/docs/how-to-secure-remote-desktop-rdp/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/casper/datasets1/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/casper/datasets1/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/enable_rdp_in_other_port_number.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-01-28-enable_wdigest_uselogoncredential_registry.md b/docs/_posts/2022-01-28-enable_wdigest_uselogoncredential_registry.md deleted file mode 100644 index 9b3469b0a9..0000000000 --- a/docs/_posts/2022-01-28-enable_wdigest_uselogoncredential_registry.md +++ /dev/null @@ -1,168 +0,0 @@ ---- -title: "Enable WDigest UseLogonCredential Registry" -excerpt: "Modify Registry -, OS Credential Dumping -" -categories: - - Endpoint -last_modified_at: 2022-01-28 -toc: true -toc_label: "" -tags: - - Modify Registry - - OS Credential Dumping - - Defense Evasion - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to detect a suspicious registry modification to enable plain text credential feature of windows. This technique was used by several malware and also by mimikatz to be able to dumpe the a plain text credential to the compromised or target host. This TTP is really a good indicator that someone wants to dump the crendential of the host so it must be a good pivot for credential dumping techniques. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-01-28 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 0c7d8ffe-25b1-11ec-9f39-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1112](https://attack.mitre.org/techniques/T1112/) | Modify Registry | Defense Evasion | - -| [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*\\System\\CurrentControlSet\\Control\\SecurityProviders\\WDigest\\*" Registry.registry_value_name = "UseLogonCredential" Registry.registry_value_data = 0x00000001 by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.process_guid Registry.registry_key_name Registry.registry_value_data -| `drop_dm_object_name(Registry)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] -| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name -| `enable_wdigest_uselogoncredential_registry_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **enable_wdigest_uselogoncredential_registry_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.dest -* Registry.user -* Registry.registry_value_name -* Registry.registry_key_name -* Registry.registry_path -* Registry.registry_value_data - - -#### How To Implement -To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Credential Dumping](/stories/credential_dumping) -* [Windows Registry Abuse](/stories/windows_registry_abuse) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | wdigest registry $registry_path$ was modified in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.csoonline.com/article/3438824/how-to-detect-and-halt-credential-theft-via-windows-wdigest.html](https://www.csoonline.com/article/3438824/how-to-detect-and-halt-credential-theft-via-windows-wdigest.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/wdigest_enable/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/wdigest_enable/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/enable_wdigest_uselogoncredential_registry.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-01-28-etw_registry_disabled.md b/docs/_posts/2022-01-28-etw_registry_disabled.md deleted file mode 100644 index c79587eef9..0000000000 --- a/docs/_posts/2022-01-28-etw_registry_disabled.md +++ /dev/null @@ -1,175 +0,0 @@ ---- -title: "ETW Registry Disabled" -excerpt: "Indicator Blocking -, Trusted Developer Utilities Proxy Execution -, Impair Defenses -" -categories: - - Endpoint -last_modified_at: 2022-01-28 -toc: true -toc_label: "" -tags: - - Indicator Blocking - - Trusted Developer Utilities Proxy Execution - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to detect a registry modification to disable ETW feature of windows. This technique is to evade EDR appliance to evade detections and hide its execution from audit logs. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-01-28 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 8ed523ac-276b-11ec-ac39-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.006](https://attack.mitre.org/techniques/T1562/006/) | Indicator Blocking | Defense Evasion | - -| [T1127](https://attack.mitre.org/techniques/T1127/) | Trusted Developer Utilities Proxy Execution | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*\\SOFTWARE\\Microsoft\\.NETFramework*" Registry.registry_value_name = ETWEnabled Registry.registry_value_data=0x00000000 by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.process_guid Registry.registry_key_name Registry.registry_value_data -| `drop_dm_object_name(Registry)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] -| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name -| `etw_registry_disabled_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **etw_registry_disabled_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.dest -* Registry.user -* Registry.registry_path -* Registry.registry_key_name -* Registry.registry_value_name -* Registry.registry_value_data - - -#### How To Implement -To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Windows Persistence Techniques](/stories/windows_persistence_techniques) -* [Windows Privilege Escalation](/stories/windows_privilege_escalation) -* [Windows Registry Abuse](/stories/windows_registry_abuse) -* [Hermetic Wiper](/stories/hermetic_wiper) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 90.0 | 90 | 100 | modified/added/deleted registry entry $Registry.registry_path$ in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://gist.github.com/Cyb3rWard0g/a4a115fd3ab518a0e593525a379adee3](https://gist.github.com/Cyb3rWard0g/a4a115fd3ab518a0e593525a379adee3) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127/etw_disable/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127/etw_disable/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/etw_registry_disabled.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-01-28-eventvwr_uac_bypass.md b/docs/_posts/2022-01-28-eventvwr_uac_bypass.md deleted file mode 100644 index 22af880f87..0000000000 --- a/docs/_posts/2022-01-28-eventvwr_uac_bypass.md +++ /dev/null @@ -1,174 +0,0 @@ ---- -title: "Eventvwr UAC Bypass" -excerpt: "Bypass User Account Control -, Abuse Elevation Control Mechanism -" -categories: - - Endpoint -last_modified_at: 2022-01-28 -toc: true -toc_label: "" -tags: - - Bypass User Account Control - - Abuse Elevation Control Mechanism - - Defense Evasion - - Privilege Escalation - - Defense Evasion - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following search identifies Eventvwr bypass by identifying the registry modification into a specific path that eventvwr.msc looks to (but is not valid) upon execution. A successful attack will include a suspicious command to be executed upon eventvwr.msc loading. Upon triage, review the parallel processes that have executed. Identify any additional registry modifications on the endpoint that may look suspicious. Remediate as necessary. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-01-28 -- **Author**: Michael Haag, Splunk -- **ID**: 9cf8fe08-7ad8-11eb-9819-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1548.002](https://attack.mitre.org/techniques/T1548/002/) | Bypass User Account Control | Defense Evasion, Privilege Escalation | - -| [T1548](https://attack.mitre.org/techniques/T1548/) | Abuse Elevation Control Mechanism | Defense Evasion, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count values(Registry.registry_key_name) as registry_key_name values(Registry.registry_path) as registry_path min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*mscfile\\shell\\open\\command\\*" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.process_guid Registry.registry_key_name Registry.registry_value_data -| `drop_dm_object_name(Registry)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] -| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name -| `eventvwr_uac_bypass_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **eventvwr_uac_bypass_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.registry_key_name -* Registry.registry_path -* Registry.user -* Registry.dest -* Registry.registry_value_name - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. - -#### Known False Positives -Some false positives may be present and will need to be filtered. - -#### Associated Analytic story -* [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics) -* [IcedID](/stories/icedid) -* [Living Off The Land](/stories/living_off_the_land) -* [Windows Registry Abuse](/stories/windows_registry_abuse) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | Registry values were modified to bypass UAC using Event Viewer on $dest$ by $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://blog.malwarebytes.com/malwarebytes-news/2021/02/lazyscripter-from-empire-to-double-rat/](https://blog.malwarebytes.com/malwarebytes-news/2021/02/lazyscripter-from-empire-to-double-rat/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1548.002/T1548.002.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1548.002/T1548.002.md) -* [https://attack.mitre.org/techniques/T1548/002/](https://attack.mitre.org/techniques/T1548/002/) -* [https://enigma0x3.net/2016/08/15/fileless-uac-bypass-using-eventvwr-exe-and-registry-hijacking/](https://enigma0x3.net/2016/08/15/fileless-uac-bypass-using-eventvwr-exe-and-registry-hijacking/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.002/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.002/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/eventvwr_uac_bypass.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-01-28-hide_user_account_from_sign-in_screen.md b/docs/_posts/2022-01-28-hide_user_account_from_sign-in_screen.md deleted file mode 100644 index e9e34612d3..0000000000 --- a/docs/_posts/2022-01-28-hide_user_account_from_sign-in_screen.md +++ /dev/null @@ -1,167 +0,0 @@ ---- -title: "Hide User Account From Sign-In Screen" -excerpt: "Disable or Modify Tools -, Impair Defenses -" -categories: - - Endpoint -last_modified_at: 2022-01-28 -toc: true -toc_label: "" -tags: - - Disable or Modify Tools - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic identifies a suspicious registry modification to hide a user account on the Windows Login screen. This technique was seen in some tradecraft where the adversary will create a hidden user account with Admin privileges in login screen to avoid noticing by the user that they already compromise and to persist on that said machine. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-01-28 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 834ba832-ad89-11eb-937d-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*\\Windows NT\\CurrentVersion\\Winlogon\\SpecialAccounts\\Userlist*" AND Registry.registry_value_data = "0x00000000" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.process_guid Registry.registry_key_name Registry.registry_value_data -| `drop_dm_object_name(Registry)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] -| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name -| `hide_user_account_from_sign_in_screen_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **hide_user_account_from_sign-in_screen_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.registry_key_name -* Registry.registry_path -* Registry.registry_value_name -* Registry.dest Registry.user - - -#### How To Implement -To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as CarbonBlack or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. - -#### Known False Positives -Unknown. Filter as needed. - -#### Associated Analytic story -* [XMRig](/stories/xmrig) -* [Windows Registry Abuse](/stories/windows_registry_abuse) -* [Azorult](/stories/azorult) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 72.0 | 90 | 80 | Suspicious registry modification ($registry_value_name$) which is used go hide a user account on the Windows Login screen detected on $dest$ executed by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/](https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/hotkey_disabled_hidden_user/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/hotkey_disabled_hidden_user/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-01-28-linux_pkexec_privilege_escalation.md b/docs/_posts/2022-01-28-linux_pkexec_privilege_escalation.md deleted file mode 100644 index 7a5b67753c..0000000000 --- a/docs/_posts/2022-01-28-linux_pkexec_privilege_escalation.md +++ /dev/null @@ -1,173 +0,0 @@ ---- -title: "Linux pkexec Privilege Escalation" -excerpt: "Exploitation for Privilege Escalation -" -categories: - - Endpoint -last_modified_at: 2022-01-28 -toc: true -toc_label: "" -tags: - - Exploitation for Privilege Escalation - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2021-4034 - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies `pkexec` spawning with no command-line arguments. A vulnerability in Polkit's pkexec component identified as CVE-2021-4034 (PwnKit) which is present in the default configuration of all major Linux distributions and can be exploited to gain full root privileges on the system. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-01-28 -- **Author**: Michael Haag, Splunk -- **ID**: 03e22c1c-8086-11ec-ac2e-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1068](https://attack.mitre.org/techniques/T1068/) | Exploitation for Privilege Escalation | Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2021-4034](https://nvd.nist.gov/vuln/detail/CVE-2021-4034) | A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine. | 7.2 | - - - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name=pkexec by _time Processes.dest Processes.process_id Processes.parent_process_name Processes.process_name Processes.process Processes.process_path -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| regex process="(^.{1}$)" -| `linux_pkexec_privilege_escalation_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **linux_pkexec_privilege_escalation_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -Depending on the EDR product in use, there are multiple ways to "null" the command-line field, Processes.process. Two that may be useful `process="(^.{0}$)"` or `| where isnull(process)`. To generate data for this behavior, Sysmon for Linux was utilized. To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -False positives may be present, filter as needed. - -#### Associated Analytic story -* [Linux Privilege Escalation](/stories/linux_privilege_escalation) -* [Linux Living Off The Land](/stories/linux_living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 56.0 | 80 | 70 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ related to a local privilege escalation in polkit pkexec. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.reddit.com/r/crowdstrike/comments/sdfeig/20220126_cool_query_friday_hunting_pwnkit_local/](https://www.reddit.com/r/crowdstrike/comments/sdfeig/20220126_cool_query_friday_hunting_pwnkit_local/) -* [https://linux.die.net/man/1/pkexec](https://linux.die.net/man/1/pkexec) -* [https://www.bleepingcomputer.com/news/security/linux-system-service-bug-gives-root-on-all-major-distros-exploit-released/](https://www.bleepingcomputer.com/news/security/linux-system-service-bug-gives-root-on-all-major-distros-exploit-released/) -* [https://access.redhat.com/security/security-updates/#/?q=polkit&p=1&sort=portal_publication_date%20desc&rows=10&portal_advisory_type=Security%20Advisory&documentKind=PortalProduct](https://access.redhat.com/security/security-updates/#/?q=polkit&p=1&sort=portal_publication_date%20desc&rows=10&portal_advisory_type=Security%20Advisory&documentKind=PortalProduct) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1068/zoom_child_process/linux-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1068/zoom_child_process/linux-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_pkexec_privilege_escalation.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-02-01-mimikatz_passtheticket_commandline_parameters.md b/docs/_posts/2022-02-01-mimikatz_passtheticket_commandline_parameters.md deleted file mode 100644 index ea2831e11f..0000000000 --- a/docs/_posts/2022-02-01-mimikatz_passtheticket_commandline_parameters.md +++ /dev/null @@ -1,168 +0,0 @@ ---- -title: "Mimikatz PassTheTicket CommandLine Parameters" -excerpt: "Use Alternate Authentication Material -, Pass the Ticket -" -categories: - - Endpoint -last_modified_at: 2022-02-01 -toc: true -toc_label: "" -tags: - - Use Alternate Authentication Material - - Pass the Ticket - - Defense Evasion - - Lateral Movement - - Defense Evasion - - Lateral Movement - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic looks for the use of Mimikatz command line parameters leveraged to execute pass the ticket attacks. Red teams and adversaries alike may use the pass the ticket technique using stolen Kerberos tickets to move laterally within an environment, bypassing normal system access controls. Defenders should be aware that adversaries may customize the source code of Mimikatz and modify the command line parameters. This would effectively bypass this analytic. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-02-01 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 13bbd574-83ac-11ec-99d4-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1550](https://attack.mitre.org/techniques/T1550/) | Use Alternate Authentication Material | Defense Evasion, Lateral Movement | - -| [T1550.003](https://attack.mitre.org/techniques/T1550/003/) | Pass the Ticket | Defense Evasion, Lateral Movement | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process = "*sekurlsa::tickets /export*" OR Processes.process = "*kerberos::ptt*") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `mimikatz_passtheticket_commandline_parameters_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **mimikatz_passtheticket_commandline_parameters_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id -* Processes.parent_process_name - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -Although highly unlikely, legitimate applications may use the same command line parameters as Mimikatz. - -#### Associated Analytic story -* [Active Directory Kerberos Attacks](/stories/active_directory_kerberos_attacks) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 36.0 | 60 | 60 | Mimikatz command line parameters for pass the ticket attacks were used on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/gentilkiwi/mimikatz](https://github.com/gentilkiwi/mimikatz) -* [https://attack.mitre.org/techniques/T1550/003/](https://attack.mitre.org/techniques/T1550/003/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1550.003/mimikatz/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1550.003/mimikatz/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/mimikatz_passtheticket_commandline_parameters.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-02-01-rubeus_command_line_parameters.md b/docs/_posts/2022-02-01-rubeus_command_line_parameters.md deleted file mode 100644 index b5218c8b77..0000000000 --- a/docs/_posts/2022-02-01-rubeus_command_line_parameters.md +++ /dev/null @@ -1,185 +0,0 @@ ---- -title: "Rubeus Command Line Parameters" -excerpt: "Use Alternate Authentication Material -, Pass the Ticket -, Steal or Forge Kerberos Tickets -, Kerberoasting -, AS-REP Roasting -" -categories: - - Endpoint -last_modified_at: 2022-02-01 -toc: true -toc_label: "" -tags: - - Use Alternate Authentication Material - - Pass the Ticket - - Steal or Forge Kerberos Tickets - - Kerberoasting - - AS-REP Roasting - - Defense Evasion - - Lateral Movement - - Defense Evasion - - Lateral Movement - - Credential Access - - Credential Access - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project and Vincent LE TOUXs MakeMeEnterpriseAdmin project. This analytic looks for the use of Rubeus command line arguments utilized in common Kerberos attacks like exporting and importing tickets, forging silver and golden tickets, requesting a TGT or TGS, kerberoasting, password spraying, etc. Red teams and adversaries alike use Rubeus for Kerberos attacks within Active Directory networks. Defenders should be aware that adversaries may customize the source code of Rubeus and modify the command line parameters. This would effectively bypass this analytic. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-02-01 -- **Author**: Mauricio Velazco, Splunk -- **ID**: cca37478-8377-11ec-b59a-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1550](https://attack.mitre.org/techniques/T1550/) | Use Alternate Authentication Material | Defense Evasion, Lateral Movement | - -| [T1550.003](https://attack.mitre.org/techniques/T1550/003/) | Pass the Ticket | Defense Evasion, Lateral Movement | - -| [T1558](https://attack.mitre.org/techniques/T1558/) | Steal or Forge Kerberos Tickets | Credential Access | - -| [T1558.003](https://attack.mitre.org/techniques/T1558/003/) | Kerberoasting | Credential Access | - -| [T1558.004](https://attack.mitre.org/techniques/T1558/004/) | AS-REP Roasting | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process = "*ptt /ticket*" OR Processes.process = "* monitor *" OR Processes.process ="* asktgt* /user:*" OR Processes.process ="* asktgs* /service:*" OR Processes.process ="* golden* /user:*" OR Processes.process ="* silver* /service:*" OR Processes.process ="* kerberoast*" OR Processes.process ="* asreproast*" OR Processes.process = "* renew* /ticket:*" OR Processes.process = "* brute* /password:*" OR Processes.process = "* brute* /passwords:*" OR Processes.process ="* harvest*") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `rubeus_command_line_parameters_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **rubeus_command_line_parameters_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id -* Processes.parent_process_name - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -Although unlikely, legitimate applications may use the same command line parameters as Rubeus. Filter as needed. - -#### Associated Analytic story -* [Active Directory Kerberos Attacks](/stories/active_directory_kerberos_attacks) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 36.0 | 60 | 60 | Rubeus command line parameters were used on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/GhostPack/Rubeus](https://github.com/GhostPack/Rubeus) -* [https://web.archive.org/web/20210725005734/http://www.harmj0y.net/blog/redteaming/from-kekeo-to-rubeus/](https://web.archive.org/web/20210725005734/http://www.harmj0y.net/blog/redteaming/from-kekeo-to-rubeus/) -* [https://attack.mitre.org/techniques/T1550/003/](https://attack.mitre.org/techniques/T1550/003/) -* [https://en.hackndo.com/kerberos-silver-golden-tickets/](https://en.hackndo.com/kerberos-silver-golden-tickets/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1550.003/rubeus/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1550.003/rubeus/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/rubeus_command_line_parameters.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-02-01-suspicious_rundll32_rename.md b/docs/_posts/2022-02-01-suspicious_rundll32_rename.md deleted file mode 100644 index 897d3f2710..0000000000 --- a/docs/_posts/2022-02-01-suspicious_rundll32_rename.md +++ /dev/null @@ -1,184 +0,0 @@ ---- -title: "Suspicious Rundll32 Rename" -excerpt: "Signed Binary Proxy Execution -, Masquerading -, Rundll32 -, Rename System Utilities -" -categories: - - Deprecated -last_modified_at: 2022-02-01 -toc: true -toc_label: "" -tags: - - Signed Binary Proxy Execution - - Masquerading - - Rundll32 - - Rename System Utilities - - Defense Evasion - - Defense Evasion - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success} - -#### Description - -The following hunting analytic identifies renamed instances of rundll32.exe executing. rundll32.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. During investigation, validate it is the legitimate rundll32.exe executing and what script content it is loading. This query relies on the original filename or internal name from the PE meta data. Expand the query as needed by looking for specific command line arguments outlined in other analytics. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-02-01 -- **Author**: Michael Haag, Splunk -- **ID**: 7360137f-abad-473e-8189-acbdaa34d114 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | - -| [T1036](https://attack.mitre.org/techniques/T1036/) | Masquerading | Defense Evasion | - -| [T1218.011](https://attack.mitre.org/techniques/T1218/011/) | Rundll32 | Defense Evasion | - -| [T1036.003](https://attack.mitre.org/techniques/T1036/003/) | Rename System Utilities | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_rundll32` by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.original_file_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `suspicious_rundll32_rename_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_rundll32](https://github.com/splunk/security_content/blob/develop/macros/process_rundll32.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -Note that **suspicious_rundll32_rename_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Although unlikely, some legitimate applications may use a moved copy of rundll32, triggering a false positive. - -#### Associated Analytic story -* [Suspicious Rundll32 Activity](/stories/suspicious_rundll32_activity) -* [Masquerading - Rename System Utilities](/stories/masquerading_-_rename_system_utilities) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 63.0 | 70 | 90 | Suspicious renamed rundll32.exe binary ran on $dest$ by $user$ | - - -#### Reference - -* [https://attack.mitre.org/techniques/T1218/011/](https://attack.mitre.org/techniques/T1218/011/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.011/T1218.011.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.011/T1218.011.md) -* [https://lolbas-project.github.io/lolbas/Binaries/Rundll32](https://lolbas-project.github.io/lolbas/Binaries/Rundll32) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.011/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.011/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/suspicious_rundll32_rename.yml) \| *version*: **4** \ No newline at end of file diff --git a/docs/_posts/2022-02-03-certutil_download_with_urlcache_and_split_arguments.md b/docs/_posts/2022-02-03-certutil_download_with_urlcache_and_split_arguments.md deleted file mode 100644 index f84dbd4d80..0000000000 --- a/docs/_posts/2022-02-03-certutil_download_with_urlcache_and_split_arguments.md +++ /dev/null @@ -1,168 +0,0 @@ ---- -title: "CertUtil Download With URLCache and Split Arguments" -excerpt: "Ingress Tool Transfer -" -categories: - - Endpoint -last_modified_at: 2022-02-03 -toc: true -toc_label: "" -tags: - - Ingress Tool Transfer - - Command And Control - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -Certutil.exe may download a file from a remote destination using `-urlcache`. This behavior does require a URL to be passed on the command-line. In addition, `-f` (force) and `-split` (Split embedded ASN.1 elements, and save to files) will be used. It is not entirely common for `certutil.exe` to contact public IP space. However, it is uncommon for `certutil.exe` to write files to world writeable paths.\ During triage, capture any files on disk and review. Review the reputation of the remote IP or domain in question. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-02-03 -- **Author**: Michael Haag, Splunk -- **ID**: 415b4306-8bfb-11eb-85c4-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1105](https://attack.mitre.org/techniques/T1105/) | Ingress Tool Transfer | Command And Control | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_certutil` (Processes.process=*urlcache* Processes.process=*split*) OR Processes.process=*urlcache* by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.original_file_name Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `certutil_download_with_urlcache_and_split_arguments_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_certutil](https://github.com/splunk/security_content/blob/develop/macros/process_certutil.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **certutil_download_with_urlcache_and_split_arguments_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Limited false positives in most environments, however tune as needed based on parent-child relationship or network connection. - -#### Associated Analytic story -* [Ingress Tool Transfer](/stories/ingress_tool_transfer) -* [DarkSide Ransomware](/stories/darkside_ransomware) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 90.0 | 90 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to download a file. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1105/](https://attack.mitre.org/techniques/T1105/) -* [https://www.avira.com/en/blog/certutil-abused-by-attackers-to-spread-threats](https://www.avira.com/en/blog/certutil-abused-by-attackers-to-spread-threats) -* [https://web.archive.org/web/20210921110637/https://www.fireeye.com/blog/threat-research/2019/10/certutil-qualms-they-came-to-drop-fombs.html](https://web.archive.org/web/20210921110637/https://www.fireeye.com/blog/threat-research/2019/10/certutil-qualms-they-came-to-drop-fombs.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1105/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1105/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2022-02-03-certutil_download_with_verifyctl_and_split_arguments.md b/docs/_posts/2022-02-03-certutil_download_with_verifyctl_and_split_arguments.md deleted file mode 100644 index b4a4ddd812..0000000000 --- a/docs/_posts/2022-02-03-certutil_download_with_verifyctl_and_split_arguments.md +++ /dev/null @@ -1,169 +0,0 @@ ---- -title: "CertUtil Download With VerifyCtl and Split Arguments" -excerpt: "Ingress Tool Transfer -" -categories: - - Endpoint -last_modified_at: 2022-02-03 -toc: true -toc_label: "" -tags: - - Ingress Tool Transfer - - Command And Control - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -Certutil.exe may download a file from a remote destination using `-VerifyCtl`. This behavior does require a URL to be passed on the command-line. In addition, `-f` (force) and `-split` (Split embedded ASN.1 elements, and save to files) will be used. It is not entirely common for `certutil.exe` to contact public IP space. \ During triage, capture any files on disk and review. Review the reputation of the remote IP or domain in question. Using `-VerifyCtl`, the file will either be written to the current working directory or `%APPDATA%\..\LocalLow\Microsoft\CryptnetUrlCache\Content\`. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-02-03 -- **Author**: Michael Haag, Splunk -- **ID**: 801ad9e4-8bfb-11eb-8b31-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1105](https://attack.mitre.org/techniques/T1105/) | Ingress Tool Transfer | Command And Control | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_certutil` (Processes.process=*verifyctl* Processes.process=*split*) OR Processes.process=*verifyctl* by Processes.dest Processes.user Processes.original_file_name Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `certutil_download_with_verifyctl_and_split_arguments_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_certutil](https://github.com/splunk/security_content/blob/develop/macros/process_certutil.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **certutil_download_with_verifyctl_and_split_arguments_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Limited false positives in most environments, however tune as needed based on parent-child relationship or network connection. - -#### Associated Analytic story -* [Ingress Tool Transfer](/stories/ingress_tool_transfer) -* [DarkSide Ransomware](/stories/darkside_ransomware) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 90.0 | 90 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to download a file. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1105/](https://attack.mitre.org/techniques/T1105/) -* [https://www.hexacorn.com/blog/2020/08/23/certutil-one-more-gui-lolbin/](https://www.hexacorn.com/blog/2020/08/23/certutil-one-more-gui-lolbin/) -* [https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-R2-and-2012/cc732443(v=ws.11)#-verifyctl](https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-R2-and-2012/cc732443(v=ws.11)#-verifyctl) -* [https://www.avira.com/en/blog/certutil-abused-by-attackers-to-spread-threats](https://www.avira.com/en/blog/certutil-abused-by-attackers-to-spread-threats) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1105/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1105/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2022-02-03-o365_added_service_principal.md b/docs/_posts/2022-02-03-o365_added_service_principal.md deleted file mode 100644 index 5f9a419895..0000000000 --- a/docs/_posts/2022-02-03-o365_added_service_principal.md +++ /dev/null @@ -1,166 +0,0 @@ ---- -title: "O365 Added Service Principal" -excerpt: "Cloud Account -, Create Account -" -categories: - - Cloud -last_modified_at: 2022-02-03 -toc: true -toc_label: "" -tags: - - Cloud Account - - Create Account - - Persistence - - Persistence - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search detects the creation of a new Federation setting by alerting about an specific event related to its creation. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-02-03 -- **Author**: Rod Soto, Splunk -- **ID**: 1668812a-6047-11eb-ae93-0242ac130002 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1136.003](https://attack.mitre.org/techniques/T1136/003/) | Cloud Account | Persistence | - -| [T1136](https://attack.mitre.org/techniques/T1136/) | Create Account | Persistence | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`o365_management_activity` Workload=AzureActiveDirectory Operation="Add service principal credentials." -| stats min(_time) as firstTime max(_time) as lastTime values(Actor{}.ID) as Actor.ID values(ModifiedProperties{}.Name) as ModifiedProperties.Name values(ModifiedProperties{}.NewValue) as ModifiedProperties.NewValue values(Target{}.ID) as Target.ID by ActorIpAddress Operation -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `o365_added_service_principal_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [o365_management_activity](https://github.com/splunk/security_content/blob/develop/macros/o365_management_activity.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **o365_added_service_principal_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Workload -* signature -* Actor{}.ID -* ModifiedProperties{}.Name -* ModifiedProperties{}.NewValue -* Target{}.ID -* ActorIpAddress - - -#### How To Implement -You must install splunk Microsoft Office 365 add-on. This search works with o365:management:activity - -#### Known False Positives -The creation of a new Federation is not necessarily malicious, however these events need to be followed closely, as it may indicate federated credential abuse or backdoor via federated identities at a different cloud provider. - -#### Associated Analytic story -* [Office 365 Detections](/stories/office_365_detections) -* [Cloud Federated Credential Abuse](/stories/cloud_federated_credential_abuse) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 42.0 | 70 | 60 | User $Actor.ID$ created a new federation setting on $Target.ID$ and added service principal credentials from IP Address $ActorIpAddress$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.fireeye.com/content/dam/fireeye-www/blog/pdfs/wp-m-unc2452-2021-000343-01.pdf](https://www.fireeye.com/content/dam/fireeye-www/blog/pdfs/wp-m-unc2452-2021-000343-01.pdf) -* [https://www.cisa.gov/uscert/ncas/alerts/aa21-008a](https://www.cisa.gov/uscert/ncas/alerts/aa21-008a) -* [https://www.splunk.com/en_us/blog/security/a-golden-saml-journey-solarwinds-continued.html](https://www.splunk.com/en_us/blog/security/a-golden-saml-journey-solarwinds-continued.html) -* [https://blog.sygnia.co/detection-and-hunting-of-golden-saml-attack?hsLang=en](https://blog.sygnia.co/detection-and-hunting-of-golden-saml-attack?hsLang=en) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.003/o365_add_service_principal/o365_add_service_principal.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.003/o365_add_service_principal/o365_add_service_principal.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/o365_added_service_principal.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-02-03-o365_bypass_mfa_via_trusted_ip.md b/docs/_posts/2022-02-03-o365_bypass_mfa_via_trusted_ip.md deleted file mode 100644 index 861cd2db17..0000000000 --- a/docs/_posts/2022-02-03-o365_bypass_mfa_via_trusted_ip.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: "O365 Bypass MFA via Trusted IP" -excerpt: "Disable or Modify Cloud Firewall -, Impair Defenses -" -categories: - - Cloud -last_modified_at: 2022-02-03 -toc: true -toc_label: "" -tags: - - Disable or Modify Cloud Firewall - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search detects newly added IP addresses/CIDR blocks to the list of MFA Trusted IPs to bypass multi factor authentication. Attackers are often known to use this technique so that they can bypass the MFA system. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-02-03 -- **Author**: Bhavin Patel, Splunk -- **ID**: c783dd98-c703-4252-9e8a-f19d9f66949e - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.007](https://attack.mitre.org/techniques/T1562/007/) | Disable or Modify Cloud Firewall | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`o365_management_activity` Operation="Set Company Information." ModifiedProperties{}.Name=StrongAuthenticationPolicy -| rex max_match=100 field=ModifiedProperties{}.NewValue "(?\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\/\d{1,2})" -| rex max_match=100 field=ModifiedProperties{}.OldValue "(?\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\/\d{1,2})" -| eval ip_addresses_old=if(isnotnull(ip_addresses_old),ip_addresses_old,"0") -| mvexpand ip_addresses_new_added -| where isnull(mvfind(ip_addresses_old,ip_addresses_new_added)) -|stats count min(_time) as firstTime max(_time) as lastTime values(ip_addresses_old) as ip_addresses_old by user ip_addresses_new_added Operation Workload vendor_account status user_id action -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `o365_bypass_mfa_via_trusted_ip_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [o365_management_activity](https://github.com/splunk/security_content/blob/develop/macros/o365_management_activity.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **o365_bypass_mfa_via_trusted_ip_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* signature -* ModifiedProperties{}.Name -* ModifiedProperties{}.NewValue -* ModifiedProperties{}.OldValue -* user -* vendor_account -* status -* user_id -* action - - -#### How To Implement -You must install Splunk Microsoft Office 365 add-on. This search works with o365:management:activity - -#### Known False Positives -Unless it is a special case, it is uncommon to continually update Trusted IPs to MFA configuration. - -#### Associated Analytic story -* [Office 365 Detections](/stories/office_365_detections) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 42.0 | 70 | 60 | User $user_id$ has added new IP addresses $ip_addresses_new_added$ to a list of trusted IPs to bypass MFA | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://i.blackhat.com/USA-20/Thursday/us-20-Bienstock-My-Cloud-Is-APTs-Cloud-Investigating-And-Defending-Office-365.pdf](https://i.blackhat.com/USA-20/Thursday/us-20-Bienstock-My-Cloud-Is-APTs-Cloud-Investigating-And-Defending-Office-365.pdf) -* [https://attack.mitre.org/techniques/T1562/007/](https://attack.mitre.org/techniques/T1562/007/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.007/o365_bypass_mfa_via_trusted_ip/o365_bypass_mfa_via_trusted_ip.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.007/o365_bypass_mfa_via_trusted_ip/o365_bypass_mfa_via_trusted_ip.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-02-03-o365_disable_mfa.md b/docs/_posts/2022-02-03-o365_disable_mfa.md deleted file mode 100644 index c8571f10e9..0000000000 --- a/docs/_posts/2022-02-03-o365_disable_mfa.md +++ /dev/null @@ -1,159 +0,0 @@ ---- -title: "O365 Disable MFA" -excerpt: "Modify Authentication Process -" -categories: - - Cloud -last_modified_at: 2022-02-03 -toc: true -toc_label: "" -tags: - - Modify Authentication Process - - Credential Access - - Defense Evasion - - Persistence - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search detects when multi factor authentication has been disabled, what entitiy performed the action and against what user - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-02-03 -- **Author**: Rod Soto, Splunk -- **ID**: c783dd98-c703-4252-9e8a-f19d9f5c949e - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1556](https://attack.mitre.org/techniques/T1556/) | Modify Authentication Process | Credential Access, Defense Evasion, Persistence | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`o365_management_activity` Operation="Disable Strong Authentication." -| stats count earliest(_time) as firstTime latest(_time) as lastTime by UserType Operation UserId ResultStatus -|`security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -| `o365_disable_mfa_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [o365_management_activity](https://github.com/splunk/security_content/blob/develop/macros/o365_management_activity.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **o365_disable_mfa_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Operation -* UserType -* user -* status -* signature -* dest -* ResultStatus - - -#### How To Implement -You must install splunk Microsoft Office 365 add-on. This search works with o365:management:activity - -#### Known False Positives -Unless it is a special case, it is uncommon to disable MFA or Strong Authentication - -#### Associated Analytic story -* [Office 365 Detections](/stories/office_365_detections) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 64.0 | 80 | 80 | User $user$ has executed an operation $Operation$ for this destination $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1556/](https://attack.mitre.org/techniques/T1556/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1556/o365_disable_mfa/o365_disable_mfa.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1556/o365_disable_mfa/o365_disable_mfa.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/o365_disable_mfa.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-02-07-rubeus_kerberos_ticket_exports_through_winlogon_access.md b/docs/_posts/2022-02-07-rubeus_kerberos_ticket_exports_through_winlogon_access.md deleted file mode 100644 index 16040e64ed..0000000000 --- a/docs/_posts/2022-02-07-rubeus_kerberos_ticket_exports_through_winlogon_access.md +++ /dev/null @@ -1,167 +0,0 @@ ---- -title: "Rubeus Kerberos Ticket Exports Through Winlogon Access" -excerpt: "Use Alternate Authentication Material -, Pass the Ticket -" -categories: - - Endpoint -last_modified_at: 2022-02-07 -toc: true -toc_label: "" -tags: - - Use Alternate Authentication Material - - Pass the Ticket - - Defense Evasion - - Lateral Movement - - Defense Evasion - - Lateral Movement - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic looks for a process accessing the winlogon.exe system process. The Splunk Threat Research team identified this behavior when using the Rubeus tool to monitor for and export kerberos tickets from memory. Before being able to export tickets. Rubeus will try to escalate privileges to SYSTEM by obtaining a handle to winlogon.exe before trying to monitor for kerberos tickets. Exporting tickets from memory is typically the first step for pass the ticket attacks. Red teams and adversaries alike may use the pass the ticket technique using stolen Kerberos tickets to move laterally within an environment, bypassing normal system access controls. Defenders should be aware that adversaries may customize the source code of Rubeus to potentially bypass this analytic. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-02-07 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 5ed8c50a-8869-11ec-876f-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1550](https://attack.mitre.org/techniques/T1550/) | Use Alternate Authentication Material | Defense Evasion, Lateral Movement | - -| [T1550.003](https://attack.mitre.org/techniques/T1550/003/) | Pass the Ticket | Defense Evasion, Lateral Movement | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - `sysmon` EventCode=10 TargetImage=C:\\Windows\\system32\\winlogon.exe (GrantedAccess=0x1f3fff) (SourceImage!=C:\\Windows\\system32\\svchost.exe AND SourceImage!=C:\\Windows\\system32\\lsass.exe AND SourceImage!=C:\\Windows\\system32\\LogonUI.exe AND SourceImage!=C:\\Windows\\system32\\smss.exe AND SourceImage!=C:\\Windows\\system32\\wbem\\wmiprvse.exe) -| stats count min(_time) as firstTime max(_time) as lastTime by Computer, SourceImage, SourceProcessId, TargetImage, TargetProcessId, EventCode, GrantedAccess -| rename Computer as dest -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `rubeus_kerberos_ticket_exports_through_winlogon_access_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **rubeus_kerberos_ticket_exports_through_winlogon_access_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* TargetImage -* CallTrace -* Computer -* TargetProcessId -* SourceImage -* SourceProcessId - - -#### How To Implement -This search needs Sysmon Logs and a sysmon configuration, which includes EventCode 10. This search uses an input macro named `sysmon`. We strongly recommend that you specify your environment-specific configurations (index, source, sourcetype, etc.) for Windows Sysmon logs. Replace the macro definition with configurations for your Splunk environment. - -#### Known False Positives -Legitimate applications may obtain a handle for winlogon.exe. Filter as needed - -#### Associated Analytic story -* [Active Directory Kerberos Attacks](/stories/active_directory_kerberos_attacks) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 36.0 | 60 | 60 | Winlogon.exe was accessed by $SourceImage$ on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/GhostPack/Rubeus](https://github.com/GhostPack/Rubeus) -* [https://web.archive.org/web/20210725005734/http://www.harmj0y.net/blog/redteaming/from-kekeo-to-rubeus/](https://web.archive.org/web/20210725005734/http://www.harmj0y.net/blog/redteaming/from-kekeo-to-rubeus/) -* [https://attack.mitre.org/techniques/T1550/003/](https://attack.mitre.org/techniques/T1550/003/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1550.003/rubeus/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1550.003/rubeus/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/rubeus_kerberos_ticket_exports_through_winlogon_access.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-02-07-windows_remote_assistance_spawning_process.md b/docs/_posts/2022-02-07-windows_remote_assistance_spawning_process.md deleted file mode 100644 index 750df54c18..0000000000 --- a/docs/_posts/2022-02-07-windows_remote_assistance_spawning_process.md +++ /dev/null @@ -1,165 +0,0 @@ ---- -title: "Windows Remote Assistance Spawning Process" -excerpt: "Process Injection -" -categories: - - Endpoint -last_modified_at: 2022-02-07 -toc: true -toc_label: "" -tags: - - Process Injection - - Defense Evasion - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the use of Microsoft Remote Assistance, msra.exe, spawning PowerShell.exe or cmd.exe as a child process. Msra.exe by default has no command-line arguments and typically spawns itself. It will generate a network connection to the remote system that is connected. This behavior is indicative of another process injected into msra.exe. Review the parent process or cross process events to identify source. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-02-07 -- **Author**: Michael Haag, Splunk -- **ID**: ced50492-8849-11ec-9f68-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1055](https://attack.mitre.org/techniques/T1055/) | Process Injection | Defense Evasion, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=msra.exe `windows_shells` by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_remote_assistance_spawning_process_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [windows_shells](https://github.com/splunk/security_content/blob/develop/macros/windows_shells.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_remote_assistance_spawning_process_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -False positives should be limited, filter as needed. Add additional shells as needed. - -#### Associated Analytic story -* [Unusual Processes](/stories/unusual_processes) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$, generating behavior not common with msra.exe. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://thedfirreport.com/2022/02/07/qbot-likes-to-move-it-move-it/](https://thedfirreport.com/2022/02/07/qbot-likes-to-move-it-move-it/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/msra/msra-windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/msra/msra-windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_remote_assistance_spawning_process.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-02-07-windows_schtasks_create_run_as_system.md b/docs/_posts/2022-02-07-windows_schtasks_create_run_as_system.md deleted file mode 100644 index 7722585244..0000000000 --- a/docs/_posts/2022-02-07-windows_schtasks_create_run_as_system.md +++ /dev/null @@ -1,175 +0,0 @@ ---- -title: "Windows Schtasks Create Run As System" -excerpt: "Scheduled Task -, Scheduled Task/Job -" -categories: - - Endpoint -last_modified_at: 2022-02-07 -toc: true -toc_label: "" -tags: - - Scheduled Task - - Scheduled Task/Job - - Execution - - Persistence - - Privilege Escalation - - Execution - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies Schtasks.exe creating a new task to start and run as an elevated user - SYSTEM. This is commonly used by adversaries to spawn a process in an elevated state. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-02-07 -- **Author**: Michael Haag, Splunk -- **ID**: 41a0e58e-884c-11ec-9976-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1053.005](https://attack.mitre.org/techniques/T1053/005/) | Scheduled Task | Execution, Persistence, Privilege Escalation | - -| [T1053](https://attack.mitre.org/techniques/T1053/) | Scheduled Task/Job | Execution, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_schtasks` Processes.process="*/create *" AND Processes.process="*/ru *" AND Processes.process="*system*" by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_schtasks_create_run_as_system_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [process_schtasks](https://github.com/splunk/security_content/blob/develop/macros/process_schtasks.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_schtasks_create_run_as_system_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -False positives will be limited to legitimate applications creating a task to run as SYSTEM. Filter as needed based on parent process, or modify the query to have world writeable paths to restrict it. - -#### Associated Analytic story -* [Windows Persistence Techniques](/stories/windows_persistence_techniques) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 48.0 | 80 | 60 | An $process_name$ was created on endpoint $dest$ attempting to spawn as SYSTEM. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://pentestlab.blog/2019/11/04/persistence-scheduled-tasks/](https://pentestlab.blog/2019/11/04/persistence-scheduled-tasks/) -* [https://www.ired.team/offensive-security/persistence/t1053-schtask](https://www.ired.team/offensive-security/persistence/t1053-schtask) -* [https://thedfirreport.com/2022/02/07/qbot-likes-to-move-it-move-it/](https://thedfirreport.com/2022/02/07/qbot-likes-to-move-it-move-it/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/schtask_system/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/schtask_system/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_schtasks_create_run_as_system.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-02-08-rundll_loading_dll_by_ordinal.md b/docs/_posts/2022-02-08-rundll_loading_dll_by_ordinal.md deleted file mode 100644 index 1ca1e1d4f7..0000000000 --- a/docs/_posts/2022-02-08-rundll_loading_dll_by_ordinal.md +++ /dev/null @@ -1,177 +0,0 @@ ---- -title: "RunDLL Loading DLL By Ordinal" -excerpt: "System Binary Proxy Execution -, Rundll32 -" -categories: - - Endpoint -last_modified_at: 2022-02-08 -toc: true -toc_label: "" -tags: - - System Binary Proxy Execution - - Rundll32 - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies rundll32.exe loading an export function by ordinal value. Adversaries may abuse rundll32.exe to proxy execution of malicious code. Using rundll32.exe, vice executing directly, may avoid triggering security tools that may not monitor execution of the rundll32.exe process because of allowlists or false positives from normal operations. Utilizing ordinal values makes it a bit more complicated for analysts to understand the behavior until the DLL is reviewed. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-02-08 -- **Author**: Michael Haag, David Dorsey, Splunk -- **ID**: 6c135f8d-5e60-454e-80b7-c56eed739833 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218](https://attack.mitre.org/techniques/T1218/) | System Binary Proxy Execution | Defense Evasion | - -| [T1218.011](https://attack.mitre.org/techniques/T1218/011/) | Rundll32 | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Installation - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_rundll32` by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| where match(process,"rundll32.+\#\d+") -| `rundll_loading_dll_by_ordinal_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [process_rundll32](https://github.com/splunk/security_content/blob/develop/macros/process_rundll32.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **rundll_loading_dll_by_ordinal_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -False positives are possible with native utilities and third party applications. Filtering may be needed based on command-line, or add world writeable paths to restrict query. - -#### Associated Analytic story -* [Unusual Processes](/stories/unusual_processes) -* [Suspicious Rundll32 Activity](/stories/suspicious_rundll32_activity) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | A rundll32 process $process_name$ with ordinal parameter like this process commandline $process$ on host $dest$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://thedfirreport.com/2022/02/07/qbot-likes-to-move-it-move-it/](https://thedfirreport.com/2022/02/07/qbot-likes-to-move-it-move-it/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.011/atomic_red_team/ordinal_windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.011/atomic_red_team/ordinal_windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml) \| *version*: **6** \ No newline at end of file diff --git a/docs/_posts/2022-02-08-unusual_number_of_kerberos_service_tickets_requested.md b/docs/_posts/2022-02-08-unusual_number_of_kerberos_service_tickets_requested.md deleted file mode 100644 index aad5633fbd..0000000000 --- a/docs/_posts/2022-02-08-unusual_number_of_kerberos_service_tickets_requested.md +++ /dev/null @@ -1,166 +0,0 @@ ---- -title: "Unusual Number of Kerberos Service Tickets Requested" -excerpt: "Steal or Forge Kerberos Tickets -, Kerberoasting -" -categories: - - Endpoint -last_modified_at: 2022-02-08 -toc: true -toc_label: "" -tags: - - Steal or Forge Kerberos Tickets - - Kerberoasting - - Credential Access - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following hunting analytic leverages Kerberos Event 4769, A Kerberos service ticket was requested, to identify a potential kerberoasting attack against Active Directory networks. Kerberoasting allows an adversary to request kerberos tickets for domain accounts typically used as service accounts and attempt to crack them offline allowing them to obtain privileged access to the domain.\ -The detection calculates the standard deviation for each host and leverages the 3-sigma statistical rule to identify an unusual number service ticket requests. To customize this analytic, users can try different combinations of the `bucket` span time and the calculation of the `upperBound` field. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-02-08 -- **Author**: Mauricio Velazco, Splunk -- **ID**: eb3e6702-8936-11ec-98fe-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1558](https://attack.mitre.org/techniques/T1558/) | Steal or Forge Kerberos Tickets | Credential Access | - -| [T1558.003](https://attack.mitre.org/techniques/T1558/003/) | Kerberoasting | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - `wineventlog_security` EventCode=4769 Service_Name!="*$" Ticket_Encryption_Type=0x17 -| bucket span=2m _time -| stats dc(Service_Name) AS unique_services values(Service_Name) as requested_services by _time, Client_Address -| eventstats avg(unique_services) as comp_avg , stdev(unique_services) as comp_std by Client_Address -| eval upperBound=(comp_avg+comp_std*3) -| eval isOutlier=if(unique_services > 2 and unique_services >= upperBound, 1, 0) -| search isOutlier=1 -| `unusual_number_of_kerberos_service_tickets_requested_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) - -> :information_source: -> **unusual_number_of_kerberos_service_tickets_requested_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Ticket_Options -* Ticket_Encryption_Type -* dest -* Service_Name -* service_id -* Client_Address - - -#### How To Implement -To successfully implement this search, you need to be ingesting Domain Controller and Kerberos events. The Advanced Security Audit policy setting `Audit Kerberos Authentication Service` within `Account Logon` needs to be enabled. - -#### Known False Positives -An single endpoint requesting a large number of kerberos service tickets is not common behavior. Possible false positive scenarios include but are not limited to vulnerability scanners, administration systems and missconfigured systems. - -#### Associated Analytic story -* [Active Directory Kerberos Attacks](/stories/active_directory_kerberos_attacks) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 36.0 | 60 | 60 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1558/003/](https://attack.mitre.org/techniques/T1558/003/) -* [https://www.ired.team/offensive-security-experiments/active-directory-kerberos-abuse/t1208-kerberoasting](https://www.ired.team/offensive-security-experiments/active-directory-kerberos-abuse/t1208-kerberoasting) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1558.003/rubeus/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1558.003/rubeus/windows-security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/unusual_number_of_kerberos_service_tickets_requested.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-02-09-kerberoasting_spn_request_with_rc4_encryption.md b/docs/_posts/2022-02-09-kerberoasting_spn_request_with_rc4_encryption.md deleted file mode 100644 index b8aee83d87..0000000000 --- a/docs/_posts/2022-02-09-kerberoasting_spn_request_with_rc4_encryption.md +++ /dev/null @@ -1,169 +0,0 @@ ---- -title: "Kerberoasting spn request with RC4 encryption" -excerpt: "Steal or Forge Kerberos Tickets -, Kerberoasting -" -categories: - - Endpoint -last_modified_at: 2022-02-09 -toc: true -toc_label: "" -tags: - - Steal or Forge Kerberos Tickets - - Kerberoasting - - Credential Access - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic leverages Kerberos Event 4769, A Kerberos service ticket was requested, to identify a potential kerberoasting attack against Active Directory networks. Kerberoasting allows an adversary to request kerberos tickets for domain accounts typically used as service accounts and attempt to crack them offline allowing them to obtain privileged access to the domain. This analytic looks for a specific combination of the Ticket_Options field based on common kerberoasting tools. Defenders should be aware that it may be possible for a Kerberoast attack to use different Ticket_Options. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-02-09 -- **Author**: Jose Hernandez, Patrick Bareiss, Mauricio Velazco, Splunk -- **ID**: 5cc67381-44fa-4111-8a37-7a230943f027 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1558](https://attack.mitre.org/techniques/T1558/) | Steal or Forge Kerberos Tickets | Credential Access | - -| [T1558.003](https://attack.mitre.org/techniques/T1558/003/) | Kerberoasting | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`wineventlog_security` EventCode=4769 Service_Name!="*$" (Ticket_Options=0x40810000 OR Ticket_Options=0x40800000 OR Ticket_Options=0x40810010) Ticket_Encryption_Type=0x17 -| stats count min(_time) as firstTime max(_time) as lastTime by dest, service, service_id, Ticket_Encryption_Type, Ticket_Options -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `kerberoasting_spn_request_with_rc4_encryption_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **kerberoasting_spn_request_with_rc4_encryption_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Ticket_Options -* Ticket_Encryption_Type -* dest -* service -* service_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting Domain Controller and Kerberos events. The Advanced Security Audit policy setting `Audit Kerberos Authentication Service` within `Account Logon` needs to be enabled. - -#### Known False Positives -Older systems that support kerberos RC4 by default like NetApp may generate false positives. Filter as needed - -#### Associated Analytic story -* [Windows Privilege Escalation](/stories/windows_privilege_escalation) -* [Active Directory Kerberos Attacks](/stories/active_directory_kerberos_attacks) -* [Hermetic Wiper](/stories/hermetic_wiper) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 72.0 | 90 | 80 | Potential kerberoasting attack via service principal name requests detected on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/redcanaryco/atomic-red-team/blob/4e3e9c8096dde00639a6b98845ec349135554ed5/atomics/T1208/T1208.md](https://github.com/redcanaryco/atomic-red-team/blob/4e3e9c8096dde00639a6b98845ec349135554ed5/atomics/T1208/T1208.md) -* [https://www.hub.trimarcsecurity.com/post/trimarc-research-detecting-kerberoasting-activity](https://www.hub.trimarcsecurity.com/post/trimarc-research-detecting-kerberoasting-activity) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1558.003/rubeus/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1558.003/rubeus/windows-security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml) \| *version*: **4** \ No newline at end of file diff --git a/docs/_posts/2022-02-11-linux_system_network_discovery.md b/docs/_posts/2022-02-11-linux_system_network_discovery.md deleted file mode 100644 index 89119be3a4..0000000000 --- a/docs/_posts/2022-02-11-linux_system_network_discovery.md +++ /dev/null @@ -1,164 +0,0 @@ ---- -title: "Linux System Network Discovery" -excerpt: "System Network Configuration Discovery -" -categories: - - Endpoint -last_modified_at: 2022-02-11 -toc: true -toc_label: "" -tags: - - System Network Configuration Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to look for possible enumeration of local network configuration. This technique is commonly used as part of recon of adversaries or threat actor to know some network information for its next or further attack. This anomaly detections may capture normal event made by administrator during auditing or testing network connection of specific host or network to network. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-02-11 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 535cb214-8b47-11ec-a2c7-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1016](https://attack.mitre.org/techniques/T1016/) | System Network Configuration Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count values(Processes.process_name) as process_name_list values(Processes.process) as process_list values(Processes.process_id) as process_id_list values(Processes.parent_process_id) as parent_process_id_list values(Processes.process_guid) as process_guid_list dc(Processes.process_name) as process_name_count from datamodel=Endpoint.Processes where Processes.process_name IN ("arp", "ifconfig", "ip", "netstat", "firewall-cmd", "ufw", "iptables", "ss", "route") by _time span=30m Processes.dest Processes.user -| where process_name_count >=4 -| `drop_dm_object_name(Processes)` -| `linux_system_network_discovery_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **linux_system_network_discovery_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase. - -#### Known False Positives -Administrator or network operator can execute this command. Please update the filter macros to remove false positives. - -#### Associated Analytic story -* [Network Discovery](/stories/network_discovery) -* [Industroyer2](/stories/industroyer2) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 9.0 | 30 | 30 | A commandline $process$ executed on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1016/T1016.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1016/T1016.md) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1016/atomic_red_team/linux_net_discovery/sysmon_linux.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1016/atomic_red_team/linux_net_discovery/sysmon_linux.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_system_network_discovery.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-02-11-windows_powershell_connect_to_internet_with_hidden_window.md b/docs/_posts/2022-02-11-windows_powershell_connect_to_internet_with_hidden_window.md deleted file mode 100644 index 8c77f3b277..0000000000 --- a/docs/_posts/2022-02-11-windows_powershell_connect_to_internet_with_hidden_window.md +++ /dev/null @@ -1,118 +0,0 @@ ---- -title: "Windows Powershell Connect to Internet With Hidden Window" -excerpt: "Automated Exfiltration" -categories: - - Endpoint -last_modified_at: 2022-02-11 -toc: true -toc_label: "" -tags: - - Automated Exfiltration - - Exfiltration - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -The following hunting analytic identifies PowerShell commands utilizing the WindowStyle parameter to hide the window on the compromised endpoint. This combination of command-line options is suspicious because it is overriding the default PowerShell execution policy, attempts to hide its activity from the user, and connects to the Internet. Removed in this version of the query is New-Object. The analytic identifies all variations of WindowStyle, as PowerShell allows the ability to shorten the parameter. For example w, win, windowsty and so forth. In addition, through our research it was identified that PowerShell will interpret different command switch types beyond the hyphen. We have added endash, emdash, horizontal bar, and forward slash. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2022-02-11 -- **Author**: Jose Hernandez, David Dorsey, Michael Haag Splunk -- **ID**: 477e068e-8b6d-11ec-b6c1-81af21670352 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1020](https://attack.mitre.org/techniques/T1020/) | Automated Exfiltration | Exfiltration | - -#### Search - -``` - -| from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line IS NOT NULL AND process_name IS NOT NULL -| where process_name="pwsh.exe" OR process_name="pwsh.exe" OR process_name="sqlps.exe" OR process_name="sqltoolsps.exe" OR process_name="powershell.exe" OR process_name="powershell_ise.exe" -| where match_regex(cmd_line, /(?i)[\\- -|\\/ -|\u2013\ -|\u2014 -|\u2015]w(in*d*o*w*s*t*y*l*e*)*\\s+[^-]/)=true -| eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) -| into write_ssa_detected_events(); -``` - -#### Macros -The SPL above uses the following Macros: - -Note that `windows_powershell_connect_to_internet_with_hidden_window_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* dest_device_id -* process_name -* parent_process_name -* process_path -* dest_user_id -* process -* cmd_line - - -#### How To Implement -You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. - -#### Known False Positives -Legitimate process can have this combination of command-line options, but it's not common. - -#### Associated Analytic story -* [Malicious PowerShell](/stories/malicious_powershell) -* [Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns](/stories/possible_backdoor_activity_associated_with_mudcarp_espionage_campaigns) -* [HAFNIUM Group](/stories/hafnium_group) -* [Log4Shell CVE-2021-44228](/stories/log4shell_cve-2021-44228) - - -#### Kill Chain Phase -* Exfiltration - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 35.0 | 50 | 70 | PowerShell processes $process$ started with parameters to modify the execution policy of the run, run in a hidden window, and connect to the Internet on host $dest$ executed by user $user$. | - - -Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` - - - -#### Reference - -* [https://regexr.com/663rr](https://regexr.com/663rr) -* [https://github.com/redcanaryco/AtomicTestHarnesses/blob/master/TestHarnesses/T1059.001_PowerShell/OutPowerShellCommandLineParameter.ps1](https://github.com/redcanaryco/AtomicTestHarnesses/blob/master/TestHarnesses/T1059.001_PowerShell/OutPowerShellCommandLineParameter.ps1) -* [https://ss64.com/ps/powershell.html](https://ss64.com/ps/powershell.html) -* [https://twitter.com/M_haggis/status/1440758396534214658?s=20](https://twitter.com/M_haggis/status/1440758396534214658?s=20) -* [https://blog.netlab.360.com/ten-families-of-malicious-samples-are-spreading-using-the-log4j2-vulnerability-now/](https://blog.netlab.360.com/ten-families-of-malicious-samples-are-spreading-using-the-log4j2-vulnerability-now/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/hidden_powershell/hidden_windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/hidden_powershell/hidden_windows-security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_powershell_connect_to_internet_with_hidden_window.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-02-11-windows_powershell_downloadfile.md b/docs/_posts/2022-02-11-windows_powershell_downloadfile.md deleted file mode 100644 index 0a911cad32..0000000000 --- a/docs/_posts/2022-02-11-windows_powershell_downloadfile.md +++ /dev/null @@ -1,111 +0,0 @@ ---- -title: "Windows Powershell DownloadFile" -excerpt: "Automated Exfiltration" -categories: - - Endpoint -last_modified_at: 2022-02-11 -toc: true -toc_label: "" -tags: - - Automated Exfiltration - - Exfiltration - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the use of PowerShell downloading a file using `DownloadFile` method. This particular method is utilized in many different PowerShell frameworks to download files and output to disk. Identify the source (IP/domain) and destination file and triage appropriately. If AMSI logging or PowerShell transaction logs are available, review for further details of the implant. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2022-02-11 -- **Author**: Jose Hernandez, Michael Haag, Splunk -- **ID**: 46440222-81d5-44b1-a376-19dcd70d1b08 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1020](https://attack.mitre.org/techniques/T1020/) | Automated Exfiltration | Exfiltration | - -#### Search - -``` - -| from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line IS NOT NULL AND process_name IS NOT NULL -| where process_name="pwsh.exe" OR process_name="pwsh.exe" OR process_name="sqlps.exe" OR process_name="sqltoolsps.exe" OR process_name="powershell.exe" OR process_name="powershell_ise.exe" -| where (like (cmd_line, "%downloadfile%")) -| eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) -| into write_ssa_detected_events(); -``` - -#### Macros -The SPL above uses the following Macros: - -Note that `windows_powershell_downloadfile_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* dest_device_id -* process_name -* parent_process_name -* process_path -* dest_user_id -* process -* cmd_line - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -False positives may be present and filtering will need to occur by parent process or command line argument. It may be required to modify this query to an EDR product for more granular coverage. - -#### Associated Analytic story -* [Malicious PowerShell](/stories/malicious_powershell) -* [Ingress Tool Transfer](/stories/ingress_tool_transfer) -* [Log4Shell CVE-2021-44228](/stories/log4shell_cve-2021-44228) - - -#### Kill Chain Phase -* Lateral Movement - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 35.0 | 50 | 70 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$. This behavior identifies the use of DownloadFile within PowerShell. | - - -Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` - - - -#### Reference - -* [https://docs.microsoft.com/en-us/dotnet/api/system.net.webclient.downloadfile?view=net-5.0](https://docs.microsoft.com/en-us/dotnet/api/system.net.webclient.downloadfile?view=net-5.0) -* [https://blog.malwarebytes.com/malwarebytes-news/2021/02/lazyscripter-from-empire-to-double-rat/](https://blog.malwarebytes.com/malwarebytes-news/2021/02/lazyscripter-from-empire-to-double-rat/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1059.001/T1059.001.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1059.001/T1059.001.md) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/atomic_red_team/downloadfile_windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/atomic_red_team/downloadfile_windows-security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_powershell_downloadfile.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-02-14-linux_dd_file_overwrite.md b/docs/_posts/2022-02-14-linux_dd_file_overwrite.md deleted file mode 100644 index 0cfb7e786f..0000000000 --- a/docs/_posts/2022-02-14-linux_dd_file_overwrite.md +++ /dev/null @@ -1,167 +0,0 @@ ---- -title: "Linux DD File Overwrite" -excerpt: "Data Destruction -" -categories: - - Endpoint -last_modified_at: 2022-02-14 -toc: true -toc_label: "" -tags: - - Data Destruction - - Impact - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to look for dd command to overwrite file. This technique was abused by adversaries or threat actor to destroy files or data on specific system or in a large number of host within network to interrupt host avilability, services and many more. This is also used to destroy data where it make the file irrecoverable by forensic techniques through overwriting files, data or local and remote drives. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-02-14 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 9b6aae5e-8d85-11ec-b2ae-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1485](https://attack.mitre.org/techniques/T1485/) | Data Destruction | Impact | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = "dd" AND Processes.process = "*of=*" by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.process_guid -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `linux_dd_file_overwrite_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **linux_dd_file_overwrite_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase. - -#### Known False Positives -Administrator or network operator can execute this command. Please update the filter macros to remove false positives. - -#### Associated Analytic story -* [Data Destruction](/stories/data_destruction) -* [Industroyer2](/stories/industroyer2) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 64.0 | 80 | 80 | A commandline $process$ executed on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://gtfobins.github.io/gtfobins/dd/](https://gtfobins.github.io/gtfobins/dd/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1485/T1485.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1485/T1485.md) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/linux_dd_file_overwrite/sysmon_linux.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/linux_dd_file_overwrite/sysmon_linux.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_dd_file_overwrite.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-02-15-detection_of_dns_tunnels.md b/docs/_posts/2022-02-15-detection_of_dns_tunnels.md deleted file mode 100644 index 234ca13d04..0000000000 --- a/docs/_posts/2022-02-15-detection_of_dns_tunnels.md +++ /dev/null @@ -1,165 +0,0 @@ ---- -title: "Detection of DNS Tunnels" -excerpt: "Exfiltration Over Unencrypted Non-C2 Protocol -" -categories: - - Deprecated -last_modified_at: 2022-02-15 -toc: true -toc_label: "" -tags: - - Exfiltration Over Unencrypted Non-C2 Protocol - - Exfiltration - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Network_Resolution ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is used to detect DNS tunneling, by calculating the sum of the length of DNS queries and DNS answers. The search also filters out potential false positives by filtering out queries made to internal systems and the queries originating from internal DNS, Web, and Email servers. Endpoints using DNS as a method of transmission for data exfiltration, command and control, or evasion of security controls can often be detected by noting an unusually large volume of DNS traffic. \ -NOTE:Deprecated because existing detection is doing the same. This detection is replaced with two other variations, if you are using MLTK then you can use this search `ESCU - DNS Query Length Outliers - MLTK - Rule` or use the standard deviation version `ESCU - DNS Query Length With High Standard Deviation - Rule`, as an alternantive. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Network_Resolution](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkResolution) -- **Last Updated**: 2022-02-15 -- **Author**: Bhavin Patel, Splunk -- **ID**: 104658f4-afdc-499f-9719-17a43f9826f4 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1048.003](https://attack.mitre.org/techniques/T1048/003/) | Exfiltration Over Unencrypted Non-C2 Protocol | Exfiltration | - -
-
- - -
- Kill Chain Phase - -
- -* Command & Control -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* PR.DS - - - -
-
- -
- CIS20 - -
- -* CIS 13 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` dc("DNS.query") as count from datamodel=Network_Resolution where nodename=DNS "DNS.message_type"="QUERY" NOT (`cim_corporate_web_domain_search("DNS.query")`) NOT "DNS.query"="*.in-addr.arpa" NOT ("DNS.src_category"="svc_infra_dns" OR "DNS.src_category"="svc_infra_webproxy" OR "DNS.src_category"="svc_infra_email*" ) by "DNS.src","DNS.query" -| rename "DNS.src" as src "DNS.query" as message -| eval length=len(message) -| stats sum(length) as length by src -| append [ tstats `security_content_summariesonly` dc("DNS.answer") as count from datamodel=Network_Resolution where nodename=DNS "DNS.message_type"="QUERY" NOT (`cim_corporate_web_domain_search("DNS.query")`) NOT "DNS.query"="*.in-addr.arpa" NOT ("DNS.src_category"="svc_infra_dns" OR "DNS.src_category"="svc_infra_webproxy" OR "DNS.src_category"="svc_infra_email*" ) by "DNS.src","DNS.answer" -| rename "DNS.src" as src "DNS.answer" as message -| eval message=if(message=="unknown","", message) -| eval length=len(message) -| stats sum(length) as length by src ] -| stats sum(length) as length by src -| where length > 10000 -| `detection_of_dns_tunnels_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **detection_of_dns_tunnels_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* DNS.query -* DNS.message_type -* DNS.src_category -* DNS.src - - -#### How To Implement -To successfully implement this search, we must ensure that DNS data is being ingested and mapped to the appropriate fields in the Network_Resolution data model. Fields like src_category are automatically provided by the Assets and Identity Framework shipped with Splunk Enterprise Security. You will need to ensure you are using the Assets and Identity Framework and populating the src_category field. You will also need to enable the `cim_corporate_web_domain_search()` macro which will essentially filter out the DNS queries made to the corporate web domains to reduce alert fatigue. - -#### Known False Positives -It's possible that normal DNS traffic will exhibit this behavior. If an alert is generated, please investigate and validate as appropriate. The threshold can also be modified to better suit your environment. - -#### Associated Analytic story -* [Data Protection](/stories/data_protection) -* [Suspicious DNS Traffic](/stories/suspicious_dns_traffic) -* [Command and Control](/stories/command_and_control) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | tbd | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/detection_of_dns_tunnels.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-02-15-windows_bits_job_persistence.md b/docs/_posts/2022-02-15-windows_bits_job_persistence.md deleted file mode 100644 index b849a2f986..0000000000 --- a/docs/_posts/2022-02-15-windows_bits_job_persistence.md +++ /dev/null @@ -1,112 +0,0 @@ ---- -title: "Windows Bits Job Persistence" -excerpt: "BITS Jobs" -categories: - - Endpoint -last_modified_at: 2022-02-15 -toc: true -toc_label: "" -tags: - - BITS Jobs - - Defense Evasion - - Persistence - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -The following query identifies Microsoft Background Intelligent Transfer Service utility `bitsadmin.exe` scheduling a BITS job to persist on an endpoint. The query identifies the parameters used to create, resume or add a file to a BITS job. Typically seen combined in a oneliner or ran in sequence. If identified, review the BITS job created and capture any files written to disk. It is possible for BITS to be used to upload files and this may require further network data analysis to identify. You can use `bitsadmin /list /verbose` to list out the jobs during investigation. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2022-02-15 -- **Author**: Michael Haag, Splunk -- **ID**: 1e25e97a-8ea4-11ec-9767-acde48001122 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1197](https://attack.mitre.org/techniques/T1197/) | BITS Jobs | Defense Evasion, Persistence | - -#### Search - -``` - -| from read_ssa_enriched_events() -| where "Endpoint_Processes" IN(_datamodels) -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line IS NOT NULL AND process_name IS NOT NULL AND process_name="bitsadmin.exe" AND (like (cmd_line, "%create%") OR like (cmd_line, "%addfile%")OR like (cmd_line, "%setnotifyflags%") OR like (cmd_line, "%setnotifycmdline%") OR like (cmd_line, "%setminretrydelay%") OR like (cmd_line, "%setcustomheaders%") OR like (cmd_line, "%resume%")) -| eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)) -| eval body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) -| into write_ssa_detected_events(); -``` - -#### Macros -The SPL above uses the following Macros: - -Note that `windows_bits_job_persistence_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* dest_device_id -* process_name -* parent_process_name -* process_path -* dest_user_id -* process -* cmd_line - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Limited false positives will be present. Typically, applications will use `BitsAdmin.exe`. Any filtering should be done based on command-line arguments (legitimate applications) or parent process. - -#### Associated Analytic story -* [BITS Jobs](/stories/bits_jobs) -* [Living Off The Land](/stories/living_off_the_land) - - -#### Kill Chain Phase -* Exploitation - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 56.0 | 70 | 80 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $dest_user_id$ attempting to persist using BITS. | - - -Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` - - - -#### Reference - -* [https://attack.mitre.org/techniques/T1197/](https://attack.mitre.org/techniques/T1197/) -* [https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/bitsadmin](https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/bitsadmin) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1197/T1197.md#atomic-test-3---persist-download--execute](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1197/T1197.md#atomic-test-3---persist-download--execute) -* [https://lolbas-project.github.io/lolbas/Binaries/Bitsadmin/](https://lolbas-project.github.io/lolbas/Binaries/Bitsadmin/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1197/atomic_red_team/bits-windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1197/atomic_red_team/bits-windows-security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_bits_job_persistence.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-02-15-windows_diskshadow_proxy_execution.md b/docs/_posts/2022-02-15-windows_diskshadow_proxy_execution.md deleted file mode 100644 index ff5d46003c..0000000000 --- a/docs/_posts/2022-02-15-windows_diskshadow_proxy_execution.md +++ /dev/null @@ -1,165 +0,0 @@ ---- -title: "Windows Diskshadow Proxy Execution" -excerpt: "System Binary Proxy Execution -" -categories: - - Endpoint -last_modified_at: 2022-02-15 -toc: true -toc_label: "" -tags: - - System Binary Proxy Execution - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -DiskShadow.exe is a Microsoft Signed binary present on Windows Server. It has a scripting mode intended for complex scripted backup operations. This feature also allows for execution of arbitrary unsigned code. This analytic looks for the usage of the scripting mode flags in executions of DiskShadow. During triage, compare to known backup behavior in your environment and then review the scripts called by diskshadow. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-02-15 -- **Author**: Lou Stella, Splunk -- **ID**: 58adae9e-8ea3-11ec-90f6-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218](https://attack.mitre.org/techniques/T1218/) | System Binary Proxy Execution | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_diskshadow` (Processes.process=*-s* OR Processes.process=*/s*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_diskshadow_proxy_execution_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [process_diskshadow](https://github.com/splunk/security_content/blob/develop/macros/process_diskshadow.yml) - -> :information_source: -> **windows_diskshadow_proxy_execution_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process -* Porcesses.dest -* Processes.user -* Processes.parent_process -* Processes.process_name -* Processes.process_id -* Processes.parent_process_id -* Processes.original_file_name - - -#### How To Implement -To successfully implement this search you need to be ingesting information on processes that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Administrators using the DiskShadow tool in their infrastructure as a main backup tool with scripts will cause false positives that can be filtered with `windows_diskshadow_proxy_execution_filter` - -#### Associated Analytic story -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | Possible Signed Binary Proxy Execution on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://bohops.com/2018/03/26/diskshadow-the-return-of-vss-evasion-persistence-and-active-directory-database-extraction/](https://bohops.com/2018/03/26/diskshadow-the-return-of-vss-evasion-persistence-and-active-directory-database-extraction/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218/diskshadow/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218/diskshadow/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_diskshadow_proxy_execution.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-02-15-windows_rasautou_dll_execution.md b/docs/_posts/2022-02-15-windows_rasautou_dll_execution.md deleted file mode 100644 index e3ba39dbbc..0000000000 --- a/docs/_posts/2022-02-15-windows_rasautou_dll_execution.md +++ /dev/null @@ -1,178 +0,0 @@ ---- -title: "Windows Rasautou DLL Execution" -excerpt: "Dynamic-link Library Injection -, System Binary Proxy Execution -, Process Injection -" -categories: - - Endpoint -last_modified_at: 2022-02-15 -toc: true -toc_label: "" -tags: - - Dynamic-link Library Injection - - System Binary Proxy Execution - - Process Injection - - Defense Evasion - - Privilege Escalation - - Defense Evasion - - Defense Evasion - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the Windows Windows Remote Auto Dialer, rasautou.exe executing an arbitrary DLL. This technique is used to execute arbitrary shellcode or DLLs via the rasautou.exe LOLBin capability. During triage, review parent and child process behavior including file and image loads. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-02-15 -- **Author**: Michael Haag, Splunk -- **ID**: 6f42b8be-8e96-11ec-ad5a-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1055.001](https://attack.mitre.org/techniques/T1055/001/) | Dynamic-link Library Injection | Defense Evasion, Privilege Escalation | - -| [T1218](https://attack.mitre.org/techniques/T1218/) | System Binary Proxy Execution | Defense Evasion | - -| [T1055](https://attack.mitre.org/techniques/T1055/) | Process Injection | Defense Evasion, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=rasautou.exe Processes.process="* -d *"AND Processes.process="* -p *" by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.original_file_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_rasautou_dll_execution_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_rasautou_dll_execution_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -False positives will be limited to applications that require Rasautou.exe to load a DLL from disk. Filter as needed. - -#### Associated Analytic story -* [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ attempting to load a DLL in a suspicious manner. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/mandiant/DueDLLigence](https://github.com/mandiant/DueDLLigence) -* [https://github.com/MHaggis/notes/blob/master/utilities/Invoke-SPLDLLigence.ps1](https://github.com/MHaggis/notes/blob/master/utilities/Invoke-SPLDLLigence.ps1) -* [https://gist.github.com/NickTyrer/c6043e4b302d5424f701f15baf136513](https://gist.github.com/NickTyrer/c6043e4b302d5424f701f15baf136513) -* [https://www.mandiant.com/resources/staying-hidden-on-the-endpoint-evading-detection-with-shellcode](https://www.mandiant.com/resources/staying-hidden-on-the-endpoint-evading-detection-with-shellcode) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055.001/rasautou/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055.001/rasautou/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_rasautou_dll_execution.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-02-16-windows_bitsadmin_download_file.md b/docs/_posts/2022-02-16-windows_bitsadmin_download_file.md deleted file mode 100644 index 6c8c02145b..0000000000 --- a/docs/_posts/2022-02-16-windows_bitsadmin_download_file.md +++ /dev/null @@ -1,118 +0,0 @@ ---- -title: "Windows Bitsadmin Download File" -excerpt: "BITS Jobs, Ingress Tool Transfer" -categories: - - Endpoint -last_modified_at: 2022-02-16 -toc: true -toc_label: "" -tags: - - BITS Jobs - - Defense Evasion - - Persistence - - Ingress Tool Transfer - - Command & Control - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -The following query identifies Microsoft Background Intelligent Transfer Service utility `bitsadmin.exe` using the `transfer` parameter to download a remote object. In addition, look for `download` or `upload` on the command-line, the switches are not required to perform a transfer. Capture any files downloaded. Review the reputation of the IP or domain used. Typically once executed, a follow on command will be used to execute the dropped file. Note that the network connection or file modification events related will not spawn or create from `bitsadmin.exe`, but the artifacts will appear in a parallel process of `svchost.exe` with a command-line similar to `svchost.exe -k netsvcs -s BITS`. It's important to review all parallel and child processes to capture any behaviors and artifacts. In some suspicious and malicious instances, BITS jobs will be created. You can use `bitsadmin /list /verbose` to list out the jobs during investigation. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2022-02-16 -- **Author**: Michael Haag, Splunk -- **ID**: d76e8188-8f5a-11ec-ace4-acde48001122 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1197](https://attack.mitre.org/techniques/T1197/) | BITS Jobs | Defense Evasion, Persistence | - -| [T1105](https://attack.mitre.org/techniques/T1105/) | Ingress Tool Transfer | Command And Control | - -#### Search - -``` - -| from read_ssa_enriched_events() -| where "Endpoint_Processes" IN(_datamodels) -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line IS NOT NULL AND process_name IS NOT NULL AND process_name="bitsadmin.exe" AND (like (cmd_line, "%transfer%")) -| eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)) -| eval body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) -| into write_ssa_detected_events(); -``` - -#### Macros -The SPL above uses the following Macros: - -Note that `windows_bitsadmin_download_file_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* dest_device_id -* process_name -* parent_process_name -* process_path -* dest_user_id -* process -* cmd_line - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Limited false positives, however it may be required to filter based on parent process name or network connection. - -#### Associated Analytic story -* [Ingress Tool Transfer](/stories/ingress_tool_transfer) -* [BITS Jobs](/stories/bits_jobs) -* [DarkSide Ransomware](/stories/darkside_ransomware) -* [Living Off The Land](/stories/living_off_the_land) - - -#### Kill Chain Phase -* Exploitation - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $dest_user_id$ attempting to download a file. | - - -Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` - - - -#### Reference - -* [https://github.com/redcanaryco/atomic-red-team/blob/8eb52117b748d378325f7719554a896e37bccec7/atomics/T1105/T1105.md#atomic-test-9---windows---bitsadmin-bits-download](https://github.com/redcanaryco/atomic-red-team/blob/8eb52117b748d378325f7719554a896e37bccec7/atomics/T1105/T1105.md#atomic-test-9---windows---bitsadmin-bits-download) -* [https://github.com/redcanaryco/atomic-red-team/blob/bc705cb7aaa5f26f2d96585fac8e4c7052df0ff9/atomics/T1197/T1197.md](https://github.com/redcanaryco/atomic-red-team/blob/bc705cb7aaa5f26f2d96585fac8e4c7052df0ff9/atomics/T1197/T1197.md) -* [https://docs.microsoft.com/en-us/windows/win32/bits/bitsadmin-tool](https://docs.microsoft.com/en-us/windows/win32/bits/bitsadmin-tool) -* [https://thedfirreport.com/2021/03/29/sodinokibi-aka-revil-ransomware/](https://thedfirreport.com/2021/03/29/sodinokibi-aka-revil-ransomware/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1197/atomic_red_team/bits-windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1197/atomic_red_team/bits-windows-security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_bitsadmin_download_file.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-02-16-windows_certutil_decode_file.md b/docs/_posts/2022-02-16-windows_certutil_decode_file.md deleted file mode 100644 index b31f7362a1..0000000000 --- a/docs/_posts/2022-02-16-windows_certutil_decode_file.md +++ /dev/null @@ -1,111 +0,0 @@ ---- -title: "Windows CertUtil Decode File" -excerpt: "Deobfuscate/Decode Files or Information" -categories: - - Endpoint -last_modified_at: 2022-02-16 -toc: true -toc_label: "" -tags: - - Deobfuscate/Decode Files or Information - - Defense Evasion - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -CertUtil.exe may be used to `encode` and `decode` a file, including PE and script code. Encoding will convert a file to base64 with `-----BEGIN CERTIFICATE-----` and `-----END CERTIFICATE-----` tags. Malicious usage will include decoding a encoded file that was downloaded. Once decoded, it will be loaded by a parallel process. Note that there are two additional command switches that may be used - `encodehex` and `decodehex`. Similarly, the file will be encoded in HEX and later decoded for further execution. During triage, identify the source of the file being decoded. Review its contents or execution behavior for further analysis. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2022-02-16 -- **Author**: Michael Haag, Splunk -- **ID**: b06983f4-8f72-11ec-ab50-acde48001122 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1140](https://attack.mitre.org/techniques/T1140/) | Deobfuscate/Decode Files or Information | Defense Evasion | - -#### Search - -``` - -| from read_ssa_enriched_events() -| where "Endpoint_Processes" IN(_datamodels) -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line IS NOT NULL AND process_name IS NOT NULL AND process_name="certutil.exe" AND (like (cmd_line, "%decode%")) -| eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)) -| eval body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) -| into write_ssa_detected_events(); -``` - -#### Macros -The SPL above uses the following Macros: - -Note that `windows_certutil_decode_file_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* dest_device_id -* process_name -* parent_process_name -* process_path -* dest_user_id -* process -* cmd_line - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Typically seen used to `encode` files, but it is possible to see legitimate use of `decode`. Filter based on parent-child relationship, file paths, endpoint or user. - -#### Associated Analytic story -* [Deobfuscate-Decode Files or Information](/stories/deobfuscate-decode_files_or_information) -* [Living Off The Land](/stories/living_off_the_land) - - -#### Kill Chain Phase -* Exploitation - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 40.0 | 50 | 80 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$ attempting to decode a file on disk. | - - -Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` - - - -#### Reference - -* [https://attack.mitre.org/techniques/T1140/](https://attack.mitre.org/techniques/T1140/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1140/T1140.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1140/T1140.md) -* [https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/certutil](https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/certutil) -* [https://www.bleepingcomputer.com/news/security/certutilexe-could-allow-attackers-to-download-malware-while-bypassing-av/](https://www.bleepingcomputer.com/news/security/certutilexe-could-allow-attackers-to-download-malware-while-bypassing-av/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/ master/datasets/attack_techniques/T1140/atomic_red_team/encode-windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/ master/datasets/attack_techniques/T1140/atomic_red_team/encode-windows-security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_certutil_decode_file.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-02-16-windows_certutil_urlcache_download.md b/docs/_posts/2022-02-16-windows_certutil_urlcache_download.md deleted file mode 100644 index 686ea244a2..0000000000 --- a/docs/_posts/2022-02-16-windows_certutil_urlcache_download.md +++ /dev/null @@ -1,111 +0,0 @@ ---- -title: "Windows CertUtil URLCache Download" -excerpt: "Ingress Tool Transfer" -categories: - - Endpoint -last_modified_at: 2022-02-16 -toc: true -toc_label: "" -tags: - - Ingress Tool Transfer - - Command & Control - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Certutil.exe may download a file from a remote destination using `-urlcache`. This behavior does require a URL to be passed on the command-line. In addition, `-f` (force) and `-split` (Split embedded ASN.1 elements, and save to files) will be used. It is not entirely common for `certutil.exe` to contact public IP space. However, it is uncommon for `certutil.exe` to write files to world writeable paths.\ During triage, capture any files on disk and review. Review the reputation of the remote IP or domain in question. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2022-02-16 -- **Author**: Michael Haag, Splunk -- **ID**: 8cb1ad38-8f6d-11ec-87a3-acde48001122 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1105](https://attack.mitre.org/techniques/T1105/) | Ingress Tool Transfer | Command And Control | - -#### Search - -``` - -| from read_ssa_enriched_events() -| where "Endpoint_Processes" IN(_datamodels) -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line IS NOT NULL AND process_name IS NOT NULL AND process_name="certutil.exe" AND (like (cmd_line, "%urlcache%") AND like (cmd_line, "%split%")) OR (like (cmd_line, "%urlcache%")) -| eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)) -| eval body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) -| into write_ssa_detected_events(); -``` - -#### Macros -The SPL above uses the following Macros: - -Note that `windows_certutil_urlcache_download_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* dest_device_id -* process_name -* parent_process_name -* process_path -* dest_user_id -* process -* cmd_line - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Limited false positives in most environments, however tune as needed based on parent-child relationship or network connection. - -#### Associated Analytic story -* [Ingress Tool Transfer](/stories/ingress_tool_transfer) -* [DarkSide Ransomware](/stories/darkside_ransomware) -* [Living Off The Land](/stories/living_off_the_land) - - -#### Kill Chain Phase -* Exploitation - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 90.0 | 90 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$ attempting to download a file. | - - -Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` - - - -#### Reference - -* [https://attack.mitre.org/techniques/T1105/](https://attack.mitre.org/techniques/T1105/) -* [https://www.avira.com/en/blog/certutil-abused-by-attackers-to-spread-threats](https://www.avira.com/en/blog/certutil-abused-by-attackers-to-spread-threats) -* [https://www.fireeye.com/blog/threat-research/2019/10/certutil-qualms-they-came-to-drop-fombs.html](https://www.fireeye.com/blog/threat-research/2019/10/certutil-qualms-they-came-to-drop-fombs.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1105/atomic_red_team/T1105-windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1105/atomic_red_team/T1105-windows-security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_certutil_urlcache_download.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-02-16-windows_certutil_verifyctl_download.md b/docs/_posts/2022-02-16-windows_certutil_verifyctl_download.md deleted file mode 100644 index 9d4948a7a1..0000000000 --- a/docs/_posts/2022-02-16-windows_certutil_verifyctl_download.md +++ /dev/null @@ -1,112 +0,0 @@ ---- -title: "Windows CertUtil VerifyCtl Download" -excerpt: "Ingress Tool Transfer" -categories: - - Endpoint -last_modified_at: 2022-02-16 -toc: true -toc_label: "" -tags: - - Ingress Tool Transfer - - Command & Control - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Certutil.exe may download a file from a remote destination using `-VerifyCtl`. This behavior does require a URL to be passed on the command-line. In addition, `-f` (force) and `-split` (Split embedded ASN.1 elements, and save to files) will be used. It is not entirely common for `certutil.exe` to contact public IP space. \ During triage, capture any files on disk and review. Review the reputation of the remote IP or domain in question. Using `-VerifyCtl`, the file will either be written to the current working directory or `%APPDATA%\..\LocalLow\Microsoft\CryptnetUrlCache\Content\<hash>`. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2022-02-16 -- **Author**: Michael Haag, Splunk -- **ID**: 9ac29c40-8f6b-11ec-b19a-acde48001122 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1105](https://attack.mitre.org/techniques/T1105/) | Ingress Tool Transfer | Command And Control | - -#### Search - -``` - -| from read_ssa_enriched_events() -| where "Endpoint_Processes" IN(_datamodels) -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line IS NOT NULL AND process_name IS NOT NULL AND process_name="certutil.exe" AND (like (cmd_line, "%verifyctl%") AND like (cmd_line, "%split%")) OR (like (cmd_line, "%verifyctl%")) -| eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)) -| eval body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) -| into write_ssa_detected_events(); -``` - -#### Macros -The SPL above uses the following Macros: - -Note that `windows_certutil_verifyctl_download_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* dest_device_id -* process_name -* parent_process_name -* process_path -* dest_user_id -* process -* cmd_line - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Limited false positives in most environments, however tune as needed based on parent-child relationship or network connection. - -#### Associated Analytic story -* [Ingress Tool Transfer](/stories/ingress_tool_transfer) -* [DarkSide Ransomware](/stories/darkside_ransomware) -* [Living Off The Land](/stories/living_off_the_land) - - -#### Kill Chain Phase -* Exploitation - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 90.0 | 90 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$ attempting to download a file. | - - -Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` - - - -#### Reference - -* [https://attack.mitre.org/techniques/T1105/](https://attack.mitre.org/techniques/T1105/) -* [https://www.hexacorn.com/blog/2020/08/23/certutil-one-more-gui-lolbin/](https://www.hexacorn.com/blog/2020/08/23/certutil-one-more-gui-lolbin/) -* [https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-R2-and-2012/cc732443(v=ws.11)#-verifyctl](https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-R2-and-2012/cc732443(v=ws.11)#-verifyctl) -* [https://www.avira.com/en/blog/certutil-abused-by-attackers-to-spread-threats](https://www.avira.com/en/blog/certutil-abused-by-attackers-to-spread-threats) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1105/atomic_red_team/T1105-windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1105/atomic_red_team/T1105-windows-security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_certutil_verifyctl_download.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-02-16-windows_powershell_start-bitstransfer.md b/docs/_posts/2022-02-16-windows_powershell_start-bitstransfer.md deleted file mode 100644 index 2e9ec6d465..0000000000 --- a/docs/_posts/2022-02-16-windows_powershell_start-bitstransfer.md +++ /dev/null @@ -1,114 +0,0 @@ ---- -title: "Windows PowerShell Start-BitsTransfer" -excerpt: "BITS Jobs, Ingress Tool Transfer" -categories: - - Endpoint -last_modified_at: 2022-02-16 -toc: true -toc_label: "" -tags: - - BITS Jobs - - Defense Evasion - - Persistence - - Ingress Tool Transfer - - Command & Control - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Start-BitsTransfer is the PowerShell "version" of BitsAdmin.exe. Similar functionality is present. This technique variation is not as commonly used by adversaries, but has been abused in the past. Lesser known uses include the ability to set the `-TransferType` to `Upload` for exfiltration of files. In an instance where `Upload` is used, it is highly possible files will be archived. During triage, review parallel processes and process lineage. Capture any files on disk and review. For the remote domain or IP, what is the reputation? - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2022-02-16 -- **Author**: Michael Haag, Splunk -- **ID**: 0bafd086-8f61-11ec-996e-acde48001122 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1197](https://attack.mitre.org/techniques/T1197/) | BITS Jobs | Defense Evasion, Persistence | - -| [T1105](https://attack.mitre.org/techniques/T1105/) | Ingress Tool Transfer | Command And Control | - -#### Search - -``` - -| from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line IS NOT NULL AND process_name IS NOT NULL -| where process_name="pwsh.exe" OR process_name="pwsh.exe" OR process_name="sqlps.exe" OR process_name="sqltoolsps.exe" OR process_name="powershell.exe" OR process_name="powershell_ise.exe" -| where (like (cmd_line, "%start-bitstransfer%")) -| eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) -| into write_ssa_detected_events(); -``` - -#### Macros -The SPL above uses the following Macros: - -Note that `windows_powershell_start-bitstransfer_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* dest_device_id -* process_name -* parent_process_name -* process_path -* dest_user_id -* process -* cmd_line - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint_Processess` datamodel. - -#### Known False Positives -Limited false positives. It is possible administrators will utilize Start-BitsTransfer for administrative tasks, otherwise filter based parent process or command-line arguments. - -#### Associated Analytic story -* [BITS Jobs](/stories/bits_jobs) -* [Living Off The Land](/stories/living_off_the_land) - - -#### Kill Chain Phase -* Exploitation - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $dest_user_id$ attempting to download a file. | - - -Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` - - - -#### Reference - -* [https://isc.sans.edu/diary/Investigating+Microsoft+BITS+Activity/23281](https://isc.sans.edu/diary/Investigating+Microsoft+BITS+Activity/23281) -* [https://docs.microsoft.com/en-us/windows/win32/bits/using-windows-powershell-to-create-bits-transfer-jobs](https://docs.microsoft.com/en-us/windows/win32/bits/using-windows-powershell-to-create-bits-transfer-jobs) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1197/atomic_red_team/T1197_windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1197/atomic_red_team/T1197_windows-security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_powershell_start-bitstransfer.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-02-17-tcp_command_and_scripting_interpreter_outbound_ldap_traffic.md b/docs/_posts/2022-02-17-tcp_command_and_scripting_interpreter_outbound_ldap_traffic.md deleted file mode 100644 index a8d3a0fb39..0000000000 --- a/docs/_posts/2022-02-17-tcp_command_and_scripting_interpreter_outbound_ldap_traffic.md +++ /dev/null @@ -1,108 +0,0 @@ ---- -title: "TCP Command and Scripting Interpreter Outbound LDAP Traffic" -excerpt: "Command and Scripting Interpreter" -categories: - - Network -last_modified_at: 2022-02-17 -toc: true -toc_label: "" -tags: - - Command and Scripting Interpreter - - Execution - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Malicious actors often abuse misconfigured LDAP servers or applications that use the LDAP servers in organizations. Outbound LDAP traffic should not be allowed outbound through your perimeter firewall. This search will help determine if you have any LDAP connections to IP addresses outside of private (RFC1918) address space. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2022-02-17 -- **Author**: Jose Hernandez, Michael Haag, Splunk -- **ID**: 4d16a90c-d1a9-4d17-8156-d0db0c73c449 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -#### Search - -``` - -| from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), dest_port=map_get(input_event, "dest_port"), event_id=ucast(map_get(input_event, "event_id"), "string", null), dest_ip=ucast(map_get(input_event, "dest_device_ips"), "collection", [])[0] -| where dest_port=389 OR dest_port=1389 OR dest_port=636 -| where NOT (cidrmatch(ip: dest_ip, cidr_range: "10.0.0.0/8") OR cidrmatch(ip: dest_ip, cidr_range: "192.168.0.0/16") OR cidrmatch(ip: dest_ip, cidr_range: "172.16.0.0/12")) -| eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "dest_port", dest_port, "dest_ip", dest_ip]) -| into write_ssa_detected_events(); -``` - -#### Macros -The SPL above uses the following Macros: - -Note that `tcp_command_and_scripting_interpreter_outbound_ldap_traffic_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* dest_device_id -* process_name -* parent_process_name -* process_path -* dest_user_id -* process -* cmd_line - - -#### How To Implement -To successfully implement this search you need to be ingesting information on network traffic, specifically data that populates the Network_Traffic datamodel. To develop this analytic we used specifically Zeek/Bro conn.log and PAN Traffic events. - -#### Known False Positives -Unknown at this moment. Outbound LDAP traffic should not be allowed outbound through your perimeter firewall. Please check those servers to verify if the activity is legitimate. - -#### Associated Analytic story -* [Log4Shell CVE-2021-44228](/stories/log4shell_cve-2021-44228) - - -#### Kill Chain Phase -* Execution - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 35.0 | 50 | 70 | An outbound LDAP connection from $src_ip$ in your infrastructure connecting to dest ip $dest_ip$ | - - -Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` - - - -#### Reference - -* [https://www.govcert.ch/blog/zero-day-exploit-targeting-popular-java-library-log4j/](https://www.govcert.ch/blog/zero-day-exploit-targeting-popular-java-library-log4j/) -* [https://www.splunk.com/en_us/blog/security/simulating-detecting-and-responding-to-log4shell-with-splunk.html](https://www.splunk.com/en_us/blog/security/simulating-detecting-and-responding-to-log4shell-with-splunk.html) -* [https://www.cisa.gov/uscert/ncas/alerts/aa21-356a](https://www.cisa.gov/uscert/ncas/alerts/aa21-356a) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059/log4shell_ldap_traffic/pantraffic.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059/log4shell_ldap_traffic/pantraffic.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/network/tcp_command_and_scripting_interpreter_outbound_ldap_traffic.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-02-17-windows_disable_notification_center.md b/docs/_posts/2022-02-17-windows_disable_notification_center.md deleted file mode 100644 index 5566bb8bc7..0000000000 --- a/docs/_posts/2022-02-17-windows_disable_notification_center.md +++ /dev/null @@ -1,167 +0,0 @@ ---- -title: "Windows Disable Notification Center" -excerpt: "Modify Registry -" -categories: - - Endpoint -last_modified_at: 2022-02-17 -toc: true -toc_label: "" -tags: - - Modify Registry - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following search identifies a modification of registry to disable the windows notification center feature in a windows host machine. This registry modification removes notification and action center from the notification area on the task bar. This modification are seen in RAT malware to cover their tracks upon downloading other of its component or other payload. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-02-17 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 1cd983c8-8fd6-11ec-a09d-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1112](https://attack.mitre.org/techniques/T1112/) | Modify Registry | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_value_name= "DisableNotificationCenter" Registry.registry_value_data = "0x00000001" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_key_name Registry.process_guid Registry.registry_value_data -| `drop_dm_object_name(Registry)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] -| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name -| `windows_disable_notification_center_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_disable_notification_center_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.registry_key_name -* Registry.registry_path -* Registry.user -* Registry.dest -* Registry.registry_value_nam - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. - -#### Known False Positives -admin or user may choose to disable this windows features. - -#### Associated Analytic story -* [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics) -* [Windows Registry Abuse](/stories/windows_registry_abuse) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 48.0 | 60 | 80 | The Windows notification center was disabled on $dest$ by $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://tccontre.blogspot.com/2020/01/remcos-rat-evading-windows-defender-av.html](https://tccontre.blogspot.com/2020/01/remcos-rat-evading-windows-defender-av.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1112/disable_notif_center/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1112/disable_notif_center/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_disable_notification_center.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-02-17-windows_diskshadow_proxy_execution.md b/docs/_posts/2022-02-17-windows_diskshadow_proxy_execution.md deleted file mode 100644 index fb756097e7..0000000000 --- a/docs/_posts/2022-02-17-windows_diskshadow_proxy_execution.md +++ /dev/null @@ -1,107 +0,0 @@ ---- -title: "Windows Diskshadow Proxy Execution" -excerpt: "Signed Binary Proxy Execution" -categories: - - Endpoint -last_modified_at: 2022-02-17 -toc: true -toc_label: "" -tags: - - Signed Binary Proxy Execution - - Defense Evasion - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -DiskShadow.exe is a Microsoft Signed binary present on Windows Server. It has a scripting mode intended for complex scripted backup operations. This feature also allows for execution of arbitrary unsigned code. This analytic looks for the usage of the scripting mode flags in executions of DiskShadow. During triage, compare to known backup behavior in your environment and then review the scripts called by diskshadow. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2022-02-17 -- **Author**: Lou Stella, Splunk -- **ID**: aa502688-9037-11ec-842d-acde48001122 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | - -#### Search - -``` - -| from read_ssa_enriched_events() -| where "Endpoint_Processes" IN(_datamodels) -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line IS NOT NULL AND process_name IS NOT NULL AND process_name="diskshadow.exe" AND (like (cmd_line, "%-s%") OR like (cmd_line, "%/s%")) -| eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)) -| eval body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) -| into write_ssa_detected_events(); -``` - -#### Macros -The SPL above uses the following Macros: - -Note that `windows_diskshadow_proxy_execution_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* dest_device_id -* process_name -* parent_process_name -* process_path -* dest_user_id -* process -* cmd_line - - -#### How To Implement -To successfully implement this search you need to be ingesting information on processes that include the name of the process responsible for the changes from your endpoints into the `Endpoint_Processess` datamodel. - -#### Known False Positives -Administrators using the DiskShadow tool in their infrastructure as a main backup tool with scripts will cause false positives - -#### Associated Analytic story -* [Living Off The Land](/stories/living_off_the_land) - - -#### Kill Chain Phase -* Exploitation - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$ attempting to run a script. | - - -Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` - - - -#### Reference - -* [https://bohops.com/2018/03/26/diskshadow-the-return-of-vss-evasion-persistence-and-active-directory-database-extraction/](https://bohops.com/2018/03/26/diskshadow-the-return-of-vss-evasion-persistence-and-active-directory-database-extraction/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218/diskshadow/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218/diskshadow/windows-security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_diskshadow_proxy_execution.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-02-17-windows_raw_access_to_master_boot_record_drive.md b/docs/_posts/2022-02-17-windows_raw_access_to_master_boot_record_drive.md deleted file mode 100644 index 39f2b80d72..0000000000 --- a/docs/_posts/2022-02-17-windows_raw_access_to_master_boot_record_drive.md +++ /dev/null @@ -1,174 +0,0 @@ ---- -title: "Windows Raw Access To Master Boot Record Drive" -excerpt: "Disk Structure Wipe -, Disk Wipe -" -categories: - - Endpoint -last_modified_at: 2022-02-17 -toc: true -toc_label: "" -tags: - - Disk Structure Wipe - - Disk Wipe - - Impact - - Impact - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to look for suspicious raw access read to drive where the master boot record is placed. This technique was seen in several attacks by adversaries or threat actor to wipe, encrypt or overwrite the master boot record code as part of their impact payload. This detection is a good indicator that there is a process try to read or write on MBR sector. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-02-17 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 7b83f666-900c-11ec-a2d9-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1561.002](https://attack.mitre.org/techniques/T1561/002/) | Disk Structure Wipe | Impact | - -| [T1561](https://attack.mitre.org/techniques/T1561/) | Disk Wipe | Impact | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventCode=9 Device = \\Device\\Harddisk0\\DR0 NOT (Image IN("*\\Windows\\System32\\*", "*\\Windows\\SysWOW64\\*")) -| stats count min(_time) as firstTime max(_time) as lastTime by Computer Image Device ProcessGuid ProcessId EventDescription EventCode -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_raw_access_to_master_boot_record_drive_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **windows_raw_access_to_master_boot_record_drive_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Computer -* Image -* Device -* ProcessGuid -* ProcessId -* EventDescription -* EventCode - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the raw access read event (like sysmon eventcode 9), process name and process guid from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -This event is really notable but we found minimal number of normal application from system32 folder like svchost.exe accessing it too. In this case we used 'system32' and 'syswow64' path as a filter for this detection. - -#### Associated Analytic story -* [Data Destruction](/stories/data_destruction) -* [Caddy Wiper](/stories/caddy_wiper) -* [WhisperGate](/stories/whispergate) -* [Hermetic Wiper](/stories/hermetic_wiper) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 90.0 | 90 | 100 | process accessing MBR $device$ in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.splunk.com/en_us/blog/security/threat-advisory-strt-ta02-destructive-software.html](https://www.splunk.com/en_us/blog/security/threat-advisory-strt-ta02-destructive-software.html) -* [https://www.crowdstrike.com/blog/technical-analysis-of-whispergate-malware/](https://www.crowdstrike.com/blog/technical-analysis-of-whispergate-malware/) -* [https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/](https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1561.002/mbr_raw_access/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1561.002/mbr_raw_access/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_raw_access_to_master_boot_record_drive.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-02-18-detect_regasm_with_network_connection.md b/docs/_posts/2022-02-18-detect_regasm_with_network_connection.md deleted file mode 100644 index 51d1e73d56..0000000000 --- a/docs/_posts/2022-02-18-detect_regasm_with_network_connection.md +++ /dev/null @@ -1,172 +0,0 @@ ---- -title: "Detect Regasm with Network Connection" -excerpt: "System Binary Proxy Execution -, Regsvcs/Regasm -" -categories: - - Endpoint -last_modified_at: 2022-02-18 -toc: true -toc_label: "" -tags: - - System Binary Proxy Execution - - Regsvcs/Regasm - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies regasm.exe with a network connection to a public IP address, exluding private IP space. This particular technique has been used in the wild to bypass application control products. Regasm.exe and Regsvcs.exe are signed by Microsoft. By contacting a remote command and control server, the adversary will have the ability to escalate privileges and complete the objectives. During investigation, identify and retrieve the content being loaded. Review parallel processes for additional suspicious behavior. Gather any other file modifications and review accordingly. Review the reputation of the remote IP or domain and block as needed. regsvcs.exe and regasm.exe are natively found in C:\Windows\Microsoft.NET\Framework\v*\regasm|regsvcs.exe and C:\Windows\Microsoft.NET\Framework64\v*\regasm|regsvcs.exe. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-02-18 -- **Author**: Michael Haag, Splunk -- **ID**: 07921114-6db4-4e2e-ae58-3ea8a52ae93f - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218](https://attack.mitre.org/techniques/T1218/) | System Binary Proxy Execution | Defense Evasion | - -| [T1218.009](https://attack.mitre.org/techniques/T1218/009/) | Regsvcs/Regasm | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventID=3 dest_ip!=10.0.0.0/12 dest_ip!=172.16.0.0/12 dest_ip!=192.168.0.0/16 process_name=regasm.exe -| rename Computer as dest -| stats count min(_time) as firstTime max(_time) as lastTime by dest, user, process_name, src_ip, dest_ip -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_regasm_with_network_connection_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **detect_regasm_with_network_connection_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventID -* dest_ip -* process_name -* Computer -* user -* src_ip -* dest_host -* dest_ip - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -Although unlikely, limited instances of regasm.exe with a network connection may cause a false positive. Filter based endpoint usage, command line arguments, or process lineage. - -#### Associated Analytic story -* [Suspicious Regsvcs Regasm Activity](/stories/suspicious_regsvcs_regasm_activity) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | An instance of $process_name$ contacting a remote destination was identified on endpoint $Computer$ by user $user$. This behavior is not normal for $process_name$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1218/009/](https://attack.mitre.org/techniques/T1218/009/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.009/T1218.009.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.009/T1218.009.md) -* [https://lolbas-project.github.io/lolbas/Binaries/Regasm/](https://lolbas-project.github.io/lolbas/Binaries/Regasm/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.009/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.009/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/detect_regasm_with_network_connection.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-02-18-detect_regsvcs_with_network_connection.md b/docs/_posts/2022-02-18-detect_regsvcs_with_network_connection.md deleted file mode 100644 index 663285a202..0000000000 --- a/docs/_posts/2022-02-18-detect_regsvcs_with_network_connection.md +++ /dev/null @@ -1,171 +0,0 @@ ---- -title: "Detect Regsvcs with Network Connection" -excerpt: "System Binary Proxy Execution -, Regsvcs/Regasm -" -categories: - - Endpoint -last_modified_at: 2022-02-18 -toc: true -toc_label: "" -tags: - - System Binary Proxy Execution - - Regsvcs/Regasm - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies Regsvcs.exe with a network connection to a public IP address, exluding private IP space. This particular technique has been used in the wild to bypass application control products. Regasm.exe and Regsvcs.exe are signed by Microsoft. By contacting a remote command and control server, the adversary will have the ability to escalate privileges and complete the objectives. During investigation, identify and retrieve the content being loaded. Review parallel processes for additional suspicious behavior. Gather any other file modifications and review accordingly. Review the reputation of the remote IP or domain and block as needed. regsvcs.exe and regasm.exe are natively found in C:\Windows\Microsoft.NET\Framework\v*\regasm|regsvcs.exe and C:\Windows\Microsoft.NET\Framework64\v*\regasm|regsvcs.exe. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-02-18 -- **Author**: Michael Haag, Splunk -- **ID**: e3e7a1c0-f2b9-445c-8493-f30a63522d1a - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218](https://attack.mitre.org/techniques/T1218/) | System Binary Proxy Execution | Defense Evasion | - -| [T1218.009](https://attack.mitre.org/techniques/T1218/009/) | Regsvcs/Regasm | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventID=3 dest_ip!=10.0.0.0/12 dest_ip!=172.16.0.0/12 dest_ip!=192.168.0.0/16 process_name=regsvcs.exe -| rename Computer as dest -| stats count min(_time) as firstTime max(_time) as lastTime by dest, user, process_name, src_ip, dest_ip -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_regsvcs_with_network_connection_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **detect_regsvcs_with_network_connection_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventID -* dest_ip -* process_name -* Computer -* user -* src_ip -* dest_host - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -Although unlikely, limited instances of regsvcs.exe may cause a false positive. Filter based endpoint usage, command line arguments, or process lineage. - -#### Associated Analytic story -* [Suspicious Regsvcs Regasm Activity](/stories/suspicious_regsvcs_regasm_activity) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | An instance of $process_name$ contacting a remote destination was identified on endpoint $Computer$ by user $user$. This behavior is not normal for $process_name$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1218/009/](https://attack.mitre.org/techniques/T1218/009/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.009/T1218.009.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.009/T1218.009.md) -* [https://lolbas-project.github.io/lolbas/Binaries/Regsvcs/](https://lolbas-project.github.io/lolbas/Binaries/Regsvcs/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.009/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.009/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/detect_regsvcs_with_network_connection.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-02-18-disabled_kerberos_pre-authentication_discovery_with_powerview.md b/docs/_posts/2022-02-18-disabled_kerberos_pre-authentication_discovery_with_powerview.md deleted file mode 100644 index 3c247d1e0f..0000000000 --- a/docs/_posts/2022-02-18-disabled_kerberos_pre-authentication_discovery_with_powerview.md +++ /dev/null @@ -1,160 +0,0 @@ ---- -title: "Disabled Kerberos Pre-Authentication Discovery With PowerView" -excerpt: "Steal or Forge Kerberos Tickets -, AS-REP Roasting -" -categories: - - Endpoint -last_modified_at: 2022-02-18 -toc: true -toc_label: "" -tags: - - Steal or Forge Kerberos Tickets - - AS-REP Roasting - - Credential Access - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-DomainUser` commandlet with specific parameters. `Get-DomainUser` is part of PowerView, a PowerShell tool used to perform enumeration on Windows Active Directory networks. As the name suggests, `Get-DomainUser` is used to identify domain users and combining it with `-PreauthNotRequired` allows adversaries to discover domain accounts with Kerberos Pre Authentication disabled.\ Red Teams and adversaries alike use may leverage PowerView to enumerate these accounts and attempt to crack their passwords offline. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-02-18 -- **Author**: Mauricio Velazco, Splunk -- **ID**: b0b34e2c-90de-11ec-baeb-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1558](https://attack.mitre.org/techniques/T1558/) | Steal or Forge Kerberos Tickets | Credential Access | - -| [T1558.004](https://attack.mitre.org/techniques/T1558/004/) | AS-REP Roasting | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - `powershell` EventCode=4104 (Message = "*Get-DomainUser*" AND Message="*PreauthNotRequired*") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `disabled_kerberos_pre_authentication_discovery_with_powerview_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **disabled_kerberos_pre-authentication_discovery_with_powerview_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Message -* ComputerName -* User - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -Administrators or power users may use PowerView for troubleshooting - -#### Associated Analytic story -* [Active Directory Kerberos Attacks](/stories/active_directory_kerberos_attacks) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 54.0 | 60 | 90 | Disabled Kerberos Pre-Authentication Discovery With PowerView from $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1558/004/](https://attack.mitre.org/techniques/T1558/004/) -* [https://m0chan.github.io/2019/07/31/How-To-Attack-Kerberos-101.html](https://m0chan.github.io/2019/07/31/How-To-Attack-Kerberos-101.html) -* [https://stealthbits.com/blog/cracking-active-directory-passwords-with-as-rep-roasting/](https://stealthbits.com/blog/cracking-active-directory-passwords-with-as-rep-roasting/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1558.004/powerview/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1558.004/powerview/windows-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disabled_kerberos_pre_authentication_discovery_with_powerview.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-02-18-interactive_session_on_remote_endpoint_with_powershell.md b/docs/_posts/2022-02-18-interactive_session_on_remote_endpoint_with_powershell.md deleted file mode 100644 index 4f3d05ca85..0000000000 --- a/docs/_posts/2022-02-18-interactive_session_on_remote_endpoint_with_powershell.md +++ /dev/null @@ -1,155 +0,0 @@ ---- -title: "Interactive Session on Remote Endpoint with PowerShell" -excerpt: "Remote Services -, Windows Remote Management -" -categories: - - Endpoint -last_modified_at: 2022-02-18 -toc: true -toc_label: "" -tags: - - Remote Services - - Windows Remote Management - - Lateral Movement - - Lateral Movement - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the usage of the `Enter-PSSession`. This commandlet can be used to open an interactive session on a remote endpoint leveraging the WinRM protocol. Red Teams and adversaries alike may abuse WinRM and `Enter-PSSession` for lateral movement and remote code execution. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-02-18 -- **Author**: Mauricio Velazco, Splunk -- **ID**: a4e8f3a4-48b2-11ec-bcfc-3e22fbd008af - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1021](https://attack.mitre.org/techniques/T1021/) | Remote Services | Lateral Movement | - -| [T1021.006](https://attack.mitre.org/techniques/T1021/006/) | Windows Remote Management | Lateral Movement | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 (Message="*Enter-PSSession*" AND Message="*-ComputerName*") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `interactive_session_on_remote_endpoint_with_powershell_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -Note that **interactive_session_on_remote_endpoint_with_powershell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Message -* ComputerName -* User - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup instructions can be found https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -Administrators may leverage WinRM and `Enter-PSSession` for administrative and troubleshooting tasks. This activity is usually limited to a small set of hosts or users. In certain environments, tuning may not be possible. - -#### Associated Analytic story -* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 45.0 | 90 | 50 | An interactive session was opened on a remote endpoint from $ComputerName | - - -#### Reference - -* [https://attack.mitre.org/techniques/T1021/006/](https://attack.mitre.org/techniques/T1021/006/) -* [https://docs.microsoft.com/en-us/powershell/module/microsoft.powershell.core/enter-pssession?view=powershell-7.2](https://docs.microsoft.com/en-us/powershell/module/microsoft.powershell.core/enter-pssession?view=powershell-7.2) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021.006/lateral_movement_pssession/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021.006/lateral_movement_pssession/windows-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/interactive_session_on_remote_endpoint_with_powershell.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-02-18-net_profiler_uac_bypass.md b/docs/_posts/2022-02-18-net_profiler_uac_bypass.md deleted file mode 100644 index 1cf612c716..0000000000 --- a/docs/_posts/2022-02-18-net_profiler_uac_bypass.md +++ /dev/null @@ -1,163 +0,0 @@ ---- -title: "NET Profiler UAC bypass" -excerpt: "Bypass User Account Control -, Abuse Elevation Control Mechanism -" -categories: - - Endpoint -last_modified_at: 2022-02-18 -toc: true -toc_label: "" -tags: - - Bypass User Account Control - - Abuse Elevation Control Mechanism - - Defense Evasion - - Privilege Escalation - - Defense Evasion - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect modification of registry to bypass UAC windows feature. This technique is to add a payload dll path on .NET COR file path that will be loaded by mmc.exe as soon it was executed. This detection rely on monitoring the registry key and values in the detection area. It may happened that windows update some dll related to mmc.exe and add dll path in this registry. In this case filtering is needed. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-02-18 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 0252ca80-e30d-11eb-8aa3-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1548.002](https://attack.mitre.org/techniques/T1548/002/) | Bypass User Account Control | Defense Evasion, Privilege Escalation | - -| [T1548](https://attack.mitre.org/techniques/T1548/) | Abuse Elevation Control Mechanism | Defense Evasion, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*\\Environment\\COR_PROFILER_PATH" Registry.registry_value_data = "*.dll" by Registry.registry_path Registry.registry_key_name Registry.registry_value_data Registry.dest -| `drop_dm_object_name(Registry)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `net_profiler_uac_bypass_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **net_profiler_uac_bypass_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.registry_path -* Registry.registry_key_name -* Registry.registry_value_name -* Registry.dest - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. - -#### Known False Positives -limited false positive. It may trigger by some windows update that will modify this registry. - -#### Associated Analytic story -* [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 63.0 | 70 | 90 | Suspicious modification of registry $registry_path$ with possible payload path $registry_value_name$ in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://offsec.almond.consulting/UAC-bypass-dotnet.html](https://offsec.almond.consulting/UAC-bypass-dotnet.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/uac_bypass/windows-sysmon2.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/uac_bypass/windows-sysmon2.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/net_profiler_uac_bypass.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-02-18-o365_excessive_authentication_failures_alert.md b/docs/_posts/2022-02-18-o365_excessive_authentication_failures_alert.md deleted file mode 100644 index 9552bd6766..0000000000 --- a/docs/_posts/2022-02-18-o365_excessive_authentication_failures_alert.md +++ /dev/null @@ -1,157 +0,0 @@ ---- -title: "O365 Excessive Authentication Failures Alert" -excerpt: "Brute Force -" -categories: - - Cloud -last_modified_at: 2022-02-18 -toc: true -toc_label: "" -tags: - - Brute Force - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search detects when an excessive number of authentication failures occur this search also includes attempts against MFA prompt codes - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-02-18 -- **Author**: Rod Soto, Splunk -- **ID**: d441364c-349c-453b-b55f-12eccab67cf9 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1110](https://attack.mitre.org/techniques/T1110/) | Brute Force | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`o365_management_activity` Workload=AzureActiveDirectory UserAuthenticationMethod=* status=failure -| stats count earliest(_time) AS firstTime latest(_time) AS lastTime values(UserAuthenticationMethod) AS UserAuthenticationMethod values(UserAgent) AS UserAgent values(status) AS status values(src_ip) AS src_ip by user -| where count > 10 -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `o365_excessive_authentication_failures_alert_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [o365_management_activity](https://github.com/splunk/security_content/blob/develop/macros/o365_management_activity.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **o365_excessive_authentication_failures_alert_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Workload -* UserAuthenticationMethod -* status -* UserAgent -* src_ip -* user - - -#### How To Implement -You must install splunk Microsoft Office 365 add-on. This search works with o365:management:activity - -#### Known False Positives -The threshold for alert is above 10 attempts and this should reduce the number of false positives. - -#### Associated Analytic story -* [Office 365 Detections](/stories/office_365_detections) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 64.0 | 80 | 80 | User $user$ has caused excessive number of authentication failures from $src_ip$ using UserAgent $UserAgent$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1110/](https://attack.mitre.org/techniques/T1110/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110/o365_brute_force_login/o365_brute_force_login.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110/o365_brute_force_login/o365_brute_force_login.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-02-18-process_deleting_its_process_file_path.md b/docs/_posts/2022-02-18-process_deleting_its_process_file_path.md deleted file mode 100644 index 1e3d6d93d3..0000000000 --- a/docs/_posts/2022-02-18-process_deleting_its_process_file_path.md +++ /dev/null @@ -1,166 +0,0 @@ ---- -title: "Process Deleting Its Process File Path" -excerpt: "Indicator Removal on Host -" -categories: - - Endpoint -last_modified_at: 2022-02-18 -toc: true -toc_label: "" -tags: - - Indicator Removal on Host - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This detection is to identify a suspicious process that tries to delete the process file path related to its process. This technique is known to be defense evasion once a certain condition of malware is satisfied or not. Clop ransomware use this technique where it will try to delete its process file path using a .bat command if the keyboard layout is not the layout it tries to infect. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-02-18 -- **Author**: Teoderick Contreras -- **ID**: f7eda4bc-871c-11eb-b110-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1070](https://attack.mitre.org/techniques/T1070/) | Indicator Removal on Host | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventCode=1 CommandLine = "* /c *" CommandLine = "* del*" Image = "*\\cmd.exe" -| eval result = if(like(process,"%".parent_process."%"), "Found", "Not Found") -| stats min(_time) as firstTime max(_time) as lastTime count by Computer user ParentImage ParentCommandLine Image CommandLine EventCode ProcessID result -| where result = "Found" -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `process_deleting_its_process_file_path_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **process_deleting_its_process_file_path_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* EventCode -* Computer -* user -* ParentImage -* ParentCommandLine -* Image -* cmdline -* ProcessID -* result -* _time - - -#### How To Implement -You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Clop Ransomware](/stories/clop_ransomware) -* [Remcos](/stories/remcos) -* [WhisperGate](/stories/whispergate) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 60.0 | 60 | 100 | A process $Image$ tries to delete its process path in commandline $cmdline$ as part of defense evasion in host $Computer$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.mandiant.com/resources/fin11-email-campaigns-precursor-for-ransomware-data-theft](https://www.mandiant.com/resources/fin11-email-campaigns-precursor-for-ransomware-data-theft) -* [https://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html](https://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html) -* [https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/](https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_a/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_a/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/process_deleting_its_process_file_path.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-02-18-rundll32_dnsquery.md b/docs/_posts/2022-02-18-rundll32_dnsquery.md deleted file mode 100644 index 75b9319c65..0000000000 --- a/docs/_posts/2022-02-18-rundll32_dnsquery.md +++ /dev/null @@ -1,162 +0,0 @@ ---- -title: "Rundll32 DNSQuery" -excerpt: "System Binary Proxy Execution -, Rundll32 -" -categories: - - Endpoint -last_modified_at: 2022-02-18 -toc: true -toc_label: "" -tags: - - System Binary Proxy Execution - - Rundll32 - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect a suspicious rundll32.exe process having a http connection and do a dns query in some web domain. This technique was seen in IcedID malware where the rundll32 that execute its payload will contact amazon.com to check internet connect and to communicate to its C&C server to download config and other file component. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-02-18 -- **Author**: Teoderick Contreras, Splunk -- **ID**: f1483f5e-ee29-11eb-9d23-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218](https://attack.mitre.org/techniques/T1218/) | System Binary Proxy Execution | Defense Evasion | - -| [T1218.011](https://attack.mitre.org/techniques/T1218/011/) | Rundll32 | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventCode=22 process_name="rundll32.exe" -| stats count min(_time) as firstTime max(_time) as lastTime by Image QueryName QueryStatus ProcessId Computer -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `rundll32_dnsquery_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **rundll32_dnsquery_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Image -* QueryName -* QueryStatus -* ProcessId -* Computer - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name and eventcode = 22 dnsquery executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed rundll32.exe may be used. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [IcedID](/stories/icedid) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 56.0 | 70 | 80 | rundll32 process $process_name$ having a dns query to $QueryName$ in host $Computer$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://any.run/malware-trends/icedid](https://any.run/malware-trends/icedid) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/inf_icedid/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/inf_icedid/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/rundll32_dnsquery.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-02-18-set_default_powershell_execution_policy_to_unrestricted_or_bypass.md b/docs/_posts/2022-02-18-set_default_powershell_execution_policy_to_unrestricted_or_bypass.md deleted file mode 100644 index 13c28723df..0000000000 --- a/docs/_posts/2022-02-18-set_default_powershell_execution_policy_to_unrestricted_or_bypass.md +++ /dev/null @@ -1,167 +0,0 @@ ---- -title: "Set Default PowerShell Execution Policy To Unrestricted or Bypass" -excerpt: "Command and Scripting Interpreter -, PowerShell -" -categories: - - Endpoint -last_modified_at: 2022-02-18 -toc: true -toc_label: "" -tags: - - Command and Scripting Interpreter - - PowerShell - - Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -Monitor for changes of the ExecutionPolicy in the registry to the values "unrestricted" or "bypass," which allows the execution of malicious scripts. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-02-18 -- **Author**: Patrick Bareiss, Splunk -- **ID**: c2590137-0b08-4985-9ec5-6ae23d92f63d - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -| [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Installation -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path=*Software\\Microsoft\\Powershell\\1\\ShellIds\\Microsoft.PowerShell* Registry.registry_value_name=ExecutionPolicy (Registry.registry_value_data=Unrestricted OR Registry.registry_value_data=Bypass) by Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.dest -| `drop_dm_object_name(Registry)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `set_default_powershell_execution_policy_to_unrestricted_or_bypass_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **set_default_powershell_execution_policy_to_unrestricted_or_bypass_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.registry_path -* Registry.registry_key_name -* Registry.registry_value_name -* Registry.dest - - -#### How To Implement -You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Registry node. You must also be ingesting logs with the fields registry_path, registry_key_name, and registry_value_name from your endpoints. - -#### Known False Positives -Administrators may attempt to change the default execution policy on a system for a variety of reasons. However, setting the policy to "unrestricted" or "bypass" as this search is designed to identify, would be unusual. Hits should be reviewed and investigated as appropriate. - -#### Associated Analytic story -* [Hermetic Wiper](/stories/hermetic_wiper) -* [Malicious PowerShell](/stories/malicious_powershell) -* [Credential Dumping](/stories/credential_dumping) -* [HAFNIUM Group](/stories/hafnium_group) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 48.0 | 60 | 80 | A registry modification in $registry_path$ with reg key $registry_key_name$ and reg value $registry_value_name$ in host $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_execution_policy/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_execution_policy/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml) \| *version*: **7** \ No newline at end of file diff --git a/docs/_posts/2022-02-18-windows_eventvwr_uac_bypass.md b/docs/_posts/2022-02-18-windows_eventvwr_uac_bypass.md deleted file mode 100644 index 570f67dc1a..0000000000 --- a/docs/_posts/2022-02-18-windows_eventvwr_uac_bypass.md +++ /dev/null @@ -1,119 +0,0 @@ ---- -title: "Windows Eventvwr UAC Bypass" -excerpt: "Bypass User Account Control, Abuse Elevation Control Mechanism" -categories: - - Endpoint -last_modified_at: 2022-02-18 -toc: true -toc_label: "" -tags: - - Bypass User Account Control - - Privilege Escalation - - Defense Evasion - - Abuse Elevation Control Mechanism - - Privilege Escalation - - Defense Evasion - - Splunk Behavioral Analytics - - Endpoint_Registry ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -The following search identifies Eventvwr bypass by identifying the registry modification into a specific path that eventvwr.msc looks to (but is not valid) upon execution. A successful attack will include a suspicious command to be executed upon eventvwr.msc loading. Upon triage, review the parallel processes that have executed. Identify any additional registry modifications on the endpoint that may look suspicious. Remediate as necessary. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Registry](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointRegistry) -- **Last Updated**: 2022-02-18 -- **Author**: Lou Stella, Splunk -- **ID**: 66adff66-90d9-11ec-aba7-acde48001122 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1548.002](https://attack.mitre.org/techniques/T1548/002/) | Bypass User Account Control | Privilege Escalation, Defense Evasion | - -| [T1548](https://attack.mitre.org/techniques/T1548/) | Abuse Elevation Control Mechanism | Privilege Escalation, Defense Evasion | - -#### Search - -``` - -| from read_ssa_enriched_events() -| where "Endpoint_Registry" IN (_datamodels) -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), registry_path=lower(ucast(map_get(input_event, "registry_path"), "string", null)), registry_hive=lower(ucast(map_get(input_event, "registry_hive"), "string", null)), registry_value_name=lower(ucast(map_get(input_event, "registry_value_name"), "string", null)), registry_key_name=lower(ucast(map_get(input_event, "parent_process_name"), "string", null)), registry_value_type=lower(ucast(map_get(input_event, "registry_value_type"), "string", null)), registry_value_data=lower(ucast(map_get(input_event, "registry_value_data"), "string", null)), process_guid=lower(ucast(map_get(input_event, "process_guid"), "string", null)) -| where registry_path IS NOT NULL AND (like (registry_path, "%mscfile\\\\shell\\\\open\\\\command%")) -| eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)) -| eval body=create_map(["registry_path", registry_path, "registry_hive", registry_hive, "registry_value_name", registry_value_name, "registry_key_name", registry_key_name, "registry_value_type", registry_value_type, "registry_value_data", registry_value_data, "process_guid", process_guid]) -| into write_ssa_detected_events(); -``` - -#### Macros -The SPL above uses the following Macros: - -Note that `windows_eventvwr_uac_bypass_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* event_id -* registry_path -* registry_hive -* registry_value_name -* registry_key_name -* registry_value_type -* registry_value_data -* process_guid - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint_Registry` datamodel. - -#### Known False Positives -None known at this time. - -#### Associated Analytic story -* [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics) -* [IcedID](/stories/icedid) -* [Living Off The Land](/stories/living_off_the_land) - - -#### Kill Chain Phase -* Privilege Escalation - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | Registry values were modified to bypass UAC using Event Viewer on $dest_device_id$ | - - -Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` - - - -#### Reference - -* [https://blog.malwarebytes.com/malwarebytes-news/2021/02/lazyscripter-from-empire-to-double-rat/](https://blog.malwarebytes.com/malwarebytes-news/2021/02/lazyscripter-from-empire-to-double-rat/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1548.002/T1548.002.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1548.002/T1548.002.md) -* [https://attack.mitre.org/techniques/T1548/002](https://attack.mitre.org/techniques/T1548/002) -* [https://enigma0x3.net/2016/08/15/fileless-uac-bypass-using-eventvwr-exe-and-registry-hijacking/](https://enigma0x3.net/2016/08/15/fileless-uac-bypass-using-eventvwr-exe-and-registry-hijacking/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.002/ssa_eventvwr/windows-sysmon-registry.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.002/ssa_eventvwr/windows-sysmon-registry.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_eventvwr_uac_bypass.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-02-18-windows_wsreset_uac_bypass.md b/docs/_posts/2022-02-18-windows_wsreset_uac_bypass.md deleted file mode 100644 index 08b8691408..0000000000 --- a/docs/_posts/2022-02-18-windows_wsreset_uac_bypass.md +++ /dev/null @@ -1,116 +0,0 @@ ---- -title: "Windows WSReset UAC Bypass" -excerpt: "Bypass User Account Control, Abuse Elevation Control Mechanism" -categories: - - Endpoint -last_modified_at: 2022-02-18 -toc: true -toc_label: "" -tags: - - Bypass User Account Control - - Privilege Escalation - - Defense Evasion - - Abuse Elevation Control Mechanism - - Privilege Escalation - - Defense Evasion - - Splunk Behavioral Analytics - - Endpoint_Registry ---- - -### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is built to detect a suspicious modification of the Windows registry related to UAC bypass. This technique is to modify the registry in this detection, create a registry value with the path of the payload and run WSreset.exe to bypass User Account Control. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Registry](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointRegistry) -- **Last Updated**: 2022-02-18 -- **Author**: Lou Stella, Splunk -- **ID**: 3118f0c2-90d9-11ec-b833-acde48001122 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1548.002](https://attack.mitre.org/techniques/T1548/002/) | Bypass User Account Control | Privilege Escalation, Defense Evasion | - -| [T1548](https://attack.mitre.org/techniques/T1548/) | Abuse Elevation Control Mechanism | Privilege Escalation, Defense Evasion | - -#### Search - -``` - -| from read_ssa_enriched_events() -| where "Endpoint_Registry" IN (_datamodels) -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), registry_path=lower(ucast(map_get(input_event, "registry_path"), "string", null)), registry_hive=lower(ucast(map_get(input_event, "registry_hive"), "string", null)), registry_value_name=lower(ucast(map_get(input_event, "registry_value_name"), "string", null)), registry_key_name=lower(ucast(map_get(input_event, "registry_key_name"), "string", null)), registry_value_type=lower(ucast(map_get(input_event, "registry_value_type"), "string", null)), registry_value_data=lower(ucast(map_get(input_event, "registry_value_data"), "string", null)), process_guid=lower(ucast(map_get(input_event, "process_guid"), "string", null)) -| where registry_path IS NOT NULL AND registry_value_name IS NOT NULL and like (registry_path, "%\\\\AppX82a6gwre4fdg3bt635tn5ctqjf8msdd2\\\\Shell\\\\open\\\\command%") AND (registry_value_name="(Default)" OR registry_value_name="DelegateExecute") -| eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)) -| eval body=create_map(["registry_path", registry_path, "registry_hive", registry_hive, "registry_value_name", registry_value_name, "registry_key_name", registry_key_name, "registry_value_type", registry_value_type, "registry_value_data", registry_value_data, "process_guid", process_guid]) -| into write_ssa_detected_events(); -``` - -#### Macros -The SPL above uses the following Macros: - -Note that `windows_wsreset_uac_bypass_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* registry_path -* registry_hive -* registry_value_name -* registry_key_name -* registry_value_type -* registry_value_data -* process_guid - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint_Registry` datamodel. - -#### Known False Positives -Unknown at this point in time. - -#### Associated Analytic story -* [Living Off The Land](/stories/living_off_the_land) -* [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics) - - -#### Kill Chain Phase -* Privilege Escalation - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 63.0 | 70 | 90 | None | - - -Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` - - - -#### Reference - -* [https://github.com/hfiref0x/UACME](https://github.com/hfiref0x/UACME) -* [https://blog.morphisec.com/trickbot-uses-a-new-windows-10-uac-bypass](https://blog.morphisec.com/trickbot-uses-a-new-windows-10-uac-bypass) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/endpoint/windows_wsreset_uac_bypass.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-02-22-disabled_kerberos_pre-authentication_discovery_with_get-aduser.md b/docs/_posts/2022-02-22-disabled_kerberos_pre-authentication_discovery_with_get-aduser.md deleted file mode 100644 index 2b99704f67..0000000000 --- a/docs/_posts/2022-02-22-disabled_kerberos_pre-authentication_discovery_with_get-aduser.md +++ /dev/null @@ -1,160 +0,0 @@ ---- -title: "Disabled Kerberos Pre-Authentication Discovery With Get-ADUser" -excerpt: "Steal or Forge Kerberos Tickets -, AS-REP Roasting -" -categories: - - Endpoint -last_modified_at: 2022-02-22 -toc: true -toc_label: "" -tags: - - Steal or Forge Kerberos Tickets - - AS-REP Roasting - - Credential Access - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-ADUser` commandlet with specific parameters. `Get-ADUser` is part of the Active Directory PowerShell module used to manage Windows Active Directory networks. As the name suggests, `Get-ADUser` is used to query for domain users. With the appropiate parameters, Get-ADUser allows adversaries to discover domain accounts with Kerberos Pre Authentication disabled.\ Red Teams and adversaries alike use may abuse Get-ADUSer to enumerate these accounts and attempt to crack their passwords offline. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-02-22 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 114c6bfe-9406-11ec-bcce-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1558](https://attack.mitre.org/techniques/T1558/) | Steal or Forge Kerberos Tickets | Credential Access | - -| [T1558.004](https://attack.mitre.org/techniques/T1558/004/) | AS-REP Roasting | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - `powershell` EventCode=4104 (Message = "*Get-ADUser*" AND Message="*4194304*") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `disabled_kerberos_pre_authentication_discovery_with_get_aduser_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **disabled_kerberos_pre-authentication_discovery_with_get-aduser_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Message -* ComputerName -* User - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -Administrators or power users may use search for accounts with Kerberos Pre Authentication disabled for legitimate purposes. - -#### Associated Analytic story -* [Active Directory Kerberos Attacks](/stories/active_directory_kerberos_attacks) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 54.0 | 60 | 90 | Disabled Kerberos Pre-Authentication Discovery With Get-ADUser from $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1558/004/](https://attack.mitre.org/techniques/T1558/004/) -* [https://m0chan.github.io/2019/07/31/How-To-Attack-Kerberos-101.html](https://m0chan.github.io/2019/07/31/How-To-Attack-Kerberos-101.html) -* [https://stealthbits.com/blog/cracking-active-directory-passwords-with-as-rep-roasting/](https://stealthbits.com/blog/cracking-active-directory-passwords-with-as-rep-roasting/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1558.004/getaduser/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1558.004/getaduser/windows-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disabled_kerberos_pre_authentication_discovery_with_get_aduser.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-02-22-kerberos_pre-authentication_flag_disabled_in_useraccountcontrol.md b/docs/_posts/2022-02-22-kerberos_pre-authentication_flag_disabled_in_useraccountcontrol.md deleted file mode 100644 index e3b8c287a9..0000000000 --- a/docs/_posts/2022-02-22-kerberos_pre-authentication_flag_disabled_in_useraccountcontrol.md +++ /dev/null @@ -1,158 +0,0 @@ ---- -title: "Kerberos Pre-Authentication Flag Disabled in UserAccountControl" -excerpt: "Steal or Forge Kerberos Tickets -, AS-REP Roasting -" -categories: - - Endpoint -last_modified_at: 2022-02-22 -toc: true -toc_label: "" -tags: - - Steal or Forge Kerberos Tickets - - AS-REP Roasting - - Credential Access - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic leverages Windows Security Event 4738, `A user account was changed`, to identify a change performed on a domain user object that disables Kerberos Pre-Authentication. Disabling the Pre Authentication flag in the UserAccountControl property allows an adversary to easily perform a brute force attack against the user's password offline leveraging the ASP REP Roasting technique. Red Teams and adversaries alike who have obtained privileges in an Active Directory network may use this technique as a backdoor or a way to escalate privileges. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-02-22 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 0cb847ee-9423-11ec-b2df-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1558](https://attack.mitre.org/techniques/T1558/) | Steal or Forge Kerberos Tickets | Credential Access | - -| [T1558.004](https://attack.mitre.org/techniques/T1558/004/) | AS-REP Roasting | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - `wineventlog_security` EventCode=4738 MSADChangedAttributes="*Don't Require Preauth' - Enabled*" -| table EventCode, Account_Name, Security_ID, MSADChangedAttributes -| `kerberos_pre_authentication_flag_disabled_in_useraccountcontrol_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) - -> :information_source: -> **kerberos_pre-authentication_flag_disabled_in_useraccountcontrol_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Account_Name -* Security_ID -* MSADChangedAttributes - - -#### How To Implement -To successfully implement this search, you need to be ingesting Domain Controller events. The Advanced Security Audit policy setting `User Account Management` within `Account Management` needs to be enabled. - -#### Known False Positives -Unknown. - -#### Associated Analytic story -* [Active Directory Kerberos Attacks](/stories/active_directory_kerberos_attacks) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 45.0 | 50 | 90 | Kerberos Pre Authentication was Disabled for $Account_Name$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://docs.microsoft.com/en-us/troubleshoot/windows-server/identity/useraccountcontrol-manipulate-account-properties](https://docs.microsoft.com/en-us/troubleshoot/windows-server/identity/useraccountcontrol-manipulate-account-properties) -* [https://m0chan.github.io/2019/07/31/How-To-Attack-Kerberos-101.html](https://m0chan.github.io/2019/07/31/How-To-Attack-Kerberos-101.html) -* [https://stealthbits.com/blog/cracking-active-directory-passwords-with-as-rep-roasting/](https://stealthbits.com/blog/cracking-active-directory-passwords-with-as-rep-roasting/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1558.004/powershell/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1558.004/powershell/windows-security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/kerberos_pre_authentication_flag_disabled_in_useraccountcontrol.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-02-22-scheduled_task_deleted_or_created_via_cmd.md b/docs/_posts/2022-02-22-scheduled_task_deleted_or_created_via_cmd.md deleted file mode 100644 index 6ac4eef9b9..0000000000 --- a/docs/_posts/2022-02-22-scheduled_task_deleted_or_created_via_cmd.md +++ /dev/null @@ -1,175 +0,0 @@ ---- -title: "Scheduled Task Deleted Or Created via CMD" -excerpt: "Scheduled Task -, Scheduled Task/Job -" -categories: - - Endpoint -last_modified_at: 2022-02-22 -toc: true -toc_label: "" -tags: - - Scheduled Task - - Scheduled Task/Job - - Execution - - Persistence - - Privilege Escalation - - Execution - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the creation or deletion of a scheduled task using schtasks.exe with flags - create or delete being passed on the command-line. This has been associated with the Dragonfly threat actor, and the SUNBURST attack against Solarwinds. This analytic replaces "Scheduled Task used in BadRabbit Ransomware". - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-02-22 -- **Author**: Bhavin Patel, Splunk -- **ID**: d5af132c-7c17-439c-9d31-13d55340f36c - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1053.005](https://attack.mitre.org/techniques/T1053/005/) | Scheduled Task | Execution, Persistence, Privilege Escalation | - -| [T1053](https://attack.mitre.org/techniques/T1053/) | Scheduled Task/Job | Execution, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.IP - - - -
-
- -
- CIS20 - -
- -* CIS 3 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count values(Processes.process) as process values(Processes.parent_process) as parent_process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=schtasks.exe (Processes.process=*delete* OR Processes.process=*create*) by Processes.user Processes.process_name Processes.parent_process_name Processes.dest -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `scheduled_task_deleted_or_created_via_cmd_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **scheduled_task_deleted_or_created_via_cmd_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process -* Processes.parent_process -* Processes.process_name -* Processes.user -* Processes.parent_process_name -* Processes.dest - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -It is possible scripts or administrators may trigger this analytic. Filter as needed based on parent process, application. - -#### Associated Analytic story -* [DHS Report TA18-074A](/stories/dhs_report_ta18-074a) -* [NOBELIUM Group](/stories/nobelium_group) -* [Windows Persistence Techniques](/stories/windows_persistence_techniques) -* [Living Off The Land](/stories/living_off_the_land) -* [Azorult](/stories/azorult) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 56.0 | 70 | 80 | A schedule task process $process_name$ with create or delete commandline $process$ in host $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://thedfirreport.com/2022/02/21/qbot-and-zerologon-lead-to-full-domain-compromise/](https://thedfirreport.com/2022/02/21/qbot-and-zerologon-lead-to-full-domain-compromise/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml) \| *version*: **6** \ No newline at end of file diff --git a/docs/_posts/2022-02-22-windows_wmi_process_call_create.md b/docs/_posts/2022-02-22-windows_wmi_process_call_create.md deleted file mode 100644 index 354377901f..0000000000 --- a/docs/_posts/2022-02-22-windows_wmi_process_call_create.md +++ /dev/null @@ -1,172 +0,0 @@ ---- -title: "Windows WMI Process Call Create" -excerpt: "Windows Management Instrumentation -" -categories: - - Endpoint -last_modified_at: 2022-02-22 -toc: true -toc_label: "" -tags: - - Windows Management Instrumentation - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to look for wmi commandlines to execute or create process. This technique was used by adversaries or threat actor to execute their malicious payload in local or remote host. This hunting query is a good pivot to start to look further which process trigger the wmi or what process it execute locally or remotely. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-02-22 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 0661c2de-93de-11ec-9833-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1047](https://attack.mitre.org/techniques/T1047/) | Windows Management Instrumentation | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_wmic` Processes.process = "* process *" Processes.process = "* call *" Processes.process = "* create *" by Processes.parent_process_name Processes.parent_process Processes.process_name Processes.process Processes.original_file_name Processes.process_id Processes.parent_process_path Processes.process_guid Processes.parent_process_id Processes.dest Processes.user Processes.process_path -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_wmi_process_call_create_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [process_wmic](https://github.com/splunk/security_content/blob/develop/macros/process_wmic.yml) - -> :information_source: -> **windows_wmi_process_call_create_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id -* Processes.process_guid - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -Administrators may execute this command for testing or auditing. - -#### Associated Analytic story -* [Suspicious WMI Use](/stories/suspicious_wmi_use) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | process with $process$ commandline executed in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/NVISOsecurity/sigma-public/blob/master/rules/windows/process_creation/win_susp_wmi_execution.yml](https://github.com/NVISOsecurity/sigma-public/blob/master/rules/windows/process_creation/win_susp_wmi_execution.yml) -* [https://github.com/redcanaryco/atomic-red-team/blob/2b804d25418004a5f1ba50e9dc637946ab8733c7/atomics/T1047/T1047.md](https://github.com/redcanaryco/atomic-red-team/blob/2b804d25418004a5f1ba50e9dc637946ab8733c7/atomics/T1047/T1047.md) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1047/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1047/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_wmi_process_call_create.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-02-23-kerberos_pre-authentication_flag_disabled_with_powershell.md b/docs/_posts/2022-02-23-kerberos_pre-authentication_flag_disabled_with_powershell.md deleted file mode 100644 index 9528d9f618..0000000000 --- a/docs/_posts/2022-02-23-kerberos_pre-authentication_flag_disabled_with_powershell.md +++ /dev/null @@ -1,152 +0,0 @@ ---- -title: "Kerberos Pre-Authentication Flag Disabled with PowerShell" -excerpt: "Steal or Forge Kerberos Tickets -, AS-REP Roasting -" -categories: - - Endpoint -last_modified_at: 2022-02-23 -toc: true -toc_label: "" -tags: - - Steal or Forge Kerberos Tickets - - AS-REP Roasting - - Credential Access - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Set-ADAccountControl` commandlet with specific parameters. `Set-ADAccountControl` is part of the Active Directory PowerShell module used to manage Windows Active Directory networks. As the name suggests, `Set-ADAccountControl` is used to modify User Account Control values for an Active Directory domain account. With the appropiate parameters, Set-ADAccountControl allows adversaries to disable Kerberos Pre-Authentication for an account to to easily perform a brute force attack against the user's password offline leveraging the ASP REP Roasting technique. Red Teams and adversaries alike who have obtained privileges in an Active Directory network may use this technique as a backdoor or a way to escalate privileges. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-02-23 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 59b51620-94c9-11ec-b3d5-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1558](https://attack.mitre.org/techniques/T1558/) | Steal or Forge Kerberos Tickets | Credential Access | - -| [T1558.004](https://attack.mitre.org/techniques/T1558/004/) | AS-REP Roasting | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - `powershell` EventCode=4104 (Message = "*Set-ADAccountControl*" AND Message="*DoesNotRequirePreAuth:$true*") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `kerberos_pre_authentication_flag_disabled_with_powershell_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -Note that **kerberos_pre-authentication_flag_disabled_with_powershell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -Although unlikely, Administrators may need to set this flag for legitimate purposes. - -#### Associated Analytic story -* [Active Directory Kerberos Attacks](/stories/active_directory_kerberos_attacks) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 45.0 | 50 | 90 | Kerberos Pre Authentication was Disabled using PowerShell on $dest$ | - - -#### Reference - -* [https://docs.microsoft.com/en-us/troubleshoot/windows-server/identity/useraccountcontrol-manipulate-account-properties](https://docs.microsoft.com/en-us/troubleshoot/windows-server/identity/useraccountcontrol-manipulate-account-properties) -* [https://m0chan.github.io/2019/07/31/How-To-Attack-Kerberos-101.html](https://m0chan.github.io/2019/07/31/How-To-Attack-Kerberos-101.html) -* [https://stealthbits.com/blog/cracking-active-directory-passwords-with-as-rep-roasting/](https://stealthbits.com/blog/cracking-active-directory-passwords-with-as-rep-roasting/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1558.004/powershell/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1558.004/powershell/windows-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/kerberos_pre_authentication_flag_disabled_with_powershell.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-02-23-windows_event_for_service_disabled.md b/docs/_posts/2022-02-23-windows_event_for_service_disabled.md deleted file mode 100644 index 89c3ce9f75..0000000000 --- a/docs/_posts/2022-02-23-windows_event_for_service_disabled.md +++ /dev/null @@ -1,163 +0,0 @@ ---- -title: "Windows Event For Service Disabled" -excerpt: "Disable or Modify Tools -, Impair Defenses -" -categories: - - Endpoint -last_modified_at: 2022-02-23 -toc: true -toc_label: "" -tags: - - Disable or Modify Tools - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic will identify suspicious system event of services that was modified from start to disabled. This technique is seen where the adversary attempts to disable security app services, other malware services to evade the defense systems on the compromised host - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-02-23 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 9c2620a8-94a1-11ec-b40c-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`wineventlog_system` EventCode=7040 Message = "*service was changed from demand start to disabled." -| stats count min(_time) as firstTime max(_time) as lastTime by ComputerName EventCode Message User Sid -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_event_for_service_disabled_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [wineventlog_system](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_system.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -Note that **windows_event_for_service_disabled_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* ComputerName -* EventCode -* Message -* User -* Sid - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the Service name, Service File Name Service Start type, and Service Type from your endpoints. - -#### Known False Positives -Windows service update may cause this event. In that scenario, filtering is needed. - -#### Associated Analytic story -* [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 36.0 | 60 | 60 | Service was disabled on $Computer$ | - - -#### Reference - -* [https://blog.talosintelligence.com/2018/02/olympic-destroyer.html](https://blog.talosintelligence.com/2018/02/olympic-destroyer.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/olympic_destroyer/system.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/olympic_destroyer/system.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_event_for_service_disabled.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-02-23-windows_excessive_disabled_services_event.md b/docs/_posts/2022-02-23-windows_excessive_disabled_services_event.md deleted file mode 100644 index 46b18ec802..0000000000 --- a/docs/_posts/2022-02-23-windows_excessive_disabled_services_event.md +++ /dev/null @@ -1,168 +0,0 @@ ---- -title: "Windows Excessive Disabled Services Event" -excerpt: "Disable or Modify Tools -, Impair Defenses -" -categories: - - Endpoint -last_modified_at: 2022-02-23 -toc: true -toc_label: "" -tags: - - Disable or Modify Tools - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic will identify suspicious excessive number of system events of services that was modified from start to disabled. This technique is seen where the adversary attempts to disable security app services, other malware services oer serve as an destructive impact to complete the objective on the compromised system. One good example for this scenario is Olympic destroyer where it disable all active services in the compromised host as part of its destructive impact and defense evasion. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-02-23 -- **Author**: Teoderick Contreras, Splunk -- **ID**: c3f85976-94a5-11ec-9a58-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`wineventlog_system` EventCode=7040 Message = "*service was changed from demand start to disabled." -| stats count values(Message) as MessageList dc(Message) as MessageCount min(_time) as firstTime max(_time) as lastTime by ComputerName EventCode User Sid -| where MessageCount >=10 -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_excessive_disabled_services_event_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [wineventlog_system](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_system.yml) - -> :information_source: -> **windows_excessive_disabled_services_event_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* ComputerName -* EventCode -* Message -* User -* Sid - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the Service name, Service File Name Service Start type, and Service Type from your endpoints. - -#### Known False Positives -Unknown - -#### Associated Analytic story -* [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 81.0 | 90 | 90 | Service was disabled in $Computer$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://blog.talosintelligence.com/2018/02/olympic-destroyer.html](https://blog.talosintelligence.com/2018/02/olympic-destroyer.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/olympic_destroyer/system.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/olympic_destroyer/system.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_excessive_disabled_services_event.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-02-23-windows_mshta_child_process.md b/docs/_posts/2022-02-23-windows_mshta_child_process.md deleted file mode 100644 index a53d135f80..0000000000 --- a/docs/_posts/2022-02-23-windows_mshta_child_process.md +++ /dev/null @@ -1,112 +0,0 @@ ---- -title: "Windows MSHTA Child Process" -excerpt: "Mshta, Signed Binary Proxy Execution" -categories: - - Endpoint -last_modified_at: 2022-02-23 -toc: true -toc_label: "" -tags: - - Mshta - - Defense Evasion - - Signed Binary Proxy Execution - - Defense Evasion - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies child processes spawning from "mshta.exe". The search will return the first time and last time these command-line arguments were used for these executions, as well as the target system, the user, parent process "mshta.exe" and its child process. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2022-02-23 -- **Author**: Michael Haag, Splunk -- **ID**: f63f7e9c-9526-11ec-9fc7-acde48001122 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218.005](https://attack.mitre.org/techniques/T1218/005/) | Mshta | Defense Evasion | - -| [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | - -#### Search - -``` - -| from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line IS NOT NULL AND process_name IS NOT NULL AND parent_process_name IS NOT NULL -| where parent_process_name="mshta.exe" AND process_name="powershell.exe" OR process_name="cmd.exe" OR process_name="scrcons.exe" OR process_name="colorcpl.exe" OR process_name="msbuild.exe" OR process_name="microsoft.workflow.compiler.exe" OR process_name="searchprotocolhost.exe" OR process_name="cscript.exe" OR process_name="wscript.exe" -| eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) -| into write_ssa_detected_events(); -``` - -#### Macros -The SPL above uses the following Macros: - -Note that `windows_mshta_child_process_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* dest_device_id -* process_name -* parent_process_name -* process_path -* dest_user_id -* process -* cmd_line - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -Although unlikely, some legitimate applications may exhibit this behavior, triggering a false positive. - -#### Associated Analytic story -* [Suspicious MSHTA Activity](/stories/suspicious_mshta_activity) -* [Living Off The Land](/stories/living_off_the_land) - - -#### Kill Chain Phase -* Exploitation - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$ attempting to access a remote destination to download an additional payload. | - - -Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` - - - -#### Reference - -* [https://github.com/redcanaryco/AtomicTestHarnesses](https://github.com/redcanaryco/AtomicTestHarnesses) -* [https://redcanary.com/blog/introducing-atomictestharnesses/](https://redcanary.com/blog/introducing-atomictestharnesses/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.005/atomic_red_team/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.005/atomic_red_team/windows-security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_mshta_child_process.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-02-23-windows_mshta_command-line_url.md b/docs/_posts/2022-02-23-windows_mshta_command-line_url.md deleted file mode 100644 index 1954dfffbb..0000000000 --- a/docs/_posts/2022-02-23-windows_mshta_command-line_url.md +++ /dev/null @@ -1,113 +0,0 @@ ---- -title: "Windows MSHTA Command-Line URL" -excerpt: "Mshta, Signed Binary Proxy Execution" -categories: - - Endpoint -last_modified_at: 2022-02-23 -toc: true -toc_label: "" -tags: - - Mshta - - Defense Evasion - - Signed Binary Proxy Execution - - Defense Evasion - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic identifies when Microsoft HTML Application Host (mshta.exe) utility is used to make remote http connections. Adversaries may use mshta.exe to proxy the download and execution of remote .hta files. The analytic identifies command line arguments of http and https being used. This technique is commonly used by malicious software to bypass preventative controls. The search will return the first time and last time these command-line arguments were used for these executions, as well as the target system, the user, process "rundll32.exe" and its parent process. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2022-02-23 -- **Author**: Michael Haag, Splunk -- **ID**: 9b35c538-94ef-11ec-9439-acde48001122 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218.005](https://attack.mitre.org/techniques/T1218/005/) | Mshta | Defense Evasion | - -| [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | - -#### Search - -``` - -| from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line IS NOT NULL AND process_name IS NOT NULL -| where process_name="mshta.exe" AND (like (cmd_line, "%http://%") OR like (cmd_line, "%https://%")) -| eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) -| into write_ssa_detected_events(); -``` - -#### Macros -The SPL above uses the following Macros: - -Note that `windows_mshta_command-line_url_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* dest_device_id -* process_name -* parent_process_name -* process_path -* dest_user_id -* process -* cmd_line - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -It is possible legitimate applications may perform this behavior and will need to be filtered. - -#### Associated Analytic story -* [Suspicious MSHTA Activity](/stories/suspicious_mshta_activity) -* [Living Off The Land](/stories/living_off_the_land) - - -#### Kill Chain Phase -* Exploitation - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$ attempting to access a remote destination to download an additional payload. | - - -Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` - - - -#### Reference - -* [https://github.com/redcanaryco/AtomicTestHarnesses](https://github.com/redcanaryco/AtomicTestHarnesses) -* [https://redcanary.com/blog/introducing-atomictestharnesses/](https://redcanary.com/blog/introducing-atomictestharnesses/) -* [https://docs.microsoft.com/en-us/windows/win32/search/-search-3x-wds-extidx-prot-implementing](https://docs.microsoft.com/en-us/windows/win32/search/-search-3x-wds-extidx-prot-implementing) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.005/atomic_red_team/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.005/atomic_red_team/windows-security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_mshta_command-line_url.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-02-23-windows_mshta_inline_hta_execution.md b/docs/_posts/2022-02-23-windows_mshta_inline_hta_execution.md deleted file mode 100644 index 38ca655f6d..0000000000 --- a/docs/_posts/2022-02-23-windows_mshta_inline_hta_execution.md +++ /dev/null @@ -1,113 +0,0 @@ ---- -title: "Windows MSHTA Inline HTA Execution" -excerpt: "Mshta, Signed Binary Proxy Execution" -categories: - - Endpoint -last_modified_at: 2022-02-23 -toc: true -toc_label: "" -tags: - - Mshta - - Defense Evasion - - Signed Binary Proxy Execution - - Defense Evasion - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies "mshta.exe" execution with inline protocol handlers. "JavaScript", "VBScript", and "About" are the only supported options when invoking HTA content directly on the command-line. The search will return the first time and last time these command-line arguments were used for these executions, as well as the target system, the user, process "mshta.exe" and its parent process. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2022-02-23 -- **Author**: Michael Haag, Splunk -- **ID**: 24962154-9524-11ec-9333-acde48001122 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218.005](https://attack.mitre.org/techniques/T1218/005/) | Mshta | Defense Evasion | - -| [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | - -#### Search - -``` - -| from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line IS NOT NULL AND process_name IS NOT NULL -| where process_name="mshta.exe" AND (like (cmd_line, "%vbscript%") OR like (cmd_line, "%javascript%") OR like (cmd_line, "%about%")) -| eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) -| into write_ssa_detected_events(); -``` - -#### Macros -The SPL above uses the following Macros: - -Note that `windows_mshta_inline_hta_execution_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* dest_device_id -* process_name -* parent_process_name -* process_path -* dest_user_id -* process -* cmd_line - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Although unlikely, some legitimate applications may exhibit this behavior, triggering a false positive. - -#### Associated Analytic story -* [Suspicious MSHTA Activity](/stories/suspicious_mshta_activity) -* [Living Off The Land](/stories/living_off_the_land) - - -#### Kill Chain Phase -* Exploitation - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$ executing with inline HTA, indicative of defense evasion. | - - -Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` - - - -#### Reference - -* [https://github.com/redcanaryco/AtomicTestHarnesses](https://github.com/redcanaryco/AtomicTestHarnesses) -* [https://redcanary.com/blog/introducing-atomictestharnesses/](https://redcanary.com/blog/introducing-atomictestharnesses/) -* [https://docs.microsoft.com/en-us/windows/win32/search/-search-3x-wds-extidx-prot-implementing](https://docs.microsoft.com/en-us/windows/win32/search/-search-3x-wds-extidx-prot-implementing) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.005/atomic_red_team/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.005/atomic_red_team/windows-security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_mshta_inline_hta_execution.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-02-23-windows_process_with_namedpipe_commandline.md b/docs/_posts/2022-02-23-windows_process_with_namedpipe_commandline.md deleted file mode 100644 index e336a11827..0000000000 --- a/docs/_posts/2022-02-23-windows_process_with_namedpipe_commandline.md +++ /dev/null @@ -1,171 +0,0 @@ ---- -title: "Windows Process With NamedPipe CommandLine" -excerpt: "Process Injection -" -categories: - - Endpoint -last_modified_at: 2022-02-23 -toc: true -toc_label: "" -tags: - - Process Injection - - Defense Evasion - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to look for process commandline that contains named pipe. This technique was seen in some adversaries, threat actor and malware like olympic destroyer to communicate to its other child processes after process injection that serve as defense evasion and privilege escalation. On the other hand this analytic may catch some normal process that using this technique for example browser application. In that scenario we include common process path we've seen during testing that cause false positive which is the program files. False positive may still be arise if the normal application is in other folder path. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-02-23 -- **Author**: Teoderick Contreras, Splunk -- **ID**: e64399d4-94a8-11ec-a9da-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1055](https://attack.mitre.org/techniques/T1055/) | Process Injection | Defense Evasion, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process = "*\\\\.\\pipe\\*" NOT (Processes.process_path IN ("*\\program files*")) by Processes.parent_process_name Processes.parent_process Processes.process_name Processes.process Processes.original_file_name Processes.process_id Processes.parent_process_path Processes.process_guid Processes.parent_process_id Processes.dest Processes.user Processes.process_path -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_process_with_namedpipe_commandline_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_process_with_namedpipe_commandline_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id -* Processes.process_guid - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -Normal browser application may use this technique. Please update the filter macros to remove false positives. - -#### Associated Analytic story -* [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | Process with named pipe in $process$ on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://blog.talosintelligence.com/2018/02/olympic-destroyer.html](https://blog.talosintelligence.com/2018/02/olympic-destroyer.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/olympic_destroyer/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/olympic_destroyer/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_process_with_namedpipe_commandline.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-02-23-windows_rundll32_inline_hta_execution.md b/docs/_posts/2022-02-23-windows_rundll32_inline_hta_execution.md deleted file mode 100644 index cba7eb63e3..0000000000 --- a/docs/_posts/2022-02-23-windows_rundll32_inline_hta_execution.md +++ /dev/null @@ -1,114 +0,0 @@ ---- -title: "Windows Rundll32 Inline HTA Execution" -excerpt: "Signed Binary Proxy Execution, Mshta" -categories: - - Endpoint -last_modified_at: 2022-02-23 -toc: true -toc_label: "" -tags: - - Signed Binary Proxy Execution - - Defense Evasion - - Mshta - - Defense Evasion - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies "rundll32.exe" execution with inline protocol handlers. "JavaScript", "VBScript", and "About" are the only supported options when invoking HTA content directly on the command-line. This type of behavior is commonly observed with fileless malware or application whitelisting bypass techniques. The search will return the first time and last time these command-line arguments were used for these executions, as well as the target system, the user, process "rundll32.exe" and its parent process. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2022-02-23 -- **Author**: Michael Haag, Splunk -- **ID**: 0caa1dd6-94f5-11ec-9786-acde48001122 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | - -| [T1218.005](https://attack.mitre.org/techniques/T1218/005/) | Mshta | Defense Evasion | - -#### Search - -``` - -| from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line IS NOT NULL AND process_name IS NOT NULL -| where process_name="rundll32.exe" AND (like (cmd_line, "%vbscript%") OR like (cmd_line, "%javascript%") OR like (cmd_line, "%about%")) -| eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) -| into write_ssa_detected_events(); -``` - -#### Macros -The SPL above uses the following Macros: - -Note that `windows_rundll32_inline_hta_execution_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* dest_device_id -* process_name -* parent_process_name -* process_path -* dest_user_id -* process -* cmd_line - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Although unlikely, some legitimate applications may exhibit this behavior, triggering a false positive. - -#### Associated Analytic story -* [Suspicious MSHTA Activity](/stories/suspicious_mshta_activity) -* [NOBELIUM Group](/stories/nobelium_group) -* [Living Off The Land](/stories/living_off_the_land) - - -#### Kill Chain Phase -* Exploitation - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 56.0 | 70 | 80 | Suspicious $process_name$ inline HTA execution on $dest_device_id$. | - - -Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` - - - -#### Reference - -* [https://github.com/redcanaryco/AtomicTestHarnesses](https://github.com/redcanaryco/AtomicTestHarnesses) -* [https://redcanary.com/blog/introducing-atomictestharnesses/](https://redcanary.com/blog/introducing-atomictestharnesses/) -* [https://docs.microsoft.com/en-us/windows/win32/search/-search-3x-wds-extidx-prot-implementing](https://docs.microsoft.com/en-us/windows/win32/search/-search-3x-wds-extidx-prot-implementing) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.005/atomic_red_team/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.005/atomic_red_team/windows-security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_rundll32_inline_hta_execution.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-02-23-windows_service_creation_using_registry_entry.md b/docs/_posts/2022-02-23-windows_service_creation_using_registry_entry.md deleted file mode 100644 index cf4168b5d4..0000000000 --- a/docs/_posts/2022-02-23-windows_service_creation_using_registry_entry.md +++ /dev/null @@ -1,179 +0,0 @@ ---- -title: "Windows Service Creation Using Registry Entry" -excerpt: "Services Registry Permissions Weakness -" -categories: - - Endpoint -last_modified_at: 2022-02-23 -toc: true -toc_label: "" -tags: - - Services Registry Permissions Weakness - - Defense Evasion - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to look for suspicious modification or creation of registry to have service entry. This technique is abused by adversaries or threat actor to persist, gain privileges in the machine or even lateral movement. This technique can be executed using reg.exe application or using windows API like for example the CrashOveride malware. This detection is a good indicator that a process is trying to create a service entry using registry ImagePath. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-02-23 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 25212358-948e-11ec-ad47-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1574.011](https://attack.mitre.org/techniques/T1574/011/) | Services Registry Permissions Weakness | Defense Evasion, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*\\SYSTEM\\CurrentControlSet\\Services*" Registry.registry_value_name = ImagePath by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid -| `drop_dm_object_name(Registry)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] -| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data -| `windows_service_creation_using_registry_entry_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_service_creation_using_registry_entry_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.registry_key_name -* Registry.registry_path -* Registry.user -* Registry.dest -* Registry.registry_value_name -* Processes.process_id -* Processes.process_name -* Processes.process -* Processes.dest -* Processes.parent_process_name -* Processes.parent_process -* Processes.process_guid - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. - -#### Known False Positives -Third party tools may used this technique to create services but not so common. - -#### Associated Analytic story -* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) -* [Suspicious Windows Registry Activities](/stories/suspicious_windows_registry_activities) -* [Windows Persistence Techniques](/stories/windows_persistence_techniques) -* [Windows Registry Abuse](/stories/windows_registry_abuse) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 64.0 | 80 | 80 | A Windows Service was created on a endpoint from $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/redcanaryco/atomic-red-team/blob/36d49de4c8b00bf36054294b4a1fcbab3917d7c5/atomics/T1574.011/T1574.011.md](https://github.com/redcanaryco/atomic-red-team/blob/36d49de4c8b00bf36054294b4a1fcbab3917d7c5/atomics/T1574.011/T1574.011.md) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1574.011/change_registry_path_service/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1574.011/change_registry_path_service/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_service_creation_using_registry_entry.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-02-24-aws_lambda_updatefunctioncode.md b/docs/_posts/2022-02-24-aws_lambda_updatefunctioncode.md deleted file mode 100644 index 3c4596dedd..0000000000 --- a/docs/_posts/2022-02-24-aws_lambda_updatefunctioncode.md +++ /dev/null @@ -1,157 +0,0 @@ ---- -title: "AWS Lambda UpdateFunctionCode" -excerpt: "User Execution -" -categories: - - Cloud -last_modified_at: 2022-02-24 -toc: true -toc_label: "" -tags: - - User Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is designed to detect IAM users attempting to update/modify AWS lambda code via the AWS CLI to gain persistence, futher access into your AWS environment and to facilitate planting backdoors. In this instance, an attacker may upload malicious code/binary to a lambda function which will be executed automatically when the funnction is triggered. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-02-24 -- **Author**: Bhavin Patel, Splunk -- **ID**: 211b80d3-6340-4345-11ad-212bf3d0d111 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1204](https://attack.mitre.org/techniques/T1204/) | User Execution | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.DS -* PR.AC -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 13 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cloudtrail` eventSource=lambda.amazonaws.com eventName=UpdateFunctionCode* errorCode = success user_type=IAMUser -| stats count min(_time) as firstTime max(_time) as lastTime values(requestParameters.functionName) as function_updated by src_ip user_arn user_agent user_type eventName aws_account_id -|`aws_lambda_updatefunctioncode_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) - -> :information_source: -> **aws_lambda_updatefunctioncode_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* eventName -* userAgent -* errorCode - - -#### How To Implement -You must install Splunk AWS Add on and enable Cloudtrail logs in your AWS Environment. - -#### Known False Positives -While this search has no known false positives, it is possible that an AWS admin or an autorized IAM user has updated the lambda fuction code legitimately. - -#### Associated Analytic story -* [Suspicious Cloud User Activities](/stories/suspicious_cloud_user_activities) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 63.0 | 70 | 90 | User $user_arn$ is attempting to update the lambda function code of $function_updated$ from this IP $src_ip$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [http://detectioninthe.cloud/execution/modify_lambda_function_code/](http://detectioninthe.cloud/execution/modify_lambda_function_code/) -* [https://sysdig.com/blog/exploit-mitigate-aws-lambdas-mitre/](https://sysdig.com/blog/exploit-mitigate-aws-lambdas-mitre/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1204/aws_updatelambdafunctioncode/aws_cloudtrail_events.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1204/aws_updatelambdafunctioncode/aws_cloudtrail_events.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/aws_lambda_updatefunctioncode.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-02-24-detect_empire_with_powershell_script_block_logging.md b/docs/_posts/2022-02-24-detect_empire_with_powershell_script_block_logging.md deleted file mode 100644 index a7a1a4cd9b..0000000000 --- a/docs/_posts/2022-02-24-detect_empire_with_powershell_script_block_logging.md +++ /dev/null @@ -1,168 +0,0 @@ ---- -title: "Detect Empire with PowerShell Script Block Logging" -excerpt: "Command and Scripting Interpreter -, PowerShell -" -categories: - - Endpoint -last_modified_at: 2022-02-24 -toc: true -toc_label: "" -tags: - - Command and Scripting Interpreter - - PowerShell - - Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify suspicious PowerShell execution. Script Block Logging captures the command sent to PowerShell, the full command to be executed. Upon enabling, logs will output to Windows event logs. Dependent upon volume, enable on critical endpoints or all. \ -This analytic identifies the common PowerShell stager used by PowerShell-Empire. Each stager that may use PowerShell all uses the same pattern. The initial HTTP will be base64 encoded and use `system.net.webclient`. Note that some obfuscation may evade the analytic. \ -During triage, review parallel processes using an EDR product or 4688 events. It will be important to understand the timeline of events around this activity. Review the entire logged PowerShell script block. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-02-24 -- **Author**: Michael Haag, Splunk -- **ID**: bc1dc6b8-c954-11eb-bade-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -| [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 (ScriptBlockText=*system.net.webclient* AND ScriptBlockText=*frombase64string*) -| stats count min(_time) as firstTime max(_time) as lastTime by Opcode Computer UserID EventCode ScriptBlockText -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_empire_with_powershell_script_block_logging_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **detect_empire_with_powershell_script_block_logging_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* ScriptBlockText -* Opcode -* Computer -* UserID -* EventCode - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -False positives may only pertain to it not being related to Empire, but another framework. Filter as needed if any applications use the same pattern. - -#### Associated Analytic story -* [Hermetic Wiper](/stories/hermetic_wiper) -* [Malicious PowerShell](/stories/malicious_powershell) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 81.0 | 90 | 90 | The following behavior was identified and typically related to PowerShell-Empire on $Computer$ by $UserID$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.](https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.) -* [https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63](https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63) -* [https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf](https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf) -* [https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/](https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/) -* [https://github.com/BC-SECURITY/Empire](https://github.com/BC-SECURITY/Empire) -* [https://www.splunk.com/en_us/blog/security/hunting-for-malicious-powershell-using-script-block-logging.html](https://www.splunk.com/en_us/blog/security/hunting-for-malicious-powershell-using-script-block-logging.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/empire.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/empire.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-02-24-detect_mimikatz_with_powershell_script_block_logging.md b/docs/_posts/2022-02-24-detect_mimikatz_with_powershell_script_block_logging.md deleted file mode 100644 index b21a7a1fd3..0000000000 --- a/docs/_posts/2022-02-24-detect_mimikatz_with_powershell_script_block_logging.md +++ /dev/null @@ -1,167 +0,0 @@ ---- -title: "Detect Mimikatz With PowerShell Script Block Logging" -excerpt: "OS Credential Dumping -, PowerShell -" -categories: - - Endpoint -last_modified_at: 2022-02-24 -toc: true -toc_label: "" -tags: - - OS Credential Dumping - - PowerShell - - Credential Access - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify suspicious PowerShell execution. Script Block Logging captures the command sent to PowerShell, the full command to be executed. Upon enabling, logs will output to Windows event logs. Dependent upon volume, enable no critical endpoints or all. \ -This analytic identifies common Mimikatz functions that may be identified in the script block, including `mimikatz`. This will catch the most basic use cases for Pass the Ticket, Pass the Hash and `-DumprCreds`. \ -During triage, review parallel processes using an EDR product or 4688 events. It will be important to understand the timeline of events around this activity. Review the entire logged PowerShell script block. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-02-24 -- **Author**: Michael Haag, Splunk -- **ID**: 8148c29c-c952-11eb-9255-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - -| [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 ScriptBlockText IN (*mimikatz*, *-dumpcr*, *sekurlsa::pth*, *kerberos::ptt*, *kerberos::golden*) -| stats count min(_time) as firstTime max(_time) as lastTime by Opcode Computer UserID EventCode ScriptBlockText -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_mimikatz_with_powershell_script_block_logging_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **detect_mimikatz_with_powershell_script_block_logging_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* ScriptBlockText -* Opcode -* Computer -* UserID -* EventCode - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -False positives should be limited as the commands being identifies are quite specific to EventCode 4104 and Mimikatz. Filter as needed. - -#### Associated Analytic story -* [Hermetic Wiper](/stories/hermetic_wiper) -* [Malicious PowerShell](/stories/malicious_powershell) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 90.0 | 90 | 100 | The following behavior was identified and typically related to MimiKatz being loaded within the context of PowerShell on $Computer$ by $UserID$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.](https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.) -* [https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63](https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63) -* [https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf](https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf) -* [https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/](https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/) -* [https://www.splunk.com/en_us/blog/security/hunting-for-malicious-powershell-using-script-block-logging.html](https://www.splunk.com/en_us/blog/security/hunting-for-malicious-powershell-using-script-block-logging.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/credaccess-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/credaccess-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-02-24-get-foresttrust_with_powershell_script_block.md b/docs/_posts/2022-02-24-get-foresttrust_with_powershell_script_block.md deleted file mode 100644 index 03a15db1b5..0000000000 --- a/docs/_posts/2022-02-24-get-foresttrust_with_powershell_script_block.md +++ /dev/null @@ -1,164 +0,0 @@ ---- -title: "Get-ForestTrust with PowerShell Script Block" -excerpt: "Domain Trust Discovery -, PowerShell -" -categories: - - Endpoint -last_modified_at: 2022-02-24 -toc: true -toc_label: "" -tags: - - Domain Trust Discovery - - PowerShell - - Discovery - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify suspicious PowerShell execution. Script Block Logging captures the command sent to PowerShell, the full command to be executed. Upon enabling, logs will output to Windows event logs. Dependent upon volume, enable on critical endpoints or all. \ -This analytic identifies Get-ForestTrust from PowerSploit in order to gather domain trust information. \ -During triage, review parallel processes using an EDR product or 4688 events. It will be important to understand the timeline of events around this activity. Review the entire logged PowerShell script block. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-02-24 -- **Author**: Michael Haag, Splunk -- **ID**: 70fac80e-0bf1-11ec-9ba0-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1482](https://attack.mitre.org/techniques/T1482/) | Domain Trust Discovery | Discovery | - -| [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 ScriptBlockText = "*get-foresttrust*" -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode ScriptBlockText Computer user_id -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `get_foresttrust_with_powershell_script_block_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **get-foresttrust_with_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* ScriptBlockText -* Path -* Opcode -* Computer -* UserID - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -False positives may be present. Tune as needed. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 12.0 | 30 | 40 | Suspicious PowerShell Get-ForestTrust was identified on endpoint $Computer$ by user $UserID$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://powersploit.readthedocs.io/en/latest/Recon/Get-ForestTrust/](https://powersploit.readthedocs.io/en/latest/Recon/Get-ForestTrust/) -* [https://www.splunk.com/en_us/blog/security/hunting-for-malicious-powershell-using-script-block-logging.html](https://www.splunk.com/en_us/blog/security/hunting-for-malicious-powershell-using-script-block-logging.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1482/discovery/windows-powershell-xml.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1482/discovery/windows-powershell-xml.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-02-25-powershell_domain_enumeration.md b/docs/_posts/2022-02-25-powershell_domain_enumeration.md deleted file mode 100644 index 2afffac1df..0000000000 --- a/docs/_posts/2022-02-25-powershell_domain_enumeration.md +++ /dev/null @@ -1,167 +0,0 @@ ---- -title: "PowerShell Domain Enumeration" -excerpt: "Command and Scripting Interpreter -, PowerShell -" -categories: - - Endpoint -last_modified_at: 2022-02-25 -toc: true -toc_label: "" -tags: - - Command and Scripting Interpreter - - PowerShell - - Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify suspicious PowerShell execution. Script Block Logging captures the command sent to PowerShell, the full command to be executed. Upon enabling, logs will output to Windows event logs. Dependent upon volume, enable on critical endpoints or all. \ -This analytic identifies specific PowerShell modules typically used to enumerate an organizations domain or users. \ -During triage, review parallel processes using an EDR product or 4688 events. It will be important to understand the timeline of events around this activity. Review the entire logged PowerShell script block. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-02-25 -- **Author**: Michael Haag, Splunk -- **ID**: e1866ce2-ca22-11eb-8e44-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -| [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 ScriptBlockText IN (*get-netdomaintrust*, *get-netforesttrust*, *get-addomain*, *get-adgroupmember*, *get-domainuser*) -| stats count min(_time) as firstTime max(_time) as lastTime by Computer EventCode ScriptBlockText -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `powershell_domain_enumeration_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **powershell_domain_enumeration_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* ScriptBlockText -* Opcode -* Computer -* UserID -* EventCode - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -It is possible there will be false positives, filter as needed. - -#### Associated Analytic story -* [Hermetic Wiper](/stories/hermetic_wiper) -* [Malicious PowerShell](/stories/malicious_powershell) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 42.0 | 60 | 70 | A suspicious powershell script contains domain enumeration command in $ScriptBlockText$ with EventCode $EventCode$ in host $Computer$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.](https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.) -* [https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63](https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63) -* [https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf](https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf) -* [https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/](https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/) -* [https://www.splunk.com/en_us/blog/security/hunting-for-malicious-powershell-using-script-block-logging.html](https://www.splunk.com/en_us/blog/security/hunting-for-malicious-powershell-using-script-block-logging.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/enumeration.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/enumeration.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/powershell_domain_enumeration.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-02-25-powershell_enable_smb1protocol_feature.md b/docs/_posts/2022-02-25-powershell_enable_smb1protocol_feature.md deleted file mode 100644 index ed94d97bb7..0000000000 --- a/docs/_posts/2022-02-25-powershell_enable_smb1protocol_feature.md +++ /dev/null @@ -1,163 +0,0 @@ ---- -title: "Powershell Enable SMB1Protocol Feature" -excerpt: "Obfuscated Files or Information -, Indicator Removal from Tools -" -categories: - - Endpoint -last_modified_at: 2022-02-25 -toc: true -toc_label: "" -tags: - - Obfuscated Files or Information - - Indicator Removal from Tools - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect a suspicious enabling of smb1protocol through "powershell.exe". This technique was seen in some ransomware (like reddot) where it enable smb share to do the lateral movement and encrypt other files within the compromise network system. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-02-25 -- **Author**: Teoderick Contreras, Splunk -- **ID**: afed80b2-d34b-11eb-a952-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1027](https://attack.mitre.org/techniques/T1027/) | Obfuscated Files or Information | Defense Evasion | - -| [T1027.005](https://attack.mitre.org/techniques/T1027/005/) | Indicator Removal from Tools | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 ScriptBlockText = "*Enable-WindowsOptionalFeature*" ScriptBlockText = "*SMB1Protocol*" -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode ScriptBlockText Computer UserID -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `powershell_enable_smb1protocol_feature_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **powershell_enable_smb1protocol_feature_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* ScriptBlockText -* Computer -* UserID - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the powershell logs from your endpoints. make sure you enable needed registry to monitor this event. - -#### Known False Positives -network operator may enable or disable this windows feature. - -#### Associated Analytic story -* [Hermetic Wiper](/stories/hermetic_wiper) -* [Malicious PowerShell](/stories/malicious_powershell) -* [Ransomware](/stories/ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | Powershell Enable SMB1Protocol Feature | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://app.any.run/tasks/c0f98850-af65-4352-9746-fbebadee4f05/](https://app.any.run/tasks/c0f98850-af65-4352-9746-fbebadee4f05/) -* [https://www.splunk.com/en_us/blog/security/hunting-for-malicious-powershell-using-script-block-logging.html](https://www.splunk.com/en_us/blog/security/hunting-for-malicious-powershell-using-script-block-logging.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/sbl_xml.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/sbl_xml.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-02-25-powershell_fileless_process_injection_via_getprocaddress.md b/docs/_posts/2022-02-25-powershell_fileless_process_injection_via_getprocaddress.md deleted file mode 100644 index 5abd2732e9..0000000000 --- a/docs/_posts/2022-02-25-powershell_fileless_process_injection_via_getprocaddress.md +++ /dev/null @@ -1,174 +0,0 @@ ---- -title: "Powershell Fileless Process Injection via GetProcAddress" -excerpt: "Command and Scripting Interpreter -, Process Injection -, PowerShell -" -categories: - - Endpoint -last_modified_at: 2022-02-25 -toc: true -toc_label: "" -tags: - - Command and Scripting Interpreter - - Process Injection - - PowerShell - - Execution - - Defense Evasion - - Privilege Escalation - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify suspicious PowerShell execution. Script Block Logging captures the command sent to PowerShell, the full command to be executed. Upon enabling, logs will output to Windows event logs. Dependent upon volume, enable no critical endpoints or all. \ -This analytic identifies `GetProcAddress` in the script block. This is not normal to be used by most PowerShell scripts and is typically unsafe/malicious. Many attack toolkits use GetProcAddress to obtain code execution. \ -In use, `$var_gpa = $var_unsafe_native_methods.GetMethod(GetProcAddress` and later referenced/executed elsewhere. \ -During triage, review parallel processes using an EDR product or 4688 events. It will be important to understand the timeline of events around this activity. Review the entire logged PowerShell script block. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-02-25 -- **Author**: Michael Haag, Splunk -- **ID**: a26d9db4-c883-11eb-9d75-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -| [T1055](https://attack.mitre.org/techniques/T1055/) | Process Injection | Defense Evasion, Privilege Escalation | - -| [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 ScriptBlockText=*getprocaddress* -| stats count min(_time) as firstTime max(_time) as lastTime by Opcode Computer UserID EventCode ScriptBlockText -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `powershell_fileless_process_injection_via_getprocaddress_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **powershell_fileless_process_injection_via_getprocaddress_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* ScriptBlockText -* Opcode -* Computer -* UserID -* EventCode - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -Limited false positives. Filter as needed. - -#### Associated Analytic story -* [Hermetic Wiper](/stories/hermetic_wiper) -* [Malicious PowerShell](/stories/malicious_powershell) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 48.0 | 60 | 80 | A suspicious powershell script contains GetProcAddress API in $ScriptBlockText$ with EventCode $EventCode$ in host $Computer$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.](https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.) -* [https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63](https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63) -* [https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf](https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf) -* [https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/](https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/) -* [https://www.splunk.com/en_us/blog/security/hunting-for-malicious-powershell-using-script-block-logging.html](https://www.splunk.com/en_us/blog/security/hunting-for-malicious-powershell-using-script-block-logging.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/sbl_xml.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/sbl_xml.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-02-25-powershell_processing_stream_of_data.md b/docs/_posts/2022-02-25-powershell_processing_stream_of_data.md deleted file mode 100644 index 234545e5a1..0000000000 --- a/docs/_posts/2022-02-25-powershell_processing_stream_of_data.md +++ /dev/null @@ -1,166 +0,0 @@ ---- -title: "Powershell Processing Stream Of Data" -excerpt: "Command and Scripting Interpreter -, PowerShell -" -categories: - - Endpoint -last_modified_at: 2022-02-25 -toc: true -toc_label: "" -tags: - - Command and Scripting Interpreter - - PowerShell - - Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies suspicious PowerShell script execution via EventCode 4104 that is processing compressed stream data. This is typically found in obfuscated PowerShell or PowerShell executing embedded .NET or binary files that are stream flattened and will be deflated durnig execution. During triage, review parallel processes within the same timeframe. Review the full script block to identify other related artifacts. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-02-25 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 0d718b52-c9f1-11eb-bc61-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -| [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 ScriptBlockText = "*IO.Compression.*" OR ScriptBlockText = "*IO.StreamReader*" OR ScriptBlockText = "*]::Decompress*" -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode ScriptBlockText Computer UserID -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `powershell_processing_stream_of_data_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **powershell_processing_stream_of_data_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* ScriptBlockText -* Computer -* UserID -* Score - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -powershell may used this function to process compressed data. - -#### Associated Analytic story -* [Hermetic Wiper](/stories/hermetic_wiper) -* [Malicious PowerShell](/stories/malicious_powershell) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 40.0 | 50 | 80 | A suspicious powershell script contains stream command in $ScriptBlockText$ commonly for processing compressed or to decompressed binary file with EventCode $EventCode$ in host $Computer$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://medium.com/@ahmedjouini99/deobfuscating-emotets-powershell-payload-e39fb116f7b9](https://medium.com/@ahmedjouini99/deobfuscating-emotets-powershell-payload-e39fb116f7b9) -* [https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell](https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell) -* [https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63](https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63) -* [https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf](https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf) -* [https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/](https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/) -* [https://www.splunk.com/en_us/blog/security/hunting-for-malicious-powershell-using-script-block-logging.html](https://www.splunk.com/en_us/blog/security/hunting-for-malicious-powershell-using-script-block-logging.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/streamreader.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/streamreader.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/powershell_processing_stream_of_data.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-02-25-recon_using_wmi_class.md b/docs/_posts/2022-02-25-recon_using_wmi_class.md deleted file mode 100644 index 4077b5c3f4..0000000000 --- a/docs/_posts/2022-02-25-recon_using_wmi_class.md +++ /dev/null @@ -1,167 +0,0 @@ ---- -title: "Recon Using WMI Class" -excerpt: "Gather Victim Host Information -, PowerShell -" -categories: - - Endpoint -last_modified_at: 2022-02-25 -toc: true -toc_label: "" -tags: - - Gather Victim Host Information - - PowerShell - - Reconnaissance - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies suspicious PowerShell via EventCode 4104, where WMI is performing an event query looking for running processes or running services. This technique is commonly found where the adversary will identify services and system information on the compromised machine. During triage, review parallel processes within the same timeframe. Review the full script block to identify other related artifacts. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-02-25 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 018c1972-ca07-11eb-9473-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1592](https://attack.mitre.org/techniques/T1592/) | Gather Victim Host Information | Reconnaissance | - -| [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 (ScriptBlockText= "*SELECT*" OR ScriptBlockText= "*Get-WmiObject*") AND (ScriptBlockText= "*Win32_Bios*" OR ScriptBlockText= "*Win32_OperatingSystem*" OR ScriptBlockText= "*Win32_Processor*" OR ScriptBlockText= "*Win32_ComputerSystem*" OR ScriptBlockText= "*Win32_ComputerSystemProduct*" OR ScriptBlockText= "*Win32_ShadowCopy*") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode ScriptBlockText Computer UserID -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `recon_using_wmi_class_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **recon_using_wmi_class_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* ScriptBlockText -* Computer -* UserID - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -network administrator may used this command for checking purposes - -#### Associated Analytic story -* [Hermetic Wiper](/stories/hermetic_wiper) -* [Malicious PowerShell](/stories/malicious_powershell) -* [Industroyer2](/stories/industroyer2) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 60.0 | 75 | 80 | A suspicious powershell script contains host recon command in $ScriptBlockText$ with EventCode $EventCode$ in host $Computer$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://news.sophos.com/en-us/2020/05/12/maze-ransomware-1-year-counting/](https://news.sophos.com/en-us/2020/05/12/maze-ransomware-1-year-counting/) -* [https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.](https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.) -* [https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63](https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63) -* [https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf](https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf) -* [https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/](https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/) -* [https://www.splunk.com/en_us/blog/security/hunting-for-malicious-powershell-using-script-block-logging.html](https://www.splunk.com/en_us/blog/security/hunting-for-malicious-powershell-using-script-block-logging.html) -* [https://www.welivesecurity.com/2022/04/12/industroyer2-industroyer-reloaded/](https://www.welivesecurity.com/2022/04/12/industroyer2-industroyer-reloaded/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/reconusingwmi.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/reconusingwmi.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/recon_using_wmi_class.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-02-25-windows_disable_memory_crash_dump.md b/docs/_posts/2022-02-25-windows_disable_memory_crash_dump.md deleted file mode 100644 index 4b67cb97fb..0000000000 --- a/docs/_posts/2022-02-25-windows_disable_memory_crash_dump.md +++ /dev/null @@ -1,177 +0,0 @@ ---- -title: "Windows Disable Memory Crash Dump" -excerpt: "Data Destruction -" -categories: - - Endpoint -last_modified_at: 2022-02-25 -toc: true -toc_label: "" -tags: - - Data Destruction - - Impact - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies a process that is attempting to disable the ability on Windows to generate a memory crash dump. This was recently identified being utilized by HermeticWiper. To disable crash dumps, the value must be set to 0. This feature is typically modified to perform a memory crash dump when a computer stops unexpectedly because of a Stop error (also known as a blue screen, system crash, or bug check). - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-02-25 -- **Author**: Michael Haag, Splunk -- **ID**: 59e54602-9680-11ec-a8a6-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1485](https://attack.mitre.org/techniques/T1485/) | Data Destruction | Impact | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry where (Registry.registry_path="*\\CurrentControlSet\\Control\\CrashControl\\CrashDumpEnabled") AND Registry.registry_value_data="0x00000000" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid Registry.registry_key_name -| `drop_dm_object_name(Registry)` -|join process_guid [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid -| `drop_dm_object_name(Processes)` -| fields _time dest user parent_process_name parent_process process_name process_path process process_guid registry_path registry_value_name registry_value_data registry_key_name] -| table _time dest user parent_process_name parent_process process_name process_path process process_guid registry_path registry_value_name registry_value_data registry_key_name -| `windows_disable_memory_crash_dump_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_disable_memory_crash_dump_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Filesystem.file_create_time -* Filesystem.process_id -* Filesystem.file_name -* Filesystem.user -* Filesystem.file_path -* Filesystem.dest -* Processes.process_id -* Processes.process_name -* Processes.process -* Processes.dest -* Processes.parent_process_name -* Processes.parent_process -* Processes.process_guid - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the Filesystem responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Filesystem` and `Registry` node. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Data Destruction](/stories/data_destruction) -* [Ransomware](/stories/ransomware) -* [Hermetic Wiper](/stories/hermetic_wiper) -* [Windows Registry Abuse](/stories/windows_registry_abuse) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 90.0 | 90 | 100 | A process $process_name$ was identified attempting to disable memory crash dumps on $dest$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://blog.talosintelligence.com/2022/02/threat-advisory-hermeticwiper.html](https://blog.talosintelligence.com/2022/02/threat-advisory-hermeticwiper.html) -* [https://docs.microsoft.com/en-us/troubleshoot/windows-server/performance/memory-dump-file-options](https://docs.microsoft.com/en-us/troubleshoot/windows-server/performance/memory-dump-file-options) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/hermetic_wiper/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/hermetic_wiper/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_disable_memory_crash_dump.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-02-25-windows_file_without_extension_in_critical_folder.md b/docs/_posts/2022-02-25-windows_file_without_extension_in_critical_folder.md deleted file mode 100644 index 7c5c0a2b02..0000000000 --- a/docs/_posts/2022-02-25-windows_file_without_extension_in_critical_folder.md +++ /dev/null @@ -1,175 +0,0 @@ ---- -title: "Windows File Without Extension In Critical Folder" -excerpt: "Data Destruction -" -categories: - - Endpoint -last_modified_at: 2022-02-25 -toc: true -toc_label: "" -tags: - - Data Destruction - - Impact - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to look for suspicious file creation in the critical folder like "System32\Drivers" folder without file extension. This artifacts was seen in latest hermeticwiper where it drops its driver component in Driver Directory both the compressed(without file extension) and the actual driver component (with .sys file extension). This TTP is really a good indication that a host might be compromised by this destructive malware that wipes the boot sector of the system. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-02-25 -- **Author**: Teoderick Contreras, Bhavin Patel, Splunk -- **ID**: 0dbcac64-963c-11ec-bf04-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1485](https://attack.mitre.org/techniques/T1485/) | Data Destruction | Impact | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Filesystem where Filesystem.file_path IN ("*\\System32\\drivers\\*", "*\\syswow64\\drivers\\*") by _time span=5m Filesystem.dest Filesystem.user Filesystem.file_name Filesystem.file_path Filesystem.process_guid Filesystem.file_create_time -| `drop_dm_object_name(Filesystem)` -| rex field="file_name" "\.(?[^\.]*$)" -| where isnull(extension) -| join process_guid [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=5m Processes.process_name Processes.dest Processes.process_guid Processes.user -| `drop_dm_object_name(Processes)`] -| stats count min(_time) as firstTime max(_time) as lastTime by dest process_name process_guid file_name file_path file_create_time user -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_file_without_extension_in_critical_folder_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_file_without_extension_in_critical_folder_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Filesystem.file_create_time -* Filesystem.process_id -* Filesystem.file_name -* Filesystem.user -* Filesystem.file_path -* Filesystem.dest -* Processes.process_name -* Processes.dest -* Processes.process_guid -* Processes.user - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the Filesystem responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Filesystem` node. - -#### Known False Positives -Unknown at this point - -#### Associated Analytic story -* [Data Destruction](/stories/data_destruction) -* [Hermetic Wiper](/stories/hermetic_wiper) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 90.0 | 90 | 100 | Driver file with out file extension drop in $file_path$ in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://blog.talosintelligence.com/2022/02/threat-advisory-hermeticwiper.html](https://blog.talosintelligence.com/2022/02/threat-advisory-hermeticwiper.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/hermetic_wiper/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/hermetic_wiper/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_file_without_extension_in_critical_folder.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-02-25-windows_raw_access_to_disk_volume_partition.md b/docs/_posts/2022-02-25-windows_raw_access_to_disk_volume_partition.md deleted file mode 100644 index 8585a4f9e0..0000000000 --- a/docs/_posts/2022-02-25-windows_raw_access_to_disk_volume_partition.md +++ /dev/null @@ -1,171 +0,0 @@ ---- -title: "Windows Raw Access To Disk Volume Partition" -excerpt: "Disk Structure Wipe -, Disk Wipe -" -categories: - - Endpoint -last_modified_at: 2022-02-25 -toc: true -toc_label: "" -tags: - - Disk Structure Wipe - - Disk Wipe - - Impact - - Impact - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to look for suspicious raw access read to device disk partition of the host machine. This technique was seen in several attacks by adversaries or threat actor to wipe, encrypt or overwrite the boot sector of each partition as part of their impact payload for example the "hermeticwiper" malware. This detection is a good indicator that there is a process try to read or write on boot sector. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-02-25 -- **Author**: Teoderick Contreras, Splunk -- **ID**: a85aa37e-9647-11ec-90c5-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1561.002](https://attack.mitre.org/techniques/T1561/002/) | Disk Structure Wipe | Impact | - -| [T1561](https://attack.mitre.org/techniques/T1561/) | Disk Wipe | Impact | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventCode=9 Device = \\Device\\HarddiskVolume* NOT (Image IN("*\\Windows\\System32\\*", "*\\Windows\\SysWOW64\\*")) -| stats count min(_time) as firstTime max(_time) as lastTime by Image Device ProcessGuid ProcessId EventDescription EventCode Computer -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_raw_access_to_disk_volume_partition_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **windows_raw_access_to_disk_volume_partition_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Computer -* Image -* Device -* ProcessGuid -* ProcessId -* EventDescription -* EventCode - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the raw access read event (like sysmon eventcode 9), process name and process guid from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -This event is really notable but we found minimal number of normal application from system32 folder like svchost.exe accessing it too. In this case we used 'system32' and 'syswow64' path as a filter for this detection. - -#### Associated Analytic story -* [Caddy Wiper](/stories/caddy_wiper) -* [Data Destruction](/stories/data_destruction) -* [Hermetic Wiper](/stories/hermetic_wiper) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 90.0 | 90 | 100 | Process accessing disk partition $device$ in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://blog.talosintelligence.com/2022/02/threat-advisory-hermeticwiper.html](https://blog.talosintelligence.com/2022/02/threat-advisory-hermeticwiper.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/hermetic_wiper/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/hermetic_wiper/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_raw_access_to_disk_volume_partition.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-02-26-serviceprincipalnames_discovery_with_powershell.md b/docs/_posts/2022-02-26-serviceprincipalnames_discovery_with_powershell.md deleted file mode 100644 index cf23e2459f..0000000000 --- a/docs/_posts/2022-02-26-serviceprincipalnames_discovery_with_powershell.md +++ /dev/null @@ -1,174 +0,0 @@ ---- -title: "ServicePrincipalNames Discovery with PowerShell" -excerpt: "Kerberoasting -" -categories: - - Endpoint -last_modified_at: 2022-02-26 -toc: true -toc_label: "" -tags: - - Kerberoasting - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies `powershell.exe` usage, using Script Block Logging EventCode 4104, related to querying the domain for Service Principle Names. typically, this is a precursor activity related to kerberoasting or the silver ticket attack. \ -What is a ServicePrincipleName? \ -A service principal name (SPN) is a unique identifier of a service instance. SPNs are used by Kerberos authentication to associate a service instance with a service logon account. This allows a client application to request that the service authenticate an account even if the client does not have the account name.\ -The following analytic identifies the use of KerberosRequestorSecurityToken class within the script block. Using .NET System.IdentityModel.Tokens.KerberosRequestorSecurityToken class in PowerShell is the equivelant of using setspn.exe. \ -During triage, review parallel processes for further suspicious activity. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-02-26 -- **Author**: Michael Haag, Splunk -- **ID**: 13243068-2d38-11ec-8908-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1558.003](https://attack.mitre.org/techniques/T1558/003/) | Kerberoasting | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 ScriptBlockText="*KerberosRequestorSecurityToken*" -| stats count min(_time) as firstTime max(_time) as lastTime by ScriptBlockText Opcode Computer UserID EventCode -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `serviceprincipalnames_discovery_with_powershell_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **serviceprincipalnames_discovery_with_powershell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* ScriptBlockText -* Opcode -* Computer -* UserID -* EventCode - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -False positives should be limited, however filter as needed. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) -* [Active Directory Kerberos Attacks](/stories/active_directory_kerberos_attacks) -* [Malicious PowerShell](/stories/malicious_powershell) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $Computer$ by user $UserID$ attempting to identify service principle names. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://docs.microsoft.com/en-us/windows/win32/ad/service-principal-names](https://docs.microsoft.com/en-us/windows/win32/ad/service-principal-names) -* [https://docs.microsoft.com/en-us/dotnet/api/system.identitymodel.tokens.kerberosrequestorsecuritytoken?view=netframework-4.8](https://docs.microsoft.com/en-us/dotnet/api/system.identitymodel.tokens.kerberosrequestorsecuritytoken?view=netframework-4.8) -* [https://www.ired.team/offensive-security-experiments/active-directory-kerberos-abuse/t1208-kerberoasting](https://www.ired.team/offensive-security-experiments/active-directory-kerberos-abuse/t1208-kerberoasting) -* [https://strontic.github.io/xcyclopedia/library/setspn.exe-5C184D581524245DAD7A0A02B51FD2C2.html](https://strontic.github.io/xcyclopedia/library/setspn.exe-5C184D581524245DAD7A0A02B51FD2C2.html) -* [https://attack.mitre.org/techniques/T1558/003/](https://attack.mitre.org/techniques/T1558/003/) -* [https://social.technet.microsoft.com/wiki/contents/articles/717.service-principal-names-spn-setspn-syntax.aspx](https://social.technet.microsoft.com/wiki/contents/articles/717.service-principal-names-spn-setspn-syntax.aspx) -* [https://web.archive.org/web/20220212163642/https://www.harmj0y.net/blog/powershell/kerberoasting-without-mimikatz/](https://web.archive.org/web/20220212163642/https://www.harmj0y.net/blog/powershell/kerberoasting-without-mimikatz/) -* [https://blog.zsec.uk/paving-2-da-wholeset/](https://blog.zsec.uk/paving-2-da-wholeset/) -* [https://msitpros.com/?p=3113](https://msitpros.com/?p=3113) -* [https://adsecurity.org/?p=3466](https://adsecurity.org/?p=3466) -* [https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.](https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.) -* [https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63](https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63) -* [https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf](https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf) -* [https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/](https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1558.003/atomic_red_team/windows-powershell_kerberos.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1558.003/atomic_red_team/windows-powershell_kerberos.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/serviceprincipalnames_discovery_with_powershell.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-02-28-excessive_distinct_processes_from_windows_temp.md b/docs/_posts/2022-02-28-excessive_distinct_processes_from_windows_temp.md deleted file mode 100644 index 74b80bc8eb..0000000000 --- a/docs/_posts/2022-02-28-excessive_distinct_processes_from_windows_temp.md +++ /dev/null @@ -1,156 +0,0 @@ ---- -title: "Excessive distinct processes from Windows Temp" -excerpt: "Command and Scripting Interpreter -" -categories: - - Endpoint -last_modified_at: 2022-02-28 -toc: true -toc_label: "" -tags: - - Command and Scripting Interpreter - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic will identify suspicious series of process executions. We have observed that post exploit framework tools like Koadic and Meterpreter will launch an excessive number of processes with distinct file paths from Windows\Temp to execute actions on objective. This behavior is extremely anomalous compared to typical application behaviors that use Windows\Temp. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Microsoft Windows](https://splunkbase.splunk.com/app/742) -- **Last Updated**: 2022-02-28 -- **Author**: Michael Hart, Mauricio Velazco, Splunk -- **ID**: 23587b6a-c479-11eb-b671-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` values(Processes.process) as process distinct_count(Processes.process) as distinct_process_count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_path = "*\\Windows\\Temp\\*" by Processes.dest Processes.user _time span=20m -| where distinct_process_count > 37 -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `excessive_distinct_processes_from_windows_temp_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **excessive_distinct_processes_from_windows_temp_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process -* Processes.dest -* Processes.user - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the full process path in the process field of CIM's Process data model. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed sc.exe may be used. - -#### Known False Positives -Many benign applications will create processes from executables in Windows\Temp, although unlikely to exceed the given threshold. Filter as needed. - -#### Associated Analytic story -* [Meterpreter](/stories/meterpreter) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | Multiple processes were executed out of windows\temp within a short amount of time on $dest$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/](https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059/meterpreter/windows_temp_processes/logExcessiveWindowsTemp.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059/meterpreter/windows_temp_processes/logExcessiveWindowsTemp.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/excessive_distinct_processes_from_windows_temp.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-02-28-excessive_number_of_distinct_processes_created_in_windows_temp_folder.md b/docs/_posts/2022-02-28-excessive_number_of_distinct_processes_created_in_windows_temp_folder.md deleted file mode 100644 index 845a2cec54..0000000000 --- a/docs/_posts/2022-02-28-excessive_number_of_distinct_processes_created_in_windows_temp_folder.md +++ /dev/null @@ -1,106 +0,0 @@ ---- -title: "Excessive number of distinct processes created in Windows Temp folder" -excerpt: "Command and Scripting Interpreter -" -categories: - - Endpoint -last_modified_at: 2022-02-28 -toc: true -toc_label: "" -tags: - - Command and Scripting Interpreter - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic will identify suspicious series of process executions. We have observed that post exploit framework tools like Koadic and Meterpreter will launch an excessive number of processes with distinct file paths from Windows\Temp to execute actions on objective. This behavior is extremely anomalous compared to typical application behaviors that use Windows\Temp. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/object-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-02-28 -- **Author**: Michael Hart, Mauricio Velazco, Splunk -- **ID**: 23587b6a-c479-11eb-b671-acde48001122 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -#### Search - -``` - -| tstats `security_content_summariesonly` values(Processes.process) as process distinct_count(Processes.process) as distinct_process_count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_path = "*\\Windows\\Temp\\*" by Processes.dest Processes.user _time span=20m -| where distinct_process_count > 37 -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `excessive_number_of_distinct_processes_created_in_windows_temp_folder_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -Note that `excessive_number_of_distinct_processes_created_in_windows_temp_folder_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process -* Processes.dest -* Processes.user - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the full process path in the process field of CIM's Process data model. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed sc.exe may be used. - -#### Known False Positives -Many benign applications will create processes from executables in Windows\Temp, although unlikely to exceed the given threshold. Filter as needed. - -#### Associated Analytic story -* [Meterpreter](/stories/meterpreter) - - -#### Kill Chain Phase -* Exploitation - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | Multiple processes were executed out of windows\temp within a short amount of time on $dest$. | - - - - -#### Reference - -* [https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/](https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059/meterpreter/windows_temp_processes/logExcessiveWindowsTemp.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059/meterpreter/windows_temp_processes/logExcessiveWindowsTemp.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-03-02-windows_modify_show_compress_color_and_info_tip_registry.md b/docs/_posts/2022-03-02-windows_modify_show_compress_color_and_info_tip_registry.md deleted file mode 100644 index 27358ce3c5..0000000000 --- a/docs/_posts/2022-03-02-windows_modify_show_compress_color_and_info_tip_registry.md +++ /dev/null @@ -1,169 +0,0 @@ ---- -title: "Windows Modify Show Compress Color And Info Tip Registry" -excerpt: "Modify Registry -" -categories: - - Endpoint -last_modified_at: 2022-03-02 -toc: true -toc_label: "" -tags: - - Modify Registry - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to look for suspicious registry modification related to file compression color and information tips. This IOC was seen in hermetic wiper where it has a thread that will create this registry entry to change the color of compressed or encrypted files in NTFS file system as well as the pop up information tips. This is a good indicator that a process tries to modified one of the registry GlobalFolderOptions related to file compression attribution in terms of color in NTFS file system. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-03-02 -- **Author**: Teoderick Contreras, Splunk -- **ID**: b7548c2e-9a10-11ec-99e3-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1112](https://attack.mitre.org/techniques/T1112/) | Modify Registry | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path = "*\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced*" AND Registry.registry_value_name IN("ShowCompColor", "ShowInfoTip") by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid -| `drop_dm_object_name(Registry)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] -| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data -| `windows_modify_show_compress_color_and_info_tip_registry_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_modify_show_compress_color_and_info_tip_registry_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.registry_key_name -* Registry.registry_path -* Registry.registry_value_name -* Registry.dest Registry.user - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the Filesystem responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` and `Registry` node. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Data Destruction](/stories/data_destruction) -* [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics) -* [Hermetic Wiper](/stories/hermetic_wiper) -* [Windows Registry Abuse](/stories/windows_registry_abuse) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | Registry modification in "ShowCompColor" and "ShowInfoTips" on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://blog.talosintelligence.com/2022/02/threat-advisory-hermeticwiper.html](https://blog.talosintelligence.com/2022/02/threat-advisory-hermeticwiper.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/hermetic_wiper/globalfolderoptions_reg/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/hermetic_wiper/globalfolderoptions_reg/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_modify_show_compress_color_and_info_tip_registry.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-03-03-aws_createaccesskey.md b/docs/_posts/2022-03-03-aws_createaccesskey.md deleted file mode 100644 index bad265d09a..0000000000 --- a/docs/_posts/2022-03-03-aws_createaccesskey.md +++ /dev/null @@ -1,168 +0,0 @@ ---- -title: "AWS CreateAccessKey" -excerpt: "Cloud Account -, Create Account -" -categories: - - Cloud -last_modified_at: 2022-03-03 -toc: true -toc_label: "" -tags: - - Cloud Account - - Create Account - - Persistence - - Persistence - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for AWS CloudTrail events where a user A who has already permission to create access keys, makes an API call to create access keys for another user B. Attackers have been know to use this technique for Privilege Escalation in case new victim(user B) has more permissions than old victim(user B) - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-03-03 -- **Author**: Bhavin Patel, Splunk -- **ID**: 2a9b80d3-6340-4345-11ad-212bf3d0d111 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1136.003](https://attack.mitre.org/techniques/T1136/003/) | Cloud Account | Persistence | - -| [T1136](https://attack.mitre.org/techniques/T1136/) | Create Account | Persistence | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.DS -* PR.AC -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 13 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cloudtrail` eventName = CreateAccessKey userAgent !=console.amazonaws.com errorCode = success -| eval match=if(match(userIdentity.userName,requestParameters.userName),1,0) -| search match=0 -| stats count min(_time) as firstTime max(_time) as lastTime by requestParameters.userName src eventName eventSource aws_account_id errorCode userAgent eventID awsRegion userIdentity.principalId user_arn -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -|`aws_createaccesskey_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) - -> :information_source: -> **aws_createaccesskey_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* eventName -* userAgent -* errorCode -* requestParameters.userName - - -#### How To Implement -You must install splunk AWS add on and Splunk App for AWS. This search works with AWS CloudTrail logs. - -#### Known False Positives -While this search has no known false positives, it is possible that an AWS admin has legitimately created keys for another user. - -#### Associated Analytic story -* [AWS IAM Privilege Escalation](/stories/aws_iam_privilege_escalation) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 63.0 | 70 | 90 | User $user_arn$ is attempting to create access keys for $requestParameters.userName$ from this IP $src$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://bishopfox.com/blog/privilege-escalation-in-aws](https://bishopfox.com/blog/privilege-escalation-in-aws) -* [https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation-part-2/](https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation-part-2/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_createaccesskey/aws_cloudtrail_events.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_createaccesskey/aws_cloudtrail_events.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/aws_createaccesskey.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2022-03-03-aws_updateloginprofile.md b/docs/_posts/2022-03-03-aws_updateloginprofile.md deleted file mode 100644 index 8b8bb3f691..0000000000 --- a/docs/_posts/2022-03-03-aws_updateloginprofile.md +++ /dev/null @@ -1,168 +0,0 @@ ---- -title: "AWS UpdateLoginProfile" -excerpt: "Cloud Account -, Create Account -" -categories: - - Cloud -last_modified_at: 2022-03-03 -toc: true -toc_label: "" -tags: - - Cloud Account - - Create Account - - Persistence - - Persistence - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for AWS CloudTrail events where a user A who has already permission to update login profile, makes an API call to update login profile for another user B . Attackers have been know to use this technique for Privilege Escalation in case new victim(user B) has more permissions than old victim(user B) - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-03-03 -- **Author**: Bhavin Patel, Splunk -- **ID**: 2a9b80d3-6a40-4115-11ad-212bf3d0d111 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1136.003](https://attack.mitre.org/techniques/T1136/003/) | Cloud Account | Persistence | - -| [T1136](https://attack.mitre.org/techniques/T1136/) | Create Account | Persistence | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.DS -* PR.AC -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 13 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - `cloudtrail` eventName = UpdateLoginProfile userAgent !=console.amazonaws.com errorCode = success -| eval match=if(match(userIdentity.userName,requestParameters.userName), 1,0) -| search match=0 -| stats count min(_time) as firstTime max(_time) as lastTime by requestParameters.userName src eventName eventSource aws_account_id errorCode userAgent eventID awsRegion userIdentity.userName user_arn -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `aws_updateloginprofile_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) - -> :information_source: -> **aws_updateloginprofile_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* eventName -* userAgent -* errorCode -* requestParameters.userName - - -#### How To Implement -You must install splunk AWS add on and Splunk App for AWS. This search works with AWS CloudTrail logs. - -#### Known False Positives -While this search has no known false positives, it is possible that an AWS admin has legitimately created keys for another user. - -#### Associated Analytic story -* [AWS IAM Privilege Escalation](/stories/aws_iam_privilege_escalation) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 30.0 | 50 | 60 | From IP address $sourceIPAddress$, user agent $userAgent$ has trigged an event $eventName$ for updating the existing login profile, potentially giving user $user_arn$ more access privilleges | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://bishopfox.com/blog/privilege-escalation-in-aws](https://bishopfox.com/blog/privilege-escalation-in-aws) -* [https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation-part-2/](https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation-part-2/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_updateloginprofile/aws_cloudtrail_events.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_updateloginprofile/aws_cloudtrail_events.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/aws_updateloginprofile.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2022-03-04-kerberos_tgt_request_using_rc4_encryption.md b/docs/_posts/2022-03-04-kerberos_tgt_request_using_rc4_encryption.md deleted file mode 100644 index 24db4f18a4..0000000000 --- a/docs/_posts/2022-03-04-kerberos_tgt_request_using_rc4_encryption.md +++ /dev/null @@ -1,153 +0,0 @@ ---- -title: "Kerberos TGT Request Using RC4 Encryption" -excerpt: "Use Alternate Authentication Material -" -categories: - - Endpoint -last_modified_at: 2022-03-04 -toc: true -toc_label: "" -tags: - - Use Alternate Authentication Material - - Defense Evasion - - Lateral Movement - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic leverages Event 4768, A Kerberos authentication ticket (TGT) was requested, to identify a TGT request with encryption type 0x17, or RC4-HMAC. This encryption type is no longer utilized by newer systems and could represent evidence of an OverPass The Hash attack. Similar to Pass The Hash, OverPass The Hash is a form of credential theft that allows adversaries to move laterally or consume resources in a target network. Leveraging this attack, an adversary who has stolen the NTLM hash of a valid domain account is able to authenticate to the Kerberos Distribution Center(KDC) on behalf of the legitimate account and obtain a Kerberos TGT ticket. Depending on the privileges of the compromised account, this ticket may be used to obtain unauthorized access to systems and other network resources. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-03-04 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 18916468-9c04-11ec-bdc6-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1550](https://attack.mitre.org/techniques/T1550/) | Use Alternate Authentication Material | Defense Evasion, Lateral Movement | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - `wineventlog_security` EventCode=4768 Ticket_Encryption_Type=0x17 Account_Name!=*$ -| `kerberos_tgt_request_using_rc4_encryption_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) - -> :information_source: -> **kerberos_tgt_request_using_rc4_encryption_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Ticket_Encryption_Type -* Account_Name -* Client_Address - - -#### How To Implement -To successfully implement this search, you need to be ingesting Domain Controller and Kerberos events. The Advanced Security Audit policy setting `Audit Kerberos Authentication Service` within `Account Logon` needs to be enabled. - -#### Known False Positives -Based on Microsoft documentation, legacy systems or applications will use RC4-HMAC as the default encryption for TGT requests. Specifically, systems before Windows Server 2008 and Windows Vista. Newer systems will use AES128 or AES256. - -#### Associated Analytic story -* [Active Directory Kerberos Attacks](/stories/active_directory_kerberos_attacks) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | A Kerberos TGT request with RC4 encryption was requested for $Account_Name$ from $Client_Address$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://stealthbits.com/blog/how-to-detect-overpass-the-hash-attacks/](https://stealthbits.com/blog/how-to-detect-overpass-the-hash-attacks/) -* [https://www.thehacker.recipes/ad/movement/kerberos/ptk](https://www.thehacker.recipes/ad/movement/kerberos/ptk) -* [https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4768](https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4768) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1550/impacket/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1550/impacket/windows-security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/kerberos_tgt_request_using_rc4_encryption.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-03-04-macos_lolbin.md b/docs/_posts/2022-03-04-macos_lolbin.md deleted file mode 100644 index 94c82a2200..0000000000 --- a/docs/_posts/2022-03-04-macos_lolbin.md +++ /dev/null @@ -1,172 +0,0 @@ ---- -title: "MacOS LOLbin" -excerpt: "Unix Shell -, Command and Scripting Interpreter -" -categories: - - Endpoint -last_modified_at: 2022-03-04 -toc: true -toc_label: "" -tags: - - Unix Shell - - Command and Scripting Interpreter - - Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -Detect multiple executions of Living off the Land (LOLbin) binaries in a short period of time. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-03-04 -- **Author**: Patrick Bareiss, Splunk -- **ID**: 58d270fb-5b39-418e-a855-4b8ac046805e - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059.004](https://attack.mitre.org/techniques/T1059/004/) | Unix Shell | Execution | - -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`osquery` name=es_process_events columns.cmdline IN ("find*", "crontab*", "screencapture*", "openssl*", "curl*", "wget*", "killall*", "funzip*") -| rename columns.* as * -| stats min(_time) as firstTime max(_time) as lastTime values(cmdline) as cmdline, values(pid) as pid, values(parent) as parent, values(path) as path, values(signing_id) as signing_id, dc(path) as dc_path by username host -| rename username as User, cmdline as process, path as process_path -| where dc_path > 3 -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `macos_lolbin_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [osquery](https://github.com/splunk/security_content/blob/develop/macros/osquery.yml) - -> :information_source: -> **macos_lolbin_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* columns.cmdline -* columns.pid -* columns.parent -* columns.path -* columns.signing_id -* columns.username -* host - - -#### How To Implement -This detection uses osquery and endpoint security on MacOS. Follow the link in references, which describes how to setup process auditing in MacOS with endpoint security and osquery. - -#### Known False Positives -None identified. - -#### Associated Analytic story -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | Multiplle LOLbin are executed on host $host$ by user $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://osquery.readthedocs.io/en/stable/deployment/process-auditing/](https://osquery.readthedocs.io/en/stable/deployment/process-auditing/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.004/macos_lolbin/osquery.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.004/macos_lolbin/osquery.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/macos_lolbin.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-03-08-suspicious_msbuild_path.md b/docs/_posts/2022-03-08-suspicious_msbuild_path.md deleted file mode 100644 index f3a0b01783..0000000000 --- a/docs/_posts/2022-03-08-suspicious_msbuild_path.md +++ /dev/null @@ -1,188 +0,0 @@ ---- -title: "Suspicious msbuild path" -excerpt: "Masquerading -, Trusted Developer Utilities Proxy Execution -, Rename System Utilities -, MSBuild -" -categories: - - Endpoint -last_modified_at: 2022-03-08 -toc: true -toc_label: "" -tags: - - Masquerading - - Trusted Developer Utilities Proxy Execution - - Rename System Utilities - - MSBuild - - Defense Evasion - - Defense Evasion - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies msbuild.exe executing from a non-standard path. Msbuild.exe is natively found in C:\Windows\Microsoft.NET\Framework\v4.0.30319 and C:\Windows\Microsoft.NET\Framework64\v4.0.30319. Instances of Visual Studio will run a copy of msbuild.exe. A moved instance of MSBuild is suspicious, however there are instances of build applications that will move or use a copy of MSBuild. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-03-08 -- **Author**: Michael Haag, Splunk -- **ID**: f5198224-551c-11eb-ae93-0242ac130002 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1036](https://attack.mitre.org/techniques/T1036/) | Masquerading | Defense Evasion | - -| [T1127](https://attack.mitre.org/techniques/T1127/) | Trusted Developer Utilities Proxy Execution | Defense Evasion | - -| [T1036.003](https://attack.mitre.org/techniques/T1036/003/) | Rename System Utilities | Defense Evasion | - -| [T1127.001](https://attack.mitre.org/techniques/T1127/001/) | MSBuild | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count values(Processes.process_name) as process_name values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_msbuild` AND (Processes.process_path!=*\\framework*\\v*\\*) by Processes.dest Processes.original_file_name Processes.parent_process Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `suspicious_msbuild_path_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_msbuild](https://github.com/splunk/security_content/blob/develop/macros/process_msbuild.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **suspicious_msbuild_path_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Some legitimate applications may use a moved copy of msbuild.exe, triggering a false positive. Baselining of MSBuild.exe usage is recommended to better understand it's path usage. Visual Studio runs an instance out of a path that will need to be filtered on. - -#### Associated Analytic story -* [Trusted Developer Utilities Proxy Execution MSBuild](/stories/trusted_developer_utilities_proxy_execution_msbuild) -* [Cobalt Strike](/stories/cobalt_strike) -* [Masquerading - Rename System Utilities](/stories/masquerading_-_rename_system_utilities) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | Msbuild.exe ran from an uncommon path on $dest$ execyted by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://lolbas-project.github.io/lolbas/Binaries/Msbuild/](https://lolbas-project.github.io/lolbas/Binaries/Msbuild/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1127.001/T1127.001.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1127.001/T1127.001.md) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127.001/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127.001/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/suspicious_msbuild_path.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2022-03-08-windows_disable_change_password_through_registry.md b/docs/_posts/2022-03-08-windows_disable_change_password_through_registry.md deleted file mode 100644 index 4a7e68182c..0000000000 --- a/docs/_posts/2022-03-08-windows_disable_change_password_through_registry.md +++ /dev/null @@ -1,175 +0,0 @@ ---- -title: "Windows Disable Change Password Through Registry" -excerpt: "Modify Registry -" -categories: - - Endpoint -last_modified_at: 2022-03-08 -toc: true -toc_label: "" -tags: - - Modify Registry - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to detect a suspicious registry modification to disable change password feature of the windows host. This registry modification may disables the Change Password button on the Windows Security dialog box (which appears when you press Ctrl+Alt+Del). As a result, users cannot change their Windows password on demand. This technique was seen in some malware family like ransomware to prevent the user to change the password after ownning the network or a system during attack. This windows feature may implemented by administrator to prevent normal user to change the password of a critical host or server, In this type of scenario filter is needed to minimized false positive. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-03-08 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 0df33e1a-9ef6-11ec-a1ad-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1112](https://attack.mitre.org/techniques/T1112/) | Modify Registry | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\DisableChangePassword" Registry.registry_value_data = "0x00000001" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid -| `drop_dm_object_name(Registry)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] -| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data -| `windows_disable_change_password_through_registry_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_disable_change_password_through_registry_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.registry_key_name -* Registry.registry_path -* Registry.registry_value_name -* Registry.dest -* Registry.user -* Processes.process_id -* Processes.process_name -* Processes.process -* Processes.dest -* Processes.parent_process_name -* Processes.parent_process -* Processes.process_guid - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the Filesystem responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` and `Registry` node. - -#### Known False Positives -This windows feature may implemented by administrator to prevent normal user to change the password of a critical host or server, In this type of scenario filter is needed to minimized false positive. - -#### Associated Analytic story -* [Ransomware](/stories/ransomware) -* [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | Registry modification in "DisableChangePassword" on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/ransom_heartbleed.thdobah](https://www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/ransom_heartbleed.thdobah) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1112/ransomware_disable_reg/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1112/ransomware_disable_reg/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_disable_change_password_through_registry.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-03-08-windows_disable_lock_workstation_feature_through_registry.md b/docs/_posts/2022-03-08-windows_disable_lock_workstation_feature_through_registry.md deleted file mode 100644 index a2dd71f025..0000000000 --- a/docs/_posts/2022-03-08-windows_disable_lock_workstation_feature_through_registry.md +++ /dev/null @@ -1,176 +0,0 @@ ---- -title: "Windows Disable Lock Workstation Feature Through Registry" -excerpt: "Modify Registry -" -categories: - - Endpoint -last_modified_at: 2022-03-08 -toc: true -toc_label: "" -tags: - - Modify Registry - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to detect a suspicious registry modification to disable Lock Computer windows features. This registry modification prevent the user from locking its screen or computer that are being abused by several malware for example ransomware. This technique was used by threat actor to make its payload more impactful to the compromised host. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-03-08 -- **Author**: Teoderick Contreras, Splunk -- **ID**: c82adbc6-9f00-11ec-a81f-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1112](https://attack.mitre.org/techniques/T1112/) | Modify Registry | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\DisableLockWorkstation" Registry.registry_value_data = "0x00000001" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid -| `drop_dm_object_name(Registry)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] -| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data -| `windows_disable_lock_workstation_feature_through_registry_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_disable_lock_workstation_feature_through_registry_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.registry_key_name -* Registry.registry_path -* Registry.registry_value_name -* Registry.dest Registry.user -* Processes.process_id -* Processes.process_name -* Processes.process -* Processes.dest -* Processes.parent_process_name -* Processes.parent_process -* Processes.process_guid - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the Filesystem responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` and `Registry` node. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Ransomware](/stories/ransomware) -* [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics) -* [Windows Registry Abuse](/stories/windows_registry_abuse) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | Registry modification in "DisableLockWorkstation" on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.bleepingcomputer.com/news/security/in-dev-ransomware-forces-you-do-to-survey-before-unlocking-computer/](https://www.bleepingcomputer.com/news/security/in-dev-ransomware-forces-you-do-to-survey-before-unlocking-computer/) -* [https://heimdalsecurity.com/blog/fatalrat-targets-telegram/](https://heimdalsecurity.com/blog/fatalrat-targets-telegram/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1112/ransomware_disable_reg/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1112/ransomware_disable_reg/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_disable_lock_workstation_feature_through_registry.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-03-08-windows_disable_logoff_button_through_registry.md b/docs/_posts/2022-03-08-windows_disable_logoff_button_through_registry.md deleted file mode 100644 index 278fceffc5..0000000000 --- a/docs/_posts/2022-03-08-windows_disable_logoff_button_through_registry.md +++ /dev/null @@ -1,176 +0,0 @@ ---- -title: "Windows Disable LogOff Button Through Registry" -excerpt: "Modify Registry -" -categories: - - Endpoint -last_modified_at: 2022-03-08 -toc: true -toc_label: "" -tags: - - Modify Registry - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to detect a suspicious registry modification to disable logoff feature in windows host. This registry when enable will prevent users to log off of the system by using any method, including programs run from the command line, such as scripts. It also disables or removes all menu items and buttons that log the user off of the system. This technique was seen abused by ransomware malware to make the compromised host un-useful and hard to remove other registry modification made on the machine that needs restart to take effect. This windows feature may implement by administrator in some server where shutdown is critical. In that scenario filter of machine and users that can modify this registry is needed. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-03-08 -- **Author**: Teoderick Contreras, Splunk -- **ID**: b2fb6830-9ed1-11ec-9fcb-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1112](https://attack.mitre.org/techniques/T1112/) | Modify Registry | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\*" Registry.registry_value_name IN ("NoLogOff", "StartMenuLogOff") Registry.registry_value_data = "0x00000001" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid -| `drop_dm_object_name(Registry)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] -| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data -| `windows_disable_logoff_button_through_registry_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_disable_logoff_button_through_registry_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.registry_key_name -* Registry.registry_path -* Registry.registry_value_name -* Registry.dest Registry.user -* Processes.process_id -* Processes.process_name -* Processes.process -* Processes.dest -* Processes.parent_process_name -* Processes.parent_process -* Processes.process_guid - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the Filesystem responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` and `Registry` node. - -#### Known False Positives -This windows feature may implement by administrator in some server where shutdown is critical. In that scenario filter of machine and users that can modify this registry is needed. - -#### Associated Analytic story -* [Ransomware](/stories/ransomware) -* [Windows Registry Abuse](/stories/windows_registry_abuse) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | Registry modification in "NoLogOff" on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.hybrid-analysis.com/sample/e2d4018fd3bd541c153af98ef7c25b2bf4a66bc3bfb89e437cde89fd08a9dd7b/5b1f4d947ca3e10f22714774](https://www.hybrid-analysis.com/sample/e2d4018fd3bd541c153af98ef7c25b2bf4a66bc3bfb89e437cde89fd08a9dd7b/5b1f4d947ca3e10f22714774) -* [https://malwiki.org/index.php?title=DigiPop.xp](https://malwiki.org/index.php?title=DigiPop.xp) -* [https://www.trendmicro.com/vinfo/be/threat-encyclopedia/search/js_noclose.e/2](https://www.trendmicro.com/vinfo/be/threat-encyclopedia/search/js_noclose.e/2) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1112/ransomware_disable_reg/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1112/ransomware_disable_reg/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_disable_logoff_button_through_registry.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-03-08-windows_disable_shutdown_button_through_registry.md b/docs/_posts/2022-03-08-windows_disable_shutdown_button_through_registry.md deleted file mode 100644 index f51b36c60c..0000000000 --- a/docs/_posts/2022-03-08-windows_disable_shutdown_button_through_registry.md +++ /dev/null @@ -1,174 +0,0 @@ ---- -title: "Windows Disable Shutdown Button Through Registry" -excerpt: "Modify Registry -" -categories: - - Endpoint -last_modified_at: 2022-03-08 -toc: true -toc_label: "" -tags: - - Modify Registry - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to detect a suspicious registry modification to disable shutdown button on the logon user. This technique was seen in several malware especially in ransomware family like killdisk malware variant to make the compromised host un-useful and hard to remove other registry modification made on the machine that needs restart to take effect. This windows feature may implement by administrator in some server where shutdown is critical. In that scenario filter of machine and users that can modify this registry is needed. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-03-08 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 55fb2958-9ecd-11ec-a06a-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1112](https://attack.mitre.org/techniques/T1112/) | Modify Registry | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where (Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\shutdownwithoutlogon" Registry.registry_value_data = "0x00000000") OR (Registry.registry_path="*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoClose" Registry.registry_value_data = "0x00000001") by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid -| `drop_dm_object_name(Registry)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] -| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data -| `windows_disable_shutdown_button_through_registry_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_disable_shutdown_button_through_registry_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.registry_key_name -* Registry.registry_path -* Registry.registry_value_name -* Registry.dest Registry.user -* Processes.process_id -* Processes.process_name -* Processes.process -* Processes.dest -* Processes.parent_process_name -* Processes.parent_process -* Processes.process_guid - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the Filesystem responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` and `Registry` node. - -#### Known False Positives -This windows feature may implement by administrator in some server where shutdown is critical. In that scenario filter of machine and users that can modify this registry is needed. - -#### Associated Analytic story -* [Ransomware](/stories/ransomware) -* [Windows Registry Abuse](/stories/windows_registry_abuse) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | Registry modification in "shutdownwithoutlogon" on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/ransom.msil.screenlocker.a/](https://www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/ransom.msil.screenlocker.a/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1112/ransomware_disable_reg/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1112/ransomware_disable_reg/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_disable_shutdown_button_through_registry.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-03-08-windows_disable_windows_group_policy_features_through_registry.md b/docs/_posts/2022-03-08-windows_disable_windows_group_policy_features_through_registry.md deleted file mode 100644 index e85859d137..0000000000 --- a/docs/_posts/2022-03-08-windows_disable_windows_group_policy_features_through_registry.md +++ /dev/null @@ -1,177 +0,0 @@ ---- -title: "Windows Disable Windows Group Policy Features Through Registry" -excerpt: "Modify Registry -" -categories: - - Endpoint -last_modified_at: 2022-03-08 -toc: true -toc_label: "" -tags: - - Modify Registry - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to detect a suspicious registry modification to disable windows features. These techniques are seen in several ransomware malware to impair the compromised host to make it hard for analyst to mitigate or response from the attack. Disabling these known features make the analysis and forensic response more hard. Disabling these feature is not so common but can still be implemented by the administrator for security purposes. In this scenario filters for users that are allowed doing this is needed. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-03-08 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 63a449ae-9f04-11ec-945e-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1112](https://attack.mitre.org/techniques/T1112/) | Modify Registry | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\*" OR Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\*" Registry.registry_value_name IN ("NoDesktop", "NoFind", "NoControlPanel", "NoFileMenu", "NoSetTaskbar", "NoTrayContextMenu", "TaskbarLockAll", "NoThemesTab","NoPropertiesMyDocuments","NoVisualStyleChoice","NoColorChoice","NoPropertiesMyDocuments") Registry.registry_value_data = "0x00000001" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid -| `drop_dm_object_name(Registry)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] -| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data -| `windows_disable_windows_group_policy_features_through_registry_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_disable_windows_group_policy_features_through_registry_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.registry_key_name -* Registry.registry_path -* Registry.registry_value_name -* Registry.dest Registry.user -* Processes.process_id -* Processes.process_name -* Processes.process -* Processes.dest -* Processes.parent_process_name -* Processes.parent_process -* Processes.process_guid - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the Filesystem responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` and `Registry` node. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Ransomware](/stories/ransomware) -* [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics) -* [Windows Registry Abuse](/stories/windows_registry_abuse) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | Registry modification to disable windows features on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://hybrid-analysis.com/sample/ef1c427394c205580576d18ba68d5911089c7da0386f19d1ca126929d3e671ab?environmentId=120&lang=en](https://hybrid-analysis.com/sample/ef1c427394c205580576d18ba68d5911089c7da0386f19d1ca126929d3e671ab?environmentId=120&lang=en) -* [https://www.sophos.com/en-us/threat-center/threat-analyses/viruses-and-spyware/Troj~Krotten-N/detailed-analysis](https://www.sophos.com/en-us/threat-center/threat-analyses/viruses-and-spyware/Troj~Krotten-N/detailed-analysis) -* [https://www.virustotal.com/gui/file/2d7855bf6470aa323edf2949b54ce2a04d9e38770f1322c3d0420c2303178d91/details](https://www.virustotal.com/gui/file/2d7855bf6470aa323edf2949b54ce2a04d9e38770f1322c3d0420c2303178d91/details) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1112/ransomware_disable_reg/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1112/ransomware_disable_reg/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_disable_windows_group_policy_features_through_registry.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-03-08-windows_hide_notification_features_through_registry.md b/docs/_posts/2022-03-08-windows_hide_notification_features_through_registry.md deleted file mode 100644 index c81bf1648e..0000000000 --- a/docs/_posts/2022-03-08-windows_hide_notification_features_through_registry.md +++ /dev/null @@ -1,175 +0,0 @@ ---- -title: "Windows Hide Notification Features Through Registry" -excerpt: "Modify Registry -" -categories: - - Endpoint -last_modified_at: 2022-03-08 -toc: true -toc_label: "" -tags: - - Modify Registry - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to detect a suspicious registry modification to hide common windows notification feature from compromised host. This technique was seen in some ransomware family to add more impact to its payload that are visually seen by user aside from the encrypted files and ransomware notes. Even this a good anomaly detection, administrator may implement this changes for auditing or security reason. In this scenario filter is needed. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-03-08 -- **Author**: Teoderick Contreras, Splunk -- **ID**: cafa4bce-9f06-11ec-a7b2-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1112](https://attack.mitre.org/techniques/T1112/) | Modify Registry | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\*" Registry.registry_value_name IN ("HideClock", "HideSCAHealth", "HideSCANetwork", "HideSCAPower", "HideSCAVolume") Registry.registry_value_data = "0x00000001" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid -| `drop_dm_object_name(Registry)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] -| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data -| `windows_hide_notification_features_through_registry_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_hide_notification_features_through_registry_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.registry_key_name -* Registry.registry_path -* Registry.registry_value_name -* Registry.dest Registry.user -* Processes.process_id -* Processes.process_name -* Processes.process -* Processes.dest -* Processes.parent_process_name -* Processes.parent_process -* Processes.process_guid - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the Filesystem responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` and `Registry` node. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Ransomware](/stories/ransomware) -* [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics) -* [Windows Registry Abuse](/stories/windows_registry_abuse) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | Registry modification to hide windows notification on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/Ransom.Win32.ONALOCKER.A/](https://www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/Ransom.Win32.ONALOCKER.A/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1112/ransomware_disable_reg/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1112/ransomware_disable_reg/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_hide_notification_features_through_registry.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-03-09-unknown_process_using_the_kerberos_protocol.md b/docs/_posts/2022-03-09-unknown_process_using_the_kerberos_protocol.md deleted file mode 100644 index ccc0b8dbdc..0000000000 --- a/docs/_posts/2022-03-09-unknown_process_using_the_kerberos_protocol.md +++ /dev/null @@ -1,168 +0,0 @@ ---- -title: "Unknown Process Using The Kerberos Protocol" -excerpt: "Use Alternate Authentication Material -" -categories: - - Endpoint -last_modified_at: 2022-03-09 -toc: true -toc_label: "" -tags: - - Use Alternate Authentication Material - - Defense Evasion - - Lateral Movement - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Network_Traffic ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies a process performing an outbound connection on port 88 used by default by the network authentication protocol Kerberos. Typically, on a regular Windows endpoint, only the lsass.exe process is the one tasked with connecting to the Kerberos Distribution Center to obtain Kerberos tickets. Identifying an unknown process using this protocol may be evidence of an adversary abusing the Kerberos protocol. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint), [Network_Traffic](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkTraffic) -- **Last Updated**: 2022-03-09 -- **Author**: Mauricio Velazco, Splunk -- **ID**: c91a0852-9fbb-11ec-af44-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1550](https://attack.mitre.org/techniques/T1550/) | Use Alternate Authentication Material | Defense Evasion, Lateral Movement | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name!=lsass.exe by _time Processes.process_id Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| join process_id [ -| tstats `security_content_summariesonly` count FROM datamodel=Network_Traffic.All_Traffic where All_Traffic.dest_port = 88 by All_Traffic.process_id All_Traffic.dest All_Traffic.dest_port -| `drop_dm_object_name(All_Traffic)` ] -| table _time dest parent_process_name process_name process_path process process_id dest_port -| `unknown_process_using_the_kerberos_protocol_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **unknown_process_using_the_kerberos_protocol_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* All_Traffic.dest_ip -* All_Traffic.dest_port -* All_Traffic.src_ip -* Processes.process_id -* Processes.process_name -* Processes.dest -* Processes.process_path -* Processes.process -* Processes.parent_process_name - - -#### How To Implement -To successfully implement this search, you must be ingesting your endpoint events and populating the Endpoint and Network data models. - -#### Known False Positives -Custom applications may leverage the Kerberos protocol. Filter as needed. - -#### Associated Analytic story -* [Active Directory Kerberos Attacks](/stories/active_directory_kerberos_attacks) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 36.0 | 60 | 60 | | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://stealthbits.com/blog/how-to-detect-overpass-the-hash-attacks/](https://stealthbits.com/blog/how-to-detect-overpass-the-hash-attacks/) -* [https://www.thehacker.recipes/ad/movement/kerberos/ptk](https://www.thehacker.recipes/ad/movement/kerberos/ptk) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1550/rubeus/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1550/rubeus/windows-security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/unknown_process_using_the_kerberos_protocol.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-03-10-kerberos_user_enumeration.md b/docs/_posts/2022-03-10-kerberos_user_enumeration.md deleted file mode 100644 index 9530cac274..0000000000 --- a/docs/_posts/2022-03-10-kerberos_user_enumeration.md +++ /dev/null @@ -1,163 +0,0 @@ ---- -title: "Kerberos User Enumeration" -excerpt: "Gather Victim Identity Information -, Email Addresses -" -categories: - - Endpoint -last_modified_at: 2022-03-10 -toc: true -toc_label: "" -tags: - - Gather Victim Identity Information - - Email Addresses - - Reconnaissance - - Reconnaissance - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic leverages Event Id 4768, A Kerberos authentication ticket (TGT) was requested, to identify one source endpoint trying to obtain an unusual number Kerberos TGT ticket for non existing users. This behavior could represent an adversary abusing the Kerberos protocol to perform a user enumeration attack against an Active Directory environment. When Kerberos is sent a TGT request with no preauthentication for an invalid username, it responds with KRB5KDC_ERR_C_PRINCIPAL_UNKNOWN or 0x6. Red teams and adversaries alike may abuse the Kerberos protocol to validate a list of users use them to perform further attacks.\ The detection calculates the standard deviation for each host and leverages the 3-sigma statistical rule to identify an unusual number requests. To customize this analytic, users can try different combinations of the `bucket` span time and the calculation of the `upperBound` field. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-03-10 -- **Author**: Mauricio Velazco, Splunk -- **ID**: d82d4af4-a0bd-11ec-9445-3e22fbd008af - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1589](https://attack.mitre.org/techniques/T1589/) | Gather Victim Identity Information | Reconnaissance | - -| [T1589.002](https://attack.mitre.org/techniques/T1589/002/) | Email Addresses | Reconnaissance | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - `wineventlog_security` EventCode=4768 Result_Code=0x6 Account_Name!="*$" -| bucket span=2m _time -| stats dc(Account_Name) AS unique_accounts values(Account_Name) as tried_accounts by _time, Client_Address -| eventstats avg(unique_accounts) as comp_avg , stdev(unique_accounts) as comp_std by Client_Address -| eval upperBound=(comp_avg+comp_std*3) -| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0) -| search isOutlier=1 -| `kerberos_user_enumeration_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) - -> :information_source: -> **kerberos_user_enumeration_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Result_Code -* Account_Name -* Client_Address - - -#### How To Implement -To successfully implement this search, you need to be ingesting Domain Controller and Kerberos events. The Advanced Security Audit policy setting `Audit Kerberos Authentication Service` within `Account Logon` needs to be enabled. - -#### Known False Positives -Possible false positive scenarios include but are not limited to vulnerability scanners and missconfigured systems. - -#### Associated Analytic story -* [Active Directory Kerberos Attacks](/stories/active_directory_kerberos_attacks) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 24.0 | 30 | 80 | Potential Kerberos based user enumeration attack $Client_Address$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/ropnop/kerbrute](https://github.com/ropnop/kerbrute) -* [https://attack.mitre.org/techniques/T1589/002/](https://attack.mitre.org/techniques/T1589/002/) -* [https://redsiege.com/tools-techniques/2020/04/user-enumeration-part-3-windows/](https://redsiege.com/tools-techniques/2020/04/user-enumeration-part-3-windows/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1589.002/kerbrute/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1589.002/kerbrute/windows-security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/kerberos_user_enumeration.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-03-15-detect_regasm_with_no_command_line_arguments.md b/docs/_posts/2022-03-15-detect_regasm_with_no_command_line_arguments.md deleted file mode 100644 index 166aa0dead..0000000000 --- a/docs/_posts/2022-03-15-detect_regasm_with_no_command_line_arguments.md +++ /dev/null @@ -1,178 +0,0 @@ ---- -title: "Detect Regasm with no Command Line Arguments" -excerpt: "System Binary Proxy Execution -, Regsvcs/Regasm -" -categories: - - Endpoint -last_modified_at: 2022-03-15 -toc: true -toc_label: "" -tags: - - System Binary Proxy Execution - - Regsvcs/Regasm - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies regasm.exe with no command line arguments. This particular behavior occurs when another process injects into regasm.exe, no command line arguments will be present. During investigation, identify any network connections and parallel processes. Identify any suspicious module loads related to credential dumping or file writes. Regasm.exe are natively found in `C:\Windows\Microsoft.NET\Framework\v*\regasm|regsvcs.exe` and `C:\Windows\Microsoft.NET\Framework64\v*\regasm|regsvcs.exe`. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-03-15 -- **Author**: Michael Haag, Splunk -- **ID**: c3bc1430-04e7-4178-835f-047d8e6e97df - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218](https://attack.mitre.org/techniques/T1218/) | System Binary Proxy Execution | Defense Evasion | - -| [T1218.009](https://attack.mitre.org/techniques/T1218/009/) | Regsvcs/Regasm | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where `process_regasm` by _time span=1h Processes.process_id Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| regex process="(?i)(regasm\.exe.{0,4}$)" -| `detect_regasm_with_no_command_line_arguments_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_regasm](https://github.com/splunk/security_content/blob/develop/macros/process_regasm.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **detect_regasm_with_no_command_line_arguments_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Although unlikely, limited instances of regasm.exe or may cause a false positive. Filter based endpoint usage, command line arguments, or process lineage. - -#### Associated Analytic story -* [Suspicious Regsvcs Regasm Activity](/stories/suspicious_regsvcs_regasm_activity) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | The process $process_name$ was spawned by $parent_process_name$ without any command-line arguments on $dest$ by $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1218/009/](https://attack.mitre.org/techniques/T1218/009/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.009/T1218.009.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.009/T1218.009.md) -* [https://lolbas-project.github.io/lolbas/Binaries/Regasm/](https://lolbas-project.github.io/lolbas/Binaries/Regasm/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.009/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.009/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/detect_regasm_with_no_command_line_arguments.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2022-03-15-detect_regsvcs_with_no_command_line_arguments.md b/docs/_posts/2022-03-15-detect_regsvcs_with_no_command_line_arguments.md deleted file mode 100644 index a4972826ff..0000000000 --- a/docs/_posts/2022-03-15-detect_regsvcs_with_no_command_line_arguments.md +++ /dev/null @@ -1,178 +0,0 @@ ---- -title: "Detect Regsvcs with No Command Line Arguments" -excerpt: "System Binary Proxy Execution -, Regsvcs/Regasm -" -categories: - - Endpoint -last_modified_at: 2022-03-15 -toc: true -toc_label: "" -tags: - - System Binary Proxy Execution - - Regsvcs/Regasm - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies regsvcs.exe with no command line arguments. This particular behavior occurs when another process injects into regsvcs.exe, no command line arguments will be present. During investigation, identify any network connections and parallel processes. Identify any suspicious module loads related to credential dumping or file writes. Regasm.exe are natively found in C:\Windows\Microsoft.NET\Framework\v*\regasm|regsvcs.exe and C:\Windows\Microsoft.NET\Framework64\v*\regasm|regsvcs.exe. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-03-15 -- **Author**: Michael Haag, Splunk -- **ID**: 6b74d578-a02e-4e94-a0d1-39440d0bf254 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218](https://attack.mitre.org/techniques/T1218/) | System Binary Proxy Execution | Defense Evasion | - -| [T1218.009](https://attack.mitre.org/techniques/T1218/009/) | Regsvcs/Regasm | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where `process_regsvcs` by _time span=1h Processes.process_id Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| regex process="(?i)(regsvcs\.exe.{0,4}$)" -| `detect_regsvcs_with_no_command_line_arguments_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_regsvcs](https://github.com/splunk/security_content/blob/develop/macros/process_regsvcs.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **detect_regsvcs_with_no_command_line_arguments_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Although unlikely, limited instances of regsvcs.exe may cause a false positive. Filter based endpoint usage, command line arguments, or process lineage. - -#### Associated Analytic story -* [Suspicious Regsvcs Regasm Activity](/stories/suspicious_regsvcs_regasm_activity) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | The process $process_name$ was spawned by $parent_process_name$ without any command-line arguments on $dest$ by $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1218/009/](https://attack.mitre.org/techniques/T1218/009/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.009/T1218.009.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.009/T1218.009.md) -* [https://lolbas-project.github.io/lolbas/Binaries/Regsvcs/](https://lolbas-project.github.io/lolbas/Binaries/Regsvcs/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.009/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.009/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/detect_regsvcs_with_no_command_line_arguments.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2022-03-15-dllhost_with_no_command_line_arguments_with_network.md b/docs/_posts/2022-03-15-dllhost_with_no_command_line_arguments_with_network.md deleted file mode 100644 index ada2c79c91..0000000000 --- a/docs/_posts/2022-03-15-dllhost_with_no_command_line_arguments_with_network.md +++ /dev/null @@ -1,166 +0,0 @@ ---- -title: "DLLHost with no Command Line Arguments with Network" -excerpt: "Process Injection -" -categories: - - Endpoint -last_modified_at: 2022-03-15 -toc: true -toc_label: "" -tags: - - Process Injection - - Defense Evasion - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies DLLHost.exe with no command line arguments with a network connection. It is unusual for DLLHost.exe to execute with no command line arguments present. This particular behavior is common with malicious software, including Cobalt Strike. During investigation, triage any network connections and parallel processes. Identify any suspicious module loads related to credential dumping or file writes. DLLHost.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-03-15 -- **Author**: Michael Haag, Splunk -- **ID**: f1c07594-a141-11eb-8407-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1055](https://attack.mitre.org/techniques/T1055/) | Process Injection | Defense Evasion, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name=dllhost.exe by _time span=1h Processes.process_id Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| regex process="(?i)(dllhost\.exe.{0,4}$)" -| join process_id [ -| tstats `security_content_summariesonly` count FROM datamodel=Network_Traffic.All_Traffic where All_Traffic.dest_port != 0 by All_Traffic.process_id All_Traffic.dest All_Traffic.dest_port -| `drop_dm_object_name(All_Traffic)` -| rename dest as C2 ] -| table _time dest parent_process_name process_name process_path process process_id dest_port C2 -| `dllhost_with_no_command_line_arguments_with_network_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **dllhost_with_no_command_line_arguments_with_network_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventID -* process_name -* process_id -* parent_process_name -* dest_port -* process_path - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` and `port` node. - -#### Known False Positives -Although unlikely, some legitimate third party applications may use a moved copy of dllhost, triggering a false positive. - -#### Associated Analytic story -* [Cobalt Strike](/stories/cobalt_strike) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | The process $process_name$ was spawned by $parent_image$ without any command-line arguments on $dest$ by $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://raw.githubusercontent.com/threatexpress/malleable-c2/c3385e481159a759f79b8acfe11acf240893b830/jquery-c2.4.2.profile](https://raw.githubusercontent.com/threatexpress/malleable-c2/c3385e481159a759f79b8acfe11acf240893b830/jquery-c2.4.2.profile) -* [https://www.cobaltstrike.com/blog/learn-pipe-fitting-for-all-of-your-offense-projects/](https://www.cobaltstrike.com/blog/learn-pipe-fitting-for-all-of-your-offense-projects/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon_dllhost.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon_dllhost.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2022-03-15-gpupdate_with_no_command_line_arguments_with_network.md b/docs/_posts/2022-03-15-gpupdate_with_no_command_line_arguments_with_network.md deleted file mode 100644 index c518f1efca..0000000000 --- a/docs/_posts/2022-03-15-gpupdate_with_no_command_line_arguments_with_network.md +++ /dev/null @@ -1,166 +0,0 @@ ---- -title: "GPUpdate with no Command Line Arguments with Network" -excerpt: "Process Injection -" -categories: - - Endpoint -last_modified_at: 2022-03-15 -toc: true -toc_label: "" -tags: - - Process Injection - - Defense Evasion - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies gpupdate.exe with no command line arguments and with a network connection. It is unusual for gpupdate.exe to execute with no command line arguments present. This particular behavior is common with malicious software, including Cobalt Strike. During investigation, triage any network connections and parallel processes. Identify any suspicious module loads related to credential dumping or file writes. gpupdate.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-03-15 -- **Author**: Michael Haag, Splunk -- **ID**: 2c853856-a140-11eb-a5b5-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1055](https://attack.mitre.org/techniques/T1055/) | Process Injection | Defense Evasion, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name=gpupdate.exe by _time span=1h Processes.process_id Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| regex process="(?i)(gpupdate\.exe.{0,4}$)" -| join process_id [ -| tstats `security_content_summariesonly` count FROM datamodel=Network_Traffic.All_Traffic where All_Traffic.dest_port != 0 by All_Traffic.process_id All_Traffic.dest All_Traffic.dest_port -| `drop_dm_object_name(All_Traffic)` -| rename dest as C2 ] -| table _time dest parent_process_name process_name process_path process process_id dest_port C2 -| `gpupdate_with_no_command_line_arguments_with_network_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **gpupdate_with_no_command_line_arguments_with_network_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventID -* process_name -* process_id -* parent_process_name -* dest_port -* process_path - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Limited false positives may be present in small environments. Tuning may be required based on parent process. - -#### Associated Analytic story -* [Cobalt Strike](/stories/cobalt_strike) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 81.0 | 90 | 90 | Process gpupdate.exe with parent_process $parent_process_name$ is executed on $dest$ by user $user$, followed by an outbound network connection to $connection_to_CNC$ on port $dest_port$. This behaviour is seen with cobaltstrike. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://raw.githubusercontent.com/xx0hcd/Malleable-C2-Profiles/0ef8cf4556e26f6d4190c56ba697c2159faa5822/crimeware/trick_ryuk.profile](https://raw.githubusercontent.com/xx0hcd/Malleable-C2-Profiles/0ef8cf4556e26f6d4190c56ba697c2159faa5822/crimeware/trick_ryuk.profile) -* [https://www.cobaltstrike.com/blog/learn-pipe-fitting-for-all-of-your-offense-projects/](https://www.cobaltstrike.com/blog/learn-pipe-fitting-for-all-of-your-offense-projects/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-03-15-kerberos_service_ticket_request_using_rc4_encryption.md b/docs/_posts/2022-03-15-kerberos_service_ticket_request_using_rc4_encryption.md deleted file mode 100644 index 54d27c0615..0000000000 --- a/docs/_posts/2022-03-15-kerberos_service_ticket_request_using_rc4_encryption.md +++ /dev/null @@ -1,165 +0,0 @@ ---- -title: "Kerberos Service Ticket Request Using RC4 Encryption" -excerpt: "Steal or Forge Kerberos Tickets -, Golden Ticket -" -categories: - - Endpoint -last_modified_at: 2022-03-15 -toc: true -toc_label: "" -tags: - - Steal or Forge Kerberos Tickets - - Golden Ticket - - Credential Access - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic leverages Kerberos Event 4769, A Kerberos service ticket was requested, to identify a potential Kerberos Service Ticket request related to a Golden Ticket attack. Adversaries who have obtained the Krbtgt account NTLM password hash may forge a Kerberos Granting Ticket (TGT) to obtain unrestricted access to an Active Directory environment. Armed with a Golden Ticket, attackers can request service tickets to move laterally and execute code on remote systems. Looking for Kerberos Service Ticket requests using the legacy RC4 encryption mechanism could represent the second stage of a Golden Ticket attack. RC4 usage should be rare on a modern network since Windows Vista & Windows Sever 2008 and newer support AES Kerberos encryption.\ Defenders should note that if an attacker does not leverage the NTLM password hash but rather the AES key to create a golden ticket, this detection may be bypassed. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-03-15 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 7d90f334-a482-11ec-908c-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1558](https://attack.mitre.org/techniques/T1558/) | Steal or Forge Kerberos Tickets | Credential Access | - -| [T1558.001](https://attack.mitre.org/techniques/T1558/001/) | Golden Ticket | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - `wineventlog_security` EventCode=4769 Service_Name="*$" (Ticket_Options=0x40810000 OR Ticket_Options=0x40800000 OR Ticket_Options=0x40810010) Ticket_Encryption_Type=0x17 -| stats count min(_time) as firstTime max(_time) as lastTime by dest, service, service_id, Ticket_Encryption_Type, Ticket_Options -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `kerberos_service_ticket_request_using_rc4_encryption_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **kerberos_service_ticket_request_using_rc4_encryption_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Ticket_Options -* Ticket_Encryption_Type -* dest -* service -* service_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting Domain Controller and Kerberos events. The Advanced Security Audit policy setting `Audit Kerberos Authentication Service` within `Account Logon` needs to be enabled. - -#### Known False Positives -Based on Microsoft documentation, legacy systems or applications will use RC4-HMAC as the default encryption for Kerberos Service Ticket requests. Specifically, systems before Windows Server 2008 and Windows Vista. Newer systems will use AES128 or AES256. - -#### Associated Analytic story -* [Active Directory Kerberos Attacks](/stories/active_directory_kerberos_attacks) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 45.0 | 90 | 50 | A Kerberos Service TTicket request with RC4 encryption was requested from $Client_Address$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1558/001/](https://attack.mitre.org/techniques/T1558/001/) -* [https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4769](https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4769) -* [https://adsecurity.org/?p=1515](https://adsecurity.org/?p=1515) -* [https://gist.github.com/TarlogicSecurity/2f221924fef8c14a1d8e29f3cb5c5c4a](https://gist.github.com/TarlogicSecurity/2f221924fef8c14a1d8e29f3cb5c5c4a) -* [https://en.hackndo.com/kerberos-silver-golden-tickets/](https://en.hackndo.com/kerberos-silver-golden-tickets/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1558.001/impacket/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1558.001/impacket/windows-security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/kerberos_service_ticket_request_using_rc4_encryption.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-03-15-rundll32_with_no_command_line_arguments_with_network.md b/docs/_posts/2022-03-15-rundll32_with_no_command_line_arguments_with_network.md deleted file mode 100644 index 8dc7db224b..0000000000 --- a/docs/_posts/2022-03-15-rundll32_with_no_command_line_arguments_with_network.md +++ /dev/null @@ -1,185 +0,0 @@ ---- -title: "Rundll32 with no Command Line Arguments with Network" -excerpt: "System Binary Proxy Execution -, Rundll32 -" -categories: - - Endpoint -last_modified_at: 2022-03-15 -toc: true -toc_label: "" -tags: - - System Binary Proxy Execution - - Rundll32 - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2021-34527 - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies rundll32.exe with no command line arguments and performing a network connection. It is unusual for rundll32.exe to execute with no command line arguments present. This particular behavior is common with malicious software, including Cobalt Strike. During investigation, triage any network connections and parallel processes. Identify any suspicious module loads related to credential dumping or file writes. Rundll32.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-03-15 -- **Author**: Michael Haag, Splunk -- **ID**: 35307032-a12d-11eb-835f-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218](https://attack.mitre.org/techniques/T1218/) | System Binary Proxy Execution | Defense Evasion | - -| [T1218.011](https://attack.mitre.org/techniques/T1218/011/) | Rundll32 | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2021-34527](https://nvd.nist.gov/vuln/detail/CVE-2021-34527) | Windows Print Spooler Remote Code Execution Vulnerability | 9.0 | - - - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where `process_rundll32` by _time span=1h Processes.process_id Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name Processes.original_file_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| regex process="(?i)(rundll32\.exe.{0,4}$)" -| join process_id [ -| tstats `security_content_summariesonly` count FROM datamodel=Network_Traffic.All_Traffic where All_Traffic.dest_port != 0 by All_Traffic.process_id All_Traffic.dest All_Traffic.dest_port -| `drop_dm_object_name(All_Traffic)` -| rename dest as C2 ] -| table _time dest parent_process_name process_name process_path process process_id dest_port C2 -| `rundll32_with_no_command_line_arguments_with_network_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [process_rundll32](https://github.com/splunk/security_content/blob/develop/macros/process_rundll32.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **rundll32_with_no_command_line_arguments_with_network_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` and `port` node. To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Although unlikely, some legitimate applications may use a moved copy of rundll32, triggering a false positive. - -#### Associated Analytic story -* [Suspicious Rundll32 Activity](/stories/suspicious_rundll32_activity) -* [Cobalt Strike](/stories/cobalt_strike) -* [PrintNightmare CVE-2021-34527](/stories/printnightmare_cve-2021-34527) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 70.0 | 70 | 100 | A rundll32 process $process_name$ with no commandline argument like this process commandline $process$ in host $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1218/011/](https://attack.mitre.org/techniques/T1218/011/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.011/T1218.011.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.011/T1218.011.md) -* [https://lolbas-project.github.io/lolbas/Binaries/Rundll32/](https://lolbas-project.github.io/lolbas/Binaries/Rundll32/) -* [https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/](https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml) \| *version*: **4** \ No newline at end of file diff --git a/docs/_posts/2022-03-15-searchprotocolhost_with_no_command_line_with_network.md b/docs/_posts/2022-03-15-searchprotocolhost_with_no_command_line_with_network.md deleted file mode 100644 index 04a239f788..0000000000 --- a/docs/_posts/2022-03-15-searchprotocolhost_with_no_command_line_with_network.md +++ /dev/null @@ -1,164 +0,0 @@ ---- -title: "SearchProtocolHost with no Command Line with Network" -excerpt: "Process Injection -" -categories: - - Endpoint -last_modified_at: 2022-03-15 -toc: true -toc_label: "" -tags: - - Process Injection - - Defense Evasion - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies searchprotocolhost.exe with no command line arguments and with a network connection. It is unusual for searchprotocolhost.exe to execute with no command line arguments present. This particular behavior is common with malicious software, including Cobalt Strike. During investigation, identify any network connections and parallel processes. Identify any suspicious module loads related to credential dumping or file writes. searchprotocolhost.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-03-15 -- **Author**: Michael Haag, Splunk -- **ID**: b690df8c-a145-11eb-a38b-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1055](https://attack.mitre.org/techniques/T1055/) | Process Injection | Defense Evasion, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name=searchprotocolhost.exe by _time span=1h Processes.process_id Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| regex process="(?i)(searchprotocolhost\.exe.{0,4}$)" -| join process_id [ -| tstats `security_content_summariesonly` count FROM datamodel=Network_Traffic.All_Traffic where All_Traffic.dest_port != 0 by All_Traffic.process_id All_Traffic.dest All_Traffic.dest_port -| `drop_dm_object_name(All_Traffic)` -| rename dest as C2 ] -| table _time dest parent_process_name process_name process_path process process_id dest_port C2 -| `searchprotocolhost_with_no_command_line_with_network_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **searchprotocolhost_with_no_command_line_with_network_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* process_name -* process_id -* parent_process_name -* dest_port -* process_path - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` and `ports` node. - -#### Known False Positives -Limited false positives may be present in small environments. Tuning may be required based on parent process. - -#### Associated Analytic story -* [Cobalt Strike](/stories/cobalt_strike) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 70.0 | 70 | 100 | A searchprotocolhost.exe process $process_name$ with no commandline in host $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/mandiant/red_team_tool_countermeasures/blob/master/rules/PGF/supplemental/hxioc/SUSPICIOUS%20EXECUTION%20OF%20SEARCHPROTOCOLHOST%20(METHODOLOGY).ioc](https://github.com/mandiant/red_team_tool_countermeasures/blob/master/rules/PGF/supplemental/hxioc/SUSPICIOUS%20EXECUTION%20OF%20SEARCHPROTOCOLHOST%20(METHODOLOGY).ioc) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon_searchprotocolhost.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon_searchprotocolhost.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2022-03-15-suspicious_dllhost_no_command_line_arguments.md b/docs/_posts/2022-03-15-suspicious_dllhost_no_command_line_arguments.md deleted file mode 100644 index 1e1a15cdee..0000000000 --- a/docs/_posts/2022-03-15-suspicious_dllhost_no_command_line_arguments.md +++ /dev/null @@ -1,167 +0,0 @@ ---- -title: "Suspicious DLLHost no Command Line Arguments" -excerpt: "Process Injection -" -categories: - - Endpoint -last_modified_at: 2022-03-15 -toc: true -toc_label: "" -tags: - - Process Injection - - Defense Evasion - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies DLLHost.exe with no command line arguments. It is unusual for DLLHost.exe to execute with no command line arguments present. This particular behavior is common with malicious software, including Cobalt Strike. During investigation, identify any network connections and parallel processes. Identify any suspicious module loads related to credential dumping or file writes. DLLHost.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-03-15 -- **Author**: Michael Haag, Splunk -- **ID**: ff61e98c-0337-4593-a78f-72a676c56f26 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1055](https://attack.mitre.org/techniques/T1055/) | Process Injection | Defense Evasion, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where `process_dllhost` by _time span=1h Processes.process_id Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| regex process="(?i)(dllhost\.exe.{0,4}$)" -| `suspicious_dllhost_no_command_line_arguments_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_dllhost](https://github.com/splunk/security_content/blob/develop/macros/process_dllhost.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **suspicious_dllhost_no_command_line_arguments_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Limited false positives may be present in small environments. Tuning may be required based on parent process. - -#### Associated Analytic story -* [Cobalt Strike](/stories/cobalt_strike) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | Suspicious dllhost.exe process with no command line arguments executed on $dest$ by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://raw.githubusercontent.com/threatexpress/malleable-c2/c3385e481159a759f79b8acfe11acf240893b830/jquery-c2.4.2.profile](https://raw.githubusercontent.com/threatexpress/malleable-c2/c3385e481159a759f79b8acfe11acf240893b830/jquery-c2.4.2.profile) -* [https://www.cobaltstrike.com/blog/learn-pipe-fitting-for-all-of-your-offense-projects/](https://www.cobaltstrike.com/blog/learn-pipe-fitting-for-all-of-your-offense-projects/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2022-03-15-suspicious_gpupdate_no_command_line_arguments.md b/docs/_posts/2022-03-15-suspicious_gpupdate_no_command_line_arguments.md deleted file mode 100644 index 686650b32a..0000000000 --- a/docs/_posts/2022-03-15-suspicious_gpupdate_no_command_line_arguments.md +++ /dev/null @@ -1,167 +0,0 @@ ---- -title: "Suspicious GPUpdate no Command Line Arguments" -excerpt: "Process Injection -" -categories: - - Endpoint -last_modified_at: 2022-03-15 -toc: true -toc_label: "" -tags: - - Process Injection - - Defense Evasion - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies gpupdate.exe with no command line arguments. It is unusual for gpupdate.exe to execute with no command line arguments present. This particular behavior is common with malicious software, including Cobalt Strike. During investigation, identify any network connections and parallel processes. Identify any suspicious module loads related to credential dumping or file writes. gpupdate.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-03-15 -- **Author**: Michael Haag, Splunk -- **ID**: f308490a-473a-40ef-ae64-dd7a6eba284a - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1055](https://attack.mitre.org/techniques/T1055/) | Process Injection | Defense Evasion, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where `process_gpupdate` by _time span=1h Processes.process_id Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| regex process="(?i)(gpupdate\.exe.{0,4}$)" -| `suspicious_gpupdate_no_command_line_arguments_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [process_gpupdate](https://github.com/splunk/security_content/blob/develop/macros/process_gpupdate.yml) - -> :information_source: -> **suspicious_gpupdate_no_command_line_arguments_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -Limited false positives may be present in small environments. Tuning may be required based on parent process. - -#### Associated Analytic story -* [Cobalt Strike](/stories/cobalt_strike) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | Suspicious gpupdate.exe process with no command line arguments executed on $dest$ by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://raw.githubusercontent.com/xx0hcd/Malleable-C2-Profiles/0ef8cf4556e26f6d4190c56ba697c2159faa5822/crimeware/trick_ryuk.profile](https://raw.githubusercontent.com/xx0hcd/Malleable-C2-Profiles/0ef8cf4556e26f6d4190c56ba697c2159faa5822/crimeware/trick_ryuk.profile) -* [https://www.cobaltstrike.com/blog/learn-pipe-fitting-for-all-of-your-offense-projects/](https://www.cobaltstrike.com/blog/learn-pipe-fitting-for-all-of-your-offense-projects/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2022-03-15-suspicious_rundll32_no_command_line_arguments.md b/docs/_posts/2022-03-15-suspicious_rundll32_no_command_line_arguments.md deleted file mode 100644 index 3a513ba44a..0000000000 --- a/docs/_posts/2022-03-15-suspicious_rundll32_no_command_line_arguments.md +++ /dev/null @@ -1,185 +0,0 @@ ---- -title: "Suspicious Rundll32 no Command Line Arguments" -excerpt: "System Binary Proxy Execution -, Rundll32 -" -categories: - - Endpoint -last_modified_at: 2022-03-15 -toc: true -toc_label: "" -tags: - - System Binary Proxy Execution - - Rundll32 - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2021-34527 - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies rundll32.exe with no command line arguments. It is unusual for rundll32.exe to execute with no command line arguments present. This particular behavior is common with malicious software, including Cobalt Strike. During investigation, identify any network connections and parallel processes. Identify any suspicious module loads related to credential dumping or file writes. Rundll32.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-03-15 -- **Author**: Michael Haag, Splunk -- **ID**: e451bd16-e4c5-4109-8eb1-c4c6ecf048b4 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218](https://attack.mitre.org/techniques/T1218/) | System Binary Proxy Execution | Defense Evasion | - -| [T1218.011](https://attack.mitre.org/techniques/T1218/011/) | Rundll32 | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2021-34527](https://nvd.nist.gov/vuln/detail/CVE-2021-34527) | Windows Print Spooler Remote Code Execution Vulnerability | 9.0 | - - - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where `process_rundll32` by _time span=1h Processes.process_id Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| regex process="(?i)(rundll32\.exe.{0,4}$)" -| `suspicious_rundll32_no_command_line_arguments_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [process_rundll32](https://github.com/splunk/security_content/blob/develop/macros/process_rundll32.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **suspicious_rundll32_no_command_line_arguments_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Although unlikely, some legitimate applications may use a moved copy of rundll32, triggering a false positive. - -#### Associated Analytic story -* [Suspicious Rundll32 Activity](/stories/suspicious_rundll32_activity) -* [Cobalt Strike](/stories/cobalt_strike) -* [PrintNightmare CVE-2021-34527](/stories/printnightmare_cve-2021-34527) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | Suspicious rundll32.exe process with no command line arguments executed on $dest$ by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1218/011/](https://attack.mitre.org/techniques/T1218/011/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.011/T1218.011.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.011/T1218.011.md) -* [https://lolbas-project.github.io/lolbas/Binaries/Rundll32/](https://lolbas-project.github.io/lolbas/Binaries/Rundll32/) -* [https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/](https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.011/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.011/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/suspicious_rundll32_no_command_line_arguments.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2022-03-15-suspicious_searchprotocolhost_no_command_line_arguments.md b/docs/_posts/2022-03-15-suspicious_searchprotocolhost_no_command_line_arguments.md deleted file mode 100644 index 38bf86e1be..0000000000 --- a/docs/_posts/2022-03-15-suspicious_searchprotocolhost_no_command_line_arguments.md +++ /dev/null @@ -1,165 +0,0 @@ ---- -title: "Suspicious SearchProtocolHost no Command Line Arguments" -excerpt: "Process Injection -" -categories: - - Endpoint -last_modified_at: 2022-03-15 -toc: true -toc_label: "" -tags: - - Process Injection - - Defense Evasion - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies searchprotocolhost.exe with no command line arguments. It is unusual for searchprotocolhost.exe to execute with no command line arguments present. This particular behavior is common with malicious software, including Cobalt Strike. During investigation, identify any network connections and parallel processes. Identify any suspicious module loads related to credential dumping or file writes. searchprotocolhost.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-03-15 -- **Author**: Michael Haag, Splunk -- **ID**: f52d2db8-31f9-4aa7-a176-25779effe55c - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1055](https://attack.mitre.org/techniques/T1055/) | Process Injection | Defense Evasion, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name=searchprotocolhost.exe by _time span=1h Processes.process_id Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| regex process="(?i)(searchprotocolhost\.exe.{0,4}$)" -| `suspicious_searchprotocolhost_no_command_line_arguments_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **suspicious_searchprotocolhost_no_command_line_arguments_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Limited false positives may be present in small environments. Tuning may be required based on parent process. - -#### Associated Analytic story -* [Cobalt Strike](/stories/cobalt_strike) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | Suspicious searchprotocolhost.exe process with no command line arguments executed on $dest$ by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/mandiant/red_team_tool_countermeasures/blob/master/rules/PGF/supplemental/hxioc/SUSPICIOUS%20EXECUTION%20OF%20SEARCHPROTOCOLHOST%20(METHODOLOGY).ioc](https://github.com/mandiant/red_team_tool_countermeasures/blob/master/rules/PGF/supplemental/hxioc/SUSPICIOUS%20EXECUTION%20OF%20SEARCHPROTOCOLHOST%20(METHODOLOGY).ioc) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2022-03-16-windows_installutil_remote_network_connection.md b/docs/_posts/2022-03-16-windows_installutil_remote_network_connection.md deleted file mode 100644 index f012129af1..0000000000 --- a/docs/_posts/2022-03-16-windows_installutil_remote_network_connection.md +++ /dev/null @@ -1,181 +0,0 @@ ---- -title: "Windows InstallUtil Remote Network Connection" -excerpt: "InstallUtil -, System Binary Proxy Execution -" -categories: - - Endpoint -last_modified_at: 2022-03-16 -toc: true -toc_label: "" -tags: - - InstallUtil - - System Binary Proxy Execution - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the Windows InstallUtil.exe binary making a remote network connection. This technique may be used to download and execute code while bypassing application control. \ -When `InstallUtil.exe` is used in a malicous manner, the path to an executable on the filesystem is typically specified. Take note of the parent process. In a suspicious instance, this will be spawned from a non-standard process like `Cmd.exe`, `PowerShell.exe` or `Explorer.exe`. \ -If used by a developer, typically this will be found with multiple command-line switches/arguments and spawn from Visual Studio. \ -During triage review resulting network connections, file modifications, and parallel processes. Capture any artifacts and review further. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-03-16 -- **Author**: Michael Haag, Splunk -- **ID**: 4fbf9270-43da-11ec-9486-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218.004](https://attack.mitre.org/techniques/T1218/004/) | InstallUtil | Defense Evasion | - -| [T1218](https://attack.mitre.org/techniques/T1218/) | System Binary Proxy Execution | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where `process_installutil` by _time span=1h Processes.process_id Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name Processes.original_file_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| join process_id [ -| tstats `security_content_summariesonly` count FROM datamodel=Network_Traffic.All_Traffic where All_Traffic.dest_port != 0 by All_Traffic.process_id All_Traffic.dest All_Traffic.dest_port -| `drop_dm_object_name(All_Traffic)` -| rename dest as C2 ] -| table _time dest parent_process_name process_name process_path process process_id dest_port C2 -| `windows_installutil_remote_network_connection_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [process_installutil](https://github.com/splunk/security_content/blob/develop/macros/process_installutil.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_installutil_remote_network_connection_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id -* Ports.process_guid -* Ports.dest -* Ports.dest_port - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` and `Ports` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Limited false positives should be present as InstallUtil is not typically used to download remote files. Filter as needed based on Developers requirements. - -#### Associated Analytic story -* [Signed Binary Proxy Execution InstallUtil](/stories/signed_binary_proxy_execution_installutil) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ generating a remote download. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.004/T1218.004.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.004/T1218.004.md) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.004/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.004/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_installutil_remote_network_connection.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-03-16-windows_installutil_uninstall_option_with_network.md b/docs/_posts/2022-03-16-windows_installutil_uninstall_option_with_network.md deleted file mode 100644 index 5204d6ee21..0000000000 --- a/docs/_posts/2022-03-16-windows_installutil_uninstall_option_with_network.md +++ /dev/null @@ -1,184 +0,0 @@ ---- -title: "Windows InstallUtil Uninstall Option with Network" -excerpt: "InstallUtil -, System Binary Proxy Execution -" -categories: - - Endpoint -last_modified_at: 2022-03-16 -toc: true -toc_label: "" -tags: - - InstallUtil - - System Binary Proxy Execution - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the Windows InstallUtil.exe binary making a remote network connection. This technique may be used to download and execute code while bypassing application control using the `/u` (uninstall) switch. \ -InstallUtil uses the functions install and uninstall within the System.Configuration.Install namespace to process .net assembly. Install function requires admin privileges, however, uninstall function can be run as an unprivileged user.\ -When `InstallUtil.exe` is used in a malicous manner, the path to an executable on the filesystem is typically specified. Take note of the parent process. In a suspicious instance, this will be spawned from a non-standard process like `Cmd.exe`, `PowerShell.exe` or `Explorer.exe`. \ -If used by a developer, typically this will be found with multiple command-line switches/arguments and spawn from Visual Studio. \ -During triage review resulting network connections, file modifications, and parallel processes. Capture any artifacts and review further. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-03-16 -- **Author**: Michael Haag, Splunk -- **ID**: 1a52c836-43ef-11ec-a36c-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218.004](https://attack.mitre.org/techniques/T1218/004/) | InstallUtil | Defense Evasion | - -| [T1218](https://attack.mitre.org/techniques/T1218/) | System Binary Proxy Execution | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where `process_installutil` Processes.process IN ("*/u*", "*uninstall*") by _time span=1h Processes.process_id Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| join process_id [ -| tstats `security_content_summariesonly` count FROM datamodel=Network_Traffic.All_Traffic where All_Traffic.dest_port != 0 by All_Traffic.process_id All_Traffic.dest All_Traffic.dest_port -| `drop_dm_object_name(All_Traffic)` -| rename dest as C2 ] -| table _time dest parent_process_name process_name process_path process process_id dest_port C2 -| `windows_installutil_uninstall_option_with_network_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [process_installutil](https://github.com/splunk/security_content/blob/develop/macros/process_installutil.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_installutil_uninstall_option_with_network_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id -* Ports.process_guid -* Ports.dest -* Ports.dest_port - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` and `Ports` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Limited false positives should be present as InstallUtil is not typically used to download remote files. Filter as needed based on Developers requirements. - -#### Associated Analytic story -* [Signed Binary Proxy Execution InstallUtil](/stories/signed_binary_proxy_execution_installutil) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ performing an uninstall. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_12](https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_12) -* [https://github.com/api0cradle/UltimateAppLockerByPassList/blob/master/md/Installutil.exe.md](https://github.com/api0cradle/UltimateAppLockerByPassList/blob/master/md/Installutil.exe.md) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.004/T1218.004.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.004/T1218.004.md) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.004/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.004/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_installutil_uninstall_option_with_network.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-03-17-modify_acl_permission_to_files_or_folder.md b/docs/_posts/2022-03-17-modify_acl_permission_to_files_or_folder.md deleted file mode 100644 index 248502084b..0000000000 --- a/docs/_posts/2022-03-17-modify_acl_permission_to_files_or_folder.md +++ /dev/null @@ -1,158 +0,0 @@ ---- -title: "Modify ACL permission To Files Or Folder" -excerpt: "File and Directory Permissions Modification -" -categories: - - Endpoint -last_modified_at: 2022-03-17 -toc: true -toc_label: "" -tags: - - File and Directory Permissions Modification - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic identifies suspicious modification of ACL permission to a files or folder to make it available to everyone. This technique may be used by the adversary to evade ACLs or protected files access. This changes is commonly configured by the file or directory owner with appropriate permission. This behavior is a good indicator if this command seen on a machine utilized by an account with no permission to do so. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-03-17 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 7e8458cc-acca-11eb-9e3f-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1222](https://attack.mitre.org/techniques/T1222/) | File and Directory Permissions Modification | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` values(Processes.process) as process values(Processes.process_id) as process_id count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name = "cacls.exe" OR Processes.process_name = "icacls.exe" OR Processes.process_name = "xcacls.exe") AND Processes.process = "*/G*" AND (Processes.process = "* everyone:*" OR Processes.process = "* SYSTEM:*" OR Processes.process = "* S-1-1-0:*") by Processes.parent_process_name Processes.process_name Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `modify_acl_permission_to_files_or_folder_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **modify_acl_permission_to_files_or_folder_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.parent_process_name -* Processes.process_name -* Processes.dest -* Processes.user -* Processes.process -* Processes.process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed cacls.exe may be used. - -#### Known False Positives -administrators may use this command. Filter as needed. - -#### Associated Analytic story -* [XMRig](/stories/xmrig) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 32.0 | 40 | 80 | Suspicious ACL permission modification on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/](https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-03-22-get_addefaultdomainpasswordpolicy_with_powershell_script_block.md b/docs/_posts/2022-03-22-get_addefaultdomainpasswordpolicy_with_powershell_script_block.md deleted file mode 100644 index b92d9ede9a..0000000000 --- a/docs/_posts/2022-03-22-get_addefaultdomainpasswordpolicy_with_powershell_script_block.md +++ /dev/null @@ -1,156 +0,0 @@ ---- -title: "Get ADDefaultDomainPasswordPolicy with Powershell Script Block" -excerpt: "Password Policy Discovery -" -categories: - - Endpoint -last_modified_at: 2022-03-22 -toc: true -toc_label: "" -tags: - - Password Policy Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-ADDefaultDomainPasswordPolicy` commandlet used to obtain the password policy in a Windows domain. Red Teams and adversaries alike may use PowerShell to enumerate domain policies for situational awareness and Active Directory Discovery. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-03-22 -- **Author**: Teoderick Contreras, Mauricio Velazco, Splunk -- **ID**: 1ff7ccc8-065a-11ec-91e4-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1201](https://attack.mitre.org/techniques/T1201/) | Password Policy Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 ScriptBlockText ="*Get-ADDefaultDomainPasswordPolicy*" -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode ScriptBlockText Computer user_id -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `get_addefaultdomainpasswordpolicy_with_powershell_script_block_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **get_addefaultdomainpasswordpolicy_with_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Message -* ComputerName -* User - - -#### How To Implement -The following Hunting analytic requires PowerShell operational logs to be imported. Modify the powershell macro as needed to match the sourcetype or add index. This analytic is specific to 4104, or PowerShell Script Block Logging. - -#### Known False Positives -Administrators or power users may use this command for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 9.0 | 30 | 30 | powershell process having commandline $Message$ to query domain password policy | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/S1ckB0y1337/Active-Directory-Exploitation-Cheat-Sheet](https://github.com/S1ckB0y1337/Active-Directory-Exploitation-Cheat-Sheet) -* [https://attack.mitre.org/techniques/T1201/](https://attack.mitre.org/techniques/T1201/) -* [https://docs.microsoft.com/en-us/powershell/module/activedirectory/get-addefaultdomainpasswordpolicy?view=windowsserver2019-ps](https://docs.microsoft.com/en-us/powershell/module/activedirectory/get-addefaultdomainpasswordpolicy?view=windowsserver2019-ps) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1201/pwd_policy_discovery/windows-powershell-xml.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1201/pwd_policy_discovery/windows-powershell-xml.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-03-22-get_domainuser_with_powershell_script_block.md b/docs/_posts/2022-03-22-get_domainuser_with_powershell_script_block.md deleted file mode 100644 index 6537929b66..0000000000 --- a/docs/_posts/2022-03-22-get_domainuser_with_powershell_script_block.md +++ /dev/null @@ -1,159 +0,0 @@ ---- -title: "Get DomainUser with PowerShell Script Block" -excerpt: "Domain Account -, Account Discovery -" -categories: - - Endpoint -last_modified_at: 2022-03-22 -toc: true -toc_label: "" -tags: - - Domain Account - - Account Discovery - - Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-DomainUser` commandlet. `GetDomainUser` is part of PowerView, a PowerShell tool used to perform enumeration on Windows domains. Red Teams and adversaries alike may use PowerView to enumerate domain users for situational awareness and Active Directory Discovery. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-03-22 -- **Author**: Teoderick Contreras, Mauricio Velazco, Splunk -- **ID**: 61994268-04f4-11ec-865c-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery | - -| [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 ScriptBlockText = "*Get-DomainUser*" -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode ScriptBlockText Computer user_id -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `get_domainuser_with_powershell_script_block_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **get_domainuser_with_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Message -* ComputerName -* User - - -#### How To Implement -The following Hunting analytic requires PowerShell operational logs to be imported. Modify the powershell macro as needed to match the sourcetype or add index. This analytic is specific to 4104, or PowerShell Script Block Logging. - -#### Known False Positives -Administrators or power users may use this command for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | powershell process having commandline $Message$ for user enumeration | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://powersploit.readthedocs.io/en/latest/Recon/Get-DomainUser/](https://powersploit.readthedocs.io/en/latest/Recon/Get-DomainUser/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/AD_discovery/windows-powershell-xml.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/AD_discovery/windows-powershell-xml.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-03-22-get_wmiobject_group_discovery_with_script_block_logging.md b/docs/_posts/2022-03-22-get_wmiobject_group_discovery_with_script_block_logging.md deleted file mode 100644 index bc2cd769f7..0000000000 --- a/docs/_posts/2022-03-22-get_wmiobject_group_discovery_with_script_block_logging.md +++ /dev/null @@ -1,166 +0,0 @@ ---- -title: "Get WMIObject Group Discovery with Script Block Logging" -excerpt: "Permission Groups Discovery -, Local Groups -" -categories: - - Endpoint -last_modified_at: 2022-03-22 -toc: true -toc_label: "" -tags: - - Permission Groups Discovery - - Local Groups - - Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify suspicious PowerShell execution. Script Block Logging captures the command sent to PowerShell, the full command to be executed. Upon enabling, logs will output to Windows event logs. Dependent upon volume, enable on critical endpoints or all. \ -This analytic identifies the usage of `Get-WMIObject Win32_Group`, which is typically used as a way to identify groups on the endpoint. Typically, by itself, is not malicious but may raise suspicion based on time of day, endpoint and username. \ -During triage, review parallel processes using an EDR product or 4688 events. It will be important to understand the timeline of events around this activity. Review the entire logged PowerShell script block. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-03-22 -- **Author**: Michael Haag, Splunk -- **ID**: 69df7f7c-155d-11ec-a055-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | - -| [T1069.001](https://attack.mitre.org/techniques/T1069/001/) | Local Groups | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 ScriptBlockText = "*Get-WMIObject*" AND ScriptBlockText = "*Win32_Group*" -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode ScriptBlockText Computer user_id -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `get_wmiobject_group_discovery_with_script_block_logging_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **get_wmiobject_group_discovery_with_script_block_logging_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Message -* ComputerName -* User - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -False positives may be present. Tune as needed. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | System group discovery enumeration on $dest$ by $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.splunk.com/en_us/blog/security/powershell-detections-threat-research-release-august-2021.html](https://www.splunk.com/en_us/blog/security/powershell-detections-threat-research-release-august-2021.html) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1069.001/T1069.001.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1069.001/T1069.001.md) -* [https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.](https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.) -* [https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63](https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63) -* [https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf](https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf) -* [https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/](https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.001/atomic_red_team/windows-powershell-xml.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.001/atomic_red_team/windows-powershell-xml.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-03-22-getadgroup_with_powershell_script_block.md b/docs/_posts/2022-03-22-getadgroup_with_powershell_script_block.md deleted file mode 100644 index 2f98054adc..0000000000 --- a/docs/_posts/2022-03-22-getadgroup_with_powershell_script_block.md +++ /dev/null @@ -1,160 +0,0 @@ ---- -title: "GetAdGroup with PowerShell Script Block" -excerpt: "Permission Groups Discovery -, Domain Groups -" -categories: - - Endpoint -last_modified_at: 2022-03-22 -toc: true -toc_label: "" -tags: - - Permission Groups Discovery - - Domain Groups - - Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-AdGroup` commandlet. The `Get-AdGroup` commandlet is used to return a list of all domain groups. Red Teams and adversaries may leverage this commandlet to enumerate domain groups for situational awareness and Active Directory Discovery. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-03-22 -- **Author**: Mauricio Velazco, Splunk -- **ID**: e4c73d68-794b-468d-b4d0-dac1772bbae7 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | - -| [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 ScriptBlockText = "*Get-ADGroup*" -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode ScriptBlockText Computer user_id -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `getadgroup_with_powershell_script_block_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **getadgroup_with_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Message -* ComputerName -* User - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -Administrators or power users may use this PowerShell commandlet for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | Domain group discovery enumeration using PowerShell on $dest$ by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1069/002/](https://attack.mitre.org/techniques/T1069/002/) -* [https://docs.microsoft.com/en-us/powershell/module/activedirectory/get-adgroup?view=windowsserver2019-ps](https://docs.microsoft.com/en-us/powershell/module/activedirectory/get-adgroup?view=windowsserver2019-ps) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.002/AD_discovery/windows-powershell-xml.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.002/AD_discovery/windows-powershell-xml.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-03-22-getcurrent_user_with_powershell_script_block.md b/docs/_posts/2022-03-22-getcurrent_user_with_powershell_script_block.md deleted file mode 100644 index c2c64120a2..0000000000 --- a/docs/_posts/2022-03-22-getcurrent_user_with_powershell_script_block.md +++ /dev/null @@ -1,157 +0,0 @@ ---- -title: "GetCurrent User with PowerShell Script Block" -excerpt: "System Owner/User Discovery -" -categories: - - Endpoint -last_modified_at: 2022-03-22 -toc: true -toc_label: "" -tags: - - System Owner/User Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `GetCurrent` method of the WindowsIdentity .NET class. This method returns an object that represents the current Windows user. Red Teams and adversaries may leverage this method to identify the logged user on a compromised endpoint for situational awareness and Active Directory Discovery. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-03-22 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 80879283-c30f-44f7-8471-d1381f6d437a - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1033](https://attack.mitre.org/techniques/T1033/) | System Owner/User Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 ScriptBlockText = "*[System.Security.Principal.WindowsIdentity]*" ScriptBlockText = "*GetCurrent()*" -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode ScriptBlockText Computer user_id -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `getcurrent_user_with_powershell_script_block_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **getcurrent_user_with_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Path -* Message -* OpCode -* ComputerName -* User -* EventCode - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -Administrators or power users may use this PowerShell commandlet for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | System user discovery on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1033/](https://attack.mitre.org/techniques/T1033/) -* [https://docs.microsoft.com/en-us/dotnet/api/system.security.principal.windowsidentity.getcurrent?view=net-6.0&viewFallbackFrom=net-5.0](https://docs.microsoft.com/en-us/dotnet/api/system.security.principal.windowsidentity.getcurrent?view=net-6.0&viewFallbackFrom=net-5.0) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1033/AD_discovery/windows-powershell-xml.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1033/AD_discovery/windows-powershell-xml.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-03-22-getlocaluser_with_powershell_script_block.md b/docs/_posts/2022-03-22-getlocaluser_with_powershell_script_block.md deleted file mode 100644 index c64352aa94..0000000000 --- a/docs/_posts/2022-03-22-getlocaluser_with_powershell_script_block.md +++ /dev/null @@ -1,166 +0,0 @@ ---- -title: "GetLocalUser with PowerShell Script Block" -excerpt: "Account Discovery -, Local Account -, PowerShell -" -categories: - - Endpoint -last_modified_at: 2022-03-22 -toc: true -toc_label: "" -tags: - - Account Discovery - - Local Account - - PowerShell - - Discovery - - Discovery - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-LocalUser` commandlet. The `Get-LocalUser` commandlet is used to return a list of all local users. Red Teams and adversaries may leverage this commandlet to enumerate users for situational awareness and Active Directory Discovery. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-03-22 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 2e891cbe-0426-11ec-9c9c-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - -| [T1087.001](https://attack.mitre.org/techniques/T1087/001/) | Local Account | Discovery | - -| [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 (ScriptBlockText = "*Get-LocalUser*") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode ScriptBlockText Computer user_id -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `getlocaluser_with_powershell_script_block_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **getlocaluser_with_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* ScriptBlockText -* Computer -* UserID - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -Administrators or power users may use this PowerShell commandlet for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) -* [Malicious PowerShell](/stories/malicious_powershell) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | Local user discovery enumeration using PowerShell on $Computer$ by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1087/001/](https://attack.mitre.org/techniques/T1087/001/) -* [https://www.splunk.com/en_us/blog/security/hunting-for-malicious-powershell-using-script-block-logging.html](https://www.splunk.com/en_us/blog/security/hunting-for-malicious-powershell-using-script-block-logging.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.001/AD_discovery/windows-powershell-xml.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.001/AD_discovery/windows-powershell-xml.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-03-22-interactive_session_on_remote_endpoint_with_powershell.md b/docs/_posts/2022-03-22-interactive_session_on_remote_endpoint_with_powershell.md deleted file mode 100644 index 6b739035e2..0000000000 --- a/docs/_posts/2022-03-22-interactive_session_on_remote_endpoint_with_powershell.md +++ /dev/null @@ -1,160 +0,0 @@ ---- -title: "Interactive Session on Remote Endpoint with PowerShell" -excerpt: "Remote Services -, Windows Remote Management -" -categories: - - Endpoint -last_modified_at: 2022-03-22 -toc: true -toc_label: "" -tags: - - Remote Services - - Windows Remote Management - - Lateral Movement - - Lateral Movement - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the usage of the `Enter-PSSession`. This commandlet can be used to open an interactive session on a remote endpoint leveraging the WinRM protocol. Red Teams and adversaries alike may abuse WinRM and `Enter-PSSession` for lateral movement and remote code execution. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-03-22 -- **Author**: Mauricio Velazco, Splunk -- **ID**: a4e8f3a4-48b2-11ec-bcfc-3e22fbd008af - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1021](https://attack.mitre.org/techniques/T1021/) | Remote Services | Lateral Movement | - -| [T1021.006](https://attack.mitre.org/techniques/T1021/006/) | Windows Remote Management | Lateral Movement | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 (ScriptBlockText="*Enter-PSSession*" AND ScriptBlockText="*-ComputerName*") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode ScriptBlockText Computer user_id -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `interactive_session_on_remote_endpoint_with_powershell_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **interactive_session_on_remote_endpoint_with_powershell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Message -* ComputerName -* User - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup instructions can be found https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -Administrators may leverage WinRM and `Enter-PSSession` for administrative and troubleshooting tasks. This activity is usually limited to a small set of hosts or users. In certain environments, tuning may not be possible. - -#### Associated Analytic story -* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 45.0 | 90 | 50 | An interactive session was opened on a remote endpoint from $ComputerName | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1021/006/](https://attack.mitre.org/techniques/T1021/006/) -* [https://docs.microsoft.com/en-us/powershell/module/microsoft.powershell.core/enter-pssession?view=powershell-7.2](https://docs.microsoft.com/en-us/powershell/module/microsoft.powershell.core/enter-pssession?view=powershell-7.2) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021.006/lateral_movement_pssession/windows-powershell-xml.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021.006/lateral_movement_pssession/windows-powershell-xml.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/interactive_session_on_remote_endpoint_with_powershell.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2022-03-22-kerberos_pre-authentication_flag_disabled_with_powershell.md b/docs/_posts/2022-03-22-kerberos_pre-authentication_flag_disabled_with_powershell.md deleted file mode 100644 index ae8a733c0f..0000000000 --- a/docs/_posts/2022-03-22-kerberos_pre-authentication_flag_disabled_with_powershell.md +++ /dev/null @@ -1,157 +0,0 @@ ---- -title: "Kerberos Pre-Authentication Flag Disabled with PowerShell" -excerpt: "Steal or Forge Kerberos Tickets -, AS-REP Roasting -" -categories: - - Endpoint -last_modified_at: 2022-03-22 -toc: true -toc_label: "" -tags: - - Steal or Forge Kerberos Tickets - - AS-REP Roasting - - Credential Access - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Set-ADAccountControl` commandlet with specific parameters. `Set-ADAccountControl` is part of the Active Directory PowerShell module used to manage Windows Active Directory networks. As the name suggests, `Set-ADAccountControl` is used to modify User Account Control values for an Active Directory domain account. With the appropiate parameters, Set-ADAccountControl allows adversaries to disable Kerberos Pre-Authentication for an account to to easily perform a brute force attack against the user's password offline leveraging the ASP REP Roasting technique. Red Teams and adversaries alike who have obtained privileges in an Active Directory network may use this technique as a backdoor or a way to escalate privileges. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-03-22 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 59b51620-94c9-11ec-b3d5-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1558](https://attack.mitre.org/techniques/T1558/) | Steal or Forge Kerberos Tickets | Credential Access | - -| [T1558.004](https://attack.mitre.org/techniques/T1558/004/) | AS-REP Roasting | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 (ScriptBlockText = "*Set-ADAccountControl*" AND ScriptBlockText="*DoesNotRequirePreAuth:$true*") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode ScriptBlockText Computer user_id -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `kerberos_pre_authentication_flag_disabled_with_powershell_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **kerberos_pre-authentication_flag_disabled_with_powershell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -Although unlikely, Administrators may need to set this flag for legitimate purposes. - -#### Associated Analytic story -* [Active Directory Kerberos Attacks](/stories/active_directory_kerberos_attacks) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 45.0 | 50 | 90 | Kerberos Pre Authentication was Disabled using PowerShell on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://docs.microsoft.com/en-us/troubleshoot/windows-server/identity/useraccountcontrol-manipulate-account-properties](https://docs.microsoft.com/en-us/troubleshoot/windows-server/identity/useraccountcontrol-manipulate-account-properties) -* [https://m0chan.github.io/2019/07/31/How-To-Attack-Kerberos-101.html](https://m0chan.github.io/2019/07/31/How-To-Attack-Kerberos-101.html) -* [https://stealthbits.com/blog/cracking-active-directory-passwords-with-as-rep-roasting/](https://stealthbits.com/blog/cracking-active-directory-passwords-with-as-rep-roasting/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1558.004/powershell/windows-powershell-xml.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1558.004/powershell/windows-powershell-xml.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/kerberos_pre_authentication_flag_disabled_with_powershell.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-03-22-powershell_execute_com_object.md b/docs/_posts/2022-03-22-powershell_execute_com_object.md deleted file mode 100644 index 91cbf07480..0000000000 --- a/docs/_posts/2022-03-22-powershell_execute_com_object.md +++ /dev/null @@ -1,169 +0,0 @@ ---- -title: "Powershell Execute COM Object" -excerpt: "Component Object Model Hijacking -, Event Triggered Execution -, PowerShell -" -categories: - - Endpoint -last_modified_at: 2022-03-22 -toc: true -toc_label: "" -tags: - - Component Object Model Hijacking - - Event Triggered Execution - - PowerShell - - Persistence - - Privilege Escalation - - Persistence - - Privilege Escalation - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect a COM CLSID execution through powershell. This technique was seen in several adversaries and malware like ransomware conti where it has a feature to execute command using COM Object. This technique may use by network operator at some cases but a good indicator if some application want to gain privilege escalation or bypass uac. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-03-22 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 65711630-f9bf-11eb-8d72-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1546.015](https://attack.mitre.org/techniques/T1546/015/) | Component Object Model Hijacking | Persistence, Privilege Escalation | - -| [T1546](https://attack.mitre.org/techniques/T1546/) | Event Triggered Execution | Persistence, Privilege Escalation | - -| [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 ScriptBlockText = "*CreateInstance([type]::GetTypeFromCLSID*" -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode ScriptBlockText Computer user_id -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `powershell_execute_com_object_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **powershell_execute_com_object_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* ScriptBlockText -* Computer -* EventCode - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -network operrator may use this command. - -#### Associated Analytic story -* [Hermetic Wiper](/stories/hermetic_wiper) -* [Malicious PowerShell](/stories/malicious_powershell) -* [Ransomware](/stories/ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 5.0 | 10 | 50 | A suspicious powershell script contains COM CLSID command in $ScriptBlockText$ with EventCode $EventCode$ in host $Computer$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://threadreaderapp.com/thread/1423361119926816776.html](https://threadreaderapp.com/thread/1423361119926816776.html) -* [https://www.splunk.com/en_us/blog/security/hunting-for-malicious-powershell-using-script-block-logging.html](https://www.splunk.com/en_us/blog/security/hunting-for-malicious-powershell-using-script-block-logging.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.015/pwh_com_object/windows-powershell-xml.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.015/pwh_com_object/windows-powershell-xml.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/powershell_execute_com_object.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-03-22-powershell_using_memory_as_backing_store.md b/docs/_posts/2022-03-22-powershell_using_memory_as_backing_store.md deleted file mode 100644 index 788a155992..0000000000 --- a/docs/_posts/2022-03-22-powershell_using_memory_as_backing_store.md +++ /dev/null @@ -1,164 +0,0 @@ ---- -title: "Powershell Using memory As Backing Store" -excerpt: "PowerShell -, Command and Scripting Interpreter -" -categories: - - Endpoint -last_modified_at: 2022-03-22 -toc: true -toc_label: "" -tags: - - PowerShell - - Command and Scripting Interpreter - - Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies suspicious PowerShell script execution via EventCode 4104 that is using memory stream as new object backstore. The malicious PowerShell script will contain stream flate data and will be decompressed in memory to run or drop the actual payload. During triage, review parallel processes within the same timeframe. Review the full script block to identify other related artifacts. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-03-22 -- **Author**: Teoderick Contreras, Splunk -- **ID**: c396a0c4-c9f2-11eb-b4f5-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | - -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 ScriptBlockText = *New-Object* ScriptBlockText = *IO.MemoryStream* -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode ScriptBlockText Computer user_id -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `powershell_using_memory_as_backing_store_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **powershell_using_memory_as_backing_store_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* ScriptBlockText -* Computer -* UserID - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -powershell may used this function to store out object into memory. - -#### Associated Analytic story -* [Hermetic Wiper](/stories/hermetic_wiper) -* [Malicious PowerShell](/stories/malicious_powershell) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 40.0 | 50 | 80 | A suspicious powershell script contains memorystream command in $ScriptBlockText$ as new object backstore with EventCode $EventCode$ in host $Computer$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://web.archive.org/web/20201112031711/https://www.carbonblack.com/blog/decoding-malicious-powershell-streams/](https://web.archive.org/web/20201112031711/https://www.carbonblack.com/blog/decoding-malicious-powershell-streams/) -* [https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.](https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.) -* [https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63](https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63) -* [https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf](https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf) -* [https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/](https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/pwsh/windows-powershell-xml.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/pwsh/windows-powershell-xml.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-03-22-recon_avproduct_through_pwh_or_wmi.md b/docs/_posts/2022-03-22-recon_avproduct_through_pwh_or_wmi.md deleted file mode 100644 index 85c22023b0..0000000000 --- a/docs/_posts/2022-03-22-recon_avproduct_through_pwh_or_wmi.md +++ /dev/null @@ -1,161 +0,0 @@ ---- -title: "Recon AVProduct Through Pwh or WMI" -excerpt: "Gather Victim Host Information -" -categories: - - Endpoint -last_modified_at: 2022-03-22 -toc: true -toc_label: "" -tags: - - Gather Victim Host Information - - Reconnaissance - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies suspicious PowerShell script execution via EventCode 4104 performing checks to identify anti-virus products installed on the endpoint. This technique is commonly found in malware and APT events where the adversary will map all running security applications or services. During triage, review parallel processes within the same timeframe. Review the full script block to identify other related artifacts. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-03-22 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 28077620-c9f6-11eb-8785-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1592](https://attack.mitre.org/techniques/T1592/) | Gather Victim Host Information | Reconnaissance | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 (ScriptBlockText = "*SELECT*" OR ScriptBlockText = "*WMIC*") AND (ScriptBlockText = "*AntiVirusProduct*" OR ScriptBlockText = "*AntiSpywareProduct*") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode ScriptBlockText Computer user_id -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `recon_avproduct_through_pwh_or_wmi_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **recon_avproduct_through_pwh_or_wmi_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* ScriptBlockText -* Computer -* UserID - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -network administrator may used this command for checking purposes - -#### Associated Analytic story -* [Hermetic Wiper](/stories/hermetic_wiper) -* [Ransomware](/stories/ransomware) -* [Malicious PowerShell](/stories/malicious_powershell) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 56.0 | 70 | 80 | A suspicious powershell script contains AV recon command in $ScriptBlockText$ with EventCode $EventCode$ in host $Computer$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://news.sophos.com/en-us/2020/05/12/maze-ransomware-1-year-counting/](https://news.sophos.com/en-us/2020/05/12/maze-ransomware-1-year-counting/) -* [https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.](https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.) -* [https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63](https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63) -* [https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf](https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf) -* [https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/](https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/) -* [https://www.splunk.com/en_us/blog/security/hunting-for-malicious-powershell-using-script-block-logging.html](https://www.splunk.com/en_us/blog/security/hunting-for-malicious-powershell-using-script-block-logging.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/t1592/pwh_av_recon/windows-powershell-xml.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/t1592/pwh_av_recon/windows-powershell-xml.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/recon_avproduct_through_pwh_or_wmi.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-03-22-remote_process_instantiation_via_dcom_and_powershell_script_block.md b/docs/_posts/2022-03-22-remote_process_instantiation_via_dcom_and_powershell_script_block.md deleted file mode 100644 index d1a7fe8c0b..0000000000 --- a/docs/_posts/2022-03-22-remote_process_instantiation_via_dcom_and_powershell_script_block.md +++ /dev/null @@ -1,160 +0,0 @@ ---- -title: "Remote Process Instantiation via DCOM and PowerShell Script Block" -excerpt: "Remote Services -, Distributed Component Object Model -" -categories: - - Endpoint -last_modified_at: 2022-03-22 -toc: true -toc_label: "" -tags: - - Remote Services - - Distributed Component Object Model - - Lateral Movement - - Lateral Movement - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of PowerShell with arguments utilized to start a process on a remote endpoint by abusing the DCOM protocol. Specifically, this search looks for the abuse of ShellExecute and ExecuteShellCommand. Red Teams and adversaries alike may abuse DCOM for lateral movement and remote code execution. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-03-22 -- **Author**: Mauricio Velazco, Splunk -- **ID**: fa1c3040-4680-11ec-a618-3e22fbd008af - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1021](https://attack.mitre.org/techniques/T1021/) | Remote Services | Lateral Movement | - -| [T1021.003](https://attack.mitre.org/techniques/T1021/003/) | Distributed Component Object Model | Lateral Movement | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 (ScriptBlockText="*Document.Application.ShellExecute*" OR ScriptBlockText="*Document.ActiveView.ExecuteShellCommand*") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode ScriptBlockText Computer user_id -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `remote_process_instantiation_via_dcom_and_powershell_script_block_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **remote_process_instantiation_via_dcom_and_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Message -* ComputerName -* User - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup instructions can be found https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -Administrators may leverage DCOM to start a process on remote systems, but this activity is usually limited to a small set of hosts or users. - -#### Associated Analytic story -* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 63.0 | 90 | 70 | A process was started on a remote endpoint from $ComputerName by abusing WMI using PowerShell.exe | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1021/003/](https://attack.mitre.org/techniques/T1021/003/) -* [https://www.cybereason.com/blog/dcom-lateral-movement-techniques](https://www.cybereason.com/blog/dcom-lateral-movement-techniques) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021.003/lateral_movement/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021.003/lateral_movement/windows-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/remote_process_instantiation_via_dcom_and_powershell_script_block.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-03-22-remote_process_instantiation_via_winrm_and_powershell_script_block.md b/docs/_posts/2022-03-22-remote_process_instantiation_via_winrm_and_powershell_script_block.md deleted file mode 100644 index adfc49a7d9..0000000000 --- a/docs/_posts/2022-03-22-remote_process_instantiation_via_winrm_and_powershell_script_block.md +++ /dev/null @@ -1,161 +0,0 @@ ---- -title: "Remote Process Instantiation via WinRM and PowerShell Script Block" -excerpt: "Remote Services -, Windows Remote Management -" -categories: - - Endpoint -last_modified_at: 2022-03-22 -toc: true -toc_label: "" -tags: - - Remote Services - - Windows Remote Management - - Lateral Movement - - Lateral Movement - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of PowerShell with arguments utilized to start a process on a remote endpoint by abusing the WinRM protocol. Specifically, this search looks for the abuse of the `Invoke-Command` commandlet. Red Teams and adversaries alike may abuse WinRM for lateral movement and remote code execution. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-03-22 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 7d4c618e-4716-11ec-951c-3e22fbd008af - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1021](https://attack.mitre.org/techniques/T1021/) | Remote Services | Lateral Movement | - -| [T1021.006](https://attack.mitre.org/techniques/T1021/006/) | Windows Remote Management | Lateral Movement | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 (ScriptBlockText="*Invoke-Command*" AND ScriptBlockText="*-ComputerName*") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode ScriptBlockText Computer user_id -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `remote_process_instantiation_via_winrm_and_powershell_script_block_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **remote_process_instantiation_via_winrm_and_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* ScriptBlockText -* Opcode -* Computer -* UserID -* EventCode - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup instructions can be found https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -Administrators may leverage WinRM and `Invoke-Command` to start a process on remote systems for system administration or automation use cases. This activity is usually limited to a small set of hosts or users. In certain environments, tuning may not be possible. - -#### Associated Analytic story -* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 45.0 | 90 | 50 | A process was started on a remote endpoint from $Computer$ by abusing WinRM using PowerShell.exe | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1021/006/](https://attack.mitre.org/techniques/T1021/006/) -* [https://pentestlab.blog/2018/05/15/lateral-movement-winrm/](https://pentestlab.blog/2018/05/15/lateral-movement-winrm/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021.006/lateral_movement_psh/windows-powershell-xml.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021.006/lateral_movement_psh/windows-powershell-xml.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/remote_process_instantiation_via_winrm_and_powershell_script_block.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-03-22-user_discovery_with_env_vars_powershell_script_block.md b/docs/_posts/2022-03-22-user_discovery_with_env_vars_powershell_script_block.md deleted file mode 100644 index b3eca55344..0000000000 --- a/docs/_posts/2022-03-22-user_discovery_with_env_vars_powershell_script_block.md +++ /dev/null @@ -1,156 +0,0 @@ ---- -title: "User Discovery With Env Vars PowerShell Script Block" -excerpt: "System Owner/User Discovery -" -categories: - - Endpoint -last_modified_at: 2022-03-22 -toc: true -toc_label: "" -tags: - - System Owner/User Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the use of PowerShell environment variables to identify the current logged user. Red Teams and adversaries may leverage this method to identify the logged user on a compromised endpoint for situational awareness and Active Directory Discovery. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-03-22 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 77f41d9e-b8be-47e3-ab35-5776f5ec1d20 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1033](https://attack.mitre.org/techniques/T1033/) | System Owner/User Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 (ScriptBlockText = "*$env:UserName*" OR ScriptBlockText = "*[System.Environment]::UserName*") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode ScriptBlockText Computer user_id -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `user_discovery_with_env_vars_powershell_script_block_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **user_discovery_with_env_vars_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Path -* Message -* OpCode -* ComputerName -* User -* EventCode - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -Administrators or power users may use this PowerShell commandlet for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | System user discovery on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1033/](https://attack.mitre.org/techniques/T1033/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1033/AD_discovery/windows-powershell-xml.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1033/AD_discovery/windows-powershell-xml.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-03-24-splunk_dos_via_malformed_s2s_request.md b/docs/_posts/2022-03-24-splunk_dos_via_malformed_s2s_request.md deleted file mode 100644 index 7b3cd4c163..0000000000 --- a/docs/_posts/2022-03-24-splunk_dos_via_malformed_s2s_request.md +++ /dev/null @@ -1,162 +0,0 @@ ---- -title: "Splunk DoS via Malformed S2S Request" -excerpt: "Network Denial of Service -" -categories: - - Application -last_modified_at: 2022-03-24 -toc: true -toc_label: "" -tags: - - Network Denial of Service - - Impact - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2021-3422 ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -On March 24th, 2022, Splunk published a security advisory for a possible Denial of Service stemming from the lack of validation in a specific key-value field in the Splunk-to-Splunk (S2S) protocol. This detection will alert on attempted exploitation in patched versions of Splunk. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-03-24 -- **Author**: Lou Stella, Splunk -- **ID**: fc246e56-953b-40c1-8634-868f9e474cbd - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1498](https://attack.mitre.org/techniques/T1498/) | Network Denial of Service | Impact | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2021-3422](https://nvd.nist.gov/vuln/detail/CVE-2021-3422) | The lack of validation of a key-value field in the Splunk-to-Splunk protocol results in a denial-of-service in Splunk Enterprise instances configured to index Universal Forwarder traffic. The vulnerability impacts Splunk Enterprise versions before 7.3.9, 8.0 versions before 8.0.9, and 8.1 versions before 8.1.3. It does not impact Universal Forwarders. When Splunk forwarding is secured using TLS or a Token, the attack requires compromising the certificate or token, or both. Implementation of either or both reduces the severity to Medium. | 4.3 | - - - -
-
- -#### Search - -``` -`splunkd` log_level="ERROR" component="TcpInputProc" thread_name="FwdDataReceiverThread" "Invalid _meta atom" -| table host, src -| `splunk_dos_via_malformed_s2s_request_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [splunkd](https://github.com/splunk/security_content/blob/develop/macros/splunkd.yml) - -> :information_source: -> **splunk_dos_via_malformed_s2s_request_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* host -* src -* log_level -* component -* thread_name - - -#### How To Implement -This detection does not require you to ingest any new data. The detection does require the ability to search the _internal index. This detection will only find attempted exploitation on versions of Splunk already patched for CVE-2021-3422. - -#### Known False Positives -None. - -#### Associated Analytic story -* [Splunk Vulnerabilities](/stories/splunk_vulnerabilities) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 50.0 | 50 | 100 | An attempt to exploit CVE-2021-3422 was detected from $src$ against $host$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.splunk.com/en_us/product-security/announcements/svd-2022-0301.html](https://www.splunk.com/en_us/product-security/announcements/svd-2022-0301.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1498/splunk_indexer_dos/splunkd.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1498/splunk_indexer_dos/splunkd.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/application/splunk_dos_via_malformed_s2s_request.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-03-28-sql_injection_with_long_urls.md b/docs/_posts/2022-03-28-sql_injection_with_long_urls.md deleted file mode 100644 index f826a17953..0000000000 --- a/docs/_posts/2022-03-28-sql_injection_with_long_urls.md +++ /dev/null @@ -1,165 +0,0 @@ ---- -title: "SQL Injection with Long URLs" -excerpt: "Exploit Public-Facing Application -" -categories: - - Web -last_modified_at: 2022-03-28 -toc: true -toc_label: "" -tags: - - Exploit Public-Facing Application - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Web ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for long URLs that have several SQL commands visible within them. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Web](https://docs.splunk.com/Documentation/CIM/latest/User/Web) -- **Last Updated**: 2022-03-28 -- **Author**: Bhavin Patel, Splunk -- **ID**: e0aad4cf-0790-423b-8328-7564d0d938f9 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1190](https://attack.mitre.org/techniques/T1190/) | Exploit Public-Facing Application | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Delivery - - -
-
- - -
- NIST - -
- -* PR.DS -* ID.RA -* PR.PT -* PR.IP -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 4 -* CIS 13 -* CIS 18 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count from datamodel=Web where Web.dest_category=web_server AND (Web.url_length > 1024 OR Web.http_user_agent_length > 200) by Web.src Web.dest Web.url Web.url_length Web.http_user_agent -| `drop_dm_object_name("Web")` -| eval url=lower(url) -| eval num_sql_cmds=mvcount(split(url, "alter%20table")) + mvcount(split(url, "between")) + mvcount(split(url, "create%20table")) + mvcount(split(url, "create%20database")) + mvcount(split(url, "create%20index")) + mvcount(split(url, "create%20view")) + mvcount(split(url, "delete")) + mvcount(split(url, "drop%20database")) + mvcount(split(url, "drop%20index")) + mvcount(split(url, "drop%20table")) + mvcount(split(url, "exists")) + mvcount(split(url, "exec")) + mvcount(split(url, "group%20by")) + mvcount(split(url, "having")) + mvcount(split(url, "insert%20into")) + mvcount(split(url, "inner%20join")) + mvcount(split(url, "left%20join")) + mvcount(split(url, "right%20join")) + mvcount(split(url, "full%20join")) + mvcount(split(url, "select")) + mvcount(split(url, "distinct")) + mvcount(split(url, "select%20top")) + mvcount(split(url, "union")) + mvcount(split(url, "xp_cmdshell")) - 24 -| where num_sql_cmds > 3 -| `sql_injection_with_long_urls_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **sql_injection_with_long_urls_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Web.dest_category -* Web.url_length -* Web.http_user_agent_length -* Web.src -* Web.dest -* Web.url -* Web.http_user_agent - - -#### How To Implement -To successfully implement this search, you need to be monitoring network communications to your web servers or ingesting your HTTP logs and populating the Web data model. You must also identify your web servers in the Enterprise Security assets table. - -#### Known False Positives -It's possible that legitimate traffic will have long URLs or long user agent strings and that common SQL commands may be found within the URL. Please investigate as appropriate. - -#### Associated Analytic story -* [SQL Injection](/stories/sql_injection) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | SQL injection attempt with url $url$ detected on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/web/sql_injection_with_long_urls.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2022-03-28-windows_deleted_registry_by_a_non_critical_process_file_path.md b/docs/_posts/2022-03-28-windows_deleted_registry_by_a_non_critical_process_file_path.md deleted file mode 100644 index 89750ce8bb..0000000000 --- a/docs/_posts/2022-03-28-windows_deleted_registry_by_a_non_critical_process_file_path.md +++ /dev/null @@ -1,175 +0,0 @@ ---- -title: "Windows Deleted Registry By A Non Critical Process File Path" -excerpt: "Modify Registry -" -categories: - - Endpoint -last_modified_at: 2022-03-28 -toc: true -toc_label: "" -tags: - - Modify Registry - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to detect deletion of registry with suspicious process file path. This technique was seen in Double Zero wiper malware where it will delete all the subkey in HKLM, HKCU and HKU registry hive as part of its destructive payload to the targeted hosts. This anomaly detections can catch possible malware or advesaries deleting registry as part of defense evasion or even payload impact but can also catch for third party application updates or installation. In this scenario false positive filter is needed. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-03-28 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 15e70689-f55b-489e-8a80-6d0cd6d8aad2 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1112](https://attack.mitre.org/techniques/T1112/) | Modify Registry | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.action=deleted by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_key_name Registry.process_guid Registry.registry_value_data Registry.action -| `drop_dm_object_name(Registry)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where NOT (Processes.process_path IN ("*\\windows\\*", "*\\program files*")) by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_path Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name action] -| table _time parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name action dest user -| `windows_deleted_registry_by_a_non_critical_process_file_path_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_deleted_registry_by_a_non_critical_process_file_path_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.registry_key_name -* Registry.registry_path -* Registry.registry_value_name -* Registry.dest -* Registry.user -* Registry.action -* Processes.process_id -* Processes.process_name -* Processes.process -* Processes.dest -* Processes.parent_process_name -* Processes.parent_process -* Processes.process_guid -* Processes.process_path - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the registry value name, registry path, and registry value data from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -This detection can catch for third party application updates or installation. In this scenario false positive filter is needed. - -#### Associated Analytic story -* [Double Zero Destructor](/stories/double_zero_destructor) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 36.0 | 60 | 60 | registry was deleted by a suspicious $process_name$ with proces path $process_path in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://blog.talosintelligence.com/2022/03/threat-advisory-doublezero.html](https://blog.talosintelligence.com/2022/03/threat-advisory-doublezero.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/doublezero_wiper/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/doublezero_wiper/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_deleted_registry_by_a_non_critical_process_file_path.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-03-28-windows_get-adcomputer_unconstrained_delegation_discovery.md b/docs/_posts/2022-03-28-windows_get-adcomputer_unconstrained_delegation_discovery.md deleted file mode 100644 index a3aedd0f60..0000000000 --- a/docs/_posts/2022-03-28-windows_get-adcomputer_unconstrained_delegation_discovery.md +++ /dev/null @@ -1,164 +0,0 @@ ---- -title: "Windows Get-AdComputer Unconstrained Delegation Discovery" -excerpt: "Remote System Discovery -" -categories: - - Endpoint -last_modified_at: 2022-03-28 -toc: true -toc_label: "" -tags: - - Remote System Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the Get-ADComputer commandlet used with specific parameters to discover Windows endpoints with Kerberos Unconstrained Delegation. Red Teams and adversaries alike may leverage use this technique for situational awareness and Active Directory Discovery. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-03-28 -- **Author**: Mauricio Velazco, Splunk -- **ID**: c8640777-469f-4638-ab44-c34a3233ffac - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1018](https://attack.mitre.org/techniques/T1018/) | Remote System Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - `powershell` EventCode=4104 (Message = "*Get-ADComputer*" AND Message = "*TrustedForDelegation*") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_get_adcomputer_unconstrained_delegation_discovery_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **windows_get-adcomputer_unconstrained_delegation_discovery_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Message -* ComputerName -* User - - -#### How To Implement -The following analytic requires PowerShell operational logs to be imported. Modify the powershell macro as needed to match the sourcetype or add index. This analytic is specific to 4104, or PowerShell Script Block Logging. - -#### Known False Positives -Administrators or power users may leverage PowerView for system management or troubleshooting. - -#### Associated Analytic story -* [Active Directory Kerberos Attacks](/stories/active_directory_kerberos_attacks) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 35.0 | 50 | 70 | Suspicious PowerShell Get-ADComputer was identified on endpoint $ComputerName$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1018/](https://attack.mitre.org/techniques/T1018/) -* [https://adsecurity.org/?p=1667](https://adsecurity.org/?p=1667) -* [https://docs.microsoft.com/en-us/defender-for-identity/cas-isp-unconstrained-kerberos](https://docs.microsoft.com/en-us/defender-for-identity/cas-isp-unconstrained-kerberos) -* [https://www.ired.team/offensive-security-experiments/active-directory-kerberos-abuse/domain-compromise-via-unrestricted-kerberos-delegation](https://www.ired.team/offensive-security-experiments/active-directory-kerberos-abuse/domain-compromise-via-unrestricted-kerberos-delegation) -* [https://www.cyberark.com/resources/threat-research-blog/weakness-within-kerberos-delegation](https://www.cyberark.com/resources/threat-research-blog/weakness-within-kerberos-delegation) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/unconstrained2/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/unconstrained2/windows-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_get_adcomputer_unconstrained_delegation_discovery.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-03-28-windows_powerview_unconstrained_delegation_discovery.md b/docs/_posts/2022-03-28-windows_powerview_unconstrained_delegation_discovery.md deleted file mode 100644 index bf1b12c71f..0000000000 --- a/docs/_posts/2022-03-28-windows_powerview_unconstrained_delegation_discovery.md +++ /dev/null @@ -1,164 +0,0 @@ ---- -title: "Windows PowerView Unconstrained Delegation Discovery" -excerpt: "Remote System Discovery -" -categories: - - Endpoint -last_modified_at: 2022-03-28 -toc: true -toc_label: "" -tags: - - Remote System Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify commandlets used by the PowerView hacking tool leveraged to discover Windows endpoints with Kerberos Unconstrained Delegation. Red Teams and adversaries alike may leverage use this technique for situational awareness and Active Directory Discovery. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-03-28 -- **Author**: Mauricio Velazco, Splunk -- **ID**: fbf9e47f-e531-4fea-942d-5c95af7ed4d6 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1018](https://attack.mitre.org/techniques/T1018/) | Remote System Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 (Message = "*Get-DomainComputer*" OR Message = "*Get-NetComputer*") AND (Message = "*-Unconstrained*") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_powerview_unconstrained_delegation_discovery_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **windows_powerview_unconstrained_delegation_discovery_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Message -* ComputerName -* User - - -#### How To Implement -The following analytic requires PowerShell operational logs to be imported. Modify the powershell macro as needed to match the sourcetype or add index. This analytic is specific to 4104, or PowerShell Script Block Logging. - -#### Known False Positives -Administrators or power users may leverage PowerView for system management or troubleshooting. - -#### Associated Analytic story -* [Active Directory Kerberos Attacks](/stories/active_directory_kerberos_attacks) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 35.0 | 50 | 70 | Suspicious PowerShell Get-DomainComputer was identified on endpoint $ComputerName$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1018/](https://attack.mitre.org/techniques/T1018/) -* [https://adsecurity.org/?p=1667](https://adsecurity.org/?p=1667) -* [https://docs.microsoft.com/en-us/defender-for-identity/cas-isp-unconstrained-kerberos](https://docs.microsoft.com/en-us/defender-for-identity/cas-isp-unconstrained-kerberos) -* [https://www.ired.team/offensive-security-experiments/active-directory-kerberos-abuse/domain-compromise-via-unrestricted-kerberos-delegation](https://www.ired.team/offensive-security-experiments/active-directory-kerberos-abuse/domain-compromise-via-unrestricted-kerberos-delegation) -* [https://www.cyberark.com/resources/threat-research-blog/weakness-within-kerberos-delegation](https://www.cyberark.com/resources/threat-research-blog/weakness-within-kerberos-delegation) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/unconstrained/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/unconstrained/windows-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_powerview_unconstrained_delegation_discovery.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-03-28-windows_terminating_lsass_process.md b/docs/_posts/2022-03-28-windows_terminating_lsass_process.md deleted file mode 100644 index 424eff1d3a..0000000000 --- a/docs/_posts/2022-03-28-windows_terminating_lsass_process.md +++ /dev/null @@ -1,169 +0,0 @@ ---- -title: "Windows Terminating Lsass Process" -excerpt: "Disable or Modify Tools -, Impair Defenses -" -categories: - - Endpoint -last_modified_at: 2022-03-28 -toc: true -toc_label: "" -tags: - - Disable or Modify Tools - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to detect a suspicious process terminating Lsass process. Lsass process is known to be a critical process that is responsible for enforcing security policy system. This process was commonly targetted by threat actor or red teamer to gain privilege escalation or persistence in the targeted machine because it handles credentials of the logon users. In this analytic we tried to detect a suspicious process having a granted access PROCESS_TERMINATE to lsass process to modify or delete protected registrys. This technique was seen in doublezero malware that tries to wipe files and registry in compromised hosts. This anomaly detection can be a good pivot of incident response for possible credential dumping or evading security policy in a host or network environment. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-03-28 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 7ab3c319-a4e7-4211-9e8c-40a049d0dba6 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventCode=10 TargetImage=*lsass.exe GrantedAccess = 0x1 -| stats count min(_time) as firstTime max(_time) as lastTime by SourceImage, TargetImage, TargetProcessId, SourceProcessId, GrantedAccess CallTrace, Computer -| rename Computer as dest -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_terminating_lsass_process_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **windows_terminating_lsass_process_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* TargetImage -* CallTrace -* Computer -* TargetProcessId -* SourceImage -* SourceProcessId -* GrantedAccess - - -#### How To Implement -This search requires Sysmon Logs and a Sysmon configuration, which includes EventCode 10 for lsass.exe. This search uses an input macro named `sysmon`. We strongly recommend that you specify your environment-specific configurations (index, source, sourcetype, etc.) for Windows Sysmon logs. Replace the macro definition with configurations for your Splunk environment. The search also uses a post-filter macro designed to filter out known false positives. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Double Zero Destructor](/stories/double_zero_destructor) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 64.0 | 80 | 80 | a process $SourceImage$ terminates Lsass process in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://blog.talosintelligence.com/2022/03/threat-advisory-doublezero.html](https://blog.talosintelligence.com/2022/03/threat-advisory-doublezero.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/doublezero_wiper/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/doublezero_wiper/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_terminating_lsass_process.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-03-29-macos_plutil.md b/docs/_posts/2022-03-29-macos_plutil.md deleted file mode 100644 index 8392c32f65..0000000000 --- a/docs/_posts/2022-03-29-macos_plutil.md +++ /dev/null @@ -1,163 +0,0 @@ ---- -title: "MacOS plutil" -excerpt: "Plist Modification -" -categories: - - Endpoint -last_modified_at: 2022-03-29 -toc: true -toc_label: "" -tags: - - Plist Modification - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -Detect usage of plutil to modify plist files. Adversaries can modiy plist files to executed binaries or add command line arguments. Plist files in auto-run locations are executed upon user logon or system startup. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-03-29 -- **Author**: Patrick Bareiss, Splunk -- **ID**: c11f2b57-92c1-4cd2-b46c-064eafb833ac - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1547.011](https://attack.mitre.org/techniques/T1547/011/) | Plist Modification | Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`osquery` name=es_process_events columns.path=/usr/bin/plutil -| rename columns.* as * -| stats count min(_time) as firstTime max(_time) as lastTime by username host cmdline pid path parent signing_id -| rename username as User, cmdline as process, path as process_path -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `macos_plutil_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [osquery](https://github.com/splunk/security_content/blob/develop/macros/osquery.yml) - -Note that **macos_plutil_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* columns.cmdline -* columns.pid -* columns.parent -* columns.path -* columns.signing_id -* columns.username -* host - - -#### How To Implement -This detection uses osquery and endpoint security on MacOS. Follow the link in references, which describes how to setup process auditing in MacOS with endpoint security and osquery. - -#### Known False Positives -Administrators using plutil to change plist files. - -#### Associated Analytic story -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | plutil are executed on $host$ from $user$ | - - -#### Reference - -* [https://osquery.readthedocs.io/en/stable/deployment/process-auditing/](https://osquery.readthedocs.io/en/stable/deployment/process-auditing/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.011/atomic_red_team/osquery.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.011/atomic_red_team/osquery.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/macos_plutil.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-03-29-windows_iso_lnk_file_creation.md b/docs/_posts/2022-03-29-windows_iso_lnk_file_creation.md deleted file mode 100644 index d6a31df127..0000000000 --- a/docs/_posts/2022-03-29-windows_iso_lnk_file_creation.md +++ /dev/null @@ -1,178 +0,0 @@ ---- -title: "Windows ISO LNK File Creation" -excerpt: "Spearphishing Attachment -, Phishing -, Malicious Link -, User Execution -" -categories: - - Endpoint -last_modified_at: 2022-03-29 -toc: true -toc_label: "" -tags: - - Spearphishing Attachment - - Phishing - - Malicious Link - - User Execution - - Initial Access - - Initial Access - - Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the use of a delivered ISO file that has been mounted and the afformention lnk or file opened within it. When the ISO file is opened, the files are saved in the %USER%\AppData\Local\Temp\\ path. The analytic identifies .iso.lnk written to the path. The name of the ISO file is prepended. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-03-29 -- **Author**: Michael Haag, Splunk -- **ID**: d7c2c09b-9569-4a9e-a8b6-6a39a99c1d32 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | - -| [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | - -| [T1204.001](https://attack.mitre.org/techniques/T1204/001/) | Malicious Link | Execution | - -| [T1204](https://attack.mitre.org/techniques/T1204/) | User Execution | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Delivery - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_path IN ("*\\Microsoft\\Windows\\Recent\\*") Filesystem.file_name IN ("*.iso.lnk") by Filesystem.file_create_time Filesystem.process_id Filesystem.file_name Filesystem.file_path Filesystem.dest -| `drop_dm_object_name(Filesystem)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_iso_lnk_file_creation_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_iso_lnk_file_creation_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* Filesystem.file_create_time -* Filesystem.process_id -* Filesystem.file_name -* Filesystem.file_path -* Filesystem.dest - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Filesystem` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -False positives may be high depending on the environment and consistent use of ISOs mounting. Restrict to servers, or filter out based on commonly used ISO names. Filter as needed. - -#### Associated Analytic story -* [Spearphishing Attachments](/stories/spearphishing_attachments) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 40.0 | 80 | 50 | An ISO file was mounted on $dest$ and should be reviewed and filtered as needed. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.microsoft.com/security/blog/2021/05/27/new-sophisticated-email-based-attack-from-nobelium/](https://www.microsoft.com/security/blog/2021/05/27/new-sophisticated-email-based-attack-from-nobelium/) -* [https://github.com/MHaggis/notes/blob/master/utilities/ISOBuilder.ps1](https://github.com/MHaggis/notes/blob/master/utilities/ISOBuilder.ps1) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1556.001/atomic_red_team/iso_windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1556.001/atomic_red_team/iso_windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_iso_lnk_file_creation.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-03-30-windows_drivers_loaded_by_signature.md b/docs/_posts/2022-03-30-windows_drivers_loaded_by_signature.md deleted file mode 100644 index f5be1cf051..0000000000 --- a/docs/_posts/2022-03-30-windows_drivers_loaded_by_signature.md +++ /dev/null @@ -1,171 +0,0 @@ ---- -title: "Windows Drivers Loaded by Signature" -excerpt: "Rootkit -, Exploitation for Privilege Escalation -" -categories: - - Endpoint -last_modified_at: 2022-03-30 -toc: true -toc_label: "" -tags: - - Rootkit - - Exploitation for Privilege Escalation - - Defense Evasion - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic assists with viewing all drivers being loaded by using Sysmon EventCode 6 (Driver Load). Sysmon provides some simple fields to assist with identifying suspicious drivers. Use this analytic to look at prevalence of driver (count), path of driver, signature status and hash. Review these fields with scrutiny until the ability to prove the driver is legitimate and has a purpose in the environment. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-03-30 -- **Author**: Michael Haag, Splunk -- **ID**: d2d4af6a-6c2b-4d79-80c5-fc2cf12a2f68 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1014](https://attack.mitre.org/techniques/T1014/) | Rootkit | Defense Evasion | - -| [T1068](https://attack.mitre.org/techniques/T1068/) | Exploitation for Privilege Escalation | Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventCode=6 -| stats min(_time) as firstTime max(_time) as lastTime values(ImageLoaded) count by Computer Signed Signature service_signature_verified service_signature_exists Hashes -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_drivers_loaded_by_signature_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **windows_drivers_loaded_by_signature_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* ImageLoaded -* Computer -* Signed -* Signature -* service_signature_verified -* service_signature_exists -* Hashes - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have the latest version of the Sysmon TA. Most EDR products provide the ability to review driver loads, or module loads, and using a query as such help with hunting for malicious drivers. - -#### Known False Positives -This analytic is meant to assist with identifying drivers loaded in the environment and not to be setup for notables off the bat. - -#### Associated Analytic story -* [Windows Drivers](/stories/windows_drivers) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 42.0 | 60 | 70 | A driver has loaded on $Computer$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://redcanary.com/blog/tracking-driver-inventory-to-expose-rootkits/](https://redcanary.com/blog/tracking-driver-inventory-to-expose-rootkits/) -* [https://attack.mitre.org/techniques/T1014/](https://attack.mitre.org/techniques/T1014/) -* [https://www.fuzzysecurity.com/tutorials/28.html](https://www.fuzzysecurity.com/tutorials/28.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1014/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1014/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_drivers_loaded_by_signature.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-03-31-windows_powerview_constrained_delegation_discovery.md b/docs/_posts/2022-03-31-windows_powerview_constrained_delegation_discovery.md deleted file mode 100644 index 9b6fa36004..0000000000 --- a/docs/_posts/2022-03-31-windows_powerview_constrained_delegation_discovery.md +++ /dev/null @@ -1,165 +0,0 @@ ---- -title: "Windows PowerView Constrained Delegation Discovery" -excerpt: "Remote System Discovery -" -categories: - - Endpoint -last_modified_at: 2022-03-31 -toc: true -toc_label: "" -tags: - - Remote System Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify commandlets used by the PowerView hacking tool leveraged to discover Windows endpoints with Kerberos Constrained Delegation. Red Teams and adversaries alike may leverage use this technique for situational awareness and Active Directory Discovery. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-03-31 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 86dc8176-6e6c-42d6-9684-5444c6557ab3 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1018](https://attack.mitre.org/techniques/T1018/) | Remote System Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 (Message = "*Get-DomainComputer*" OR Message = "*Get-NetComputer*") AND (Message = "*-TrustedToAuth*") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_powerview_constrained_delegation_discovery_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **windows_powerview_constrained_delegation_discovery_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Message -* ComputerName -* User - - -#### How To Implement -The following analytic requires PowerShell operational logs to be imported. Modify the powershell macro as needed to match the sourcetype or add index. This analytic is specific to 4104, or PowerShell Script Block Logging. - -#### Known False Positives -Administrators or power users may leverage PowerView for system management or troubleshooting. - -#### Associated Analytic story -* [Active Directory Kerberos Attacks](/stories/active_directory_kerberos_attacks) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 35.0 | 50 | 70 | Suspicious PowerShell Get-DomainComputer was identified on endpoint $ComputerName$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1018/](https://attack.mitre.org/techniques/T1018/) -* [https://adsecurity.org/?p=1667](https://adsecurity.org/?p=1667) -* [https://docs.microsoft.com/en-us/defender-for-identity/cas-isp-unconstrained-kerberos](https://docs.microsoft.com/en-us/defender-for-identity/cas-isp-unconstrained-kerberos) -* [https://www.guidepointsecurity.com/blog/delegating-like-a-boss-abusing-kerberos-delegation-in-active-directory/](https://www.guidepointsecurity.com/blog/delegating-like-a-boss-abusing-kerberos-delegation-in-active-directory/) -* [https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/constrained-delegation](https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/constrained-delegation) -* [https://www.cyberark.com/resources/threat-research-blog/weakness-within-kerberos-delegation](https://www.cyberark.com/resources/threat-research-blog/weakness-within-kerberos-delegation) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/constrained/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/constrained/windows-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_powerview_constrained_delegation_discovery.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-03-31-windows_registry_certificate_added.md b/docs/_posts/2022-03-31-windows_registry_certificate_added.md deleted file mode 100644 index 5fd0bbf3cb..0000000000 --- a/docs/_posts/2022-03-31-windows_registry_certificate_added.md +++ /dev/null @@ -1,175 +0,0 @@ ---- -title: "Windows Registry Certificate Added" -excerpt: "Install Root Certificate -, Subvert Trust Controls -" -categories: - - Endpoint -last_modified_at: 2022-03-31 -toc: true -toc_label: "" -tags: - - Install Root Certificate - - Subvert Trust Controls - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies installation of a root CA certificate by monitoring the registry. The base paths may be found [here](https://gist.github.com/mattifestation/75d6117707bcf8c26845b3cbb6ad2b6b/raw/ae65ef15c706140ffc2e165615204e20f2903028/RootCAInstallationDetection.xml). In short, there are specific certificate registry paths that will be written to (SetValue) when a new certificate is added. The high-fidelity events to pay attention to are SetValue events where the TargetObject property ends with "\Blob" as this indicates the direct installation or modification of a root certificate binary blob. The other high fidelity reference will be which process is making the registry modifications. There are very few processes that modify these day to day, therefore monitoring for all to start (hunting) provides a great beginning. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-03-31 -- **Author**: Michael Haag, Splunk -- **ID**: 5ee98b2f-8b9e-457a-8bdc-dd41aaba9e87 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1553.004](https://attack.mitre.org/techniques/T1553/004/) | Install Root Certificate | Defense Evasion | - -| [T1553](https://attack.mitre.org/techniques/T1553/) | Subvert Trust Controls | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path IN ("*\\certificates\\*") AND Registry.registry_value_name="Blob" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.process_guid Registry.registry_key_name Registry.registry_value_data -| `drop_dm_object_name(Registry)` -| join process_guid _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.process_guid -| `drop_dm_object_name(Processes)`] -| table _time dest user process_name process process_guid registry_path registry_value_name registry_value_data registry_key_name -| `windows_registry_certificate_added_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_registry_certificate_added_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.registry_path -* Registry.registry_key_name -* Registry.registry_value_name -* Registry.dest -* Processes.process_id -* Processes.process_name -* Processes.process -* Processes.dest -* Processes.process_guid - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` and `Registry` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -False positives will be limited to a legitimate business applicating consistently adding new root certificates to the endpoint. Filter by user, process, or thumbprint. - -#### Associated Analytic story -* [Windows Drivers](/stories/windows_drivers) -* [Windows Registry Abuse](/stories/windows_registry_abuse) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 42.0 | 60 | 70 | A root certificate was added on $dest$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://posts.specterops.io/code-signing-certificate-cloning-attacks-and-defenses-6f98657fc6ec](https://posts.specterops.io/code-signing-certificate-cloning-attacks-and-defenses-6f98657fc6ec) -* [https://github.com/redcanaryco/atomic-red-team/tree/master/atomics/T1553.004](https://github.com/redcanaryco/atomic-red-team/tree/master/atomics/T1553.004) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1587.002/atomic_red_team/certblob_windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1587.002/atomic_red_team/certblob_windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_registry_certificate_added.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-03-31-windows_registry_modification_for_safe_mode_persistence.md b/docs/_posts/2022-03-31-windows_registry_modification_for_safe_mode_persistence.md deleted file mode 100644 index 42dd0062e6..0000000000 --- a/docs/_posts/2022-03-31-windows_registry_modification_for_safe_mode_persistence.md +++ /dev/null @@ -1,174 +0,0 @@ ---- -title: "Windows Registry Modification for Safe Mode Persistence" -excerpt: "Registry Run Keys / Startup Folder -, Boot or Logon Autostart Execution -" -categories: - - Endpoint -last_modified_at: 2022-03-31 -toc: true -toc_label: "" -tags: - - Registry Run Keys / Startup Folder - - Boot or Logon Autostart Execution - - Persistence - - Privilege Escalation - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies a modification or registry add to the safeboot registry as an autostart mechanism. This technique is utilized by adversaries to persist a driver or service into Safe Mode. Two keys are monitored in this analytic, Minimal and Network. adding values to Minimal will load into Safe Mode and by adding into Network it will provide the service or drive the ability to perform network connections in Safe Mode. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-03-31 -- **Author**: Teoderick Contreras, Michael Haag, Splunk -- **ID**: c6149154-c9d8-11eb-9da7-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1547.001](https://attack.mitre.org/techniques/T1547/001/) | Registry Run Keys / Startup Folder | Persistence, Privilege Escalation | - -| [T1547](https://attack.mitre.org/techniques/T1547/) | Boot or Logon Autostart Execution | Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path IN ("*SYSTEM\\CurrentControlSet\\Control\\SafeBoot\\Minimal\\*","*SYSTEM\\CurrentControlSet\\Control\\SafeBoot\\Network\\*") by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.process_guid Registry.registry_key_name Registry.registry_value_data -| `drop_dm_object_name(Registry)` -| join process_guid _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.process_guid -| `drop_dm_object_name(Processes)`] -| table _time dest user process_name process process_guid registry_path registry_value_name registry_value_data registry_key_name -| `windows_registry_modification_for_safe_mode_persistence_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_registry_modification_for_safe_mode_persistence_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.registry_path -* Registry.registry_key_name -* Registry.registry_value_name -* Registry.dest -* Processes.process_id -* Processes.process_name -* Processes.process -* Processes.dest -* Processes.process_guid - - -#### How To Implement -To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. - -#### Known False Positives -updated windows application needed in safe boot may used this registry - -#### Associated Analytic story -* [Ransomware](/stories/ransomware) -* [Windows Registry Abuse](/stories/windows_registry_abuse) -* [Windows Drivers](/stories/windows_drivers) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 42.0 | 60 | 70 | Safeboot registry $registry_path$ was added or modified with a new value $registry_value_name$ on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://malware.news/t/threat-analysis-unit-tau-threat-intelligence-notification-snatch-ransomware/36365](https://malware.news/t/threat-analysis-unit-tau-threat-intelligence-notification-snatch-ransomware/36365) -* [https://redcanary.com/blog/tracking-driver-inventory-to-expose-rootkits/](https://redcanary.com/blog/tracking-driver-inventory-to-expose-rootkits/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1112/T1112.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1112/T1112.md) -* [https://blog.didierstevens.com/2007/03/26/playing-with-safe-mode/](https://blog.didierstevens.com/2007/03/26/playing-with-safe-mode/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/data1/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/data1/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_registry_modification_for_safe_mode_persistence.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2022-04-02-getnettcpconnection_with_powershell_script_block.md b/docs/_posts/2022-04-02-getnettcpconnection_with_powershell_script_block.md deleted file mode 100644 index 4567d87c32..0000000000 --- a/docs/_posts/2022-04-02-getnettcpconnection_with_powershell_script_block.md +++ /dev/null @@ -1,155 +0,0 @@ ---- -title: "GetNetTcpconnection with PowerShell Script Block" -excerpt: "System Network Connections Discovery -" -categories: - - Endpoint -last_modified_at: 2022-04-02 -toc: true -toc_label: "" -tags: - - System Network Connections Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-NetTcpconnection ` commandlet. This commandlet is used to return a listing of network connections on a compromised system. Red Teams and adversaries alike may use this commandlet for situational awareness and Active Directory Discovery. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-04-02 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 091712ff-b02a-4d43-82ed-34765515d95d - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1049](https://attack.mitre.org/techniques/T1049/) | System Network Connections Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 (ScriptBlockText = "*Get-NetTcpconnection*") -| stats count min(_time) as firstTime max(_time) as lastTime by Opcode Computer UserID EventCode ScriptBlockText -| `security_content_ctime(firstTime)` -| `getnettcpconnection_with_powershell_script_block_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **getnettcpconnection_with_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* ScriptBlockText -* Opcode -* Computer -* UserID -* EventCode - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -Administrators or power users may use this PowerShell commandlet for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | Network Connection discovery on $Computer$ by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1049/](https://attack.mitre.org/techniques/T1049/) -* [https://docs.microsoft.com/en-us/powershell/module/nettcpip/get-nettcpconnection?view=windowsserver2019-ps](https://docs.microsoft.com/en-us/powershell/module/nettcpip/get-nettcpconnection?view=windowsserver2019-ps) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/nettcpconnection.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/nettcpconnection.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-04-04-github_actions_disable_security_workflow.md b/docs/_posts/2022-04-04-github_actions_disable_security_workflow.md deleted file mode 100644 index 008e97ef0a..0000000000 --- a/docs/_posts/2022-04-04-github_actions_disable_security_workflow.md +++ /dev/null @@ -1,174 +0,0 @@ ---- -title: "GitHub Actions Disable Security Workflow" -excerpt: "Compromise Software Supply Chain -, Supply Chain Compromise -" -categories: - - Cloud -last_modified_at: 2022-04-04 -toc: true -toc_label: "" -tags: - - Compromise Software Supply Chain - - Supply Chain Compromise - - Initial Access - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search detects a disabled security workflow in GitHub Actions. An attacker can disable a security workflow in GitHub actions to hide malicious code in it. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-04-04 -- **Author**: Patrick Bareiss, Splunk -- **ID**: 0459f1a5-c0ac-4987-82d6-65081209f854 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1195.002](https://attack.mitre.org/techniques/T1195/002/) | Compromise Software Supply Chain | Initial Access | - -| [T1195](https://attack.mitre.org/techniques/T1195/) | Supply Chain Compromise | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.DS -* PR.AC -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 13 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`github` workflow_run.event=push OR workflow_run.event=pull_request -| stats values(workflow_run.name) as workflow_run.name by workflow_run.head_commit.id workflow_run.event workflow_run.head_branch workflow_run.head_commit.author.email workflow_run.head_commit.author.name workflow_run.head_commit.message workflow_run.head_commit.timestamp workflow_run.head_repository.full_name workflow_run.head_repository.owner.id workflow_run.head_repository.owner.login workflow_run.head_repository.owner.type -| rename workflow_run.head_commit.author.name as user, workflow_run.head_commit.author.email as user_email, workflow_run.head_repository.full_name as repository, workflow_run.head_branch as branch -| search NOT workflow_run.name=*security-testing* -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `github_actions_disable_security_workflow_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [github](https://github.com/splunk/security_content/blob/develop/macros/github.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **github_actions_disable_security_workflow_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* workflow_run.event -* workflow_run.name -* workflow_run.head_commit.id -* workflow_run.event workflow_run.head_branch -* workflow_run.head_commit.author.email -* workflow_run.head_commit.author.name -* workflow_run.head_commit.message -* workflow_run.head_commit.timestamp -* workflow_run.head_repository.full_name -* workflow_run.head_repository.owner.id -* workflow_run.head_repository.owner.login -* workflow_run.head_repository.owner.type - - -#### How To Implement -You must index GitHub logs. You can follow the url in reference to onboard GitHub logs. Sometimes GitHub logs are truncated, make sure to disable it in props.conf. Replace *security-testing* with the name of your security testing workflow in GitHub Actions. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Dev Sec Ops](/stories/dev_sec_ops) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 27.0 | 30 | 90 | Security Workflow is disabled in branch $branch$ for repository $repository$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.splunk.com/en_us/blog/tips-and-tricks/getting-github-data-with-webhooks.html](https://www.splunk.com/en_us/blog/tips-and-tricks/getting-github-data-with-webhooks.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1195.002/github_actions_disable_security_workflow/github_actions_disable_security_workflow.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1195.002/github_actions_disable_security_workflow/github_actions_disable_security_workflow.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/github_actions_disable_security_workflow.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-04-04-windows_driver_load_non-standard_path.md b/docs/_posts/2022-04-04-windows_driver_load_non-standard_path.md deleted file mode 100644 index e8bf097fdc..0000000000 --- a/docs/_posts/2022-04-04-windows_driver_load_non-standard_path.md +++ /dev/null @@ -1,164 +0,0 @@ ---- -title: "Windows Driver Load Non-Standard Path" -excerpt: "Rootkit -" -categories: - - Endpoint -last_modified_at: 2022-04-04 -toc: true -toc_label: "" -tags: - - Rootkit - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic uses Windows EventCode 7045 to identify new Kernel Mode Drivers being loaded in Windows from a non-standard path. Note that, adversaries may move malicious or vulnerable drivers into these paths and load up. The idea is that this analytic provides visibility into drivers loading in non-standard file paths. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-04-04 -- **Author**: Michael Haag, Splunk -- **ID**: 9216ef3d-066a-4958-8f27-c84589465e62 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1014](https://attack.mitre.org/techniques/T1014/) | Rootkit | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Installation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`wineventlog_system` EventCode=7045 Service_Type="kernel mode driver" NOT (Service_File_Name IN ("*\\Windows\\*", "*\\Program File*", "*\\systemroot\\*","%SystemRoot%*", "system32\*")) -| stats count min(_time) as firstTime max(_time) as lastTime by ComputerName EventCode Service_File_Name Service_Name Service_Start_Type Service_Type -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_driver_load_non_standard_path_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [wineventlog_system](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_system.yml) - -> :information_source: -> **windows_driver_load_non-standard_path_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* ComputerName -* EventCode -* Service_File_Name -* Service_Name -* Service_Start_Type -* Service_Type - - -#### How To Implement -To implement this analytic, the Windows EventCode 7045 will need to be logged. The Windows TA for Splunk is also recommended. - -#### Known False Positives -False positives may be present based on legitimate third party applications needing to install drivers. Filter, or allow list known good drivers consistently being installed in these paths. - -#### Associated Analytic story -* [Windows Drivers](/stories/windows_drivers) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 36.0 | 60 | 60 | A kernel mode driver was loaded from a non-standard path on $ComputerName$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://redcanary.com/blog/tracking-driver-inventory-to-expose-rootkits/](https://redcanary.com/blog/tracking-driver-inventory-to-expose-rootkits/) -* [https://attack.mitre.org/techniques/T1014/](https://attack.mitre.org/techniques/T1014/) -* [https://www.fuzzysecurity.com/tutorials/28.html](https://www.fuzzysecurity.com/tutorials/28.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1068/drivers/7045_kerneldrivers.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1068/drivers/7045_kerneldrivers.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_driver_load_non_standard_path.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-04-04-windows_event_for_service_disabled.md b/docs/_posts/2022-04-04-windows_event_for_service_disabled.md deleted file mode 100644 index 5d7224b035..0000000000 --- a/docs/_posts/2022-04-04-windows_event_for_service_disabled.md +++ /dev/null @@ -1,167 +0,0 @@ ---- -title: "Windows Event For Service Disabled" -excerpt: "Disable or Modify Tools -, Impair Defenses -" -categories: - - Endpoint -last_modified_at: 2022-04-04 -toc: true -toc_label: "" -tags: - - Disable or Modify Tools - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic will identify suspicious system event of services that was modified from start to disabled. This technique is seen where the adversary attempts to disable security app services, other malware services to evade the defense systems on the compromised host - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-04-04 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 9c2620a8-94a1-11ec-b40c-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`wineventlog_system` EventCode=7040 Message = "*service was changed from demand start to disabled." -| stats count min(_time) as firstTime max(_time) as lastTime by ComputerName EventCode Message User Sid service service_name -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_event_for_service_disabled_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [wineventlog_system](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_system.yml) - -> :information_source: -> **windows_event_for_service_disabled_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* ComputerName -* EventCode -* Message -* User -* Sid - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the Service name, Service File Name Service Start type, and Service Type from your endpoints. - -#### Known False Positives -Windows service update may cause this event. In that scenario, filtering is needed. - -#### Associated Analytic story -* [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 36.0 | 60 | 60 | Service was disabled on $Computer$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://blog.talosintelligence.com/2018/02/olympic-destroyer.html](https://blog.talosintelligence.com/2018/02/olympic-destroyer.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/olympic_destroyer/system.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/olympic_destroyer/system.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_event_for_service_disabled.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-04-05-java_writing_jsp_file.md b/docs/_posts/2022-04-05-java_writing_jsp_file.md deleted file mode 100644 index c33802b2bf..0000000000 --- a/docs/_posts/2022-04-05-java_writing_jsp_file.md +++ /dev/null @@ -1,187 +0,0 @@ ---- -title: "Java Writing JSP File" -excerpt: "Exploit Public-Facing Application -" -categories: - - Endpoint -last_modified_at: 2022-04-05 -toc: true -toc_label: "" -tags: - - Exploit Public-Facing Application - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2022-22965 - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the process java writing a .jsp to disk. This is potentially indicative of a web shell being written to disk. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-04-05 -- **Author**: Michael Haag, Splunk -- **ID**: eb65619c-4f8d-4383-a975-d352765d344b - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1190](https://attack.mitre.org/techniques/T1190/) | Exploit Public-Facing Application | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2022-22965](https://nvd.nist.gov/vuln/detail/CVE-2022-22965) | A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it. | 7.5 | - - - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name IN ("java","java.exe", "javaw.exe") by _time Processes.process_id Processes.process_name Processes.dest Processes.process_guid Processes.user -| `drop_dm_object_name(Processes)` -| join process_guid [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Filesystem where Filesystem.file_name="*.jsp*" by _time Filesystem.dest Filesystem.file_create_time Filesystem.file_name Filesystem.file_path Filesystem.process_guid Filesystem.user -| `drop_dm_object_name(Filesystem)` -| fields _time process_guid file_path file_name file_create_time user dest process_name] -| stats count min(_time) as firstTime max(_time) as lastTime by dest process_name process_guid file_name file_path file_create_time user -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `java_writing_jsp_file_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **java_writing_jsp_file_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id -* Filesystem.dest -* Filesystem.file_create_time -* Filesystem.file_name -* Filesystem.file_path -* Filesystem.process_guid -* Filesystem.user - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` and `Filesystem` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -False positives are possible and filtering may be required. Restrict by assets or filter known jsp files that are common for the environment. - -#### Associated Analytic story -* [Spring4Shell CVE-2022-22965](/stories/spring4shell_cve-2022-22965) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 42.0 | 60 | 70 | An instance of $process_name$ was identified on endpoint $dest$ writing a jsp file to disk, potentially indicative of exploitation. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.microsoft.com/security/blog/2022/04/04/springshell-rce-vulnerability-guidance-for-protecting-against-and-detecting-cve-2022-22965/](https://www.microsoft.com/security/blog/2022/04/04/springshell-rce-vulnerability-guidance-for-protecting-against-and-detecting-cve-2022-22965/) -* [https://github.com/TheGejr/SpringShell](https://github.com/TheGejr/SpringShell) -* [https://www.tenable.com/blog/spring4shell-faq-spring-framework-remote-code-execution-vulnerability](https://www.tenable.com/blog/spring4shell-faq-spring-framework-remote-code-execution-vulnerability) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/spring4shell/java_write_jsp-linux-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/spring4shell/java_write_jsp-linux-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/java_writing_jsp_file.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-04-05-linux_iptables_firewall_modification.md b/docs/_posts/2022-04-05-linux_iptables_firewall_modification.md deleted file mode 100644 index 83a4715e3a..0000000000 --- a/docs/_posts/2022-04-05-linux_iptables_firewall_modification.md +++ /dev/null @@ -1,167 +0,0 @@ ---- -title: "Linux Iptables Firewall Modification" -excerpt: "Disable or Modify System Firewall -, Impair Defenses -" -categories: - - Endpoint -last_modified_at: 2022-04-05 -toc: true -toc_label: "" -tags: - - Disable or Modify System Firewall - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for suspicious commandline that modify the iptables firewall setting of a linux machine. This technique was seen in cyclopsblink malware where it modifies the firewall setting of the compromised machine to allow traffic to its tcp port that will be used to communicate with its C2 server. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-04-05 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 309d59dc-1e1b-49b2-9800-7cf18d12f7b7 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.004](https://attack.mitre.org/techniques/T1562/004/) | Disable or Modify System Firewall | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process = "*iptables *" AND Processes.process = "* --dport *" AND Processes.process = "* ACCEPT*" by Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.process_guid Processes.dest Processes.user Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `linux_iptables_firewall_modification_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -Note that **linux_iptables_firewall_modification_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase. - -#### Known False Positives -administrator may do this commandline for auditing and testing purposes. In this scenario filter is needed. - -#### Associated Analytic story -* [Cyclops BLink](/stories/cyclops_blink) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | A commandline $process$ that may modify iptables firewall on $dest$ | - - -#### Reference - -* [https://www.ncsc.gov.uk/files/Cyclops-Blink-Malware-Analysis-Report.pdf](https://www.ncsc.gov.uk/files/Cyclops-Blink-Malware-Analysis-Report.pdf) -* [https://www.trendmicro.com/en_us/research/22/c/cyclops-blink-sets-sights-on-asus-routers--.html](https://www.trendmicro.com/en_us/research/22/c/cyclops-blink-sets-sights-on-asus-routers--.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/cyclopsblink/sysmon_linux.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/cyclopsblink/sysmon_linux.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_iptables_firewall_modification.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-04-05-linux_kworker_process_commandline.md b/docs/_posts/2022-04-05-linux_kworker_process_commandline.md deleted file mode 100644 index 84c9fa1320..0000000000 --- a/docs/_posts/2022-04-05-linux_kworker_process_commandline.md +++ /dev/null @@ -1,167 +0,0 @@ ---- -title: "Linux Kworker Process CommandLine" -excerpt: "Masquerade Task or Service -, Masquerading -" -categories: - - Endpoint -last_modified_at: 2022-04-05 -toc: true -toc_label: "" -tags: - - Masquerade Task or Service - - Masquerading - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for suspicious process kworker commandline in a linux machine. kworker process name or thread are common name of kernel thread in linux process. So it is really a suspicious event a normal user process contain this process commandline. This technique was seen in cyclopsblink malware to blend its core and other of its child process as normal kworker on the compromised machine. This detection might be a good pivot to look for other IOC related to cyclopsblink malware or attacks. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-04-05 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 1cefb270-74a5-4e27-aa0c-2b6fa7c5b4ed - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1036.004](https://attack.mitre.org/techniques/T1036/004/) | Masquerade Task or Service | Defense Evasion | - -| [T1036](https://attack.mitre.org/techniques/T1036/) | Masquerading | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process = "*[kworker/*" OR Processes.parent_process = "*[kworker/*" by Processes.parent_process_name Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.process_guid Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `linux_kworker_process_commandline_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -Note that **linux_kworker_process_commandline_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Cyclops BLink](/stories/cyclops_blink) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 64.0 | 80 | 80 | a $process_name$ with kworker commandline in $dest$ | - - -#### Reference - -* [https://www.ncsc.gov.uk/files/Cyclops-Blink-Malware-Analysis-Report.pdf](https://www.ncsc.gov.uk/files/Cyclops-Blink-Malware-Analysis-Report.pdf) -* [https://www.trendmicro.com/en_us/research/22/c/cyclops-blink-sets-sights-on-asus-routers--.html](https://www.trendmicro.com/en_us/research/22/c/cyclops-blink-sets-sights-on-asus-routers--.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/cyclopsblink/sysmon_linux.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/cyclopsblink/sysmon_linux.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_kworker_process_commandline.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-04-05-linux_stdout_redirection_to_dev_null_file.md b/docs/_posts/2022-04-05-linux_stdout_redirection_to_dev_null_file.md deleted file mode 100644 index 20a44c84b6..0000000000 --- a/docs/_posts/2022-04-05-linux_stdout_redirection_to_dev_null_file.md +++ /dev/null @@ -1,174 +0,0 @@ ---- -title: "Linux Stdout Redirection To Dev Null File" -excerpt: "Disable or Modify System Firewall -, Impair Defenses -" -categories: - - Endpoint -last_modified_at: 2022-04-05 -toc: true -toc_label: "" -tags: - - Disable or Modify System Firewall - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for suspicious commandline that redirect the stdout or possible stderror to dev/null file. This technique was seen in cyclopsblink malware where it redirect the possible output or error while modify the iptables firewall setting of the compromised machine to hide its action from the user. This Anomaly detection is a good pivot to look further why process or user use this un common approach. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-04-05 -- **Author**: Teoderick Contreras, Splunk -- **ID**: de62b809-a04d-46b5-9a15-8298d330f0c8 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.004](https://attack.mitre.org/techniques/T1562/004/) | Disable or Modify System Firewall | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process = "*&>/dev/null*" by Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.process_guid Processes.dest Processes.user Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `linux_stdout_redirection_to_dev_null_file_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **linux_stdout_redirection_to_dev_null_file_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [CyclopsBLink](/stories/cyclopsblink) -* [Industroyer2](/stories/industroyer2) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 36.0 | 60 | 60 | a commandline $process$ that redirect stdout to dev/null in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.ncsc.gov.uk/files/Cyclops-Blink-Malware-Analysis-Report.pdf](https://www.ncsc.gov.uk/files/Cyclops-Blink-Malware-Analysis-Report.pdf) -* [https://www.trendmicro.com/en_us/research/22/c/cyclops-blink-sets-sights-on-asus-routers--.html](https://www.trendmicro.com/en_us/research/22/c/cyclops-blink-sets-sights-on-asus-routers--.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/cyclopsblink/sysmon_linux.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/cyclopsblink/sysmon_linux.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/endpoint/linux_stdout_redirection_to_dev_null_file.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-04-05-spring4shell_payload_url_request.md b/docs/_posts/2022-04-05-spring4shell_payload_url_request.md deleted file mode 100644 index b8f841f9ad..0000000000 --- a/docs/_posts/2022-04-05-spring4shell_payload_url_request.md +++ /dev/null @@ -1,180 +0,0 @@ ---- -title: "Spring4Shell Payload URL Request" -excerpt: "Web Shell -, Server Software Component -, Exploit Public-Facing Application -" -categories: - - Web -last_modified_at: 2022-04-05 -toc: true -toc_label: "" -tags: - - Web Shell - - Server Software Component - - Exploit Public-Facing Application - - Persistence - - Persistence - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2022-22965 - - Web ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic is static indicators related to CVE-2022-22963, Spring4Shell. The 3 indicators provide an amount of fidelity that source IP is attemping to exploit a web shell on the destination. The filename and cmd are arbitrary in this exploitation. Java will write a JSP to disk and a process will spawn from Java based on the cmd passed. This is indicative of typical web shell activity. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Web](https://docs.splunk.com/Documentation/CIM/latest/User/Web) -- **Last Updated**: 2022-04-05 -- **Author**: Michael Haag, Splunk -- **ID**: 2850c734-2d44-4431-8139-1a56f6f54c01 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1505.003](https://attack.mitre.org/techniques/T1505/003/) | Web Shell | Persistence | - -| [T1505](https://attack.mitre.org/techniques/T1505/) | Server Software Component | Persistence | - -| [T1190](https://attack.mitre.org/techniques/T1190/) | Exploit Public-Facing Application | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2022-22965](https://nvd.nist.gov/vuln/detail/CVE-2022-22965) | A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it. | 7.5 | - - - -
-
- -#### Search - -``` - -| tstats count from datamodel=Web where Web.http_method IN ("GET") Web.url IN ("*tomcatwar.jsp*","*poc.jsp*","*shell.jsp*") by Web.http_user_agent Web.http_method, Web.url,Web.url_length Web.src, Web.dest sourcetype -| `drop_dm_object_name("Web")` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `spring4shell_payload_url_request_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **spring4shell_payload_url_request_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Web.http_method -* Web.url -* Web.url_length -* Web.src -* Web.dest -* Web.http_user_agent - - -#### How To Implement -To successfully implement this search you need to be ingesting information on Web traffic that include fields relavent for traffic into the `Web` datamodel. - -#### Known False Positives -The jsp file names are static names used in current proof of concept code. = - -#### Associated Analytic story -* [Spring4Shell CVE-2022-22965](/stories/spring4shell_cve-2022-22965) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 36.0 | 60 | 60 | A URL was requested related to Spring4Shell POC code on $dest$ by $src$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.microsoft.com/security/blog/2022/04/04/springshell-rce-vulnerability-guidance-for-protecting-against-and-detecting-cve-2022-22965/](https://www.microsoft.com/security/blog/2022/04/04/springshell-rce-vulnerability-guidance-for-protecting-against-and-detecting-cve-2022-22965/) -* [https://github.com/TheGejr/SpringShell](https://github.com/TheGejr/SpringShell) -* [https://www.tenable.com/blog/spring4shell-faq-spring-framework-remote-code-execution-vulnerability](https://www.tenable.com/blog/spring4shell-faq-spring-framework-remote-code-execution-vulnerability) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/spring4shell/spring4shell_nginx.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/spring4shell/spring4shell_nginx.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/web/spring4shell_payload_url_request.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-04-05-web_jsp_request_via_url.md b/docs/_posts/2022-04-05-web_jsp_request_via_url.md deleted file mode 100644 index 1cde456bc1..0000000000 --- a/docs/_posts/2022-04-05-web_jsp_request_via_url.md +++ /dev/null @@ -1,180 +0,0 @@ ---- -title: "Web JSP Request via URL" -excerpt: "Web Shell -, Server Software Component -, Exploit Public-Facing Application -" -categories: - - Web -last_modified_at: 2022-04-05 -toc: true -toc_label: "" -tags: - - Web Shell - - Server Software Component - - Exploit Public-Facing Application - - Persistence - - Persistence - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2022-22965 - - Web ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the common URL requests used by a recent CVE - CVE-2022-22965, or Spring4Shell, to access a webshell on the remote webserver. The filename and cmd are arbitrary in this exploitation. Java will write a JSP to disk and a process will spawn from Java based on the cmd passed. This is indicative of typical web shell activity. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Web](https://docs.splunk.com/Documentation/CIM/latest/User/Web) -- **Last Updated**: 2022-04-05 -- **Author**: Michael Haag, Splunk -- **ID**: 2850c734-2d44-4431-8139-1a56f6f54c01 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1505.003](https://attack.mitre.org/techniques/T1505/003/) | Web Shell | Persistence | - -| [T1505](https://attack.mitre.org/techniques/T1505/) | Server Software Component | Persistence | - -| [T1190](https://attack.mitre.org/techniques/T1190/) | Exploit Public-Facing Application | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2022-22965](https://nvd.nist.gov/vuln/detail/CVE-2022-22965) | A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it. | 7.5 | - - - -
-
- -#### Search - -``` - -| tstats count from datamodel=Web where Web.http_method IN ("GET") Web.url IN ("*.jsp?cmd=*","*j&cmd=*") by Web.http_user_agent Web.http_method, Web.url,Web.url_length Web.src, Web.dest sourcetype -| `drop_dm_object_name("Web")` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `web_jsp_request_via_url_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **web_jsp_request_via_url_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Web.http_method -* Web.url -* Web.url_length -* Web.src -* Web.dest -* Web.http_user_agent - - -#### How To Implement -To successfully implement this search you need to be ingesting information on Web traffic that include fields relavent for traffic into the `Web` datamodel. - -#### Known False Positives -False positives may be present with legitimate applications. Attempt to filter by dest IP or use Asset groups to restrict to servers. - -#### Associated Analytic story -* [Spring4Shell CVE-2022-22965](/stories/spring4shell_cve-2022-22965) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 72.0 | 90 | 80 | A suspicious URL has been requested against $dest$ by $src$, related to web shell activity. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.microsoft.com/security/blog/2022/04/04/springshell-rce-vulnerability-guidance-for-protecting-against-and-detecting-cve-2022-22965/](https://www.microsoft.com/security/blog/2022/04/04/springshell-rce-vulnerability-guidance-for-protecting-against-and-detecting-cve-2022-22965/) -* [https://github.com/TheGejr/SpringShell](https://github.com/TheGejr/SpringShell) -* [https://www.tenable.com/blog/spring4shell-faq-spring-framework-remote-code-execution-vulnerability](https://www.tenable.com/blog/spring4shell-faq-spring-framework-remote-code-execution-vulnerability) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/spring4shell/spring4shell_nginx.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/spring4shell/spring4shell_nginx.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/web/web_jsp_request_via_url.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-04-05-web_spring_cloud_function_functionrouter.md b/docs/_posts/2022-04-05-web_spring_cloud_function_functionrouter.md deleted file mode 100644 index 135f9b4bd6..0000000000 --- a/docs/_posts/2022-04-05-web_spring_cloud_function_functionrouter.md +++ /dev/null @@ -1,169 +0,0 @@ ---- -title: "Web Spring Cloud Function FunctionRouter" -excerpt: "Exploit Public-Facing Application -" -categories: - - Web -last_modified_at: 2022-04-05 -toc: true -toc_label: "" -tags: - - Exploit Public-Facing Application - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2022-22963 - - Web ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies activity related to the web application Spring Cloud Function that was recently idenfied as vulnerable. This is CVE-2022-22963. Multiple proof of concept code was released. The URI that is hit includes `functionrouter`. The specifics of the exploit include a status of 500. In this query we did not include it, but for filtering you can add Web.status=500. The exploit data itself (based on all the POCs) is located in the form_data field. This field will include all class.modules being called. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Web](https://docs.splunk.com/Documentation/CIM/latest/User/Web) -- **Last Updated**: 2022-04-05 -- **Author**: Michael Haag, Splunk -- **ID**: 89dddbad-369a-4f8a-ace2-2439218735bc - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1190](https://attack.mitre.org/techniques/T1190/) | Exploit Public-Facing Application | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2022-22963](https://nvd.nist.gov/vuln/detail/CVE-2022-22963) | In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources. | 7.5 | - - - -
-
- -#### Search - -``` - -| tstats count from datamodel=Web where Web.http_method IN ("POST") Web.url="*/functionRouter*" by Web.http_user_agent Web.http_method, Web.url,Web.url_length Web.src, Web.dest Web.status sourcetype -| `drop_dm_object_name("Web")` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `web_spring_cloud_function_functionrouter_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **web_spring_cloud_function_functionrouter_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Web.http_method -* Web.url -* Web.url_length -* Web.src -* Web.dest -* Web.http_user_agent - - -#### How To Implement -To successfully implement this search you need to be ingesting information on Web traffic that include fields relavent for traffic into the `Web` datamodel. - -#### Known False Positives -False positives may be present with legitimate applications. Attempt to filter by dest IP or use Asset groups to restrict to servers. - -#### Associated Analytic story -* [Spring4Shell CVE-2022-22965](/stories/spring4shell_cve-2022-22965) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 42.0 | 70 | 60 | A suspicious URL has been requested against $dest$ by $src$, related to a vulnerability in Spring Cloud. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/rapid7/metasploit-framework/pull/16395](https://github.com/rapid7/metasploit-framework/pull/16395) -* [https://github.com/hktalent/spring-spel-0day-poc](https://github.com/hktalent/spring-spel-0day-poc) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/spring4shell/all_functionrouter_http_streams.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/spring4shell/all_functionrouter_http_streams.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/web/web_spring_cloud_function_functionrouter.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-04-05-windows_indirect_command_execution_via_forfiles.md b/docs/_posts/2022-04-05-windows_indirect_command_execution_via_forfiles.md deleted file mode 100644 index 0393e4c84c..0000000000 --- a/docs/_posts/2022-04-05-windows_indirect_command_execution_via_forfiles.md +++ /dev/null @@ -1,169 +0,0 @@ ---- -title: "Windows Indirect Command Execution Via forfiles" -excerpt: "Indirect Command Execution -" -categories: - - Endpoint -last_modified_at: 2022-04-05 -toc: true -toc_label: "" -tags: - - Indirect Command Execution - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-04-05 -- **Author**: Eric McGinnis, Splunk -- **ID**: 1fdf31c9-ff4d-4c48-b799-0e8666e08787 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1202](https://attack.mitre.org/techniques/T1202/) | Indirect Command Execution | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.AE - - - -
-
- -
- CIS20 - -
- -* CIS 8 -* CIS 10 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process="*forfiles* /c *" by Processes.dest Processes.user Processes.parent_process Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.process_path -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_indirect_command_execution_via_forfiles_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_indirect_command_execution_via_forfiles_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.dest -* Processes.user -* Processes.parent_process -* Processes.parent_process_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id -* Processes.process_path - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the full process path in the process field of CIM's Process data model. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where forfiles.exe may be used. - -#### Known False Positives -Some legacy applications may be run using pcalua.exe. Similarly, forfiles.exe may be used in legitimate batch scripts. Filter these results as needed. - -#### Associated Analytic story -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | The Program Compatability Assistant (pcalua.exe) launched the process $process_name$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://twitter.com/KyleHanslovan/status/912659279806640128](https://twitter.com/KyleHanslovan/status/912659279806640128) -* [https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/forfiles](https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/forfiles) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1202/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1202/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_indirect_command_execution_via_forfiles.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-04-05-windows_indirect_command_execution_via_pcalua.md b/docs/_posts/2022-04-05-windows_indirect_command_execution_via_pcalua.md deleted file mode 100644 index 89de9e7418..0000000000 --- a/docs/_posts/2022-04-05-windows_indirect_command_execution_via_pcalua.md +++ /dev/null @@ -1,169 +0,0 @@ ---- -title: "Windows Indirect Command Execution Via pcalua" -excerpt: "Indirect Command Execution -" -categories: - - Endpoint -last_modified_at: 2022-04-05 -toc: true -toc_label: "" -tags: - - Indirect Command Execution - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic detects programs that have been started by pcalua.exe. pcalua.exe is the Microsoft Windows Program Compatability Assistant. While this tool can be used to start legitimate programs, it has been observed being used to evade protections on command line execution. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-04-05 -- **Author**: Eric McGinnis, Splunk -- **ID**: 3428ac18-a410-4823-816c-ce697d26f7a8 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1202](https://attack.mitre.org/techniques/T1202/) | Indirect Command Execution | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.AE - - - -
-
- -
- CIS20 - -
- -* CIS 8 -* CIS 10 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process="*pcalua* -a*" by Processes.dest Processes.user Processes.parent_process Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.process_path -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_indirect_command_execution_via_pcalua_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_indirect_command_execution_via_pcalua_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.dest -* Processes.user -* Processes.parent_process -* Processes.parent_process_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id -* Processes.process_path - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the full process path in the process field of CIM's Process data model. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where pcalua.exe may be used. - -#### Known False Positives -Some legacy applications may be run using pcalua.exe. Filter these results as needed. - -#### Associated Analytic story -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | The Program Compatability Assistant (pcalua.exe) launched the process $process_name$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://twitter.com/KyleHanslovan/status/912659279806640128](https://twitter.com/KyleHanslovan/status/912659279806640128) -* [https://lolbas-project.github.io/lolbas/Binaries/Pcalua/](https://lolbas-project.github.io/lolbas/Binaries/Pcalua/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1202/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1202/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_indirect_command_execution_via_pcalua.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-04-06-web_spring4shell_http_request_class_module.md b/docs/_posts/2022-04-06-web_spring4shell_http_request_class_module.md deleted file mode 100644 index d73eeffe74..0000000000 --- a/docs/_posts/2022-04-06-web_spring4shell_http_request_class_module.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: "Web Spring4Shell HTTP Request Class Module" -excerpt: "Exploit Public-Facing Application -" -categories: - - Web -last_modified_at: 2022-04-06 -toc: true -toc_label: "" -tags: - - Exploit Public-Facing Application - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2022-22965 - - Web ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the payload related to Spring4Shell, CVE-2022-22965. This analytic uses Splunk Stream HTTP to view the http request body, form data. STRT reviewed all the current proof of concept code and determined the commonality with the payloads being passed used the same fields "class.module.classLoader.resources.context.parent.pipeline.first". - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Web](https://docs.splunk.com/Documentation/CIM/latest/User/Web) -- **Last Updated**: 2022-04-06 -- **Author**: Michael Haag, Splunk -- **ID**: fcdfd69d-0ca3-4476-920e-9b633cb4593e - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1190](https://attack.mitre.org/techniques/T1190/) | Exploit Public-Facing Application | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2022-22965](https://nvd.nist.gov/vuln/detail/CVE-2022-22965) | A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it. | 7.5 | - - - -
-
- -#### Search - -``` -`stream_http` http_method IN ("POST") -| stats values(form_data) as http_request_body min(_time) as firstTime max(_time) as lastTime count by http_method http_user_agent uri_path url bytes_in bytes_out -| search http_request_body IN ("*class.module.classLoader.resources.context.parent.pipeline.first.fileDateFormat=_*", "*class.module.classLoader.resources.context.parent.pipeline.first.pattern*","*suffix=.jsp*") -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `web_spring4shell_http_request_class_module_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [stream_http](https://github.com/splunk/security_content/blob/develop/macros/stream_http.yml) - -> :information_source: -> **web_spring4shell_http_request_class_module_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* http_request_body -* http_method -* http_user_agent -* uri_path -* url -* bytes_in -* bytes_out - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the stream HTTP logs or network logs that catch network traffic. Make sure that the http-request-body, payload, or request field is enabled. - -#### Known False Positives -False positives may occur and filtering may be required. Restrict analytic to asset type. - -#### Associated Analytic story -* [Spring4Shell CVE-2022-22965](/stories/spring4shell_cve-2022-22965) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 72.0 | 90 | 80 | A http body request related to Spring4Shell has been sent to $dest$ by $src$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/DDuarte/springshell-rce-poc/blob/master/poc.py](https://github.com/DDuarte/springshell-rce-poc/blob/master/poc.py) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/spring4shell/http_request_body_streams.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/spring4shell/http_request_body_streams.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/web/web_spring4shell_http_request_class_module.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-04-07-any_powershell_downloadfile.md b/docs/_posts/2022-04-07-any_powershell_downloadfile.md deleted file mode 100644 index e59a109794..0000000000 --- a/docs/_posts/2022-04-07-any_powershell_downloadfile.md +++ /dev/null @@ -1,185 +0,0 @@ ---- -title: "Any Powershell DownloadFile" -excerpt: "Command and Scripting Interpreter -, PowerShell -, Ingress Tool Transfer -" -categories: - - Endpoint -last_modified_at: 2022-04-07 -toc: true -toc_label: "" -tags: - - Command and Scripting Interpreter - - PowerShell - - Ingress Tool Transfer - - Execution - - Execution - - Command And Control - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2021-44228 - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the use of PowerShell downloading a file using `DownloadFile` method. This particular method is utilized in many different PowerShell frameworks to download files and output to disk. Identify the source (IP/domain) and destination file and triage appropriately. If AMSI logging or PowerShell transaction logs are available, review for further details of the implant. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-04-07 -- **Author**: Michael Haag, Splunk -- **ID**: 1a93b7ea-7af7-11eb-adb5-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -| [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | - -| [T1105](https://attack.mitre.org/techniques/T1105/) | Ingress Tool Transfer | Command And Control | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2021-44228](https://nvd.nist.gov/vuln/detail/CVE-2021-44228) | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects. | 9.3 | - - - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_powershell` Processes.process=*DownloadFile* by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `any_powershell_downloadfile_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml) - -> :information_source: -> **any_powershell_downloadfile_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -False positives may be present and filtering will need to occur by parent process or command line argument. It may be required to modify this query to an EDR product for more granular coverage. - -#### Associated Analytic story -* [Hermetic Wiper](/stories/hermetic_wiper) -* [Malicious PowerShell](/stories/malicious_powershell) -* [Ingress Tool Transfer](/stories/ingress_tool_transfer) -* [Log4Shell CVE-2021-44228](/stories/log4shell_cve-2021-44228) -* [DarkCrystal RAT](/stories/darkcrystal_rat) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 56.0 | 80 | 70 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$. This behavior identifies the use of DownloadFile within PowerShell. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://docs.microsoft.com/en-us/dotnet/api/system.net.webclient.downloadfile?view=net-5.0](https://docs.microsoft.com/en-us/dotnet/api/system.net.webclient.downloadfile?view=net-5.0) -* [https://blog.malwarebytes.com/malwarebytes-news/2021/02/lazyscripter-from-empire-to-double-rat/](https://blog.malwarebytes.com/malwarebytes-news/2021/02/lazyscripter-from-empire-to-double-rat/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1059.001/T1059.001.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1059.001/T1059.001.md) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/any_powershell_downloadfile.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2022-04-07-any_powershell_downloadstring.md b/docs/_posts/2022-04-07-any_powershell_downloadstring.md deleted file mode 100644 index 4ed02b76f5..0000000000 --- a/docs/_posts/2022-04-07-any_powershell_downloadstring.md +++ /dev/null @@ -1,179 +0,0 @@ ---- -title: "Any Powershell DownloadString" -excerpt: "Command and Scripting Interpreter -, PowerShell -, Ingress Tool Transfer -" -categories: - - Endpoint -last_modified_at: 2022-04-07 -toc: true -toc_label: "" -tags: - - Command and Scripting Interpreter - - PowerShell - - Ingress Tool Transfer - - Execution - - Execution - - Command And Control - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the use of PowerShell downloading a file using `DownloadString` method. This particular method is utilized in many different PowerShell frameworks to download files and output to disk. Identify the source (IP/domain) and destination file and triage appropriately. If AMSI logging or PowerShell transaction logs are available, review for further details of the implant. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-04-07 -- **Author**: Michael Haag, Splunk -- **ID**: 4d015ef2-7adf-11eb-95da-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -| [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | - -| [T1105](https://attack.mitre.org/techniques/T1105/) | Ingress Tool Transfer | Command And Control | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_powershell` Processes.process=*.DownloadString* by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `any_powershell_downloadstring_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml) - -> :information_source: -> **any_powershell_downloadstring_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -False positives may be present and filtering will need to occur by parent process or command line argument. It may be required to modify this query to an EDR product for more granular coverage. - -#### Associated Analytic story -* [Hermetic Wiper](/stories/hermetic_wiper) -* [Malicious PowerShell](/stories/malicious_powershell) -* [HAFNIUM Group](/stories/hafnium_group) -* [Ingress Tool Transfer](/stories/ingress_tool_transfer) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 56.0 | 80 | 70 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$. This behavior identifies the use of DownloadString within PowerShell. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://docs.microsoft.com/en-us/dotnet/api/system.net.webclient.downloadstring?view=net-5.0](https://docs.microsoft.com/en-us/dotnet/api/system.net.webclient.downloadstring?view=net-5.0) -* [https://blog.malwarebytes.com/malwarebytes-news/2021/02/lazyscripter-from-empire-to-double-rat/](https://blog.malwarebytes.com/malwarebytes-news/2021/02/lazyscripter-from-empire-to-double-rat/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1059.001/T1059.001.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1059.001/T1059.001.md) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/any_powershell_downloadstring.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2022-04-07-detect_html_help_renamed.md b/docs/_posts/2022-04-07-detect_html_help_renamed.md deleted file mode 100644 index 6acb966621..0000000000 --- a/docs/_posts/2022-04-07-detect_html_help_renamed.md +++ /dev/null @@ -1,176 +0,0 @@ ---- -title: "Detect HTML Help Renamed" -excerpt: "System Binary Proxy Execution -, Compiled HTML File -" -categories: - - Endpoint -last_modified_at: 2022-04-07 -toc: true -toc_label: "" -tags: - - System Binary Proxy Execution - - Compiled HTML File - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies a renamed instance of hh.exe (HTML Help) executing a Compiled HTML Help (CHM). This particular technique will load Windows script code from a compiled help file. CHM files may contain nearly any file type embedded, but only execute html/htm. Upon a successful execution, the following script engines may be used for execution - JScript, VBScript, VBScript.Encode, JScript.Encode, JScript.Compact. Analyst may identify vbscript.dll or jscript.dll loading into hh.exe upon execution. The "htm" and "html" file extensions were the only extensions observed to be supported for the execution of Shortcut commands or WSH script code. During investigation, identify script content origination. Validate it is the legitimate version of hh.exe by reviewing the PE metadata. hh.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-04-07 -- **Author**: Michael Haag, Splunk -- **ID**: 62fed254-513b-460e-953d-79771493a9f3 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218](https://attack.mitre.org/techniques/T1218/) | System Binary Proxy Execution | Defense Evasion | - -| [T1218.001](https://attack.mitre.org/techniques/T1218/001/) | Compiled HTML File | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name!=hh.exe AND Processes.original_file_name=HH.EXE by Processes.dest Processes.user Processes.parent_process_name Processes.original_file_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_html_help_renamed_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **detect_html_help_renamed_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Although unlikely a renamed instance of hh.exe will be used legitimately, filter as needed. - -#### Associated Analytic story -* [Suspicious Compiled HTML Activity](/stories/suspicious_compiled_html_activity) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | The following $process_name$ has been identified as renamed, spawning from $parent_process_name$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1218/001/](https://attack.mitre.org/techniques/T1218/001/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.001/T1218.001.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.001/T1218.001.md) -* [https://lolbas-project.github.io/lolbas/Binaries/Hh/](https://lolbas-project.github.io/lolbas/Binaries/Hh/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.001/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.001/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/detect_html_help_renamed.yml) \| *version*: **4** \ No newline at end of file diff --git a/docs/_posts/2022-04-07-detect_mshta_renamed.md b/docs/_posts/2022-04-07-detect_mshta_renamed.md deleted file mode 100644 index 6c7bb3deb7..0000000000 --- a/docs/_posts/2022-04-07-detect_mshta_renamed.md +++ /dev/null @@ -1,175 +0,0 @@ ---- -title: "Detect mshta renamed" -excerpt: "System Binary Proxy Execution -, Mshta -" -categories: - - Endpoint -last_modified_at: 2022-04-07 -toc: true -toc_label: "" -tags: - - System Binary Proxy Execution - - Mshta - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies renamed instances of mshta.exe executing. Mshta.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. This analytic utilizes the internal name of the PE to identify if is the legitimate mshta binary. Further analysis should be performed to review the executed content and validation it is the real mshta. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-04-07 -- **Author**: Michael Haag, Splunk -- **ID**: 8f45fcf0-5b68-11eb-ae93-0242ac130002 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218](https://attack.mitre.org/techniques/T1218/) | System Binary Proxy Execution | Defense Evasion | - -| [T1218.005](https://attack.mitre.org/techniques/T1218/005/) | Mshta | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name!=mshta.exe AND Processes.original_file_name=MSHTA.EXE by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.original_file_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_mshta_renamed_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **detect_mshta_renamed_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Although unlikely, some legitimate applications may use a moved copy of mshta.exe, but never renamed, triggering a false positive. - -#### Associated Analytic story -* [Suspicious MSHTA Activity](/stories/suspicious_mshta_activity) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | The following $process_name$ has been identified as renamed, spawning from $parent_process_name$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/redcanaryco/AtomicTestHarnesses](https://github.com/redcanaryco/AtomicTestHarnesses) -* [https://redcanary.com/blog/introducing-atomictestharnesses/](https://redcanary.com/blog/introducing-atomictestharnesses/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.005/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.005/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/detect_mshta_renamed.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2022-04-07-detect_renamed_psexec.md b/docs/_posts/2022-04-07-detect_renamed_psexec.md deleted file mode 100644 index db349684ac..0000000000 --- a/docs/_posts/2022-04-07-detect_renamed_psexec.md +++ /dev/null @@ -1,173 +0,0 @@ ---- -title: "Detect Renamed PSExec" -excerpt: "System Services -, Service Execution -" -categories: - - Endpoint -last_modified_at: 2022-04-07 -toc: true -toc_label: "" -tags: - - System Services - - Service Execution - - Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies renamed instances of `PsExec.exe` being utilized on an endpoint. Most instances, it is highly probable to capture `Psexec.exe` or other SysInternal utility usage with the command-line argument of `-accepteula`. During triage, validate this is the legitimate version of `PsExec` by reviewing the PE metadata. In addition, review parallel processes for further suspicious behavior. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-04-07 -- **Author**: Michael Haag, Splunk -- **ID**: 683e6196-b8e8-11eb-9a79-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1569](https://attack.mitre.org/techniques/T1569/) | System Services | Execution | - -| [T1569.002](https://attack.mitre.org/techniques/T1569/002/) | Service Execution | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name!=psexec.exe OR Processes.process_name!=psexec64.exe) AND Processes.original_file_name=psexec.c by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.original_file_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_renamed_psexec_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **detect_renamed_psexec_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Limited false positives should be present. It is possible some third party applications may use older versions of PsExec, filter as needed. - -#### Associated Analytic story -* [SamSam Ransomware](/stories/samsam_ransomware) -* [DHS Report TA18-074A](/stories/dhs_report_ta18-074a) -* [HAFNIUM Group](/stories/hafnium_group) -* [DarkSide Ransomware](/stories/darkside_ransomware) -* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 27.0 | 30 | 90 | The following $process_name$ has been identified as renamed, spawning from $parent_process_name$ on $dest$ by $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1569.002/T1569.002.yaml](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1569.002/T1569.002.yaml) -* [https://redcanary.com/blog/threat-hunting-psexec-lateral-movement/](https://redcanary.com/blog/threat-hunting-psexec-lateral-movement/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1569.002/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1569.002/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/detect_renamed_psexec.yml) \| *version*: **4** \ No newline at end of file diff --git a/docs/_posts/2022-04-07-suspicious_microsoft_workflow_compiler_rename.md b/docs/_posts/2022-04-07-suspicious_microsoft_workflow_compiler_rename.md deleted file mode 100644 index 8a944454e2..0000000000 --- a/docs/_posts/2022-04-07-suspicious_microsoft_workflow_compiler_rename.md +++ /dev/null @@ -1,182 +0,0 @@ ---- -title: "Suspicious microsoft workflow compiler rename" -excerpt: "Masquerading -, Trusted Developer Utilities Proxy Execution -, Rename System Utilities -" -categories: - - Endpoint -last_modified_at: 2022-04-07 -toc: true -toc_label: "" -tags: - - Masquerading - - Trusted Developer Utilities Proxy Execution - - Rename System Utilities - - Defense Evasion - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies a renamed instance of microsoft.workflow.compiler.exe. Microsoft.workflow.compiler.exe is natively found in C:\Windows\Microsoft.NET\Framework64\v4.0.30319 and is rarely utilized. When investigating, identify the executed code on disk and review. A spawned child process from microsoft.workflow.compiler.exe is uncommon. In any instance, microsoft.workflow.compiler.exe spawning from an Office product or any living off the land binary is highly suspect. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-04-07 -- **Author**: Michael Haag, Splunk -- **ID**: f0db4464-55d9-11eb-ae93-0242ac130002 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1036](https://attack.mitre.org/techniques/T1036/) | Masquerading | Defense Evasion | - -| [T1127](https://attack.mitre.org/techniques/T1127/) | Trusted Developer Utilities Proxy Execution | Defense Evasion | - -| [T1036.003](https://attack.mitre.org/techniques/T1036/003/) | Rename System Utilities | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name!=microsoft.workflow.compiler.exe AND Processes.original_file_name=Microsoft.Workflow.Compiler.exe by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.original_file_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `suspicious_microsoft_workflow_compiler_rename_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **suspicious_microsoft_workflow_compiler_rename_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Although unlikely, some legitimate applications may use a moved copy of microsoft.workflow.compiler.exe, triggering a false positive. - -#### Associated Analytic story -* [Trusted Developer Utilities Proxy Execution](/stories/trusted_developer_utilities_proxy_execution) -* [Cobalt Strike](/stories/cobalt_strike) -* [Masquerading - Rename System Utilities](/stories/masquerading_-_rename_system_utilities) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 63.0 | 70 | 90 | Suspicious renamed microsoft.workflow.compiler.exe binary ran on $dest$ by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://lolbas-project.github.io/lolbas/Binaries/Microsoft.Workflow.Compiler/](https://lolbas-project.github.io/lolbas/Binaries/Microsoft.Workflow.Compiler/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218/T1218.md#atomic-test-6---microsoftworkflowcompilerexe-payload-execution](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218/T1218.md#atomic-test-6---microsoftworkflowcompilerexe-payload-execution) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml) \| *version*: **4** \ No newline at end of file diff --git a/docs/_posts/2022-04-07-suspicious_msbuild_rename.md b/docs/_posts/2022-04-07-suspicious_msbuild_rename.md deleted file mode 100644 index c2a68c2137..0000000000 --- a/docs/_posts/2022-04-07-suspicious_msbuild_rename.md +++ /dev/null @@ -1,188 +0,0 @@ ---- -title: "Suspicious MSBuild Rename" -excerpt: "Masquerading -, Trusted Developer Utilities Proxy Execution -, Rename System Utilities -, MSBuild -" -categories: - - Endpoint -last_modified_at: 2022-04-07 -toc: true -toc_label: "" -tags: - - Masquerading - - Trusted Developer Utilities Proxy Execution - - Rename System Utilities - - MSBuild - - Defense Evasion - - Defense Evasion - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies renamed instances of msbuild.exe executing. Msbuild.exe is natively found in C:\Windows\Microsoft.NET\Framework\v4.0.30319 and C:\Windows\Microsoft.NET\Framework64\v4.0.30319. During investigation, identify the code executed and what is executing a renamed instance of MSBuild. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-04-07 -- **Author**: Michael Haag, Splunk -- **ID**: 4006adac-5937-11eb-ae93-0242ac130002 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1036](https://attack.mitre.org/techniques/T1036/) | Masquerading | Defense Evasion | - -| [T1127](https://attack.mitre.org/techniques/T1127/) | Trusted Developer Utilities Proxy Execution | Defense Evasion | - -| [T1036.003](https://attack.mitre.org/techniques/T1036/003/) | Rename System Utilities | Defense Evasion | - -| [T1127.001](https://attack.mitre.org/techniques/T1127/001/) | MSBuild | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name!=msbuild.exe AND Processes.original_file_name=MSBuild.exe by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.original_file_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `suspicious_msbuild_rename_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **suspicious_msbuild_rename_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Although unlikely, some legitimate applications may use a moved copy of msbuild, triggering a false positive. - -#### Associated Analytic story -* [Trusted Developer Utilities Proxy Execution MSBuild](/stories/trusted_developer_utilities_proxy_execution_msbuild) -* [Cobalt Strike](/stories/cobalt_strike) -* [Masquerading - Rename System Utilities](/stories/masquerading_-_rename_system_utilities) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 63.0 | 70 | 90 | Suspicious renamed msbuild.exe binary ran on $dest$ by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://lolbas-project.github.io/lolbas/Binaries/Msbuild/](https://lolbas-project.github.io/lolbas/Binaries/Msbuild/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1127.001/T1127.001.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1127.001/T1127.001.md) -* [https://github.com/infosecn1nja/MaliciousMacroMSBuild/](https://github.com/infosecn1nja/MaliciousMacroMSBuild/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127.001/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127.001/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/suspicious_msbuild_rename.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2022-04-07-suspicious_rundll32_rename.md b/docs/_posts/2022-04-07-suspicious_rundll32_rename.md deleted file mode 100644 index 27def35b42..0000000000 --- a/docs/_posts/2022-04-07-suspicious_rundll32_rename.md +++ /dev/null @@ -1,186 +0,0 @@ ---- -title: "Suspicious Rundll32 Rename" -excerpt: "System Binary Proxy Execution -, Masquerading -, Rundll32 -, Rename System Utilities -" -categories: - - Deprecated -last_modified_at: 2022-04-07 -toc: true -toc_label: "" -tags: - - System Binary Proxy Execution - - Masquerading - - Rundll32 - - Rename System Utilities - - Defense Evasion - - Defense Evasion - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following hunting analytic identifies renamed instances of rundll32.exe executing. rundll32.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. During investigation, validate it is the legitimate rundll32.exe executing and what script content it is loading. This query relies on the original filename or internal name from the PE meta data. Expand the query as needed by looking for specific command line arguments outlined in other analytics. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-04-07 -- **Author**: Michael Haag, Splunk -- **ID**: 7360137f-abad-473e-8189-acbdaa34d114 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218](https://attack.mitre.org/techniques/T1218/) | System Binary Proxy Execution | Defense Evasion | - -| [T1036](https://attack.mitre.org/techniques/T1036/) | Masquerading | Defense Evasion | - -| [T1218.011](https://attack.mitre.org/techniques/T1218/011/) | Rundll32 | Defense Evasion | - -| [T1036.003](https://attack.mitre.org/techniques/T1036/003/) | Rename System Utilities | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.original_file_name=RUNDLL32.exe AND Processes.process_name!=rundll32.exe by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.original_file_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `suspicious_rundll32_rename_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **suspicious_rundll32_rename_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Although unlikely, some legitimate applications may use a moved copy of rundll32, triggering a false positive. - -#### Associated Analytic story -* [Suspicious Rundll32 Activity](/stories/suspicious_rundll32_activity) -* [Masquerading - Rename System Utilities](/stories/masquerading_-_rename_system_utilities) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 63.0 | 70 | 90 | Suspicious renamed rundll32.exe binary ran on $dest$ by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1218/011/](https://attack.mitre.org/techniques/T1218/011/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.011/T1218.011.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.011/T1218.011.md) -* [https://lolbas-project.github.io/lolbas/Binaries/Rundll32/](https://lolbas-project.github.io/lolbas/Binaries/Rundll32/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.011/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.011/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/deprecated/suspicious_rundll32_rename.yml) \| *version*: **5** \ No newline at end of file diff --git a/docs/_posts/2022-04-12-linux_account_manipulation_of_ssh_config_and_keys.md b/docs/_posts/2022-04-12-linux_account_manipulation_of_ssh_config_and_keys.md deleted file mode 100644 index a74fe596ec..0000000000 --- a/docs/_posts/2022-04-12-linux_account_manipulation_of_ssh_config_and_keys.md +++ /dev/null @@ -1,187 +0,0 @@ ---- -title: "Linux Account Manipulation Of SSH Config and Keys" -excerpt: "Data Destruction -, File Deletion -, Indicator Removal on Host -" -categories: - - Endpoint -last_modified_at: 2022-04-12 -toc: true -toc_label: "" -tags: - - Data Destruction - - File Deletion - - Indicator Removal on Host - - Impact - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to detect a deletion of ssh key in a linux machine. attacker may delete or modify ssh key to impair some security features or act as defense evasion in compromised linux machine. This Anomaly can be also a good indicator of a malware trying to wipe or delete several files in a compromised host as part of its destructive payload like what acidrain malware does in linux or router machines. This detection can be a good pivot to check what process and user tries to delete this type of files which is not so common and need further investigation. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-04-12 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 73a56508-1cf5-4df7-b8d9-5737fbdc27d2 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1485](https://attack.mitre.org/techniques/T1485/) | Data Destruction | Impact | - -| [T1070.004](https://attack.mitre.org/techniques/T1070/004/) | File Deletion | Defense Evasion | - -| [T1070](https://attack.mitre.org/techniques/T1070/) | Indicator Removal on Host | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.action=deleted AND Filesystem.file_path IN ("/etc/ssh/*", "~/.ssh/*") by _time span=1h Filesystem.file_name Filesystem.file_path Filesystem.dest Filesystem.process_guid Filesystem.action -| `drop_dm_object_name(Filesystem)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.parent_process_name != unknown by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_path Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name action] -| table process_name process proc_guid file_name file_path action _time parent_process_name parent_process process_path dest user -| `linux_account_manipulation_of_ssh_config_and_keys_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **linux_account_manipulation_of_ssh_config_and_keys_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Filesystem.dest -* Filesystem.file_create_time -* Filesystem.file_name -* Filesystem.process_guid -* Filesystem.file_path -* Filesystem.action -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.process_name -* Processes.process_path -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase. - -#### Known False Positives -Administrator or network operator can execute this command. Please update the filter macros to remove false positives. - -#### Associated Analytic story -* [Acidrain](/stories/acidrain) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | a $process_name$ deleting a SSH key in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.sentinelone.com/labs/acidrain-a-modem-wiper-rains-down-on-europe/](https://www.sentinelone.com/labs/acidrain-a-modem-wiper-rains-down-on-europe/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/acidrain/sysmon_linux.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/acidrain/sysmon_linux.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_account_manipulation_of_ssh_config_and_keys.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-04-12-linux_deletion_of_cron_jobs.md b/docs/_posts/2022-04-12-linux_deletion_of_cron_jobs.md deleted file mode 100644 index 435922fa30..0000000000 --- a/docs/_posts/2022-04-12-linux_deletion_of_cron_jobs.md +++ /dev/null @@ -1,187 +0,0 @@ ---- -title: "Linux Deletion Of Cron Jobs" -excerpt: "Data Destruction -, File Deletion -, Indicator Removal on Host -" -categories: - - Endpoint -last_modified_at: 2022-04-12 -toc: true -toc_label: "" -tags: - - Data Destruction - - File Deletion - - Indicator Removal on Host - - Impact - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to detect a deletion of cron job in a linux machine. This technique can be related to an attacker, threat actor or malware to disable scheduled cron jobs that might be related to security or to evade some detections. We also saw that this technique can be a good indicator for malware that is trying to wipe or delete several files on the compromised host like the acidrain malware. This anomaly detection can be a good pivot detection to look for process and user doing it why they doing. Take note that this event can be done by administrator so filtering on those possible false positive event is needed. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-04-12 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 3b132a71-9335-4f33-9932-00bb4f6ac7e8 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1485](https://attack.mitre.org/techniques/T1485/) | Data Destruction | Impact | - -| [T1070.004](https://attack.mitre.org/techniques/T1070/004/) | File Deletion | Defense Evasion | - -| [T1070](https://attack.mitre.org/techniques/T1070/) | Indicator Removal on Host | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.action=deleted Filesystem.file_path ="/etc/cron.*" by _time span=1h Filesystem.file_name Filesystem.file_path Filesystem.dest Filesystem.process_guid Filesystem.action -| `drop_dm_object_name(Filesystem)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.parent_process_name != unknown by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_path Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name action] -| table process_name process proc_guid file_name file_path action _time parent_process_name parent_process process_path dest user -| `linux_deletion_of_cron_jobs_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **linux_deletion_of_cron_jobs_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Filesystem.dest -* Filesystem.file_create_time -* Filesystem.file_name -* Filesystem.process_guid -* Filesystem.file_path -* Filesystem.action -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.process_name -* Processes.process_path -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase. - -#### Known False Positives -Administrator or network operator can execute this command. Please update the filter macros to remove false positives. - -#### Associated Analytic story -* [AcidRain](/stories/acidrain) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | a $process_name$ deleting cron jobs in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.sentinelone.com/labs/acidrain-a-modem-wiper-rains-down-on-europe/](https://www.sentinelone.com/labs/acidrain-a-modem-wiper-rains-down-on-europe/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/acidrain/sysmon_linux.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/acidrain/sysmon_linux.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_deletion_of_cron_jobs.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-04-12-linux_deletion_of_init_daemon_script.md b/docs/_posts/2022-04-12-linux_deletion_of_init_daemon_script.md deleted file mode 100644 index 960ecca8e6..0000000000 --- a/docs/_posts/2022-04-12-linux_deletion_of_init_daemon_script.md +++ /dev/null @@ -1,187 +0,0 @@ ---- -title: "Linux Deletion Of Init Daemon Script" -excerpt: "Data Destruction -, File Deletion -, Indicator Removal on Host -" -categories: - - Endpoint -last_modified_at: 2022-04-12 -toc: true -toc_label: "" -tags: - - Data Destruction - - File Deletion - - Indicator Removal on Host - - Impact - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to detect a deletion of init daemon script in a linux machine. daemon script that place in /etc/init.d/ is a directory that can start and stop some daemon services in linux machines. attacker may delete or modify daemon script to impair some security features or act as defense evasion in a compromised linux machine. This TTP can be also a good indicator of a malware trying to wipe or delete several files in compromised host as part of its destructive payload like what acidrain malware does in linux or router machines. This detection can be a good pivot to check what process and user tries to delete this type of files which is not so common and need further investigation. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-04-12 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 729aab57-d26f-4156-b97f-ab8dda8f44b1 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1485](https://attack.mitre.org/techniques/T1485/) | Data Destruction | Impact | - -| [T1070.004](https://attack.mitre.org/techniques/T1070/004/) | File Deletion | Defense Evasion | - -| [T1070](https://attack.mitre.org/techniques/T1070/) | Indicator Removal on Host | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.action=deleted Filesystem.file_path IN ( "/etc/init.d/*") by _time span=1h Filesystem.file_name Filesystem.file_path Filesystem.dest Filesystem.process_guid Filesystem.action -| `drop_dm_object_name(Filesystem)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.parent_process_name != unknown by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_path Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name action] -| table process_name process proc_guid file_name file_path action _time parent_process_name parent_process process_path dest user -| `linux_deletion_of_init_daemon_script_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **linux_deletion_of_init_daemon_script_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Filesystem.dest -* Filesystem.file_create_time -* Filesystem.file_name -* Filesystem.process_guid -* Filesystem.file_path -* Filesystem.action -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.process_name -* Processes.process_path -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase. - -#### Known False Positives -Administrator or network operator can execute this command. Please update the filter macros to remove false positives. - -#### Associated Analytic story -* [AcidRain](/stories/acidrain) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | a $process_name$ deleting a daemon script in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.sentinelone.com/labs/acidrain-a-modem-wiper-rains-down-on-europe/](https://www.sentinelone.com/labs/acidrain-a-modem-wiper-rains-down-on-europe/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/acidrain/sysmon_linux.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/acidrain/sysmon_linux.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_deletion_of_init_daemon_script.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-04-12-linux_deletion_of_services.md b/docs/_posts/2022-04-12-linux_deletion_of_services.md deleted file mode 100644 index 5c373fb15e..0000000000 --- a/docs/_posts/2022-04-12-linux_deletion_of_services.md +++ /dev/null @@ -1,187 +0,0 @@ ---- -title: "Linux Deletion Of Services" -excerpt: "Data Destruction -, File Deletion -, Indicator Removal on Host -" -categories: - - Endpoint -last_modified_at: 2022-04-12 -toc: true -toc_label: "" -tags: - - Data Destruction - - File Deletion - - Indicator Removal on Host - - Impact - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to detect a deletion of services in a linux machine. attacker may delete or modify services to impair some security features or act as defense evasion in a compromised linux machine. This TTP can be also a good indicator of a malware trying to wipe or delete several files in a compromised host as part of its destructive payload like what acidrain malware does in linux or router machines. This detection can be a good pivot to check what process and user tries to delete this type of files which is not so common and need further investigation. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-04-12 -- **Author**: Teoderick Contreras, Splunk -- **ID**: b509bbd3-0331-4aaa-8e4a-d2affe100af6 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1485](https://attack.mitre.org/techniques/T1485/) | Data Destruction | Impact | - -| [T1070.004](https://attack.mitre.org/techniques/T1070/004/) | File Deletion | Defense Evasion | - -| [T1070](https://attack.mitre.org/techniques/T1070/) | Indicator Removal on Host | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.action=deleted Filesystem.file_path IN ( "/etc/systemd/*", "/usr/lib/systemd/*") Filesystem.file_path = "*.service" by _time span=1h Filesystem.file_name Filesystem.file_path Filesystem.dest Filesystem.process_guid Filesystem.action -| `drop_dm_object_name(Filesystem)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.parent_process_name != unknown by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_path Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name action] -| table process_name process proc_guid file_name file_path action _time parent_process_name parent_process process_path dest user -| `linux_deletion_of_services_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **linux_deletion_of_services_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Filesystem.dest -* Filesystem.file_create_time -* Filesystem.file_name -* Filesystem.process_guid -* Filesystem.file_path -* Filesystem.action -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.process_name -* Processes.process_path -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase. - -#### Known False Positives -Administrator or network operator can execute this command. Please update the filter macros to remove false positives. - -#### Associated Analytic story -* [AcidRain](/stories/acidrain) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 64.0 | 80 | 80 | a $process_name$ deleting a services in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.sentinelone.com/labs/acidrain-a-modem-wiper-rains-down-on-europe/](https://www.sentinelone.com/labs/acidrain-a-modem-wiper-rains-down-on-europe/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/acidrain/sysmon_linux.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/acidrain/sysmon_linux.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_deletion_of_services.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-04-12-linux_deletion_of_ssh_hash_conf.md b/docs/_posts/2022-04-12-linux_deletion_of_ssh_hash_conf.md deleted file mode 100644 index bb633b1096..0000000000 --- a/docs/_posts/2022-04-12-linux_deletion_of_ssh_hash_conf.md +++ /dev/null @@ -1,183 +0,0 @@ ---- -title: "Linux deletion Of SSH Hash Conf" -excerpt: "Data Destruction -, File Deletion -, Indicator Removal on Host -" -categories: - - Endpoint -last_modified_at: 2022-04-12 -toc: true -toc_label: "" -tags: - - Data Destruction - - File Deletion - - Indicator Removal on Host - - Impact - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to detect a deletion of ssh key in a linux machine. attacker may delete or modify ssh key to impair some security features or act as defense evasion in compromised linux machine. This Anomaly can be also a good indicator of a malware trying to wipe or delete several files in a compromised host as part of its destructive payload like what acidrain malware does in linux or router machines. This detection can be a good pivot to check what process and user tries to delete this type of files which is not so common and need further investigation. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-04-12 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 73a56508-1cf5-4df7-b8d9-5737fbdc27d2 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1485](https://attack.mitre.org/techniques/T1485/) | Data Destruction | Impact | - -| [T1070.004](https://attack.mitre.org/techniques/T1070/004/) | File Deletion | Defense Evasion | - -| [T1070](https://attack.mitre.org/techniques/T1070/) | Indicator Removal on Host | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.action=deleted AND Filesystem.file_path IN ("/etc/ssh/*", "~/.ssh/*") by _time span=1h Filesystem.file_name Filesystem.file_path Filesystem.dest Filesystem.process_guid Filesystem.action -| `drop_dm_object_name(Filesystem)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.parent_process_name != unknown by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_path Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name action] -| table process_name process proc_guid file_name file_path action _time parent_process_name parent_process process_path dest user -| `linux_deletion_of_ssh_hash_conf_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -Note that **linux_deletion_of_ssh_hash_conf_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Filesystem.dest -* Filesystem.file_create_time -* Filesystem.file_name -* Filesystem.process_guid -* Filesystem.file_path -* Filesystem.action -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.process_name -* Processes.process_path -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase. - -#### Known False Positives -Administrator or network operator can execute this command. Please update the filter macros to remove false positives. - -#### Associated Analytic story -* [Acidrain](/stories/acidrain) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | a $process_name$ deleting a SSH key in $dest$ | - - -#### Reference - -* [https://www.sentinelone.com/labs/acidrain-a-modem-wiper-rains-down-on-europe/](https://www.sentinelone.com/labs/acidrain-a-modem-wiper-rains-down-on-europe/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/acidrain/sysmon_linux.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/acidrain/sysmon_linux.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_deletion_of_ssh_hash_conf.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-04-12-linux_deletion_of_ssh_key.md b/docs/_posts/2022-04-12-linux_deletion_of_ssh_key.md deleted file mode 100644 index 066be2bc3a..0000000000 --- a/docs/_posts/2022-04-12-linux_deletion_of_ssh_key.md +++ /dev/null @@ -1,183 +0,0 @@ ---- -title: "Linux deletion Of SSH Key" -excerpt: "Data Destruction -, File Deletion -, Indicator Removal on Host -" -categories: - - Endpoint -last_modified_at: 2022-04-12 -toc: true -toc_label: "" -tags: - - Data Destruction - - File Deletion - - Indicator Removal on Host - - Impact - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to detect a deletion of ssh key in a linux machine. attacker may delete or modify ssh key to impair some security features or act as defense evasion in compromised linux machine. This Anomaly can be also a good indicator of a malware trying to wipe or delete several files in a compromised host as part of its destructive payload like what acidrain malware does in linux or router machines. This detection can be a good pivot to check what process and user tries to delete this type of files which is not so common and need further investigation. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-04-12 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 73a56508-1cf5-4df7-b8d9-5737fbdc27d2 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1485](https://attack.mitre.org/techniques/T1485/) | Data Destruction | Impact | - -| [T1070.004](https://attack.mitre.org/techniques/T1070/004/) | File Deletion | Defense Evasion | - -| [T1070](https://attack.mitre.org/techniques/T1070/) | Indicator Removal on Host | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.action=deleted Filesystem.file_path = "/etc/ssh/*" by _time span=1h Filesystem.file_name Filesystem.file_path Filesystem.dest Filesystem.process_guid Filesystem.action -| `drop_dm_object_name(Filesystem)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.parent_process_name != unknown by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_path Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name action] -| table process_name process proc_guid file_name file_path action _time parent_process_name parent_process process_path dest user -| `linux_deletion_of_ssh_key_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -Note that **linux_deletion_of_ssh_key_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Filesystem.dest -* Filesystem.file_create_time -* Filesystem.file_name -* Filesystem.process_guid -* Filesystem.file_path -* Filesystem.action -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.process_name -* Processes.process_path -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase. - -#### Known False Positives -Administrator or network operator can execute this command. Please update the filter macros to remove false positives. - -#### Associated Analytic story -* [Acidrain](/stories/acidrain) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | a $process_name$ deleting a SSH key in $dest$ | - - -#### Reference - -* [https://www.sentinelone.com/labs/acidrain-a-modem-wiper-rains-down-on-europe/](https://www.sentinelone.com/labs/acidrain-a-modem-wiper-rains-down-on-europe/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/acidrain/sysmon_linux.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/acidrain/sysmon_linux.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_deletion_of_ssh_key.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-04-12-linux_deletion_of_ssl_certificate.md b/docs/_posts/2022-04-12-linux_deletion_of_ssl_certificate.md deleted file mode 100644 index 21c0aef1d0..0000000000 --- a/docs/_posts/2022-04-12-linux_deletion_of_ssl_certificate.md +++ /dev/null @@ -1,187 +0,0 @@ ---- -title: "Linux Deletion of SSL Certificate" -excerpt: "Data Destruction -, File Deletion -, Indicator Removal on Host -" -categories: - - Endpoint -last_modified_at: 2022-04-12 -toc: true -toc_label: "" -tags: - - Data Destruction - - File Deletion - - Indicator Removal on Host - - Impact - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to detect a deletion of ssl certificate in a linux machine. attacker may delete or modify ssl certificate to impair some security features or act as defense evasion in compromised linux machine. This Anomaly can be also a good indicator of a malware trying to wipe or delete several files in a compromised host as part of its destructive payload like what acidrain malware does in linux or router machines. This detection can be a good pivot to check what process and user tries to delete this type of files which is not so common and need further investigation. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-04-12 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 839ab790-a60a-4f81-bfb3-02567063f615 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1485](https://attack.mitre.org/techniques/T1485/) | Data Destruction | Impact | - -| [T1070.004](https://attack.mitre.org/techniques/T1070/004/) | File Deletion | Defense Evasion | - -| [T1070](https://attack.mitre.org/techniques/T1070/) | Indicator Removal on Host | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.action=deleted Filesystem.file_path = "/etc/ssl/certs/*" Filesystem.file_path IN ("*.pem", "*.crt") by _time span=1h Filesystem.file_name Filesystem.file_path Filesystem.dest Filesystem.process_guid Filesystem.action -| `drop_dm_object_name(Filesystem)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.parent_process_name != unknown by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_path Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name action] -| table process_name process proc_guid file_name file_path action _time parent_process_name parent_process process_path dest user -| `linux_deletion_of_ssl_certificate_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **linux_deletion_of_ssl_certificate_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Filesystem.dest -* Filesystem.file_create_time -* Filesystem.file_name -* Filesystem.process_guid -* Filesystem.file_path -* Filesystem.action -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.process_name -* Processes.process_path -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase. - -#### Known False Positives -Administrator or network operator can execute this command. Please update the filter macros to remove false positives. - -#### Associated Analytic story -* [Acidrain](/stories/acidrain) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | a $process_name$ deleting a SSL certificate in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.sentinelone.com/labs/acidrain-a-modem-wiper-rains-down-on-europe/](https://www.sentinelone.com/labs/acidrain-a-modem-wiper-rains-down-on-europe/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/acidrain/sysmon_linux.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/acidrain/sysmon_linux.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_deletion_of_ssl_certificate.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-04-12-linux_high_frequency_of_file_deletion_in_etc_folder.md b/docs/_posts/2022-04-12-linux_high_frequency_of_file_deletion_in_etc_folder.md deleted file mode 100644 index a8eafe5afc..0000000000 --- a/docs/_posts/2022-04-12-linux_high_frequency_of_file_deletion_in_etc_folder.md +++ /dev/null @@ -1,188 +0,0 @@ ---- -title: "Linux High Frequency Of File Deletion In Etc Folder" -excerpt: "Data Destruction -, File Deletion -, Indicator Removal on Host -" -categories: - - Endpoint -last_modified_at: 2022-04-12 -toc: true -toc_label: "" -tags: - - Data Destruction - - File Deletion - - Indicator Removal on Host - - Impact - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to detect a high frequency of file deletion relative to process name and process id /etc/ folder. These events was seen in acidrain wiper malware where it tries to delete all files in a non-standard directory in linux directory. This detection already contains some filter that might cause false positive during our testing. But we recommend to add more filter if needed. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-04-12 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 9d867448-2aff-4d07-876c-89409a752ff8 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1485](https://attack.mitre.org/techniques/T1485/) | Data Destruction | Impact | - -| [T1070.004](https://attack.mitre.org/techniques/T1070/004/) | File Deletion | Defense Evasion | - -| [T1070](https://attack.mitre.org/techniques/T1070/) | Indicator Removal on Host | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` values(Filesystem.file_name) as deletedFileNames values(Filesystem.file_path) as deletedFilePath dc(Filesystem.file_path) as numOfDelFilePath count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.action=deleted Filesystem.file_path = "/etc/*" by _time span=1h Filesystem.dest Filesystem.process_guid Filesystem.action -| `drop_dm_object_name(Filesystem)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.parent_process_name != unknown NOT (Processes.parent_process_name IN ("/usr/bin/dpkg", "*usr/bin/python*", "*/usr/bin/apt-*", "/bin/rm", "*splunkd", "/usr/bin/mandb")) by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_path Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name action] -| table process_name process proc_guid action _time deletedFileNames deletedFilePath numOfDelFilePath parent_process_name parent_process process_path dest user -| where numOfDelFilePath >= 200 -| `linux_high_frequency_of_file_deletion_in_etc_folder_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **linux_high_frequency_of_file_deletion_in_etc_folder_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Filesystem.dest -* Filesystem.file_create_time -* Filesystem.file_name -* Filesystem.process_guid -* Filesystem.file_path -* Filesystem.action -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.process_name -* Processes.process_path -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase. - -#### Known False Positives -linux package installer/uninstaller may cause this event. Please update you filter macro to remove false positives. - -#### Associated Analytic story -* [AcidRain](/stories/acidrain) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | a $process_name$ deleting multiple files in /etc/ folder in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.sentinelone.com/labs/acidrain-a-modem-wiper-rains-down-on-europe/](https://www.sentinelone.com/labs/acidrain-a-modem-wiper-rains-down-on-europe/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/acidrain/sysmon_linux.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/acidrain/sysmon_linux.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_high_frequency_of_file_deletion_in_etc_folder.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-04-13-windows_registry_delete_task_sd.md b/docs/_posts/2022-04-13-windows_registry_delete_task_sd.md deleted file mode 100644 index 12f96affcf..0000000000 --- a/docs/_posts/2022-04-13-windows_registry_delete_task_sd.md +++ /dev/null @@ -1,177 +0,0 @@ ---- -title: "Windows Registry Delete Task SD" -excerpt: "Scheduled Task -, Impair Defenses -" -categories: - - Endpoint -last_modified_at: 2022-04-13 -toc: true -toc_label: "" -tags: - - Scheduled Task - - Impair Defenses - - Execution - - Persistence - - Privilege Escalation - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies a process attempting to delete a scheduled task SD (Security Descriptor) from within the registry path of that task. This may occur from a non-standard process running and may not come from reg.exe. This particular behavior will remove the actual Task Name from the Task Scheduler GUI and from the command-line query - schtasks.exe /query. In addition, in order to perform this action, the user context will need to be SYSTEM. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-04-13 -- **Author**: Michael Haag, Splunk -- **ID**: ffeb7893-ff06-446f-815b-33ca73224e92 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1053.005](https://attack.mitre.org/techniques/T1053/005/) | Scheduled Task | Execution, Persistence, Privilege Escalation | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Installation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path IN ("*\\Schedule\\TaskCache\\Tree\\*") Registry.user="SYSTEM" Registry.registry_value_name="SD" (Registry.action=Deleted OR Registry.action=modified) by _time Registry.dest Registry.process_guid Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_key_name Registry.registry_value_data Registry.status Registry.action -| `drop_dm_object_name(Registry)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_registry_delete_task_sd_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_registry_delete_task_sd_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.registry_path -* Registry.registry_key_name -* Registry.registry_value_name -* Registry.dest -* Processes.process_id -* Processes.process_name -* Processes.process -* Processes.dest -* Processes.process_guid - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -False positives should be limited as the activity is not common to delete ONLY the SD from the registry. Filter as needed. Update the analytic Modified or Deleted values based on product that is in the datamodel. - -#### Associated Analytic story -* [Windows Registry Abuse](/stories/windows_registry_abuse) -* [Windows Persistence Techniques](/stories/windows_persistence_techniques) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | A scheduled task security descriptor was deleted from the registry on $dest$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.microsoft.com/security/blog/2022/04/12/tarrask-malware-uses-scheduled-tasks-for-defense-evasion/](https://www.microsoft.com/security/blog/2022/04/12/tarrask-malware-uses-scheduled-tasks-for-defense-evasion/) -* [https://gist.github.com/MHaggis/5f7fd6745915166fc6da863d685e2728](https://gist.github.com/MHaggis/5f7fd6745915166fc6da863d685e2728) -* [https://gist.github.com/MHaggis/b246e2fae6213e762a6e694cabaf0c17](https://gist.github.com/MHaggis/b246e2fae6213e762a6e694cabaf0c17) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/taskschedule/sd_delete_windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/taskschedule/sd_delete_windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_registry_delete_task_sd.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-04-18-nltest_domain_trust_discovery.md b/docs/_posts/2022-04-18-nltest_domain_trust_discovery.md deleted file mode 100644 index 223c93175a..0000000000 --- a/docs/_posts/2022-04-18-nltest_domain_trust_discovery.md +++ /dev/null @@ -1,174 +0,0 @@ ---- -title: "NLTest Domain Trust Discovery" -excerpt: "Domain Trust Discovery -" -categories: - - Endpoint -last_modified_at: 2022-04-18 -toc: true -toc_label: "" -tags: - - Domain Trust Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for the execution of `nltest.exe` with command-line arguments utilized to query for Domain Trust information. Two arguments `/domain trusts`, returns a list of trusted domains, and `/all_trusts`, returns all trusted domains. Red Teams and adversaries alike use NLTest.exe to enumerate the current domain to assist with further understanding where to pivot next. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-04-18 -- **Author**: Michael Haag, Splunk -- **ID**: c3e05466-5f22-11eb-ae93-0242ac130002 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1482](https://attack.mitre.org/techniques/T1482/) | Domain Trust Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_nltest` (Processes.process=*/domain_trusts* OR Processes.process=*/all_trusts*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `nltest_domain_trust_discovery_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [process_nltest](https://github.com/splunk/security_content/blob/develop/macros/process_nltest.yml) - -> :information_source: -> **nltest_domain_trust_discovery_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process_name -* Processes.process -* Processes.dest -* Processes.user -* Processes.parent_process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Administrators may use nltest for troubleshooting purposes, otherwise, rarely used. - -#### Associated Analytic story -* [Ryuk Ransomware](/stories/ryuk_ransomware) -* [Domain Trust Discovery](/stories/domain_trust_discovery) -* [IcedID](/stories/icedid) -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | Domain trust discovery execution on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1482/T1482.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1482/T1482.md) -* [https://malware.news/t/lets-learn-trickbot-implements-network-collector-module-leveraging-cmd-wmi-ldap/19104](https://malware.news/t/lets-learn-trickbot-implements-network-collector-module-leveraging-cmd-wmi-ldap/19104) -* [https://attack.mitre.org/techniques/T1482/](https://attack.mitre.org/techniques/T1482/) -* [https://owasp.org/www-pdf-archive/Red_Team_Operating_in_a_Modern_Environment.pdf](https://owasp.org/www-pdf-archive/Red_Team_Operating_in_a_Modern_Environment.pdf) -* [https://ss64.com/nt/nltest.html](https://ss64.com/nt/nltest.html) -* [https://redcanary.com/threat-detection-report/techniques/domain-trust-discovery/](https://redcanary.com/threat-detection-report/techniques/domain-trust-discovery/) -* [https://thedfirreport.com/2020/10/08/ryuks-return/](https://thedfirreport.com/2020/10/08/ryuks-return/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1482/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1482/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/nltest_domain_trust_discovery.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-04-22-linux_adding_crontab_using_list_parameter.md b/docs/_posts/2022-04-22-linux_adding_crontab_using_list_parameter.md deleted file mode 100644 index 23b9dfd822..0000000000 --- a/docs/_posts/2022-04-22-linux_adding_crontab_using_list_parameter.md +++ /dev/null @@ -1,178 +0,0 @@ ---- -title: "Linux Adding Crontab Using List Parameter" -excerpt: "Cron -, Scheduled Task/Job -" -categories: - - Endpoint -last_modified_at: 2022-04-22 -toc: true -toc_label: "" -tags: - - Cron - - Scheduled Task/Job - - Execution - - Persistence - - Privilege Escalation - - Execution - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies a suspicious cron jobs modification using crontab list parameters. This command line parameter can be abused by malware like industroyer2, adversaries, and red teamers to add a crontab entry to their malicious code to execute to the schedule they want. This event can also be executed by administrator or normal user for automation purposes so filter is needed. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-04-22 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 52f6d751-1fd4-4c74-a4c9-777ecfeb5c58 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1053.003](https://attack.mitre.org/techniques/T1053/003/) | Cron | Execution, Persistence, Privilege Escalation | - -| [T1053](https://attack.mitre.org/techniques/T1053/) | Scheduled Task/Job | Execution, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = "crontab" Processes.process= "* -l*" by Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `linux_adding_crontab_using_list_parameter_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **linux_adding_crontab_using_list_parameter_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase. - -#### Known False Positives -Administrator or network operator can use this application for automation purposes. Please update the filter macros to remove false positives. - -#### Associated Analytic story -* [Industroyer2](/stories/industroyer2) -* [Linux Privilege Escalation](/stories/linux_privilege_escalation) -* [Linux Persistence Techniques](/stories/linux_persistence_techniques) -* [Linux Living Off The Land](/stories/linux_living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | A possible crontab list command $process$ executed on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.welivesecurity.com/2022/04/12/industroyer2-industroyer-reloaded/](https://www.welivesecurity.com/2022/04/12/industroyer2-industroyer-reloaded/) -* [https://cert.gov.ua/article/39518](https://cert.gov.ua/article/39518) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.003/crontab_list_parameter/sysmon_linux.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.003/crontab_list_parameter/sysmon_linux.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_adding_crontab_using_list_parameter.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-04-22-linux_deleting_critical_directory_using_rm_command.md b/docs/_posts/2022-04-22-linux_deleting_critical_directory_using_rm_command.md deleted file mode 100644 index f5f77d7472..0000000000 --- a/docs/_posts/2022-04-22-linux_deleting_critical_directory_using_rm_command.md +++ /dev/null @@ -1,167 +0,0 @@ ---- -title: "Linux Deleting Critical Directory Using RM Command" -excerpt: "Data Destruction -" -categories: - - Endpoint -last_modified_at: 2022-04-22 -toc: true -toc_label: "" -tags: - - Data Destruction - - Impact - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies a suspicious deletion of a critical folder in Linux machine using rm command. This technique was seen in industroyer2 campaign to wipe or destroy energy facilities of a targeted sector. Deletion in these list of folder is not so common since it need some elevated privileges to access some of it. We recommend to look further events specially in file access or file deletion, process commandline that may related to this technique. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-04-22 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 33f89303-cc6f-49ad-921d-2eaea38a6f7a - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1485](https://attack.mitre.org/techniques/T1485/) | Data Destruction | Impact | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name =rm AND Processes.process= "* -rf *" AND Processes.process IN ("*/boot/*", "*/var/log/*", "*/etc/*", "*/dev/*") by Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.process_guid Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `linux_deleting_critical_directory_using_rm_command_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **linux_deleting_critical_directory_using_rm_command_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase. - -#### Known False Positives -Administrator or network operator can use this application for automation purposes. Please update the filter macros to remove false positives. - -#### Associated Analytic story -* [Industroyer2](/stories/industroyer2) -* [Data Destruction](/stories/data_destruction) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 64.0 | 80 | 80 | A deletion in known critical list of folder using rm command $process$ executed on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.welivesecurity.com/2022/04/12/industroyer2-industroyer-reloaded/](https://www.welivesecurity.com/2022/04/12/industroyer2-industroyer-reloaded/) -* [https://cert.gov.ua/article/39518](https://cert.gov.ua/article/39518) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/rm_shred_critical_dir/sysmon_linux.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/rm_shred_critical_dir/sysmon_linux.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_deleting_critical_directory_using_rm_command.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-04-22-linux_disable_services.md b/docs/_posts/2022-04-22-linux_disable_services.md deleted file mode 100644 index d099ecf726..0000000000 --- a/docs/_posts/2022-04-22-linux_disable_services.md +++ /dev/null @@ -1,166 +0,0 @@ ---- -title: "Linux Disable Services" -excerpt: "Service Stop -" -categories: - - Endpoint -last_modified_at: 2022-04-22 -toc: true -toc_label: "" -tags: - - Service Stop - - Impact - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic is to detect events that attempts to disable a service. This is typically identified in parallel with other instances of service enumeration of attempts to stop a service and then delete it. Adversaries utilize this technique like industroyer2 malware to terminate security services or other related services to continue there objective as a destructive payload. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-04-22 -- **Author**: Teoderick Contreras, Splunk -- **ID**: f2e08a38-6689-4df4-ad8c-b51c16262316 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1489](https://attack.mitre.org/techniques/T1489/) | Service Stop | Impact | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name IN ("systemctl", "service", "svcadm") Processes.process = "* disable*" by Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.process_guid Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `linux_disable_services_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **linux_disable_services_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase. - -#### Known False Positives -Administrator or network operator can use this application for automation purposes. Please update the filter macros to remove false positives. - -#### Associated Analytic story -* [Industroyer2](/stories/industroyer2) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | An instance of $parent_process_name$ spawning $process_name$ was identified attempting to disable services on endpoint $dest$ by $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.welivesecurity.com/2022/04/12/industroyer2-industroyer-reloaded/](https://www.welivesecurity.com/2022/04/12/industroyer2-industroyer-reloaded/) -* [https://cert.gov.ua/article/39518](https://cert.gov.ua/article/39518) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1489/linux_service_stop_disable/sysmon_linux.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1489/linux_service_stop_disable/sysmon_linux.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_disable_services.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-04-22-linux_high_frequency_of_file_deletion_in_boot_folder.md b/docs/_posts/2022-04-22-linux_high_frequency_of_file_deletion_in_boot_folder.md deleted file mode 100644 index 544f3f8fac..0000000000 --- a/docs/_posts/2022-04-22-linux_high_frequency_of_file_deletion_in_boot_folder.md +++ /dev/null @@ -1,190 +0,0 @@ ---- -title: "Linux High Frequency Of File Deletion In Boot Folder" -excerpt: "Data Destruction -, File Deletion -, Indicator Removal on Host -" -categories: - - Endpoint -last_modified_at: 2022-04-22 -toc: true -toc_label: "" -tags: - - Data Destruction - - File Deletion - - Indicator Removal on Host - - Impact - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to detect a high frequency of file deletion relative to process name and process id /boot/ folder. These events was seen in industroyer2 wiper malware where it tries to delete all files in a critical directory in linux directory. This detection already contains some filter that might cause false positive during our testing. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-04-22 -- **Author**: Teoderick Contreras, Splunk -- **ID**: e27fbc5d-0445-4c4a-bc39-87f060d5c602 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1485](https://attack.mitre.org/techniques/T1485/) | Data Destruction | Impact | - -| [T1070.004](https://attack.mitre.org/techniques/T1070/004/) | File Deletion | Defense Evasion | - -| [T1070](https://attack.mitre.org/techniques/T1070/) | Indicator Removal on Host | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` values(Filesystem.file_name) as deletedFileNames values(Filesystem.file_path) as deletedFilePath dc(Filesystem.file_path) as numOfDelFilePath count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.action=deleted Filesystem.file_path = "/boot/*" by _time span=1h Filesystem.dest Filesystem.process_guid Filesystem.action -| `drop_dm_object_name(Filesystem)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.parent_process_name != unknown NOT (Processes.parent_process_name IN ("/usr/bin/dpkg", "*usr/bin/python*", "*/usr/bin/apt-*", "/bin/rm", "*splunkd", "/usr/bin/mandb")) by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_path Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name action] -| table process_name process proc_guid action _time deletedFileNames deletedFilePath numOfDelFilePath parent_process_name parent_process process_path dest user -| where numOfDelFilePath >= 200 -| `linux_high_frequency_of_file_deletion_in_boot_folder_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **linux_high_frequency_of_file_deletion_in_boot_folder_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Filesystem.dest -* Filesystem.file_create_time -* Filesystem.file_name -* Filesystem.process_guid -* Filesystem.file_path -* Filesystem.action -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.process_name -* Processes.process_path -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase. - -#### Known False Positives -linux package installer/uninstaller may cause this event. Please update you filter macro to remove false positives. - -#### Associated Analytic story -* [Industroyer2](/stories/industroyer2) -* [Data Destruction](/stories/data_destruction) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 100 | 80 | a $process_name$ deleting multiple files in /boot/ folder in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.welivesecurity.com/2022/04/12/industroyer2-industroyer-reloaded/](https://www.welivesecurity.com/2022/04/12/industroyer2-industroyer-reloaded/) -* [https://cert.gov.ua/article/39518](https://cert.gov.ua/article/39518) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/rm_boot_dir/sysmon_linux.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/rm_boot_dir/sysmon_linux.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_high_frequency_of_file_deletion_in_boot_folder.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-04-22-linux_shred_overwrite_command.md b/docs/_posts/2022-04-22-linux_shred_overwrite_command.md deleted file mode 100644 index f1c6a95dc1..0000000000 --- a/docs/_posts/2022-04-22-linux_shred_overwrite_command.md +++ /dev/null @@ -1,168 +0,0 @@ ---- -title: "Linux Shred Overwrite Command" -excerpt: "Data Destruction -" -categories: - - Endpoint -last_modified_at: 2022-04-22 -toc: true -toc_label: "" -tags: - - Data Destruction - - Impact - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to detect a shred process to overwrite a files in a linux machine. Shred Linux application is designed to overwrite file to hide its contents or make the deleted file un-recoverable. Weve seen this technique in industroyer2 malware that tries to wipe energy facilities of targeted sector as part of its destructive attack. It might be some normal user may use this command for valid purposes but it is recommended to check what files, disk or folder it tries to shred that might be good pivot for incident response in this type of destructive malware. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-04-22 -- **Author**: Teoderick Contreras, Splunk -- **ID**: c1952cf1-643c-4965-82de-11c067cbae76 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1485](https://attack.mitre.org/techniques/T1485/) | Data Destruction | Impact | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name =shred AND Processes.process IN ("*-n*", "*-u*", "*-z*", "*-s*") by Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.process_guid Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `linux_shred_overwrite_command_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **linux_shred_overwrite_command_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase. - -#### Known False Positives -Administrator or network operator can use this application for automation purposes. Please update the filter macros to remove false positives. - -#### Associated Analytic story -* [Industroyer2](/stories/industroyer2) -* [Linux Privilege Escalation](/stories/linux_privilege_escalation) -* [Linux Persistence Techniques](/stories/linux_persistence_techniques) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | A possible shred overwrite command $process$ executed on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.welivesecurity.com/2022/04/12/industroyer2-industroyer-reloaded/](https://www.welivesecurity.com/2022/04/12/industroyer2-industroyer-reloaded/) -* [https://cert.gov.ua/article/39518](https://cert.gov.ua/article/39518) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/rm_shred_critical_dir/sysmon_linux.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/rm_shred_critical_dir/sysmon_linux.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_shred_overwrite_command.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-04-22-linux_stop_services.md b/docs/_posts/2022-04-22-linux_stop_services.md deleted file mode 100644 index f9ba9a7b71..0000000000 --- a/docs/_posts/2022-04-22-linux_stop_services.md +++ /dev/null @@ -1,166 +0,0 @@ ---- -title: "Linux Stop Services" -excerpt: "Service Stop -" -categories: - - Endpoint -last_modified_at: 2022-04-22 -toc: true -toc_label: "" -tags: - - Service Stop - - Impact - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic is to detect events that attempt to stop or clear a service. This is typically identified in parallel with other instances of service enumeration of attempts to stop a service and then delete it. Adversaries utilize this technique like industroyer2 malware to terminate security services or other related services to continue there objective as a destructive payload. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-04-22 -- **Author**: Teoderick Contreras, Splunk -- **ID**: d05204a5-9f1c-4946-a7f3-4fa58d76d5fd - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1489](https://attack.mitre.org/techniques/T1489/) | Service Stop | Impact | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name IN ("systemctl", "service", "svcadm") Processes.process ="*stop*" by Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.process_guid Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `linux_stop_services_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **linux_stop_services_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase. - -#### Known False Positives -Administrator or network operator can use this application for automation purposes. Please update the filter macros to remove false positives. - -#### Associated Analytic story -* [Industroyer2](/stories/industroyer2) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | An instance of $parent_process_name$ spawning $process_name$ was identified attempting to stop services on endpoint $dest$ by $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.welivesecurity.com/2022/04/12/industroyer2-industroyer-reloaded/](https://www.welivesecurity.com/2022/04/12/industroyer2-industroyer-reloaded/) -* [https://cert.gov.ua/article/39518](https://cert.gov.ua/article/39518) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1489/linux_service_stop_disable/sysmon_linux.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1489/linux_service_stop_disable/sysmon_linux.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_stop_services.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-04-22-windows_processes_killed_by_industroyer2_malware.md b/docs/_posts/2022-04-22-windows_processes_killed_by_industroyer2_malware.md deleted file mode 100644 index b10e220124..0000000000 --- a/docs/_posts/2022-04-22-windows_processes_killed_by_industroyer2_malware.md +++ /dev/null @@ -1,169 +0,0 @@ ---- -title: "Windows Processes Killed By Industroyer2 Malware" -excerpt: "Service Stop -" -categories: - - Endpoint -last_modified_at: 2022-04-22 -toc: true -toc_label: "" -tags: - - Service Stop - - Impact - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic is to look for known processes killed by industroyer2 malware. This technique was seen in the industroyer2 malware attack that tries to kill several processes of windows host machines related to the energy facility network. This anomaly might be a good indicator to check which process kill these processes or why the process was killed. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-04-22 -- **Author**: Teoderick Contreras, Splunk -- **ID**: d8bea5ca-9d4a-4249-8b56-64a619109835 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1489](https://attack.mitre.org/techniques/T1489/) | Service Stop | Impact | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventCode=5 process_name IN ("PServiceControl.exe", "PService_PPD.exe") -| stats min(_time) as firstTime max(_time) as lastTime count by process_name process process_path process_guid process_id EventCode dest user_id -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_processes_killed_by_industroyer2_malware_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **windows_processes_killed_by_industroyer2_malware_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id -* Processes.process_guid - - -#### How To Implement -To successfully implement this search, you need to be ingesting Windows Security Event Logs with 4698 EventCode enabled. The Windows TA is also required. - -#### Known False Positives -False positives are possible if legitimate applications are allowed to terminate this process during testing or updates. Filter as needed based on paths that are used legitimately. - -#### Associated Analytic story -* [Industroyer2](/stories/industroyer2) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 36.0 | 60 | 60 | process was terminated $process_name$ in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.welivesecurity.com/2022/04/12/industroyer2-industroyer-reloaded/](https://www.welivesecurity.com/2022/04/12/industroyer2-industroyer-reloaded/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/industroyer2/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/industroyer2/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_processes_killed_by_industroyer2_malware.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-04-25-windows_linked_policies_in_adsi_discovery.md b/docs/_posts/2022-04-25-windows_linked_policies_in_adsi_discovery.md deleted file mode 100644 index 70fa0e4f3f..0000000000 --- a/docs/_posts/2022-04-25-windows_linked_policies_in_adsi_discovery.md +++ /dev/null @@ -1,168 +0,0 @@ ---- -title: "Windows Linked Policies In ADSI Discovery" -excerpt: "Domain Account -, Account Discovery -" -categories: - - Endpoint -last_modified_at: 2022-04-25 -toc: true -toc_label: "" -tags: - - Domain Account - - Account Discovery - - Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the `[Adsisearcher]` type accelerator being used to query Active Directory for domain groups. Red Teams and adversaries may leverage `[Adsisearcher]` to enumerate domain organizational unit for situational awareness and Active Directory Discovery. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-04-25 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 510ea428-4731-4d2f-8829-a28293e427aa - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery | - -| [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 ScriptBlockText = "*[adsisearcher]*" ScriptBlockText = "*objectcategory=organizationalunit*" ScriptBlockText = "*findAll()*" -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode ScriptBlockText Computer user_id -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_linked_policies_in_adsi_discovery_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **windows_linked_policies_in_adsi_discovery_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* ScriptBlockText -* Computer -* user_id - - -#### How To Implement -The following Hunting analytic requires PowerShell operational logs to be imported. Modify the powershell macro as needed to match the sourcetype or add index. This analytic is specific to 4104, or PowerShell Script Block Logging. - -#### Known False Positives -Administrators or power users may use this command for troubleshooting. - -#### Associated Analytic story -* [Industroyer2](/stories/industroyer2) -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | powershell process having commandline $Message$ for user enumeration | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.welivesecurity.com/2022/04/12/industroyer2-industroyer-reloaded/](https://www.welivesecurity.com/2022/04/12/industroyer2-industroyer-reloaded/) -* [https://medium.com/@pentesttas/discover-hidden-gpo-s-on-active-directory-using-ps-adsi-a284b6814c81](https://medium.com/@pentesttas/discover-hidden-gpo-s-on-active-directory-using-ps-adsi-a284b6814c81) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/adsi_discovery/windows-powershell-xml2.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/adsi_discovery/windows-powershell-xml2.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_linked_policies_in_adsi_discovery.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-04-25-windows_root_domain_linked_policies_discovery.md b/docs/_posts/2022-04-25-windows_root_domain_linked_policies_discovery.md deleted file mode 100644 index dc17c69bb6..0000000000 --- a/docs/_posts/2022-04-25-windows_root_domain_linked_policies_discovery.md +++ /dev/null @@ -1,168 +0,0 @@ ---- -title: "Windows Root Domain linked policies Discovery" -excerpt: "Domain Account -, Account Discovery -" -categories: - - Endpoint -last_modified_at: 2022-04-25 -toc: true -toc_label: "" -tags: - - Domain Account - - Account Discovery - - Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the `[Adsisearcher]` type accelerator being used to query Active Directory for domain groups. Red Teams and adversaries may leverage `[Adsisearcher]` to enumerate root domain linked policies for situational awareness and Active Directory Discovery. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-04-25 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 80ffaede-1f12-49d5-a86e-b4b599b68b3c - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery | - -| [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 ScriptBlockText = "*[adsisearcher]*" ScriptBlockText = "*.SearchRooT*" ScriptBlockText = "*.gplink*" -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode ScriptBlockText Computer user_id -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_root_domain_linked_policies_discovery_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **windows_root_domain_linked_policies_discovery_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* ScriptBlockText -* Computer -* user_id - - -#### How To Implement -The following Hunting analytic requires PowerShell operational logs to be imported. Modify the powershell macro as needed to match the sourcetype or add index. This analytic is specific to 4104, or PowerShell Script Block Logging. - -#### Known False Positives -Administrators or power users may use this command for troubleshooting. - -#### Associated Analytic story -* [Industroyer2](/stories/industroyer2) -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | powershell process having commandline $Message$ for user enumeration | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.welivesecurity.com/2022/04/12/industroyer2-industroyer-reloaded/](https://www.welivesecurity.com/2022/04/12/industroyer2-industroyer-reloaded/) -* [https://medium.com/@pentesttas/discover-hidden-gpo-s-on-active-directory-using-ps-adsi-a284b6814c81](https://medium.com/@pentesttas/discover-hidden-gpo-s-on-active-directory-using-ps-adsi-a284b6814c81) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/adsi_discovery/windows-powershell-xml1.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/adsi_discovery/windows-powershell-xml1.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_root_domain_linked_policies_discovery.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-04-26-powershell_fileless_script_contains_base64_encoded_content.md b/docs/_posts/2022-04-26-powershell_fileless_script_contains_base64_encoded_content.md deleted file mode 100644 index 8ec146fe4c..0000000000 --- a/docs/_posts/2022-04-26-powershell_fileless_script_contains_base64_encoded_content.md +++ /dev/null @@ -1,172 +0,0 @@ ---- -title: "Powershell Fileless Script Contains Base64 Encoded Content" -excerpt: "Command and Scripting Interpreter -, Obfuscated Files or Information -, PowerShell -" -categories: - - Endpoint -last_modified_at: 2022-04-26 -toc: true -toc_label: "" -tags: - - Command and Scripting Interpreter - - Obfuscated Files or Information - - PowerShell - - Execution - - Defense Evasion - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify suspicious PowerShell execution. Script Block Logging captures the command sent to PowerShell, the full command to be executed. Upon enabling, logs will output to Windows event logs. Dependent upon volume, enable on critical endpoints or all. \ -This analytic identifies `FromBase64String` within the script block. A typical malicious instance will include additional code. \ -Command example - `[Byte[]]$var_code = [System.Convert]::FromBase64String(38uqIyMjQ6rG....` \ -During triage, review parallel processes using an EDR product or 4688 events. It will be important to understand the timeline of events around this activity. Review the entire logged PowerShell script block. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-04-26 -- **Author**: Michael Haag, Splunk -- **ID**: 8acbc04c-c882-11eb-b060-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -| [T1027](https://attack.mitre.org/techniques/T1027/) | Obfuscated Files or Information | Defense Evasion | - -| [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 ScriptBlockText=*frombase64string* -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode ScriptBlockText Computer UserID -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `powershell_fileless_script_contains_base64_encoded_content_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **powershell_fileless_script_contains_base64_encoded_content_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* ScriptBlockText -* Opcode -* Computer -* UserID -* EventCodes - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -False positives should be limited. Filter as needed. - -#### Associated Analytic story -* [Hermetic Wiper](/stories/hermetic_wiper) -* [Malicious PowerShell](/stories/malicious_powershell) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 56.0 | 70 | 80 | A suspicious powershell script contains base64 command in $Message$ with EventCode $EventCode$ in host $ComputerName$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.](https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.) -* [https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63](https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63) -* [https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf](https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf) -* [https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/](https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/frombase64string.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/frombase64string.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-04-26-powershell_get_localgroup_discovery_with_script_block_logging.md b/docs/_posts/2022-04-26-powershell_get_localgroup_discovery_with_script_block_logging.md deleted file mode 100644 index ee2fee3daf..0000000000 --- a/docs/_posts/2022-04-26-powershell_get_localgroup_discovery_with_script_block_logging.md +++ /dev/null @@ -1,167 +0,0 @@ ---- -title: "Powershell Get LocalGroup Discovery with Script Block Logging" -excerpt: "Permission Groups Discovery -, Local Groups -" -categories: - - Endpoint -last_modified_at: 2022-04-26 -toc: true -toc_label: "" -tags: - - Permission Groups Discovery - - Local Groups - - Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify suspicious PowerShell execution. Script Block Logging captures the command sent to PowerShell, the full command to be executed. Upon enabling, logs will output to Windows event logs. Dependent upon volume, enable on critical endpoints or all. \ -This analytic identifies PowerShell cmdlet - `get-localgroup` being ran. Typically, by itself, is not malicious but may raise suspicion based on time of day, endpoint and username. \ -During triage, review parallel processes using an EDR product or 4688 events. It will be important to understand the timeline of events around this activity. Review the entire logged PowerShell script block. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-04-26 -- **Author**: Michael Haag, Splunk -- **ID**: d7c6ad22-155c-11ec-bb64-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | - -| [T1069.001](https://attack.mitre.org/techniques/T1069/001/) | Local Groups | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 ScriptBlockText = "*get-localgroup*" -| stats count min(_time) as firstTime max(_time) as lastTime by Opcode Computer UserID EventCode ScriptBlockText -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `powershell_get_localgroup_discovery_with_script_block_logging_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **powershell_get_localgroup_discovery_with_script_block_logging_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* ScriptBlockText -* Opcode -* Computer -* UserID -* EventCode - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -False positives may be present. Tune as needed. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | Local group discovery on $dest$ by $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.splunk.com/en_us/blog/security/powershell-detections-threat-research-release-august-2021.html](https://www.splunk.com/en_us/blog/security/powershell-detections-threat-research-release-august-2021.html) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1069.001/T1069.001.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1069.001/T1069.001.md) -* [https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell](https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell) -* [https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63](https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63) -* [https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf](https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf) -* [https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/](https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/getlocalgroup.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/getlocalgroup.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-04-26-windows_hidden_schedule_task_settings.md b/docs/_posts/2022-04-26-windows_hidden_schedule_task_settings.md deleted file mode 100644 index 78de749e75..0000000000 --- a/docs/_posts/2022-04-26-windows_hidden_schedule_task_settings.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: "Windows Hidden Schedule Task Settings" -excerpt: "Scheduled Task/Job -" -categories: - - Endpoint -last_modified_at: 2022-04-26 -toc: true -toc_label: "" -tags: - - Scheduled Task/Job - - Execution - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following query utilizes Windows Security EventCode 4698, A scheduled task was created, to identify suspicious tasks registered on Windows either via schtasks.exe OR TaskService with a hidden settings that are unique entry of malware like industroyer2 or attack that uses lolbin to download other file or payload to the infected machine. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-04-26 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 0b730470-5fe8-4b13-93a7-fe0ad014d0cc - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1053](https://attack.mitre.org/techniques/T1053/) | Scheduled Task/Job | Execution, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`wineventlog_security` EventCode=4698 -| xmlkv Message -| search Hidden = true -| stats count min(_time) as firstTime max(_time) as lastTime by Task_Name, Command, Author, Hidden, dest -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_hidden_schedule_task_settings_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **windows_hidden_schedule_task_settings_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* dest -* Task_Name -* Command -* Author -* Enabled -* Hidden -* Arguments - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the task schedule (Exa. Security Log EventCode 4698) endpoints. Tune and filter known instances of Task schedule used in your environment. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Industroyer2](/stories/industroyer2) -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 64.0 | 80 | 80 | A schedule task with hidden setting enable in host $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.welivesecurity.com/2022/04/12/industroyer2-industroyer-reloaded/](https://www.welivesecurity.com/2022/04/12/industroyer2-industroyer-reloaded/) -* [https://cert.gov.ua/article/39518](https://cert.gov.ua/article/39518) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053/hidden_schedule_task/security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053/hidden_schedule_task/security.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_hidden_schedule_task_settings.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-04-27-splunk_xss_in_monitoring_console.md b/docs/_posts/2022-04-27-splunk_xss_in_monitoring_console.md deleted file mode 100644 index 5b9c01e73b..0000000000 --- a/docs/_posts/2022-04-27-splunk_xss_in_monitoring_console.md +++ /dev/null @@ -1,163 +0,0 @@ ---- -title: "Splunk XSS in Monitoring Console" -excerpt: "Drive-by Compromise -" -categories: - - Application -last_modified_at: 2022-04-27 -toc: true -toc_label: "" -tags: - - Drive-by Compromise - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2022-27183 ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -On May 3rd, 2022, Splunk published a security advisory for a reflective Cross-Site Scripting (XSS) vulnerability stemming from the lack of input validation in the Distributed Monitoring Console app. This detection will alert on attempted exploitation in patched versions of Splunk as well as actual exploitation in unpatched version of Splunk. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-04-27 -- **Author**: Lou Stella, Splunk -- **ID**: b11accac-6fa3-4103-8a1a-7210f1a67087 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1189](https://attack.mitre.org/techniques/T1189/) | Drive-by Compromise | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2022-27183](https://nvd.nist.gov/vuln/detail/CVE-2022-27183) | The Monitoring Console app configured in Distributed mode allows for a Reflected XSS in a query parameter in Splunk Enterprise versions before 8.1.4. The Monitoring Console app is a bundled app included in Splunk Enterprise, not for download on SplunkBase, and not installed on Splunk Cloud Platform instances. Note that the Cloud Monitoring Console is not impacted. | 4.3 | - - - -
-
- -#### Search - -``` - `splunkd_web` method="GET" uri_query="description=%3C*" -| table _time host status clientip user uri -| `splunk_xss_in_monitoring_console_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [splunkd_web](https://github.com/splunk/security_content/blob/develop/macros/splunkd_web.yml) - -> :information_source: -> **splunk_xss_in_monitoring_console_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* method -* uri_query -* status -* clientip -* user -* uri - - -#### How To Implement -This detection does not require you to ingest any new data. The detection does require the ability to search the _internal index. This detection will find attempted exploitation of CVE-2022-27183. - -#### Known False Positives -Use of the monitoring console where the less-than sign (<) is the first character in the description field. - -#### Associated Analytic story -* [Splunk Vulnerabilities](/stories/splunk_vulnerabilities) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 40.0 | 50 | 80 | A potential XSS attempt has been detected from $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.splunk.com/en_us/product-security/announcements/svd-2022-0505.html](https://www.splunk.com/en_us/product-security/announcements/svd-2022-0505.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1189/xss/splunk_web_access.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1189/xss/splunk_web_access.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/application/splunk_xss_in_monitoring_console.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-04-27-windows_computer_account_created_by_computer_account.md b/docs/_posts/2022-04-27-windows_computer_account_created_by_computer_account.md deleted file mode 100644 index 2c0de92432..0000000000 --- a/docs/_posts/2022-04-27-windows_computer_account_created_by_computer_account.md +++ /dev/null @@ -1,167 +0,0 @@ ---- -title: "Windows Computer Account Created by Computer Account" -excerpt: "Steal or Forge Kerberos Tickets -" -categories: - - Endpoint -last_modified_at: 2022-04-27 -toc: true -toc_label: "" -tags: - - Steal or Forge Kerberos Tickets - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifes a Computer Account creating a new Computer Account with specific a Service Principle Name - "RestrictedKrbHost". The RestrictedKrbHost service class allows client applications to use Kerberos authentication when they do not have the identity of the service but have the server name. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-04-27 -- **Author**: Michael Haag, Splunk -- **ID**: 97a8dc5f-8a7c-4fed-9e3e-ec407fd0268a - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1558](https://attack.mitre.org/techniques/T1558/) | Steal or Forge Kerberos Tickets | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`wineventlog_security` EventCode=4741 user_type=computer Subject_Account_Domain!="NT AUTHORITY" Message=*RestrictedKrbHost* -| stats count min(_time) as firstTime max(_time) as lastTime by dest, subject, action ,src_user, user, Account_Name, Subject_Account_Name,Subject_Account_Domain -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_computer_account_created_by_computer_account_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **windows_computer_account_created_by_computer_account_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* dest -* subject -* action -* src_user -* user -* Account_Name -* Subject_Account_Name -* Subject_Account_Domain - - -#### How To Implement -To successfully implement this search, you need to be ingesting Windows Security Event Logs with 4741 EventCode enabled. The Windows TA is also required. - -#### Known False Positives -It is possible third party applications may have a computer account that adds computer accounts, filtering may be required. - -#### Associated Analytic story -* [Active Directory Kerberos Attacks](/stories/active_directory_kerberos_attacks) -* [Local Privilege Escalation With KrbRelayUp](/stories/local_privilege_escalation_with_krbrelayup) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 30.0 | 50 | 60 | A Computer Account created a Computer Account on $dest$, possibly indicative of Kerberos relay attack. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://docs.microsoft.com/en-us/openspecs/windows_protocols/ms-kile/445e4499-7e49-4f2a-8d82-aaf2d1ee3c47](https://docs.microsoft.com/en-us/openspecs/windows_protocols/ms-kile/445e4499-7e49-4f2a-8d82-aaf2d1ee3c47) -* [https://github.com/Dec0ne/KrbRelayUp](https://github.com/Dec0ne/KrbRelayUp) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1558/krbrelayup/krbrelayup.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1558/krbrelayup/krbrelayup.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_computer_account_created_by_computer_account.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-04-27-windows_computer_account_requesting_kerberos_ticket.md b/docs/_posts/2022-04-27-windows_computer_account_requesting_kerberos_ticket.md deleted file mode 100644 index b5599f262c..0000000000 --- a/docs/_posts/2022-04-27-windows_computer_account_requesting_kerberos_ticket.md +++ /dev/null @@ -1,165 +0,0 @@ ---- -title: "Windows Computer Account Requesting Kerberos Ticket" -excerpt: "Steal or Forge Kerberos Tickets -" -categories: - - Endpoint -last_modified_at: 2022-04-27 -toc: true -toc_label: "" -tags: - - Steal or Forge Kerberos Tickets - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies a ComputerAccount requesting a Kerberos Ticket. typically, a user account requests a Kerberos ticket. This behavior was identified with KrbUpRelay, but additional Kerberos attacks have exhibited similar behavior. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-04-27 -- **Author**: Michael Haag, Splunk -- **ID**: fb3b2bb3-75a4-4279-848a-165b42624770 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1558](https://attack.mitre.org/techniques/T1558/) | Steal or Forge Kerberos Tickets | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`wineventlog_security` EventCode=4768 Account_Name="*$" src_ip!="::1" -| stats count min(_time) as firstTime max(_time) as lastTime by dest, subject, action, Supplied_Realm_Name, user, Account_Name, src_ip -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_computer_account_requesting_kerberos_ticket_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **windows_computer_account_requesting_kerberos_ticket_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* dest -* subject -* action -* Supplied_Realm_Name -* user -* Account_Name -* src_ip - - -#### How To Implement -To successfully implement this search, you need to be ingesting Windows Security Event Logs with 4768 EventCode enabled. The Windows TA is also required. - -#### Known False Positives -It is possible false positives will be present based on third party applications. Filtering may be needed. - -#### Associated Analytic story -* [Active Directory Kerberos Attacks](/stories/active_directory_kerberos_attacks) -* [Local Privilege Escalation With KrbRelayUp](/stories/local_privilege_escalation_with_krbrelayup) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 35.0 | 50 | 70 | A Computer Account requested a Kerberos ticket on $dest$, possibly indicative of Kerberos relay attack. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/Dec0ne/KrbRelayUp](https://github.com/Dec0ne/KrbRelayUp) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1558/krbrelayup/krbrelayup.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1558/krbrelayup/krbrelayup.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_computer_account_requesting_kerberos_ticket.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-04-27-windows_kerberos_local_successful_logon.md b/docs/_posts/2022-04-27-windows_kerberos_local_successful_logon.md deleted file mode 100644 index 8801b6f266..0000000000 --- a/docs/_posts/2022-04-27-windows_kerberos_local_successful_logon.md +++ /dev/null @@ -1,165 +0,0 @@ ---- -title: "Windows Kerberos Local Successful Logon" -excerpt: "Steal or Forge Kerberos Tickets -" -categories: - - Endpoint -last_modified_at: 2022-04-27 -toc: true -toc_label: "" -tags: - - Steal or Forge Kerberos Tickets - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies a local successful authentication event on a Windows endpoint using the Kerberos package. The target user security identified will be set to the built-in local Administrator account, along with the remote address as localhost - 127.0.0.1. This may be indicative of a kerberos relay attack. Upon triage, review for recently ran binaries on disk. In addition, look for new computer accounts added to Active Directory and other anomolous AD events. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-04-27 -- **Author**: Michael Haag, Splunk -- **ID**: 8309c3a8-4d34-48ae-ad66-631658214653 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1558](https://attack.mitre.org/techniques/T1558/) | Steal or Forge Kerberos Tickets | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`wineventlog_security` EventCode=4624 Logon_Type=3 Authentication_Package=Kerberos action=success src_ip=127.0.0.1 -| stats count min(_time) as firstTime max(_time) as lastTime by dest, subject, action, Security_ID, user, Account_Name, src_ip -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_kerberos_local_successful_logon_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **windows_kerberos_local_successful_logon_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* dest -* subject -* action -* Security_ID -* user -* Account_Name -* src_ip - - -#### How To Implement -To successfully implement this search, you need to be ingesting Windows Security Event Logs with 4624 EventCode enabled. The Windows TA is also required. - -#### Known False Positives -False positives are possible, filtering may be required to restrict to workstations vs domain controllers. Filter as needed. - -#### Associated Analytic story -* [Active Directory Kerberos Attacks](/stories/active_directory_kerberos_attacks) -* [Local Privilege Escalation With KrbRelayUp](/stories/local_privilege_escalation_with_krbrelayup) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 64.0 | 80 | 80 | A successful localhost Kerberos authentication event occurred on $dest$, possibly indicative of Kerberos relay attack. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/Dec0ne/KrbRelayUp](https://github.com/Dec0ne/KrbRelayUp) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1558/krbrelayup/krbrelayup.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1558/krbrelayup/krbrelayup.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_kerberos_local_successful_logon.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-04-28-windows_computer_account_with_spn.md b/docs/_posts/2022-04-28-windows_computer_account_with_spn.md deleted file mode 100644 index 82539a9f8d..0000000000 --- a/docs/_posts/2022-04-28-windows_computer_account_with_spn.md +++ /dev/null @@ -1,169 +0,0 @@ ---- -title: "Windows Computer Account With SPN" -excerpt: "Steal or Forge Kerberos Tickets -" -categories: - - Endpoint -last_modified_at: 2022-04-28 -toc: true -toc_label: "" -tags: - - Steal or Forge Kerberos Tickets - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies two SPNs, HOST and RestrictedKrbHost, added using the KrbRelayUp behavior. This particular behavior has been found in other Kerberos based attacks. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-04-28 -- **Author**: Michael Haag, Splunk -- **ID**: 9a3e57e7-33f4-470e-b25d-165baa6e8357 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1558](https://attack.mitre.org/techniques/T1558/) | Steal or Forge Kerberos Tickets | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Installation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`wineventlog_security` EventCode=4741 MSADChangedAttributes IN ("*HOST/*","*RestrictedKrbHost/*") AND New_UAC_Value=0x80 -| eval Effecting_Account=mvindex(Security_ID,1) -| eval New_Computer_Account_Name=mvindex(Security_ID,0) -| stats count min(_time) as firstTime max(_time) as lastTime values(EventCode),values(Account_Domain),values(Security_ID), values(Effecting_Account), values(New_Computer_Account_Name),values(SAM_Account_Name),values(DNS_Host_Name),values(MSADChangedAttributes) by dest Logon_ID subject -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_computer_account_with_spn_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **windows_computer_account_with_spn_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* MSADChangedAttributes -* New_UAC_Value -* Security_ID -* Account_Domain -* SAM_Account_Name -* DNS_Host_Name -* Logon_Id - - -#### How To Implement -To successfully implement this search, you need to be ingesting Windows Security Event Logs with 4741 EventCode enabled. The Windows TA is also required. - -#### Known False Positives -It is possible third party applications may add these SPNs to Computer Accounts, filtering may be needed. - -#### Associated Analytic story -* [Active Directory Kerberos Attacks](/stories/active_directory_kerberos_attacks) -* [Local Privilege Escalation With KrbRelayUp](/stories/local_privilege_escalation_with_krbrelayup) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 64.0 | 80 | 80 | A Computer Account was created with SPNs related to Kerberos on $dest$, possibly indicative of Kerberos relay attack. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.trustedsec.com/blog/an-attack-path-mapping-approach-to-cves-2021-42287-and-2021-42278](https://www.trustedsec.com/blog/an-attack-path-mapping-approach-to-cves-2021-42287-and-2021-42278) -* [https://github.com/Dec0ne/KrbRelayUp](https://github.com/Dec0ne/KrbRelayUp) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1558/krbrelayup/krbrelayup.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1558/krbrelayup/krbrelayup.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_computer_account_with_spn.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-04-29-path_traversal_spl_injection.md b/docs/_posts/2022-04-29-path_traversal_spl_injection.md deleted file mode 100644 index a5fb373842..0000000000 --- a/docs/_posts/2022-04-29-path_traversal_spl_injection.md +++ /dev/null @@ -1,161 +0,0 @@ ---- -title: "Path traversal SPL injection" -excerpt: "File and Directory Discovery -" -categories: - - Application -last_modified_at: 2022-04-29 -toc: true -toc_label: "" -tags: - - File and Directory Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2022-26889 ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -On May 3rd, 2022, Splunk published a security advisory for a Path traversal in search parameter that can potentiall allow SPL injection. An attacker can cause the application to load data from incorrect endpoints, urls leading to outcomes such as running arbitrary SPL queries. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-04-29 -- **Author**: Rod Soto, Splunk -- **ID**: dfe55688-82ed-4d24-a21b-ed8f0e0fda99 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1083](https://attack.mitre.org/techniques/T1083/) | File and Directory Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2022-26889](https://nvd.nist.gov/vuln/detail/CVE-2022-26889) | In Splunk Enterprise versions before 8.1.2, the uri path to load a relative resource within a web page is vulnerable to path traversal. It allows an attacker to potentially inject arbitrary content into the web page (e.g., HTML Injection, XSS) or bypass SPL safeguards for risky commands. The attack is browser-based. An attacker cannot exploit the attack at will and requires the attacker to initiate a request within the victim's browser (e.g., phishing). | 5.1 | - - - -
-
- -#### Search - -``` - `path_traversal_spl_injection` -| search "\/..\/..\/..\/..\/..\/..\/..\/..\/..\/" -| stats count by status clientip method uri_path uri_query -| `path_traversal_spl_injection_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [path_traversal_spl_injection](https://github.com/splunk/security_content/blob/develop/macros/path_traversal_spl_injection.yml) - -> :information_source: -> **path_traversal_spl_injection_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* status -* clientip -* method -* uri_path -* uri_query - - -#### How To Implement -This detection does not require you to ingest any new data. The detection does require the ability to search the _internal index. This search will provide search UI requests with path traversal parameter ("../../../../../../../../../") which shows exploitation attempts. - -#### Known False Positives -This search may find additional path traversal exploitation attempts. - -#### Associated Analytic story -* [Splunk Vulnerabilities](/stories/splunk_vulnerabilities) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 40.0 | 50 | 80 | Path traversal exploitation attempt from $clientip$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.splunk.com/en_us/product-security/announcements/svd-2022-0506.html](https://www.splunk.com/en_us/product-security/announcements/svd-2022-0506.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://raw.githubusercontent.com/splunk/attack_data/master/datasets/attack_techniques/T1083/splunk/path_traversal_spl_injection.txt](https://raw.githubusercontent.com/splunk/attack_data/master/datasets/attack_techniques/T1083/splunk/path_traversal_spl_injection.txt) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/application/path_traversal_spl_injection.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-04-29-splunk_user_enumeration_attempt.md b/docs/_posts/2022-04-29-splunk_user_enumeration_attempt.md deleted file mode 100644 index 04582da67b..0000000000 --- a/docs/_posts/2022-04-29-splunk_user_enumeration_attempt.md +++ /dev/null @@ -1,166 +0,0 @@ ---- -title: "Splunk User Enumeration Attempt" -excerpt: "Valid Accounts -" -categories: - - Application -last_modified_at: 2022-04-29 -toc: true -toc_label: "" -tags: - - Valid Accounts - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2021-33845 ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -On May 3rd, 2022, Splunk published a security advisory for username enumeration stemming from verbose login failure messages present on some REST endpoints. This detection will alert on attempted exploitation in patched versions of Splunk as well as actual exploitation in unpatched version of Splunk. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-04-29 -- **Author**: Lou Stella, Splunk -- **ID**: 25625cb4-1c4d-4463-b0f9-7cb462699cde - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2021-33845](https://nvd.nist.gov/vuln/detail/CVE-2021-33845) | The Splunk Enterprise REST API allows enumeration of usernames via the lockout error message. The potential vulnerability impacts Splunk Enterprise instances before 8.1.7 when configured to repress verbose login errors. | 5.0 | - - - -
-
- -#### Search - -``` - `splunkd_failed_auths` -| stats count(user) as auths by user, src -| where auths>5 -| stats values(user) as "Users", sum(auths) as TotalFailedAuths by src -| `splunk_user_enumeration_attempt_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [splunkd_failed_auths](https://github.com/splunk/security_content/blob/develop/macros/splunkd_failed_auths.yml) - -> :information_source: -> **splunk_user_enumeration_attempt_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* user -* src -* info -* action - - -#### How To Implement -This detection does not require you to ingest any new data. The detection does require the ability to search the _audit index. This detection may assist in efforts to find password spraying or brute force authorization attempts in addition to someone enumerating usernames. - -#### Known False Positives -Automation executing authentication attempts against your Splunk infrastructure with outdated credentials may cause false positives. - -#### Associated Analytic story -* [Splunk Vulnerabilities](/stories/splunk_vulnerabilities) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 40.0 | 50 | 80 | $TotalFailedAuths$ failed authentication events to Splunk from $src$ detected. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.splunk.com/en_us/product-security/announcements/svd-2022-0502.html](https://www.splunk.com/en_us/product-security/announcements/svd-2022-0502.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/splunkd_auth/audittrail.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/splunkd_auth/audittrail.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/application/splunk_user_enumeration_attempt.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-04-30-linux_iptables_firewall_modification.md b/docs/_posts/2022-04-30-linux_iptables_firewall_modification.md deleted file mode 100644 index e4d8947e32..0000000000 --- a/docs/_posts/2022-04-30-linux_iptables_firewall_modification.md +++ /dev/null @@ -1,179 +0,0 @@ ---- -title: "Linux Iptables Firewall Modification" -excerpt: "Disable or Modify System Firewall -, Impair Defenses -" -categories: - - Endpoint -last_modified_at: 2022-04-30 -toc: true -toc_label: "" -tags: - - Disable or Modify System Firewall - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for suspicious commandline that modify the iptables firewall setting of a linux machine. This technique was seen in cyclopsblink malware where it modifies the firewall setting of the compromised machine to allow traffic to its tcp port that will be used to communicate with its C2 server. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-04-30 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 309d59dc-1e1b-49b2-9800-7cf18d12f7b7 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.004](https://attack.mitre.org/techniques/T1562/004/) | Disable or Modify System Firewall | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process = "*iptables *" AND Processes.process = "* --dport *" AND Processes.process = "* ACCEPT*" AND Processes.process = "*&>/dev/null*" AND Processes.process = "* tcp *" AND NOT(Processes.parent_process_path IN("/bin/*", "/lib/*", "/usr/bin/*", "/sbin/*")) by Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.process_guid Processes.dest Processes.user Processes.parent_process_name Processes.parent_process_path Processes.process_path -| rex field=Processes.process "--dport (?3269 -|636 -|989 -|994 -|995 -|8443)" -| stats values(Processes.process) as processes_exec values(port) as ports values(Processes.process_guid) as guids values(Processes.process_id) as pids dc(port) as port_count count by Processes.process_name Processes.parent_process_name Processes.parent_process_id Processes.dest Processes.user Processes.parent_process_path Processes.process_path firstTime lastTime -| where port_count >=3 -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `linux_iptables_firewall_modification_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **linux_iptables_firewall_modification_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase. - -#### Known False Positives -administrator may do this commandline for auditing and testing purposes. In this scenario filter is needed. - -#### Associated Analytic story -* [CyclopsBLink](/stories/cyclopsblink) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | A commandline $process$ that may modify iptables firewall on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.ncsc.gov.uk/files/Cyclops-Blink-Malware-Analysis-Report.pdf](https://www.ncsc.gov.uk/files/Cyclops-Blink-Malware-Analysis-Report.pdf) -* [https://www.trendmicro.com/en_us/research/22/c/cyclops-blink-sets-sights-on-asus-routers--.html](https://www.trendmicro.com/en_us/research/22/c/cyclops-blink-sets-sights-on-asus-routers--.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/cyclopsblink/sysmon_linux.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/cyclopsblink/sysmon_linux.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_iptables_firewall_modification.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-04-30-linux_kworker_process_in_writable_process_path.md b/docs/_posts/2022-04-30-linux_kworker_process_in_writable_process_path.md deleted file mode 100644 index 81557141a0..0000000000 --- a/docs/_posts/2022-04-30-linux_kworker_process_in_writable_process_path.md +++ /dev/null @@ -1,173 +0,0 @@ ---- -title: "Linux Kworker Process In Writable Process Path" -excerpt: "Masquerade Task or Service -, Masquerading -" -categories: - - Endpoint -last_modified_at: 2022-04-30 -toc: true -toc_label: "" -tags: - - Masquerade Task or Service - - Masquerading - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for suspicious process kworker commandline in a linux machine. kworker process name or thread are common names of kernel threads in linux process. This hunting detections can lead to investigate process contains process path in writable directory in linux like /home/, /var/log and /tmp/. This technique was seen in cyclopsblink malware to blend its core and other of its child process as normal kworker on the compromised machine. This detection might be a good pivot to look for other IOC related to cyclopsblink malware or attacks. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-04-30 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 1cefb270-74a5-4e27-aa0c-2b6fa7c5b4ed - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1036.004](https://attack.mitre.org/techniques/T1036/004/) | Masquerade Task or Service | Defense Evasion | - -| [T1036](https://attack.mitre.org/techniques/T1036/) | Masquerading | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process = "*[kworker/*" Processes.parent_process_path IN ("/home/*", "/tmp/*", "/var/log/*") Processes.process="*iptables*" by Processes.parent_process_name Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.parent_process_path Processes.process_guid Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `linux_kworker_process_in_writable_process_path_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **linux_kworker_process_in_writable_process_path_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id -* Processes.parent_process_path -* Processes.process_path - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [CyclopsBLink](/stories/cyclopsblink) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 36.0 | 60 | 60 | a $process_name$ with kworker commandline in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.ncsc.gov.uk/files/Cyclops-Blink-Malware-Analysis-Report.pdf](https://www.ncsc.gov.uk/files/Cyclops-Blink-Malware-Analysis-Report.pdf) -* [https://www.trendmicro.com/en_us/research/22/c/cyclops-blink-sets-sights-on-asus-routers--.html](https://www.trendmicro.com/en_us/research/22/c/cyclops-blink-sets-sights-on-asus-routers--.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/cyclopsblink/sysmon_linux.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/cyclopsblink/sysmon_linux.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_kworker_process_in_writable_process_path.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-05-02-delete_shadowcopy_with_powershell.md b/docs/_posts/2022-05-02-delete_shadowcopy_with_powershell.md deleted file mode 100644 index 4e9539d792..0000000000 --- a/docs/_posts/2022-05-02-delete_shadowcopy_with_powershell.md +++ /dev/null @@ -1,159 +0,0 @@ ---- -title: "Delete ShadowCopy With PowerShell" -excerpt: "Inhibit System Recovery -" -categories: - - Endpoint -last_modified_at: 2022-05-02 -toc: true -toc_label: "" -tags: - - Inhibit System Recovery - - Impact - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This following analytic detects PowerShell command to delete shadow copy using the WMIC PowerShell module. This technique was seen used by a recent adversary to deploy DarkSide Ransomware where it executed a child process of PowerShell to execute a hex encoded command to delete shadow copy. This hex encoded command was able to be decrypted by PowerShell log. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-05-02 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 5ee2bcd0-b2ff-11eb-bb34-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1490](https://attack.mitre.org/techniques/T1490/) | Inhibit System Recovery | Impact | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 ScriptBlockText= "*ShadowCopy*" (ScriptBlockText = "*Delete*" OR ScriptBlockText = "*Remove*") -| stats count min(_time) as firstTime max(_time) as lastTime by Opcode Computer UserID EventCode ScriptBlockText -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `delete_shadowcopy_with_powershell_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **delete_shadowcopy_with_powershell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* ScriptBlockText -* Opcode -* Computer -* UserID -* EventCode - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the powershell logs from your endpoints. make sure you enable needed registry to monitor this event. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [DarkSide Ransomware](/stories/darkside_ransomware) -* [Ransomware](/stories/ransomware) -* [Revil Ransomware](/stories/revil_ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 81.0 | 90 | 90 | An attempt to delete ShadowCopy was performed using PowerShell on $Computer$ by $User$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.mandiant.com/resources/shining-a-light-on-darkside-ransomware-operations](https://www.mandiant.com/resources/shining-a-light-on-darkside-ransomware-operations) -* [https://www.techtarget.com/searchwindowsserver/tutorial/Set-up-PowerShell-script-block-logging-for-added-security](https://www.techtarget.com/searchwindowsserver/tutorial/Set-up-PowerShell-script-block-logging-for-added-security) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/sbl_xml.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/sbl_xml.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/delete_shadowcopy_with_powershell.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-05-02-exchange_powershell_module_usage.md b/docs/_posts/2022-05-02-exchange_powershell_module_usage.md deleted file mode 100644 index 8dc84c43b6..0000000000 --- a/docs/_posts/2022-05-02-exchange_powershell_module_usage.md +++ /dev/null @@ -1,167 +0,0 @@ ---- -title: "Exchange PowerShell Module Usage" -excerpt: "Command and Scripting Interpreter -, PowerShell -" -categories: - - Endpoint -last_modified_at: 2022-05-02 -toc: true -toc_label: "" -tags: - - Command and Scripting Interpreter - - PowerShell - - Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - -### :warning: WARNING THIS IS A EXPERIMENTAL analytic -We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported. - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the usage of Exchange PowerShell modules that were recently used for a proof of concept related to ProxyShell. Currently, there is no active data shared or data we could re-produce relate to this part of the ProxyShell chain of exploits. \ -Inherently, the usage of the modules is not malicious, but reviewing parallel processes, and user, of the session will assist with determining the intent. \ -Module - New-MailboxExportRequest will begin the process of exporting contents of a primary mailbox or archive to a .pst file. \ -Module - New-managementroleassignment can assign a management role to a management role group, management role assignment policy, user, or universal security group (USG). - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-05-02 -- **Author**: Michael Haag -- **ID**: 2d10095e-05ae-11ec-8fdf-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -| [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 ScriptBlockText IN ("*New-MailboxExportRequest*", "*New-ManagementRoleAssignment*") -| stats count min(_time) as firstTime max(_time) as lastTime by lastTime by Opcode Computer UserID EventCode ScriptBlockText -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `exchange_powershell_module_usage_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **exchange_powershell_module_usage_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* ScriptBlockText -* Opcode -* Computer -* UserID -* EventCode - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -Administrators or power users may use this PowerShell commandlet for troubleshooting. - -#### Associated Analytic story -* [ProxyShell](/stories/proxyshell) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | Local user discovery enumeration using PowerShell on $dest$ by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://docs.microsoft.com/en-us/powershell/module/exchange/new-mailboxexportrequest?view=exchange-ps](https://docs.microsoft.com/en-us/powershell/module/exchange/new-mailboxexportrequest?view=exchange-ps) -* [https://docs.microsoft.com/en-us/powershell/module/exchange/new-managementroleassignment?view=exchange-ps](https://docs.microsoft.com/en-us/powershell/module/exchange/new-managementroleassignment?view=exchange-ps) -* [https://blog.orange.tw/2021/08/proxyshell-a-new-attack-surface-on-ms-exchange-part-3.html](https://blog.orange.tw/2021/08/proxyshell-a-new-attack-surface-on-ms-exchange-part-3.html) -* [https://www.zerodayinitiative.com/blog/2021/8/17/from-pwn2own-2021-a-new-attack-surface-on-microsoft-exchange-proxyshell](https://www.zerodayinitiative.com/blog/2021/8/17/from-pwn2own-2021-a-new-attack-surface-on-microsoft-exchange-proxyshell) -* [https://thedfirreport.com/2021/11/15/exchange-exploit-leads-to-domain-wide-ransomware/](https://thedfirreport.com/2021/11/15/exchange-exploit-leads-to-domain-wide-ransomware/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/endpoint/exchange_powershell_module_usage.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-05-02-get-domaintrust_with_powershell_script_block.md b/docs/_posts/2022-05-02-get-domaintrust_with_powershell_script_block.md deleted file mode 100644 index 7d062c98df..0000000000 --- a/docs/_posts/2022-05-02-get-domaintrust_with_powershell_script_block.md +++ /dev/null @@ -1,161 +0,0 @@ ---- -title: "Get-DomainTrust with PowerShell Script Block" -excerpt: "Domain Trust Discovery -" -categories: - - Endpoint -last_modified_at: 2022-05-02 -toc: true -toc_label: "" -tags: - - Domain Trust Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify suspicious PowerShell execution. Script Block Logging captures the command sent to PowerShell, the full command to be executed. Upon enabling, logs will output to Windows event logs. Dependent upon volume, enable on critical endpoints or all. \ -This analytic identifies Get-DomainTrust from PowerView in order to gather domain trust information. \ -During triage, review parallel processes using an EDR product or 4688 events. It will be important to understand the timeline of events around this activity. Review the entire logged PowerShell script block. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-05-02 -- **Author**: Michael Haag, Splunk -- **ID**: 89275e7e-0548-11ec-bf75-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1482](https://attack.mitre.org/techniques/T1482/) | Domain Trust Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 ScriptBlockText = "*get-domaintrust*" -| stats count min(_time) as firstTime max(_time) as lastTime by Opcode Computer UserID EventCode ScriptBlockText -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `get_domaintrust_with_powershell_script_block_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **get-domaintrust_with_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* ScriptBlockText -* Opcode -* Computer -* UserID -* EventCode - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -It is possible certain system management frameworks utilize this command to gather trust information. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 12.0 | 30 | 40 | Suspicious PowerShell Get-DomainTrust was identified on endpoint $Computer$ by user $UserID$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://blog.harmj0y.net/redteaming/a-guide-to-attacking-domain-trusts/](https://blog.harmj0y.net/redteaming/a-guide-to-attacking-domain-trusts/) -* [https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.](https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.) -* [https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63](https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63) -* [https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf](https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf) -* [https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/](https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/domaintrust.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/domaintrust.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-05-02-get_aduserresultantpasswordpolicy_with_powershell_script_block.md b/docs/_posts/2022-05-02-get_aduserresultantpasswordpolicy_with_powershell_script_block.md deleted file mode 100644 index f0a972fa96..0000000000 --- a/docs/_posts/2022-05-02-get_aduserresultantpasswordpolicy_with_powershell_script_block.md +++ /dev/null @@ -1,157 +0,0 @@ ---- -title: "Get ADUserResultantPasswordPolicy with Powershell Script Block" -excerpt: "Password Policy Discovery -" -categories: - - Endpoint -last_modified_at: 2022-05-02 -toc: true -toc_label: "" -tags: - - Password Policy Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-ADUserResultantPasswordPolicy` commandlet used to obtain the password policy in a Windows domain. Red Teams and adversaries alike may use PowerShell to enumerate domain policies for situational awareness and Active Directory Discovery. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-05-02 -- **Author**: Teoderick Contreras, Mauricio Velazco, Splunk -- **ID**: 737e1eb0-065a-11ec-921a-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1201](https://attack.mitre.org/techniques/T1201/) | Password Policy Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 ScriptBlockText="*Get-ADUserResultantPasswordPolicy*" -| stats count min(_time) as firstTime max(_time) as lastTime by Opcode Computer UserID EventCode ScriptBlockText -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `get_aduserresultantpasswordpolicy_with_powershell_script_block_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **get_aduserresultantpasswordpolicy_with_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* ScriptBlockText -* Opcode -* Computer -* UserID -* EventCode - - -#### How To Implement -The following Hunting analytic requires PowerShell operational logs to be imported. Modify the powershell macro as needed to match the sourcetype or add index. This analytic is specific to 4104, or PowerShell Script Block Logging. - -#### Known False Positives -Administrators or power users may use this command for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 9.0 | 30 | 30 | powershell process having commandline $ScriptBlockText$ to query domain user password policy. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/S1ckB0y1337/Active-Directory-Exploitation-Cheat-Sheet](https://github.com/S1ckB0y1337/Active-Directory-Exploitation-Cheat-Sheet) -* [https://attack.mitre.org/techniques/T1201/](https://attack.mitre.org/techniques/T1201/) -* [https://docs.microsoft.com/en-us/powershell/module/activedirectory/get-aduserresultantpasswordpolicy?view=windowsserver2019-ps](https://docs.microsoft.com/en-us/powershell/module/activedirectory/get-aduserresultantpasswordpolicy?view=windowsserver2019-ps) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/sbl_xml.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/sbl_xml.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-05-02-get_domainpolicy_with_powershell_script_block.md b/docs/_posts/2022-05-02-get_domainpolicy_with_powershell_script_block.md deleted file mode 100644 index 655d6780c2..0000000000 --- a/docs/_posts/2022-05-02-get_domainpolicy_with_powershell_script_block.md +++ /dev/null @@ -1,157 +0,0 @@ ---- -title: "Get DomainPolicy with Powershell Script Block" -excerpt: "Password Policy Discovery -" -categories: - - Endpoint -last_modified_at: 2022-05-02 -toc: true -toc_label: "" -tags: - - Password Policy Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get DomainPolicy` commandlet used to obtain the password policy in a Windows domain. Red Teams and adversaries alike may use PowerShell to enumerate domain policies for situational awareness and Active Directory Discovery. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-05-02 -- **Author**: Teoderick Contreras, Splunk -- **ID**: a360d2b2-065a-11ec-b0bf-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1201](https://attack.mitre.org/techniques/T1201/) | Password Policy Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 ScriptBlockText ="*Get-DomainPolicy*" -| stats count min(_time) as firstTime max(_time) as lastTime by Opcode Computer UserID EventCode ScriptBlockText -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `get_domainpolicy_with_powershell_script_block_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **get_domainpolicy_with_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* ScriptBlockText -* Opcode -* Computer -* UserID -* EventCode - - -#### How To Implement -The following Hunting analytic requires PowerShell operational logs to be imported. Modify the powershell macro as needed to match the sourcetype or add index. This analytic is specific to 4104, or PowerShell Script Block Logging. - -#### Known False Positives -Administrators or power users may use this command for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 30.0 | 50 | 60 | powershell process having commandline $ScriptBlockText$ to query domain policy. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/S1ckB0y1337/Active-Directory-Exploitation-Cheat-Sheet](https://github.com/S1ckB0y1337/Active-Directory-Exploitation-Cheat-Sheet) -* [https://powersploit.readthedocs.io/en/latest/Recon/Get-DomainPolicy/](https://powersploit.readthedocs.io/en/latest/Recon/Get-DomainPolicy/) -* [https://attack.mitre.org/techniques/T1201/](https://attack.mitre.org/techniques/T1201/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/domainpolicy.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/domainpolicy.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-05-02-getadcomputer_with_powershell_script_block.md b/docs/_posts/2022-05-02-getadcomputer_with_powershell_script_block.md deleted file mode 100644 index e2d297a22f..0000000000 --- a/docs/_posts/2022-05-02-getadcomputer_with_powershell_script_block.md +++ /dev/null @@ -1,155 +0,0 @@ ---- -title: "GetAdComputer with PowerShell Script Block" -excerpt: "Remote System Discovery -" -categories: - - Endpoint -last_modified_at: 2022-05-02 -toc: true -toc_label: "" -tags: - - Remote System Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-AdGroup` commandlet. The `Get-AdGroup` commandlet is used to return a list of all domain computers. Red Teams and adversaries may leverage this commandlet to enumerate domain computers for situational awareness and Active Directory Discovery. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-05-02 -- **Author**: Mauricio Velazco, Splunk -- **ID**: a9a1da02-8e27-4bf7-a348-f4389c9da487 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1018](https://attack.mitre.org/techniques/T1018/) | Remote System Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 (ScriptBlockText = "*Get-AdComputer*") -| stats count min(_time) as firstTime max(_time) as lastTime by Opcode Computer UserID EventCode ScriptBlockText -| `security_content_ctime(firstTime)` -| `getadcomputer_with_powershell_script_block_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **getadcomputer_with_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* ScriptBlockText -* Opcode -* Computer -* UserID -* EventCode - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -Administrators or power users may use this PowerShell commandlet for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | Remote system discovery enumeration on $Computer$ by $UserID$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1018/](https://attack.mitre.org/techniques/T1018/) -* [https://docs.microsoft.com/en-us/powershell/module/activedirectory/get-adgroup?view=windowsserver2019-ps](https://docs.microsoft.com/en-us/powershell/module/activedirectory/get-adgroup?view=windowsserver2019-ps) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/AD_discovery/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/AD_discovery/windows-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2022-05-02-getdomaincomputer_with_powershell_script_block.md b/docs/_posts/2022-05-02-getdomaincomputer_with_powershell_script_block.md deleted file mode 100644 index 579220084a..0000000000 --- a/docs/_posts/2022-05-02-getdomaincomputer_with_powershell_script_block.md +++ /dev/null @@ -1,155 +0,0 @@ ---- -title: "GetDomainComputer with PowerShell Script Block" -excerpt: "Remote System Discovery -" -categories: - - Endpoint -last_modified_at: 2022-05-02 -toc: true -toc_label: "" -tags: - - Remote System Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-DomainComputer` commandlet. `GetDomainComputer` is part of PowerView, a PowerShell tool used to perform enumeration on Windows domains. Red Teams and adversaries alike may use PowerView to enumerate domain computers for situational awareness and Active Directory Discovery. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-05-02 -- **Author**: Mauricio Velazco, Splunk -- **ID**: f64da023-b988-4775-8d57-38e512beb56e - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1018](https://attack.mitre.org/techniques/T1018/) | Remote System Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 (ScriptBlockText = "*Get-DomainComputer*") -| stats count min(_time) as firstTime max(_time) as lastTime by Opcode Computer UserID EventCode ScriptBlockText -| `security_content_ctime(firstTime)` -| `getdomaincomputer_with_powershell_script_block_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **getdomaincomputer_with_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* ScriptBlockText -* Opcode -* Computer -* UserID -* EventCode - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -Administrators or power users may use PowerView for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 24.0 | 30 | 80 | Remote system discovery with PowerView on $Computer$ by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1018/](https://attack.mitre.org/techniques/T1018/) -* [https://powersploit.readthedocs.io/en/latest/Recon/Get-DomainComputer/](https://powersploit.readthedocs.io/en/latest/Recon/Get-DomainComputer/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/sbl_xml.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/sbl_xml.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-05-02-getdomaincontroller_with_powershell_script_block.md b/docs/_posts/2022-05-02-getdomaincontroller_with_powershell_script_block.md deleted file mode 100644 index d74d2d6079..0000000000 --- a/docs/_posts/2022-05-02-getdomaincontroller_with_powershell_script_block.md +++ /dev/null @@ -1,155 +0,0 @@ ---- -title: "GetDomainController with PowerShell Script Block" -excerpt: "Remote System Discovery -" -categories: - - Endpoint -last_modified_at: 2022-05-02 -toc: true -toc_label: "" -tags: - - Remote System Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-DomainController` commandlet. `Get-DomainController` is part of PowerView, a PowerShell tool used to perform enumeration on Windows domains. Red Teams and adversaries alike may use PowerView to enumerate domain computers for situational awareness and Active Directory Discovery. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-05-02 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 676b600a-a94d-4951-b346-11329431e6c1 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1018](https://attack.mitre.org/techniques/T1018/) | Remote System Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 (ScriptBlockText = "*Get-DomainController*") -| stats count min(_time) as firstTime max(_time) as lastTime by Opcode Computer UserID EventCode ScriptBlockText -| `security_content_ctime(firstTime)` -| `getdomaincontroller_with_powershell_script_block_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **getdomaincontroller_with_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* ScriptBlockText -* Opcode -* Computer -* UserID -* EventCode - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -Administrators or power users may use this PowerShell commandlet for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 24.0 | 30 | 80 | Remote system discovery with PowerView on $Computer$ by $UserID$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1018/](https://attack.mitre.org/techniques/T1018/) -* [https://powersploit.readthedocs.io/en/latest/Recon/Get-DomainController/](https://powersploit.readthedocs.io/en/latest/Recon/Get-DomainController/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/getdc.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/getdc.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-05-02-getdomaingroup_with_powershell_script_block.md b/docs/_posts/2022-05-02-getdomaingroup_with_powershell_script_block.md deleted file mode 100644 index c6ece6af3b..0000000000 --- a/docs/_posts/2022-05-02-getdomaingroup_with_powershell_script_block.md +++ /dev/null @@ -1,160 +0,0 @@ ---- -title: "GetDomainGroup with PowerShell Script Block" -excerpt: "Permission Groups Discovery -, Domain Groups -" -categories: - - Endpoint -last_modified_at: 2022-05-02 -toc: true -toc_label: "" -tags: - - Permission Groups Discovery - - Domain Groups - - Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-DomainGroup` commandlet. `Get-DomainGroup` is part of PowerView, a PowerShell tool used to perform enumeration on Windows domains. As the name suggests, `Get-DomainGroup` is used to query domain groups. Red Teams and adversaries may leverage this function to enumerate domain groups for situational awareness and Active Directory Discovery. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-05-02 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 09725404-a44f-4ed3-9efa-8ed5d69e4c53 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | - -| [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 (ScriptBlockText = "*Get-DomainGroup*") -| stats count min(_time) as firstTime max(_time) as lastTime by Opcode Computer UserID EventCode ScriptBlockText -| `security_content_ctime(firstTime)` -| `getdomaingroup_with_powershell_script_block_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **getdomaingroup_with_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* ScriptBlockText -* Opcode -* Computer -* UserID -* EventCode - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -Administrators or power users may use this PowerView functions for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | Domain group discovery enumeration using PowerView on $Computer$ by $UserID$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1069/002/](https://attack.mitre.org/techniques/T1069/002/) -* [https://powersploit.readthedocs.io/en/latest/Recon/Get-DomainGroup/](https://powersploit.readthedocs.io/en/latest/Recon/Get-DomainGroup/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/domaingroup.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/domaingroup.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-05-02-getwmiobject_ds_computer_with_powershell_script_block.md b/docs/_posts/2022-05-02-getwmiobject_ds_computer_with_powershell_script_block.md deleted file mode 100644 index 0ac94a228c..0000000000 --- a/docs/_posts/2022-05-02-getwmiobject_ds_computer_with_powershell_script_block.md +++ /dev/null @@ -1,155 +0,0 @@ ---- -title: "GetWmiObject Ds Computer with PowerShell Script Block" -excerpt: "Remote System Discovery -" -categories: - - Endpoint -last_modified_at: 2022-05-02 -toc: true -toc_label: "" -tags: - - Remote System Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-WmiObject` commandlet. The `DS_Computer` class parameter leverages WMI to query for all domain computers. Red Teams and adversaries may leverage this commandlet to enumerate domain computers for situational awareness and Active Directory Discovery. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-05-02 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 29b99201-723c-4118-847a-db2b3d3fb8ea - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1018](https://attack.mitre.org/techniques/T1018/) | Remote System Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 (ScriptBlockText=*Get-WmiObject* AND ScriptBlockText="*namespace root\\directory\\ldap*" AND ScriptBlockText="*class ds_computer*") -| stats count min(_time) as firstTime max(_time) as lastTime by Opcode Computer UserID EventCode ScriptBlockText -| `security_content_ctime(firstTime)` -| `getwmiobject_ds_computer_with_powershell_script_block_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **getwmiobject_ds_computer_with_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* ScriptBlockText -* Opcode -* Computer -* UserID -* EventCode - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -Administrators or power users may use this PowerShell commandlet for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | Remote system discovery enumeration on $Computer$ by $UserID$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1018/](https://attack.mitre.org/techniques/T1018/) -* [https://docs.microsoft.com/en-us/powershell/module/microsoft.powershell.management/get-wmiobject?view=powershell-5.1](https://docs.microsoft.com/en-us/powershell/module/microsoft.powershell.management/get-wmiobject?view=powershell-5.1) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/sbl_xml.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/sbl_xml.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-05-02-getwmiobject_ds_group_with_powershell_script_block.md b/docs/_posts/2022-05-02-getwmiobject_ds_group_with_powershell_script_block.md deleted file mode 100644 index 2926cfe6fb..0000000000 --- a/docs/_posts/2022-05-02-getwmiobject_ds_group_with_powershell_script_block.md +++ /dev/null @@ -1,160 +0,0 @@ ---- -title: "GetWmiObject Ds Group with PowerShell Script Block" -excerpt: "Permission Groups Discovery -, Domain Groups -" -categories: - - Endpoint -last_modified_at: 2022-05-02 -toc: true -toc_label: "" -tags: - - Permission Groups Discovery - - Domain Groups - - Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-WmiObject` commandlet used with specific parameters . The `DS_Group` parameter leverages WMI to query for all domain groups. Red Teams and adversaries may leverage this commandlet to enumerate domain groups for situational awareness and Active Directory Discovery. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-05-02 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 67740bd3-1506-469c-b91d-effc322cc6e5 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | - -| [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 (ScriptBlockText=*Get-WmiObject* AND ScriptBlockText="*namespace root\\directory\\ldap*" AND ScriptBlockText="*class ds_group*") -| stats count min(_time) as firstTime max(_time) as lastTime by Opcode Computer UserID EventCode ScriptBlockText -| `security_content_ctime(firstTime)` -| `getwmiobject_ds_group_with_powershell_script_block_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **getwmiobject_ds_group_with_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* ScriptBlockText -* Opcode -* Computer -* UserID -* EventCode - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -Administrators or power users may use this PowerShell commandlet for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | Domain group discovery enumeration using PowerShell on $Computer$ by $UserID$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1069/002/](https://attack.mitre.org/techniques/T1069/002/) -* [https://docs.microsoft.com/en-us/powershell/module/microsoft.powershell.management/get-wmiobject?view=powershell-5.1](https://docs.microsoft.com/en-us/powershell/module/microsoft.powershell.management/get-wmiobject?view=powershell-5.1) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/sbl_xml.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/sbl_xml.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-05-02-getwmiobject_ds_user_with_powershell_script_block.md b/docs/_posts/2022-05-02-getwmiobject_ds_user_with_powershell_script_block.md deleted file mode 100644 index c725834aa6..0000000000 --- a/docs/_posts/2022-05-02-getwmiobject_ds_user_with_powershell_script_block.md +++ /dev/null @@ -1,161 +0,0 @@ ---- -title: "GetWmiObject DS User with PowerShell Script Block" -excerpt: "Domain Account -, Account Discovery -" -categories: - - Endpoint -last_modified_at: 2022-05-02 -toc: true -toc_label: "" -tags: - - Domain Account - - Account Discovery - - Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-WmiObject` commandlet. The `DS_User` class parameter leverages WMI to query for all domain users. Red Teams and adversaries may leverage this commandlet to enumerate domain users for situational awareness and Active Directory Discovery. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-05-02 -- **Author**: Teoderick Contreras, Mauricio Velazco, Splunk -- **ID**: fabd364e-04f3-11ec-b34b-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery | - -| [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 ScriptBlockText = "*get-wmiobject*" ScriptBlockText = "*ds_user*" ScriptBlockText = "*-namespace*" ScriptBlockText = "*root\\directory\\ldap*" -| stats count min(_time) as firstTime max(_time) as lastTime by Opcode Computer UserID EventCode ScriptBlockText -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `getwmiobject_ds_user_with_powershell_script_block_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **getwmiobject_ds_user_with_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* ScriptBlockText -* Opcode -* Computer -* UserID -* EventCode - - -#### How To Implement -he following Hunting analytic requires PowerShell operational logs to be imported. Modify the powershell macro as needed to match the sourcetype or add index. This analytic is specific to 4104, or PowerShell Script Block Logging. - -#### Known False Positives -Administrators or power users may use this command for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | powershell process having commandline $ScriptBlockText$ for user enumeration | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.blackhillsinfosec.com/red-blue-purple/](https://www.blackhillsinfosec.com/red-blue-purple/) -* [https://docs.microsoft.com/en-us/windows/win32/wmisdk/describing-the-ldap-namespace](https://docs.microsoft.com/en-us/windows/win32/wmisdk/describing-the-ldap-namespace) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/AD_discovery/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/AD_discovery/windows-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-05-02-getwmiobject_user_account_with_powershell_script_block.md b/docs/_posts/2022-05-02-getwmiobject_user_account_with_powershell_script_block.md deleted file mode 100644 index d58e4c95b0..0000000000 --- a/docs/_posts/2022-05-02-getwmiobject_user_account_with_powershell_script_block.md +++ /dev/null @@ -1,165 +0,0 @@ ---- -title: "GetWmiObject User Account with PowerShell Script Block" -excerpt: "Account Discovery -, Local Account -, PowerShell -" -categories: - - Endpoint -last_modified_at: 2022-05-02 -toc: true -toc_label: "" -tags: - - Account Discovery - - Local Account - - PowerShell - - Discovery - - Discovery - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-WmiObject` commandlet used with specific parameters. The `Win32_UserAccount` parameter is used to return a list of all local users. Red Teams and adversaries may leverage this commandlet to enumerate users for situational awareness and Active Directory Discovery. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-05-02 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 640b0eda-0429-11ec-accd-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - -| [T1087.001](https://attack.mitre.org/techniques/T1087/001/) | Local Account | Discovery | - -| [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 (ScriptBlockText="*Get-WmiObject*" AND ScriptBlockText="*Win32_UserAccount*") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode ScriptBlockText Computer UserID -| `security_content_ctime(firstTime)` -| `getwmiobject_user_account_with_powershell_script_block_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **getwmiobject_user_account_with_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* ScriptBlockText -* Computer -* UserID - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -Administrators or power users may use this PowerShell commandlet for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) -* [Malicious PowerShell](/stories/malicious_powershell) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | Local user discovery enumeration using PowerShell on $Computer$ by $UserID$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1087/001/](https://attack.mitre.org/techniques/T1087/001/) -* [https://www.splunk.com/en_us/blog/security/hunting-for-malicious-powershell-using-script-block-logging.html](https://www.splunk.com/en_us/blog/security/hunting-for-malicious-powershell-using-script-block-logging.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.001/AD_discovery/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.001/AD_discovery/windows-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-05-02-mailsniper_invoke_functions.md b/docs/_posts/2022-05-02-mailsniper_invoke_functions.md deleted file mode 100644 index 7b6ebe3924..0000000000 --- a/docs/_posts/2022-05-02-mailsniper_invoke_functions.md +++ /dev/null @@ -1,161 +0,0 @@ ---- -title: "Mailsniper Invoke functions" -excerpt: "Email Collection -, Local Email Collection -" -categories: - - Endpoint -last_modified_at: 2022-05-02 -toc: true -toc_label: "" -tags: - - Email Collection - - Local Email Collection - - Collection - - Collection - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect known mailsniper.ps1 functions executed in a machine. This technique was seen in some attacker to harvest some sensitive e-mail in a compromised exchange server. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-05-02 -- **Author**: Teoderick Contreras, Splunk -- **ID**: a36972c8-b894-11eb-9f78-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1114](https://attack.mitre.org/techniques/T1114/) | Email Collection | Collection | - -| [T1114.001](https://attack.mitre.org/techniques/T1114/001/) | Local Email Collection | Collection | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 ScriptBlockText IN ("*Invoke-GlobalO365MailSearch*", "*Invoke-GlobalMailSearch*", "*Invoke-SelfSearch*", "*Invoke-PasswordSprayOWA*", "*Invoke-PasswordSprayEWS*","*Invoke-DomainHarvestOWA*", "*Invoke-UsernameHarvestOWA*","*Invoke-OpenInboxFinder*","*Invoke-InjectGEventAPI*","*Invoke-InjectGEvent*","*Invoke-SearchGmail*", "*Invoke-MonitorCredSniper*", "*Invoke-AddGmailRule*","*Invoke-PasswordSprayEAS*","*Invoke-UsernameHarvestEAS*") -| stats count min(_time) as firstTime max(_time) as lastTime by Opcode Computer UserID EventCode ScriptBlockText -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `mailsniper_invoke_functions_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **mailsniper_invoke_functions_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* ScriptBlockText -* Opcode -* Computer -* UserID -* EventCode - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the powershell logs from your endpoints. make sure you enable needed registry to monitor this event. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Data Exfiltration](/stories/data_exfiltration) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 72.0 | 90 | 80 | mailsniper.ps1 functions $ScriptBlockText$ executed on a $Computer$ by user $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.blackhillsinfosec.com/introducing-mailsniper-a-tool-for-searching-every-users-email-for-sensitive-data/](https://www.blackhillsinfosec.com/introducing-mailsniper-a-tool-for-searching-every-users-email-for-sensitive-data/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/sbl_xml.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/sbl_xml.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/mailsniper_invoke_functions.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-05-02-powershell_4104_hunting.md b/docs/_posts/2022-05-02-powershell_4104_hunting.md deleted file mode 100644 index 5cd3577ba1..0000000000 --- a/docs/_posts/2022-05-02-powershell_4104_hunting.md +++ /dev/null @@ -1,341 +0,0 @@ ---- -title: "PowerShell 4104 Hunting" -excerpt: "Command and Scripting Interpreter -, PowerShell -" -categories: - - Endpoint -last_modified_at: 2022-05-02 -toc: true -toc_label: "" -tags: - - Command and Scripting Interpreter - - PowerShell - - Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following Hunting analytic assists with identifying suspicious PowerShell execution using Script Block Logging, or EventCode 4104. This analytic is not meant to be ran hourly, but occasionally to identify malicious or suspicious PowerShell. This analytic is a combination of work completed by Alex Teixeira and Splunk Threat Research Team. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-05-02 -- **Author**: Michael Haag, Splunk -- **ID**: d6f2b006-0041-11ec-8885-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -| [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 -| eval DoIt = if(match(ScriptBlockText,"(?i)(\$doit)"), "4", 0) -| eval enccom=if(match(ScriptBlockText,"[A-Za-z0-9+\/]{44,}([A-Za-z0-9+\/]{4} -|[A-Za-z0-9+\/]{3}= -|[A-Za-z0-9+\/]{2}==)") OR match(ScriptBlockText, "(?i)[-]e(nc*o*d*e*d*c*o*m*m*a*n*d*)*\s+[^-]"),4,0) -| eval suspcmdlet=if(match(ScriptBlockText, "(?i)Add-Exfiltration -|Add-Persistence -|Add-RegBackdoor -|Add-ScrnSaveBackdoor -|Check-VM -|Do-Exfiltration -|Enabled-DuplicateToken -|Exploit-Jboss -|Find-Fruit -|Find-GPOLocation -|Find-TrustedDocuments -|Get-ApplicationHost -|Get-ChromeDump -|Get-ClipboardContents -|Get-FoxDump -|Get-GPPPassword -|Get-IndexedItem -|Get-Keystrokes -|LSASecret -|Get-PassHash -|Get-RegAlwaysInstallElevated -|Get-RegAutoLogon -|Get-RickAstley -|Get-Screenshot -|Get-SecurityPackages -|Get-ServiceFilePermission -|Get-ServicePermission -|Get-ServiceUnquoted -|Get-SiteListPassword -|Get-System -|Get-TimedScreenshot -|Get-UnattendedInstallFile -|Get-Unconstrained -|Get-VaultCredential -|Get-VulnAutoRun -|Get-VulnSchTask -|Gupt-Backdoor -|HTTP-Login -|Install-SSP -|Install-ServiceBinary -|Invoke-ACLScanner -|Invoke-ADSBackdoor -|Invoke-ARPScan -|Invoke-AllChecks -|Invoke-BackdoorLNK -|Invoke-BypassUAC -|Invoke-CredentialInjection -|Invoke-DCSync -|Invoke-DllInjection -|Invoke-DowngradeAccount -|Invoke-EgressCheck -|Invoke-Inveigh -|Invoke-InveighRelay -|Invoke-Mimikittenz -|Invoke-NetRipper -|Invoke-NinjaCopy -|Invoke-PSInject -|Invoke-Paranoia -|Invoke-PortScan -|Invoke-PoshRat -|Invoke-PostExfil -|Invoke-PowerDump -|Invoke-PowerShellTCP -|Invoke-PsExec -|Invoke-PsUaCme -|Invoke-ReflectivePEInjection -|Invoke-ReverseDNSLookup -|Invoke-RunAs -|Invoke-SMBScanner -|Invoke-SSHCommand -|Invoke-Service -|Invoke-Shellcode -|Invoke-Tater -|Invoke-ThunderStruck -|Invoke-Token -|Invoke-UserHunter -|Invoke-VoiceTroll -|Invoke-WScriptBypassUAC -|Invoke-WinEnum -|MailRaider -|New-HoneyHash -|Out-Minidump -|Port-Scan -|PowerBreach -|PowerUp -|PowerView -|Remove-Update -|Set-MacAttribute -|Set-Wallpaper -|Show-TargetScreen -|Start-CaptureServer -|VolumeShadowCopyTools -|NEEEEWWW -|(Computer -|User)Property -|CachedRDPConnection -|get-net\S+ -|invoke-\S+hunter -|Install-Service -|get-\S+(credent -|password) -|remoteps -|Kerberos.*(policy -|ticket) -|netfirewall -|Uninstall-Windows -|Verb\s+Runas -|AmsiBypass -|nishang -|Invoke-Interceptor -|EXEonRemote -|NetworkRelay -|PowerShelludp -|PowerShellIcmp -|CreateShortcut -|copy-vss -|invoke-dll -|invoke-mass -|out-shortcut -|Invoke-ShellCommand"),1,0) -| eval base64 = if(match(lower(ScriptBlockText),"frombase64"), "4", 0) -| eval empire=if(match(lower(ScriptBlockText),"system.net.webclient") AND match(lower(ScriptBlockText), "frombase64string") ,5,0) -| eval mimikatz=if(match(lower(ScriptBlockText),"mimikatz") OR match(lower(ScriptBlockText), "-dumpcr") OR match(lower(ScriptBlockText), "SEKURLSA::Pth") OR match(lower(ScriptBlockText), "kerberos::ptt") OR match(lower(ScriptBlockText), "kerberos::golden") ,5,0) -| eval iex = if(match(lower(ScriptBlockText),"iex"), "2", 0) -| eval webclient=if(match(lower(ScriptBlockText),"http") OR match(lower(ScriptBlockText),"web(client -|request)") OR match(lower(ScriptBlockText),"socket") OR match(lower(ScriptBlockText),"download(file -|string)") OR match(lower(ScriptBlockText),"bitstransfer") OR match(lower(ScriptBlockText),"internetexplorer.application") OR match(lower(ScriptBlockText),"xmlhttp"),5,0) -| eval get = if(match(lower(ScriptBlockText),"get-"), "1", 0) -| eval rundll32 = if(match(lower(ScriptBlockText),"rundll32"), "4", 0) -| eval suspkeywrd=if(match(ScriptBlockText, "(?i)(bitstransfer -|mimik -|metasp -|AssemblyBuilderAccess -|Reflection\.Assembly -|shellcode -|injection -|cnvert -|shell\.application -|start-process -|Rc4ByteStream -|System\.Security\.Cryptography -|lsass\.exe -|localadmin -|LastLoggedOn -|hijack -|BackupPrivilege -|ngrok -|comsvcs -|backdoor -|brute.?force -|Port.?Scan -|Exfiltration -|exploit -|DisableRealtimeMonitoring -|beacon)"),1,0) -| eval syswow64 = if(match(lower(ScriptBlockText),"syswow64"), "3", 0) -| eval httplocal = if(match(lower(ScriptBlockText),"http://127.0.0.1"), "4", 0) -| eval reflection = if(match(lower(ScriptBlockText),"reflection"), "1", 0) -| eval invokewmi=if(match(lower(ScriptBlockText), "(?i)(wmiobject -|WMIMethod -|RemoteWMI -|PowerShellWmi -|wmicommand)"),5,0) -| eval downgrade=if(match(ScriptBlockText, "(?i)([-]ve*r*s*i*o*n*\s+2)") OR match(lower(ScriptBlockText),"powershell -version"),3,0) -| eval compressed=if(match(ScriptBlockText, "(?i)GZipStream -|::Decompress -|IO.Compression -|write-zip -|(expand -|compress)-Archive"),5,0) -| eval invokecmd = if(match(lower(ScriptBlockText),"invoke-command"), "4", 0) -| addtotals fieldname=Score DoIt, enccom, suspcmdlet, suspkeywrd, compressed, downgrade, mimikatz, iex, empire, rundll32, webclient, syswow64, httplocal, reflection, invokewmi, invokecmd, base64, get -| stats values(Score) by DoIt, enccom, compressed, downgrade, iex, mimikatz, rundll32, empire, webclient, syswow64, httplocal, reflection, invokewmi, invokecmd, base64, get, suspcmdlet, suspkeywrd -| `powershell_4104_hunting_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **powershell_4104_hunting_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* ScriptBlockText -* Opcode -* Computer -* UserID -* EventCode - - -#### How To Implement -The following Hunting analytic requires PowerShell operational logs to be imported. Modify the powershell macro as needed to match the sourcetype or add index. This analytic is specific to 4104, or PowerShell Script Block Logging. - -#### Known False Positives -Limited false positives. May filter as needed. - -#### Associated Analytic story -* [Hermetic Wiper](/stories/hermetic_wiper) -* [Malicious PowerShell](/stories/malicious_powershell) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $Computer$ by user $user$ executing suspicious commands. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/inodee/threathunting-spl/blob/master/hunt-queries/powershell_qualifiers.md](https://github.com/inodee/threathunting-spl/blob/master/hunt-queries/powershell_qualifiers.md) -* [https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell](https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell) -* [https://github.com/marcurdy/dfir-toolset/blob/master/Powershell%20Blueteam.txt](https://github.com/marcurdy/dfir-toolset/blob/master/Powershell%20Blueteam.txt) -* [https://devblogs.microsoft.com/powershell/powershell-the-blue-team/](https://devblogs.microsoft.com/powershell/powershell-the-blue-team/) -* [https://docs.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_logging?view=powershell-5.1](https://docs.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_logging?view=powershell-5.1) -* [https://www.mandiant.com/resources/greater-visibilityt](https://www.mandiant.com/resources/greater-visibilityt) -* [https://hurricanelabs.com/splunk-tutorials/how-to-use-powershell-transcription-logs-in-splunk/](https://hurricanelabs.com/splunk-tutorials/how-to-use-powershell-transcription-logs-in-splunk/) -* [https://www.splunk.com/en_us/blog/security/hunting-for-malicious-powershell-using-script-block-logging.html](https://www.splunk.com/en_us/blog/security/hunting-for-malicious-powershell-using-script-block-logging.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/sbl_xml.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/sbl_xml.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/powershell_4104_hunting.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2022-05-02-powershell_creating_thread_mutex.md b/docs/_posts/2022-05-02-powershell_creating_thread_mutex.md deleted file mode 100644 index 96a6d3a6bc..0000000000 --- a/docs/_posts/2022-05-02-powershell_creating_thread_mutex.md +++ /dev/null @@ -1,168 +0,0 @@ ---- -title: "Powershell Creating Thread Mutex" -excerpt: "Obfuscated Files or Information -, Indicator Removal from Tools -, PowerShell -" -categories: - - Endpoint -last_modified_at: 2022-05-02 -toc: true -toc_label: "" -tags: - - Obfuscated Files or Information - - Indicator Removal from Tools - - PowerShell - - Defense Evasion - - Defense Evasion - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies suspicious PowerShell script execution via EventCode 4104 that is using the `mutex` function. This function is commonly seen in some obfuscated PowerShell scripts to make sure that only one instance of there process is running on a compromise machine. During triage, review parallel processes within the same timeframe. Review the full script block to identify other related artifacts. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-05-02 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 637557ec-ca08-11eb-bd0a-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1027](https://attack.mitre.org/techniques/T1027/) | Obfuscated Files or Information | Defense Evasion | - -| [T1027.005](https://attack.mitre.org/techniques/T1027/005/) | Indicator Removal from Tools | Defense Evasion | - -| [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 ScriptBlockText = "*Threading.Mutex*" -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode ScriptBlockText Computer UserID -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `powershell_creating_thread_mutex_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **powershell_creating_thread_mutex_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* ScriptBlockText -* Computer -* UserID - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -powershell developer may used this function in their script for instance checking too. - -#### Associated Analytic story -* [Malicious PowerShell](/stories/malicious_powershell) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 40.0 | 50 | 80 | A suspicious powershell script contains Thread Mutex in $ScriptBlockText$ with EventCode $EventCode$ in host $Computer$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://isc.sans.edu/forums/diary/Some+Powershell+Malicious+Code/22988/](https://isc.sans.edu/forums/diary/Some+Powershell+Malicious+Code/22988/) -* [https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.](https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.) -* [https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63](https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63) -* [https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf](https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf) -* [https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/](https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/sbl_xml.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/sbl_xml.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/powershell_creating_thread_mutex.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2022-05-02-powershell_loading_dotnet_into_memory_via_reflection.md b/docs/_posts/2022-05-02-powershell_loading_dotnet_into_memory_via_reflection.md deleted file mode 100644 index 161fdd2029..0000000000 --- a/docs/_posts/2022-05-02-powershell_loading_dotnet_into_memory_via_reflection.md +++ /dev/null @@ -1,167 +0,0 @@ ---- -title: "PowerShell Loading DotNET into Memory via Reflection" -excerpt: "Command and Scripting Interpreter -, PowerShell -" -categories: - - Endpoint -last_modified_at: 2022-05-02 -toc: true -toc_label: "" -tags: - - Command and Scripting Interpreter - - PowerShell - - Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify suspicious PowerShell execution. Script Block Logging captures the command sent to PowerShell, the full command to be executed. Upon enabling, logs will output to Windows event logs. Dependent upon volume, enable no critical endpoints or all. \ -This analytic identifies the use of PowerShell loading .net assembly via reflection. This is commonly found in malicious PowerShell usage, including Empire and Cobalt Strike. In addition, the `load(` value may be modifed by removing `(` and it will identify more events to review. \ -During triage, review parallel processes using an EDR product or 4688 events. It will be important to understand the timeline of events around this activity. Review the entire logged PowerShell script block. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-05-02 -- **Author**: Michael Haag, Splunk -- **ID**: 85bc3f30-ca28-11eb-bd21-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -| [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 ScriptBlockText IN ("*[system.reflection.assembly]::load(*","*[reflection.assembly]*", "*reflection.assembly*") -| stats count min(_time) as firstTime max(_time) as lastTime by Opcode Computer UserID EventCode ScriptBlockText -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `powershell_loading_dotnet_into_memory_via_reflection_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **powershell_loading_dotnet_into_memory_via_reflection_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* ScriptBlockText -* Opcode -* Computer -* UserID -* EventCode - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -False positives should be limited as day to day scripts do not use this method. - -#### Associated Analytic story -* [Hermetic Wiper](/stories/hermetic_wiper) -* [Malicious PowerShell](/stories/malicious_powershell) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 56.0 | 70 | 80 | A suspicious powershell script contains reflective class assembly command in $ScriptBlockText$ to load .net code in memory with EventCode $EventCode$ in host $Computer$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://docs.microsoft.com/en-us/dotnet/api/system.reflection.assembly?view=net-5.0](https://docs.microsoft.com/en-us/dotnet/api/system.reflection.assembly?view=net-5.0) -* [https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.](https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.) -* [https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63](https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63) -* [https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf](https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf) -* [https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/](https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/reflection.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/reflection.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_reflection.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-05-02-powershell_remove_windows_defender_directory.md b/docs/_posts/2022-05-02-powershell_remove_windows_defender_directory.md deleted file mode 100644 index 2d01e6842c..0000000000 --- a/docs/_posts/2022-05-02-powershell_remove_windows_defender_directory.md +++ /dev/null @@ -1,167 +0,0 @@ ---- -title: "Powershell Remove Windows Defender Directory" -excerpt: "Disable or Modify Tools -, Impair Defenses -" -categories: - - Endpoint -last_modified_at: 2022-05-02 -toc: true -toc_label: "" -tags: - - Disable or Modify Tools - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic will identify a suspicious PowerShell command used to delete the Windows Defender folder. This technique was seen used by the WhisperGate malware campaign where it used Nirsofts advancedrun.exe to gain administrative privileges to then execute a PowerShell command to delete the Windows Defender folder. This is a good indicator the offending process is trying corrupt a Windows Defender installation. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-05-02 -- **Author**: Teoderick Contreras, Splunk -- **ID**: adf47620-79fa-11ec-b248-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 ScriptBlockText = "*rmdir *" AND ScriptBlockText = "*\\Microsoft\\Windows Defender*" -| stats count min(_time) as firstTime max(_time) as lastTime by Opcode Computer UserID EventCode ScriptBlockText -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `powershell_remove_windows_defender_directory_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **powershell_remove_windows_defender_directory_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* ScriptBlockText -* Opcode -* Computer -* UserID -* EventCode - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [WhisperGate](/stories/whispergate) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 90.0 | 100 | 90 | suspicious powershell script $ScriptBlockText$ was executed on the $Computer$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/](https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/sbl_xml.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/sbl_xml.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2022-05-02-windows_krbrelayup_service_creation.md b/docs/_posts/2022-05-02-windows_krbrelayup_service_creation.md deleted file mode 100644 index 197ec18a1a..0000000000 --- a/docs/_posts/2022-05-02-windows_krbrelayup_service_creation.md +++ /dev/null @@ -1,163 +0,0 @@ ---- -title: "Windows KrbRelayUp Service Creation" -excerpt: "Windows Service -" -categories: - - Endpoint -last_modified_at: 2022-05-02 -toc: true -toc_label: "" -tags: - - Windows Service - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the default service name created by KrbRelayUp. Defenders should be aware that attackers could change the hardcoded service name of the KrbRelayUp tool and bypass this detection. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-05-02 -- **Author**: Michael Haag, Splunk -- **ID**: e40ef542-8241-4419-9af4-6324582ea60a - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1543.003](https://attack.mitre.org/techniques/T1543/003/) | Windows Service | Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`wineventlog_system` EventCode=7045 Service_Name IN ("KrbSCM") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Service_File_Name Service_Name Service_Start_Type Service_Type -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_krbrelayup_service_creation_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [wineventlog_system](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_system.yml) - -> :information_source: -> **windows_krbrelayup_service_creation_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Service_File_Name -* Service_Name -* Service_Start_Type -* Service_Type - - -#### How To Implement -To successfully implement this search, you need to be ingesting Windows System Event Logs with 7045 EventCode enabled. The Windows TA is also required. - -#### Known False Positives -False positives should be limited as this is specific to KrbRelayUp based attack. Filter as needed. - -#### Associated Analytic story -* [Local Privilege Escalation With KrbRelayUp](/stories/local_privilege_escalation_with_krbrelayup) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 64.0 | 80 | 80 | A service was created on $dest$, related to KrbRelayUp. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/Dec0ne/KrbRelayUp](https://github.com/Dec0ne/KrbRelayUp) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1558/krbrelayup/krbrelayup.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1558/krbrelayup/krbrelayup.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_krbrelayup_service_creation.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-05-02-wmi_recon_running_process_or_services.md b/docs/_posts/2022-05-02-wmi_recon_running_process_or_services.md deleted file mode 100644 index 4f73182311..0000000000 --- a/docs/_posts/2022-05-02-wmi_recon_running_process_or_services.md +++ /dev/null @@ -1,159 +0,0 @@ ---- -title: "WMI Recon Running Process Or Services" -excerpt: "Gather Victim Host Information -" -categories: - - Endpoint -last_modified_at: 2022-05-02 -toc: true -toc_label: "" -tags: - - Gather Victim Host Information - - Reconnaissance - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies suspicious PowerShell script execution via EventCode 4104, where WMI is performing an event query looking for running processes or running services. This technique is commonly found in malware and APT events where the adversary will map all running security applications or services on the compromised machine. During triage, review parallel processes within the same timeframe. Review the full script block to identify other related artifacts. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-05-02 -- **Author**: Teoderick Contreras, Splunk -- **ID**: b5cd5526-cce7-11eb-b3bd-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1592](https://attack.mitre.org/techniques/T1592/) | Gather Victim Host Information | Reconnaissance | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 ScriptBlockText= "*SELECT*" AND (ScriptBlockText="*Win32_Process*" OR ScriptBlockText="*Win32_Service*") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode ScriptBlockText Computer UserID -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `wmi_recon_running_process_or_services_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **wmi_recon_running_process_or_services_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* ScriptBlockText -* Opcode -* Computer -* UserID -* EventCode - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -network administrator may used this command for checking purposes - -#### Associated Analytic story -* [Hermetic Wiper](/stories/hermetic_wiper) -* [Malicious PowerShell](/stories/malicious_powershell) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 30.0 | 30 | 100 | Suspicious powerShell script execution by $user$ on $Computer$ via EventCode 4104, where WMI is performing an event query looking for running processes or running services | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://news.sophos.com/en-us/2020/05/12/maze-ransomware-1-year-counting/](https://news.sophos.com/en-us/2020/05/12/maze-ransomware-1-year-counting/) -* [https://www.eideon.com/2018-03-02-THL03-WMIBackdoors/](https://www.eideon.com/2018-03-02-THL03-WMIBackdoors/) -* [https://github.com/trustedsec/SysmonCommunityGuide/blob/master/chapters/WMI-events.md](https://github.com/trustedsec/SysmonCommunityGuide/blob/master/chapters/WMI-events.md) -* [https://in.security/2019/04/03/an-intro-into-abusing-and-identifying-wmi-event-subscriptions-for-persistence/](https://in.security/2019/04/03/an-intro-into-abusing-and-identifying-wmi-event-subscriptions-for-persistence/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/win32process.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/win32process.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/wmi_recon_running_process_or_services.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-05-03-disabled_kerberos_pre-authentication_discovery_with_get-aduser.md b/docs/_posts/2022-05-03-disabled_kerberos_pre-authentication_discovery_with_get-aduser.md deleted file mode 100644 index 84d1304b12..0000000000 --- a/docs/_posts/2022-05-03-disabled_kerberos_pre-authentication_discovery_with_get-aduser.md +++ /dev/null @@ -1,161 +0,0 @@ ---- -title: "Disabled Kerberos Pre-Authentication Discovery With Get-ADUser" -excerpt: "Steal or Forge Kerberos Tickets -, AS-REP Roasting -" -categories: - - Endpoint -last_modified_at: 2022-05-03 -toc: true -toc_label: "" -tags: - - Steal or Forge Kerberos Tickets - - AS-REP Roasting - - Credential Access - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-ADUser` commandlet with specific parameters. `Get-ADUser` is part of the Active Directory PowerShell module used to manage Windows Active Directory networks. As the name suggests, `Get-ADUser` is used to query for domain users. With the appropiate parameters, Get-ADUser allows adversaries to discover domain accounts with Kerberos Pre Authentication disabled.\ Red Teams and adversaries alike use may abuse Get-ADUSer to enumerate these accounts and attempt to crack their passwords offline. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-05-03 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 114c6bfe-9406-11ec-bcce-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1558](https://attack.mitre.org/techniques/T1558/) | Steal or Forge Kerberos Tickets | Credential Access | - -| [T1558.004](https://attack.mitre.org/techniques/T1558/004/) | AS-REP Roasting | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - `powershell` EventCode=4104 (ScriptBlockText = "*Get-ADUser*" AND ScriptBlockText="*4194304*") -| stats count min(_time) as firstTime max(_time) as lastTime by Opcode Computer UserID EventCode ScriptBlockText -| `security_content_ctime(firstTime)` -| `disabled_kerberos_pre_authentication_discovery_with_get_aduser_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **disabled_kerberos_pre-authentication_discovery_with_get-aduser_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* ScriptBlockText -* Opcode -* Computer -* UserID -* EventCode - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -Administrators or power users may use search for accounts with Kerberos Pre Authentication disabled for legitimate purposes. - -#### Associated Analytic story -* [Active Directory Kerberos Attacks](/stories/active_directory_kerberos_attacks) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 54.0 | 60 | 90 | Disabled Kerberos Pre-Authentication Discovery With Get-ADUser from $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1558/004/](https://attack.mitre.org/techniques/T1558/004/) -* [https://m0chan.github.io/2019/07/31/How-To-Attack-Kerberos-101.html](https://m0chan.github.io/2019/07/31/How-To-Attack-Kerberos-101.html) -* [https://stealthbits.com/blog/cracking-active-directory-passwords-with-as-rep-roasting/](https://stealthbits.com/blog/cracking-active-directory-passwords-with-as-rep-roasting/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1558.004/getaduser/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1558.004/getaduser/windows-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disabled_kerberos_pre_authentication_discovery_with_get_aduser.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-05-03-disabled_kerberos_pre-authentication_discovery_with_powerview.md b/docs/_posts/2022-05-03-disabled_kerberos_pre-authentication_discovery_with_powerview.md deleted file mode 100644 index 316018d21b..0000000000 --- a/docs/_posts/2022-05-03-disabled_kerberos_pre-authentication_discovery_with_powerview.md +++ /dev/null @@ -1,161 +0,0 @@ ---- -title: "Disabled Kerberos Pre-Authentication Discovery With PowerView" -excerpt: "Steal or Forge Kerberos Tickets -, AS-REP Roasting -" -categories: - - Endpoint -last_modified_at: 2022-05-03 -toc: true -toc_label: "" -tags: - - Steal or Forge Kerberos Tickets - - AS-REP Roasting - - Credential Access - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-DomainUser` commandlet with specific parameters. `Get-DomainUser` is part of PowerView, a PowerShell tool used to perform enumeration on Windows Active Directory networks. As the name suggests, `Get-DomainUser` is used to identify domain users and combining it with `-PreauthNotRequired` allows adversaries to discover domain accounts with Kerberos Pre Authentication disabled.\ Red Teams and adversaries alike use may leverage PowerView to enumerate these accounts and attempt to crack their passwords offline. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-05-03 -- **Author**: Mauricio Velazco, Splunk -- **ID**: b0b34e2c-90de-11ec-baeb-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1558](https://attack.mitre.org/techniques/T1558/) | Steal or Forge Kerberos Tickets | Credential Access | - -| [T1558.004](https://attack.mitre.org/techniques/T1558/004/) | AS-REP Roasting | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - `powershell` EventCode=4104 (ScriptBlockText = "*Get-DomainUser*" AND ScriptBlockText="*PreauthNotRequired*") -| stats count min(_time) as firstTime max(_time) as lastTime by Opcode Computer UserID EventCode ScriptBlockText -| `security_content_ctime(firstTime)` -| `disabled_kerberos_pre_authentication_discovery_with_powerview_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **disabled_kerberos_pre-authentication_discovery_with_powerview_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* ScriptBlockText -* Opcode -* Computer -* UserID -* EventCode - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -Administrators or power users may use PowerView for troubleshooting - -#### Associated Analytic story -* [Active Directory Kerberos Attacks](/stories/active_directory_kerberos_attacks) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 54.0 | 60 | 90 | Disabled Kerberos Pre-Authentication Discovery With PowerView from $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1558/004/](https://attack.mitre.org/techniques/T1558/004/) -* [https://m0chan.github.io/2019/07/31/How-To-Attack-Kerberos-101.html](https://m0chan.github.io/2019/07/31/How-To-Attack-Kerberos-101.html) -* [https://stealthbits.com/blog/cracking-active-directory-passwords-with-as-rep-roasting/](https://stealthbits.com/blog/cracking-active-directory-passwords-with-as-rep-roasting/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/getdomainuser.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/getdomainuser.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disabled_kerberos_pre_authentication_discovery_with_powerview.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-05-05-windows_service_create_kernel_mode_driver.md b/docs/_posts/2022-05-05-windows_service_create_kernel_mode_driver.md deleted file mode 100644 index 7127c9061b..0000000000 --- a/docs/_posts/2022-05-05-windows_service_create_kernel_mode_driver.md +++ /dev/null @@ -1,179 +0,0 @@ ---- -title: "Windows Service Create Kernel Mode Driver" -excerpt: "Windows Service -, Create or Modify System Process -, Exploitation for Privilege Escalation -" -categories: - - Endpoint -last_modified_at: 2022-05-05 -toc: true -toc_label: "" -tags: - - Windows Service - - Create or Modify System Process - - Exploitation for Privilege Escalation - - Persistence - - Privilege Escalation - - Persistence - - Privilege Escalation - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifes a new kernel driver being added to Windows using sc.exe. Adding a Kernel driver is not common day to day and should be investigated to further understand the source. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-05-05 -- **Author**: Michael Haag, Splunk -- **ID**: 0b4e3b06-1b2b-4885-b752-cf06d12a90cb - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1543.003](https://attack.mitre.org/techniques/T1543/003/) | Windows Service | Persistence, Privilege Escalation | - -| [T1543](https://attack.mitre.org/techniques/T1543/) | Create or Modify System Process | Persistence, Privilege Escalation | - -| [T1068](https://attack.mitre.org/techniques/T1068/) | Exploitation for Privilege Escalation | Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Installation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=sc.exe Processes.process="*kernel*" by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_service_create_kernel_mode_driver_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_service_create_kernel_mode_driver_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -False positives may be present based on common applications adding new drivers, however, filter as needed. - -#### Associated Analytic story -* [Windows Drivers](/stories/windows_drivers) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 48.0 | 60 | 80 | Service control, $process_name$, loaded a new kernel mode driver on $dest$ by $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.aon.com/cyber-solutions/aon_cyber_labs/yours-truly-signed-av-driver-weaponizing-an-antivirus-driver/](https://www.aon.com/cyber-solutions/aon_cyber_labs/yours-truly-signed-av-driver-weaponizing-an-antivirus-driver/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1068/drivers/sc_kernel.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1068/drivers/sc_kernel.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_service_create_kernel_mode_driver.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-05-10-detect_aws_console_login_by_new_user.md b/docs/_posts/2022-05-10-detect_aws_console_login_by_new_user.md deleted file mode 100644 index 11f1a6b710..0000000000 --- a/docs/_posts/2022-05-10-detect_aws_console_login_by_new_user.md +++ /dev/null @@ -1,156 +0,0 @@ ---- -title: "Detect AWS Console Login by New User" -excerpt: "" -categories: - - Cloud -last_modified_at: 2022-05-10 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Authentication ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for AWS CloudTrail events wherein a console login event by a user was recorded within the last hour, then compares the event to a lookup file of previously seen users (by ARN values) who have logged into the console. The alert is fired if the user has logged into the console for the first time within the last hour - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Authentication](https://docs.splunk.com/Documentation/CIM/latest/User/Authentication) -- **Last Updated**: 2022-05-10 -- **Author**: Rico Valdez, Splunk -- **ID**: bc91a8cd-35e7-4bb2-6140-e756cc46fd71 - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.DP -* DE.AE - - - -
-
- -
- CIS20 - -
- -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats earliest(_time) as firstTime latest(_time) as lastTime from datamodel=Authentication where Authentication.signature=ConsoleLogin by Authentication.user -| `drop_dm_object_name(Authentication)` -| join user type=outer [ inputlookup previously_seen_users_console_logins -| stats min(firstTime) as earliestseen by user] -| eval userStatus=if(earliestseen >= relative_time(now(), "-24h@h") OR isnull(earliestseen), "First Time Logging into AWS Console", "Previously Seen User") -| where userStatus="First Time Logging into AWS Console" -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_aws_console_login_by_new_user_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **detect_aws_console_login_by_new_user_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Lookups -The SPL above uses the following Lookups: - -* [previously_seen_users_console_logins](https://github.com/splunk/security_content/blob/develop/lookups/previously_seen_users_console_logins.yml) with [data](https://github.com/splunk/security_content/tree/develop/lookups/previously_seen_users_console_logins.csv) - -#### Required field -* _time -* Authentication.signature -* Authentication.user - - -#### How To Implement -You must install and configure the Splunk Add-on for AWS (version 5.1.0 or later) and Enterprise Security 6.2, which contains the required updates to the Authentication data model for cloud use cases. Run the `Previously Seen Users in CloudTrail - Initial` support search only once to create a baseline of previously seen IAM users within the last 30 days. Run `Previously Seen Users in CloudTrail - Update` hourly (or more frequently depending on how often you run the detection searches) to refresh the baselines. - -#### Known False Positives -When a legitimate new user logins for the first time, this activity will be detected. Check how old the account is and verify that the user activity is legitimate. - -#### Associated Analytic story -* [Suspicious Cloud Authentication Activities](/stories/suspicious_cloud_authentication_activities) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 30.0 | 50 | 60 | User $user$ is logging into the AWS console for the first time | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/detect_aws_console_login_by_new_user.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-05-10-f5_big-ip_icontrol_rest_vulnerability_cve-2022-1388.md b/docs/_posts/2022-05-10-f5_big-ip_icontrol_rest_vulnerability_cve-2022-1388.md deleted file mode 100644 index 74fb6f8c97..0000000000 --- a/docs/_posts/2022-05-10-f5_big-ip_icontrol_rest_vulnerability_cve-2022-1388.md +++ /dev/null @@ -1,171 +0,0 @@ ---- -title: "F5 BIG-IP iControl REST Vulnerability CVE-2022-1388" -excerpt: "Exploit Public-Facing Application -" -categories: - - Network -last_modified_at: 2022-05-10 -toc: true -toc_label: "" -tags: - - Exploit Public-Facing Application - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2022-1388 - - Web ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies a recent unauthenticated remote code execution vulnerablity against the F5 BIG-IP iControl REST API. The analytic identifies the URI path found in the POCs and the HTTP Method of POST. In addition, the request header will have the commands that may be executed in fields utilcmdargs and the auth field of X-F5-Auth-Token, which may have a random base64 encoded value. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Web](https://docs.splunk.com/Documentation/CIM/latest/User/Web) -- **Last Updated**: 2022-05-10 -- **Author**: Michael Haag, Splunk -- **ID**: bb1c2c30-107a-4e56-a4b9-1f7022867bfe - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1190](https://attack.mitre.org/techniques/T1190/) | Exploit Public-Facing Application | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2022-1388](https://nvd.nist.gov/vuln/detail/CVE-2022-1388) | On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x versions, undisclosed requests may bypass iControl REST authentication. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | 7.5 | - - - -
-
- -#### Search - -``` - -| tstats count from datamodel=Web where Web.url="*/mgmt/tm/util/bash*" Web.http_method="POST" by Web.http_user_agent Web.http_method, Web.url,Web.url_length Web.src, Web.dest -| `drop_dm_object_name("Web")` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `f5_big_ip_icontrol_rest_vulnerability_cve_2022_1388_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **f5_big-ip_icontrol_rest_vulnerability_cve-2022-1388_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* Web.http_method -* Web.url -* Web.url_length -* Web.src -* Web.dest -* Web.http_user_agent - - -#### How To Implement -To successfully implement this search, you need to be ingesting web or proxy logs, or ensure it is being filled by a proxy like device, into the Web Datamodel. For additional filtering, allow list private IP space or restrict by known good. - -#### Known False Positives -False positives may be present if the activity is blocked or was not successful. Filter known vulnerablity scanners. Filter as needed. - -#### Associated Analytic story -* [F5 BIG-IP Vulnerability CVE-2022-1388](/stories/f5_big-ip_vulnerability_cve-2022-1388) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 70.0 | 100 | 70 | An attempt to exploit CVE-2022-1388 against an F5 appliance $dest$ has occurred. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/dk4trin/templates-nuclei/blob/main/CVE-2022-1388.yaml](https://github.com/dk4trin/templates-nuclei/blob/main/CVE-2022-1388.yaml) -* [https://www.randori.com/blog/vulnerability-analysis-cve-2022-1388/](https://www.randori.com/blog/vulnerability-analysis-cve-2022-1388/) -* [https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1388](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1388) -* [https://twitter.com/da_667/status/1523770267327250438?s=20&t=-JnB_aNWuJFsmcOmxGUWLQ](https://twitter.com/da_667/status/1523770267327250438?s=20&t=-JnB_aNWuJFsmcOmxGUWLQ) -* [https://github.com/horizon3ai/CVE-2022-1388/blob/main/CVE-2022-1388.py](https://github.com/horizon3ai/CVE-2022-1388/blob/main/CVE-2022-1388.py) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/f5/f5.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/f5/f5.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/network/f5_big_ip_icontrol_rest_vulnerability_cve_2022_1388.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-05-11-potential_password_in_username.md b/docs/_posts/2022-05-11-potential_password_in_username.md deleted file mode 100644 index b02953a543..0000000000 --- a/docs/_posts/2022-05-11-potential_password_in_username.md +++ /dev/null @@ -1,182 +0,0 @@ ---- -title: "Potential password in username" -excerpt: "Local Accounts -, Credentials In Files -" -categories: - - Endpoint -last_modified_at: 2022-05-11 -toc: true -toc_label: "" -tags: - - Local Accounts - - Credentials In Files - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Authentication ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search identifies users who have entered their passwords in username fields. This is done by looking for failed authentication attempts using usernames with a length longer than 7 characters and a high Shannon entropy, and looks for the next successful authentication attempt from the same source system to the same destination system as the failed attempt. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Authentication](https://docs.splunk.com/Documentation/CIM/latest/User/Authentication) -- **Last Updated**: 2022-05-11 -- **Author**: Mikael Bjerkeland, Splunk -- **ID**: 5ced34b4-ab32-4bb0-8f22-3b8f186f0a38 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1078.003](https://attack.mitre.org/techniques/T1078/003/) | Local Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -| [T1552.001](https://attack.mitre.org/techniques/T1552/001/) | Credentials In Files | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` earliest(_time) AS starttime latest(_time) AS endtime latest(sourcetype) AS sourcetype values(Authentication.src) AS src values(Authentication.dest) AS dest count FROM datamodel=Authentication WHERE nodename=Authentication.Failed_Authentication BY "Authentication.user" -| `drop_dm_object_name(Authentication)` -| lookup ut_shannon_lookup word AS user -| where ut_shannon>3 AND len(user)>=8 AND mvcount(src) == 1 -| sort count, - ut_shannon -| eval incorrect_password=user -| eval endtime=endtime+1000 -| map maxsearches=70 search=" -| tstats `security_content_summariesonly` earliest(_time) AS starttime latest(_time) AS endtime latest(sourcetype) AS sourcetype values(Authentication.src) AS src values(Authentication.dest) AS dest count FROM datamodel=Authentication WHERE nodename=Authentication.Successful_Authentication Authentication.src=\"$src$\" Authentication.dest=\"$dest$\" sourcetype IN (\"$sourcetype$\") earliest=\"$starttime$\" latest=\"$endtime$\" BY \"Authentication.user\" -| `drop_dm_object_name(\"Authentication\")` -| `potential_password_in_username_false_positive_reduction` -| eval incorrect_password=\"$incorrect_password$\" -| eval ut_shannon=\"$ut_shannon$\" -| sort count" -| where user!=incorrect_password -| outlier action=RM count -| `potential_password_in_username_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [potential_password_in_username_false_positive_reduction](https://github.com/splunk/security_content/blob/develop/macros/potential_password_in_username_false_positive_reduction.yml) - -> :information_source: -> **potential_password_in_username_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* Authentication.user -* Authentication.src -* Authentication.dest -* sourcetype - - -#### How To Implement -To successfully implement this search, you need to have relevant authentication logs mapped to the Authentication data model. You also need to have the Splunk TA URL Toolbox (https://splunkbase.splunk.com/app/2734/) installed. The detection must run with a time interval shorter than endtime+1000. - -#### Known False Positives -Valid usernames with high entropy or source/destination system pairs with multiple authenticating users will make it difficult to identify the real user authenticating. - -#### Associated Analytic story -* [Credential Dumping](/stories/credential_dumping) -* [Insider Threat](/stories/insider_threat) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 21.0 | 30 | 70 | Potential password in username ($user$) with Shannon entropy ($ut_shannon$) | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://medium.com/@markmotig/search-for-passwords-accidentally-typed-into-the-username-field-975f1a389928](https://medium.com/@markmotig/search-for-passwords-accidentally-typed-into-the-username-field-975f1a389928) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1552.001/password_in_username/linux_secure.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1552.001/password_in_username/linux_secure.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/potential_password_in_username.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-05-16-cobalt_strike_named_pipes.md b/docs/_posts/2022-05-16-cobalt_strike_named_pipes.md deleted file mode 100644 index 2f657018cd..0000000000 --- a/docs/_posts/2022-05-16-cobalt_strike_named_pipes.md +++ /dev/null @@ -1,171 +0,0 @@ ---- -title: "Cobalt Strike Named Pipes" -excerpt: "Process Injection -" -categories: - - Endpoint -last_modified_at: 2022-05-16 -toc: true -toc_label: "" -tags: - - Process Injection - - Defense Evasion - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the use of default or publicly known named pipes used with Cobalt Strike. A named pipe is a named, one-way or duplex pipe for communication between the pipe server and one or more pipe clients. Cobalt Strike uses named pipes in many ways and has default values used with the Artifact Kit and Malleable C2 Profiles. The following query assists with identifying these default named pipes. Each EDR product presents named pipes a little different. Consider taking the values and generating a query based on the product of choice. \ -Upon triage, review the process performing the named pipe. If it is explorer.exe, It is possible it was injected into by another process. Review recent parallel processes to identify suspicious patterns or behaviors. A parallel process may have a network connection, review and follow the connection back to identify any file modifications. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-05-16 -- **Author**: Michael Haag, Splunk -- **ID**: 5876d429-0240-4709-8b93-ea8330b411b5 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1055](https://attack.mitre.org/techniques/T1055/) | Process Injection | Defense Evasion, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventID=17 OR EventID=18 PipeName IN (\\msagent_*, \\DserNamePipe*, \\srvsvc_*, \\postex_*, \\status_*, \\MSSE-*, \\spoolss_*, \\win_svc*, \\ntsvcs*, \\winsock*, \\UIA_PIPE*) -| stats count min(_time) as firstTime max(_time) as lastTime by Computer, process_name, process_id process_path, PipeName -| rename Computer as dest -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `cobalt_strike_named_pipes_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **cobalt_strike_named_pipes_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventID -* PipeName -* Computer -* process_name -* process_path -* process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -The idea of using named pipes with Cobalt Strike is to blend in. Therefore, some of the named pipes identified and added may cause false positives. Filter by process name or pipe name to reduce false positives. - -#### Associated Analytic story -* [Cobalt Strike](/stories/cobalt_strike) -* [Trickbot](/stories/trickbot) -* [DarkSide Ransomware](/stories/darkside_ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 72.0 | 80 | 90 | An instance of $process_name$ was identified on endpoint $Computer$ by user $user$ accessing known suspicious named pipes related to Cobalt Strike. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1218/009/](https://attack.mitre.org/techniques/T1218/009/) -* [https://docs.microsoft.com/en-us/windows/win32/ipc/named-pipes](https://docs.microsoft.com/en-us/windows/win32/ipc/named-pipes) -* [https://hstechdocs.helpsystems.com/manuals/cobaltstrike/current/userguide/index.htm#cshid=1040](https://hstechdocs.helpsystems.com/manuals/cobaltstrike/current/userguide/index.htm#cshid=1040) -* [https://www.cobaltstrike.com/blog/learn-pipe-fitting-for-all-of-your-offense-projects/](https://www.cobaltstrike.com/blog/learn-pipe-fitting-for-all-of-your-offense-projects/) -* [https://gist.github.com/MHaggis/6c600e524045a6d49c35291a21e10752](https://gist.github.com/MHaggis/6c600e524045a6d49c35291a21e10752) -* [https://www.mandiant.com/resources/shining-a-light-on-darkside-ransomware-operations](https://www.mandiant.com/resources/shining-a-light-on-darkside-ransomware-operations) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/cobalt_strike_named_pipes.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-05-16-windows_system_file_on_disk.md b/docs/_posts/2022-05-16-windows_system_file_on_disk.md deleted file mode 100644 index a4469a0c63..0000000000 --- a/docs/_posts/2022-05-16-windows_system_file_on_disk.md +++ /dev/null @@ -1,167 +0,0 @@ ---- -title: "Windows System File on Disk" -excerpt: "Exploitation for Privilege Escalation -" -categories: - - Endpoint -last_modified_at: 2022-05-16 -toc: true -toc_label: "" -tags: - - Exploitation for Privilege Escalation - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following hunting analytic will assist with identifying new .sys files introduced in the environment. This query is meant to identify sys file creates on disk. There will be noise, but reducing common process names or applications should help to limit any volume. The idea is to identify new sys files written to disk and identify them before they're added as a new kernel mode driver. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-05-16 -- **Author**: Michael Haag, Splunk -- **ID**: 993ce99d-9cdd-42c7-a2cf-733d5954e5a6 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1068](https://attack.mitre.org/techniques/T1068/) | Exploitation for Privilege Escalation | Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Delivery - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_name="*.sys*" by _time span=1h Filesystem.dest Filesystem.file_create_time Filesystem.file_name Filesystem.file_path Filesystem.file_hash -| `drop_dm_object_name(Filesystem)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_system_file_on_disk_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_system_file_on_disk_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on files from your endpoints into the `Endpoint` datamodel in the `Filesystem` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. In addition, filtering may occur by adding NOT (Filesystem.file_path IN ("*\\Windows\\*", "*\\Program File*", "*\\systemroot\\*","%SystemRoot%*", "system32\*")). This will level out the noise generated to potentally lead to generating notables. - -#### Known False Positives -False positives will be present. Filter as needed. - -#### Associated Analytic story -* [Windows Drivers](/stories/windows_drivers) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 10.0 | 20 | 50 | A new driver is present on $dest$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://redcanary.com/blog/tracking-driver-inventory-to-expose-rootkits/](https://redcanary.com/blog/tracking-driver-inventory-to-expose-rootkits/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1068/drivers/sysmon_sys_filemod.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1068/drivers/sysmon_sys_filemod.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_system_file_on_disk.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-05-17-aws_create_policy_version_to_allow_all_resources.md b/docs/_posts/2022-05-17-aws_create_policy_version_to_allow_all_resources.md deleted file mode 100644 index a393a209b4..0000000000 --- a/docs/_posts/2022-05-17-aws_create_policy_version_to_allow_all_resources.md +++ /dev/null @@ -1,181 +0,0 @@ ---- -title: "AWS Create Policy Version to allow all resources" -excerpt: "Cloud Accounts -, Valid Accounts -" -categories: - - Cloud -last_modified_at: 2022-05-17 -toc: true -toc_label: "" -tags: - - Cloud Accounts - - Valid Accounts - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for AWS CloudTrail events where a user created a policy version that allows them to access any resource in their account. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-05-17 -- **Author**: Bhavin Patel, Splunk -- **ID**: 2a9b80d3-6340-4345-b5ad-212bf3d0dac4 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1078.004](https://attack.mitre.org/techniques/T1078/004/) | Cloud Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.DS -* PR.AC -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 13 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cloudtrail` eventName=CreatePolicyVersion eventSource = iam.amazonaws.com errorCode = success -| spath input=requestParameters.policyDocument output=key_policy_statements path=Statement{} -| mvexpand key_policy_statements -| spath input=key_policy_statements output=key_policy_action_1 path=Action -| where key_policy_action_1 = "*" -| stats count min(_time) as firstTime max(_time) as lastTime values(key_policy_statements) as policy_added by eventName eventSource aws_account_id errorCode userAgent eventID awsRegion user user_arn -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -|`aws_create_policy_version_to_allow_all_resources_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) - -> :information_source: -> **aws_create_policy_version_to_allow_all_resources_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* eventName -* userAgent -* errorCode -* eventSource -* requestParameters.userName -* requestParameters.policyDocument -* aws_account_id -* awsRegion -* eventID - - -#### How To Implement -You must install splunk AWS add on and Splunk App for AWS. This search works with AWS CloudTrail logs. - -#### Known False Positives -While this search has no known false positives, it is possible that an AWS admin has legitimately created a policy to allow a user to access all resources. That said, AWS strongly advises against granting full control to all AWS resources and you must verify this activity. - -#### Associated Analytic story -* [AWS IAM Privilege Escalation](/stories/aws_iam_privilege_escalation) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | User $user$ created a policy version that allows them to access any resource in their account. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://bishopfox.com/blog/privilege-escalation-in-aws](https://bishopfox.com/blog/privilege-escalation-in-aws) -* [https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation-part-2/](https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation-part-2/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_create_policy_version/aws_cloudtrail_events.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_create_policy_version/aws_cloudtrail_events.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2022-05-19-vmware_server_side_template_injection_hunt.md b/docs/_posts/2022-05-19-vmware_server_side_template_injection_hunt.md deleted file mode 100644 index 15d64bc64e..0000000000 --- a/docs/_posts/2022-05-19-vmware_server_side_template_injection_hunt.md +++ /dev/null @@ -1,172 +0,0 @@ ---- -title: "VMware Server Side Template Injection Hunt" -excerpt: "Exploit Public-Facing Application -" -categories: - - Web -last_modified_at: 2022-05-19 -toc: true -toc_label: "" -tags: - - Exploit Public-Facing Application - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2022-22954 - - Web ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following hunting analytic identifies the server side template injection related to CVE-2022-22954, however is a variation found within the same endpoint of the URL scheme. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Web](https://docs.splunk.com/Documentation/CIM/latest/User/Web) -- **Last Updated**: 2022-05-19 -- **Author**: Michael Haag, Splunk -- **ID**: 5796b570-ad12-44df-b1b5-b7e6ae3aabb0 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1190](https://attack.mitre.org/techniques/T1190/) | Exploit Public-Facing Application | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2022-22954](https://nvd.nist.gov/vuln/detail/CVE-2022-22954) | VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code execution. | 10.0 | - - - -
-
- -#### Search - -``` - -| tstats count from datamodel=Web where Web.http_method IN ("GET") Web.url="*deviceudid=*" AND Web.url IN ("*java.lang.ProcessBuilder*","*freemarker.template.utility.ObjectConstructor*") by Web.http_user_agent Web.http_method, Web.url,Web.url_length Web.src, Web.dest sourcetype -| `drop_dm_object_name("Web")` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `vmware_server_side_template_injection_hunt_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **vmware_server_side_template_injection_hunt_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* Web.http_method -* Web.url -* Web.url_length -* Web.src -* Web.dest -* Web.http_user_agent - - -#### How To Implement -To successfully implement this search, you need to be ingesting web or proxy logs, or ensure it is being filled by a proxy like device, into the Web Datamodel. For additional filtering, allow list private IP space or restrict by known good. - -#### Known False Positives -False positives may be present if the activity is blocked or was not successful. Filter known vulnerablity scanners. Filter as needed. - -#### Associated Analytic story -* [VMware Server Side Injection and Privilege Escalation](/stories/vmware_server_side_injection_and_privilege_escalation) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 35.0 | 70 | 50 | An attempt to exploit a VMware Server Side Injection CVE-2022-22954 on $dest$ has occurred. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.cisa.gov/uscert/ncas/alerts/aa22-138b](https://www.cisa.gov/uscert/ncas/alerts/aa22-138b) -* [https://github.com/wvu/metasploit-framework/blob/master/modules/exploits/linux/http/vmware_workspace_one_access_cve_2022_22954.rb](https://github.com/wvu/metasploit-framework/blob/master/modules/exploits/linux/http/vmware_workspace_one_access_cve_2022_22954.rb) -* [https://github.com/sherlocksecurity/VMware-CVE-2022-22954](https://github.com/sherlocksecurity/VMware-CVE-2022-22954) -* [https://www.vmware.com/security/advisories/VMSA-2022-0011.html](https://www.vmware.com/security/advisories/VMSA-2022-0011.html) -* [https://attackerkb.com/topics/BDXyTqY1ld/cve-2022-22954/rapid7-analysis](https://attackerkb.com/topics/BDXyTqY1ld/cve-2022-22954/rapid7-analysis) -* [https://twitter.com/wvuuuuuuuuuuuuu/status/1519476924757778433](https://twitter.com/wvuuuuuuuuuuuuu/status/1519476924757778433) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/vmware/vmware_scanning_pan_threat.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/vmware/vmware_scanning_pan_threat.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/web/vmware_server_side_template_injection_hunt.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-05-19-vmware_workspace_one_freemarker_server-side_template_injection.md b/docs/_posts/2022-05-19-vmware_workspace_one_freemarker_server-side_template_injection.md deleted file mode 100644 index c0a4a1ccdd..0000000000 --- a/docs/_posts/2022-05-19-vmware_workspace_one_freemarker_server-side_template_injection.md +++ /dev/null @@ -1,171 +0,0 @@ ---- -title: "VMware Workspace ONE Freemarker Server-side Template Injection" -excerpt: "Exploit Public-Facing Application -" -categories: - - Web -last_modified_at: 2022-05-19 -toc: true -toc_label: "" -tags: - - Exploit Public-Facing Application - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2022-22954 - - Web ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the server side template injection related to CVE-2022-22954. Based on the scanning activity across the internet and proof of concept code available the template injection occurs at catalog-portal/ui/oauth/verify?error=&deviceudid=. Upon triage, review parallel processes and VMware logs. Following the deviceudid= may be a command to be executed. Capture any file creates and review modified files on disk. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Web](https://docs.splunk.com/Documentation/CIM/latest/User/Web) -- **Last Updated**: 2022-05-19 -- **Author**: Michael Haag, Splunk -- **ID**: 9e5726fe-8fde-460e-bd74-cddcf6c86113 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1190](https://attack.mitre.org/techniques/T1190/) | Exploit Public-Facing Application | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2022-22954](https://nvd.nist.gov/vuln/detail/CVE-2022-22954) | VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code execution. | 10.0 | - - - -
-
- -#### Search - -``` - -| tstats count from datamodel=Web where Web.http_method IN ("GET") Web.url="*/catalog-portal/ui/oauth/verify?error=&deviceudid=*" AND Web.url="*freemarker.template.utility.Execute*" by Web.http_user_agent Web.http_method, Web.url,Web.url_length Web.src, Web.dest sourcetype -| `drop_dm_object_name("Web")` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `vmware_workspace_one_freemarker_server_side_template_injection_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **vmware_workspace_one_freemarker_server-side_template_injection_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* Web.http_method -* Web.url -* Web.url_length -* Web.src -* Web.dest -* Web.http_user_agent - - -#### How To Implement -To successfully implement this search, you need to be ingesting web or proxy logs, or ensure it is being filled by a proxy like device, into the Web Datamodel. For additional filtering, allow list private IP space or restrict by known good. - -#### Known False Positives -False positives may be present if the activity is blocked or was not successful. Filter known vulnerablity scanners. Filter as needed. - -#### Associated Analytic story -* [VMware Server Side Injection and Privilege Escalation](/stories/vmware_server_side_injection_and_privilege_escalation) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | An attempt to exploit a VMware Server Side Injection CVE-2022-22954 on $dest$ has occurred. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.cisa.gov/uscert/ncas/alerts/aa22-138b](https://www.cisa.gov/uscert/ncas/alerts/aa22-138b) -* [https://github.com/wvu/metasploit-framework/blob/master/modules/exploits/linux/http/vmware_workspace_one_access_cve_2022_22954.rb](https://github.com/wvu/metasploit-framework/blob/master/modules/exploits/linux/http/vmware_workspace_one_access_cve_2022_22954.rb) -* [https://github.com/sherlocksecurity/VMware-CVE-2022-22954](https://github.com/sherlocksecurity/VMware-CVE-2022-22954) -* [https://www.vmware.com/security/advisories/VMSA-2022-0011.html](https://www.vmware.com/security/advisories/VMSA-2022-0011.html) -* [https://attackerkb.com/topics/BDXyTqY1ld/cve-2022-22954/rapid7-analysis](https://attackerkb.com/topics/BDXyTqY1ld/cve-2022-22954/rapid7-analysis) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/vmware/vmware_scanning_pan_threat.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/vmware/vmware_scanning_pan_threat.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/web/vmware_workspace_one_freemarker_server_side_template_injection.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-05-23-schtasks_scheduling_job_on_remote_system.md b/docs/_posts/2022-05-23-schtasks_scheduling_job_on_remote_system.md deleted file mode 100644 index faa65f5472..0000000000 --- a/docs/_posts/2022-05-23-schtasks_scheduling_job_on_remote_system.md +++ /dev/null @@ -1,169 +0,0 @@ ---- -title: "Schtasks scheduling job on remote system" -excerpt: "Scheduled Task -, Scheduled Task/Job -" -categories: - - Endpoint -last_modified_at: 2022-05-23 -toc: true -toc_label: "" -tags: - - Scheduled Task - - Scheduled Task/Job - - Execution - - Persistence - - Privilege Escalation - - Execution - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for the execution of `schtasks.exe` with command-line arguments utilized to create a Scheduled Task on a remote endpoint. Red Teams and adversaries alike may abuse the Task Scheduler for lateral movement and remote code execution. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-05-23 -- **Author**: David Dorsey, Mauricio Velazco, Splunk -- **ID**: 1297fb80-f42a-4b4a-9c8a-88c066237cf6 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1053.005](https://attack.mitre.org/techniques/T1053/005/) | Scheduled Task | Execution, Persistence, Privilege Escalation | - -| [T1053](https://attack.mitre.org/techniques/T1053/) | Scheduled Task/Job | Execution, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.IP - - - -
-
- -
- CIS20 - -
- -* CIS 3 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name = schtasks.exe OR Processes.original_file_name=schtasks.exe) (Processes.process="*/create*" AND Processes.process="*/s*") by Processes.process_name Processes.process Processes.parent_process_name Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `schtasks_scheduling_job_on_remote_system_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **schtasks_scheduling_job_on_remote_system_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process_name -* Processes.process -* Processes.parent_process_name -* Processes.dest -* Processes.user - - -#### How To Implement -You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. - -#### Known False Positives -Administrators may create scheduled tasks on remote systems, but this activity is usually limited to a small set of hosts or users. It is important to validate and investigate as appropriate. - -#### Associated Analytic story -* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) -* [NOBELIUM Group](/stories/nobelium_group) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 63.0 | 70 | 90 | A schedule task process $process_name$ with remote job command-line $process$ in host $dest$ by $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml) \| *version*: **6** \ No newline at end of file diff --git a/docs/_posts/2022-05-23-splunk_command_and_scripting_interpreter_risky_commands.md b/docs/_posts/2022-05-23-splunk_command_and_scripting_interpreter_risky_commands.md deleted file mode 100644 index c0228632f6..0000000000 --- a/docs/_posts/2022-05-23-splunk_command_and_scripting_interpreter_risky_commands.md +++ /dev/null @@ -1,181 +0,0 @@ ---- -title: "Splunk Command and Scripting Interpreter Risky Commands" -excerpt: "Command and Scripting Interpreter -" -categories: - - Application -last_modified_at: 2022-05-23 -toc: true -toc_label: "" -tags: - - Command and Scripting Interpreter - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2022-32154 - - Splunk_Audit ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The Splunk platform contains built-in search processing language (SPL) safeguards to warn you when you are about to unknowingly run a search that contains commands that might be a security risk. This warning appears when you click a link or type a URL that loads a search that contains risky commands. The warning does not appear when you create ad hoc searches. This warning alerts you to the possibility of unauthorized actions by a malicious user. Unauthorized actions include - Copying or transferring data (data exfiltration), Deleting data and Overwriting data. All risky commands may be found here https://docs.splunk.com/Documentation/Splunk/latest/Security/SPLsafeguards#Commands_that_trigger_the_warninga. A possible scenario when this might occur is when a malicious actor creates a search that includes commands that exfiltrate or damage data. The malicious actor then sends an unsuspecting user a link to the search. The URL contains a query string (q) and a search identifier (sid), but the sid is not valid. The malicious actor hopes the user will use the link and the search will run. During analysis, pivot based on user name and filter any user or queries not needed. Queries ran from a dashboard are seen as adhoc queries. When a query runs from a dashboard it will not show in audittrail logs the source dashboard name. The query defaults to adhoc and no Splunk system user activity. In addition, modify this query by removing key commands that generate too much noise, or too little, and create separate queries with higher confidence to alert on. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Splunk_Audit](https://docs.splunk.com/Documentation/CIM/latest/User/SplunkAudit) -- **Last Updated**: 2022-05-23 -- **Author**: Michael Haag, Splunk -- **ID**: 1cf58ae1-9177-40b8-a26c-8966040f11ae - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2022-32154](https://nvd.nist.gov/vuln/detail/CVE-2022-32154) | Dashboards in Splunk Enterprise versions before 9.0 might let an attacker inject risky search commands into a form token when the token is used in a query in a cross-origin request. The result bypasses SPL safeguards for risky commands. See New capabilities can limit access to some custom and potentially risky commands (https://docs.splunk.com/Documentation/Splunk/9.0.0/Security/SPLsafeguards#New_capabilities_can_limit_access_to_some_custom_and_potentially_risky_commands) for more information. Note that the attack is browser-based and an attacker cannot exploit it at will. | 4.0 | - - - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Splunk_Audit.Search_Activity where Search_Activity.search IN ("* -| runshellscript *", "* -| collect *","* -| delete *", "* -| fit *", "* -| outputcsv *", "* -| outputlookup *", "* -| run *", "* -| script *", "* -| sendalert *", "* -| sendemail *", "* -| tscolle*") Search_Activity.search_type=adhoc Search_Activity.user!=splunk-system-user by Search_Activity.search Search_Activity.info Search_Activity.total_run_time Search_Activity.user Search_Activity.search_type -| `drop_dm_object_name(Search_Activity)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `splunk_command_and_scripting_interpreter_risky_commands_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **splunk_command_and_scripting_interpreter_risky_commands_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Search_Activity.search -* Search_Activity.info -* Search_Activity.total_run_time -* Search_Activity.user -* Search_Activity.savedsearch_name -* Search_Activity.search_type - - -#### How To Implement -To successfully implement this search acceleration is recommended against the Search_Activity datamodel that runs against the splunk _audit index. In addition, this analytic requires the Common Information Model App which includes the Splunk Audit Datamodel https://splunkbase.splunk.com/app/1621/. Splunk SOAR customers can find a SOAR workbook that walks an analyst through the process of running these hunting searches in the references list of this detection. In order to use this workbook, a user will need to run a curl command to post the file to their SOAR instance such as "curl -u username:password https://soar.instance.name/rest/rest/workbook_template -d @splunk_psa_0622.json". A user should then create an empty container or case, attach the workbook, and begin working through the tasks. - -#### Known False Positives -False positives will be present until properly filtered by Username and search name. - -#### Associated Analytic story -* [Splunk Vulnerabilities](/stories/splunk_vulnerabilities) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 20.0 | 50 | 40 | A risky Splunk command has ran by $user$ and should be reviewed. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://docs.splunk.com/Documentation/Splunk/latest/Security/SPLsafeguards#Commands_that_trigger_the_warning](https://docs.splunk.com/Documentation/Splunk/latest/Security/SPLsafeguards#Commands_that_trigger_the_warning) -* [https://www.github.com/splunk/security_content/blob/develop/workbooks/splunk_psa_0622.json](https://www.github.com/splunk/security_content/blob/develop/workbooks/splunk_psa_0622.json) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1213/audittrail/audittrail.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1213/audittrail/audittrail.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/application/splunk_command_and_scripting_interpreter_risky_commands.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-05-24-splunk_protocol_impersonation_weak_encryption_simplerequest.md b/docs/_posts/2022-05-24-splunk_protocol_impersonation_weak_encryption_simplerequest.md deleted file mode 100644 index f5092f9ff3..0000000000 --- a/docs/_posts/2022-05-24-splunk_protocol_impersonation_weak_encryption_simplerequest.md +++ /dev/null @@ -1,162 +0,0 @@ ---- -title: "Splunk protocol impersonation weak encryption simplerequest" -excerpt: "Digital Certificates -" -categories: - - Application -last_modified_at: 2022-05-24 -toc: true -toc_label: "" -tags: - - Digital Certificates - - Resource Development - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2022-32152 ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -On Splunk version 9 on Python3 client libraries verify server certificates by default and use CA certificate store. This search warns a user about a failure to validate a certificate using python3 request. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-05-24 -- **Author**: Rod Soto, Splunk -- **ID**: 839d12a6-b119-4d44-ac4f-13eed95412c8 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1588.004](https://attack.mitre.org/techniques/T1588/004/) | Digital Certificates | Resource Development | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2022-32152](https://nvd.nist.gov/vuln/detail/CVE-2022-32152) | Splunk Enterprise peers in Splunk Enterprise versions before 9.0 and Splunk Cloud Platform versions before 8.2.2203 did not validate the TLS certificates during Splunk-to-Splunk communications by default. Splunk peer communications configured properly with valid certificates were not vulnerable. However, an attacker with administrator credentials could add a peer without a valid certificate and connections from misconfigured nodes without valid certificates did not fail by default. For Splunk Enterprise, update to Splunk Enterprise version 9.0 and Configure TLS host name validation for Splunk-to-Splunk communications (https://docs.splunk.com/Documentation/Splunk/9.0.0/Security/EnableTLSCertHostnameValidation) to enable the remediation. | 6.5 | - - - -
-
- -#### Search - -``` -`splunk_python` "simpleRequest SSL certificate validation is enabled without hostname verification" -| stats count by host path -| `splunk_protocol_impersonation_weak_encryption_simplerequest_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [splunk_python](https://github.com/splunk/security_content/blob/develop/macros/splunk_python.yml) - -> :information_source: -> **splunk_protocol_impersonation_weak_encryption_simplerequest_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* host -* event_message -* path - - -#### How To Implement -Must upgrade to Splunk version 9 and Configure TLS host name validation for Splunk Python modules in order to apply this search. Splunk SOAR customers can find a SOAR workbook that walks an analyst through the process of running these hunting searches in the references list of this detection. In order to use this workbook, a user will need to run a curl command to post the file to their SOAR instance such as "curl -u username:password https://soar.instance.name/rest/rest/workbook_template -d @splunk_psa_0622.json". A user should then create an empty container or case, attach the workbook, and begin working through the tasks. - -#### Known False Positives -This search tries to address validation of server and client certificates within Splunk infrastructure, it might produce results from accidental or unintended requests to port 8089. - -#### Associated Analytic story -* [Splunk Vulnerabilities](/stories/splunk_vulnerabilities) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 40.0 | 50 | 80 | Failed to validate certificate on $host$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.splunk.com/en_us/product-security](https://www.splunk.com/en_us/product-security) -* [https://docs.splunk.com/Documentation/Splunk/9.0.0/Security/EnableTLSCertHostnameValidation](https://docs.splunk.com/Documentation/Splunk/9.0.0/Security/EnableTLSCertHostnameValidation) -* [https://www.github.com/splunk/security_content/blob/develop/workbooks/splunk_psa_0622.json](https://www.github.com/splunk/security_content/blob/develop/workbooks/splunk_psa_0622.json) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://raw.githubusercontent.com/splunk/attack_data/master/datasets/attack_techniques/T1558.004/splk_protocol_impersonation_weak_encryption_simplerequest.txt](https://raw.githubusercontent.com/splunk/attack_data/master/datasets/attack_techniques/T1558.004/splk_protocol_impersonation_weak_encryption_simplerequest.txt) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/application/splunk_protocol_impersonation_weak_encryption_simplerequest.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-05-25-splunk_identified_ssl_tls_certificates.md b/docs/_posts/2022-05-25-splunk_identified_ssl_tls_certificates.md deleted file mode 100644 index 84ec1d7f32..0000000000 --- a/docs/_posts/2022-05-25-splunk_identified_ssl_tls_certificates.md +++ /dev/null @@ -1,166 +0,0 @@ ---- -title: "Splunk Identified SSL TLS Certificates" -excerpt: "Network Sniffing -" -categories: - - Network -last_modified_at: 2022-05-25 -toc: true -toc_label: "" -tags: - - Network Sniffing - - Credential Access - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2022-32151 - - CVE-2022-32152 ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic uses tags of SSL, TLS and certificate to identify the usage of the Splunk default certificates being utilized in the environment. Recommended guidance is to utilize valid TLS certificates which documentation may be found in Splunk Docs - https://docs.splunk.com/Documentation/Splunk/8.2.6/Security/AboutsecuringyourSplunkconfigurationwithSSL. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-05-25 -- **Author**: Michael Haag, Splunk -- **ID**: 620fbb89-86fd-4e2e-925f-738374277586 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1040](https://attack.mitre.org/techniques/T1040/) | Network Sniffing | Credential Access, Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2022-32151](https://nvd.nist.gov/vuln/detail/CVE-2022-32151) | The httplib and urllib Python libraries that Splunk shipped with Splunk Enterprise did not validate certificates using the certificate authority (CA) certificate stores by default in Splunk Enterprise versions before 9.0 and Splunk Cloud Platform versions before 8.2.2203. Python 3 client libraries now verify server certificates by default and use the appropriate CA certificate stores for each library. Apps and add-ons that include their own HTTP libraries are not affected. For Splunk Enterprise, update to Splunk Enterprise version 9.0 and Configure TLS host name validation for Splunk-to-Splunk communications (https://docs.splunk.com/Documentation/Splunk/9.0.0/Security/EnableTLSCertHostnameValidation) to enable the remediation. | 6.4 | -| [CVE-2022-32152](https://nvd.nist.gov/vuln/detail/CVE-2022-32152) | Splunk Enterprise peers in Splunk Enterprise versions before 9.0 and Splunk Cloud Platform versions before 8.2.2203 did not validate the TLS certificates during Splunk-to-Splunk communications by default. Splunk peer communications configured properly with valid certificates were not vulnerable. However, an attacker with administrator credentials could add a peer without a valid certificate and connections from misconfigured nodes without valid certificates did not fail by default. For Splunk Enterprise, update to Splunk Enterprise version 9.0 and Configure TLS host name validation for Splunk-to-Splunk communications (https://docs.splunk.com/Documentation/Splunk/9.0.0/Security/EnableTLSCertHostnameValidation) to enable the remediation. | 6.5 | - - - -
-
- -#### Search - -``` -tag IN (ssl, tls, certificate) ssl_issuer_common_name=*splunk* -| stats values(src) AS "Host(s) with Default Cert" count by ssl_issuer ssl_subject_common_name ssl_subject_organization ssl_subject host sourcetype -| `splunk_identified_ssl_tls_certificates_filter` -``` - -#### Macros -The SPL above uses the following Macros: - -> :information_source: -> **splunk_identified_ssl_tls_certificates_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* ssl_issuer -* ssl_subject_common_name -* ssl_subject_organization -* ssl_subject -* host -* sourcetype - - -#### How To Implement -Ingestion of SSL/TLS data is needed and to be tagged properly as ssl, tls or certificate. This data may come from a proxy, zeek, or Splunk Streams. Splunk SOAR customers can find a SOAR workbook that walks an analyst through the process of running these hunting searches in the references list of this detection. In order to use this workbook, a user will need to run a curl command to post the file to their SOAR instance such as "curl -u username:password https://soar.instance.name/rest/rest/workbook_template -d @splunk_psa_0622.json". A user should then create an empty container or case, attach the workbook, and begin working through the tasks. - -#### Known False Positives -False positives will not be present as it is meant to assist with identifying default certificates being utilized. - -#### Associated Analytic story -* [Splunk Vulnerabilities](/stories/splunk_vulnerabilities) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 42.0 | 60 | 70 | The following $dest$ is using the self signed Splunk certificate. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://docs.splunk.com/Documentation/Splunk/8.2.6/Security/AboutsecuringyourSplunkconfigurationwithSSL](https://docs.splunk.com/Documentation/Splunk/8.2.6/Security/AboutsecuringyourSplunkconfigurationwithSSL) -* [https://www.github.com/splunk/security_content/blob/develop/workbooks/splunk_psa_0622.json](https://www.github.com/splunk/security_content/blob/develop/workbooks/splunk_psa_0622.json) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1040/ssltls/ssl_splunk.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1040/ssltls/ssl_splunk.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/network/splunk_identified_ssl_tls_certificates.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-05-25-splunk_protocol_impersonation_weak_encryption_configuration.md b/docs/_posts/2022-05-25-splunk_protocol_impersonation_weak_encryption_configuration.md deleted file mode 100644 index b89c0105ee..0000000000 --- a/docs/_posts/2022-05-25-splunk_protocol_impersonation_weak_encryption_configuration.md +++ /dev/null @@ -1,167 +0,0 @@ ---- -title: "Splunk Protocol Impersonation Weak Encryption Configuration" -excerpt: "Protocol Impersonation -" -categories: - - Application -last_modified_at: 2022-05-25 -toc: true -toc_label: "" -tags: - - Protocol Impersonation - - Command And Control - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2022-32151 ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -On June 14th, 2022, Splunk released a security advisory relating to TLS validation occuring within the httplib and urllib python libraries shipped with Splunk. In addition to upgrading to Splunk Enterprise 9.0 or later, several configuration settings need to be set. This search will check those configurations on the search head it is run from as well as its search peers. In addition to these settings, the PYTHONHTTPSVERIFY setting in $SPLUNK_HOME/etc/splunk-launch.conf needs to be enabled as well. Other components such as additional search heads or anything this rest command cannot be distributed to will need to be manually checked. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-05-25 -- **Author**: Lou Stella, Splunk -- **ID**: 900892bf-70a9-4787-8c99-546dd98ce461 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1001.003](https://attack.mitre.org/techniques/T1001/003/) | Protocol Impersonation | Command And Control | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2022-32151](https://nvd.nist.gov/vuln/detail/CVE-2022-32151) | The httplib and urllib Python libraries that Splunk shipped with Splunk Enterprise did not validate certificates using the certificate authority (CA) certificate stores by default in Splunk Enterprise versions before 9.0 and Splunk Cloud Platform versions before 8.2.2203. Python 3 client libraries now verify server certificates by default and use the appropriate CA certificate stores for each library. Apps and add-ons that include their own HTTP libraries are not affected. For Splunk Enterprise, update to Splunk Enterprise version 9.0 and Configure TLS host name validation for Splunk-to-Splunk communications (https://docs.splunk.com/Documentation/Splunk/9.0.0/Security/EnableTLSCertHostnameValidation) to enable the remediation. | 6.4 | - - - -
-
- -#### Search - -``` - -| rest /services/server/info -| table splunk_server version server_roles -| join splunk_server [ -| rest /servicesNS/nobody/search/configs/conf-server/ search="PythonSslClientConfig" -| table splunk_server sslVerifyServerCert sslVerifyServerName] -| join splunk_server [ -| rest /servicesNS/nobody/search/configs/conf-web/settings -| table splunk_server serverCert sslVersions] -| rename sslVerifyServerCert as "Server.conf:PythonSSLClientConfig:sslVerifyServerCert", sslVerifyServerName as "Server.conf:PythonSSLClientConfig:sslVerifyServerName", serverCert as "Web.conf:Settings:serverCert", sslVersions as "Web.conf:Settings:sslVersions" -| `splunk_protocol_impersonation_weak_encryption_configuration_filter` -``` - -#### Macros -The SPL above uses the following Macros: - -> :information_source: -> **splunk_protocol_impersonation_weak_encryption_configuration_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* none - - -#### How To Implement -The user running this search is required to have a permission allowing them to dispatch REST requests to indexers (The `dispatch_rest_to_indexers` capability). Splunk SOAR customers can find a SOAR workbook that walks an analyst through the process of running these hunting searches in the references list of this detection. In order to use this workbook, a user will need to run a curl command to post the file to their SOAR instance such as "curl -u username:password https://soar.instance.name/rest/rest/workbook_template -d @splunk_psa_0622.json". A user should then create an empty container or case, attach the workbook, and begin working through the tasks. - -#### Known False Positives -While all of the settings on each device returned by this search may appear to be hardened, you will still need to verify the value of PYTHONHTTPSVERIFY in $SPLUNK_HOME/etc/splunk-launch.conf on each device in order to harden the python configuration. - -#### Associated Analytic story -* [Splunk Vulnerabilities](/stories/splunk_vulnerabilities) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 50.0 | 50 | 100 | $splunk_server$ may not be properly validating TLS Certificates | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://docs.splunk.com/Documentation/Splunk/9.0.0/Security/EnableTLSCertHostnameValidation](https://docs.splunk.com/Documentation/Splunk/9.0.0/Security/EnableTLSCertHostnameValidation) -* [https://www.splunk.com/en_us/product-security/announcements/svd-2022-0601.html](https://www.splunk.com/en_us/product-security/announcements/svd-2022-0601.html) -* [https://www.github.com/splunk/security_content/blob/develop/workbooks/splunk_psa_0622.json](https://www.github.com/splunk/security_content/blob/develop/workbooks/splunk_psa_0622.json) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1213/audittrail/audittrail.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1213/audittrail/audittrail.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/application/splunk_protocol_impersonation_weak_encryption_configuration.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-05-26-linux_at_application_execution.md b/docs/_posts/2022-05-26-linux_at_application_execution.md deleted file mode 100644 index f840f31900..0000000000 --- a/docs/_posts/2022-05-26-linux_at_application_execution.md +++ /dev/null @@ -1,177 +0,0 @@ ---- -title: "Linux At Application Execution" -excerpt: "At -, Scheduled Task/Job -" -categories: - - Endpoint -last_modified_at: 2022-05-26 -toc: true -toc_label: "" -tags: - - At - - Scheduled Task/Job - - Execution - - Persistence - - Privilege Escalation - - Execution - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies a suspicious process creation of At application. This process can be used by malware, adversaries and red teamers to create persistence entry to the targeted or compromised host with their malicious code. This anomaly detection can be a good indicator to investigate the event before and after this process execution, when it was executed and what schedule task it will execute. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-05-26 -- **Author**: Teoderick Contreras, Splunk -- **ID**: bf0a378e-5f3c-11ec-a6de-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1053.002](https://attack.mitre.org/techniques/T1053/002/) | At | Execution, Persistence, Privilege Escalation | - -| [T1053](https://attack.mitre.org/techniques/T1053/) | Scheduled Task/Job | Execution, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count from datamodel=Endpoint.Processes where Processes.process_name IN ("at", "atd") OR Processes.parent_process_name IN ("at", "atd") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.process_guid -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `linux_at_application_execution_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **linux_at_application_execution_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase. - -#### Known False Positives -Administrator or network operator can use this application for automation purposes. Please update the filter macros to remove false positives. - -#### Associated Analytic story -* [Linux Privilege Escalation](/stories/linux_privilege_escalation) -* [Linux Persistence Techniques](/stories/linux_persistence_techniques) -* [Linux Living Off The Land](/stories/linux_living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 9.0 | 30 | 30 | At application was executed in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1053/001/](https://attack.mitre.org/techniques/T1053/001/) -* [https://www.linkedin.com/pulse/getting-attacker-ip-address-from-malicious-linux-job-craig-rowland/](https://www.linkedin.com/pulse/getting-attacker-ip-address-from-malicious-linux-job-craig-rowland/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.002/at_execution/sysmon_linux.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.002/at_execution/sysmon_linux.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_at_application_execution.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-05-26-linux_possible_append_command_to_at_allow_config_file.md b/docs/_posts/2022-05-26-linux_possible_append_command_to_at_allow_config_file.md deleted file mode 100644 index 460b2cc15f..0000000000 --- a/docs/_posts/2022-05-26-linux_possible_append_command_to_at_allow_config_file.md +++ /dev/null @@ -1,176 +0,0 @@ ---- -title: "Linux Possible Append Command To At Allow Config File" -excerpt: "At -, Scheduled Task/Job -" -categories: - - Endpoint -last_modified_at: 2022-05-26 -toc: true -toc_label: "" -tags: - - At - - Scheduled Task/Job - - Execution - - Persistence - - Privilege Escalation - - Execution - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for suspicious commandline that may use to append user entry to /etc/at.allow or /etc/at.deny. These 2 files are commonly abused by malware, adversaries or red teamers to persist on the targeted or compromised host. These config file can restrict user that can only execute at application (another schedule task application in linux). attacker can create a user or add the compromised username to that config file to execute at to schedule it malicious code. This anomaly detection can be a good indicator to investigate further the entry in created config file and who created it to verify if it is a false positive. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-05-26 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 7bc20606-5f40-11ec-a586-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1053.002](https://attack.mitre.org/techniques/T1053/002/) | At | Execution, Persistence, Privilege Escalation | - -| [T1053](https://attack.mitre.org/techniques/T1053/) | Scheduled Task/Job | Execution, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count from datamodel=Endpoint.Processes where Processes.process = "*echo*" AND Processes.process IN("*/etc/at.allow", "*/etc/at.deny") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.process_guid -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `linux_possible_append_command_to_at_allow_config_file_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **linux_possible_append_command_to_at_allow_config_file_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase. - -#### Known False Positives -Administrator or network operator can use this commandline for automation purposes. Please update the filter macros to remove false positives. - -#### Associated Analytic story -* [Linux Privilege Escalation](/stories/linux_privilege_escalation) -* [Linux Persistence Techniques](/stories/linux_persistence_techniques) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 9.0 | 30 | 30 | A commandline $process$ that may modify at allow config file in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://linuxize.com/post/at-command-in-linux/](https://linuxize.com/post/at-command-in-linux/) -* [https://attack.mitre.org/techniques/T1053/001/](https://attack.mitre.org/techniques/T1053/001/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.002/at_execution/sysmon_linux.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.002/at_execution/sysmon_linux.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_possible_append_command_to_at_allow_config_file.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-05-26-macos_plutil.md b/docs/_posts/2022-05-26-macos_plutil.md deleted file mode 100644 index 9d7140b763..0000000000 --- a/docs/_posts/2022-05-26-macos_plutil.md +++ /dev/null @@ -1,166 +0,0 @@ ---- -title: "MacOS plutil" -excerpt: "Plist File Modification -" -categories: - - Endpoint -last_modified_at: 2022-05-26 -toc: true -toc_label: "" -tags: - - Plist File Modification - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -Detect usage of plutil to modify plist files. Adversaries can modiy plist files to executed binaries or add command line arguments. Plist files in auto-run locations are executed upon user logon or system startup. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-05-26 -- **Author**: Patrick Bareiss, Splunk -- **ID**: c11f2b57-92c1-4cd2-b46c-064eafb833ac - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1647](https://attack.mitre.org/techniques/T1647/) | Plist File Modification | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`osquery` name=es_process_events columns.path=/usr/bin/plutil -| rename columns.* as * -| stats count min(_time) as firstTime max(_time) as lastTime by username host cmdline pid path parent signing_id -| rename username as User, cmdline as process, path as process_path -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `macos_plutil_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [osquery](https://github.com/splunk/security_content/blob/develop/macros/osquery.yml) - -> :information_source: -> **macos_plutil_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* columns.cmdline -* columns.pid -* columns.parent -* columns.path -* columns.signing_id -* columns.username -* host - - -#### How To Implement -This detection uses osquery and endpoint security on MacOS. Follow the link in references, which describes how to setup process auditing in MacOS with endpoint security and osquery. - -#### Known False Positives -Administrators using plutil to change plist files. - -#### Associated Analytic story -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | plutil are executed on $host$ from $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://osquery.readthedocs.io/en/stable/deployment/process-auditing/](https://osquery.readthedocs.io/en/stable/deployment/process-auditing/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1647/atomic_red_team/osquery.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1647/atomic_red_team/osquery.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/macos_plutil.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-05-26-splunk_digital_certificates_infrastructure_version.md b/docs/_posts/2022-05-26-splunk_digital_certificates_infrastructure_version.md deleted file mode 100644 index 0ccf3987be..0000000000 --- a/docs/_posts/2022-05-26-splunk_digital_certificates_infrastructure_version.md +++ /dev/null @@ -1,165 +0,0 @@ ---- -title: "Splunk Digital Certificates Infrastructure Version" -excerpt: "Digital Certificates -" -categories: - - Application -last_modified_at: 2022-05-26 -toc: true -toc_label: "" -tags: - - Digital Certificates - - Resource Development - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2022-32153 ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search will check the TLS validation is properly configured on the search head it is run from as well as its search peers after Splunk version 9. Other components such as additional search heads or anything this rest command cannot be distributed to will need to be manually checked. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-05-26 -- **Author**: Lou Stella, Splunk -- **ID**: 3c162281-7edb-4ebc-b9a4-5087aaf28fa7 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1587.003](https://attack.mitre.org/techniques/T1587/003/) | Digital Certificates | Resource Development | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2022-32153](https://nvd.nist.gov/vuln/detail/CVE-2022-32153) | Splunk Enterprise peers in Splunk Enterprise versions before 9.0 and Splunk Cloud Platform versions before 8.2.2203 did not validate the TLS certificates during Splunk-to-Splunk communications by default. Splunk peer communications configured properly with valid certificates were not vulnerable. However, an attacker with administrator credentials could add a peer without a valid certificate and connections from misconfigured nodes without valid certificates did not fail by default. For Splunk Enterprise, update to Splunk Enterprise version 9.0 and Configure TLS host name validation for Splunk-to-Splunk communications (https://docs.splunk.com/Documentation/Splunk/9.0.0/Security/EnableTLSCertHostnameValidation) to enable the remediation. | 6.8 | - - - -
-
- -#### Search - -``` - -| rest /services/server/info -| table splunk_server version server_roles -| join splunk_server [ -| rest /servicesNS/nobody/search/configs/conf-server/ search="sslConfig" -| table splunk_server sslVerifyServerCert sslVerifyServerName serverCert] -| fillnull value="Not Set" -| rename sslVerifyServerCert as "Server.conf:SslConfig:sslVerifyServerCert", sslVerifyServerName as "Server.conf:SslConfig:sslVerifyServerName", serverCert as "Server.conf:SslConfig:serverCert" -| `splunk_digital_certificates_infrastructure_version_filter` -``` - -#### Macros -The SPL above uses the following Macros: - -> :information_source: -> **splunk_digital_certificates_infrastructure_version_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* none - - -#### How To Implement -The user running this search is required to have a permission allowing them to dispatch REST requests to indexers (the `dispatch_rest_to_indexers` capability) in some architectures. Splunk SOAR customers can find a SOAR workbook that walks an analyst through the process of running these hunting searches in the references list of this detection. In order to use this workbook, a user will need to run a curl command to post the file to their SOAR instance such as "curl -u username:password https://soar.instance.name/rest/rest/workbook_template -d @splunk_psa_0622.json". A user should then create an empty container or case, attach the workbook, and begin working through the tasks. - -#### Known False Positives -No known at this time. - -#### Associated Analytic story -* [Splunk Vulnerabilities](/stories/splunk_vulnerabilities) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 50.0 | 50 | 100 | $splunk_server$ may not be properly validating TLS Certificates | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://docs.splunk.com/Documentation/Splunk/9.0.0/Security/EnableTLSCertHostnameValidation#Configure_TLS_host_name_validation_for_Splunk-to-Splunk_communication](https://docs.splunk.com/Documentation/Splunk/9.0.0/Security/EnableTLSCertHostnameValidation#Configure_TLS_host_name_validation_for_Splunk-to-Splunk_communication) -* [https://www.splunk.com/en_us/product-security/announcements/svd-2022-0602.html](https://www.splunk.com/en_us/product-security/announcements/svd-2022-0602.html) -* [https://www.github.com/splunk/security_content/blob/develop/workbooks/splunk_psa_0622.json](https://www.github.com/splunk/security_content/blob/develop/workbooks/splunk_psa_0622.json) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1213/audittrail/audittrail.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1213/audittrail/audittrail.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/application/splunk_digital_certificates_infrastructure_version.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-05-26-splunk_digital_certificates_lack_of_encryption.md b/docs/_posts/2022-05-26-splunk_digital_certificates_lack_of_encryption.md deleted file mode 100644 index 325a871fd5..0000000000 --- a/docs/_posts/2022-05-26-splunk_digital_certificates_lack_of_encryption.md +++ /dev/null @@ -1,165 +0,0 @@ ---- -title: "Splunk Digital Certificates Lack of Encryption" -excerpt: "Digital Certificates -" -categories: - - Application -last_modified_at: 2022-05-26 -toc: true -toc_label: "" -tags: - - Digital Certificates - - Resource Development - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2022-32151 ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -On June 14th, 2022, Splunk released a security advisory relating to the authentication that happens between Universal Forwarders and Deployment Servers. In some circumstances, an unauthenticated client can download forwarder bundles from the Deployment Server. In other circumstances, a client may be allowed to publish a forwarder bundle to other clients, which may allow for arbitrary code execution. The fixes for these require upgrading to at least Splunk 9.0 on the forwarder as well. This is a great opportunity to configure TLS across the environment. This search looks for forwarders that are not using TLS and adds risk to those entities. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-05-26 -- **Author**: Lou Stella, Splunk -- **ID**: 386a7ebc-737b-48cf-9ca8-5405459ed508 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1587.003](https://attack.mitre.org/techniques/T1587/003/) | Digital Certificates | Resource Development | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2022-32151](https://nvd.nist.gov/vuln/detail/CVE-2022-32151) | The httplib and urllib Python libraries that Splunk shipped with Splunk Enterprise did not validate certificates using the certificate authority (CA) certificate stores by default in Splunk Enterprise versions before 9.0 and Splunk Cloud Platform versions before 8.2.2203. Python 3 client libraries now verify server certificates by default and use the appropriate CA certificate stores for each library. Apps and add-ons that include their own HTTP libraries are not affected. For Splunk Enterprise, update to Splunk Enterprise version 9.0 and Configure TLS host name validation for Splunk-to-Splunk communications (https://docs.splunk.com/Documentation/Splunk/9.0.0/Security/EnableTLSCertHostnameValidation) to enable the remediation. | 6.4 | - - - -
-
- -#### Search - -``` -`splunkd` group="tcpin_connections" ssl="false" -| stats values(sourceIp) latest(fwdType) latest(version) by hostname -| `splunk_digital_certificates_lack_of_encryption_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [splunkd](https://github.com/splunk/security_content/blob/develop/macros/splunkd.yml) - -> :information_source: -> **splunk_digital_certificates_lack_of_encryption_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* group -* ssl -* sourceIp -* fwdType -* version -* hostname - - -#### How To Implement -This anomaly search looks for forwarder connections that are not currently using TLS. It then presents the source IP, the type of forwarder, and the version of the forwarder. You can also remove the "ssl=false" argument from the initial stanza in order to get a full list of all your forwarders that are sending data, and the version of Splunk software they are running, for audit purposes. Splunk SOAR customers can find a SOAR workbook that walks an analyst through the process of running these hunting searches in the references list of this detection. In order to use this workbook, a user will need to run a curl command to post the file to their SOAR instance such as "curl -u username:password https://soar.instance.name/rest/rest/workbook_template -d @splunk_psa_0622.json". A user should then create an empty container or case, attach the workbook, and begin working through the tasks. - -#### Known False Positives -None at this time - -#### Associated Analytic story -* [Splunk Vulnerabilities](/stories/splunk_vulnerabilities) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 20.0 | 25 | 80 | $hostname$ is not using TLS when forwarding data | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.splunk.com/en_us/product-security/announcements/svd-2022-0607.html](https://www.splunk.com/en_us/product-security/announcements/svd-2022-0607.html) -* [https://www.splunk.com/en_us/product-security/announcements/svd-2022-0601.html](https://www.splunk.com/en_us/product-security/announcements/svd-2022-0601.html) -* [https://www.github.com/splunk/security_content/blob/develop/workbooks/splunk_psa_0622.json](https://www.github.com/splunk/security_content/blob/develop/workbooks/splunk_psa_0622.json) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1587.003/splunk_fwder/splunkd.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1587.003/splunk_fwder/splunkd.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/application/splunk_digital_certificates_lack_of_encryption.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-05-26-splunk_process_injection_forwarder_bundle_downloads.md b/docs/_posts/2022-05-26-splunk_process_injection_forwarder_bundle_downloads.md deleted file mode 100644 index 0786a14e97..0000000000 --- a/docs/_posts/2022-05-26-splunk_process_injection_forwarder_bundle_downloads.md +++ /dev/null @@ -1,164 +0,0 @@ ---- -title: "Splunk Process Injection Forwarder Bundle Downloads" -excerpt: "Process Injection -" -categories: - - Application -last_modified_at: 2022-05-26 -toc: true -toc_label: "" -tags: - - Process Injection - - Defense Evasion - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2022-32157 ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -On June 14th, 2022, Splunk released a security advisory relating to the authentication that happens between Universal Forwarders and Deployment Servers. In some circumstances, an unauthenticated client can download forwarder bundles from the Deployment Server. This hunting search pulls a full list of forwarder bundle downloads where the peer column is the forwarder, the host column is the Deployment Server, and then you have a list of the apps downloaded and the serverclasses in which the peer is a member of. You should look for apps or clients that you do not recognize as being part of your environment. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-05-26 -- **Author**: Lou Stella, Splunk -- **ID**: 8ea57d78-1aac-45d2-a913-0cd603fb6e9e - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1055](https://attack.mitre.org/techniques/T1055/) | Process Injection | Defense Evasion, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2022-32157](https://nvd.nist.gov/vuln/detail/CVE-2022-32157) | Splunk Enterprise deployment servers in versions before 9.0 allow unauthenticated downloading of forwarder bundles. Remediation requires you to update the deployment server to version 9.0 and Configure authentication for deployment servers and clients (https://docs.splunk.com/Documentation/Splunk/9.0.0/Security/ConfigDSDCAuthEnhancements#Configure_authentication_for_deployment_servers_and_clients). Once enabled, deployment servers can manage only Universal Forwarder versions 9.0 and higher. Though the vulnerability does not directly affect Universal Forwarders, remediation requires updating all Universal Forwarders that the deployment server manages to version 9.0 or higher prior to enabling the remediation. | 5.0 | - - - -
-
- -#### Search - -``` -`splunkd` component="PackageDownloadRestHandler" -| stats values(app) values(serverclass) by peer, host -| `splunk_process_injection_forwarder_bundle_downloads_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [splunkd](https://github.com/splunk/security_content/blob/develop/macros/splunkd.yml) - -> :information_source: -> **splunk_process_injection_forwarder_bundle_downloads_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* component -* app -* serverclass -* peer -* host - - -#### How To Implement -This hunting search uses native logs produced when a deployment server is within your environment. Splunk SOAR customers can find a SOAR workbook that walks an analyst through the process of running these hunting searches in the references list of this detection. In order to use this workbook, a user will need to run a curl command to post the file to their SOAR instance such as "curl -u username:password https://soar.instance.name/rest/rest/workbook_template -d @splunk_psa_0622.json". A user should then create an empty container or case, attach the workbook, and begin working through the tasks. - -#### Known False Positives -None at this time. - -#### Associated Analytic story -* [Splunk Vulnerabilities](/stories/splunk_vulnerabilities) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 35.0 | 50 | 70 | $peer$ downloaded apps from $host$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.splunk.com/en_us/product-security/announcements/svd-2022-0607.html](https://www.splunk.com/en_us/product-security/announcements/svd-2022-0607.html) -* [https://www.github.com/splunk/security_content/blob/develop/workbooks/splunk_psa_0622.json](https://www.github.com/splunk/security_content/blob/develop/workbooks/splunk_psa_0622.json) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/splunk_ds/splunkd.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/splunk_ds/splunkd.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/application/splunk_process_injection_forwarder_bundle_downloads.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-05-26-splunk_protocol_impersonation_weak_encryption_selfsigned.md b/docs/_posts/2022-05-26-splunk_protocol_impersonation_weak_encryption_selfsigned.md deleted file mode 100644 index 3381cea1ff..0000000000 --- a/docs/_posts/2022-05-26-splunk_protocol_impersonation_weak_encryption_selfsigned.md +++ /dev/null @@ -1,162 +0,0 @@ ---- -title: "Splunk protocol impersonation weak encryption selfsigned" -excerpt: "Digital Certificates -" -categories: - - Application -last_modified_at: 2022-05-26 -toc: true -toc_label: "" -tags: - - Digital Certificates - - Resource Development - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2022-32152 ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -On June 14th 2022, Splunk released vulnerability advisory addresing Python TLS validation which was not set before Splunk version 9. This search displays events showing WARNING of using Splunk issued default selfsigned certificates. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-05-26 -- **Author**: Rod Soto, Splunk -- **ID**: c76c7a2e-df49-414a-bb36-dce2683770de - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1588.004](https://attack.mitre.org/techniques/T1588/004/) | Digital Certificates | Resource Development | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2022-32152](https://nvd.nist.gov/vuln/detail/CVE-2022-32152) | Splunk Enterprise peers in Splunk Enterprise versions before 9.0 and Splunk Cloud Platform versions before 8.2.2203 did not validate the TLS certificates during Splunk-to-Splunk communications by default. Splunk peer communications configured properly with valid certificates were not vulnerable. However, an attacker with administrator credentials could add a peer without a valid certificate and connections from misconfigured nodes without valid certificates did not fail by default. For Splunk Enterprise, update to Splunk Enterprise version 9.0 and Configure TLS host name validation for Splunk-to-Splunk communications (https://docs.splunk.com/Documentation/Splunk/9.0.0/Security/EnableTLSCertHostnameValidation) to enable the remediation. | 6.5 | - - - -
-
- -#### Search - -``` -`splunkd` certificate event_message="X509 certificate* should not be used*" -| stats count by host CN component log_level -| `splunk_protocol_impersonation_weak_encryption_selfsigned_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [splunkd](https://github.com/splunk/security_content/blob/develop/macros/splunkd.yml) - -> :information_source: -> **splunk_protocol_impersonation_weak_encryption_selfsigned_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* host -* CN -* event_message - - -#### How To Implement -Must upgrade to Splunk version 9 and Configure TLS in order to apply this search. Splunk SOAR customers can find a SOAR workbook that walks an analyst through the process of running these hunting searches in the references list of this detection. In order to use this workbook, a user will need to run a curl command to post the file to their SOAR instance such as "curl -u username:password https://soar.instance.name/rest/rest/workbook_template -d @splunk_psa_0622.json". A user should then create an empty container or case, attach the workbook, and begin working through the tasks. - -#### Known False Positives -This searches finds self signed certificates issued by Splunk which are not recommended from Splunk version 9 forward. - -#### Associated Analytic story -* [Splunk Vulnerabilities](/stories/splunk_vulnerabilities) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 40.0 | 50 | 80 | Splunk default issued certificate at $host$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.splunk.com/en_us/product-security](https://www.splunk.com/en_us/product-security) -* [https://docs.splunk.com/Documentation/Splunk/9.0.0/Security/EnableTLSCertHostnameValidation](https://docs.splunk.com/Documentation/Splunk/9.0.0/Security/EnableTLSCertHostnameValidation) -* [https://www.github.com/splunk/security_content/blob/develop/workbooks/splunk_psa_0622.json](https://www.github.com/splunk/security_content/blob/develop/workbooks/splunk_psa_0622.json) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://raw.githubusercontent.com/splunk/attack_data/master/datasets/attack_techniques/T1558.004/splunk_protocol_impersonation_weak_encryption_selfsigned.txt](https://raw.githubusercontent.com/splunk/attack_data/master/datasets/attack_techniques/T1558.004/splunk_protocol_impersonation_weak_encryption_selfsigned.txt) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/application/splunk_protocol_impersonation_weak_encryption_selfsigned.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-05-27-splunk_command_and_scripting_interpreter_delete_usage.md b/docs/_posts/2022-05-27-splunk_command_and_scripting_interpreter_delete_usage.md deleted file mode 100644 index d75ccf9983..0000000000 --- a/docs/_posts/2022-05-27-splunk_command_and_scripting_interpreter_delete_usage.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: "Splunk Command and Scripting Interpreter Delete Usage" -excerpt: "Command and Scripting Interpreter -" -categories: - - Application -last_modified_at: 2022-05-27 -toc: true -toc_label: "" -tags: - - Command and Scripting Interpreter - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2022-32154 - - Splunk_Audit ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the use of the risky command - Delete - that may be utilized in Splunk to delete some or all data queried for. In order to use Delete in Splunk, one must be assigned the role. This is typically not used and should generate an anomaly if it is used. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Splunk_Audit](https://docs.splunk.com/Documentation/CIM/latest/User/SplunkAudit) -- **Last Updated**: 2022-05-27 -- **Author**: Michael Haag, Splunk -- **ID**: 8d3d5d5e-ca43-42be-aa1f-bc64375f6b04 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2022-32154](https://nvd.nist.gov/vuln/detail/CVE-2022-32154) | Dashboards in Splunk Enterprise versions before 9.0 might let an attacker inject risky search commands into a form token when the token is used in a query in a cross-origin request. The result bypasses SPL safeguards for risky commands. See New capabilities can limit access to some custom and potentially risky commands (https://docs.splunk.com/Documentation/Splunk/9.0.0/Security/SPLsafeguards#New_capabilities_can_limit_access_to_some_custom_and_potentially_risky_commands) for more information. Note that the attack is browser-based and an attacker cannot exploit it at will. | 4.0 | - - - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Splunk_Audit.Search_Activity where Search_Activity.search IN ("* -| delete*") Search_Activity.search_type=adhoc Search_Activity.user!=splunk-system-user by Search_Activity.search Search_Activity.info Search_Activity.total_run_time Search_Activity.user Search_Activity.search_type -| `drop_dm_object_name(Search_Activity)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `splunk_command_and_scripting_interpreter_delete_usage_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **splunk_command_and_scripting_interpreter_delete_usage_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Search_Activity.search -* Search_Activity.info -* Search_Activity.total_run_time -* Search_Activity.user -* Search_Activity.savedsearch_name -* Search_Activity.search_type - - -#### How To Implement -To successfully implement this search acceleration is recommended against the Search_Activity datamodel that runs against the splunk _audit index. In addition, this analytic requires the Common Information Model App which includes the Splunk Audit Datamodel https://splunkbase.splunk.com/app/1621/. - -#### Known False Positives -False positives may be present if this command is used as a common practice. Filter as needed. - -#### Associated Analytic story -* [Splunk Vulnerabilities](/stories/splunk_vulnerabilities) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 27.0 | 90 | 30 | $user$ executed the 'delete' command, if this is unexpected it should be reviewed. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://docs.splunk.com/Documentation/Splunk/latest/Security/SPLsafeguards#Commands_that_trigger_the_warning](https://docs.splunk.com/Documentation/Splunk/latest/Security/SPLsafeguards#Commands_that_trigger_the_warning) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1213/audittrail/audittrail.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1213/audittrail/audittrail.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/application/splunk_command_and_scripting_interpreter_delete_usage.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-05-27-splunk_command_and_scripting_interpreter_risky_spl_mltk.md b/docs/_posts/2022-05-27-splunk_command_and_scripting_interpreter_risky_spl_mltk.md deleted file mode 100644 index 6b99c37e55..0000000000 --- a/docs/_posts/2022-05-27-splunk_command_and_scripting_interpreter_risky_spl_mltk.md +++ /dev/null @@ -1,176 +0,0 @@ ---- -title: "Splunk Command and Scripting Interpreter Risky SPL MLTK" -excerpt: "Command and Scripting Interpreter -" -categories: - - Application -last_modified_at: 2022-05-27 -toc: true -toc_label: "" -tags: - - Command and Scripting Interpreter - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2022-32154 - - Splunk_Audit ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This detection utilizes machine learning model named "risky_command_abuse" trained from "Splunk Command and Scripting Interpreter Risky SPL MLTK Baseline". It should be scheduled to run hourly to detect whether a user has run searches containing risky SPL from this list https://docs.splunk.com/Documentation/Splunk/latest/Security/SPLsafeguards#Commands_that_trigger_the_warninga with abnormally long running time in the past one hour, comparing with his/her past seven days history. This search uses the trained baseline to infer whether a search is an outlier (isOutlier ~= 1.0) or not (isOutlier~= 0.0) - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Splunk_Audit](https://docs.splunk.com/Documentation/CIM/latest/User/SplunkAudit) -- **Last Updated**: 2022-05-27 -- **Author**: Abhinav Mishra, Kumar Sharad and Xiao Lin, Splunk -- **ID**: 19d0146c-2eae-4e53-8d39-1198a78fa9ca - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.AE - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 6 - - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2022-32154](https://nvd.nist.gov/vuln/detail/CVE-2022-32154) | Dashboards in Splunk Enterprise versions before 9.0 might let an attacker inject risky search commands into a form token when the token is used in a query in a cross-origin request. The result bypasses SPL safeguards for risky commands. See New capabilities can limit access to some custom and potentially risky commands (https://docs.splunk.com/Documentation/Splunk/9.0.0/Security/SPLsafeguards#New_capabilities_can_limit_access_to_some_custom_and_potentially_risky_commands) for more information. Note that the attack is browser-based and an attacker cannot exploit it at will. | 4.0 | - - - -
-
- -#### Search - -``` - -| tstats sum(Search_Activity.total_run_time) AS run_time, values(Search_Activity.search) as searches, count FROM datamodel=Splunk_Audit.Search_Activity WHERE (Search_Activity.user!="") AND (Search_Activity.total_run_time>1) AND (earliest=-1h@h latest=now) AND (Search_Activity.search IN ("* -| runshellscript *", "* -| collect *","* -| delete *", "* -| fit *", "* -| outputcsv *", "* -| outputlookup *", "* -| run *", "* -| script *", "* -| sendalert *", "* -| sendemail *", "* -| tscolle*")) AND (Search_Activity.search_type=adhoc) AND (Search_Activity.user!=splunk-system-user) BY _time, Search_Activity.user span=1h -| apply risky_command_abuse -| fields _time, Search_Activity.user, searches, run_time, IsOutlier(run_time) -| rename IsOutlier(run_time) as isOutlier, _time as timestamp -| where isOutlier>0.5 -| `splunk_command_and_scripting_interpreter_risky_spl_mltk_filter` -``` - -#### Macros -The SPL above uses the following Macros: - -> :information_source: -> **splunk_command_and_scripting_interpreter_risky_spl_mltk_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Search_Activity.search -* Search_Activity.total_run_time -* Search_Activity.user -* Search_Activity.search_type - - -#### How To Implement -This detection depends on MLTK app which can be found here - https://splunkbase.splunk.com/app/2890/ and the Splunk Audit datamodel which can be found here - https://splunkbase.splunk.com/app/1621/. Baseline model needs to be built using "Splunk Command and Scripting Interpreter Risky SPL MLTK Baseline" before this search can run. Please note that the current search only finds matches exactly one space between separator bar and risky commands. - -#### Known False Positives -If the run time of a search exceeds the boundaries of outlier defined by the fitted density function model, false positives can occur, incorrectly labeling a long running search as potentially risky. - -#### Associated Analytic story -* [Splunk Vulnerabilities](/stories/splunk_vulnerabilities) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 20.0 | 50 | 40 | Abnormally long run time for risk SPL command seen by user $(Search_Activity.user). | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://docs.splunk.com/Documentation/Splunk/latest/Security/SPLsafeguards#Commands_that_trigger_the_warning](https://docs.splunk.com/Documentation/Splunk/latest/Security/SPLsafeguards#Commands_that_trigger_the_warning) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://github.com/splunk/attack_data/raw/master/datasets/attack_techniques/T1203/search_activity.txt](https://github.com/splunk/attack_data/raw/master/datasets/attack_techniques/T1203/search_activity.txt) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/application/splunk_command_and_scripting_interpreter_risky_spl_mltk.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-05-30-windows_command_and_scripting_interpreter_path_traversal_exec.md b/docs/_posts/2022-05-30-windows_command_and_scripting_interpreter_path_traversal_exec.md deleted file mode 100644 index 3ee32e08b9..0000000000 --- a/docs/_posts/2022-05-30-windows_command_and_scripting_interpreter_path_traversal_exec.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: "Windows Command and Scripting Interpreter Path Traversal Exec" -excerpt: "Command and Scripting Interpreter -" -categories: - - Endpoint -last_modified_at: 2022-05-30 -toc: true -toc_label: "" -tags: - - Command and Scripting Interpreter - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies path traversal commandline execution. This technique was seen in malicious document that execute malicious code using msdt.exe and path traversal technique that serve as defense evasion. This TTP is a good pivot to look for more suspicious process and commandline that runs before and after this execution. This may help you to find possible downloaded malware or other lolbin execution. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-05-30 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 58fcdeb1-728d-415d-b0d7-3ab18a275ec2 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes where Processes.process="*\/..\/..\/..\/..\/..\/..\/..\/..\/..\/*" by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.original_file_name Processes.process_id Processes.parent_process_id Processes.process_hash -| `drop_dm_object_name("Processes")` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_command_and_scripting_interpreter_path_traversal_exec_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **windows_command_and_scripting_interpreter_path_traversal_exec_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product - -#### Known False Positives -Not known at this moment. - -#### Associated Analytic story -* [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics) -* [Microsoft Support Diagnostic Tool Vulnerability CVE-2022-30190](/stories/microsoft_support_diagnostic_tool_vulnerability_cve-2022-30190) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 90.0 | 90 | 100 | A parent process $parent_process_name$ has spawned a child $process_name$ with path traversal commandline $process$ in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://app.any.run/tasks/713f05d2-fe78-4b9d-a744-f7c133e3fafb/](https://app.any.run/tasks/713f05d2-fe78-4b9d-a744-f7c133e3fafb/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059/path_traversal/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059/path_traversal/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_command_and_scripting_interpreter_path_traversal_exec.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-05-30-windows_execute_arbitrary_commands_with_msdt.md b/docs/_posts/2022-05-30-windows_execute_arbitrary_commands_with_msdt.md deleted file mode 100644 index ef11bcbd9c..0000000000 --- a/docs/_posts/2022-05-30-windows_execute_arbitrary_commands_with_msdt.md +++ /dev/null @@ -1,179 +0,0 @@ ---- -title: "Windows Execute Arbitrary Commands with MSDT" -excerpt: "System Binary Proxy Execution -" -categories: - - Endpoint -last_modified_at: 2022-05-30 -toc: true -toc_label: "" -tags: - - System Binary Proxy Execution - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2022-30190 - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies a recently disclosed arbitraty command execution using Windows msdt.exe - a Diagnostics Troubleshooting Wizard. The sample identified will use the ms-msdt:/ protocol handler to load msdt.exe to retrieve a remote payload. During triage, review file modifications for html. Identify parallel process execution that may be related, including an Office Product. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-05-30 -- **Author**: Michael Haag, Teoderick Contreras, Splunk -- **ID**: e1d5145f-38fe-42b9-a5d5-457796715f97 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218](https://attack.mitre.org/techniques/T1218/) | System Binary Proxy Execution | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2022-30190](https://nvd.nist.gov/vuln/detail/CVE-2022-30190) | Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability. | 9.3 | - - - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=msdt.exe Processes.process IN ("*ms-msdt:/id*","*ms-msdt:-id*","*/id*") AND (Processes.process="*IT_BrowseForFile=*" OR Processes.process="*IT_RebrowseForFile=*" OR Processes.process="*.xml*") AND Processes.process="*PCWDiagnostic*" by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_execute_arbitrary_commands_with_msdt_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **windows_execute_arbitrary_commands_with_msdt_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -False positives may be present, filter as needed. Added .xml to potentially capture any answer file usage. Remove as needed. - -#### Associated Analytic story -* [Microsoft Support Diagnostic Tool Vulnerability CVE-2022-30190](/stories/microsoft_support_diagnostic_tool_vulnerability_cve-2022-30190) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 100.0 | 100 | 100 | A parent process $parent_process_name$ has spawned a child process $process_name$ on host $dest$ possibly indicative of indirect command execution. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://isc.sans.edu/diary/rss/28694](https://isc.sans.edu/diary/rss/28694) -* [https://doublepulsar.com/follina-a-microsoft-office-code-execution-vulnerability-1a47fce5629e](https://doublepulsar.com/follina-a-microsoft-office-code-execution-vulnerability-1a47fce5629e) -* [https://twitter.com/nao_sec/status/1530196847679401984?s=20&t=ZiXYI4dQuA-0_dzQzSUb3A](https://twitter.com/nao_sec/status/1530196847679401984?s=20&t=ZiXYI4dQuA-0_dzQzSUb3A) -* [https://app.any.run/tasks/713f05d2-fe78-4b9d-a744-f7c133e3fafb/](https://app.any.run/tasks/713f05d2-fe78-4b9d-a744-f7c133e3fafb/) -* [https://www.virustotal.com/gui/file/4a24048f81afbe9fb62e7a6a49adbd1faf41f266b5f9feecdceb567aec096784/detection](https://www.virustotal.com/gui/file/4a24048f81afbe9fb62e7a6a49adbd1faf41f266b5f9feecdceb567aec096784/detection) -* [https://strontic.github.io/xcyclopedia/library/msdt.exe-152D4C9F63EFB332CCB134C6953C0104.html](https://strontic.github.io/xcyclopedia/library/msdt.exe-152D4C9F63EFB332CCB134C6953C0104.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/msdt.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/msdt.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_execute_arbitrary_commands_with_msdt.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-05-30-windows_office_product_spawning_msdt.md b/docs/_posts/2022-05-30-windows_office_product_spawning_msdt.md deleted file mode 100644 index d88c00db39..0000000000 --- a/docs/_posts/2022-05-30-windows_office_product_spawning_msdt.md +++ /dev/null @@ -1,185 +0,0 @@ ---- -title: "Windows Office Product Spawning MSDT" -excerpt: "Phishing -, Spearphishing Attachment -" -categories: - - Endpoint -last_modified_at: 2022-05-30 -toc: true -toc_label: "" -tags: - - Phishing - - Spearphishing Attachment - - Initial Access - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2022-30190 - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies a Microsoft Office product spawning the Windows msdt.exe process. MSDT is a Diagnostics Troubleshooting Wizard native to Windows. This behavior is related to a recently identified sample utilizing protocol handlers to evade preventative controls, including if macros are disabled in the document. During triage, review file modifications for html. In addition, parallel processes including PowerShell and CertUtil. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-05-30 -- **Author**: Michael Haag, Teoderick Contreras, Splunk -- **ID**: 127eba64-c981-40bf-8589-1830638864a7 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | - -| [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2022-30190](https://nvd.nist.gov/vuln/detail/CVE-2022-30190) | Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability. | 9.3 | - - - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name IN ("winword.exe","excel.exe","powerpnt.exe","outlook.exe","mspub.exe","visio.exe") Processes.process_name=msdt.exe by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_office_product_spawning_msdt_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_office_product_spawning_msdt_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -how To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -False positives should be limited, however filter as needed. - -#### Associated Analytic story -* [Spearphishing Attachments](/stories/spearphishing_attachments) -* [Microsoft Support Diagnostic Tool Vulnerability CVE-2022-30190](/stories/microsoft_support_diagnostic_tool_vulnerability_cve-2022-30190) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 100.0 | 100 | 100 | Office parent process $parent_process_name$ has spawned a child process $process_name$ on host $dest$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://isc.sans.edu/diary/rss/28694](https://isc.sans.edu/diary/rss/28694) -* [https://doublepulsar.com/follina-a-microsoft-office-code-execution-vulnerability-1a47fce5629e](https://doublepulsar.com/follina-a-microsoft-office-code-execution-vulnerability-1a47fce5629e) -* [https://twitter.com/nao_sec/status/1530196847679401984?s=20&t=ZiXYI4dQuA-0_dzQzSUb3A](https://twitter.com/nao_sec/status/1530196847679401984?s=20&t=ZiXYI4dQuA-0_dzQzSUb3A) -* [https://app.any.run/tasks/713f05d2-fe78-4b9d-a744-f7c133e3fafb/](https://app.any.run/tasks/713f05d2-fe78-4b9d-a744-f7c133e3fafb/) -* [https://www.virustotal.com/gui/file/4a24048f81afbe9fb62e7a6a49adbd1faf41f266b5f9feecdceb567aec096784/detection](https://www.virustotal.com/gui/file/4a24048f81afbe9fb62e7a6a49adbd1faf41f266b5f9feecdceb567aec096784/detection) -* [https://strontic.github.io/xcyclopedia/library/msdt.exe-152D4C9F63EFB332CCB134C6953C0104.html](https://strontic.github.io/xcyclopedia/library/msdt.exe-152D4C9F63EFB332CCB134C6953C0104.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/msdt.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/msdt.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_office_product_spawning_msdt.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-06-01-mshtml_module_load_in_office_product.md b/docs/_posts/2022-06-01-mshtml_module_load_in_office_product.md deleted file mode 100644 index b18ce4fe3e..0000000000 --- a/docs/_posts/2022-06-01-mshtml_module_load_in_office_product.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: "MSHTML Module Load in Office Product" -excerpt: "Phishing -, Spearphishing Attachment -" -categories: - - Endpoint -last_modified_at: 2022-06-01 -toc: true -toc_label: "" -tags: - - Phishing - - Spearphishing Attachment - - Initial Access - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2021-40444 - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following detection identifies the module load of mshtml.dll into an Office product. This behavior has been related to CVE-2021-40444, whereas the malicious document will load ActiveX, which activates the MSHTML component. The vulnerability resides in the MSHTML component. During triage, identify parallel processes and capture any file modifications for analysis. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-06-01 -- **Author**: Michael Haag, Mauricio Velazco, Splunk -- **ID**: 5f1c168e-118b-11ec-84ff-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | - -| [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2021-40444](https://nvd.nist.gov/vuln/detail/CVE-2021-40444) | Microsoft MSHTML Remote Code Execution Vulnerability | 6.8 | - - - -
-
- -#### Search - -``` -`sysmon` EventID=7 process_name IN ("winword.exe","excel.exe","powerpnt.exe","mspub.exe","visio.exe","wordpad.exe","wordview.exe") ImageLoaded IN ("*\\mshtml.dll", "*\\Microsoft.mshtml.dll","*\\IE.Interop.MSHTML.dll","*\\MshtmlDac.dll","*\\MshtmlDed.dll","*\\MshtmlDer.dll") -| stats count min(_time) as firstTime max(_time) as lastTime by Computer, process_name, ImageLoaded, OriginalFileName, ProcessGuid -| rename Computer as dest -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `mshtml_module_load_in_office_product_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **mshtml_module_load_in_office_product_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* ImageLoaded -* process_name -* OriginalFileName -* process_id -* dest - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process names and image loads from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -Limited false positives will be present, however, tune as necessary. - -#### Associated Analytic story -* [Spearphishing Attachments](/stories/spearphishing_attachments) -* [Microsoft MSHTML Remote Code Execution CVE-2021-40444](/stories/microsoft_mshtml_remote_code_execution_cve-2021-40444) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | An instance of $process_name$ was identified on endpoint $dest$ loading mshtml.dll. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://app.any.run/tasks/36c14029-9df8-439c-bba0-45f2643b0c70/](https://app.any.run/tasks/36c14029-9df8-439c-bba0-45f2643b0c70/) -* [https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40444](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40444) -* [https://strontic.github.io/xcyclopedia/index-dll](https://strontic.github.io/xcyclopedia/index-dll) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_mshtml.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_mshtml.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/mshtml_module_load_in_office_product.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-06-01-suspicious_process_with_discord_dns_query.md b/docs/_posts/2022-06-01-suspicious_process_with_discord_dns_query.md deleted file mode 100644 index d62428fbc2..0000000000 --- a/docs/_posts/2022-06-01-suspicious_process_with_discord_dns_query.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: "Suspicious Process With Discord DNS Query" -excerpt: "Visual Basic -, Command and Scripting Interpreter -" -categories: - - Endpoint -last_modified_at: 2022-06-01 -toc: true -toc_label: "" -tags: - - Visual Basic - - Command and Scripting Interpreter - - Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic identifies a process making a DNS query to Discord, a well known instant messaging and digital distribution platform. Discord can be abused by adversaries, as seen in the WhisperGate campaign, to host and download malicious. external files. A process resolving a Discord DNS name could be an indicator of malware trying to download files from Discord for further execution. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-06-01 -- **Author**: Teoderick Contreras, Mauricio Velazco, Splunk -- **ID**: 4d4332ae-792c-11ec-89c1-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059.005](https://attack.mitre.org/techniques/T1059/005/) | Visual Basic | Execution | - -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventCode=22 QueryName IN ("*discord*") Image != "*\\AppData\\Local\\Discord\\*" AND Image != "*\\Program Files*" AND Image != "discord.exe" -| stats count min(_time) as firstTime max(_time) as lastTime by Image QueryName QueryStatus process_name QueryResults Computer -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `suspicious_process_with_discord_dns_query_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **suspicious_process_with_discord_dns_query_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Image -* QueryName -* QueryStatus -* process_name -* QueryResults -* Computer - - -#### How To Implement -his detection relies on sysmon logs with the Event ID 22, DNS Query. - -#### Known False Positives -Noise and false positive can be seen if the following instant messaging is allowed to use within corporate network. In this case, a filter is needed. - -#### Associated Analytic story -* [WhisperGate](/stories/whispergate) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 64.0 | 80 | 80 | suspicious process $process_name$ has a dns query in $QueryName$ on $Computer$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/](https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/) -* [https://medium.com/s2wblog/analysis-of-destructive-malware-whispergate-targeting-ukraine-9d5d158f19f3](https://medium.com/s2wblog/analysis-of-destructive-malware-whispergate-targeting-ukraine-9d5d158f19f3) -* [https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/](https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.005/discord_dnsquery/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.005/discord_dnsquery/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-06-01-unload_sysmon_filter_driver.md b/docs/_posts/2022-06-01-unload_sysmon_filter_driver.md deleted file mode 100644 index 4678bd2d68..0000000000 --- a/docs/_posts/2022-06-01-unload_sysmon_filter_driver.md +++ /dev/null @@ -1,168 +0,0 @@ ---- -title: "Unload Sysmon Filter Driver" -excerpt: "Disable or Modify Tools -, Impair Defenses -" -categories: - - Endpoint -last_modified_at: 2022-06-01 -toc: true -toc_label: "" -tags: - - Disable or Modify Tools - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -Attackers often disable security tools to avoid detection. This search looks for the usage of process `fltMC.exe` to unload a Sysmon Driver that will stop sysmon from collecting the data. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-06-01 -- **Author**: Bhavin Patel, Splunk -- **ID**: e5928ff3-23eb-4d8b-b8a4-dcbc844fdfbe - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime values(Processes.process) as process max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=fltMC.exe AND Processes.process=*unload* AND Processes.process=*SysmonDrv* by Processes.process_name Processes.process_id Processes.parent_process_name Processes.process Processes.dest Processes.user -| `drop_dm_object_name("Processes")` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -|`unload_sysmon_filter_driver_filter` -| table firstTime lastTime dest user count process_name process_id parent_process_name process -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **unload_sysmon_filter_driver_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_name -* Processes.dest -* Processes.user - - -#### How To Implement -You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. This search is also shipped with `unload_sysmon_filter_driver_filter` macro, update this macro to filter out false positives. - -#### Known False Positives -Unknown at the moment - -#### Associated Analytic story -* [Disabling Security Tools](/stories/disabling_security_tools) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 45.0 | 50 | 90 | Possible Sysmon filter driver unloading on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.ired.team/offensive-security/defense-evasion/unloading-sysmon-driver](https://www.ired.team/offensive-security/defense-evasion/unloading-sysmon-driver) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/unload_sysmon/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/unload_sysmon/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/unload_sysmon_filter_driver.yml) \| *version*: **4** \ No newline at end of file diff --git a/docs/_posts/2022-06-01-wermgr_process_connecting_to_ip_check_web_services.md b/docs/_posts/2022-06-01-wermgr_process_connecting_to_ip_check_web_services.md deleted file mode 100644 index e4ce581afd..0000000000 --- a/docs/_posts/2022-06-01-wermgr_process_connecting_to_ip_check_web_services.md +++ /dev/null @@ -1,165 +0,0 @@ ---- -title: "Wermgr Process Connecting To IP Check Web Services" -excerpt: "Gather Victim Network Information -, IP Addresses -" -categories: - - Endpoint -last_modified_at: 2022-06-01 -toc: true -toc_label: "" -tags: - - Gather Victim Network Information - - IP Addresses - - Reconnaissance - - Reconnaissance - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -this search is designed to detect suspicious wermgr.exe process that tries to connect to known IP web services. This technique is know for trickbot and other trojan spy malware to recon the infected machine and look for its ip address without so much finger print on the commandline process. Since wermgr.exe is designed for error handling process of windows it is really suspicious that this process is trying to connect to this IP web services cause that maybe cause of some malicious code injection. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-06-01 -- **Author**: Teoderick Contreras, Mauricio Velazco, Splunk -- **ID**: ed313326-a0f9-11eb-a89c-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1590](https://attack.mitre.org/techniques/T1590/) | Gather Victim Network Information | Reconnaissance | - -| [T1590.005](https://attack.mitre.org/techniques/T1590/005/) | IP Addresses | Reconnaissance | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventCode =22 process_name = wermgr.exe QueryName IN ("*wtfismyip.com", "*checkip.amazonaws.com", "*ipecho.net", "*ipinfo.io", "*api.ipify.org", "*icanhazip.com", "*ip.anysrc.com","*api.ip.sb", "ident.me", "www.myexternalip.com", "*zen.spamhaus.org", "*cbl.abuseat.org", "*b.barracudacentral.org","*dnsbl-1.uceprotect.net", "*spam.dnsbl.sorbs.net") -| stats min(_time) as firstTime max(_time) as lastTime count by Image process_name ProcessId QueryName QueryStatus QueryResults Computer EventCode -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `wermgr_process_connecting_to_ip_check_web_services_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **wermgr_process_connecting_to_ip_check_web_services_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* process_path -* process_name -* process_id -* QueryName -* QueryStatus -* QueryResults -* Computer -* EventCode - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, dns query name process path , and query ststus from your endpoints like EventCode 22. If you are using Sysmon, you must have at least version 12 of the Sysmon TA. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Trickbot](/stories/trickbot) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 56.0 | 70 | 80 | Wermgr.exe process connecting IP location web services on $ComputerName$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://labs.vipre.com/trickbot-and-its-modules/](https://labs.vipre.com/trickbot-and-its-modules/) -* [https://whitehat.eu/incident-response-case-study-featuring-ryuk-and-trickbot-part-2/](https://whitehat.eu/incident-response-case-study-featuring-ryuk-and-trickbot-part-2/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/trickbot/infection/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/trickbot/infection/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-06-01-windows_command_and_scripting_interpreter_hunting_path_traversal.md b/docs/_posts/2022-06-01-windows_command_and_scripting_interpreter_hunting_path_traversal.md deleted file mode 100644 index 45e5636f24..0000000000 --- a/docs/_posts/2022-06-01-windows_command_and_scripting_interpreter_hunting_path_traversal.md +++ /dev/null @@ -1,175 +0,0 @@ ---- -title: "Windows Command and Scripting Interpreter Hunting Path Traversal" -excerpt: "Command and Scripting Interpreter -" -categories: - - Endpoint -last_modified_at: 2022-06-01 -toc: true -toc_label: "" -tags: - - Command and Scripting Interpreter - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies path traversal command-line execution and should be used to tune and driver other more higher fidelity analytics. This technique was seen in malicious document that execute malicious code using msdt.exe and path traversal technique that serve as defense evasion. This Hunting query is a good pivot to look for possible suspicious process and command-line that runs execute path traversal technique to run malicious code. This may help you to find possible downloaded malware or other lolbin execution. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-06-01 -- **Author**: Teoderick Contreras, Michael Haag, Splunk -- **ID**: d0026380-b3c4-4da0-ac8e-02790063ff6b - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes by Processes.original_file_name Processes.process_id Processes.parent_process_id Processes.process_hash Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process -| `drop_dm_object_name("Processes")` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| eval count_of_pattern1 = (mvcount(split(process,"/.."))-1) -| eval count_of_pattern2 = (mvcount(split(process,"\.."))-1) -| eval count_of_pattern3 = (mvcount(split(process,"\\.."))-1) -| eval count_of_pattern4 = (mvcount(split(process,"//.."))-1) -| search count_of_pattern1 > 1 OR count_of_pattern2 > 1 OR count_of_pattern3 > 1 OR count_of_pattern4 > 1 -| `windows_command_and_scripting_interpreter_hunting_path_traversal_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_command_and_scripting_interpreter_hunting_path_traversal_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product - -#### Known False Positives -false positive may vary depends on the score you want to check. The bigger number of path traversal string count the better. - -#### Associated Analytic story -* [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics) -* [Microsoft Support Diagnostic Tool Vulnerability CVE-2022-30190](/stories/microsoft_support_diagnostic_tool_vulnerability_cve-2022-30190) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 36.0 | 60 | 60 | A parent process $parent_process_name$ has spawned a child $process_name$ with path traversal commandline $process$ in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://app.any.run/tasks/713f05d2-fe78-4b9d-a744-f7c133e3fafb/](https://app.any.run/tasks/713f05d2-fe78-4b9d-a744-f7c133e3fafb/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059/path_traversal/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059/path_traversal/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_command_and_scripting_interpreter_hunting_path_traversal.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-06-01-windows_command_and_scripting_interpreter_path_traversal_exec.md b/docs/_posts/2022-06-01-windows_command_and_scripting_interpreter_path_traversal_exec.md deleted file mode 100644 index 7d1376be5b..0000000000 --- a/docs/_posts/2022-06-01-windows_command_and_scripting_interpreter_path_traversal_exec.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: "Windows Command and Scripting Interpreter Path Traversal Exec" -excerpt: "Command and Scripting Interpreter -" -categories: - - Endpoint -last_modified_at: 2022-06-01 -toc: true -toc_label: "" -tags: - - Command and Scripting Interpreter - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies path traversal command-line execution. This technique was seen in malicious document that execute malicious code using msdt.exe and path traversal technique that serve as defense evasion. This TTP is a good pivot to look for more suspicious process and command-line that runs before and after this execution. This may help you to find possible downloaded malware or other lolbin execution. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-06-01 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 58fcdeb1-728d-415d-b0d7-3ab18a275ec2 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes where Processes.process="*\/..\/..\/..\/*" OR Processes.process="*\\..\\..\\..\\*" OR Processes.process="*\/\/..\/\/..\/\/..\/\/*" by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.original_file_name Processes.process_id Processes.parent_process_id Processes.process_hash -| `drop_dm_object_name("Processes")` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_command_and_scripting_interpreter_path_traversal_exec_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_command_and_scripting_interpreter_path_traversal_exec_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product - -#### Known False Positives -Not known at this moment. - -#### Associated Analytic story -* [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics) -* [Microsoft Support Diagnostic Tool Vulnerability CVE-2022-30190](/stories/microsoft_support_diagnostic_tool_vulnerability_cve-2022-30190) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 90.0 | 90 | 100 | A parent process $parent_process_name$ has spawned a child $process_name$ with path traversal commandline $process$ in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://app.any.run/tasks/713f05d2-fe78-4b9d-a744-f7c133e3fafb/](https://app.any.run/tasks/713f05d2-fe78-4b9d-a744-f7c133e3fafb/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059/path_traversal/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059/path_traversal/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_command_and_scripting_interpreter_path_traversal_exec.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-06-01-windows_installutil_credential_theft.md b/docs/_posts/2022-06-01-windows_installutil_credential_theft.md deleted file mode 100644 index 41f5193809..0000000000 --- a/docs/_posts/2022-06-01-windows_installutil_credential_theft.md +++ /dev/null @@ -1,171 +0,0 @@ ---- -title: "Windows InstallUtil Credential Theft" -excerpt: "InstallUtil -, System Binary Proxy Execution -" -categories: - - Endpoint -last_modified_at: 2022-06-01 -toc: true -toc_label: "" -tags: - - InstallUtil - - System Binary Proxy Execution - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the Windows InstallUtil.exe binary loading `vaultcli.dll` and Samlib.dll`. This technique may be used to execute code to bypassing application control and capture credentials by utilizing a tool like MimiKatz. \ -When `InstallUtil.exe` is used in a malicous manner, the path to an executable on the filesystem is typically specified. Take note of the parent process. In a suspicious instance, this will be spawned from a non-standard process like `Cmd.exe`, `PowerShell.exe` or `Explorer.exe`. \ -If used by a developer, typically this will be found with multiple command-line switches/arguments and spawn from Visual Studio. \ -During triage review resulting network connections, file modifications, and parallel processes. Capture any artifacts and review further. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-06-01 -- **Author**: Michael Haag, Mauricio Velazo, Splunk -- **ID**: ccfeddec-43ec-11ec-b494-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218.004](https://attack.mitre.org/techniques/T1218/004/) | InstallUtil | Defense Evasion | - -| [T1218](https://attack.mitre.org/techniques/T1218/) | System Binary Proxy Execution | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventCode=7 process_name=installutil.exe ImageLoaded IN ("*\\samlib.dll", "*\\vaultcli.dll") -| stats count min(_time) as firstTime max(_time) as lastTime by Computer, process_name, ImageLoaded, OriginalFileName, ProcessId -| rename Computer as dest -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_installutil_credential_theft_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **windows_installutil_credential_theft_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and module loads from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -Typically this will not trigger as by it's very nature InstallUtil does not need credentials. Filter as needed. - -#### Associated Analytic story -* [Signed Binary Proxy Execution InstallUtil](/stories/signed_binary_proxy_execution_installutil) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ loading samlib.dll and vaultcli.dll to potentially capture credentials in memory. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://gist.github.com/xorrior/bbac3919ca2aef8d924bdf3b16cce3d0](https://gist.github.com/xorrior/bbac3919ca2aef8d924bdf3b16cce3d0) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.004/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.004/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_installutil_credential_theft.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-06-03-confluence_unauthenticated_remote_code_execution_cve-2022-26134.md b/docs/_posts/2022-06-03-confluence_unauthenticated_remote_code_execution_cve-2022-26134.md deleted file mode 100644 index 8efa8efaee..0000000000 --- a/docs/_posts/2022-06-03-confluence_unauthenticated_remote_code_execution_cve-2022-26134.md +++ /dev/null @@ -1,176 +0,0 @@ ---- -title: "Confluence Unauthenticated Remote Code Execution CVE-2022-26134" -excerpt: "Server Software Component -, Exploit Public-Facing Application -" -categories: - - Web -last_modified_at: 2022-06-03 -toc: true -toc_label: "" -tags: - - Server Software Component - - Exploit Public-Facing Application - - Persistence - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2022-26134 - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic assists with identifying CVE-2022-26134 based exploitation utilizing the Web datamodel to cover network and CIM compliant web logs. The parameters were captured from live scanning and the POC provided by Rapid7. This analytic is written against multiple proof of concept codes released and seen in the wild (scanning). During triage, review any endpoint based logs for further activity including writing a jsp file to disk and commands/processes spawning running as root from the Confluence process. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-06-03 -- **Author**: Michael Haag, Splunk -- **ID**: fcf4bd3f-a79f-4b7a-83bf-2692d60b859c - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1505](https://attack.mitre.org/techniques/T1505/) | Server Software Component | Persistence | - -| [T1190](https://attack.mitre.org/techniques/T1190/) | Exploit Public-Facing Application | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2022-26134](https://nvd.nist.gov/vuln/detail/CVE-2022-26134) | In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are from 1.3.0 before 7.4.17, from 7.13.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and from 7.18.0 before 7.18.1. | 7.5 | - - - -
-
- -#### Search - -``` - -| tstats count min(_time) as firstTime max(_time) as lastTime from datamodel=Web where Web.url IN ("*${*", "*%2F%7B*") (Web.url="*org.apache.commons.io.IOUtils*" Web.url="*java.lang.Runtime@getRuntime().exec*") OR (Web.url="*java.lang.Runtime%40getRuntime%28%29.exec*") OR (Web.url="*getEngineByName*" AND Web.url="*nashorn*" AND Web.url="*ProcessBuilder*") by Web.http_user_agent Web.http_method, Web.url,Web.url_length Web.src, Web.dest sourcetype -| `drop_dm_object_name("Web")` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `confluence_unauthenticated_remote_code_execution_cve_2022_26134_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **confluence_unauthenticated_remote_code_execution_cve-2022-26134_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Web.http_method -* Web.url -* Web.url_length -* Web.src -* Web.dest -* Web.http_user_agent - - -#### How To Implement -This detection requires the Web datamodel to be populated from a supported Technology Add-On like Splunk for Apache or Splunk for Nginx. In addition, network based logs or event data like PAN Threat. - -#### Known False Positives -Tune based on assets if possible, or restrict to known Confluence servers. Remove the ${ for a more broad query. To identify more exec, remove everything up to the last parameter (Runtime().exec) for a broad query. - -#### Associated Analytic story -* [Atlassian Confluence Server and Data Center CVE-2022-26134](/stories/atlassian_confluence_server_and_data_center_cve-2022-26134) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 100.0 | 100 | 100 | A URL was requested related to CVE-2022-26134, a unauthenticated remote code execution vulnerability, on $dest$ by $src$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html](https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html) -* [https://www.splunk.com/en_us/blog/security/atlassian-confluence-vulnerability-cve-2022-26134.html](https://www.splunk.com/en_us/blog/security/atlassian-confluence-vulnerability-cve-2022-26134.html) -* [https://www.rapid7.com/blog/post/2022/06/02/active-exploitation-of-confluence-cve-2022-26134/](https://www.rapid7.com/blog/post/2022/06/02/active-exploitation-of-confluence-cve-2022-26134/) -* [https://www.volexity.com/blog/2022/06/02/zero-day-exploitation-of-atlassian-confluence/](https://www.volexity.com/blog/2022/06/02/zero-day-exploitation-of-atlassian-confluence/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/java/confluence.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/java/confluence.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/web/confluence_unauthenticated_remote_code_execution_cve_2022_26134.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-06-03-excessive_usage_of_nslookup_app.md b/docs/_posts/2022-06-03-excessive_usage_of_nslookup_app.md deleted file mode 100644 index dfadb5ea68..0000000000 --- a/docs/_posts/2022-06-03-excessive_usage_of_nslookup_app.md +++ /dev/null @@ -1,165 +0,0 @@ ---- -title: "Excessive Usage of NSLOOKUP App" -excerpt: "Exfiltration Over Alternative Protocol -" -categories: - - Endpoint -last_modified_at: 2022-06-03 -toc: true -toc_label: "" -tags: - - Exfiltration Over Alternative Protocol - - Exfiltration - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect potential DNS exfiltration using nslookup application. This technique are seen in couple of malware and APT group to exfiltrated collected data in a infected machine or infected network. This detection is looking for unique use of nslookup where it tries to use specific record type (TXT, A, AAAA) that are commonly used by attacker and also the retry parameter which is designed to query C2 DNS multiple tries. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-06-03 -- **Author**: Teoderick Contreras, Stanislav Miskovic, Splunk -- **ID**: 0a69fdaa-a2b8-11eb-b16d-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1048](https://attack.mitre.org/techniques/T1048/) | Exfiltration Over Alternative Protocol | Exfiltration | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventCode = 1 process_name = "nslookup.exe" -| bucket _time span=1m -| stats count as numNsLookup by Computer, _time -| eventstats avg(numNsLookup) as avgNsLookup, stdev(numNsLookup) as stdNsLookup, count as numSlots by Computer -| eval upperThreshold=(avgNsLookup + stdNsLookup *3) -| eval isOutlier=if(numNsLookup > 20 and numNsLookup >= upperThreshold, 1, 0) -| search isOutlier=1 -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `excessive_usage_of_nslookup_app_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **excessive_usage_of_nslookup_app_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Computer -* process_name -* EventCode - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances of nslookup.exe may be used. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Suspicious DNS Traffic](/stories/suspicious_dns_traffic) -* [Dynamic DNS](/stories/dynamic_dns) -* [Data Exfiltration](/stories/data_exfiltration) -* [Command and Control](/stories/command_and_control) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 28.0 | 40 | 70 | Excessive usage of nslookup.exe has been detected on $Computer$. This detection is triggered as as it violates the dynamic threshold | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.mandiant.com/resources/fin7-spear-phishing-campaign-targets-personnel-involved-sec-filings](https://www.mandiant.com/resources/fin7-spear-phishing-campaign-targets-personnel-involved-sec-filings) -* [https://www.varonis.com/blog/dns-tunneling](https://www.varonis.com/blog/dns-tunneling) -* [https://www.microsoft.com/security/blog/2021/01/20/deep-dive-into-the-solorigate-second-stage-activation-from-sunburst-to-teardrop-and-raindrop/](https://www.microsoft.com/security/blog/2021/01/20/deep-dive-into-the-solorigate-second-stage-activation-from-sunburst-to-teardrop-and-raindrop/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1048.003/nslookup_exfil/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1048.003/nslookup_exfil/sysmon.log) -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1048.003/nslookup_exfil/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1048.003/nslookup_exfil/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/excessive_usage_of_nslookup_app.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-06-03-java_writing_jsp_file.md b/docs/_posts/2022-06-03-java_writing_jsp_file.md deleted file mode 100644 index 2179360efe..0000000000 --- a/docs/_posts/2022-06-03-java_writing_jsp_file.md +++ /dev/null @@ -1,188 +0,0 @@ ---- -title: "Java Writing JSP File" -excerpt: "Exploit Public-Facing Application -" -categories: - - Endpoint -last_modified_at: 2022-06-03 -toc: true -toc_label: "" -tags: - - Exploit Public-Facing Application - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2022-22965 - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the process java writing a .jsp to disk. This is potentially indicative of a web shell being written to disk. Modify and tune the analytic based on data ingested. For instance, it may be worth running a broad query for jsp file writes first before performing a join. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-06-03 -- **Author**: Michael Haag, Splunk -- **ID**: eb65619c-4f8d-4383-a975-d352765d344b - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1190](https://attack.mitre.org/techniques/T1190/) | Exploit Public-Facing Application | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2022-22965](https://nvd.nist.gov/vuln/detail/CVE-2022-22965) | A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it. | 7.5 | - - - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name IN ("java","java.exe", "javaw.exe") by _time Processes.process_id Processes.process_name Processes.dest Processes.process_guid Processes.user -| `drop_dm_object_name(Processes)` -| join process_guid [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Filesystem where Filesystem.file_name="*.jsp*" by _time Filesystem.dest Filesystem.file_create_time Filesystem.file_name Filesystem.file_path Filesystem.process_guid Filesystem.user -| `drop_dm_object_name(Filesystem)` -| fields _time process_guid file_path file_name file_create_time user dest process_name] -| stats count min(_time) as firstTime max(_time) as lastTime by dest process_name process_guid file_name file_path file_create_time user -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `java_writing_jsp_file_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **java_writing_jsp_file_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id -* Filesystem.dest -* Filesystem.file_create_time -* Filesystem.file_name -* Filesystem.file_path -* Filesystem.process_guid -* Filesystem.user - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` and `Filesystem` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -False positives are possible and filtering may be required. Restrict by assets or filter known jsp files that are common for the environment. - -#### Associated Analytic story -* [Spring4Shell CVE-2022-22965](/stories/spring4shell_cve-2022-22965) -* [Atlassian Confluence Server and Data Center CVE-2022-26134](/stories/atlassian_confluence_server_and_data_center_cve-2022-26134) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 42.0 | 60 | 70 | An instance of $process_name$ was identified on endpoint $dest$ writing a jsp file to disk, potentially indicative of exploitation. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.microsoft.com/security/blog/2022/04/04/springshell-rce-vulnerability-guidance-for-protecting-against-and-detecting-cve-2022-22965/](https://www.microsoft.com/security/blog/2022/04/04/springshell-rce-vulnerability-guidance-for-protecting-against-and-detecting-cve-2022-22965/) -* [https://github.com/TheGejr/SpringShell](https://github.com/TheGejr/SpringShell) -* [https://www.tenable.com/blog/spring4shell-faq-spring-framework-remote-code-execution-vulnerability](https://www.tenable.com/blog/spring4shell-faq-spring-framework-remote-code-execution-vulnerability) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/spring4shell/java_write_jsp-linux-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/spring4shell/java_write_jsp-linux-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/java_writing_jsp_file.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-06-03-linux_iptables_firewall_modification.md b/docs/_posts/2022-06-03-linux_iptables_firewall_modification.md deleted file mode 100644 index 8712816018..0000000000 --- a/docs/_posts/2022-06-03-linux_iptables_firewall_modification.md +++ /dev/null @@ -1,179 +0,0 @@ ---- -title: "Linux Iptables Firewall Modification" -excerpt: "Disable or Modify System Firewall -, Impair Defenses -" -categories: - - Endpoint -last_modified_at: 2022-06-03 -toc: true -toc_label: "" -tags: - - Disable or Modify System Firewall - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for suspicious commandline that modify the iptables firewall setting of a linux machine. This technique was seen in cyclopsblink malware where it modifies the firewall setting of the compromised machine to allow traffic to its tcp port that will be used to communicate with its C2 server. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-06-03 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 309d59dc-1e1b-49b2-9800-7cf18d12f7b7 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.004](https://attack.mitre.org/techniques/T1562/004/) | Disable or Modify System Firewall | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process = "*iptables *" AND Processes.process = "* --dport *" AND Processes.process = "* ACCEPT*" AND Processes.process = "*&>/dev/null*" AND Processes.process = "* tcp *" AND NOT(Processes.parent_process_path IN("/bin/*", "/lib/*", "/usr/bin/*", "/sbin/*")) by Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.process_guid Processes.dest _time span=10s Processes.user Processes.parent_process_name Processes.parent_process_path Processes.process_path -| rex field=Processes.process "--dport (?3269 -|636 -|989 -|994 -|995 -|8443)" -| stats values(Processes.process) as processes_exec values(port) as ports values(Processes.process_guid) as guids values(Processes.process_id) as pids dc(port) as port_count count by Processes.process_name Processes.parent_process_name Processes.parent_process_id Processes.dest Processes.user Processes.parent_process_path Processes.process_path -| where port_count >=3 -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `linux_iptables_firewall_modification_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **linux_iptables_firewall_modification_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase. - -#### Known False Positives -administrator may do this commandline for auditing and testing purposes. In this scenario filter is needed. - -#### Associated Analytic story -* [CyclopsBLink](/stories/cyclopsblink) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | A commandline $process$ that may modify iptables firewall on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.ncsc.gov.uk/files/Cyclops-Blink-Malware-Analysis-Report.pdf](https://www.ncsc.gov.uk/files/Cyclops-Blink-Malware-Analysis-Report.pdf) -* [https://www.trendmicro.com/en_us/research/22/c/cyclops-blink-sets-sights-on-asus-routers--.html](https://www.trendmicro.com/en_us/research/22/c/cyclops-blink-sets-sights-on-asus-routers--.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/cyclopsblink/sysmon_linux.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/cyclopsblink/sysmon_linux.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_iptables_firewall_modification.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2022-06-07-windows_impair_defense_delete_win_defender_context_menu.md b/docs/_posts/2022-06-07-windows_impair_defense_delete_win_defender_context_menu.md deleted file mode 100644 index 055066a576..0000000000 --- a/docs/_posts/2022-06-07-windows_impair_defense_delete_win_defender_context_menu.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: "Windows Impair Defense Delete Win Defender Context Menu" -excerpt: "Disable or Modify Tools -, Impair Defenses -" -categories: - - Endpoint -last_modified_at: 2022-06-07 -toc: true -toc_label: "" -tags: - - Disable or Modify Tools - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The search looks for the deletion of Windows Defender context menu within the registry. This is consistent behavior with RAT malware across a fleet of endpoints. This particular behavior is executed when an adversary gains access to an endpoint and begins to perform execution. Usually, a batch (.bat) will be executed and multiple registry and scheduled task modifications will occur. During triage, review parallel processes and identify any further file modifications. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-06-07 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 395ed5fe-ad13-4366-9405-a228427bdd91 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Delivery - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path = "*\\shellex\\ContextMenuHandlers\\EPP" Registry.action = deleted by Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid Registry.action Registry.dest Registry.user -| `drop_dm_object_name(Registry)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_impair_defense_delete_win_defender_context_menu_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_impair_defense_delete_win_defender_context_menu_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.registry_key_name -* Registry.registry_value_name -* Registry.dest -* Registry.user -* Registry.registry_path -* Registry.action - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. - -#### Known False Positives -It is unusual to turn this feature off a Windows system since it is a default security control, although it is not rare for some policies to disable it. Although no false positives have been identified, use the provided filter macro to tune the search. - -#### Associated Analytic story -* [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics) -* [Windows Registry Abuse](/stories/windows_registry_abuse) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | Windows Defender context menu registry key deleted on $dest$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://blog.malwarebytes.com/malwarebytes-news/2021/02/lazyscripter-from-empire-to-double-rat/](https://blog.malwarebytes.com/malwarebytes-news/2021/02/lazyscripter-from-empire-to-double-rat/) -* [https://app.any.run/tasks/45f5d114-91ea-486c-ab01-41c4093d2861/](https://app.any.run/tasks/45f5d114-91ea-486c-ab01-41c4093d2861/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/delete_win_defender_context_menu/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/delete_win_defender_context_menu/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_impair_defense_delete_win_defender_context_menu.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-06-07-windows_impair_defense_delete_win_defender_profile_registry.md b/docs/_posts/2022-06-07-windows_impair_defense_delete_win_defender_profile_registry.md deleted file mode 100644 index 13f5c42b38..0000000000 --- a/docs/_posts/2022-06-07-windows_impair_defense_delete_win_defender_profile_registry.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: "Windows Impair Defense Delete Win Defender Profile Registry" -excerpt: "Disable or Modify Tools -, Impair Defenses -" -categories: - - Endpoint -last_modified_at: 2022-06-07 -toc: true -toc_label: "" -tags: - - Disable or Modify Tools - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The search looks for the deletion of Windows Defender main profile within the registry. This was used by RAT malware across a fleet of endpoints. This particular behavior is typically executed when an adversary gains access to an endpoint and beings to perform execution. Usually, a batch (.bat) will be executed and multiple registry and scheduled task modifications will occur. During triage, review parallel processes and identify any further file modifications. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-06-07 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 65d4b105-ec52-48ec-ac46-289d0fbf7d96 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Delivery - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path = "*\\Policies\\Microsoft\\Windows Defender" Registry.action = deleted by Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid Registry.action Registry.user Registry.dest -| `drop_dm_object_name(Registry)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_impair_defense_delete_win_defender_profile_registry_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_impair_defense_delete_win_defender_profile_registry_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.registry_key_name -* Registry.registry_value_name -* Registry.dest -* Registry.user -* Registry.registry_path -* Registry.action - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. - -#### Known False Positives -It is unusual to turn this feature off a Windows system since it is a default security control, although it is not rare for some policies to disable it. Although no false positives have been identified, use the provided filter macro to tune the search. - -#### Associated Analytic story -* [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics) -* [Windows Registry Abuse](/stories/windows_registry_abuse) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 64.0 | 80 | 80 | Windows Defender Logger registry key set to 'disabled' on $dest$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://blog.malwarebytes.com/malwarebytes-news/2021/02/lazyscripter-from-empire-to-double-rat/](https://blog.malwarebytes.com/malwarebytes-news/2021/02/lazyscripter-from-empire-to-double-rat/) -* [https://app.any.run/tasks/45f5d114-91ea-486c-ab01-41c4093d2861/](https://app.any.run/tasks/45f5d114-91ea-486c-ab01-41c4093d2861/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/delete_win_defender_context_menu/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/delete_win_defender_context_menu/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_impair_defense_delete_win_defender_profile_registry.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-06-07-windows_impair_defenses_disable_win_defender_auto_logging.md b/docs/_posts/2022-06-07-windows_impair_defenses_disable_win_defender_auto_logging.md deleted file mode 100644 index 1dc2c0cb10..0000000000 --- a/docs/_posts/2022-06-07-windows_impair_defenses_disable_win_defender_auto_logging.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: "Windows Impair Defenses Disable Win Defender Auto Logging" -excerpt: "Disable or Modify Tools -, Impair Defenses -" -categories: - - Endpoint -last_modified_at: 2022-06-07 -toc: true -toc_label: "" -tags: - - Disable or Modify Tools - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The search looks for the Registry Key DefenderApiLogger or DefenderAuditLogger set to disable. This is consistent with RAT malware across a fleet of endpoints. This particular behavior is typically executed when an adversary gains access to an endpoint and beings to perform execution. Usually, a batch (.bat) will be executed and multiple registry and scheduled task modifications will occur. During triage, review parallel processes and identify any further file modifications. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-06-07 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 76406a0f-f5e0-4167-8e1f-337fdc0f1b0c - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Delivery - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where (Registry.registry_path = "*WMI\\Autologger\\DefenderApiLogger\\Start" OR Registry.registry_path = "*WMI\\Autologger\\DefenderAuditLogger\\Start") Registry.registry_value_data ="0x00000000" by Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid Registry.action Registry.dest Registry.user -| `drop_dm_object_name(Registry)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_impair_defenses_disable_win_defender_auto_logging_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_impair_defenses_disable_win_defender_auto_logging_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.registry_key_name -* Registry.registry_value_name -* Registry.dest -* Registry.user -* Registry.registry_path -* Registry.action - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. - -#### Known False Positives -It is unusual to turn this feature off a Windows system since it is a default security control, although it is not rare for some policies to disable it. Although no false positives have been identified, use the provided filter macro to tune the search. - -#### Associated Analytic story -* [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics) -* [Windows Registry Abuse](/stories/windows_registry_abuse) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 24.0 | 30 | 80 | Windows Defender Logger registry key set to 'disabled' on $dest$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://blog.malwarebytes.com/malwarebytes-news/2021/02/lazyscripter-from-empire-to-double-rat/](https://blog.malwarebytes.com/malwarebytes-news/2021/02/lazyscripter-from-empire-to-double-rat/) -* [https://app.any.run/tasks/45f5d114-91ea-486c-ab01-41c4093d2861/](https://app.any.run/tasks/45f5d114-91ea-486c-ab01-41c4093d2861/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/disable_defender_logging/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/disable_defender_logging/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_impair_defenses_disable_win_defender_auto_logging.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-06-13-windows_msiexec_spawn_discovery_command.md b/docs/_posts/2022-06-13-windows_msiexec_spawn_discovery_command.md deleted file mode 100644 index 13556e097f..0000000000 --- a/docs/_posts/2022-06-13-windows_msiexec_spawn_discovery_command.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: "Windows MSIExec Spawn Discovery Command" -excerpt: "Msiexec -" -categories: - - Endpoint -last_modified_at: 2022-06-13 -toc: true -toc_label: "" -tags: - - Msiexec - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies MSIExec spawning multiple discovery commands, including spawning Cmd.exe or PowerShell.exe. Typically, child processes are not common from MSIExec other than MSIExec spawning itself. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-06-13 -- **Author**: Michael Haag, Splunk -- **ID**: e9d05aa2-32f0-411b-930c-5b8ca5c4fcee - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218.007](https://attack.mitre.org/techniques/T1218/007/) | Msiexec | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=msiexec.exe Processes.process_name IN ("powershell.exe","cmd.exe", "nltest.exe","ipconfig.exe","systeminfo.exe") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_msiexec_spawn_discovery_command_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_msiexec_spawn_discovery_command_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -False positives will be present with MSIExec spawning Cmd or PowerShell. Filtering will be needed. In addition, add other known discovery processes to enhance query. - -#### Associated Analytic story -* [Windows System Binary Proxy Execution MSIExec](/stories/windows_system_binary_proxy_execution_msiexec) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 35.0 | 70 | 50 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ running different discovery commands. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://thedfirreport.com/2022/06/06/will-the-real-msiexec-please-stand-up-exploit-leads-to-data-exfiltration/](https://thedfirreport.com/2022/06/06/will-the-real-msiexec-please-stand-up-exploit-leads-to-data-exfiltration/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.007/T1218.007.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.007/T1218.007.md) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.007/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.007/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_msiexec_spawn_discovery_command.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-06-14-windows_msiexec_dllregisterserver.md b/docs/_posts/2022-06-14-windows_msiexec_dllregisterserver.md deleted file mode 100644 index 3ad5ce4a1d..0000000000 --- a/docs/_posts/2022-06-14-windows_msiexec_dllregisterserver.md +++ /dev/null @@ -1,171 +0,0 @@ ---- -title: "Windows MSIExec DLLRegisterServer" -excerpt: "Msiexec -" -categories: - - Endpoint -last_modified_at: 2022-06-14 -toc: true -toc_label: "" -tags: - - Msiexec - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the usage of msiexec.exe using the /y switch parameter, which grants the ability for msiexec to load DLLRegisterServer. Upon triage, review parent process and capture any artifacts for further review. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-06-14 -- **Author**: Michael Haag, Splunk -- **ID**: fdb59aef-d88f-4909-8369-ec2afbd2c398 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218.007](https://attack.mitre.org/techniques/T1218/007/) | Msiexec | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_msiexec` Processes.process IN ("*/y*", "*-y*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_msiexec_dllregisterserver_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [process_msiexec](https://github.com/splunk/security_content/blob/develop/macros/process_msiexec.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_msiexec_dllregisterserver_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -This analytic will need to be tuned for your environment based on legitimate usage of msiexec.exe. Filter as needed. - -#### Associated Analytic story -* [Windows System Binary Proxy Execution MSIExec](/stories/windows_system_binary_proxy_execution_msiexec) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 35.0 | 70 | 50 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to register a file. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://thedfirreport.com/2022/06/06/will-the-real-msiexec-please-stand-up-exploit-leads-to-data-exfiltration/](https://thedfirreport.com/2022/06/06/will-the-real-msiexec-please-stand-up-exploit-leads-to-data-exfiltration/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.007/T1218.007.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.007/T1218.007.md) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.007/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.007/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_msiexec_dllregisterserver.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-06-14-windows_msiexec_unregister_dllregisterserver.md b/docs/_posts/2022-06-14-windows_msiexec_unregister_dllregisterserver.md deleted file mode 100644 index cbeb3d8cca..0000000000 --- a/docs/_posts/2022-06-14-windows_msiexec_unregister_dllregisterserver.md +++ /dev/null @@ -1,171 +0,0 @@ ---- -title: "Windows MSIExec Unregister DLLRegisterServer" -excerpt: "Msiexec -" -categories: - - Endpoint -last_modified_at: 2022-06-14 -toc: true -toc_label: "" -tags: - - Msiexec - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the usage of msiexec.exe using the /z switch parameter, which grants the ability for msiexec to unload DLLRegisterServer. Upon triage, review parent process and capture any artifacts for further review. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-06-14 -- **Author**: Michael Haag, Splunk -- **ID**: a27db3c5-1a9a-46df-a577-765d3f1a3c24 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218.007](https://attack.mitre.org/techniques/T1218/007/) | Msiexec | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_msiexec` Processes.process IN ("*/z*", "*-z*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_msiexec_unregister_dllregisterserver_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [process_msiexec](https://github.com/splunk/security_content/blob/develop/macros/process_msiexec.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_msiexec_unregister_dllregisterserver_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -This analytic will need to be tuned for your environment based on legitimate usage of msiexec.exe. Filter as needed. - -#### Associated Analytic story -* [Windows System Binary Proxy Execution MSIExec](/stories/windows_system_binary_proxy_execution_msiexec) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 35.0 | 70 | 50 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to unregister a file. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://thedfirreport.com/2022/06/06/will-the-real-msiexec-please-stand-up-exploit-leads-to-data-exfiltration/](https://thedfirreport.com/2022/06/06/will-the-real-msiexec-please-stand-up-exploit-leads-to-data-exfiltration/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.007/T1218.007.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.007/T1218.007.md) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.007/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.007/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_msiexec_unregister_dllregisterserver.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-06-16-detect_risky_spl_using_pretrained_ml_model.md b/docs/_posts/2022-06-16-detect_risky_spl_using_pretrained_ml_model.md deleted file mode 100644 index 6bc96fbb5e..0000000000 --- a/docs/_posts/2022-06-16-detect_risky_spl_using_pretrained_ml_model.md +++ /dev/null @@ -1,167 +0,0 @@ ---- -title: "Detect Risky SPL using Pretrained ML Model" -excerpt: "Command and Scripting Interpreter -" -categories: - - Application -last_modified_at: 2022-06-16 -toc: true -toc_label: "" -tags: - - Command and Scripting Interpreter - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2022-32154 - - Splunk_Audit ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic uses a pretrained machine learning text classifier to detect potentially risky commands. The model is trained independently and then the model file is packaged within ESCU for usage. A command is deemed risky based on the presence of certain trigger keywords, along with the context and the role of the user (please see references). The model uses custom features to predict whether a SPL is risky using text classification. The model takes as input the command text, user and search type and outputs a risk score between [0,1]. A high score indicates higher likelihood of a command being risky. This model is on-prem only. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Splunk_Audit](https://docs.splunk.com/Documentation/CIM/latest/User/SplunkAudit) -- **Last Updated**: 2022-06-16 -- **Author**: Abhinav Mishra, Kumar Sharad, Namratha Sreekanta and Xiao Lin, Splunk -- **ID**: b4aefb5f-1037-410d-a149-1e091288ba33 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.AE - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 6 - - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2022-32154](https://nvd.nist.gov/vuln/detail/CVE-2022-32154) | Dashboards in Splunk Enterprise versions before 9.0 might let an attacker inject risky search commands into a form token when the token is used in a query in a cross-origin request. The result bypasses SPL safeguards for risky commands. See New capabilities can limit access to some custom and potentially risky commands (https://docs.splunk.com/Documentation/Splunk/9.0.0/Security/SPLsafeguards#New_capabilities_can_limit_access_to_some_custom_and_potentially_risky_commands) for more information. Note that the attack is browser-based and an attacker cannot exploit it at will. | 4.0 | - - - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Splunk_Audit.Search_Activity where Search_Activity.search_type=adhoc Search_Activity.user!=splunk-system-user by Search_Activity.search Search_Activity.user Search_Activity.search_type -| eval spl_text = 'Search_Activity.search'. " " .'Search_Activity.user'. " " .'Search_Activity.search_type' -| dedup spl_text -| apply risky_spl_pre_trained_model -| where risk_score > 0.5 -| `drop_dm_object_name(Search_Activity)` -| table search, user, search_type, risk_score -| `detect_risky_spl_using_pretrained_ml_model_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **detect_risky_spl_using_pretrained_ml_model_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Search_Activity.search -* Search_Activity.user -* Search_Activity.search_type - - -#### How To Implement -This detection depends on the MLTK app which can be found here - https://splunkbase.splunk.com/app/2890/ and the Splunk Audit datamodel which can be found here - https://splunkbase.splunk.com/app/1621/. Additionally, you need to be ingesting logs which include Search_Activity.search, Search_Activity.user, Search_Activity.search_type from your endpoints. The risk score threshold should be adjusted based on the environment. The detection uses a custom MLTK model hence we need a few more steps for deployment, as outlined here - https://gist.github.com/ksharad-splunk/be2a62227966049047f5e5c4f2adcabb. - -#### Known False Positives -False positives may be present if suspicious behavior is observed, as determined by frequent usage of risky keywords. - -#### Associated Analytic story -* [Splunk Vulnerabilities](/stories/splunk_vulnerabilities) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 20.0 | 50 | 40 | A potentially risky Splunk command has been run by $user$, kindly review. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://docs.splunk.com/Documentation/Splunk/latest/Security/SPLsafeguards#Commands_that_trigger_the_warning](https://docs.splunk.com/Documentation/Splunk/latest/Security/SPLsafeguards#Commands_that_trigger_the_warning) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://github.com/splunk/attack_data/raw/master/datasets/attack_techniques/T1203/search_activity.txt](https://github.com/splunk/attack_data/raw/master/datasets/attack_techniques/T1203/search_activity.txt) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/application/detect_risky_spl_using_pretrained_ml_model.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-06-16-windows_msiexec_remote_download.md b/docs/_posts/2022-06-16-windows_msiexec_remote_download.md deleted file mode 100644 index 42ead5cf1b..0000000000 --- a/docs/_posts/2022-06-16-windows_msiexec_remote_download.md +++ /dev/null @@ -1,171 +0,0 @@ ---- -title: "Windows MSIExec Remote Download" -excerpt: "Msiexec -" -categories: - - Endpoint -last_modified_at: 2022-06-16 -toc: true -toc_label: "" -tags: - - Msiexec - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies msiexec.exe with http in the command-line. This procedure will utilize msiexec.exe to download a remote file and load it. During triage, review parallel processes and capture any artifacts on disk for review. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-06-16 -- **Author**: Michael Haag, Splunk -- **ID**: 6aa49ff2-3c92-4586-83e0-d83eb693dfda - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218.007](https://attack.mitre.org/techniques/T1218/007/) | Msiexec | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_msiexec` Processes.process IN ("*http://*", "*https://*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_msiexec_remote_download_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [process_msiexec](https://github.com/splunk/security_content/blob/develop/macros/process_msiexec.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_msiexec_remote_download_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -False positives may be present, filter by destination or parent process as needed. - -#### Associated Analytic story -* [Windows System Binary Proxy Execution MSIExec](/stories/windows_system_binary_proxy_execution_msiexec) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 35.0 | 70 | 50 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to download a remote file. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://thedfirreport.com/2022/06/06/will-the-real-msiexec-please-stand-up-exploit-leads-to-data-exfiltration/](https://thedfirreport.com/2022/06/06/will-the-real-msiexec-please-stand-up-exploit-leads-to-data-exfiltration/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.007/T1218.007.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.007/T1218.007.md) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.007/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.007/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_msiexec_remote_download.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-06-16-windows_msiexec_with_network_connections.md b/docs/_posts/2022-06-16-windows_msiexec_with_network_connections.md deleted file mode 100644 index d0b36e3649..0000000000 --- a/docs/_posts/2022-06-16-windows_msiexec_with_network_connections.md +++ /dev/null @@ -1,174 +0,0 @@ ---- -title: "Windows MSIExec With Network Connections" -excerpt: "Msiexec -" -categories: - - Endpoint -last_modified_at: 2022-06-16 -toc: true -toc_label: "" -tags: - - Msiexec - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies MSIExec with any network connection over port 443 or 80. Typically, MSIExec does not perform network communication to the internet. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-06-16 -- **Author**: Michael Haag, Splunk -- **ID**: 827409a1-5393-4d8d-8da4-bbb297c262a7 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218.007](https://attack.mitre.org/techniques/T1218/007/) | Msiexec | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where `process_msiexec` by _time Processes.process_id Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| join process_id [ -| tstats `security_content_summariesonly` count FROM datamodel=Network_Traffic.All_Traffic where All_Traffic.dest_port IN ("80","443") by All_Traffic.process_id All_Traffic.dest All_Traffic.dest_port All_Traffic.dest_ip -| `drop_dm_object_name(All_Traffic)` ] -| table _time dest parent_process_name process_name process_path process process_id dest_port dest_ip -| `windows_msiexec_with_network_connections_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [process_msiexec](https://github.com/splunk/security_content/blob/develop/macros/process_msiexec.yml) -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_msiexec_with_network_connections_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process_id -* Processes.process_name -* Processes.dest -* Processes.process_path -* Processes.process -* Processes.parent_process_name -* All_Traffic.process_id -* All_Traffic.dest -* All_Traffic.dest_port -* All_Traffic.dest_ip - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. Add parent process as a filter, filter known good processes. This may be voluminous due to the join on process_id. All_Traffic does not have process_guid, yet. - -#### Known False Positives -False positives will be present and filtering is required. - -#### Associated Analytic story -* [Windows System Binary Proxy Execution MSIExec](/stories/windows_system_binary_proxy_execution_msiexec) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 35.0 | 70 | 50 | An instance of $process_name$ was identified on endpoint $dest$ contacting a remote destination. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://thedfirreport.com/2022/06/06/will-the-real-msiexec-please-stand-up-exploit-leads-to-data-exfiltration/](https://thedfirreport.com/2022/06/06/will-the-real-msiexec-please-stand-up-exploit-leads-to-data-exfiltration/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.007/T1218.007.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.007/T1218.007.md) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.007/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.007/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_msiexec_with_network_connections.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-06-21-aws_ecr_container_scanning_findings_high.md b/docs/_posts/2022-06-21-aws_ecr_container_scanning_findings_high.md deleted file mode 100644 index 68334536f8..0000000000 --- a/docs/_posts/2022-06-21-aws_ecr_container_scanning_findings_high.md +++ /dev/null @@ -1,174 +0,0 @@ ---- -title: "AWS ECR Container Scanning Findings High" -excerpt: "Malicious Image -, User Execution -" -categories: - - Cloud -last_modified_at: 2022-06-21 -toc: true -toc_label: "" -tags: - - Malicious Image - - User Execution - - Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for AWS CloudTrail events from AWS Elastic Container Service (ECR). You need to activate image scanning in order to get the event DescribeImageScanFindings with the results. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-06-21 -- **Author**: Patrick Bareiss, Splunk -- **ID**: 62721bd2-1d82-4623-b6e6-aac170014423 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1204.003](https://attack.mitre.org/techniques/T1204/003/) | Malicious Image | Execution | - -| [T1204](https://attack.mitre.org/techniques/T1204/) | User Execution | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.DS -* PR.AC -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 13 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cloudtrail` eventSource=ecr.amazonaws.com eventName=DescribeImageScanFindings -| spath path=responseElements.imageScanFindings.findings{} output=findings -| mvexpand findings -| spath input=findings -| search severity=HIGH -| rename name as finding_name, description as finding_description, requestParameters.imageId.imageDigest as imageDigest, requestParameters.repositoryName as image -| eval finding = finding_name.", ".finding_description -| eval phase="release" -| eval severity="high" -| stats min(_time) as firstTime max(_time) as lastTime by awsRegion, eventName, eventSource, imageDigest, image, userName, src_ip, finding, phase, severity -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `aws_ecr_container_scanning_findings_high_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) - -> :information_source: -> **aws_ecr_container_scanning_findings_high_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* eventSource -* eventName -* responseElements.imageScanFindings.findings{} -* awsRegion -* requestParameters.imageId.imageDigest -* requestParameters.repositoryName -* user -* userName -* src_ip - - -#### How To Implement -You must install splunk AWS add on and Splunk App for AWS. This search works with AWS CloudTrail logs. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Dev Sec Ops](/stories/dev_sec_ops) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 70.0 | 70 | 100 | Vulnerabilities with severity high found in image $image$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://docs.aws.amazon.com/AmazonECR/latest/userguide/image-scanning.html](https://docs.aws.amazon.com/AmazonECR/latest/userguide/image-scanning.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/aws_ecr_container_scanning_findings_high.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-06-21-windows_gather_victim_network_info_through_ip_check_web_services.md b/docs/_posts/2022-06-21-windows_gather_victim_network_info_through_ip_check_web_services.md deleted file mode 100644 index 4e5ebec2f9..0000000000 --- a/docs/_posts/2022-06-21-windows_gather_victim_network_info_through_ip_check_web_services.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: "Windows Gather Victim Network Info Through Ip Check Web Services" -excerpt: "IP Addresses -, Gather Victim Network Information -" -categories: - - Endpoint -last_modified_at: 2022-06-21 -toc: true -toc_label: "" -tags: - - IP Addresses - - Gather Victim Network Information - - Reconnaissance - - Reconnaissance - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies process that attempts to connect to a known IP web services. This technique is commonly used by trickbot and other malware to perform reconnaissance against the infected machine and look for its IP address. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-06-21 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 70f7c952-0758-46d6-9148-d8969c4481d1 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1590.005](https://attack.mitre.org/techniques/T1590/005/) | IP Addresses | Reconnaissance | - -| [T1590](https://attack.mitre.org/techniques/T1590/) | Gather Victim Network Information | Reconnaissance | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventCode=22 QueryName IN ("*wtfismyip.com", "*checkip.amazonaws.com", "*ipecho.net", "*ipinfo.io", "*api.ipify.org", "*icanhazip.com", "*ip.anysrc.com","*api.ip.sb", "ident.me", "www.myexternalip.com", "*zen.spamhaus.org", "*cbl.abuseat.org", "*b.barracudacentral.org", "*dnsbl-1.uceprotect.net", "*spam.dnsbl.sorbs.net", "*iplogger.org*", "*ip-api.com*") -| stats min(_time) as firstTime max(_time) as lastTime count by Image ProcessId QueryName QueryStatus QueryResults Computer EventCode -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_gather_victim_network_info_through_ip_check_web_services_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **windows_gather_victim_network_info_through_ip_check_web_services_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Image -* ProcessId -* QueryName -* QueryStatus -* QueryResults -* Computer -* EventCode - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, dns query name process path , and query ststus from your endpoints like EventCode 22. If you are using Sysmon, you must have at least version 12 of the Sysmon TA. - -#### Known False Positives -Filter internet browser application to minimize the false positive of this detection. - -#### Associated Analytic story -* [Azorult](/stories/azorult) -* [DarkCrystal RAT](/stories/darkcrystal_rat) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | process connecting IP location web services on $Computer$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://app.any.run/tasks/a6f2ffe2-e6e2-4396-ae2e-04ea0143f2d8/](https://app.any.run/tasks/a6f2ffe2-e6e2-4396-ae2e-04ea0143f2d8/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/azorult/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/azorult/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_gather_victim_network_info_through_ip_check_web_services.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-06-21-windows_remote_services_allow_rdp_in_firewall.md b/docs/_posts/2022-06-21-windows_remote_services_allow_rdp_in_firewall.md deleted file mode 100644 index 9f289eb00b..0000000000 --- a/docs/_posts/2022-06-21-windows_remote_services_allow_rdp_in_firewall.md +++ /dev/null @@ -1,171 +0,0 @@ ---- -title: "Windows Remote Services Allow Rdp In Firewall" -excerpt: "Remote Desktop Protocol -, Remote Services -" -categories: - - Endpoint -last_modified_at: 2022-06-21 -toc: true -toc_label: "" -tags: - - Remote Desktop Protocol - - Remote Services - - Lateral Movement - - Lateral Movement - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic is to identify a modification in the Windows firewall to enable remote desktop protocol on a targeted machine. This technique was seen in several adversaries, malware or red teamer to remotely access the compromised or targeted host by allowing this protocol in firewall. Even this protocol might be allowed in some production environment, This TTP behavior is a good pivot to check who and why the user want to enable this feature through firewall which is also common traits of attack to start lateral movement. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-06-21 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 9170cb54-ea15-41e1-9dfc-9f3363ce9b02 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1021.001](https://attack.mitre.org/techniques/T1021/001/) | Remote Desktop Protocol | Lateral Movement | - -| [T1021](https://attack.mitre.org/techniques/T1021/) | Remote Services | Lateral Movement | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` values(Processes.process) as cmdline values(Processes.parent_process_name) as parent_process values(Processes.process_name) count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name = "netsh.exe" OR Processes.original_file_name= "netsh.exe") AND Processes.process = "*firewall*" AND Processes.process = "*add*" AND Processes.process = "*protocol=TCP*" AND Processes.process = "*localport=3389*" AND Processes.process = "*action=allow*" by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_remote_services_allow_rdp_in_firewall_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_remote_services_allow_rdp_in_firewall_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process_name -* Processes.process -* Processes.parent_process_name -* Processes.parent_process -* Processes.process_id -* Processes.parent_process_id -* Processes.dest -* Processes.user - - -#### How To Implement -To successfully implement this search, you must be ingesting data that records process activity from your hosts to populate the endpoint data model in the processes node. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -administrators may enable or disable this feature that may cause some false positive. - -#### Associated Analytic story -* [Azorult](/stories/azorult) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | new firewall rules was added to allow rdp connection to $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://app.any.run/tasks/a6f2ffe2-e6e2-4396-ae2e-04ea0143f2d8/](https://app.any.run/tasks/a6f2ffe2-e6e2-4396-ae2e-04ea0143f2d8/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/azorult/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/azorult/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_remote_services_allow_rdp_in_firewall.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-06-21-windows_remote_services_allow_remote_assistance.md b/docs/_posts/2022-06-21-windows_remote_services_allow_remote_assistance.md deleted file mode 100644 index 1467125892..0000000000 --- a/docs/_posts/2022-06-21-windows_remote_services_allow_remote_assistance.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: "Windows Remote Services Allow Remote Assistance" -excerpt: "Remote Desktop Protocol -, Remote Services -" -categories: - - Endpoint -last_modified_at: 2022-06-21 -toc: true -toc_label: "" -tags: - - Remote Desktop Protocol - - Remote Services - - Lateral Movement - - Lateral Movement - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic is to identify a modification in the Windows registry to enable remote desktop assistance on a targeted machine. This technique was seen in several adversaries, malware or red teamer like azorult to remotely access the compromised or targeted host by enabling this protocol in registry. Even this protocol might be allowed in some production environment, This Anomaly behavior is a good pivot to check who and why the user want to enable this feature through registry which is un-common. And as per stated in microsoft documentation the default value of this registry is false that makes this a good indicator of suspicious behavior. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-06-21 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 9bce3a97-bc97-4e89-a1aa-ead151c82fbb - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1021.001](https://attack.mitre.org/techniques/T1021/001/) | Remote Desktop Protocol | Lateral Movement | - -| [T1021](https://attack.mitre.org/techniques/T1021/) | Remote Services | Lateral Movement | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path= "*\\Control\\Terminal Server\\fAllowToGetHelp*" Registry.registry_value_data="0x00000001" by Registry.registry_key_name Registry.user Registry.registry_path Registry.registry_value_data Registry.action Registry.dest -| `drop_dm_object_name(Registry)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_remote_services_allow_remote_assistance_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_remote_services_allow_remote_assistance_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.registry_key_name -* Registry.registry_path -* Registry.user -* Registry.dest -* Registry.registry_value_name -* Registry.action - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. - -#### Known False Positives -administrators may enable or disable this feature that may cause some false positive. - -#### Associated Analytic story -* [Azorult](/stories/azorult) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | the registry for rdp protocol was modified to enable in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://docs.microsoft.com/en-us/windows-hardware/customize/desktop/unattend/microsoft-windows-remoteassistance-exe-fallowtogethelp](https://docs.microsoft.com/en-us/windows-hardware/customize/desktop/unattend/microsoft-windows-remoteassistance-exe-fallowtogethelp) -* [https://app.any.run/tasks/a6f2ffe2-e6e2-4396-ae2e-04ea0143f2d8/](https://app.any.run/tasks/a6f2ffe2-e6e2-4396-ae2e-04ea0143f2d8/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/azorult/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/azorult/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_remote_services_allow_remote_assistance.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-06-21-windows_remote_services_rdp_enable.md b/docs/_posts/2022-06-21-windows_remote_services_rdp_enable.md deleted file mode 100644 index ffd7f8fac5..0000000000 --- a/docs/_posts/2022-06-21-windows_remote_services_rdp_enable.md +++ /dev/null @@ -1,169 +0,0 @@ ---- -title: "Windows Remote Services Rdp Enable" -excerpt: "Remote Desktop Protocol -, Remote Services -" -categories: - - Endpoint -last_modified_at: 2022-06-21 -toc: true -toc_label: "" -tags: - - Remote Desktop Protocol - - Remote Services - - Lateral Movement - - Lateral Movement - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic is to identify a modification in the Windows registry to enable remote desktop protocol on a targeted machine. This technique was seen in several adversaries, malware or red teamer to remotely access the compromised or targeted host by enabling this protocol in registry. Even this protocol might be allowed in some production environment, This TTP behavior is a good pivot to check who and why the user want to enable this feature through registry which is un-common. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-06-21 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 8fbd2e88-4ea5-40b9-9217-fd0855e08cc0 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1021.001](https://attack.mitre.org/techniques/T1021/001/) | Remote Desktop Protocol | Lateral Movement | - -| [T1021](https://attack.mitre.org/techniques/T1021/) | Remote Services | Lateral Movement | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path= "*\\Control\\Terminal Server\\fDenyTSConnections*" Registry.registry_value_data="0x00000000" by Registry.registry_key_name Registry.user Registry.registry_path Registry.registry_value_data Registry.action Registry.dest -| `drop_dm_object_name(Registry)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_remote_services_rdp_enable_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_remote_services_rdp_enable_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.registry_key_name -* Registry.registry_path -* Registry.user -* Registry.dest -* Registry.registry_value_name -* Registry.action - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. - -#### Known False Positives -administrators may enable or disable this feature that may cause some false positive. - -#### Associated Analytic story -* [Azorult](/stories/azorult) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | the registry for rdp protocol was modified to enable in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.hybrid-analysis.com/sample/9d6611c2779316f1ef4b4a6edcfdfb5e770fe32b31ec2200df268c3bd236ed75?environmentId=100](https://www.hybrid-analysis.com/sample/9d6611c2779316f1ef4b4a6edcfdfb5e770fe32b31ec2200df268c3bd236ed75?environmentId=100) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/azorult/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/azorult/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_remote_services_rdp_enable.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-06-21-windows_service_stop_by_deletion.md b/docs/_posts/2022-06-21-windows_service_stop_by_deletion.md deleted file mode 100644 index fe4e2a8944..0000000000 --- a/docs/_posts/2022-06-21-windows_service_stop_by_deletion.md +++ /dev/null @@ -1,168 +0,0 @@ ---- -title: "Windows Service Stop By Deletion" -excerpt: "Service Stop -" -categories: - - Endpoint -last_modified_at: 2022-06-21 -toc: true -toc_label: "" -tags: - - Service Stop - - Impact - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies Windows Service Control, `sc.exe`, attempting to delete a service. This is typically identified in parallel with other instances of service enumeration of attempts to stop a service and then delete it. Adversaries utilize this technique to terminate security services or other related services to continue there objective and evade detections. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-06-21 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 196ff536-58d9-4d1b-9686-b176b04e430b - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1489](https://attack.mitre.org/techniques/T1489/) | Service Stop | Impact | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name = sc.exe OR Processes.original_file_name = sc.exe) Processes.process="* delete *" by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_service_stop_by_deletion_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_service_stop_by_deletion_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process_name -* Processes.process -* Processes.parent_process_name -* Processes.parent_process -* Processes.process_id -* Processes.parent_process_id -* Processes.dest -* Processes.user - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -It is possible administrative scripts may start/stop/delete services. Filter as needed. - -#### Associated Analytic story -* [Azorult](/stories/azorult) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ attempting to delete a service. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://app.any.run/tasks/a6f2ffe2-e6e2-4396-ae2e-04ea0143f2d8/](https://app.any.run/tasks/a6f2ffe2-e6e2-4396-ae2e-04ea0143f2d8/) -* [https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/](https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1543.003/T1543.003.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1543.003/T1543.003.md) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/azorult/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/azorult/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_service_stop_by_deletion.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-06-22-windows_modify_registry_disable_toast_notifications.md b/docs/_posts/2022-06-22-windows_modify_registry_disable_toast_notifications.md deleted file mode 100644 index d49d990792..0000000000 --- a/docs/_posts/2022-06-22-windows_modify_registry_disable_toast_notifications.md +++ /dev/null @@ -1,165 +0,0 @@ ---- -title: "Windows Modify Registry Disable Toast Notifications" -excerpt: "Modify Registry -" -categories: - - Endpoint -last_modified_at: 2022-06-22 -toc: true -toc_label: "" -tags: - - Modify Registry - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic is to identify a modification in the Windows registry to disable toast notifications. This Windows Operating System feature is responsible for alerting or notifying user if application or OS need some updates. Adversaries and malwares like Azorult abuse this technique to disable important update notification in compromised host. This anomaly detection is a good pivot to look for further events related to defense evasion and execution. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-06-22 -- **Author**: Teoderick Contreras, Splunk -- **ID**: ed4eeacb-8d5a-488e-bc97-1ce6ded63b84 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1112](https://attack.mitre.org/techniques/T1112/) | Modify Registry | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\PushNotifications\\ToastEnabled*" Registry.registry_value_data="0x00000000" by Registry.registry_key_name Registry.user Registry.registry_path Registry.registry_value_data Registry.action Registry.dest -| `drop_dm_object_name(Registry)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_modify_registry_disable_toast_notifications_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_modify_registry_disable_toast_notifications_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.registry_key_name -* Registry.registry_path -* Registry.user -* Registry.dest -* Registry.registry_value_name -* Registry.action - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. - -#### Known False Positives -administrators may enable or disable this feature that may cause some false positive. - -#### Associated Analytic story -* [Azorult](/stories/azorult) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | the registry for DisallowRun settings was modified to enable in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://docs.microsoft.com/en-us/windows-hardware/customize/desktop/unattend/microsoft-windows-remoteassistance-exe-fallowtogethelp](https://docs.microsoft.com/en-us/windows-hardware/customize/desktop/unattend/microsoft-windows-remoteassistance-exe-fallowtogethelp) -* [https://app.any.run/tasks/a6f2ffe2-e6e2-4396-ae2e-04ea0143f2d8/](https://app.any.run/tasks/a6f2ffe2-e6e2-4396-ae2e-04ea0143f2d8/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/azorult/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/azorult/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_modify_registry_disable_toast_notifications.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-06-22-windows_modify_registry_disable_windows_security_center_notif.md b/docs/_posts/2022-06-22-windows_modify_registry_disable_windows_security_center_notif.md deleted file mode 100644 index 7c5be7d25a..0000000000 --- a/docs/_posts/2022-06-22-windows_modify_registry_disable_windows_security_center_notif.md +++ /dev/null @@ -1,165 +0,0 @@ ---- -title: "Windows Modify Registry Disable Windows Security Center Notif" -excerpt: "Modify Registry -" -categories: - - Endpoint -last_modified_at: 2022-06-22 -toc: true -toc_label: "" -tags: - - Modify Registry - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic is to identify a modification in the Windows registry to disable windows center notifications. This Windows Operating System feature is responsible for alerting or notifying user if application or OS need some updates. Adversaries and malwares like Azorult abuse this technique to disable important update notification in compromised host. This anomaly detection is a good pivot to look for further events related to defense evasion and execution. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-06-22 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 27ed3e79-6d86-44dd-b9ab-524451c97a7b - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1112](https://attack.mitre.org/techniques/T1112/) | Modify Registry | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path= "*\\Windows\\CurrentVersion\\ImmersiveShell\\UseActionCenterExperience*" Registry.registry_value_data="0x00000000" by Registry.registry_key_name Registry.user Registry.registry_path Registry.registry_value_data Registry.action Registry.dest -| `drop_dm_object_name(Registry)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_modify_registry_disable_windows_security_center_notif_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_modify_registry_disable_windows_security_center_notif_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.registry_key_name -* Registry.registry_path -* Registry.user -* Registry.dest -* Registry.registry_value_name -* Registry.action - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. - -#### Known False Positives -administrators may enable or disable this feature that may cause some false positive. - -#### Associated Analytic story -* [Azorult](/stories/azorult) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | the registry for security center notification settings was modified to disable mode in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://docs.microsoft.com/en-us/windows-hardware/customize/desktop/unattend/microsoft-windows-remoteassistance-exe-fallowtogethelp](https://docs.microsoft.com/en-us/windows-hardware/customize/desktop/unattend/microsoft-windows-remoteassistance-exe-fallowtogethelp) -* [https://app.any.run/tasks/a6f2ffe2-e6e2-4396-ae2e-04ea0143f2d8/](https://app.any.run/tasks/a6f2ffe2-e6e2-4396-ae2e-04ea0143f2d8/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/azorult/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/azorult/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_modify_registry_disable_windows_security_center_notif.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-06-22-windows_modify_registry_disabling_wer_settings.md b/docs/_posts/2022-06-22-windows_modify_registry_disabling_wer_settings.md deleted file mode 100644 index 0539f5fe14..0000000000 --- a/docs/_posts/2022-06-22-windows_modify_registry_disabling_wer_settings.md +++ /dev/null @@ -1,165 +0,0 @@ ---- -title: "Windows Modify Registry Disabling WER Settings" -excerpt: "Modify Registry -" -categories: - - Endpoint -last_modified_at: 2022-06-22 -toc: true -toc_label: "" -tags: - - Modify Registry - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies a modification in the Windows registry to disable Windows error reporting settings. This Windows feature allows the user to report bugs, errors, failure or problems encountered in specific application or processes. Adversaries use this technique to hide any error or failure that some of its malicious components trigger. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-06-22 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 21cbcaf1-b51f-496d-a0c1-858ff3070452 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1112](https://attack.mitre.org/techniques/T1112/) | Modify Registry | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\Windows Error Reporting\\disable*" Registry.registry_value_data="0x00000001" by Registry.registry_key_name Registry.user Registry.registry_path Registry.registry_value_data Registry.action Registry.dest -| `drop_dm_object_name(Registry)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_modify_registry_disabling_wer_settings_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_modify_registry_disabling_wer_settings_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.registry_key_name -* Registry.registry_path -* Registry.user -* Registry.dest -* Registry.registry_value_name -* Registry.action - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. - -#### Known False Positives -Administrators may enable or disable this feature that may cause some false positive, however is not common. Filter as needed. - -#### Associated Analytic story -* [Azorult](/stories/azorult) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | the registry for WER settings was modified to be disabled on $dest$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://docs.microsoft.com/en-us/windows-hardware/customize/desktop/unattend/microsoft-windows-remoteassistance-exe-fallowtogethelp](https://docs.microsoft.com/en-us/windows-hardware/customize/desktop/unattend/microsoft-windows-remoteassistance-exe-fallowtogethelp) -* [https://app.any.run/tasks/a6f2ffe2-e6e2-4396-ae2e-04ea0143f2d8/](https://app.any.run/tasks/a6f2ffe2-e6e2-4396-ae2e-04ea0143f2d8/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/azorult/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/azorult/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_modify_registry_disabling_wer_settings.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-06-22-windows_modify_registry_disallow_windows_app.md b/docs/_posts/2022-06-22-windows_modify_registry_disallow_windows_app.md deleted file mode 100644 index aaef9baf7c..0000000000 --- a/docs/_posts/2022-06-22-windows_modify_registry_disallow_windows_app.md +++ /dev/null @@ -1,164 +0,0 @@ ---- -title: "Windows Modify Registry DisAllow Windows App" -excerpt: "Modify Registry -" -categories: - - Endpoint -last_modified_at: 2022-06-22 -toc: true -toc_label: "" -tags: - - Modify Registry - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies modification in the Windows registry to prevent user running specific computer programs that could aid them in manually removing malware or detecting it using security products. This technique was recently identified in Azorult malware where it uses this registry value to prevent several AV products to execute on the compromised host machine. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-06-22 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 4bc788d3-c83a-48c5-a4e2-e0c6dba57889 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1112](https://attack.mitre.org/techniques/T1112/) | Modify Registry | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\DisallowRun*" Registry.registry_value_data="0x00000001" by Registry.registry_key_name Registry.user Registry.registry_path Registry.registry_value_data Registry.action Registry.dest -| `drop_dm_object_name(Registry)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_modify_registry_disallow_windows_app_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_modify_registry_disallow_windows_app_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.registry_key_name -* Registry.registry_path -* Registry.user -* Registry.dest -* Registry.registry_value_name -* Registry.action - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. - -#### Known False Positives -Administrators may enable or disable this feature that may cause some false positive. Filter as needed. - -#### Associated Analytic story -* [Azorult](/stories/azorult) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | The registry for DisallowRun settings was modified to enable in $dest$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://app.any.run/tasks/a6f2ffe2-e6e2-4396-ae2e-04ea0143f2d8/](https://app.any.run/tasks/a6f2ffe2-e6e2-4396-ae2e-04ea0143f2d8/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/azorult/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/azorult/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_modify_registry_disallow_windows_app.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-06-22-windows_modify_registry_suppress_win_defender_notif.md b/docs/_posts/2022-06-22-windows_modify_registry_suppress_win_defender_notif.md deleted file mode 100644 index 6607e67ca9..0000000000 --- a/docs/_posts/2022-06-22-windows_modify_registry_suppress_win_defender_notif.md +++ /dev/null @@ -1,165 +0,0 @@ ---- -title: "Windows Modify Registry Suppress Win Defender Notif" -excerpt: "Modify Registry -" -categories: - - Endpoint -last_modified_at: 2022-06-22 -toc: true -toc_label: "" -tags: - - Modify Registry - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic is to identify a modification in the Windows registry to suppress windows defender notification. This technique was abuse by adversaries and threat actor to bypassed windows defender on the targeted host. Azorult malware is one of the malware use this technique that also disable toast notification and other windows features as part of its malicious behavior. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-06-22 -- **Author**: Teoderick Contreras, Splunk -- **ID**: e3b42daf-fff4-429d-bec8-2a199468cea9 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1112](https://attack.mitre.org/techniques/T1112/) | Modify Registry | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path= "*\\Windows Defender\\UX Configuration\\Notification_Suppress*" Registry.registry_value_data="0x00000001" by Registry.registry_key_name Registry.user Registry.registry_path Registry.registry_value_data Registry.action Registry.dest -| `drop_dm_object_name(Registry)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_modify_registry_suppress_win_defender_notif_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_modify_registry_suppress_win_defender_notif_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.registry_key_name -* Registry.registry_path -* Registry.user -* Registry.dest -* Registry.registry_value_name -* Registry.action - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. - -#### Known False Positives -administrators may enable or disable this feature that may cause some false positive. - -#### Associated Analytic story -* [Azorult](/stories/azorult) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | the registry for suppresing windows fdefender notification settings was modified to disabled in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://docs.microsoft.com/en-us/windows-hardware/customize/desktop/unattend/microsoft-windows-remoteassistance-exe-fallowtogethelp](https://docs.microsoft.com/en-us/windows-hardware/customize/desktop/unattend/microsoft-windows-remoteassistance-exe-fallowtogethelp) -* [https://app.any.run/tasks/a6f2ffe2-e6e2-4396-ae2e-04ea0143f2d8/](https://app.any.run/tasks/a6f2ffe2-e6e2-4396-ae2e-04ea0143f2d8/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/azorult/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/azorult/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_modify_registry_suppress_win_defender_notif.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-06-22-windows_powerview_kerberos_service_ticket_request.md b/docs/_posts/2022-06-22-windows_powerview_kerberos_service_ticket_request.md deleted file mode 100644 index 75f7474d96..0000000000 --- a/docs/_posts/2022-06-22-windows_powerview_kerberos_service_ticket_request.md +++ /dev/null @@ -1,168 +0,0 @@ ---- -title: "Windows PowerView Kerberos Service Ticket Request" -excerpt: "Steal or Forge Kerberos Tickets -, Kerberoasting -" -categories: - - Endpoint -last_modified_at: 2022-06-22 -toc: true -toc_label: "" -tags: - - Steal or Forge Kerberos Tickets - - Kerberoasting - - Credential Access - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-DomainSPNTicket` commandlets with specific parameters. This commandlet is a part of PowerView, a PowerShell tool used to perform enumeration and discovery on Windows Active Directory networks. As the name suggests, this commandlet is used to request the kerberos ticket for a specified service principal name (SPN). Once the ticket is received, it may be cracked using password cracking tools like hashcat to extract the password of the SPN account. Red Teams and adversaries alike may leverage PowerView and these commandlets to identify accounts that can be attacked with the Kerberoasting technique. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-06-22 -- **Author**: Gowthamaraj Rajendran, Splunk -- **ID**: 970455a1-4ac2-47e1-a9a5-9e75443ddcb9 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1558](https://attack.mitre.org/techniques/T1558/) | Steal or Forge Kerberos Tickets | Credential Access | - -| [T1558.003](https://attack.mitre.org/techniques/T1558/003/) | Kerberoasting | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 ScriptBlockText=*Get-DomainSPNTicket* -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode ScriptBlockText Computer -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_powerview_kerberos_service_ticket_request_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **windows_powerview_kerberos_service_ticket_request_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Computer -* ScriptBlockText - - -#### How To Implement -The following analytic requires PowerShell operational logs to be imported. Modify the powershell macro as needed to match the sourcetype or add index. This analytic is specific to 4104, or PowerShell Script Block Logging. - -#### Known False Positives -False positive may include Administrators using PowerView for troubleshooting and management. - -#### Associated Analytic story -* [Active Directory Kerberos Attacks](/stories/active_directory_kerberos_attacks) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 27.0 | 30 | 90 | PowerView commandlets used for requesting SPN service ticket executed on $Computer$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://powersploit.readthedocs.io/en/latest/Recon/Get-DomainSPNTicket/](https://powersploit.readthedocs.io/en/latest/Recon/Get-DomainSPNTicket/) -* [https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/kerberoast](https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/kerberoast) -* [https://github.com/PowerShellMafia/PowerSploit/blob/master/Recon/PowerView.ps1](https://github.com/PowerShellMafia/PowerSploit/blob/master/Recon/PowerView.ps1) -* [https://www.ired.team/offensive-security-experiments/active-directory-kerberos-abuse/t1208-kerberoasting](https://www.ired.team/offensive-security-experiments/active-directory-kerberos-abuse/t1208-kerberoasting) -* [https://attack.mitre.org/techniques/T1558/003](https://attack.mitre.org/techniques/T1558/003) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1558.003/powerview/windows-powershell-xml.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1558.003/powerview/windows-powershell-xml.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_powerview_kerberos_service_ticket_request.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-06-22-windows_powerview_spn_discovery.md b/docs/_posts/2022-06-22-windows_powerview_spn_discovery.md deleted file mode 100644 index 74b4341344..0000000000 --- a/docs/_posts/2022-06-22-windows_powerview_spn_discovery.md +++ /dev/null @@ -1,168 +0,0 @@ ---- -title: "Windows PowerView SPN Discovery" -excerpt: "Steal or Forge Kerberos Tickets -, Kerberoasting -" -categories: - - Endpoint -last_modified_at: 2022-06-22 -toc: true -toc_label: "" -tags: - - Steal or Forge Kerberos Tickets - - Kerberoasting - - Credential Access - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-DomainUser` or `Get-NetUSer` commandlets with specific parameters. These commandlets are part of PowerView, a PowerShell tool used to perform enumeration and discovery on Windows Active Directory networks. As the names suggest, these commandlets are used to identify domain users in a network and combining them with the `-SPN` parameter allows adversaries to discover domain accounts associated with a Service Principal Name (SPN). Red Teams and adversaries alike may leverage PowerView and these commandlets to identify accounts that can be attacked with the Kerberoasting technique. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-06-22 -- **Author**: Gowthamaraj Rajendran, Splunk -- **ID**: a7093c28-796c-4ebb-9997-e2c18b870837 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1558](https://attack.mitre.org/techniques/T1558/) | Steal or Forge Kerberos Tickets | Credential Access | - -| [T1558.003](https://attack.mitre.org/techniques/T1558/003/) | Kerberoasting | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 (ScriptBlockText =*Get-NetUser* OR ScriptBlockText=*Get-DomainUser*) ScriptBlockText= *-SPN* -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode ScriptBlockText Computer -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_powerview_spn_discovery_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **windows_powerview_spn_discovery_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* Computer -* ScriptBlockText - - -#### How To Implement -The following analytic requires PowerShell operational logs to be imported. Modify the powershell macro as needed to match the sourcetype or add index. This analytic is specific to 4104, or PowerShell Script Block Logging. - -#### Known False Positives -False positive may include Administrators using PowerView for troubleshooting and management. - -#### Associated Analytic story -* [Active Directory Kerberos Attacks](/stories/active_directory_kerberos_attacks) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 27.0 | 30 | 90 | PowerView commandlets used for SPN discovery executed on $Computer$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/kerberoast](https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/kerberoast) -* [https://github.com/PowerShellMafia/PowerSploit/blob/master/Recon/PowerView.ps1](https://github.com/PowerShellMafia/PowerSploit/blob/master/Recon/PowerView.ps1) -* [https://www.ired.team/offensive-security-experiments/active-directory-kerberos-abuse/t1208-kerberoasting](https://www.ired.team/offensive-security-experiments/active-directory-kerberos-abuse/t1208-kerberoasting) -* [https://attack.mitre.org/techniques/T1558/003](https://attack.mitre.org/techniques/T1558/003) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1558.003/powerview-2/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1558.003/powerview-2/windows-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_powerview_spn_discovery.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-06-22-windows_remote_access_software_rms_registry.md b/docs/_posts/2022-06-22-windows_remote_access_software_rms_registry.md deleted file mode 100644 index 0f11829f51..0000000000 --- a/docs/_posts/2022-06-22-windows_remote_access_software_rms_registry.md +++ /dev/null @@ -1,165 +0,0 @@ ---- -title: "Windows Remote Access Software RMS Registry" -excerpt: "Remote Access Software -" -categories: - - Endpoint -last_modified_at: 2022-06-22 -toc: true -toc_label: "" -tags: - - Remote Access Software - - Command And Control - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic is to identify a modification or creation of Windows registry related to the Remote Manipulator System (RMS) Remote Admin tool. RMS is a legitimate tool developed by russian organization TektonIT and has been observed being abused by adversaries to gain remote access to the targeted host. Azorult malware utilized RMS to gain remote access. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-06-22 -- **Author**: Teoderick Contreras, Splunk -- **ID**: e5b7b5a9-e471-4be8-8c5d-4083983ba329 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1219](https://attack.mitre.org/techniques/T1219/) | Remote Access Software | Command And Control | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path= "*\\SYSTEM\\Remote Manipulator System*" by Registry.registry_key_name Registry.user Registry.registry_path Registry.registry_value_data Registry.action Registry.dest -| `drop_dm_object_name(Registry)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_remote_access_software_rms_registry_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_remote_access_software_rms_registry_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.registry_key_name -* Registry.registry_path -* Registry.user -* Registry.dest -* Registry.registry_value_name -* Registry.action - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. - -#### Known False Positives -administrators may enable or disable this feature that may cause some false positive. - -#### Associated Analytic story -* [Azorult](/stories/azorult) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 90.0 | 100 | 90 | the registry related to RMS tool is created in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://app.any.run/tasks/a6f2ffe2-e6e2-4396-ae2e-04ea0143f2d8/](https://app.any.run/tasks/a6f2ffe2-e6e2-4396-ae2e-04ea0143f2d8/) -* [https://malpedia.caad.fkie.fraunhofer.de/details/win.rms](https://malpedia.caad.fkie.fraunhofer.de/details/win.rms) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/azorult/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/azorult/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_remote_access_software_rms_registry.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-06-23-windows_modify_registry_disable_win_defender_raw_write_notif.md b/docs/_posts/2022-06-23-windows_modify_registry_disable_win_defender_raw_write_notif.md deleted file mode 100644 index ebc12480cd..0000000000 --- a/docs/_posts/2022-06-23-windows_modify_registry_disable_win_defender_raw_write_notif.md +++ /dev/null @@ -1,165 +0,0 @@ ---- -title: "Windows Modify Registry Disable Win Defender Raw Write Notif" -excerpt: "Modify Registry -" -categories: - - Endpoint -last_modified_at: 2022-06-23 -toc: true -toc_label: "" -tags: - - Modify Registry - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies a modification in the Windows registry to disable Windows Defender raw write notification feature. This policy controls whether raw volume write notifications are sent to behavior monitoring or not. This registry was recently identified in Azorult malware to bypass Windows Defender detections or behavior monitoring in terms of volume write. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-06-23 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 0e5e25c3-32f4-46f7-ba4a-5b95c3b90f5b - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1112](https://attack.mitre.org/techniques/T1112/) | Modify Registry | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path= "*\\Windows Defender\\Real-Time Protection\\DisableRawWriteNotification*" Registry.registry_value_data="0x00000001" by Registry.registry_key_name Registry.user Registry.registry_path Registry.registry_value_data Registry.action Registry.dest -| `drop_dm_object_name(Registry)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_modify_registry_disable_win_defender_raw_write_notif_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_modify_registry_disable_win_defender_raw_write_notif_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.registry_key_name -* Registry.registry_path -* Registry.user -* Registry.dest -* Registry.registry_value_name -* Registry.action - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. - -#### Known False Positives -Administrators may enable or disable this feature that may cause some false positive. Filter as needed. - -#### Associated Analytic story -* [Azorult](/stories/azorult) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | The registry for raw write notification settings was modified to disable in $dest$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://admx.help/?Category=SystemCenterEndpointProtection&Policy=Microsoft.Policies.Antimalware::real-time_protection_disablerawwritenotification](https://admx.help/?Category=SystemCenterEndpointProtection&Policy=Microsoft.Policies.Antimalware::real-time_protection_disablerawwritenotification) -* [https://app.any.run/tasks/a6f2ffe2-e6e2-4396-ae2e-04ea0143f2d8/](https://app.any.run/tasks/a6f2ffe2-e6e2-4396-ae2e-04ea0143f2d8/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/azorult/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/azorult/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_modify_registry_disable_win_defender_raw_write_notif.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-06-23-windows_valid_account_with_never_expires_password.md b/docs/_posts/2022-06-23-windows_valid_account_with_never_expires_password.md deleted file mode 100644 index 1cd8558d2c..0000000000 --- a/docs/_posts/2022-06-23-windows_valid_account_with_never_expires_password.md +++ /dev/null @@ -1,171 +0,0 @@ ---- -title: "Windows Valid Account With Never Expires Password" -excerpt: "Service Stop -" -categories: - - Endpoint -last_modified_at: 2022-06-23 -toc: true -toc_label: "" -tags: - - Service Stop - - Impact - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies net.exe updating user account policies for password requirement with non-expiring password. This technique was seen in several adversaries and malware like Azorult to maintain the foothold (persistence), gaining privilege escalation, defense evasion and possible for lateral movement for specific users or created user account on the targeted host. This TTP detections is a good pivot to see further what other events that users executes on the machines. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-06-23 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 73a931db-1830-48b3-8296-cd9cfa09c3c8 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1489](https://attack.mitre.org/techniques/T1489/) | Service Stop | Impact | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_net` AND Processes.process="* accounts *" AND Processes.process="* /maxpwage:unlimited" by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_valid_account_with_never_expires_password_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [process_net](https://github.com/splunk/security_content/blob/develop/macros/process_net.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_valid_account_with_never_expires_password_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -This behavior is not commonly seen in production environment and not advisable, filter as needed. - -#### Associated Analytic story -* [Azorult](/stories/azorult) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 100.0 | 100 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ attempting to make non-expiring password on host user accounts. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://app.any.run/tasks/a6f2ffe2-e6e2-4396-ae2e-04ea0143f2d8/](https://app.any.run/tasks/a6f2ffe2-e6e2-4396-ae2e-04ea0143f2d8/) -* [https://docs.microsoft.com/en-us/troubleshoot/windows-server/networking/net-commands-on-operating-systems](https://docs.microsoft.com/en-us/troubleshoot/windows-server/networking/net-commands-on-operating-systems) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/azorult/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/azorult/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_valid_account_with_never_expires_password.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-06-24-windows_application_layer_protocol_rms_radmin_tool_namedpipe.md b/docs/_posts/2022-06-24-windows_application_layer_protocol_rms_radmin_tool_namedpipe.md deleted file mode 100644 index d7f5b149ab..0000000000 --- a/docs/_posts/2022-06-24-windows_application_layer_protocol_rms_radmin_tool_namedpipe.md +++ /dev/null @@ -1,164 +0,0 @@ ---- -title: "Windows Application Layer Protocol RMS Radmin Tool Namedpipe" -excerpt: "Application Layer Protocol -" -categories: - - Endpoint -last_modified_at: 2022-06-24 -toc: true -toc_label: "" -tags: - - Application Layer Protocol - - Command And Control - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the use of default or publicly known named pipes used by RMX remote admin tool. A named pipe is a named, one-way or duplex pipe for communication between the pipe server and one or more pipe clients. RMX Tool uses named pipes in many way as part of its communication for its server and client component. This tool was abuse by several adversaries and malware like Azorult to collect data to the targeted host. This TTP is a good indicator that this tool was install in production premise and need to check if the user has a valid reason why it need to install this legitimate application. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-06-24 -- **Author**: Teoderick Contreras, Splunk -- **ID**: b62a6040-49f4-47c8-b3f6-fc1adb952a33 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1071](https://attack.mitre.org/techniques/T1071/) | Application Layer Protocol | Command And Control | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`sysmon` EventCode IN (17, 18) EventType IN ( "CreatePipe", "ConnectPipe") PipeName IN ("\\RManFUSServerNotify32", "\\RManFUSCallbackNotify32", "\\RMSPrint*") -| stats min(_time) as firstTime max(_time) as lastTime count by Image EventType ProcessId PipeName Computer UserID -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_application_layer_protocol_rms_radmin_tool_namedpipe_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) - -> :information_source: -> **windows_application_layer_protocol_rms_radmin_tool_namedpipe_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Image -* EventType -* ProcessId -* PipeName -* Computer -* UserID - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -False positives may be present. Filter based on pipe name or process. - -#### Associated Analytic story -* [Azorult](/stories/azorult) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 81.0 | 90 | 90 | possible RMS admin tool named pipe was created in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://app.any.run/tasks/a6f2ffe2-e6e2-4396-ae2e-04ea0143f2d8/](https://app.any.run/tasks/a6f2ffe2-e6e2-4396-ae2e-04ea0143f2d8/) -* [https://attack.mitre.org/techniques/T1071/](https://attack.mitre.org/techniques/T1071/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/azorult/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/azorult/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_application_layer_protocol_rms_radmin_tool_namedpipe.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-06-24-windows_impair_defense_add_xml_applocker_rules.md b/docs/_posts/2022-06-24-windows_impair_defense_add_xml_applocker_rules.md deleted file mode 100644 index 8ebf909852..0000000000 --- a/docs/_posts/2022-06-24-windows_impair_defense_add_xml_applocker_rules.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: "Windows Impair Defense Add Xml Applocker Rules" -excerpt: "Disable or Modify Tools -, Impair Defenses -" -categories: - - Endpoint -last_modified_at: 2022-06-24 -toc: true -toc_label: "" -tags: - - Disable or Modify Tools - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic is to identify a process that imports applocker xml policy using PowerShell commandlet. This technique was seen in Azorult malware where it drop an xml Applocker policy that will deny several AV products and further executed the PowerShell Applocker commandlet. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-06-24 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 467ed9d9-8035-470e-ad5e-ae5189283033 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_powershell` AND Processes.process="*Import-Module Applocker*" AND Processes.process="*Set-AppLockerPolicy *" AND Processes.process="* -XMLPolicy *" by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_impair_defense_add_xml_applocker_rules_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml) - -> :information_source: -> **windows_impair_defense_add_xml_applocker_rules_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.registry_key_name -* Registry.registry_path -* Registry.user -* Registry.dest -* Registry.registry_value_name -* Registry.action - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Administrators may execute this command that may cause some false positive. - -#### Associated Analytic story -* [Azorult](/stories/azorult) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | Applocker importing xml policy command was executed in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://app.any.run/tasks/a6f2ffe2-e6e2-4396-ae2e-04ea0143f2d8/](https://app.any.run/tasks/a6f2ffe2-e6e2-4396-ae2e-04ea0143f2d8/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/azorult/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/azorult/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_impair_defense_add_xml_applocker_rules.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-06-24-windows_impair_defense_deny_security_software_with_applocker.md b/docs/_posts/2022-06-24-windows_impair_defense_deny_security_software_with_applocker.md deleted file mode 100644 index adda0f0a97..0000000000 --- a/docs/_posts/2022-06-24-windows_impair_defense_deny_security_software_with_applocker.md +++ /dev/null @@ -1,175 +0,0 @@ ---- -title: "Windows Impair Defense Deny Security Software With Applocker" -excerpt: "Disable or Modify Tools -, Impair Defenses -" -categories: - - Endpoint -last_modified_at: 2022-06-24 -toc: true -toc_label: "" -tags: - - Disable or Modify Tools - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies a modification in the Windows registry by the Applocker utility that contains details or registry data values related to denying the execution of several security products. This technique was seen in Azorult malware where it drops an xml Applocker policy that will deny several AV products and then loaded by using PowerShell Applocker commandlet. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-06-24 -- **Author**: Teoderick Contreras, Splunk -- **ID**: e0b6ca60-9e29-4450-b51a-bba0abae2313 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where (Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Group Policy Objects\\*" AND Registry.registry_path= "*}Machine\\Software\\Policies\\Microsoft\\Windows\\SrpV2*") OR Registry.registry_path="*\\Software\\Policies\\Microsoft\\Windows\\SrpV2*" AND Registry.registry_value_data = "*Action\=\"Deny\"*" AND Registry.registry_value_data IN("*O=SYMANTEC*","*O=MCAFEE*","*O=KASPERSKY*","*O=BLEEPING COMPUTER*", "*O=PANDA SECURITY*","*O=SYSTWEAK SOFTWARE*", "*O=TREND MICRO*", "*O=AVAST*", "*O=GRIDINSOFT*", "*O=MICROSOFT*", "*O=NANO SECURITY*", "*O=SUPERANTISPYWARE.COM*", "*O=DOCTOR WEB*", "*O=MALWAREBYTES*", "*O=ESET*", "*O=AVIRA*", "*O=WEBROOT*") by Registry.user Registry.registry_path Registry.registry_value_data Registry.action Registry.registry_key_name Registry.dest -| `drop_dm_object_name(Registry)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_impair_defense_deny_security_software_with_applocker_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_impair_defense_deny_security_software_with_applocker_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. - -#### Known False Positives -False positives may be present based on organization use of Applocker. Filter as needed. - -#### Associated Analytic story -* [Azorult](/stories/azorult) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 100.0 | 100 | 100 | Applocker registry modification to deny the action of several AV products on $dest$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://app.any.run/tasks/a6f2ffe2-e6e2-4396-ae2e-04ea0143f2d8/](https://app.any.run/tasks/a6f2ffe2-e6e2-4396-ae2e-04ea0143f2d8/) -* [https://www.microsoftpressstore.com/articles/article.aspx?p=2228450&seqNum=11](https://www.microsoftpressstore.com/articles/article.aspx?p=2228450&seqNum=11) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/azorult/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/azorult/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_impair_defense_deny_security_software_with_applocker.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-06-24-windows_modify_registry_regedit_silent_reg_import.md b/docs/_posts/2022-06-24-windows_modify_registry_regedit_silent_reg_import.md deleted file mode 100644 index 37d6241173..0000000000 --- a/docs/_posts/2022-06-24-windows_modify_registry_regedit_silent_reg_import.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: "Windows Modify Registry Regedit Silent Reg Import" -excerpt: "Modify Registry -" -categories: - - Endpoint -last_modified_at: 2022-06-24 -toc: true -toc_label: "" -tags: - - Modify Registry - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies modification of Windows registry using regedit.exe application with silent mode parameter. regedit.exe windows application is commonly used as GUI app to check or modify registry. This application is also has undocumented command-line parameter and one of those are silent mode parameter that performs action without stopping for confirmation with dialog box. Importing registry from .reg files need to monitor in a production environment since it can be used adversaries to import RMS registry in compromised host. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-06-24 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 824dd598-71be-4203-bc3b-024f4cda340e - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1112](https://attack.mitre.org/techniques/T1112/) | Modify Registry | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="regedit.exe" OR Processes.original_file_name="regedit.exe") AND Processes.process="* /s *" AND Processes.process="*.reg*" by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_modify_registry_regedit_silent_reg_import_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_modify_registry_regedit_silent_reg_import_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Administrators may execute this command that may cause some false positive. Filter as needed. - -#### Associated Analytic story -* [Azorult](/stories/azorult) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | The regedit app was executed with silet mode parameter to import .reg file on $dest$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://app.any.run/tasks/a6f2ffe2-e6e2-4396-ae2e-04ea0143f2d8/](https://app.any.run/tasks/a6f2ffe2-e6e2-4396-ae2e-04ea0143f2d8/) -* [https://www.techtarget.com/searchwindowsserver/tip/Command-line-options-for-Regeditexe](https://www.techtarget.com/searchwindowsserver/tip/Command-line-options-for-Regeditexe) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/azorult/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/azorult/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_modify_registry_regedit_silent_reg_import.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-06-24-windows_remote_service_rdpwinst_tool_execution.md b/docs/_posts/2022-06-24-windows_remote_service_rdpwinst_tool_execution.md deleted file mode 100644 index 7c0dcff0eb..0000000000 --- a/docs/_posts/2022-06-24-windows_remote_service_rdpwinst_tool_execution.md +++ /dev/null @@ -1,174 +0,0 @@ ---- -title: "Windows Remote Service Rdpwinst Tool Execution" -excerpt: "Remote Desktop Protocol -, Remote Services -" -categories: - - Endpoint -last_modified_at: 2022-06-24 -toc: true -toc_label: "" -tags: - - Remote Desktop Protocol - - Remote Services - - Lateral Movement - - Lateral Movement - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies RDPWInst.exe tool, which is a RDP wrapper library tool designed to enable remote desktop host support and concurrent RDP session on reduced functionality system. Unfortunately, this open project was abused by adversaries to enable RDP connection to the targeted host for remote access and potentially be for lateral movement. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-06-24 -- **Author**: Teoderick Contreras, Splunk -- **ID**: c8127f87-c7c9-4036-89ed-8fe4b30e678c - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1021.001](https://attack.mitre.org/techniques/T1021/001/) | Remote Desktop Protocol | Lateral Movement | - -| [T1021](https://attack.mitre.org/techniques/T1021/) | Remote Services | Lateral Movement | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="RDPWInst.exe" OR Processes.original_file_name="RDPWInst.exe") AND Processes.process IN ("* -i*", "* -s*", "* -o*", "* -w*", "* -r*") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_remote_service_rdpwinst_tool_execution_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_remote_service_rdpwinst_tool_execution_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -This tool was designed for home usage and not commonly seen in production environment. Filter as needed. - -#### Associated Analytic story -* [Azorult](/stories/azorult) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 81.0 | 90 | 90 | Rdpwinst.exe executed on $dest$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://app.any.run/tasks/a6f2ffe2-e6e2-4396-ae2e-04ea0143f2d8/](https://app.any.run/tasks/a6f2ffe2-e6e2-4396-ae2e-04ea0143f2d8/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/azorult/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/azorult/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_remote_service_rdpwinst_tool_execution.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-06-28-outbound_network_connection_from_java_using_default_ports.md b/docs/_posts/2022-06-28-outbound_network_connection_from_java_using_default_ports.md deleted file mode 100644 index 94f1061cf6..0000000000 --- a/docs/_posts/2022-06-28-outbound_network_connection_from_java_using_default_ports.md +++ /dev/null @@ -1,173 +0,0 @@ ---- -title: "Outbound Network Connection from Java Using Default Ports" -excerpt: "Exploit Public-Facing Application -" -categories: - - Endpoint -last_modified_at: 2022-06-28 -toc: true -toc_label: "" -tags: - - Exploit Public-Facing Application - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2021-44228 - - Endpoint - - Network_Traffic ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -A required step while exploiting the CVE-2021-44228-Log4j vulnerability is that the victim server will perform outbound connections to attacker-controlled infrastructure. This is required as part of the JNDI lookup as well as for retrieving the second stage .class payload. The following analytic identifies the Java process reaching out to default ports used by the LDAP and RMI protocols. This behavior could represent successfull exploitation. Note that adversaries can easily decide to use arbitrary ports for these protocols and potentially bypass this detection. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint), [Network_Traffic](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkTraffic) -- **Last Updated**: 2022-06-28 -- **Author**: Mauricio Velazco, Lou Stella, Splunk -- **ID**: d2c14d28-5c47-11ec-9892-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1190](https://attack.mitre.org/techniques/T1190/) | Exploit Public-Facing Application | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2021-44228](https://nvd.nist.gov/vuln/detail/CVE-2021-44228) | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects. | 9.3 | - - - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where (Processes.process_name="java.exe" OR Processes.process_name=javaw.exe OR Processes.process_name=javaw.exe) by _time Processes.process_id Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| join process_id [ -| tstats `security_content_summariesonly` count FROM datamodel=Network_Traffic.All_Traffic where (All_Traffic.dest_port= 389 OR All_Traffic.dest_port= 636 OR All_Traffic.dest_port = 1389 OR All_Traffic.dest_port = 1099 ) by All_Traffic.process_id All_Traffic.dest All_Traffic.dest_port -| `drop_dm_object_name(All_Traffic)` -| rename dest as connection_to_CNC] -| table _time dest parent_process_name process_name process_path process connection_to_CNC dest_port -| `outbound_network_connection_from_java_using_default_ports_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **outbound_network_connection_from_java_using_default_ports_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.process_id -* Processes.process_name -* Processes.dest -* Processes.process_path -* Processes.process -* Processes.parent_process_name -* All_Traffic.process_id -* All_Traffic.dest -* All_Traffic.dest_port - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Legitimate Java applications may use perform outbound connections to these ports. Filter as needed - -#### Associated Analytic story -* [Log4Shell CVE-2021-44228](/stories/log4shell_cve-2021-44228) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 54.0 | 90 | 60 | Java performed outbound connections to default ports of LDAP or RMI on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.lunasec.io/docs/blog/log4j-zero-day/](https://www.lunasec.io/docs/blog/log4j-zero-day/) -* [https://www.govcert.admin.ch/blog/zero-day-exploit-targeting-popular-java-library-log4j/](https://www.govcert.admin.ch/blog/zero-day-exploit-targeting-popular-java-library-log4j/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/outbound_java/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/outbound_java/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/outbound_network_connection_from_java_using_default_ports.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-06-28-windows_odbcconf_load_dll.md b/docs/_posts/2022-06-28-windows_odbcconf_load_dll.md deleted file mode 100644 index c2c36b461e..0000000000 --- a/docs/_posts/2022-06-28-windows_odbcconf_load_dll.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: "Windows Odbcconf Load DLL" -excerpt: "Odbcconf -" -categories: - - Endpoint -last_modified_at: 2022-06-28 -toc: true -toc_label: "" -tags: - - Odbcconf - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies odbcconf.exe, Windows Open Database Connectivity utility, utilizing the action function of regsvr to load a DLL. An example will look like - odbcconf.exe /A { REGSVR T1218-2.dll }. During triage, review parent process, parallel procesess and file modifications. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-06-28 -- **Author**: Michael Haag, Splunk -- **ID**: 141e7fca-a9f0-40fd-a539-9aac8be41f1b - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218.008](https://attack.mitre.org/techniques/T1218/008/) | Odbcconf | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=odbcconf.exe Processes.process IN ("*/a *", "*-a*") Processes.process="*regsvr*" by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_odbcconf_load_dll_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_odbcconf_load_dll_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -False positives may be present and filtering may need to occur based on legitimate application usage. Filter as needed. - -#### Associated Analytic story -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 42.0 | 60 | 70 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to circumvent controls. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://strontic.github.io/xcyclopedia/library/odbcconf.exe-07FBA12552331355C103999806627314.html](https://strontic.github.io/xcyclopedia/library/odbcconf.exe-07FBA12552331355C103999806627314.html) -* [https://twitter.com/redcanary/status/1541838407894171650?s=20&t=kp3WBPtfnyA3xW7D7wx0uw](https://twitter.com/redcanary/status/1541838407894171650?s=20&t=kp3WBPtfnyA3xW7D7wx0uw) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.008/atomic_red_team/windows-sysmon-odbc-regsvr.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.008/atomic_red_team/windows-sysmon-odbc-regsvr.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_odbcconf_load_dll.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-06-29-remote_system_discovery_with_adsisearcher.md b/docs/_posts/2022-06-29-remote_system_discovery_with_adsisearcher.md deleted file mode 100644 index f56b600f94..0000000000 --- a/docs/_posts/2022-06-29-remote_system_discovery_with_adsisearcher.md +++ /dev/null @@ -1,154 +0,0 @@ ---- -title: "Remote System Discovery with Adsisearcher" -excerpt: "Remote System Discovery -" -categories: - - Endpoint -last_modified_at: 2022-06-29 -toc: true -toc_label: "" -tags: - - Remote System Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the `[Adsisearcher]` type accelerator being used to query Active Directory for domain computers. Red Teams and adversaries may leverage `[Adsisearcher]` to enumerate domain computers for situational awareness and Active Directory Discovery. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-06-29 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 70803451-0047-4e12-9d63-77fa7eb8649c - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1018](https://attack.mitre.org/techniques/T1018/) | Remote System Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 ScriptBlockText = "*adsisearcher*" AND ScriptBlockText = "*objectcategory=computer*" AND ScriptBlockText IN ("*findAll()*","*findOne()*") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode ScriptBlockText Computer UserID -| `security_content_ctime(firstTime)` -| `remote_system_discovery_with_adsisearcher_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **remote_system_discovery_with_adsisearcher_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* EventCode -* ScriptBlockText -* Computer -* UserID - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -Administrators or power users may use Adsisearcher for troubleshooting. - -#### Associated Analytic story -* [Active Directory Discovery](/stories/active_directory_discovery) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | Remote system discovery enumeration on $Computer$ by $user$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1018/](https://attack.mitre.org/techniques/T1018/) -* [https://devblogs.microsoft.com/scripting/use-the-powershell-adsisearcher-type-accelerator-to-search-active-directory/](https://devblogs.microsoft.com/scripting/use-the-powershell-adsisearcher-type-accelerator-to-search-active-directory/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/AD_discovery/adsisearcher-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/AD_discovery/adsisearcher-powershell.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-06-29-windows_execute_arbitrary_commands_with_msdt.md b/docs/_posts/2022-06-29-windows_execute_arbitrary_commands_with_msdt.md deleted file mode 100644 index 8e2345bdb3..0000000000 --- a/docs/_posts/2022-06-29-windows_execute_arbitrary_commands_with_msdt.md +++ /dev/null @@ -1,179 +0,0 @@ ---- -title: "Windows Execute Arbitrary Commands with MSDT" -excerpt: "System Binary Proxy Execution -" -categories: - - Endpoint -last_modified_at: 2022-06-29 -toc: true -toc_label: "" -tags: - - System Binary Proxy Execution - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2022-30190 - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies a recently disclosed arbitraty command execution using Windows msdt.exe - a Diagnostics Troubleshooting Wizard. The sample identified will use the ms-msdt:/ protocol handler to load msdt.exe to retrieve a remote payload. During triage, review file modifications for html. Identify parallel process execution that may be related, including an Office Product. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-06-29 -- **Author**: Michael Haag, Teoderick Contreras, Splunk -- **ID**: e1d5145f-38fe-42b9-a5d5-457796715f97 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218](https://attack.mitre.org/techniques/T1218/) | System Binary Proxy Execution | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2022-30190](https://nvd.nist.gov/vuln/detail/CVE-2022-30190) | Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability. | 9.3 | - - - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=msdt.exe Processes.process IN ("*msdt*","*ms-msdt:*","*ms-msdt:/id*","*ms-msdt:-id*","*/id*") AND (Processes.process="*IT_BrowseForFile=*" OR Processes.process="*IT_RebrowseForFile=*" OR Processes.process="*.xml*") AND Processes.process="*PCWDiagnostic*" by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_execute_arbitrary_commands_with_msdt_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_execute_arbitrary_commands_with_msdt_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -False positives may be present, filter as needed. Added .xml to potentially capture any answer file usage. Remove as needed. - -#### Associated Analytic story -* [Microsoft Support Diagnostic Tool Vulnerability CVE-2022-30190](/stories/microsoft_support_diagnostic_tool_vulnerability_cve-2022-30190) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 100.0 | 100 | 100 | A parent process $parent_process_name$ has spawned a child process $process_name$ on host $dest$ possibly indicative of indirect command execution. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://isc.sans.edu/diary/rss/28694](https://isc.sans.edu/diary/rss/28694) -* [https://doublepulsar.com/follina-a-microsoft-office-code-execution-vulnerability-1a47fce5629e](https://doublepulsar.com/follina-a-microsoft-office-code-execution-vulnerability-1a47fce5629e) -* [https://twitter.com/nao_sec/status/1530196847679401984?s=20&t=ZiXYI4dQuA-0_dzQzSUb3A](https://twitter.com/nao_sec/status/1530196847679401984?s=20&t=ZiXYI4dQuA-0_dzQzSUb3A) -* [https://app.any.run/tasks/713f05d2-fe78-4b9d-a744-f7c133e3fafb/](https://app.any.run/tasks/713f05d2-fe78-4b9d-a744-f7c133e3fafb/) -* [https://www.virustotal.com/gui/file/4a24048f81afbe9fb62e7a6a49adbd1faf41f266b5f9feecdceb567aec096784/detection](https://www.virustotal.com/gui/file/4a24048f81afbe9fb62e7a6a49adbd1faf41f266b5f9feecdceb567aec096784/detection) -* [https://strontic.github.io/xcyclopedia/library/msdt.exe-152D4C9F63EFB332CCB134C6953C0104.html](https://strontic.github.io/xcyclopedia/library/msdt.exe-152D4C9F63EFB332CCB134C6953C0104.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/msdt.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/msdt.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_execute_arbitrary_commands_with_msdt.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2022-06-30-windows_odbcconf_hunting.md b/docs/_posts/2022-06-30-windows_odbcconf_hunting.md deleted file mode 100644 index f8fde50f98..0000000000 --- a/docs/_posts/2022-06-30-windows_odbcconf_hunting.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: "Windows Odbcconf Hunting" -excerpt: "Odbcconf -" -categories: - - Endpoint -last_modified_at: 2022-06-30 -toc: true -toc_label: "" -tags: - - Odbcconf - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies Odbcconf.exe running in the environment to assist with identifying tuning higher fidelity analytics related to Odbcconf.exe. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-06-30 -- **Author**: Michael Haag, Splunk -- **ID**: 0562ad4b-fdaa-4882-b12f-7b8e0034cd72 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218.008](https://attack.mitre.org/techniques/T1218/008/) | Odbcconf | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=odbcconf.exe by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_odbcconf_hunting_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_odbcconf_hunting_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -False positives will be present as this is meant to assist with filtering and tuning. - -#### Associated Analytic story -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 6.0 | 30 | 20 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to circumvent controls. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://strontic.github.io/xcyclopedia/library/odbcconf.exe-07FBA12552331355C103999806627314.html](https://strontic.github.io/xcyclopedia/library/odbcconf.exe-07FBA12552331355C103999806627314.html) -* [https://twitter.com/redcanary/status/1541838407894171650?s=20&t=kp3WBPtfnyA3xW7D7wx0uw](https://twitter.com/redcanary/status/1541838407894171650?s=20&t=kp3WBPtfnyA3xW7D7wx0uw) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.008/atomic_red_team/windows-sysmon-odbc-regsvr.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.008/atomic_red_team/windows-sysmon-odbc-regsvr.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_odbcconf_hunting.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-06-30-windows_odbcconf_load_response_file.md b/docs/_posts/2022-06-30-windows_odbcconf_load_response_file.md deleted file mode 100644 index cf4d7d60ee..0000000000 --- a/docs/_posts/2022-06-30-windows_odbcconf_load_response_file.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: "Windows Odbcconf Load Response File" -excerpt: "Odbcconf -" -categories: - - Endpoint -last_modified_at: 2022-06-30 -toc: true -toc_label: "" -tags: - - Odbcconf - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the odbcconf.exe, Windows Open Database Connectivity utility, loading up a resource file. The file extension is arbitrary and may be named anything. The resource file itself may have different commands supported by Odbcconf to load up a DLL (REGSVR) on disk or additional commands. During triage, review file modifications and parallel processes. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-06-30 -- **Author**: Michael Haag, Splunk -- **ID**: 1acafff9-1347-4b40-abae-f35aa4ba85c1 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218.008](https://attack.mitre.org/techniques/T1218/008/) | Odbcconf | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=odbcconf.exe Processes.process IN ("*-f *","*/f *") Processes.process="*.rsp*" by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_odbcconf_load_response_file_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_odbcconf_load_response_file_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -False positives may be present and filtering may need to occur based on legitimate application usage. Filter as needed. - -#### Associated Analytic story -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 42.0 | 60 | 70 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to circumvent controls. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://strontic.github.io/xcyclopedia/library/odbcconf.exe-07FBA12552331355C103999806627314.html](https://strontic.github.io/xcyclopedia/library/odbcconf.exe-07FBA12552331355C103999806627314.html) -* [https://twitter.com/redcanary/status/1541838407894171650?s=20&t=kp3WBPtfnyA3xW7D7wx0uw](https://twitter.com/redcanary/status/1541838407894171650?s=20&t=kp3WBPtfnyA3xW7D7wx0uw) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.008/atomic_red_team/windows-sysmon-odbc-rsp.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.008/atomic_red_team/windows-sysmon-odbc-rsp.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_odbcconf_load_response_file.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-06-30-windows_powershell_import_applocker_policy.md b/docs/_posts/2022-06-30-windows_powershell_import_applocker_policy.md deleted file mode 100644 index 0c5cfceca3..0000000000 --- a/docs/_posts/2022-06-30-windows_powershell_import_applocker_policy.md +++ /dev/null @@ -1,160 +0,0 @@ ---- -title: "Windows Powershell Import Applocker Policy" -excerpt: "PowerShell -" -categories: - - Endpoint -last_modified_at: 2022-06-30 -toc: true -toc_label: "" -tags: - - PowerShell - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic is to identify the imports of Windows PowerShell Applocker commandlets. This technique was seen in Azorult malware where it drops an xml Applocker policy that will deny several AV product and then loaded using PowerShell Applocker commandlet. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-06-30 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 102af98d-0ca3-4aa4-98d6-7ab2b98b955a - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`powershell` EventCode=4104 ScriptBlockText="*Import-Module Applocker*" ScriptBlockText="*Set-AppLockerPolicy *" ScriptBlockText="* -XMLPolicy *" -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode ScriptBlockText Computer user_id -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_powershell_import_applocker_policy_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml) - -> :information_source: -> **windows_powershell_import_applocker_policy_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* ScriptBlockText -* Computer -* EventCode - - -#### How To Implement -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -#### Known False Positives -administrators may execute this command that may cause some false positive. - -#### Associated Analytic story -* [Azorult](/stories/azorult) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | A PowerShell script contains Import Applocker Policy command $ScriptBlockText$ with EventCode $EventCode$ in host $Computer$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://app.any.run/tasks/a6f2ffe2-e6e2-4396-ae2e-04ea0143f2d8/](https://app.any.run/tasks/a6f2ffe2-e6e2-4396-ae2e-04ea0143f2d8/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/import_applocker_policy/windows-powershell-xml2.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/import_applocker_policy/windows-powershell-xml2.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_powershell_import_applocker_policy.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-07-07-office_product_writing_cab_or_inf.md b/docs/_posts/2022-07-07-office_product_writing_cab_or_inf.md deleted file mode 100644 index e83936c782..0000000000 --- a/docs/_posts/2022-07-07-office_product_writing_cab_or_inf.md +++ /dev/null @@ -1,177 +0,0 @@ ---- -title: "Office Product Writing cab or inf" -excerpt: "Phishing -, Spearphishing Attachment -" -categories: - - Endpoint -last_modified_at: 2022-07-07 -toc: true -toc_label: "" -tags: - - Phishing - - Spearphishing Attachment - - Initial Access - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2021-40444 - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies behavior related to CVE-2021-40444. Whereas the malicious document will load ActiveX and download the remote payload (.inf, .cab). During triage, review parallel processes and further activity on endpoint to identify additional patterns. Retrieve the file modifications and analyze further. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-07-07 -- **Author**: Michael Haag, Splunk -- **ID**: f48cd1d4-125a-11ec-a447-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | - -| [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2021-40444](https://nvd.nist.gov/vuln/detail/CVE-2021-40444) | Microsoft MSHTML Remote Code Execution Vulnerability | 6.8 | - - - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name IN ("winword.exe","excel.exe","powerpnt.exe","mspub.exe","visio.exe","wordpad.exe","wordview.exe") by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| join proc_guid, _time [ -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_name IN ("*.inf","*.cab") by _time span=1h Filesystem.dest Filesystem.file_create_time Filesystem.file_name Filesystem.file_path Filesystem.process_guid -| `drop_dm_object_name(Filesystem)` -|rename process_guid as proc_guid -| fields _time dest file_create_time file_name file_path process_name process_path process proc_guid] -| dedup file_create_time -| table dest, process_name, process, file_create_time, file_name, file_path, proc_guid -| `office_product_writing_cab_or_inf_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **office_product_writing_cab_or_inf_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* dest -* process_name -* process -* file_create_time -* file_name -* file_path - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node and `Filesystem` node. - -#### Known False Positives -The query is structured in a way that `action` (read, create) is not defined. Review the results of this query, filter, and tune as necessary. It may be necessary to generate this query specific to your endpoint product. - -#### Associated Analytic story -* [Spearphishing Attachments](/stories/spearphishing_attachments) -* [Microsoft MSHTML Remote Code Execution CVE-2021-40444](/stories/microsoft_mshtml_remote_code_execution_cve-2021-40444) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | An instance of $process_name$ was identified on $dest$ writing an inf or cab file to this. This is not typical of $process_name$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://twitter.com/vxunderground/status/1436326057179860992?s=20](https://twitter.com/vxunderground/status/1436326057179860992?s=20) -* [https://app.any.run/tasks/36c14029-9df8-439c-bba0-45f2643b0c70/](https://app.any.run/tasks/36c14029-9df8-439c-bba0-45f2643b0c70/) -* [https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40444](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40444) -* [https://twitter.com/RonnyTNL/status/1436334640617373699?s=20](https://twitter.com/RonnyTNL/status/1436334640617373699?s=20) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_cabinf.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_cabinf.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/office_product_writing_cab_or_inf.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-07-07-suspicious_image_creation_in_appdata_folder.md b/docs/_posts/2022-07-07-suspicious_image_creation_in_appdata_folder.md deleted file mode 100644 index 0fae19c71b..0000000000 --- a/docs/_posts/2022-07-07-suspicious_image_creation_in_appdata_folder.md +++ /dev/null @@ -1,163 +0,0 @@ ---- -title: "Suspicious Image Creation In Appdata Folder" -excerpt: "Screen Capture -" -categories: - - Endpoint -last_modified_at: 2022-07-07 -toc: true -toc_label: "" -tags: - - Screen Capture - - Collection - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to detect a suspicious creation of image in appdata folder made by process that also has a file reference in appdata folder. This technique was seen in remcos rat that capture screenshot of the compromised machine and place it in the appdata and will be send to its C2 server. This TTP is really a good indicator to check that process because it is in suspicious folder path and image files are not commonly created by user in this folder path. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-07-07 -- **Author**: Teoderick Contreras, Splunk -- **ID**: f6f904c4-1ac0-11ec-806b-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1113](https://attack.mitre.org/techniques/T1113/) | Screen Capture | Collection | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name=*.exe Processes.process_path="*\\appdata\\Roaming\\*" by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_name IN ("*.png","*.jpg","*.bmp","*.gif","*.tiff") Filesystem.file_path= "*\\appdata\\Roaming\\*" by _time span=1h Filesystem.dest Filesystem.file_create_time Filesystem.file_name Filesystem.file_path Filesystem.process_guid -| `drop_dm_object_name(Filesystem)` -|rename process_guid as proc_guid -| fields _time dest file_create_time file_name file_path process_name process_path process proc_guid] -| `suspicious_image_creation_in_appdata_folder_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **suspicious_image_creation_in_appdata_folder_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* dest -* file_create_time -* file_name -* file_path -* process_name -* process_path -* process - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Remcos](/stories/remcos) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | process $process_name$ creating image file $file_path$ in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://success.trendmicro.com/dcx/s/solution/1123281-remcos-malware-information?language=en_US](https://success.trendmicro.com/dcx/s/solution/1123281-remcos-malware-information?language=en_US) -* [https://blog.malwarebytes.com/threat-intelligence/2021/07/remcos-rat-delivered-via-visual-basic/](https://blog.malwarebytes.com/threat-intelligence/2021/07/remcos-rat-delivered-via-visual-basic/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos_agent/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos_agent/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-07-07-suspicious_wav_file_in_appdata_folder.md b/docs/_posts/2022-07-07-suspicious_wav_file_in_appdata_folder.md deleted file mode 100644 index 4c596a0e71..0000000000 --- a/docs/_posts/2022-07-07-suspicious_wav_file_in_appdata_folder.md +++ /dev/null @@ -1,163 +0,0 @@ ---- -title: "Suspicious WAV file in Appdata Folder" -excerpt: "Screen Capture -" -categories: - - Endpoint -last_modified_at: 2022-07-07 -toc: true -toc_label: "" -tags: - - Screen Capture - - Collection - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic is to detect a suspicious creation of .wav file in appdata folder. This behavior was seen in Remcos RAT malware where it put the audio recording in the appdata\audio folde as part of data collection. this recording can be send to its C2 server as part of its exfiltration to the compromised machine. creation of wav files in this folder path is not a ussual disk place used by user to save audio format file. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-07-07 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 5be109e6-1ac5-11ec-b421-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1113](https://attack.mitre.org/techniques/T1113/) | Screen Capture | Collection | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name=*.exe Processes.process_path="*\\appdata\\Roaming\\*" by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| join proc_guid, _time [ -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_name IN ("*.wav") Filesystem.file_path = "*\\appdata\\Roaming\\*" by _time span=1h Filesystem.dest Filesystem.file_create_time Filesystem.file_name Filesystem.file_path Filesystem.process_guid -| `drop_dm_object_name(Filesystem)` -|rename process_guid as proc_guid -| fields file_name file_path process_name process_path process dest file_create_time _time proc_guid] -| `suspicious_wav_file_in_appdata_folder_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **suspicious_wav_file_in_appdata_folder_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* dest -* file_create_time -* file_name -* file_path -* process_name -* process_path -* process - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, file_name, file_path and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [Remcos](/stories/remcos) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | process $process_name$ creating image file $file_path$ in $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://success.trendmicro.com/dcx/s/solution/1123281-remcos-malware-information?language=en_US](https://success.trendmicro.com/dcx/s/solution/1123281-remcos-malware-information?language=en_US) -* [https://blog.malwarebytes.com/threat-intelligence/2021/07/remcos-rat-delivered-via-visual-basic/](https://blog.malwarebytes.com/threat-intelligence/2021/07/remcos-rat-delivered-via-visual-basic/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos_agent/sysmon_wav.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos_agent/sysmon_wav.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-07-07-windows_binary_proxy_execution_mavinject_dll_injection.md b/docs/_posts/2022-07-07-windows_binary_proxy_execution_mavinject_dll_injection.md deleted file mode 100644 index 69a4b75aec..0000000000 --- a/docs/_posts/2022-07-07-windows_binary_proxy_execution_mavinject_dll_injection.md +++ /dev/null @@ -1,176 +0,0 @@ ---- -title: "Windows Binary Proxy Execution Mavinject DLL Injection" -excerpt: "Mavinject -, System Binary Proxy Execution -" -categories: - - Endpoint -last_modified_at: 2022-07-07 -toc: true -toc_label: "" -tags: - - Mavinject - - System Binary Proxy Execution - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -Adversaries may abuse mavinject.exe to inject malicious DLLs into running processes (i.e. Dynamic-link Library Injection), allowing for arbitrary code execution (ex. C:\Windows\system32\mavinject.exe PID /INJECTRUNNING PATH_DLL). In addition to Dynamic-link Library Injection, Mavinject.exe can also be abused to perform import descriptor injection via its /HMODULE command-line parameter (ex. mavinject.exe PID /HMODULE=BASE_ADDRESS PATH_DLL ORDINAL_NUMBER). This command would inject an import table entry consisting of the specified DLL into the module at the given base address. During triage, review file modifcations and parallel processes. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-07-07 -- **Author**: Michael Haag, Splunk -- **ID**: ccf4b61b-1b26-4f2e-a089-f2009c569c57 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1218.013](https://attack.mitre.org/techniques/T1218/013/) | Mavinject | Defense Evasion | - -| [T1218](https://attack.mitre.org/techniques/T1218/) | System Binary Proxy Execution | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=mavinject.exe Processes.process IN ("*injectrunning*", "*hmodule=0x*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_binary_proxy_execution_mavinject_dll_injection_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_binary_proxy_execution_mavinject_dll_injection_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -False positives may be present, filter on DLL name or parent process. - -#### Associated Analytic story -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting load a DLL. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1218/013/](https://attack.mitre.org/techniques/T1218/013/) -* [https://posts.specterops.io/mavinject-exe-functionality-deconstructed-c29ab2cf5c0e](https://posts.specterops.io/mavinject-exe-functionality-deconstructed-c29ab2cf5c0e) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218/T1218.md#atomic-test-1---mavinject---inject-dll-into-running-process](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218/T1218.md#atomic-test-1---mavinject---inject-dll-into-running-process) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.013/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.013/atomic_red_team/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_binary_proxy_execution_mavinject_dll_injection.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-07-08-living_off_the_land.md b/docs/_posts/2022-07-08-living_off_the_land.md deleted file mode 100644 index 134210e727..0000000000 --- a/docs/_posts/2022-07-08-living_off_the_land.md +++ /dev/null @@ -1,177 +0,0 @@ ---- -title: "Living Off The Land" -excerpt: "Ingress Tool Transfer -, Exploit Public-Facing Application -, Command and Scripting Interpreter -" -categories: - - Endpoint -last_modified_at: 2022-07-08 -toc: true -toc_label: "" -tags: - - Ingress Tool Transfer - - Exploit Public-Facing Application - - Command and Scripting Interpreter - - Command And Control - - Initial Access - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Risk ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following correlation identifies a distinct amount of analytics associated with the Living Off The Land analytic story that identify potentially suspicious behavior. - -- **Type**: [Correlation](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Risk](https://docs.splunk.com/Documentation/CIM/latest/User/Risk) -- **Last Updated**: 2022-07-08 -- **Author**: Michael Haag, Splunk -- **ID**: 1be30d80-3a39-4df9-9102-64a467b24abc - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1105](https://attack.mitre.org/techniques/T1105/) | Ingress Tool Transfer | Command And Control | - -| [T1190](https://attack.mitre.org/techniques/T1190/) | Exploit Public-Facing Application | Initial Access | - -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Risk.All_Risk where All_Risk.analyticstories="Living Off The Land" All_Risk.risk_object_type="system" by All_Risk.risk_object All_Risk.annotations.mitre_attack.mitre_tactic source -| `drop_dm_object_name(All_Risk)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| stats values(source) as detection_name values(annotations.mitre_attack.mitre_tactic) as tactics values(firstTime) as firstTime values(lastTime) as lastTime dc(annotations.mitre_attack.mitre_tactic) as distinct_tactics dc(source) as distinct_detection_name by risk_object -| where distinct_detection_name >= 2 -| `living_off_the_land_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **living_off_the_land_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* All_Risk.analyticstories -* All_Risk.risk_object_type -* All_Risk.risk_object -* All_Risk.annotations.mitre_attack.mitre_tactic -* source - - -#### How To Implement -To implement this correlation search a user needs to enable all detections in the Living Off The Land Analytic Story and confirm it is generating risk events. A simple search `index=risk analyticstories="Living Off The Land"` should contain events. - -#### Known False Positives -There are no known false positive for this search, but it could contain false positives as multiple detections can trigger and not have successful exploitation. Modify the static value distinct_detection_name to a higher value. It is also required to tune analytics that are also tagged to ensure volume is never too much. - -#### Associated Analytic story -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 63.0 | 90 | 70 | An increase of Living Off The Land behavior has been detected on $affected_systems$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.splunk.com/en_us/blog/security/living-off-the-land-threat-research-february-2022-release.html](https://www.splunk.com/en_us/blog/security/living-off-the-land-threat-research-february-2022-release.html) -* [https://research.splunk.com/stories/living_off_the_land/](https://research.splunk.com/stories/living_off_the_land/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://raw.githubusercontent.com/splunk/attack_data/master/datasets/attack_techniques/T1218/living_off_the_land/lolbinrisk.log](https://raw.githubusercontent.com/splunk/attack_data/master/datasets/attack_techniques/T1218/living_off_the_land/lolbinrisk.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/living_off_the_land.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-07-11-azure_active_directory_high_risk_sign-in.md b/docs/_posts/2022-07-11-azure_active_directory_high_risk_sign-in.md deleted file mode 100644 index 07e45f0d0d..0000000000 --- a/docs/_posts/2022-07-11-azure_active_directory_high_risk_sign-in.md +++ /dev/null @@ -1,169 +0,0 @@ ---- -title: "Azure Active Directory High Risk Sign-in" -excerpt: "Brute Force -, Password Spraying -" -categories: - - Cloud -last_modified_at: 2022-07-11 -toc: true -toc_label: "" -tags: - - Brute Force - - Password Spraying - - Credential Access - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic triggers on a high risk sign-in against Azure Active Directory identified by Azure Identity Protection. Identity Protection monitors sign-in events using heuristics and machine learning to identify potentially malicious events and categorizes them in three categories high, medium and low. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-07-11 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 1ecff169-26d7-4161-9a7b-2ac4c8e61bea - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1110](https://attack.mitre.org/techniques/T1110/) | Brute Force | Credential Access | - -| [T1110.003](https://attack.mitre.org/techniques/T1110/003/) | Password Spraying | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - `azuread` body.category=UserRiskEvents body.properties.riskLevel=high -| rename body.properties.* as * -| stats values(userPrincipalName) by _time, ipAddress, activity, riskLevel, riskEventType, additionalInfo -| `azure_active_directory_high_risk_sign_in_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [azuread](https://github.com/splunk/security_content/blob/develop/macros/azuread.yml) - -> :information_source: -> **azure_active_directory_high_risk_sign-in_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* body.category -* body.properties.riskLevel -* body.properties.userPrincipalName -* body.properties.ipAddress -* body.properties.activity -* body.properties.riskEventType -* body.properties.additionalInfo - - -#### How To Implement -You must install the latest version of Splunk Add-on for Microsoft Cloud Services from Splunkbase (https://splunkbase.splunk.com/app/3110/#/details). You must be ingesting Azure Active Directory events into your Splunk environment. You must be ingesting Azure Active Directory events in your Splunk environment. Specifically, this analytic leverages the RiskyUsers and UserRiskEvents log category. - -#### Known False Positives -Details for the risk calculation algorithm used by Identity Protection are unknown and may be prone to false positives. - -#### Associated Analytic story -* [Azure Active Directory Account Takeover](/stories/azure_active_directory_account_takeover) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 54.0 | 60 | 90 | A high risk event was identified by Identify Protection for user $body.properties.userPrincipalName$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1110/003/](https://attack.mitre.org/techniques/T1110/003/) -* [https://docs.microsoft.com/en-us/security/compass/incident-response-playbook-password-spray](https://docs.microsoft.com/en-us/security/compass/incident-response-playbook-password-spray) -* [https://docs.microsoft.com/en-us/azure/active-directory/identity-protection/overview-identity-protection](https://docs.microsoft.com/en-us/azure/active-directory/identity-protection/overview-identity-protection) -* [https://docs.microsoft.com/en-us/azure/active-directory/identity-protection/concept-identity-protection-risks](https://docs.microsoft.com/en-us/azure/active-directory/identity-protection/concept-identity-protection-risks) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/azuread_highrisk/azure-audit.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/azuread_highrisk/azure-audit.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/azure_active_directory_high_risk_sign_in.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-07-11-azure_ad_unusual_number_of_failed_authentications_from_ip.md b/docs/_posts/2022-07-11-azure_ad_unusual_number_of_failed_authentications_from_ip.md deleted file mode 100644 index cd7209d473..0000000000 --- a/docs/_posts/2022-07-11-azure_ad_unusual_number_of_failed_authentications_from_ip.md +++ /dev/null @@ -1,173 +0,0 @@ ---- -title: "Azure AD Unusual Number of Failed Authentications From Ip" -excerpt: "Brute Force -, Password Spraying -" -categories: - - Cloud -last_modified_at: 2022-07-11 -toc: true -toc_label: "" -tags: - - Brute Force - - Password Spraying - - Credential Access - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies one source Ip failing to authenticate with multiple valid users. This behavior could represent an adversary performing a Password Spraying attack against an Azure Active Directory tenant to obtain initial access or elevate privileges. Error Code 50126 represents an invalid password.\ -The detection calculates the standard deviation for source Ip and leverages the 3-sigma statistical rule to identify an unusual number of failed authentication attempts. To customize this analytic, users can try different combinations of the `bucket` span time and the calculation of the `upperBound` field. This logic can be used for real time security monitoring as well as threat hunting exercises.\ -While looking for anomalies using statistical methods like the standard deviation can have benefits, we also recommend using threshold-based detections to complement coverage. A similar analytic following the threshold model is `Azure AD Multiple Users Failing To Authenticate From Ip`. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-07-11 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 3d8d3a36-93b8-42d7-8d91-c5f24cec223d - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1110](https://attack.mitre.org/techniques/T1110/) | Brute Force | Credential Access | - -| [T1110.003](https://attack.mitre.org/techniques/T1110/003/) | Password Spraying | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - `azuread` body.properties.status.errorCode= 50126 body.category= SignInLogs body.properties.authenticationDetails{}.succeeded= false -| rename body.properties.* as * -| bucket span=5m _time -| stats dc(userPrincipalName) AS unique_accounts values(userPrincipalName) as tried_accounts by _time, ipAddress -| eventstats avg(unique_accounts) as ip_avg , stdev(unique_accounts) as ip_std by ipAddress -| eval upperBound=(ip_avg+ip_std*3) -| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0) -| `azure_ad_unusual_number_of_failed_authentications_from_ip_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [azuread](https://github.com/splunk/security_content/blob/develop/macros/azuread.yml) - -> :information_source: -> **azure_ad_unusual_number_of_failed_authentications_from_ip_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* body.properties.status.errorCode -* body.category -* body.properties.authenticationDetails -* body.properties.userPrincipalName -* body.properties.ipAddress - - -#### How To Implement -You must install the latest version of Splunk Add-on for Microsoft Cloud Services from Splunkbase(https://splunkbase.splunk.com/app/3110/#/details). You must be ingesting Azure Active Directory events into your Splunk environment. You must be ingesting Azure Active Directory events in your Splunk environment. Specifically, this analytic leverages the SignInLogs log category. - -#### Known False Positives -A source Ip failing to authenticate with multiple users is not a common for legitimate behavior. - -#### Associated Analytic story -* [Azure Active Directory Account Takeover](/stories/azure_active_directory_account_takeover) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 54.0 | 60 | 90 | Possible Password Spraying attack against Azure AD from source ip $body.properties.ipAddress$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1110/003/](https://attack.mitre.org/techniques/T1110/003/) -* [https://docs.microsoft.com/en-us/security/compass/incident-response-playbook-password-spray](https://docs.microsoft.com/en-us/security/compass/incident-response-playbook-password-spray) -* [https://www.cisa.gov/uscert/ncas/alerts/aa21-008a](https://www.cisa.gov/uscert/ncas/alerts/aa21-008a) -* [https://docs.microsoft.com/azure/active-directory/reports-monitoring/reference-sign-ins-error-codes](https://docs.microsoft.com/azure/active-directory/reports-monitoring/reference-sign-ins-error-codes) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/azuread/azure-audit.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/azuread/azure-audit.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/azure_ad_unusual_number_of_failed_authentications_from_ip.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-07-11-windows_identify_protocol_handlers.md b/docs/_posts/2022-07-11-windows_identify_protocol_handlers.md deleted file mode 100644 index 99444ee6e1..0000000000 --- a/docs/_posts/2022-07-11-windows_identify_protocol_handlers.md +++ /dev/null @@ -1,183 +0,0 @@ ---- -title: "Windows Identify Protocol Handlers" -excerpt: "Command and Scripting Interpreter -" -categories: - - Endpoint -last_modified_at: 2022-07-11 -toc: true -toc_label: "" -tags: - - Command and Scripting Interpreter - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following hunting analytic will identify any protocol handlers utilized on the command-line. A protocol handler is an application that knows how to handle particular types of links: for example, a mail client is a protocol handler for "mailto:" links. When the user clicks a "mailto:" link, the browser opens the application selected as the handler for the "mailto:" protocol (or offers them a choice of handlers, depending on their settings). To identify protocol handlers we can use NirSoft https://www.nirsoft.net/utils/url_protocol_view.html URLProtocolView or query the registry using PowerShell: get-Item Registry::HKEY_CLASSES_ROOT\* | Select-Object "Property","PSChildName" | Where-Object -Property Property -Match "^URL*" #|Export-Csv -path c:\temp\url_all.csv. Note my query is limited to URL in the property to limit the scope of this query to similar handlers as ms-msdt. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-07-11 -- **Author**: Michael Haag, Splunk -- **ID**: bd5c311e-a6ea-48ae-a289-19a3398e3648 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Processes.process) as process values(Processes.parent_process) as parent_process from datamodel=Endpoint.Processes by Processes.dest Processes.user Processes.process_name Processes.process -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `drop_dm_object_name(Processes)` -| lookup windows_protocol_handlers handler AS process OUTPUT handler ishandler -| where ishandler="TRUE" -| `windows_identify_protocol_handlers_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_identify_protocol_handlers_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Lookups -The SPL above uses the following Lookups: - -* [windows_protocol_handlers](https://github.com/splunk/security_content/blob/develop/lookups/windows_protocol_handlers.yml) with [data](https://github.com/splunk/security_content/tree/develop/lookups/windows_protocol_handlers.csv) - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -False positives will be found. https and http is a URL Protocol handler that will trigger this analytic. Tune based on process or command-line. - -#### Associated Analytic story -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 6.0 | 30 | 20 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ utilizing a protocol handler. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.oreilly.com/library/view/learning-java/1565927184/apas02.html](https://www.oreilly.com/library/view/learning-java/1565927184/apas02.html) -* [https://blogs.windows.com/msedgedev/2022/01/20/getting-started-url-protocol-handlers-microsoft-edge/](https://blogs.windows.com/msedgedev/2022/01/20/getting-started-url-protocol-handlers-microsoft-edge/) -* [https://github.com/Mr-Un1k0d3r/PoisonHandler](https://github.com/Mr-Un1k0d3r/PoisonHandler) -* [https://www.mdsec.co.uk/2021/03/phishing-users-to-take-a-test/](https://www.mdsec.co.uk/2021/03/phishing-users-to-take-a-test/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218/T1218.md#atomic-test-5---protocolhandlerexe-downloaded-a-suspicious-file](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218/T1218.md#atomic-test-5---protocolhandlerexe-downloaded-a-suspicious-file) -* [https://techcommunity.microsoft.com/t5/windows-it-pro-blog/disabling-the-msix-ms-appinstaller-protocol-handler/ba-p/3119479](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/disabling-the-msix-ms-appinstaller-protocol-handler/ba-p/3119479) -* [https://www.huntress.com/blog/microsoft-office-remote-code-execution-follina-msdt-bug](https://www.huntress.com/blog/microsoft-office-remote-code-execution-follina-msdt-bug) -* [https://parsiya.net/blog/2021-03-17-attack-surface-analysis-part-2-custom-protocol-handlers/](https://parsiya.net/blog/2021-03-17-attack-surface-analysis-part-2-custom-protocol-handlers/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059/protocol_handlers/protocolhandlers.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059/protocol_handlers/protocolhandlers.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_identify_protocol_handlers.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-07-12-aws_defense_evasion_stop_logging_cloudtrail.md b/docs/_posts/2022-07-12-aws_defense_evasion_stop_logging_cloudtrail.md deleted file mode 100644 index 6be54f4310..0000000000 --- a/docs/_posts/2022-07-12-aws_defense_evasion_stop_logging_cloudtrail.md +++ /dev/null @@ -1,168 +0,0 @@ ---- -title: "AWS Defense Evasion Stop Logging Cloudtrail" -excerpt: "Disable Cloud Logs -, Impair Defenses -" -categories: - - Cloud -last_modified_at: 2022-07-12 -toc: true -toc_label: "" -tags: - - Disable Cloud Logs - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic identifies `StopLogging` events in CloudTrail logs. Adversaries often try to impair their target's defenses by stopping their macliious activity from being logged, so that they may operate with stealth and avoid detection. When the adversary has the right type of permissions in the compromised AWS environment, they may easily stop logging. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-07-12 -- **Author**: Bhavin Patel, Splunk -- **ID**: 8a2f3ca2-4eb5-4389-a549-14063882e537 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.008](https://attack.mitre.org/techniques/T1562/008/) | Disable Cloud Logs | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cloudtrail` eventName = StopLogging eventSource = cloudtrail.amazonaws.com userAgent !=console.amazonaws.com errorCode = success -| stats count min(_time) as firstTime max(_time) as lastTime values(requestParameters.name) as stopped_cloudtrail_name by src region eventName userAgent user_arn aws_account_id -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `aws_defense_evasion_stop_logging_cloudtrail_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) - -> :information_source: -> **aws_defense_evasion_stop_logging_cloudtrail_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* eventName -* eventSource -* requestParameters.name -* userAgent -* aws_account_id -* src -* region - - -#### How To Implement -You must install Splunk AWS Add on and enable Cloudtrail logs in your AWS Environment. - -#### Known False Positives -While this search has no known false positives, it is possible that an AWS admin has stopped cloudtrail logging. Please investigate this activity. - -#### Associated Analytic story -* [AWS Defense Evasion](/stories/aws_defense_evasion) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 90.0 | 100 | 90 | User $user_arn$ has stopped Cloudtrail logging for account id $aws_account_id$ from IP $src$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1562/008/](https://attack.mitre.org/techniques/T1562/008/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/stop_delete_cloudtrail/aws_cloudtrail_events.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/stop_delete_cloudtrail/aws_cloudtrail_events.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/aws_defense_evasion_stop_logging_cloudtrail.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-07-12-azure_ad_multiple_users_failing_to_authenticate_from_ip.md b/docs/_posts/2022-07-12-azure_ad_multiple_users_failing_to_authenticate_from_ip.md deleted file mode 100644 index 3483238cec..0000000000 --- a/docs/_posts/2022-07-12-azure_ad_multiple_users_failing_to_authenticate_from_ip.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: "Azure AD Multiple Users Failing To Authenticate From Ip" -excerpt: "Brute Force -, Password Spraying -" -categories: - - Cloud -last_modified_at: 2022-07-12 -toc: true -toc_label: "" -tags: - - Brute Force - - Password Spraying - - Credential Access - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies one source Ip failing to authenticate with 30 unique valid users within 5 minutes. This behavior could represent an adversary performing a Password Spraying attack against an Azure Active Directory tenant to obtain initial access or elevate privileges. Error Code 50126 represents an invalid password. This logic can be used for real time security monitoring as well as threat hunting exercises.\ -Azure AD tenants can be very different depending on the organization. Users should test this detection and customize the arbitrary threshold if needed. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-07-12 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 94481a6a-8f59-4c86-957f-55a71e3612a6 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1110](https://attack.mitre.org/techniques/T1110/) | Brute Force | Credential Access | - -| [T1110.003](https://attack.mitre.org/techniques/T1110/003/) | Password Spraying | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - `azuread` body.properties.status.errorCode= 50126 body.category= SignInLogs body.properties.authenticationDetails{}.succeeded= false -| rename body.properties.* as * -| bucket span=5m _time -| stats dc(userPrincipalName) AS unique_accounts values(userPrincipalName) as tried_accounts by _time, ipAddress -| where unique_accounts > 30 -| `azure_ad_multiple_users_failing_to_authenticate_from_ip_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [azuread](https://github.com/splunk/security_content/blob/develop/macros/azuread.yml) - -> :information_source: -> **azure_ad_multiple_users_failing_to_authenticate_from_ip_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* body.properties.status.errorCode -* body.category -* body.properties.authenticationDetails -* body.properties.userPrincipalName -* body.properties.ipAddress - - -#### How To Implement -You must install the latest version of Splunk Add-on for Microsoft Cloud Services from Splunkbase(https://splunkbase.splunk.com/app/3110/#/details). You must be ingesting Azure Active Directory events into your Splunk environment. You must be ingesting Azure Active Directory events in your Splunk environment. Specifically, this analytic leverages the SignInLogs log category. - -#### Known False Positives -A source Ip failing to authenticate with multiple users is not a common for legitimate behavior. - -#### Associated Analytic story -* [Azure Active Directory Account Takeover](/stories/azure_active_directory_account_takeover) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 63.0 | 70 | 90 | Source Ip $body.properties.ipAddress$ failed to authenticate with 30 users within 5 minutes. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1110/003/](https://attack.mitre.org/techniques/T1110/003/) -* [https://docs.microsoft.com/en-us/security/compass/incident-response-playbook-password-spray](https://docs.microsoft.com/en-us/security/compass/incident-response-playbook-password-spray) -* [https://www.cisa.gov/uscert/ncas/alerts/aa21-008a](https://www.cisa.gov/uscert/ncas/alerts/aa21-008a) -* [https://docs.microsoft.com/azure/active-directory/reports-monitoring/reference-sign-ins-error-codes](https://docs.microsoft.com/azure/active-directory/reports-monitoring/reference-sign-ins-error-codes) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/azuread/azure-audit.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/azuread/azure-audit.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/azure_ad_multiple_users_failing_to_authenticate_from_ip.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-07-12-azure_ad_successful_single-factor_authentication.md b/docs/_posts/2022-07-12-azure_ad_successful_single-factor_authentication.md deleted file mode 100644 index 77c71e8715..0000000000 --- a/docs/_posts/2022-07-12-azure_ad_successful_single-factor_authentication.md +++ /dev/null @@ -1,162 +0,0 @@ ---- -title: "Azure AD Successful Single-Factor Authentication" -excerpt: "Security Account Manager -" -categories: - - Cloud -last_modified_at: 2022-07-12 -toc: true -toc_label: "" -tags: - - Security Account Manager - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies a successful authentication event against Azure Active Directory for an account without Multi-Factor Authentication enabled. This could be evidence of a missconfiguration, a policy violation or an account take over attempt that should be investigated - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-07-12 -- **Author**: Mauricio Velazco, Splunk -- **ID**: a560e7f6-1711-4353-885b-40be53101fcd - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1003.002](https://attack.mitre.org/techniques/T1003/002/) | Security Account Manager | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - `azuread` body.category=SignInLogs body.properties.authenticationRequirement=singleFactorAuthentication body.properties.authenticationDetails{}.succeeded=true -| rename body.properties.* as * -| stats values(userPrincipalName) by _time, ipAddress, appDisplayName, authenticationRequirement -| `azure_ad_successful_single_factor_authentication_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [azuread](https://github.com/splunk/security_content/blob/develop/macros/azuread.yml) - -> :information_source: -> **azure_ad_successful_single-factor_authentication_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* body.category -* body.properties.authenticationRequirement -* body.properties.authenticationDetails -* body.properties.userPrincipalName -* body.properties.ipAddress -* body.properties.appDisplayName - - -#### How To Implement -You must install the latest version of Splunk Add-on for Microsoft Cloud Services from Splunkbase(https://splunkbase.splunk.com/app/3110/#/details). You must be ingesting Azure Active Directory events into your Splunk environment. You must be ingesting Azure Active Directory events in your Splunk environment. Specifically, this analytic leverages the SignInLogs log category. - -#### Known False Positives -Although not recommended, certain users may be required without multi-factor authentication. Filter as needed - -#### Associated Analytic story -* [Azure Active Directory Account Takeover](/stories/azure_active_directory_account_takeover) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 50.0 | 50 | 100 | Successful authentication for user $body.properties.userPrincipalName$ without MFA | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1078/004/](https://attack.mitre.org/techniques/T1078/004/) -* [https://docs.microsoft.com/en-us/azure/active-directory/authentication/concept-mfa-howitworks*](https://docs.microsoft.com/en-us/azure/active-directory/authentication/concept-mfa-howitworks*) -* [https://www.forbes.com/sites/daveywinder/2020/07/08/new-dark-web-audit-reveals-15-billion-stolen-logins-from-100000-breaches-passwords-hackers-cybercrime/?sh=69927b2a180f](https://www.forbes.com/sites/daveywinder/2020/07/08/new-dark-web-audit-reveals-15-billion-stolen-logins-from-100000-breaches-passwords-hackers-cybercrime/?sh=69927b2a180f) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078.004/azuread/azure-audit.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078.004/azuread/azure-audit.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/azure_ad_successful_single_factor_authentication.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-07-12-spring4shell_payload_url_request.md b/docs/_posts/2022-07-12-spring4shell_payload_url_request.md deleted file mode 100644 index e1c61a9c8d..0000000000 --- a/docs/_posts/2022-07-12-spring4shell_payload_url_request.md +++ /dev/null @@ -1,180 +0,0 @@ ---- -title: "Spring4Shell Payload URL Request" -excerpt: "Web Shell -, Server Software Component -, Exploit Public-Facing Application -" -categories: - - Web -last_modified_at: 2022-07-12 -toc: true -toc_label: "" -tags: - - Web Shell - - Server Software Component - - Exploit Public-Facing Application - - Persistence - - Persistence - - Initial Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - CVE-2022-22965 - - Web ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic is static indicators related to CVE-2022-22963, Spring4Shell. The 3 indicators provide an amount of fidelity that source IP is attemping to exploit a web shell on the destination. The filename and cmd are arbitrary in this exploitation. Java will write a JSP to disk and a process will spawn from Java based on the cmd passed. This is indicative of typical web shell activity. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Web](https://docs.splunk.com/Documentation/CIM/latest/User/Web) -- **Last Updated**: 2022-07-12 -- **Author**: Michael Haag, Splunk -- **ID**: 9d44d649-7d67-4559-95c1-8022ff49420b - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1505.003](https://attack.mitre.org/techniques/T1505/003/) | Web Shell | Persistence | - -| [T1505](https://attack.mitre.org/techniques/T1505/) | Server Software Component | Persistence | - -| [T1190](https://attack.mitre.org/techniques/T1190/) | Exploit Public-Facing Application | Initial Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
-| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | -| ----------- | ----------- | -------------- | -| [CVE-2022-22965](https://nvd.nist.gov/vuln/detail/CVE-2022-22965) | A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it. | 7.5 | - - - -
-
- -#### Search - -``` - -| tstats count from datamodel=Web where Web.http_method IN ("GET") Web.url IN ("*tomcatwar.jsp*","*poc.jsp*","*shell.jsp*") by Web.http_user_agent Web.http_method, Web.url,Web.url_length Web.src, Web.dest sourcetype -| `drop_dm_object_name("Web")` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `spring4shell_payload_url_request_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) - -> :information_source: -> **spring4shell_payload_url_request_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Web.http_method -* Web.url -* Web.url_length -* Web.src -* Web.dest -* Web.http_user_agent - - -#### How To Implement -To successfully implement this search you need to be ingesting information on Web traffic that include fields relavent for traffic into the `Web` datamodel. - -#### Known False Positives -The jsp file names are static names used in current proof of concept code. = - -#### Associated Analytic story -* [Spring4Shell CVE-2022-22965](/stories/spring4shell_cve-2022-22965) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 36.0 | 60 | 60 | A URL was requested related to Spring4Shell POC code on $dest$ by $src$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://www.microsoft.com/security/blog/2022/04/04/springshell-rce-vulnerability-guidance-for-protecting-against-and-detecting-cve-2022-22965/](https://www.microsoft.com/security/blog/2022/04/04/springshell-rce-vulnerability-guidance-for-protecting-against-and-detecting-cve-2022-22965/) -* [https://github.com/TheGejr/SpringShell](https://github.com/TheGejr/SpringShell) -* [https://www.tenable.com/blog/spring4shell-faq-spring-framework-remote-code-execution-vulnerability](https://www.tenable.com/blog/spring4shell-faq-spring-framework-remote-code-execution-vulnerability) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/spring4shell/spring4shell_nginx.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/spring4shell/spring4shell_nginx.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/web/spring4shell_payload_url_request.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-07-13-aws_defense_evasion_delete_cloudtrail.md b/docs/_posts/2022-07-13-aws_defense_evasion_delete_cloudtrail.md deleted file mode 100644 index d67243e2a5..0000000000 --- a/docs/_posts/2022-07-13-aws_defense_evasion_delete_cloudtrail.md +++ /dev/null @@ -1,168 +0,0 @@ ---- -title: "AWS Defense Evasion Delete Cloudtrail" -excerpt: "Disable Cloud Logs -, Impair Defenses -" -categories: - - Cloud -last_modified_at: 2022-07-13 -toc: true -toc_label: "" -tags: - - Disable Cloud Logs - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic identifies AWS `DeleteTrail` events within CloudTrail logs. Adversaries often try to impair their target's defenses by stopping their malicious activity from being logged, so that they may operate with stealth and avoid detection. When the adversary has the right type of permissions in the compromised AWS environment, they may delete the the entire cloudtrail that is logging activities in the environment. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-07-13 -- **Author**: Bhavin Patel, Splunk -- **ID**: 82092925-9ca1-4e06-98b8-85a2d3889552 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.008](https://attack.mitre.org/techniques/T1562/008/) | Disable Cloud Logs | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cloudtrail` eventName = DeleteTrail eventSource = cloudtrail.amazonaws.com userAgent !=console.amazonaws.com errorCode = success -| stats count min(_time) as firstTime max(_time) as lastTime values(requestParameters.name) as deleted_cloudtrail_name by src region eventName userAgent user_arn aws_account_id -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `aws_defense_evasion_delete_cloudtrail_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) - -> :information_source: -> **aws_defense_evasion_delete_cloudtrail_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* eventName -* eventSource -* requestParameters.name -* userAgent -* aws_account_id -* src -* region - - -#### How To Implement -You must install Splunk AWS Add on and enable CloudTrail logs in your AWS Environment. - -#### Known False Positives -While this search has no known false positives, it is possible that an AWS admin has stopped cloudTrail logging. Please investigate this activity. - -#### Associated Analytic story -* [AWS Defense Evasion](/stories/aws_defense_evasion) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 90.0 | 100 | 90 | User $user_arn$ has delete a CloudTrail logging for account id $aws_account_id$ from IP $src$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1562/008/](https://attack.mitre.org/techniques/T1562/008/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/stop_delete_cloudtrail/aws_cloudtrail_events.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/stop_delete_cloudtrail/aws_cloudtrail_events.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/aws_defense_evasion_delete_cloudtrail.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-07-13-azure_ad_successful_powershell_authentication.md b/docs/_posts/2022-07-13-azure_ad_successful_powershell_authentication.md deleted file mode 100644 index d7732dc4a0..0000000000 --- a/docs/_posts/2022-07-13-azure_ad_successful_powershell_authentication.md +++ /dev/null @@ -1,174 +0,0 @@ ---- -title: "Azure AD Successful PowerShell Authentication" -excerpt: "Valid Accounts -, Cloud Accounts -" -categories: - - Cloud -last_modified_at: 2022-07-13 -toc: true -toc_label: "" -tags: - - Valid Accounts - - Cloud Accounts - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies a successful authentication event against an Azure AD tenant using PowerShell commandlets. This behavior is not common for regular, non administrative users. After compromising an account in Azure AD, attackers and red teams alike will perform enumeration and discovery techniques. One method of executing these techniques is leveraging the native PowerShell modules. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-07-13 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 62f10052-d7b3-4e48-b57b-56f8e3ac7ceb - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -| [T1078.004](https://attack.mitre.org/techniques/T1078/004/) | Cloud Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - `azuread` body.category=SignInLogs body.properties.authenticationDetails{}.succeeded=true body.properties.appDisplayName="Azure Active Directory PowerShell" -| rename body.properties.* as * -| stats values(userPrincipalName) by _time, ipAddress, appDisplayName, userAgent -| `azure_ad_successful_powershell_authentication_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [azuread](https://github.com/splunk/security_content/blob/develop/macros/azuread.yml) - -> :information_source: -> **azure_ad_successful_powershell_authentication_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* body.properties.appDisplayName -* body.category -* body.properties.userPrincipalName -* body.properties.ipAddress -* body.properties.appDisplayName -* body.properties.userAgent - - -#### How To Implement -You must install the latest version of Splunk Add-on for Microsoft Cloud Services from Splunkbase(https://splunkbase.splunk.com/app/3110/#/details). You must be ingesting Azure Active Directory events into your Splunk environment. You must be ingesting Azure Active Directory events in your Splunk environment. Specifically, this analytic leverages the SignInLogs log category. - -#### Known False Positives -Administrative users will likely use PowerShell commandlets to troubleshoot and maintain the environment. Filter as needed. - -#### Associated Analytic story -* [Azure Active Directory Account Takeover](/stories/azure_active_directory_account_takeover) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 54.0 | 60 | 90 | Successful authentication for user $body.properties.userPrincipalName$ using PowerShell. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1078/004/](https://attack.mitre.org/techniques/T1078/004/) -* [https://docs.microsoft.com/en-us/powershell/module/azuread/connect-azuread?view=azureadps-2.0](https://docs.microsoft.com/en-us/powershell/module/azuread/connect-azuread?view=azureadps-2.0) -* [https://securitycafe.ro/2022/04/29/pentesting-azure-recon-techniques/](https://securitycafe.ro/2022/04/29/pentesting-azure-recon-techniques/) -* [https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Methodology%20and%20Resources/Cloud%20-%20Azure%20Pentest.md](https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Methodology%20and%20Resources/Cloud%20-%20Azure%20Pentest.md) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078.004/azuread_pws/azure-audit.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078.004/azuread_pws/azure-audit.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/azure_ad_successful_powershell_authentication.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-07-14-azure_ad_authentication_failed_during_mfa_challenge.md b/docs/_posts/2022-07-14-azure_ad_authentication_failed_during_mfa_challenge.md deleted file mode 100644 index 2e3b4a1154..0000000000 --- a/docs/_posts/2022-07-14-azure_ad_authentication_failed_during_mfa_challenge.md +++ /dev/null @@ -1,179 +0,0 @@ ---- -title: "Azure AD Authentication Failed During MFA Challenge" -excerpt: "Valid Accounts -, Cloud Accounts -, Multi-Factor Authentication Request Generation -" -categories: - - Cloud -last_modified_at: 2022-07-14 -toc: true -toc_label: "" -tags: - - Valid Accounts - - Cloud Accounts - - Multi-Factor Authentication Request Generation - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Defense Evasion - - Initial Access - - Persistence - - Privilege Escalation - - Credential Access - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies an authentication attempt event against an Azure AD tenant that fails during the Multi Factor Authentication challenge. This behavior may represent an adversary trying to authenticate with compromised credentials. In some cases, adversaries may continuously repeat login attempts in order to bombard users with MFA push notifications, SMS messages, and phone calls, potentially resulting in the user finally accepting the authentication request. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-07-14 -- **Author**: Mauricio Velazco, Splunk -- **ID**: e62c9c2e-bf51-4719-906c-3074618fcc1c - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -| [T1078.004](https://attack.mitre.org/techniques/T1078/004/) | Cloud Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | - -| [T1621](https://attack.mitre.org/techniques/T1621/) | Multi-Factor Authentication Request Generation | Credential Access | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - `azuread` body.category=SignInLogs body.properties.status.errorCode=500121 -| rename body.properties.* as * -| stats values(userPrincipalName) by _time, ipAddress, status.additionalDetails, appDisplayName, userAgent -| `azure_ad_authentication_failed_during_mfa_challenge_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [azuread](https://github.com/splunk/security_content/blob/develop/macros/azuread.yml) - -> :information_source: -> **azure_ad_authentication_failed_during_mfa_challenge_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* body.category -* body.properties.status.errorCode -* body.properties.userPrincipalName -* body.properties.ipAddress -* body.properties.status.additionalDetails -* body.properties.appDisplayName -* body.properties.userAgent - - -#### How To Implement -You must install the latest version of Splunk Add-on for Microsoft Cloud Services from Splunkbase(https://splunkbase.splunk.com/app/3110/#/details). You must be ingesting Azure Active Directory events into your Splunk environment. You must be ingesting Azure Active Directory events in your Splunk environment. Specifically, this analytic leverages the RiskyUsers and UserRiskEvents log category. - -#### Known False Positives -Legitimate users may miss to reply the MFA challenge within the time window or deny it by mistake. - -#### Associated Analytic story -* [Azure Active Directory Account Takeover](/stories/azure_active_directory_account_takeover) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 54.0 | 60 | 90 | User $body.properties.userPrincipalName$ failed to pass MFA challenge | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1621/](https://attack.mitre.org/techniques/T1621/) -* [https://attack.mitre.org/techniques/T1078/004/](https://attack.mitre.org/techniques/T1078/004/) -* [https://docs.microsoft.com/en-us/azure/active-directory/authentication/concept-mfa-howitworks](https://docs.microsoft.com/en-us/azure/active-directory/authentication/concept-mfa-howitworks) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1621/azuread/azure-audit.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1621/azuread/azure-audit.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/azure_ad_authentication_failed_during_mfa_challenge.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-07-15-certutil_exe_certificate_extraction.md b/docs/_posts/2022-07-15-certutil_exe_certificate_extraction.md deleted file mode 100644 index f26825b569..0000000000 --- a/docs/_posts/2022-07-15-certutil_exe_certificate_extraction.md +++ /dev/null @@ -1,158 +0,0 @@ ---- -title: "Certutil exe certificate extraction" -excerpt: "" -categories: - - Endpoint -last_modified_at: 2022-07-15 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search looks for arguments to certutil.exe indicating the manipulation or extraction of Certificate. This certificate can then be used to sign new authentication tokens specially inside Federated environments such as Windows ADFS. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-07-15 -- **Author**: Rod Soto, Splunk -- **ID**: 337a46be-600f-11eb-ae93-0242ac130002 - - -#### Annotations - -
- ATT&CK - -
- -
-
- - -
- Kill Chain Phase - -
- -* Installation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=certutil.exe Processes.process = "*-exportPFX*" by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `certutil_exe_certificate_extraction_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **certutil_exe_certificate_extraction_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -#### Known False Positives -Unless there are specific use cases, manipulating or exporting certificates using certutil is uncommon. Extraction of certificate has been observed during attacks such as Golden SAML and other campaigns targeting Federated services. - -#### Associated Analytic story -* [Windows Persistence Techniques](/stories/windows_persistence_techniques) -* [Cloud Federated Credential Abuse](/stories/cloud_federated_credential_abuse) -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 63.0 | 90 | 70 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting export a certificate. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://blog.sygnia.co/detection-and-hunting-of-golden-saml-attack](https://blog.sygnia.co/detection-and-hunting-of-golden-saml-attack) -* [https://strontic.github.io/xcyclopedia/library/certutil.exe-09A8A29BAA3A451713FD3D07943B4A43.html](https://strontic.github.io/xcyclopedia/library/certutil.exe-09A8A29BAA3A451713FD3D07943B4A43.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/certutil_exe_certificate_extraction/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/certutil_exe_certificate_extraction/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/certutil_exe_certificate_extraction.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-07-15-powershell_disable_security_monitoring.md b/docs/_posts/2022-07-15-powershell_disable_security_monitoring.md deleted file mode 100644 index 29cdd34dfe..0000000000 --- a/docs/_posts/2022-07-15-powershell_disable_security_monitoring.md +++ /dev/null @@ -1,171 +0,0 @@ ---- -title: "Powershell Disable Security Monitoring" -excerpt: "Disable or Modify Tools -, Impair Defenses -" -categories: - - Endpoint -last_modified_at: 2022-07-15 -toc: true -toc_label: "" -tags: - - Disable or Modify Tools - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This search is to identifies a modification in registry to disable the windows denfender real time behavior monitoring. This event or technique is commonly seen in RAT, bot, or Trojan to disable AV to evade detections. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-07-15 -- **Author**: Michael Haag, Splunk -- **ID**: c148a894-dd93-11eb-bf2a-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_powershell` Processes.process="*set-mppreference*" AND Processes.process IN ("*disablerealtimemonitoring*","*disableioavprotection*","*disableintrusionpreventionsystem*","*disablescriptscanning*","*disableblockatfirstseen*","*DisableBehaviorMonitoring*","*drtm *","*dioavp *","*dscrptsc *","*dbaf *","*dbm *") by Processes.dest Processes.user Processes.parent_process Processes.original_file_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `powershell_disable_security_monitoring_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml) - -> :information_source: -> **powershell_disable_security_monitoring_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Limited false positives. However, tune based on scripts that may perform this action. - -#### Associated Analytic story -* [Ransomware](/stories/ransomware) -* [Revil Ransomware](/stories/revil_ransomware) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1562.001/T1562.001.md#atomic-test-15---tamper-with-windows-defender-atp-powershell](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1562.001/T1562.001.md#atomic-test-15---tamper-with-windows-defender-atp-powershell) -* [https://docs.microsoft.com/en-us/powershell/module/defender/set-mppreference?view=windowsserver2022-ps](https://docs.microsoft.com/en-us/powershell/module/defender/set-mppreference?view=windowsserver2022-ps) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/pwh_defender_disabling/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/pwh_defender_disabling/windows-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/powershell_disable_security_monitoring.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2022-07-15-windows_mof_event_triggered_execution_via_wmi.md b/docs/_posts/2022-07-15-windows_mof_event_triggered_execution_via_wmi.md deleted file mode 100644 index 97d58f137b..0000000000 --- a/docs/_posts/2022-07-15-windows_mof_event_triggered_execution_via_wmi.md +++ /dev/null @@ -1,174 +0,0 @@ ---- -title: "Windows MOF Event Triggered Execution via WMI" -excerpt: "Windows Management Instrumentation Event Subscription -" -categories: - - Endpoint -last_modified_at: 2022-07-15 -toc: true -toc_label: "" -tags: - - Windows Management Instrumentation Event Subscription - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following anaytic identifies MOFComp.exe loading a MOF file. The Managed Object Format (MOF) compiler parses a file containing MOF statements and adds the classes and class instances defined in the file to the WMI repository. Typically, MOFComp.exe does not reach out to the public internet or load a MOF file from User Profile paths. A filter and consumer is typically registered in WMI. Review parallel processes and query WMI subscriptions to gather artifacts. The default path of mofcomp.exe is C:\Windows\System32\wbem. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-07-15 -- **Author**: Michael Haag, Splunk -- **ID**: e59b5a73-32bf-4467-a585-452c36ae10c1 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1546.003](https://attack.mitre.org/techniques/T1546/003/) | Windows Management Instrumentation Event Subscription | Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.parent_process_name IN ("cmd.exe", "powershell.exe") Processes.process_name=mofcomp.exe) OR (Processes.process_name=mofcomp.exe Processes.process IN ("*\\AppData\\Local\\*","*\\Users\\Public\\*", "*\\WINDOWS\\Temp\\*")) by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_mof_event_triggered_execution_via_wmi_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_mof_event_triggered_execution_via_wmi_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -False positives may be present from automation based applications (SCCM), filtering may be required. In addition, break the query out based on volume of usage. Filter process names or f - -#### Associated Analytic story -* [Living Off The Land](/stories/living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 64.0 | 80 | 80 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ loading a MOF file. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1546/003/](https://attack.mitre.org/techniques/T1546/003/) -* [https://thedfirreport.com/2022/07/11/select-xmrig-from-sqlserver/](https://thedfirreport.com/2022/07/11/select-xmrig-from-sqlserver/) -* [https://docs.microsoft.com/en-us/windows/win32/wmisdk/mofcomp](https://docs.microsoft.com/en-us/windows/win32/wmisdk/mofcomp) -* [https://pentestlab.blog/2020/01/21/persistence-wmi-event-subscription/](https://pentestlab.blog/2020/01/21/persistence-wmi-event-subscription/) -* [https://www.sakshamdixit.com/wmi-events/](https://www.sakshamdixit.com/wmi-events/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.003/atomic_red_team/mofcomp.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.003/atomic_red_team/mofcomp.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_mof_event_triggered_execution_via_wmi.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-07-17-aws_defense_evasion_delete_cloudwatch_log_group.md b/docs/_posts/2022-07-17-aws_defense_evasion_delete_cloudwatch_log_group.md deleted file mode 100644 index f02495f7de..0000000000 --- a/docs/_posts/2022-07-17-aws_defense_evasion_delete_cloudwatch_log_group.md +++ /dev/null @@ -1,168 +0,0 @@ ---- -title: "AWS Defense Evasion Delete CloudWatch Log Group" -excerpt: "Impair Defenses -, Disable Cloud Logs -" -categories: - - Cloud -last_modified_at: 2022-07-17 -toc: true -toc_label: "" -tags: - - Impair Defenses - - Disable Cloud Logs - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic identifies AWS `DeleteLogGroup` events in CloudTrail logs. Attackers may evade the logging capability by deleting the log group in CloudWatch. This will stop sending the logs and metrics to CloudWatch. When the adversary has the right type of permissions within the compromised AWS environment, they may delete the CloudWatch log group that is logging activities in the environment. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-07-17 -- **Author**: Gowthamaraj Rajendran, Splunk -- **ID**: d308b0f1-edb7-4a62-a614-af321160710f - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -| [T1562.008](https://attack.mitre.org/techniques/T1562/008/) | Disable Cloud Logs | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cloudtrail` eventName = DeleteLogGroup eventSource = logs.amazonaws.com userAgent !=console.amazonaws.com errorCode = success -| stats count min(_time) as firstTime max(_time) as lastTime values(requestParameters.logGroupName) as log_group_name by src region eventName userAgent user_arn aws_account_id -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `aws_defense_evasion_delete_cloudwatch_log_group_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) - -> :information_source: -> **aws_defense_evasion_delete_cloudwatch_log_group_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* eventName -* eventSource -* requestParameters.name -* userAgent -* aws_account_id -* src -* region - - -#### How To Implement -You must install Splunk AWS Add on and enable CloudTrail logs in your AWS Environment. - -#### Known False Positives -While this search has no known false positives, it is possible that an AWS admin has deleted CloudWatch logging. Please investigate this activity. - -#### Associated Analytic story -* [AWS Defense Evasion](/stories/aws_defense_evasion) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 90.0 | 100 | 90 | User $user_arn$ has deleted a CloudWatch logging group for account id $aws_account_id$ from IP $src$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1562/008/](https://attack.mitre.org/techniques/T1562/008/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/delete_cloudwatch_log_group/aws_cloudtrail_events.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/delete_cloudwatch_log_group/aws_cloudtrail_events.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/aws_defense_evasion_delete_cloudwatch_log_group.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-07-17-aws_defense_evasion_update_cloudtrail.md b/docs/_posts/2022-07-17-aws_defense_evasion_update_cloudtrail.md deleted file mode 100644 index 886df670fd..0000000000 --- a/docs/_posts/2022-07-17-aws_defense_evasion_update_cloudtrail.md +++ /dev/null @@ -1,168 +0,0 @@ ---- -title: "AWS Defense Evasion Update Cloudtrail" -excerpt: "Impair Defenses -, Disable Cloud Logs -" -categories: - - Cloud -last_modified_at: 2022-07-17 -toc: true -toc_label: "" -tags: - - Impair Defenses - - Disable Cloud Logs - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic identifies `UpdateTrail` events in CloudTrail logs. Attackers may evade the logging capability by updating the settings and impairing them with wrong parameters. For example, Attackers may change the multi-regional log into a single region logs, which evades the logging for other regions. When the adversary has the right type of permissions in the compromised AWS environment, they may update the CloudTrail settings that is logging activities in your environment. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-07-17 -- **Author**: Gowthamaraj Rajendran, Splunk -- **ID**: 7c921d28-ef48-4f1b-85b3-0af8af7697db - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -| [T1562.008](https://attack.mitre.org/techniques/T1562/008/) | Disable Cloud Logs | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cloudtrail` eventName = UpdateTrail eventSource = cloudtrail.amazonaws.com userAgent !=console.amazonaws.com errorCode = success -| stats count min(_time) as firstTime max(_time) as lastTime values(requestParameters.name) as cloudtrail_name by src region eventName userAgent user_arn aws_account_id -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `aws_defense_evasion_update_cloudtrail_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) - -> :information_source: -> **aws_defense_evasion_update_cloudtrail_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* eventName -* eventSource -* requestParameters.name -* userAgent -* aws_account_id -* src -* region - - -#### How To Implement -You must install Splunk AWS Add on and enable CloudTrail logs in your AWS Environment. - -#### Known False Positives -While this search has no known false positives, it is possible that an AWS admin has updated cloudtrail logging. Please investigate this activity. - -#### Associated Analytic story -* [AWS Defense Evasion](/stories/aws_defense_evasion) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 90.0 | 100 | 90 | User $user_arn$ has updated a cloudtrail logging for account id $aws_account_id$ from IP $src$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1562/008/](https://attack.mitre.org/techniques/T1562/008/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/update_cloudtrail/aws_cloudtrail_events.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/update_cloudtrail/aws_cloudtrail_events.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/aws_defense_evasion_update_cloudtrail.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-07-19-allow_inbound_traffic_by_firewall_rule_registry.md b/docs/_posts/2022-07-19-allow_inbound_traffic_by_firewall_rule_registry.md deleted file mode 100644 index b75d110ed0..0000000000 --- a/docs/_posts/2022-07-19-allow_inbound_traffic_by_firewall_rule_registry.md +++ /dev/null @@ -1,176 +0,0 @@ ---- -title: "Allow Inbound Traffic By Firewall Rule Registry" -excerpt: "Remote Desktop Protocol -, Remote Services -" -categories: - - Endpoint -last_modified_at: 2022-07-19 -toc: true -toc_label: "" -tags: - - Remote Desktop Protocol - - Remote Services - - Lateral Movement - - Lateral Movement - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic detects a potential suspicious modification of firewall rule registry allowing inbound traffic in specific port with public profile. This technique was identified when an adversary wants to grant remote access to a machine by allowing the traffic in a firewall rule. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-07-19 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 0a46537c-be02-11eb-92ca-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1021.001](https://attack.mitre.org/techniques/T1021/001/) | Remote Desktop Protocol | Lateral Movement | - -| [T1021](https://attack.mitre.org/techniques/T1021/) | Remote Services | Lateral Movement | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path= "*\\System\\CurrentControlSet\\Services\\SharedAccess\\Parameters\\FirewallPolicy\\FirewallRules\\*" Registry.registry_value_data = "* -|Action=Allow -|*" Registry.registry_value_data = "* -|Dir=In -|*" Registry.registry_value_data = "* -|LPort=*" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.process_guid Registry.registry_key_name Registry.registry_value_data -| `drop_dm_object_name(Registry)` -|rename process_guid as proc_guid -|join proc_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid -| `drop_dm_object_name(Processes)` -|rename process_guid as proc_guid -| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] -| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name -| `allow_inbound_traffic_by_firewall_rule_registry_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **allow_inbound_traffic_by_firewall_rule_registry_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.registry_path -* Registry.registry_value_name -* Registry.registry_key_name -* Registry.registry_value_data -* Registry.action -* Registry.dest -* Registry.user - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. - -#### Known False Positives -network admin may add/remove/modify public inbound firewall rule that may cause this rule to be triggered. - -#### Associated Analytic story -* [Prohibited Traffic Allowed or Protocol Mismatch](/stories/prohibited_traffic_allowed_or_protocol_mismatch) -* [Windows Registry Abuse](/stories/windows_registry_abuse) -* [Azorult](/stories/azorult) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | Suspicious firewall allow rule modifications were detected via the registry on endpoint $dest$ by user $user$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://docs.microsoft.com/en-us/powershell/module/netsecurity/new-netfirewallrule?view=windowsserver2019-ps](https://docs.microsoft.com/en-us/powershell/module/netsecurity/new-netfirewallrule?view=windowsserver2019-ps) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/casper/datasets1/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/casper/datasets1/windows-sysmon.log) -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/azorult/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/azorult/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2022-07-19-wmic_noninteractive_app_uninstallation.md b/docs/_posts/2022-07-19-wmic_noninteractive_app_uninstallation.md deleted file mode 100644 index 7b073bc0b0..0000000000 --- a/docs/_posts/2022-07-19-wmic_noninteractive_app_uninstallation.md +++ /dev/null @@ -1,169 +0,0 @@ ---- -title: "Wmic NonInteractive App Uninstallation" -excerpt: "Disable or Modify Tools -, Impair Defenses -" -categories: - - Endpoint -last_modified_at: 2022-07-19 -toc: true -toc_label: "" -tags: - - Disable or Modify Tools - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic indentifies WMIC command-line attempting to uninstall application non-interactively. This technique was seen in IceID to uninstall AV products on the compromised host to evade detection. This Hunting query maybe a good indicator that some process tries to uninstall application using wmic which is not a common behavior. This approach may seen in some script or third part appication to uninstall their application but it is a good thing to check what it uninstall and why. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-07-19 -- **Author**: Teoderick Contreras, Splunk -- **ID**: bff0e7a0-317f-11ec-ab4e-acde48001122 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- - - -
-
- -
- CIS20 - -
- - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=wmic.exe Processes.process="* product *" Processes.process="*where name*" Processes.process="*call uninstall*" Processes.process="*/nointeractive*" by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.original_file_name Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `wmic_noninteractive_app_uninstallation_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **wmic_noninteractive_app_uninstallation_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Third party application may use this approach to uninstall applications. - -#### Associated Analytic story -* [IceID](/stories/iceid) -* [Azorult](/stories/azorult) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | Wmic $process_name$ with command-line $process$ on $dest$ attempting to uninstall software. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/](https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/disable_av/sysmon2.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/disable_av/sysmon2.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-07-20-linux_persistence_and_privilege_escalation_risk_behavior.md b/docs/_posts/2022-07-20-linux_persistence_and_privilege_escalation_risk_behavior.md deleted file mode 100644 index 5101b49155..0000000000 --- a/docs/_posts/2022-07-20-linux_persistence_and_privilege_escalation_risk_behavior.md +++ /dev/null @@ -1,167 +0,0 @@ ---- -title: "Linux Persistence and Privilege Escalation Risk Behavior" -excerpt: "Abuse Elevation Control Mechanism -" -categories: - - Endpoint -last_modified_at: 2022-07-20 -toc: true -toc_label: "" -tags: - - Abuse Elevation Control Mechanism - - Defense Evasion - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Risk ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following correlation is specific to Linux persistence and privilege escalation tactics and is tied to two analytic stories and any Linux analytic tied to persistence and privilege escalation. These techniques often overlap with Persistence techniques, as OS features that let an adversary persist can execute in an elevated context. - -- **Type**: [Correlation](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Risk](https://docs.splunk.com/Documentation/CIM/latest/User/Risk) -- **Last Updated**: 2022-07-20 -- **Author**: Michael Haag, Splunk -- **ID**: ad5ac21b-3b1e-492c-8e19-ea5d5e8e5cf1 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1548](https://attack.mitre.org/techniques/T1548/) | Abuse Elevation Control Mechanism | Defense Evasion, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Risk.All_Risk where (All_Risk.analyticstories IN ("Linux Privilege Escalation", "Linux Persistence Techniques") OR source = "*Linux*") All_Risk.annotations.mitre_attack.mitre_tactic IN ("persistence", "privilege-escalation") All_Risk.risk_object_type="system" by All_Risk.risk_object All_Risk.annotations.mitre_attack.mitre_tactic source All_Risk.description -| `drop_dm_object_name(All_Risk)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| stats values(source) as detection_name values(annotations.mitre_attack.mitre_tactic) as tactics values(firstTime) as firstTime values(lastTime) as lastTime dc(annotations.mitre_attack.mitre_tactic) as distinct_tactics dc(source) as distinct_detection_name by risk_object -| where distinct_detection_name >= 4 -| `linux_persistence_and_privilege_escalation_risk_behavior_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **linux_persistence_and_privilege_escalation_risk_behavior_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* All_Risk.analyticstories -* All_Risk.risk_object_type -* All_Risk.risk_object -* All_Risk.annotations.mitre_attack.mitre_tactic -* source - - -#### How To Implement -Ensure Linux anomaly and TTP analytics are enabled. TTP may be set to Notables for point detections, anomaly should not be notables but risk generators. The correlation relies on more than x amount of distict detection names generated before generating a notable. Modify the value as needed. Default value is set to 4. This value may need to be increased based on activity in your environment. - -#### Known False Positives -False positives will be present based on many factors. Tune the correlation as needed to reduce too many triggers. - -#### Associated Analytic story -* [Linux Privilege Escalation](/stories/linux_privilege_escalation) -* [Linux Persistence Techniques](/stories/linux_persistence_techniques) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 56.0 | 70 | 80 | Privilege escalation and persistence behaviors have been identified on $risk_object$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/tactics/TA0004/](https://attack.mitre.org/tactics/TA0004/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/linux_risk/linuxrisk.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/linux_risk/linuxrisk.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_persistence_and_privilege_escalation_risk_behavior.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-07-20-registry_keys_used_for_persistence.md b/docs/_posts/2022-07-20-registry_keys_used_for_persistence.md deleted file mode 100644 index a4ef1e513f..0000000000 --- a/docs/_posts/2022-07-20-registry_keys_used_for_persistence.md +++ /dev/null @@ -1,177 +0,0 @@ ---- -title: "Registry Keys Used For Persistence" -excerpt: "Registry Run Keys / Startup Folder -, Boot or Logon Autostart Execution -" -categories: - - Endpoint -last_modified_at: 2022-07-20 -toc: true -toc_label: "" -tags: - - Registry Run Keys / Startup Folder - - Boot or Logon Autostart Execution - - Persistence - - Privilege Escalation - - Persistence - - Privilege Escalation - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The search looks for modifications to registry keys that can be used to launch an application or service at system startup. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)- **Datasource**: [Splunk Add-on for Sysmon](https://splunkbase.splunk.com/app/5709) -- **Last Updated**: 2022-07-20 -- **Author**: Jose Hernandez, David Dorsey, Teoderick Contreras, Rod Soto, Splunk -- **ID**: f5f6af30-7aa7-4295-bfe9-07fe87c01a4b - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1547.001](https://attack.mitre.org/techniques/T1547/001/) | Registry Run Keys / Startup Folder | Persistence, Privilege Escalation | - -| [T1547](https://attack.mitre.org/techniques/T1547/) | Boot or Logon Autostart Execution | Persistence, Privilege Escalation | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* PR.PT -* DE.CM -* DE.AE - - - -
-
- -
- CIS20 - -
- -* CIS 8 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where (Registry.registry_path=*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnce OR Registry.registry_path=*\\currentversion\\run* OR Registry.registry_path=*\\currentVersion\\Windows\\Appinit_Dlls* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Shell* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Notify* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Userinit* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\VmApplet* OR Registry.registry_path=*\\currentversion\\policies\\explorer\\run* OR Registry.registry_path=*\\currentversion\\runservices* OR Registry.registry_path=HKLM\\SOFTWARE\\Microsoft\\Netsh\\* OR (Registry.registry_path="*Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options*" AND Registry.registry_key_name=Debugger) OR (Registry.registry_path="*\\CurrentControlSet\\Control\\Lsa" AND Registry.registry_key_name="Security Packages") OR (Registry.registry_path="*\\CurrentControlSet\\Control\\Lsa\\OSConfig" AND Registry.registry_key_name="Security Packages") OR (Registry.registry_path="*\\Microsoft\\Windows NT\\CurrentVersion\\SilentProcessExit\\*") OR (Registry.registry_path="*currentVersion\\Windows" AND Registry.registry_key_name="Load") OR (Registry.registry_path="*\\CurrentVersion" AND Registry.registry_key_name="Svchost") OR (Registry.registry_path="*\\CurrentControlSet\Control\Session Manager"AND Registry.registry_key_name="BootExecute") OR (Registry.registry_path="*\\Software\\Run" AND Registry.registry_key_name="auto_update")) by Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid Registry.registry_key_name -| `drop_dm_object_name(Registry)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `registry_keys_used_for_persistence_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **registry_keys_used_for_persistence_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Registry.registry_key_name -* Registry.registry_path -* Registry.dest -* Registry.user - - -#### How To Implement -To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. - -#### Known False Positives -There are many legitimate applications that must execute on system startup and will use these registry keys to accomplish that task. - -#### Associated Analytic story -* [Suspicious Windows Registry Activities](/stories/suspicious_windows_registry_activities) -* [Suspicious MSHTA Activity](/stories/suspicious_mshta_activity) -* [DHS Report TA18-074A](/stories/dhs_report_ta18-074a) -* [Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns](/stories/possible_backdoor_activity_associated_with_mudcarp_espionage_campaigns) -* [Ransomware](/stories/ransomware) -* [Windows Persistence Techniques](/stories/windows_persistence_techniques) -* [Emotet Malware DHS Report TA18-201A ](/stories/emotet_malware__dhs_report_ta18-201a_) -* [IcedID](/stories/icedid) -* [Remcos](/stories/remcos) -* [Windows Registry Abuse](/stories/windows_registry_abuse) -* [Azorult](/stories/azorult) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 76.0 | 80 | 95 | A registry activity in $registry_path$ related to persistence in host $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.001/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.001/atomic_red_team/windows-sysmon.log) -* [https://media.githubusercontent.com/splunk/attack_data/master/datasets/attack_techniques/T1547.001/atomic_red_team/t1547001-runonce.log](https://media.githubusercontent.com/splunk/attack_data/master/datasets/attack_techniques/T1547.001/atomic_red_team/t1547001-runonce.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/registry_keys_used_for_persistence.yml) \| *version*: **8** \ No newline at end of file diff --git a/docs/_posts/2022-07-25-aws_defense_evasion_putbucketlifecycle.md b/docs/_posts/2022-07-25-aws_defense_evasion_putbucketlifecycle.md deleted file mode 100644 index 36bed54338..0000000000 --- a/docs/_posts/2022-07-25-aws_defense_evasion_putbucketlifecycle.md +++ /dev/null @@ -1,173 +0,0 @@ ---- -title: "AWS Defense Evasion PutBucketLifecycle" -excerpt: "Disable Cloud Logs -, Impair Defenses -" -categories: - - Cloud -last_modified_at: 2022-07-25 -toc: true -toc_label: "" -tags: - - Disable Cloud Logs - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic identifies `PutBucketLifecycle` events in CloudTrail logs where a user has created a new lifecycle rule for an S3 bucket with a short expiration period. Attackers may use this API call to impair the CloudTrail logging by removing logs from the S3 bucket by changing the object expiration day to 1 day, in which case the CloudTrail logs will be deleted. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-07-25 -- **Author**: Bhavin Patel -- **ID**: ce1c0e2b-9303-4903-818b-0d9002fc6ea4 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.008](https://attack.mitre.org/techniques/T1562/008/) | Disable Cloud Logs | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cloudtrail` eventName=PutBucketLifecycle user_type=IAMUser errorCode=success -| spath path=requestParameters{}.LifecycleConfiguration{}.Rule{}.Expiration{}.Days output=expiration_days -| spath path=requestParameters{}.bucketName output=bucket_name -| stats count min(_time) as firstTime max(_time) as lastTime by src region eventName userAgent user_arn aws_account_id expiration_days bucket_name user_type -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| where expiration_days < 3 -| `aws_defense_evasion_putbucketlifecycle_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) - -> :information_source: -> **aws_defense_evasion_putbucketlifecycle_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* eventName -* eventSource -* requestParameters.name -* userAgent -* aws_account_id -* src -* region -* requestParameters{}.LifecycleConfiguration{}.Rule{}.Expiration{}.Days -* requestParameters{}.bucketName - - -#### How To Implement -You must install Splunk AWS Add on and enable CloudTrail logs in your AWS Environment. We recommend our users to set the expiration days value according to your company's log retention policies. - -#### Known False Positives -While this search has no known false positives, it is possible that it is a legitimate admin activity. Please consider filtering out these noisy events using userAgent, user_arn field names. - -#### Associated Analytic story -* [AWS Defense Evasion](/stories/aws_defense_evasion) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 20.0 | 50 | 40 | User $user_arn$ has created a new rule to on an S3 bucket $bucket_name$ with short expiration days | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://stratus-red-team.cloud/attack-techniques/AWS/aws.defense-evasion.cloudtrail-lifecycle-rule/](https://stratus-red-team.cloud/attack-techniques/AWS/aws.defense-evasion.cloudtrail-lifecycle-rule/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/put_bucketlifecycle/aws_cloudtrail_events.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/put_bucketlifecycle/aws_cloudtrail_events.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/aws_defense_evasion_putbucketlifecycle.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-07-26-aws_defense_evasion_impair_security_services.md b/docs/_posts/2022-07-26-aws_defense_evasion_impair_security_services.md deleted file mode 100644 index 13994fe00b..0000000000 --- a/docs/_posts/2022-07-26-aws_defense_evasion_impair_security_services.md +++ /dev/null @@ -1,171 +0,0 @@ ---- -title: "AWS Defense Evasion Impair Security Services" -excerpt: "Disable Cloud Logs -, Impair Defenses -" -categories: - - Cloud -last_modified_at: 2022-07-26 -toc: true -toc_label: "" -tags: - - Disable Cloud Logs - - Impair Defenses - - Defense Evasion - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic looks for several delete specific API calls made to AWS Security Services like CloudWatch, GuardDuty and Web Application Firewalls. These API calls are often leveraged by adversaries to weaken existing security defenses by deleting logging configurations in the CloudWatch alarm, delete a set of detectors from your Guardduty environment or simply delete a bunch of CloudWatch alarms to remain stealthy and avoid detection. - -- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - -- **Last Updated**: 2022-07-26 -- **Author**: Bhavin Patel, Gowthamaraj Rajendran, Splunk -- **ID**: b28c4957-96a6-47e0-a965-6c767aac1458 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1562.008](https://attack.mitre.org/techniques/T1562/008/) | Disable Cloud Logs | Defense Evasion | - -| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Actions on Objectives - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` -`cloudtrail` eventName IN ("DeleteLogStream","DeleteDetector","DeleteIPSet","DeleteWebACL","DeleteRule","DeleteRuleGroup","DeleteLoggingConfiguration","DeleteAlarms") -| stats count min(_time) as firstTime max(_time) as lastTime values(eventName) as eventName values(eventSource) as eventSource values(requestParameters.*) as * by src region user_arn aws_account_id user_type user_agent errorCode -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `aws_defense_evasion_impair_security_services_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) - -> :information_source: -> **aws_defense_evasion_impair_security_services_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* eventName -* eventSource -* user_agent -* user_type -* aws_account_id -* src -* region -* errorCode - - -#### How To Implement -You must install Splunk AWS Add on and enable CloudTrail logs in your AWS Environment. - -#### Known False Positives -While this search has no known false positives, it is possible that it is a legitimate admin activity. Please consider filtering out these noisy events using userAgent, user_arn field names. - -#### Associated Analytic story -* [AWS Defense Evasion](/stories/aws_defense_evasion) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 42.0 | 70 | 60 | User $user_arn$ has made potentially risky api calls $eventName$ that could impair AWS security services for account id $aws_account_id$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://docs.aws.amazon.com/cli/latest/reference/guardduty/index.html](https://docs.aws.amazon.com/cli/latest/reference/guardduty/index.html) -* [https://docs.aws.amazon.com/cli/latest/reference/waf/index.html](https://docs.aws.amazon.com/cli/latest/reference/waf/index.html) -* [https://www.elastic.co/guide/en/security/current/prebuilt-rules.html](https://www.elastic.co/guide/en/security/current/prebuilt-rules.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/aws_delete_security_services/aws_cloudtrail_events.json](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/aws_delete_security_services/aws_cloudtrail_events.json) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/cloud/aws_defense_evasion_impair_security_services.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-07-27-linux_decode_base64_to_shell.md b/docs/_posts/2022-07-27-linux_decode_base64_to_shell.md deleted file mode 100644 index 9712cd7e6a..0000000000 --- a/docs/_posts/2022-07-27-linux_decode_base64_to_shell.md +++ /dev/null @@ -1,179 +0,0 @@ ---- -title: "Linux Decode Base64 to Shell" -excerpt: "Obfuscated Files or Information -, Unix Shell -" -categories: - - Endpoint -last_modified_at: 2022-07-27 -toc: true -toc_label: "" -tags: - - Obfuscated Files or Information - - Unix Shell - - Defense Evasion - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies base64 being decoded and passed to a Linux shell. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-07-27 -- **Author**: Michael Haag, Splunk -- **ID**: 637b603e-1799-40fd-bf87-47ecbd551b66 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1027](https://attack.mitre.org/techniques/T1027/) | Obfuscated Files or Information | Defense Evasion | - -| [T1059.004](https://attack.mitre.org/techniques/T1059/004/) | Unix Shell | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Delivery -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process IN ("*base64 -d*","*base64 --decode*") AND Processes.process="* -|*" `linux_shells` by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `linux_decode_base64_to_shell_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) -* [linux_shells](https://github.com/splunk/security_content/blob/develop/macros/linux_shells.yml) - -> :information_source: -> **linux_decode_base64_to_shell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -False positives may be present based on legitimate software being utilized. Filter as needed. - -#### Associated Analytic story -* [Linux Living Off The Land](/stories/linux_living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.0 | 50 | 50 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ decoding base64 and passing it to a shell. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1027/T1027.md#atomic-test-1---decode-base64-data-into-script](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1027/T1027.md#atomic-test-1---decode-base64-data-into-script) -* [https://redcanary.com/blog/lateral-movement-with-secure-shell/](https://redcanary.com/blog/lateral-movement-with-secure-shell/) -* [https://linux.die.net/man/1/base64](https://linux.die.net/man/1/base64) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1027/atomic_red_team/linux-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1027/atomic_red_team/linux-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_decode_base64_to_shell.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-07-27-linux_kernel_module_enumeration.md b/docs/_posts/2022-07-27-linux_kernel_module_enumeration.md deleted file mode 100644 index a586f443b2..0000000000 --- a/docs/_posts/2022-07-27-linux_kernel_module_enumeration.md +++ /dev/null @@ -1,174 +0,0 @@ ---- -title: "Linux Kernel Module Enumeration" -excerpt: "System Information Discovery -, Rootkit -" -categories: - - Endpoint -last_modified_at: 2022-07-27 -toc: true -toc_label: "" -tags: - - System Information Discovery - - Rootkit - - Discovery - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the process kmod being utilized to list kernel modules in use. Typically, this is not seen as malicious, however it may be a precurser to the use of insmod to install a module. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-07-27 -- **Author**: Michael Haag, Splunk -- **ID**: 6df99886-0e04-4c11-8b88-325747419278 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1082](https://attack.mitre.org/techniques/T1082/) | System Information Discovery | Discovery | - -| [T1014](https://attack.mitre.org/techniques/T1014/) | Rootkit | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=kmod Processes.process IN ("*lsmod*", "*list*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `linux_kernel_module_enumeration_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **linux_kernel_module_enumeration_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -False positives are present based on automated tooling or system administrative usage. Filter as needed. - -#### Associated Analytic story -* [Linux Rootkit](/stories/linux_rootkit) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ enumeration kernel modules. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://man7.org/linux/man-pages/man8/kmod.8.html](https://man7.org/linux/man-pages/man8/kmod.8.html) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1082/atomic_red_team/linux-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1082/atomic_red_team/linux-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_kernel_module_enumeration.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-07-27-linux_obfuscated_files_or_information_base64_decode.md b/docs/_posts/2022-07-27-linux_obfuscated_files_or_information_base64_decode.md deleted file mode 100644 index 15921f9b1d..0000000000 --- a/docs/_posts/2022-07-27-linux_obfuscated_files_or_information_base64_decode.md +++ /dev/null @@ -1,172 +0,0 @@ ---- -title: "Linux Obfuscated Files or Information Base64 Decode" -excerpt: "Obfuscated Files or Information -" -categories: - - Endpoint -last_modified_at: 2022-07-27 -toc: true -toc_label: "" -tags: - - Obfuscated Files or Information - - Defense Evasion - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the use of base64 decode on Linux being utilized to deobfuscate a file. Identify the source of the file and determine if legitimate. Review parallel processes for further behavior before and after. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-07-27 -- **Author**: Michael Haag, Splunk -- **ID**: 303b38b2-c03f-44e2-8f41-4594606fcfc7 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1027](https://attack.mitre.org/techniques/T1027/) | Obfuscated Files or Information | Defense Evasion | - -
-
- - -
- Kill Chain Phase - -
- -* Delivery -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process IN ("*base64 -d*","*base64 --decode*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `linux_obfuscated_files_or_information_base64_decode_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **linux_obfuscated_files_or_information_base64_decode_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -False positives may be present and will require some tuning based on processes. Filter as needed. - -#### Associated Analytic story -* [Linux Living Off The Land](/stories/linux_living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ decoding base64. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1027/T1027.md#atomic-test-1---decode-base64-data-into-script](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1027/T1027.md#atomic-test-1---decode-base64-data-into-script) -* [https://redcanary.com/blog/lateral-movement-with-secure-shell/](https://redcanary.com/blog/lateral-movement-with-secure-shell/) -* [https://linux.die.net/man/1/base64](https://linux.die.net/man/1/base64) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1027/atomic_red_team/linux-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1027/atomic_red_team/linux-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_obfuscated_files_or_information_base64_decode.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-07-27-linux_ssh_authorized_keys_modification.md b/docs/_posts/2022-07-27-linux_ssh_authorized_keys_modification.md deleted file mode 100644 index f835615d3f..0000000000 --- a/docs/_posts/2022-07-27-linux_ssh_authorized_keys_modification.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: "Linux SSH Authorized Keys Modification" -excerpt: "SSH Authorized Keys -" -categories: - - Endpoint -last_modified_at: 2022-07-27 -toc: true -toc_label: "" -tags: - - SSH Authorized Keys - - Persistence - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies based on process execution the modification of SSH Authorized Keys. Adversaries perform this behavior to persist on endpoints. During triage, review parallel processes and capture any additional file modifications for review. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-07-27 -- **Author**: Michael Haag, Splunk -- **ID**: f5ab595e-28e5-4327-8077-5008ba97c850 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1098.004](https://attack.mitre.org/techniques/T1098/004/) | SSH Authorized Keys | Persistence | - -
-
- - -
- Kill Chain Phase - -
- -* Installation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name IN ("bash","cat") Processes.process IN ("*/authorized_keys*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `linux_ssh_authorized_keys_modification_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **linux_ssh_authorized_keys_modification_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -Filtering will be required as system administrators will add and remove. One way to filter query is to add "echo". - -#### Associated Analytic story -* [Linux Living Off The Land](/stories/linux_living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 15.0 | 30 | 50 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ modifying SSH Authorized Keys. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://redcanary.com/blog/lateral-movement-with-secure-shell/](https://redcanary.com/blog/lateral-movement-with-secure-shell/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1098.004/T1098.004.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1098.004/T1098.004.md) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098.004/ssh_authorized_keys/authkey_linux-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098.004/ssh_authorized_keys/authkey_linux-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_ssh_authorized_keys_modification.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-07-27-linux_ssh_remote_services_script_execute.md b/docs/_posts/2022-07-27-linux_ssh_remote_services_script_execute.md deleted file mode 100644 index e280892974..0000000000 --- a/docs/_posts/2022-07-27-linux_ssh_remote_services_script_execute.md +++ /dev/null @@ -1,169 +0,0 @@ ---- -title: "Linux SSH Remote Services Script Execute" -excerpt: "SSH -" -categories: - - Endpoint -last_modified_at: 2022-07-27 -toc: true -toc_label: "" -tags: - - SSH - - Lateral Movement - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies SSH being utilized to move laterally and execute a script or file on the remote host. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-07-27 -- **Author**: Michael Haag, Splunk -- **ID**: aa1748dd-4a5c-457a-9cf6-ca7b4eb711b3 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1021.004](https://attack.mitre.org/techniques/T1021/004/) | SSH | Lateral Movement | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=ssh Processes.process IN ("*oStrictHostKeyChecking*", "*oConnectTimeout*", "*oBatchMode*") AND CommandLine IN ("*http:*","*https:*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `linux_ssh_remote_services_script_execute_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **linux_ssh_remote_services_script_execute_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -This is not a common command to be executed. Filter as needed. - -#### Associated Analytic story -* [Linux Living Off The Land](/stories/linux_living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 56.0 | 80 | 70 | An instance of $process_name$ was identified on endpoint $dest$ by user $user$ attempting to move laterally and download a file. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://redcanary.com/blog/lateral-movement-with-secure-shell/](https://redcanary.com/blog/lateral-movement-with-secure-shell/) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021.004/atomic_red_team/linux-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021.004/atomic_red_team/linux-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_ssh_remote_services_script_execute.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-07-27-windows_system_logoff_commandline.md b/docs/_posts/2022-07-27-windows_system_logoff_commandline.md deleted file mode 100644 index a90d25c8a3..0000000000 --- a/docs/_posts/2022-07-27-windows_system_logoff_commandline.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: "Windows System LogOff Commandline" -excerpt: "System Shutdown/Reboot -" -categories: - - Endpoint -last_modified_at: 2022-07-27 -toc: true -toc_label: "" -tags: - - System Shutdown/Reboot - - Impact - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies Windows commandlined to logoff a windows host machine. This technique was seen in several APT, RAT like dcrat and other commodity malware to shutdown the machine to add more impact, interrupt access, aid destruction of the system like wiping disk or inhibit system recovery. This TTP is a good pivot to check why application trigger this commandline which is not so common way to logoff a machine. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-07-27 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 74a8133f-93e7-4b71-9bd3-13a66124fd57 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1529](https://attack.mitre.org/techniques/T1529/) | System Shutdown/Reboot | Impact | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name = shutdown.exe OR Processes.original_file_name = shutdown.exe) Processes.process="*shutdown*" Processes.process="* /l*" Processes.process="* /t*" by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_system_logoff_commandline_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_system_logoff_commandline_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -Administrator may execute this commandline to trigger shutdown, logoff or restart the host machine. - -#### Associated Analytic story -* [DarkCrystal RAT](/stories/darkcrystal_rat) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 56.0 | 70 | 80 | Process name $process_name$ is seen to execute logoff commandline on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1529/](https://attack.mitre.org/techniques/T1529/) -* [https://www.mandiant.com/resources/analyzing-dark-crystal-rat-backdoor](https://www.mandiant.com/resources/analyzing-dark-crystal-rat-backdoor) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/reboot_logoff_commandline/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/reboot_logoff_commandline/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_system_logoff_commandline.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-07-27-windows_system_reboot_commandline.md b/docs/_posts/2022-07-27-windows_system_reboot_commandline.md deleted file mode 100644 index 69032bd65f..0000000000 --- a/docs/_posts/2022-07-27-windows_system_reboot_commandline.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: "Windows System Reboot CommandLine" -excerpt: "System Shutdown/Reboot -" -categories: - - Endpoint -last_modified_at: 2022-07-27 -toc: true -toc_label: "" -tags: - - System Shutdown/Reboot - - Impact - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies Windows commandlined to reboot a windows host machine. This technique was seen in several APT, RAT like dcrat and other commodity malware to shutdown the machine to add more impact, interrupt access, aid destruction of the system like wiping disk or inhibit system recovery. This TTP is a good pivot to check why application trigger this commandline which is not so common way to reboot a machine. Compare to shutdown and logoff shutdown.exe feature, reboot seen in some automation script like ansible to reboot the machine. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-07-27 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 97fc2b60-c8eb-4711-93f7-d26fade3686f - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1529](https://attack.mitre.org/techniques/T1529/) | System Shutdown/Reboot | Impact | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name = shutdown.exe OR Processes.original_file_name = shutdown.exe) Processes.process="*shutdown*" Processes.process="* /r*" Processes.process="* /t*" by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_system_reboot_commandline_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_system_reboot_commandline_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -Administrator may execute this commandline to trigger shutdown or restart the host machine. - -#### Associated Analytic story -* [DarkCrystal RAT](/stories/darkcrystal_rat) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 30.0 | 60 | 50 | Process $process_name$ that executed reboot via commandline on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1529/](https://attack.mitre.org/techniques/T1529/) -* [https://www.mandiant.com/resources/analyzing-dark-crystal-rat-backdoor](https://www.mandiant.com/resources/analyzing-dark-crystal-rat-backdoor) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/reboot_logoff_commandline/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/reboot_logoff_commandline/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_system_reboot_commandline.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-07-27-windows_system_shutdown_commandline.md b/docs/_posts/2022-07-27-windows_system_shutdown_commandline.md deleted file mode 100644 index 11e2aabc48..0000000000 --- a/docs/_posts/2022-07-27-windows_system_shutdown_commandline.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: "Windows System Shutdown CommandLine" -excerpt: "System Shutdown/Reboot -" -categories: - - Endpoint -last_modified_at: 2022-07-27 -toc: true -toc_label: "" -tags: - - System Shutdown/Reboot - - Impact - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies Windows commandlined to shutdown a windows host machine. This technique was seen in several APT, RAT like dcrat and other commodity malware to shutdown the machine to add more impact, interrupt access, aid destruction of the system like wiping disk or inhibit system recovery. This TTP is a good pivot to check why application trigger this commandline which is not so common way to shutdown a machine. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-07-27 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 4fee57b8-d825-4bf3-9ea8-bf405cdb614c - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1529](https://attack.mitre.org/techniques/T1529/) | System Shutdown/Reboot | Impact | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name = shutdown.exe OR Processes.original_file_name = shutdown.exe) Processes.process="*shutdown*" Processes.process="* /s*" Processes.process="* /t*" by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_system_shutdown_commandline_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_system_shutdown_commandline_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -#### Known False Positives -Administrator may execute this commandline to trigger shutdown or restart the host machine. - -#### Associated Analytic story -* [DarkCrystal RAT](/stories/darkcrystal_rat) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 49.0 | 70 | 70 | Process $process_name$ seen to execute shutdown via commandline on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1529/](https://attack.mitre.org/techniques/T1529/) -* [https://www.mandiant.com/resources/analyzing-dark-crystal-rat-backdoor](https://www.mandiant.com/resources/analyzing-dark-crystal-rat-backdoor) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/dcrat/shutdown_commandline/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/dcrat/shutdown_commandline/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_system_shutdown_commandline.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-07-28-linux_clipboard_data_copy.md b/docs/_posts/2022-07-28-linux_clipboard_data_copy.md deleted file mode 100644 index ec5bde1098..0000000000 --- a/docs/_posts/2022-07-28-linux_clipboard_data_copy.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: "Linux Clipboard Data Copy" -excerpt: "Clipboard Data -" -categories: - - Endpoint -last_modified_at: 2022-07-28 -toc: true -toc_label: "" -tags: - - Clipboard Data - - Collection - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies the use of Linux Xclip copying data out of the clipboard. Adversaries have utilized this technique to capture passwords, IP addresses, or store payloads. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-07-28 -- **Author**: Michael Haag, Splunk -- **ID**: 7173b2ad-6146-418f-85ae-c3479e4515fc - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1115](https://attack.mitre.org/techniques/T1115/) | Clipboard Data | Collection | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=xclip Processes.process IN ("*-o *", "*-sel *", "*-selection *", "*clip *","*clipboard*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `linux_clipboard_data_copy_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **linux_clipboard_data_copy_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -#### Known False Positives -False positives may be present on Linux desktop as it may commonly be used by administrators or end users. Filter as needed. - -#### Associated Analytic story -* [Linux Living Off The Land](/stories/linux_living_off_the_land) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 16.0 | 40 | 40 | An instance of $process_name$ was identified on endpoint $dest$ by user $user$ adding or removing content from the clipboard. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://attack.mitre.org/techniques/T1115/](https://attack.mitre.org/techniques/T1115/) -* [https://linux.die.net/man/1/xclip](https://linux.die.net/man/1/xclip) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1115/atomic_red_team/linux-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1115/atomic_red_team/linux-sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_clipboard_data_copy.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-07-28-windows_command_shell_dcrat_forkbomb_payload.md b/docs/_posts/2022-07-28-windows_command_shell_dcrat_forkbomb_payload.md deleted file mode 100644 index e9061fd00e..0000000000 --- a/docs/_posts/2022-07-28-windows_command_shell_dcrat_forkbomb_payload.md +++ /dev/null @@ -1,177 +0,0 @@ ---- -title: "Windows Command Shell DCRat ForkBomb Payload" -excerpt: "Windows Command Shell -, Command and Scripting Interpreter -" -categories: - - Endpoint -last_modified_at: 2022-07-28 -toc: true -toc_label: "" -tags: - - Windows Command Shell - - Command and Scripting Interpreter - - Execution - - Execution - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies DCRat "forkbomb" payload feature. This technique was seen in dark crystal RAT backdoor capabilities where it will execute several cmd child process executing "notepad.exe & pause". This analytic detects the multiple cmd.exe and child process notepad.exe execution using batch script in the targeted host within 30s timeframe. this TTP can be a good pivot to check DCRat infection. - -- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-07-28 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 2bb1a362-7aa8-444a-92ed-1987e8da83e1 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1059.003](https://attack.mitre.org/techniques/T1059/003/) | Windows Command Shell | Execution | - -| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - -
-
- - -
- Kill Chain Phase - -
- -* Exploitation - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` values(Processes.process) as process values(Processes.parent_process) as parent_process values(Processes.parent_process_id) as parent_process_id values(Processes.process_id) as process_id dc(Processes.parent_process_id) as parent_process_id_count dc(Processes.process_id) as process_id_count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name= "cmd.exe" (Processes.process_name = "notepad.exe" OR Processes.original_file_name= "notepad.exe") Processes.parent_process = "*.bat*" by Processes.parent_process_name Processes.process_name Processes.original_file_name Processes.parent_process Processes.dest Processes.user _time span=30s -| where parent_process_id_count>= 10 AND process_id_count >=10 -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_command_shell_dcrat_forkbomb_payload_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_command_shell_dcrat_forkbomb_payload_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances of wermgr.exe may be used. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [DarkCrystal RAT](/stories/darkcrystal_rat) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 81.0 | 90 | 90 | Multiple cmd.exe processes with child process of notepad.exe executed on $dest$ | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://cert.gov.ua/article/405538](https://cert.gov.ua/article/405538) -* [https://malpedia.caad.fkie.fraunhofer.de/details/win.dcrat](https://malpedia.caad.fkie.fraunhofer.de/details/win.dcrat) -* [https://www.mandiant.com/resources/analyzing-dark-crystal-rat-backdoor](https://www.mandiant.com/resources/analyzing-dark-crystal-rat-backdoor) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/dcrat/dcrat_forkbomb/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/dcrat/dcrat_forkbomb/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_command_shell_dcrat_forkbomb_payload.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-07-28-windows_system_time_discovery_w32tm_delay.md b/docs/_posts/2022-07-28-windows_system_time_discovery_w32tm_delay.md deleted file mode 100644 index ead5cd04d9..0000000000 --- a/docs/_posts/2022-07-28-windows_system_time_discovery_w32tm_delay.md +++ /dev/null @@ -1,171 +0,0 @@ ---- -title: "Windows System Time Discovery W32tm Delay" -excerpt: "System Time Discovery -" -categories: - - Endpoint -last_modified_at: 2022-07-28 -toc: true -toc_label: "" -tags: - - System Time Discovery - - Discovery - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic identifies DCRat delay time tactics using w32tm. This technique was seen in DCRAT malware where it uses stripchart function of w32tm.exe application to delay the execution of its payload like c2 communication , beaconing and execution. This anomaly detection may help the analyst to check other possible event like the process who execute this command that may lead to DCRat attack. - -- **Type**: [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-07-28 -- **Author**: Teoderick Contreras, Splunk -- **ID**: b2cc69e7-11ba-42dc-a269-59c069a48870 - - -#### Annotations - -
- ATT&CK - -
- - -| ID | Technique | Tactic | -| -------------- | ---------------- |-------------------- | -| [T1124](https://attack.mitre.org/techniques/T1124/) | System Time Discovery | Discovery | - -
-
- - -
- Kill Chain Phase - -
- -* Reconnaissance - - -
-
- - -
- NIST - -
- -* DE.CM - - - -
-
- -
- CIS20 - -
- -* CIS 3 -* CIS 5 -* CIS 16 - - - -
-
- -
- CVE - -
- - -
-
- -#### Search - -``` - -| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = w32tm.exe Processes.process= "* /stripchart *" Processes.process= "* /computer:localhost *" Processes.process= "* /period:*" Processes.process= "* /dataonly *" Processes.process= "* /samples:*" by Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_system_time_discovery_w32tm_delay_filter` -``` - -#### Macros -The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) - -> :information_source: -> **windows_system_time_discovery_w32tm_delay_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. - -#### Required field -* _time -* Processes.dest -* Processes.user -* Processes.parent_process_name -* Processes.parent_process -* Processes.original_file_name -* Processes.process_name -* Processes.process -* Processes.process_id -* Processes.parent_process_path -* Processes.process_path -* Processes.parent_process_id - - -#### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances of wermgr.exe may be used. - -#### Known False Positives -unknown - -#### Associated Analytic story -* [DarkCrystal RAT](/stories/darkcrystal_rat) - - - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 36.0 | 60 | 60 | Process name w32tm.exe is using suspcicious command line arguments $process$ on host $dest$. | - - -> :information_source: -> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author. - -#### Reference - -* [https://cert.gov.ua/article/405538](https://cert.gov.ua/article/405538) -* [https://malpedia.caad.fkie.fraunhofer.de/details/win.dcrat](https://malpedia.caad.fkie.fraunhofer.de/details/win.dcrat) -* [https://www.mandiant.com/resources/analyzing-dark-crystal-rat-backdoor](https://www.mandiant.com/resources/analyzing-dark-crystal-rat-backdoor) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/dcrat/dcrat_delay_execution/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/dcrat/dcrat_delay_execution/sysmon.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_system_time_discovery_w32tm_delay.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_sass/minimal-mistakes.scss b/docs/_sass/minimal-mistakes.scss deleted file mode 100644 index 3b252e5620..0000000000 --- a/docs/_sass/minimal-mistakes.scss +++ /dev/null @@ -1,40 +0,0 @@ -/*! - * Minimal Mistakes Jekyll Theme 4.24.0 by Michael Rose - * Copyright 2013-2020 Michael Rose - mademistakes.com | @mmistakes - * Licensed under MIT (https://github.com/mmistakes/minimal-mistakes/blob/master/LICENSE) -*/ - -/* Variables */ -@import "minimal-mistakes/variables"; - -/* Mixins and functions */ -@import "minimal-mistakes/vendor/breakpoint/breakpoint"; -@include breakpoint-set("to ems", true); -@import "minimal-mistakes/vendor/magnific-popup/magnific-popup"; // Magnific Popup -@import "minimal-mistakes/vendor/susy/susy"; -@import "minimal-mistakes/mixins"; - -/* Core CSS */ -@import "minimal-mistakes/reset"; -@import "minimal-mistakes/base"; -@import "minimal-mistakes/forms"; -@import "minimal-mistakes/tables"; -@import "minimal-mistakes/animations"; - -/* Components */ -@import "minimal-mistakes/buttons"; -@import "minimal-mistakes/notices"; -@import "minimal-mistakes/masthead"; -@import "minimal-mistakes/navigation"; -@import "minimal-mistakes/footer"; -@import "minimal-mistakes/search"; -@import "minimal-mistakes/syntax"; - -/* Utility classes */ -@import "minimal-mistakes/utilities"; - -/* Layout specific */ -@import "minimal-mistakes/page"; -@import "minimal-mistakes/archive"; -@import "minimal-mistakes/sidebar"; -@import "minimal-mistakes/print"; diff --git a/docs/_sass/minimal-mistakes/_animations.scss b/docs/_sass/minimal-mistakes/_animations.scss deleted file mode 100644 index 25ef77fbbf..0000000000 --- a/docs/_sass/minimal-mistakes/_animations.scss +++ /dev/null @@ -1,21 +0,0 @@ -/* ========================================================================== - ANIMATIONS - ========================================================================== */ - -@-webkit-keyframes intro { - 0% { - opacity: 0; - } - 100% { - opacity: 1; - } -} - -@keyframes intro { - 0% { - opacity: 0; - } - 100% { - opacity: 1; - } -} \ No newline at end of file diff --git a/docs/_sass/minimal-mistakes/_archive.scss b/docs/_sass/minimal-mistakes/_archive.scss deleted file mode 100644 index 9f576323e7..0000000000 --- a/docs/_sass/minimal-mistakes/_archive.scss +++ /dev/null @@ -1,463 +0,0 @@ -/* ========================================================================== - ARCHIVE - ========================================================================== */ - -.archive { - margin-top: 1em; - margin-bottom: 2em; - - @include breakpoint($large) { - float: right; - width: calc(100% - #{$right-sidebar-width-narrow}); - padding-right: $right-sidebar-width-narrow; - } - - @include breakpoint($x-large) { - width: calc(100% - #{$right-sidebar-width}); - padding-right: $right-sidebar-width; - } -} - -.archive__item { - position: relative; - - a { - position: relative; - z-index: 10; - } - - a[rel="permalink"] { - position: static; - } -} - -.archive__subtitle { - margin: 1.414em 0 0.5em; - padding-bottom: 0.5em; - font-size: $type-size-5; - color: $muted-text-color; - border-bottom: 1px solid $border-color; - - + .list__item .archive__item-title { - margin-top: 0.5em; - } -} - -.archive__item-title { - margin-bottom: 0.25em; - font-family: $sans-serif-narrow; - line-height: initial; - overflow: hidden; - text-overflow: ellipsis; - - a[rel="permalink"]::before { - content: ''; - position: absolute; - left: 0; - top: 0; - right: 0; - bottom: 0; - } - - a + a { - opacity: 0.5; - } -} - -/* remove border*/ -.page__content { - .archive__item-title { - margin-top: 1em; - border-bottom: none; - } -} - -.archive__item-excerpt { - margin-top: 0; - font-size: $type-size-6; - - & + p { - text-indent: 0; - } - - a { - position: relative; - } -} - -.archive__item-teaser { - position: relative; - border-radius: $border-radius; - overflow: hidden; - - img { - width: 100%; - } -} - -.archive__item-caption { - position: absolute; - bottom: 0; - right: 0; - margin: 0 auto; - padding: 2px 5px; - color: #fff; - font-family: $caption-font-family; - font-size: $type-size-8; - background: #000; - text-align: right; - z-index: 5; - opacity: 0.5; - border-radius: $border-radius 0 0 0; - - @include breakpoint($large) { - padding: 5px 10px; - } - - a { - color: #fff; - text-decoration: none; - } -} - -/* - List view - ========================================================================== */ - -.list__item { - .page__meta { - margin: 0 0 4px; - font-size: 0.6em; - } -} - -/* - Grid view - ========================================================================== */ - -.archive { - .grid__wrapper { - /* extend grid elements to the right */ - - @include breakpoint($large) { - margin-right: -1 * $right-sidebar-width-narrow; - } - - @include breakpoint($x-large) { - margin-right: -1 * $right-sidebar-width; - } - } -} - -.grid__item { - margin-bottom: 2em; - - @include breakpoint($small) { - float: left; - width: span(5 of 10); - - &:nth-child(2n + 1) { - clear: both; - margin-left: 0; - } - - &:nth-child(2n + 2) { - clear: none; - margin-left: gutter(of 10); - } - } - - @include breakpoint($medium) { - margin-left: 0; /* override margin*/ - margin-right: 0; /* override margin*/ - width: span(3 of 12); - - &:nth-child(2n + 1) { - clear: none; - } - - &:nth-child(4n + 1) { - clear: both; - } - - &:nth-child(4n + 2) { - clear: none; - margin-left: gutter(1 of 12); - } - - &:nth-child(4n + 3) { - clear: none; - margin-left: gutter(1 of 12); - } - - &:nth-child(4n + 4) { - clear: none; - margin-left: gutter(1 of 12); - } - } - - .page__meta { - margin: 0 0 4px; - font-size: 0.6em; - } - - .page__meta-sep { - display: block; - - &::before { - display: none; - } - } - - .archive__item-title { - margin-top: 0.5em; - font-size: $type-size-5; - } - - .archive__item-excerpt { - display: none; - - @include breakpoint($medium) { - display: block; - font-size: $type-size-6; - } - } - - .archive__item-teaser { - @include breakpoint($small) { - max-height: 200px; - } - - @include breakpoint($medium) { - max-height: 120px; - } - } -} - -/* - Features - ========================================================================== */ - -.feature__wrapper { - @include clearfix(); - margin-bottom: 2em; - border-bottom: 1px solid $border-color; - - .archive__item-title { - margin-bottom: 0; - } -} - -.feature__item { - position: relative; - margin-bottom: 2em; - font-size: 1.125em; - - @include breakpoint($small) { - float: left; - margin-bottom: 0; - width: span(4 of 12); - - &:nth-child(3n + 1) { - clear: both; - margin-left: 0; - } - - &:nth-child(3n + 2) { - clear: none; - margin-left: gutter(of 12); - } - - &:nth-child(3n + 3) { - clear: none; - margin-left: gutter(of 12); - } - - .feature__item-teaser { - max-height: 200px; - overflow: hidden; - } - } - - .archive__item-body { - padding-left: gutter(1 of 12); - padding-right: gutter(1 of 12); - } - - a.btn::before { - content: ''; - position: absolute; - left: 0; - top: 0; - right: 0; - bottom: 0; - } - - &--left { - position: relative; - float: left; - margin-left: 0; - margin-right: 0; - width: 100%; - clear: both; - font-size: 1.125em; - - .archive__item { - float: left; - } - - .archive__item-teaser { - margin-bottom: 2em; - } - - a.btn::before { - content: ''; - position: absolute; - left: 0; - top: 0; - right: 0; - bottom: 0; - } - - @include breakpoint($small) { - .archive__item-teaser { - float: left; - width: span(5 of 12); - } - - .archive__item-body { - float: right; - padding-left: gutter(0.5 of 12); - padding-right: gutter(1 of 12); - width: span(7 of 12); - } - } - } - - &--right { - position: relative; - float: left; - margin-left: 0; - margin-right: 0; - width: 100%; - clear: both; - font-size: 1.125em; - - .archive__item { - float: left; - } - - .archive__item-teaser { - margin-bottom: 2em; - } - - a.btn::before { - content: ''; - position: absolute; - left: 0; - top: 0; - right: 0; - bottom: 0; - } - - @include breakpoint($small) { - text-align: right; - - .archive__item-teaser { - float: right; - width: span(5 of 12); - } - - .archive__item-body { - float: left; - width: span(7 of 12); - padding-left: gutter(0.5 of 12); - padding-right: gutter(1 of 12); - } - } - } - - &--center { - position: relative; - float: left; - margin-left: 0; - margin-right: 0; - width: 100%; - clear: both; - font-size: 1.125em; - - .archive__item { - float: left; - width: 100%; - } - - .archive__item-teaser { - margin-bottom: 2em; - } - - a.btn::before { - content: ''; - position: absolute; - left: 0; - top: 0; - right: 0; - bottom: 0; - } - - @include breakpoint($small) { - text-align: center; - - .archive__item-teaser { - margin: 0 auto; - width: span(5 of 12); - } - - .archive__item-body { - margin: 0 auto; - width: span(7 of 12); - } - } - } -} - -/* Place inside an archive layout */ - -.archive { - .feature__wrapper { - .archive__item-title { - margin-top: 0.25em; - font-size: 1em; - } - } - - .feature__item, - .feature__item--left, - .feature__item--center, - .feature__item--right { - font-size: 1em; - } -} - -/* - Wide Pages - ========================================================================== */ - - .wide { - .archive { - @include breakpoint($large) { - padding-right: 0; - } - - @include breakpoint($x-large) { - padding-right: 0; - } - } -} - -/* Place inside a single layout */ - -.layout--single { - .feature__wrapper { - display: inline-block; - } -} diff --git a/docs/_sass/minimal-mistakes/_base.scss b/docs/_sass/minimal-mistakes/_base.scss deleted file mode 100644 index 3796eb6130..0000000000 --- a/docs/_sass/minimal-mistakes/_base.scss +++ /dev/null @@ -1,357 +0,0 @@ -/* ========================================================================== - BASE ELEMENTS - ========================================================================== */ - -html { - /* sticky footer fix */ - position: relative; - min-height: 100%; -} - -body { - margin: 0; - padding: 0; - color: $text-color; - font-family: $global-font-family; - line-height: 1.5; - - &.overflow--hidden { - /* when primary navigation is visible, the content in the background won't scroll */ - overflow: hidden; - } -} - -h1, -h2, -h3, -h4, -h5, -h6 { - margin: 2em 0 0.5em; - line-height: 1.2; - font-family: $header-font-family; - font-weight: bold; -} - -h1 { - margin-top: 0; - font-size: $h-size-1; -} - -h2 { - font-size: $h-size-2; -} - -h3 { - font-size: $h-size-3; -} - -h4 { - font-size: $h-size-4; -} - -h5 { - font-size: $h-size-5; -} - -h6 { - font-size: $h-size-6; -} - -small, -.small { - font-size: $type-size-6; -} - -p { - margin-bottom: 1.3em; -} - -u, -ins { - text-decoration: none; - border-bottom: 1px solid $text-color; - a { - color: inherit; - } -} - -del a { - color: inherit; -} - -/* reduce orphans and widows when printing */ - -p, -pre, -blockquote, -ul, -ol, -dl, -figure, -table, -fieldset { - orphans: 3; - widows: 3; -} - -/* abbreviations */ - -abbr[title], -abbr[data-original-title] { - text-decoration: none; - cursor: help; - border-bottom: 1px dotted $text-color; -} - -/* blockquotes */ - -blockquote { - margin: 2em 1em 2em 0; - padding-left: 1em; - padding-right: 1em; - font-style: italic; - border-left: 0.25em solid $primary-color; - - cite { - font-style: italic; - - &:before { - content: "\2014"; - padding-right: 5px; - } - } -} - -/* links */ - -a { - &:focus { - @extend %tab-focus; - } - - &:visited { - color: $link-color-visited; - } - - &:hover { - color: $link-color-hover; - outline: 0; - } -} - -/* buttons */ - -button:focus { - @extend %tab-focus; -} - -/* code */ - -tt, -code, -kbd, -samp, -pre { - font-family: $monospace; -} - -pre { - overflow-x: auto; /* add scrollbars to wide code blocks*/ -} - -p > code, -a > code, -li > code, -figcaption > code, -td > code { - padding-top: 0.1rem; - padding-bottom: 0.1rem; - font-size: 0.8em; - background: $code-background-color; - border-radius: $border-radius; - - &:before, - &:after { - letter-spacing: -0.2em; - content: "\00a0"; /* non-breaking space*/ - } -} - -/* horizontal rule */ - -hr { - display: block; - margin: 1em 0; - border: 0; - border-top: 1px solid $border-color; -} - -/* lists */ - -ul li, -ol li { - margin-bottom: 0.5em; -} - -li ul, -li ol { - margin-top: 0.5em; -} - -/* - Media and embeds - ========================================================================== */ - -/* Figures and images */ - -figure { - display: -webkit-box; - display: flex; - -webkit-box-pack: justify; - justify-content: space-between; - -webkit-box-align: start; - align-items: flex-start; - flex-wrap: wrap; - margin: 2em 0; - - img, - iframe, - .fluid-width-video-wrapper { - margin-bottom: 1em; - } - - img { - width: 100%; - border-radius: $border-radius; - -webkit-transition: $global-transition; - transition: $global-transition; - } - - > a { - display: block; - } - - &.half { - > a, - > img { - @include breakpoint($small) { - width: calc(50% - 0.5em); - } - } - - figcaption { - width: 100%; - } - } - - &.third { - > a, - > img { - @include breakpoint($small) { - width: calc(33.3333% - 0.5em); - } - } - - figcaption { - width: 100%; - } - } -} - -/* Figure captions */ - -figcaption { - margin-bottom: 0.5em; - color: $muted-text-color; - font-family: $caption-font-family; - font-size: $type-size-6; - - a { - -webkit-transition: $global-transition; - transition: $global-transition; - - &:hover { - color: $link-color-hover; - } - } -} - -/* Fix IE9 SVG bug */ - -svg:not(:root) { - overflow: hidden; -} - -/* - Navigation lists - ========================================================================== */ - -/** - * Removes margins, padding, and bullet points from navigation lists - * - * Example usage: - * - */ - -nav { - ul { - margin: 0; - padding: 0; - } - - li { - list-style: none; - } - - a { - text-decoration: none; - } - - /* override white-space for nested lists */ - ul li, - ol li { - margin-bottom: 0; - } - - li ul, - li ol { - margin-top: 0; - } -} - -/* - Global animation transition - ========================================================================== */ - -b, -i, -strong, -em, -blockquote, -p, -q, -span, -figure, -img, -h1, -h2, -header, -input, -a, -tr, -td, -form button, -input[type="submit"], -.btn, -.highlight, -.archive__item-teaser { - -webkit-transition: $global-transition; - transition: $global-transition; -} diff --git a/docs/_sass/minimal-mistakes/_buttons.scss b/docs/_sass/minimal-mistakes/_buttons.scss deleted file mode 100644 index 9ef60a8453..0000000000 --- a/docs/_sass/minimal-mistakes/_buttons.scss +++ /dev/null @@ -1,97 +0,0 @@ -/* ========================================================================== - BUTTONS - ========================================================================== */ - -/* - Default button - ========================================================================== */ - -.btn { - /* default */ - display: inline-block; - margin-bottom: 0.25em; - padding: 0.5em 1em; - font-family: $sans-serif; - font-size: $type-size-6; - font-weight: bold; - text-align: center; - text-decoration: none; - border-width: 0; - border-radius: $border-radius; - cursor: pointer; - - .icon { - margin-right: 0.5em; - } - - .icon + .hidden { - margin-left: -0.5em; /* override for hidden text*/ - } - - /* button colors */ - $buttoncolors: - (primary, $primary-color), - (inverse, #fff), - (light-outline, transparent), - (success, $success-color), - (warning, $warning-color), - (danger, $danger-color), - (info, $info-color), - (facebook, $facebook-color), - (twitter, $twitter-color), - (linkedin, $linkedin-color); - - @each $buttoncolor, $color in $buttoncolors { - &--#{$buttoncolor} { - @include yiq-contrasted($color); - @if ($buttoncolor == inverse) { - border: 1px solid $border-color; - } - @if ($buttoncolor == light-outline) { - border: 1px solid #fff; - } - - &:visited { - @include yiq-contrasted($color); - } - - &:hover { - @include yiq-contrasted(mix(#000, $color, 20%)); - } - } - } - - /* fills width of parent container */ - &--block { - display: block; - width: 100%; - - + .btn--block { - margin-top: 0.25em; - } - } - - /* disabled */ - &--disabled { - pointer-events: none; - cursor: not-allowed; - filter: alpha(opacity=65); - box-shadow: none; - opacity: 0.65; - } - - /* extra large button */ - &--x-large { - font-size: $type-size-4; - } - - /* large button */ - &--large { - font-size: $type-size-5; - } - - /* small button */ - &--small { - font-size: $type-size-7; - } -} \ No newline at end of file diff --git a/docs/_sass/minimal-mistakes/_footer.scss b/docs/_sass/minimal-mistakes/_footer.scss deleted file mode 100644 index c0b0625bda..0000000000 --- a/docs/_sass/minimal-mistakes/_footer.scss +++ /dev/null @@ -1,85 +0,0 @@ -/* ========================================================================== - FOOTER - ========================================================================== */ - -.page__footer { - @include clearfix; - float: left; - margin-left: 0; - margin-right: 0; - width: 100%; - margin-top: 3em; - color: $muted-text-color; - -webkit-animation: $intro-transition; - animation: $intro-transition; - -webkit-animation-delay: 0.45s; - animation-delay: 0.45s; - background-color: $footer-background-color; - - footer { - @include clearfix; - margin-left: auto; - margin-right: auto; - margin-top: 2em; - max-width: 100%; - padding: 0 1em 2em; - - @include breakpoint($x-large) { - max-width: $x-large; - } - } - - a { - color: inherit; - text-decoration: none; - - &:hover { - text-decoration: underline; - } - } - - .fas, - .fab, - .far, - .fal { - color: $muted-text-color; - } -} - -.page__footer-copyright { - font-family: $global-font-family; - font-size: $type-size-7; -} - -.page__footer-follow { - ul { - margin: 0; - padding: 0; - list-style-type: none; - } - - li { - display: inline-block; - padding-top: 5px; - padding-bottom: 5px; - font-family: $sans-serif-narrow; - font-size: $type-size-6; - text-transform: uppercase; - } - - li + li:before { - content: ""; - padding-right: 5px; - } - - a { - padding-right: 10px; - font-weight: bold; - } - - .social-icons { - a { - white-space: nowrap; - } - } -} diff --git a/docs/_sass/minimal-mistakes/_forms.scss b/docs/_sass/minimal-mistakes/_forms.scss deleted file mode 100644 index 0dd9b480b7..0000000000 --- a/docs/_sass/minimal-mistakes/_forms.scss +++ /dev/null @@ -1,359 +0,0 @@ -/* ========================================================================== - Forms - ========================================================================== */ - -form { - margin: 0 0 5px 0; - padding: 1em; - background-color: $form-background-color; - - fieldset { - margin-bottom: 5px; - padding: 0; - border-width: 0; - } - - legend { - display: block; - width: 100%; - margin-bottom: 5px * 2; - *margin-left: -7px; - padding: 0; - color: $text-color; - border: 0; - white-space: normal; - } - - p { - margin-bottom: (5px / 2); - } - - ul { - list-style-type: none; - margin: 0 0 5px 0; - padding: 0; - } - - br { - display: none; - } -} - -label, -input, -button, -select, -textarea { - vertical-align: baseline; - *vertical-align: middle; -} - -input, -button, -select, -textarea { - box-sizing: border-box; - font-family: $sans-serif; -} - -label { - display: block; - margin-bottom: 0.25em; - color: $text-color; - cursor: pointer; - - small { - font-size: $type-size-6; - } - - input, - textarea, - select { - display: block; - } -} - -input, -textarea, -select { - display: inline-block; - width: 100%; - padding: 0.25em; - margin-bottom: 0.5em; - color: $text-color; - background-color: $background-color; - border: $border-color; - border-radius: $border-radius; - box-shadow: $box-shadow; -} - -.input-mini { - width: 60px; -} - -.input-small { - width: 90px; -} - -input[type="image"], -input[type="checkbox"], -input[type="radio"] { - width: auto; - height: auto; - padding: 0; - margin: 3px 0; - *margin-top: 0; - line-height: normal; - cursor: pointer; - border-radius: 0; - border: 0 \9; - box-shadow: none; -} - -input[type="checkbox"], -input[type="radio"] { - box-sizing: border-box; - padding: 0; - *width: 13px; - *height: 13px; -} - -input[type="image"] { - border: 0; -} - -input[type="file"] { - width: auto; - padding: initial; - line-height: initial; - border: initial; - background-color: transparent; - background-color: initial; - box-shadow: none; -} - -input[type="button"], -input[type="reset"], -input[type="submit"] { - width: auto; - height: auto; - cursor: pointer; - *overflow: visible; -} - -select, -input[type="file"] { - *margin-top: 4px; -} - -select { - width: auto; - background-color: #fff; -} - -select[multiple], -select[size] { - height: auto; -} - -textarea { - resize: vertical; - height: auto; - overflow: auto; - vertical-align: top; -} - -input[type="hidden"] { - display: none; -} - -.form { - position: relative; -} - -.radio, -.checkbox { - padding-left: 18px; - font-weight: normal; -} - -.radio input[type="radio"], -.checkbox input[type="checkbox"] { - float: left; - margin-left: -18px; -} - -.radio.inline, -.checkbox.inline { - display: inline-block; - padding-top: 5px; - margin-bottom: 0; - vertical-align: middle; -} - -.radio.inline + .radio.inline, -.checkbox.inline + .checkbox.inline { - margin-left: 10px; -} - -/* - Disabled state - ========================================================================== */ - -input[disabled], -select[disabled], -textarea[disabled], -input[readonly], -select[readonly], -textarea[readonly] { - opacity: 0.5; - cursor: not-allowed; -} - -/* - Focus & active state - ========================================================================== */ - -input:focus, -textarea:focus { - border-color: $primary-color; - outline: 0; - outline: thin dotted \9; - box-shadow: inset 0 1px 3px rgba($text-color, 0.06), - 0 0 5px rgba($primary-color, 0.7); -} - -input[type="file"]:focus, -input[type="radio"]:focus, -input[type="checkbox"]:focus, -select:focus { - box-shadow: none; -} - -/* - Help text - ========================================================================== */ - -.help-block, -.help-inline { - color: $muted-text-color; -} - -.help-block { - display: block; - margin-bottom: 1em; - line-height: 1em; -} - -.help-inline { - display: inline-block; - vertical-align: middle; - padding-left: 5px; -} - -/* - .form-group - ========================================================================== */ - -.form-group { - margin-bottom: 5px; - padding: 0; - border-width: 0; -} - -/* - .form-inline - ========================================================================== */ - -.form-inline input, -.form-inline textarea, -.form-inline select { - display: inline-block; - margin-bottom: 0; -} - -.form-inline label { - display: inline-block; -} - -.form-inline .radio, -.form-inline .checkbox, -.form-inline .radio { - padding-left: 0; - margin-bottom: 0; - vertical-align: middle; -} - -.form-inline .radio input[type="radio"], -.form-inline .checkbox input[type="checkbox"] { - float: left; - margin-left: 0; - margin-right: 3px; -} - -/* - .form-search - ========================================================================== */ - -.form-search input, -.form-search textarea, -.form-search select { - display: inline-block; - margin-bottom: 0; -} - -.form-search .search-query { - padding-left: 14px; - padding-right: 14px; - margin-bottom: 0; - border-radius: 14px; -} - -.form-search label { - display: inline-block; -} - -.form-search .radio, -.form-search .checkbox, -.form-inline .radio { - padding-left: 0; - margin-bottom: 0; - vertical-align: middle; -} - -.form-search .radio input[type="radio"], -.form-search .checkbox input[type="checkbox"] { - float: left; - margin-left: 0; - margin-right: 3px; -} - -/* - .form--loading - ========================================================================== */ - -.form--loading:before { - content: ""; -} - -.form--loading .form__spinner { - display: block; -} - -.form:before { - position: absolute; - top: 0; - left: 0; - width: 100%; - height: 100%; - background-color: rgba(255, 255, 255, 0.7); - z-index: 10; -} - -.form__spinner { - display: none; - position: absolute; - top: 50%; - left: 50%; - z-index: 11; -} diff --git a/docs/_sass/minimal-mistakes/_masthead.scss b/docs/_sass/minimal-mistakes/_masthead.scss deleted file mode 100644 index 2dfefccef6..0000000000 --- a/docs/_sass/minimal-mistakes/_masthead.scss +++ /dev/null @@ -1,93 +0,0 @@ -/* ========================================================================== - MASTHEAD - ========================================================================== */ - -.masthead { - position: relative; - border-bottom: 1px solid $border-color; - -webkit-animation: $intro-transition; - animation: $intro-transition; - -webkit-animation-delay: 0.15s; - animation-delay: 0.15s; - z-index: 20; - - &__inner-wrap { - @include clearfix; - margin-left: auto; - margin-right: auto; - padding: 1em; - max-width: 100%; - display: -webkit-box; - display: -ms-flexbox; - display: flex; - -webkit-box-pack: justify; - -ms-flex-pack: justify; - justify-content: space-between; - font-family: $sans-serif-narrow; - - @include breakpoint($x-large) { - max-width: $max-width; - } - - nav { - z-index: 10; - } - - a { - text-decoration: none; - } - } -} - -.site-logo img { - max-height: 2rem; -} - -.site-title { - display: -webkit-box; - display: -ms-flexbox; - display: flex; - -ms-flex-item-align: center; - align-self: center; - font-weight: bold; - // z-index: 20; -} - -.site-subtitle { - display: block; - font-size: $type-size-8; -} - -.masthead__menu { - float: left; - margin-left: 0; - margin-right: 0; - width: 100%; - clear: both; - - .site-nav { - margin-left: 0; - - @include breakpoint($small) { - float: right; - } - } - - ul { - margin: 0; - padding: 0; - clear: both; - list-style-type: none; - } -} - -.masthead__menu-item { - display: block; - list-style-type: none; - white-space: nowrap; - - &--lg { - padding-right: 2em; - font-weight: 700; - } -} diff --git a/docs/_sass/minimal-mistakes/_mixins.scss b/docs/_sass/minimal-mistakes/_mixins.scss deleted file mode 100644 index 4aa9eb09ca..0000000000 --- a/docs/_sass/minimal-mistakes/_mixins.scss +++ /dev/null @@ -1,92 +0,0 @@ -/* ========================================================================== - MIXINS - ========================================================================== */ - -%tab-focus { - /* Default*/ - outline: thin dotted $focus-color; - /* Webkit*/ - outline: 5px auto $focus-color; - outline-offset: -2px; -} - -/* - em function - ========================================================================== */ - -@function em($target, $context: $doc-font-size) { - @return ($target / $context) * 1em; -} - - -/* - Bourbon clearfix - ========================================================================== */ - -/* - * Provides an easy way to include a clearfix for containing floats. - * link http://cssmojo.com/latest_new_clearfix_so_far/ - * - * example scss - Usage - * - * .element { - * @include clearfix; - * } - * - * example css - CSS Output - * - * .element::after { - * clear: both; - * content: ""; - * display: table; - * } -*/ - -@mixin clearfix { - clear: both; - - &::after { - clear: both; - content: ""; - display: table; - } -} - -/* - Compass YIQ Color Contrast - https://github.com/easy-designs/yiq-color-contrast - ========================================================================== */ - -@function yiq-is-light( - $color, - $threshold: $yiq-contrasted-threshold -) { - $red: red($color); - $green: green($color); - $blue: blue($color); - - $yiq: (($red*299)+($green*587)+($blue*114))/1000; - - @if $yiq-debug { @debug $yiq, $threshold; } - - @return if($yiq >= $threshold, true, false); -} - -@function yiq-contrast-color( - $color, - $dark: $yiq-contrasted-dark-default, - $light: $yiq-contrasted-light-default, - $threshold: $yiq-contrasted-threshold -) { - @return if(yiq-is-light($color, $threshold), $yiq-contrasted-dark-default, $yiq-contrasted-light-default); -} - -@mixin yiq-contrasted( - $background-color, - $dark: $yiq-contrasted-dark-default, - $light: $yiq-contrasted-light-default, - $threshold: $yiq-contrasted-threshold -) { - background-color: $background-color; - color: yiq-contrast-color($background-color, $dark, $light, $threshold); -} \ No newline at end of file diff --git a/docs/_sass/minimal-mistakes/_navigation.scss b/docs/_sass/minimal-mistakes/_navigation.scss deleted file mode 100644 index 24d1b1b5ce..0000000000 --- a/docs/_sass/minimal-mistakes/_navigation.scss +++ /dev/null @@ -1,573 +0,0 @@ -/* ========================================================================== - NAVIGATION - ========================================================================== */ - -/* - Breadcrumb navigation links - ========================================================================== */ - -.breadcrumbs { - @include clearfix; - margin: 0 auto; - max-width: 100%; - padding-left: 1em; - padding-right: 1em; - font-family: $sans-serif; - -webkit-animation: $intro-transition; - animation: $intro-transition; - -webkit-animation-delay: 0.3s; - animation-delay: 0.3s; - - @include breakpoint($x-large) { - max-width: $x-large; - } - - ol { - padding: 0; - list-style: none; - font-size: $type-size-6; - - @include breakpoint($large) { - float: right; - width: calc(100% - #{$right-sidebar-width-narrow}); - } - - @include breakpoint($x-large) { - width: calc(100% - #{$right-sidebar-width}); - } - } - - li { - display: inline; - } - - .current { - font-weight: bold; - } -} - -/* - Post pagination navigation links - ========================================================================== */ - -.pagination { - @include clearfix(); - float: left; - margin-top: 1em; - padding-top: 1em; - width: 100%; - - ul { - margin: 0; - padding: 0; - list-style-type: none; - font-family: $sans-serif; - } - - li { - display: block; - float: left; - margin-left: -1px; - - a { - display: block; - margin-bottom: 0.25em; - padding: 0.5em 1em; - font-family: $sans-serif; - font-size: 14px; - font-weight: bold; - line-height: 1.5; - text-align: center; - text-decoration: none; - color: $muted-text-color; - border: 1px solid mix(#000, $border-color, 25%); - border-radius: 0; - - &:hover { - color: $link-color-hover; - } - - &.current, - &.current.disabled { - color: #fff; - background: $primary-color; - } - - &.disabled { - color: rgba($muted-text-color, 0.5); - pointer-events: none; - cursor: not-allowed; - } - } - - &:first-child { - margin-left: 0; - - a { - border-top-left-radius: $border-radius; - border-bottom-left-radius: $border-radius; - } - } - - &:last-child { - a { - border-top-right-radius: $border-radius; - border-bottom-right-radius: $border-radius; - } - } - } - - /* next/previous buttons */ - &--pager { - display: block; - padding: 1em 2em; - float: left; - width: 50%; - font-family: $sans-serif; - font-size: $type-size-5; - font-weight: bold; - text-align: center; - text-decoration: none; - color: $muted-text-color; - border: 1px solid mix(#000, $border-color, 25%); - border-radius: $border-radius; - - &:hover { - @include yiq-contrasted($muted-text-color); - } - - &:first-child { - border-top-right-radius: 0; - border-bottom-right-radius: 0; - } - - &:last-child { - margin-left: -1px; - border-top-left-radius: 0; - border-bottom-left-radius: 0; - } - - &.disabled { - color: rgba($muted-text-color, 0.5); - pointer-events: none; - cursor: not-allowed; - } - } -} - -.page__content + .pagination, -.page__meta + .pagination, -.page__share + .pagination, -.page__comments + .pagination { - margin-top: 2em; - padding-top: 2em; - border-top: 1px solid $border-color; -} - -/* - Priority plus navigation - ========================================================================== */ - -.greedy-nav { - position: relative; - display: -webkit-box; - display: -ms-flexbox; - display: flex; - -webkit-box-align: center; - -ms-flex-align: center; - align-items: center; - min-height: $nav-height; - background: $background-color; - - a { - display: block; - margin: 0 1rem; - color: $masthead-link-color; - text-decoration: none; - -webkit-transition: none; - transition: none; - - &:hover { - color: $masthead-link-color-hover; - } - - &.site-logo { - margin-left: 0; - margin-right: 0.5rem; - } - - &.site-title { - margin-left: 0; - } - } - - img { - -webkit-transition: none; - transition: none; - } - - &__toggle { - -ms-flex-item-align: center; - align-self: center; - height: $nav-toggle-height; - border: 0; - outline: none; - background-color: transparent; - cursor: pointer; - } - - .visible-links { - display: -webkit-box; - display: -ms-flexbox; - display: flex; - -webkit-box-pack: end; - -ms-flex-pack: end; - justify-content: flex-end; - -webkit-box-flex: 1; - -ms-flex: 1; - flex: 1; - overflow: hidden; - - li { - -webkit-box-flex: 0; - -ms-flex: none; - flex: none; - } - - a { - position: relative; - - &:before { - content: ""; - position: absolute; - left: 0; - bottom: 0; - height: 4px; - background: $primary-color; - width: 100%; - -webkit-transition: $global-transition; - transition: $global-transition; - -webkit-transform: scaleX(0) translate3d(0, 0, 0); - transform: scaleX(0) translate3d(0, 0, 0); // hide - } - - &:hover:before { - -webkit-transform: scaleX(1); - -ms-transform: scaleX(1); - transform: scaleX(1); // reveal - } - } - } - - .hidden-links { - position: absolute; - top: 100%; - right: 0; - margin-top: 15px; - padding: 5px; - border: 1px solid $border-color; - border-radius: $border-radius; - background: $background-color; - -webkit-box-shadow: 0 2px 4px 0 rgba(#000, 0.16), - 0 2px 10px 0 rgba(#000, 0.12); - box-shadow: 0 2px 4px 0 rgba(#000, 0.16), 0 2px 10px 0 rgba(#000, 0.12); - - &.hidden { - display: none; - } - - a { - margin: 0; - padding: 10px 20px; - font-size: $type-size-5; - - &:hover { - color: $masthead-link-color-hover; - background: $navicon-link-color-hover; - } - } - - &:before { - content: ""; - position: absolute; - top: -11px; - right: 10px; - width: 0; - border-style: solid; - border-width: 0 10px 10px; - border-color: $border-color transparent; - display: block; - z-index: 0; - } - - &:after { - content: ""; - position: absolute; - top: -10px; - right: 10px; - width: 0; - border-style: solid; - border-width: 0 10px 10px; - border-color: $background-color transparent; - display: block; - z-index: 1; - } - - li { - display: block; - border-bottom: 1px solid $border-color; - - &:last-child { - border-bottom: none; - } - } - } -} - -.no-js { - .greedy-nav { - .visible-links { - -ms-flex-wrap: wrap; - flex-wrap: wrap; - overflow: visible; - } - } -} - -/* - Navigation list - ========================================================================== */ - -.nav__list { - margin-bottom: 1.5em; - - input[type="checkbox"], - label { - display: none; - } - - @include breakpoint(max-width $large - 1px) { - label { - position: relative; - display: inline-block; - padding: 0.5em 2.5em 0.5em 1em; - color: $gray; - font-size: $type-size-6; - font-weight: bold; - border: 1px solid $light-gray; - border-radius: $border-radius; - z-index: 20; - -webkit-transition: 0.2s ease-out; - transition: 0.2s ease-out; - cursor: pointer; - - &:before, - &:after { - content: ""; - position: absolute; - right: 1em; - top: 1.25em; - width: 0.75em; - height: 0.125em; - line-height: 1; - background-color: $gray; - -webkit-transition: 0.2s ease-out; - transition: 0.2s ease-out; - } - - &:after { - -webkit-transform: rotate(90deg); - -ms-transform: rotate(90deg); - transform: rotate(90deg); - } - - &:hover { - color: #fff; - border-color: $gray; - background-color: mix(white, #000, 20%); - - &:before, - &:after { - background-color: #fff; - } - } - } - - /* selected*/ - input:checked + label { - color: white; - background-color: mix(white, #000, 20%); - - &:before, - &:after { - background-color: #fff; - } - } - - /* on hover show expand*/ - label:hover:after { - -webkit-transform: rotate(90deg); - -ms-transform: rotate(90deg); - transform: rotate(90deg); - } - - input:checked + label:hover:after { - -webkit-transform: rotate(0); - -ms-transform: rotate(0); - transform: rotate(0); - } - - ul { - margin-bottom: 1em; - } - - a { - display: block; - padding: 0.25em 0; - - @include breakpoint($large) { - padding-top: 0.125em; - padding-bottom: 0.125em; - } - - &:hover { - text-decoration: underline; - } - } - } -} - -.nav__list .nav__items { - margin: 0; - font-size: 1.25rem; - - a { - color: inherit; - } - - .active { - margin-left: -0.5em; - padding-left: 0.5em; - padding-right: 0.5em; - font-weight: bold; - } - - @include breakpoint(max-width $large - 1px) { - position: relative; - max-height: 0; - opacity: 0%; - overflow: hidden; - z-index: 10; - -webkit-transition: 0.3s ease-in-out; - transition: 0.3s ease-in-out; - -webkit-transform: translate(0, 10%); - -ms-transform: translate(0, 10%); - transform: translate(0, 10%); - } -} - -@include breakpoint(max-width $large - 1px) { - .nav__list input:checked ~ .nav__items { - -webkit-transition: 0.5s ease-in-out; - transition: 0.5s ease-in-out; - max-height: 9999px; /* exaggerate max-height to accommodate tall lists*/ - overflow: visible; - opacity: 1; - margin-top: 1em; - -webkit-transform: translate(0, 0); - -ms-transform: translate(0, 0); - transform: translate(0, 0); - } -} - -.nav__title { - margin: 0; - padding: 0.5rem 0.75rem; - font-family: $sans-serif-narrow; - font-size: $type-size-5; - font-weight: bold; -} - -.nav__sub-title { - display: block; - margin: 0.5rem 0; - padding: 0.25rem 0; - font-family: $sans-serif-narrow; - font-size: $type-size-6; - font-weight: bold; - text-transform: uppercase; - border-bottom: 1px solid $border-color; -} - -/* - Table of contents navigation - ========================================================================== */ - -.toc { - font-family: $sans-serif-narrow; - color: $gray; - background-color: $background-color; - border: 1px solid $border-color; - border-radius: $border-radius; - -webkit-box-shadow: $box-shadow; - box-shadow: $box-shadow; - - .nav__title { - color: #fff; - font-size: $type-size-6; - background: $primary-color; - border-top-left-radius: $border-radius; - border-top-right-radius: $border-radius; - } - - // Scrollspy marks toc items as .active when they are in focus - .active a { - @include yiq-contrasted($active-color); - } -} - -.toc__menu { - margin: 0; - padding: 0; - width: 100%; - list-style: none; - font-size: $type-size-6; - - @include breakpoint($large) { - font-size: $type-size-7; - } - - a { - display: block; - padding: 0.25rem 0.75rem; - color: $muted-text-color; - font-weight: bold; - line-height: 1.5; - border-bottom: 1px solid $border-color; - - &:hover { - color: $text-color; - } - } - - li ul > li a { - padding-left: 1.25rem; - font-weight: normal; - } - - li ul li ul > li a { - padding-left: 1.75rem; - } - - li ul li ul li ul > li a { - padding-left: 2.25rem; - } - - li ul li ul li ul li ul > li a { - padding-left: 2.75rem; - } - - li ul li ul li ul li ul li ul > li a { - padding-left: 3.25rem - } -} diff --git a/docs/_sass/minimal-mistakes/_notices.scss b/docs/_sass/minimal-mistakes/_notices.scss deleted file mode 100644 index 3a9b5e606e..0000000000 --- a/docs/_sass/minimal-mistakes/_notices.scss +++ /dev/null @@ -1,105 +0,0 @@ -/* ========================================================================== - NOTICE TEXT BLOCKS - ========================================================================== */ - -/** - * Default Kramdown usage (no indents!): - *
- * #### Headline for the Notice - * Text for the notice - *
- */ - -@mixin notice($notice-color) { - margin: 2em 0 !important; /* override*/ - padding: 1em; - color: $text-color; - font-family: $global-font-family; - font-size: $type-size-6 !important; - text-indent: initial; /* override*/ - background-color: mix($background-color, $notice-color, $notice-background-mix); - border-radius: $border-radius; - box-shadow: 0 1px 1px rgba($notice-color, 0.25); - - h4 { - margin-top: 0 !important; /* override*/ - margin-bottom: 0.75em; - line-height: inherit; - } - - @at-root .page__content #{&} h4 { - /* using at-root to override .page-content h4 font size*/ - margin-bottom: 0; - font-size: 1em; - } - - p { - &:last-child { - margin-bottom: 0 !important; /* override*/ - } - } - - h4 + p { - /* remove space above paragraphs that appear directly after notice headline*/ - margin-top: 0; - padding-top: 0; - } - - a { - color: mix(#000, $notice-color, 10%); - - &:hover { - color: mix(#000, $notice-color, 50%); - } - } - - code { - background-color: mix($background-color, $notice-color, $code-notice-background-mix) - } - - pre code { - background-color: inherit; - } - - ul { - &:last-child { - margin-bottom: 0; /* override*/ - } - } -} - -/* Default notice */ - -.notice { - @include notice($light-gray); -} - -/* Primary notice */ - -.notice--primary { - @include notice($primary-color); -} - -/* Info notice */ - -.notice--info { - @include notice($info-color); -} - -/* Warning notice */ - -.notice--warning { - @include notice($warning-color); -} - -/* Success notice */ - -.notice--success { - @include notice($success-color); -} - -/* Danger notice */ - -.notice--danger { - @include notice($danger-color); -} diff --git a/docs/_sass/minimal-mistakes/_page.scss b/docs/_sass/minimal-mistakes/_page.scss deleted file mode 100644 index 9e3f540902..0000000000 --- a/docs/_sass/minimal-mistakes/_page.scss +++ /dev/null @@ -1,564 +0,0 @@ -/* ========================================================================== - SINGLE PAGE/POST - ========================================================================== */ - -#main { - @include clearfix; - margin-left: auto; - margin-right: auto; - padding-left: 1em; - padding-right: 1em; - -webkit-animation: $intro-transition; - animation: $intro-transition; - max-width: 100%; - -webkit-animation-delay: 0.15s; - animation-delay: 0.15s; - - @include breakpoint($x-large) { - max-width: $max-width; - } -} - -body { - display: -webkit-box; - display: -ms-flexbox; - display: flex; - min-height: 100vh; - -webkit-box-orient: vertical; - -webkit-box-direction: normal; - -ms-flex-direction: column; - flex-direction: column; -} - -.initial-content, -.search-content { - flex: 1 0 auto; -} - -.page { - @include breakpoint($large) { - float: right; - width: calc(100% - #{$right-sidebar-width-narrow}); - padding-right: $right-sidebar-width-narrow; - } - - @include breakpoint($x-large) { - width: calc(100% - #{$right-sidebar-width}); - padding-right: $right-sidebar-width; - } - - .page__inner-wrap { - float: left; - margin-top: 1em; - margin-left: 0; - margin-right: 0; - width: 100%; - clear: both; - - .page__content, - .page__meta, - .page__share { - position: relative; - float: left; - margin-left: 0; - margin-right: 0; - width: 100%; - clear: both; - } - } -} - -.page__title { - margin-top: 0; - line-height: 1; - - a { - color: $text-color; - text-decoration: none; - } - - & + .page__meta { - margin-top: -0.5em; - } -} - -.page__lead { - font-family: $global-font-family; - font-size: $type-size-4; -} - -.page__content { - h2 { - padding-bottom: 0.5em; - border-bottom: 1px solid $border-color; - } - - h1, h2, h3, h4, h5, h6 { - .header-link { - position: relative; - left: 0.5em; - opacity: 0; - font-size: 0.8em; - -webkit-transition: opacity 0.2s ease-in-out 0.1s; - -moz-transition: opacity 0.2s ease-in-out 0.1s; - -o-transition: opacity 0.2s ease-in-out 0.1s; - transition: opacity 0.2s ease-in-out 0.1s; - } - - &:hover .header-link { - opacity: 1; - } - } - - p, - li, - dl { - font-size: 1em; - } - - /* paragraph indents */ - p { - margin: 0 0 $indent-var; - - /* sibling indentation*/ - @if $paragraph-indent == true { - & + p { - text-indent: $indent-var; - margin-top: -($indent-var); - } - } - } - - a:not(.btn) { - &:hover { - text-decoration: underline; - - img { - box-shadow: 0 0 10px rgba(#000, 0.25); - } - } - } - - dt { - margin-top: 1em; - font-family: $sans-serif; - font-weight: bold; - } - - dd { - margin-left: 1em; - font-family: $sans-serif; - font-size: $type-size-6; - } - - .small { - font-size: $type-size-6; - } - - /* blockquote citations */ - blockquote + .small { - margin-top: -1.5em; - padding-left: 1.25rem; - } -} - -.page__hero { - position: relative; - margin-bottom: 2em; - @include clearfix; - -webkit-animation: $intro-transition; - animation: $intro-transition; - -webkit-animation-delay: 0.25s; - animation-delay: 0.25s; - - &--overlay { - position: relative; - margin-bottom: 2em; - padding: 3em 0; - @include clearfix; - background-size: cover; - background-repeat: no-repeat; - background-position: center; - -webkit-animation: $intro-transition; - animation: $intro-transition; - -webkit-animation-delay: 0.25s; - animation-delay: 0.25s; - - a { - color: #fff; - } - - .wrapper { - padding-left: 1em; - padding-right: 1em; - - @include breakpoint($x-large) { - max-width: $x-large; - } - } - - .page__title, - .page__meta, - .page__lead, - .btn { - color: #fff; - text-shadow: 1px 1px 4px rgba(#000, 0.5); - } - - .page__lead { - max-width: $medium; - } - - .page__title { - font-size: $type-size-2; - - @include breakpoint($small) { - font-size: $type-size-1; - } - } - } -} - -.page__hero-image { - width: 100%; - height: auto; - -ms-interpolation-mode: bicubic; -} - -.page__hero-caption { - position: absolute; - bottom: 0; - right: 0; - margin: 0 auto; - padding: 2px 5px; - color: #fff; - font-family: $caption-font-family; - font-size: $type-size-7; - background: #000; - text-align: right; - z-index: 5; - opacity: 0.5; - border-radius: $border-radius 0 0 0; - - @include breakpoint($large) { - padding: 5px 10px; - } - - a { - color: #fff; - text-decoration: none; - } -} - -/* - Social sharing - ========================================================================== */ - -.page__share { - margin-top: 2em; - padding-top: 1em; - border-top: 1px solid $border-color; - - @include breakpoint(max-width $small) { - .btn span { - border: 0; - clip: rect(0 0 0 0); - height: 1px; - margin: -1px; - overflow: hidden; - padding: 0; - position: absolute; - width: 1px; - } - } -} - -.page__share-title { - margin-bottom: 10px; - font-size: $type-size-6; - text-transform: uppercase; -} - -/* - Page meta - ========================================================================== */ - -.page__meta { - margin-top: 2em; - color: $muted-text-color; - font-family: $sans-serif; - font-size: $type-size-6; - - p { - margin: 0; - } - - a { - color: inherit; - } -} - -.page__meta-title { - margin-bottom: 10px; - font-size: $type-size-6; - text-transform: uppercase; -} - -.page__meta-sep::before { - content: "\2022"; - padding-left: 0.5em; - padding-right: 0.5em; -} - -/* - Page taxonomy - ========================================================================== */ - -.page__taxonomy { - .sep { - display: none; - } - - strong { - margin-right: 10px; - } -} - -.page__taxonomy-item { - display: inline-block; - margin-right: 5px; - margin-bottom: 8px; - padding: 5px 10px; - text-decoration: none; - border: 1px solid mix(#000, $border-color, 25%); - border-radius: $border-radius; - - &:hover { - text-decoration: none; - color: $link-color-hover; - } -} - -.taxonomy__section { - margin-bottom: 2em; - padding-bottom: 1em; - - &:not(:last-child) { - border-bottom: solid 1px $border-color; - } - - .archive__item-title { - margin-top: 0; - } - - .archive__subtitle { - clear: both; - border: 0; - } - - + .taxonomy__section { - margin-top: 2em; - } -} - -.taxonomy__title { - margin-bottom: 0.5em; - color: $muted-text-color; -} - -.taxonomy__count { - color: $muted-text-color; -} - -.taxonomy__index { - display: grid; - grid-column-gap: 2em; - grid-template-columns: repeat(3, 1fr); - margin: 1.414em 0; - padding: 0; - font-size: 0.75em; - list-style: none; - - @include breakpoint($large) { - grid-template-columns: repeat(3, 1fr); - } - - a { - display: -webkit-box; - display: -ms-flexbox; - display: flex; - padding: 0.25em 0; - -webkit-box-pack: justify; - -ms-flex-pack: justify; - justify-content: space-between; - color: inherit; - text-decoration: none; - border-bottom: 1px solid $border-color; - } -} - -.back-to-top { - display: block; - clear: both; - color: $muted-text-color; - font-size: 0.6em; - text-transform: uppercase; - text-align: right; - text-decoration: none; -} - -/* - Comments - ========================================================================== */ - -.page__comments { - float: left; - margin-left: 0; - margin-right: 0; - width: 100%; - clear: both; -} - -.page__comments-title { - margin-top: 2rem; - margin-bottom: 10px; - padding-top: 2rem; - font-size: $type-size-6; - border-top: 1px solid $border-color; - text-transform: uppercase; -} - -.page__comments-form { - -webkit-transition: $global-transition; - transition: $global-transition; - - &.disabled { - input, - button, - textarea, - label { - pointer-events: none; - cursor: not-allowed; - filter: alpha(opacity=65); - box-shadow: none; - opacity: 0.65; - } - } -} - -.comment { - @include clearfix(); - margin: 1em 0; - - &:not(:last-child) { - border-bottom: 1px solid $border-color; - } -} - -.comment__avatar-wrapper { - float: left; - width: 60px; - height: 60px; - - @include breakpoint($large) { - width: 100px; - height: 100px; - } -} - -.comment__avatar { - width: 40px; - height: 40px; - border-radius: 50%; - - @include breakpoint($large) { - width: 80px; - height: 80px; - padding: 5px; - border: 1px solid $border-color; - } -} - -.comment__content-wrapper { - float: right; - width: calc(100% - 60px); - - @include breakpoint($large) { - width: calc(100% - 100px); - } -} - -.comment__author { - margin: 0; - - a { - text-decoration: none; - } -} - -.comment__date { - @extend .page__meta; - margin: 0; - - a { - text-decoration: none; - } -} - -/* - Related - ========================================================================== */ - -.page__related { - @include clearfix(); - float: left; - margin-top: 2em; - padding-top: 1em; - border-top: 1px solid $border-color; - - @include breakpoint($large) { - float: right; - width: calc(100% - #{$right-sidebar-width-narrow}); - } - - @include breakpoint($x-large) { - width: calc(100% - #{$right-sidebar-width}); - } - - a { - color: inherit; - text-decoration: none; - } -} - -.page__related-title { - margin-bottom: 10px; - font-size: $type-size-6; - text-transform: uppercase; -} - -/* - Wide Pages - ========================================================================== */ - -.wide { - .page { - @include breakpoint($large) { - padding-right: 0; - } - - @include breakpoint($x-large) { - padding-right: 0; - } - } - - .page__related { - @include breakpoint($large) { - padding-right: 0; - } - - @include breakpoint($x-large) { - padding-right: 0; - } - } -} diff --git a/docs/_sass/minimal-mistakes/_print.scss b/docs/_sass/minimal-mistakes/_print.scss deleted file mode 100644 index b93f1d404e..0000000000 --- a/docs/_sass/minimal-mistakes/_print.scss +++ /dev/null @@ -1,252 +0,0 @@ -/* ========================================================================== - PRINT STYLES - ========================================================================== */ - -@media print { - - [hidden] { - display: none; - } - - * { - -moz-box-sizing: border-box; - -webkit-box-sizing: border-box; - box-sizing: border-box; - } - - html { - margin: 0; - padding: 0; - min-height: auto !important; - font-size: 16px; - } - - body { - margin: 0 auto; - background: #fff !important; - color: #000 !important; - font-size: 1rem; - line-height: 1.5; - -moz-osx-font-smoothing: grayscale; - -webkit-font-smoothing: antialiased; - text-rendering: optimizeLegibility; - } - - h1, - h2, - h3, - h4, - h5, - h6 { - color: #000; - line-height: 1.2; - margin-bottom: 0.75rem; - margin-top: 0; - } - - h1 { - font-size: 2.5rem; - } - - h2 { - font-size: 2rem; - } - - h3 { - font-size: 1.75rem; - } - - h4 { - font-size: 1.5rem; - } - - h5 { - font-size: 1.25rem; - } - - h6 { - font-size: 1rem; - } - - a, - a:visited { - color: #000; - text-decoration: underline; - word-wrap: break-word; - } - - table { - border-collapse: collapse; - } - - thead { - display: table-header-group; - } - - table, - th, - td { - border-bottom: 1px solid #000; - } - - td, - th { - padding: 8px 16px; - } - - img { - border: 0; - display: block; - max-width: 100% !important; - vertical-align: middle; - } - - hr { - border: 0; - border-bottom: 2px solid #bbb; - height: 0; - margin: 2.25rem 0; - padding: 0; - } - - dt { - font-weight: bold; - } - - dd { - margin: 0; - margin-bottom: 0.75rem; - } - - abbr[title], - acronym[title] { - border: 0; - text-decoration: none; - } - - table, - blockquote, - pre, - code, - figure, - li, - hr, - ul, - ol, - a, - tr { - page-break-inside: avoid; - } - - h2, - h3, - h4, - p, - a { - orphans: 3; - widows: 3; - } - - h1, - h2, - h3, - h4, - h5, - h6 { - page-break-after: avoid; - page-break-inside: avoid; - } - - h1 + p, - h2 + p, - h3 + p { - page-break-before: avoid; - } - - img { - page-break-after: auto; - page-break-before: auto; - page-break-inside: avoid; - } - - pre { - white-space: pre-wrap !important; - word-wrap: break-word; - } - - a[href^='http://']:after, - a[href^='https://']:after, - a[href^='ftp://']:after { - content: " (" attr(href) ")"; - font-size: 80%; - } - - abbr[title]:after, - acronym[title]:after { - content: " (" attr(title) ")"; - } - - #main { - max-width: 100%; - } - - .page { - margin: 0; - padding: 0; - width: 100%; - } - - .page-break, - .page-break-before { - page-break-before: always; - } - - .page-break-after { - page-break-after: always; - } - - .no-print { - display: none; - } - - a.no-reformat:after { - content: ''; - } - - abbr[title].no-reformat:after, - acronym[title].no-reformat:after { - content: ''; - } - - .page__hero-caption { - color: #000 !important; - background: #fff !important; - opacity: 1; - - a { - color: #000 !important; - } - } - -/* - Hide the following elements on print - ========================================================================== */ - - .masthead, - .toc, - .page__share, - .page__related, - .pagination, - .ads, - .page__footer, - .page__comments-form, - .author__avatar, - .author__content, - .author__urls-wrapper, - .nav__list, - .sidebar, - .adsbygoogle { - display: none !important; - height: 1px !important; - } -} \ No newline at end of file diff --git a/docs/_sass/minimal-mistakes/_reset.scss b/docs/_sass/minimal-mistakes/_reset.scss deleted file mode 100644 index 2259fd0c23..0000000000 --- a/docs/_sass/minimal-mistakes/_reset.scss +++ /dev/null @@ -1,187 +0,0 @@ -/* ========================================================================== - STYLE RESETS - ========================================================================== */ - -* { box-sizing: border-box; } - -html { - /* apply a natural box layout model to all elements */ - box-sizing: border-box; - background-color: $background-color; - font-size: 16px; - - @include breakpoint($medium) { - font-size: 18px; - } - - @include breakpoint($large) { - font-size: 20px; - } - - @include breakpoint($x-large) { - font-size: 22px; - } - - -webkit-text-size-adjust: 100%; - -ms-text-size-adjust: 100%; -} - -/* Remove margin */ - -body { margin: 0; } - -/* Selected elements */ - -::-moz-selection { - color: #fff; - background: #000; -} - -::selection { - color: #fff; - background: #000; -} - -/* Display HTML5 elements in IE6-9 and FF3 */ - -article, -aside, -details, -figcaption, -figure, -footer, -header, -hgroup, -main, -nav, -section { - display: block; -} - -/* Display block in IE6-9 and FF3 */ - -audio, -canvas, -video { - display: inline-block; - *display: inline; - *zoom: 1; -} - -/* Prevents modern browsers from displaying 'audio' without controls */ - -audio:not([controls]) { - display: none; -} - -a { - color: $link-color; -} - -/* Apply focus state */ - -a:focus { - @extend %tab-focus; -} - -/* Remove outline from links */ - -a:hover, -a:active { - outline: 0; -} - -/* Prevent sub and sup affecting line-height in all browsers */ - -sub, -sup { - position: relative; - font-size: 75%; - line-height: 0; - vertical-align: baseline; -} - -sup { - top: -0.5em; -} - -sub { - bottom: -0.25em; -} - -/* img border in anchor's and image quality */ - -img { - /* Responsive images (ensure images don't scale beyond their parents) */ - max-width: 100%; /* part 1: Set a maximum relative to the parent*/ - width: auto\9; /* IE7-8 need help adjusting responsive images*/ - height: auto; /* part 2: Scale the height according to the width, otherwise you get stretching*/ - - vertical-align: middle; - border: 0; - -ms-interpolation-mode: bicubic; -} - -/* Prevent max-width from affecting Google Maps */ - -#map_canvas img, -.google-maps img { - max-width: none; -} - -/* Consistent form font size in all browsers, margin changes, misc */ - -button, -input, -select, -textarea { - margin: 0; - font-size: 100%; - vertical-align: middle; -} - -button, -input { - *overflow: visible; /* inner spacing ie IE6/7*/ - line-height: normal; /* FF3/4 have !important on line-height in UA stylesheet*/ -} - -button::-moz-focus-inner, -input::-moz-focus-inner { /* inner padding and border oddities in FF3/4*/ - padding: 0; - border: 0; -} - -button, -html input[type="button"], // avoid the WebKit bug in Android 4.0.* where (2) destroys native `audio` and `video` controls -input[type="reset"], -input[type="submit"] { - -webkit-appearance: button; /* corrects inability to style clickable `input` types in iOS*/ - cursor: pointer; /* improves usability and consistency of cursor style between image-type `input` and others*/ -} - -label, -select, -button, -input[type="button"], -input[type="reset"], -input[type="submit"], -input[type="radio"], -input[type="checkbox"] { - cursor: pointer; /* improves usability and consistency of cursor style between image-type `input` and others*/ -} - -input[type="search"] { /* Appearance in Safari/Chrome*/ - box-sizing: border-box; - -webkit-appearance: textfield; -} - -input[type="search"]::-webkit-search-decoration, -input[type="search"]::-webkit-search-cancel-button { - -webkit-appearance: none; /* inner-padding issues in Chrome OSX, Safari 5*/ -} - -textarea { - overflow: auto; /* remove vertical scrollbar in IE6-9*/ - vertical-align: top; /* readability and alignment cross-browser*/ -} \ No newline at end of file diff --git a/docs/_sass/minimal-mistakes/_search.scss b/docs/_sass/minimal-mistakes/_search.scss deleted file mode 100644 index fa7ee832bf..0000000000 --- a/docs/_sass/minimal-mistakes/_search.scss +++ /dev/null @@ -1,132 +0,0 @@ -/* ========================================================================== - SEARCH - ========================================================================== */ - -.layout--search { - .archive__item-teaser { - margin-bottom: 0.25em; - } -} - -.search__toggle { - margin-left: 1rem; - margin-right: 1rem; - height: $nav-toggle-height; - border: 0; - outline: none; - color: $primary-color; - background-color: transparent; - cursor: pointer; - -webkit-transition: 0.2s; - transition: 0.2s; - - &:hover { - color: mix(#000, $primary-color, 25%); - } -} - -.search-icon { - width: 100%; - height: 100%; -} - -.search-content { - display: none; - visibility: hidden; - padding-top: 1em; - padding-bottom: 1em; - - &__inner-wrap { - width: 100%; - margin-left: auto; - margin-right: auto; - padding-left: 1em; - padding-right: 1em; - -webkit-animation: $intro-transition; - animation: $intro-transition; - -webkit-animation-delay: 0.15s; - animation-delay: 0.15s; - - @include breakpoint($x-large) { - max-width: $max-width; - } - - } - - &__form { - background-color: transparent; - } - - .search-input { - display: block; - margin-bottom: 0; - padding: 0; - border: none; - outline: none; - box-shadow: none; - background-color: transparent; - font-size: $type-size-3; - - @include breakpoint($large) { - font-size: $type-size-2; - } - - @include breakpoint($x-large) { - font-size: $type-size-1; - } - } - - &.is--visible { - display: block; - visibility: visible; - - &::after { - content: ""; - display: block; - } - } - - .results__found { - margin-top: 0.5em; - font-size: $type-size-6; - } - - .archive__item { - margin-bottom: 2em; - - @include breakpoint($large) { - width: 75%; - } - - @include breakpoint($x-large) { - width: 50%; - } - } - - .archive__item-title { - margin-top: 0; - } - - .archive__item-excerpt { - margin-bottom: 0; - } -} - -/* Algolia search */ - -.ais-search-box { - max-width: 100% !important; - margin-bottom: 2em; -} - -.archive__item-title .ais-Highlight { - color: $primary-color; - font-style: normal; - text-decoration: underline; -} - -.archive__item-excerpt .ais-Highlight { - color: $primary-color; - font-style: normal; - font-weight: bold; -} diff --git a/docs/_sass/minimal-mistakes/_sidebar.scss b/docs/_sass/minimal-mistakes/_sidebar.scss deleted file mode 100644 index 02b455b420..0000000000 --- a/docs/_sass/minimal-mistakes/_sidebar.scss +++ /dev/null @@ -1,353 +0,0 @@ -/* ========================================================================== - SIDEBAR - ========================================================================== */ - -/* - Default - ========================================================================== */ - -.sidebar { - @include clearfix(); - // @include breakpoint(max-width $large) { - // /* fix z-index order of follow links */ - // position: relative; - // z-index: 10; - // -webkit-transform: translate3d(0, 0, 0); - // transform: translate3d(0, 0, 0); - // } - - @include breakpoint($large) { - float: left; - width: calc(#{$right-sidebar-width-narrow} - 1em); - opacity: 0.75; - -webkit-transition: opacity 0.2s ease-in-out; - transition: opacity 0.2s ease-in-out; - - &:hover { - opacity: 1; - } - - &.sticky { - overflow-y: auto; - /* calculate height of nav list - viewport height - nav height - masthead x-padding - */ - max-height: calc(100vh - #{$nav-height} - 2em); - } - } - - @include breakpoint($x-large) { - width: calc(#{$right-sidebar-width} - 1em); - } - - > * { - margin-top: 1em; - margin-bottom: 1em; - } - - h2, - h3, - h4, - h5, - h6 { - margin-bottom: 0; - font-family: $sans-serif-narrow; - } - - p, - li { - font-family: $sans-serif; - font-size: $type-size-6; - line-height: 1.5; - } - - img { - width: 100%; - - &.emoji { - width: 20px; - height: 20px; - } - } -} - -.sidebar__right { - margin-bottom: 1em; - - @include breakpoint($large) { - position: absolute; - top: 0; - right: 0; - width: $right-sidebar-width-narrow; - margin-right: -1 * $right-sidebar-width-narrow; - padding-left: 1em; - z-index: 10; - - &.sticky { - @include clearfix(); - position: -webkit-sticky; - position: sticky; - top: 2em; - float: right; - - .toc { - .toc__menu { - overflow-y: auto; - max-height: calc(100vh - 7em); - } - } - } - } - - @include breakpoint($x-large) { - width: $right-sidebar-width; - margin-right: -1 * $right-sidebar-width; - } -} - -.splash .sidebar__right { - @include breakpoint($large) { - position: relative; - float: right; - margin-right: 0; - } - - @include breakpoint($x-large) { - margin-right: 0; - } -} - -/* - Author profile and links - ========================================================================== */ - -.author__avatar { - display: table-cell; - vertical-align: top; - width: 36px; - height: 36px; - - @include breakpoint($large) { - display: block; - width: auto; - height: auto; - } - - img { - max-width: 110px; - border-radius: 50%; - - @include breakpoint($large) { - padding: 5px; - border: 1px solid $border-color; - } - } -} - -.author__content { - display: table-cell; - vertical-align: top; - padding-left: 15px; - padding-right: 25px; - line-height: 1; - - @include breakpoint($large) { - display: block; - width: 100%; - padding-left: 0; - padding-right: 0; - } - - a { - color: inherit; - text-decoration: none; - } -} - -.author__name { - margin: 0; - - @include breakpoint($large) { - margin-top: 10px; - margin-bottom: 10px; - } -} -.sidebar .author__name { - font-family: $sans-serif; - font-size: $type-size-5; -} - -.author__bio { - margin: 0; - - @include breakpoint($large) { - margin-top: 10px; - margin-bottom: 20px; - } -} - -.author__urls-wrapper { - position: relative; - display: table-cell; - vertical-align: middle; - font-family: $sans-serif; - z-index: 20; - cursor: pointer; - - li:last-child { - a { - margin-bottom: 0; - } - } - - .author__urls { - span.label { - padding-left: 5px; - } - } - - @include breakpoint($large) { - display: block; - } - - button { - position: relative; - margin-bottom: 0; - - &:before { - @supports (pointer-events: none) { - content: ''; - position: fixed; - top: 0; - left: 0; - width: 100%; - height: 100%; - pointer-events: none; - } - } - - &.open { - &:before { - pointer-events: auto; - } - } - - @include breakpoint($large) { - display: none; - } - } -} - -.author__urls { - display: none; - position: absolute; - right: 0; - margin-top: 15px; - padding: 10px; - list-style-type: none; - border: 1px solid $border-color; - border-radius: $border-radius; - background: $background-color; - box-shadow: 0 2px 4px 0 rgba(#000, 0.16), 0 2px 10px 0 rgba(#000, 0.12); - cursor: default; - - &.is--visible { - display: block; - } - - @include breakpoint($large) { - display: block; - position: relative; - margin: 0; - padding: 0; - border: 0; - background: transparent; - box-shadow: none; - } - - &:before { - display: block; - content: ""; - position: absolute; - top: -11px; - left: calc(50% - 10px); - width: 0; - border-style: solid; - border-width: 0 10px 10px; - border-color: $border-color transparent; - z-index: 0; - - @include breakpoint($large) { - display: none; - } - } - - &:after { - display: block; - content: ""; - position: absolute; - top: -10px; - left: calc(50% - 10px); - width: 0; - border-style: solid; - border-width: 0 10px 10px; - border-color: $background-color transparent; - z-index: 1; - - @include breakpoint($large) { - display: none; - } - } - - ul { - padding: 10px; - list-style-type: none; - } - - li { - white-space: nowrap; - } - - a { - display: block; - margin-bottom: 5px; - padding-right: 5px; - padding-top: 2px; - padding-bottom: 2px; - color: inherit; - font-size: $type-size-5; - text-decoration: none; - - &:hover { - text-decoration: underline; - } - } -} - -/* - Wide Pages - ========================================================================== */ - -.wide .sidebar__right { - margin-bottom: 1em; - - @include breakpoint($large) { - position: initial; - top: initial; - right: initial; - width: initial; - margin-right: initial; - padding-left: initial; - z-index: initial; - - &.sticky { - float: none; - } - } - - @include breakpoint($x-large) { - width: initial; - margin-right: initial; - } -} - diff --git a/docs/_sass/minimal-mistakes/_syntax.scss b/docs/_sass/minimal-mistakes/_syntax.scss deleted file mode 100644 index 726520202b..0000000000 --- a/docs/_sass/minimal-mistakes/_syntax.scss +++ /dev/null @@ -1,324 +0,0 @@ -/* ========================================================================== - Syntax highlighting - ========================================================================== */ - -div.highlighter-rouge, -figure.highlight { - position: relative; - margin-bottom: 1em; - background: $base00; - color: $base05; - font-family: $monospace; - font-size: $type-size-6; - line-height: 1.8; - border-radius: $border-radius; - - > pre, - pre.highlight { - margin: 0; - padding: 1em; - } -} - -.highlight table { - margin-bottom: 0; - font-size: 1em; - border: 0; - - td { - padding: 0; - width: calc(100% - 1em); - border: 0; - - /* line numbers*/ - &.gutter, - &.rouge-gutter { - padding-right: 1em; - width: 1em; - color: $base04; - border-right: 1px solid $base04; - text-align: right; - } - - /* code */ - &.code, - &.rouge-code { - padding-left: 1em; - } - } - - pre { - margin: 0; - } -} - -.highlight pre { - width: 100%; -} - -.highlight .hll { - background-color: $base06; -} -.highlight { - .c { - /* Comment */ - color: $base04; - } - .err { - /* Error */ - color: $base08; - } - .k { - /* Keyword */ - color: $base0e; - } - .l { - /* Literal */ - color: $base09; - } - .n { - /* Name */ - color: $base05; - } - .o { - /* Operator */ - color: $base0c; - } - .p { - /* Punctuation */ - color: $base05; - } - .cm { - /* Comment.Multiline */ - color: $base04; - } - .cp { - /* Comment.Preproc */ - color: $base04; - } - .c1 { - /* Comment.Single */ - color: $base04; - } - .cs { - /* Comment.Special */ - color: $base04; - } - .gd { - /* Generic.Deleted */ - color: $base08; - } - .ge { - /* Generic.Emph */ - font-style: italic; - } - .gh { - /* Generic.Heading */ - color: $base05; - font-weight: bold; - } - .gi { - /* Generic.Inserted */ - color: $base0b; - } - .gp { - /* Generic.Prompt */ - color: $base04; - font-weight: bold; - } - .gs { - /* Generic.Strong */ - font-weight: bold; - } - .gu { - /* Generic.Subheading */ - color: $base0c; - font-weight: bold; - } - .kc { - /* Keyword.Constant */ - color: $base0e; - } - .kd { - /* Keyword.Declaration */ - color: $base0e; - } - .kn { - /* Keyword.Namespace */ - color: $base0c; - } - .kp { - /* Keyword.Pseudo */ - color: $base0e; - } - .kr { - /* Keyword.Reserved */ - color: $base0e; - } - .kt { - /* Keyword.Type */ - color: $base0a; - } - .ld { - /* Literal.Date */ - color: $base0b; - } - .m { - /* Literal.Number */ - color: $base09; - } - .s { - /* Literal.String */ - color: $base0b; - } - .na { - /* Name.Attribute */ - color: $base0d; - } - .nb { - /* Name.Builtin */ - color: $base05; - } - .nc { - /* Name.Class */ - color: $base0a; - } - .no { - /* Name.Constant */ - color: $base08; - } - .nd { - /* Name.Decorator */ - color: $base0c; - } - .ni { - /* Name.Entity */ - color: $base05; - } - .ne { - /* Name.Exception */ - color: $base08; - } - .nf { - /* Name.Function */ - color: $base0d; - } - .nl { - /* Name.Label */ - color: $base05; - } - .nn { - /* Name.Namespace */ - color: $base0a; - } - .nx { - /* Name.Other */ - color: $base0d; - } - .py { - /* Name.Property */ - color: $base05; - } - .nt { - /* Name.Tag */ - color: $base0c; - } - .nv { - /* Name.Variable */ - color: $base08; - } - .ow { - /* Operator.Word */ - color: $base0c; - } - .w { - /* Text.Whitespace */ - color: $base05; - } - .mf { - /* Literal.Number.Float */ - color: $base09; - } - .mh { - /* Literal.Number.Hex */ - color: $base09; - } - .mi { - /* Literal.Number.Integer */ - color: $base09; - } - .mo { - /* Literal.Number.Oct */ - color: $base09; - } - .sb { - /* Literal.String.Backtick */ - color: $base0b; - } - .sc { - /* Literal.String.Char */ - color: $base05; - } - .sd { - /* Literal.String.Doc */ - color: $base04; - } - .s2 { - /* Literal.String.Double */ - color: $base0b; - } - .se { - /* Literal.String.Escape */ - color: $base09; - } - .sh { - /* Literal.String.Heredoc */ - color: $base0b; - } - .si { - /* Literal.String.Interpol */ - color: $base09; - } - .sx { - /* Literal.String.Other */ - color: $base0b; - } - .sr { - /* Literal.String.Regex */ - color: $base0b; - } - .s1 { - /* Literal.String.Single */ - color: $base0b; - } - .ss { - /* Literal.String.Symbol */ - color: $base0b; - } - .bp { - /* Name.Builtin.Pseudo */ - color: $base05; - } - .vc { - /* Name.Variable.Class */ - color: $base08; - } - .vg { - /* Name.Variable.Global */ - color: $base08; - } - .vi { - /* Name.Variable.Instance */ - color: $base08; - } - .il { - /* Literal.Number.Integer.Long */ - color: $base09; - } -} - -.gist { - th, td { - border-bottom: 0; - } -} \ No newline at end of file diff --git a/docs/_sass/minimal-mistakes/_tables.scss b/docs/_sass/minimal-mistakes/_tables.scss deleted file mode 100644 index c270a775bf..0000000000 --- a/docs/_sass/minimal-mistakes/_tables.scss +++ /dev/null @@ -1,39 +0,0 @@ -/* ========================================================================== - TABLES - ========================================================================== */ - -table { - display: block; - margin-bottom: 1em; - width: 100%; - font-family: $global-font-family; - font-size: $type-size-6; - border-collapse: collapse; - overflow-x: auto; - - & + table { - margin-top: 1em; - } -} - -thead { - background-color: $border-color; - border-bottom: 2px solid mix(#000, $border-color, 25%); -} - -th { - padding: 0.5em; - font-weight: bold; - text-align: left; -} - -td { - padding: 0.5em; - border-bottom: 1px solid mix(#000, $border-color, 25%); -} - -tr, -td, -th { - vertical-align: middle; -} \ No newline at end of file diff --git a/docs/_sass/minimal-mistakes/_utilities.scss b/docs/_sass/minimal-mistakes/_utilities.scss deleted file mode 100644 index 1c127d3664..0000000000 --- a/docs/_sass/minimal-mistakes/_utilities.scss +++ /dev/null @@ -1,593 +0,0 @@ -/* ========================================================================== - UTILITY CLASSES - ========================================================================== */ - -/* - Visibility - ========================================================================== */ - -/* http://www.456bereastreet.com/archive/200711/screen_readers_sometimes_ignore_displaynone/ */ - -.hidden, -.is--hidden { - display: none; - visibility: hidden; -} - -/* for preloading images */ - -.load { - display: none; -} - -.transparent { - opacity: 0; -} - -/* https://developer.yahoo.com/blogs/ydn/clip-hidden-content-better-accessibility-53456.html */ - -.visually-hidden, -.screen-reader-text, -.screen-reader-text span, -.screen-reader-shortcut { - position: absolute !important; - clip: rect(1px, 1px, 1px, 1px); - height: 1px !important; - width: 1px !important; - border: 0 !important; - overflow: hidden; -} - -body:hover .visually-hidden a, -body:hover .visually-hidden input, -body:hover .visually-hidden button { - display: none !important; -} - -/* screen readers */ - -.screen-reader-text:focus, -.screen-reader-shortcut:focus { - clip: auto !important; - height: auto !important; - width: auto !important; - display: block; - font-size: 1em; - font-weight: bold; - padding: 15px 23px 14px; - background: #fff; - z-index: 100000; - text-decoration: none; - box-shadow: 0 0 2px 2px rgba(0, 0, 0, 0.6); -} - -/* - Skip links - ========================================================================== */ - -.skip-link { - position: fixed; - z-index: 20; - margin: 0; - font-family: $sans-serif; - white-space: nowrap; -} - -.skip-link li { - height: 0; - width: 0; - list-style: none; -} - -/* - Type - ========================================================================== */ - -.text-left { - text-align: left; -} - -.text-center { - text-align: center; -} - -.text-right { - text-align: right; -} - -.text-justify { - text-align: justify; -} - -.text-nowrap { - white-space: nowrap; -} - -/* - Task lists - ========================================================================== */ - -.task-list { - padding:0; - - li { - list-style-type: none; - } - - .task-list-item-checkbox { - margin-right: 0.5em; - opacity: 1; - } -} - -.task-list .task-list { - margin-left: 1em; -} - -/* - Alignment - ========================================================================== */ - -/* clearfix */ - -.cf { - clear: both; -} - -.wrapper { - margin-left: auto; - margin-right: auto; - width: 100%; -} - -/* - Images - ========================================================================== */ - -/* image align left */ - -.align-left { - display: block; - margin-left: auto; - margin-right: auto; - - @include breakpoint($small) { - float: left; - margin-right: 1em; - } -} - -/* image align right */ - -.align-right { - display: block; - margin-left: auto; - margin-right: auto; - - @include breakpoint($small) { - float: right; - margin-left: 1em; - } -} - -/* image align center */ - -.align-center { - display: block; - margin-left: auto; - margin-right: auto; -} - -/* file page content container */ - -.full { - @include breakpoint($large) { - margin-right: -1 * span(2.5 of 12) !important; - } -} - -/* - Icons - ========================================================================== */ - -.icon { - display: inline-block; - fill: currentColor; - width: 1em; - height: 1.1em; - line-height: 1; - position: relative; - top: -0.1em; - vertical-align: middle; -} - -/* social icons*/ - -.social-icons { - .fas, - .fab, - .far, - .fal { - color: $text-color; - } - - .fa-behance, - .fa-behance-square { - color: $behance-color; - } - - .fa-bitbucket { - color: $bitbucket-color; - } - - .fa-dribbble, - .fa-dribble-square { - color: $dribbble-color; - } - - .fa-facebook, - .fa-facebook-square, - .fa-facebook-f { - color: $facebook-color; - } - - .fa-flickr { - color: $flickr-color; - } - - .fa-foursquare { - color: $foursquare-color; - } - - .fa-github, - .fa-github-alt, - .fa-github-square { - color: $github-color; - } - - .fa-gitlab { - color: $gitlab-color; - } - - .fa-instagram { - color: $instagram-color; - } - - .fa-keybase { - color: $keybase-color; - } - - .fa-lastfm, - .fa-lastfm-square { - color: $lastfm-color; - } - - .fa-linkedin, - .fa-linkedin-in { - color: $linkedin-color; - } - - .fa-mastodon, - .fa-mastodon-square { - color: $mastodon-color; - } - - .fa-pinterest, - .fa-pinterest-p, - .fa-pinterest-square { - color: $pinterest-color; - } - - .fa-reddit { - color: $reddit-color; - } - - .fa-rss, - .fa-rss-square { - color: $rss-color; - } - - .fa-soundcloud { - color: $soundcloud-color; - } - - .fa-stack-exchange, - .fa-stack-overflow { - color: $stackoverflow-color; - } - - .fa-tumblr, - .fa-tumblr-square { - color: $tumblr-color; - } - - .fa-twitter, - .fa-twitter-square { - color: $twitter-color; - } - - .fa-vimeo, - .fa-vimeo-square, - .fa-vimeo-v { - color: $vimeo-color; - } - - .fa-vine { - color: $vine-color; - } - - .fa-youtube { - color: $youtube-color; - } - - .fa-xing, - .fa-xing-square { - color: $xing-color; - } -} - -/* - Navicons - ========================================================================== */ - -.navicon { - position: relative; - width: $navicon-width; - height: $navicon-height; - background: $primary-color; - margin: auto; - -webkit-transition: 0.3s; - transition: 0.3s; - - &:before, - &:after { - content: ""; - position: absolute; - left: 0; - width: $navicon-width; - height: $navicon-height; - background: $primary-color; - -webkit-transition: 0.3s; - transition: 0.3s; - } - - &:before { - top: (-2 * $navicon-height); - } - - &:after { - bottom: (-2 * $navicon-height); - } -} - -.close .navicon { - /* hide the middle line*/ - background: transparent; - - /* overlay the lines by setting both their top values to 0*/ - &:before, - &:after { - -webkit-transform-origin: 50% 50%; - -ms-transform-origin: 50% 50%; - transform-origin: 50% 50%; - top: 0; - width: $navicon-width; - } - - /* rotate the lines to form the x shape*/ - &:before { - -webkit-transform: rotate3d(0, 0, 1, 45deg); - transform: rotate3d(0, 0, 1, 45deg); - } - &:after { - -webkit-transform: rotate3d(0, 0, 1, -45deg); - transform: rotate3d(0, 0, 1, -45deg); - } -} - -.greedy-nav__toggle { - &:before { - @supports (pointer-events: none) { - content: ''; - position: fixed; - top: 0; - left: 0; - width: 100%; - height: 100%; - opacity: 0; - background-color: $background-color; - -webkit-transition: $global-transition; - transition: $global-transition; - pointer-events: none; - } - } - - &.close { - &:before { - opacity: 0.9; - -webkit-transition: $global-transition; - transition: $global-transition; - pointer-events: auto; - } - } -} - -.greedy-nav__toggle:hover { - .navicon, - .navicon:before, - .navicon:after { - background: mix(#000, $primary-color, 25%); - } - - &.close { - .navicon { - background: transparent; - } - } -} - -/* - Sticky, fixed to top content - ========================================================================== */ - -.sticky { - @include breakpoint($large) { - @include clearfix(); - position: -webkit-sticky; - position: sticky; - top: 2em; - - > * { - display: block; - } - } -} - -/* - Wells - ========================================================================== */ - -.well { - min-height: 20px; - padding: 19px; - margin-bottom: 20px; - background-color: #f5f5f5; - border: 1px solid #e3e3e3; - border-radius: $border-radius; - box-shadow: inset 0 1px 1px rgba(0, 0, 0, 0.05); -} - -/* - Modals - ========================================================================== */ - -.show-modal { - overflow: hidden; - position: relative; - - &:before { - position: absolute; - content: ""; - top: 0; - left: 0; - width: 100%; - height: 100%; - z-index: 999; - background-color: rgba(255, 255, 255, 0.85); - } - - .modal { - display: block; - } -} - -.modal { - display: none; - position: fixed; - width: 300px; - top: 50%; - left: 50%; - margin-left: -150px; - margin-top: -150px; - min-height: 0; - z-index: 9999; - background: #fff; - border: 1px solid $border-color; - border-radius: $border-radius; - box-shadow: $box-shadow; - - &__title { - margin: 0; - padding: 0.5em 1em; - } - - &__supporting-text { - padding: 0 1em 0.5em 1em; - } - - &__actions { - padding: 0.5em 1em; - border-top: 1px solid $border-color; - } -} - -/* - Footnotes - ========================================================================== */ - -.footnote { - color: mix(#fff, $gray, 25%); - text-decoration: none; -} - -.footnotes { - color: mix(#fff, $gray, 25%); - - ol, - li, - p { - margin-bottom: 0; - font-size: $type-size-6; - } -} - -a.reversefootnote { - color: $gray; - text-decoration: none; - - &:hover { - text-decoration: underline; - } -} - -/* - Required - ========================================================================== */ - -.required { - color: $danger-color; - font-weight: bold; -} - -/* - Google Custom Search Engine - ========================================================================== */ - -.gsc-control-cse { - table, - tr, - td { - border: 0; /* remove table borders widget */ - } -} - -/* - Responsive Video Embed - ========================================================================== */ - -.responsive-video-container { - position: relative; - margin-bottom: 1em; - padding-bottom: 56.25%; - height: 0; - overflow: hidden; - max-width: 100%; - - iframe, - object, - embed { - position: absolute; - top: 0; - left: 0; - width: 100%; - height: 100%; - } -} - -// full screen video fixes -:-webkit-full-screen-ancestor { - .masthead, - .page__footer { - position: static; - } -} diff --git a/docs/_sass/minimal-mistakes/_variables.scss b/docs/_sass/minimal-mistakes/_variables.scss deleted file mode 100644 index 81a3acf7b8..0000000000 --- a/docs/_sass/minimal-mistakes/_variables.scss +++ /dev/null @@ -1,173 +0,0 @@ -/* ========================================================================== - Variables - ========================================================================== */ - -/* - Typography - ========================================================================== */ - -$doc-font-size: 16 !default; - -/* paragraph indention */ -$paragraph-indent: false !default; // true, false (default) -$indent-var: 1.3em !default; - -/* system typefaces */ -$serif: Georgia, Times, serif !default; -$sans-serif: -apple-system, BlinkMacSystemFont, "Roboto", "Segoe UI", - "Helvetica Neue", "Lucida Grande", Arial, sans-serif !default; -$monospace: Monaco, Consolas, "Lucida Console", monospace !default; - -/* sans serif typefaces */ -$sans-serif-narrow: $sans-serif !default; -$helvetica: Helvetica, "Helvetica Neue", Arial, sans-serif !default; - -/* serif typefaces */ -$georgia: Georgia, serif !default; -$times: Times, serif !default; -$bodoni: "Bodoni MT", serif !default; -$calisto: "Calisto MT", serif !default; -$garamond: Garamond, serif !default; - -$global-font-family: $sans-serif !default; -$header-font-family: $sans-serif !default; -$caption-font-family: $serif !default; - -/* type scale */ -$type-size-1: 2.441em !default; // ~39.056px -$type-size-2: 1.953em !default; // ~31.248px -$type-size-3: 1.563em !default; // ~25.008px -$type-size-4: 1.25em !default; // ~20px -$type-size-5: 1em !default; // ~16px -$type-size-6: 0.75em !default; // ~12px -$type-size-7: 0.6875em !default; // ~11px -$type-size-8: 0.625em !default; // ~10px - -/* headline scale */ -$h-size-1: 1.563em !default; // ~25.008px -$h-size-2: 1.25em !default; // ~20px -$h-size-3: 1.125em !default; // ~18px -$h-size-4: 1.0625em !default; // ~17px -$h-size-5: 1.03125em !default; // ~16.5px -$h-size-6: 1em !default; // ~16px - -/* - Colors - ========================================================================== */ - -$gray: #7a8288 !default; -$dark-gray: mix(#000, $gray, 50%) !default; -$darker-gray: mix(#000, $gray, 60%) !default; -$light-gray: mix(#fff, $gray, 50%) !default; -$lighter-gray: mix(#fff, $gray, 90%) !default; - -$background-color: #fff !default; -$code-background-color: #fafafa !default; -$code-background-color-dark: $light-gray !default; -$text-color: $dark-gray !default; -$muted-text-color: mix(#fff, $text-color, 20%) !default; -$border-color: $lighter-gray !default; -$form-background-color: $lighter-gray !default; -$footer-background-color: $lighter-gray !default; - -$primary-color: #6f777d !default; -$success-color: #3fa63f !default; -$warning-color: #d67f05 !default; -$danger-color: #ee5f5b !default; -$info-color: #3b9cba !default; -$focus-color: $primary-color !default; -$active-color: mix(#fff, $primary-color, 80%) !default; - -/* YIQ color contrast */ -$yiq-contrasted-dark-default: $dark-gray !default; -$yiq-contrasted-light-default: #fff !default; -$yiq-contrasted-threshold: 175 !default; -$yiq-debug: false !default; - -/* brands */ -$behance-color: #1769ff !default; -$bitbucket-color: #205081 !default; -$dribbble-color: #ea4c89 !default; -$facebook-color: #3b5998 !default; -$flickr-color: #ff0084 !default; -$foursquare-color: #0072b1 !default; -$github-color: #171516 !default; -$gitlab-color: #e24329 !default; -$instagram-color: #517fa4 !default; -$keybase-color: #ef7639 !default; -$lastfm-color: #d51007 !default; -$linkedin-color: #007bb6 !default; -$mastodon-color: #2b90d9 !default; -$pinterest-color: #cb2027 !default; -$reddit-color: #ff4500 !default; -$rss-color: #fa9b39 !default; -$soundcloud-color: #ff3300 !default; -$stackoverflow-color: #fe7a15 !default; -$tumblr-color: #32506d !default; -$twitter-color: #55acee !default; -$vimeo-color: #1ab7ea !default; -$vine-color: #00bf8f !default; -$youtube-color: #bb0000 !default; -$xing-color: #006567 !default; - -/* links */ -$link-color: mix(#000, $info-color, 20%) !default; -$link-color-hover: mix(#000, $link-color, 25%) !default; -$link-color-visited: mix(#fff, $link-color, 15%) !default; -$masthead-link-color: $primary-color !default; -$masthead-link-color-hover: mix(#000, $primary-color, 25%) !default; -$navicon-link-color-hover: mix(#fff, $primary-color, 75%) !default; - -/* notices */ -$notice-background-mix: 80% !default; -$code-notice-background-mix: 90% !default; - -/* syntax highlighting (base16) */ -$base00: #263238 !default; -$base01: #2e3c43 !default; -$base02: #314549 !default; -$base03: #546e7a !default; -$base04: #b2ccd6 !default; -$base05: #eeffff !default; -$base06: #eeffff !default; -$base07: #ffffff !default; -$base08: #f07178 !default; -$base09: #f78c6c !default; -$base0a: #ffcb6b !default; -$base0b: #c3e88d !default; -$base0c: #89ddff !default; -$base0d: #82aaff !default; -$base0e: #c792ea !default; -$base0f: #ff5370 !default; - -/* - Breakpoints - ========================================================================== */ - -$small: 600px !default; -$medium: 768px !default; -$medium-wide: 900px !default; -$large: 1024px !default; -$x-large: 1280px !default; -$max-width: $x-large !default; - -/* - Grid - ========================================================================== */ - -$right-sidebar-width-narrow: 200px !default; -$right-sidebar-width: 300px !default; -$right-sidebar-width-wide: 400px !default; - -/* - Other - ========================================================================== */ - -$border-radius: 4px !default; -$box-shadow: 0 1px 1px rgba(0, 0, 0, 0.125) !default; -$nav-height: 2em !default; -$nav-toggle-height: 2rem !default; -$navicon-width: 1.5rem !default; -$navicon-height: 0.25rem !default; -$global-transition: all 0.2s ease-in-out !default; -$intro-transition: intro 0.3s both !default; diff --git a/docs/_sass/minimal-mistakes/skins/_air.scss b/docs/_sass/minimal-mistakes/skins/_air.scss deleted file mode 100644 index 0e5360c331..0000000000 --- a/docs/_sass/minimal-mistakes/skins/_air.scss +++ /dev/null @@ -1,23 +0,0 @@ -/* ========================================================================== - Air skin - ========================================================================== */ - -/* Colors */ -$background-color: #eeeeee !default; -$text-color: #222831 !default; -$muted-text-color: #393e46 !default; -$primary-color: #0092ca !default; -$border-color: mix(#fff, #393e46, 75%) !default; -$footer-background-color: $primary-color !default; -$link-color: #393e46 !default; -$masthead-link-color: $text-color !default; -$masthead-link-color-hover: $text-color !default; -$navicon-link-color-hover: mix(#fff, $text-color, 80%) !default; - -.page__footer { - color: #fff !important; // override -} - -.page__footer-follow .social-icons .svg-inline--fa { - color: inherit; -} diff --git a/docs/_sass/minimal-mistakes/skins/_aqua.scss b/docs/_sass/minimal-mistakes/skins/_aqua.scss deleted file mode 100644 index 7c3944e071..0000000000 --- a/docs/_sass/minimal-mistakes/skins/_aqua.scss +++ /dev/null @@ -1,34 +0,0 @@ -/* ========================================================================== - Aqua skin - ========================================================================== */ - -/* Colors */ -$gray : #1976d2 !default; -$dark-gray : mix(#000, $gray, 40%) !default; -$darker-gray : mix(#000, $gray, 60%) !default; -$light-gray : mix(#fff, $gray, 50%) !default; -$lighter-gray : mix(#fff, $gray, 90%) !default; - -$body-color : #fff !default; -$background-color : #f0fff0 !default; -$code-background-color : $lighter-gray !default; -$code-background-color-dark : $light-gray !default; -$text-color : $dark-gray !default; -$border-color : $lighter-gray !default; - -$primary-color : $gray !default; -$success-color : #27ae60 !default; -$warning-color : #e67e22 !default; -$danger-color : #c0392b !default; -$info-color : #03a9f4 !default; - -/* links */ -$link-color : $info-color !default; -$link-color-hover : mix(#000, $link-color, 25%) !default; -$link-color-visited : mix(#fff, $link-color, 25%) !default; -$masthead-link-color : $primary-color !default; -$masthead-link-color-hover : mix(#000, $primary-color, 25%) !default; - -/* notices */ -$notice-background-mix: 90% !default; -$code-notice-background-mix: 95% !default; diff --git a/docs/_sass/minimal-mistakes/skins/_contrast.scss b/docs/_sass/minimal-mistakes/skins/_contrast.scss deleted file mode 100644 index 38283b8f6f..0000000000 --- a/docs/_sass/minimal-mistakes/skins/_contrast.scss +++ /dev/null @@ -1,52 +0,0 @@ -/* ========================================================================== - Contrast skin - ========================================================================== */ - -/* Colors */ -$text-color: #000 !default; -$muted-text-color: $text-color !default; -$primary-color: #ff0000 !default; -$border-color: mix(#fff, $text-color, 75%) !default; -$footer-background-color: #000 !default; -$link-color: #0000ff !default; -$masthead-link-color: $text-color !default; -$masthead-link-color-hover: $text-color !default; -$navicon-link-color-hover: mix(#fff, $text-color, 80%) !default; - -/* contrast syntax highlighting (base16) */ -$base00: #000000 !default; -$base01: #242422 !default; -$base02: #484844 !default; -$base03: #6c6c66 !default; -$base04: #918f88 !default; -$base05: #b5b3aa !default; -$base06: #d9d7cc !default; -$base07: #fdfbee !default; -$base08: #ff6c60 !default; -$base09: #e9c062 !default; -$base0a: #ffffb6 !default; -$base0b: #a8ff60 !default; -$base0c: #c6c5fe !default; -$base0d: #96cbfe !default; -$base0e: #ff73fd !default; -$base0f: #b18a3d !default; - -.page__content { - .notice, - .notice--primary, - .notice--info, - .notice--warning, - .notice--success, - .notice--danger { - color: $text-color; - } -} - -.page__footer { - color: #fff !important; // override -} - -.page__footer-follow .social-icons i, -.page__footer-follow .social-icons .svg-inline--fa { - color: inherit; -} diff --git a/docs/_sass/minimal-mistakes/skins/_dark.scss b/docs/_sass/minimal-mistakes/skins/_dark.scss deleted file mode 100644 index 3805349377..0000000000 --- a/docs/_sass/minimal-mistakes/skins/_dark.scss +++ /dev/null @@ -1,30 +0,0 @@ -/* ========================================================================== - Dark skin - ========================================================================== */ - -/* Colors */ -$background-color: #252a34 !default; -$text-color: #eaeaea !default; -$primary-color: #00adb5 !default; -$border-color: mix(#fff, $background-color, 20%) !default; -$code-background-color: mix(#000, $background-color, 15%) !default; -$code-background-color-dark: mix(#000, $background-color, 20%) !default; -$form-background-color: mix(#000, $background-color, 15%) !default; -$footer-background-color: mix(#000, $background-color, 30%) !default; -$link-color: mix($primary-color, $text-color, 40%) !default; -$link-color-hover: mix(#fff, $link-color, 25%) !default; -$link-color-visited: mix(#000, $link-color, 25%) !default; -$masthead-link-color: $text-color !default; -$masthead-link-color-hover: mix(#000, $text-color, 20%) !default; -$navicon-link-color-hover: mix(#000, $background-color, 30%) !default; - -.author__urls.social-icons i, -.author__urls.social-icons .svg-inline--fa, -.page__footer-follow .social-icons i, -.page__footer-follow .social-icons .svg-inline--fa { - color: inherit; -} - -.ais-search-box .ais-search-box--input { - background-color: $form-background-color; -} diff --git a/docs/_sass/minimal-mistakes/skins/_default.scss b/docs/_sass/minimal-mistakes/skins/_default.scss deleted file mode 100644 index 7489b58473..0000000000 --- a/docs/_sass/minimal-mistakes/skins/_default.scss +++ /dev/null @@ -1,5 +0,0 @@ -/* ========================================================================== - Default skin - ========================================================================== */ - -// Intentionally left blank diff --git a/docs/_sass/minimal-mistakes/skins/_dirt.scss b/docs/_sass/minimal-mistakes/skins/_dirt.scss deleted file mode 100644 index 5090f559da..0000000000 --- a/docs/_sass/minimal-mistakes/skins/_dirt.scss +++ /dev/null @@ -1,33 +0,0 @@ -/* ========================================================================== - Dirt skin - ========================================================================== */ - -/* Colors */ -$background-color: #f3f3f3 !default; -$text-color: #343434 !default; -$muted-text-color: #8e8b82 !default; -$primary-color: #343434 !default; -$border-color: #e9dcbe !default; -$footer-background-color: #e9dcbe !default; -$link-color: #343434 !default; -$masthead-link-color: $text-color !default; -$masthead-link-color-hover: $text-color !default; -$navicon-link-color-hover: mix(#fff, $text-color, 80%) !default; - -/* dirt syntax highlighting (base16) */ -$base00: #231e18 !default; -$base01: #302b25 !default; -$base02: #48413a !default; -$base03: #9d8b70 !default; -$base04: #b4a490 !default; -$base05: #cabcb1 !default; -$base06: #d7c8bc !default; -$base07: #e4d4c8 !default; -$base08: #d35c5c !default; -$base09: #ca7f32 !default; -$base0a: #e0ac16 !default; -$base0b: #b7ba53 !default; -$base0c: #6eb958 !default; -$base0d: #88a4d3 !default; -$base0e: #bb90e2 !default; -$base0f: #b49368 !default; diff --git a/docs/_sass/minimal-mistakes/skins/_mint.scss b/docs/_sass/minimal-mistakes/skins/_mint.scss deleted file mode 100644 index 28557a3a29..0000000000 --- a/docs/_sass/minimal-mistakes/skins/_mint.scss +++ /dev/null @@ -1,24 +0,0 @@ -/* ========================================================================== - Mint skin - ========================================================================== */ - -/* Colors */ -$background-color: #f3f6f6 !default; -$text-color: #40514e !default; -$muted-text-color: #40514e !default; -$primary-color: #11999e !default; -$border-color: mix(#fff, #40514e, 75%) !default; -$footer-background-color: #30e3ca !default; -$link-color: #11999e !default; -$masthead-link-color: $text-color !default; -$masthead-link-color-hover: $text-color !default; -$navicon-link-color-hover: mix(#fff, $text-color, 80%) !default; - -.page__footer { - color: #fff !important; // override -} - -.page__footer-follow .social-icons i, -.page__footer-follow .social-icons .svg-inline--fa { - color: inherit; -} diff --git a/docs/_sass/minimal-mistakes/skins/_neon.scss b/docs/_sass/minimal-mistakes/skins/_neon.scss deleted file mode 100644 index a4f2ef5d9d..0000000000 --- a/docs/_sass/minimal-mistakes/skins/_neon.scss +++ /dev/null @@ -1,63 +0,0 @@ -/* ========================================================================== - Neon skin - ========================================================================== */ - -/* Colors */ -$background-color: #141010 !default; -$text-color: #fff6fb !default; -$primary-color: #f21368 !default; -$border-color: mix(#fff, $background-color, 20%) !default; -$code-background-color: mix(#000, $background-color, 15%) !default; -$code-background-color-dark: mix(#000, $background-color, 20%) !default; -$form-background-color: mix(#000, $background-color, 15%) !default; -$footer-background-color: mix($primary-color, #000, 10%) !default; -$link-color: $primary-color !default; -$link-color-hover: mix(#fff, $link-color, 25%) !default; -$link-color-visited: mix(#000, $link-color, 25%) !default; -$masthead-link-color: $text-color !default; -$masthead-link-color-hover: mix(#000, $text-color, 20%) !default; -$navicon-link-color-hover: mix(#000, $background-color, 30%) !default; - -/* notices */ -$notice-background-mix: 90% !default; -$code-notice-background-mix: 95% !default; - -/* neon syntax highlighting (base16) */ -$base00: #ffffff !default; -$base01: #e0e0e0 !default; -$base02: #d0d0d0 !default; -$base03: #b0b0b0 !default; -$base04: #000000 !default; -$base05: #101010 !default; -$base06: #151515 !default; -$base07: #202020 !default; -$base08: #ff0086 !default; -$base09: #fd8900 !default; -$base0a: #aba800 !default; -$base0b: #00c918 !default; -$base0c: #1faaaa !default; -$base0d: #3777e6 !default; -$base0e: #ad00a1 !default; -$base0f: #cc6633 !default; - -.author__urls.social-icons i, -.author__urls.social-icons .svg-inline--fa, -.page__footer-follow .social-icons i, -.page__footer-follow .social-icons .svg-inline--fa { - color: inherit; -} - -/* next/previous buttons */ -.pagination--pager { - color: $text-color; - background-color: $primary-color; - border-color: transparent; - - &:visited { - color: $text-color; - } -} - -.ais-search-box .ais-search-box--input { - background-color: $form-background-color; -} \ No newline at end of file diff --git a/docs/_sass/minimal-mistakes/skins/_plum.scss b/docs/_sass/minimal-mistakes/skins/_plum.scss deleted file mode 100644 index defa69cde7..0000000000 --- a/docs/_sass/minimal-mistakes/skins/_plum.scss +++ /dev/null @@ -1,70 +0,0 @@ -/* ========================================================================== - Plum skin - ========================================================================== */ - -/* Colors */ -$background-color: #521477 !default; -$text-color: #fffd86 !default; -$primary-color: #c327ab !default; -$border-color: mix(#fff, $background-color, 20%) !default; -$code-background-color: mix(#000, $background-color, 15%) !default; -$code-background-color-dark: mix(#000, $background-color, 20%) !default; -$form-background-color: mix(#000, $background-color, 15%) !default; -$footer-background-color: mix(#000, $background-color, 25%) !default; -$link-color: $primary-color !default; -$link-color-hover: mix(#fff, $link-color, 25%) !default; -$link-color-visited: mix(#000, $link-color, 25%) !default; -$masthead-link-color: $text-color !default; -$masthead-link-color-hover: mix(#000, $text-color, 20%) !default; -$navicon-link-color-hover: mix(#000, $background-color, 30%) !default; - -/* notices */ -$notice-background-mix: 70% !default; -$code-notice-background-mix: 80% !default; - -/* plum syntax highlighting (base16) */ -$base00: #ffffff !default; -$base01: #e0e0e0 !default; -$base02: #d0d0d0 !default; -$base03: #b0b0b0 !default; -$base04: #000000 !default; -$base05: #101010 !default; -$base06: #151515 !default; -$base07: #202020 !default; -$base08: #ff0086 !default; -$base09: #fd8900 !default; -$base0a: #aba800 !default; -$base0b: #00c918 !default; -$base0c: #1faaaa !default; -$base0d: #3777e6 !default; -$base0e: #ad00a1 !default; -$base0f: #cc6633 !default; - -.author__urls.social-icons i, -.author__urls.social-icons .svg-inline--fa, -.page__footer-follow .social-icons i, -.page__footer-follow .social-icons .svg-inline--fa { - color: inherit; -} - -.page__content { - a, - a:visited { - color: inherit; - } -} - -/* next/previous buttons */ -.pagination--pager { - color: $text-color; - background-color: $primary-color; - border-color: transparent; - - &:visited { - color: $text-color; - } -} - -.ais-search-box .ais-search-box--input { - background-color: $form-background-color; -} \ No newline at end of file diff --git a/docs/_sass/minimal-mistakes/skins/_sunrise.scss b/docs/_sass/minimal-mistakes/skins/_sunrise.scss deleted file mode 100644 index bc259f6d8d..0000000000 --- a/docs/_sass/minimal-mistakes/skins/_sunrise.scss +++ /dev/null @@ -1,49 +0,0 @@ -/* ========================================================================== - Sunrise skin - ========================================================================== */ - -/* Colors */ -$dark-gray: #0e2431 !default; -$background-color: #e8d5b7 !default; -$text-color: #000 !default; -$muted-text-color: $dark-gray !default; -$primary-color: #fc3a52 !default; -$border-color: mix(#000, $background-color, 20%) !default; -$code-background-color: mix(#fff, $background-color, 20%) !default; -$code-background-color-dark: mix(#000, $background-color, 10%) !default; -$form-background-color: mix(#fff, $background-color, 15%) !default; -$footer-background-color: #f9b248 !default; -$link-color: mix(#000, $primary-color, 10%) !default; -$link-color-hover: mix(#fff, $link-color, 25%) !default; -$link-color-visited: mix(#000, $link-color, 25%) !default; -$masthead-link-color: $text-color !default; -$masthead-link-color-hover: mix(#000, $text-color, 20%) !default; -$navicon-link-color-hover: mix(#000, $background-color, 30%) !default; - -/* notices */ -$notice-background-mix: 75% !default; - -/* sunrise syntax highlighting (base16) */ -$base00: #1d1f21 !default; -$base01: #282a2e !default; -$base02: #373b41 !default; -$base03: #969896 !default; -$base04: #b4b7b4 !default; -$base05: #c5c8c6 !default; -$base06: #e0e0e0 !default; -$base07: #ffffff !default; -$base08: #cc6666 !default; -$base09: #de935f !default; -$base0a: #f0c674 !default; -$base0b: #b5bd68 !default; -$base0c: #8abeb7 !default; -$base0d: #81a2be !default; -$base0e: #b294bb !default; -$base0f: #a3685a !default; - -.author__urls.social-icons i, -.author__urls.social-icons .svg-inline--fa, -.page__footer-follow .social-icons i, -.page__footer-follow .social-icons .svg-inline--fa { - color: inherit; -} diff --git a/docs/_stories/acidrain.md b/docs/_stories/acidrain.md deleted file mode 100644 index 1a3f939f81..0000000000 --- a/docs/_stories/acidrain.md +++ /dev/null @@ -1,45 +0,0 @@ ---- -title: "AcidRain" -last_modified_at: 2022-04-12 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Leverage searches that allow you to detect and investigate unusual activities that might relate to the acidrain malware including deleting of files and etc. AcidRain is an ELF MIPS malware specifically designed to wipe modems and routers. The complete list of targeted devices is unknown at this time, but WatchGuard FireBox has specifically been listed as a target. This malware is capable of wiping and deleting non-standard linux files and overwriting storage device files that might related to router, ssd card and many more. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-04-12 -- **Author**: Teoderick Contreras, Splunk -- **ID**: c68717c6-4938-434b-987c-e1ce9d516124 - -#### Narrative - -Adversaries may use this technique to maximize the impact on the target organization in operations where network wide availability interruption is the goal. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Linux Deletion Of Cron Jobs](/endpoint/linux_deletion_of_cron_jobs/) | [Data Destruction](/tags/#data-destruction), [File Deletion](/tags/#file-deletion), [Indicator Removal on Host](/tags/#indicator-removal-on-host)| Anomaly | -| [Linux Deletion Of Init Daemon Script](/endpoint/linux_deletion_of_init_daemon_script/) | [Data Destruction](/tags/#data-destruction), [File Deletion](/tags/#file-deletion), [Indicator Removal on Host](/tags/#indicator-removal-on-host)| TTP | -| [Linux Deletion Of Services](/endpoint/linux_deletion_of_services/) | [Data Destruction](/tags/#data-destruction), [File Deletion](/tags/#file-deletion), [Indicator Removal on Host](/tags/#indicator-removal-on-host)| TTP | -| [Linux High Frequency Of File Deletion In Etc Folder](/endpoint/linux_high_frequency_of_file_deletion_in_etc_folder/) | [Data Destruction](/tags/#data-destruction), [File Deletion](/tags/#file-deletion), [Indicator Removal on Host](/tags/#indicator-removal-on-host)| Anomaly | - -#### Reference - -* [https://www.sentinelone.com/labs/acidrain-a-modem-wiper-rains-down-on-europe/](https://www.sentinelone.com/labs/acidrain-a-modem-wiper-rains-down-on-europe/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/acidrain.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/active_directory_discovery.md b/docs/_stories/active_directory_discovery.md deleted file mode 100644 index a47fe11c82..0000000000 --- a/docs/_stories/active_directory_discovery.md +++ /dev/null @@ -1,133 +0,0 @@ ---- -title: "Active Directory Discovery" -last_modified_at: 2021-08-20 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Exploitation - - Reconnaissance ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Monitor for activities and techniques associated with Discovery and Reconnaissance within with Active Directory environments. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-08-20 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 8460679c-2b21-463e-b381-b813417c32f2 - -#### Narrative - -Discovery consists of techniques an adversay uses to gain knowledge about an internal environment or network. These techniques provide adversaries with situational awareness and allows them to have the necessary information before deciding how to act or who/what to target next.\ -Once an attacker obtains an initial foothold in an Active Directory environment, she is forced to engage in Discovery techniques in the initial phases of a breach to better understand and navigate the target network. Some examples include but are not limited to enumerating domain users, domain admins, computers, domain controllers, network shares, group policy objects, domain trusts, etc. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [AdsiSearcher Account Discovery](/endpoint/adsisearcher_account_discovery/) | [Domain Account](/tags/#domain-account), [Account Discovery](/tags/#account-discovery)| TTP | -| [Domain Account Discovery with Dsquery](/endpoint/domain_account_discovery_with_dsquery/) | [Domain Account](/tags/#domain-account), [Account Discovery](/tags/#account-discovery)| Hunting | -| [Domain Account Discovery With Net App](/endpoint/domain_account_discovery_with_net_app/) | [Domain Account](/tags/#domain-account), [Account Discovery](/tags/#account-discovery)| TTP | -| [Domain Account Discovery with Wmic](/endpoint/domain_account_discovery_with_wmic/) | [Domain Account](/tags/#domain-account), [Account Discovery](/tags/#account-discovery)| TTP | -| [Domain Controller Discovery with Nltest](/endpoint/domain_controller_discovery_with_nltest/) | [Remote System Discovery](/tags/#remote-system-discovery)| TTP | -| [Domain Controller Discovery with Wmic](/endpoint/domain_controller_discovery_with_wmic/) | [Remote System Discovery](/tags/#remote-system-discovery)| Hunting | -| [Domain Group Discovery with Adsisearcher](/endpoint/domain_group_discovery_with_adsisearcher/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Domain Groups](/tags/#domain-groups)| TTP | -| [Domain Group Discovery With Dsquery](/endpoint/domain_group_discovery_with_dsquery/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Domain Groups](/tags/#domain-groups)| Hunting | -| [Domain Group Discovery With Net](/endpoint/domain_group_discovery_with_net/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Domain Groups](/tags/#domain-groups)| Hunting | -| [Domain Group Discovery With Wmic](/endpoint/domain_group_discovery_with_wmic/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Domain Groups](/tags/#domain-groups)| Hunting | -| [DSQuery Domain Discovery](/endpoint/dsquery_domain_discovery/) | [Domain Trust Discovery](/tags/#domain-trust-discovery)| TTP | -| [Elevated Group Discovery With Net](/endpoint/elevated_group_discovery_with_net/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Domain Groups](/tags/#domain-groups)| TTP | -| [Elevated Group Discovery with PowerView](/endpoint/elevated_group_discovery_with_powerview/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Domain Groups](/tags/#domain-groups)| Hunting | -| [Elevated Group Discovery With Wmic](/endpoint/elevated_group_discovery_with_wmic/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Domain Groups](/tags/#domain-groups)| TTP | -| [Get ADDefaultDomainPasswordPolicy with Powershell](/endpoint/get_addefaultdomainpasswordpolicy_with_powershell/) | [Password Policy Discovery](/tags/#password-policy-discovery)| Hunting | -| [Get ADDefaultDomainPasswordPolicy with Powershell Script Block](/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block/) | [Password Policy Discovery](/tags/#password-policy-discovery)| Hunting | -| [Get ADUser with PowerShell](/endpoint/get_aduser_with_powershell/) | [Domain Account](/tags/#domain-account), [Account Discovery](/tags/#account-discovery)| Hunting | -| [Get ADUser with PowerShell Script Block](/endpoint/get_aduser_with_powershell_script_block/) | [Domain Account](/tags/#domain-account), [Account Discovery](/tags/#account-discovery)| Hunting | -| [Get ADUserResultantPasswordPolicy with Powershell](/endpoint/get_aduserresultantpasswordpolicy_with_powershell/) | [Password Policy Discovery](/tags/#password-policy-discovery)| TTP | -| [Get ADUserResultantPasswordPolicy with Powershell Script Block](/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block/) | [Password Policy Discovery](/tags/#password-policy-discovery)| TTP | -| [Get DomainPolicy with Powershell](/endpoint/get_domainpolicy_with_powershell/) | [Password Policy Discovery](/tags/#password-policy-discovery)| TTP | -| [Get DomainPolicy with Powershell Script Block](/endpoint/get_domainpolicy_with_powershell_script_block/) | [Password Policy Discovery](/tags/#password-policy-discovery)| TTP | -| [Get-DomainTrust with PowerShell](/endpoint/get-domaintrust_with_powershell/) | [Domain Trust Discovery](/tags/#domain-trust-discovery)| TTP | -| [Get-DomainTrust with PowerShell Script Block](/endpoint/get-domaintrust_with_powershell_script_block/) | [Domain Trust Discovery](/tags/#domain-trust-discovery)| TTP | -| [Get DomainUser with PowerShell](/endpoint/get_domainuser_with_powershell/) | [Domain Account](/tags/#domain-account), [Account Discovery](/tags/#account-discovery)| TTP | -| [Get DomainUser with PowerShell Script Block](/endpoint/get_domainuser_with_powershell_script_block/) | [Domain Account](/tags/#domain-account), [Account Discovery](/tags/#account-discovery)| TTP | -| [Get-ForestTrust with PowerShell](/endpoint/get-foresttrust_with_powershell/) | [Domain Trust Discovery](/tags/#domain-trust-discovery)| TTP | -| [Get-ForestTrust with PowerShell Script Block](/endpoint/get-foresttrust_with_powershell_script_block/) | [Domain Trust Discovery](/tags/#domain-trust-discovery), [PowerShell](/tags/#powershell)| TTP | -| [Get WMIObject Group Discovery](/endpoint/get_wmiobject_group_discovery/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Local Groups](/tags/#local-groups)| Hunting | -| [Get WMIObject Group Discovery with Script Block Logging](/endpoint/get_wmiobject_group_discovery_with_script_block_logging/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Local Groups](/tags/#local-groups)| Hunting | -| [GetAdComputer with PowerShell](/endpoint/getadcomputer_with_powershell/) | [Remote System Discovery](/tags/#remote-system-discovery)| Hunting | -| [GetAdComputer with PowerShell Script Block](/endpoint/getadcomputer_with_powershell_script_block/) | [Remote System Discovery](/tags/#remote-system-discovery)| Hunting | -| [GetAdGroup with PowerShell](/endpoint/getadgroup_with_powershell/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Domain Groups](/tags/#domain-groups)| Hunting | -| [GetAdGroup with PowerShell Script Block](/endpoint/getadgroup_with_powershell_script_block/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Domain Groups](/tags/#domain-groups)| Hunting | -| [GetCurrent User with PowerShell](/endpoint/getcurrent_user_with_powershell/) | [System Owner/User Discovery](/tags/#system-owner/user-discovery)| Hunting | -| [GetCurrent User with PowerShell Script Block](/endpoint/getcurrent_user_with_powershell_script_block/) | [System Owner/User Discovery](/tags/#system-owner/user-discovery)| Hunting | -| [GetDomainComputer with PowerShell](/endpoint/getdomaincomputer_with_powershell/) | [Remote System Discovery](/tags/#remote-system-discovery)| TTP | -| [GetDomainComputer with PowerShell Script Block](/endpoint/getdomaincomputer_with_powershell_script_block/) | [Remote System Discovery](/tags/#remote-system-discovery)| TTP | -| [GetDomainController with PowerShell](/endpoint/getdomaincontroller_with_powershell/) | [Remote System Discovery](/tags/#remote-system-discovery)| Hunting | -| [GetDomainController with PowerShell Script Block](/endpoint/getdomaincontroller_with_powershell_script_block/) | [Remote System Discovery](/tags/#remote-system-discovery)| TTP | -| [GetDomainGroup with PowerShell](/endpoint/getdomaingroup_with_powershell/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Domain Groups](/tags/#domain-groups)| TTP | -| [GetDomainGroup with PowerShell Script Block](/endpoint/getdomaingroup_with_powershell_script_block/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Domain Groups](/tags/#domain-groups)| TTP | -| [GetLocalUser with PowerShell](/endpoint/getlocaluser_with_powershell/) | [Account Discovery](/tags/#account-discovery), [Local Account](/tags/#local-account)| Hunting | -| [GetLocalUser with PowerShell Script Block](/endpoint/getlocaluser_with_powershell_script_block/) | [Account Discovery](/tags/#account-discovery), [Local Account](/tags/#local-account), [PowerShell](/tags/#powershell)| Hunting | -| [GetNetTcpconnection with PowerShell](/endpoint/getnettcpconnection_with_powershell/) | [System Network Connections Discovery](/tags/#system-network-connections-discovery)| Hunting | -| [GetNetTcpconnection with PowerShell Script Block](/endpoint/getnettcpconnection_with_powershell_script_block/) | [System Network Connections Discovery](/tags/#system-network-connections-discovery)| Hunting | -| [GetWmiObject Ds Computer with PowerShell](/endpoint/getwmiobject_ds_computer_with_powershell/) | [Remote System Discovery](/tags/#remote-system-discovery)| TTP | -| [GetWmiObject Ds Computer with PowerShell Script Block](/endpoint/getwmiobject_ds_computer_with_powershell_script_block/) | [Remote System Discovery](/tags/#remote-system-discovery)| TTP | -| [GetWmiObject Ds Group with PowerShell](/endpoint/getwmiobject_ds_group_with_powershell/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Domain Groups](/tags/#domain-groups)| TTP | -| [GetWmiObject Ds Group with PowerShell Script Block](/endpoint/getwmiobject_ds_group_with_powershell_script_block/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Domain Groups](/tags/#domain-groups)| TTP | -| [GetWmiObject DS User with PowerShell](/endpoint/getwmiobject_ds_user_with_powershell/) | [Domain Account](/tags/#domain-account), [Account Discovery](/tags/#account-discovery)| TTP | -| [GetWmiObject DS User with PowerShell Script Block](/endpoint/getwmiobject_ds_user_with_powershell_script_block/) | [Domain Account](/tags/#domain-account), [Account Discovery](/tags/#account-discovery)| TTP | -| [GetWmiObject User Account with PowerShell](/endpoint/getwmiobject_user_account_with_powershell/) | [Account Discovery](/tags/#account-discovery), [Local Account](/tags/#local-account)| Hunting | -| [GetWmiObject User Account with PowerShell Script Block](/endpoint/getwmiobject_user_account_with_powershell_script_block/) | [Account Discovery](/tags/#account-discovery), [Local Account](/tags/#local-account), [PowerShell](/tags/#powershell)| Hunting | -| [Local Account Discovery with Net](/endpoint/local_account_discovery_with_net/) | [Account Discovery](/tags/#account-discovery), [Local Account](/tags/#local-account)| Hunting | -| [Local Account Discovery With Wmic](/endpoint/local_account_discovery_with_wmic/) | [Account Discovery](/tags/#account-discovery), [Local Account](/tags/#local-account)| Hunting | -| [Net Localgroup Discovery](/endpoint/net_localgroup_discovery/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Local Groups](/tags/#local-groups)| Hunting | -| [Network Connection Discovery With Arp](/endpoint/network_connection_discovery_with_arp/) | [System Network Connections Discovery](/tags/#system-network-connections-discovery)| Hunting | -| [Network Connection Discovery With Net](/endpoint/network_connection_discovery_with_net/) | [System Network Connections Discovery](/tags/#system-network-connections-discovery)| Hunting | -| [Network Connection Discovery With Netstat](/endpoint/network_connection_discovery_with_netstat/) | [System Network Connections Discovery](/tags/#system-network-connections-discovery)| Hunting | -| [Network Discovery Using Route Windows App](/endpoint/network_discovery_using_route_windows_app/) | [System Network Configuration Discovery](/tags/#system-network-configuration-discovery), [Internet Connection Discovery](/tags/#internet-connection-discovery)| Hunting | -| [NLTest Domain Trust Discovery](/endpoint/nltest_domain_trust_discovery/) | [Domain Trust Discovery](/tags/#domain-trust-discovery)| TTP | -| [Password Policy Discovery with Net](/endpoint/password_policy_discovery_with_net/) | [Password Policy Discovery](/tags/#password-policy-discovery)| Hunting | -| [PowerShell Get LocalGroup Discovery](/endpoint/powershell_get_localgroup_discovery/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Local Groups](/tags/#local-groups)| Hunting | -| [Powershell Get LocalGroup Discovery with Script Block Logging](/endpoint/powershell_get_localgroup_discovery_with_script_block_logging/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Local Groups](/tags/#local-groups)| Hunting | -| [Remote System Discovery with Adsisearcher](/endpoint/remote_system_discovery_with_adsisearcher/) | [Remote System Discovery](/tags/#remote-system-discovery)| TTP | -| [Remote System Discovery with Dsquery](/endpoint/remote_system_discovery_with_dsquery/) | [Remote System Discovery](/tags/#remote-system-discovery)| Hunting | -| [Remote System Discovery with Net](/endpoint/remote_system_discovery_with_net/) | [Remote System Discovery](/tags/#remote-system-discovery)| Hunting | -| [Remote System Discovery with Wmic](/endpoint/remote_system_discovery_with_wmic/) | [Remote System Discovery](/tags/#remote-system-discovery)| TTP | -| [ServicePrincipalNames Discovery with PowerShell](/endpoint/serviceprincipalnames_discovery_with_powershell/) | [Kerberoasting](/tags/#kerberoasting)| TTP | -| [ServicePrincipalNames Discovery with SetSPN](/endpoint/serviceprincipalnames_discovery_with_setspn/) | [Kerberoasting](/tags/#kerberoasting)| TTP | -| [System User Discovery With Query](/endpoint/system_user_discovery_with_query/) | [System Owner/User Discovery](/tags/#system-owner/user-discovery)| Hunting | -| [System User Discovery With Whoami](/endpoint/system_user_discovery_with_whoami/) | [System Owner/User Discovery](/tags/#system-owner/user-discovery)| Hunting | -| [User Discovery With Env Vars PowerShell](/endpoint/user_discovery_with_env_vars_powershell/) | [System Owner/User Discovery](/tags/#system-owner/user-discovery)| Hunting | -| [User Discovery With Env Vars PowerShell Script Block](/endpoint/user_discovery_with_env_vars_powershell_script_block/) | [System Owner/User Discovery](/tags/#system-owner/user-discovery)| Hunting | -| [Windows Hidden Schedule Task Settings](/endpoint/windows_hidden_schedule_task_settings/) | [Scheduled Task/Job](/tags/#scheduled-task/job)| TTP | -| [Windows Linked Policies In ADSI Discovery](/endpoint/windows_linked_policies_in_adsi_discovery/) | [Domain Account](/tags/#domain-account), [Account Discovery](/tags/#account-discovery)| Anomaly | -| [Windows Root Domain linked policies Discovery](/endpoint/windows_root_domain_linked_policies_discovery/) | [Domain Account](/tags/#domain-account), [Account Discovery](/tags/#account-discovery)| Anomaly | -| [Wmic Group Discovery](/endpoint/wmic_group_discovery/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Local Groups](/tags/#local-groups)| Hunting | - -#### Reference - -* [https://attack.mitre.org/tactics/TA0007/](https://attack.mitre.org/tactics/TA0007/) -* [https://adsecurity.org/?p=2535](https://adsecurity.org/?p=2535) -* [https://attack.mitre.org/techniques/T1087/001/](https://attack.mitre.org/techniques/T1087/001/) -* [https://attack.mitre.org/techniques/T1087/002/](https://attack.mitre.org/techniques/T1087/002/) -* [https://attack.mitre.org/techniques/T1087/003/](https://attack.mitre.org/techniques/T1087/003/) -* [https://attack.mitre.org/techniques/T1482/](https://attack.mitre.org/techniques/T1482/) -* [https://attack.mitre.org/techniques/T1201/](https://attack.mitre.org/techniques/T1201/) -* [https://attack.mitre.org/techniques/T1069/001/](https://attack.mitre.org/techniques/T1069/001/) -* [https://attack.mitre.org/techniques/T1069/002/](https://attack.mitre.org/techniques/T1069/002/) -* [https://attack.mitre.org/techniques/T1018/](https://attack.mitre.org/techniques/T1018/) -* [https://attack.mitre.org/techniques/T1049/](https://attack.mitre.org/techniques/T1049/) -* [https://attack.mitre.org/techniques/T1033/](https://attack.mitre.org/techniques/T1033/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/active_directory_discovery.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/active_directory_kerberos_attacks.md b/docs/_stories/active_directory_kerberos_attacks.md deleted file mode 100644 index 2d9b051285..0000000000 --- a/docs/_stories/active_directory_kerberos_attacks.md +++ /dev/null @@ -1,82 +0,0 @@ ---- -title: "Active Directory Kerberos Attacks" -last_modified_at: 2022-02-02 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Network_Traffic - - Actions on Objectives - - Exploitation - - Installation - - Reconnaissance ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Monitor for activities and techniques associated with Kerberos based attacks within with Active Directory environments. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint), [Network_Traffic](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkTraffic) -- **Last Updated**: 2022-02-02 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 38b8cf16-8461-11ec-ade1-acde48001122 - -#### Narrative - -Kerberos, initially named after Cerberus, the three-headed dog in Greek mythology, is a network authentication protocol that allows computers and users to prove their identity through a trusted third-party. This trusted third-party issues Kerberos tickets using symmetric encryption to allow users access to services and network resources based on their privilege level. Kerberos is the default authentication protocol used on Windows Active Directory networks since the introduction of Windows Server 2003. With Kerberos being the backbone of Windows authentication, it is commonly abused by adversaries across the different phases of a breach including initial access, privilege escalation, defense evasion, credential access, lateral movement, etc.\ This Analytic Story groups detection use cases in which the Kerberos protocol is abused. Defenders can leverage these analytics to detect and hunt for adversaries engaging in Kerberos based attacks. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Disabled Kerberos Pre-Authentication Discovery With Get-ADUser](/endpoint/disabled_kerberos_pre-authentication_discovery_with_get-aduser/) | [Steal or Forge Kerberos Tickets](/tags/#steal-or-forge-kerberos-tickets), [AS-REP Roasting](/tags/#as-rep-roasting)| TTP | -| [Disabled Kerberos Pre-Authentication Discovery With PowerView](/endpoint/disabled_kerberos_pre-authentication_discovery_with_powerview/) | [Steal or Forge Kerberos Tickets](/tags/#steal-or-forge-kerberos-tickets), [AS-REP Roasting](/tags/#as-rep-roasting)| TTP | -| [Kerberoasting spn request with RC4 encryption](/endpoint/kerberoasting_spn_request_with_rc4_encryption/) | [Steal or Forge Kerberos Tickets](/tags/#steal-or-forge-kerberos-tickets), [Kerberoasting](/tags/#kerberoasting)| TTP | -| [Kerberos Pre-Authentication Flag Disabled in UserAccountControl](/endpoint/kerberos_pre-authentication_flag_disabled_in_useraccountcontrol/) | [Steal or Forge Kerberos Tickets](/tags/#steal-or-forge-kerberos-tickets), [AS-REP Roasting](/tags/#as-rep-roasting)| TTP | -| [Kerberos Pre-Authentication Flag Disabled with PowerShell](/endpoint/kerberos_pre-authentication_flag_disabled_with_powershell/) | [Steal or Forge Kerberos Tickets](/tags/#steal-or-forge-kerberos-tickets), [AS-REP Roasting](/tags/#as-rep-roasting)| TTP | -| [Kerberos Service Ticket Request Using RC4 Encryption](/endpoint/kerberos_service_ticket_request_using_rc4_encryption/) | [Steal or Forge Kerberos Tickets](/tags/#steal-or-forge-kerberos-tickets), [Golden Ticket](/tags/#golden-ticket)| TTP | -| [Kerberos TGT Request Using RC4 Encryption](/endpoint/kerberos_tgt_request_using_rc4_encryption/) | [Use Alternate Authentication Material](/tags/#use-alternate-authentication-material)| TTP | -| [Kerberos User Enumeration](/endpoint/kerberos_user_enumeration/) | [Gather Victim Identity Information](/tags/#gather-victim-identity-information), [Email Addresses](/tags/#email-addresses)| Anomaly | -| [Mimikatz PassTheTicket CommandLine Parameters](/endpoint/mimikatz_passtheticket_commandline_parameters/) | [Use Alternate Authentication Material](/tags/#use-alternate-authentication-material), [Pass the Ticket](/tags/#pass-the-ticket)| TTP | -| [Multiple Users Failing To Authenticate From Host Using Kerberos](/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos/) | [Password Spraying](/tags/#password-spraying), [Brute Force](/tags/#brute-force)| Anomaly | -| [PetitPotam Suspicious Kerberos TGT Request](/endpoint/petitpotam_suspicious_kerberos_tgt_request/) | [OS Credential Dumping](/tags/#os-credential-dumping)| TTP | -| [Rubeus Command Line Parameters](/endpoint/rubeus_command_line_parameters/) | [Use Alternate Authentication Material](/tags/#use-alternate-authentication-material), [Pass the Ticket](/tags/#pass-the-ticket), [Steal or Forge Kerberos Tickets](/tags/#steal-or-forge-kerberos-tickets), [Kerberoasting](/tags/#kerberoasting), [AS-REP Roasting](/tags/#as-rep-roasting)| TTP | -| [Rubeus Kerberos Ticket Exports Through Winlogon Access](/endpoint/rubeus_kerberos_ticket_exports_through_winlogon_access/) | [Use Alternate Authentication Material](/tags/#use-alternate-authentication-material), [Pass the Ticket](/tags/#pass-the-ticket)| TTP | -| [ServicePrincipalNames Discovery with PowerShell](/endpoint/serviceprincipalnames_discovery_with_powershell/) | [Kerberoasting](/tags/#kerberoasting)| TTP | -| [ServicePrincipalNames Discovery with SetSPN](/endpoint/serviceprincipalnames_discovery_with_setspn/) | [Kerberoasting](/tags/#kerberoasting)| TTP | -| [Suspicious Kerberos Service Ticket Request](/endpoint/suspicious_kerberos_service_ticket_request/) | [Valid Accounts](/tags/#valid-accounts), [Domain Accounts](/tags/#domain-accounts)| TTP | -| [Suspicious Ticket Granting Ticket Request](/endpoint/suspicious_ticket_granting_ticket_request/) | [Valid Accounts](/tags/#valid-accounts), [Domain Accounts](/tags/#domain-accounts)| Hunting | -| [Unknown Process Using The Kerberos Protocol](/endpoint/unknown_process_using_the_kerberos_protocol/) | [Use Alternate Authentication Material](/tags/#use-alternate-authentication-material)| TTP | -| [Unusual Number of Kerberos Service Tickets Requested](/endpoint/unusual_number_of_kerberos_service_tickets_requested/) | [Steal or Forge Kerberos Tickets](/tags/#steal-or-forge-kerberos-tickets), [Kerberoasting](/tags/#kerberoasting)| Anomaly | -| [Windows Computer Account Created by Computer Account](/endpoint/windows_computer_account_created_by_computer_account/) | [Steal or Forge Kerberos Tickets](/tags/#steal-or-forge-kerberos-tickets)| TTP | -| [Windows Computer Account Requesting Kerberos Ticket](/endpoint/windows_computer_account_requesting_kerberos_ticket/) | [Steal or Forge Kerberos Tickets](/tags/#steal-or-forge-kerberos-tickets)| TTP | -| [Windows Computer Account With SPN](/endpoint/windows_computer_account_with_spn/) | [Steal or Forge Kerberos Tickets](/tags/#steal-or-forge-kerberos-tickets)| TTP | -| [Windows Disabled Users Failing To Authenticate Kerberos](/endpoint/windows_disabled_users_failing_to_authenticate_kerberos/) | [Password Spraying](/tags/#password-spraying), [Brute Force](/tags/#brute-force)| Anomaly | -| [Windows Get-AdComputer Unconstrained Delegation Discovery](/endpoint/windows_get-adcomputer_unconstrained_delegation_discovery/) | [Remote System Discovery](/tags/#remote-system-discovery)| TTP | -| [Windows Invalid Users Failed Authentication via Kerberos](/endpoint/windows_invalid_users_failed_authentication_via_kerberos/) | [Password Spraying](/tags/#password-spraying), [Brute Force](/tags/#brute-force)| Anomaly | -| [Windows Kerberos Local Successful Logon](/endpoint/windows_kerberos_local_successful_logon/) | [Steal or Forge Kerberos Tickets](/tags/#steal-or-forge-kerberos-tickets)| TTP | -| [Windows PowerView Constrained Delegation Discovery](/endpoint/windows_powerview_constrained_delegation_discovery/) | [Remote System Discovery](/tags/#remote-system-discovery)| TTP | -| [Windows PowerView Kerberos Service Ticket Request](/endpoint/windows_powerview_kerberos_service_ticket_request/) | [Steal or Forge Kerberos Tickets](/tags/#steal-or-forge-kerberos-tickets), [Kerberoasting](/tags/#kerberoasting)| TTP | -| [Windows PowerView SPN Discovery](/endpoint/windows_powerview_spn_discovery/) | [Steal or Forge Kerberos Tickets](/tags/#steal-or-forge-kerberos-tickets), [Kerberoasting](/tags/#kerberoasting)| TTP | -| [Windows PowerView Unconstrained Delegation Discovery](/endpoint/windows_powerview_unconstrained_delegation_discovery/) | [Remote System Discovery](/tags/#remote-system-discovery)| TTP | -| [Unusual Number of Computer Service Tickets Requested](/endpoint/unusual_number_of_computer_service_tickets_requested/) | [Valid Accounts](/tags/#valid-accounts)| Hunting | - -#### Reference - -* [https://en.wikipedia.org/wiki/Kerberos_(protocol)](https://en.wikipedia.org/wiki/Kerberos_(protocol)) -* [https://docs.microsoft.com/en-us/openspecs/windows_protocols/ms-kile/2a32282e-dd48-4ad9-a542-609804b02cc9](https://docs.microsoft.com/en-us/openspecs/windows_protocols/ms-kile/2a32282e-dd48-4ad9-a542-609804b02cc9) -* [https://m0chan.github.io/2019/07/31/How-To-Attack-Kerberos-101.html](https://m0chan.github.io/2019/07/31/How-To-Attack-Kerberos-101.html) -* [https://stealthbits.com/blog/cracking-active-directory-passwords-with-as-rep-roasting/](https://stealthbits.com/blog/cracking-active-directory-passwords-with-as-rep-roasting/) -* [https://attack.mitre.org/techniques/T1558/003/](https://attack.mitre.org/techniques/T1558/003/) -* [https://attack.mitre.org/techniques/T1550/003/](https://attack.mitre.org/techniques/T1550/003/) -* [https://attack.mitre.org/techniques/T1558/004/](https://attack.mitre.org/techniques/T1558/004/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/active_directory_kerberos_attacks.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/active_directory_lateral_movement.md b/docs/_stories/active_directory_lateral_movement.md deleted file mode 100644 index f7b2e57295..0000000000 --- a/docs/_stories/active_directory_lateral_movement.md +++ /dev/null @@ -1,85 +0,0 @@ ---- -title: "Active Directory Lateral Movement" -last_modified_at: 2021-12-09 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Network_Traffic - - Actions on Objectives - - Exploitation - - Reconnaissance ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Detect and investigate tactics, techniques, and procedures around how attackers move laterally within an Active Directory environment. Since lateral movement is often a necessary step in a breach, it is important for cyber defenders to deploy detection coverage. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint), [Network_Traffic](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkTraffic) -- **Last Updated**: 2021-12-09 -- **Author**: David Dorsey, Mauricio Velazco Splunk -- **ID**: 399d65dc-1f08-499b-a259-aad9051f38ad - -#### Narrative - -Once attackers gain a foothold within an enterprise, they will seek to expand their accesses and leverage techniques that facilitate lateral movement. Attackers will often spend quite a bit of time and effort moving laterally. Because lateral movement renders an attacker the most vulnerable to detection, it's an excellent focus for detection and investigation.\ -Indications of lateral movement in an Active Directory network can include the abuse of system utilities (such as `psexec.exe`), unauthorized use of remote desktop services, `file/admin$` shares, WMI, PowerShell, Service Control Manager, the DCOM protocol, WinRM or the abuse of scheduled tasks. Organizations must be extra vigilant in detecting lateral movement techniques and look for suspicious activity in and around high-value strategic network assets, such as Active Directory, which are often considered the primary target or "crown jewels" to a persistent threat actor.\ -An adversary can use lateral movement for multiple purposes, including remote execution of tools, pivoting to additional systems, obtaining access to specific information or files, access to additional credentials, exfiltrating data, or delivering a secondary effect. Adversaries may use legitimate credentials alongside inherent network and operating-system functionality to remotely connect to other systems and remain under the radar of network defenders.\ -If there is evidence of lateral movement, it is imperative for analysts to collect evidence of the associated offending hosts. For example, an attacker might leverage host A to gain access to host B. From there, the attacker may try to move laterally to host C. In this example, the analyst should gather as much information as possible from all three hosts. \ - It is also important to collect authentication logs for each host, to ensure that the offending accounts are well-documented. Analysts should account for all processes to ensure that the attackers did not install unauthorized software. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Detect Activity Related to Pass the Hash Attacks](/endpoint/detect_activity_related_to_pass_the_hash_attacks/) | [Use Alternate Authentication Material](/tags/#use-alternate-authentication-material), [Pass the Hash](/tags/#pass-the-hash)| TTP | -| [Detect PsExec With accepteula Flag](/endpoint/detect_psexec_with_accepteula_flag/) | [Remote Services](/tags/#remote-services), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares)| TTP | -| [Detect Renamed PSExec](/endpoint/detect_renamed_psexec/) | [System Services](/tags/#system-services), [Service Execution](/tags/#service-execution)| Hunting | -| [Executable File Written in Administrative SMB Share](/endpoint/executable_file_written_in_administrative_smb_share/) | [Remote Services](/tags/#remote-services), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares)| TTP | -| [Impacket Lateral Movement Commandline Parameters](/endpoint/impacket_lateral_movement_commandline_parameters/) | [Remote Services](/tags/#remote-services), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares), [Distributed Component Object Model](/tags/#distributed-component-object-model), [Windows Management Instrumentation](/tags/#windows-management-instrumentation), [Windows Service](/tags/#windows-service)| TTP | -| [Interactive Session on Remote Endpoint with PowerShell](/endpoint/interactive_session_on_remote_endpoint_with_powershell/) | [Remote Services](/tags/#remote-services), [Windows Remote Management](/tags/#windows-remote-management)| TTP | -| [Mmc LOLBAS Execution Process Spawn](/endpoint/mmc_lolbas_execution_process_spawn/) | [Remote Services](/tags/#remote-services), [Distributed Component Object Model](/tags/#distributed-component-object-model), [MMC](/tags/#mmc)| TTP | -| [Possible Lateral Movement PowerShell Spawn](/endpoint/possible_lateral_movement_powershell_spawn/) | [Remote Services](/tags/#remote-services), [Distributed Component Object Model](/tags/#distributed-component-object-model), [Windows Remote Management](/tags/#windows-remote-management), [Windows Management Instrumentation](/tags/#windows-management-instrumentation), [Scheduled Task](/tags/#scheduled-task), [Windows Service](/tags/#windows-service), [PowerShell](/tags/#powershell), [MMC](/tags/#mmc)| TTP | -| [Remote Process Instantiation via DCOM and PowerShell](/endpoint/remote_process_instantiation_via_dcom_and_powershell/) | [Remote Services](/tags/#remote-services), [Distributed Component Object Model](/tags/#distributed-component-object-model)| TTP | -| [Remote Process Instantiation via DCOM and PowerShell Script Block](/endpoint/remote_process_instantiation_via_dcom_and_powershell_script_block/) | [Remote Services](/tags/#remote-services), [Distributed Component Object Model](/tags/#distributed-component-object-model)| TTP | -| [Remote Process Instantiation via WinRM and PowerShell](/endpoint/remote_process_instantiation_via_winrm_and_powershell/) | [Remote Services](/tags/#remote-services), [Windows Remote Management](/tags/#windows-remote-management)| TTP | -| [Remote Process Instantiation via WinRM and PowerShell Script Block](/endpoint/remote_process_instantiation_via_winrm_and_powershell_script_block/) | [Remote Services](/tags/#remote-services), [Windows Remote Management](/tags/#windows-remote-management)| TTP | -| [Remote Process Instantiation via WinRM and Winrs](/endpoint/remote_process_instantiation_via_winrm_and_winrs/) | [Remote Services](/tags/#remote-services), [Windows Remote Management](/tags/#windows-remote-management)| TTP | -| [Remote Process Instantiation via WMI](/endpoint/remote_process_instantiation_via_wmi/) | [Windows Management Instrumentation](/tags/#windows-management-instrumentation)| TTP | -| [Remote Process Instantiation via WMI and PowerShell](/endpoint/remote_process_instantiation_via_wmi_and_powershell/) | [Windows Management Instrumentation](/tags/#windows-management-instrumentation)| TTP | -| [Remote Process Instantiation via WMI and PowerShell Script Block](/endpoint/remote_process_instantiation_via_wmi_and_powershell_script_block/) | [Windows Management Instrumentation](/tags/#windows-management-instrumentation)| TTP | -| [Scheduled Task Creation on Remote Endpoint using At](/endpoint/scheduled_task_creation_on_remote_endpoint_using_at/) | [Scheduled Task/Job](/tags/#scheduled-task/job), [At](/tags/#at)| TTP | -| [Scheduled Task Initiation on Remote Endpoint](/endpoint/scheduled_task_initiation_on_remote_endpoint/) | [Scheduled Task/Job](/tags/#scheduled-task/job), [Scheduled Task](/tags/#scheduled-task)| TTP | -| [Schtasks scheduling job on remote system](/endpoint/schtasks_scheduling_job_on_remote_system/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job)| TTP | -| [Services LOLBAS Execution Process Spawn](/endpoint/services_lolbas_execution_process_spawn/) | [Create or Modify System Process](/tags/#create-or-modify-system-process), [Windows Service](/tags/#windows-service)| TTP | -| [Short Lived Scheduled Task](/endpoint/short_lived_scheduled_task/) | [Scheduled Task](/tags/#scheduled-task)| TTP | -| [Svchost LOLBAS Execution Process Spawn](/endpoint/svchost_lolbas_execution_process_spawn/) | [Scheduled Task/Job](/tags/#scheduled-task/job), [Scheduled Task](/tags/#scheduled-task)| TTP | -| [Windows Service Created With Suspicious Service Path](/endpoint/windows_service_created_with_suspicious_service_path/) | [System Services](/tags/#system-services), [Service Execution](/tags/#service-execution)| TTP | -| [Windows Service Created Within Public Path](/endpoint/windows_service_created_within_public_path/) | [Create or Modify System Process](/tags/#create-or-modify-system-process), [Windows Service](/tags/#windows-service)| TTP | -| [Windows Service Creation on Remote Endpoint](/endpoint/windows_service_creation_on_remote_endpoint/) | [Create or Modify System Process](/tags/#create-or-modify-system-process), [Windows Service](/tags/#windows-service)| TTP | -| [Windows Service Creation Using Registry Entry](/endpoint/windows_service_creation_using_registry_entry/) | [Services Registry Permissions Weakness](/tags/#services-registry-permissions-weakness)| TTP | -| [Windows Service Initiation on Remote Endpoint](/endpoint/windows_service_initiation_on_remote_endpoint/) | [Create or Modify System Process](/tags/#create-or-modify-system-process), [Windows Service](/tags/#windows-service)| TTP | -| [WinEvent Scheduled Task Created Within Public Path](/endpoint/winevent_scheduled_task_created_within_public_path/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job)| TTP | -| [Wmiprsve LOLBAS Execution Process Spawn](/endpoint/wmiprsve_lolbas_execution_process_spawn/) | [Windows Management Instrumentation](/tags/#windows-management-instrumentation)| TTP | -| [Wsmprovhost LOLBAS Execution Process Spawn](/endpoint/wsmprovhost_lolbas_execution_process_spawn/) | [Remote Services](/tags/#remote-services), [Windows Remote Management](/tags/#windows-remote-management)| TTP | -| [Randomly Generated Scheduled Task Name](/endpoint/randomly_generated_scheduled_task_name/) | [Scheduled Task/Job](/tags/#scheduled-task/job), [Scheduled Task](/tags/#scheduled-task)| Hunting | -| [Randomly Generated Windows Service Name](/endpoint/randomly_generated_windows_service_name/) | [Create or Modify System Process](/tags/#create-or-modify-system-process), [Windows Service](/tags/#windows-service)| Hunting | -| [Remote Desktop Process Running On System](/endpoint/remote_desktop_process_running_on_system/) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol), [Remote Services](/tags/#remote-services)| Hunting | -| [Unusual Number of Computer Service Tickets Requested](/endpoint/unusual_number_of_computer_service_tickets_requested/) | [Valid Accounts](/tags/#valid-accounts)| Hunting | -| [Unusual Number of Remote Endpoint Authentication Events](/endpoint/unusual_number_of_remote_endpoint_authentication_events/) | [Valid Accounts](/tags/#valid-accounts)| Hunting | -| [Remote Desktop Network Traffic](/network/remote_desktop_network_traffic/) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol), [Remote Services](/tags/#remote-services)| Anomaly | - -#### Reference - -* [https://www.fireeye.com/blog/executive-perspective/2015/08/malware_lateral_move.html](https://www.fireeye.com/blog/executive-perspective/2015/08/malware_lateral_move.html) -* [http://www.irongeek.com/i.php?page=videos/derbycon7/t405-hunting-lateral-movement-for-fun-and-profit-mauricio-velazco](http://www.irongeek.com/i.php?page=videos/derbycon7/t405-hunting-lateral-movement-for-fun-and-profit-mauricio-velazco) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/active_directory_lateral_movement.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_stories/active_directory_password_spraying.md b/docs/_stories/active_directory_password_spraying.md deleted file mode 100644 index 64daa552ee..0000000000 --- a/docs/_stories/active_directory_password_spraying.md +++ /dev/null @@ -1,52 +0,0 @@ ---- -title: "Active Directory Password Spraying" -last_modified_at: 2021-04-07 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Monitor for activities and techniques associated with Password Spraying attacks within Active Directory environments. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: -- **Last Updated**: 2021-04-07 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 3de109da-97d2-11eb-8b6a-acde48001122 - -#### Narrative - -In a password spraying attack, adversaries leverage one or a small list of commonly used / popular passwords against a large volume of usernames to acquire valid account credentials. Unlike a Brute Force attack that targets a specific user or small group of users with a large number of passwords, password spraying follows the opposite aproach and increases the chances of obtaining valid credentials while avoiding account lockouts. This allows adversaries to remain undetected if the target organization does not have the proper monitoring and detection controls in place.\ -Password Spraying can be leveraged by adversaries across different stages in an attack. It can be used to obtain an iniial access to an environment but can also be used to escalate privileges when access has been already achieved. In some scenarios, this technique capitalizes on a security policy most organizations implement, password rotation. As enterprise users change their passwords, it is possible some pick predictable, seasonal passwords such as `$CompanyNameWinter`, `Summer2021`, etc.\ -Specifically, this Analytic Story is focused on detecting possible Password Spraying attacks against Active Directory environments leveraging Windows Event Logs in the `Account Logon` and `Logon/Logoff` Advanced Audit Policy categories. It presents 9 detection analytics which can aid defenders in identifyng instances where one source user, source host or source process attempts to authenticate against a target or targets using a high, unsual, number of unique users. A user, host or process attempting to authenticate with multiple users is not common behavior for legitimate systems and should be monitored by security teams. Possible false positive scenarios include but are not limited to vulnerability scanners, remote administration tools, multi-user systems and missconfigured systems. These should be easily spotted when first implementing the detection and addded to an allow list or lookup table. The presented detections can also be used in Threat Hunting exercises. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Multiple Invalid Users Failing To Authenticate From Host Using NTLM](/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm/) | [Password Spraying](/tags/#password-spraying), [Brute Force](/tags/#brute-force)| Anomaly | -| [Multiple Users Failing To Authenticate From Host Using Kerberos](/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos/) | [Password Spraying](/tags/#password-spraying), [Brute Force](/tags/#brute-force)| Anomaly | -| [Multiple Users Failing To Authenticate From Host Using NTLM](/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm/) | [Password Spraying](/tags/#password-spraying), [Brute Force](/tags/#brute-force)| Anomaly | -| [Multiple Users Failing To Authenticate From Process](/endpoint/multiple_users_failing_to_authenticate_from_process/) | [Password Spraying](/tags/#password-spraying), [Brute Force](/tags/#brute-force)| Anomaly | -| [Multiple Users Remotely Failing To Authenticate From Host](/endpoint/multiple_users_remotely_failing_to_authenticate_from_host/) | [Password Spraying](/tags/#password-spraying), [Brute Force](/tags/#brute-force)| Anomaly | -| [Windows Disabled Users Failing To Authenticate Kerberos](/endpoint/windows_disabled_users_failing_to_authenticate_kerberos/) | [Password Spraying](/tags/#password-spraying), [Brute Force](/tags/#brute-force)| Anomaly | -| [Windows Invalid Users Failed Authentication via Kerberos](/endpoint/windows_invalid_users_failed_authentication_via_kerberos/) | [Password Spraying](/tags/#password-spraying), [Brute Force](/tags/#brute-force)| Anomaly | -| [Windows Users Authenticate Using Explicit Credentials](/endpoint/windows_users_authenticate_using_explicit_credentials/) | [Password Spraying](/tags/#password-spraying), [Brute Force](/tags/#brute-force)| Anomaly | - -#### Reference - -* [https://attack.mitre.org/techniques/T1110/003/](https://attack.mitre.org/techniques/T1110/003/) -* [https://www.microsoft.com/security/blog/2020/04/23/protecting-organization-password-spray-attacks/](https://www.microsoft.com/security/blog/2020/04/23/protecting-organization-password-spray-attacks/) -* [https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/dn452415(v=ws.11)](https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/dn452415(v=ws.11)) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/active_directory_password_spraying.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/apache_struts_vulnerability.md b/docs/_stories/apache_struts_vulnerability.md deleted file mode 100644 index 804db44d9c..0000000000 --- a/docs/_stories/apache_struts_vulnerability.md +++ /dev/null @@ -1,59 +0,0 @@ ---- -title: "Apache Struts Vulnerability" -last_modified_at: 2018-12-06 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Actions on Objectives - - Delivery - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Detect and investigate activities--such as unusually long `Content-Type` length, suspicious java classes and web servers executing suspicious processes--consistent with attempts to exploit Apache Struts vulnerabilities. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2018-12-06 -- **Author**: Rico Valdez, Splunk -- **ID**: 2dcfd6a2-e7d2-4873-b6ba-adaf819d2a1e - -#### Narrative - -In March of 2017, a remote code-execution vulnerability in the Jakarta Multipart parser in Apache Struts, a widely used open-source framework for creating Java web applications, was disclosed and assigned to CVE-2017-5638. About two months later, hackers exploited the flaw to carry out the world's 5th largest data breach. The target, credit giant Equifax, told investigators that it had become aware of the vulnerability two months before the attack. \ -The exploit involved manipulating the `Content-Type HTTP` header to execute commands embedded in the header.\ -This Analytic Story contains two different searches that help to identify activity that may be related to this issue. The first search looks for characteristics of the `Content-Type` header consistent with attempts to exploit the vulnerability. This should be a relatively pertinent indicator, as the `Content-Type` header is generally consistent and does not have a large degree of variation.\ -The second search looks for the execution of various commands typically entered on the command shell when an attacker first lands on a system. These commands are not generally executed on web servers during the course of day-to-day operation, but they may be used when the system is undergoing maintenance or troubleshooting.\ -First, it is helpful is to understand how often the notable event is generated, as well as the commonalities in some of these events. This may help determine whether this is a common occurrence that is of a lesser concern or a rare event that may require more extensive investigation. It can also help to understand whether the issue is restricted to a single user or system or is broader in scope.\ -When looking at the target of the behavior illustrated by the event, you should note the sensitivity of the user and or/system to help determine the potential impact. It is also helpful to see what other events involving the target have occurred in the recent past. This can help tie different events together and give further situational awareness regarding the target.\ -Various types of information for external systems should be reviewed and (potentially) collected if the incident is, indeed, judged to be malicious. Information like this can be useful in generating your own threat intelligence to create alerts in the future.\ -Looking at the country, responsible party, and fully qualified domain names associated with the external IP address--as well as the registration information associated with those domain names, if they are frequently visited by others--can help you answer the question of "who," in regard to the external system. Answering that can help qualify the event and may serve useful for tracking. In addition, there are various sources that can provide some reputation information on the IP address or domain name, which can assist in determining if the event is malicious in nature. Finally, determining whether or not there are other events associated with the IP address may help connect some dots or show other events that should be brought into scope.\ -Gathering various data elements on the system of interest can sometimes help quickly determine that something suspicious may be happening. Some of these items include determining who else may have recently logged into the system, whether any unusual scheduled tasks exist, whether the system is communicating on suspicious ports, whether there are modifications to sensitive registry keys, and whether there are any known vulnerabilities on the system. This information can often highlight other activity commonly seen in attack scenarios or give more information about how the system may have been targeted.\ -hen a specific service or application is targeted, it is often helpful to know the associated version to help determine whether or not it is vulnerable to a specific exploit.\ -hen it is suspected there is an attack targeting a web server, it is helpful to look at some of the behavior of the web service to see if there is evidence that the service has been compromised. Some indications of this might be network connections to external resources, the web service spawning child processes that are not associated with typical behavior, and whether the service wrote any files that might be malicious in nature.\ -In the event that a suspicious file is found, we can review more information about it to help determine if it is, in fact, malicious. Identifying the file type, any processes that have the file open, what processes created and/or modified the file, and the number of systems that may have this file can help to determine if the file is malicious. Also, determining the file hash and checking it against reputation sources, such as VirusTotal, can sometimes quickly help determine whether it is malicious in nature.\ -Often, a simple inspection of a suspect process name and path can tell you if the system has been compromised. For example, if `svchost.exe` is found running from a location other than `C:\Windows\System32`, it is likely something malicious designed to hide in plain sight when simply reviewing process names. Similarly, if the process itself seems legitimate, but the parent process is running from the temporary browser cache, there may be activity initiated via a compromised website the user visited.\ -It can also be very helpful to examine various behaviors of the process of interest or the parent of the process that is of interest. For example, if it turns out that the process of interest is malicious, it would be good to see if the parent to that process spawned other processes that might also be worth further scrutiny. If a process is suspect, reviewing the network connections made around the time of the event and/or if the process spawned any child processes could be helpful in determining whether it is malicious or executing a malicious script. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Suspicious Java Classes](/application/suspicious_java_classes/) | None| Anomaly | -| [Web Servers Executing Suspicious Processes](/application/web_servers_executing_suspicious_processes/) | [System Information Discovery](/tags/#system-information-discovery)| TTP | -| [Unusually Long Content-Type Length](/network/unusually_long_content-type_length/) | None| Anomaly | - -#### Reference - -* [https://github.com/SpiderLabs/owasp-modsecurity-crs/blob/v3.2/dev/rules/REQUEST-944-APPLICATION-ATTACK-JAVA.conf](https://github.com/SpiderLabs/owasp-modsecurity-crs/blob/v3.2/dev/rules/REQUEST-944-APPLICATION-ATTACK-JAVA.conf) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/apache_struts_vulnerability.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/asset_tracking.md b/docs/_stories/asset_tracking.md deleted file mode 100644 index 476cc87fa7..0000000000 --- a/docs/_stories/asset_tracking.md +++ /dev/null @@ -1,44 +0,0 @@ ---- -title: "Asset Tracking" -last_modified_at: 2017-09-13 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Network_Sessions - - Actions on Objectives - - Delivery - - Reconnaissance ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Keep a careful inventory of every asset on your network to make it easier to detect rogue devices. Unauthorized/unmanaged devices could be an indication of malicious behavior that should be investigated further. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Network_Sessions](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkSessions) -- **Last Updated**: 2017-09-13 -- **Author**: Bhavin Patel, Splunk -- **ID**: 91c676cf-0b23-438d-abee-f6335e1fce77 - -#### Narrative - -This Analytic Story is designed to help you develop a better understanding of what authorized and unauthorized devices are part of your enterprise. This story can help you better categorize and classify assets, providing critical business context and awareness of their assets during an incident. Information derived from this Analytic Story can be used to better inform and support other analytic stories. For successful detection, you will need to leverage the Assets and Identity Framework from Enterprise Security to populate your known assets. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Detect Unauthorized Assets by MAC address](/network/detect_unauthorized_assets_by_mac_address/) | None| TTP | - -#### Reference - -* [https://www.cisecurity.org/controls/inventory-of-authorized-and-unauthorized-devices/](https://www.cisecurity.org/controls/inventory-of-authorized-and-unauthorized-devices/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/asset_tracking.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/atlassian_confluence_server_and_data_center_cve-2022-26134.md b/docs/_stories/atlassian_confluence_server_and_data_center_cve-2022-26134.md deleted file mode 100644 index fd7c817eff..0000000000 --- a/docs/_stories/atlassian_confluence_server_and_data_center_cve-2022-26134.md +++ /dev/null @@ -1,46 +0,0 @@ ---- -title: "Atlassian Confluence Server and Data Center CVE-2022-26134" -last_modified_at: 2022-06-03 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -On June 2, security researchers at Volexity published a blog outlining the discovery of an unauthenticated remote code execution zero day vulnerability (CVE-2022-26134) being actively exploited in Atlassian Confluence Server and Data Center instances in the wild. Atlassian released a fix within 24 hours of the blog''s release. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-06-03 -- **Author**: Michael Haag, Splunk -- **ID**: 91623a50-41fa-4c4e-8637-c239b80ff439 - -#### Narrative - -Atlassian describes the vulnerability as an Object-Graph Navigation Language (OGNL) injection allowing an unauthenticated user to execute arbitrary code on a Confluence Server or Data Server instance. Volexity did not release proof-of-concept (POC) exploit code, but researchers there have observed coordinated, widespread exploitation. Volexity first discovered the vulnerability over the weekend on two Internet-facing web servers running Confluence Server software. The investigation was due to suspicious activity on the hosts, including JSP webshells that were written to disk. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Java Writing JSP File](/endpoint/java_writing_jsp_file/) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application)| TTP | -| [Confluence Unauthenticated Remote Code Execution CVE-2022-26134](/web/confluence_unauthenticated_remote_code_execution_cve-2022-26134/) | [Server Software Component](/tags/#server-software-component), [Exploit Public-Facing Application](/tags/#exploit-public-facing-application)| TTP | - -#### Reference - -* [https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html](https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html) -* [https://www.splunk.com/en_us/blog/security/atlassian-confluence-vulnerability-cve-2022-26134.html](https://www.splunk.com/en_us/blog/security/atlassian-confluence-vulnerability-cve-2022-26134.html) -* [https://www.rapid7.com/blog/post/2022/06/02/active-exploitation-of-confluence-cve-2022-26134/](https://www.rapid7.com/blog/post/2022/06/02/active-exploitation-of-confluence-cve-2022-26134/) -* [https://www.volexity.com/blog/2022/06/02/zero-day-exploitation-of-atlassian-confluence/](https://www.volexity.com/blog/2022/06/02/zero-day-exploitation-of-atlassian-confluence/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/atlassian_confluence_server_and_data_center_cve-2022-26134.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/aws_cross_account_activity.md b/docs/_stories/aws_cross_account_activity.md deleted file mode 100644 index 7d54b5e8b9..0000000000 --- a/docs/_stories/aws_cross_account_activity.md +++ /dev/null @@ -1,47 +0,0 @@ ---- -title: "AWS Cross Account Activity" -last_modified_at: 2018-06-04 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Track when a user assumes an IAM role in another AWS account to obtain cross-account access to services and resources in that account. Accessing new roles could be an indication of malicious activity. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: -- **Last Updated**: 2018-06-04 -- **Author**: David Dorsey, Splunk -- **ID**: 2f2f610a-d64d-48c2-b57c-967a2b49ab5a - -#### Narrative - -Amazon Web Services (AWS) admins manage access to AWS resources and services across the enterprise using AWS's Identity and Access Management (IAM) functionality. IAM provides the ability to create and manage AWS users, groups, and roles-each with their own unique set of privileges and defined access to specific resources (such as EC2 instances, the AWS Management Console, API, or the command-line interface). Unlike conventional (human) users, IAM roles are assumable by anyone in the organization. They provide users with dynamically created temporary security credentials that expire within a set time period.\ -Herein lies the rub. In between the time between when the temporary credentials are issued and when they expire is a period of opportunity, where a user could leverage the temporary credentials to wreak havoc-spin up or remove instances, create new users, elevate privileges, and other malicious activities-throughout the environment.\ -This Analytic Story includes searches that will help you monitor your AWS CloudTrail logs for evidence of suspicious cross-account activity. For example, while accessing multiple AWS accounts and roles may be perfectly valid behavior, it may be suspicious when an account requests privileges of an account it has not accessed in the past. After identifying suspicious activities, you can use the provided investigative searches to help you probe more deeply. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [aws detect attach to role policy](/cloud/aws_detect_attach_to_role_policy/) | [Valid Accounts](/tags/#valid-accounts)| Hunting | -| [aws detect permanent key creation](/cloud/aws_detect_permanent_key_creation/) | [Valid Accounts](/tags/#valid-accounts)| Hunting | -| [aws detect role creation](/cloud/aws_detect_role_creation/) | [Valid Accounts](/tags/#valid-accounts)| Hunting | -| [aws detect sts assume role abuse](/cloud/aws_detect_sts_assume_role_abuse/) | [Valid Accounts](/tags/#valid-accounts)| Hunting | -| [aws detect sts get session token abuse](/cloud/aws_detect_sts_get_session_token_abuse/) | [Use Alternate Authentication Material](/tags/#use-alternate-authentication-material)| Hunting | - -#### Reference - -* [https://aws.amazon.com/blogs/security/aws-cloudtrail-now-tracks-cross-account-activity-to-its-origin/](https://aws.amazon.com/blogs/security/aws-cloudtrail-now-tracks-cross-account-activity-to-its-origin/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/aws_cross_account_activity.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/aws_cryptomining.md b/docs/_stories/aws_cryptomining.md deleted file mode 100644 index d2db97af0e..0000000000 --- a/docs/_stories/aws_cryptomining.md +++ /dev/null @@ -1,50 +0,0 @@ ---- -title: "AWS Cryptomining" -last_modified_at: 2018-03-08 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Actions on Objectives - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Monitor your AWS EC2 instances for activities related to cryptojacking/cryptomining. New instances that originate from previously unseen regions, users who launch abnormally high numbers of instances, or EC2 instances started by previously unseen users are just a few examples of potentially malicious behavior. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: -- **Last Updated**: 2018-03-08 -- **Author**: David Dorsey, Splunk -- **ID**: ced74200-8465-4bc3-bd2c-9a782eec6750 - -#### Narrative - -Cryptomining is an intentionally difficult, resource-intensive business. Its complexity was designed into the process to ensure that the number of blocks mined each day would remain steady. So, it's par for the course that ambitious, but unscrupulous, miners make amassing the computing power of large enterprises--a practice known as cryptojacking--a top priority. \ -Cryptojacking has attracted an increasing amount of media attention since its explosion in popularity in the fall of 2017. The attacks have moved from in-browser exploits and mobile phones to enterprise cloud services, such as Amazon Web Services (AWS). It's difficult to determine exactly how widespread the practice has become, since bad actors continually evolve their ability to escape detection, including employing unlisted endpoints, moderating their CPU usage, and hiding the mining pool's IP address behind a free CDN. \ -When malicious miners appropriate a cloud instance, often spinning up hundreds of new instances, the costs can become astronomical for the account holder. So, it is critically important to monitor your systems for suspicious activities that could indicate that your network has been infiltrated. \ -This Analytic Story is focused on detecting suspicious new instances in your EC2 environment to help prevent such a disaster. It contains detection searches that will detect when a previously unused instance type or AMI is used. It also contains support searches to build lookup files to ensure proper execution of the detection searches. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Abnormally High AWS Instances Launched by User](/deprecated/abnormally_high_aws_instances_launched_by_user/) | [Cloud Accounts](/tags/#cloud-accounts)| Anomaly | -| [Abnormally High AWS Instances Launched by User - MLTK](/deprecated/abnormally_high_aws_instances_launched_by_user_-_mltk/) | [Cloud Accounts](/tags/#cloud-accounts)| Anomaly | -| [EC2 Instance Started In Previously Unseen Region](/deprecated/ec2_instance_started_in_previously_unseen_region/) | [Unused/Unsupported Cloud Regions](/tags/#unused/unsupported-cloud-regions)| Anomaly | -| [EC2 Instance Started With Previously Unseen AMI](/deprecated/ec2_instance_started_with_previously_unseen_ami/) | None| Anomaly | -| [EC2 Instance Started With Previously Unseen Instance Type](/deprecated/ec2_instance_started_with_previously_unseen_instance_type/) | None| Anomaly | -| [EC2 Instance Started With Previously Unseen User](/deprecated/ec2_instance_started_with_previously_unseen_user/) | [Cloud Accounts](/tags/#cloud-accounts)| Anomaly | - -#### Reference - -* [https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf](https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/aws_cryptomining.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/aws_defense_evasion.md b/docs/_stories/aws_defense_evasion.md deleted file mode 100644 index 86474cdca5..0000000000 --- a/docs/_stories/aws_defense_evasion.md +++ /dev/null @@ -1,46 +0,0 @@ ---- -title: "AWS Defense Evasion" -last_modified_at: 2022-07-15 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Actions on Objectives ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Identify activity and techniques associated with the Evasion of Defenses within AWS, such as Disabling CloudTrail, Deleting CloudTrail and many others. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: -- **Last Updated**: 2022-07-15 -- **Author**: Gowthamaraj Rajendran, Splunk -- **ID**: 4e00b690-293f-434d-a9d8-bcfb2ea5fff9 - -#### Narrative - -Adversaries employ a variety of techniques in order to avoid detection and operate without barriers. This often involves modifying the configuration of security monitoring tools to get around them or explicitly disabling them to prevent them from running. This Analytic Story includes analytics that identify activity consistent with adversaries attempting to disable various security mechanisms on AWS. Such activity may involve deleting the CloudTrail logs , as this is where all the AWS logs get stored or explicitly changing the retention policy of S3 buckets. Other times, adversaries attempt deletion of a specified AWS CloudWatch log group. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [AWS Defense Evasion Delete Cloudtrail](/cloud/aws_defense_evasion_delete_cloudtrail/) | [Disable Cloud Logs](/tags/#disable-cloud-logs), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [AWS Defense Evasion Delete CloudWatch Log Group](/cloud/aws_defense_evasion_delete_cloudwatch_log_group/) | [Impair Defenses](/tags/#impair-defenses), [Disable Cloud Logs](/tags/#disable-cloud-logs)| TTP | -| [AWS Defense Evasion Impair Security Services](/cloud/aws_defense_evasion_impair_security_services/) | [Disable Cloud Logs](/tags/#disable-cloud-logs), [Impair Defenses](/tags/#impair-defenses)| Hunting | -| [AWS Defense Evasion PutBucketLifecycle](/cloud/aws_defense_evasion_putbucketlifecycle/) | [Disable Cloud Logs](/tags/#disable-cloud-logs), [Impair Defenses](/tags/#impair-defenses)| Hunting | -| [AWS Defense Evasion Stop Logging Cloudtrail](/cloud/aws_defense_evasion_stop_logging_cloudtrail/) | [Disable Cloud Logs](/tags/#disable-cloud-logs), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [AWS Defense Evasion Update Cloudtrail](/cloud/aws_defense_evasion_update_cloudtrail/) | [Impair Defenses](/tags/#impair-defenses), [Disable Cloud Logs](/tags/#disable-cloud-logs)| TTP | - -#### Reference - -* [https://attack.mitre.org/tactics/TA0005/](https://attack.mitre.org/tactics/TA0005/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/aws_defense_evasion.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/aws_iam_privilege_escalation.md b/docs/_stories/aws_iam_privilege_escalation.md deleted file mode 100644 index bb4c51519c..0000000000 --- a/docs/_stories/aws_iam_privilege_escalation.md +++ /dev/null @@ -1,54 +0,0 @@ ---- -title: "AWS IAM Privilege Escalation" -last_modified_at: 2021-03-08 -toc: true -toc_label: "" -tags: - - Splunk Security Analytics for AWS - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Actions on Objectives - - Reconnaissance ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic story contains detections that query your AWS Cloudtrail for activities related to privilege escalation. - -- **Product**: Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: -- **Last Updated**: 2021-03-08 -- **Author**: Bhavin Patel, Splunk -- **ID**: ced74200-8465-4bc3-bd2c-22782eec6750 - -#### Narrative - -Amazon Web Services provides a neat feature called Identity and Access Management (IAM) that enables organizations to manage various AWS services and resources in a secure way. All IAM users have roles, groups and policies associated with them which governs and sets permissions to allow a user to access specific restrictions.\ -However, if these IAM policies are misconfigured and have specific combinations of weak permissions; it can allow attackers to escalate their privileges and further compromise the organization. Rhino Security Labs have published comprehensive blogs detailing various AWS Escalation methods. By using this as an inspiration, Splunks research team wants to highlight how these attack vectors look in AWS Cloudtrail logs and provide you with detection queries to uncover these potentially malicious events via this Analytic Story. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [AWS Create Policy Version to allow all resources](/cloud/aws_create_policy_version_to_allow_all_resources/) | [Cloud Accounts](/tags/#cloud-accounts), [Valid Accounts](/tags/#valid-accounts)| TTP | -| [AWS CreateAccessKey](/cloud/aws_createaccesskey/) | [Cloud Account](/tags/#cloud-account), [Create Account](/tags/#create-account)| Hunting | -| [AWS CreateLoginProfile](/cloud/aws_createloginprofile/) | [Cloud Account](/tags/#cloud-account), [Create Account](/tags/#create-account)| TTP | -| [AWS IAM Assume Role Policy Brute Force](/cloud/aws_iam_assume_role_policy_brute_force/) | [Cloud Infrastructure Discovery](/tags/#cloud-infrastructure-discovery), [Brute Force](/tags/#brute-force)| TTP | -| [AWS IAM Delete Policy](/cloud/aws_iam_delete_policy/) | [Account Manipulation](/tags/#account-manipulation)| Hunting | -| [AWS IAM Failure Group Deletion](/cloud/aws_iam_failure_group_deletion/) | [Account Manipulation](/tags/#account-manipulation)| Anomaly | -| [AWS IAM Successful Group Deletion](/cloud/aws_iam_successful_group_deletion/) | [Cloud Groups](/tags/#cloud-groups), [Account Manipulation](/tags/#account-manipulation), [Permission Groups Discovery](/tags/#permission-groups-discovery)| Hunting | -| [AWS SetDefaultPolicyVersion](/cloud/aws_setdefaultpolicyversion/) | [Cloud Accounts](/tags/#cloud-accounts), [Valid Accounts](/tags/#valid-accounts)| TTP | -| [AWS UpdateLoginProfile](/cloud/aws_updateloginprofile/) | [Cloud Account](/tags/#cloud-account), [Create Account](/tags/#create-account)| TTP | - -#### Reference - -* [https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation/](https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation/) -* [https://www.cyberark.com/resources/threat-research-blog/the-cloud-shadow-admin-threat-10-permissions-to-protect](https://www.cyberark.com/resources/threat-research-blog/the-cloud-shadow-admin-threat-10-permissions-to-protect) -* [https://labs.bishopfox.com/tech-blog/privilege-escalation-in-aws](https://labs.bishopfox.com/tech-blog/privilege-escalation-in-aws) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/aws_iam_privilege_escalation.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/aws_network_acl_activity.md b/docs/_stories/aws_network_acl_activity.md deleted file mode 100644 index 5e385cd391..0000000000 --- a/docs/_stories/aws_network_acl_activity.md +++ /dev/null @@ -1,47 +0,0 @@ ---- -title: "AWS Network ACL Activity" -last_modified_at: 2018-05-21 -toc: true -toc_label: "" -tags: - - Splunk Security Analytics for AWS - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Actions on Objectives - - Command & Control ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Monitor your AWS network infrastructure for bad configurations and malicious activity. Investigative searches help you probe deeper, when the facts warrant it. - -- **Product**: Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: -- **Last Updated**: 2018-05-21 -- **Author**: Bhavin Patel, Splunk -- **ID**: 2e8948a5-5239-406b-b56b-6c50ff268af4 - -#### Narrative - -AWS CloudTrail is an AWS service that helps you enable governance, compliance, and operational/risk auditing of your AWS account. Actions taken by a user, role, or an AWS service are recorded as events in CloudTrail. It is crucial for a company to monitor events and actions taken in the AWS Management Console, AWS Command Line Interface, and AWS SDKs and APIs to ensure that your servers are not vulnerable to attacks. This analytic story contains detection searches that leverage CloudTrail logs from AWS to check for bad configurations and malicious activity in your AWS network access controls. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [AWS Network Access Control List Created with All Open Ports](/cloud/aws_network_access_control_list_created_with_all_open_ports/) | [Disable or Modify Cloud Firewall](/tags/#disable-or-modify-cloud-firewall), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [AWS Network Access Control List Deleted](/cloud/aws_network_access_control_list_deleted/) | [Disable or Modify Cloud Firewall](/tags/#disable-or-modify-cloud-firewall), [Impair Defenses](/tags/#impair-defenses)| Anomaly | -| [Detect Spike in Network ACL Activity](/deprecated/detect_spike_in_network_acl_activity/) | [Disable or Modify Cloud Firewall](/tags/#disable-or-modify-cloud-firewall)| Anomaly | -| [Detect Spike in blocked Outbound Traffic from your AWS](/cloud/detect_spike_in_blocked_outbound_traffic_from_your_aws/) | None| Anomaly | - -#### Reference - -* [https://docs.aws.amazon.com/AmazonVPC/latest/UserGuide/VPC_Appendix_NACLs.html](https://docs.aws.amazon.com/AmazonVPC/latest/UserGuide/VPC_Appendix_NACLs.html) -* [https://aws.amazon.com/blogs/security/how-to-help-prepare-for-ddos-attacks-by-reducing-your-attack-surface/](https://aws.amazon.com/blogs/security/how-to-help-prepare-for-ddos-attacks-by-reducing-your-attack-surface/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/aws_network_acl_activity.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_stories/aws_privilege_escalation.md b/docs/_stories/aws_privilege_escalation.md deleted file mode 100644 index a51aad3e32..0000000000 --- a/docs/_stories/aws_privilege_escalation.md +++ /dev/null @@ -1,70 +0,0 @@ ---- -title: "AWS IAM Privilege Escalation" -excerpt: "This analytic story contains detections that query your AWS Cloudtrail for activities related to privilege escalation." -last_modified_at: 2020-07-27 -tags: - - T1069.003 - - T1078.004 - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Adversary Tactics ---- - -### AWS IAM Privilege Escalation -This analytic story contains detections that query your AWS Cloudtrail for activities related to privilege escalation. - -- **Product**: Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: -- **ATT&CK**: [T1069.003](https://attack.mitre.org/techniques/T1069.003/), [T1078.004](https://attack.mitre.org/techniques/T1078.004/), [T1098](https://attack.mitre.org/techniques/T1098/), [T1110](https://attack.mitre.org/techniques/T1110/), [T1136.003](https://attack.mitre.org/techniques/T1136.003/), [T1580](https://attack.mitre.org/techniques/T1580/) -- **Last Updated**: 2021-03-08 - -#### Detection Profile - -* [AWS Create Policy Version to allow all resources](detections.md#aws-create-policy-version-to-allow-all-resources) - -* [AWS CreateAccessKey](detections.md#aws-createaccesskey) - -* [AWS CreateLoginProfile](detections.md#aws-createloginprofile) - -* [AWS IAM Assume Role Policy Brute Force](detections.md#aws-iam-assume-role-policy-brute-force) - -* [AWS IAM Delete Policy](detections.md#aws-iam-delete-policy) - -* [AWS IAM Failure Group Deletion](detections.md#aws-iam-failure-group-deletion) - -* [AWS IAM Successful Group Deletion](detections.md#aws-iam-successful-group-deletion) - -* [AWS SetDefaultPolicyVersion](detections.md#aws-setdefaultpolicyversion) - -* [AWS UpdateLoginProfile](detections.md#aws-updateloginprofile) - - -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------| -| T1078.004 | Cloud Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | -| T1136.003 | Cloud Account | Persistence | -| T1580 | Cloud Infrastructure Discovery | Discovery | -| T1110 | Brute Force | Credential Access | -| T1098 | Account Manipulation | Persistence | -| T1069.003 | Cloud Groups | Discovery | - -#### Kill Chain Phase - -* Actions on Objectives - -* Reconnaissance - - -#### Reference - -* https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation/ - -* https://www.cyberark.com/resources/threat-research-blog/the-cloud-shadow-admin-threat-10-permissions-to-protect - -* https://labs.bishopfox.com/tech-blog/privilege-escalation-in-aws - - -_version_: 1 diff --git a/docs/_stories/aws_security_hub_alerts.md b/docs/_stories/aws_security_hub_alerts.md deleted file mode 100644 index dcb7accb37..0000000000 --- a/docs/_stories/aws_security_hub_alerts.md +++ /dev/null @@ -1,43 +0,0 @@ ---- -title: "AWS Security Hub Alerts" -last_modified_at: 2020-08-04 -toc: true -toc_label: "" -tags: - - Splunk Security Analytics for AWS - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This story is focused around detecting Security Hub alerts generated from AWS - -- **Product**: Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: -- **Last Updated**: 2020-08-04 -- **Author**: Bhavin Patel, Splunk -- **ID**: 2f2f610a-d64d-48c2-b57c-96722b49ab5a - -#### Narrative - -AWS Security Hub collects and consolidates findings from AWS security services enabled in your environment, such as intrusion detection findings from Amazon GuardDuty, vulnerability scans from Amazon Inspector, S3 bucket policy findings from Amazon Macie, publicly accessible and cross-account resources from IAM Access Analyzer, and resources lacking WAF coverage from AWS Firewall Manager. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Detect Spike in AWS Security Hub Alerts for EC2 Instance](/cloud/detect_spike_in_aws_security_hub_alerts_for_ec2_instance/) | None| Anomaly | -| [Detect Spike in AWS Security Hub Alerts for User](/cloud/detect_spike_in_aws_security_hub_alerts_for_user/) | None| Anomaly | - -#### Reference - -* [https://aws.amazon.com/security-hub/features/](https://aws.amazon.com/security-hub/features/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/aws_security_hub_alerts.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/aws_suspicious_provisioning_activities.md b/docs/_stories/aws_suspicious_provisioning_activities.md deleted file mode 100644 index 59f3817c1f..0000000000 --- a/docs/_stories/aws_suspicious_provisioning_activities.md +++ /dev/null @@ -1,45 +0,0 @@ ---- -title: "AWS Suspicious Provisioning Activities" -last_modified_at: 2018-03-16 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Monitor your AWS provisioning activities for behaviors originating from unfamiliar or unusual locations. These behaviors may indicate that malicious activities are occurring somewhere within your network. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: -- **Last Updated**: 2018-03-16 -- **Author**: David Dorsey, Splunk -- **ID**: 3338b567-3804-4261-9889-cf0ca4753c7f - -#### Narrative - -Because most enterprise AWS activities originate from familiar geographic locations, monitoring for activity from unknown or unusual regions is an important security measure. This indicator can be especially useful in environments where it is impossible to add specific IPs to an allow list because they vary. \ -This Analytic Story was designed to provide you with flexibility in the precision you employ in specifying legitimate geographic regions. It can be as specific as an IP address or a city, or as broad as a region (think state) or an entire country. By determining how precise you want your geographical locations to be and monitoring for new locations that haven't previously accessed your environment, you can detect adversaries as they begin to probe your environment. Since there are legitimate reasons for activities from unfamiliar locations, this is not a standalone indicator. Nevertheless, location can be a relevant piece of information that you may wish to investigate further. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [AWS Cloud Provisioning From Previously Unseen City](/deprecated/aws_cloud_provisioning_from_previously_unseen_city/) | [Unused/Unsupported Cloud Regions](/tags/#unused/unsupported-cloud-regions)| Anomaly | -| [AWS Cloud Provisioning From Previously Unseen Country](/deprecated/aws_cloud_provisioning_from_previously_unseen_country/) | [Unused/Unsupported Cloud Regions](/tags/#unused/unsupported-cloud-regions)| Anomaly | -| [AWS Cloud Provisioning From Previously Unseen IP Address](/deprecated/aws_cloud_provisioning_from_previously_unseen_ip_address/) | None| Anomaly | -| [AWS Cloud Provisioning From Previously Unseen Region](/deprecated/aws_cloud_provisioning_from_previously_unseen_region/) | [Unused/Unsupported Cloud Regions](/tags/#unused/unsupported-cloud-regions)| Anomaly | - -#### Reference - -* [https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf](https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/aws_suspicious_provisioning_activities.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/aws_user_monitoring.md b/docs/_stories/aws_user_monitoring.md deleted file mode 100644 index f5c2c1deab..0000000000 --- a/docs/_stories/aws_user_monitoring.md +++ /dev/null @@ -1,51 +0,0 @@ ---- -title: "AWS User Monitoring" -last_modified_at: 2018-03-12 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Actions on Objectives - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Detect and investigate dormant user accounts for your AWS environment that have become active again. Because inactive and ad-hoc accounts are common attack targets, it's critical to enable governance within your environment. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: -- **Last Updated**: 2018-03-12 -- **Author**: Bhavin Patel, Splunk -- **ID**: 2e8948a5-5239-406b-b56b-6c50f1269af3 - -#### Narrative - -It seems obvious that it is critical to monitor and control the users who have access to your cloud infrastructure. Nevertheless, it's all too common for enterprises to lose track of ad-hoc accounts, leaving their servers vulnerable to attack. In fact, this was the very oversight that led to Tesla's cryptojacking attack in February, 2018.\ -In addition to compromising the security of your data, when bad actors leverage your compute resources, it can incur monumental costs, since you will be billed for any new EC2 instances and increased bandwidth usage. \ -Fortunately, you can leverage Amazon Web Services (AWS) CloudTrail--a tool that helps you enable governance, compliance, and risk auditing of your AWS account--to give you increased visibility into your user and resource activity by recording AWS Management Console actions and API calls. You can identify which users and accounts called AWS, the source IP address from which the calls were made, and when the calls occurred.\ -The detection searches in this Analytic Story are designed to help you uncover AWS API activities from users not listed in the identity table, as well as similar activities from disabled accounts. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [AWS Excessive Security Scanning](/cloud/aws_excessive_security_scanning/) | [Cloud Service Discovery](/tags/#cloud-service-discovery)| TTP | -| [Detect API activity from users without MFA](/deprecated/detect_api_activity_from_users_without_mfa/) | None| Hunting | -| [Detect AWS API Activities From Unapproved Accounts](/deprecated/detect_aws_api_activities_from_unapproved_accounts/) | [Cloud Accounts](/tags/#cloud-accounts)| Hunting | -| [Detect new API calls from user roles](/deprecated/detect_new_api_calls_from_user_roles/) | [Cloud Accounts](/tags/#cloud-accounts)| Anomaly | -| [Detect Spike in AWS API Activity](/deprecated/detect_spike_in_aws_api_activity/) | [Cloud Accounts](/tags/#cloud-accounts)| Anomaly | -| [Detect Spike in Security Group Activity](/deprecated/detect_spike_in_security_group_activity/) | [Cloud Accounts](/tags/#cloud-accounts)| Anomaly | - -#### Reference - -* [https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf](https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf) -* [https://redlock.io/blog/cryptojacking-tesla](https://redlock.io/blog/cryptojacking-tesla) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/aws_user_monitoring.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/azorult.md b/docs/_stories/azorult.md deleted file mode 100644 index de9440d619..0000000000 --- a/docs/_stories/azorult.md +++ /dev/null @@ -1,100 +0,0 @@ ---- -title: "Azorult" -last_modified_at: 2022-06-09 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Actions on Objectives - - Delivery - - Exploitation - - Installation - - Reconnaissance ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Leverage searches that allow you to detect and investigate unusual activities that might relate to the Azorult malware including firewall modification, icacl execution, spawning more process, botnet c2 communication, defense evasion and etc. The AZORULT malware was first discovered in 2016 to be an information stealer that steals browsing history, cookies, ID/passwords, cryptocurrency information and more. It can also be a downloader of other malware. A variant of this malware was able to create a new, hidden administrator account on the machine to set a registry key to establish a Remote Desktop Protocol (RDP) connection. Exploit kits such as Fallout Exploit Kit (EK) and phishing mails with social engineering technique are one of the major infection vectors of the AZORult malware. The current malspam and phishing emails use fake product order requests, invoice documents and payment information requests. This Trojan-Spyware connects to command and control (C&C) servers of attacker to send and receive information. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-06-09 -- **Author**: Teoderick Contreras, Splunk -- **ID**: efed5343-4ac2-42b1-a16d-da2428d0ce94 - -#### Narrative - -Adversaries may use this technique to maximize the impact on the target organization in operations where network wide availability interruption is the goal. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Allow Inbound Traffic By Firewall Rule Registry](/endpoint/allow_inbound_traffic_by_firewall_rule_registry/) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol), [Remote Services](/tags/#remote-services)| TTP | -| [Allow Operation with Consent Admin](/endpoint/allow_operation_with_consent_admin/) | [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism)| TTP | -| [Attempt To Stop Security Service](/endpoint/attempt_to_stop_security_service/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [CHCP Command Execution](/endpoint/chcp_command_execution/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter)| TTP | -| [CMD Carry Out String Command Parameter](/endpoint/cmd_carry_out_string_command_parameter/) | [Windows Command Shell](/tags/#windows-command-shell), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter)| Hunting | -| [Create local admin accounts using net exe](/endpoint/create_local_admin_accounts_using_net_exe/) | [Local Account](/tags/#local-account), [Create Account](/tags/#create-account)| TTP | -| [Detect Use of cmd exe to Launch Script Interpreters](/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Windows Command Shell](/tags/#windows-command-shell)| TTP | -| [Disable Defender BlockAtFirstSeen Feature](/endpoint/disable_defender_blockatfirstseen_feature/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Disable Defender Enhanced Notification](/endpoint/disable_defender_enhanced_notification/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Disable Defender Spynet Reporting](/endpoint/disable_defender_spynet_reporting/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Disable Defender Submit Samples Consent Feature](/endpoint/disable_defender_submit_samples_consent_feature/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Disable Show Hidden Files](/endpoint/disable_show_hidden_files/) | [Hidden Files and Directories](/tags/#hidden-files-and-directories), [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Hide Artifacts](/tags/#hide-artifacts), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Disable Windows Behavior Monitoring](/endpoint/disable_windows_behavior_monitoring/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Disabling Remote User Account Control](/endpoint/disabling_remote_user_account_control/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism)| TTP | -| [Excessive Attempt To Disable Services](/endpoint/excessive_attempt_to_disable_services/) | [Service Stop](/tags/#service-stop)| Anomaly | -| [Excessive Usage Of Cacls App](/endpoint/excessive_usage_of_cacls_app/) | [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification)| Anomaly | -| [Excessive Usage Of Net App](/endpoint/excessive_usage_of_net_app/) | [Account Access Removal](/tags/#account-access-removal)| Anomaly | -| [Excessive Usage Of SC Service Utility](/endpoint/excessive_usage_of_sc_service_utility/) | [System Services](/tags/#system-services), [Service Execution](/tags/#service-execution)| Anomaly | -| [Excessive Usage Of Taskkill](/endpoint/excessive_usage_of_taskkill/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| Anomaly | -| [Executables Or Script Creation In Suspicious Path](/endpoint/executables_or_script_creation_in_suspicious_path/) | [Masquerading](/tags/#masquerading)| TTP | -| [Firewall Allowed Program Enable](/endpoint/firewall_allowed_program_enable/) | [Disable or Modify System Firewall](/tags/#disable-or-modify-system-firewall), [Impair Defenses](/tags/#impair-defenses)| Anomaly | -| [Hide User Account From Sign-In Screen](/endpoint/hide_user_account_from_sign-in_screen/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Hiding Files And Directories With Attrib exe](/endpoint/hiding_files_and_directories_with_attrib_exe/) | [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification), [Windows File and Directory Permissions Modification](/tags/#windows-file-and-directory-permissions-modification)| TTP | -| [Icacls Deny Command](/endpoint/icacls_deny_command/) | [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification)| TTP | -| [Net Localgroup Discovery](/endpoint/net_localgroup_discovery/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Local Groups](/tags/#local-groups)| Hunting | -| [Network Connection Discovery With Net](/endpoint/network_connection_discovery_with_net/) | [System Network Connections Discovery](/tags/#system-network-connections-discovery)| Hunting | -| [Non Firefox Process Access Firefox Profile Dir](/endpoint/non_firefox_process_access_firefox_profile_dir/) | [Credentials from Password Stores](/tags/#credentials-from-password-stores), [Credentials from Web Browsers](/tags/#credentials-from-web-browsers)| Anomaly | -| [Processes launching netsh](/endpoint/processes_launching_netsh/) | [Disable or Modify System Firewall](/tags/#disable-or-modify-system-firewall), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Registry Keys Used For Persistence](/endpoint/registry_keys_used_for_persistence/) | [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution)| TTP | -| [Sc exe Manipulating Windows Services](/endpoint/sc_exe_manipulating_windows_services/) | [Windows Service](/tags/#windows-service), [Create or Modify System Process](/tags/#create-or-modify-system-process)| TTP | -| [Scheduled Task Deleted Or Created via CMD](/endpoint/scheduled_task_deleted_or_created_via_cmd/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job)| TTP | -| [Suspicious Scheduled Task from Public Directory](/endpoint/suspicious_scheduled_task_from_public_directory/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job)| Anomaly | -| [Windows Application Layer Protocol RMS Radmin Tool Namedpipe](/endpoint/windows_application_layer_protocol_rms_radmin_tool_namedpipe/) | [Application Layer Protocol](/tags/#application-layer-protocol)| TTP | -| [Windows Defender Exclusion Registry Entry](/endpoint/windows_defender_exclusion_registry_entry/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Windows DisableAntiSpyware Registry](/endpoint/windows_disableantispyware_registry/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Windows Gather Victim Network Info Through Ip Check Web Services](/endpoint/windows_gather_victim_network_info_through_ip_check_web_services/) | [IP Addresses](/tags/#ip-addresses), [Gather Victim Network Information](/tags/#gather-victim-network-information)| Hunting | -| [Windows Impair Defense Add Xml Applocker Rules](/endpoint/windows_impair_defense_add_xml_applocker_rules/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| Hunting | -| [Windows Impair Defense Deny Security Software With Applocker](/endpoint/windows_impair_defense_deny_security_software_with_applocker/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Windows Modify Registry Disable Toast Notifications](/endpoint/windows_modify_registry_disable_toast_notifications/) | [Modify Registry](/tags/#modify-registry)| Anomaly | -| [Windows Modify Registry Disable Win Defender Raw Write Notif](/endpoint/windows_modify_registry_disable_win_defender_raw_write_notif/) | [Modify Registry](/tags/#modify-registry)| Anomaly | -| [Windows Modify Registry Disable Windows Security Center Notif](/endpoint/windows_modify_registry_disable_windows_security_center_notif/) | [Modify Registry](/tags/#modify-registry)| Anomaly | -| [Windows Modify Registry Disabling WER Settings](/endpoint/windows_modify_registry_disabling_wer_settings/) | [Modify Registry](/tags/#modify-registry)| TTP | -| [Windows Modify Registry DisAllow Windows App](/endpoint/windows_modify_registry_disallow_windows_app/) | [Modify Registry](/tags/#modify-registry)| TTP | -| [Windows Modify Registry Regedit Silent Reg Import](/endpoint/windows_modify_registry_regedit_silent_reg_import/) | [Modify Registry](/tags/#modify-registry)| Anomaly | -| [Windows Modify Registry Suppress Win Defender Notif](/endpoint/windows_modify_registry_suppress_win_defender_notif/) | [Modify Registry](/tags/#modify-registry)| Anomaly | -| [Windows Powershell Import Applocker Policy](/endpoint/windows_powershell_import_applocker_policy/) | [PowerShell](/tags/#powershell)| TTP | -| [Windows Remote Access Software RMS Registry](/endpoint/windows_remote_access_software_rms_registry/) | [Remote Access Software](/tags/#remote-access-software)| TTP | -| [Windows Remote Service Rdpwinst Tool Execution](/endpoint/windows_remote_service_rdpwinst_tool_execution/) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol), [Remote Services](/tags/#remote-services)| TTP | -| [Windows Remote Services Allow Rdp In Firewall](/endpoint/windows_remote_services_allow_rdp_in_firewall/) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol), [Remote Services](/tags/#remote-services)| Anomaly | -| [Windows Remote Services Allow Remote Assistance](/endpoint/windows_remote_services_allow_remote_assistance/) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol), [Remote Services](/tags/#remote-services)| Anomaly | -| [Windows Remote Services Rdp Enable](/endpoint/windows_remote_services_rdp_enable/) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol), [Remote Services](/tags/#remote-services)| TTP | -| [Windows Service Stop By Deletion](/endpoint/windows_service_stop_by_deletion/) | [Service Stop](/tags/#service-stop)| TTP | -| [Windows Valid Account With Never Expires Password](/endpoint/windows_valid_account_with_never_expires_password/) | [Service Stop](/tags/#service-stop)| TTP | -| [Wmic NonInteractive App Uninstallation](/endpoint/wmic_noninteractive_app_uninstallation/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| Hunting | - -#### Reference - -* [https://success.trendmicro.com/dcx/s/solution/000146108-azorult-malware-information?language=en_US&sfdcIFrameOrigin=null](https://success.trendmicro.com/dcx/s/solution/000146108-azorult-malware-information?language=en_US&sfdcIFrameOrigin=null) -* [https://app.any.run/tasks/a6f2ffe2-e6e2-4396-ae2e-04ea0143f2d8/](https://app.any.run/tasks/a6f2ffe2-e6e2-4396-ae2e-04ea0143f2d8/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/azorult.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/azure_active_directory_account_takeover.md b/docs/_stories/azure_active_directory_account_takeover.md deleted file mode 100644 index 5ed75782ac..0000000000 --- a/docs/_stories/azure_active_directory_account_takeover.md +++ /dev/null @@ -1,52 +0,0 @@ ---- -title: "Azure Active Directory Account Takeover" -last_modified_at: 2022-07-14 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Monitor for activities and techniques associated with Account Takover attacks against Azure Active Directory tenants. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: -- **Last Updated**: 2022-07-14 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 41514c46-7118-4eab-a9bb-f3bfa4e3bea9 - -#### Narrative - -Azure Active Directory (Azure AD) is Microsofts enterprise cloud-based identity and access management (IAM) service. Azure AD is the backbone of most of Azure services like Office 365. It can sync with on-premise Active Directory environments and provide authentication to other cloud-based systems via the OAuth protocol. According to Microsoft, Azure AD manages more than 1.2 billion identities and processes over 8 billion authentications per day.\ Account Takeover (ATO) is an attack whereby cybercriminals gain unauthorized access to online accounts by using different techniques like brute force, social engineering, phishing & spear phishing, credential stuffing, etc. By posing as the real user, cyber-criminals can change account details, send out phishing emails, steal financial information or sensitive data, or use any stolen information to access further accounts within the organization.\ This analytic storic groups detections that can help security operations teams identify the potential compromise of Azure Active Directory accounts. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Azure Active Directory High Risk Sign-in](/cloud/azure_active_directory_high_risk_sign-in/) | [Brute Force](/tags/#brute-force), [Password Spraying](/tags/#password-spraying)| TTP | -| [Azure AD Authentication Failed During MFA Challenge](/cloud/azure_ad_authentication_failed_during_mfa_challenge/) | [Valid Accounts](/tags/#valid-accounts), [Cloud Accounts](/tags/#cloud-accounts), [Multi-Factor Authentication Request Generation](/tags/#multi-factor-authentication-request-generation)| TTP | -| [Azure AD Multiple Users Failing To Authenticate From Ip](/cloud/azure_ad_multiple_users_failing_to_authenticate_from_ip/) | [Brute Force](/tags/#brute-force), [Password Spraying](/tags/#password-spraying)| Anomaly | -| [Azure AD Successful PowerShell Authentication](/cloud/azure_ad_successful_powershell_authentication/) | [Valid Accounts](/tags/#valid-accounts), [Cloud Accounts](/tags/#cloud-accounts)| TTP | -| [Azure AD Successful Single-Factor Authentication](/cloud/azure_ad_successful_single-factor_authentication/) | [Security Account Manager](/tags/#security-account-manager)| TTP | -| [Azure AD Unusual Number of Failed Authentications From Ip](/cloud/azure_ad_unusual_number_of_failed_authentications_from_ip/) | [Brute Force](/tags/#brute-force), [Password Spraying](/tags/#password-spraying)| Anomaly | - -#### Reference - -* [https://docs.microsoft.com/en-us/azure/active-directory/fundamentals/active-directory-whatis](https://docs.microsoft.com/en-us/azure/active-directory/fundamentals/active-directory-whatis) -* [https://azure.microsoft.com/en-us/services/active-directory/#overview](https://azure.microsoft.com/en-us/services/active-directory/#overview) -* [https://attack.mitre.org/techniques/T1586/](https://attack.mitre.org/techniques/T1586/) -* [https://docs.microsoft.com/en-us/azure/active-directory/fundamentals/active-directory-compare-azure-ad-to-ad](https://docs.microsoft.com/en-us/azure/active-directory/fundamentals/active-directory-compare-azure-ad-to-ad) -* [https://www.imperva.com/learn/application-security/account-takeover-ato/](https://www.imperva.com/learn/application-security/account-takeover-ato/) -* [https://www.varonis.com/blog/azure-active-directory](https://www.varonis.com/blog/azure-active-directory) -* [https://www.barracuda.com/glossary/account-takeover](https://www.barracuda.com/glossary/account-takeover) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/azure_active_directory_account_takeover.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_stories/baron_samedit_cve-2021-3156.md b/docs/_stories/baron_samedit_cve-2021-3156.md deleted file mode 100644 index 9b82076f7e..0000000000 --- a/docs/_stories/baron_samedit_cve-2021-3156.md +++ /dev/null @@ -1,43 +0,0 @@ ---- -title: "Baron Samedit CVE-2021-3156" -last_modified_at: 2021-01-27 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Uncover activity consistent with CVE-2021-3156. Discovered by the Qualys Research Team, this vulnerability has been found to affect sudo across multiple Linux distributions (Ubuntu 20.04 and prior, Debian 10 and prior, Fedora 33 and prior). As this vulnerability was committed to code in July 2011, there will be many distributions affected. Successful exploitation of this vulnerability allows any unprivileged user to gain root privileges on the vulnerable host. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: -- **Last Updated**: 2021-01-27 -- **Author**: Shannon Davis, Splunk -- **ID**: 817b0dfc-23ba-4bcc-96cc-2cb77e428fbe - -#### Narrative - -A non-privledged user is able to execute the sudoedit command to trigger a buffer overflow. After the successful buffer overflow, they are then able to gain root privileges on the affected host. The conditions needed to be run are a trailing "\" along with shell and edit flags. Monitoring the /var/log directory on Linux hosts using the Splunk Universal Forwarder will allow you to pick up this behavior when using the provided detection. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Detect Baron Samedit CVE-2021-3156](/endpoint/detect_baron_samedit_cve-2021-3156/) | [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation)| TTP | -| [Detect Baron Samedit CVE-2021-3156 Segfault](/endpoint/detect_baron_samedit_cve-2021-3156_segfault/) | [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation)| TTP | -| [Detect Baron Samedit CVE-2021-3156 via OSQuery](/endpoint/detect_baron_samedit_cve-2021-3156_via_osquery/) | [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation)| TTP | - -#### Reference - -* [https://blog.qualys.com/vulnerabilities-research/2021/01/26/cve-2021-3156-heap-based-buffer-overflow-in-sudo-baron-samedit](https://blog.qualys.com/vulnerabilities-research/2021/01/26/cve-2021-3156-heap-based-buffer-overflow-in-sudo-baron-samedit) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/baron_samedit_cve-2021-3156.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/bits_jobs.md b/docs/_stories/bits_jobs.md deleted file mode 100644 index 8f941660f3..0000000000 --- a/docs/_stories/bits_jobs.md +++ /dev/null @@ -1,45 +0,0 @@ ---- -title: "BITS Jobs" -last_modified_at: 2021-03-26 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Adversaries may abuse BITS jobs to persistently execute or clean up after malicious payloads. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-03-26 -- **Author**: Michael Haag, Splunk -- **ID**: dbc7edce-8e4c-11eb-9f31-acde48001122 - -#### Narrative - -Windows Background Intelligent Transfer Service (BITS) is a low-bandwidth, asynchronous file transfer mechanism exposed through Component Object Model (COM). BITS is commonly used by updaters, messengers, and other applications preferred to operate in the background (using available idle bandwidth) without interrupting other networked applications. File transfer tasks are implemented as BITS jobs, which contain a queue of one or more file operations. The interface to create and manage BITS jobs is accessible through PowerShell and the BITSAdmin tool. Adversaries may abuse BITS to download, execute, and even clean up after running malicious code. BITS tasks are self-contained in the BITS job database, without new files or registry modifications, and often permitted by host firewalls. BITS enabled execution may also enable persistence by creating long-standing jobs (the default maximum lifetime is 90 days and extendable) or invoking an arbitrary program when a job completes or errors (including after system reboots). - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [BITS Job Persistence](/endpoint/bits_job_persistence/) | [BITS Jobs](/tags/#bits-jobs)| TTP | -| [BITSAdmin Download File](/endpoint/bitsadmin_download_file/) | [BITS Jobs](/tags/#bits-jobs), [Ingress Tool Transfer](/tags/#ingress-tool-transfer)| TTP | -| [PowerShell Start-BitsTransfer](/endpoint/powershell_start-bitstransfer/) | [BITS Jobs](/tags/#bits-jobs)| TTP | - -#### Reference - -* [https://attack.mitre.org/techniques/T1197/](https://attack.mitre.org/techniques/T1197/) -* [https://docs.microsoft.com/en-us/windows/win32/bits/bitsadmin-tool](https://docs.microsoft.com/en-us/windows/win32/bits/bitsadmin-tool) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/bits_jobs.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/blackmatter_ransomware.md b/docs/_stories/blackmatter_ransomware.md deleted file mode 100644 index 4b8d85e38d..0000000000 --- a/docs/_stories/blackmatter_ransomware.md +++ /dev/null @@ -1,50 +0,0 @@ ---- -title: "BlackMatter Ransomware" -last_modified_at: 2021-09-06 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Leverage searches that allow you to detect and investigate unusual activities that might relate to the BlackMatter ransomware, including looking for file writes associated with BlackMatter, force safe mode boot, autadminlogon account registry modification and more. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-09-06 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 0da348a3-78a0-412e-ab27-2de9dd7f9fee - -#### Narrative - -BlackMatter ransomware campaigns targeting healthcare and other vertical sectors, involve the use of ransomware payloads along with exfiltration of data per HHS bulletin. Malicious actors demand payment for ransome of data and threaten deletion and exposure of exfiltrated data. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Add DefaultUser And Password In Registry](/endpoint/add_defaultuser_and_password_in_registry/) | [Credentials in Registry](/tags/#credentials-in-registry), [Unsecured Credentials](/tags/#unsecured-credentials)| Anomaly | -| [Auto Admin Logon Registry Entry](/endpoint/auto_admin_logon_registry_entry/) | [Credentials in Registry](/tags/#credentials-in-registry), [Unsecured Credentials](/tags/#unsecured-credentials)| TTP | -| [Bcdedit Command Back To Normal Mode Boot](/endpoint/bcdedit_command_back_to_normal_mode_boot/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery)| TTP | -| [Change To Safe Mode With Network Config](/endpoint/change_to_safe_mode_with_network_config/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery)| TTP | -| [Known Services Killed by Ransomware](/endpoint/known_services_killed_by_ransomware/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery)| TTP | -| [Modification Of Wallpaper](/endpoint/modification_of_wallpaper/) | [Defacement](/tags/#defacement)| TTP | -| [Ransomware Notes bulk creation](/endpoint/ransomware_notes_bulk_creation/) | [Data Encrypted for Impact](/tags/#data-encrypted-for-impact)| Anomaly | - -#### Reference - -* [https://news.sophos.com/en-us/2021/08/09/blackmatter-ransomware-emerges-from-the-shadow-of-darkside/](https://news.sophos.com/en-us/2021/08/09/blackmatter-ransomware-emerges-from-the-shadow-of-darkside/) -* [https://www.bleepingcomputer.com/news/security/blackmatter-ransomware-gang-rises-from-the-ashes-of-darkside-revil/](https://www.bleepingcomputer.com/news/security/blackmatter-ransomware-gang-rises-from-the-ashes-of-darkside-revil/) -* [https://blog.malwarebytes.com/ransomware/2021/07/blackmatter-a-new-ransomware-group-claims-link-to-darkside-revil/](https://blog.malwarebytes.com/ransomware/2021/07/blackmatter-a-new-ransomware-group-claims-link-to-darkside-revil/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/blackmatter_ransomware.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/brand_monitoring.md b/docs/_stories/brand_monitoring.md deleted file mode 100644 index ef53170244..0000000000 --- a/docs/_stories/brand_monitoring.md +++ /dev/null @@ -1,51 +0,0 @@ ---- -title: "Brand Monitoring" -last_modified_at: 2017-12-19 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Email - - Network_Resolution - - Web - - Actions on Objectives - - Delivery ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Detect and investigate activity that may indicate that an adversary is using faux domains to mislead users into interacting with malicious infrastructure. Monitor DNS, email, and web traffic for permutations of your brand name. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Email](https://docs.splunk.com/Documentation/CIM/latest/User/Email), [Network_Resolution](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkResolution), [Web](https://docs.splunk.com/Documentation/CIM/latest/User/Web) -- **Last Updated**: 2017-12-19 -- **Author**: David Dorsey, Splunk -- **ID**: 91c676cf-0b23-438d-abee-f6335e1fce78 - -#### Narrative - -While you can educate your users and customers about the risks and threats posed by typosquatting, phishing, and corporate espionage, human error is a persistent fact of life. Of course, your adversaries are all too aware of this reality and will happily leverage it for nefarious purposes whenever possible3phishing with lookalike addresses, embedding faux command-and-control domains in malware, and hosting malicious content on domains that closely mimic your corporate servers. This is where brand monitoring comes in.\ -You can use our adaptation of `DNSTwist`, together with the support searches in this Analytic Story, to generate permutations of specified brands and external domains. Splunk can monitor email, DNS requests, and web traffic for these permutations and provide you with early warnings and situational awareness--powerful elements of an effective defense.\ -Notable events will include IP addresses, URLs, and user data. Drilling down can provide you with even more actionable intelligence, including likely geographic information, contextual searches to help you scope the problem, and investigative searches. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Monitor DNS For Brand Abuse](/deprecated/monitor_dns_for_brand_abuse/) | None| TTP | -| [Monitor Email For Brand Abuse](/application/monitor_email_for_brand_abuse/) | None| TTP | -| [Monitor Web Traffic For Brand Abuse](/web/monitor_web_traffic_for_brand_abuse/) | None| TTP | - -#### Reference - -* [https://www.zerofox.com/blog/what-is-digital-risk-monitoring/](https://www.zerofox.com/blog/what-is-digital-risk-monitoring/) -* [https://securingtomorrow.mcafee.com/consumer/family-safety/what-is-typosquatting/](https://securingtomorrow.mcafee.com/consumer/family-safety/what-is-typosquatting/) -* [https://blog.malwarebytes.com/cybercrime/2016/06/explained-typosquatting/](https://blog.malwarebytes.com/cybercrime/2016/06/explained-typosquatting/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/brand_monitoring.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/caddy_wiper.md b/docs/_stories/caddy_wiper.md deleted file mode 100644 index 13d1dfb255..0000000000 --- a/docs/_stories/caddy_wiper.md +++ /dev/null @@ -1,44 +0,0 @@ ---- -title: "Caddy Wiper" -last_modified_at: 2022-03-25 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Caddy Wiper is a destructive payload that detects if its running on a Domain Controller and executes killswitch if detected. If not in a DC it destroys Users and subsequent mapped drives. This wiper also destroys drive partitions inculding boot partitions. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-03-25 -- **Author**: Teoderick Contreras, Rod Soto, Splunk -- **ID**: 435a156a-8ef1-4184-bd52-22328fb65d3a - -#### Narrative - -Caddy Wiper is destructive malware operation found by ESET multiple organizations in Ukraine. This malicious payload destroys user files, avoids executing on Dnomain Controllers and destroys boot and drive partitions. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Windows Raw Access To Disk Volume Partition](/endpoint/windows_raw_access_to_disk_volume_partition/) | [Disk Structure Wipe](/tags/#disk-structure-wipe), [Disk Wipe](/tags/#disk-wipe)| Anomaly | -| [Windows Raw Access To Master Boot Record Drive](/endpoint/windows_raw_access_to_master_boot_record_drive/) | [Disk Structure Wipe](/tags/#disk-structure-wipe), [Disk Wipe](/tags/#disk-wipe)| TTP | - -#### Reference - -* [https://twitter.com/ESETresearch/status/1503436420886712321](https://twitter.com/ESETresearch/status/1503436420886712321) -* [https://www.welivesecurity.com/2022/03/15/caddywiper-new-wiper-malware-discovered-ukraine/](https://www.welivesecurity.com/2022/03/15/caddywiper-new-wiper-malware-discovered-ukraine/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/caddy_wiper.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/clop_ransomware.md b/docs/_stories/clop_ransomware.md deleted file mode 100644 index 69d1b00ab0..0000000000 --- a/docs/_stories/clop_ransomware.md +++ /dev/null @@ -1,58 +0,0 @@ ---- -title: "Clop Ransomware" -last_modified_at: 2021-03-17 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Actions on Objectives - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Leverage searches that allow you to detect and investigate unusual activities that might relate to the Clop ransomware, including looking for file writes associated with Clope, encrypting network shares, deleting and resizing shadow volume storage, registry key modification, deleting of security logs, and more. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-03-17 -- **Author**: Rod Soto, Teoderick Contreras, Splunk -- **ID**: 5a6f6849-1a26-4fae-aa05-fa730556eeb6 - -#### Narrative - -Clop ransomware campaigns targeting healthcare and other vertical sectors, involve the use of ransomware payloads along with exfiltration of data per HHS bulletin. Malicious actors demand payment for ransome of data and threaten deletion and exposure of exfiltrated data. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Clop Common Exec Parameter](/endpoint/clop_common_exec_parameter/) | [User Execution](/tags/#user-execution)| TTP | -| [Clop Ransomware Known Service Name](/endpoint/clop_ransomware_known_service_name/) | [Create or Modify System Process](/tags/#create-or-modify-system-process)| TTP | -| [Common Ransomware Extensions](/endpoint/common_ransomware_extensions/) | [Data Destruction](/tags/#data-destruction)| Hunting | -| [Common Ransomware Notes](/endpoint/common_ransomware_notes/) | [Data Destruction](/tags/#data-destruction)| Hunting | -| [Deleting Shadow Copies](/endpoint/deleting_shadow_copies/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery)| TTP | -| [High Process Termination Frequency](/endpoint/high_process_termination_frequency/) | [Data Encrypted for Impact](/tags/#data-encrypted-for-impact)| Anomaly | -| [Process Deleting Its Process File Path](/endpoint/process_deleting_its_process_file_path/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host)| TTP | -| [Ransomware Notes bulk creation](/endpoint/ransomware_notes_bulk_creation/) | [Data Encrypted for Impact](/tags/#data-encrypted-for-impact)| Anomaly | -| [Resize ShadowStorage volume](/endpoint/resize_shadowstorage_volume/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery)| TTP | -| [Suspicious Event Log Service Behavior](/endpoint/suspicious_event_log_service_behavior/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host), [Clear Windows Event Logs](/tags/#clear-windows-event-logs)| TTP | -| [Suspicious wevtutil Usage](/endpoint/suspicious_wevtutil_usage/) | [Clear Windows Event Logs](/tags/#clear-windows-event-logs), [Indicator Removal on Host](/tags/#indicator-removal-on-host)| TTP | -| [Windows Event Log Cleared](/endpoint/windows_event_log_cleared/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host), [Clear Windows Event Logs](/tags/#clear-windows-event-logs)| TTP | -| [Windows High File Deletion Frequency](/endpoint/windows_high_file_deletion_frequency/) | [Data Destruction](/tags/#data-destruction)| Anomaly | -| [Windows Service Created With Suspicious Service Path](/endpoint/windows_service_created_with_suspicious_service_path/) | [System Services](/tags/#system-services), [Service Execution](/tags/#service-execution)| TTP | - -#### Reference - -* [https://www.hhs.gov/sites/default/files/analyst-note-cl0p-tlp-white.pdf](https://www.hhs.gov/sites/default/files/analyst-note-cl0p-tlp-white.pdf) -* [https://securityaffairs.co/wordpress/115250/data-breach/qualys-clop-ransomware.html](https://securityaffairs.co/wordpress/115250/data-breach/qualys-clop-ransomware.html) -* [https://www.darkreading.com/attacks-breaches/qualys-is-the-latest-victim-of-accellion-data-breach/d/d-id/1340323](https://www.darkreading.com/attacks-breaches/qualys-is-the-latest-victim-of-accellion-data-breach/d/d-id/1340323) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/clop_ransomware.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/cloud_cryptomining.md b/docs/_stories/cloud_cryptomining.md deleted file mode 100644 index 3ea75f75ac..0000000000 --- a/docs/_stories/cloud_cryptomining.md +++ /dev/null @@ -1,50 +0,0 @@ ---- -title: "Cloud Cryptomining" -last_modified_at: 2019-10-02 -toc: true -toc_label: "" -tags: - - Splunk Security Analytics for AWS - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Change - - Actions on Objectives ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Monitor your cloud compute instances for activities related to cryptojacking/cryptomining. New instances that originate from previously unseen regions, users who launch abnormally high numbers of instances, or compute instances started by previously unseen users are just a few examples of potentially malicious behavior. - -- **Product**: Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Change](https://docs.splunk.com/Documentation/CIM/latest/User/Change) -- **Last Updated**: 2019-10-02 -- **Author**: David Dorsey, Splunk -- **ID**: 3b96d13c-fdc7-45dd-b3ad-c132b31cdd2a - -#### Narrative - -Cryptomining is an intentionally difficult, resource-intensive business. Its complexity was designed into the process to ensure that the number of blocks mined each day would remain steady. So, it's par for the course that ambitious, but unscrupulous, miners make amassing the computing power of large enterprises--a practice known as cryptojacking--a top priority. \ -Cryptojacking has attracted an increasing amount of media attention since its explosion in popularity in the fall of 2017. The attacks have moved from in-browser exploits and mobile phones to enterprise cloud services, such as Amazon Web Services (AWS), Google Cloud Platform (GCP), and Azure. It's difficult to determine exactly how widespread the practice has become, since bad actors continually evolve their ability to escape detection, including employing unlisted endpoints, moderating their CPU usage, and hiding the mining pool's IP address behind a free CDN. \ -When malicious miners appropriate a cloud instance, often spinning up hundreds of new instances, the costs can become astronomical for the account holder. So it is critically important to monitor your systems for suspicious activities that could indicate that your network has been infiltrated. \ -This Analytic Story is focused on detecting suspicious new instances in your cloud environment to help prevent cryptominers from gaining a foothold. It contains detection searches that will detect when a previously unused instance type or AMI is used. It also contains support searches to build lookup files to ensure proper execution of the detection searches. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Cloud Compute Instance Created By Previously Unseen User](/cloud/cloud_compute_instance_created_by_previously_unseen_user/) | [Cloud Accounts](/tags/#cloud-accounts), [Valid Accounts](/tags/#valid-accounts)| Anomaly | -| [Cloud Compute Instance Created In Previously Unused Region](/cloud/cloud_compute_instance_created_in_previously_unused_region/) | [Unused/Unsupported Cloud Regions](/tags/#unused/unsupported-cloud-regions)| Anomaly | -| [Cloud Compute Instance Created With Previously Unseen Image](/cloud/cloud_compute_instance_created_with_previously_unseen_image/) | None| Anomaly | -| [Cloud Compute Instance Created With Previously Unseen Instance Type](/cloud/cloud_compute_instance_created_with_previously_unseen_instance_type/) | None| Anomaly | -| [Abnormally High Number Of Cloud Instances Launched](/cloud/abnormally_high_number_of_cloud_instances_launched/) | [Cloud Accounts](/tags/#cloud-accounts), [Valid Accounts](/tags/#valid-accounts)| Anomaly | - -#### Reference - -* [https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf](https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/cloud_cryptomining.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/cloud_federated_credential_abuse.md b/docs/_stories/cloud_federated_credential_abuse.md deleted file mode 100644 index 6cda73f89c..0000000000 --- a/docs/_stories/cloud_federated_credential_abuse.md +++ /dev/null @@ -1,58 +0,0 @@ ---- -title: "Cloud Federated Credential Abuse" -last_modified_at: 2021-01-26 -toc: true -toc_label: "" -tags: - - Splunk Security Analytics for AWS - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Actions on Objectives - - Command & Control - - Exploitation - - Installation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytical story addresses events that indicate abuse of cloud federated credentials. These credentials are usually extracted from endpoint desktop or servers specially those servers that provide federation services such as Windows Active Directory Federation Services. Identity Federation relies on objects such as Oauth2 tokens, cookies or SAML assertions in order to provide seamless access between cloud and perimeter environments. If these objects are either hijacked or forged then attackers will be able to pivot into victim's cloud environements. - -- **Product**: Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-01-26 -- **Author**: Rod Soto, Splunk -- **ID**: cecdc1e7-0af2-4a55-8967-b9ea62c0317d - -#### Narrative - -This story is composed of detection searches based on endpoint that addresses the use of Mimikatz, Escalation of Privileges and Abnormal processes that may indicate the extraction of Federated directory objects such as passwords, Oauth2 tokens, certificates and keys. Cloud environment (AWS, Azure) related events are also addressed in specific cloud environment detection searches. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [AWS SAML Access by Provider User and Principal](/cloud/aws_saml_access_by_provider_user_and_principal/) | [Valid Accounts](/tags/#valid-accounts)| Anomaly | -| [AWS SAML Update identity provider](/cloud/aws_saml_update_identity_provider/) | [Valid Accounts](/tags/#valid-accounts)| TTP | -| [O365 Add App Role Assignment Grant User](/cloud/o365_add_app_role_assignment_grant_user/) | [Cloud Account](/tags/#cloud-account), [Create Account](/tags/#create-account)| TTP | -| [O365 Added Service Principal](/cloud/o365_added_service_principal/) | [Cloud Account](/tags/#cloud-account), [Create Account](/tags/#create-account)| TTP | -| [O365 Excessive SSO logon errors](/cloud/o365_excessive_sso_logon_errors/) | [Modify Authentication Process](/tags/#modify-authentication-process)| Anomaly | -| [O365 New Federated Domain Added](/cloud/o365_new_federated_domain_added/) | [Cloud Account](/tags/#cloud-account), [Create Account](/tags/#create-account)| TTP | -| [Detect Mimikatz Via PowerShell And EventCode 4703](/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703/) | [LSASS Memory](/tags/#lsass-memory)| TTP | -| [Certutil exe certificate extraction](/endpoint/certutil_exe_certificate_extraction/) | None| TTP | -| [Detect Mimikatz Using Loaded Images](/endpoint/detect_mimikatz_using_loaded_images/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping)| TTP | -| [Registry Keys Used For Privilege Escalation](/endpoint/registry_keys_used_for_privilege_escalation/) | [Image File Execution Options Injection](/tags/#image-file-execution-options-injection), [Event Triggered Execution](/tags/#event-triggered-execution)| TTP | -| [Detect Rare Executables](/endpoint/detect_rare_executables/) | None| Anomaly | - -#### Reference - -* [https://www.cyberark.com/resources/threat-research-blog/golden-saml-newly-discovered-attack-technique-forges-authentication-to-cloud-apps](https://www.cyberark.com/resources/threat-research-blog/golden-saml-newly-discovered-attack-technique-forges-authentication-to-cloud-apps) -* [https://www.fireeye.com/content/dam/fireeye-www/blog/pdfs/wp-m-unc2452-2021-000343-01.pdf](https://www.fireeye.com/content/dam/fireeye-www/blog/pdfs/wp-m-unc2452-2021-000343-01.pdf) -* [https://us-cert.cisa.gov/ncas/alerts/aa21-008a](https://us-cert.cisa.gov/ncas/alerts/aa21-008a) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/cloud_federated_credential_abuse.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/cobalt_strike.md b/docs/_stories/cobalt_strike.md deleted file mode 100644 index 5a4b0e2248..0000000000 --- a/docs/_stories/cobalt_strike.md +++ /dev/null @@ -1,74 +0,0 @@ ---- -title: "Cobalt Strike" -last_modified_at: 2021-02-16 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Actions on Objectives - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Cobalt Strike is threat emulation software. Red teams and penetration testers use Cobalt Strike to demonstrate the risk of a breach and evaluate mature security programs. Most recently, Cobalt Strike has become the choice tool by threat groups due to its ease of use and extensibility. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-02-16 -- **Author**: Michael Haag, Splunk -- **ID**: bcfd17e8-5461-400a-80a2-3b7d1459220c - -#### Narrative - -This Analytic Story supports you to detect Tactics, Techniques and Procedures (TTPs) from Cobalt Strike. Cobalt Strike has many ways to be enhanced by using aggressor scripts, malleable C2 profiles, default attack packages, and much more. For endpoint behavior, Cobalt Strike is most commonly identified via named pipes, spawn to processes, and DLL function names. Many additional variables are provided for in memory operation of the beacon implant. On the network, depending on the malleable C2 profile used, it is near infinite in the amount of ways to conceal the C2 traffic with Cobalt Strike. Not every query may be specific to Cobalt Strike the tool, but the methodologies and techniques used by it.\ -Splunk Threat Research reviewed all publicly available instances of Malleabe C2 Profiles and generated a list of the most commonly used spawnto and pipenames.\ -`Spawnto_x86` and `spawnto_x64` is the process that Cobalt Strike will spawn and injects shellcode into.\ -Pipename sets the named pipe name used in Cobalt Strikes Beacon SMB C2 traffic.\ -With that, new detections were generated focused on these spawnto processes spawning without command line arguments. Similar, the named pipes most commonly used by Cobalt Strike added as a detection. In generating content for Cobalt Strike, the following is considered:\ -- Is it normal for spawnto_ value to have no command line arguments? No command line arguments and a network connection?\ -- What is the default, or normal, process lineage for spawnto_ value?\ -- Does the spawnto_ value make network connections?\ -- Is it normal for spawnto_ value to load jscript, vbscript, Amsi.dll, and clr.dll?\ -While investigating a detection related to this Analytic Story, keep in mind the parent process, process path, and any file modifications that may occur. Tuning may need to occur to remove any false positives. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Anomalous usage of 7zip](/endpoint/anomalous_usage_of_7zip/) | [Archive via Utility](/tags/#archive-via-utility), [Archive Collected Data](/tags/#archive-collected-data)| Anomaly | -| [CMD Echo Pipe - Escalation](/endpoint/cmd_echo_pipe_-_escalation/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Windows Command Shell](/tags/#windows-command-shell), [Windows Service](/tags/#windows-service), [Create or Modify System Process](/tags/#create-or-modify-system-process)| TTP | -| [Cobalt Strike Named Pipes](/endpoint/cobalt_strike_named_pipes/) | [Process Injection](/tags/#process-injection)| TTP | -| [Detect Regsvr32 Application Control Bypass](/endpoint/detect_regsvr32_application_control_bypass/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Regsvr32](/tags/#regsvr32)| TTP | -| [DLLHost with no Command Line Arguments with Network](/endpoint/dllhost_with_no_command_line_arguments_with_network/) | [Process Injection](/tags/#process-injection)| TTP | -| [GPUpdate with no Command Line Arguments with Network](/endpoint/gpupdate_with_no_command_line_arguments_with_network/) | [Process Injection](/tags/#process-injection)| TTP | -| [Rundll32 with no Command Line Arguments with Network](/endpoint/rundll32_with_no_command_line_arguments_with_network/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Rundll32](/tags/#rundll32)| TTP | -| [SearchProtocolHost with no Command Line with Network](/endpoint/searchprotocolhost_with_no_command_line_with_network/) | [Process Injection](/tags/#process-injection)| TTP | -| [Services Escalate Exe](/endpoint/services_escalate_exe/) | [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism)| TTP | -| [Suspicious DLLHost no Command Line Arguments](/endpoint/suspicious_dllhost_no_command_line_arguments/) | [Process Injection](/tags/#process-injection)| TTP | -| [Suspicious GPUpdate no Command Line Arguments](/endpoint/suspicious_gpupdate_no_command_line_arguments/) | [Process Injection](/tags/#process-injection)| TTP | -| [Suspicious microsoft workflow compiler rename](/endpoint/suspicious_microsoft_workflow_compiler_rename/) | [Masquerading](/tags/#masquerading), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Rename System Utilities](/tags/#rename-system-utilities)| Hunting | -| [Suspicious msbuild path](/endpoint/suspicious_msbuild_path/) | [Masquerading](/tags/#masquerading), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Rename System Utilities](/tags/#rename-system-utilities), [MSBuild](/tags/#msbuild)| TTP | -| [Suspicious MSBuild Rename](/endpoint/suspicious_msbuild_rename/) | [Masquerading](/tags/#masquerading), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Rename System Utilities](/tags/#rename-system-utilities), [MSBuild](/tags/#msbuild)| Hunting | -| [Suspicious Rundll32 StartW](/endpoint/suspicious_rundll32_startw/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Rundll32](/tags/#rundll32)| TTP | -| [Suspicious Rundll32 no Command Line Arguments](/endpoint/suspicious_rundll32_no_command_line_arguments/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Rundll32](/tags/#rundll32)| TTP | -| [Suspicious SearchProtocolHost no Command Line Arguments](/endpoint/suspicious_searchprotocolhost_no_command_line_arguments/) | [Process Injection](/tags/#process-injection)| TTP | - -#### Reference - -* [https://www.cobaltstrike.com/](https://www.cobaltstrike.com/) -* [https://www.infocyte.com/blog/2020/09/02/cobalt-strike-the-new-favorite-among-thieves/](https://www.infocyte.com/blog/2020/09/02/cobalt-strike-the-new-favorite-among-thieves/) -* [https://bluescreenofjeff.com/2017-01-24-how-to-write-malleable-c2-profiles-for-cobalt-strike/](https://bluescreenofjeff.com/2017-01-24-how-to-write-malleable-c2-profiles-for-cobalt-strike/) -* [https://blog.talosintelligence.com/2020/09/coverage-strikes-back-cobalt-strike-paper.html](https://blog.talosintelligence.com/2020/09/coverage-strikes-back-cobalt-strike-paper.html) -* [https://www.fireeye.com/blog/threat-research/2020/12/unauthorized-access-of-fireeye-red-team-tools.html](https://www.fireeye.com/blog/threat-research/2020/12/unauthorized-access-of-fireeye-red-team-tools.html) -* [https://github.com/MichaelKoczwara/Awesome-CobaltStrike-Defence](https://github.com/MichaelKoczwara/Awesome-CobaltStrike-Defence) -* [https://github.com/zer0yu/Awesome-CobaltStrike](https://github.com/zer0yu/Awesome-CobaltStrike) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/cobalt_strike.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/coldroot_macos_rat.md b/docs/_stories/coldroot_macos_rat.md deleted file mode 100644 index bc50283cb3..0000000000 --- a/docs/_stories/coldroot_macos_rat.md +++ /dev/null @@ -1,49 +0,0 @@ ---- -title: "ColdRoot MacOS RAT" -last_modified_at: 2019-01-09 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Command & Control - - Installation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Leverage searches that allow you to detect and investigate unusual activities that relate to the ColdRoot Remote Access Trojan that affects MacOS. An example of some of these activities are changing sensative binaries in the MacOS sub-system, detecting process names and executables associated with the RAT, detecting when a keyboard tab is installed on a MacOS machine and more. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2019-01-09 -- **Author**: Jose Hernandez, Splunk -- **ID**: bd91a2bc-d20b-4f44-a982-1bea98e86390 - -#### Narrative - -Conventional wisdom holds that Apple's MacOS operating system is significantly less vulnerable to attack than Windows machines. While that point is debatable, it is true that attacks against MacOS systems are much less common. However, this fact does not mean that Macs are impervious to breaches. To the contrary, research has shown that that Mac malware is increasing at an alarming rate. According to AV-test, in 2018, there were 86,865 new MacOS malware variants, up from 27,338 the year before—a 31% increase. In contrast, the independent research firm found that new Windows malware had increased from 65.17M to 76.86M during that same period, less than half the rate of growth. The bottom line is that while the numbers look a lot smaller than Windows, it's definitely time to take Mac security more seriously.\ -This Analytic Story addresses the ColdRoot remote access trojan (RAT), which was uploaded to Github in 2016, but was still escaping detection by the first quarter of 2018, when a new, more feature-rich variant was discovered masquerading as an Apple audio driver. Among other capabilities, the Pascal-based ColdRoot can heist passwords from users' keychains and remotely control infected machines without detection. In the initial report of his findings, Patrick Wardle, Chief Research Officer for Digita Security, explained that the new ColdRoot RAT could start and kill processes on the breached system, spawn new remote-desktop sessions, take screen captures and assemble them into a live stream of the victim's desktop, and more.\ -Searches in this Analytic Story leverage the capabilities of OSquery to address ColdRoot detection from several different angles, such as looking for the existence of associated files and processes, and monitoring for signs of an installed keylogger. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Osquery pack - ColdRoot detection](/deprecated/osquery_pack_-_coldroot_detection/) | None| TTP | -| [MacOS - Re-opened Applications](/endpoint/macos_-_re-opened_applications/) | None| TTP | -| [Processes Tapping Keyboard Events](/endpoint/processes_tapping_keyboard_events/) | None| TTP | - -#### Reference - -* [https://www.intego.com/mac-security-blog/osxcoldroot-and-the-rat-invasion/](https://www.intego.com/mac-security-blog/osxcoldroot-and-the-rat-invasion/) -* [https://objective-see.com/blog/blog_0x2A.html](https://objective-see.com/blog/blog_0x2A.html) -* [https://www.bleepingcomputer.com/news/security/coldroot-rat-still-undetectable-despite-being-uploaded-on-github-two-years-ago/](https://www.bleepingcomputer.com/news/security/coldroot-rat-still-undetectable-despite-being-uploaded-on-github-two-years-ago/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/coldroot_macos_rat.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/collection_and_staging.md b/docs/_stories/collection_and_staging.md deleted file mode 100644 index 80ed684105..0000000000 --- a/docs/_stories/collection_and_staging.md +++ /dev/null @@ -1,53 +0,0 @@ ---- -title: "Collection and Staging" -last_modified_at: 2020-02-03 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Network_Traffic - - Actions on Objectives - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Monitor for and investigate activities--such as suspicious writes to the Windows Recycling Bin or email servers sending high amounts of traffic to specific hosts, for example--that may indicate that an adversary is harvesting and exfiltrating sensitive data. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint), [Network_Traffic](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkTraffic) -- **Last Updated**: 2020-02-03 -- **Author**: Rico Valdez, Splunk -- **ID**: 8e03c61e-13c4-4dcd-bfbe-5ce5a8dc031a - -#### Narrative - -A common adversary goal is to identify and exfiltrate data of value from a target organization. This data may include email conversations and addresses, confidential company information, links to network design/infrastructure, important dates, and so on.\ - Attacks are composed of three activities: identification, collection, and staging data for exfiltration. Identification typically involves scanning systems and observing user activity. Collection can involve the transfer of large amounts of data from various repositories. Staging/preparation includes moving data to a central location and compressing (and optionally encoding and/or encrypting) it. All of these activities provide opportunities for defenders to identify their presence. \ -Use the searches to detect and monitor suspicious behavior related to these activities. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Suspicious writes to System Volume Information](/deprecated/suspicious_writes_to_system_volume_information/) | [Masquerading](/tags/#masquerading)| Hunting | -| [Detect Renamed 7-Zip](/endpoint/detect_renamed_7-zip/) | [Archive via Utility](/tags/#archive-via-utility), [Archive Collected Data](/tags/#archive-collected-data)| Hunting | -| [Detect Renamed WinRAR](/endpoint/detect_renamed_winrar/) | [Archive via Utility](/tags/#archive-via-utility), [Archive Collected Data](/tags/#archive-collected-data)| Hunting | -| [Suspicious writes to windows Recycle Bin](/endpoint/suspicious_writes_to_windows_recycle_bin/) | [Masquerading](/tags/#masquerading)| TTP | -| [Email files written outside of the Outlook directory](/application/email_files_written_outside_of_the_outlook_directory/) | [Email Collection](/tags/#email-collection), [Local Email Collection](/tags/#local-email-collection)| TTP | -| [Email servers sending high volume traffic to hosts](/application/email_servers_sending_high_volume_traffic_to_hosts/) | [Email Collection](/tags/#email-collection), [Remote Email Collection](/tags/#remote-email-collection)| Anomaly | -| [Hosts receiving high volume of network traffic from email server](/network/hosts_receiving_high_volume_of_network_traffic_from_email_server/) | [Remote Email Collection](/tags/#remote-email-collection), [Email Collection](/tags/#email-collection)| Anomaly | - -#### Reference - -* [https://attack.mitre.org/wiki/Collection](https://attack.mitre.org/wiki/Collection) -* [https://attack.mitre.org/wiki/Technique/T1074](https://attack.mitre.org/wiki/Technique/T1074) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/collection_and_staging.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/command_and_control.md b/docs/_stories/command_and_control.md deleted file mode 100644 index bc37a93a9b..0000000000 --- a/docs/_stories/command_and_control.md +++ /dev/null @@ -1,65 +0,0 @@ ---- -title: "Command and Control" -last_modified_at: 2018-06-01 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Network_Resolution - - Network_Traffic - - Actions on Objectives - - Command & Control - - Delivery - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Detect and investigate tactics, techniques, and procedures leveraged by attackers to establish and operate command and control channels. Implants installed by attackers on compromised endpoints use these channels to receive instructions and send data back to the malicious operators. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint), [Network_Resolution](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkResolution), [Network_Traffic](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkTraffic) -- **Last Updated**: 2018-06-01 -- **Author**: Rico Valdez, Splunk -- **ID**: 943773c6-c4de-4f38-89a8-0b92f98804d8 - -#### Narrative - -Threat actors typically architect and implement an infrastructure to use in various ways during the course of their attack campaigns. In some cases, they leverage this infrastructure for scanning and performing reconnaissance activities. In others, they may use this infrastructure to launch actual attacks. One of the most important functions of this infrastructure is to establish servers that will communicate with implants on compromised endpoints. These servers establish a command and control channel that is used to proxy data between the compromised endpoint and the attacker. These channels relay commands from the attacker to the compromised endpoint and the output of those commands back to the attacker.\ -Because this communication is so critical for an adversary, they often use techniques designed to hide the true nature of the communications. There are many different techniques used to establish and communicate over these channels. This Analytic Story provides searches that look for a variety of the techniques used for these channels, as well as indications that these channels are active, by examining logs associated with border control devices and network-access control lists. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Clients Connecting to Multiple DNS Servers](/deprecated/clients_connecting_to_multiple_dns_servers/) | [Exfiltration Over Unencrypted Non-C2 Protocol](/tags/#exfiltration-over-unencrypted-non-c2-protocol)| TTP | -| [Detect Long DNS TXT Record Response](/deprecated/detect_long_dns_txt_record_response/) | [Exfiltration Over Unencrypted Non-C2 Protocol](/tags/#exfiltration-over-unencrypted-non-c2-protocol)| TTP | -| [Detection of DNS Tunnels](/deprecated/detection_of_dns_tunnels/) | [Exfiltration Over Unencrypted Non-C2 Protocol](/tags/#exfiltration-over-unencrypted-non-c2-protocol)| TTP | -| [DNS Query Requests Resolved by Unauthorized DNS Servers](/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers/) | [DNS](/tags/#dns)| TTP | -| [DNS Exfiltration Using Nslookup App](/endpoint/dns_exfiltration_using_nslookup_app/) | [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol)| TTP | -| [Excessive Usage of NSLOOKUP App](/endpoint/excessive_usage_of_nslookup_app/) | [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol)| Anomaly | -| [Detect Spike in blocked Outbound Traffic from your AWS](/cloud/detect_spike_in_blocked_outbound_traffic_from_your_aws/) | None| Anomaly | -| [Detect Large Outbound ICMP Packets](/network/detect_large_outbound_icmp_packets/) | [Non-Application Layer Protocol](/tags/#non-application-layer-protocol)| TTP | -| [DNS Query Length Outliers - MLTK](/network/dns_query_length_outliers_-_mltk/) | [DNS](/tags/#dns), [Application Layer Protocol](/tags/#application-layer-protocol)| Anomaly | -| [Excessive DNS Failures](/network/excessive_dns_failures/) | [DNS](/tags/#dns), [Application Layer Protocol](/tags/#application-layer-protocol)| Anomaly | -| [Prohibited Network Traffic Allowed](/network/prohibited_network_traffic_allowed/) | [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol)| TTP | -| [Protocol or Port Mismatch](/network/protocol_or_port_mismatch/) | [Exfiltration Over Unencrypted Non-C2 Protocol](/tags/#exfiltration-over-unencrypted-non-c2-protocol), [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol)| Anomaly | -| [TOR Traffic](/network/tor_traffic/) | [Application Layer Protocol](/tags/#application-layer-protocol), [Web Protocols](/tags/#web-protocols)| TTP | -| [Detect hosts connecting to dynamic domain providers](/network/detect_hosts_connecting_to_dynamic_domain_providers/) | [Drive-by Compromise](/tags/#drive-by-compromise)| TTP | -| [DNS Query Length With High Standard Deviation](/network/dns_query_length_with_high_standard_deviation/) | [Exfiltration Over Unencrypted Non-C2 Protocol](/tags/#exfiltration-over-unencrypted-non-c2-protocol), [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol)| Anomaly | -| [Multiple Archive Files Http Post Traffic](/network/multiple_archive_files_http_post_traffic/) | [Exfiltration Over Unencrypted Non-C2 Protocol](/tags/#exfiltration-over-unencrypted-non-c2-protocol), [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol)| TTP | -| [Plain HTTP POST Exfiltrated Data](/network/plain_http_post_exfiltrated_data/) | [Exfiltration Over Unencrypted Non-C2 Protocol](/tags/#exfiltration-over-unencrypted-non-c2-protocol), [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol)| TTP | - -#### Reference - -* [https://attack.mitre.org/wiki/Command_and_Control](https://attack.mitre.org/wiki/Command_and_Control) -* [https://searchsecurity.techtarget.com/feature/Command-and-control-servers-The-puppet-masters-that-govern-malware](https://searchsecurity.techtarget.com/feature/Command-and-control-servers-The-puppet-masters-that-govern-malware) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/command_and_control.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/common_phishing_frameworks.md b/docs/_stories/common_phishing_frameworks.md deleted file mode 100644 index 827f39c280..0000000000 --- a/docs/_stories/common_phishing_frameworks.md +++ /dev/null @@ -1,46 +0,0 @@ ---- -title: "Common Phishing Frameworks" -last_modified_at: 2019-04-29 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Network_Resolution - - Command & Control - - Delivery ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Detect DNS and web requests to fake websites generated by the EvilGinx2 toolkit. These websites are designed to fool unwitting users who have clicked on a malicious link in a phishing email. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Network_Resolution](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkResolution) -- **Last Updated**: 2019-04-29 -- **Author**: Splunk Research Team, Splunk -- **ID**: 9a64ab44-9214-4639-8163-7eaa2621bd61 - -#### Narrative - -As most people know, these emails use fraudulent domains, [email scraping](https://www.cyberscoop.com/emotet-trojan-phishing-scraping-templates-cofense-geodo/), familiar contact names inserted as senders, and other tactics to lure targets into clicking a malicious link, opening an attachment with a [nefarious payload](https://www.cyberscoop.com/emotet-trojan-phishing-scraping-templates-cofense-geodo/), or entering sensitive personal information that perpetrators may intercept. This attack technique requires a relatively low level of skill and allows adversaries to easily cast a wide net. Because phishing is a technique that relies on human psychology, you will never be able to eliminate this vulnerability 100%. But you can use automated detection to significantly reduce the risks.\ -This Analytic Story focuses on detecting signs of MiTM attacks enabled by [EvilGinx2](https://github.com/kgretzky/evilginx2), a toolkit that sets up a transparent proxy between the targeted site and the user. In this way, the attacker is able to intercept credentials and two-factor identification tokens. It employs a proxy template to allow a registered domain to impersonate targeted sites, such as Linkedin, Amazon, Okta, Github, Twitter, Instagram, Reddit, Office 365, and others. It can even register SSL certificates and camouflage them via a URL shortener, making them difficult to detect. Searches in this story look for signs of MiTM attacks enabled by EvilGinx2. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Detect DNS requests to Phishing Sites leveraging EvilGinx2](/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2/) | [Spearphishing via Service](/tags/#spearphishing-via-service)| TTP | - -#### Reference - -* [https://github.com/kgretzky/evilginx2](https://github.com/kgretzky/evilginx2) -* [https://attack.mitre.org/techniques/T1192/](https://attack.mitre.org/techniques/T1192/) -* [https://breakdev.org/evilginx-advanced-phishing-with-two-factor-authentication-bypass/](https://breakdev.org/evilginx-advanced-phishing-with-two-factor-authentication-bypass/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/common_phishing_frameworks.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/container_implantation_monitoring_and_investigation.md b/docs/_stories/container_implantation_monitoring_and_investigation.md deleted file mode 100644 index a8a5a7c554..0000000000 --- a/docs/_stories/container_implantation_monitoring_and_investigation.md +++ /dev/null @@ -1,39 +0,0 @@ ---- -title: "Container Implantation Monitoring and Investigation" -last_modified_at: 2020-02-20 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Use the searches in this story to monitor your Kubernetes registry repositories for upload, and deployment of potentially vulnerable, backdoor, or implanted containers. These searches provide information on source users, destination path, container names and repository names. The searches provide context to address Mitre T1525 which refers to container implantation upload to a company's repository either in Amazon Elastic Container Registry, Google Container Registry and Azure Container Registry. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: -- **Last Updated**: 2020-02-20 -- **Author**: Rod Soto, Rico Valdez, Splunk -- **ID**: aa0e28b1-0521-4b6f-9d2a-7b87e34af246 - -#### Narrative - -Container Registrys provide a way for organizations to keep customized images of their development and infrastructure environment in private. However if these repositories are misconfigured or priviledge users credentials are compromise, attackers can potentially upload implanted containers which can be deployed across the organization. These searches allow operator to monitor who, when and what was uploaded to container registry. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| - -#### Reference - -* [https://github.com/splunk/cloud-datamodel-security-research](https://github.com/splunk/cloud-datamodel-security-research) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/container_implantation_monitoring_and_investigation.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/credential_dumping.md b/docs/_stories/credential_dumping.md deleted file mode 100644 index 6061c3fe08..0000000000 --- a/docs/_stories/credential_dumping.md +++ /dev/null @@ -1,74 +0,0 @@ ---- -title: "Credential Dumping" -last_modified_at: 2020-02-04 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Authentication - - Endpoint - - Actions on Objectives - - Exploitation - - Installation - - Reconnaissance ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Uncover activity consistent with credential dumping, a technique wherein attackers compromise systems and attempt to obtain and exfiltrate passwords. The threat actors use these pilfered credentials to further escalate privileges and spread throughout a target environment. The included searches in this Analytic Story are designed to identify attempts to credential dumping. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Authentication](https://docs.splunk.com/Documentation/CIM/latest/User/Authentication), [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2020-02-04 -- **Author**: Rico Valdez, Splunk -- **ID**: 854d78bf-d0e2-4f4e-b05c-640905f86d7a - -#### Narrative - -Credential dumping—gathering credentials from a target system, often hashed or encrypted—is a common attack technique. Even though the credentials may not be in plain text, an attacker can still exfiltrate the data and set to cracking it offline, on their own systems. The threat actors target a variety of sources to extract them, including the Security Accounts Manager (SAM), Local Security Authority (LSA), NTDS from Domain Controllers, or the Group Policy Preference (GPP) files.\ -Once attackers obtain valid credentials, they use them to move throughout a target network with ease, discovering new systems and identifying assets of interest. Credentials obtained in this manner typically include those of privileged users, which may provide access to more sensitive information and system operations.\ -The detection searches in this Analytic Story monitor access to the Local Security Authority Subsystem Service (LSASS) process, the usage of shadowcopies for credential dumping and some other techniques for credential dumping. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Dump LSASS via procdump Rename](/deprecated/dump_lsass_via_procdump_rename/) | [LSASS Memory](/tags/#lsass-memory)| Hunting | -| [Unsigned Image Loaded by LSASS](/deprecated/unsigned_image_loaded_by_lsass/) | [LSASS Memory](/tags/#lsass-memory)| TTP | -| [Access LSASS Memory for Dump Creation](/endpoint/access_lsass_memory_for_dump_creation/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping)| TTP | -| [Attempted Credential Dump From Registry via Reg exe](/endpoint/attempted_credential_dump_from_registry_via_reg_exe/) | [Security Account Manager](/tags/#security-account-manager), [OS Credential Dumping](/tags/#os-credential-dumping)| TTP | -| [Create Remote Thread into LSASS](/endpoint/create_remote_thread_into_lsass/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping)| TTP | -| [Creation of lsass Dump with Taskmgr](/endpoint/creation_of_lsass_dump_with_taskmgr/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping)| TTP | -| [Creation of Shadow Copy](/endpoint/creation_of_shadow_copy/) | [NTDS](/tags/#ntds), [OS Credential Dumping](/tags/#os-credential-dumping)| TTP | -| [Creation of Shadow Copy with wmic and powershell](/endpoint/creation_of_shadow_copy_with_wmic_and_powershell/) | [NTDS](/tags/#ntds), [OS Credential Dumping](/tags/#os-credential-dumping)| TTP | -| [Credential Dumping via Copy Command from Shadow Copy](/endpoint/credential_dumping_via_copy_command_from_shadow_copy/) | [NTDS](/tags/#ntds), [OS Credential Dumping](/tags/#os-credential-dumping)| TTP | -| [Credential Dumping via Symlink to Shadow Copy](/endpoint/credential_dumping_via_symlink_to_shadow_copy/) | [NTDS](/tags/#ntds), [OS Credential Dumping](/tags/#os-credential-dumping)| TTP | -| [Detect Copy of ShadowCopy with Script Block Logging](/endpoint/detect_copy_of_shadowcopy_with_script_block_logging/) | [Security Account Manager](/tags/#security-account-manager), [OS Credential Dumping](/tags/#os-credential-dumping)| TTP | -| [Detect Credential Dumping through LSASS access](/endpoint/detect_credential_dumping_through_lsass_access/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping)| TTP | -| [Detect Mimikatz Using Loaded Images](/endpoint/detect_mimikatz_using_loaded_images/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping)| TTP | -| [Dump LSASS via comsvcs DLL](/endpoint/dump_lsass_via_comsvcs_dll/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping)| TTP | -| [Dump LSASS via procdump](/endpoint/dump_lsass_via_procdump/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping)| TTP | -| [Enable WDigest UseLogonCredential Registry](/endpoint/enable_wdigest_uselogoncredential_registry/) | [Modify Registry](/tags/#modify-registry), [OS Credential Dumping](/tags/#os-credential-dumping)| TTP | -| [Esentutl SAM Copy](/endpoint/esentutl_sam_copy/) | [Security Account Manager](/tags/#security-account-manager), [OS Credential Dumping](/tags/#os-credential-dumping)| Hunting | -| [Extraction of Registry Hives](/endpoint/extraction_of_registry_hives/) | [Security Account Manager](/tags/#security-account-manager), [OS Credential Dumping](/tags/#os-credential-dumping)| TTP | -| [Ntdsutil Export NTDS](/endpoint/ntdsutil_export_ntds/) | [NTDS](/tags/#ntds), [OS Credential Dumping](/tags/#os-credential-dumping)| TTP | -| [Potential password in username](/endpoint/potential_password_in_username/) | [Local Accounts](/tags/#local-accounts), [Credentials In Files](/tags/#credentials-in-files)| Hunting | -| [SAM Database File Access Attempt](/endpoint/sam_database_file_access_attempt/) | [Security Account Manager](/tags/#security-account-manager), [OS Credential Dumping](/tags/#os-credential-dumping)| Hunting | -| [SecretDumps Offline NTDS Dumping Tool](/endpoint/secretdumps_offline_ntds_dumping_tool/) | [NTDS](/tags/#ntds), [OS Credential Dumping](/tags/#os-credential-dumping)| TTP | -| [Set Default PowerShell Execution Policy To Unrestricted or Bypass](/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell)| TTP | -| [Windows Hunting System Account Targeting Lsass](/endpoint/windows_hunting_system_account_targeting_lsass/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping)| Hunting | -| [Windows Non-System Account Targeting Lsass](/endpoint/windows_non-system_account_targeting_lsass/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping)| TTP | -| [Windows Possible Credential Dumping](/endpoint/windows_possible_credential_dumping/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping)| TTP | - -#### Reference - -* [https://attack.mitre.org/wiki/Technique/T1003](https://attack.mitre.org/wiki/Technique/T1003) -* [https://cyberwardog.blogspot.com/2017/03/chronicles-of-threat-hunter-hunting-for.html](https://cyberwardog.blogspot.com/2017/03/chronicles-of-threat-hunter-hunting-for.html) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/credential_dumping.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_stories/cyclopsblink.md b/docs/_stories/cyclopsblink.md deleted file mode 100644 index 49ed3cec2d..0000000000 --- a/docs/_stories/cyclopsblink.md +++ /dev/null @@ -1,45 +0,0 @@ ---- -title: "CyclopsBLink" -last_modified_at: 2022-04-07 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Leverage searches that allow you to detect and investigate unusual activities that might relate to the cyclopsblink malware including firewall modification, spawning more process, botnet c2 communication, defense evasion and etc. Cyclops Blink is a Linux ELF executable compiled for 32-bit x86 and PowerPC architecture that has targeted several network devices. The complete list of targeted devices is unknown at this time, but WatchGuard FireBox has specifically been listed as a target. The modular malware consists of core components and modules that are deployed as child processes using the Linux API fork. At this point, four modules have been identified that download and upload files, gather system information and contain updating mechanisms for the malware itself. Additional modules can be downloaded and executed from the command and control (C2) server. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-04-07 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 7c75b1c8-dfff-46f1-8250-e58df91b6fd9 - -#### Narrative - -Adversaries may use this technique to maximize the impact on the target organization in operations where network wide availability interruption is the goal. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Linux Iptables Firewall Modification](/endpoint/linux_iptables_firewall_modification/) | [Disable or Modify System Firewall](/tags/#disable-or-modify-system-firewall), [Impair Defenses](/tags/#impair-defenses)| Anomaly | -| [Linux Kworker Process In Writable Process Path](/endpoint/linux_kworker_process_in_writable_process_path/) | [Masquerade Task or Service](/tags/#masquerade-task-or-service), [Masquerading](/tags/#masquerading)| Hunting | -| [Linux Stdout Redirection To Dev Null File](/endpoint/linux_stdout_redirection_to_dev_null_file/) | [Disable or Modify System Firewall](/tags/#disable-or-modify-system-firewall), [Impair Defenses](/tags/#impair-defenses)| Anomaly | - -#### Reference - -* [https://www.ncsc.gov.uk/files/Cyclops-Blink-Malware-Analysis-Report.pdf](https://www.ncsc.gov.uk/files/Cyclops-Blink-Malware-Analysis-Report.pdf) -* [https://www.trendmicro.com/en_us/research/22/c/cyclops-blink-sets-sights-on-asus-routers--.html](https://www.trendmicro.com/en_us/research/22/c/cyclops-blink-sets-sights-on-asus-routers--.html) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/cyclopsblink.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/darkcrystal_rat.md b/docs/_stories/darkcrystal_rat.md deleted file mode 100644 index f50f718fb7..0000000000 --- a/docs/_stories/darkcrystal_rat.md +++ /dev/null @@ -1,62 +0,0 @@ ---- -title: "DarkCrystal RAT" -last_modified_at: 2022-07-26 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Actions on Objectives - - Command & Control - - Exploitation - - Reconnaissance ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Leverage searches that allow you to detect and investigate unusual activities that might relate to the DcRat malware including ddos, spawning more process, botnet c2 communication, defense evasion and etc. The DcRat malware is known commercial backdoor that was first released in 2018. This tool was sold in underground forum and known to be one of the cheapest commercial RATs. DcRat is modular and bespoke plugin framework make it a very flexible option, helpful for a range of nefearious uses. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-07-26 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 639e6006-0885-4847-9394-ddc2902629bf - -#### Narrative - -Adversaries may use this technique to maximize the impact on the target organization in operations where network wide availability interruption is the goal. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Any Powershell DownloadFile](/endpoint/any_powershell_downloadfile/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell), [Ingress Tool Transfer](/tags/#ingress-tool-transfer)| TTP | -| [CMD Carry Out String Command Parameter](/endpoint/cmd_carry_out_string_command_parameter/) | [Windows Command Shell](/tags/#windows-command-shell), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter)| Hunting | -| [Executables Or Script Creation In Suspicious Path](/endpoint/executables_or_script_creation_in_suspicious_path/) | [Masquerading](/tags/#masquerading)| TTP | -| [Malicious PowerShell Process - Encoded Command](/endpoint/malicious_powershell_process_-_encoded_command/) | [Obfuscated Files or Information](/tags/#obfuscated-files-or-information)| Hunting | -| [Malicious PowerShell Process - Execution Policy Bypass](/endpoint/malicious_powershell_process_-_execution_policy_bypass/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell)| TTP | -| [Office Document Executing Macro Code](/endpoint/office_document_executing_macro_code/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment)| TTP | -| [Office Product Spawn CMD Process](/endpoint/office_product_spawn_cmd_process/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Mshta](/tags/#mshta)| TTP | -| [Suspicious Process File Path](/endpoint/suspicious_process_file_path/) | [Create or Modify System Process](/tags/#create-or-modify-system-process)| TTP | -| [Windows Command Shell DCRat ForkBomb Payload](/endpoint/windows_command_shell_dcrat_forkbomb_payload/) | [Windows Command Shell](/tags/#windows-command-shell), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter)| TTP | -| [Windows Gather Victim Network Info Through Ip Check Web Services](/endpoint/windows_gather_victim_network_info_through_ip_check_web_services/) | [IP Addresses](/tags/#ip-addresses), [Gather Victim Network Information](/tags/#gather-victim-network-information)| Hunting | -| [Windows High File Deletion Frequency](/endpoint/windows_high_file_deletion_frequency/) | [Data Destruction](/tags/#data-destruction)| Anomaly | -| [Windows System LogOff Commandline](/endpoint/windows_system_logoff_commandline/) | [System Shutdown/Reboot](/tags/#system-shutdown/reboot)| Anomaly | -| [Windows System Reboot CommandLine](/endpoint/windows_system_reboot_commandline/) | [System Shutdown/Reboot](/tags/#system-shutdown/reboot)| Anomaly | -| [Windows System Shutdown CommandLine](/endpoint/windows_system_shutdown_commandline/) | [System Shutdown/Reboot](/tags/#system-shutdown/reboot)| Anomaly | -| [Windows System Time Discovery W32tm Delay](/endpoint/windows_system_time_discovery_w32tm_delay/) | [System Time Discovery](/tags/#system-time-discovery)| Anomaly | -| [Winword Spawning Cmd](/endpoint/winword_spawning_cmd/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment)| TTP | -| [Winword Spawning PowerShell](/endpoint/winword_spawning_powershell/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment)| TTP | - -#### Reference - -* [https://www.mandiant.com/resources/analyzing-dark-crystal-rat-backdoor](https://www.mandiant.com/resources/analyzing-dark-crystal-rat-backdoor) -* [https://malpedia.caad.fkie.fraunhofer.de/details/win.dcrat](https://malpedia.caad.fkie.fraunhofer.de/details/win.dcrat) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/darkcrystal_rat.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/darkside_ransomware.md b/docs/_stories/darkside_ransomware.md deleted file mode 100644 index acd19dcc91..0000000000 --- a/docs/_stories/darkside_ransomware.md +++ /dev/null @@ -1,60 +0,0 @@ ---- -title: "DarkSide Ransomware" -last_modified_at: 2021-05-12 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Actions on Objectives - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Leverage searches that allow you to detect and investigate unusual activities that might relate to the DarkSide Ransomware - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-05-12 -- **Author**: Bhavin Patel, Splunk -- **ID**: 507edc74-13d5-4339-878e-b9114ded1f35 - -#### Narrative - -This story addresses Darkside ransomware. This ransomware payload has many similarities to common ransomware however there are certain items particular to it. The creation of a .TXT log that shows every item being encrypted as well as the creation of ransomware notes and files adding a machine ID created based on CRC32 checksum algorithm. This ransomware payload leaves machines in minimal operation level,enough to browse the attackers websites. A customized URI with leaked information is presented to each victim.This is the ransomware payload that shut down the Colonial pipeline. The story is composed of several detection searches covering similar items to other ransomware payloads and those particular to Darkside payload. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Attempted Credential Dump From Registry via Reg exe](/endpoint/attempted_credential_dump_from_registry_via_reg_exe/) | [Security Account Manager](/tags/#security-account-manager), [OS Credential Dumping](/tags/#os-credential-dumping)| TTP | -| [BITSAdmin Download File](/endpoint/bitsadmin_download_file/) | [BITS Jobs](/tags/#bits-jobs), [Ingress Tool Transfer](/tags/#ingress-tool-transfer)| TTP | -| [CertUtil Download With URLCache and Split Arguments](/endpoint/certutil_download_with_urlcache_and_split_arguments/) | [Ingress Tool Transfer](/tags/#ingress-tool-transfer)| TTP | -| [CertUtil Download With VerifyCtl and Split Arguments](/endpoint/certutil_download_with_verifyctl_and_split_arguments/) | [Ingress Tool Transfer](/tags/#ingress-tool-transfer)| TTP | -| [CMLUA Or CMSTPLUA UAC Bypass](/endpoint/cmlua_or_cmstplua_uac_bypass/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [CMSTP](/tags/#cmstp)| TTP | -| [Cobalt Strike Named Pipes](/endpoint/cobalt_strike_named_pipes/) | [Process Injection](/tags/#process-injection)| TTP | -| [Delete ShadowCopy With PowerShell](/endpoint/delete_shadowcopy_with_powershell/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery)| TTP | -| [Detect Mimikatz Using Loaded Images](/endpoint/detect_mimikatz_using_loaded_images/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping)| TTP | -| [Detect PsExec With accepteula Flag](/endpoint/detect_psexec_with_accepteula_flag/) | [Remote Services](/tags/#remote-services), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares)| TTP | -| [Detect RClone Command-Line Usage](/endpoint/detect_rclone_command-line_usage/) | [Automated Exfiltration](/tags/#automated-exfiltration)| TTP | -| [Detect Renamed PSExec](/endpoint/detect_renamed_psexec/) | [System Services](/tags/#system-services), [Service Execution](/tags/#service-execution)| Hunting | -| [Detect Renamed RClone](/endpoint/detect_renamed_rclone/) | [Automated Exfiltration](/tags/#automated-exfiltration)| Hunting | -| [Extraction of Registry Hives](/endpoint/extraction_of_registry_hives/) | [Security Account Manager](/tags/#security-account-manager), [OS Credential Dumping](/tags/#os-credential-dumping)| TTP | -| [Ransomware Notes bulk creation](/endpoint/ransomware_notes_bulk_creation/) | [Data Encrypted for Impact](/tags/#data-encrypted-for-impact)| Anomaly | -| [SLUI RunAs Elevated](/endpoint/slui_runas_elevated/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism)| TTP | -| [SLUI Spawning a Process](/endpoint/slui_spawning_a_process/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism)| TTP | -| [Windows Possible Credential Dumping](/endpoint/windows_possible_credential_dumping/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping)| TTP | - -#### Reference - -* [https://www.splunk.com/en_us/blog/security/the-darkside-of-the-ransomware-pipeline.htmlbig-game-hunting-with-ryuk-another-lucrative-targeted-ransomware/](https://www.splunk.com/en_us/blog/security/the-darkside-of-the-ransomware-pipeline.htmlbig-game-hunting-with-ryuk-another-lucrative-targeted-ransomware/) -* [https://www.mandiant.com/resources/shining-a-light-on-darkside-ransomware-operations](https://www.mandiant.com/resources/shining-a-light-on-darkside-ransomware-operations) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/darkside_ransomware.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/data_destruction.md b/docs/_stories/data_destruction.md deleted file mode 100644 index 28148fd502..0000000000 --- a/docs/_stories/data_destruction.md +++ /dev/null @@ -1,56 +0,0 @@ ---- -title: "Data Destruction" -last_modified_at: 2022-02-14 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Leverage searches that allow you to detect and investigate unusual activities that might relate to the data destruction, including deleting files, overwriting files, wiping disk and encrypting files. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-02-14 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 4ae5c0d1-cebd-47d1-bfce-71bf096e38aa - -#### Narrative - -Adversaries may use this technique to maximize the impact on the target organization in operations where network wide availability interruption is the goal. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [CMD Carry Out String Command Parameter](/endpoint/cmd_carry_out_string_command_parameter/) | [Windows Command Shell](/tags/#windows-command-shell), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter)| Hunting | -| [Executable File Written in Administrative SMB Share](/endpoint/executable_file_written_in_administrative_smb_share/) | [Remote Services](/tags/#remote-services), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares)| TTP | -| [Executables Or Script Creation In Suspicious Path](/endpoint/executables_or_script_creation_in_suspicious_path/) | [Masquerading](/tags/#masquerading)| TTP | -| [Linux DD File Overwrite](/endpoint/linux_dd_file_overwrite/) | [Data Destruction](/tags/#data-destruction)| TTP | -| [Linux Deleting Critical Directory Using RM Command](/endpoint/linux_deleting_critical_directory_using_rm_command/) | [Data Destruction](/tags/#data-destruction)| TTP | -| [Linux High Frequency Of File Deletion In Boot Folder](/endpoint/linux_high_frequency_of_file_deletion_in_boot_folder/) | [Data Destruction](/tags/#data-destruction), [File Deletion](/tags/#file-deletion), [Indicator Removal on Host](/tags/#indicator-removal-on-host)| TTP | -| [Regsvr32 Silent and Install Param Dll Loading](/endpoint/regsvr32_silent_and_install_param_dll_loading/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Regsvr32](/tags/#regsvr32)| Anomaly | -| [Suspicious Process File Path](/endpoint/suspicious_process_file_path/) | [Create or Modify System Process](/tags/#create-or-modify-system-process)| TTP | -| [Windows Disable Memory Crash Dump](/endpoint/windows_disable_memory_crash_dump/) | [Data Destruction](/tags/#data-destruction)| TTP | -| [Windows File Without Extension In Critical Folder](/endpoint/windows_file_without_extension_in_critical_folder/) | [Data Destruction](/tags/#data-destruction)| TTP | -| [Windows Modify Show Compress Color And Info Tip Registry](/endpoint/windows_modify_show_compress_color_and_info_tip_registry/) | [Modify Registry](/tags/#modify-registry)| TTP | -| [Windows Raw Access To Disk Volume Partition](/endpoint/windows_raw_access_to_disk_volume_partition/) | [Disk Structure Wipe](/tags/#disk-structure-wipe), [Disk Wipe](/tags/#disk-wipe)| Anomaly | -| [Windows Raw Access To Master Boot Record Drive](/endpoint/windows_raw_access_to_master_boot_record_drive/) | [Disk Structure Wipe](/tags/#disk-structure-wipe), [Disk Wipe](/tags/#disk-wipe)| TTP | - -#### Reference - -* [https://attack.mitre.org/techniques/T1485/](https://attack.mitre.org/techniques/T1485/) -* [https://researchcenter.paloaltonetworks.com/2018/09/unit42-xbash-combines-botnet-ransomware-coinmining-worm-targets-linux-windows/](https://researchcenter.paloaltonetworks.com/2018/09/unit42-xbash-combines-botnet-ransomware-coinmining-worm-targets-linux-windows/) -* [https://www.picussecurity.com/blog/a-brief-history-and-further-technical-analysis-of-sodinokibi-ransomware](https://www.picussecurity.com/blog/a-brief-history-and-further-technical-analysis-of-sodinokibi-ransomware) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/data_destruction.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/data_exfiltration.md b/docs/_stories/data_exfiltration.md deleted file mode 100644 index b705879b14..0000000000 --- a/docs/_stories/data_exfiltration.md +++ /dev/null @@ -1,54 +0,0 @@ ---- -title: "Data Exfiltration" -last_modified_at: 2020-10-21 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Network_Traffic - - Actions on Objectives - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -The stealing of data by an adversary. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint), [Network_Traffic](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkTraffic) -- **Last Updated**: 2020-10-21 -- **Author**: Shannon Davis, Splunk -- **ID**: 66b0fe0c-1351-11eb-adc1-0242ac120002 - -#### Narrative - -Exfiltration comes in many flavors. Adversaries can collect data over encrypted or non-encrypted channels. They can utilise Command and Control channels that are already in place to exfiltrate data. They can use both standard data transfer protocols such as FTP, SCP, etc to exfiltrate data. Or they can use non-standard protocols such as DNS, ICMP, etc with specially crafted fields to try and circumvent security technologies in place. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Detect shared ec2 snapshot](/cloud/detect_shared_ec2_snapshot/) | [Transfer Data to Cloud Account](/tags/#transfer-data-to-cloud-account)| TTP | -| [O365 PST export alert](/cloud/o365_pst_export_alert/) | [Email Collection](/tags/#email-collection)| TTP | -| [O365 Suspicious Admin Email Forwarding](/cloud/o365_suspicious_admin_email_forwarding/) | [Email Forwarding Rule](/tags/#email-forwarding-rule), [Email Collection](/tags/#email-collection)| Anomaly | -| [O365 Suspicious User Email Forwarding](/cloud/o365_suspicious_user_email_forwarding/) | [Email Forwarding Rule](/tags/#email-forwarding-rule), [Email Collection](/tags/#email-collection)| Anomaly | -| [DNS Exfiltration Using Nslookup App](/endpoint/dns_exfiltration_using_nslookup_app/) | [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol)| TTP | -| [Excessive Usage of NSLOOKUP App](/endpoint/excessive_usage_of_nslookup_app/) | [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol)| Anomaly | -| [Mailsniper Invoke functions](/endpoint/mailsniper_invoke_functions/) | [Email Collection](/tags/#email-collection), [Local Email Collection](/tags/#local-email-collection)| TTP | -| [Gdrive suspicious file sharing](/cloud/gdrive_suspicious_file_sharing/) | [Phishing](/tags/#phishing)| Hunting | -| [Detect SNICat SNI Exfiltration](/network/detect_snicat_sni_exfiltration/) | [Exfiltration Over C2 Channel](/tags/#exfiltration-over-c2-channel)| TTP | -| [Multiple Archive Files Http Post Traffic](/network/multiple_archive_files_http_post_traffic/) | [Exfiltration Over Unencrypted Non-C2 Protocol](/tags/#exfiltration-over-unencrypted-non-c2-protocol), [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol)| TTP | -| [Plain HTTP POST Exfiltrated Data](/network/plain_http_post_exfiltrated_data/) | [Exfiltration Over Unencrypted Non-C2 Protocol](/tags/#exfiltration-over-unencrypted-non-c2-protocol), [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol)| TTP | - -#### Reference - -* [https://attack.mitre.org/tactics/TA0010/](https://attack.mitre.org/tactics/TA0010/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/data_exfiltration.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/data_protection.md b/docs/_stories/data_protection.md deleted file mode 100644 index 667578a818..0000000000 --- a/docs/_stories/data_protection.md +++ /dev/null @@ -1,49 +0,0 @@ ---- -title: "Data Protection" -last_modified_at: 2017-09-14 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Change_Analysis - - Network_Resolution - - Actions on Objectives - - Command & Control - - Installation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Fortify your data-protection arsenal--while continuing to ensure data confidentiality and integrity--with searches that monitor for and help you investigate possible signs of data exfiltration. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Change_Analysis](https://docs.splunk.com/Documentation/CIM/latest/User/ChangeAnalysis), [Network_Resolution](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkResolution) -- **Last Updated**: 2017-09-14 -- **Author**: Bhavin Patel, Splunk -- **ID**: 91c676cf-0b23-438d-abee-f6335e1fce33 - -#### Narrative - -Attackers can leverage a variety of resources to compromise or exfiltrate enterprise data. Common exfiltration techniques include remote-access channels via low-risk, high-payoff active-collections operations and close-access operations using insiders and removable media. While this Analytic Story is not a comprehensive listing of all the methods by which attackers can exfiltrate data, it provides a useful starting point. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Detect USB device insertion](/deprecated/detect_usb_device_insertion/) | None| TTP | -| [Detection of DNS Tunnels](/deprecated/detection_of_dns_tunnels/) | [Exfiltration Over Unencrypted Non-C2 Protocol](/tags/#exfiltration-over-unencrypted-non-c2-protocol)| TTP | -| [Detect hosts connecting to dynamic domain providers](/network/detect_hosts_connecting_to_dynamic_domain_providers/) | [Drive-by Compromise](/tags/#drive-by-compromise)| TTP | - -#### Reference - -* [https://www.cisecurity.org/controls/data-protection/](https://www.cisecurity.org/controls/data-protection/) -* [https://www.sans.org/reading-room/whitepapers/dns/splunk-detect-dns-tunneling-37022](https://www.sans.org/reading-room/whitepapers/dns/splunk-detect-dns-tunneling-37022) -* [https://umbrella.cisco.com/blog/2013/04/15/on-the-trail-of-malicious-dynamic-dns-domains/](https://umbrella.cisco.com/blog/2013/04/15/on-the-trail-of-malicious-dynamic-dns-domains/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/data_protection.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/deobfuscate-decode_files_or_information.md b/docs/_stories/deobfuscate-decode_files_or_information.md deleted file mode 100644 index 56c9e6c1e3..0000000000 --- a/docs/_stories/deobfuscate-decode_files_or_information.md +++ /dev/null @@ -1,42 +0,0 @@ ---- -title: "Deobfuscate-Decode Files or Information" -last_modified_at: 2021-03-24 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Adversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-03-24 -- **Author**: Michael Haag, Splunk -- **ID**: 0bd01a54-8cbe-11eb-abcd-acde48001122 - -#### Narrative - -An example of obfuscated files is `Certutil.exe` usage to encode a portable executable to a certificate file, which is base64 encoded, to hide the originating file. There are many utilities cross-platform to encode using XOR, using compressed .cab files to hide contents and scripting languages that may perform similar native Windows tasks. Triaging an event related will require the capability to review related process events and file modifications. Using a tool such as CyberChef will assist with identifying the encoding that was used, and potentially assist with decoding the contents. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [CertUtil With Decode Argument](/endpoint/certutil_with_decode_argument/) | [Deobfuscate/Decode Files or Information](/tags/#deobfuscate/decode-files-or-information)| TTP | - -#### Reference - -* [https://attack.mitre.org/techniques/T1140/](https://attack.mitre.org/techniques/T1140/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/deobfuscate-decode_files_or_information.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/detect_zerologon_attack.md b/docs/_stories/detect_zerologon_attack.md deleted file mode 100644 index 15537b5e43..0000000000 --- a/docs/_stories/detect_zerologon_attack.md +++ /dev/null @@ -1,49 +0,0 @@ ---- -title: "Detect Zerologon Attack" -last_modified_at: 2020-09-18 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Actions on Objectives - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Uncover activity related to the execution of Zerologon CVE-2020-11472, a technique wherein attackers target a Microsoft Windows Domain Controller to reset its computer account password. The result from this attack is attackers can now provide themselves high privileges and take over Domain Controller. The included searches in this Analytic Story are designed to identify attempts to reset Domain Controller Computer Account via exploit code remotely or via the use of tool Mimikatz as payload carrier. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: -- **Last Updated**: 2020-09-18 -- **Author**: Rod Soto, Jose Hernandez, Stan Miskowicz, David Dorsey, Shannon Davis Splunk -- **ID**: 5d14a962-569e-4578-939f-f386feb63ce4 - -#### Narrative - -This attack is a privilege escalation technique, where attacker targets a Netlogon secure channel connection to a domain controller, using Netlogon Remote Protocol (MS-NRPC). This vulnerability exposes vulnerable Windows Domain Controllers to be targeted via unaunthenticated RPC calls which eventually reset Domain Contoller computer account ($) providing the attacker the opportunity to exfil domain controller credential secrets and assign themselve high privileges that can lead to domain controller and potentially complete network takeover. The detection searches in this Analytic Story use Windows Event viewer events and Sysmon events to detect attack execution, these searches monitor access to the Local Security Authority Subsystem Service (LSASS) process which is an indicator of the use of Mimikatz tool which has bee updated to carry this attack payload. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Detect Credential Dumping through LSASS access](/endpoint/detect_credential_dumping_through_lsass_access/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping)| TTP | -| [Detect Mimikatz Using Loaded Images](/endpoint/detect_mimikatz_using_loaded_images/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping)| TTP | -| [Windows Possible Credential Dumping](/endpoint/windows_possible_credential_dumping/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping)| TTP | -| [Detect Computer Changed with Anonymous Account](/endpoint/detect_computer_changed_with_anonymous_account/) | [Exploitation of Remote Services](/tags/#exploitation-of-remote-services)| Hunting | -| [Detect Zerologon via Zeek](/network/detect_zerologon_via_zeek/) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application)| TTP | - -#### Reference - -* [https://attack.mitre.org/wiki/Technique/T1003](https://attack.mitre.org/wiki/Technique/T1003) -* [https://github.com/SecuraBV/CVE-2020-1472](https://github.com/SecuraBV/CVE-2020-1472) -* [https://www.secura.com/blog/zero-logon](https://www.secura.com/blog/zero-logon) -* [https://nvd.nist.gov/vuln/detail/CVE-2020-1472](https://nvd.nist.gov/vuln/detail/CVE-2020-1472) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/detect_zerologon_attack.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/dev_sec_ops.md b/docs/_stories/dev_sec_ops.md deleted file mode 100644 index 4703354b9e..0000000000 --- a/docs/_stories/dev_sec_ops.md +++ /dev/null @@ -1,64 +0,0 @@ ---- -title: "Dev Sec Ops" -last_modified_at: 2021-08-18 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Actions on Objectives - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This story is focused around detecting attacks on a DevSecOps lifeccycle which consists of the phases plan, code, build, test, release, deploy, operate and monitor. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: -- **Last Updated**: 2021-08-18 -- **Author**: Patrick Bareiss, Splunk -- **ID**: 0ca8c38e-631e-4b81-940c-f9c5450ce41e - -#### Narrative - -DevSecOps is a collaborative framework, which thinks about application and infrastructure security from the start. This means that security tools are part of the continuous integration and continuous deployment pipeline. In this analytics story, we focused on detections around the tools used in this framework such as GitHub as a version control system, GDrive for the documentation, CircleCI as the CI/CD pipeline, Kubernetes as the container execution engine and multiple security tools such as Semgrep and Kube-Hunter. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [AWS ECR Container Scanning Findings High](/cloud/aws_ecr_container_scanning_findings_high/) | [Malicious Image](/tags/#malicious-image), [User Execution](/tags/#user-execution)| TTP | -| [AWS ECR Container Scanning Findings Low Informational Unknown](/cloud/aws_ecr_container_scanning_findings_low_informational_unknown/) | [Malicious Image](/tags/#malicious-image), [User Execution](/tags/#user-execution)| Hunting | -| [AWS ECR Container Scanning Findings Medium](/cloud/aws_ecr_container_scanning_findings_medium/) | [Malicious Image](/tags/#malicious-image), [User Execution](/tags/#user-execution)| Anomaly | -| [AWS ECR Container Upload Outside Business Hours](/cloud/aws_ecr_container_upload_outside_business_hours/) | [Malicious Image](/tags/#malicious-image), [User Execution](/tags/#user-execution)| Anomaly | -| [AWS ECR Container Upload Unknown User](/cloud/aws_ecr_container_upload_unknown_user/) | [Malicious Image](/tags/#malicious-image), [User Execution](/tags/#user-execution)| Anomaly | -| [Circle CI Disable Security Job](/cloud/circle_ci_disable_security_job/) | [Compromise Client Software Binary](/tags/#compromise-client-software-binary)| Anomaly | -| [Circle CI Disable Security Step](/cloud/circle_ci_disable_security_step/) | [Compromise Client Software Binary](/tags/#compromise-client-software-binary)| Anomaly | -| [Correlation by Repository and Risk](/cloud/correlation_by_repository_and_risk/) | [Malicious Image](/tags/#malicious-image), [User Execution](/tags/#user-execution)| Correlation | -| [Correlation by User and Risk](/cloud/correlation_by_user_and_risk/) | [Malicious Image](/tags/#malicious-image), [User Execution](/tags/#user-execution)| Correlation | -| [GitHub Actions Disable Security Workflow](/cloud/github_actions_disable_security_workflow/) | [Compromise Software Supply Chain](/tags/#compromise-software-supply-chain), [Supply Chain Compromise](/tags/#supply-chain-compromise)| Anomaly | -| [Github Commit Changes In Master](/cloud/github_commit_changes_in_master/) | [Trusted Relationship](/tags/#trusted-relationship)| Anomaly | -| [Github Commit In Develop](/cloud/github_commit_in_develop/) | [Trusted Relationship](/tags/#trusted-relationship)| Anomaly | -| [GitHub Dependabot Alert](/cloud/github_dependabot_alert/) | [Compromise Software Dependencies and Development Tools](/tags/#compromise-software-dependencies-and-development-tools), [Supply Chain Compromise](/tags/#supply-chain-compromise)| Anomaly | -| [GitHub Pull Request from Unknown User](/cloud/github_pull_request_from_unknown_user/) | [Compromise Software Dependencies and Development Tools](/tags/#compromise-software-dependencies-and-development-tools), [Supply Chain Compromise](/tags/#supply-chain-compromise)| Anomaly | -| [Gsuite Drive Share In External Email](/cloud/gsuite_drive_share_in_external_email/) | [Exfiltration to Cloud Storage](/tags/#exfiltration-to-cloud-storage), [Exfiltration Over Web Service](/tags/#exfiltration-over-web-service)| Anomaly | -| [GSuite Email Suspicious Attachment](/cloud/gsuite_email_suspicious_attachment/) | [Spearphishing Attachment](/tags/#spearphishing-attachment), [Phishing](/tags/#phishing)| Anomaly | -| [Gsuite Email Suspicious Subject With Attachment](/cloud/gsuite_email_suspicious_subject_with_attachment/) | [Spearphishing Attachment](/tags/#spearphishing-attachment), [Phishing](/tags/#phishing)| Anomaly | -| [Gsuite Email With Known Abuse Web Service Link](/cloud/gsuite_email_with_known_abuse_web_service_link/) | [Spearphishing Attachment](/tags/#spearphishing-attachment), [Phishing](/tags/#phishing)| Anomaly | -| [Gsuite Outbound Email With Attachment To External Domain](/cloud/gsuite_outbound_email_with_attachment_to_external_domain/) | [Exfiltration Over Unencrypted Non-C2 Protocol](/tags/#exfiltration-over-unencrypted-non-c2-protocol), [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol)| Anomaly | -| [Gsuite Suspicious Shared File Name](/cloud/gsuite_suspicious_shared_file_name/) | [Spearphishing Attachment](/tags/#spearphishing-attachment), [Phishing](/tags/#phishing)| Anomaly | -| [Kubernetes Nginx Ingress LFI](/cloud/kubernetes_nginx_ingress_lfi/) | [Exploitation for Credential Access](/tags/#exploitation-for-credential-access)| TTP | -| [Kubernetes Nginx Ingress RFI](/cloud/kubernetes_nginx_ingress_rfi/) | [Exploitation for Credential Access](/tags/#exploitation-for-credential-access)| TTP | -| [Kubernetes Scanner Image Pulling](/cloud/kubernetes_scanner_image_pulling/) | [Cloud Service Discovery](/tags/#cloud-service-discovery)| TTP | - -#### Reference - -* [https://www.redhat.com/en/topics/devops/what-is-devsecops](https://www.redhat.com/en/topics/devops/what-is-devsecops) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/dev_sec_ops.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/dhs_report_ta18-074a.md b/docs/_stories/dhs_report_ta18-074a.md deleted file mode 100644 index b92b143b1e..0000000000 --- a/docs/_stories/dhs_report_ta18-074a.md +++ /dev/null @@ -1,63 +0,0 @@ ---- -title: "DHS Report TA18-074A" -last_modified_at: 2020-01-22 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Network_Traffic - - Actions on Objectives - - Command & Control - - Exploitation - - Installation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Monitor for suspicious activities associated with DHS Technical Alert US-CERT TA18-074A. Some of the activities that adversaries used in these compromises included spearfishing attacks, malware, watering-hole domains, many and more. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint), [Network_Traffic](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkTraffic) -- **Last Updated**: 2020-01-22 -- **Author**: Rico Valdez, Splunk -- **ID**: 0c016e5c-88be-4e2c-8c6c-c2b55b4fb4ef - -#### Narrative - -The frequency of nation-state cyber attacks has increased significantly over the last decade. Employing numerous tactics and techniques, these attacks continue to escalate in complexity. \ -There is a wide range of motivations for these state-sponsored hacks, including stealing valuable corporate, military, or diplomatic dataѿall of which could confer advantages in various arenas. They may also target critical infrastructure. \ -One joint Technical Alert (TA) issued by the Department of Homeland and the FBI in mid-March of 2018 attributed some cyber activity targeting utility infrastructure to operatives sponsored by the Russian government. The hackers executed spearfishing attacks, installed malware, employed watering-hole domains, and more. While they caused no physical damage, the attacks provoked fears that a nation-state could turn off water, redirect power, or compromise a nuclear power plant.\ -Suspicious activities--spikes in SMB traffic, processes that launch netsh (to modify the network configuration), suspicious registry modifications, and many more--may all be events you may wish to investigate further. While the use of these technique may be an indication that a nation-state actor is attempting to compromise your environment, it is important to note that these techniques are often employed by other groups, as well. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [First time seen command line argument](/deprecated/first_time_seen_command_line_argument/) | [PowerShell](/tags/#powershell), [Windows Command Shell](/tags/#windows-command-shell)| Hunting | -| [Create local admin accounts using net exe](/endpoint/create_local_admin_accounts_using_net_exe/) | [Local Account](/tags/#local-account), [Create Account](/tags/#create-account)| TTP | -| [Detect New Local Admin account](/endpoint/detect_new_local_admin_account/) | [Local Account](/tags/#local-account), [Create Account](/tags/#create-account)| TTP | -| [Detect PsExec With accepteula Flag](/endpoint/detect_psexec_with_accepteula_flag/) | [Remote Services](/tags/#remote-services), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares)| TTP | -| [Detect Renamed PSExec](/endpoint/detect_renamed_psexec/) | [System Services](/tags/#system-services), [Service Execution](/tags/#service-execution)| Hunting | -| [Malicious PowerShell Process - Execution Policy Bypass](/endpoint/malicious_powershell_process_-_execution_policy_bypass/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell)| TTP | -| [Processes launching netsh](/endpoint/processes_launching_netsh/) | [Disable or Modify System Firewall](/tags/#disable-or-modify-system-firewall), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Registry Keys Used For Persistence](/endpoint/registry_keys_used_for_persistence/) | [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution)| TTP | -| [Sc exe Manipulating Windows Services](/endpoint/sc_exe_manipulating_windows_services/) | [Windows Service](/tags/#windows-service), [Create or Modify System Process](/tags/#create-or-modify-system-process)| TTP | -| [Scheduled Task Deleted Or Created via CMD](/endpoint/scheduled_task_deleted_or_created_via_cmd/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job)| TTP | -| [Single Letter Process On Endpoint](/endpoint/single_letter_process_on_endpoint/) | [User Execution](/tags/#user-execution), [Malicious File](/tags/#malicious-file)| TTP | -| [Suspicious Reg exe Process](/endpoint/suspicious_reg_exe_process/) | [Modify Registry](/tags/#modify-registry)| TTP | -| [Detect Outbound SMB Traffic](/network/detect_outbound_smb_traffic/) | [File Transfer Protocols](/tags/#file-transfer-protocols), [Application Layer Protocol](/tags/#application-layer-protocol)| TTP | -| [SMB Traffic Spike](/network/smb_traffic_spike/) | [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares), [Remote Services](/tags/#remote-services)| Anomaly | -| [SMB Traffic Spike - MLTK](/network/smb_traffic_spike_-_mltk/) | [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares), [Remote Services](/tags/#remote-services)| Anomaly | - -#### Reference - -* [https://www.us-cert.gov/ncas/alerts/TA18-074A](https://www.us-cert.gov/ncas/alerts/TA18-074A) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/dhs_report_ta18-074a.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_stories/disabling_security_tools.md b/docs/_stories/disabling_security_tools.md deleted file mode 100644 index 33a01aa290..0000000000 --- a/docs/_stories/disabling_security_tools.md +++ /dev/null @@ -1,50 +0,0 @@ ---- -title: "Disabling Security Tools" -last_modified_at: 2020-02-04 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Actions on Objectives - - Installation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Looks for activities and techniques associated with the disabling of security tools on a Windows system, such as suspicious `reg.exe` processes, processes launching netsh, and many others. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2020-02-04 -- **Author**: Rico Valdez, Splunk -- **ID**: fcc27099-46a0-46b0-a271-5c7dab56b6f1 - -#### Narrative - -Attackers employ a variety of tactics in order to avoid detection and operate without barriers. This often involves modifying the configuration of security tools to get around them or explicitly disabling them to prevent them from running. This Analytic Story includes searches that look for activity consistent with attackers attempting to disable various security mechanisms. Such activity may involve monitoring for suspicious registry activity, as this is where much of the configuration for Windows and various other programs reside, or explicitly attempting to shut down security-related services. Other times, attackers attempt various tricks to prevent specific programs from running, such as adding the certificates with which the security tools are signed to a block list (which would prevent them from running). - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Attempt To Add Certificate To Untrusted Store](/endpoint/attempt_to_add_certificate_to_untrusted_store/) | [Install Root Certificate](/tags/#install-root-certificate), [Subvert Trust Controls](/tags/#subvert-trust-controls)| TTP | -| [Attempt To Stop Security Service](/endpoint/attempt_to_stop_security_service/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Processes launching netsh](/endpoint/processes_launching_netsh/) | [Disable or Modify System Firewall](/tags/#disable-or-modify-system-firewall), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Sc exe Manipulating Windows Services](/endpoint/sc_exe_manipulating_windows_services/) | [Windows Service](/tags/#windows-service), [Create or Modify System Process](/tags/#create-or-modify-system-process)| TTP | -| [Suspicious Reg exe Process](/endpoint/suspicious_reg_exe_process/) | [Modify Registry](/tags/#modify-registry)| TTP | -| [Unload Sysmon Filter Driver](/endpoint/unload_sysmon_filter_driver/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | - -#### Reference - -* [https://attack.mitre.org/wiki/Technique/T1089](https://attack.mitre.org/wiki/Technique/T1089) -* [https://blog.malwarebytes.com/cybercrime/2015/11/vonteera-adware-uses-certificates-to-disable-anti-malware/](https://blog.malwarebytes.com/cybercrime/2015/11/vonteera-adware-uses-certificates-to-disable-anti-malware/) -* [https://web.archive.org/web/20220425194457/https://www.operationblockbuster.com/wp-content/uploads/2016/02/Operation-Blockbuster-Tools-Report.pdf](https://web.archive.org/web/20220425194457/https://www.operationblockbuster.com/wp-content/uploads/2016/02/Operation-Blockbuster-Tools-Report.pdf) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/disabling_security_tools.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_stories/dns_amplification_attacks.md b/docs/_stories/dns_amplification_attacks.md deleted file mode 100644 index 9a27370600..0000000000 --- a/docs/_stories/dns_amplification_attacks.md +++ /dev/null @@ -1,44 +0,0 @@ ---- -title: "DNS Amplification Attacks" -last_modified_at: 2016-09-13 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Network_Resolution - - Actions on Objectives ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -DNS poses a serious threat as a Denial of Service (DOS) amplifier, if it responds to `ANY` queries. This Analytic Story can help you detect attackers who may be abusing your company's DNS infrastructure to launch amplification attacks, causing Denial of Service to other victims. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Network_Resolution](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkResolution) -- **Last Updated**: 2016-09-13 -- **Author**: Bhavin Patel, Splunk -- **ID**: a563972b-d2e2-4978-b6ca-6e83e24af4d3 - -#### Narrative - -The Domain Name System (DNS) is the protocol used to map domain names to IP addresses. It has been proven to work very well for its intended function. However if DNS is misconfigured, servers can be abused by attackers to levy amplification or redirection attacks against victims. Because DNS responses to `ANY` queries are so much larger than the queries themselves--and can be made with a UDP packet, which does not require a handshake--attackers can spoof the source address of the packet and cause much more data to be sent to the victim than if they sent the traffic themselves. The `ANY` requests are will be larger than normal DNS server requests, due to the fact that the server provides significant details, such as MX records and associated IP addresses. A large volume of this traffic can result in a DOS on the victim's machine. This misconfiguration leads to two possible victims, the first being the DNS servers participating in an attack and the other being the hosts that are the targets of the DOS attack.\ -The search in this story can help you to detect if attackers are abusing your company's DNS infrastructure to launch DNS amplification attacks causing Denial of Service to other victims. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Large Volume of DNS ANY Queries](/network/large_volume_of_dns_any_queries/) | [Network Denial of Service](/tags/#network-denial-of-service), [Reflection Amplification](/tags/#reflection-amplification)| Anomaly | - -#### Reference - -* [https://www.us-cert.gov/ncas/alerts/TA13-088A](https://www.us-cert.gov/ncas/alerts/TA13-088A) -* [https://www.imperva.com/learn/application-security/dns-amplification/](https://www.imperva.com/learn/application-security/dns-amplification/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/dns_amplification_attacks.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/dns_hijacking.md b/docs/_stories/dns_hijacking.md deleted file mode 100644 index 250d2998bb..0000000000 --- a/docs/_stories/dns_hijacking.md +++ /dev/null @@ -1,57 +0,0 @@ ---- -title: "DNS Hijacking" -last_modified_at: 2020-02-04 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Network_Resolution - - Actions on Objectives - - Command & Control ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Secure your environment against DNS hijacks with searches that help you detect and investigate unauthorized changes to DNS records. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Network_Resolution](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkResolution) -- **Last Updated**: 2020-02-04 -- **Author**: Bhavin Patel, Splunk -- **ID**: 8169f17b-ef68-4b59-aa28-586907301221 - -#### Narrative - -Dubbed the Achilles heel of the Internet (see https://www.f5.com/labs/articles/threat-intelligence/dns-is-still-the-achilles-heel-of-the-internet-25613), DNS plays a critical role in routing web traffic but is notoriously vulnerable to attack. One reason is its distributed nature. It relies on unstructured connections between millions of clients and servers over inherently insecure protocols.\ -The gravity and extent of the importance of securing DNS from attacks is undeniable. The fallout of compromised DNS can be disastrous. Not only can hackers bring down an entire business, they can intercept confidential information, emails, and login credentials, as well. \ -On January 22, 2019, the US Department of Homeland Security 2019's Cybersecurity and Infrastructure Security Agency (CISA) raised awareness of some high-profile DNS hijacking attacks against infrastructure, both in the United States and abroad. It issued Emergency Directive 19-01 (see https://cyber.dhs.gov/ed/19-01/), which summarized the activity and required government agencies to take the following four actions, all within 10 days: \ -1. For all .gov or other agency-managed domains, audit public DNS records on all authoritative and secondary DNS servers, verify that they resolve to the intended location or report them to CISA.\ -1. Update the passwords for all accounts on systems that can make changes to each agency 2019's DNS records.\ -1. Implement multi-factor authentication (MFA) for all accounts on systems that can make changes to each agency's 2019 DNS records or, if impossible, provide CISA with the names of systems, the reasons why MFA cannot be enabled within the required timeline, and an ETA for when it can be enabled.\ -1. CISA will begin regular delivery of newly added certificates to Certificate Transparency (CT) logs for agency domains via the Cyber Hygiene service. Upon receipt, agencies must immediately begin monitoring CT log data for certificates issued that they did not request. If an agency confirms that a certificate was unauthorized, it must report the certificate to the issuing certificate authority and to CISA. Of course, it makes sense to put equivalent actions in place within your environment, as well. \ -In DNS hijacking, the attacker assumes control over an account or makes use of a DNS service exploit to make changes to DNS records. Once they gain access, attackers can substitute their own MX records, name-server records, and addresses, redirecting emails and traffic through their infrastructure, where they can read, copy, or modify information seen. They can also generate valid encryption certificates to help them avoid browser-certificate checks. In one notable attack on the Internet service provider, GoDaddy, the hackers altered Sender Policy Framework (SPF) records a relatively minor change that did not inflict excessive damage but allowed for more effective spam campaigns.\ -The searches in this Analytic Story help you detect and investigate activities that may indicate that DNS hijacking has taken place within your environment. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Clients Connecting to Multiple DNS Servers](/deprecated/clients_connecting_to_multiple_dns_servers/) | [Exfiltration Over Unencrypted Non-C2 Protocol](/tags/#exfiltration-over-unencrypted-non-c2-protocol)| TTP | -| [DNS Query Requests Resolved by Unauthorized DNS Servers](/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers/) | [DNS](/tags/#dns)| TTP | -| [DNS record changed](/deprecated/dns_record_changed/) | [DNS](/tags/#dns)| TTP | -| [Detect hosts connecting to dynamic domain providers](/network/detect_hosts_connecting_to_dynamic_domain_providers/) | [Drive-by Compromise](/tags/#drive-by-compromise)| TTP | - -#### Reference - -* [https://www.fireeye.com/blog/threat-research/2017/09/apt33-insights-into-iranian-cyber-espionage.html](https://www.fireeye.com/blog/threat-research/2017/09/apt33-insights-into-iranian-cyber-espionage.html) -* [https://umbrella.cisco.com/blog/2013/04/15/on-the-trail-of-malicious-dynamic-dns-domains/](https://umbrella.cisco.com/blog/2013/04/15/on-the-trail-of-malicious-dynamic-dns-domains/) -* [http://www.noip.com/blog/2014/07/11/dynamic-dns-can-use-2/](http://www.noip.com/blog/2014/07/11/dynamic-dns-can-use-2/) -* [https://www.splunk.com/blog/2015/08/04/detecting-dynamic-dns-domains-in-splunk.html](https://www.splunk.com/blog/2015/08/04/detecting-dynamic-dns-domains-in-splunk.html) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/dns_hijacking.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/domain_trust_discovery.md b/docs/_stories/domain_trust_discovery.md deleted file mode 100644 index 34b748a7a5..0000000000 --- a/docs/_stories/domain_trust_discovery.md +++ /dev/null @@ -1,44 +0,0 @@ ---- -title: "Domain Trust Discovery" -last_modified_at: 2021-03-25 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Adversaries may attempt to gather information on domain trust relationships that may be used to identify lateral movement opportunities in Windows multi-domain/forest environments. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-03-25 -- **Author**: Michael Haag, Splunk -- **ID**: e6f30f14-8daf-11eb-a017-acde48001122 - -#### Narrative - -Domain trusts provide a mechanism for a domain to allow access to resources based on the authentication procedures of another domain. Domain trusts allow the users of the trusted domain to access resources in the trusting domain. The information discovered may help the adversary conduct SID-History Injection, Pass the Ticket, and Kerberoasting. Domain trusts can be enumerated using the DSEnumerateDomainTrusts() Win32 API call, .NET methods, and LDAP. The Windows utility Nltest is known to be used by adversaries to enumerate domain trusts. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [DSQuery Domain Discovery](/endpoint/dsquery_domain_discovery/) | [Domain Trust Discovery](/tags/#domain-trust-discovery)| TTP | -| [NLTest Domain Trust Discovery](/endpoint/nltest_domain_trust_discovery/) | [Domain Trust Discovery](/tags/#domain-trust-discovery)| TTP | -| [Windows AdFind Exe](/endpoint/windows_adfind_exe/) | [Remote System Discovery](/tags/#remote-system-discovery)| TTP | - -#### Reference - -* [https://attack.mitre.org/techniques/T1482/](https://attack.mitre.org/techniques/T1482/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/domain_trust_discovery.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/double_zero_destructor.md b/docs/_stories/double_zero_destructor.md deleted file mode 100644 index fe98bd2bd5..0000000000 --- a/docs/_stories/double_zero_destructor.md +++ /dev/null @@ -1,46 +0,0 @@ ---- -title: "Double Zero Destructor" -last_modified_at: 2022-03-25 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Double Zero Destructor is a destructive payload that enumerates Domain Controllers and executes killswitch if detected. Overwrites files with Zero blocks or using MS Windows API calls such as NtFileOpen, NtFSControlFile. This payload also deletes registry hives HKCU,HKLM, HKU, HKLM BCD. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-03-25 -- **Author**: Teoderick Contreras, Rod Soto, Splunk -- **ID**: f56e8c00-3224-4955-9a6e-924ec7da1df7 - -#### Narrative - -Double zero destructor enumerates domain controllers, delete registry hives and overwrites files using zero blocks and API calls. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Executables Or Script Creation In Suspicious Path](/endpoint/executables_or_script_creation_in_suspicious_path/) | [Masquerading](/tags/#masquerading)| TTP | -| [Suspicious Process File Path](/endpoint/suspicious_process_file_path/) | [Create or Modify System Process](/tags/#create-or-modify-system-process)| TTP | -| [Windows Deleted Registry By A Non Critical Process File Path](/endpoint/windows_deleted_registry_by_a_non_critical_process_file_path/) | [Modify Registry](/tags/#modify-registry)| Anomaly | -| [Windows Terminating Lsass Process](/endpoint/windows_terminating_lsass_process/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| Anomaly | - -#### Reference - -* [https://cert.gov.ua/article/38088](https://cert.gov.ua/article/38088) -* [https://blog.talosintelligence.com/2022/03/threat-advisory-doublezero.html](https://blog.talosintelligence.com/2022/03/threat-advisory-doublezero.html) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/double_zero_destructor.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/dynamic_dns.md b/docs/_stories/dynamic_dns.md deleted file mode 100644 index 68515c0119..0000000000 --- a/docs/_stories/dynamic_dns.md +++ /dev/null @@ -1,52 +0,0 @@ ---- -title: "Dynamic DNS" -last_modified_at: 2018-09-06 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Network_Resolution - - Web - - Actions on Objectives - - Command & Control - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Detect and investigate hosts in your environment that may be communicating with dynamic domain providers. Attackers may leverage these services to help them avoid firewall blocks and deny lists. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint), [Network_Resolution](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkResolution), [Web](https://docs.splunk.com/Documentation/CIM/latest/User/Web) -- **Last Updated**: 2018-09-06 -- **Author**: Bhavin Patel, Splunk -- **ID**: 8169f17b-ef68-4b59-aae8-586907301221 - -#### Narrative - -Dynamic DNS services (DDNS) are legitimate low-cost or free services that allow users to rapidly update domain resolutions to IP infrastructure. While their usage can be benign, malicious actors can abuse DDNS to host harmful payloads or interactive-command-and-control infrastructure. These attackers will manually update or automate domain resolution changes by routing dynamic domains to IP addresses that circumvent firewall blocks and deny lists and frustrate a network defender's analytic and investigative processes. These searches will look for DNS queries made from within your infrastructure to suspicious dynamic domains and then investigate more deeply, when appropriate. While this list of top-level dynamic domains is not exhaustive, it can be dynamically updated as new suspicious dynamic domains are identified. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Detect web traffic to dynamic domain providers](/deprecated/detect_web_traffic_to_dynamic_domain_providers/) | [Web Protocols](/tags/#web-protocols)| TTP | -| [DNS Exfiltration Using Nslookup App](/endpoint/dns_exfiltration_using_nslookup_app/) | [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol)| TTP | -| [Excessive Usage of NSLOOKUP App](/endpoint/excessive_usage_of_nslookup_app/) | [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol)| Anomaly | -| [Detect hosts connecting to dynamic domain providers](/network/detect_hosts_connecting_to_dynamic_domain_providers/) | [Drive-by Compromise](/tags/#drive-by-compromise)| TTP | - -#### Reference - -* [https://www.fireeye.com/blog/threat-research/2017/09/apt33-insights-into-iranian-cyber-espionage.html](https://www.fireeye.com/blog/threat-research/2017/09/apt33-insights-into-iranian-cyber-espionage.html) -* [https://umbrella.cisco.com/blog/2013/04/15/on-the-trail-of-malicious-dynamic-dns-domains/](https://umbrella.cisco.com/blog/2013/04/15/on-the-trail-of-malicious-dynamic-dns-domains/) -* [http://www.noip.com/blog/2014/07/11/dynamic-dns-can-use-2/](http://www.noip.com/blog/2014/07/11/dynamic-dns-can-use-2/) -* [https://www.splunk.com/blog/2015/08/04/detecting-dynamic-dns-domains-in-splunk.html](https://www.splunk.com/blog/2015/08/04/detecting-dynamic-dns-domains-in-splunk.html) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/dynamic_dns.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_stories/emotet_malware__dhs_report_ta18-201a_.md b/docs/_stories/emotet_malware__dhs_report_ta18-201a_.md deleted file mode 100644 index 4d43e55985..0000000000 --- a/docs/_stories/emotet_malware__dhs_report_ta18-201a_.md +++ /dev/null @@ -1,60 +0,0 @@ ---- -title: "Emotet Malware DHS Report TA18-201A " -last_modified_at: 2020-01-27 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Email - - Endpoint - - Network_Traffic - - Actions on Objectives - - Command & Control - - Delivery - - Exploitation - - Installation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Detect rarely used executables, specific registry paths that may confer malware survivability and persistence, instances where cmd.exe is used to launch script interpreters, and other indicators that the Emotet financial malware has compromised your environment. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Email](https://docs.splunk.com/Documentation/CIM/latest/User/Email), [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint), [Network_Traffic](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkTraffic) -- **Last Updated**: 2020-01-27 -- **Author**: Bhavin Patel, Splunk -- **ID**: bb9f5ed2-916e-4364-bb6d-91c310efcf52 - -#### Narrative - -The trojan downloader known as Emotet first surfaced in 2014, when it was discovered targeting the banking industry to steal credentials. However, according to a joint technical alert (TA) issued by three government agencies (https://www.us-cert.gov/ncas/alerts/TA18-201A), Emotet has evolved far beyond those beginnings to become what a ThreatPost article called a threat-delivery service(see https://threatpost.com/emotet-malware-evolves-beyond-banking-to-threat-delivery-service/134342/). For example, in early 2018, Emotet was found to be using its loader function to spread the Quakbot and Ransomware variants. \ -According to the TA, the the malware continues to be among the most costly and destructive malware affecting the private and public sectors. Researchers have linked it to the threat group Mealybug, which has also been on the security communitys radar since 2014.\ -The searches in this Analytic Story will help you find executables that are rarely used in your environment, specific registry paths that malware often uses to ensure survivability and persistence, instances where cmd.exe is used to launch script interpreters, and other indicators that Emotet or other malware has compromised your environment. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Prohibited Software On Endpoint](/deprecated/prohibited_software_on_endpoint/) | None| Hunting | -| [Detect Use of cmd exe to Launch Script Interpreters](/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Windows Command Shell](/tags/#windows-command-shell)| TTP | -| [Registry Keys Used For Persistence](/endpoint/registry_keys_used_for_persistence/) | [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution)| TTP | -| [Email Attachments With Lots Of Spaces](/application/email_attachments_with_lots_of_spaces/) | None| Anomaly | -| [Suspicious Email Attachment Extensions](/application/suspicious_email_attachment_extensions/) | [Spearphishing Attachment](/tags/#spearphishing-attachment), [Phishing](/tags/#phishing)| Anomaly | -| [Detect Rare Executables](/endpoint/detect_rare_executables/) | None| Anomaly | -| [Detection of tools built by NirSoft](/endpoint/detection_of_tools_built_by_nirsoft/) | [Software Deployment Tools](/tags/#software-deployment-tools)| TTP | -| [SMB Traffic Spike](/network/smb_traffic_spike/) | [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares), [Remote Services](/tags/#remote-services)| Anomaly | -| [SMB Traffic Spike - MLTK](/network/smb_traffic_spike_-_mltk/) | [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares), [Remote Services](/tags/#remote-services)| Anomaly | - -#### Reference - -* [https://www.us-cert.gov/ncas/alerts/TA18-201A](https://www.us-cert.gov/ncas/alerts/TA18-201A) -* [https://www.first.org/resources/papers/conf2017/Advanced-Incident-Detection-and-Threat-Hunting-using-Sysmon-and-Splunk.pdf](https://www.first.org/resources/papers/conf2017/Advanced-Incident-Detection-and-Threat-Hunting-using-Sysmon-and-Splunk.pdf) -* [https://www.vkremez.com/2017/05/emotet-banking-trojan-malware-analysis.html](https://www.vkremez.com/2017/05/emotet-banking-trojan-malware-analysis.html) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/emotet_malware__dhs_report_ta18-201a_.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/f5_big-ip_vulnerability_cve-2022-1388.md b/docs/_stories/f5_big-ip_vulnerability_cve-2022-1388.md deleted file mode 100644 index f4561a9a75..0000000000 --- a/docs/_stories/f5_big-ip_vulnerability_cve-2022-1388.md +++ /dev/null @@ -1,46 +0,0 @@ ---- -title: "F5 BIG-IP Vulnerability CVE-2022-1388" -last_modified_at: 2022-05-10 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Web - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -CVE-2022-1388 is a unauthenticated remote code execution vulnerablity against BIG-IP iControl REST API. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Web](https://docs.splunk.com/Documentation/CIM/latest/User/Web) -- **Last Updated**: 2022-05-10 -- **Author**: Michael Haag, Splunk -- **ID**: 0367b177-f8d6-4c4b-a62d-86f52a590bff - -#### Narrative - -CVE-2022-1388 is a critical vulnerability (CVSS 9.8) in the management interface of F5 Networks'' BIG-IP solution that enables an unauthenticated attacker to gain remote code execution on the system through bypassing F5''s iControl REST authentication. The vulnerability was first discovered by F5''s internal product security team and disclosed publicly on May 4, 2022, per Randori. This vulnerability,CVE-2022-1388, may allow an unauthenticated attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands, create or delete files, or disable services. There is no data plane exposure; this is a control plane issue only per F5 article K23605346. Is CVE-2022-1388 Exploitable? Yes. There are now multiple POC scripts available and reports of threat actors scanning and potentially exploiting the vulnerablity. Per Randori the specific interface needed to exploit this vulnerability is rarely publicly exposed, and the risk to most organizations of exploitation by an unauthenticated external actor is low. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [F5 BIG-IP iControl REST Vulnerability CVE-2022-1388](/network/f5_big-ip_icontrol_rest_vulnerability_cve-2022-1388/) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application)| TTP | - -#### Reference - -* [https://github.com/dk4trin/templates-nuclei/blob/main/CVE-2022-1388.yaml](https://github.com/dk4trin/templates-nuclei/blob/main/CVE-2022-1388.yaml) -* [https://www.randori.com/blog/vulnerability-analysis-cve-2022-1388/](https://www.randori.com/blog/vulnerability-analysis-cve-2022-1388/) -* [https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1388](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1388) -* [https://twitter.com/da_667/status/1523770267327250438?s=20&t=-JnB_aNWuJFsmcOmxGUWLQ](https://twitter.com/da_667/status/1523770267327250438?s=20&t=-JnB_aNWuJFsmcOmxGUWLQ) -* [https://github.com/horizon3ai/CVE-2022-1388/blob/main/CVE-2022-1388.py](https://github.com/horizon3ai/CVE-2022-1388/blob/main/CVE-2022-1388.py) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/f5_big-ip_vulnerability_cve-2022-1388.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/f5_tmui_rce_cve-2020-5902.md b/docs/_stories/f5_tmui_rce_cve-2020-5902.md deleted file mode 100644 index ca3302ea1e..0000000000 --- a/docs/_stories/f5_tmui_rce_cve-2020-5902.md +++ /dev/null @@ -1,43 +0,0 @@ ---- -title: "F5 TMUI RCE CVE-2020-5902" -last_modified_at: 2020-08-02 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Uncover activity consistent with CVE-2020-5902. Discovered by Positive Technologies researchers, this vulnerability affects F5 BIG-IP, BIG-IQ. and Traffix SDC devices (vulnerable versions in F5 support link below). This vulnerability allows unauthenticated users, along with authenticated users, who have access to the configuration utility to execute system commands, create/delete files, disable services, and/or execute Java code. This vulnerability can result in full system compromise. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: -- **Last Updated**: 2020-08-02 -- **Author**: Shannon Davis, Splunk -- **ID**: 7678c968-d46e-11ea-87d0-0242ac130003 - -#### Narrative - -A client is able to perform a remote code execution on an exposed and vulnerable system. The detection search in this Analytic Story uses syslog to detect the malicious behavior. Syslog is going to be the best detection method, as any systems using SSL to protect their management console will make detection via wire data difficult. The searches included used Splunk Connect For Syslog (https://splunkbase.splunk.com/app/4740/), and used a custom destination port to help define the data as F5 data (covered in https://splunk-connect-for-syslog.readthedocs.io/en/master/sources/F5/) - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Detect F5 TMUI RCE CVE-2020-5902](/web/detect_f5_tmui_rce_cve-2020-5902/) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application)| TTP | - -#### Reference - -* [https://www.ptsecurity.com/ww-en/about/news/f5-fixes-critical-vulnerability-discovered-by-positive-technologies-in-big-ip-application-delivery-controller/](https://www.ptsecurity.com/ww-en/about/news/f5-fixes-critical-vulnerability-discovered-by-positive-technologies-in-big-ip-application-delivery-controller/) -* [https://support.f5.com/csp/article/K52145254](https://support.f5.com/csp/article/K52145254) -* [https://blog.cloudflare.com/cve-2020-5902-helping-to-protect-against-the-f5-tmui-rce-vulnerability/](https://blog.cloudflare.com/cve-2020-5902-helping-to-protect-against-the-f5-tmui-rce-vulnerability/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/f5_tmui_rce_cve-2020-5902.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/fin7.md b/docs/_stories/fin7.md deleted file mode 100644 index 6ebc12420f..0000000000 --- a/docs/_stories/fin7.md +++ /dev/null @@ -1,55 +0,0 @@ ---- -title: "FIN7" -last_modified_at: 2021-09-14 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Leverage searches that allow you to detect and investigate unusual activities that might relate to the FIN7 JS Implant and JSSLoader, including looking for Image Loading of ldap and wmi modules, associated with its payload, data collection and script execution. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-09-14 -- **Author**: Teoderick Contreras, Splunk -- **ID**: df2b00d3-06ba-49f1-b253-b19cef19b569 - -#### Narrative - -FIN7 is a Russian criminal advanced persistent threat group that has primarily targeted the U.S. retail, restaurant, and hospitality sectors since mid-2015. A portion of FIN7 is run out of the front company Combi Security. It has been called one of the most successful criminal hacking groups in the world. this passed few day FIN7 tools and implant are seen in the wild where its code is updated. the FIN& is known to use the spear phishing attack as a entry to targetted network or host that will drop its staging payload like the JS and JSSloader. Now this artifacts and implants seen downloading other malware like cobaltstrike and event ransomware to encrypt host. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Check Elevated CMD using whoami](/endpoint/check_elevated_cmd_using_whoami/) | [System Owner/User Discovery](/tags/#system-owner/user-discovery)| TTP | -| [Cmdline Tool Not Executed In CMD Shell](/endpoint/cmdline_tool_not_executed_in_cmd_shell/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [JavaScript](/tags/#javascript)| TTP | -| [Jscript Execution Using Cscript App](/endpoint/jscript_execution_using_cscript_app/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [JavaScript](/tags/#javascript)| TTP | -| [MS Scripting Process Loading Ldap Module](/endpoint/ms_scripting_process_loading_ldap_module/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [JavaScript](/tags/#javascript)| Anomaly | -| [MS Scripting Process Loading WMI Module](/endpoint/ms_scripting_process_loading_wmi_module/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [JavaScript](/tags/#javascript)| Anomaly | -| [Non Chrome Process Accessing Chrome Default Dir](/endpoint/non_chrome_process_accessing_chrome_default_dir/) | [Credentials from Password Stores](/tags/#credentials-from-password-stores), [Credentials from Web Browsers](/tags/#credentials-from-web-browsers)| Anomaly | -| [Non Firefox Process Access Firefox Profile Dir](/endpoint/non_firefox_process_access_firefox_profile_dir/) | [Credentials from Password Stores](/tags/#credentials-from-password-stores), [Credentials from Web Browsers](/tags/#credentials-from-web-browsers)| Anomaly | -| [Office Application Drop Executable](/endpoint/office_application_drop_executable/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment)| TTP | -| [Office Product Spawning Wmic](/endpoint/office_product_spawning_wmic/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment)| TTP | -| [Vbscript Execution Using Wscript App](/endpoint/vbscript_execution_using_wscript_app/) | [Visual Basic](/tags/#visual-basic), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter)| TTP | -| [Wscript Or Cscript Suspicious Child Process](/endpoint/wscript_or_cscript_suspicious_child_process/) | [Process Injection](/tags/#process-injection), [Create or Modify System Process](/tags/#create-or-modify-system-process), [Parent PID Spoofing](/tags/#parent-pid-spoofing), [Access Token Manipulation](/tags/#access-token-manipulation)| TTP | -| [XSL Script Execution With WMIC](/endpoint/xsl_script_execution_with_wmic/) | [XSL Script Processing](/tags/#xsl-script-processing)| TTP | - -#### Reference - -* [https://en.wikipedia.org/wiki/FIN7](https://en.wikipedia.org/wiki/FIN7) -* [https://threatpost.com/fin7-windows-11-release/169206/](https://threatpost.com/fin7-windows-11-release/169206/) -* [https://www.proofpoint.com/us/blog/threat-insight/jssloader-recoded-and-reloaded](https://www.proofpoint.com/us/blog/threat-insight/jssloader-recoded-and-reloaded) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/fin7.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/gcp_cross_account_activity.md b/docs/_stories/gcp_cross_account_activity.md deleted file mode 100644 index 8d762bdbc1..0000000000 --- a/docs/_stories/gcp_cross_account_activity.md +++ /dev/null @@ -1,46 +0,0 @@ ---- -title: "GCP Cross Account Activity" -last_modified_at: 2020-09-01 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Track when a user assumes an IAM role in another GCP account to obtain cross-account access to services and resources in that account. Accessing new roles could be an indication of malicious activity. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: -- **Last Updated**: 2020-09-01 -- **Author**: Rod Soto, Splunk -- **ID**: 0432039c-ef41-4b03-b157-450c25dad1e6 - -#### Narrative - -Google Cloud Platform (GCP) admins manage access to GCP resources and services across the enterprise using GCP Identity and Access Management (IAM) functionality. IAM provides the ability to create and manage GCP users, groups, and roles-each with their own unique set of privileges and defined access to specific resources (such as Compute instances, the GCP Management Console, API, or the command-line interface). Unlike conventional (human) users, IAM roles are potentially assumable by anyone in the organization. They provide users with dynamically created temporary security credentials that expire within a set time period.\ -In between the time between when the temporary credentials are issued and when they expire is a period of opportunity, where a user could leverage the temporary credentials to wreak havoc-spin up or remove instances, create new users, elevate privileges, and other malicious activities-throughout the environment.\ -This Analytic Story includes searches that will help you monitor your GCP Audit logs logs for evidence of suspicious cross-account activity. For example, while accessing multiple GCP accounts and roles may be perfectly valid behavior, it may be suspicious when an account requests privileges of an account it has not accessed in the past. After identifying suspicious activities, you can use the provided investigative searches to help you probe more deeply. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [GCP Detect accounts with high risk roles by project](/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project/) | [Valid Accounts](/tags/#valid-accounts)| Hunting | -| [GCP Detect high risk permissions by resource and account](/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account/) | [Valid Accounts](/tags/#valid-accounts)| Hunting | -| [gcp detect oauth token abuse](/deprecated/gcp_detect_oauth_token_abuse/) | [Valid Accounts](/tags/#valid-accounts)| Hunting | -| [GCP Detect gcploit framework](/cloud/gcp_detect_gcploit_framework/) | [Valid Accounts](/tags/#valid-accounts)| TTP | - -#### Reference - -* [https://cloud.google.com/iam/docs/understanding-service-accounts](https://cloud.google.com/iam/docs/understanding-service-accounts) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/gcp_cross_account_activity.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/hafnium_group.md b/docs/_stories/hafnium_group.md deleted file mode 100644 index ddbe954a9a..0000000000 --- a/docs/_stories/hafnium_group.md +++ /dev/null @@ -1,66 +0,0 @@ ---- -title: "HAFNIUM Group" -last_modified_at: 2021-03-03 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Network_Traffic - - Actions on Objectives - - Command & Control - - Exploitation - - Installation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -HAFNIUM group was identified by Microsoft as exploiting 4 Microsoft Exchange CVEs in the wild - CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint), [Network_Traffic](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkTraffic) -- **Last Updated**: 2021-03-03 -- **Author**: Michael Haag, Splunk -- **ID**: beae2ab0-7c3f-11eb-8b63-acde48001122 - -#### Narrative - -On Tuesday, March 2, 2021, Microsoft released a set of security patches for its mail server, Microsoft Exchange. These patches respond to a group of vulnerabilities known to impact Exchange 2013, 2016, and 2019. It is important to note that an Exchange 2010 security update has also been issued, though the CVEs do not reference that version as being vulnerable.\ -While the CVEs do not shed much light on the specifics of the vulnerabilities or exploits, the first vulnerability (CVE-2021-26855) has a remote network attack vector that allows the attacker, a group Microsoft named HAFNIUM, to authenticate as the Exchange server. Three additional vulnerabilities (CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065) were also identified as part of this activity. When chained together along with CVE-2021-26855 for initial access, the attacker would have complete control over the Exchange server. This includes the ability to run code as SYSTEM and write to any path on the server.\ -The following Splunk detections assist with identifying the HAFNIUM groups tradecraft and methodology. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Dump LSASS via procdump Rename](/deprecated/dump_lsass_via_procdump_rename/) | [LSASS Memory](/tags/#lsass-memory)| Hunting | -| [Any Powershell DownloadString](/endpoint/any_powershell_downloadstring/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell), [Ingress Tool Transfer](/tags/#ingress-tool-transfer)| TTP | -| [Detect Exchange Web Shell](/endpoint/detect_exchange_web_shell/) | [Server Software Component](/tags/#server-software-component), [Web Shell](/tags/#web-shell), [Exploit Public-Facing Application](/tags/#exploit-public-facing-application)| TTP | -| [Detect New Local Admin account](/endpoint/detect_new_local_admin_account/) | [Local Account](/tags/#local-account), [Create Account](/tags/#create-account)| TTP | -| [Detect PsExec With accepteula Flag](/endpoint/detect_psexec_with_accepteula_flag/) | [Remote Services](/tags/#remote-services), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares)| TTP | -| [Detect Renamed PSExec](/endpoint/detect_renamed_psexec/) | [System Services](/tags/#system-services), [Service Execution](/tags/#service-execution)| Hunting | -| [Dump LSASS via comsvcs DLL](/endpoint/dump_lsass_via_comsvcs_dll/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping)| TTP | -| [Dump LSASS via procdump](/endpoint/dump_lsass_via_procdump/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping)| TTP | -| [Malicious PowerShell Process - Execution Policy Bypass](/endpoint/malicious_powershell_process_-_execution_policy_bypass/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell)| TTP | -| [Nishang PowershellTCPOneLine](/endpoint/nishang_powershelltcponeline/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell)| TTP | -| [Ntdsutil Export NTDS](/endpoint/ntdsutil_export_ntds/) | [NTDS](/tags/#ntds), [OS Credential Dumping](/tags/#os-credential-dumping)| TTP | -| [PowerShell - Connect To Internet With Hidden Window](/endpoint/powershell_-_connect_to_internet_with_hidden_window/) | [PowerShell](/tags/#powershell), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter)| Hunting | -| [Set Default PowerShell Execution Policy To Unrestricted or Bypass](/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell)| TTP | -| [Unified Messaging Service Spawning a Process](/endpoint/unified_messaging_service_spawning_a_process/) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application)| TTP | -| [W3WP Spawning Shell](/endpoint/w3wp_spawning_shell/) | [Server Software Component](/tags/#server-software-component), [Web Shell](/tags/#web-shell)| TTP | -| [Email servers sending high volume traffic to hosts](/application/email_servers_sending_high_volume_traffic_to_hosts/) | [Email Collection](/tags/#email-collection), [Remote Email Collection](/tags/#remote-email-collection)| Anomaly | - -#### Reference - -* [https://www.splunk.com/en_us/blog/security/detecting-hafnium-exchange-server-zero-day-activity-in-splunk.html](https://www.splunk.com/en_us/blog/security/detecting-hafnium-exchange-server-zero-day-activity-in-splunk.html) -* [https://www.volexity.com/blog/2021/03/02/active-exploitation-of-microsoft-exchange-zero-day-vulnerabilities/](https://www.volexity.com/blog/2021/03/02/active-exploitation-of-microsoft-exchange-zero-day-vulnerabilities/) -* [https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/](https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/) -* [https://blog.rapid7.com/2021/03/03/rapid7s-insightidr-enables-detection-and-response-to-microsoft-exchange-0-day/](https://blog.rapid7.com/2021/03/03/rapid7s-insightidr-enables-detection-and-response-to-microsoft-exchange-0-day/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/hafnium_group.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/hermetic_wiper.md b/docs/_stories/hermetic_wiper.md deleted file mode 100644 index a604392772..0000000000 --- a/docs/_stories/hermetic_wiper.md +++ /dev/null @@ -1,99 +0,0 @@ ---- -title: "Hermetic Wiper" -last_modified_at: 2022-03-02 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Email - - Endpoint - - Actions on Objectives - - Command & Control - - Delivery - - Exploitation - - Installation - - Reconnaissance ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic story contains detections that allow security analysts to detect and investigate unusual activities that might relate to the destructive malware targeting Ukrainian organizations also known as "Hermetic Wiper". This analytic story looks for abuse of Regsvr32, executables written in administrative SMB Share, suspicious processes, disabling of memory crash dump and more. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Email](https://docs.splunk.com/Documentation/CIM/latest/User/Email), [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-03-02 -- **Author**: Teoderick Contreras, Rod Soto, Michael Haag, Splunk -- **ID**: b7511c2e-9a10-11ec-99e3-acde48001122 - -#### Narrative - -Hermetic Wiper is destructive malware operation found by Sentinel One targeting multiple organizations in Ukraine. This malicious payload corrupts Master Boot Records, uses signed drivers and manipulates NTFS attributes for file destruction. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Suspicious Powershell Command-Line Arguments](/deprecated/suspicious_powershell_command-line_arguments/) | [PowerShell](/tags/#powershell)| TTP | -| [Uncommon Processes On Endpoint](/deprecated/uncommon_processes_on_endpoint/) | [Malicious File](/tags/#malicious-file)| Hunting | -| [Active Setup Registry Autostart](/endpoint/active_setup_registry_autostart/) | [Active Setup](/tags/#active-setup), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution)| TTP | -| [Any Powershell DownloadFile](/endpoint/any_powershell_downloadfile/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell), [Ingress Tool Transfer](/tags/#ingress-tool-transfer)| TTP | -| [Any Powershell DownloadString](/endpoint/any_powershell_downloadstring/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell), [Ingress Tool Transfer](/tags/#ingress-tool-transfer)| TTP | -| [Change Default File Association](/endpoint/change_default_file_association/) | [Change Default File Association](/tags/#change-default-file-association), [Event Triggered Execution](/tags/#event-triggered-execution)| TTP | -| [CMD Carry Out String Command Parameter](/endpoint/cmd_carry_out_string_command_parameter/) | [Windows Command Shell](/tags/#windows-command-shell), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter)| Hunting | -| [Detect Empire with PowerShell Script Block Logging](/endpoint/detect_empire_with_powershell_script_block_logging/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell)| TTP | -| [Detect Mimikatz With PowerShell Script Block Logging](/endpoint/detect_mimikatz_with_powershell_script_block_logging/) | [OS Credential Dumping](/tags/#os-credential-dumping), [PowerShell](/tags/#powershell)| TTP | -| [ETW Registry Disabled](/endpoint/etw_registry_disabled/) | [Indicator Blocking](/tags/#indicator-blocking), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Executable File Written in Administrative SMB Share](/endpoint/executable_file_written_in_administrative_smb_share/) | [Remote Services](/tags/#remote-services), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares)| TTP | -| [Executables Or Script Creation In Suspicious Path](/endpoint/executables_or_script_creation_in_suspicious_path/) | [Masquerading](/tags/#masquerading)| TTP | -| [Kerberoasting spn request with RC4 encryption](/endpoint/kerberoasting_spn_request_with_rc4_encryption/) | [Steal or Forge Kerberos Tickets](/tags/#steal-or-forge-kerberos-tickets), [Kerberoasting](/tags/#kerberoasting)| TTP | -| [Linux Java Spawning Shell](/endpoint/linux_java_spawning_shell/) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application)| TTP | -| [Logon Script Event Trigger Execution](/endpoint/logon_script_event_trigger_execution/) | [Boot or Logon Initialization Scripts](/tags/#boot-or-logon-initialization-scripts), [Logon Script (Windows)](/tags/#logon-script-(windows))| TTP | -| [Malicious PowerShell Process - Encoded Command](/endpoint/malicious_powershell_process_-_encoded_command/) | [Obfuscated Files or Information](/tags/#obfuscated-files-or-information)| Hunting | -| [Malicious PowerShell Process With Obfuscation Techniques](/endpoint/malicious_powershell_process_with_obfuscation_techniques/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell)| TTP | -| [MSI Module Loaded by Non-System Binary](/endpoint/msi_module_loaded_by_non-system_binary/) | [DLL Side-Loading](/tags/#dll-side-loading), [Hijack Execution Flow](/tags/#hijack-execution-flow)| Hunting | -| [Overwriting Accessibility Binaries](/endpoint/overwriting_accessibility_binaries/) | [Event Triggered Execution](/tags/#event-triggered-execution), [Accessibility Features](/tags/#accessibility-features)| TTP | -| [Possible Lateral Movement PowerShell Spawn](/endpoint/possible_lateral_movement_powershell_spawn/) | [Remote Services](/tags/#remote-services), [Distributed Component Object Model](/tags/#distributed-component-object-model), [Windows Remote Management](/tags/#windows-remote-management), [Windows Management Instrumentation](/tags/#windows-management-instrumentation), [Scheduled Task](/tags/#scheduled-task), [Windows Service](/tags/#windows-service), [PowerShell](/tags/#powershell), [MMC](/tags/#mmc)| TTP | -| [PowerShell 4104 Hunting](/endpoint/powershell_4104_hunting/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell)| Hunting | -| [PowerShell - Connect To Internet With Hidden Window](/endpoint/powershell_-_connect_to_internet_with_hidden_window/) | [PowerShell](/tags/#powershell), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter)| Hunting | -| [PowerShell Domain Enumeration](/endpoint/powershell_domain_enumeration/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell)| TTP | -| [Powershell Enable SMB1Protocol Feature](/endpoint/powershell_enable_smb1protocol_feature/) | [Obfuscated Files or Information](/tags/#obfuscated-files-or-information), [Indicator Removal from Tools](/tags/#indicator-removal-from-tools)| TTP | -| [Powershell Execute COM Object](/endpoint/powershell_execute_com_object/) | [Component Object Model Hijacking](/tags/#component-object-model-hijacking), [Event Triggered Execution](/tags/#event-triggered-execution), [PowerShell](/tags/#powershell)| TTP | -| [Powershell Fileless Process Injection via GetProcAddress](/endpoint/powershell_fileless_process_injection_via_getprocaddress/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Process Injection](/tags/#process-injection), [PowerShell](/tags/#powershell)| TTP | -| [Powershell Fileless Script Contains Base64 Encoded Content](/endpoint/powershell_fileless_script_contains_base64_encoded_content/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Obfuscated Files or Information](/tags/#obfuscated-files-or-information), [PowerShell](/tags/#powershell)| TTP | -| [PowerShell Loading DotNET into Memory via Reflection](/endpoint/powershell_loading_dotnet_into_memory_via_reflection/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell)| TTP | -| [Powershell Processing Stream Of Data](/endpoint/powershell_processing_stream_of_data/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell)| TTP | -| [Powershell Using memory As Backing Store](/endpoint/powershell_using_memory_as_backing_store/) | [PowerShell](/tags/#powershell), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter)| TTP | -| [Recon AVProduct Through Pwh or WMI](/endpoint/recon_avproduct_through_pwh_or_wmi/) | [Gather Victim Host Information](/tags/#gather-victim-host-information)| TTP | -| [Recon Using WMI Class](/endpoint/recon_using_wmi_class/) | [Gather Victim Host Information](/tags/#gather-victim-host-information), [PowerShell](/tags/#powershell)| TTP | -| [Registry Keys Used For Privilege Escalation](/endpoint/registry_keys_used_for_privilege_escalation/) | [Image File Execution Options Injection](/tags/#image-file-execution-options-injection), [Event Triggered Execution](/tags/#event-triggered-execution)| TTP | -| [Regsvr32 Silent and Install Param Dll Loading](/endpoint/regsvr32_silent_and_install_param_dll_loading/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Regsvr32](/tags/#regsvr32)| Anomaly | -| [Runas Execution in CommandLine](/endpoint/runas_execution_in_commandline/) | [Access Token Manipulation](/tags/#access-token-manipulation), [Token Impersonation/Theft](/tags/#token-impersonation/theft)| Hunting | -| [Screensaver Event Trigger Execution](/endpoint/screensaver_event_trigger_execution/) | [Event Triggered Execution](/tags/#event-triggered-execution), [Screensaver](/tags/#screensaver)| TTP | -| [Set Default PowerShell Execution Policy To Unrestricted or Bypass](/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell)| TTP | -| [Suspicious Process File Path](/endpoint/suspicious_process_file_path/) | [Create or Modify System Process](/tags/#create-or-modify-system-process)| TTP | -| [Time Provider Persistence Registry](/endpoint/time_provider_persistence_registry/) | [Time Providers](/tags/#time-providers), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution)| TTP | -| [Unloading AMSI via Reflection](/endpoint/unloading_amsi_via_reflection/) | [Impair Defenses](/tags/#impair-defenses), [PowerShell](/tags/#powershell), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter)| TTP | -| [W3WP Spawning Shell](/endpoint/w3wp_spawning_shell/) | [Server Software Component](/tags/#server-software-component), [Web Shell](/tags/#web-shell)| TTP | -| [Windows Disable Memory Crash Dump](/endpoint/windows_disable_memory_crash_dump/) | [Data Destruction](/tags/#data-destruction)| TTP | -| [Windows File Without Extension In Critical Folder](/endpoint/windows_file_without_extension_in_critical_folder/) | [Data Destruction](/tags/#data-destruction)| TTP | -| [Windows Modify Show Compress Color And Info Tip Registry](/endpoint/windows_modify_show_compress_color_and_info_tip_registry/) | [Modify Registry](/tags/#modify-registry)| TTP | -| [Windows Raw Access To Disk Volume Partition](/endpoint/windows_raw_access_to_disk_volume_partition/) | [Disk Structure Wipe](/tags/#disk-structure-wipe), [Disk Wipe](/tags/#disk-wipe)| Anomaly | -| [Windows Raw Access To Master Boot Record Drive](/endpoint/windows_raw_access_to_master_boot_record_drive/) | [Disk Structure Wipe](/tags/#disk-structure-wipe), [Disk Wipe](/tags/#disk-wipe)| TTP | -| [WMI Recon Running Process Or Services](/endpoint/wmi_recon_running_process_or_services/) | [Gather Victim Host Information](/tags/#gather-victim-host-information)| TTP | -| [Email Attachments With Lots Of Spaces](/application/email_attachments_with_lots_of_spaces/) | None| Anomaly | -| [Suspicious Email Attachment Extensions](/application/suspicious_email_attachment_extensions/) | [Spearphishing Attachment](/tags/#spearphishing-attachment), [Phishing](/tags/#phishing)| Anomaly | -| [Child Processes of Spoolsv exe](/endpoint/child_processes_of_spoolsv_exe/) | [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation)| TTP | -| [Print Processor Registry Autostart](/endpoint/print_processor_registry_autostart/) | [Print Processors](/tags/#print-processors), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution)| TTP | - -#### Reference - -* [https://www.sentinelone.com/labs/hermetic-wiper-ukraine-under-attack/](https://www.sentinelone.com/labs/hermetic-wiper-ukraine-under-attack/) -* [https://www.cisa.gov/uscert/ncas/alerts/aa22-057a](https://www.cisa.gov/uscert/ncas/alerts/aa22-057a) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/hermetic_wiper.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/hidden_cobra_malware.md b/docs/_stories/hidden_cobra_malware.md deleted file mode 100644 index 3d81551f91..0000000000 --- a/docs/_stories/hidden_cobra_malware.md +++ /dev/null @@ -1,58 +0,0 @@ ---- -title: "Hidden Cobra Malware" -last_modified_at: 2020-01-22 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Network_Resolution - - Network_Traffic - - Actions on Objectives - - Command & Control ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Monitor for and investigate activities, including the creation or deletion of hidden shares and file writes, that may be evidence of infiltration by North Korean government-sponsored cybercriminals. Details of this activity were reported in DHS Report TA-18-149A. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint), [Network_Resolution](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkResolution), [Network_Traffic](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkTraffic) -- **Last Updated**: 2020-01-22 -- **Author**: Rico Valdez, Splunk -- **ID**: baf7580b-d4b4-4774-8173-7d198e9da335 - -#### Narrative - -North Korea's government-sponsored "cyber army" has been slowly building momentum and gaining sophistication over the last 15 years or so. As a result, the group's activity, which the US government refers to as "Hidden Cobra," has surreptitiously crept onto the collective radar as a preeminent global threat.\ -These state-sponsored actors are thought to be responsible for everything from a hack on a South Korean nuclear plant to an attack on Sony in anticipation of its release of the movie "The Interview" at the end of 2014. They're also notorious for cyberespionage. In recent years, the group seems to be focused on financial crimes, such as cryptojacking.\ -In June of 2018, The Department of Homeland Security, together with the FBI and other U.S. government partners, issued Technical Alert (TA-18-149A) to advise the public about two variants of North Korean malware. One variant, dubbed "Joanap," is a multi-stage peer-to-peer botnet that allows North Korean state actors to exfiltrate data, download and execute secondary payloads, and initialize proxy communications. The other variant, "Brambul," is a Windows32 SMB worm that is dropped into a victim network. When executed, the malware attempts to spread laterally within a victim's local subnet, connecting via the SMB protocol and initiating brute-force password attacks. It reports details to the Hidden Cobra actors via email, so they can use the information for secondary remote operations.\ -Among other searches in this Analytic Story is a detection search that looks for the creation or deletion of hidden shares, such as, "adnim$," which the Hidden Cobra malware creates on the target system. Another looks for the creation of three malicious files associated with the malware. You can also use a search in this story to investigate activity that indicates that malware is sending email back to the attackers. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [First time seen command line argument](/deprecated/first_time_seen_command_line_argument/) | [PowerShell](/tags/#powershell), [Windows Command Shell](/tags/#windows-command-shell)| Hunting | -| [Suspicious File Write](/deprecated/suspicious_file_write/) | None| Hunting | -| [Create or delete windows shares using net exe](/endpoint/create_or_delete_windows_shares_using_net_exe/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host), [Network Share Connection Removal](/tags/#network-share-connection-removal)| TTP | -| [Remote Desktop Process Running On System](/endpoint/remote_desktop_process_running_on_system/) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol), [Remote Services](/tags/#remote-services)| Hunting | -| [Detect Outbound SMB Traffic](/network/detect_outbound_smb_traffic/) | [File Transfer Protocols](/tags/#file-transfer-protocols), [Application Layer Protocol](/tags/#application-layer-protocol)| TTP | -| [DNS Query Length Outliers - MLTK](/network/dns_query_length_outliers_-_mltk/) | [DNS](/tags/#dns), [Application Layer Protocol](/tags/#application-layer-protocol)| Anomaly | -| [Remote Desktop Network Traffic](/network/remote_desktop_network_traffic/) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol), [Remote Services](/tags/#remote-services)| Anomaly | -| [SMB Traffic Spike](/network/smb_traffic_spike/) | [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares), [Remote Services](/tags/#remote-services)| Anomaly | -| [SMB Traffic Spike - MLTK](/network/smb_traffic_spike_-_mltk/) | [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares), [Remote Services](/tags/#remote-services)| Anomaly | -| [DNS Query Length With High Standard Deviation](/network/dns_query_length_with_high_standard_deviation/) | [Exfiltration Over Unencrypted Non-C2 Protocol](/tags/#exfiltration-over-unencrypted-non-c2-protocol), [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol)| Anomaly | - -#### Reference - -* [https://web.archive.org/web/20191220004307/https://www.us-cert.gov/HIDDEN-COBRA-North-Korean-Malicious-Cyber-Activity](https://web.archive.org/web/20191220004307/https://www.us-cert.gov/HIDDEN-COBRA-North-Korean-Malicious-Cyber-Activity) -* [https://web.archive.org/web/20220421112536/https://www.operationblockbuster.com/wp-content/uploads/2016/02/Operation-Blockbuster-Destructive-Malware-Report.pdf](https://web.archive.org/web/20220421112536/https://www.operationblockbuster.com/wp-content/uploads/2016/02/Operation-Blockbuster-Destructive-Malware-Report.pdf) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/hidden_cobra_malware.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_stories/host_redirection.md b/docs/_stories/host_redirection.md deleted file mode 100644 index 4ab74f8622..0000000000 --- a/docs/_stories/host_redirection.md +++ /dev/null @@ -1,44 +0,0 @@ ---- -title: "Host Redirection" -last_modified_at: 2017-09-14 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Network_Resolution - - Command & Control ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Detect evidence of tactics used to redirect traffic from a host to a destination other than the one intended--potentially one that is part of an adversary's attack infrastructure. An example is redirecting communications regarding patches and updates or misleading users into visiting a malicious website. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Network_Resolution](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkResolution) -- **Last Updated**: 2017-09-14 -- **Author**: Rico Valdez, Splunk -- **ID**: 2e8948a5-5239-406b-b56b-6c50fe268af4 - -#### Narrative - -Attackers will often attempt to manipulate client communications for nefarious purposes. In some cases, an attacker may endeavor to modify a local host file to redirect communications with resources (such as antivirus or system-update services) to prevent clients from receiving patches or updates. In other cases, an attacker might use this tactic to have the client connect to a site that looks like the intended site, but instead installs malware or collects information from the victim. Additionally, an attacker may redirect a victim in order to execute a MITM attack and observe communications. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Clients Connecting to Multiple DNS Servers](/deprecated/clients_connecting_to_multiple_dns_servers/) | [Exfiltration Over Unencrypted Non-C2 Protocol](/tags/#exfiltration-over-unencrypted-non-c2-protocol)| TTP | -| [DNS Query Requests Resolved by Unauthorized DNS Servers](/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers/) | [DNS](/tags/#dns)| TTP | -| [Windows hosts file modification](/deprecated/windows_hosts_file_modification/) | None| TTP | - -#### Reference - -* [https://blog.malwarebytes.com/cybercrime/2016/09/hosts-file-hijacks/](https://blog.malwarebytes.com/cybercrime/2016/09/hosts-file-hijacks/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/host_redirection.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/icedid.md b/docs/_stories/icedid.md deleted file mode 100644 index a5153582c8..0000000000 --- a/docs/_stories/icedid.md +++ /dev/null @@ -1,71 +0,0 @@ ---- -title: "IcedID" -last_modified_at: 2021-07-29 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Actions on Objectives - - Exploitation - - Reconnaissance ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Leverage searches that allow you to detect and investigate unusual activities that might relate to the IcedID banking trojan, including looking for file writes associated with its payload, process injection, shellcode execution and data collection. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-07-29 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 1d2cc747-63d7-49a9-abb8-93aa36305603 - -#### Narrative - -IcedId banking trojan campaigns targeting banks and other vertical sectors.This malware is known in Microsoft Windows OS targetting browser such as firefox and chrom to steal banking information. It is also known to its unique payload downloaded in C2 where it can be a .png file that hides the core shellcode bot using steganography technique or gzip dat file that contains "license.dat" which is the actual core icedid bot. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Account Discovery With Net App](/endpoint/account_discovery_with_net_app/) | [Domain Account](/tags/#domain-account), [Account Discovery](/tags/#account-discovery)| TTP | -| [CHCP Command Execution](/endpoint/chcp_command_execution/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter)| TTP | -| [CMD Carry Out String Command Parameter](/endpoint/cmd_carry_out_string_command_parameter/) | [Windows Command Shell](/tags/#windows-command-shell), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter)| Hunting | -| [Create Remote Thread In Shell Application](/endpoint/create_remote_thread_in_shell_application/) | [Process Injection](/tags/#process-injection)| TTP | -| [Disable Schedule Task](/endpoint/disable_schedule_task/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Drop IcedID License dat](/endpoint/drop_icedid_license_dat/) | [User Execution](/tags/#user-execution), [Malicious File](/tags/#malicious-file)| Hunting | -| [Eventvwr UAC Bypass](/endpoint/eventvwr_uac_bypass/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism)| TTP | -| [FodHelper UAC Bypass](/endpoint/fodhelper_uac_bypass/) | [Modify Registry](/tags/#modify-registry), [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism)| TTP | -| [IcedID Exfiltrated Archived File Creation](/endpoint/icedid_exfiltrated_archived_file_creation/) | [Archive via Utility](/tags/#archive-via-utility), [Archive Collected Data](/tags/#archive-collected-data)| Hunting | -| [Mshta spawning Rundll32 OR Regsvr32 Process](/endpoint/mshta_spawning_rundll32_or_regsvr32_process/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Mshta](/tags/#mshta)| TTP | -| [NLTest Domain Trust Discovery](/endpoint/nltest_domain_trust_discovery/) | [Domain Trust Discovery](/tags/#domain-trust-discovery)| TTP | -| [Office Application Spawn Regsvr32 process](/endpoint/office_application_spawn_regsvr32_process/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment)| TTP | -| [Office Application Spawn rundll32 process](/endpoint/office_application_spawn_rundll32_process/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment)| TTP | -| [Office Document Executing Macro Code](/endpoint/office_document_executing_macro_code/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment)| TTP | -| [Office Product Spawning MSHTA](/endpoint/office_product_spawning_mshta/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment)| TTP | -| [Registry Keys Used For Persistence](/endpoint/registry_keys_used_for_persistence/) | [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution)| TTP | -| [Regsvr32 with Known Silent Switch Cmdline](/endpoint/regsvr32_with_known_silent_switch_cmdline/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Regsvr32](/tags/#regsvr32)| Anomaly | -| [Rundll32 Create Remote Thread To A Process](/endpoint/rundll32_create_remote_thread_to_a_process/) | [Process Injection](/tags/#process-injection)| TTP | -| [Rundll32 CreateRemoteThread In Browser](/endpoint/rundll32_createremotethread_in_browser/) | [Process Injection](/tags/#process-injection)| TTP | -| [Rundll32 DNSQuery](/endpoint/rundll32_dnsquery/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Rundll32](/tags/#rundll32)| TTP | -| [Rundll32 Process Creating Exe Dll Files](/endpoint/rundll32_process_creating_exe_dll_files/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Rundll32](/tags/#rundll32)| TTP | -| [Schedule Task with Rundll32 Command Trigger](/endpoint/schedule_task_with_rundll32_command_trigger/) | [Scheduled Task/Job](/tags/#scheduled-task/job)| TTP | -| [Sqlite Module In Temp Folder](/endpoint/sqlite_module_in_temp_folder/) | [Data from Local System](/tags/#data-from-local-system)| TTP | -| [Suspicious IcedID Rundll32 Cmdline](/endpoint/suspicious_icedid_rundll32_cmdline/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Rundll32](/tags/#rundll32)| TTP | -| [Suspicious Rundll32 PluginInit](/endpoint/suspicious_rundll32_plugininit/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Rundll32](/tags/#rundll32)| TTP | -| [WinEvent Scheduled Task Created Within Public Path](/endpoint/winevent_scheduled_task_created_within_public_path/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job)| TTP | -| [WinEvent Windows Task Scheduler Event Action Started](/endpoint/winevent_windows_task_scheduler_event_action_started/) | [Scheduled Task](/tags/#scheduled-task)| Hunting | - -#### Reference - -* [https://threatpost.com/icedid-banking-trojan-surges-emotet/165314/](https://threatpost.com/icedid-banking-trojan-surges-emotet/165314/) -* [https://app.any.run/tasks/48414a33-3d66-4a46-afe5-c2003bb55ccf/](https://app.any.run/tasks/48414a33-3d66-4a46-afe5-c2003bb55ccf/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/icedid.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/industroyer2.md b/docs/_stories/industroyer2.md deleted file mode 100644 index d14ba34e91..0000000000 --- a/docs/_stories/industroyer2.md +++ /dev/null @@ -1,68 +0,0 @@ ---- -title: "Industroyer2" -last_modified_at: 2022-04-21 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Actions on Objectives - - Exploitation - - Reconnaissance ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Leverage searches that allow you to detect and investigate unusual activities that might relate to the Industroyer2 attack, including file writes associated with its payload, lateral movement, persistence, privilege escalation and data destruction. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-04-21 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 7ff7db2b-b001-498e-8fe8-caf2dbc3428a - -#### Narrative - -Industroyer2 is part of continuous attack to ukraine targeting energy facilities. This malware is a windows binary that implement IEC-104 protocol to communicate with industrial equipments. This attack consist of several destructive linux script component to wipe or delete several linux critical files, powershell for domain enumeration and caddywiper to wipe boot sector of the targeted host. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [AdsiSearcher Account Discovery](/endpoint/adsisearcher_account_discovery/) | [Domain Account](/tags/#domain-account), [Account Discovery](/tags/#account-discovery)| TTP | -| [Attempted Credential Dump From Registry via Reg exe](/endpoint/attempted_credential_dump_from_registry_via_reg_exe/) | [Security Account Manager](/tags/#security-account-manager), [OS Credential Dumping](/tags/#os-credential-dumping)| TTP | -| [Dump LSASS via comsvcs DLL](/endpoint/dump_lsass_via_comsvcs_dll/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping)| TTP | -| [Executable File Written in Administrative SMB Share](/endpoint/executable_file_written_in_administrative_smb_share/) | [Remote Services](/tags/#remote-services), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares)| TTP | -| [Executables Or Script Creation In Suspicious Path](/endpoint/executables_or_script_creation_in_suspicious_path/) | [Masquerading](/tags/#masquerading)| TTP | -| [Impacket Lateral Movement Commandline Parameters](/endpoint/impacket_lateral_movement_commandline_parameters/) | [Remote Services](/tags/#remote-services), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares), [Distributed Component Object Model](/tags/#distributed-component-object-model), [Windows Management Instrumentation](/tags/#windows-management-instrumentation), [Windows Service](/tags/#windows-service)| TTP | -| [Linux Adding Crontab Using List Parameter](/endpoint/linux_adding_crontab_using_list_parameter/) | [Cron](/tags/#cron), [Scheduled Task/Job](/tags/#scheduled-task/job)| Hunting | -| [Linux DD File Overwrite](/endpoint/linux_dd_file_overwrite/) | [Data Destruction](/tags/#data-destruction)| TTP | -| [Linux Deleting Critical Directory Using RM Command](/endpoint/linux_deleting_critical_directory_using_rm_command/) | [Data Destruction](/tags/#data-destruction)| TTP | -| [Linux Disable Services](/endpoint/linux_disable_services/) | [Service Stop](/tags/#service-stop)| TTP | -| [Linux High Frequency Of File Deletion In Boot Folder](/endpoint/linux_high_frequency_of_file_deletion_in_boot_folder/) | [Data Destruction](/tags/#data-destruction), [File Deletion](/tags/#file-deletion), [Indicator Removal on Host](/tags/#indicator-removal-on-host)| TTP | -| [Linux Shred Overwrite Command](/endpoint/linux_shred_overwrite_command/) | [Data Destruction](/tags/#data-destruction)| TTP | -| [Linux Stop Services](/endpoint/linux_stop_services/) | [Service Stop](/tags/#service-stop)| TTP | -| [Linux System Network Discovery](/endpoint/linux_system_network_discovery/) | [System Network Configuration Discovery](/tags/#system-network-configuration-discovery)| Anomaly | -| [Recon Using WMI Class](/endpoint/recon_using_wmi_class/) | [Gather Victim Host Information](/tags/#gather-victim-host-information), [PowerShell](/tags/#powershell)| TTP | -| [Schtasks Run Task On Demand](/endpoint/schtasks_run_task_on_demand/) | [Scheduled Task/Job](/tags/#scheduled-task/job)| TTP | -| [Suspicious Process File Path](/endpoint/suspicious_process_file_path/) | [Create or Modify System Process](/tags/#create-or-modify-system-process)| TTP | -| [Windows Hidden Schedule Task Settings](/endpoint/windows_hidden_schedule_task_settings/) | [Scheduled Task/Job](/tags/#scheduled-task/job)| TTP | -| [Windows Linked Policies In ADSI Discovery](/endpoint/windows_linked_policies_in_adsi_discovery/) | [Domain Account](/tags/#domain-account), [Account Discovery](/tags/#account-discovery)| Anomaly | -| [Windows Processes Killed By Industroyer2 Malware](/endpoint/windows_processes_killed_by_industroyer2_malware/) | [Service Stop](/tags/#service-stop)| Anomaly | -| [Windows Root Domain linked policies Discovery](/endpoint/windows_root_domain_linked_policies_discovery/) | [Domain Account](/tags/#domain-account), [Account Discovery](/tags/#account-discovery)| Anomaly | -| [WinEvent Scheduled Task Created Within Public Path](/endpoint/winevent_scheduled_task_created_within_public_path/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job)| TTP | -| [WinEvent Windows Task Scheduler Event Action Started](/endpoint/winevent_windows_task_scheduler_event_action_started/) | [Scheduled Task](/tags/#scheduled-task)| Hunting | -| [Linux Stdout Redirection To Dev Null File](/endpoint/linux_stdout_redirection_to_dev_null_file/) | [Disable or Modify System Firewall](/tags/#disable-or-modify-system-firewall), [Impair Defenses](/tags/#impair-defenses)| Anomaly | - -#### Reference - -* [https://cert.gov.ua/article/39518](https://cert.gov.ua/article/39518) -* [https://www.welivesecurity.com/2022/04/12/industroyer2-industroyer-reloaded/](https://www.welivesecurity.com/2022/04/12/industroyer2-industroyer-reloaded/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/industroyer2.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/information_sabotage.md b/docs/_stories/information_sabotage.md deleted file mode 100644 index 9acee4b867..0000000000 --- a/docs/_stories/information_sabotage.md +++ /dev/null @@ -1,43 +0,0 @@ ---- -title: "Information Sabotage" -last_modified_at: 2021-11-17 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Splunk Behavioral Analytics - - Endpoint - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Leverage searches that allow you to detect and investigate unusual activities that might correlate to insider threat specially in terms of information sabotage. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud, Splunk Behavioral Analytics -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-11-17 -- **Author**: Teoderick Contreras, Splunk -- **ID**: b71ba595-ef80-4e39-8b66-887578a7a71b - -#### Narrative - -Information sabotage is the type of crime many people associate with insider threat. Where the current or former employees, contractors, or business partners intentionally exceeded or misused an authorized level of access to networks, systems, or data with the intention of harming a specific individual, the organization, or the organization's data, systems, and/or daily business operations. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [High Frequency Copy Of Files In Network Share](/endpoint/high_frequency_copy_of_files_in_network_share/) | [Transfer Data to Cloud Account](/tags/#transfer-data-to-cloud-account)| Anomaly | - -#### Reference - -* [https://insights.sei.cmu.edu/blog/insider-threat-deep-dive-it-sabotage/](https://insights.sei.cmu.edu/blog/insider-threat-deep-dive-it-sabotage/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/information_sabotage.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/ingress_tool_transfer.md b/docs/_stories/ingress_tool_transfer.md deleted file mode 100644 index 1063859b5d..0000000000 --- a/docs/_stories/ingress_tool_transfer.md +++ /dev/null @@ -1,52 +0,0 @@ ---- -title: "Ingress Tool Transfer" -last_modified_at: 2021-03-24 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Actions on Objectives - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Adversaries may transfer tools or other files from an external system into a compromised environment. Files may be copied from an external adversary controlled system through the command and control channel to bring tools into the victim network or through alternate protocols with another tool such as FTP. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-03-24 -- **Author**: Michael Haag, Splunk -- **ID**: b3782036-8cbd-11eb-9d8e-acde48001122 - -#### Narrative - -Ingress tool transfer is a Technique under tactic Command and Control. Behaviors will include the use of living off the land binaries to download implants or binaries over alternate communication ports. It is imperative to baseline applications on endpoints to understand what generates network activity, to where, and what is its native behavior. These utilities, when abused, will write files to disk in world writeable paths.\ During triage, review the reputation of the remote public destination IP or domain. Capture any files written to disk and perform analysis. Review other parrallel processes for additional behaviors. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Any Powershell DownloadFile](/endpoint/any_powershell_downloadfile/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell), [Ingress Tool Transfer](/tags/#ingress-tool-transfer)| TTP | -| [Any Powershell DownloadString](/endpoint/any_powershell_downloadstring/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell), [Ingress Tool Transfer](/tags/#ingress-tool-transfer)| TTP | -| [BITSAdmin Download File](/endpoint/bitsadmin_download_file/) | [BITS Jobs](/tags/#bits-jobs), [Ingress Tool Transfer](/tags/#ingress-tool-transfer)| TTP | -| [CertUtil Download With URLCache and Split Arguments](/endpoint/certutil_download_with_urlcache_and_split_arguments/) | [Ingress Tool Transfer](/tags/#ingress-tool-transfer)| TTP | -| [CertUtil Download With VerifyCtl and Split Arguments](/endpoint/certutil_download_with_verifyctl_and_split_arguments/) | [Ingress Tool Transfer](/tags/#ingress-tool-transfer)| TTP | -| [Curl Download and Bash Execution](/endpoint/curl_download_and_bash_execution/) | [Ingress Tool Transfer](/tags/#ingress-tool-transfer)| TTP | -| [Wget Download and Bash Execution](/endpoint/wget_download_and_bash_execution/) | [Ingress Tool Transfer](/tags/#ingress-tool-transfer)| TTP | -| [Windows Curl Download to Suspicious Path](/endpoint/windows_curl_download_to_suspicious_path/) | [Ingress Tool Transfer](/tags/#ingress-tool-transfer)| TTP | -| [Windows Curl Upload to Remote Destination](/endpoint/windows_curl_upload_to_remote_destination/) | [Ingress Tool Transfer](/tags/#ingress-tool-transfer)| TTP | -| [Suspicious Curl Network Connection](/endpoint/suspicious_curl_network_connection/) | [Ingress Tool Transfer](/tags/#ingress-tool-transfer)| TTP | - -#### Reference - -* [https://attack.mitre.org/techniques/T1105/](https://attack.mitre.org/techniques/T1105/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/ingress_tool_transfer.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/insider_threat.md b/docs/_stories/insider_threat.md deleted file mode 100644 index 4ee44b4807..0000000000 --- a/docs/_stories/insider_threat.md +++ /dev/null @@ -1,54 +0,0 @@ ---- -title: "Insider Threat" -last_modified_at: 2022-05-19 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Splunk Behavioral Analytics - - Authentication - - Endpoint - - Exploitation - - Reconnaissance ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Monitor for activities and techniques associated with insider threats and specifically focusing on malicious insiders operating with in a corporate environment. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud, Splunk Behavioral Analytics -- **Datamodel**: [Authentication](https://docs.splunk.com/Documentation/CIM/latest/User/Authentication), [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-05-19 -- **Author**: Jose Hernandez, Splunk -- **ID**: c633df29-a950-4c4c-a0f8-02be6730797c - -#### Narrative - -Insider Threats are best defined by CISA: "Insider threat incidents are possible in any sector or organization. An insider threat is typically a current or former employee, third-party contractor, or business partner. In their present or former role, the person has or had access to an organization's network systems, data, or premises, and uses their access (sometimes unwittingly). To combat the insider threat, organizations can implement a proactive, prevention-focused mitigation program to detect and identify threats, assess risk, and manage that risk - before an incident occurs." An insider is any person who has or had authorized access to or knowledge of an organization's resources, including personnel, facilities, information, equipment, networks, and systems. These are the common insiders that create insider threats: Departing Employees, Security Evaders, Malicious Insiders, and Negligent Employees. This story aims at detecting the malicious insider. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Gsuite Drive Share In External Email](/cloud/gsuite_drive_share_in_external_email/) | [Exfiltration to Cloud Storage](/tags/#exfiltration-to-cloud-storage), [Exfiltration Over Web Service](/tags/#exfiltration-over-web-service)| Anomaly | -| [Gsuite Outbound Email With Attachment To External Domain](/cloud/gsuite_outbound_email_with_attachment_to_external_domain/) | [Exfiltration Over Unencrypted Non-C2 Protocol](/tags/#exfiltration-over-unencrypted-non-c2-protocol), [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol)| Anomaly | -| [High Frequency Copy Of Files In Network Share](/endpoint/high_frequency_copy_of_files_in_network_share/) | [Transfer Data to Cloud Account](/tags/#transfer-data-to-cloud-account)| Anomaly | -| [Multiple Users Failing To Authenticate From Process](/endpoint/multiple_users_failing_to_authenticate_from_process/) | [Password Spraying](/tags/#password-spraying), [Brute Force](/tags/#brute-force)| Anomaly | -| [Potential password in username](/endpoint/potential_password_in_username/) | [Local Accounts](/tags/#local-accounts), [Credentials In Files](/tags/#credentials-in-files)| Hunting | -| [Windows Users Authenticate Using Explicit Credentials](/endpoint/windows_users_authenticate_using_explicit_credentials/) | [Password Spraying](/tags/#password-spraying), [Brute Force](/tags/#brute-force)| Anomaly | - -#### Reference - -* [https://www.imperva.com/learn/application-security/insider-threats/](https://www.imperva.com/learn/application-security/insider-threats/) -* [https://www.cisa.gov/defining-insider-threats](https://www.cisa.gov/defining-insider-threats) -* [https://www.code42.com/glossary/types-of-insider-threats/](https://www.code42.com/glossary/types-of-insider-threats/) -* [https://github.com/Insider-Threat/Insider-Threat](https://github.com/Insider-Threat/Insider-Threat) -* [https://ctid.mitre-engenuity.org/our-work/insider-ttp-kb/](https://ctid.mitre-engenuity.org/our-work/insider-ttp-kb/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/insider_threat.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/jboss_vulnerability.md b/docs/_stories/jboss_vulnerability.md deleted file mode 100644 index 5236cd6e6d..0000000000 --- a/docs/_stories/jboss_vulnerability.md +++ /dev/null @@ -1,58 +0,0 @@ ---- -title: "JBoss Vulnerability" -last_modified_at: 2017-09-14 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Web - - Delivery - - Reconnaissance ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -In March of 2016, adversaries were seen using JexBoss--an open-source utility used for testing and exploiting JBoss application servers. These searches help detect evidence of these attacks, such as network connections to external resources or web services spawning atypical child processes, among others. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Web](https://docs.splunk.com/Documentation/CIM/latest/User/Web) -- **Last Updated**: 2017-09-14 -- **Author**: Bhavin Patel, Splunk -- **ID**: 1f5294cb-b85f-4c2d-9c58-ffcf248f52bd - -#### Narrative - -This Analytic Story looks for probing and exploitation attempts targeting JBoss application servers. While the vulnerabilities associated with this story are rather dated, they were leveraged in a spring 2016 campaign in connection with the Samsam ransomware variant. Incidents involving this ransomware are unique, in that they begin with attacks against vulnerable services, rather than the phishing or drive-by attacks more common with ransomware. In this case, vulnerable JBoss applications appear to be the target of choice.\ -It is helpful to understand how often a notable event generated by this story occurs, as well as the commonalities between some of these events, both of which may provide clues about whether this is a common occurrence of minimal concern or a rare event that may require more extensive investigation. It may also help to understand whether the issue is restricted to a single user/system or whether it is broader in scope.\ -When looking at the target of the behavior uncovered by the event, you should note the sensitivity of the user and or/system to help determine the potential impact. It is also helpful to identify other recent events involving the target. This can help tie different events together and give further situational awareness regarding the target host.\ -Various types of information for external systems should be reviewed and, potentially, collected if the incident is, indeed, judged to be malicious. This data may be useful for generating your own threat intelligence, so you can create future alerts.\ -The following factors may assist you in determining whether the event is malicious: \ -1. Country of origin\ -1. Responsible party\ -1. Fully qualified domain names associated with the external IP address\ -1. Registration of fully qualified domain names associated with external IP address Determining whether it is a dynamic domain frequently visited by others and/or how third parties categorize it can also help you qualify and understand the event and possible motivation for the attack. In addition, there are various sources that may provide reputation information on the IP address or domain name, which can assist you in determining whether the event is malicious in nature. Finally, determining whether there are other events associated with the IP address may help connect data points or expose other historic events that might be brought back into scope.\ -Gathering various data on the system of interest can sometimes help quickly determine whether something suspicious is happening. Some of these items include determining who else may have logged into the system recently, whether any unusual scheduled tasks exist, whether the system is communicating on suspicious ports, whether there are modifications to sensitive registry keys, and/or whether there are any known vulnerabilities on the system. This information can often highlight other activity commonly seen in attack scenarios or give more information about how the system may have been targeted.\ -hen a specific service or application is targeted, it is often helpful to know the associated version, to help determine whether it is vulnerable to a specific exploit.\ -If you suspect an attack targeting a web server, it is helpful to look at some of the behavior of the web service to see if there is evidence that the service has been compromised. Some indications of this might be network connections to external resources, the web service spawning child processes that are not associated with typical behavior, and whether the service wrote any files that might be malicious in nature.\ -If a suspicious file is found, we can review more information about it to help determine if it is, in fact, malicious. Identifying the file type, any processes that opened the file, the processes that may have created and/or modified the file, and how many other systems potentially have this file can you determine whether the file is malicious. Also, determining the file hash and checking it against reputation sources, such as VirusTotal, can sometimes help you quickly determine if it is malicious in nature.\ -Often, a simple inspection of a suspect process name and path can tell you if the system has been compromised. For example, if svchost.exe is found running from a location other than `C:\Windows\System32`, it is likely something malicious designed to hide in plain sight when simply reviewing process names. \ -It can also be helpful to examine various behaviors of and the parent of the process of interest. For example, if it turns out the process of interest is malicious, it would be good to see whether the parent process spawned other processes that might also warrant further scrutiny. If a process is suspect, a review of the network connections made around the time of the event and noting whether the process has spawned any child processes could be helpful in determining whether it is malicious or executing a malicious script. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Detect attackers scanning for vulnerable JBoss servers](/web/detect_attackers_scanning_for_vulnerable_jboss_servers/) | [System Information Discovery](/tags/#system-information-discovery)| TTP | -| [Detect malicious requests to exploit JBoss servers](/web/detect_malicious_requests_to_exploit_jboss_servers/) | None| TTP | - -#### Reference - -* [http://www.deependresearch.org/2016/04/jboss-exploits-view-from-victim.html](http://www.deependresearch.org/2016/04/jboss-exploits-view-from-victim.html) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/jboss_vulnerability.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/kubernetes_scanning_activity.md b/docs/_stories/kubernetes_scanning_activity.md deleted file mode 100644 index b97382498d..0000000000 --- a/docs/_stories/kubernetes_scanning_activity.md +++ /dev/null @@ -1,46 +0,0 @@ ---- -title: "Kubernetes Scanning Activity" -last_modified_at: 2020-04-15 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Reconnaissance ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This story addresses detection against Kubernetes cluster fingerprint scan and attack by providing information on items such as source ip, user agent, cluster names. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: -- **Last Updated**: 2020-04-15 -- **Author**: Rod Soto, Splunk -- **ID**: a9ef59cf-e981-4e66-9eef-bb049f695c09 - -#### Narrative - -Kubernetes is the most used container orchestration platform, this orchestration platform contains sensitve information and management priviledges of production workloads, microservices and applications. These searches allow operator to detect suspicious unauthenticated requests from the internet to kubernetes cluster. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [GCP Kubernetes cluster scan detection](/deprecated/gcp_kubernetes_cluster_scan_detection/) | [Cloud Service Discovery](/tags/#cloud-service-discovery)| TTP | -| [Kubernetes Azure pod scan fingerprint](/deprecated/kubernetes_azure_pod_scan_fingerprint/) | None| Hunting | -| [Kubernetes Azure scan fingerprint](/deprecated/kubernetes_azure_scan_fingerprint/) | [Cloud Service Discovery](/tags/#cloud-service-discovery)| Hunting | -| [Amazon EKS Kubernetes cluster scan detection](/cloud/amazon_eks_kubernetes_cluster_scan_detection/) | [Cloud Service Discovery](/tags/#cloud-service-discovery)| Hunting | -| [Amazon EKS Kubernetes Pod scan detection](/cloud/amazon_eks_kubernetes_pod_scan_detection/) | [Cloud Service Discovery](/tags/#cloud-service-discovery)| Hunting | -| [GCP Kubernetes cluster pod scan detection](/cloud/gcp_kubernetes_cluster_pod_scan_detection/) | [Cloud Service Discovery](/tags/#cloud-service-discovery)| Hunting | - -#### Reference - -* [https://github.com/splunk/cloud-datamodel-security-research](https://github.com/splunk/cloud-datamodel-security-research) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/kubernetes_scanning_activity.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/kubernetes_sensitive_object_access_activity.md b/docs/_stories/kubernetes_sensitive_object_access_activity.md deleted file mode 100644 index 6db4713f72..0000000000 --- a/docs/_stories/kubernetes_sensitive_object_access_activity.md +++ /dev/null @@ -1,49 +0,0 @@ ---- -title: "Kubernetes Sensitive Object Access Activity" -last_modified_at: 2020-05-20 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This story addresses detection and response of accounts acccesing Kubernetes cluster sensitive objects such as configmaps or secrets providing information on items such as user user, group. object, namespace and authorization reason. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: -- **Last Updated**: 2020-05-20 -- **Author**: Rod Soto, Splunk -- **ID**: c7d4dbf0-a171-4eaf-8444-4f40392e4f92 - -#### Narrative - -Kubernetes is the most used container orchestration platform, this orchestration platform contains sensitive objects within its architecture, specifically configmaps and secrets, if accessed by an attacker can lead to further compromise. These searches allow operator to detect suspicious requests against Kubernetes sensitive objects. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [AWS EKS Kubernetes cluster sensitive object access](/deprecated/aws_eks_kubernetes_cluster_sensitive_object_access/) | None| Hunting | -| [Kubernetes AWS detect service accounts forbidden failure access](/deprecated/kubernetes_aws_detect_service_accounts_forbidden_failure_access/) | None| Hunting | -| [Kubernetes Azure detect sensitive object access](/deprecated/kubernetes_azure_detect_sensitive_object_access/) | None| Hunting | -| [Kubernetes Azure detect service accounts forbidden failure access](/deprecated/kubernetes_azure_detect_service_accounts_forbidden_failure_access/) | None| Hunting | -| [Kubernetes Azure detect suspicious kubectl calls](/deprecated/kubernetes_azure_detect_suspicious_kubectl_calls/) | None| Hunting | -| [Kubernetes GCP detect sensitive object access](/deprecated/kubernetes_gcp_detect_sensitive_object_access/) | None| Hunting | -| [Kubernetes GCP detect service accounts forbidden failure access](/deprecated/kubernetes_gcp_detect_service_accounts_forbidden_failure_access/) | None| Hunting | -| [Kubernetes GCP detect suspicious kubectl calls](/deprecated/kubernetes_gcp_detect_suspicious_kubectl_calls/) | None| Hunting | -| [Kubernetes AWS detect suspicious kubectl calls](/cloud/kubernetes_aws_detect_suspicious_kubectl_calls/) | None| Hunting | - -#### Reference - -* [https://www.splunk.com/en_us/blog/security/approaching-kubernetes-security-detecting-kubernetes-scan-with-splunk.html](https://www.splunk.com/en_us/blog/security/approaching-kubernetes-security-detecting-kubernetes-scan-with-splunk.html) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/kubernetes_sensitive_object_access_activity.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/kubernetes_sensitive_role_activity.md b/docs/_stories/kubernetes_sensitive_role_activity.md deleted file mode 100644 index 9547787aff..0000000000 --- a/docs/_stories/kubernetes_sensitive_role_activity.md +++ /dev/null @@ -1,49 +0,0 @@ ---- -title: "Kubernetes Sensitive Role Activity" -last_modified_at: 2020-05-20 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This story addresses detection and response around Sensitive Role usage within a Kubernetes clusters against cluster resources and namespaces. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: -- **Last Updated**: 2020-05-20 -- **Author**: Rod Soto, Splunk -- **ID**: 8b3984d2-17b6-47e9-ba43-a3376e70fdcc - -#### Narrative - -Kubernetes is the most used container orchestration platform, this orchestration platform contains sensitive roles within its architecture, specifically configmaps and secrets, if accessed by an attacker can lead to further compromise. These searches allow operator to detect suspicious requests against Kubernetes role activities - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Kubernetes AWS detect most active service accounts by pod](/deprecated/kubernetes_aws_detect_most_active_service_accounts_by_pod/) | None| Hunting | -| [Kubernetes AWS detect RBAC authorization by account](/deprecated/kubernetes_aws_detect_rbac_authorization_by_account/) | None| Hunting | -| [Kubernetes AWS detect sensitive role access](/deprecated/kubernetes_aws_detect_sensitive_role_access/) | None| Hunting | -| [Kubernetes Azure active service accounts by pod namespace](/deprecated/kubernetes_azure_active_service_accounts_by_pod_namespace/) | None| Hunting | -| [Kubernetes Azure detect RBAC authorization by account](/deprecated/kubernetes_azure_detect_rbac_authorization_by_account/) | None| Hunting | -| [Kubernetes Azure detect sensitive role access](/deprecated/kubernetes_azure_detect_sensitive_role_access/) | None| Hunting | -| [Kubernetes GCP detect RBAC authorizations by account](/deprecated/kubernetes_gcp_detect_rbac_authorizations_by_account/) | None| Hunting | -| [Kubernetes GCP detect most active service accounts by pod](/deprecated/kubernetes_gcp_detect_most_active_service_accounts_by_pod/) | None| Hunting | -| [Kubernetes GCP detect sensitive role access](/deprecated/kubernetes_gcp_detect_sensitive_role_access/) | None| Hunting | - -#### Reference - -* [https://www.splunk.com/en_us/blog/security/approaching-kubernetes-security-detecting-kubernetes-scan-with-splunk.html](https://www.splunk.com/en_us/blog/security/approaching-kubernetes-security-detecting-kubernetes-scan-with-splunk.html) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/kubernetes_sensitive_role_activity.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/lateral_movement.md b/docs/_stories/lateral_movement.md deleted file mode 100644 index 0dfa81f91f..0000000000 --- a/docs/_stories/lateral_movement.md +++ /dev/null @@ -1,78 +0,0 @@ ---- -title: "Lateral Movement" -last_modified_at: 2021-11-23 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Authentication - - Endpoint - - Network_Traffic ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Detect and investigate tactics, techniques, and procedures around how attackers move laterally within the enterprise. Because lateral movement can expose the adversary to detection, it should be an important focus for security analysts. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Authentication](https://docs.splunk.com/Documentation/CIM/latest/User/Authentication), [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint), [Network_Traffic](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkTraffic) -- **Last Updated**: 2021-11-23 -- **Author**: David Dorsey, Mauricio Velazco Splunk -- **ID**: 399d65dc-1f08-499b-a259-aad9051f38ad - -#### Narrative - -Once attackers gain a foothold within an enterprise, they will seek to expand their accesses and leverage techniques that facilitate lateral movement. Attackers will often spend quite a bit of time and effort moving laterally. Because lateral movement renders an attacker the most vulnerable to detection, it's an excellent focus for detection and investigation.\ -Indications of lateral movement can include the abuse of system utilities (such as `psexec.exe`), unauthorized use of remote desktop services, `file/admin$` shares, WMI, PowerShell, pass-the-hash, or the abuse of scheduled tasks. Organizations must be extra vigilant in detecting lateral movement techniques and look for suspicious activity in and around high-value strategic network assets, such as Active Directory, which are often considered the primary target or "crown jewels" to a persistent threat actor.\ -An adversary can use lateral movement for multiple purposes, including remote execution of tools, pivoting to additional systems, obtaining access to specific information or files, access to additional credentials, exfiltrating data, or delivering a secondary effect. Adversaries may use legitimate credentials alongside inherent network and operating-system functionality to remotely connect to other systems and remain under the radar of network defenders.\ -If there is evidence of lateral movement, it is imperative for analysts to collect evidence of the associated offending hosts. For example, an attacker might leverage host A to gain access to host B. From there, the attacker may try to move laterally to host C. In this example, the analyst should gather as much information as possible from all three hosts. \ - It is also important to collect authentication logs for each host, to ensure that the offending accounts are well-documented. Analysts should account for all processes to ensure that the attackers did not install unauthorized software. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Detect Activity Related to Pass the Hash Attacks](/endpoint/detect_activity_related_to_pass_the_hash_attacks/) | [Use Alternate Authentication Material](/tags/#use-alternate-authentication-material), [Pass the Hash](/tags/#pass-the-hash) | TTP | -| [Detect PsExec With accepteula Flag](/endpoint/detect_psexec_with_accepteula_flag/) | [Remote Services](/tags/#remote-services), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares) | TTP | -| [Detect Renamed PSExec](/endpoint/detect_renamed_psexec/) | [System Services](/tags/#system-services), [Service Execution](/tags/#service-execution) | Hunting | -| [Executable File Written in Administrative SMB Share](/endpoint/executable_file_written_in_administrative_smb_share/) | [Remote Services](/tags/#remote-services), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares) | TTP | -| [Impacket Lateral Movement Commandline Parameters](/endpoint/impacket_lateral_movement_commandline_parameters/) | [Remote Services](/tags/#remote-services), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares), [Distributed Component Object Model](/tags/#distributed-component-object-model), [Windows Management Instrumentation](/tags/#windows-management-instrumentation), [Windows Service](/tags/#windows-service) | TTP | -| [Interactive Session on Remote Endpoint with PowerShell](/endpoint/interactive_session_on_remote_endpoint_with_powershell/) | [Remote Services](/tags/#remote-services), [Windows Remote Management](/tags/#windows-remote-management) | TTP | -| [Mmc LOLBAS Execution Process Spawn](/endpoint/mmc_lolbas_execution_process_spawn/) | [Remote Services](/tags/#remote-services), [Distributed Component Object Model](/tags/#distributed-component-object-model) | TTP | -| [Potential Pass the Token or Hash Observed at the Destination Device](/endpoint/potential_pass_the_token_or_hash_observed_at_the_destination_device/) | [Use Alternate Authentication Material](/tags/#use-alternate-authentication-material), [Pass the Hash](/tags/#pass-the-hash) | TTP | -| [Potential Pass the Token or Hash Observed by an Event Collecting Device](/endpoint/potential_pass_the_token_or_hash_observed_by_an_event_collecting_device/) | [Use Alternate Authentication Material](/tags/#use-alternate-authentication-material), [Pass the Hash](/tags/#pass-the-hash) | TTP | -| [Remote Desktop Network Traffic](/network/remote_desktop_network_traffic/) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol), [Remote Services](/tags/#remote-services) | Anomaly | -| [Remote Desktop Process Running On System](/endpoint/remote_desktop_process_running_on_system/) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol), [Remote Services](/tags/#remote-services) | Hunting | -| [Remote Process Instantiation via DCOM and PowerShell](/endpoint/remote_process_instantiation_via_dcom_and_powershell/) | [Remote Services](/tags/#remote-services), [Distributed Component Object Model](/tags/#distributed-component-object-model) | TTP | -| [Remote Process Instantiation via DCOM and PowerShell Script Block](/endpoint/remote_process_instantiation_via_dcom_and_powershell_script_block/) | [Remote Services](/tags/#remote-services), [Distributed Component Object Model](/tags/#distributed-component-object-model) | TTP | -| [Remote Process Instantiation via WMI](/endpoint/remote_process_instantiation_via_wmi/) | [Windows Management Instrumentation](/tags/#windows-management-instrumentation) | TTP | -| [Remote Process Instantiation via WMI and PowerShell](/endpoint/remote_process_instantiation_via_wmi_and_powershell/) | [Windows Management Instrumentation](/tags/#windows-management-instrumentation) | TTP | -| [Remote Process Instantiation via WMI and PowerShell Script Block](/endpoint/remote_process_instantiation_via_wmi_and_powershell_script_block/) | [Windows Management Instrumentation](/tags/#windows-management-instrumentation) | TTP | -| [Remote Process Instantiation via WinRM and PowerShell](/endpoint/remote_process_instantiation_via_winrm_and_powershell/) | [Remote Services](/tags/#remote-services), [Windows Remote Management](/tags/#windows-remote-management) | TTP | -| [Remote Process Instantiation via WinRM and PowerShell Script Block](/endpoint/remote_process_instantiation_via_winrm_and_powershell_script_block/) | [Remote Services](/tags/#remote-services), [Windows Remote Management](/tags/#windows-remote-management) | TTP | -| [Remote Process Instantiation via WinRM and Winrs](/endpoint/remote_process_instantiation_via_winrm_and_winrs/) | [Remote Services](/tags/#remote-services), [Windows Remote Management](/tags/#windows-remote-management) | TTP | -| [Scheduled Task Creation on Remote Endpoint using At](/endpoint/scheduled_task_creation_on_remote_endpoint_using_at/) | [Scheduled Task/Job](/tags/#scheduled-task/job), [At (Windows)](/tags/#at-(windows)) | TTP | -| [Scheduled Task Initiation on Remote Endpoint](/endpoint/scheduled_task_initiation_on_remote_endpoint/) | [Scheduled Task/Job](/tags/#scheduled-task/job), [Scheduled Task](/tags/#scheduled-task) | TTP | -| [Schtasks scheduling job on remote system](/endpoint/schtasks_scheduling_job_on_remote_system/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job) | TTP | -| [Services LOLBAS Execution Process Spawn](/endpoint/services_lolbas_execution_process_spawn/) | [Create or Modify System Process](/tags/#create-or-modify-system-process), [Windows Service](/tags/#windows-service) | TTP | -| [Svchost LOLBAS Execution Process Spawn](/endpoint/svchost_lolbas_execution_process_spawn/) | [Scheduled Task/Job](/tags/#scheduled-task/job), [Scheduled Task](/tags/#scheduled-task) | TTP | -| [WinEvent Scheduled Task Created Within Public Path](/endpoint/winevent_scheduled_task_created_within_public_path/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job) | TTP | -| [Windows Service Created With Suspicious Service Path](/endpoint/windows_service_created_with_suspicious_service_path/) | [System Services](/tags/#system-services), [Service Execution](/tags/#service-execution) | TTP | -| [Windows Service Created Within Public Path](/endpoint/windows_service_created_within_public_path/) | [Create or Modify System Process](/tags/#create-or-modify-system-process), [Windows Service](/tags/#windows-service) | TTP | -| [Windows Service Creation on Remote Endpoint](/endpoint/windows_service_creation_on_remote_endpoint/) | [Create or Modify System Process](/tags/#create-or-modify-system-process), [Windows Service](/tags/#windows-service) | TTP | -| [Windows Service Initiation on Remote Endpoint](/endpoint/windows_service_initiation_on_remote_endpoint/) | [Create or Modify System Process](/tags/#create-or-modify-system-process), [Windows Service](/tags/#windows-service) | TTP | -| [Wmiprsve LOLBAS Execution Process Spawn](/endpoint/wmiprsve_lolbas_execution_process_spawn/) | [Windows Management Instrumentation](/tags/#windows-management-instrumentation) | TTP | -| [Wsmprovhost LOLBAS Execution Process Spawn](/endpoint/wsmprovhost_lolbas_execution_process_spawn/) | [Remote Services](/tags/#remote-services), [Windows Remote Management](/tags/#windows-remote-management) | TTP | - -#### Reference - -* [https://www.fireeye.com/blog/executive-perspective/2015/08/malware_lateral_move.html](https://www.fireeye.com/blog/executive-perspective/2015/08/malware_lateral_move.html) -* [https://www.youtube.com/watch?v=hVTkkkM9XDg](https://www.youtube.com/watch?v=hVTkkkM9XDg) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/lateral_movement.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_stories/linux_living_off_the_land.md b/docs/_stories/linux_living_off_the_land.md deleted file mode 100644 index 50e0cac11d..0000000000 --- a/docs/_stories/linux_living_off_the_land.md +++ /dev/null @@ -1,68 +0,0 @@ ---- -title: "Linux Living Off The Land" -last_modified_at: 2022-07-27 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Actions on Objectives - - Delivery - - Exploitation - - Installation - - Reconnaissance ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Linux Living Off The Land consists of binaries that may be used to bypass local security restrictions within misconfigured systems. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-07-27 -- **Author**: Michael Haag, Splunk -- **ID**: e405a2d7-dc8e-4227-8e9d-f60267b8c0cd - -#### Narrative - -Similar to Windows LOLBAS project, the GTFOBins project focuses solely on Unix binaries that may be abused in multiple categories including Reverse Shell, File Upload, File Download and much more. These binaries are native to the operating system and the functionality is typically native. The behaviors are typically not malicious by default or vulnerable, but these are built in functionality of the applications. When reviewing any notables or hunting through mountains of events of interest, it's important to identify the binary, review command-line arguments, path of file, and capture any network and file modifications. Linux analysis may be a bit cumbersome due to volume and how process behavior is seen in EDR products. Piecing it together will require some effort. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Curl Download and Bash Execution](/endpoint/curl_download_and_bash_execution/) | [Ingress Tool Transfer](/tags/#ingress-tool-transfer)| TTP | -| [Linux Add Files In Known Crontab Directories](/endpoint/linux_add_files_in_known_crontab_directories/) | [Cron](/tags/#cron), [Scheduled Task/Job](/tags/#scheduled-task/job)| Anomaly | -| [Linux Adding Crontab Using List Parameter](/endpoint/linux_adding_crontab_using_list_parameter/) | [Cron](/tags/#cron), [Scheduled Task/Job](/tags/#scheduled-task/job)| Hunting | -| [Linux At Allow Config File Creation](/endpoint/linux_at_allow_config_file_creation/) | [Cron](/tags/#cron), [Scheduled Task/Job](/tags/#scheduled-task/job)| Anomaly | -| [Linux At Application Execution](/endpoint/linux_at_application_execution/) | [At](/tags/#at), [Scheduled Task/Job](/tags/#scheduled-task/job)| Anomaly | -| [Linux Change File Owner To Root](/endpoint/linux_change_file_owner_to_root/) | [Linux and Mac File and Directory Permissions Modification](/tags/#linux-and-mac-file-and-directory-permissions-modification), [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification)| Anomaly | -| [Linux Clipboard Data Copy](/endpoint/linux_clipboard_data_copy/) | [Clipboard Data](/tags/#clipboard-data)| Anomaly | -| [Linux Common Process For Elevation Control](/endpoint/linux_common_process_for_elevation_control/) | [Setuid and Setgid](/tags/#setuid-and-setgid), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism)| Hunting | -| [Linux Decode Base64 to Shell](/endpoint/linux_decode_base64_to_shell/) | [Obfuscated Files or Information](/tags/#obfuscated-files-or-information), [Unix Shell](/tags/#unix-shell)| TTP | -| [Linux Edit Cron Table Parameter](/endpoint/linux_edit_cron_table_parameter/) | [Cron](/tags/#cron), [Scheduled Task/Job](/tags/#scheduled-task/job)| Hunting | -| [Linux Obfuscated Files or Information Base64 Decode](/endpoint/linux_obfuscated_files_or_information_base64_decode/) | [Obfuscated Files or Information](/tags/#obfuscated-files-or-information)| Anomaly | -| [Linux pkexec Privilege Escalation](/endpoint/linux_pkexec_privilege_escalation/) | [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation)| TTP | -| [Linux Possible Access Or Modification Of sshd Config File](/endpoint/linux_possible_access_or_modification_of_sshd_config_file/) | [SSH Authorized Keys](/tags/#ssh-authorized-keys), [Account Manipulation](/tags/#account-manipulation)| Anomaly | -| [Linux Possible Append Cronjob Entry on Existing Cronjob File](/endpoint/linux_possible_append_cronjob_entry_on_existing_cronjob_file/) | [Cron](/tags/#cron), [Scheduled Task/Job](/tags/#scheduled-task/job)| Hunting | -| [Linux Possible Cronjob Modification With Editor](/endpoint/linux_possible_cronjob_modification_with_editor/) | [Cron](/tags/#cron), [Scheduled Task/Job](/tags/#scheduled-task/job)| Hunting | -| [Linux Possible Ssh Key File Creation](/endpoint/linux_possible_ssh_key_file_creation/) | [SSH Authorized Keys](/tags/#ssh-authorized-keys), [Account Manipulation](/tags/#account-manipulation)| Anomaly | -| [Linux Service File Created In Systemd Directory](/endpoint/linux_service_file_created_in_systemd_directory/) | [Systemd Timers](/tags/#systemd-timers), [Scheduled Task/Job](/tags/#scheduled-task/job)| Anomaly | -| [Linux Service Restarted](/endpoint/linux_service_restarted/) | [Systemd Timers](/tags/#systemd-timers), [Scheduled Task/Job](/tags/#scheduled-task/job)| Anomaly | -| [Linux Service Started Or Enabled](/endpoint/linux_service_started_or_enabled/) | [Systemd Timers](/tags/#systemd-timers), [Scheduled Task/Job](/tags/#scheduled-task/job)| Anomaly | -| [Linux Setuid Using Chmod Utility](/endpoint/linux_setuid_using_chmod_utility/) | [Setuid and Setgid](/tags/#setuid-and-setgid), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism)| Anomaly | -| [Linux SSH Authorized Keys Modification](/endpoint/linux_ssh_authorized_keys_modification/) | [SSH Authorized Keys](/tags/#ssh-authorized-keys)| Anomaly | -| [Linux SSH Remote Services Script Execute](/endpoint/linux_ssh_remote_services_script_execute/) | [SSH](/tags/#ssh)| TTP | -| [Suspicious Curl Network Connection](/endpoint/suspicious_curl_network_connection/) | [Ingress Tool Transfer](/tags/#ingress-tool-transfer)| TTP | - -#### Reference - -* [https://gtfobins.github.io/](https://gtfobins.github.io/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/linux_living_off_the_land.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/linux_persistence_techniques.md b/docs/_stories/linux_persistence_techniques.md deleted file mode 100644 index 3b8a17f7cb..0000000000 --- a/docs/_stories/linux_persistence_techniques.md +++ /dev/null @@ -1,80 +0,0 @@ ---- -title: "Linux Persistence Techniques" -last_modified_at: 2021-12-17 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Risk - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Monitor for activities and techniques associated with maintaining persistence on a Linux system--a sign that an adversary may have compromised your environment. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint), [Risk](https://docs.splunk.com/Documentation/CIM/latest/User/Risk) -- **Last Updated**: 2021-12-17 -- **Author**: Teoderick Contreras, Splunk -- **ID**: e40d13e5-d38b-457e-af2a-e8e6a2f2b516 - -#### Narrative - -Maintaining persistence is one of the first steps taken by attackers after the initial compromise. Attackers leverage various custom and built-in tools to ensure survivability and persistent access within a compromised enterprise. This Analytic Story provides searches to help you identify various behaviors used by attackers to maintain persistent access to a Linux environment. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Linux Add Files In Known Crontab Directories](/endpoint/linux_add_files_in_known_crontab_directories/) | [Cron](/tags/#cron), [Scheduled Task/Job](/tags/#scheduled-task/job)| Anomaly | -| [Linux Add User Account](/endpoint/linux_add_user_account/) | [Local Account](/tags/#local-account), [Create Account](/tags/#create-account)| Hunting | -| [Linux Adding Crontab Using List Parameter](/endpoint/linux_adding_crontab_using_list_parameter/) | [Cron](/tags/#cron), [Scheduled Task/Job](/tags/#scheduled-task/job)| Hunting | -| [Linux At Allow Config File Creation](/endpoint/linux_at_allow_config_file_creation/) | [Cron](/tags/#cron), [Scheduled Task/Job](/tags/#scheduled-task/job)| Anomaly | -| [Linux At Application Execution](/endpoint/linux_at_application_execution/) | [At](/tags/#at), [Scheduled Task/Job](/tags/#scheduled-task/job)| Anomaly | -| [Linux Change File Owner To Root](/endpoint/linux_change_file_owner_to_root/) | [Linux and Mac File and Directory Permissions Modification](/tags/#linux-and-mac-file-and-directory-permissions-modification), [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification)| Anomaly | -| [Linux Common Process For Elevation Control](/endpoint/linux_common_process_for_elevation_control/) | [Setuid and Setgid](/tags/#setuid-and-setgid), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism)| Hunting | -| [Linux Doas Conf File Creation](/endpoint/linux_doas_conf_file_creation/) | [Sudo and Sudo Caching](/tags/#sudo-and-sudo-caching), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism)| Anomaly | -| [Linux Doas Tool Execution](/endpoint/linux_doas_tool_execution/) | [Sudo and Sudo Caching](/tags/#sudo-and-sudo-caching), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism)| Anomaly | -| [Linux Edit Cron Table Parameter](/endpoint/linux_edit_cron_table_parameter/) | [Cron](/tags/#cron), [Scheduled Task/Job](/tags/#scheduled-task/job)| Hunting | -| [Linux File Created In Kernel Driver Directory](/endpoint/linux_file_created_in_kernel_driver_directory/) | [Kernel Modules and Extensions](/tags/#kernel-modules-and-extensions), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution)| Anomaly | -| [Linux File Creation In Init Boot Directory](/endpoint/linux_file_creation_in_init_boot_directory/) | [RC Scripts](/tags/#rc-scripts), [Boot or Logon Initialization Scripts](/tags/#boot-or-logon-initialization-scripts)| Anomaly | -| [Linux File Creation In Profile Directory](/endpoint/linux_file_creation_in_profile_directory/) | [Unix Shell Configuration Modification](/tags/#unix-shell-configuration-modification), [Event Triggered Execution](/tags/#event-triggered-execution)| Anomaly | -| [Linux Insert Kernel Module Using Insmod Utility](/endpoint/linux_insert_kernel_module_using_insmod_utility/) | [Kernel Modules and Extensions](/tags/#kernel-modules-and-extensions), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution)| Anomaly | -| [Linux Install Kernel Module Using Modprobe Utility](/endpoint/linux_install_kernel_module_using_modprobe_utility/) | [Kernel Modules and Extensions](/tags/#kernel-modules-and-extensions), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution)| Anomaly | -| [Linux NOPASSWD Entry In Sudoers File](/endpoint/linux_nopasswd_entry_in_sudoers_file/) | [Sudo and Sudo Caching](/tags/#sudo-and-sudo-caching), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism)| Anomaly | -| [Linux Persistence and Privilege Escalation Risk Behavior](/endpoint/linux_persistence_and_privilege_escalation_risk_behavior/) | [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism)| Correlation | -| [Linux Possible Access Or Modification Of sshd Config File](/endpoint/linux_possible_access_or_modification_of_sshd_config_file/) | [SSH Authorized Keys](/tags/#ssh-authorized-keys), [Account Manipulation](/tags/#account-manipulation)| Anomaly | -| [Linux Possible Access To Credential Files](/endpoint/linux_possible_access_to_credential_files/) | [/etc/passwd and /etc/shadow](/tags/#/etc/passwd-and-/etc/shadow), [OS Credential Dumping](/tags/#os-credential-dumping)| Anomaly | -| [Linux Possible Access To Sudoers File](/endpoint/linux_possible_access_to_sudoers_file/) | [Sudo and Sudo Caching](/tags/#sudo-and-sudo-caching), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism)| Anomaly | -| [Linux Possible Append Command To At Allow Config File](/endpoint/linux_possible_append_command_to_at_allow_config_file/) | [At](/tags/#at), [Scheduled Task/Job](/tags/#scheduled-task/job)| Anomaly | -| [Linux Possible Append Command To Profile Config File](/endpoint/linux_possible_append_command_to_profile_config_file/) | [Unix Shell Configuration Modification](/tags/#unix-shell-configuration-modification), [Event Triggered Execution](/tags/#event-triggered-execution)| Anomaly | -| [Linux Possible Append Cronjob Entry on Existing Cronjob File](/endpoint/linux_possible_append_cronjob_entry_on_existing_cronjob_file/) | [Cron](/tags/#cron), [Scheduled Task/Job](/tags/#scheduled-task/job)| Hunting | -| [Linux Possible Cronjob Modification With Editor](/endpoint/linux_possible_cronjob_modification_with_editor/) | [Cron](/tags/#cron), [Scheduled Task/Job](/tags/#scheduled-task/job)| Hunting | -| [Linux Possible Ssh Key File Creation](/endpoint/linux_possible_ssh_key_file_creation/) | [SSH Authorized Keys](/tags/#ssh-authorized-keys), [Account Manipulation](/tags/#account-manipulation)| Anomaly | -| [Linux Preload Hijack Library Calls](/endpoint/linux_preload_hijack_library_calls/) | [Dynamic Linker Hijacking](/tags/#dynamic-linker-hijacking), [Hijack Execution Flow](/tags/#hijack-execution-flow)| TTP | -| [Linux Service File Created In Systemd Directory](/endpoint/linux_service_file_created_in_systemd_directory/) | [Systemd Timers](/tags/#systemd-timers), [Scheduled Task/Job](/tags/#scheduled-task/job)| Anomaly | -| [Linux Service Restarted](/endpoint/linux_service_restarted/) | [Systemd Timers](/tags/#systemd-timers), [Scheduled Task/Job](/tags/#scheduled-task/job)| Anomaly | -| [Linux Service Started Or Enabled](/endpoint/linux_service_started_or_enabled/) | [Systemd Timers](/tags/#systemd-timers), [Scheduled Task/Job](/tags/#scheduled-task/job)| Anomaly | -| [Linux Setuid Using Chmod Utility](/endpoint/linux_setuid_using_chmod_utility/) | [Setuid and Setgid](/tags/#setuid-and-setgid), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism)| Anomaly | -| [Linux Setuid Using Setcap Utility](/endpoint/linux_setuid_using_setcap_utility/) | [Setuid and Setgid](/tags/#setuid-and-setgid), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism)| Anomaly | -| [Linux Shred Overwrite Command](/endpoint/linux_shred_overwrite_command/) | [Data Destruction](/tags/#data-destruction)| TTP | -| [Linux Sudo OR Su Execution](/endpoint/linux_sudo_or_su_execution/) | [Sudo and Sudo Caching](/tags/#sudo-and-sudo-caching), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism)| Hunting | -| [Linux Sudoers Tmp File Creation](/endpoint/linux_sudoers_tmp_file_creation/) | [Sudo and Sudo Caching](/tags/#sudo-and-sudo-caching), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism)| Anomaly | -| [Linux Visudo Utility Execution](/endpoint/linux_visudo_utility_execution/) | [Sudo and Sudo Caching](/tags/#sudo-and-sudo-caching), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism)| Anomaly | - -#### Reference - -* [https://attack.mitre.org/techniques/T1053/](https://attack.mitre.org/techniques/T1053/) -* [https://kifarunix.com/scheduling-tasks-using-at-command-in-linux/](https://kifarunix.com/scheduling-tasks-using-at-command-in-linux/) -* [https://gtfobins.github.io/gtfobins/at/](https://gtfobins.github.io/gtfobins/at/) -* [https://www.cert.ssi.gouv.fr/uploads/CERTFR-2021-CTI-005.pdf](https://www.cert.ssi.gouv.fr/uploads/CERTFR-2021-CTI-005.pdf) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/linux_persistence_techniques.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/linux_post-exploitation.md b/docs/_stories/linux_post-exploitation.md deleted file mode 100644 index 1f67698e00..0000000000 --- a/docs/_stories/linux_post-exploitation.md +++ /dev/null @@ -1,42 +0,0 @@ ---- -title: "Linux Post-Exploitation" -last_modified_at: 2021-12-03 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic story identifies popular Linux post exploitation tools such as autoSUID, LinEnum, LinPEAS, Linux Exploit Suggesters, MimiPenguin. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-12-03 -- **Author**: Rod Soto -- **ID**: d310ccfe-5477-11ec-ad05-acde48001122 - -#### Narrative - -These tools allow operators find possible exploits or paths for privilege escalation based on SUID binaries, user permissions, kernel version and distro version. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Suspicious Linux Discovery Commands](/endpoint/suspicious_linux_discovery_commands/) | [Unix Shell](/tags/#unix-shell)| TTP | - -#### Reference - -* [https://attack.mitre.org/matrices/enterprise/linux/](https://attack.mitre.org/matrices/enterprise/linux/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/linux_post-exploitation.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/linux_privilege_escalation.md b/docs/_stories/linux_privilege_escalation.md deleted file mode 100644 index fdb6ca337d..0000000000 --- a/docs/_stories/linux_privilege_escalation.md +++ /dev/null @@ -1,78 +0,0 @@ ---- -title: "Linux Privilege Escalation" -last_modified_at: 2021-12-17 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Risk - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Monitor for and investigate activities that may be associated with a Linux privilege-escalation attack, including unusual processes running on endpoints, schedule task, services, setuid, root execution and more. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint), [Risk](https://docs.splunk.com/Documentation/CIM/latest/User/Risk) -- **Last Updated**: 2021-12-17 -- **Author**: Teoderick Contreras, Splunk -- **ID**: b9879c24-670a-44c0-895e-98cdb7d0e848 - -#### Narrative - -Privilege escalation is a "land-and-expand" technique, wherein an adversary gains an initial foothold on a host and then exploits its weaknesses to increase his privileges. The motivation is simple: certain actions on a Linux machine--such as installing software--may require higher-level privileges than those the attacker initially acquired. By increasing his privilege level, the attacker can gain the control required to carry out his malicious ends. This Analytic Story provides searches to detect and investigate behaviors that attackers may use to elevate their privileges in your environment. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Linux Add Files In Known Crontab Directories](/endpoint/linux_add_files_in_known_crontab_directories/) | [Cron](/tags/#cron), [Scheduled Task/Job](/tags/#scheduled-task/job)| Anomaly | -| [Linux Add User Account](/endpoint/linux_add_user_account/) | [Local Account](/tags/#local-account), [Create Account](/tags/#create-account)| Hunting | -| [Linux Adding Crontab Using List Parameter](/endpoint/linux_adding_crontab_using_list_parameter/) | [Cron](/tags/#cron), [Scheduled Task/Job](/tags/#scheduled-task/job)| Hunting | -| [Linux At Allow Config File Creation](/endpoint/linux_at_allow_config_file_creation/) | [Cron](/tags/#cron), [Scheduled Task/Job](/tags/#scheduled-task/job)| Anomaly | -| [Linux At Application Execution](/endpoint/linux_at_application_execution/) | [At](/tags/#at), [Scheduled Task/Job](/tags/#scheduled-task/job)| Anomaly | -| [Linux Change File Owner To Root](/endpoint/linux_change_file_owner_to_root/) | [Linux and Mac File and Directory Permissions Modification](/tags/#linux-and-mac-file-and-directory-permissions-modification), [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification)| Anomaly | -| [Linux Common Process For Elevation Control](/endpoint/linux_common_process_for_elevation_control/) | [Setuid and Setgid](/tags/#setuid-and-setgid), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism)| Hunting | -| [Linux Doas Conf File Creation](/endpoint/linux_doas_conf_file_creation/) | [Sudo and Sudo Caching](/tags/#sudo-and-sudo-caching), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism)| Anomaly | -| [Linux Doas Tool Execution](/endpoint/linux_doas_tool_execution/) | [Sudo and Sudo Caching](/tags/#sudo-and-sudo-caching), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism)| Anomaly | -| [Linux Edit Cron Table Parameter](/endpoint/linux_edit_cron_table_parameter/) | [Cron](/tags/#cron), [Scheduled Task/Job](/tags/#scheduled-task/job)| Hunting | -| [Linux File Created In Kernel Driver Directory](/endpoint/linux_file_created_in_kernel_driver_directory/) | [Kernel Modules and Extensions](/tags/#kernel-modules-and-extensions), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution)| Anomaly | -| [Linux File Creation In Init Boot Directory](/endpoint/linux_file_creation_in_init_boot_directory/) | [RC Scripts](/tags/#rc-scripts), [Boot or Logon Initialization Scripts](/tags/#boot-or-logon-initialization-scripts)| Anomaly | -| [Linux File Creation In Profile Directory](/endpoint/linux_file_creation_in_profile_directory/) | [Unix Shell Configuration Modification](/tags/#unix-shell-configuration-modification), [Event Triggered Execution](/tags/#event-triggered-execution)| Anomaly | -| [Linux Insert Kernel Module Using Insmod Utility](/endpoint/linux_insert_kernel_module_using_insmod_utility/) | [Kernel Modules and Extensions](/tags/#kernel-modules-and-extensions), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution)| Anomaly | -| [Linux Install Kernel Module Using Modprobe Utility](/endpoint/linux_install_kernel_module_using_modprobe_utility/) | [Kernel Modules and Extensions](/tags/#kernel-modules-and-extensions), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution)| Anomaly | -| [Linux NOPASSWD Entry In Sudoers File](/endpoint/linux_nopasswd_entry_in_sudoers_file/) | [Sudo and Sudo Caching](/tags/#sudo-and-sudo-caching), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism)| Anomaly | -| [Linux Persistence and Privilege Escalation Risk Behavior](/endpoint/linux_persistence_and_privilege_escalation_risk_behavior/) | [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism)| Correlation | -| [Linux pkexec Privilege Escalation](/endpoint/linux_pkexec_privilege_escalation/) | [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation)| TTP | -| [Linux Possible Access Or Modification Of sshd Config File](/endpoint/linux_possible_access_or_modification_of_sshd_config_file/) | [SSH Authorized Keys](/tags/#ssh-authorized-keys), [Account Manipulation](/tags/#account-manipulation)| Anomaly | -| [Linux Possible Access To Credential Files](/endpoint/linux_possible_access_to_credential_files/) | [/etc/passwd and /etc/shadow](/tags/#/etc/passwd-and-/etc/shadow), [OS Credential Dumping](/tags/#os-credential-dumping)| Anomaly | -| [Linux Possible Access To Sudoers File](/endpoint/linux_possible_access_to_sudoers_file/) | [Sudo and Sudo Caching](/tags/#sudo-and-sudo-caching), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism)| Anomaly | -| [Linux Possible Append Command To At Allow Config File](/endpoint/linux_possible_append_command_to_at_allow_config_file/) | [At](/tags/#at), [Scheduled Task/Job](/tags/#scheduled-task/job)| Anomaly | -| [Linux Possible Append Command To Profile Config File](/endpoint/linux_possible_append_command_to_profile_config_file/) | [Unix Shell Configuration Modification](/tags/#unix-shell-configuration-modification), [Event Triggered Execution](/tags/#event-triggered-execution)| Anomaly | -| [Linux Possible Append Cronjob Entry on Existing Cronjob File](/endpoint/linux_possible_append_cronjob_entry_on_existing_cronjob_file/) | [Cron](/tags/#cron), [Scheduled Task/Job](/tags/#scheduled-task/job)| Hunting | -| [Linux Possible Cronjob Modification With Editor](/endpoint/linux_possible_cronjob_modification_with_editor/) | [Cron](/tags/#cron), [Scheduled Task/Job](/tags/#scheduled-task/job)| Hunting | -| [Linux Possible Ssh Key File Creation](/endpoint/linux_possible_ssh_key_file_creation/) | [SSH Authorized Keys](/tags/#ssh-authorized-keys), [Account Manipulation](/tags/#account-manipulation)| Anomaly | -| [Linux Preload Hijack Library Calls](/endpoint/linux_preload_hijack_library_calls/) | [Dynamic Linker Hijacking](/tags/#dynamic-linker-hijacking), [Hijack Execution Flow](/tags/#hijack-execution-flow)| TTP | -| [Linux Service File Created In Systemd Directory](/endpoint/linux_service_file_created_in_systemd_directory/) | [Systemd Timers](/tags/#systemd-timers), [Scheduled Task/Job](/tags/#scheduled-task/job)| Anomaly | -| [Linux Service Restarted](/endpoint/linux_service_restarted/) | [Systemd Timers](/tags/#systemd-timers), [Scheduled Task/Job](/tags/#scheduled-task/job)| Anomaly | -| [Linux Service Started Or Enabled](/endpoint/linux_service_started_or_enabled/) | [Systemd Timers](/tags/#systemd-timers), [Scheduled Task/Job](/tags/#scheduled-task/job)| Anomaly | -| [Linux Setuid Using Chmod Utility](/endpoint/linux_setuid_using_chmod_utility/) | [Setuid and Setgid](/tags/#setuid-and-setgid), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism)| Anomaly | -| [Linux Setuid Using Setcap Utility](/endpoint/linux_setuid_using_setcap_utility/) | [Setuid and Setgid](/tags/#setuid-and-setgid), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism)| Anomaly | -| [Linux Shred Overwrite Command](/endpoint/linux_shred_overwrite_command/) | [Data Destruction](/tags/#data-destruction)| TTP | -| [Linux Sudo OR Su Execution](/endpoint/linux_sudo_or_su_execution/) | [Sudo and Sudo Caching](/tags/#sudo-and-sudo-caching), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism)| Hunting | -| [Linux Sudoers Tmp File Creation](/endpoint/linux_sudoers_tmp_file_creation/) | [Sudo and Sudo Caching](/tags/#sudo-and-sudo-caching), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism)| Anomaly | -| [Linux Visudo Utility Execution](/endpoint/linux_visudo_utility_execution/) | [Sudo and Sudo Caching](/tags/#sudo-and-sudo-caching), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism)| Anomaly | - -#### Reference - -* [https://attack.mitre.org/tactics/TA0004/](https://attack.mitre.org/tactics/TA0004/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/linux_privilege_escalation.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/linux_rootkit.md b/docs/_stories/linux_rootkit.md deleted file mode 100644 index eece76bf1d..0000000000 --- a/docs/_stories/linux_rootkit.md +++ /dev/null @@ -1,48 +0,0 @@ ---- -title: "Linux Rootkit" -last_modified_at: 2022-07-27 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Exploitation - - Reconnaissance ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Adversaries may use rootkits to hide the presence of programs, files, network connections, services, drivers, and other system components. Rootkits are programs that hide the existence of malware by intercepting/hooking and modifying operating system API calls that supply system information. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-07-27 -- **Author**: Michael Haag, Splunk -- **ID**: e30f4054-ac08-4999-b8bc-5cc46886c18d - -#### Narrative - -Rootkits or rootkit enabling functionality may reside at the user or kernel level in the operating system or lower, to include a hypervisor, Master Boot Record, or System Firmware. Rootkits have been seen for Windows, Linux, and Mac OS X systems. Linux rootkits may not standout as much as a Windows rootkit, therefore understanding what kernel modules are installed today and monitoring for new is important. As with any rootkit, it may blend in using a common kernel name or variation of legitimate names. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Linux File Created In Kernel Driver Directory](/endpoint/linux_file_created_in_kernel_driver_directory/) | [Kernel Modules and Extensions](/tags/#kernel-modules-and-extensions), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution)| Anomaly | -| [Linux Insert Kernel Module Using Insmod Utility](/endpoint/linux_insert_kernel_module_using_insmod_utility/) | [Kernel Modules and Extensions](/tags/#kernel-modules-and-extensions), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution)| Anomaly | -| [Linux Install Kernel Module Using Modprobe Utility](/endpoint/linux_install_kernel_module_using_modprobe_utility/) | [Kernel Modules and Extensions](/tags/#kernel-modules-and-extensions), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution)| Anomaly | -| [Linux Kernel Module Enumeration](/endpoint/linux_kernel_module_enumeration/) | [System Information Discovery](/tags/#system-information-discovery), [Rootkit](/tags/#rootkit)| Anomaly | - -#### Reference - -* [https://attack.mitre.org/techniques/T1014/](https://attack.mitre.org/techniques/T1014/) -* [https://content.fireeye.com/apt-41/rpt-apt41](https://content.fireeye.com/apt-41/rpt-apt41) -* [https://medium.com/chronicle-blog/winnti-more-than-just-windows-and-gates-e4f03436031a](https://medium.com/chronicle-blog/winnti-more-than-just-windows-and-gates-e4f03436031a) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/linux_rootkit.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/living_off_the_land.md b/docs/_stories/living_off_the_land.md deleted file mode 100644 index d9fd58ec4f..0000000000 --- a/docs/_stories/living_off_the_land.md +++ /dev/null @@ -1,128 +0,0 @@ ---- -title: "Living Off The Land" -last_modified_at: 2022-03-16 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Risk - - Actions on Objectives - - Exploitation - - Installation - - Reconnaissance ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Leverage analytics that allow you to identify the presence of an adversary leveraging native applications within your environment. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint), [Risk](https://docs.splunk.com/Documentation/CIM/latest/User/Risk) -- **Last Updated**: 2022-03-16 -- **Author**: Lou Stella, Splunk -- **ID**: 6f7982e2-900b-11ec-a54a-acde48001122 - -#### Narrative - -Living Off The Land refers to an adversary methodology of using native applications already installed on the target operating system to achieve their objective. Native utilities provide the adversary with reduced chances of detection by antivirus software or EDR tools. This allows the adversary to blend in with native process behavior. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [BITS Job Persistence](/endpoint/bits_job_persistence/) | [BITS Jobs](/tags/#bits-jobs)| TTP | -| [BITSAdmin Download File](/endpoint/bitsadmin_download_file/) | [BITS Jobs](/tags/#bits-jobs), [Ingress Tool Transfer](/tags/#ingress-tool-transfer)| TTP | -| [CertUtil Download With URLCache and Split Arguments](/endpoint/certutil_download_with_urlcache_and_split_arguments/) | [Ingress Tool Transfer](/tags/#ingress-tool-transfer)| TTP | -| [CertUtil Download With VerifyCtl and Split Arguments](/endpoint/certutil_download_with_verifyctl_and_split_arguments/) | [Ingress Tool Transfer](/tags/#ingress-tool-transfer)| TTP | -| [Certutil exe certificate extraction](/endpoint/certutil_exe_certificate_extraction/) | None| TTP | -| [CertUtil With Decode Argument](/endpoint/certutil_with_decode_argument/) | [Deobfuscate/Decode Files or Information](/tags/#deobfuscate/decode-files-or-information)| TTP | -| [CMD Carry Out String Command Parameter](/endpoint/cmd_carry_out_string_command_parameter/) | [Windows Command Shell](/tags/#windows-command-shell), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter)| Hunting | -| [Control Loading from World Writable Directory](/endpoint/control_loading_from_world_writable_directory/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Control Panel](/tags/#control-panel)| TTP | -| [Creation of Shadow Copy with wmic and powershell](/endpoint/creation_of_shadow_copy_with_wmic_and_powershell/) | [NTDS](/tags/#ntds), [OS Credential Dumping](/tags/#os-credential-dumping)| TTP | -| [Detect HTML Help Renamed](/endpoint/detect_html_help_renamed/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Compiled HTML File](/tags/#compiled-html-file)| Hunting | -| [Detect HTML Help Spawn Child Process](/endpoint/detect_html_help_spawn_child_process/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Compiled HTML File](/tags/#compiled-html-file)| TTP | -| [Detect HTML Help URL in Command Line](/endpoint/detect_html_help_url_in_command_line/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Compiled HTML File](/tags/#compiled-html-file)| TTP | -| [Detect HTML Help Using InfoTech Storage Handlers](/endpoint/detect_html_help_using_infotech_storage_handlers/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Compiled HTML File](/tags/#compiled-html-file)| TTP | -| [Detect mshta inline hta execution](/endpoint/detect_mshta_inline_hta_execution/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Mshta](/tags/#mshta)| TTP | -| [Detect mshta renamed](/endpoint/detect_mshta_renamed/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Mshta](/tags/#mshta)| Hunting | -| [Detect MSHTA Url in Command Line](/endpoint/detect_mshta_url_in_command_line/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Mshta](/tags/#mshta)| TTP | -| [Detect Regasm Spawning a Process](/endpoint/detect_regasm_spawning_a_process/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Regsvcs/Regasm](/tags/#regsvcs/regasm)| TTP | -| [Detect Regasm with Network Connection](/endpoint/detect_regasm_with_network_connection/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Regsvcs/Regasm](/tags/#regsvcs/regasm)| TTP | -| [Detect Regasm with no Command Line Arguments](/endpoint/detect_regasm_with_no_command_line_arguments/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Regsvcs/Regasm](/tags/#regsvcs/regasm)| TTP | -| [Detect Regsvcs Spawning a Process](/endpoint/detect_regsvcs_spawning_a_process/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Regsvcs/Regasm](/tags/#regsvcs/regasm)| TTP | -| [Detect Regsvcs with Network Connection](/endpoint/detect_regsvcs_with_network_connection/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Regsvcs/Regasm](/tags/#regsvcs/regasm)| TTP | -| [Detect Regsvcs with No Command Line Arguments](/endpoint/detect_regsvcs_with_no_command_line_arguments/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Regsvcs/Regasm](/tags/#regsvcs/regasm)| TTP | -| [Detect Regsvr32 Application Control Bypass](/endpoint/detect_regsvr32_application_control_bypass/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Regsvr32](/tags/#regsvr32)| TTP | -| [Detect Rundll32 Application Control Bypass - advpack](/endpoint/detect_rundll32_application_control_bypass_-_advpack/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Rundll32](/tags/#rundll32)| TTP | -| [Detect Rundll32 Application Control Bypass - setupapi](/endpoint/detect_rundll32_application_control_bypass_-_setupapi/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Rundll32](/tags/#rundll32)| TTP | -| [Detect Rundll32 Application Control Bypass - syssetup](/endpoint/detect_rundll32_application_control_bypass_-_syssetup/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Rundll32](/tags/#rundll32)| TTP | -| [Detect Rundll32 Inline HTA Execution](/endpoint/detect_rundll32_inline_hta_execution/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Mshta](/tags/#mshta)| TTP | -| [Disable Schedule Task](/endpoint/disable_schedule_task/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Dump LSASS via comsvcs DLL](/endpoint/dump_lsass_via_comsvcs_dll/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping)| TTP | -| [Esentutl SAM Copy](/endpoint/esentutl_sam_copy/) | [Security Account Manager](/tags/#security-account-manager), [OS Credential Dumping](/tags/#os-credential-dumping)| Hunting | -| [Eventvwr UAC Bypass](/endpoint/eventvwr_uac_bypass/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism)| TTP | -| [Living Off The Land](/endpoint/living_off_the_land/) | [Ingress Tool Transfer](/tags/#ingress-tool-transfer), [Exploit Public-Facing Application](/tags/#exploit-public-facing-application), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter)| Correlation | -| [MacOS LOLbin](/endpoint/macos_lolbin/) | [Unix Shell](/tags/#unix-shell), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter)| TTP | -| [MacOS plutil](/endpoint/macos_plutil/) | [Plist File Modification](/tags/#plist-file-modification)| TTP | -| [Mmc LOLBAS Execution Process Spawn](/endpoint/mmc_lolbas_execution_process_spawn/) | [Remote Services](/tags/#remote-services), [Distributed Component Object Model](/tags/#distributed-component-object-model), [MMC](/tags/#mmc)| TTP | -| [Mshta spawning Rundll32 OR Regsvr32 Process](/endpoint/mshta_spawning_rundll32_or_regsvr32_process/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Mshta](/tags/#mshta)| TTP | -| [Ntdsutil Export NTDS](/endpoint/ntdsutil_export_ntds/) | [NTDS](/tags/#ntds), [OS Credential Dumping](/tags/#os-credential-dumping)| TTP | -| [Reg exe Manipulating Windows Services Registry Keys](/endpoint/reg_exe_manipulating_windows_services_registry_keys/) | [Services Registry Permissions Weakness](/tags/#services-registry-permissions-weakness), [Hijack Execution Flow](/tags/#hijack-execution-flow)| TTP | -| [Regsvr32 Silent and Install Param Dll Loading](/endpoint/regsvr32_silent_and_install_param_dll_loading/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Regsvr32](/tags/#regsvr32)| Anomaly | -| [Regsvr32 with Known Silent Switch Cmdline](/endpoint/regsvr32_with_known_silent_switch_cmdline/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Regsvr32](/tags/#regsvr32)| Anomaly | -| [Remote WMI Command Attempt](/endpoint/remote_wmi_command_attempt/) | [Windows Management Instrumentation](/tags/#windows-management-instrumentation)| TTP | -| [Rundll32 Control RunDLL Hunt](/endpoint/rundll32_control_rundll_hunt/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Rundll32](/tags/#rundll32)| Hunting | -| [Rundll32 Control RunDLL World Writable Directory](/endpoint/rundll32_control_rundll_world_writable_directory/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Rundll32](/tags/#rundll32)| TTP | -| [Rundll32 Create Remote Thread To A Process](/endpoint/rundll32_create_remote_thread_to_a_process/) | [Process Injection](/tags/#process-injection)| TTP | -| [Rundll32 CreateRemoteThread In Browser](/endpoint/rundll32_createremotethread_in_browser/) | [Process Injection](/tags/#process-injection)| TTP | -| [Rundll32 DNSQuery](/endpoint/rundll32_dnsquery/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Rundll32](/tags/#rundll32)| TTP | -| [Rundll32 Process Creating Exe Dll Files](/endpoint/rundll32_process_creating_exe_dll_files/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Rundll32](/tags/#rundll32)| TTP | -| [Rundll32 Shimcache Flush](/endpoint/rundll32_shimcache_flush/) | [Modify Registry](/tags/#modify-registry)| TTP | -| [RunDLL Loading DLL By Ordinal](/endpoint/rundll_loading_dll_by_ordinal/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Rundll32](/tags/#rundll32)| TTP | -| [Schedule Task with HTTP Command Arguments](/endpoint/schedule_task_with_http_command_arguments/) | [Scheduled Task/Job](/tags/#scheduled-task/job)| TTP | -| [Schedule Task with Rundll32 Command Trigger](/endpoint/schedule_task_with_rundll32_command_trigger/) | [Scheduled Task/Job](/tags/#scheduled-task/job)| TTP | -| [Scheduled Task Creation on Remote Endpoint using At](/endpoint/scheduled_task_creation_on_remote_endpoint_using_at/) | [Scheduled Task/Job](/tags/#scheduled-task/job), [At](/tags/#at)| TTP | -| [Scheduled Task Deleted Or Created via CMD](/endpoint/scheduled_task_deleted_or_created_via_cmd/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job)| TTP | -| [Scheduled Task Initiation on Remote Endpoint](/endpoint/scheduled_task_initiation_on_remote_endpoint/) | [Scheduled Task/Job](/tags/#scheduled-task/job), [Scheduled Task](/tags/#scheduled-task)| TTP | -| [Schtasks scheduling job on remote system](/endpoint/schtasks_scheduling_job_on_remote_system/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job)| TTP | -| [Services LOLBAS Execution Process Spawn](/endpoint/services_lolbas_execution_process_spawn/) | [Create or Modify System Process](/tags/#create-or-modify-system-process), [Windows Service](/tags/#windows-service)| TTP | -| [Suspicious IcedID Rundll32 Cmdline](/endpoint/suspicious_icedid_rundll32_cmdline/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Rundll32](/tags/#rundll32)| TTP | -| [Suspicious microsoft workflow compiler rename](/endpoint/suspicious_microsoft_workflow_compiler_rename/) | [Masquerading](/tags/#masquerading), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Rename System Utilities](/tags/#rename-system-utilities)| Hunting | -| [Suspicious microsoft workflow compiler usage](/endpoint/suspicious_microsoft_workflow_compiler_usage/) | [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution)| TTP | -| [Suspicious msbuild path](/endpoint/suspicious_msbuild_path/) | [Masquerading](/tags/#masquerading), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Rename System Utilities](/tags/#rename-system-utilities), [MSBuild](/tags/#msbuild)| TTP | -| [Suspicious MSBuild Rename](/endpoint/suspicious_msbuild_rename/) | [Masquerading](/tags/#masquerading), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Rename System Utilities](/tags/#rename-system-utilities), [MSBuild](/tags/#msbuild)| Hunting | -| [Suspicious MSBuild Spawn](/endpoint/suspicious_msbuild_spawn/) | [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [MSBuild](/tags/#msbuild)| TTP | -| [Suspicious mshta child process](/endpoint/suspicious_mshta_child_process/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Mshta](/tags/#mshta)| TTP | -| [Suspicious mshta spawn](/endpoint/suspicious_mshta_spawn/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Mshta](/tags/#mshta)| TTP | -| [Suspicious Regsvr32 Register Suspicious Path](/endpoint/suspicious_regsvr32_register_suspicious_path/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Regsvr32](/tags/#regsvr32)| TTP | -| [Suspicious Rundll32 dllregisterserver](/endpoint/suspicious_rundll32_dllregisterserver/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Rundll32](/tags/#rundll32)| TTP | -| [Suspicious Scheduled Task from Public Directory](/endpoint/suspicious_scheduled_task_from_public_directory/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job)| Anomaly | -| [Svchost LOLBAS Execution Process Spawn](/endpoint/svchost_lolbas_execution_process_spawn/) | [Scheduled Task/Job](/tags/#scheduled-task/job), [Scheduled Task](/tags/#scheduled-task)| TTP | -| [Windows Binary Proxy Execution Mavinject DLL Injection](/endpoint/windows_binary_proxy_execution_mavinject_dll_injection/) | [Mavinject](/tags/#mavinject), [System Binary Proxy Execution](/tags/#system-binary-proxy-execution)| TTP | -| [Windows Diskshadow Proxy Execution](/endpoint/windows_diskshadow_proxy_execution/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution)| TTP | -| [Windows Identify Protocol Handlers](/endpoint/windows_identify_protocol_handlers/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter)| Hunting | -| [Windows Indirect Command Execution Via forfiles](/endpoint/windows_indirect_command_execution_via_forfiles/) | [Indirect Command Execution](/tags/#indirect-command-execution)| TTP | -| [Windows Indirect Command Execution Via pcalua](/endpoint/windows_indirect_command_execution_via_pcalua/) | [Indirect Command Execution](/tags/#indirect-command-execution)| TTP | -| [Windows InstallUtil in Non Standard Path](/endpoint/windows_installutil_in_non_standard_path/) | [Masquerading](/tags/#masquerading), [Rename System Utilities](/tags/#rename-system-utilities), [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [InstallUtil](/tags/#installutil)| TTP | -| [Windows InstallUtil Remote Network Connection](/endpoint/windows_installutil_remote_network_connection/) | [InstallUtil](/tags/#installutil), [System Binary Proxy Execution](/tags/#system-binary-proxy-execution)| TTP | -| [Windows InstallUtil Uninstall Option](/endpoint/windows_installutil_uninstall_option/) | [InstallUtil](/tags/#installutil), [System Binary Proxy Execution](/tags/#system-binary-proxy-execution)| TTP | -| [Windows InstallUtil Uninstall Option with Network](/endpoint/windows_installutil_uninstall_option_with_network/) | [InstallUtil](/tags/#installutil), [System Binary Proxy Execution](/tags/#system-binary-proxy-execution)| TTP | -| [Windows InstallUtil URL in Command Line](/endpoint/windows_installutil_url_in_command_line/) | [InstallUtil](/tags/#installutil), [System Binary Proxy Execution](/tags/#system-binary-proxy-execution)| TTP | -| [Windows MOF Event Triggered Execution via WMI](/endpoint/windows_mof_event_triggered_execution_via_wmi/) | [Windows Management Instrumentation Event Subscription](/tags/#windows-management-instrumentation-event-subscription)| TTP | -| [Windows Odbcconf Hunting](/endpoint/windows_odbcconf_hunting/) | [Odbcconf](/tags/#odbcconf)| Hunting | -| [Windows Odbcconf Load DLL](/endpoint/windows_odbcconf_load_dll/) | [Odbcconf](/tags/#odbcconf)| TTP | -| [Windows Odbcconf Load Response File](/endpoint/windows_odbcconf_load_response_file/) | [Odbcconf](/tags/#odbcconf)| TTP | -| [WSReset UAC Bypass](/endpoint/wsreset_uac_bypass/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism)| TTP | - -#### Reference - -* [https://lolbas-project.github.io/](https://lolbas-project.github.io/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/living_off_the_land.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_stories/local_privilege_escalation_with_krbrelayup.md b/docs/_stories/local_privilege_escalation_with_krbrelayup.md deleted file mode 100644 index edd27fba58..0000000000 --- a/docs/_stories/local_privilege_escalation_with_krbrelayup.md +++ /dev/null @@ -1,52 +0,0 @@ ---- -title: "Local Privilege Escalation With KrbRelayUp" -last_modified_at: 2022-04-28 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Actions on Objectives - - Exploitation - - Installation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -KrbRelayUp is a tool that allows local privilege escalation from low-priviliged domain user to local system on domain-joined computers. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-04-28 -- **Author**: Michael Haag, Mauricio Velazco, Splunk -- **ID**: 765790f0-2f8f-4048-8321-fd1928ec2546 - -#### Narrative - -In October 2021, James Forshaw from Googles Project Zero released a research blog post titled `Using Kerberos for Authentication Relay Attacks`. This research introduced, for the first time, ways to make Windows authenticate to a different Service Principal Name (SPN) than what would normally be derived from the hostname the client is connecting to. This effectively proved that relaying Kerberos authentication is possible\\. In April 2022, security researcher Mor Davidovich released a tool named KrbRelayUp which implements Kerberos relaying as well as other known Kerberos techniques with the goal of escalating privileges from a low-privileged domain user on a domain-joined device and obtain a SYSTEM shell. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Windows Computer Account Created by Computer Account](/endpoint/windows_computer_account_created_by_computer_account/) | [Steal or Forge Kerberos Tickets](/tags/#steal-or-forge-kerberos-tickets)| TTP | -| [Windows Computer Account Requesting Kerberos Ticket](/endpoint/windows_computer_account_requesting_kerberos_ticket/) | [Steal or Forge Kerberos Tickets](/tags/#steal-or-forge-kerberos-tickets)| TTP | -| [Windows Computer Account With SPN](/endpoint/windows_computer_account_with_spn/) | [Steal or Forge Kerberos Tickets](/tags/#steal-or-forge-kerberos-tickets)| TTP | -| [Windows Kerberos Local Successful Logon](/endpoint/windows_kerberos_local_successful_logon/) | [Steal or Forge Kerberos Tickets](/tags/#steal-or-forge-kerberos-tickets)| TTP | -| [Windows KrbRelayUp Service Creation](/endpoint/windows_krbrelayup_service_creation/) | [Windows Service](/tags/#windows-service)| TTP | - -#### Reference - -* [https://github.com/Dec0ne/KrbRelayUp](https://github.com/Dec0ne/KrbRelayUp) -* [https://gist.github.com/tothi/bf6c59d6de5d0c9710f23dae5750c4b9](https://gist.github.com/tothi/bf6c59d6de5d0c9710f23dae5750c4b9) -* [https://googleprojectzero.blogspot.com/2021/10/using-kerberos-for-authentication-relay.html](https://googleprojectzero.blogspot.com/2021/10/using-kerberos-for-authentication-relay.html) -* [https://dirkjanm.io/relaying-kerberos-over-dns-with-krbrelayx-and-mitm6/](https://dirkjanm.io/relaying-kerberos-over-dns-with-krbrelayx-and-mitm6/) -* [https://github.com/cube0x0/KrbRelay](https://github.com/cube0x0/KrbRelay) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/local_privilege_escalation_with_krbrelayup.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/log4shell_cve-2021-44228.md b/docs/_stories/log4shell_cve-2021-44228.md deleted file mode 100644 index 98d47310f3..0000000000 --- a/docs/_stories/log4shell_cve-2021-44228.md +++ /dev/null @@ -1,65 +0,0 @@ ---- -title: "Log4Shell CVE-2021-44228" -last_modified_at: 2021-12-11 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Network_Traffic - - Risk - - Web - - Actions on Objectives - - Command & Control - - Exploitation - - Reconnaissance ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Log4Shell or CVE-2021-44228 is a Remote Code Execution (RCE) vulnerability in the Apache Log4j library, a widely used and ubiquitous logging framework for Java. The vulnerability allows an attacker who can control log messages to execute arbitrary code loaded from attacker-controlled servers and we anticipate that most apps using the Log4j library will meet this condition. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint), [Network_Traffic](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkTraffic), [Risk](https://docs.splunk.com/Documentation/CIM/latest/User/Risk), [Web](https://docs.splunk.com/Documentation/CIM/latest/User/Web) -- **Last Updated**: 2021-12-11 -- **Author**: Jose Hernandez -- **ID**: b4453928-5a98-11ec-afcd-8de10b48fc52 - -#### Narrative - -In late November 2021, Chen Zhaojun of Alibaba identified a remote code execution vulnerability. Previous work was seen in a 2016 Blackhat talk by Alvaro Munoz and Oleksandr Mirosh called ["A Journey from JNDI/LDAP Manipulation to Remote Code Execution Dream Land"](https://www.blackhat.com/docs/us-16/materials/us-16-Munoz-A-Journey-From-JNDI-LDAP-Manipulation-To-RCE.pdf). Reported under the CVE ID : CVE-2021-44228, released to the public on December 10, 2021. The vulnerability is exploited through improper deserialization of user input passed into the framework. It permits remote code execution and it can allow an attacker to leak sensitive data, such as environment variables, or execute malicious software on the target system. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Any Powershell DownloadFile](/endpoint/any_powershell_downloadfile/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell), [Ingress Tool Transfer](/tags/#ingress-tool-transfer)| TTP | -| [CMD Carry Out String Command Parameter](/endpoint/cmd_carry_out_string_command_parameter/) | [Windows Command Shell](/tags/#windows-command-shell), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter)| Hunting | -| [Curl Download and Bash Execution](/endpoint/curl_download_and_bash_execution/) | [Ingress Tool Transfer](/tags/#ingress-tool-transfer)| TTP | -| [Hunting for Log4Shell](/endpoint/hunting_for_log4shell/) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application)| Hunting | -| [Java Class File download by Java User Agent](/endpoint/java_class_file_download_by_java_user_agent/) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application)| TTP | -| [Linux Java Spawning Shell](/endpoint/linux_java_spawning_shell/) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application)| TTP | -| [Log4Shell CVE-2021-44228 Exploitation](/endpoint/log4shell_cve-2021-44228_exploitation/) | [Ingress Tool Transfer](/tags/#ingress-tool-transfer), [Exploit Public-Facing Application](/tags/#exploit-public-facing-application), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter)| Correlation | -| [Outbound Network Connection from Java Using Default Ports](/endpoint/outbound_network_connection_from_java_using_default_ports/) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application)| TTP | -| [PowerShell - Connect To Internet With Hidden Window](/endpoint/powershell_-_connect_to_internet_with_hidden_window/) | [PowerShell](/tags/#powershell), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter)| Hunting | -| [Wget Download and Bash Execution](/endpoint/wget_download_and_bash_execution/) | [Ingress Tool Transfer](/tags/#ingress-tool-transfer)| TTP | -| [Windows Java Spawning Shells](/endpoint/windows_java_spawning_shells/) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application)| TTP | -| [Detect Outbound LDAP Traffic](/network/detect_outbound_ldap_traffic/) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter)| Hunting | -| [Log4Shell JNDI Payload Injection Attempt](/web/log4shell_jndi_payload_injection_attempt/) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application)| Anomaly | -| [Log4Shell JNDI Payload Injection with Outbound Connection](/web/log4shell_jndi_payload_injection_with_outbound_connection/) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application)| Anomaly | - -#### Reference - -* [https://mbechler.github.io/2021/12/10/PSA_Log4Shell_JNDI_Injection/](https://mbechler.github.io/2021/12/10/PSA_Log4Shell_JNDI_Injection/) -* [https://www.fastly.com/blog/digging-deeper-into-log4shell-0day-rce-exploit-found-in-log4j](https://www.fastly.com/blog/digging-deeper-into-log4shell-0day-rce-exploit-found-in-log4j) -* [https://www.crowdstrike.com/blog/log4j2-vulnerability-analysis-and-mitigation-recommendations/](https://www.crowdstrike.com/blog/log4j2-vulnerability-analysis-and-mitigation-recommendations/) -* [https://www.lunasec.io/docs/blog/log4j-zero-day/](https://www.lunasec.io/docs/blog/log4j-zero-day/) -* [https://www.splunk.com/en_us/blog/security/log-jammin-log4j-2-rce.html](https://www.splunk.com/en_us/blog/security/log-jammin-log4j-2-rce.html) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/log4shell_cve-2021-44228.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/malicious_powershell.md b/docs/_stories/malicious_powershell.md deleted file mode 100644 index afa4018a1b..0000000000 --- a/docs/_stories/malicious_powershell.md +++ /dev/null @@ -1,84 +0,0 @@ ---- -title: "Malicious PowerShell" -last_modified_at: 2017-08-23 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Actions on Objectives - - Command & Control - - Exploitation - - Installation - - Reconnaissance ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Attackers are finding stealthy ways "live off the land," leveraging utilities and tools that come standard on the endpoint--such as PowerShell--to achieve their goals without downloading binary files. These searches can help you detect and investigate PowerShell command-line options that may be indicative of malicious intent. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2017-08-23 -- **Author**: David Dorsey, Splunk -- **ID**: 2c8ff66e-0b57-42af-8ad7-912438a403fc - -#### Narrative - -The searches in this Analytic Story monitor for parameters often used for malicious purposes. It is helpful to understand how often the notable events generated by this story occur, as well as the commonalities between some of these events. These factors may provide clues about whether this is a common occurrence of minimal concern or a rare event that may require more extensive investigation. Likewise, it is important to determine whether the issue is restricted to a single user/system or is broader in scope. \ -The following factors may assist you in determining whether the event is malicious: \ -1. Country of origin \ -1. Responsible party \ -1. Fully qualified domain names associated with the external IP address \ -1. Registration of fully qualified domain names associated with external IP address \ -Determining whether it is a dynamic domain frequently visited by others and/or how third parties categorize it can also help you answer some questions surrounding the attacker and details related to the external system. In addition, there are various sources--such as VirusTotal— that can provide some reputation information on the IP address or domain name, which can assist in determining whether the event is malicious. Finally, determining whether there are other events associated with the IP address may help connect data points or show other events that should be brought into scope. \ -Gathering data on the system of interest can sometimes help you quickly determine whether something suspicious is happening. Some of these items include finding out who else may have recently logged into the system, whether any unusual scheduled tasks exist, whether the system is communicating on suspicious ports, whether there are modifications to sensitive registry keys, and whether there are any known vulnerabilities on the system. This information can often highlight other activity commonly seen in attack scenarios or give more information about how the system may have been targeted. \ -Often, a simple inspection of the process name and path can tell you if the system has been compromised. For example, if `svchost.exe` is found running from a location other than `C:\Windows\System32`, it is likely something malicious designed to hide in plain sight when cursorily reviewing process names. Similarly, if the process itself seems legitimate, but the parent process is running from the temporary browser cache, that could be indicative of activity initiated via a compromised website a user visited. \ -It can also be very helpful to examine various behaviors of the process of interest or the parent of the process of interest. For example, if it turns out the process of interest is malicious, it would be good to see if the parent to that process spawned other processes that might be worth further scrutiny. If a process is suspect, a review of the network connections made in and around the time of the event and/or whether the process spawned any child processes could be helpful, as well. \ -In the event a system is suspected of having been compromised via a malicious website, we suggest reviewing the browsing activity from that system around the time of the event. If categories are given for the URLs visited, that can help you zero in on possible malicious sites. \ -Most recently we have added new content related to PowerShell Script Block logging, Windows EventCode 4104. Script block logging presents the deobfuscated and raw script executed on an endpoint. The analytics produced were tested against commonly used attack frameworks - PowerShell-Empire, Cobalt Strike and Covenant. In addition, we sampled publicly available samples that utilize PowerShell and validated coverage. The analytics are here to identify suspicious usage, cmdlets, or script values. 4104 events are enabled via the Windows registry and may generate a large volume of data if enabled globally. Enabling on critical systems or a limited set may be best. During triage of 4104 events, review parallel processes for other processes and command executed. Identify any file modifications and network communication and review accordingly. Fortunately, we get the full script to determine the level of threat identified. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Suspicious Powershell Command-Line Arguments](/deprecated/suspicious_powershell_command-line_arguments/) | [PowerShell](/tags/#powershell)| TTP | -| [Any Powershell DownloadFile](/endpoint/any_powershell_downloadfile/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell), [Ingress Tool Transfer](/tags/#ingress-tool-transfer)| TTP | -| [Any Powershell DownloadString](/endpoint/any_powershell_downloadstring/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell), [Ingress Tool Transfer](/tags/#ingress-tool-transfer)| TTP | -| [Detect Empire with PowerShell Script Block Logging](/endpoint/detect_empire_with_powershell_script_block_logging/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell)| TTP | -| [Detect Mimikatz With PowerShell Script Block Logging](/endpoint/detect_mimikatz_with_powershell_script_block_logging/) | [OS Credential Dumping](/tags/#os-credential-dumping), [PowerShell](/tags/#powershell)| TTP | -| [GetLocalUser with PowerShell Script Block](/endpoint/getlocaluser_with_powershell_script_block/) | [Account Discovery](/tags/#account-discovery), [Local Account](/tags/#local-account), [PowerShell](/tags/#powershell)| Hunting | -| [GetWmiObject User Account with PowerShell Script Block](/endpoint/getwmiobject_user_account_with_powershell_script_block/) | [Account Discovery](/tags/#account-discovery), [Local Account](/tags/#local-account), [PowerShell](/tags/#powershell)| Hunting | -| [Malicious PowerShell Process - Encoded Command](/endpoint/malicious_powershell_process_-_encoded_command/) | [Obfuscated Files or Information](/tags/#obfuscated-files-or-information)| Hunting | -| [Malicious PowerShell Process With Obfuscation Techniques](/endpoint/malicious_powershell_process_with_obfuscation_techniques/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell)| TTP | -| [Possible Lateral Movement PowerShell Spawn](/endpoint/possible_lateral_movement_powershell_spawn/) | [Remote Services](/tags/#remote-services), [Distributed Component Object Model](/tags/#distributed-component-object-model), [Windows Remote Management](/tags/#windows-remote-management), [Windows Management Instrumentation](/tags/#windows-management-instrumentation), [Scheduled Task](/tags/#scheduled-task), [Windows Service](/tags/#windows-service), [PowerShell](/tags/#powershell), [MMC](/tags/#mmc)| TTP | -| [PowerShell 4104 Hunting](/endpoint/powershell_4104_hunting/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell)| Hunting | -| [PowerShell - Connect To Internet With Hidden Window](/endpoint/powershell_-_connect_to_internet_with_hidden_window/) | [PowerShell](/tags/#powershell), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter)| Hunting | -| [Powershell Creating Thread Mutex](/endpoint/powershell_creating_thread_mutex/) | [Obfuscated Files or Information](/tags/#obfuscated-files-or-information), [Indicator Removal from Tools](/tags/#indicator-removal-from-tools), [PowerShell](/tags/#powershell)| TTP | -| [PowerShell Domain Enumeration](/endpoint/powershell_domain_enumeration/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell)| TTP | -| [Powershell Enable SMB1Protocol Feature](/endpoint/powershell_enable_smb1protocol_feature/) | [Obfuscated Files or Information](/tags/#obfuscated-files-or-information), [Indicator Removal from Tools](/tags/#indicator-removal-from-tools)| TTP | -| [Powershell Execute COM Object](/endpoint/powershell_execute_com_object/) | [Component Object Model Hijacking](/tags/#component-object-model-hijacking), [Event Triggered Execution](/tags/#event-triggered-execution), [PowerShell](/tags/#powershell)| TTP | -| [Powershell Fileless Process Injection via GetProcAddress](/endpoint/powershell_fileless_process_injection_via_getprocaddress/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Process Injection](/tags/#process-injection), [PowerShell](/tags/#powershell)| TTP | -| [Powershell Fileless Script Contains Base64 Encoded Content](/endpoint/powershell_fileless_script_contains_base64_encoded_content/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Obfuscated Files or Information](/tags/#obfuscated-files-or-information), [PowerShell](/tags/#powershell)| TTP | -| [PowerShell Loading DotNET into Memory via Reflection](/endpoint/powershell_loading_dotnet_into_memory_via_reflection/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell)| TTP | -| [Powershell Processing Stream Of Data](/endpoint/powershell_processing_stream_of_data/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell)| TTP | -| [Powershell Using memory As Backing Store](/endpoint/powershell_using_memory_as_backing_store/) | [PowerShell](/tags/#powershell), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter)| TTP | -| [Recon AVProduct Through Pwh or WMI](/endpoint/recon_avproduct_through_pwh_or_wmi/) | [Gather Victim Host Information](/tags/#gather-victim-host-information)| TTP | -| [Recon Using WMI Class](/endpoint/recon_using_wmi_class/) | [Gather Victim Host Information](/tags/#gather-victim-host-information), [PowerShell](/tags/#powershell)| TTP | -| [ServicePrincipalNames Discovery with PowerShell](/endpoint/serviceprincipalnames_discovery_with_powershell/) | [Kerberoasting](/tags/#kerberoasting)| TTP | -| [Set Default PowerShell Execution Policy To Unrestricted or Bypass](/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell)| TTP | -| [Unloading AMSI via Reflection](/endpoint/unloading_amsi_via_reflection/) | [Impair Defenses](/tags/#impair-defenses), [PowerShell](/tags/#powershell), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter)| TTP | -| [WMI Recon Running Process Or Services](/endpoint/wmi_recon_running_process_or_services/) | [Gather Victim Host Information](/tags/#gather-victim-host-information)| TTP | - -#### Reference - -* [https://blogs.mcafee.com/mcafee-labs/malware-employs-powershell-to-infect-systems/](https://blogs.mcafee.com/mcafee-labs/malware-employs-powershell-to-infect-systems/) -* [https://www.crowdstrike.com/blog/bears-midst-intrusion-democratic-national-committee/](https://www.crowdstrike.com/blog/bears-midst-intrusion-democratic-national-committee/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/malicious_powershell.yml) \| *version*: **5** \ No newline at end of file diff --git a/docs/_stories/masquerading_-_rename_system_utilities.md b/docs/_stories/masquerading_-_rename_system_utilities.md deleted file mode 100644 index 4119989902..0000000000 --- a/docs/_stories/masquerading_-_rename_system_utilities.md +++ /dev/null @@ -1,54 +0,0 @@ ---- -title: "Masquerading - Rename System Utilities" -last_modified_at: 2021-04-26 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Actions on Objectives - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Adversaries may rename legitimate system utilities to try to evade security mechanisms concerning the usage of those utilities. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-04-26 -- **Author**: Michael Haag, Splunk -- **ID**: f0258af4-a6ae-11eb-b3c2-acde48001122 - -#### Narrative - -Security monitoring and control mechanisms may be in place for system utilities adversaries are capable of abusing. It may be possible to bypass those security mechanisms by renaming the utility prior to utilization (ex: rename rundll32.exe). An alternative case occurs when a legitimate utility is copied or moved to a different directory and renamed to avoid detections based on system utilities executing from non-standard paths.\ -The following content is here to assist with binaries within `system32` or `syswow64` being moved to a new location or an adversary bringing a the binary in to execute.\ -There will be false positives as some native Windows processes are moved or ran by third party applications from different paths. If file names are mismatched between the file name on disk and that of the binarys PE metadata, this is a likely indicator that a binary was renamed after it was compiled. Collecting and comparing disk and resource filenames for binaries by looking to see if the InternalName, OriginalFilename, and or ProductName match what is expected could provide useful leads, but may not always be indicative of malicious activity. Do not focus on the possible names a file could have, but instead on the command-line arguments that are known to be used and are distinct because it will have a better rate of detection. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Execution of File With Spaces Before Extension](/deprecated/execution_of_file_with_spaces_before_extension/) | [Rename System Utilities](/tags/#rename-system-utilities)| TTP | -| [Suspicious Rundll32 Rename](/deprecated/suspicious_rundll32_rename/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Masquerading](/tags/#masquerading), [Rundll32](/tags/#rundll32), [Rename System Utilities](/tags/#rename-system-utilities)| Hunting | -| [Execution of File with Multiple Extensions](/endpoint/execution_of_file_with_multiple_extensions/) | [Masquerading](/tags/#masquerading), [Rename System Utilities](/tags/#rename-system-utilities)| TTP | -| [Sdelete Application Execution](/endpoint/sdelete_application_execution/) | [Data Destruction](/tags/#data-destruction), [File Deletion](/tags/#file-deletion), [Indicator Removal on Host](/tags/#indicator-removal-on-host)| TTP | -| [Suspicious microsoft workflow compiler rename](/endpoint/suspicious_microsoft_workflow_compiler_rename/) | [Masquerading](/tags/#masquerading), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Rename System Utilities](/tags/#rename-system-utilities)| Hunting | -| [Suspicious msbuild path](/endpoint/suspicious_msbuild_path/) | [Masquerading](/tags/#masquerading), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Rename System Utilities](/tags/#rename-system-utilities), [MSBuild](/tags/#msbuild)| TTP | -| [Suspicious MSBuild Rename](/endpoint/suspicious_msbuild_rename/) | [Masquerading](/tags/#masquerading), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Rename System Utilities](/tags/#rename-system-utilities), [MSBuild](/tags/#msbuild)| Hunting | -| [System Processes Run From Unexpected Locations](/endpoint/system_processes_run_from_unexpected_locations/) | [Masquerading](/tags/#masquerading), [Rename System Utilities](/tags/#rename-system-utilities)| TTP | -| [Windows DotNet Binary in Non Standard Path](/endpoint/windows_dotnet_binary_in_non_standard_path/) | [Masquerading](/tags/#masquerading), [Rename System Utilities](/tags/#rename-system-utilities), [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [InstallUtil](/tags/#installutil)| TTP | -| [Windows InstallUtil in Non Standard Path](/endpoint/windows_installutil_in_non_standard_path/) | [Masquerading](/tags/#masquerading), [Rename System Utilities](/tags/#rename-system-utilities), [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [InstallUtil](/tags/#installutil)| TTP | - -#### Reference - -* [https://attack.mitre.org/techniques/T1036/003/](https://attack.mitre.org/techniques/T1036/003/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/masquerading_-_rename_system_utilities.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/meterpreter.md b/docs/_stories/meterpreter.md deleted file mode 100644 index 49ad93ce2b..0000000000 --- a/docs/_stories/meterpreter.md +++ /dev/null @@ -1,47 +0,0 @@ ---- -title: "Meterpreter" -last_modified_at: 2021-06-08 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Meterpreter provides red teams, pen testers and threat actors interactive access to a compromised host to run commands, upload payloads, download files, and other actions. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-06-08 -- **Author**: Michael Hart -- **ID**: d5f8e298-c85a-11eb-9fea-acde48001122 - -#### Narrative - -This Analytic Story supports you to detect Tactics, Techniques and Procedures (TTPs) from Meterpreter. Meterpreter is a Metasploit payload for remote execution that leverages DLL injection to make it extremely difficult to detect. Since the software runs in memory, no new processes are created upon injection. It also leverages encrypted communication channels.\ -Meterpreter enables the operator to remotely run commands on the target machine, upload payloads, download files, dump password hashes, and much more. It is difficult to determine from the forensic evidence what actions the operator performed. Splunk Research, however, has observed anomalous behaviors on the compromised hosts that seem to only appear when Meterpreter is executing various commands. With that, we have written new detections targeted to these detections.\ -While investigating a detection related to this analytic story, please bear in mind that the detections look for anomalies in system behavior. It will be imperative to look for other signs in the endpoint and network logs for lateral movement, discovery and other actions to confirm that the host was compromised and a remote actor used it to progress on their objectives. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Excessive distinct processes from Windows Temp](/endpoint/excessive_distinct_processes_from_windows_temp/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter)| Anomaly | -| [Excessive number of taskhost processes](/endpoint/excessive_number_of_taskhost_processes/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter)| Anomaly | - -#### Reference - -* [https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/](https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/) -* [https://doubleoctopus.com/security-wiki/threats-and-tools/meterpreter/](https://doubleoctopus.com/security-wiki/threats-and-tools/meterpreter/) -* [https://www.rapid7.com/products/metasploit/](https://www.rapid7.com/products/metasploit/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/meterpreter.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/microsoft_mshtml_remote_code_execution_cve-2021-40444.md b/docs/_stories/microsoft_mshtml_remote_code_execution_cve-2021-40444.md deleted file mode 100644 index 78e4530140..0000000000 --- a/docs/_stories/microsoft_mshtml_remote_code_execution_cve-2021-40444.md +++ /dev/null @@ -1,50 +0,0 @@ ---- -title: "Microsoft MSHTML Remote Code Execution CVE-2021-40444" -last_modified_at: 2021-09-08 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -CVE-2021-40444 is a remote code execution vulnerability in MSHTML, recently used to delivery targeted spearphishing documents. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-09-08 -- **Author**: Michael Haag, Splunk -- **ID**: 4ad4253e-10ca-11ec-8235-acde48001122 - -#### Narrative - -Microsoft is aware of targeted attacks that attempt to exploit this vulnerability, CVE-2021-40444 by using specially-crafted Microsoft Office documents. MSHTML is a software component used to render web pages on Windows. Although it is 2019s most commonly associated with Internet Explorer, it is also used in other software. CVE-2021-40444 received a CVSS score of 8.8 out of 10. MSHTML is the beating heart of Internet Explorer, the vulnerability also exists in that browser. Although given its limited use, there is little risk of infection by that vector. Microsoft Office applications use the MSHTML component to display web content in Office documents. The attack depends on MSHTML loading a specially crafted ActiveX control when the target opens a malicious Office document. The loaded ActiveX control can then run arbitrary code to infect the system with more malware. At the moment all supported Windows versions are vulnerable. Since there is no patch available yet, Microsoft proposes a few methods to block these attacks. \ -1. Disable the installation of all ActiveX controls in Internet Explorer via the registry. Previously-installed ActiveX controls will still run, but no new ones will be added, including malicious ones. Open documents from the Internet in Protected View or Application Guard for Office, both of which prevent the current attack. This is a default setting but it may have been changed. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Control Loading from World Writable Directory](/endpoint/control_loading_from_world_writable_directory/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Control Panel](/tags/#control-panel)| TTP | -| [MSHTML Module Load in Office Product](/endpoint/mshtml_module_load_in_office_product/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment)| TTP | -| [Office Product Writing cab or inf](/endpoint/office_product_writing_cab_or_inf/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment)| TTP | -| [Office Spawning Control](/endpoint/office_spawning_control/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment)| TTP | -| [Rundll32 Control RunDLL Hunt](/endpoint/rundll32_control_rundll_hunt/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Rundll32](/tags/#rundll32)| Hunting | -| [Rundll32 Control RunDLL World Writable Directory](/endpoint/rundll32_control_rundll_world_writable_directory/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Rundll32](/tags/#rundll32)| TTP | - -#### Reference - -* [https://blog.malwarebytes.com/exploits-and-vulnerabilities/2021/09/windows-mshtml-zero-day-actively-exploited-mitigations-required/](https://blog.malwarebytes.com/exploits-and-vulnerabilities/2021/09/windows-mshtml-zero-day-actively-exploited-mitigations-required/) -* [https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40444](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40444) -* [https://www.echotrail.io/insights/search/control.exe](https://www.echotrail.io/insights/search/control.exe) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/microsoft_mshtml_remote_code_execution_cve-2021-40444.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/microsoft_support_diagnostic_tool_vulnerability_cve-2022-30190.md b/docs/_stories/microsoft_support_diagnostic_tool_vulnerability_cve-2022-30190.md deleted file mode 100644 index d2c82762e4..0000000000 --- a/docs/_stories/microsoft_support_diagnostic_tool_vulnerability_cve-2022-30190.md +++ /dev/null @@ -1,51 +0,0 @@ ---- -title: "Microsoft Support Diagnostic Tool Vulnerability CVE-2022-30190" -last_modified_at: 2022-05-31 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -On Monday May 30, 2022, Microsoft issued CVE-2022-30190 regarding the Microsoft Support Diagnostic Tool (MSDT) in Windows vulnerability. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-05-31 -- **Author**: Michael Haag, Teoderick Contreras, Splunk -- **ID**: 2a60a99e-c93a-4036-af70-768fac838019 - -#### Narrative - -A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run arbitrary code with the privileges of the calling application. The attacker can then install programs, view, change, or delete data, or create new accounts in the context allowed by the user''s rights. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Windows Command and Scripting Interpreter Hunting Path Traversal](/endpoint/windows_command_and_scripting_interpreter_hunting_path_traversal/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter)| Hunting | -| [Windows Command and Scripting Interpreter Path Traversal Exec](/endpoint/windows_command_and_scripting_interpreter_path_traversal_exec/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter)| TTP | -| [Windows Execute Arbitrary Commands with MSDT](/endpoint/windows_execute_arbitrary_commands_with_msdt/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution)| TTP | -| [Windows Office Product Spawning MSDT](/endpoint/windows_office_product_spawning_msdt/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment)| TTP | - -#### Reference - -* [https://msrc-blog.microsoft.com/2022/05/30/guidance-for-cve-2022-30190-microsoft-support-diagnostic-tool-vulnerability/](https://msrc-blog.microsoft.com/2022/05/30/guidance-for-cve-2022-30190-microsoft-support-diagnostic-tool-vulnerability/) -* [https://isc.sans.edu/diary/rss/28694](https://isc.sans.edu/diary/rss/28694) -* [https://doublepulsar.com/follina-a-microsoft-office-code-execution-vulnerability-1a47fce5629e](https://doublepulsar.com/follina-a-microsoft-office-code-execution-vulnerability-1a47fce5629e) -* [https://twitter.com/nao_sec/status/1530196847679401984?s=20&t=ZiXYI4dQuA-0_dzQzSUb3A](https://twitter.com/nao_sec/status/1530196847679401984?s=20&t=ZiXYI4dQuA-0_dzQzSUb3A) -* [https://app.any.run/tasks/713f05d2-fe78-4b9d-a744-f7c133e3fafb/](https://app.any.run/tasks/713f05d2-fe78-4b9d-a744-f7c133e3fafb/) -* [https://www.virustotal.com/gui/file/4a24048f81afbe9fb62e7a6a49adbd1faf41f266b5f9feecdceb567aec096784/detection](https://www.virustotal.com/gui/file/4a24048f81afbe9fb62e7a6a49adbd1faf41f266b5f9feecdceb567aec096784/detection) -* [https://strontic.github.io/xcyclopedia/library/msdt.exe-152D4C9F63EFB332CCB134C6953C0104.html](https://strontic.github.io/xcyclopedia/library/msdt.exe-152D4C9F63EFB332CCB134C6953C0104.html) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/microsoft_support_diagnostic_tool_vulnerability_cve-2022-30190.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/monitor_backup_solution.md b/docs/_stories/monitor_backup_solution.md deleted file mode 100644 index 8588b00b8a..0000000000 --- a/docs/_stories/monitor_backup_solution.md +++ /dev/null @@ -1,42 +0,0 @@ ---- -title: "Monitor Backup Solution" -last_modified_at: 2017-09-12 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Address common concerns when monitoring your backup processes. These searches can help you reduce risks from ransomware, device theft, or denial of physical access to a host by backing up data on endpoints. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: -- **Last Updated**: 2017-09-12 -- **Author**: David Dorsey, Splunk -- **ID**: abe807c7-1eb6-4304-ac32-6e7aacdb891d - -#### Narrative - -Having backups is a standard best practice that helps ensure continuity of business operations. Having mature backup processes can also help you reduce the risks of many security-related incidents and streamline your response processes. The detection searches in this Analytic Story will help you identify systems that have backup failures, as well as systems that have not been backed up for an extended period of time. The story will also return the notable event history and all of the backup logs for an endpoint. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Extended Period Without Successful Netbackup Backups](/deprecated/extended_period_without_successful_netbackup_backups/) | None| Hunting | -| [Unsuccessful Netbackup backups](/deprecated/unsuccessful_netbackup_backups/) | None| Hunting | - -#### Reference - -* [https://www.carbonblack.com/2016/03/04/tracking-locky-ransomware-using-carbon-black/](https://www.carbonblack.com/2016/03/04/tracking-locky-ransomware-using-carbon-black/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/monitor_backup_solution.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/monitor_for_unauthorized_software.md b/docs/_stories/monitor_for_unauthorized_software.md deleted file mode 100644 index ce9d496ded..0000000000 --- a/docs/_stories/monitor_for_unauthorized_software.md +++ /dev/null @@ -1,46 +0,0 @@ ---- -title: "Monitor for Unauthorized Software" -last_modified_at: 2017-09-15 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Actions on Objectives - - Command & Control - - Installation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Identify and investigate prohibited/unauthorized software or processes that may be concealing malicious behavior within your environment. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2017-09-15 -- **Author**: David Dorsey, Splunk -- **ID**: 8892a655-6205-43f7-abba-06460e38c8ae - -#### Narrative - -It is critical to identify unauthorized software and processes running on enterprise endpoints and determine whether they are likely to be malicious. This Analytic Story requires the user to populate the Interesting Processes table within Enterprise Security with prohibited processes. An included support search will augment this data, adding information on processes thought to be malicious. This search requires data from endpoint detection-and-response solutions, endpoint data sources (such as Sysmon), or Windows Event Logs--assuming that the Active Directory administrator has enabled process tracking within the System Event Audit Logs.\ -It is important to investigate any software identified as suspicious, in order to understand how it was installed or executed. Analyzing authentication logs or any historic notable events might elicit additional investigative leads of interest. For best results, schedule the search to run every two weeks. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Prohibited Software On Endpoint](/deprecated/prohibited_software_on_endpoint/) | None| Hunting | -| [Attacker Tools On Endpoint](/endpoint/attacker_tools_on_endpoint/) | [Match Legitimate Name or Location](/tags/#match-legitimate-name-or-location), [Masquerading](/tags/#masquerading), [OS Credential Dumping](/tags/#os-credential-dumping), [Active Scanning](/tags/#active-scanning)| TTP | - -#### Reference - -* [https://www.crowdstrike.com/blog/bears-midst-intrusion-democratic-national-committee/](https://www.crowdstrike.com/blog/bears-midst-intrusion-democratic-national-committee/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/monitor_for_unauthorized_software.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/monitor_for_updates.md b/docs/_stories/monitor_for_updates.md deleted file mode 100644 index e78a38741e..0000000000 --- a/docs/_stories/monitor_for_updates.md +++ /dev/null @@ -1,44 +0,0 @@ ---- -title: "Monitor for Updates" -last_modified_at: 2017-09-15 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Updates - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Monitor your enterprise to ensure that your endpoints are being patched and updated. Adversaries notoriously exploit known vulnerabilities that could be mitigated by applying routine security patches. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Updates](https://docs.splunk.com/Documentation/CIM/latest/User/Updates) -- **Last Updated**: 2017-09-15 -- **Author**: Rico Valdez, Splunk -- **ID**: 9ef8d677-7b52-4213-a038-99cfc7acc2d8 - -#### Narrative - -It is a common best practice to ensure that endpoints are being patched and updated in a timely manner, in order to reduce the risk of compromise via a publicly disclosed vulnerability. Timely application of updates/patches is important to eliminate known vulnerabilities that may be exploited by various threat actors.\ -Searches in this analytic story are designed to help analysts monitor endpoints for system patches and/or updates. This helps analysts identify any systems that are not successfully updated in a timely matter.\ -Microsoft releases updates for Windows systems on a monthly cadence. They should be installed as soon as possible after following internal testing and validation procedures. Patches and updates for other systems or applications are typically released as needed. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [No Windows Updates in a time frame](/application/no_windows_updates_in_a_time_frame/) | None| Hunting | - -#### Reference - -* [https://learn.cisecurity.org/20-controls-download](https://learn.cisecurity.org/20-controls-download) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/monitor_for_updates.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/netsh_abuse.md b/docs/_stories/netsh_abuse.md deleted file mode 100644 index 0ed97685ef..0000000000 --- a/docs/_stories/netsh_abuse.md +++ /dev/null @@ -1,46 +0,0 @@ ---- -title: "Netsh Abuse" -last_modified_at: 2017-01-05 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Actions on Objectives ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Detect activities and various techniques associated with the abuse of `netsh.exe`, which can disable local firewall settings or set up a remote connection to a host from an infected system. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2017-01-05 -- **Author**: Bhavin Patel, Splunk -- **ID**: 2b1800dd-92f9-47ec-a981-fdf1351e5f65 - -#### Narrative - -It is a common practice for attackers of all types to leverage native Windows tools and functionality to execute commands for malicious reasons. One such tool on Windows OS is `netsh.exe`,a command-line scripting utility that allows you to--either locally or remotely--display or modify the network configuration of a computer that is currently running. `Netsh.exe` can be used to discover and disable local firewall settings. It can also be used to set up a remote connection to a host from an infected system.\ -To get started, run the detection search to identify parent processes of `netsh.exe`. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Processes created by netsh](/deprecated/processes_created_by_netsh/) | [Disable or Modify System Firewall](/tags/#disable-or-modify-system-firewall)| TTP | -| [Processes launching netsh](/endpoint/processes_launching_netsh/) | [Disable or Modify System Firewall](/tags/#disable-or-modify-system-firewall), [Impair Defenses](/tags/#impair-defenses)| TTP | - -#### Reference - -* [https://docs.microsoft.com/en-us/previous-versions/tn-archive/bb490939(v=technet.10)](https://docs.microsoft.com/en-us/previous-versions/tn-archive/bb490939(v=technet.10)) -* [https://htmlpreview.github.io/?https://github.com/MatthewDemaske/blogbackup/blob/master/netshell.html](https://htmlpreview.github.io/?https://github.com/MatthewDemaske/blogbackup/blob/master/netshell.html) -* [https://blogs.jpcert.or.jp/en/2016/01/windows-commands-abused-by-attackers.html](https://blogs.jpcert.or.jp/en/2016/01/windows-commands-abused-by-attackers.html) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/netsh_abuse.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/network_discovery.md b/docs/_stories/network_discovery.md deleted file mode 100644 index dd9cf0ebab..0000000000 --- a/docs/_stories/network_discovery.md +++ /dev/null @@ -1,44 +0,0 @@ ---- -title: "Network Discovery" -last_modified_at: 2022-02-14 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Reconnaissance ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Leverage searches that allow you to detect and investigate unusual activities that might relate to the network discovery, including looking for network configuration, settings such as IP, MAC address, firewall settings and many more. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-02-14 -- **Author**: Teoderick Contreras, Splunk -- **ID**: af228995-f182-49d7-90b3-2a732944f00f - -#### Narrative - -Adversaries may use the information from System Network Configuration Discovery during automated discovery to shape follow-on behaviors, including determining certain access within the target network and what actions to do next. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Linux System Network Discovery](/endpoint/linux_system_network_discovery/) | [System Network Configuration Discovery](/tags/#system-network-configuration-discovery)| Anomaly | - -#### Reference - -* [https://attack.mitre.org/techniques/T1016/](https://attack.mitre.org/techniques/T1016/) -* [https://www.welivesecurity.com/wp-content/uploads/2021/01/ESET_Kobalos.pdf](https://www.welivesecurity.com/wp-content/uploads/2021/01/ESET_Kobalos.pdf) -* [https://researchcenter.paloaltonetworks.com/2018/09/unit42-xbash-combines-botnet-ransomware-coinmining-worm-targets-linux-windows/](https://researchcenter.paloaltonetworks.com/2018/09/unit42-xbash-combines-botnet-ransomware-coinmining-worm-targets-linux-windows/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/network_discovery.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/nobelium_group.md b/docs/_stories/nobelium_group.md deleted file mode 100644 index 30e74e117b..0000000000 --- a/docs/_stories/nobelium_group.md +++ /dev/null @@ -1,61 +0,0 @@ ---- -title: "NOBELIUM Group" -last_modified_at: 2020-12-14 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Network_Traffic - - Web - - Actions on Objectives - - Command & Control - - Exploitation - - Installation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Sunburst is a trojanized updates to SolarWinds Orion IT monitoring and management software. It was discovered by FireEye in December 2020. The actors behind this campaign gained access to numerous public and private organizations around the world. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint), [Network_Traffic](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkTraffic), [Web](https://docs.splunk.com/Documentation/CIM/latest/User/Web) -- **Last Updated**: 2020-12-14 -- **Author**: Patrick Bareiss, Michael Haag, Splunk -- **ID**: 758196b5-2e21-424f-a50c-6e421ce926c2 - -#### Narrative - -This Analytic Story supports you to detect Tactics, Techniques and Procedures (TTPs) of the NOBELIUM Group. The threat actor behind sunburst compromised the SolarWinds.Orion.Core.BusinessLayer.dll, is a SolarWinds digitally-signed component of the Orion software framework that contains a backdoor that communicates via HTTP to third party servers. The detections in this Analytic Story are focusing on the dll loading events, file create events and network events to detect This malware. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Anomalous usage of 7zip](/endpoint/anomalous_usage_of_7zip/) | [Archive via Utility](/tags/#archive-via-utility), [Archive Collected Data](/tags/#archive-collected-data)| Anomaly | -| [Detect Prohibited Applications Spawning cmd exe](/endpoint/detect_prohibited_applications_spawning_cmd_exe/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Windows Command Shell](/tags/#windows-command-shell)| Hunting | -| [Detect Rundll32 Inline HTA Execution](/endpoint/detect_rundll32_inline_hta_execution/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Mshta](/tags/#mshta)| TTP | -| [Malicious PowerShell Process - Encoded Command](/endpoint/malicious_powershell_process_-_encoded_command/) | [Obfuscated Files or Information](/tags/#obfuscated-files-or-information)| Hunting | -| [Sc exe Manipulating Windows Services](/endpoint/sc_exe_manipulating_windows_services/) | [Windows Service](/tags/#windows-service), [Create or Modify System Process](/tags/#create-or-modify-system-process)| TTP | -| [Scheduled Task Deleted Or Created via CMD](/endpoint/scheduled_task_deleted_or_created_via_cmd/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job)| TTP | -| [Schtasks scheduling job on remote system](/endpoint/schtasks_scheduling_job_on_remote_system/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job)| TTP | -| [Windows AdFind Exe](/endpoint/windows_adfind_exe/) | [Remote System Discovery](/tags/#remote-system-discovery)| TTP | -| [First Time Seen Running Windows Service](/endpoint/first_time_seen_running_windows_service/) | [System Services](/tags/#system-services), [Service Execution](/tags/#service-execution)| Anomaly | -| [Sunburst Correlation DLL and Network Event](/endpoint/sunburst_correlation_dll_and_network_event/) | [Exploitation for Client Execution](/tags/#exploitation-for-client-execution)| TTP | -| [Detect Outbound SMB Traffic](/network/detect_outbound_smb_traffic/) | [File Transfer Protocols](/tags/#file-transfer-protocols), [Application Layer Protocol](/tags/#application-layer-protocol)| TTP | -| [TOR Traffic](/network/tor_traffic/) | [Application Layer Protocol](/tags/#application-layer-protocol), [Web Protocols](/tags/#web-protocols)| TTP | -| [Supernova Webshell](/web/supernova_webshell/) | [Web Shell](/tags/#web-shell)| TTP | - -#### Reference - -* [https://www.microsoft.com/security/blog/2021/03/04/goldmax-goldfinder-sibot-analyzing-nobelium-malware/](https://www.microsoft.com/security/blog/2021/03/04/goldmax-goldfinder-sibot-analyzing-nobelium-malware/) -* [https://www.fireeye.com/blog/threat-research/2020/12/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor.html](https://www.fireeye.com/blog/threat-research/2020/12/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor.html) -* [https://msrc-blog.microsoft.com/2020/12/13/customer-guidance-on-recent-nation-state-cyber-attacks/](https://msrc-blog.microsoft.com/2020/12/13/customer-guidance-on-recent-nation-state-cyber-attacks/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/nobelium_group.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_stories/office_365_detections.md b/docs/_stories/office_365_detections.md deleted file mode 100644 index fdaf45ba3f..0000000000 --- a/docs/_stories/office_365_detections.md +++ /dev/null @@ -1,54 +0,0 @@ ---- -title: "Office 365 Detections" -last_modified_at: 2020-12-16 -toc: true -toc_label: "" -tags: - - Splunk Security Analytics for AWS - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Actions on Objectives - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This story is focused around detecting Office 365 Attacks. - -- **Product**: Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: -- **Last Updated**: 2020-12-16 -- **Author**: Patrick Bareiss, Splunk -- **ID**: 1a51dd71-effc-48b2-abc4-3e9cdb61e5b9 - -#### Narrative - -More and more companies are using Microsofts Office 365 cloud offering. Therefore, we see more and more attacks against Office 365. This story provides various detections for Office 365 attacks. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [O365 Add App Role Assignment Grant User](/cloud/o365_add_app_role_assignment_grant_user/) | [Cloud Account](/tags/#cloud-account), [Create Account](/tags/#create-account)| TTP | -| [O365 Added Service Principal](/cloud/o365_added_service_principal/) | [Cloud Account](/tags/#cloud-account), [Create Account](/tags/#create-account)| TTP | -| [O365 Bypass MFA via Trusted IP](/cloud/o365_bypass_mfa_via_trusted_ip/) | [Disable or Modify Cloud Firewall](/tags/#disable-or-modify-cloud-firewall), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [O365 Disable MFA](/cloud/o365_disable_mfa/) | [Modify Authentication Process](/tags/#modify-authentication-process)| TTP | -| [O365 Excessive Authentication Failures Alert](/cloud/o365_excessive_authentication_failures_alert/) | [Brute Force](/tags/#brute-force)| Anomaly | -| [O365 Excessive SSO logon errors](/cloud/o365_excessive_sso_logon_errors/) | [Modify Authentication Process](/tags/#modify-authentication-process)| Anomaly | -| [O365 New Federated Domain Added](/cloud/o365_new_federated_domain_added/) | [Cloud Account](/tags/#cloud-account), [Create Account](/tags/#create-account)| TTP | -| [O365 PST export alert](/cloud/o365_pst_export_alert/) | [Email Collection](/tags/#email-collection)| TTP | -| [O365 Suspicious Admin Email Forwarding](/cloud/o365_suspicious_admin_email_forwarding/) | [Email Forwarding Rule](/tags/#email-forwarding-rule), [Email Collection](/tags/#email-collection)| Anomaly | -| [O365 Suspicious Rights Delegation](/cloud/o365_suspicious_rights_delegation/) | [Remote Email Collection](/tags/#remote-email-collection), [Email Collection](/tags/#email-collection)| TTP | -| [O365 Suspicious User Email Forwarding](/cloud/o365_suspicious_user_email_forwarding/) | [Email Forwarding Rule](/tags/#email-forwarding-rule), [Email Collection](/tags/#email-collection)| Anomaly | -| [High Number of Login Failures from a single source](/cloud/high_number_of_login_failures_from_a_single_source/) | [Password Guessing](/tags/#password-guessing), [Brute Force](/tags/#brute-force)| Anomaly | - -#### Reference - -* [https://i.blackhat.com/USA-20/Thursday/us-20-Bienstock-My-Cloud-Is-APTs-Cloud-Investigating-And-Defending-Office-365.pdf](https://i.blackhat.com/USA-20/Thursday/us-20-Bienstock-My-Cloud-Is-APTs-Cloud-Investigating-And-Defending-Office-365.pdf) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/office_365_detections.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/orangeworm_attack_group.md b/docs/_stories/orangeworm_attack_group.md deleted file mode 100644 index d0bbd976c1..0000000000 --- a/docs/_stories/orangeworm_attack_group.md +++ /dev/null @@ -1,50 +0,0 @@ ---- -title: "Orangeworm Attack Group" -last_modified_at: 2020-01-22 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Actions on Objectives - - Command & Control - - Installation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Detect activities and various techniques associated with the Orangeworm Attack Group, a group that frequently targets the healthcare industry. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2020-01-22 -- **Author**: David Dorsey, Splunk -- **ID**: bb9f5ed2-916e-4364-bb6d-97c370efcf52 - -#### Narrative - -In May of 2018, the attack group Orangeworm was implicated for installing a custom backdoor called Trojan.Kwampirs within large international healthcare corporations in the United States, Europe, and Asia. This malware provides the attackers with remote access to the target system, decrypting and extracting a copy of its main DLL payload from its resource section. Before writing the payload to disk, it inserts a randomly generated string into the middle of the decrypted payload in an attempt to evade hash-based detections.\ -Awareness of the Orangeworm group first surfaced in January, 2015. It has conducted targeted attacks against related industries, as well, such as pharmaceuticals and healthcare IT solution providers.\ -Healthcare may be a promising target, because it is notoriously behind in technology, often using older operating systems and neglecting to patch computers. Even so, the group was able to evade detection for a full three years. Sources say that the malware spread quickly within the target networks, infecting computers used to control medical devices, such as MRI and X-ray machines.\ -This Analytic Story is designed to help you detect and investigate suspicious activities that may be indicative of an Orangeworm attack. One detection search looks for command-line arguments. Another monitors for uses of sc.exe, a non-essential Windows file that can manipulate Windows services. One of the investigative searches helps you get more information on web hosts that you suspect have been compromised. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [First time seen command line argument](/deprecated/first_time_seen_command_line_argument/) | [PowerShell](/tags/#powershell), [Windows Command Shell](/tags/#windows-command-shell)| Hunting | -| [Sc exe Manipulating Windows Services](/endpoint/sc_exe_manipulating_windows_services/) | [Windows Service](/tags/#windows-service), [Create or Modify System Process](/tags/#create-or-modify-system-process)| TTP | -| [First Time Seen Running Windows Service](/endpoint/first_time_seen_running_windows_service/) | [System Services](/tags/#system-services), [Service Execution](/tags/#service-execution)| Anomaly | - -#### Reference - -* [https://www.symantec.com/blogs/threat-intelligence/orangeworm-targets-healthcare-us-europe-asia](https://www.symantec.com/blogs/threat-intelligence/orangeworm-targets-healthcare-us-europe-asia) -* [https://www.infosecurity-magazine.com/news/healthcare-targeted-by-hacker/](https://www.infosecurity-magazine.com/news/healthcare-targeted-by-hacker/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/orangeworm_attack_group.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_stories/petitpotam_ntlm_relay_on_active_directory_certificate_services.md b/docs/_stories/petitpotam_ntlm_relay_on_active_directory_certificate_services.md deleted file mode 100644 index 16d2ac36ce..0000000000 --- a/docs/_stories/petitpotam_ntlm_relay_on_active_directory_certificate_services.md +++ /dev/null @@ -1,48 +0,0 @@ ---- -title: "PetitPotam NTLM Relay on Active Directory Certificate Services" -last_modified_at: 2021-08-31 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -PetitPotam (CVE-2021-36942,) is a vulnerablity identified in Microsofts EFSRPC Protocol that can allow an unauthenticated account to escalate privileges to domain administrator given the right circumstances. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: -- **Last Updated**: 2021-08-31 -- **Author**: Michael Haag, Mauricio Velazco, Splunk -- **ID**: 97aecafc-0a68-11ec-962f-acde48001122 - -#### Narrative - -In June 2021, security researchers at SpecterOps released a blog post and white paper detailing several potential attack vectors against Active Directory Certificated Services (ADCS). ADCS is a Microsoft product that implements Public Key Infrastrucutre (PKI) functionality and can be used by organizations to provide and manage digital certiticates within Active Directory.\ In July 2021, a security researcher released PetitPotam, a tool that allows attackers to coerce Windows systems into authenticating to arbitrary endpoints.\ Combining PetitPotam with the identified ADCS attack vectors allows attackers to escalate privileges from an unauthenticated anonymous user to full domain admin privileges. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [PetitPotam Network Share Access Request](/endpoint/petitpotam_network_share_access_request/) | [Forced Authentication](/tags/#forced-authentication)| TTP | -| [PetitPotam Suspicious Kerberos TGT Request](/endpoint/petitpotam_suspicious_kerberos_tgt_request/) | [OS Credential Dumping](/tags/#os-credential-dumping)| TTP | - -#### Reference - -* [https://us-cert.cisa.gov/ncas/current-activity/2021/07/27/microsoft-releases-guidance-mitigating-petitpotam-ntlm-relay](https://us-cert.cisa.gov/ncas/current-activity/2021/07/27/microsoft-releases-guidance-mitigating-petitpotam-ntlm-relay) -* [https://support.microsoft.com/en-us/topic/kb5005413-mitigating-ntlm-relay-attacks-on-active-directory-certificate-services-ad-cs-3612b773-4043-4aa9-b23d-b87910cd3429](https://support.microsoft.com/en-us/topic/kb5005413-mitigating-ntlm-relay-attacks-on-active-directory-certificate-services-ad-cs-3612b773-4043-4aa9-b23d-b87910cd3429) -* [https://www.specterops.io/assets/resources/Certified_Pre-Owned.pdf](https://www.specterops.io/assets/resources/Certified_Pre-Owned.pdf) -* [https://github.com/topotam/PetitPotam/](https://github.com/topotam/PetitPotam/) -* [https://github.com/gentilkiwi/mimikatz/releases/tag/2.2.0-20210723](https://github.com/gentilkiwi/mimikatz/releases/tag/2.2.0-20210723) -* [https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36942](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36942) -* [https://attack.mitre.org/techniques/T1187/](https://attack.mitre.org/techniques/T1187/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/petitpotam_ntlm_relay_on_active_directory_certificate_services.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/possible_backdoor_activity_associated_with_mudcarp_espionage_campaigns.md b/docs/_stories/possible_backdoor_activity_associated_with_mudcarp_espionage_campaigns.md deleted file mode 100644 index 035b4d45f7..0000000000 --- a/docs/_stories/possible_backdoor_activity_associated_with_mudcarp_espionage_campaigns.md +++ /dev/null @@ -1,75 +0,0 @@ ---- -title: "Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns" -last_modified_at: 2020-01-22 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Actions on Objectives - - Command & Control ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Monitor your environment for suspicious behaviors that resemble the techniques employed by the MUDCARP threat group. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2020-01-22 -- **Author**: iDefense Cyber Espionage Team, iDefense -- **ID**: 988C59C5-0A1C-45B6-A555-0C62276E327E - -#### Narrative - -This story was created as a joint effort between iDefense and Splunk.\ -iDefense analysts have recently discovered a Windows executable file that, upon execution, spoofs a decryption tool and then drops a file that appears to be the custom-built javascript backdoor, "Orz," which is associated with the threat actors known as MUDCARP (as well as "temp.Periscope" and "Leviathan"). The file is executed using Wscript.\ -The MUDCARP techniques include the use of the compressed-folders module from Microsoft, zipfldr.dll, with RouteTheCall export to run the malicious process or command. After a successful reboot, the malware is made persistent by a manipulating `[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]'help'='c:\\windows\\system32\\rundll32.exe c:\\windows\\system32\\zipfldr.dll,RouteTheCall c:\\programdata\\winapp.exe'`. Though this technique is not exclusive to MUDCARP, it has been spotted in the group's arsenal of advanced techniques seen in the wild.\ -This Analytic Story searches for evidence of tactics, techniques, and procedures (TTPs) that allow for the use of a endpoint detection-and-response (EDR) bypass technique to mask the true parent of a malicious process. It can also be set as a registry key for further sandbox evasion and to allow the malware to launch only after reboot.\ -If behavioral searches included in this story yield positive hits, iDefense recommends conducting IOC searches for the following:\ -\ -1. www.chemscalere[.]com\ -1. chemscalere[.]com\ -1. about.chemscalere[.]com\ -1. autoconfig.chemscalere[.]com\ -1. autodiscover.chemscalere[.]com\ -1. catalog.chemscalere[.]com\ -1. cpanel.chemscalere[.]com\ -1. db.chemscalere[.]com\ -1. ftp.chemscalere[.]com\ -1. mail.chemscalere[.]com\ -1. news.chemscalere[.]com\ -1. update.chemscalere[.]com\ -1. webmail.chemscalere[.]com\ -1. www.candlelightparty[.]org\ -1. candlelightparty[.]org\ -1. newapp.freshasianews[.]comIn addition, iDefense also recommends that organizations review their environments for activity related to the following hashes:\ -\ -1. cd195ee448a3657b5c2c2d13e9c7a2e2\ -1. b43ad826fe6928245d3c02b648296b43\ -1. 889a9b52566448231f112a5ce9b5dfaf\ -1. b8ec65dab97cdef3cd256cc4753f0c54\ -1. 04d83cd3813698de28cfbba326d7647c - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [First time seen command line argument](/deprecated/first_time_seen_command_line_argument/) | [PowerShell](/tags/#powershell), [Windows Command Shell](/tags/#windows-command-shell)| Hunting | -| [PowerShell - Connect To Internet With Hidden Window](/endpoint/powershell_-_connect_to_internet_with_hidden_window/) | [PowerShell](/tags/#powershell), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter)| Hunting | -| [Registry Keys Used For Persistence](/endpoint/registry_keys_used_for_persistence/) | [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution)| TTP | -| [Unusually Long Command Line](/endpoint/unusually_long_command_line/) | None| Anomaly | -| [Unusually Long Command Line - MLTK](/endpoint/unusually_long_command_line_-_mltk/) | None| Anomaly | - -#### Reference - -* [https://www.infosecurity-magazine.com/news/scope-of-mudcarp-attacks-highlight-1/](https://www.infosecurity-magazine.com/news/scope-of-mudcarp-attacks-highlight-1/) -* [http://blog.amossys.fr/badflick-is-not-so-bad.html](http://blog.amossys.fr/badflick-is-not-so-bad.html) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/possible_backdoor_activity_associated_with_mudcarp_espionage_campaigns.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/printnightmare_cve-2021-34527.md b/docs/_stories/printnightmare_cve-2021-34527.md deleted file mode 100644 index c54e58d307..0000000000 --- a/docs/_stories/printnightmare_cve-2021-34527.md +++ /dev/null @@ -1,59 +0,0 @@ ---- -title: "PrintNightmare CVE-2021-34527" -last_modified_at: 2021-07-01 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Actions on Objectives - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -The following analytic story identifies behaviors related PrintNightmare, or CVE-2021-34527 previously known as (CVE-2021-1675), to gain privilege escalation on the vulnerable machine. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-07-01 -- **Author**: Splunk Threat Research Team -- **ID**: fd79470a-da88-11eb-b803-acde48001122 - -#### Narrative - -This vulnerability affects the Print Spooler service, enabled by default on Windows systems, and allows adversaries to trick this service into installing a remotely hosted print driver using a low privileged user account. Successful exploitation effectively allows adversaries to execute code in the target system (Remote Code Execution) in the context of the Print Spooler service which runs with the highest privileges (Privilege Escalation). \ -The prerequisites for successful exploitation consist of: \ -1. Print Spooler service enabled on the target system \ -1. Network connectivity to the target system (initial access has been obtained) \ -1. Hash or password for a low privileged user ( or computer ) account. \ -In the most impactful scenario, an attacker would be able to leverage this vulnerability to obtain a SYSTEM shell on a domain controller and so escalate their privileges from a low privileged domain account to full domain access in the target environment as shown below. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Print Spooler Adding A Printer Driver](/endpoint/print_spooler_adding_a_printer_driver/) | [Print Processors](/tags/#print-processors), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution)| TTP | -| [Print Spooler Failed to Load a Plug-in](/endpoint/print_spooler_failed_to_load_a_plug-in/) | [Print Processors](/tags/#print-processors), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution)| TTP | -| [Rundll32 with no Command Line Arguments with Network](/endpoint/rundll32_with_no_command_line_arguments_with_network/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Rundll32](/tags/#rundll32)| TTP | -| [Spoolsv Spawning Rundll32](/endpoint/spoolsv_spawning_rundll32/) | [Print Processors](/tags/#print-processors), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution)| TTP | -| [Spoolsv Suspicious Loaded Modules](/endpoint/spoolsv_suspicious_loaded_modules/) | [Print Processors](/tags/#print-processors), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution)| TTP | -| [Spoolsv Suspicious Process Access](/endpoint/spoolsv_suspicious_process_access/) | [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation)| TTP | -| [Spoolsv Writing a DLL](/endpoint/spoolsv_writing_a_dll/) | [Print Processors](/tags/#print-processors), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution)| TTP | -| [Spoolsv Writing a DLL - Sysmon](/endpoint/spoolsv_writing_a_dll_-_sysmon/) | [Print Processors](/tags/#print-processors), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution)| TTP | -| [Suspicious Rundll32 no Command Line Arguments](/endpoint/suspicious_rundll32_no_command_line_arguments/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Rundll32](/tags/#rundll32)| TTP | - -#### Reference - -* [https://github.com/cube0x0/CVE-2021-1675/](https://github.com/cube0x0/CVE-2021-1675/) -* [https://blog.truesec.com/2021/06/30/fix-for-printnightmare-cve-2021-1675-exploit-to-keep-your-print-servers-running-while-a-patch-is-not-available/](https://blog.truesec.com/2021/06/30/fix-for-printnightmare-cve-2021-1675-exploit-to-keep-your-print-servers-running-while-a-patch-is-not-available/) -* [https://blog.truesec.com/2021/06/30/exploitable-critical-rce-vulnerability-allows-regular-users-to-fully-compromise-active-directory-printnightmare-cve-2021-1675/](https://blog.truesec.com/2021/06/30/exploitable-critical-rce-vulnerability-allows-regular-users-to-fully-compromise-active-directory-printnightmare-cve-2021-1675/) -* [https://www.reddit.com/r/msp/comments/ob6y02/critical_vulnerability_printnightmare_exposes](https://www.reddit.com/r/msp/comments/ob6y02/critical_vulnerability_printnightmare_exposes) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/printnightmare_cve-2021-34527.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/prohibited_traffic_allowed_or_protocol_mismatch.md b/docs/_stories/prohibited_traffic_allowed_or_protocol_mismatch.md deleted file mode 100644 index 0424770478..0000000000 --- a/docs/_stories/prohibited_traffic_allowed_or_protocol_mismatch.md +++ /dev/null @@ -1,53 +0,0 @@ ---- -title: "Prohibited Traffic Allowed or Protocol Mismatch" -last_modified_at: 2017-09-11 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Network_Resolution - - Network_Traffic - - Actions on Objectives - - Command & Control - - Delivery - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Detect instances of prohibited network traffic allowed in the environment, as well as protocols running on non-standard ports. Both of these types of behaviors typically violate policy and can be leveraged by attackers. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint), [Network_Resolution](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkResolution), [Network_Traffic](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkTraffic) -- **Last Updated**: 2017-09-11 -- **Author**: Rico Valdez, Splunk -- **ID**: 6d13121c-90f3-446d-8ac3-27efbbc65218 - -#### Narrative - -A traditional security best practice is to control the ports, protocols, and services allowed within your environment. By limiting the services and protocols to those explicitly approved by policy, administrators can minimize the attack surface. The combined effect allows both network defenders and security controls to focus and not be mired in superfluous traffic or data types. Looking for deviations to policy can identify attacker activity that abuses services and protocols to run on alternate or non-standard ports in the attempt to avoid detection or frustrate forensic analysts. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Allow Inbound Traffic By Firewall Rule Registry](/endpoint/allow_inbound_traffic_by_firewall_rule_registry/) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol), [Remote Services](/tags/#remote-services)| TTP | -| [Allow Inbound Traffic In Firewall Rule](/endpoint/allow_inbound_traffic_in_firewall_rule/) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol), [Remote Services](/tags/#remote-services)| TTP | -| [Enable RDP In Other Port Number](/endpoint/enable_rdp_in_other_port_number/) | [Remote Services](/tags/#remote-services)| TTP | -| [Prohibited Network Traffic Allowed](/network/prohibited_network_traffic_allowed/) | [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol)| TTP | -| [Protocol or Port Mismatch](/network/protocol_or_port_mismatch/) | [Exfiltration Over Unencrypted Non-C2 Protocol](/tags/#exfiltration-over-unencrypted-non-c2-protocol), [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol)| Anomaly | -| [TOR Traffic](/network/tor_traffic/) | [Application Layer Protocol](/tags/#application-layer-protocol), [Web Protocols](/tags/#web-protocols)| TTP | -| [Detect hosts connecting to dynamic domain providers](/network/detect_hosts_connecting_to_dynamic_domain_providers/) | [Drive-by Compromise](/tags/#drive-by-compromise)| TTP | - -#### Reference - -* [http://www.novetta.com/2015/02/advanced-methods-to-detect-advanced-cyber-attacks-protocol-abuse/](http://www.novetta.com/2015/02/advanced-methods-to-detect-advanced-cyber-attacks-protocol-abuse/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/prohibited_traffic_allowed_or_protocol_mismatch.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/proxyshell.md b/docs/_stories/proxyshell.md deleted file mode 100644 index c4f382c5f1..0000000000 --- a/docs/_stories/proxyshell.md +++ /dev/null @@ -1,51 +0,0 @@ ---- -title: "ProxyShell" -last_modified_at: 2021-08-24 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Exploitation - - Reconnaissance ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -ProxyShell is a chain of exploits targeting on-premise Microsoft Exchange Server - CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-08-24 -- **Author**: Michael Haag, Teoderick Contreras, Mauricio Velazco, Splunk -- **ID**: 413bb68e-04e2-11ec-a835-acde48001122 - -#### Narrative - -During Pwn2Own April 2021, a security researcher demonstrated an attack chain targeting on-premise Microsoft Exchange Server. August 5th, the same researcher publicly released further details and demonstrated the attack chain. CVE-2021-34473 Pre-auth path confusion leads to ACL Bypass (Patched in April by KB5001779) CVE-2021-34523 - Elevation of privilege on Exchange PowerShell backend (Patched in April by KB5001779) . CVE-2021-31207 - Post-auth Arbitrary-File-Write leads to RCE (Patched in May by KB5003435) Upon successful exploitation, the remote attacker will have SYSTEM privileges on the Exchange Server. In addition to remote access/execution, the adversary may be able to run Exchange PowerShell Cmdlets to perform further actions. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Detect Exchange Web Shell](/endpoint/detect_exchange_web_shell/) | [Server Software Component](/tags/#server-software-component), [Web Shell](/tags/#web-shell), [Exploit Public-Facing Application](/tags/#exploit-public-facing-application)| TTP | -| [W3WP Spawning Shell](/endpoint/w3wp_spawning_shell/) | [Server Software Component](/tags/#server-software-component), [Web Shell](/tags/#web-shell)| TTP | -| [Exchange PowerShell Abuse via SSRF](/endpoint/exchange_powershell_abuse_via_ssrf/) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application)| TTP | -| [Exchange PowerShell Module Usage](/endpoint/exchange_powershell_module_usage/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell)| TTP | -| [MS Exchange Mailbox Replication service writing Active Server Pages](/endpoint/ms_exchange_mailbox_replication_service_writing_active_server_pages/) | [Server Software Component](/tags/#server-software-component), [Web Shell](/tags/#web-shell), [Exploit Public-Facing Application](/tags/#exploit-public-facing-application)| TTP | - -#### Reference - -* [https://y4y.space/2021/08/12/my-steps-of-reproducing-proxyshell/](https://y4y.space/2021/08/12/my-steps-of-reproducing-proxyshell/) -* [https://www.zerodayinitiative.com/blog/2021/8/17/from-pwn2own-2021-a-new-attack-surface-on-microsoft-exchange-proxyshell](https://www.zerodayinitiative.com/blog/2021/8/17/from-pwn2own-2021-a-new-attack-surface-on-microsoft-exchange-proxyshell) -* [https://www.youtube.com/watch?v=FC6iHw258RI](https://www.youtube.com/watch?v=FC6iHw258RI) -* [https://www.huntress.com/blog/rapid-response-microsoft-exchange-servers-still-vulnerable-to-proxyshell-exploit#what-should-you-do](https://www.huntress.com/blog/rapid-response-microsoft-exchange-servers-still-vulnerable-to-proxyshell-exploit#what-should-you-do) -* [https://i.blackhat.com/USA21/Wednesday-Handouts/us-21-ProxyLogon-Is-Just-The-Tip-Of-The-Iceberg-A-New-Attack-Surface-On-Microsoft-Exchange-Server.pdf](https://i.blackhat.com/USA21/Wednesday-Handouts/us-21-ProxyLogon-Is-Just-The-Tip-Of-The-Iceberg-A-New-Attack-Surface-On-Microsoft-Exchange-Server.pdf) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/proxyshell.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/ransomware.md b/docs/_stories/ransomware.md deleted file mode 100644 index ece4ff2fdd..0000000000 --- a/docs/_stories/ransomware.md +++ /dev/null @@ -1,124 +0,0 @@ ---- -title: "Ransomware" -last_modified_at: 2020-02-04 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Network_Traffic - - Actions on Objectives - - Command & Control - - Delivery - - Exploitation - - Reconnaissance ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Leverage searches that allow you to detect and investigate unusual activities that might relate to ransomware--spikes in SMB traffic, suspicious wevtutil usage, the presence of common ransomware extensions, and system processes run from unexpected locations, and many others. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint), [Network_Traffic](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkTraffic) -- **Last Updated**: 2020-02-04 -- **Author**: David Dorsey, Splunk -- **ID**: cf309d0d-d4aa-4fbb-963d-1e79febd3756 - -#### Narrative - -Ransomware is an ever-present risk to the enterprise, wherein an infected host encrypts business-critical data, holding it hostage until the victim pays the attacker a ransom. There are many types and varieties of ransomware that can affect an enterprise. Attackers can deploy ransomware to enterprises through spearphishing campaigns and driveby downloads, as well as through traditional remote service-based exploitation. In the case of the WannaCry campaign, there was self-propagating wormable functionality that was used to maximize infection. Fortunately, organizations can apply several techniques--such as those in this Analytic Story--to detect and or mitigate the effects of ransomware. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Scheduled tasks used in BadRabbit ransomware](/deprecated/scheduled_tasks_used_in_badrabbit_ransomware/) | [Scheduled Task](/tags/#scheduled-task)| TTP | -| [7zip CommandLine To SMB Share Path](/endpoint/7zip_commandline_to_smb_share_path/) | [Archive via Utility](/tags/#archive-via-utility), [Archive Collected Data](/tags/#archive-collected-data)| Hunting | -| [Allow File And Printing Sharing In Firewall](/endpoint/allow_file_and_printing_sharing_in_firewall/) | [Disable or Modify Cloud Firewall](/tags/#disable-or-modify-cloud-firewall), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Allow Network Discovery In Firewall](/endpoint/allow_network_discovery_in_firewall/) | [Disable or Modify Cloud Firewall](/tags/#disable-or-modify-cloud-firewall), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Allow Operation with Consent Admin](/endpoint/allow_operation_with_consent_admin/) | [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism)| TTP | -| [BCDEdit Failure Recovery Modification](/endpoint/bcdedit_failure_recovery_modification/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery)| TTP | -| [Clear Unallocated Sector Using Cipher App](/endpoint/clear_unallocated_sector_using_cipher_app/) | [File Deletion](/tags/#file-deletion), [Indicator Removal on Host](/tags/#indicator-removal-on-host)| TTP | -| [CMLUA Or CMSTPLUA UAC Bypass](/endpoint/cmlua_or_cmstplua_uac_bypass/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [CMSTP](/tags/#cmstp)| TTP | -| [Common Ransomware Extensions](/endpoint/common_ransomware_extensions/) | [Data Destruction](/tags/#data-destruction)| Hunting | -| [Common Ransomware Notes](/endpoint/common_ransomware_notes/) | [Data Destruction](/tags/#data-destruction)| Hunting | -| [Conti Common Exec parameter](/endpoint/conti_common_exec_parameter/) | [User Execution](/tags/#user-execution)| TTP | -| [Delete ShadowCopy With PowerShell](/endpoint/delete_shadowcopy_with_powershell/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery)| TTP | -| [Deleting Shadow Copies](/endpoint/deleting_shadow_copies/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery)| TTP | -| [Detect RClone Command-Line Usage](/endpoint/detect_rclone_command-line_usage/) | [Automated Exfiltration](/tags/#automated-exfiltration)| TTP | -| [Detect Renamed RClone](/endpoint/detect_renamed_rclone/) | [Automated Exfiltration](/tags/#automated-exfiltration)| Hunting | -| [Detect SharpHound Command-Line Arguments](/endpoint/detect_sharphound_command-line_arguments/) | [Domain Account](/tags/#domain-account), [Local Groups](/tags/#local-groups), [Domain Trust Discovery](/tags/#domain-trust-discovery), [Local Account](/tags/#local-account), [Account Discovery](/tags/#account-discovery), [Domain Groups](/tags/#domain-groups), [Permission Groups Discovery](/tags/#permission-groups-discovery)| TTP | -| [Detect SharpHound File Modifications](/endpoint/detect_sharphound_file_modifications/) | [Domain Account](/tags/#domain-account), [Local Groups](/tags/#local-groups), [Domain Trust Discovery](/tags/#domain-trust-discovery), [Local Account](/tags/#local-account), [Account Discovery](/tags/#account-discovery), [Domain Groups](/tags/#domain-groups), [Permission Groups Discovery](/tags/#permission-groups-discovery)| TTP | -| [Detect SharpHound Usage](/endpoint/detect_sharphound_usage/) | [Domain Account](/tags/#domain-account), [Local Groups](/tags/#local-groups), [Domain Trust Discovery](/tags/#domain-trust-discovery), [Local Account](/tags/#local-account), [Account Discovery](/tags/#account-discovery), [Domain Groups](/tags/#domain-groups), [Permission Groups Discovery](/tags/#permission-groups-discovery)| TTP | -| [Disable AMSI Through Registry](/endpoint/disable_amsi_through_registry/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Disable ETW Through Registry](/endpoint/disable_etw_through_registry/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Disable Logs Using WevtUtil](/endpoint/disable_logs_using_wevtutil/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host), [Clear Windows Event Logs](/tags/#clear-windows-event-logs)| TTP | -| [Disable Windows Behavior Monitoring](/endpoint/disable_windows_behavior_monitoring/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Excessive Service Stop Attempt](/endpoint/excessive_service_stop_attempt/) | [Service Stop](/tags/#service-stop)| Anomaly | -| [Excessive Usage Of Net App](/endpoint/excessive_usage_of_net_app/) | [Account Access Removal](/tags/#account-access-removal)| Anomaly | -| [Excessive Usage Of SC Service Utility](/endpoint/excessive_usage_of_sc_service_utility/) | [System Services](/tags/#system-services), [Service Execution](/tags/#service-execution)| Anomaly | -| [Execute Javascript With Jscript COM CLSID](/endpoint/execute_javascript_with_jscript_com_clsid/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Visual Basic](/tags/#visual-basic)| TTP | -| [Fsutil Zeroing File](/endpoint/fsutil_zeroing_file/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host)| TTP | -| [ICACLS Grant Command](/endpoint/icacls_grant_command/) | [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification)| TTP | -| [Known Services Killed by Ransomware](/endpoint/known_services_killed_by_ransomware/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery)| TTP | -| [Modification Of Wallpaper](/endpoint/modification_of_wallpaper/) | [Defacement](/tags/#defacement)| TTP | -| [Msmpeng Application DLL Side Loading](/endpoint/msmpeng_application_dll_side_loading/) | [DLL Side-Loading](/tags/#dll-side-loading), [Hijack Execution Flow](/tags/#hijack-execution-flow)| TTP | -| [Permission Modification using Takeown App](/endpoint/permission_modification_using_takeown_app/) | [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification)| TTP | -| [Powershell Disable Security Monitoring](/endpoint/powershell_disable_security_monitoring/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Powershell Enable SMB1Protocol Feature](/endpoint/powershell_enable_smb1protocol_feature/) | [Obfuscated Files or Information](/tags/#obfuscated-files-or-information), [Indicator Removal from Tools](/tags/#indicator-removal-from-tools)| TTP | -| [Powershell Execute COM Object](/endpoint/powershell_execute_com_object/) | [Component Object Model Hijacking](/tags/#component-object-model-hijacking), [Event Triggered Execution](/tags/#event-triggered-execution), [PowerShell](/tags/#powershell)| TTP | -| [Prevent Automatic Repair Mode using Bcdedit](/endpoint/prevent_automatic_repair_mode_using_bcdedit/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery)| TTP | -| [Recon AVProduct Through Pwh or WMI](/endpoint/recon_avproduct_through_pwh_or_wmi/) | [Gather Victim Host Information](/tags/#gather-victim-host-information)| TTP | -| [Recursive Delete of Directory In Batch CMD](/endpoint/recursive_delete_of_directory_in_batch_cmd/) | [File Deletion](/tags/#file-deletion), [Indicator Removal on Host](/tags/#indicator-removal-on-host)| TTP | -| [Registry Keys Used For Persistence](/endpoint/registry_keys_used_for_persistence/) | [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution)| TTP | -| [Remote Process Instantiation via WMI](/endpoint/remote_process_instantiation_via_wmi/) | [Windows Management Instrumentation](/tags/#windows-management-instrumentation)| TTP | -| [Revil Common Exec Parameter](/endpoint/revil_common_exec_parameter/) | [User Execution](/tags/#user-execution)| TTP | -| [Revil Registry Entry](/endpoint/revil_registry_entry/) | [Modify Registry](/tags/#modify-registry)| TTP | -| [Rundll32 LockWorkStation](/endpoint/rundll32_lockworkstation/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Rundll32](/tags/#rundll32)| Anomaly | -| [Schtasks used for forcing a reboot](/endpoint/schtasks_used_for_forcing_a_reboot/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job)| TTP | -| [Suspicious Event Log Service Behavior](/endpoint/suspicious_event_log_service_behavior/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host), [Clear Windows Event Logs](/tags/#clear-windows-event-logs)| TTP | -| [Suspicious Scheduled Task from Public Directory](/endpoint/suspicious_scheduled_task_from_public_directory/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job)| Anomaly | -| [Suspicious wevtutil Usage](/endpoint/suspicious_wevtutil_usage/) | [Clear Windows Event Logs](/tags/#clear-windows-event-logs), [Indicator Removal on Host](/tags/#indicator-removal-on-host)| TTP | -| [System Processes Run From Unexpected Locations](/endpoint/system_processes_run_from_unexpected_locations/) | [Masquerading](/tags/#masquerading), [Rename System Utilities](/tags/#rename-system-utilities)| TTP | -| [UAC Bypass With Colorui COM Object](/endpoint/uac_bypass_with_colorui_com_object/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [CMSTP](/tags/#cmstp)| TTP | -| [Uninstall App Using MsiExec](/endpoint/uninstall_app_using_msiexec/) | [Msiexec](/tags/#msiexec), [System Binary Proxy Execution](/tags/#system-binary-proxy-execution)| TTP | -| [USN Journal Deletion](/endpoint/usn_journal_deletion/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host)| TTP | -| [WBAdmin Delete System Backups](/endpoint/wbadmin_delete_system_backups/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery)| TTP | -| [Wbemprox COM Object Execution](/endpoint/wbemprox_com_object_execution/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [CMSTP](/tags/#cmstp)| TTP | -| [Windows Disable Change Password Through Registry](/endpoint/windows_disable_change_password_through_registry/) | [Modify Registry](/tags/#modify-registry)| Anomaly | -| [Windows Disable Lock Workstation Feature Through Registry](/endpoint/windows_disable_lock_workstation_feature_through_registry/) | [Modify Registry](/tags/#modify-registry)| Anomaly | -| [Windows Disable LogOff Button Through Registry](/endpoint/windows_disable_logoff_button_through_registry/) | [Modify Registry](/tags/#modify-registry)| Anomaly | -| [Windows Disable Memory Crash Dump](/endpoint/windows_disable_memory_crash_dump/) | [Data Destruction](/tags/#data-destruction)| TTP | -| [Windows Disable Shutdown Button Through Registry](/endpoint/windows_disable_shutdown_button_through_registry/) | [Modify Registry](/tags/#modify-registry)| Anomaly | -| [Windows Disable Windows Group Policy Features Through Registry](/endpoint/windows_disable_windows_group_policy_features_through_registry/) | [Modify Registry](/tags/#modify-registry)| Anomaly | -| [Windows DiskCryptor Usage](/endpoint/windows_diskcryptor_usage/) | [Data Encrypted for Impact](/tags/#data-encrypted-for-impact)| Hunting | -| [Windows DotNet Binary in Non Standard Path](/endpoint/windows_dotnet_binary_in_non_standard_path/) | [Masquerading](/tags/#masquerading), [Rename System Utilities](/tags/#rename-system-utilities), [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [InstallUtil](/tags/#installutil)| TTP | -| [Windows Event Log Cleared](/endpoint/windows_event_log_cleared/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host), [Clear Windows Event Logs](/tags/#clear-windows-event-logs)| TTP | -| [Windows Hide Notification Features Through Registry](/endpoint/windows_hide_notification_features_through_registry/) | [Modify Registry](/tags/#modify-registry)| Anomaly | -| [Windows InstallUtil in Non Standard Path](/endpoint/windows_installutil_in_non_standard_path/) | [Masquerading](/tags/#masquerading), [Rename System Utilities](/tags/#rename-system-utilities), [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [InstallUtil](/tags/#installutil)| TTP | -| [Windows NirSoft AdvancedRun](/endpoint/windows_nirsoft_advancedrun/) | [Tool](/tags/#tool)| TTP | -| [Windows Raccine Scheduled Task Deletion](/endpoint/windows_raccine_scheduled_task_deletion/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools)| TTP | -| [Windows Registry Modification for Safe Mode Persistence](/endpoint/windows_registry_modification_for_safe_mode_persistence/) | [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution)| TTP | -| [WinEvent Scheduled Task Created to Spawn Shell](/endpoint/winevent_scheduled_task_created_to_spawn_shell/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job)| TTP | -| [WinEvent Scheduled Task Created Within Public Path](/endpoint/winevent_scheduled_task_created_within_public_path/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job)| TTP | -| [MS Exchange Mailbox Replication service writing Active Server Pages](/endpoint/ms_exchange_mailbox_replication_service_writing_active_server_pages/) | [Server Software Component](/tags/#server-software-component), [Web Shell](/tags/#web-shell), [Exploit Public-Facing Application](/tags/#exploit-public-facing-application)| TTP | -| [Spike in File Writes](/endpoint/spike_in_file_writes/) | None| Anomaly | -| [Unusually Long Command Line](/endpoint/unusually_long_command_line/) | None| Anomaly | -| [Unusually Long Command Line - MLTK](/endpoint/unusually_long_command_line_-_mltk/) | None| Anomaly | -| [Prohibited Network Traffic Allowed](/network/prohibited_network_traffic_allowed/) | [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol)| TTP | -| [SMB Traffic Spike](/network/smb_traffic_spike/) | [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares), [Remote Services](/tags/#remote-services)| Anomaly | -| [SMB Traffic Spike - MLTK](/network/smb_traffic_spike_-_mltk/) | [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares), [Remote Services](/tags/#remote-services)| Anomaly | -| [TOR Traffic](/network/tor_traffic/) | [Application Layer Protocol](/tags/#application-layer-protocol), [Web Protocols](/tags/#web-protocols)| TTP | - -#### Reference - -* [https://web.archive.org/web/20190826231258/https://www.carbonblack.com/2017/06/28/carbon-black-threat-research-technical-analysis-petya-notpetya-ransomware/](https://web.archive.org/web/20190826231258/https://www.carbonblack.com/2017/06/28/carbon-black-threat-research-technical-analysis-petya-notpetya-ransomware/) -* [https://www.splunk.com/blog/2017/06/27/closing-the-detection-to-mitigation-gap-or-to-petya-or-notpetya-whocares-.html](https://www.splunk.com/blog/2017/06/27/closing-the-detection-to-mitigation-gap-or-to-petya-or-notpetya-whocares-.html) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/ransomware.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/ransomware_cloud.md b/docs/_stories/ransomware_cloud.md deleted file mode 100644 index 62f4b76f05..0000000000 --- a/docs/_stories/ransomware_cloud.md +++ /dev/null @@ -1,45 +0,0 @@ ---- -title: "Ransomware Cloud" -last_modified_at: 2020-10-27 -toc: true -toc_label: "" -tags: - - Splunk Security Analytics for AWS - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Leverage searches that allow you to detect and investigate unusual activities that might relate to ransomware. These searches include cloud related objects that may be targeted by malicious actors via cloud providers own encryption features. - -- **Product**: Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: -- **Last Updated**: 2020-10-27 -- **Author**: Rod Soto, David Dorsey, Splunk -- **ID**: f52f6c43-05f8-4b19-a9d3-5b8c56da91c2 - -#### Narrative - -Ransomware is an ever-present risk to the enterprise, wherein an infected host encrypts business-critical data, holding it hostage until the victim pays the attacker a ransom. There are many types and varieties of ransomware that can affect an enterprise.Cloud ransomware can be deployed by obtaining high privilege credentials from targeted users or resources. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [AWS Detect Users creating keys with encrypt policy without MFA](/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa/) | [Data Encrypted for Impact](/tags/#data-encrypted-for-impact)| TTP | -| [AWS Detect Users with KMS keys performing encryption S3](/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3/) | [Data Encrypted for Impact](/tags/#data-encrypted-for-impact)| Anomaly | - -#### Reference - -* [https://rhinosecuritylabs.com/aws/s3-ransomware-part-1-attack-vector/](https://rhinosecuritylabs.com/aws/s3-ransomware-part-1-attack-vector/) -* [https://github.com/d1vious/git-wild-hunt](https://github.com/d1vious/git-wild-hunt) -* [https://www.youtube.com/watch?v=PgzNib37g0M](https://www.youtube.com/watch?v=PgzNib37g0M) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/ransomware_cloud.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/remcos.md b/docs/_stories/remcos.md deleted file mode 100644 index 2c7fd4b3eb..0000000000 --- a/docs/_stories/remcos.md +++ /dev/null @@ -1,71 +0,0 @@ ---- -title: "Remcos" -last_modified_at: 2021-09-23 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Actions on Objectives - - Exploitation - - Reconnaissance ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Leverage searches that allow you to detect and investigate unusual activities that might relate to the Remcos RAT trojan, including looking for file writes associated with its payload, screencapture, registry modification, UAC bypassed, persistence and data collection.. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-09-23 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 2bd4aa08-b9a5-40cf-bfe5-7d43f13d496c - -#### Narrative - -Remcos or Remote Control and Surveillance, marketed as a legitimate software for remotely managing Windows systems is now widely used in multiple malicious campaigns both APT and commodity malware by threat actors. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Add or Set Windows Defender Exclusion](/endpoint/add_or_set_windows_defender_exclusion/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Disabling Remote User Account Control](/endpoint/disabling_remote_user_account_control/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism)| TTP | -| [Executables Or Script Creation In Suspicious Path](/endpoint/executables_or_script_creation_in_suspicious_path/) | [Masquerading](/tags/#masquerading)| TTP | -| [Jscript Execution Using Cscript App](/endpoint/jscript_execution_using_cscript_app/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [JavaScript](/tags/#javascript)| TTP | -| [Loading Of Dynwrapx Module](/endpoint/loading_of_dynwrapx_module/) | [Process Injection](/tags/#process-injection), [Dynamic-link Library Injection](/tags/#dynamic-link-library-injection)| TTP | -| [Malicious InProcServer32 Modification](/endpoint/malicious_inprocserver32_modification/) | [Regsvr32](/tags/#regsvr32), [Modify Registry](/tags/#modify-registry)| TTP | -| [Non Chrome Process Accessing Chrome Default Dir](/endpoint/non_chrome_process_accessing_chrome_default_dir/) | [Credentials from Password Stores](/tags/#credentials-from-password-stores), [Credentials from Web Browsers](/tags/#credentials-from-web-browsers)| Anomaly | -| [Non Firefox Process Access Firefox Profile Dir](/endpoint/non_firefox_process_access_firefox_profile_dir/) | [Credentials from Password Stores](/tags/#credentials-from-password-stores), [Credentials from Web Browsers](/tags/#credentials-from-web-browsers)| Anomaly | -| [Possible Browser Pass View Parameter](/endpoint/possible_browser_pass_view_parameter/) | [Credentials from Web Browsers](/tags/#credentials-from-web-browsers), [Credentials from Password Stores](/tags/#credentials-from-password-stores)| Hunting | -| [Powershell Windows Defender Exclusion Commands](/endpoint/powershell_windows_defender_exclusion_commands/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Process Deleting Its Process File Path](/endpoint/process_deleting_its_process_file_path/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host)| TTP | -| [Process Writing DynamicWrapperX](/endpoint/process_writing_dynamicwrapperx/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Component Object Model](/tags/#component-object-model)| Hunting | -| [Registry Keys Used For Persistence](/endpoint/registry_keys_used_for_persistence/) | [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution)| TTP | -| [Regsvr32 Silent and Install Param Dll Loading](/endpoint/regsvr32_silent_and_install_param_dll_loading/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Regsvr32](/tags/#regsvr32)| Anomaly | -| [Regsvr32 with Known Silent Switch Cmdline](/endpoint/regsvr32_with_known_silent_switch_cmdline/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Regsvr32](/tags/#regsvr32)| Anomaly | -| [Remcos client registry install entry](/endpoint/remcos_client_registry_install_entry/) | [Modify Registry](/tags/#modify-registry)| TTP | -| [Remcos RAT File Creation in Remcos Folder](/endpoint/remcos_rat_file_creation_in_remcos_folder/) | [Screen Capture](/tags/#screen-capture)| TTP | -| [Suspicious Image Creation In Appdata Folder](/endpoint/suspicious_image_creation_in_appdata_folder/) | [Screen Capture](/tags/#screen-capture)| TTP | -| [Suspicious Process DNS Query Known Abuse Web Services](/endpoint/suspicious_process_dns_query_known_abuse_web_services/) | [Visual Basic](/tags/#visual-basic), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter)| TTP | -| [Suspicious Process File Path](/endpoint/suspicious_process_file_path/) | [Create or Modify System Process](/tags/#create-or-modify-system-process)| TTP | -| [Suspicious WAV file in Appdata Folder](/endpoint/suspicious_wav_file_in_appdata_folder/) | [Screen Capture](/tags/#screen-capture)| TTP | -| [System Info Gathering Using Dxdiag Application](/endpoint/system_info_gathering_using_dxdiag_application/) | [Gather Victim Host Information](/tags/#gather-victim-host-information)| Hunting | -| [Vbscript Execution Using Wscript App](/endpoint/vbscript_execution_using_wscript_app/) | [Visual Basic](/tags/#visual-basic), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter)| TTP | -| [Windows Defender Exclusion Registry Entry](/endpoint/windows_defender_exclusion_registry_entry/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Winhlp32 Spawning a Process](/endpoint/winhlp32_spawning_a_process/) | [Process Injection](/tags/#process-injection)| TTP | -| [Wscript Or Cscript Suspicious Child Process](/endpoint/wscript_or_cscript_suspicious_child_process/) | [Process Injection](/tags/#process-injection), [Create or Modify System Process](/tags/#create-or-modify-system-process), [Parent PID Spoofing](/tags/#parent-pid-spoofing), [Access Token Manipulation](/tags/#access-token-manipulation)| TTP | - -#### Reference - -* [https://success.trendmicro.com/solution/1123281-remcos-malware-information](https://success.trendmicro.com/solution/1123281-remcos-malware-information) -* [https://attack.mitre.org/software/S0332/](https://attack.mitre.org/software/S0332/) -* [https://malpedia.caad.fkie.fraunhofer.de/details/win.remcos#:~:text=Remcos%20(acronym%20of%20Remote%20Control,used%20to%20remotely%20control%20computers.&text=Remcos%20can%20be%20used%20for,been%20used%20in%20hacking%20campaigns.](https://malpedia.caad.fkie.fraunhofer.de/details/win.remcos#:~:text=Remcos%20(acronym%20of%20Remote%20Control,used%20to%20remotely%20control%20computers.&text=Remcos%20can%20be%20used%20for,been%20used%20in%20hacking%20campaigns.) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/remcos.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/revil_ransomware.md b/docs/_stories/revil_ransomware.md deleted file mode 100644 index be227dbe79..0000000000 --- a/docs/_stories/revil_ransomware.md +++ /dev/null @@ -1,51 +0,0 @@ ---- -title: "Revil Ransomware" -last_modified_at: 2021-06-04 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Leverage searches that allow you to detect and investigate unusual activities that might relate to the Revil ransomware, including looking for file writes associated with Revil, encrypting network shares, deleting shadow volume storage, registry key modification, deleting of security logs, and more. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-06-04 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 817cae42-f54b-457a-8a36-fbf45521e29e - -#### Narrative - -Revil ransomware is a RaaS,that a single group may operates and manges the development of this ransomware. It involve the use of ransomware payloads along with exfiltration of data. Malicious actors demand payment for ransome of data and threaten deletion and exposure of exfiltrated data. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Allow Network Discovery In Firewall](/endpoint/allow_network_discovery_in_firewall/) | [Disable or Modify Cloud Firewall](/tags/#disable-or-modify-cloud-firewall), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Delete ShadowCopy With PowerShell](/endpoint/delete_shadowcopy_with_powershell/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery)| TTP | -| [Disable Windows Behavior Monitoring](/endpoint/disable_windows_behavior_monitoring/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Modification Of Wallpaper](/endpoint/modification_of_wallpaper/) | [Defacement](/tags/#defacement)| TTP | -| [Msmpeng Application DLL Side Loading](/endpoint/msmpeng_application_dll_side_loading/) | [DLL Side-Loading](/tags/#dll-side-loading), [Hijack Execution Flow](/tags/#hijack-execution-flow)| TTP | -| [Powershell Disable Security Monitoring](/endpoint/powershell_disable_security_monitoring/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Revil Common Exec Parameter](/endpoint/revil_common_exec_parameter/) | [User Execution](/tags/#user-execution)| TTP | -| [Revil Registry Entry](/endpoint/revil_registry_entry/) | [Modify Registry](/tags/#modify-registry)| TTP | -| [Wbemprox COM Object Execution](/endpoint/wbemprox_com_object_execution/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [CMSTP](/tags/#cmstp)| TTP | - -#### Reference - -* [https://krebsonsecurity.com/2021/05/a-closer-look-at-the-darkside-ransomware-gang/](https://krebsonsecurity.com/2021/05/a-closer-look-at-the-darkside-ransomware-gang/) -* [https://www.mcafee.com/blogs/other-blogs/mcafee-labs/mcafee-atr-analyzes-sodinokibi-aka-revil-ransomware-as-a-service-what-the-code-tells-us/](https://www.mcafee.com/blogs/other-blogs/mcafee-labs/mcafee-atr-analyzes-sodinokibi-aka-revil-ransomware-as-a-service-what-the-code-tells-us/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/revil_ransomware.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/router_and_infrastructure_security.md b/docs/_stories/router_and_infrastructure_security.md deleted file mode 100644 index 6410b07948..0000000000 --- a/docs/_stories/router_and_infrastructure_security.md +++ /dev/null @@ -1,54 +0,0 @@ ---- -title: "Router and Infrastructure Security" -last_modified_at: 2017-09-12 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Authentication - - Network_Traffic - - Actions on Objectives - - Delivery - - Exploitation - - Reconnaissance ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Validate the security configuration of network infrastructure and verify that only authorized users and systems are accessing critical assets. Core routing and switching infrastructure are common strategic targets for attackers. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Authentication](https://docs.splunk.com/Documentation/CIM/latest/User/Authentication), [Network_Traffic](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkTraffic) -- **Last Updated**: 2017-09-12 -- **Author**: Bhavin Patel, Splunk -- **ID**: 91c676cf-0b23-438d-abee-f6335e177e77 - -#### Narrative - -Networking devices, such as routers and switches, are often overlooked as resources that attackers will leverage to subvert an enterprise. Advanced threats actors have shown a proclivity to target these critical assets as a means to siphon and redirect network traffic, flash backdoored operating systems, and implement cryptographic weakened algorithms to more easily decrypt network traffic.\ -This Analytic Story helps you gain a better understanding of how your network devices are interacting with your hosts. By compromising your network devices, attackers can obtain direct access to the company's internal infrastructure— effectively increasing the attack surface and accessing private services/data. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Detect New Login Attempts to Routers](/application/detect_new_login_attempts_to_routers/) | None| TTP | -| [Detect ARP Poisoning](/network/detect_arp_poisoning/) | [Hardware Additions](/tags/#hardware-additions), [Network Denial of Service](/tags/#network-denial-of-service), [Adversary-in-the-Middle](/tags/#adversary-in-the-middle), [ARP Cache Poisoning](/tags/#arp-cache-poisoning)| TTP | -| [Detect IPv6 Network Infrastructure Threats](/network/detect_ipv6_network_infrastructure_threats/) | [Hardware Additions](/tags/#hardware-additions), [Network Denial of Service](/tags/#network-denial-of-service), [Adversary-in-the-Middle](/tags/#adversary-in-the-middle), [ARP Cache Poisoning](/tags/#arp-cache-poisoning)| TTP | -| [Detect Port Security Violation](/network/detect_port_security_violation/) | [Hardware Additions](/tags/#hardware-additions), [Network Denial of Service](/tags/#network-denial-of-service), [Adversary-in-the-Middle](/tags/#adversary-in-the-middle), [ARP Cache Poisoning](/tags/#arp-cache-poisoning)| TTP | -| [Detect Rogue DHCP Server](/network/detect_rogue_dhcp_server/) | [Hardware Additions](/tags/#hardware-additions), [Network Denial of Service](/tags/#network-denial-of-service), [Adversary-in-the-Middle](/tags/#adversary-in-the-middle)| TTP | -| [Detect Software Download To Network Device](/network/detect_software_download_to_network_device/) | [TFTP Boot](/tags/#tftp-boot), [Pre-OS Boot](/tags/#pre-os-boot)| TTP | -| [Detect Traffic Mirroring](/network/detect_traffic_mirroring/) | [Hardware Additions](/tags/#hardware-additions), [Automated Exfiltration](/tags/#automated-exfiltration), [Network Denial of Service](/tags/#network-denial-of-service), [Traffic Duplication](/tags/#traffic-duplication)| TTP | - -#### Reference - -* [https://web.archive.org/web/20210420020040/https://www.fireeye.com/blog/executive-perspective/2015/09/the_new_route_toper.html](https://web.archive.org/web/20210420020040/https://www.fireeye.com/blog/executive-perspective/2015/09/the_new_route_toper.html) -* [https://www.cisco.com/c/en/us/about/security-center/event-response/synful-knock.html](https://www.cisco.com/c/en/us/about/security-center/event-response/synful-knock.html) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/router_and_infrastructure_security.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/ryuk_ransomware.md b/docs/_stories/ryuk_ransomware.md deleted file mode 100644 index 38a1ec8a21..0000000000 --- a/docs/_stories/ryuk_ransomware.md +++ /dev/null @@ -1,63 +0,0 @@ ---- -title: "Ryuk Ransomware" -last_modified_at: 2020-11-06 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Network_Traffic - - Actions on Objectives - - Delivery - - Exploitation - - Reconnaissance ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Leverage searches that allow you to detect and investigate unusual activities that might relate to the Ryuk ransomware, including looking for file writes associated with Ryuk, Stopping Security Access Manager, DisableAntiSpyware registry key modification, suspicious psexec use, and more. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint), [Network_Traffic](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkTraffic) -- **Last Updated**: 2020-11-06 -- **Author**: Jose Hernandez, Splunk -- **ID**: 507edc74-13d5-4339-878e-b9744ded1f35 - -#### Narrative - -Cybersecurity Infrastructure Security Agency (CISA) released Alert (AA20-302A) on October 28th called Ransomware Activity Targeting the Healthcare and Public Health Sector. This alert details TTPs associated with ongoing and possible imminent attacks against the Healthcare sector, and is a joint advisory in coordination with other U.S. Government agencies. The objective of these malicious campaigns is to infiltrate targets in named sectors and to drop ransomware payloads, which will likely cause disruption of service and increase risk of actual harm to the health and safety of patients at hospitals, even with the aggravant of an ongoing COVID-19 pandemic. This document specifically refers to several crimeware exploitation frameworks, emphasizing the use of Ryuk ransomware as payload. The Ryuk ransomware payload is not new. It has been well documented and identified in multiple variants. Payloads need a carrier, and for Ryuk it has often been exploitation frameworks such as Cobalt Strike, or popular crimeware frameworks such as Emotet or Trickbot. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Windows connhost exe started forcefully](/deprecated/windows_connhost_exe_started_forcefully/) | [Windows Command Shell](/tags/#windows-command-shell)| TTP | -| [BCDEdit Failure Recovery Modification](/endpoint/bcdedit_failure_recovery_modification/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery)| TTP | -| [Common Ransomware Extensions](/endpoint/common_ransomware_extensions/) | [Data Destruction](/tags/#data-destruction)| Hunting | -| [Common Ransomware Notes](/endpoint/common_ransomware_notes/) | [Data Destruction](/tags/#data-destruction)| Hunting | -| [NLTest Domain Trust Discovery](/endpoint/nltest_domain_trust_discovery/) | [Domain Trust Discovery](/tags/#domain-trust-discovery)| TTP | -| [Ryuk Test Files Detected](/endpoint/ryuk_test_files_detected/) | [Data Encrypted for Impact](/tags/#data-encrypted-for-impact)| TTP | -| [Ryuk Wake on LAN Command](/endpoint/ryuk_wake_on_lan_command/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Windows Command Shell](/tags/#windows-command-shell)| TTP | -| [Suspicious Scheduled Task from Public Directory](/endpoint/suspicious_scheduled_task_from_public_directory/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job)| Anomaly | -| [WBAdmin Delete System Backups](/endpoint/wbadmin_delete_system_backups/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery)| TTP | -| [Windows DisableAntiSpyware Registry](/endpoint/windows_disableantispyware_registry/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Windows Security Account Manager Stopped](/endpoint/windows_security_account_manager_stopped/) | [Service Stop](/tags/#service-stop)| TTP | -| [WinEvent Scheduled Task Created to Spawn Shell](/endpoint/winevent_scheduled_task_created_to_spawn_shell/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job)| TTP | -| [WinEvent Scheduled Task Created Within Public Path](/endpoint/winevent_scheduled_task_created_within_public_path/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job)| TTP | -| [Spike in File Writes](/endpoint/spike_in_file_writes/) | None| Anomaly | -| [Remote Desktop Network Bruteforce](/network/remote_desktop_network_bruteforce/) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol), [Remote Services](/tags/#remote-services)| TTP | -| [Remote Desktop Network Traffic](/network/remote_desktop_network_traffic/) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol), [Remote Services](/tags/#remote-services)| Anomaly | - -#### Reference - -* [https://www.splunk.com/en_us/blog/security/detecting-ryuk-using-splunk-attack-range.html](https://www.splunk.com/en_us/blog/security/detecting-ryuk-using-splunk-attack-range.html) -* [https://www.crowdstrike.com/blog/big-game-hunting-with-ryuk-another-lucrative-targeted-ransomware/](https://www.crowdstrike.com/blog/big-game-hunting-with-ryuk-another-lucrative-targeted-ransomware/) -* [https://us-cert.cisa.gov/ncas/alerts/aa20-302a](https://us-cert.cisa.gov/ncas/alerts/aa20-302a) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/ryuk_ransomware.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/samaccountname_spoofing_and_domain_controller_impersonation.md b/docs/_stories/samaccountname_spoofing_and_domain_controller_impersonation.md deleted file mode 100644 index 353bd445ab..0000000000 --- a/docs/_stories/samaccountname_spoofing_and_domain_controller_impersonation.md +++ /dev/null @@ -1,46 +0,0 @@ ---- -title: "sAMAccountName Spoofing and Domain Controller Impersonation" -last_modified_at: 2021-12-20 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Monitor for activities and techniques associated with the exploitation of the sAMAccountName Spoofing (CVE-2021-42278) and Domain Controller Impersonation (CVE-2021-42287) vulnerabilities. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-12-20 -- **Author**: Mauricio Velazco, Splunk -- **ID**: 0244fdee-61be-11ec-900e-acde48001122 - -#### Narrative - -On November 9, 2021, Microsoft released patches to address two vulnerabilities that affect Windows Active Directory networks, sAMAccountName Spoofing (CVE-2021-42278) and Domain Controller Impersonation (CVE-2021-42287). On December 10, 2021, security researchers Charlie Clark and Andrew Schwartz released a blog post where they shared how to weaponise these vulnerabilities in a target network an the initial detection opportunities. When successfully exploited, CVE-2021-42278 and CVE-2021-42287 allow an adversary, who has stolen the credentials of a low priviled domain user, to obtain a Kerberos Service ticket for a Domain Controller computer account. The only requirement is to have network connectivity to a domain controller. This attack vector effectivelly allows attackers to escalate their privileges in an Active Directory from a regular domain user account and take control of a domain controller. While patches have been released to address these vulnerabilities, deploying detection controls for this attack may help help defenders identify attackers attempting exploitation. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Suspicious Computer Account Name Change](/endpoint/suspicious_computer_account_name_change/) | [Valid Accounts](/tags/#valid-accounts), [Domain Accounts](/tags/#domain-accounts)| TTP | -| [Suspicious Kerberos Service Ticket Request](/endpoint/suspicious_kerberos_service_ticket_request/) | [Valid Accounts](/tags/#valid-accounts), [Domain Accounts](/tags/#domain-accounts)| TTP | -| [Suspicious Ticket Granting Ticket Request](/endpoint/suspicious_ticket_granting_ticket_request/) | [Valid Accounts](/tags/#valid-accounts), [Domain Accounts](/tags/#domain-accounts)| Hunting | - -#### Reference - -* [https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42278](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42278) -* [https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42287](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42287) -* [https://exploit.ph/cve-2021-42287-cve-2021-42278-weaponisation.html](https://exploit.ph/cve-2021-42287-cve-2021-42278-weaponisation.html) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/samaccountname_spoofing_and_domain_controller_impersonation.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/samsam_ransomware.md b/docs/_stories/samsam_ransomware.md deleted file mode 100644 index 4d90161e95..0000000000 --- a/docs/_stories/samsam_ransomware.md +++ /dev/null @@ -1,70 +0,0 @@ ---- -title: "SamSam Ransomware" -last_modified_at: 2018-12-13 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Network_Traffic - - Web - - Actions on Objectives - - Command & Control - - Delivery - - Exploitation - - Installation - - Reconnaissance ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Leverage searches that allow you to detect and investigate unusual activities that might relate to the SamSam ransomware, including looking for file writes associated with SamSam, RDP brute force attacks, the presence of files with SamSam ransomware extensions, suspicious psexec use, and more. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint), [Network_Traffic](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkTraffic), [Web](https://docs.splunk.com/Documentation/CIM/latest/User/Web) -- **Last Updated**: 2018-12-13 -- **Author**: Rico Valdez, Splunk -- **ID**: c4b89506-fbcf-4cb7-bfd6-527e54789604 - -#### Narrative - -The first version of the SamSam ransomware (a.k.a. Samas or SamsamCrypt) was launched in 2015 by a group of Iranian threat actors. The malicious software has affected and continues to affect thousands of victims and has raised almost $6M in ransom.\ -Although categorized under the heading of ransomware, SamSam campaigns have some importance distinguishing characteristics. Most notable is the fact that conventional ransomware is a numbers game. Perpetrators use a "spray-and-pray" approach with phishing campaigns or other mechanisms, charging a small ransom (typically under $1,000). The goal is to find a large number of victims willing to pay these mini-ransoms, adding up to a lucrative payday. They use relatively simple methods for infecting systems.\ -SamSam attacks are different beasts. They have become progressively more targeted and skillful than typical ransomware attacks. First, malicious actors break into a victim's network, surveil it, then run the malware manually. The attacks are tailored to cause maximum damage and the threat actors usually demand amounts in the tens of thousands of dollars.\ -In a typical attack on one large healthcare organization in 2018, the company ended up paying a ransom of four Bitcoins, then worth $56,707. Reports showed that access to the company's files was restored within two hours of paying the sum.\ -According to Sophos, SamSam previously leveraged RDP to gain access to targeted networks via brute force. SamSam is not spread automatically, like other malware. It requires skill because it forces the attacker to adapt their tactics to the individual environment. Next, the actors escalate their privileges to admin level. They scan the networks for worthy targets, using conventional tools, such as PsExec or PaExec, to deploy/execute, quickly encrypting files.\ -This Analytic Story includes searches designed to help detect and investigate signs of the SamSam ransomware, such as the creation of fileswrites to system32, writes with tell-tale extensions, batch files written to system32, and evidence of brute-force attacks via RDP. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Prohibited Software On Endpoint](/deprecated/prohibited_software_on_endpoint/) | None| Hunting | -| [Attacker Tools On Endpoint](/endpoint/attacker_tools_on_endpoint/) | [Match Legitimate Name or Location](/tags/#match-legitimate-name-or-location), [Masquerading](/tags/#masquerading), [OS Credential Dumping](/tags/#os-credential-dumping), [Active Scanning](/tags/#active-scanning)| TTP | -| [Batch File Write to System32](/endpoint/batch_file_write_to_system32/) | [User Execution](/tags/#user-execution), [Malicious File](/tags/#malicious-file)| TTP | -| [Common Ransomware Extensions](/endpoint/common_ransomware_extensions/) | [Data Destruction](/tags/#data-destruction)| Hunting | -| [Common Ransomware Notes](/endpoint/common_ransomware_notes/) | [Data Destruction](/tags/#data-destruction)| Hunting | -| [Deleting Shadow Copies](/endpoint/deleting_shadow_copies/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery)| TTP | -| [Detect PsExec With accepteula Flag](/endpoint/detect_psexec_with_accepteula_flag/) | [Remote Services](/tags/#remote-services), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares)| TTP | -| [Detect Renamed PSExec](/endpoint/detect_renamed_psexec/) | [System Services](/tags/#system-services), [Service Execution](/tags/#service-execution)| Hunting | -| [File with Samsam Extension](/endpoint/file_with_samsam_extension/) | None| TTP | -| [Samsam Test File Write](/endpoint/samsam_test_file_write/) | [Data Encrypted for Impact](/tags/#data-encrypted-for-impact)| TTP | -| [Spike in File Writes](/endpoint/spike_in_file_writes/) | None| Anomaly | -| [Remote Desktop Network Bruteforce](/network/remote_desktop_network_bruteforce/) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol), [Remote Services](/tags/#remote-services)| TTP | -| [Remote Desktop Network Traffic](/network/remote_desktop_network_traffic/) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol), [Remote Services](/tags/#remote-services)| Anomaly | -| [Detect attackers scanning for vulnerable JBoss servers](/web/detect_attackers_scanning_for_vulnerable_jboss_servers/) | [System Information Discovery](/tags/#system-information-discovery)| TTP | -| [Detect malicious requests to exploit JBoss servers](/web/detect_malicious_requests_to_exploit_jboss_servers/) | None| TTP | - -#### Reference - -* [https://www.crowdstrike.com/blog/an-in-depth-analysis-of-samsam-ransomware-and-boss-spider/](https://www.crowdstrike.com/blog/an-in-depth-analysis-of-samsam-ransomware-and-boss-spider/) -* [https://nakedsecurity.sophos.com/2018/07/31/samsam-the-almost-6-million-ransomware/](https://nakedsecurity.sophos.com/2018/07/31/samsam-the-almost-6-million-ransomware/) -* [https://thehackernews.com/2018/07/samsam-ransomware-attacks.html](https://thehackernews.com/2018/07/samsam-ransomware-attacks.html) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/samsam_ransomware.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/signed_binary_proxy_execution_installutil.md b/docs/_stories/signed_binary_proxy_execution_installutil.md deleted file mode 100644 index c1906641e2..0000000000 --- a/docs/_stories/signed_binary_proxy_execution_installutil.md +++ /dev/null @@ -1,53 +0,0 @@ ---- -title: "Signed Binary Proxy Execution InstallUtil" -last_modified_at: 2021-11-12 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Adversaries may use InstallUtil to proxy execution of code through a trusted Windows utility. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-11-12 -- **Author**: Michael Haag, Splunk -- **ID**: 9482a314-43dc-11ec-a3c9-acde48001122 - -#### Narrative - -InstallUtil is a command-line utility that allows for installation and uninstallation of resources by executing specific installer components specified in .NET binaries. InstallUtil is digitally signed by Microsoft and located in the .NET directories on a Windows system: C:\Windows\Microsoft.NET\Framework\v\InstallUtil.exe and C:\Windows\Microsoft.NET\Framework64\v\InstallUtil.exe. \ -There are multiple ways to instantiate InstallUtil and they are all outlined within Atomic Red Team - https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.004/T1218.004.md. Two specific ways may be used and that includes invoking via installer assembly class constructor through .NET and via InstallUtil.exe. \ -Typically, adversaries will utilize the most commonly found way to invoke via InstallUtil Uninstall method. \ -Note that parallel processes, and parent process, play a role in how InstallUtil is being used. In particular, a developer using InstallUtil will spawn from VisualStudio. Adversaries, will spawn from non-standard processes like Explorer.exe, cmd.exe or PowerShell.exe. It's important to review the command-line to identify the DLL being loaded. \ -Parallel processes may also include csc.exe being used to compile a local `.cs` file. This file will be the input to the output. Developers usually do not build direct on the command shell, therefore this should raise suspicion. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Windows DotNet Binary in Non Standard Path](/endpoint/windows_dotnet_binary_in_non_standard_path/) | [Masquerading](/tags/#masquerading), [Rename System Utilities](/tags/#rename-system-utilities), [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [InstallUtil](/tags/#installutil)| TTP | -| [Windows InstallUtil Credential Theft](/endpoint/windows_installutil_credential_theft/) | [InstallUtil](/tags/#installutil), [System Binary Proxy Execution](/tags/#system-binary-proxy-execution)| TTP | -| [Windows InstallUtil in Non Standard Path](/endpoint/windows_installutil_in_non_standard_path/) | [Masquerading](/tags/#masquerading), [Rename System Utilities](/tags/#rename-system-utilities), [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [InstallUtil](/tags/#installutil)| TTP | -| [Windows InstallUtil Remote Network Connection](/endpoint/windows_installutil_remote_network_connection/) | [InstallUtil](/tags/#installutil), [System Binary Proxy Execution](/tags/#system-binary-proxy-execution)| TTP | -| [Windows InstallUtil Uninstall Option](/endpoint/windows_installutil_uninstall_option/) | [InstallUtil](/tags/#installutil), [System Binary Proxy Execution](/tags/#system-binary-proxy-execution)| TTP | -| [Windows InstallUtil Uninstall Option with Network](/endpoint/windows_installutil_uninstall_option_with_network/) | [InstallUtil](/tags/#installutil), [System Binary Proxy Execution](/tags/#system-binary-proxy-execution)| TTP | -| [Windows InstallUtil URL in Command Line](/endpoint/windows_installutil_url_in_command_line/) | [InstallUtil](/tags/#installutil), [System Binary Proxy Execution](/tags/#system-binary-proxy-execution)| TTP | - -#### Reference - -* [https://attack.mitre.org/techniques/T1218/004/](https://attack.mitre.org/techniques/T1218/004/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.004/T1218.004.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.004/T1218.004.md) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/signed_binary_proxy_execution_installutil.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/silver_sparrow.md b/docs/_stories/silver_sparrow.md deleted file mode 100644 index 66387c4eef..0000000000 --- a/docs/_stories/silver_sparrow.md +++ /dev/null @@ -1,46 +0,0 @@ ---- -title: "Silver Sparrow" -last_modified_at: 2021-02-24 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Actions on Objectives ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Silver Sparrow, identified by Red Canary Intelligence, is a new forward looking MacOS (Intel and M1) malicious software downloader utilizing JavaScript for execution and a launchAgent to establish persistence. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-02-24 -- **Author**: Michael Haag, Splunk -- **ID**: cb4f48fe-7699-11eb-af77-acde48001122 - -#### Narrative - -Silver Sparrow works is a dropper and uses typical persistence mechanisms on a Mac. It is cross platform, covering both Intel and Apple M1 architecture. To this date, no implant has been downloaded for malicious purposes. During installation of the update.pkg or updater.pkg file, the malicious software utilizes JavaScript to generate files and scripts on disk for persistence.These files later download a implant from an S3 bucket every hour. This analytic assists with identifying different types of macOS malware families establishing LaunchAgent persistence. Per SentinelOne source, it is predicted that Silver Sparrow is likely selling itself as a mechanism to 3rd party Caffiliates or pay-per-install (PPI) partners, typically seen as commodity adware/malware. Additional indicators and behaviors may be found within the references. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Suspicious Curl Network Connection](/endpoint/suspicious_curl_network_connection/) | [Ingress Tool Transfer](/tags/#ingress-tool-transfer)| TTP | -| [Suspicious PlistBuddy Usage](/endpoint/suspicious_plistbuddy_usage/) | [Launch Agent](/tags/#launch-agent), [Create or Modify System Process](/tags/#create-or-modify-system-process)| TTP | -| [Suspicious PlistBuddy Usage via OSquery](/endpoint/suspicious_plistbuddy_usage_via_osquery/) | [Launch Agent](/tags/#launch-agent), [Create or Modify System Process](/tags/#create-or-modify-system-process)| TTP | -| [Suspicious SQLite3 LSQuarantine Behavior](/endpoint/suspicious_sqlite3_lsquarantine_behavior/) | [Data Staged](/tags/#data-staged)| TTP | - -#### Reference - -* [https://redcanary.com/blog/clipping-silver-sparrows-wings/](https://redcanary.com/blog/clipping-silver-sparrows-wings/) -* [https://www.sentinelone.com/blog/5-things-you-need-to-know-about-silver-sparrow/](https://www.sentinelone.com/blog/5-things-you-need-to-know-about-silver-sparrow/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/silver_sparrow.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/spearphishing_attachments.md b/docs/_stories/spearphishing_attachments.md deleted file mode 100644 index a3e95a82cb..0000000000 --- a/docs/_stories/spearphishing_attachments.md +++ /dev/null @@ -1,74 +0,0 @@ ---- -title: "Spearphishing Attachments" -last_modified_at: 2019-04-29 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Actions on Objectives - - Delivery - - Exploitation - - Installation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Detect signs of malicious payloads that may indicate that your environment has been breached via a phishing attack. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2019-04-29 -- **Author**: Splunk Research Team, Splunk -- **ID**: 57226b40-94f3-4ce5-b101-a75f67759c27 - -#### Narrative - -Despite its simplicity, phishing remains the most pervasive and dangerous cyberthreat. In fact, research shows that as many as [91% of all successful attacks](https://digitalguardian.com/blog/91-percent-cyber-attacks-start-phishing-email-heres-how-protect-against-phishing) are initiated via a phishing email. \ -As most people know, these emails use fraudulent domains, [email scraping](https://www.cyberscoop.com/emotet-trojan-phishing-scraping-templates-cofense-geodo/), familiar contact names inserted as senders, and other tactics to lure targets into clicking a malicious link, opening an attachment with a [nefarious payload](https://www.cyberscoop.com/emotet-trojan-phishing-scraping-templates-cofense-geodo/), or entering sensitive personal information that perpetrators may intercept. This attack technique requires a relatively low level of skill and allows adversaries to easily cast a wide net. Worse, because its success relies on the gullibility of humans, it's impossible to completely "automate" it out of your environment. However, you can use ES and ESCU to detect and investigate potentially malicious payloads injected into your environment subsequent to a phishing attack. \ -While any kind of file may contain a malicious payload, some are more likely to be perceived as benign (and thus more often escape notice) by the average victim—especially when the attacker sends an email that seems to be from one of their contacts. An example is Microsoft Office files. Most corporate users are familiar with documents with the following suffixes: .doc/.docx (MS Word), .xls/.xlsx (MS Excel), and .ppt/.pptx (MS PowerPoint), so they may click without a second thought, slashing a hole in their organizations' security. \ -Following is a typical series of events, according to an [article by Trend Micro](https://blog.trendmicro.com/trendlabs-security-intelligence/rising-trend-attackers-using-lnk-files-download-malware/):\ -1. Attacker sends a phishing email. Recipient downloads the attached file, which is typically a .docx or .zip file with an embedded .lnk file\ -1. The .lnk file executes a PowerShell script\ -1. Powershell executes a reverse shell, rendering the exploit successful As a side note, adversaries are likely to use a tool like Empire to craft and obfuscate payloads and their post-injection activities, such as [exfiltration, lateral movement, and persistence](https://github.com/EmpireProject/Empire).\ -This Analytic Story focuses on detecting signs that a malicious payload has been injected into your environment. For example, one search detects outlook.exe writing a .zip file. Another looks for suspicious .lnk files launching processes. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Excel Spawning PowerShell](/endpoint/excel_spawning_powershell/) | [Security Account Manager](/tags/#security-account-manager), [OS Credential Dumping](/tags/#os-credential-dumping)| TTP | -| [Excel Spawning Windows Script Host](/endpoint/excel_spawning_windows_script_host/) | [Security Account Manager](/tags/#security-account-manager), [OS Credential Dumping](/tags/#os-credential-dumping)| TTP | -| [MSHTML Module Load in Office Product](/endpoint/mshtml_module_load_in_office_product/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment)| TTP | -| [Office Application Spawn rundll32 process](/endpoint/office_application_spawn_rundll32_process/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment)| TTP | -| [Office Document Creating Schedule Task](/endpoint/office_document_creating_schedule_task/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment)| TTP | -| [Office Document Executing Macro Code](/endpoint/office_document_executing_macro_code/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment)| TTP | -| [Office Document Spawned Child Process To Download](/endpoint/office_document_spawned_child_process_to_download/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment)| TTP | -| [Office Product Spawning BITSAdmin](/endpoint/office_product_spawning_bitsadmin/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment)| TTP | -| [Office Product Spawning CertUtil](/endpoint/office_product_spawning_certutil/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment)| TTP | -| [Office Product Spawning MSHTA](/endpoint/office_product_spawning_mshta/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment)| TTP | -| [Office Product Spawning Rundll32 with no DLL](/endpoint/office_product_spawning_rundll32_with_no_dll/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment)| TTP | -| [Office Product Spawning Wmic](/endpoint/office_product_spawning_wmic/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment)| TTP | -| [Office Product Writing cab or inf](/endpoint/office_product_writing_cab_or_inf/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment)| TTP | -| [Office Spawning Control](/endpoint/office_spawning_control/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment)| TTP | -| [Process Creating LNK file in Suspicious Location](/endpoint/process_creating_lnk_file_in_suspicious_location/) | [Phishing](/tags/#phishing), [Spearphishing Link](/tags/#spearphishing-link)| TTP | -| [Windows ISO LNK File Creation](/endpoint/windows_iso_lnk_file_creation/) | [Spearphishing Attachment](/tags/#spearphishing-attachment), [Phishing](/tags/#phishing), [Malicious Link](/tags/#malicious-link), [User Execution](/tags/#user-execution)| Hunting | -| [Windows Office Product Spawning MSDT](/endpoint/windows_office_product_spawning_msdt/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment)| TTP | -| [Winword Spawning Cmd](/endpoint/winword_spawning_cmd/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment)| TTP | -| [Winword Spawning PowerShell](/endpoint/winword_spawning_powershell/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment)| TTP | -| [Winword Spawning Windows Script Host](/endpoint/winword_spawning_windows_script_host/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment)| TTP | -| [Gdrive suspicious file sharing](/cloud/gdrive_suspicious_file_sharing/) | [Phishing](/tags/#phishing)| Hunting | -| [Gsuite suspicious calendar invite](/cloud/gsuite_suspicious_calendar_invite/) | [Phishing](/tags/#phishing)| Hunting | -| [Detect Outlook exe writing a zip file](/endpoint/detect_outlook_exe_writing_a_zip_file/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment)| TTP | - -#### Reference - -* [https://www.fireeye.com/blog/threat-research/2019/04/spear-phishing-campaign-targets-ukraine-government.html](https://www.fireeye.com/blog/threat-research/2019/04/spear-phishing-campaign-targets-ukraine-government.html) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/spearphishing_attachments.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/spectre_and_meltdown_vulnerabilities.md b/docs/_stories/spectre_and_meltdown_vulnerabilities.md deleted file mode 100644 index 1b6155290d..0000000000 --- a/docs/_stories/spectre_and_meltdown_vulnerabilities.md +++ /dev/null @@ -1,42 +0,0 @@ ---- -title: "Spectre And Meltdown Vulnerabilities" -last_modified_at: 2018-01-08 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Vulnerabilities - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Assess and mitigate your systems' vulnerability to Spectre and Meltdown exploitation with the searches in this Analytic Story. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Vulnerabilities](https://docs.splunk.com/Documentation/CIM/latest/User/Vulnerabilities) -- **Last Updated**: 2018-01-08 -- **Author**: David Dorsey, Splunk -- **ID**: 6d3306f6-bb2b-4219-8609-8efad64032f2 - -#### Narrative - -Meltdown and Spectre exploit critical vulnerabilities in modern CPUs that allow unintended access to data in memory. This Analytic Story will help you identify the systems can be patched for these vulnerabilities, as well as those that still need to be patched. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Spectre and Meltdown Vulnerable Systems](/deprecated/spectre_and_meltdown_vulnerable_systems/) | None| TTP | - -#### Reference - -* [https://meltdownattack.com/](https://meltdownattack.com/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/spectre_and_meltdown_vulnerabilities.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/splunk_enterprise_vulnerability.md b/docs/_stories/splunk_enterprise_vulnerability.md deleted file mode 100644 index eafa15d1c4..0000000000 --- a/docs/_stories/splunk_enterprise_vulnerability.md +++ /dev/null @@ -1,51 +0,0 @@ ---- -title: "Splunk Enterprise Vulnerability" -last_modified_at: 2017-09-19 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Delivery ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Keeping your Splunk deployment up to date is critical and may help you reduce the risk of CVE-2016-4859, an open-redirection vulnerability within some older versions of Splunk Enterprise. The detection search will help ensure that users are being properly authenticated and not being redirected to malicious domains. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: -- **Last Updated**: 2017-09-19 -- **Author**: Bhavin Patel, Splunk -- **ID**: 4e692b96-de2d-4bd1-9105-37e2368a8db1 - -#### Narrative - -This Analytic Story is associated with CVE-2016-4859, an open-redirect vulnerability in the following versions of Splunk Enterprise:\ -\ -1. Splunk Enterprise 6.4.x, prior to 6.4.3\ -1. Splunk Enterprise 6.3.x, prior to 6.3.6\ -1. Splunk Enterprise 6.2.x, prior to 6.2.10\ -1. Splunk Enterprise 6.1.x, prior to 6.1.11\ -1. Splunk Enterprise 6.0.x, prior to 6.0.12\ -1. Splunk Enterprise 5.0.x, prior to 5.0.16\ -1. Splunk Light, prior to 6.4.3CVE-2016-4859 allows attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. (Credit: Noriaki Iwasaki, Cyber Defense Institute, Inc.).\ -It is important to ensure that your Splunk deployment is being kept up to date and is properly configured. This detection search allows analysts to monitor internal logs to ensure users are properly authenticated and cannot be redirected to any malicious third-party websites. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Open Redirect in Splunk Web](/deprecated/open_redirect_in_splunk_web/) | None| TTP | - -#### Reference - -* [http://www.splunk.com/view/SP-CAAAPQ6#announce](http://www.splunk.com/view/SP-CAAAPQ6#announce) -* [https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4859](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4859) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/splunk_enterprise_vulnerability.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/splunk_enterprise_vulnerability_cve-2018-11409.md b/docs/_stories/splunk_enterprise_vulnerability_cve-2018-11409.md deleted file mode 100644 index 481129cb91..0000000000 --- a/docs/_stories/splunk_enterprise_vulnerability_cve-2018-11409.md +++ /dev/null @@ -1,46 +0,0 @@ ---- -title: "Splunk Enterprise Vulnerability CVE-2018-11409" -last_modified_at: 2018-06-14 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Delivery ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Reduce the risk of CVE-2018-11409, an information disclosure vulnerability within some older versions of Splunk Enterprise, with searches designed to help ensure that your Splunk system does not leak information to authenticated users. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: -- **Last Updated**: 2018-06-14 -- **Author**: David Dorsey, Splunk -- **ID**: 1fc34cbc-34e9-43ba-87ab-6811c9e95400 - -#### Narrative - -Although there have been no reports of it being exploited, Splunk Enterprise versions through 7.0.1 reportedly have a vulnerability that may expose information through a REST endpoint (read more here: https://www.splunk.com/view/SP-CAAAP5E#VulnerabilityDescriptionsandRatings). NIST has included it in its vulnerability database (read more here: https://nvd.nist.gov/vuln/detail/CVE-2018-11409). The REST endpoint that exposes system information is also necessary for the proper operation of Splunk clustering and instrumentation. Customers should upgrade to the latest version to reduce the risk of this vulnerability.\ -Splunk Enterprise exposes partial information about the host operating system, hardware, and Splunk license. Splunk Enterprise before 6.6.0 exposes this information without authentication. Splunk Enterprise 6.6.0 and later exposes this information only to authenticated Splunk users. Based on the information exposure, Splunk characterizes this issue as a low severity impact.\ -Read more in Splunk's official response: https://www.splunk.com/view/SP-CAAAP5E#VulnerabilityDescriptionsandRatings.\ -A detection search within this Analytic Story looks for vulnerabilities described in CVE-2018-11409: Information Exposure (https://nvd.nist.gov/vuln/detail/CVE-2018-11409). If it turns up activities that may be specific, you can use the included investigative searches to return information regarding web activity and network traffic by src_ip. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Splunk Enterprise Information Disclosure](/deprecated/splunk_enterprise_information_disclosure/) | None| TTP | - -#### Reference - -* [https://nvd.nist.gov/vuln/detail/CVE-2018-11409](https://nvd.nist.gov/vuln/detail/CVE-2018-11409) -* [https://www.splunk.com/view/SP-CAAAP5E#VulnerabilityDescriptionsandRatings](https://www.splunk.com/view/SP-CAAAP5E#VulnerabilityDescriptionsandRatings) -* [https://www.exploit-db.com/exploits/44865/](https://www.exploit-db.com/exploits/44865/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/splunk_enterprise_vulnerability_cve-2018-11409.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/splunk_vulnerabilities.md b/docs/_stories/splunk_vulnerabilities.md deleted file mode 100644 index 91fc04e7cb..0000000000 --- a/docs/_stories/splunk_vulnerabilities.md +++ /dev/null @@ -1,61 +0,0 @@ ---- -title: "Splunk Vulnerabilities" -last_modified_at: 2022-03-28 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Splunk_Audit - - Actions on Objectives - - Delivery - - Exploitation - - Reconnaissance ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Keeping your Splunk Enterprise deployment up to date is critical and will help you reduce the risk associated with vulnerabilities in the product. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Splunk_Audit](https://docs.splunk.com/Documentation/CIM/latest/User/SplunkAudit) -- **Last Updated**: 2022-03-28 -- **Author**: Lou Stella, Splunk -- **ID**: 5354df00-dce2-48ac-9a64-8adb48006828 - -#### Narrative - -This analytic story includes detections that focus on attacker behavior targeted at your Splunk environment directly. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Detect Risky SPL using Pretrained ML Model](/application/detect_risky_spl_using_pretrained_ml_model/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter)| Anomaly | -| [Path traversal SPL injection](/application/path_traversal_spl_injection/) | [File and Directory Discovery](/tags/#file-and-directory-discovery)| TTP | -| [Splunk Command and Scripting Interpreter Delete Usage](/application/splunk_command_and_scripting_interpreter_delete_usage/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter)| Anomaly | -| [Splunk Command and Scripting Interpreter Risky Commands](/application/splunk_command_and_scripting_interpreter_risky_commands/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter)| Hunting | -| [Splunk Command and Scripting Interpreter Risky SPL MLTK](/application/splunk_command_and_scripting_interpreter_risky_spl_mltk/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter)| Anomaly | -| [Splunk Digital Certificates Infrastructure Version](/application/splunk_digital_certificates_infrastructure_version/) | [Digital Certificates](/tags/#digital-certificates)| Hunting | -| [Splunk Digital Certificates Lack of Encryption](/application/splunk_digital_certificates_lack_of_encryption/) | [Digital Certificates](/tags/#digital-certificates)| Anomaly | -| [Splunk DoS via Malformed S2S Request](/application/splunk_dos_via_malformed_s2s_request/) | [Network Denial of Service](/tags/#network-denial-of-service)| TTP | -| [Splunk Process Injection Forwarder Bundle Downloads](/application/splunk_process_injection_forwarder_bundle_downloads/) | [Process Injection](/tags/#process-injection)| Hunting | -| [Splunk Protocol Impersonation Weak Encryption Configuration](/application/splunk_protocol_impersonation_weak_encryption_configuration/) | [Protocol Impersonation](/tags/#protocol-impersonation)| Hunting | -| [Splunk protocol impersonation weak encryption selfsigned](/application/splunk_protocol_impersonation_weak_encryption_selfsigned/) | [Digital Certificates](/tags/#digital-certificates)| Hunting | -| [Splunk protocol impersonation weak encryption simplerequest](/application/splunk_protocol_impersonation_weak_encryption_simplerequest/) | [Digital Certificates](/tags/#digital-certificates)| Hunting | -| [Splunk User Enumeration Attempt](/application/splunk_user_enumeration_attempt/) | [Valid Accounts](/tags/#valid-accounts)| TTP | -| [Splunk XSS in Monitoring Console](/application/splunk_xss_in_monitoring_console/) | [Drive-by Compromise](/tags/#drive-by-compromise)| TTP | -| [Open Redirect in Splunk Web](/deprecated/open_redirect_in_splunk_web/) | None| TTP | -| [Splunk Enterprise Information Disclosure](/deprecated/splunk_enterprise_information_disclosure/) | None| TTP | -| [Splunk Identified SSL TLS Certificates](/network/splunk_identified_ssl_tls_certificates/) | [Network Sniffing](/tags/#network-sniffing)| Hunting | - -#### Reference - -* [https://www.splunk.com/en_us/product-security/announcements.html](https://www.splunk.com/en_us/product-security/announcements.html) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/splunk_vulnerabilities.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/spring4shell_cve-2022-22965.md b/docs/_stories/spring4shell_cve-2022-22965.md deleted file mode 100644 index bfba249196..0000000000 --- a/docs/_stories/spring4shell_cve-2022-22965.md +++ /dev/null @@ -1,54 +0,0 @@ ---- -title: "Spring4Shell CVE-2022-22965" -last_modified_at: 2022-04-05 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Web - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Spring4Shell is the nickname given to a zero-day vulnerability in the Spring Core Framework, a programming and configuration model for Java-based enterprise applications. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint), [Web](https://docs.splunk.com/Documentation/CIM/latest/User/Web) -- **Last Updated**: 2022-04-05 -- **Author**: Michael Haag, Splunk -- **ID**: dcc19913-6918-4ed2-bbba-a6b484c10ef4 - -#### Narrative - -An attacker could exploit Spring4Shell by sending a specially crafted request to a vulnerable server. However, exploitation of Spring4Shell requires certain prerequisites, whereas the original Log4Shell vulnerability affected all versions of Log4j 2 using the default configuration. \ -According to Spring, the following requirements were included in the vulnerability report, however the post cautions that there may be other ways in which this can be exploited so this may not be a complete list of requirements at this time: \ -- Java Development Kit (JDK) 9 or greater \ -- Apache Tomcat as the Servlet container \ -- Packaged as a WAR \ -- spring-webmvc or spring-webflux dependency \ - - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Java Writing JSP File](/endpoint/java_writing_jsp_file/) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application)| TTP | -| [Linux Java Spawning Shell](/endpoint/linux_java_spawning_shell/) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application)| TTP | -| [Spring4Shell Payload URL Request](/web/spring4shell_payload_url_request/) | [Web Shell](/tags/#web-shell), [Server Software Component](/tags/#server-software-component), [Exploit Public-Facing Application](/tags/#exploit-public-facing-application)| TTP | -| [Web JSP Request via URL](/web/web_jsp_request_via_url/) | [Web Shell](/tags/#web-shell), [Server Software Component](/tags/#server-software-component), [Exploit Public-Facing Application](/tags/#exploit-public-facing-application)| TTP | -| [Web Spring4Shell HTTP Request Class Module](/web/web_spring4shell_http_request_class_module/) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application)| TTP | -| [Web Spring Cloud Function FunctionRouter](/web/web_spring_cloud_function_functionrouter/) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application)| TTP | - -#### Reference - -* [https://www.tenable.com/blog/spring4shell-faq-spring-framework-remote-code-execution-vulnerability](https://www.tenable.com/blog/spring4shell-faq-spring-framework-remote-code-execution-vulnerability) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/spring4shell_cve-2022-22965.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/sql_injection.md b/docs/_stories/sql_injection.md deleted file mode 100644 index c17a536bd7..0000000000 --- a/docs/_stories/sql_injection.md +++ /dev/null @@ -1,44 +0,0 @@ ---- -title: "SQL Injection" -last_modified_at: 2017-09-19 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Web - - Delivery ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Use the searches in this Analytic Story to help you detect structured query language (SQL) injection attempts characterized by long URLs that contain malicious parameters. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Web](https://docs.splunk.com/Documentation/CIM/latest/User/Web) -- **Last Updated**: 2017-09-19 -- **Author**: Bhavin Patel, Splunk -- **ID**: 4f6632f5-449c-4686-80df-57625f59bab3 - -#### Narrative - -It is very common for attackers to inject SQL parameters into vulnerable web applications, which then interpret the malicious SQL statements.\ -This Analytic Story contains a search designed to identify attempts by attackers to leverage this technique to compromise a host and gain a foothold in the target environment. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [SQL Injection with Long URLs](/web/sql_injection_with_long_urls/) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application)| TTP | - -#### Reference - -* [https://capec.mitre.org/data/definitions/66.html](https://capec.mitre.org/data/definitions/66.html) -* [https://www.incapsula.com/web-application-security/sql-injection.html](https://www.incapsula.com/web-application-security/sql-injection.html) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/sql_injection.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/suspicious_aws_ec2_activities.md b/docs/_stories/suspicious_aws_ec2_activities.md deleted file mode 100644 index 6e42bf9a18..0000000000 --- a/docs/_stories/suspicious_aws_ec2_activities.md +++ /dev/null @@ -1,47 +0,0 @@ ---- -title: "Suspicious AWS EC2 Activities" -last_modified_at: 2018-02-09 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Actions on Objectives - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Use the searches in this Analytic Story to monitor your AWS EC2 instances for evidence of anomalous activity and suspicious behaviors, such as EC2 instances that originate from unusual locations or those launched by previously unseen users (among others). Included investigative searches will help you probe more deeply, when the information warrants it. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: -- **Last Updated**: 2018-02-09 -- **Author**: Bhavin Patel, Splunk -- **ID**: 2e8948a5-5239-406b-b56b-6c50f1268af3 - -#### Narrative - -AWS CloudTrail is an AWS service that helps you enable governance, compliance, and risk auditing within your AWS account. Actions taken by a user, role, or an AWS service are recorded as events in CloudTrail. It is crucial for a company to monitor events and actions taken in the AWS Console, AWS command-line interface, and AWS SDKs and APIs to ensure that your EC2 instances are not vulnerable to attacks. This Analytic Story identifies suspicious activities in your AWS EC2 instances and helps you respond and investigate those activities. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Abnormally High AWS Instances Launched by User](/deprecated/abnormally_high_aws_instances_launched_by_user/) | [Cloud Accounts](/tags/#cloud-accounts)| Anomaly | -| [Abnormally High AWS Instances Launched by User - MLTK](/deprecated/abnormally_high_aws_instances_launched_by_user_-_mltk/) | [Cloud Accounts](/tags/#cloud-accounts)| Anomaly | -| [Abnormally High AWS Instances Terminated by User](/deprecated/abnormally_high_aws_instances_terminated_by_user/) | [Cloud Accounts](/tags/#cloud-accounts)| Anomaly | -| [Abnormally High AWS Instances Terminated by User - MLTK](/deprecated/abnormally_high_aws_instances_terminated_by_user_-_mltk/) | [Cloud Accounts](/tags/#cloud-accounts)| Anomaly | -| [EC2 Instance Started In Previously Unseen Region](/deprecated/ec2_instance_started_in_previously_unseen_region/) | [Unused/Unsupported Cloud Regions](/tags/#unused/unsupported-cloud-regions)| Anomaly | -| [EC2 Instance Started With Previously Unseen User](/deprecated/ec2_instance_started_with_previously_unseen_user/) | [Cloud Accounts](/tags/#cloud-accounts)| Anomaly | - -#### Reference - -* [https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf](https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/suspicious_aws_ec2_activities.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/suspicious_aws_login_activities.md b/docs/_stories/suspicious_aws_login_activities.md deleted file mode 100644 index ba94fdb33a..0000000000 --- a/docs/_stories/suspicious_aws_login_activities.md +++ /dev/null @@ -1,46 +0,0 @@ ---- -title: "Suspicious AWS Login Activities" -last_modified_at: 2019-05-01 -toc: true -toc_label: "" -tags: - - Splunk Security Analytics for AWS - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Authentication - - Actions on Objectives ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Monitor your AWS authentication events using your CloudTrail logs. Searches within this Analytic Story will help you stay aware of and investigate suspicious logins. - -- **Product**: Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Authentication](https://docs.splunk.com/Documentation/CIM/latest/User/Authentication) -- **Last Updated**: 2019-05-01 -- **Author**: Bhavin Patel, Splunk -- **ID**: 2e8948a5-5239-406b-b56b-6c59f1268af3 - -#### Narrative - -It is important to monitor and control who has access to your AWS infrastructure. Detecting suspicious logins to your AWS infrastructure will provide good starting points for investigations. Abusive behaviors caused by compromised credentials can lead to direct monetary costs, as you will be billed for any EC2 instances created by the attacker. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Detect AWS Console Login by User from New City](/cloud/detect_aws_console_login_by_user_from_new_city/) | [Unused/Unsupported Cloud Regions](/tags/#unused/unsupported-cloud-regions)| Hunting | -| [Detect AWS Console Login by User from New Country](/cloud/detect_aws_console_login_by_user_from_new_country/) | [Unused/Unsupported Cloud Regions](/tags/#unused/unsupported-cloud-regions)| Hunting | -| [Detect AWS Console Login by User from New Region](/cloud/detect_aws_console_login_by_user_from_new_region/) | [Unused/Unsupported Cloud Regions](/tags/#unused/unsupported-cloud-regions)| Hunting | -| [Detect new user AWS Console Login](/deprecated/detect_new_user_aws_console_login/) | [Cloud Accounts](/tags/#cloud-accounts)| Hunting | - -#### Reference - -* [https://docs.aws.amazon.com/IAM/latest/UserGuide/cloudtrail-integration.html](https://docs.aws.amazon.com/IAM/latest/UserGuide/cloudtrail-integration.html) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/suspicious_aws_login_activities.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/suspicious_aws_s3_activities.md b/docs/_stories/suspicious_aws_s3_activities.md deleted file mode 100644 index 61e15e43ff..0000000000 --- a/docs/_stories/suspicious_aws_s3_activities.md +++ /dev/null @@ -1,48 +0,0 @@ ---- -title: "Suspicious AWS S3 Activities" -last_modified_at: 2018-07-24 -toc: true -toc_label: "" -tags: - - Splunk Security Analytics for AWS - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Actions on Objectives ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Use the searches in this Analytic Story to monitor your AWS S3 buckets for evidence of anomalous activity and suspicious behaviors, such as detecting open S3 buckets and buckets being accessed from a new IP. The contextual and investigative searches will give you more information, when required. - -- **Product**: Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: -- **Last Updated**: 2018-07-24 -- **Author**: Bhavin Patel, Splunk -- **ID**: 66732346-8fb0-407b-9633-da16756567d6 - -#### Narrative - -As cloud computing has exploded, so has the number of creative attacks on virtual environments. And as the number-two cloud-service provider, Amazon Web Services (AWS) has certainly had its share.\ -Amazon's "shared responsibility" model dictates that the company has responsibility for the environment outside of the VM and the customer is responsible for the security inside of the S3 container. As such, it's important to stay vigilant for activities that may belie suspicious behavior inside of your environment.\ -Among things to look out for are S3 access from unfamiliar locations and by unfamiliar users. Some of the searches in this Analytic Story help you detect suspicious behavior and others help you investigate more deeply, when the situation warrants. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Detect New Open S3 buckets](/cloud/detect_new_open_s3_buckets/) | [Data from Cloud Storage Object](/tags/#data-from-cloud-storage-object)| TTP | -| [Detect New Open S3 Buckets over AWS CLI](/cloud/detect_new_open_s3_buckets_over_aws_cli/) | [Data from Cloud Storage Object](/tags/#data-from-cloud-storage-object)| TTP | -| [Detect S3 access from a new IP](/cloud/detect_s3_access_from_a_new_ip/) | [Data from Cloud Storage Object](/tags/#data-from-cloud-storage-object)| Anomaly | -| [Detect Spike in S3 Bucket deletion](/cloud/detect_spike_in_s3_bucket_deletion/) | [Data from Cloud Storage Object](/tags/#data-from-cloud-storage-object)| Anomaly | - -#### Reference - -* [https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf](https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf) -* [https://www.tripwire.com/state-of-security/security-data-protection/cloud/public-aws-s3-buckets-writable/](https://www.tripwire.com/state-of-security/security-data-protection/cloud/public-aws-s3-buckets-writable/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/suspicious_aws_s3_activities.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_stories/suspicious_aws_traffic.md b/docs/_stories/suspicious_aws_traffic.md deleted file mode 100644 index 158f5f7938..0000000000 --- a/docs/_stories/suspicious_aws_traffic.md +++ /dev/null @@ -1,45 +0,0 @@ ---- -title: "Suspicious AWS Traffic" -last_modified_at: 2018-05-07 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Actions on Objectives - - Command & Control ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Leverage these searches to monitor your AWS network traffic for evidence of anomalous activity and suspicious behaviors, such as a spike in blocked outbound traffic in your virtual private cloud (VPC). - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: -- **Last Updated**: 2018-05-07 -- **Author**: Bhavin Patel, Splunk -- **ID**: 2e8948a5-5239-406b-b56b-6c50f2168af3 - -#### Narrative - -A virtual private cloud (VPC) is an on-demand managed cloud-computing service that isolates computing resources for each client. Inside the VPC container, the environment resembles a physical network. \ -Amazon's VPC service enables you to launch EC2 instances and leverage other Amazon resources. The traffic that flows in and out of this VPC can be controlled via network access-control rules and security groups. Amazon also has a feature called VPC Flow Logs that enables you to log IP traffic going to and from the network interfaces in your VPC. This data is stored using Amazon CloudWatch Logs.\ - Attackers may abuse the AWS infrastructure with insecure VPCs so they can co-opt AWS resources for command-and-control nodes, data exfiltration, and more. Once an EC2 instance is compromised, an attacker may initiate outbound network connections for malicious reasons. Monitoring these network traffic behaviors is crucial for understanding the type of traffic flowing in and out of your network and to alert you to suspicious activities.\ -The searches in this Analytic Story will monitor your AWS network traffic for evidence of anomalous activity and suspicious behaviors. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Detect Spike in blocked Outbound Traffic from your AWS](/cloud/detect_spike_in_blocked_outbound_traffic_from_your_aws/) | None| Anomaly | - -#### Reference - -* [https://rhinosecuritylabs.com/aws/hiding-cloudcobalt-strike-beacon-c2-using-amazon-apis/](https://rhinosecuritylabs.com/aws/hiding-cloudcobalt-strike-beacon-c2-using-amazon-apis/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/suspicious_aws_traffic.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/suspicious_cloud_authentication_activities.md b/docs/_stories/suspicious_cloud_authentication_activities.md deleted file mode 100644 index d133c233fd..0000000000 --- a/docs/_stories/suspicious_cloud_authentication_activities.md +++ /dev/null @@ -1,49 +0,0 @@ ---- -title: "Suspicious Cloud Authentication Activities" -last_modified_at: 2020-06-04 -toc: true -toc_label: "" -tags: - - Splunk Security Analytics for AWS - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Authentication - - Actions on Objectives ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Monitor your cloud authentication events. Searches within this Analytic Story leverage the recent cloud updates to the Authentication data model to help you stay aware of and investigate suspicious login activity. - -- **Product**: Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Authentication](https://docs.splunk.com/Documentation/CIM/latest/User/Authentication) -- **Last Updated**: 2020-06-04 -- **Author**: Rico Valdez, Splunk -- **ID**: 6380ebbb-55c5-4fce-b754-01fd565fb73c - -#### Narrative - -It is important to monitor and control who has access to your cloud infrastructure. Detecting suspicious logins will provide good starting points for investigations. Abusive behaviors caused by compromised credentials can lead to direct monetary costs, as you will be billed for any compute activity whether legitimate or otherwise.\ -This Analytic Story has data model versions of cloud searches leveraging Authentication data, including those looking for suspicious login activity, and cross-account activity for AWS. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [AWS Cross Account Activity From Previously Unseen Account](/cloud/aws_cross_account_activity_from_previously_unseen_account/) | None| Anomaly | -| [Detect AWS Console Login by New User](/cloud/detect_aws_console_login_by_new_user/) | None| Hunting | -| [Detect AWS Console Login by User from New City](/cloud/detect_aws_console_login_by_user_from_new_city/) | [Unused/Unsupported Cloud Regions](/tags/#unused/unsupported-cloud-regions)| Hunting | -| [Detect AWS Console Login by User from New Country](/cloud/detect_aws_console_login_by_user_from_new_country/) | [Unused/Unsupported Cloud Regions](/tags/#unused/unsupported-cloud-regions)| Hunting | -| [Detect AWS Console Login by User from New Region](/cloud/detect_aws_console_login_by_user_from_new_region/) | [Unused/Unsupported Cloud Regions](/tags/#unused/unsupported-cloud-regions)| Hunting | - -#### Reference - -* [https://aws.amazon.com/blogs/security/aws-cloudtrail-now-tracks-cross-account-activity-to-its-origin/](https://aws.amazon.com/blogs/security/aws-cloudtrail-now-tracks-cross-account-activity-to-its-origin/) -* [https://docs.aws.amazon.com/IAM/latest/UserGuide/cloudtrail-integration.html](https://docs.aws.amazon.com/IAM/latest/UserGuide/cloudtrail-integration.html) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/suspicious_cloud_authentication_activities.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/suspicious_cloud_instance_activities.md b/docs/_stories/suspicious_cloud_instance_activities.md deleted file mode 100644 index 28543be7be..0000000000 --- a/docs/_stories/suspicious_cloud_instance_activities.md +++ /dev/null @@ -1,46 +0,0 @@ ---- -title: "Suspicious Cloud Instance Activities" -last_modified_at: 2020-08-25 -toc: true -toc_label: "" -tags: - - Splunk Security Analytics for AWS - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Change - - Actions on Objectives ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Monitor your cloud infrastructure provisioning activities for behaviors originating from unfamiliar or unusual locations. These behaviors may indicate that malicious activities are occurring somewhere within your cloud environment. - -- **Product**: Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Change](https://docs.splunk.com/Documentation/CIM/latest/User/Change) -- **Last Updated**: 2020-08-25 -- **Author**: David Dorsey, Splunk -- **ID**: 8168ca88-392e-42f4-85a2-767579c660ce - -#### Narrative - -Monitoring your cloud infrastructure logs allows you enable governance, compliance, and risk auditing. It is crucial for a company to monitor events and actions taken in the their cloud environments to ensure that your instances are not vulnerable to attacks. This Analytic Story identifies suspicious activities in your cloud compute instances and helps you respond and investigate those activities. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Cloud Instance Modified By Previously Unseen User](/cloud/cloud_instance_modified_by_previously_unseen_user/) | [Cloud Accounts](/tags/#cloud-accounts), [Valid Accounts](/tags/#valid-accounts)| Anomaly | -| [Detect shared ec2 snapshot](/cloud/detect_shared_ec2_snapshot/) | [Transfer Data to Cloud Account](/tags/#transfer-data-to-cloud-account)| TTP | -| [Abnormally High Number Of Cloud Instances Destroyed](/cloud/abnormally_high_number_of_cloud_instances_destroyed/) | [Cloud Accounts](/tags/#cloud-accounts), [Valid Accounts](/tags/#valid-accounts)| Anomaly | -| [Abnormally High Number Of Cloud Instances Launched](/cloud/abnormally_high_number_of_cloud_instances_launched/) | [Cloud Accounts](/tags/#cloud-accounts), [Valid Accounts](/tags/#valid-accounts)| Anomaly | - -#### Reference - -* [https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf](https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/suspicious_cloud_instance_activities.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/suspicious_cloud_provisioning_activities.md b/docs/_stories/suspicious_cloud_provisioning_activities.md deleted file mode 100644 index 450fe8e90f..0000000000 --- a/docs/_stories/suspicious_cloud_provisioning_activities.md +++ /dev/null @@ -1,47 +0,0 @@ ---- -title: "Suspicious Cloud Provisioning Activities" -last_modified_at: 2018-08-20 -toc: true -toc_label: "" -tags: - - Splunk Security Analytics for AWS - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Change - - Actions on Objectives ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Monitor your cloud infrastructure provisioning activities for behaviors originating from unfamiliar or unusual locations. These behaviors may indicate that malicious activities are occurring somewhere within your cloud environment. - -- **Product**: Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Change](https://docs.splunk.com/Documentation/CIM/latest/User/Change) -- **Last Updated**: 2018-08-20 -- **Author**: David Dorsey, Splunk -- **ID**: 51045ded-1575-4ba6-aef7-af6c73cffd86 - -#### Narrative - -Because most enterprise cloud infrastructure activities originate from familiar geographic locations, monitoring for activity from unknown or unusual regions is an important security measure. This indicator can be especially useful in environments where it is impossible to add specific IPs to an allow list because they vary.\ -This Analytic Story was designed to provide you with flexibility in the precision you employ in specifying legitimate geographic regions. It can be as specific as an IP address or a city, or as broad as a region (think state) or an entire country. By determining how precise you want your geographical locations to be and monitoring for new locations that haven't previously accessed your environment, you can detect adversaries as they begin to probe your environment. Since there are legitimate reasons for activities from unfamiliar locations, this is not a standalone indicator. Nevertheless, location can be a relevant piece of information that you may wish to investigate further. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Cloud Provisioning Activity From Previously Unseen City](/cloud/cloud_provisioning_activity_from_previously_unseen_city/) | [Valid Accounts](/tags/#valid-accounts)| Anomaly | -| [Cloud Provisioning Activity From Previously Unseen Country](/cloud/cloud_provisioning_activity_from_previously_unseen_country/) | [Valid Accounts](/tags/#valid-accounts)| Anomaly | -| [Cloud Provisioning Activity From Previously Unseen IP Address](/cloud/cloud_provisioning_activity_from_previously_unseen_ip_address/) | [Valid Accounts](/tags/#valid-accounts)| Anomaly | -| [Cloud Provisioning Activity From Previously Unseen Region](/cloud/cloud_provisioning_activity_from_previously_unseen_region/) | [Valid Accounts](/tags/#valid-accounts)| Anomaly | - -#### Reference - -* [https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf](https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/suspicious_cloud_provisioning_activities.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/suspicious_cloud_user_activities.md b/docs/_stories/suspicious_cloud_user_activities.md deleted file mode 100644 index 97550ddb7e..0000000000 --- a/docs/_stories/suspicious_cloud_user_activities.md +++ /dev/null @@ -1,50 +0,0 @@ ---- -title: "Suspicious Cloud User Activities" -last_modified_at: 2020-09-04 -toc: true -toc_label: "" -tags: - - Splunk Security Analytics for AWS - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Change - - Actions on Objectives - - Reconnaissance ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Detect and investigate suspicious activities by users and roles in your cloud environments. - -- **Product**: Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Change](https://docs.splunk.com/Documentation/CIM/latest/User/Change) -- **Last Updated**: 2020-09-04 -- **Author**: David Dorsey, Splunk -- **ID**: 1ed5ce7d-5469-4232-92af-89d1a3595b39 - -#### Narrative - -It seems obvious that it is critical to monitor and control the users who have access to your cloud infrastructure. Nevertheless, it's all too common for enterprises to lose track of ad-hoc accounts, leaving their servers vulnerable to attack. In fact, this was the very oversight that led to Tesla's cryptojacking attack in February, 2018.\ -In addition to compromising the security of your data, when bad actors leverage your compute resources, it can incur monumental costs, since you will be billed for any new instances and increased bandwidth usage. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Abnormally High Number Of Cloud Infrastructure API Calls](/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls/) | [Cloud Accounts](/tags/#cloud-accounts), [Valid Accounts](/tags/#valid-accounts)| Anomaly | -| [Abnormally High Number Of Cloud Security Group API Calls](/cloud/abnormally_high_number_of_cloud_security_group_api_calls/) | [Cloud Accounts](/tags/#cloud-accounts), [Valid Accounts](/tags/#valid-accounts)| Anomaly | -| [AWS IAM AccessDenied Discovery Events](/cloud/aws_iam_accessdenied_discovery_events/) | [Cloud Infrastructure Discovery](/tags/#cloud-infrastructure-discovery)| Anomaly | -| [AWS Lambda UpdateFunctionCode](/cloud/aws_lambda_updatefunctioncode/) | [User Execution](/tags/#user-execution)| Hunting | -| [Cloud API Calls From Previously Unseen User Roles](/cloud/cloud_api_calls_from_previously_unseen_user_roles/) | [Valid Accounts](/tags/#valid-accounts)| Anomaly | - -#### Reference - -* [https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf](https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf) -* [https://redlock.io/blog/cryptojacking-tesla](https://redlock.io/blog/cryptojacking-tesla) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/suspicious_cloud_user_activities.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/suspicious_command-line_executions.md b/docs/_stories/suspicious_command-line_executions.md deleted file mode 100644 index 8110604e98..0000000000 --- a/docs/_stories/suspicious_command-line_executions.md +++ /dev/null @@ -1,52 +0,0 @@ ---- -title: "Suspicious Command-Line Executions" -last_modified_at: 2020-02-03 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Actions on Objectives - - Command & Control - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Leveraging the Windows command-line interface (CLI) is one of the most common attack techniques--one that is also detailed in the MITRE ATT&CK framework. Use this Analytic Story to help you identify unusual or suspicious use of the CLI on Windows systems. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2020-02-03 -- **Author**: Bhavin Patel, Splunk -- **ID**: f4368ddf-d59f-4192-84f6-778ac5a3ffc7 - -#### Narrative - -The ability to execute arbitrary commands via the Windows CLI is a primary goal for the adversary. With access to the shell, an attacker can easily run scripts and interact with the target system. Often, attackers may only have limited access to the shell or may obtain access in unusual ways. In addition, malware may execute and interact with the CLI in ways that would be considered unusual and inconsistent with typical user activity. This provides defenders with opportunities to identify suspicious use and investigate, as appropriate. This Analytic Story contains various searches to help identify this suspicious activity, as well as others to aid you in deeper investigation. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [First time seen command line argument](/deprecated/first_time_seen_command_line_argument/) | [PowerShell](/tags/#powershell), [Windows Command Shell](/tags/#windows-command-shell)| Hunting | -| [Detect Prohibited Applications Spawning cmd exe](/endpoint/detect_prohibited_applications_spawning_cmd_exe/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Windows Command Shell](/tags/#windows-command-shell)| Hunting | -| [Detect Use of cmd exe to Launch Script Interpreters](/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Windows Command Shell](/tags/#windows-command-shell)| TTP | -| [Potentially malicious code on commandline](/endpoint/potentially_malicious_code_on_commandline/) | [Windows Command Shell](/tags/#windows-command-shell)| Anomaly | -| [System Processes Run From Unexpected Locations](/endpoint/system_processes_run_from_unexpected_locations/) | [Masquerading](/tags/#masquerading), [Rename System Utilities](/tags/#rename-system-utilities)| TTP | -| [Unusually Long Command Line](/endpoint/unusually_long_command_line/) | None| Anomaly | -| [Unusually Long Command Line - MLTK](/endpoint/unusually_long_command_line_-_mltk/) | None| Anomaly | - -#### Reference - -* [https://attack.mitre.org/wiki/Technique/T1059](https://attack.mitre.org/wiki/Technique/T1059) -* [https://www.microsoft.com/en-us/wdsi/threats/macro-malware](https://www.microsoft.com/en-us/wdsi/threats/macro-malware) -* [https://www.fireeye.com/content/dam/fireeye-www/services/pdfs/mandiant-apt1-report.pdf](https://www.fireeye.com/content/dam/fireeye-www/services/pdfs/mandiant-apt1-report.pdf) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/suspicious_command-line_executions.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_stories/suspicious_compiled_html_activity.md b/docs/_stories/suspicious_compiled_html_activity.md deleted file mode 100644 index a66ceec586..0000000000 --- a/docs/_stories/suspicious_compiled_html_activity.md +++ /dev/null @@ -1,50 +0,0 @@ ---- -title: "Suspicious Compiled HTML Activity" -last_modified_at: 2021-02-11 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Actions on Objectives ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Monitor and detect techniques used by attackers who leverage the mshta.exe process to execute malicious code. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-02-11 -- **Author**: Michael Haag, Splunk -- **ID**: a09db4d1-3827-4833-87b8-3a397e532119 - -#### Narrative - -Adversaries may abuse Compiled HTML files (.chm) to conceal malicious code. CHM files are commonly distributed as part of the Microsoft HTML Help system. CHM files are compressed compilations of various content such as HTML documents, images, and scripting/web related programming languages such VBA, JScript, Java, and ActiveX. CHM content is displayed using underlying components of the Internet Explorer browser loaded by the HTML Help executable program (hh.exe). \ -HH.exe relies upon hhctrl.ocx to load CHM topics.This will load upon execution of a chm file. \ -During investigation, review all parallel processes and child processes. It is possible for file modification events to occur and it is best to capture the CHM file and decompile it for further analysis. \ -Upon usage of InfoTech Storage Handlers, ms-its, its, mk, itss.dll will load. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Detect HTML Help Renamed](/endpoint/detect_html_help_renamed/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Compiled HTML File](/tags/#compiled-html-file)| Hunting | -| [Detect HTML Help Spawn Child Process](/endpoint/detect_html_help_spawn_child_process/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Compiled HTML File](/tags/#compiled-html-file)| TTP | -| [Detect HTML Help URL in Command Line](/endpoint/detect_html_help_url_in_command_line/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Compiled HTML File](/tags/#compiled-html-file)| TTP | -| [Detect HTML Help Using InfoTech Storage Handlers](/endpoint/detect_html_help_using_infotech_storage_handlers/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Compiled HTML File](/tags/#compiled-html-file)| TTP | - -#### Reference - -* [https://redcanary.com/blog/introducing-atomictestharnesses/](https://redcanary.com/blog/introducing-atomictestharnesses/) -* [https://attack.mitre.org/techniques/T1218/001/](https://attack.mitre.org/techniques/T1218/001/) -* [https://docs.microsoft.com/en-us/windows/win32/api/htmlhelp/nf-htmlhelp-htmlhelpa](https://docs.microsoft.com/en-us/windows/win32/api/htmlhelp/nf-htmlhelp-htmlhelpa) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/suspicious_compiled_html_activity.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/suspicious_dns_traffic.md b/docs/_stories/suspicious_dns_traffic.md deleted file mode 100644 index 427fd5c281..0000000000 --- a/docs/_stories/suspicious_dns_traffic.md +++ /dev/null @@ -1,56 +0,0 @@ ---- -title: "Suspicious DNS Traffic" -last_modified_at: 2017-09-18 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Network_Resolution - - Actions on Objectives - - Command & Control - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Attackers often attempt to hide within or otherwise abuse the domain name system (DNS). You can thwart attempts to manipulate this omnipresent protocol by monitoring for these types of abuses. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint), [Network_Resolution](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkResolution) -- **Last Updated**: 2017-09-18 -- **Author**: Rico Valdez, Splunk -- **ID**: 3c3835c0-255d-4f9e-ab84-e29ec9ec9b56 - -#### Narrative - -Although DNS is one of the fundamental underlying protocols that make the Internet work, it is often ignored (perhaps because of its complexity and effectiveness). However, attackers have discovered ways to abuse the protocol to meet their objectives. One potential abuse involves manipulating DNS to hijack traffic and redirect it to an IP address under the attacker's control. This could inadvertently send users intending to visit google.com, for example, to an unrelated malicious website. Another technique involves using the DNS protocol for command-and-control activities with the attacker's malicious code or to covertly exfiltrate data. The searches within this Analytic Story look for these types of abuses. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Clients Connecting to Multiple DNS Servers](/deprecated/clients_connecting_to_multiple_dns_servers/) | [Exfiltration Over Unencrypted Non-C2 Protocol](/tags/#exfiltration-over-unencrypted-non-c2-protocol)| TTP | -| [Detect Long DNS TXT Record Response](/deprecated/detect_long_dns_txt_record_response/) | [Exfiltration Over Unencrypted Non-C2 Protocol](/tags/#exfiltration-over-unencrypted-non-c2-protocol)| TTP | -| [Detection of DNS Tunnels](/deprecated/detection_of_dns_tunnels/) | [Exfiltration Over Unencrypted Non-C2 Protocol](/tags/#exfiltration-over-unencrypted-non-c2-protocol)| TTP | -| [DNS Query Requests Resolved by Unauthorized DNS Servers](/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers/) | [DNS](/tags/#dns)| TTP | -| [DNS Exfiltration Using Nslookup App](/endpoint/dns_exfiltration_using_nslookup_app/) | [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol)| TTP | -| [Excessive Usage of NSLOOKUP App](/endpoint/excessive_usage_of_nslookup_app/) | [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol)| Anomaly | -| [DNS Query Length Outliers - MLTK](/network/dns_query_length_outliers_-_mltk/) | [DNS](/tags/#dns), [Application Layer Protocol](/tags/#application-layer-protocol)| Anomaly | -| [Excessive DNS Failures](/network/excessive_dns_failures/) | [DNS](/tags/#dns), [Application Layer Protocol](/tags/#application-layer-protocol)| Anomaly | -| [Detect hosts connecting to dynamic domain providers](/network/detect_hosts_connecting_to_dynamic_domain_providers/) | [Drive-by Compromise](/tags/#drive-by-compromise)| TTP | -| [DNS Query Length With High Standard Deviation](/network/dns_query_length_with_high_standard_deviation/) | [Exfiltration Over Unencrypted Non-C2 Protocol](/tags/#exfiltration-over-unencrypted-non-c2-protocol), [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol)| Anomaly | - -#### Reference - -* [http://blogs.splunk.com/2015/10/01/random-words-on-entropy-and-dns/](http://blogs.splunk.com/2015/10/01/random-words-on-entropy-and-dns/) -* [http://www.darkreading.com/analytics/security-monitoring/got-malware-three-signs-revealed-in-dns-traffic/d/d-id/1139680](http://www.darkreading.com/analytics/security-monitoring/got-malware-three-signs-revealed-in-dns-traffic/d/d-id/1139680) -* [https://live.paloaltonetworks.com/t5/Threat-Vulnerability-Articles/What-are-suspicious-DNS-queries/ta-p/71454](https://live.paloaltonetworks.com/t5/Threat-Vulnerability-Articles/What-are-suspicious-DNS-queries/ta-p/71454) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/suspicious_dns_traffic.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/suspicious_emails.md b/docs/_stories/suspicious_emails.md deleted file mode 100644 index e5b935dac8..0000000000 --- a/docs/_stories/suspicious_emails.md +++ /dev/null @@ -1,50 +0,0 @@ ---- -title: "Suspicious Emails" -last_modified_at: 2020-01-27 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Email - - UEBA - - Delivery ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Email remains one of the primary means for attackers to gain an initial foothold within the modern enterprise. Detect and investigate suspicious emails in your environment with the help of the searches in this Analytic Story. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Email](https://docs.splunk.com/Documentation/CIM/latest/User/Email), [UEBA](https://docs.splunk.com/Documentation/CIM/latest/User/UEBA) -- **Last Updated**: 2020-01-27 -- **Author**: Bhavin Patel, Splunk -- **ID**: 2b1800dd-92f9-47ec-a981-fdf1351e5d55 - -#### Narrative - -It is a common practice for attackers of all types to leverage targeted spearphishing campaigns and mass mailers to deliver weaponized email messages and attachments. Fortunately, there are a number of ways to monitor email data in Splunk to detect suspicious content.\ -Once a phishing message has been detected, the next steps are to answer the following questions: \ -1. Which users have received this or a similar message in the past?\ -1. When did the targeted campaign begin?\ -1. Have any users interacted with the content of the messages (by downloading an attachment or clicking on a malicious URL)?This Analytic Story provides detection searches to identify suspicious emails, as well as contextual and investigative searches to help answer some of these questions. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Suspicious Email - UBA Anomaly](/deprecated/suspicious_email_-_uba_anomaly/) | [Phishing](/tags/#phishing)| Anomaly | -| [Email Attachments With Lots Of Spaces](/application/email_attachments_with_lots_of_spaces/) | None| Anomaly | -| [Monitor Email For Brand Abuse](/application/monitor_email_for_brand_abuse/) | None| TTP | -| [Suspicious Email Attachment Extensions](/application/suspicious_email_attachment_extensions/) | [Spearphishing Attachment](/tags/#spearphishing-attachment), [Phishing](/tags/#phishing)| Anomaly | - -#### Reference - -* [https://www.splunk.com/blog/2015/06/26/phishing-hits-a-new-level-of-quality/](https://www.splunk.com/blog/2015/06/26/phishing-hits-a-new-level-of-quality/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/suspicious_emails.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/suspicious_gcp_storage_activities.md b/docs/_stories/suspicious_gcp_storage_activities.md deleted file mode 100644 index de12c58c83..0000000000 --- a/docs/_stories/suspicious_gcp_storage_activities.md +++ /dev/null @@ -1,43 +0,0 @@ ---- -title: "Suspicious GCP Storage Activities" -last_modified_at: 2020-08-05 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Actions on Objectives ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Use the searches in this Analytic Story to monitor your GCP Storage buckets for evidence of anomalous activity and suspicious behaviors, such as detecting open storage buckets and buckets being accessed from a new IP. The contextual and investigative searches will give you more information, when required. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: -- **Last Updated**: 2020-08-05 -- **Author**: Shannon Davis, Splunk -- **ID**: 4d656b2e-d6be-11ea-87d0-0242ac130003 - -#### Narrative - -Similar to other cloud providers, GCP operates on a shared responsibility model. This means the end user, you, are responsible for setting appropriate access control lists and permissions on your GCP resources.\ This Analytics Story concentrates on detecting things like open storage buckets (both read and write) along with storage bucket access from unfamiliar users and IP addresses. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Detect GCP Storage access from a new IP](/cloud/detect_gcp_storage_access_from_a_new_ip/) | [Data from Cloud Storage Object](/tags/#data-from-cloud-storage-object)| Anomaly | -| [Detect New Open GCP Storage Buckets](/cloud/detect_new_open_gcp_storage_buckets/) | [Data from Cloud Storage Object](/tags/#data-from-cloud-storage-object)| TTP | - -#### Reference - -* [https://cloud.google.com/blog/products/gcp/4-steps-for-hardening-your-cloud-storage-buckets-taking-charge-of-your-security](https://cloud.google.com/blog/products/gcp/4-steps-for-hardening-your-cloud-storage-buckets-taking-charge-of-your-security) -* [https://rhinosecuritylabs.com/gcp/google-cloud-platform-gcp-bucket-enumeration/](https://rhinosecuritylabs.com/gcp/google-cloud-platform-gcp-bucket-enumeration/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/suspicious_gcp_storage_activities.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/suspicious_mshta_activity.md b/docs/_stories/suspicious_mshta_activity.md deleted file mode 100644 index c69daf5ef9..0000000000 --- a/docs/_stories/suspicious_mshta_activity.md +++ /dev/null @@ -1,65 +0,0 @@ ---- -title: "Suspicious MSHTA Activity" -last_modified_at: 2021-01-20 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Actions on Objectives - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Monitor and detect techniques used by attackers who leverage the mshta.exe process to execute malicious code. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-01-20 -- **Author**: Bhavin Patel, Michael Haag, Splunk -- **ID**: 1e5a5a53-540b-462a-8fb7-f44a4292f5dc - -#### Narrative - -One common adversary tactic is to bypass application control solutions via the mshta.exe process, which loads Microsoft HTML applications (mshtml.dll) with the .hta suffix. In these cases, attackers use the trusted Windows utility to proxy execution of malicious files, whether an .hta application, javascript, or VBScript.\ -The searches in this story help you detect and investigate suspicious activity that may indicate that an attacker is leveraging mshta.exe to execute malicious code.\ -Triage\ -Validate execution \ -1. Determine if MSHTA.exe executed. Validate the OriginalFileName of MSHTA.exe and further PE metadata. If executed outside of c:\windows\system32 or c:\windows\syswow64, it should be highly suspect.\ -1. Determine if script code was executed with MSHTA.\ -Situational Awareness\ -The objective of this step is meant to identify suspicious behavioral indicators related to executed of Script code by MSHTA.exe.\ -1. Parent process. Is the parent process a known LOLBin? Is the parent process an Office Application?\ -1. Module loads. Are the known MSHTA.exe modules being loaded by a non-standard application? Is MSHTA loading any suspicious .DLLs?\ -1. Network connections. Any network connections? Review the reputation of the remote IP or domain.\ -Retrieval of script code\ -The objective of this step is to confirm the executed script code is benign or malicious. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Detect mshta inline hta execution](/endpoint/detect_mshta_inline_hta_execution/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Mshta](/tags/#mshta)| TTP | -| [Detect mshta renamed](/endpoint/detect_mshta_renamed/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Mshta](/tags/#mshta)| Hunting | -| [Detect MSHTA Url in Command Line](/endpoint/detect_mshta_url_in_command_line/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Mshta](/tags/#mshta)| TTP | -| [Detect Prohibited Applications Spawning cmd exe](/endpoint/detect_prohibited_applications_spawning_cmd_exe/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Windows Command Shell](/tags/#windows-command-shell)| Hunting | -| [Detect Rundll32 Inline HTA Execution](/endpoint/detect_rundll32_inline_hta_execution/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Mshta](/tags/#mshta)| TTP | -| [Registry Keys Used For Persistence](/endpoint/registry_keys_used_for_persistence/) | [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution)| TTP | -| [Suspicious mshta child process](/endpoint/suspicious_mshta_child_process/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Mshta](/tags/#mshta)| TTP | -| [Suspicious mshta spawn](/endpoint/suspicious_mshta_spawn/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Mshta](/tags/#mshta)| TTP | - -#### Reference - -* [https://redcanary.com/blog/introducing-atomictestharnesses/](https://redcanary.com/blog/introducing-atomictestharnesses/) -* [https://redcanary.com/blog/windows-registry-attacks-threat-detection/](https://redcanary.com/blog/windows-registry-attacks-threat-detection/) -* [https://attack.mitre.org/techniques/T1218/005/](https://attack.mitre.org/techniques/T1218/005/) -* [https://medium.com/@mbromileyDFIR/malware-monday-aebb456356c5](https://medium.com/@mbromileyDFIR/malware-monday-aebb456356c5) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/suspicious_mshta_activity.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_stories/suspicious_okta_activity.md b/docs/_stories/suspicious_okta_activity.md deleted file mode 100644 index ecb34b2f7a..0000000000 --- a/docs/_stories/suspicious_okta_activity.md +++ /dev/null @@ -1,48 +0,0 @@ ---- -title: "Suspicious Okta Activity" -last_modified_at: 2020-04-02 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Monitor your Okta environment for suspicious activities. Due to the Covid outbreak, many users are migrating over to leverage cloud services more and more. Okta is a popular tool to manage multiple users and the web-based applications they need to stay productive. The searches in this story will help monitor your Okta environment for suspicious activities and associated user behaviors. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: -- **Last Updated**: 2020-04-02 -- **Author**: Rico Valdez, Splunk -- **ID**: 9cbd34af-8f39-4476-a423-bacd126c750b - -#### Narrative - -Okta is the leading single sign on (SSO) provider, allowing users to authenticate once to Okta, and from there access a variety of web-based applications. These applications are assigned to users and allow administrators to centrally manage which users are allowed to access which applications. It also provides centralized logging to help understand how the applications are used and by whom. \ -While SSO is a major convenience for users, it also provides attackers with an opportunity. If the attacker can gain access to Okta, they can access a variety of applications. As such monitoring the environment is important. \ -With people moving quickly to adopt web-based applications and ways to manage them, many are still struggling to understand how best to monitor these environments. This analytic story provides searches to help monitor this environment, and identify events and activity that warrant further investigation such as credential stuffing or password spraying attacks, and users logging in from multiple locations when travel is disallowed. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Multiple Okta Users With Invalid Credentials From The Same IP](/application/multiple_okta_users_with_invalid_credentials_from_the_same_ip/) | [Valid Accounts](/tags/#valid-accounts), [Default Accounts](/tags/#default-accounts)| TTP | -| [Okta Account Lockout Events](/application/okta_account_lockout_events/) | [Valid Accounts](/tags/#valid-accounts), [Default Accounts](/tags/#default-accounts)| Anomaly | -| [Okta Failed SSO Attempts](/application/okta_failed_sso_attempts/) | [Valid Accounts](/tags/#valid-accounts), [Default Accounts](/tags/#default-accounts)| Anomaly | -| [Okta User Logins From Multiple Cities](/application/okta_user_logins_from_multiple_cities/) | [Valid Accounts](/tags/#valid-accounts), [Default Accounts](/tags/#default-accounts)| Anomaly | - -#### Reference - -* [https://attack.mitre.org/wiki/Technique/T1078](https://attack.mitre.org/wiki/Technique/T1078) -* [https://owasp.org/www-community/attacks/Credential_stuffing](https://owasp.org/www-community/attacks/Credential_stuffing) -* [https://searchsecurity.techtarget.com/answer/What-is-a-password-spraying-attack-and-how-does-it-work](https://searchsecurity.techtarget.com/answer/What-is-a-password-spraying-attack-and-how-does-it-work) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/suspicious_okta_activity.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/suspicious_regsvcs_regasm_activity.md b/docs/_stories/suspicious_regsvcs_regasm_activity.md deleted file mode 100644 index 348fe881a1..0000000000 --- a/docs/_stories/suspicious_regsvcs_regasm_activity.md +++ /dev/null @@ -1,49 +0,0 @@ ---- -title: "Suspicious Regsvcs Regasm Activity" -last_modified_at: 2021-02-11 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Actions on Objectives ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Monitor and detect techniques used by attackers who leverage the mshta.exe process to execute malicious code. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-02-11 -- **Author**: Michael Haag, Splunk -- **ID**: 2cdf33a0-4805-4b61-b025-59c20f418fbe - -#### Narrative - - Adversaries may abuse Regsvcs and Regasm to proxy execution of code through a trusted Windows utility. Regsvcs and Regasm are Windows command-line utilities that are used to register .NET Component Object Model (COM) assemblies. Both are digitally signed by Microsoft. The following queries assist with detecting suspicious and malicious usage of Regasm.exe and Regsvcs.exe. Upon reviewing usage of Regasm.exe Regsvcs.exe, review file modification events for possible script code written. Review parallel process events for csc.exe being utilized to compile script code. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Detect Regasm Spawning a Process](/endpoint/detect_regasm_spawning_a_process/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Regsvcs/Regasm](/tags/#regsvcs/regasm)| TTP | -| [Detect Regasm with Network Connection](/endpoint/detect_regasm_with_network_connection/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Regsvcs/Regasm](/tags/#regsvcs/regasm)| TTP | -| [Detect Regasm with no Command Line Arguments](/endpoint/detect_regasm_with_no_command_line_arguments/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Regsvcs/Regasm](/tags/#regsvcs/regasm)| TTP | -| [Detect Regsvcs Spawning a Process](/endpoint/detect_regsvcs_spawning_a_process/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Regsvcs/Regasm](/tags/#regsvcs/regasm)| TTP | -| [Detect Regsvcs with Network Connection](/endpoint/detect_regsvcs_with_network_connection/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Regsvcs/Regasm](/tags/#regsvcs/regasm)| TTP | -| [Detect Regsvcs with No Command Line Arguments](/endpoint/detect_regsvcs_with_no_command_line_arguments/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Regsvcs/Regasm](/tags/#regsvcs/regasm)| TTP | - -#### Reference - -* [https://attack.mitre.org/techniques/T1218/009/](https://attack.mitre.org/techniques/T1218/009/) -* [https://github.com/rapid7/metasploit-framework/blob/master/documentation/modules/evasion/windows/applocker_evasion_regasm_regsvcs.md](https://github.com/rapid7/metasploit-framework/blob/master/documentation/modules/evasion/windows/applocker_evasion_regasm_regsvcs.md) -* [https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/](https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/suspicious_regsvcs_regasm_activity.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/suspicious_regsvr32_activity.md b/docs/_stories/suspicious_regsvr32_activity.md deleted file mode 100644 index bd5882e26b..0000000000 --- a/docs/_stories/suspicious_regsvr32_activity.md +++ /dev/null @@ -1,49 +0,0 @@ ---- -title: "Suspicious Regsvr32 Activity" -last_modified_at: 2021-01-29 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Actions on Objectives - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Monitor and detect techniques used by attackers who leverage the regsvr32.exe process to execute malicious code. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-01-29 -- **Author**: Michael Haag, Splunk -- **ID**: b8bee41e-624f-11eb-ae93-0242ac130002 - -#### Narrative - -One common adversary tactic is to bypass application control solutions via the regsvr32.exe process. This particular bypass was popularized with "SquiblyDoo" using the "scrobj.dll" dll to load .sct scriptlets. This technique is still widely used by adversaries to bypass detection and prevention controls. The file extension of the DLL is irrelevant (it may load a .txt file extension for example). The searches in this story help you detect and investigate suspicious activity that may indicate that an adversary is leveraging regsvr32.exe to execute malicious code. Validate execution Determine if regsvr32.exe executed. Validate the OriginalFileName of regsvr32.exe and further PE metadata. If executed outside of c:\windows\system32 or c:\windows\syswow64, it should be highly suspect. Determine if script code was executed with regsvr32. Situational Awareness - The objective of this step is meant to identify suspicious behavioral indicators related to executed of Script code by regsvr32.exe. Parent process. Is the parent process a known LOLBin? Is the parent process an Office Application? Module loads. Is regsvr32 loading any suspicious .DLLs? Unsigned or signed from non-standard paths. Network connections. Any network connections? Review the reputation of the remote IP or domain. Retrieval of Script Code - confirm the executed script code is benign or malicious. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Detect Regsvr32 Application Control Bypass](/endpoint/detect_regsvr32_application_control_bypass/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Regsvr32](/tags/#regsvr32)| TTP | -| [Malicious InProcServer32 Modification](/endpoint/malicious_inprocserver32_modification/) | [Regsvr32](/tags/#regsvr32), [Modify Registry](/tags/#modify-registry)| TTP | -| [Regsvr32 Silent and Install Param Dll Loading](/endpoint/regsvr32_silent_and_install_param_dll_loading/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Regsvr32](/tags/#regsvr32)| Anomaly | -| [Regsvr32 with Known Silent Switch Cmdline](/endpoint/regsvr32_with_known_silent_switch_cmdline/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Regsvr32](/tags/#regsvr32)| Anomaly | -| [Suspicious Regsvr32 Register Suspicious Path](/endpoint/suspicious_regsvr32_register_suspicious_path/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Regsvr32](/tags/#regsvr32)| TTP | - -#### Reference - -* [https://attack.mitre.org/techniques/T1218/010/](https://attack.mitre.org/techniques/T1218/010/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.010/T1218.010.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.010/T1218.010.md) -* [https://lolbas-project.github.io/lolbas/Binaries/Regsvr32/](https://lolbas-project.github.io/lolbas/Binaries/Regsvr32/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/suspicious_regsvr32_activity.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/suspicious_rundll32_activity.md b/docs/_stories/suspicious_rundll32_activity.md deleted file mode 100644 index 24e21a3e9d..0000000000 --- a/docs/_stories/suspicious_rundll32_activity.md +++ /dev/null @@ -1,57 +0,0 @@ ---- -title: "Suspicious Rundll32 Activity" -last_modified_at: 2021-02-03 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Actions on Objectives - - Exploitation - - Installation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Monitor and detect techniques used by attackers who leverage rundll32.exe to execute arbitrary malicious code. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-02-03 -- **Author**: Michael Haag, Splunk -- **ID**: 80a65487-854b-42f1-80a1-935e4c170694 - -#### Narrative - -One common adversary tactic is to bypass application control solutions via the rundll32.exe process. Natively, rundll32.exe will load DLLs and is a great example of a Living off the Land Binary. Rundll32.exe may load malicious DLLs by ordinals, function names or directly. The queries in this story focus on loading default DLLs, syssetup.dll, ieadvpack.dll, advpack.dll and setupapi.dll from disk that may be abused by adversaries. Additionally, two analytics developed to assist with identifying DLLRegisterServer, Start and StartW functions being called. The searches in this story help you detect and investigate suspicious activity that may indicate that an adversary is leveraging rundll32.exe to execute malicious code. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Suspicious Rundll32 Rename](/deprecated/suspicious_rundll32_rename/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Masquerading](/tags/#masquerading), [Rundll32](/tags/#rundll32), [Rename System Utilities](/tags/#rename-system-utilities)| Hunting | -| [Detect Rundll32 Application Control Bypass - advpack](/endpoint/detect_rundll32_application_control_bypass_-_advpack/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Rundll32](/tags/#rundll32)| TTP | -| [Detect Rundll32 Application Control Bypass - setupapi](/endpoint/detect_rundll32_application_control_bypass_-_setupapi/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Rundll32](/tags/#rundll32)| TTP | -| [Detect Rundll32 Application Control Bypass - syssetup](/endpoint/detect_rundll32_application_control_bypass_-_syssetup/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Rundll32](/tags/#rundll32)| TTP | -| [Dump LSASS via comsvcs DLL](/endpoint/dump_lsass_via_comsvcs_dll/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping)| TTP | -| [Rundll32 Control RunDLL Hunt](/endpoint/rundll32_control_rundll_hunt/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Rundll32](/tags/#rundll32)| Hunting | -| [Rundll32 Control RunDLL World Writable Directory](/endpoint/rundll32_control_rundll_world_writable_directory/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Rundll32](/tags/#rundll32)| TTP | -| [Rundll32 with no Command Line Arguments with Network](/endpoint/rundll32_with_no_command_line_arguments_with_network/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Rundll32](/tags/#rundll32)| TTP | -| [RunDLL Loading DLL By Ordinal](/endpoint/rundll_loading_dll_by_ordinal/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Rundll32](/tags/#rundll32)| TTP | -| [Suspicious Rundll32 dllregisterserver](/endpoint/suspicious_rundll32_dllregisterserver/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Rundll32](/tags/#rundll32)| TTP | -| [Suspicious Rundll32 StartW](/endpoint/suspicious_rundll32_startw/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Rundll32](/tags/#rundll32)| TTP | -| [Suspicious Rundll32 no Command Line Arguments](/endpoint/suspicious_rundll32_no_command_line_arguments/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Rundll32](/tags/#rundll32)| TTP | - -#### Reference - -* [https://attack.mitre.org/techniques/T1218/011/](https://attack.mitre.org/techniques/T1218/011/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.011/T1218.011.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.011/T1218.011.md) -* [https://lolbas-project.github.io/lolbas/Binaries/Rundll32](https://lolbas-project.github.io/lolbas/Binaries/Rundll32) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/suspicious_rundll32_activity.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/suspicious_windows_registry_activities.md b/docs/_stories/suspicious_windows_registry_activities.md deleted file mode 100644 index e7dbed4ac2..0000000000 --- a/docs/_stories/suspicious_windows_registry_activities.md +++ /dev/null @@ -1,55 +0,0 @@ ---- -title: "Suspicious Windows Registry Activities" -last_modified_at: 2018-05-31 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Actions on Objectives - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Monitor and detect registry changes initiated from remote locations, which can be a sign that an attacker has infiltrated your system. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2018-05-31 -- **Author**: Bhavin Patel, Splunk -- **ID**: 2b1800dd-92f9-47dd-a981-fdf1351e5d55 - -#### Narrative - -Attackers are developing increasingly sophisticated techniques for hijacking target servers, while evading detection. One such technique that has become progressively more common is registry modification.\ - The registry is a key component of the Windows operating system. It has a hierarchical database called "registry" that contains settings, options, and values for executables. Once the threat actor gains access to a machine, they can use reg.exe to modify their account to obtain administrator-level privileges, maintain persistence, and move laterally within the environment.\ - The searches in this story are designed to help you detect behaviors associated with manipulation of the Windows registry. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Reg exe used to hide files directories via registry keys](/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys/) | [Hidden Files and Directories](/tags/#hidden-files-and-directories)| TTP | -| [Remote Registry Key modifications](/deprecated/remote_registry_key_modifications/) | None| TTP | -| [Suspicious Changes to File Associations](/deprecated/suspicious_changes_to_file_associations/) | [Change Default File Association](/tags/#change-default-file-association)| TTP | -| [Disable UAC Remote Restriction](/endpoint/disable_uac_remote_restriction/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism)| TTP | -| [Disabling Remote User Account Control](/endpoint/disabling_remote_user_account_control/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism)| TTP | -| [Monitor Registry Keys for Print Monitors](/endpoint/monitor_registry_keys_for_print_monitors/) | [Port Monitors](/tags/#port-monitors), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution)| TTP | -| [Registry Keys for Creating SHIM Databases](/endpoint/registry_keys_for_creating_shim_databases/) | [Application Shimming](/tags/#application-shimming), [Event Triggered Execution](/tags/#event-triggered-execution)| TTP | -| [Registry Keys Used For Persistence](/endpoint/registry_keys_used_for_persistence/) | [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution)| TTP | -| [Registry Keys Used For Privilege Escalation](/endpoint/registry_keys_used_for_privilege_escalation/) | [Image File Execution Options Injection](/tags/#image-file-execution-options-injection), [Event Triggered Execution](/tags/#event-triggered-execution)| TTP | -| [Windows Service Creation Using Registry Entry](/endpoint/windows_service_creation_using_registry_entry/) | [Services Registry Permissions Weakness](/tags/#services-registry-permissions-weakness)| TTP | - -#### Reference - -* [https://redcanary.com/blog/windows-registry-attacks-threat-detection/](https://redcanary.com/blog/windows-registry-attacks-threat-detection/) -* [https://attack.mitre.org/wiki/Technique/T1112](https://attack.mitre.org/wiki/Technique/T1112) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/suspicious_windows_registry_activities.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/suspicious_wmi_use.md b/docs/_stories/suspicious_wmi_use.md deleted file mode 100644 index 867fa3af99..0000000000 --- a/docs/_stories/suspicious_wmi_use.md +++ /dev/null @@ -1,54 +0,0 @@ ---- -title: "Suspicious WMI Use" -last_modified_at: 2018-10-23 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Actions on Objectives - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Attackers are increasingly abusing Windows Management Instrumentation (WMI), a framework and associated utilities available on all modern Windows operating systems. Because WMI can be leveraged to manage both local and remote systems, it is important to identify the processes executed and the user context within which the activity occurred. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2018-10-23 -- **Author**: Rico Valdez, Splunk -- **ID**: c8ddc5be-69bc-4202-b3ab-4010b27d7ad5 - -#### Narrative - -WMI is a Microsoft infrastructure for management data and operations on Windows operating systems. It includes of a set of utilities that can be leveraged to manage both local and remote Windows systems. Attackers are increasingly turning to WMI abuse in their efforts to conduct nefarious tasks, such as reconnaissance, detection of antivirus and virtual machines, code execution, lateral movement, persistence, and data exfiltration. The detection searches included in this Analytic Story are used to look for suspicious use of WMI commands that attackers may leverage to interact with remote systems. The searches specifically look for the use of WMI to run processes on remote systems. In the event that unauthorized WMI execution occurs, it will be important for analysts and investigators to determine the context of the event. These details may provide insights related to how WMI was used and to what end. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Detect WMI Event Subscription Persistence](/endpoint/detect_wmi_event_subscription_persistence/) | [Windows Management Instrumentation Event Subscription](/tags/#windows-management-instrumentation-event-subscription), [Event Triggered Execution](/tags/#event-triggered-execution)| TTP | -| [Process Execution via WMI](/endpoint/process_execution_via_wmi/) | [Windows Management Instrumentation](/tags/#windows-management-instrumentation)| TTP | -| [Remote Process Instantiation via WMI](/endpoint/remote_process_instantiation_via_wmi/) | [Windows Management Instrumentation](/tags/#windows-management-instrumentation)| TTP | -| [Remote WMI Command Attempt](/endpoint/remote_wmi_command_attempt/) | [Windows Management Instrumentation](/tags/#windows-management-instrumentation)| TTP | -| [Script Execution via WMI](/endpoint/script_execution_via_wmi/) | [Windows Management Instrumentation](/tags/#windows-management-instrumentation)| TTP | -| [Windows WMI Process Call Create](/endpoint/windows_wmi_process_call_create/) | [Windows Management Instrumentation](/tags/#windows-management-instrumentation)| Hunting | -| [WMI Permanent Event Subscription - Sysmon](/endpoint/wmi_permanent_event_subscription_-_sysmon/) | [Windows Management Instrumentation Event Subscription](/tags/#windows-management-instrumentation-event-subscription), [Event Triggered Execution](/tags/#event-triggered-execution)| TTP | -| [WMIC XSL Execution via URL](/endpoint/wmic_xsl_execution_via_url/) | [XSL Script Processing](/tags/#xsl-script-processing)| TTP | -| [XSL Script Execution With WMIC](/endpoint/xsl_script_execution_with_wmic/) | [XSL Script Processing](/tags/#xsl-script-processing)| TTP | -| [WMI Permanent Event Subscription](/endpoint/wmi_permanent_event_subscription/) | [Windows Management Instrumentation](/tags/#windows-management-instrumentation)| TTP | -| [WMI Temporary Event Subscription](/endpoint/wmi_temporary_event_subscription/) | [Windows Management Instrumentation](/tags/#windows-management-instrumentation)| TTP | - -#### Reference - -* [https://www.blackhat.com/docs/us-15/materials/us-15-Graeber-Abusing-Windows-Management-Instrumentation-WMI-To-Build-A-Persistent%20Asynchronous-And-Fileless-Backdoor-wp.pdf](https://www.blackhat.com/docs/us-15/materials/us-15-Graeber-Abusing-Windows-Management-Instrumentation-WMI-To-Build-A-Persistent%20Asynchronous-And-Fileless-Backdoor-wp.pdf) -* [https://web.archive.org/web/20210921091529/https://www.fireeye.com/blog/threat-research/2017/03/wmimplant_a_wmi_ba.html](https://web.archive.org/web/20210921091529/https://www.fireeye.com/blog/threat-research/2017/03/wmimplant_a_wmi_ba.html) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/suspicious_wmi_use.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_stories/suspicious_zoom_child_processes.md b/docs/_stories/suspicious_zoom_child_processes.md deleted file mode 100644 index 759265b3e1..0000000000 --- a/docs/_stories/suspicious_zoom_child_processes.md +++ /dev/null @@ -1,46 +0,0 @@ ---- -title: "Suspicious Zoom Child Processes" -last_modified_at: 2020-04-13 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Actions on Objectives - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Attackers are using Zoom as an vector to increase privileges on a sytems. This story detects new child processes of zoom and provides investigative actions for this detection. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2020-04-13 -- **Author**: David Dorsey, Splunk -- **ID**: aa3749a6-49c7-491e-a03f-4eaee5fe0258 - -#### Narrative - -Zoom is a leader in modern enterprise video communications and its usage has increased dramatically with a large amount of the population under stay-at-home orders due to the COVID-19 pandemic. With increased usage has come increased scrutiny and several security flaws have been found with this application on both Windows and macOS systems.\ -Current detections focus on finding new child processes of this application on a per host basis. Investigative searches are included to gather information needed during an investigation. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Detect Prohibited Applications Spawning cmd exe](/endpoint/detect_prohibited_applications_spawning_cmd_exe/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Windows Command Shell](/tags/#windows-command-shell)| Hunting | -| [First Time Seen Child Process of Zoom](/endpoint/first_time_seen_child_process_of_zoom/) | [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation)| Anomaly | - -#### Reference - -* [https://blog.rapid7.com/2020/04/02/dispelling-zoom-bugbears-what-you-need-to-know-about-the-latest-zoom-vulnerabilities/](https://blog.rapid7.com/2020/04/02/dispelling-zoom-bugbears-what-you-need-to-know-about-the-latest-zoom-vulnerabilities/) -* [https://threatpost.com/two-zoom-zero-day-flaws-uncovered/154337/](https://threatpost.com/two-zoom-zero-day-flaws-uncovered/154337/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/suspicious_zoom_child_processes.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/trickbot.md b/docs/_stories/trickbot.md deleted file mode 100644 index 87c8bc60c9..0000000000 --- a/docs/_stories/trickbot.md +++ /dev/null @@ -1,60 +0,0 @@ ---- -title: "Trickbot" -last_modified_at: 2021-04-20 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Actions on Objectives - - Exploitation - - Installation - - Reconnaissance ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Leverage searches that allow you to detect and investigate unusual activities that might relate to the trickbot banking trojan, including looking for file writes associated with its payload, process injection, shellcode execution and data collection even in LDAP environment. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-04-20 -- **Author**: Rod Soto, Teoderick Contreras, Splunk -- **ID**: 16f93769-8342-44c0-9b1d-f131937cce8e - -#### Narrative - -trickbot banking trojan campaigns targeting banks and other vertical sectors.This malware is known in Microsoft Windows OS where target security Microsoft Defender to prevent its detection and removal. steal Verizon credentials and targeting banks using its multi component modules that collect and exfiltrate data. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Account Discovery With Net App](/endpoint/account_discovery_with_net_app/) | [Domain Account](/tags/#domain-account), [Account Discovery](/tags/#account-discovery)| TTP | -| [Attempt To Stop Security Service](/endpoint/attempt_to_stop_security_service/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Cobalt Strike Named Pipes](/endpoint/cobalt_strike_named_pipes/) | [Process Injection](/tags/#process-injection)| TTP | -| [Executable File Written in Administrative SMB Share](/endpoint/executable_file_written_in_administrative_smb_share/) | [Remote Services](/tags/#remote-services), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares)| TTP | -| [Mshta spawning Rundll32 OR Regsvr32 Process](/endpoint/mshta_spawning_rundll32_or_regsvr32_process/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Mshta](/tags/#mshta)| TTP | -| [Office Application Spawn rundll32 process](/endpoint/office_application_spawn_rundll32_process/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment)| TTP | -| [Office Document Executing Macro Code](/endpoint/office_document_executing_macro_code/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment)| TTP | -| [Office Product Spawn CMD Process](/endpoint/office_product_spawn_cmd_process/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Mshta](/tags/#mshta)| TTP | -| [Powershell Remote Thread To Known Windows Process](/endpoint/powershell_remote_thread_to_known_windows_process/) | [Process Injection](/tags/#process-injection)| TTP | -| [Schedule Task with Rundll32 Command Trigger](/endpoint/schedule_task_with_rundll32_command_trigger/) | [Scheduled Task/Job](/tags/#scheduled-task/job)| TTP | -| [Suspicious Rundll32 StartW](/endpoint/suspicious_rundll32_startw/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Rundll32](/tags/#rundll32)| TTP | -| [Trickbot Named Pipe](/endpoint/trickbot_named_pipe/) | [Process Injection](/tags/#process-injection)| TTP | -| [Wermgr Process Connecting To IP Check Web Services](/endpoint/wermgr_process_connecting_to_ip_check_web_services/) | [Gather Victim Network Information](/tags/#gather-victim-network-information), [IP Addresses](/tags/#ip-addresses)| TTP | -| [Wermgr Process Create Executable File](/endpoint/wermgr_process_create_executable_file/) | [Obfuscated Files or Information](/tags/#obfuscated-files-or-information)| TTP | -| [Wermgr Process Spawned CMD Or Powershell Process](/endpoint/wermgr_process_spawned_cmd_or_powershell_process/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter)| TTP | - -#### Reference - -* [https://en.wikipedia.org/wiki/Trickbot](https://en.wikipedia.org/wiki/Trickbot) -* [https://blog.checkpoint.com/2021/03/11/february-2021s-most-wanted-malware-trickbot-takes-over-following-emotet-shutdown/](https://blog.checkpoint.com/2021/03/11/february-2021s-most-wanted-malware-trickbot-takes-over-following-emotet-shutdown/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/trickbot.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/trusted_developer_utilities_proxy_execution.md b/docs/_stories/trusted_developer_utilities_proxy_execution.md deleted file mode 100644 index fce1de6bf3..0000000000 --- a/docs/_stories/trusted_developer_utilities_proxy_execution.md +++ /dev/null @@ -1,46 +0,0 @@ ---- -title: "Trusted Developer Utilities Proxy Execution" -last_modified_at: 2021-01-12 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Monitor and detect behaviors used by attackers who leverage trusted developer utilities to execute malicious code. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-01-12 -- **Author**: Michael Haag, Splunk -- **ID**: 270a67a6-55d8-11eb-ae93-0242ac130002 - -#### Narrative - -Adversaries may take advantage of trusted developer utilities to proxy execution of malicious payloads. There are many utilities used for software development related tasks that can be used to execute code in various forms to assist in development, debugging, and reverse engineering. These utilities may often be signed with legitimate certificates that allow them to execute on a system and proxy execution of malicious code through a trusted process that effectively bypasses application control solutions.\ -The searches in this story help you detect and investigate suspicious activity that may indicate that an adversary is leveraging microsoft.workflow.compiler.exe to execute malicious code. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Suspicious microsoft workflow compiler rename](/endpoint/suspicious_microsoft_workflow_compiler_rename/) | [Masquerading](/tags/#masquerading), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Rename System Utilities](/tags/#rename-system-utilities)| Hunting | -| [Suspicious microsoft workflow compiler usage](/endpoint/suspicious_microsoft_workflow_compiler_usage/) | [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution)| TTP | - -#### Reference - -* [https://attack.mitre.org/techniques/T1127/](https://attack.mitre.org/techniques/T1127/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218/T1218.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218/T1218.md) -* [https://lolbas-project.github.io/lolbas/Binaries/Microsoft.Workflow.Compiler/](https://lolbas-project.github.io/lolbas/Binaries/Microsoft.Workflow.Compiler/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/trusted_developer_utilities_proxy_execution.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/trusted_developer_utilities_proxy_execution_msbuild.md b/docs/_stories/trusted_developer_utilities_proxy_execution_msbuild.md deleted file mode 100644 index a0ca7c63b0..0000000000 --- a/docs/_stories/trusted_developer_utilities_proxy_execution_msbuild.md +++ /dev/null @@ -1,63 +0,0 @@ ---- -title: "Trusted Developer Utilities Proxy Execution MSBuild" -last_modified_at: 2021-01-21 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Monitor and detect techniques used by attackers who leverage the msbuild.exe process to execute malicious code. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-01-21 -- **Author**: Michael Haag, Splunk -- **ID**: be3418e2-551b-11eb-ae93-0242ac130002 - -#### Narrative - -Adversaries may use MSBuild to proxy execution of code through a trusted Windows utility. MSBuild.exe (Microsoft Build Engine) is a software build platform used by Visual Studio and is native to Windows. It handles XML formatted project files that define requirements for loading and building various platforms and configurations.\ -The inline task capability of MSBuild that was introduced in .NET version 4 allows for C# code to be inserted into an XML project file. MSBuild will compile and execute the inline task. MSBuild.exe is a signed Microsoft binary, so when it is used this way it can execute arbitrary code and bypass application control defenses that are configured to allow MSBuild.exe execution.\ -The searches in this story help you detect and investigate suspicious activity that may indicate that an adversary is leveraging msbuild.exe to execute malicious code.\ -Triage\ -Validate execution\ -1. Determine if MSBuild.exe executed. Validate the OriginalFileName of MSBuild.exe and further PE metadata.\ -1. Determine if script code was executed with MSBuild.\ -Situational Awareness\ -The objective of this step is meant to identify suspicious behavioral indicators related to executed of Script code by MSBuild.exe.\ -1. Parent process. Is the parent process a known LOLBin? Is the parent process an Office Application?\ -1. Module loads. Are the known MSBuild.exe modules being loaded by a non-standard application? Is MSbuild loading any suspicious .DLLs?\ -1. Network connections. Any network connections? Review the reputation of the remote IP or domain.\ -Retrieval of script code\ -The objective of this step is to confirm the executed script code is benign or malicious. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [MSBuild Suspicious Spawned By Script Process](/endpoint/msbuild_suspicious_spawned_by_script_process/) | [MSBuild](/tags/#msbuild), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution)| TTP | -| [Suspicious msbuild path](/endpoint/suspicious_msbuild_path/) | [Masquerading](/tags/#masquerading), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Rename System Utilities](/tags/#rename-system-utilities), [MSBuild](/tags/#msbuild)| TTP | -| [Suspicious MSBuild Rename](/endpoint/suspicious_msbuild_rename/) | [Masquerading](/tags/#masquerading), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Rename System Utilities](/tags/#rename-system-utilities), [MSBuild](/tags/#msbuild)| Hunting | -| [Suspicious MSBuild Spawn](/endpoint/suspicious_msbuild_spawn/) | [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [MSBuild](/tags/#msbuild)| TTP | - -#### Reference - -* [https://attack.mitre.org/techniques/T1127/001/](https://attack.mitre.org/techniques/T1127/001/) -* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1127.001/T1127.001.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1127.001/T1127.001.md) -* [https://github.com/infosecn1nja/MaliciousMacroMSBuild](https://github.com/infosecn1nja/MaliciousMacroMSBuild) -* [https://github.com/xorrior/RandomPS-Scripts/blob/master/Invoke-ExecuteMSBuild.ps1](https://github.com/xorrior/RandomPS-Scripts/blob/master/Invoke-ExecuteMSBuild.ps1) -* [https://lolbas-project.github.io/lolbas/Binaries/Msbuild/](https://lolbas-project.github.io/lolbas/Binaries/Msbuild/) -* [https://github.com/MHaggis/CBR-Queries/blob/master/msbuild.md](https://github.com/MHaggis/CBR-Queries/blob/master/msbuild.md) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/trusted_developer_utilities_proxy_execution_msbuild.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/unusual_aws_ec2_modifications.md b/docs/_stories/unusual_aws_ec2_modifications.md deleted file mode 100644 index 04cb3f0acd..0000000000 --- a/docs/_stories/unusual_aws_ec2_modifications.md +++ /dev/null @@ -1,42 +0,0 @@ ---- -title: "Unusual AWS EC2 Modifications" -last_modified_at: 2018-04-09 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Identify unusual changes to your AWS EC2 instances that may indicate malicious activity. Modifications to your EC2 instances by previously unseen users is an example of an activity that may warrant further investigation. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: -- **Last Updated**: 2018-04-09 -- **Author**: David Dorsey, Splunk -- **ID**: 73de57ef-0dfc-411f-b1e7-fa24428aeae0 - -#### Narrative - -A common attack technique is to infiltrate a cloud instance and make modifications. The adversary can then secure access to your infrastructure or hide their activities. So it's important to stay alert to changes that may indicate that your environment has been compromised. \ - Searches within this Analytic Story can help you detect the presence of a threat by monitoring for EC2 instances that have been created or changed--either by users that have never previously performed these activities or by known users who modify or create instances in a way that have not been done before. This story also provides investigative searches that help you go deeper once you detect suspicious behavior. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [EC2 Instance Modified With Previously Unseen User](/deprecated/ec2_instance_modified_with_previously_unseen_user/) | [Cloud Accounts](/tags/#cloud-accounts)| Anomaly | - -#### Reference - -* [https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf](https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/unusual_aws_ec2_modifications.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/unusual_processes.md b/docs/_stories/unusual_processes.md deleted file mode 100644 index cccd2ec2e6..0000000000 --- a/docs/_stories/unusual_processes.md +++ /dev/null @@ -1,65 +0,0 @@ ---- -title: "Unusual Processes" -last_modified_at: 2020-02-04 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Actions on Objectives - - Command & Control - - Exploitation - - Installation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Quickly identify systems running new or unusual processes in your environment that could be indicators of suspicious activity. Processes run from unusual locations, those with conspicuously long command lines, and rare executables are all examples of activities that may warrant deeper investigation. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2020-02-04 -- **Author**: Bhavin Patel, Splunk -- **ID**: f4368e3f-d59f-4192-84f6-748ac5a3ddb6 - -#### Narrative - -Being able to profile a host's processes within your environment can help you more quickly identify processes that seem out of place when compared to the rest of the population of hosts or asset types.\ -This Analytic Story lets you identify processes that are either a) not typically seen running or b) have some sort of suspicious command-line arguments associated with them. This Analytic Story will also help you identify the user running these processes and the associated process activity on the host.\ -In the event an unusual process is identified, it is imperative to better understand how that process was able to execute on the host, when it first executed, and whether other hosts are affected. This extra information may provide clues that can help the analyst further investigate any suspicious activity. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Uncommon Processes On Endpoint](/deprecated/uncommon_processes_on_endpoint/) | [Malicious File](/tags/#malicious-file)| Hunting | -| [Attacker Tools On Endpoint](/endpoint/attacker_tools_on_endpoint/) | [Match Legitimate Name or Location](/tags/#match-legitimate-name-or-location), [Masquerading](/tags/#masquerading), [OS Credential Dumping](/tags/#os-credential-dumping), [Active Scanning](/tags/#active-scanning)| TTP | -| [Detect processes used for System Network Configuration Discovery](/endpoint/detect_processes_used_for_system_network_configuration_discovery/) | [System Network Configuration Discovery](/tags/#system-network-configuration-discovery)| TTP | -| [Rundll32 Shimcache Flush](/endpoint/rundll32_shimcache_flush/) | [Modify Registry](/tags/#modify-registry)| TTP | -| [RunDLL Loading DLL By Ordinal](/endpoint/rundll_loading_dll_by_ordinal/) | [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Rundll32](/tags/#rundll32)| TTP | -| [Suspicious Copy on System32](/endpoint/suspicious_copy_on_system32/) | [Rename System Utilities](/tags/#rename-system-utilities), [Masquerading](/tags/#masquerading)| TTP | -| [System Processes Run From Unexpected Locations](/endpoint/system_processes_run_from_unexpected_locations/) | [Masquerading](/tags/#masquerading), [Rename System Utilities](/tags/#rename-system-utilities)| TTP | -| [Verclsid CLSID Execution](/endpoint/verclsid_clsid_execution/) | [Verclsid](/tags/#verclsid), [System Binary Proxy Execution](/tags/#system-binary-proxy-execution)| Hunting | -| [Windows DotNet Binary in Non Standard Path](/endpoint/windows_dotnet_binary_in_non_standard_path/) | [Masquerading](/tags/#masquerading), [Rename System Utilities](/tags/#rename-system-utilities), [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [InstallUtil](/tags/#installutil)| TTP | -| [Windows InstallUtil in Non Standard Path](/endpoint/windows_installutil_in_non_standard_path/) | [Masquerading](/tags/#masquerading), [Rename System Utilities](/tags/#rename-system-utilities), [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [InstallUtil](/tags/#installutil)| TTP | -| [Windows NirSoft AdvancedRun](/endpoint/windows_nirsoft_advancedrun/) | [Tool](/tags/#tool)| TTP | -| [Windows Remote Assistance Spawning Process](/endpoint/windows_remote_assistance_spawning_process/) | [Process Injection](/tags/#process-injection)| TTP | -| [Wscript Or Cscript Suspicious Child Process](/endpoint/wscript_or_cscript_suspicious_child_process/) | [Process Injection](/tags/#process-injection), [Create or Modify System Process](/tags/#create-or-modify-system-process), [Parent PID Spoofing](/tags/#parent-pid-spoofing), [Access Token Manipulation](/tags/#access-token-manipulation)| TTP | -| [Detect Rare Executables](/endpoint/detect_rare_executables/) | None| Anomaly | -| [Unusually Long Command Line](/endpoint/unusually_long_command_line/) | None| Anomaly | -| [Unusually Long Command Line - MLTK](/endpoint/unusually_long_command_line_-_mltk/) | None| Anomaly | -| [WinRM Spawning a Process](/endpoint/winrm_spawning_a_process/) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application)| TTP | - -#### Reference - -* [https://web.archive.org/web/20210921093439/https://www.fireeye.com/blog/threat-research/2017/08/monitoring-windows-console-activity-part-two.html](https://web.archive.org/web/20210921093439/https://www.fireeye.com/blog/threat-research/2017/08/monitoring-windows-console-activity-part-two.html) -* [https://www.splunk.com/pdfs/technical-briefs/advanced-threat-detection-and-response-tech-brief.pdf](https://www.splunk.com/pdfs/technical-briefs/advanced-threat-detection-and-response-tech-brief.pdf) -* [https://www.sans.org/reading-room/whitepapers/logging/detecting-security-incidents-windows-workstation-event-logs-34262](https://www.sans.org/reading-room/whitepapers/logging/detecting-security-incidents-windows-workstation-event-logs-34262) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/unusual_processes.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_stories/use_of_cleartext_protocols.md b/docs/_stories/use_of_cleartext_protocols.md deleted file mode 100644 index dfa68e74f6..0000000000 --- a/docs/_stories/use_of_cleartext_protocols.md +++ /dev/null @@ -1,43 +0,0 @@ ---- -title: "Use of Cleartext Protocols" -last_modified_at: 2017-09-15 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Network_Traffic - - Actions on Objectives - - Reconnaissance ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Leverage searches that detect cleartext network protocols that may leak credentials or should otherwise be encrypted. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Network_Traffic](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkTraffic) -- **Last Updated**: 2017-09-15 -- **Author**: Bhavin Patel, Splunk -- **ID**: 826e6431-aeef-41b4-9fc0-6d0985d65a21 - -#### Narrative - -Various legacy protocols operate by default in the clear, without the protections of encryption. This potentially leaks sensitive information that can be exploited by passively sniffing network traffic. Depending on the protocol, this information could be highly sensitive, or could allow for session hijacking. In addition, these protocols send authentication information, which would allow for the harvesting of usernames and passwords that could potentially be used to authenticate and compromise secondary systems. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Protocols passing authentication in cleartext](/network/protocols_passing_authentication_in_cleartext/) | None| TTP | - -#### Reference - -* [https://www.monkey.org/~dugsong/dsniff/](https://www.monkey.org/~dugsong/dsniff/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/use_of_cleartext_protocols.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/vmware_server_side_injection_and_privilege_escalation.md b/docs/_stories/vmware_server_side_injection_and_privilege_escalation.md deleted file mode 100644 index 72f0acb599..0000000000 --- a/docs/_stories/vmware_server_side_injection_and_privilege_escalation.md +++ /dev/null @@ -1,44 +0,0 @@ ---- -title: "VMware Server Side Injection and Privilege Escalation" -last_modified_at: 2022-05-19 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Web - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Recently disclosed CVE-2022-22954 and CVE-2022-22960 have been identified in the wild abusing VMware products to compromise internet faced devices and escalate privileges. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Web](https://docs.splunk.com/Documentation/CIM/latest/User/Web) -- **Last Updated**: 2022-05-19 -- **Author**: Michael Haag, Splunk -- **ID**: d6d51cc2-a092-43b7-9f61-1159943afe39 - -#### Narrative - -On April 6, 2022, VMware published VMSA-2022-0011, which discloses multiple vulnerabilities discovered by Steven Seeley (mr_me) of Qihoo 360 Vulnerability Research Institute. The most critical of the CVEs published in VMSA-2022-0011 is CVE-2022-22954, which is a server-side template injection issue with a CVSSv3 base score of 9.8. The vulnerability allows an unauthenticated user with network access to the web interface to execute an arbitrary shell command as the VMware user. To further exacerbate this issue, VMware also disclosed a local privilege escalation issue, CVE-2022-22960, which permits the attacker to gain root after exploiting CVE-2022-22954. Products affected include - VMware Workspace ONE Access (Access) 20.10.0.0 - 20.10.0.1, 21.08.0.0 - 21.08.0.1 and VMware Identity Manager (vIDM) 3.3.3 - 3.3.6. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [VMware Server Side Template Injection Hunt](/web/vmware_server_side_template_injection_hunt/) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application)| Hunting | -| [VMware Workspace ONE Freemarker Server-side Template Injection](/web/vmware_workspace_one_freemarker_server-side_template_injection/) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application)| Anomaly | - -#### Reference - -* [https://attackerkb.com/topics/BDXyTqY1ld/cve-2022-22954/rapid7-analysis](https://attackerkb.com/topics/BDXyTqY1ld/cve-2022-22954/rapid7-analysis) -* [https://www.cisa.gov/uscert/ncas/alerts/aa22-138b](https://www.cisa.gov/uscert/ncas/alerts/aa22-138b) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/vmware_server_side_injection_and_privilege_escalation.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/web_fraud_detection.md b/docs/_stories/web_fraud_detection.md deleted file mode 100644 index e48c7c2603..0000000000 --- a/docs/_stories/web_fraud_detection.md +++ /dev/null @@ -1,50 +0,0 @@ ---- -title: "Web Fraud Detection" -last_modified_at: 2018-10-08 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Actions on Objectives - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Monitor your environment for activity consistent with common attack techniques bad actors use when attempting to compromise web servers or other web-related assets. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: -- **Last Updated**: 2018-10-08 -- **Author**: Jim Apger, Splunk -- **ID**: 18bb45b9-7684-45c6-9e97-1fdd0d98c0a7 - -#### Narrative - -The Federal Bureau of Investigations (FBI) defines Internet fraud as the use of Internet services or software with Internet access to defraud victims or to otherwise take advantage of them. According to the Bureau, Internet crime schemes are used to steal millions of dollars each year from victims and continue to plague the Internet through various methods. The agency includes phishing scams, data breaches, Denial of Service (DOS) attacks, email account compromise, malware, spoofing, and ransomware in this category.\ -These crimes are not the fraud itself, but rather the attack techniques commonly employed by fraudsters in their pursuit of data that enables them to commit malicious actssuch as obtaining and using stolen credit cards. They represent a serious problem that is steadily increasing and not likely to go away anytime soon.\ -When developing a strategy for preventing fraud in your environment, its important to look across all of your web services for evidence that attackers are abusing enterprise resources to enumerate systems, harvest data for secondary fraudulent activity, or abuse terms of service.This Analytic Story looks for evidence of common Internet attack techniques that could be indicative of web fraud in your environmentincluding account harvesting, anomalous user clickspeed, and password sharing across accounts, to name just a few.\ -The account-harvesting search focuses on web pages used for user-account registration. It detects the creation of a large number of user accounts using the same email domain name, a type of activity frequently seen in advance of a fraud campaign.\ -The anomalous clickspeed search looks for users who are moving through your website at a faster-than-normal speed or with a perfect click cadence (high periodicity or low standard deviation), which could indicate that the user is a script, not an actual human.\ -Another search detects incidents wherein a single password is used across multiple accounts, which may indicate that a fraudster has infiltrated your environment and embedded a common password within a script. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Web Fraud - Account Harvesting](/deprecated/web_fraud_-_account_harvesting/) | [Create Account](/tags/#create-account)| TTP | -| [Web Fraud - Anomalous User Clickspeed](/deprecated/web_fraud_-_anomalous_user_clickspeed/) | [Valid Accounts](/tags/#valid-accounts)| Anomaly | -| [Web Fraud - Password Sharing Across Accounts](/deprecated/web_fraud_-_password_sharing_across_accounts/) | None| Anomaly | - -#### Reference - -* [https://www.fbi.gov/scams-and-safety/common-fraud-schemes/internet-fraud](https://www.fbi.gov/scams-and-safety/common-fraud-schemes/internet-fraud) -* [https://www.fbi.gov/news/stories/2017-internet-crime-report-released-050718](https://www.fbi.gov/news/stories/2017-internet-crime-report-released-050718) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/web_fraud_detection.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/whispergate.md b/docs/_stories/whispergate.md deleted file mode 100644 index 73367f7ee0..0000000000 --- a/docs/_stories/whispergate.md +++ /dev/null @@ -1,66 +0,0 @@ ---- -title: "WhisperGate" -last_modified_at: 2022-01-19 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Actions on Objectives - - Command & Control - - Exploitation - - Installation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This analytic story contains detections that allow security analysts to detect and investigate unusual activities that might relate to the destructive malware targeting Ukrainian organizations also known as "WhisperGate". This analytic story looks for suspicious process execution, command-line activity, downloads, DNS queries and more. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-01-19 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 0150e6e5-3171-442e-83f8-1ccd8599569b - -#### Narrative - -WhisperGate/DEV-0586 is destructive malware operation found by MSTIC (Microsoft Threat Inteligence Center) targeting multiple organizations in Ukraine. This operation campaign consist of several malware component like the downloader that abuses discord platform, overwrite or destroy master boot record (MBR) of the targeted host, wiper and also windows defender evasion techniques. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Add or Set Windows Defender Exclusion](/endpoint/add_or_set_windows_defender_exclusion/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Attempt To Stop Security Service](/endpoint/attempt_to_stop_security_service/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [CMD Carry Out String Command Parameter](/endpoint/cmd_carry_out_string_command_parameter/) | [Windows Command Shell](/tags/#windows-command-shell), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter)| Hunting | -| [Excessive File Deletion In WinDefender Folder](/endpoint/excessive_file_deletion_in_windefender_folder/) | [Data Destruction](/tags/#data-destruction)| TTP | -| [Executables Or Script Creation In Suspicious Path](/endpoint/executables_or_script_creation_in_suspicious_path/) | [Masquerading](/tags/#masquerading)| TTP | -| [Impacket Lateral Movement Commandline Parameters](/endpoint/impacket_lateral_movement_commandline_parameters/) | [Remote Services](/tags/#remote-services), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares), [Distributed Component Object Model](/tags/#distributed-component-object-model), [Windows Management Instrumentation](/tags/#windows-management-instrumentation), [Windows Service](/tags/#windows-service)| TTP | -| [Malicious PowerShell Process - Encoded Command](/endpoint/malicious_powershell_process_-_encoded_command/) | [Obfuscated Files or Information](/tags/#obfuscated-files-or-information)| Hunting | -| [Ping Sleep Batch Command](/endpoint/ping_sleep_batch_command/) | [Virtualization/Sandbox Evasion](/tags/#virtualization/sandbox-evasion), [Time Based Evasion](/tags/#time-based-evasion)| Anomaly | -| [Powershell Remove Windows Defender Directory](/endpoint/powershell_remove_windows_defender_directory/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Powershell Windows Defender Exclusion Commands](/endpoint/powershell_windows_defender_exclusion_commands/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Process Deleting Its Process File Path](/endpoint/process_deleting_its_process_file_path/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host)| TTP | -| [Suspicious Process DNS Query Known Abuse Web Services](/endpoint/suspicious_process_dns_query_known_abuse_web_services/) | [Visual Basic](/tags/#visual-basic), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter)| TTP | -| [Suspicious Process File Path](/endpoint/suspicious_process_file_path/) | [Create or Modify System Process](/tags/#create-or-modify-system-process)| TTP | -| [Suspicious Process With Discord DNS Query](/endpoint/suspicious_process_with_discord_dns_query/) | [Visual Basic](/tags/#visual-basic), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter)| Anomaly | -| [Windows DotNet Binary in Non Standard Path](/endpoint/windows_dotnet_binary_in_non_standard_path/) | [Masquerading](/tags/#masquerading), [Rename System Utilities](/tags/#rename-system-utilities), [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [InstallUtil](/tags/#installutil)| TTP | -| [Windows High File Deletion Frequency](/endpoint/windows_high_file_deletion_frequency/) | [Data Destruction](/tags/#data-destruction)| Anomaly | -| [Windows InstallUtil in Non Standard Path](/endpoint/windows_installutil_in_non_standard_path/) | [Masquerading](/tags/#masquerading), [Rename System Utilities](/tags/#rename-system-utilities), [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [InstallUtil](/tags/#installutil)| TTP | -| [Windows NirSoft AdvancedRun](/endpoint/windows_nirsoft_advancedrun/) | [Tool](/tags/#tool)| TTP | -| [Windows NirSoft Utilities](/endpoint/windows_nirsoft_utilities/) | [Tool](/tags/#tool)| Hunting | -| [Windows Raw Access To Master Boot Record Drive](/endpoint/windows_raw_access_to_master_boot_record_drive/) | [Disk Structure Wipe](/tags/#disk-structure-wipe), [Disk Wipe](/tags/#disk-wipe)| TTP | -| [Wscript Or Cscript Suspicious Child Process](/endpoint/wscript_or_cscript_suspicious_child_process/) | [Process Injection](/tags/#process-injection), [Create or Modify System Process](/tags/#create-or-modify-system-process), [Parent PID Spoofing](/tags/#parent-pid-spoofing), [Access Token Manipulation](/tags/#access-token-manipulation)| TTP | - -#### Reference - -* [https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/](https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/) -* [https://medium.com/s2wblog/analysis-of-destructive-malware-whispergate-targeting-ukraine-9d5d158f19f3](https://medium.com/s2wblog/analysis-of-destructive-malware-whispergate-targeting-ukraine-9d5d158f19f3) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/whispergate.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/windows_defense_evasion_tactics.md b/docs/_stories/windows_defense_evasion_tactics.md deleted file mode 100644 index 8abb5678a2..0000000000 --- a/docs/_stories/windows_defense_evasion_tactics.md +++ /dev/null @@ -1,94 +0,0 @@ ---- -title: "Windows Defense Evasion Tactics" -last_modified_at: 2018-05-31 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Actions on Objectives - - Delivery - - Exploitation - - Reconnaissance ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Detect tactics used by malware to evade defenses on Windows endpoints. A few of these include suspicious `reg.exe` processes, files hidden with `attrib.exe` and disabling user-account control, among many others - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2018-05-31 -- **Author**: David Dorsey, Splunk -- **ID**: 56e24a28-5003-4047-b2db-e8f3c4618064 - -#### Narrative - -Defense evasion is a tactic--identified in the MITRE ATT&CK framework--that adversaries employ in a variety of ways to bypass or defeat defensive security measures. There are many techniques enumerated by the MITRE ATT&CK framework that are applicable in this context. This Analytic Story includes searches designed to identify the use of such techniques on Windows platforms. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Reg exe used to hide files directories via registry keys](/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys/) | [Hidden Files and Directories](/tags/#hidden-files-and-directories)| TTP | -| [Remote Registry Key modifications](/deprecated/remote_registry_key_modifications/) | None| TTP | -| [Add or Set Windows Defender Exclusion](/endpoint/add_or_set_windows_defender_exclusion/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [CSC Net On The Fly Compilation](/endpoint/csc_net_on_the_fly_compilation/) | [Compile After Delivery](/tags/#compile-after-delivery), [Obfuscated Files or Information](/tags/#obfuscated-files-or-information)| Hunting | -| [Disable Registry Tool](/endpoint/disable_registry_tool/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Disable Security Logs Using MiniNt Registry](/endpoint/disable_security_logs_using_minint_registry/) | [Modify Registry](/tags/#modify-registry)| TTP | -| [Disable Show Hidden Files](/endpoint/disable_show_hidden_files/) | [Hidden Files and Directories](/tags/#hidden-files-and-directories), [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Hide Artifacts](/tags/#hide-artifacts), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Disable UAC Remote Restriction](/endpoint/disable_uac_remote_restriction/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism)| TTP | -| [Disable Windows Behavior Monitoring](/endpoint/disable_windows_behavior_monitoring/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Disable Windows SmartScreen Protection](/endpoint/disable_windows_smartscreen_protection/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Disabling CMD Application](/endpoint/disabling_cmd_application/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Disabling ControlPanel](/endpoint/disabling_controlpanel/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Disabling Firewall with Netsh](/endpoint/disabling_firewall_with_netsh/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Disabling FolderOptions Windows Feature](/endpoint/disabling_folderoptions_windows_feature/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Disabling NoRun Windows App](/endpoint/disabling_norun_windows_app/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Disabling Remote User Account Control](/endpoint/disabling_remote_user_account_control/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism)| TTP | -| [Disabling SystemRestore In Registry](/endpoint/disabling_systemrestore_in_registry/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery)| TTP | -| [Disabling Task Manager](/endpoint/disabling_task_manager/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Eventvwr UAC Bypass](/endpoint/eventvwr_uac_bypass/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism)| TTP | -| [Excessive number of service control start as disabled](/endpoint/excessive_number_of_service_control_start_as_disabled/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| Anomaly | -| [Firewall Allowed Program Enable](/endpoint/firewall_allowed_program_enable/) | [Disable or Modify System Firewall](/tags/#disable-or-modify-system-firewall), [Impair Defenses](/tags/#impair-defenses)| Anomaly | -| [FodHelper UAC Bypass](/endpoint/fodhelper_uac_bypass/) | [Modify Registry](/tags/#modify-registry), [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism)| TTP | -| [Hiding Files And Directories With Attrib exe](/endpoint/hiding_files_and_directories_with_attrib_exe/) | [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification), [Windows File and Directory Permissions Modification](/tags/#windows-file-and-directory-permissions-modification)| TTP | -| [NET Profiler UAC bypass](/endpoint/net_profiler_uac_bypass/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism)| TTP | -| [Powershell Windows Defender Exclusion Commands](/endpoint/powershell_windows_defender_exclusion_commands/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Sdclt UAC Bypass](/endpoint/sdclt_uac_bypass/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism)| TTP | -| [SilentCleanup UAC Bypass](/endpoint/silentcleanup_uac_bypass/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism)| TTP | -| [SLUI RunAs Elevated](/endpoint/slui_runas_elevated/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism)| TTP | -| [SLUI Spawning a Process](/endpoint/slui_spawning_a_process/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism)| TTP | -| [Suspicious Reg exe Process](/endpoint/suspicious_reg_exe_process/) | [Modify Registry](/tags/#modify-registry)| TTP | -| [UAC Bypass MMC Load Unsigned Dll](/endpoint/uac_bypass_mmc_load_unsigned_dll/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism), [MMC](/tags/#mmc)| TTP | -| [Windows Command and Scripting Interpreter Hunting Path Traversal](/endpoint/windows_command_and_scripting_interpreter_hunting_path_traversal/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter)| Hunting | -| [Windows Command and Scripting Interpreter Path Traversal Exec](/endpoint/windows_command_and_scripting_interpreter_path_traversal_exec/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter)| TTP | -| [Windows Defender Exclusion Registry Entry](/endpoint/windows_defender_exclusion_registry_entry/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Windows Disable Change Password Through Registry](/endpoint/windows_disable_change_password_through_registry/) | [Modify Registry](/tags/#modify-registry)| Anomaly | -| [Windows Disable Lock Workstation Feature Through Registry](/endpoint/windows_disable_lock_workstation_feature_through_registry/) | [Modify Registry](/tags/#modify-registry)| Anomaly | -| [Windows Disable Notification Center](/endpoint/windows_disable_notification_center/) | [Modify Registry](/tags/#modify-registry)| Anomaly | -| [Windows Disable Windows Group Policy Features Through Registry](/endpoint/windows_disable_windows_group_policy_features_through_registry/) | [Modify Registry](/tags/#modify-registry)| Anomaly | -| [Windows DisableAntiSpyware Registry](/endpoint/windows_disableantispyware_registry/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Windows DISM Remove Defender](/endpoint/windows_dism_remove_defender/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Windows Event For Service Disabled](/endpoint/windows_event_for_service_disabled/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| Hunting | -| [Windows Excessive Disabled Services Event](/endpoint/windows_excessive_disabled_services_event/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Windows Hide Notification Features Through Registry](/endpoint/windows_hide_notification_features_through_registry/) | [Modify Registry](/tags/#modify-registry)| Anomaly | -| [Windows Impair Defense Delete Win Defender Context Menu](/endpoint/windows_impair_defense_delete_win_defender_context_menu/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| Hunting | -| [Windows Impair Defense Delete Win Defender Profile Registry](/endpoint/windows_impair_defense_delete_win_defender_profile_registry/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| Anomaly | -| [Windows Impair Defenses Disable Win Defender Auto Logging](/endpoint/windows_impair_defenses_disable_win_defender_auto_logging/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| Anomaly | -| [Windows Modify Show Compress Color And Info Tip Registry](/endpoint/windows_modify_show_compress_color_and_info_tip_registry/) | [Modify Registry](/tags/#modify-registry)| TTP | -| [Windows Process With NamedPipe CommandLine](/endpoint/windows_process_with_namedpipe_commandline/) | [Process Injection](/tags/#process-injection)| Anomaly | -| [Windows Rasautou DLL Execution](/endpoint/windows_rasautou_dll_execution/) | [Dynamic-link Library Injection](/tags/#dynamic-link-library-injection), [System Binary Proxy Execution](/tags/#system-binary-proxy-execution), [Process Injection](/tags/#process-injection)| TTP | -| [WSReset UAC Bypass](/endpoint/wsreset_uac_bypass/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism)| TTP | - -#### Reference - -* [https://attack.mitre.org/wiki/Defense_Evasion](https://attack.mitre.org/wiki/Defense_Evasion) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/windows_defense_evasion_tactics.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/windows_discovery_techniques.md b/docs/_stories/windows_discovery_techniques.md deleted file mode 100644 index 70faba41ad..0000000000 --- a/docs/_stories/windows_discovery_techniques.md +++ /dev/null @@ -1,45 +0,0 @@ ---- -title: "Windows Discovery Techniques" -last_modified_at: 2021-03-04 -toc: true -toc_label: "" -tags: - - Splunk Behavioral Analytics - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Reconnaissance ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Monitors for behaviors associated with adversaries discovering objects in the environment that can be leveraged in the progression of the attack. - -- **Product**: Splunk Behavioral Analytics, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-03-04 -- **Author**: Michael Hart, Splunk -- **ID**: f7aba570-7d59-11eb-825e-acde48001122 - -#### Narrative - -Attackers may not have much if any insight into their target's environment before the initial compromise. Once a foothold has been established, attackers will start enumerating objects in the environment (accounts, services, network shares, etc.) that can be used to achieve their objectives. This Analytic Story provides searches to help identify activities consistent with adversaries gaining knowledge of compromised Windows environments. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Net Localgroup Discovery](/endpoint/net_localgroup_discovery/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Local Groups](/tags/#local-groups)| Hunting | - -#### Reference - -* [https://attack.mitre.org/tactics/TA0007/](https://attack.mitre.org/tactics/TA0007/) -* [https://cyberd.us/penetration-testing](https://cyberd.us/penetration-testing) -* [https://attack.mitre.org/software/S0521/](https://attack.mitre.org/software/S0521/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/windows_discovery_techniques.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/windows_dns_sigred_cve-2020-1350.md b/docs/_stories/windows_dns_sigred_cve-2020-1350.md deleted file mode 100644 index c41fd1f7f0..0000000000 --- a/docs/_stories/windows_dns_sigred_cve-2020-1350.md +++ /dev/null @@ -1,44 +0,0 @@ ---- -title: "Windows DNS SIGRed CVE-2020-1350" -last_modified_at: 2020-07-28 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Network_Resolution - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Uncover activity consistent with CVE-2020-1350, or SIGRed. Discovered by Checkpoint researchers, this vulnerability affects Windows 2003 to 2019, and is triggered by a malicious DNS response (only affects DNS over TCP). An attacker can use the malicious payload to cause a buffer overflow on the vulnerable system, leading to compromise. The included searches in this Analytic Story are designed to identify the large response payload for SIG and KEY DNS records which can be used for the exploit. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Network_Resolution](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkResolution) -- **Last Updated**: 2020-07-28 -- **Author**: Shannon Davis, Splunk -- **ID**: 36dbb206-d073-11ea-87d0-0242ac130003 - -#### Narrative - -When a client requests a DNS record for a particular domain, that request gets routed first through the client's locally configured DNS server, then to any DNS server(s) configured as forwarders, and then onto the target domain's own DNS server(s). If a attacker wanted to, they could host a malicious DNS server that responds to the initial request with a specially crafted large response (~65KB). This response would flow through to the client's local DNS server, which if not patched for CVE-2020-1350, would cause the buffer overflow. The detection searches in this Analytic Story use wire data to detect the malicious behavior. Searches for Splunk Stream and Zeek are included. The Splunk Stream search correlates across stream:dns and stream:tcp, while the Zeek search correlates across bro:dns:json and bro:conn:json. These correlations are required to pick up both the DNS record types (SIG and KEY) along with the payload size (>65KB). - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Detect Windows DNS SIGRed via Splunk Stream](/network/detect_windows_dns_sigred_via_splunk_stream/) | [Exploitation for Client Execution](/tags/#exploitation-for-client-execution)| TTP | -| [Detect Windows DNS SIGRed via Zeek](/network/detect_windows_dns_sigred_via_zeek/) | [Exploitation for Client Execution](/tags/#exploitation-for-client-execution)| TTP | - -#### Reference - -* [https://research.checkpoint.com/2020/resolving-your-way-into-domain-admin-exploiting-a-17-year-old-bug-in-windows-dns-servers/](https://research.checkpoint.com/2020/resolving-your-way-into-domain-admin-exploiting-a-17-year-old-bug-in-windows-dns-servers/) -* [https://support.microsoft.com/en-au/help/4569509/windows-dns-server-remote-code-execution-vulnerability](https://support.microsoft.com/en-au/help/4569509/windows-dns-server-remote-code-execution-vulnerability) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/windows_dns_sigred_cve-2020-1350.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/windows_drivers.md b/docs/_stories/windows_drivers.md deleted file mode 100644 index e8afe41098..0000000000 --- a/docs/_stories/windows_drivers.md +++ /dev/null @@ -1,53 +0,0 @@ ---- -title: "Windows Drivers" -last_modified_at: 2022-03-30 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Delivery - - Exploitation - - Installation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Adversaries may use rootkits to hide the presence of programs, files, network connections, services, drivers, and other system components. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-03-30 -- **Author**: Michael Haag, Splunk -- **ID**: d0a9323f-9411-4da6-86b2-18c184d750c0 - -#### Narrative - -A rootkit on Windows may sometimes be in the form of a Windows Driver. A driver typically has a file extension of .sys, however the internals of a sys file is similar to a Windows DLL. For Microsoft Windows to load a driver, a few requirements are needed. First, it must have a valid signature. Second, typically it should load from the windows\system32\drivers path. There are a few methods to investigate drivers in the environment. Drivers are noisy. An inventory of all drivers is important to understand prevalence. A driver location (Path) is also important when attempting to baseline. Looking at a driver name and path is not enough, we must also explore the signing information. Product, description, company name, signer and signing result are all items to take into account when reviewing drivers. What makes a driver malicious? Depending if a driver was dropped during a campaign or you are baselining drivers after, triaging a driver to determine maliciousness may be tough. We break this into two categories - 1. vulnerable drivers 2. driver rootkits. Attempt to identify prevelance of the driver. Is it on one or many? Review the signing information if it is present. Is it common? A lot of driver hunting will lead down rabbit holes, but we hope to help lead the way. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Windows Driver Load Non-Standard Path](/endpoint/windows_driver_load_non-standard_path/) | [Rootkit](/tags/#rootkit)| TTP | -| [Windows Drivers Loaded by Signature](/endpoint/windows_drivers_loaded_by_signature/) | [Rootkit](/tags/#rootkit), [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation)| Hunting | -| [Windows Registry Certificate Added](/endpoint/windows_registry_certificate_added/) | [Install Root Certificate](/tags/#install-root-certificate), [Subvert Trust Controls](/tags/#subvert-trust-controls)| TTP | -| [Windows Registry Modification for Safe Mode Persistence](/endpoint/windows_registry_modification_for_safe_mode_persistence/) | [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution)| TTP | -| [Windows Service Create Kernel Mode Driver](/endpoint/windows_service_create_kernel_mode_driver/) | [Windows Service](/tags/#windows-service), [Create or Modify System Process](/tags/#create-or-modify-system-process), [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation)| TTP | -| [Windows System File on Disk](/endpoint/windows_system_file_on_disk/) | [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation)| Hunting | - -#### Reference - -* [https://redcanary.com/blog/tracking-driver-inventory-to-expose-rootkits/](https://redcanary.com/blog/tracking-driver-inventory-to-expose-rootkits/) -* [https://www.trendmicro.com/en_us/research/22/e/avoslocker-ransomware-variant-abuses-driver-file-to-disable-anti-Virus-scans-log4shell.html](https://www.trendmicro.com/en_us/research/22/e/avoslocker-ransomware-variant-abuses-driver-file-to-disable-anti-Virus-scans-log4shell.html) -* [https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/daxin-backdoor-espionage](https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/daxin-backdoor-espionage) -* [https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2018/03/08064459/Equation_group_questions_and_answers.pdf](https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2018/03/08064459/Equation_group_questions_and_answers.pdf) -* [https://www.welivesecurity.com/2022/01/11/signed-kernel-drivers-unguarded-gateway-windows-core/](https://www.welivesecurity.com/2022/01/11/signed-kernel-drivers-unguarded-gateway-windows-core/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/windows_drivers.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/windows_file_extension_and_association_abuse.md b/docs/_stories/windows_file_extension_and_association_abuse.md deleted file mode 100644 index 2524e94673..0000000000 --- a/docs/_stories/windows_file_extension_and_association_abuse.md +++ /dev/null @@ -1,49 +0,0 @@ ---- -title: "Windows File Extension and Association Abuse" -last_modified_at: 2018-01-26 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Actions on Objectives ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Detect and investigate suspected abuse of file extensions and Windows file associations. Some of the malicious behaviors involved may include inserting spaces before file extensions or prepending the file extension with a different one, among other techniques. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2018-01-26 -- **Author**: Rico Valdez, Splunk -- **ID**: 30552a76-ac78-48e4-b3c0-de4e34e9563d - -#### Narrative - -Attackers use a variety of techniques to entice users to run malicious code or to persist on an endpoint. One way to accomplish these goals is to leverage file extensions and the mechanism Windows uses to associate files with specific applications. \ - Since its earliest days, Windows has used extensions to identify file types. Users have become familiar with these extensions and their application associations. For example, if users see that a file ends in `.doc` or `.docx`, they will assume that it is a Microsoft Word document and expect that double-clicking will open it using `winword.exe`. The user will typically also presume that the `.docx` file is safe. \ - Attackers take advantage of this expectation by obfuscating the true file extension. They can accomplish this in a couple of ways. One technique involves inserting multiple spaces in the file name before the extension to hide the extension from the GUI, obscuring the true nature of the file. Another approach involves prepending the real extension with a different one. This is especially effective when Windows is configured to "hide extensions for known file types." In this case, the real extension is not displayed, but the prepended one is, leading end users to believe the file is a different type than it actually is.\ -Changing the association between a file extension and an application can allow an attacker to execute arbitrary code. The technique typically involves changing the association for an often-launched file type to associate instead with a malicious program the attacker has dropped on the endpoint. When the end user launches a file that has been manipulated in this way, it will execute the attacker's malware. It will also execute the application the end user expected to run, cleverly obscuring the fact that something suspicious has occurred.\ -Run the searches in this story to detect and investigate suspicious behavior that may indicate abuse or manipulation of Windows file extensions and/or associations. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Execution of File With Spaces Before Extension](/deprecated/execution_of_file_with_spaces_before_extension/) | [Rename System Utilities](/tags/#rename-system-utilities)| TTP | -| [Suspicious Changes to File Associations](/deprecated/suspicious_changes_to_file_associations/) | [Change Default File Association](/tags/#change-default-file-association)| TTP | -| [Execution of File with Multiple Extensions](/endpoint/execution_of_file_with_multiple_extensions/) | [Masquerading](/tags/#masquerading), [Rename System Utilities](/tags/#rename-system-utilities)| TTP | - -#### Reference - -* [https://blog.malwarebytes.com/cybercrime/2013/12/file-extensions-2/](https://blog.malwarebytes.com/cybercrime/2013/12/file-extensions-2/) -* [https://attack.mitre.org/wiki/Technique/T1042](https://attack.mitre.org/wiki/Technique/T1042) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/windows_file_extension_and_association_abuse.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/windows_log_manipulation.md b/docs/_stories/windows_log_manipulation.md deleted file mode 100644 index bda0412d1e..0000000000 --- a/docs/_stories/windows_log_manipulation.md +++ /dev/null @@ -1,49 +0,0 @@ ---- -title: "Windows Log Manipulation" -last_modified_at: 2017-09-12 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Actions on Objectives ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Adversaries often try to cover their tracks by manipulating Windows logs. Use these searches to help you monitor for suspicious activity surrounding log files--an essential component of an effective defense. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2017-09-12 -- **Author**: Rico Valdez, Splunk -- **ID**: b6db2c60-a281-48b4-95f1-2cd99ed56835 - -#### Narrative - -Because attackers often modify system logs to cover their tracks and/or to thwart the investigative process, log monitoring is an industry-recognized best practice. While there are legitimate reasons to manipulate system logs, it is still worthwhile to keep track of who manipulated the logs, when they manipulated them, and in what way they manipulated them (determining which accesses, tools, or utilities were employed). Even if no malicious activity is detected, the knowledge of an attempt to manipulate system logs may be indicative of a broader security risk that should be thoroughly investigated.\ -The Analytic Story gives users two different ways to detect manipulation of Windows Event Logs and one way to detect deletion of the Update Sequence Number (USN) Change Journal. The story helps determine the history of the host and the users who have accessed it. Finally, the story aides in investigation by retrieving all the information on the process that caused these events (if the process has been identified). - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Deleting Shadow Copies](/endpoint/deleting_shadow_copies/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery)| TTP | -| [Suspicious Event Log Service Behavior](/endpoint/suspicious_event_log_service_behavior/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host), [Clear Windows Event Logs](/tags/#clear-windows-event-logs)| TTP | -| [Suspicious wevtutil Usage](/endpoint/suspicious_wevtutil_usage/) | [Clear Windows Event Logs](/tags/#clear-windows-event-logs), [Indicator Removal on Host](/tags/#indicator-removal-on-host)| TTP | -| [USN Journal Deletion](/endpoint/usn_journal_deletion/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host)| TTP | -| [Windows Event Log Cleared](/endpoint/windows_event_log_cleared/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host), [Clear Windows Event Logs](/tags/#clear-windows-event-logs)| TTP | - -#### Reference - -* [https://www.crowdstrike.com/blog/bears-midst-intrusion-democratic-national-committee/](https://www.crowdstrike.com/blog/bears-midst-intrusion-democratic-national-committee/) -* [https://zeltser.com/security-incident-log-review-checklist/](https://zeltser.com/security-incident-log-review-checklist/) -* [http://journeyintoir.blogspot.com/2013/01/re-introducing-usnjrnl.html](http://journeyintoir.blogspot.com/2013/01/re-introducing-usnjrnl.html) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/windows_log_manipulation.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_stories/windows_persistence_techniques.md b/docs/_stories/windows_persistence_techniques.md deleted file mode 100644 index 71c20e448b..0000000000 --- a/docs/_stories/windows_persistence_techniques.md +++ /dev/null @@ -1,77 +0,0 @@ ---- -title: "Windows Persistence Techniques" -last_modified_at: 2018-05-31 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Actions on Objectives - - Exploitation - - Installation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Monitor for activities and techniques associated with maintaining persistence on a Windows system--a sign that an adversary may have compromised your environment. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2018-05-31 -- **Author**: Bhavin Patel, Splunk -- **ID**: 30874d4f-20a1-488f-85ec-5d52ef74e3f9 - -#### Narrative - -Maintaining persistence is one of the first steps taken by attackers after the initial compromise. Attackers leverage various custom and built-in tools to ensure survivability and persistent access within a compromised enterprise. This Analytic Story provides searches to help you identify various behaviors used by attackers to maintain persistent access to a Windows environment. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Reg exe used to hide files directories via registry keys](/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys/) | [Hidden Files and Directories](/tags/#hidden-files-and-directories)| TTP | -| [Remote Registry Key modifications](/deprecated/remote_registry_key_modifications/) | None| TTP | -| [Active Setup Registry Autostart](/endpoint/active_setup_registry_autostart/) | [Active Setup](/tags/#active-setup), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution)| TTP | -| [Certutil exe certificate extraction](/endpoint/certutil_exe_certificate_extraction/) | None| TTP | -| [Change Default File Association](/endpoint/change_default_file_association/) | [Change Default File Association](/tags/#change-default-file-association), [Event Triggered Execution](/tags/#event-triggered-execution)| TTP | -| [Detect Path Interception By Creation Of program exe](/endpoint/detect_path_interception_by_creation_of_program_exe/) | [Path Interception by Unquoted Path](/tags/#path-interception-by-unquoted-path), [Hijack Execution Flow](/tags/#hijack-execution-flow)| TTP | -| [ETW Registry Disabled](/endpoint/etw_registry_disabled/) | [Indicator Blocking](/tags/#indicator-blocking), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Hiding Files And Directories With Attrib exe](/endpoint/hiding_files_and_directories_with_attrib_exe/) | [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification), [Windows File and Directory Permissions Modification](/tags/#windows-file-and-directory-permissions-modification)| TTP | -| [Logon Script Event Trigger Execution](/endpoint/logon_script_event_trigger_execution/) | [Boot or Logon Initialization Scripts](/tags/#boot-or-logon-initialization-scripts), [Logon Script (Windows)](/tags/#logon-script-(windows))| TTP | -| [Monitor Registry Keys for Print Monitors](/endpoint/monitor_registry_keys_for_print_monitors/) | [Port Monitors](/tags/#port-monitors), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution)| TTP | -| [Reg exe Manipulating Windows Services Registry Keys](/endpoint/reg_exe_manipulating_windows_services_registry_keys/) | [Services Registry Permissions Weakness](/tags/#services-registry-permissions-weakness), [Hijack Execution Flow](/tags/#hijack-execution-flow)| TTP | -| [Registry Keys for Creating SHIM Databases](/endpoint/registry_keys_for_creating_shim_databases/) | [Application Shimming](/tags/#application-shimming), [Event Triggered Execution](/tags/#event-triggered-execution)| TTP | -| [Registry Keys Used For Persistence](/endpoint/registry_keys_used_for_persistence/) | [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution)| TTP | -| [Sc exe Manipulating Windows Services](/endpoint/sc_exe_manipulating_windows_services/) | [Windows Service](/tags/#windows-service), [Create or Modify System Process](/tags/#create-or-modify-system-process)| TTP | -| [Schedule Task with HTTP Command Arguments](/endpoint/schedule_task_with_http_command_arguments/) | [Scheduled Task/Job](/tags/#scheduled-task/job)| TTP | -| [Schedule Task with Rundll32 Command Trigger](/endpoint/schedule_task_with_rundll32_command_trigger/) | [Scheduled Task/Job](/tags/#scheduled-task/job)| TTP | -| [Scheduled Task Deleted Or Created via CMD](/endpoint/scheduled_task_deleted_or_created_via_cmd/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job)| TTP | -| [Schtasks used for forcing a reboot](/endpoint/schtasks_used_for_forcing_a_reboot/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job)| TTP | -| [Screensaver Event Trigger Execution](/endpoint/screensaver_event_trigger_execution/) | [Event Triggered Execution](/tags/#event-triggered-execution), [Screensaver](/tags/#screensaver)| TTP | -| [Shim Database File Creation](/endpoint/shim_database_file_creation/) | [Application Shimming](/tags/#application-shimming), [Event Triggered Execution](/tags/#event-triggered-execution)| TTP | -| [Shim Database Installation With Suspicious Parameters](/endpoint/shim_database_installation_with_suspicious_parameters/) | [Application Shimming](/tags/#application-shimming), [Event Triggered Execution](/tags/#event-triggered-execution)| TTP | -| [Suspicious Scheduled Task from Public Directory](/endpoint/suspicious_scheduled_task_from_public_directory/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job)| Anomaly | -| [Time Provider Persistence Registry](/endpoint/time_provider_persistence_registry/) | [Time Providers](/tags/#time-providers), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution)| TTP | -| [Windows Registry Delete Task SD](/endpoint/windows_registry_delete_task_sd/) | [Scheduled Task](/tags/#scheduled-task), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Windows Schtasks Create Run As System](/endpoint/windows_schtasks_create_run_as_system/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job)| TTP | -| [Windows Service Creation Using Registry Entry](/endpoint/windows_service_creation_using_registry_entry/) | [Services Registry Permissions Weakness](/tags/#services-registry-permissions-weakness)| TTP | -| [WinEvent Scheduled Task Created to Spawn Shell](/endpoint/winevent_scheduled_task_created_to_spawn_shell/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job)| TTP | -| [WinEvent Scheduled Task Created Within Public Path](/endpoint/winevent_scheduled_task_created_within_public_path/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job)| TTP | -| [WinEvent Windows Task Scheduler Event Action Started](/endpoint/winevent_windows_task_scheduler_event_action_started/) | [Scheduled Task](/tags/#scheduled-task)| Hunting | -| [Print Processor Registry Autostart](/endpoint/print_processor_registry_autostart/) | [Print Processors](/tags/#print-processors), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution)| TTP | - -#### Reference - -* [http://www.fuzzysecurity.com/tutorials/19.html](http://www.fuzzysecurity.com/tutorials/19.html) -* [https://www.fireeye.com/blog/threat-research/2010/07/malware-persistence-windows-registry.html](https://www.fireeye.com/blog/threat-research/2010/07/malware-persistence-windows-registry.html) -* [http://resources.infosecinstitute.com/common-malware-persistence-mechanisms/](http://resources.infosecinstitute.com/common-malware-persistence-mechanisms/) -* [https://www.fireeye.com/blog/threat-research/2017/05/fin7-shim-databases-persistence.html](https://www.fireeye.com/blog/threat-research/2017/05/fin7-shim-databases-persistence.html) -* [https://www.youtube.com/watch?v=dq2Hv7J9fvk](https://www.youtube.com/watch?v=dq2Hv7J9fvk) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/windows_persistence_techniques.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_stories/windows_privilege_escalation.md b/docs/_stories/windows_privilege_escalation.md deleted file mode 100644 index a533847a87..0000000000 --- a/docs/_stories/windows_privilege_escalation.md +++ /dev/null @@ -1,56 +0,0 @@ ---- -title: "Windows Privilege Escalation" -last_modified_at: 2020-02-04 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Actions on Objectives - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Monitor for and investigate activities that may be associated with a Windows privilege-escalation attack, including unusual processes running on endpoints, modified registry keys, and more. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2020-02-04 -- **Author**: David Dorsey, Splunk -- **ID**: 644e22d3-598a-429c-a007-16fdb802cae5 - -#### Narrative - -Privilege escalation is a "land-and-expand" technique, wherein an adversary gains an initial foothold on a host and then exploits its weaknesses to increase his privileges. The motivation is simple: certain actions on a Windows machine--such as installing software--may require higher-level privileges than those the attacker initially acquired. By increasing his privilege level, the attacker can gain the control required to carry out his malicious ends. This Analytic Story provides searches to detect and investigate behaviors that attackers may use to elevate their privileges in your environment. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Uncommon Processes On Endpoint](/deprecated/uncommon_processes_on_endpoint/) | [Malicious File](/tags/#malicious-file)| Hunting | -| [Active Setup Registry Autostart](/endpoint/active_setup_registry_autostart/) | [Active Setup](/tags/#active-setup), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution)| TTP | -| [Change Default File Association](/endpoint/change_default_file_association/) | [Change Default File Association](/tags/#change-default-file-association), [Event Triggered Execution](/tags/#event-triggered-execution)| TTP | -| [ETW Registry Disabled](/endpoint/etw_registry_disabled/) | [Indicator Blocking](/tags/#indicator-blocking), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Kerberoasting spn request with RC4 encryption](/endpoint/kerberoasting_spn_request_with_rc4_encryption/) | [Steal or Forge Kerberos Tickets](/tags/#steal-or-forge-kerberos-tickets), [Kerberoasting](/tags/#kerberoasting)| TTP | -| [Logon Script Event Trigger Execution](/endpoint/logon_script_event_trigger_execution/) | [Boot or Logon Initialization Scripts](/tags/#boot-or-logon-initialization-scripts), [Logon Script (Windows)](/tags/#logon-script-(windows))| TTP | -| [MSI Module Loaded by Non-System Binary](/endpoint/msi_module_loaded_by_non-system_binary/) | [DLL Side-Loading](/tags/#dll-side-loading), [Hijack Execution Flow](/tags/#hijack-execution-flow)| Hunting | -| [Overwriting Accessibility Binaries](/endpoint/overwriting_accessibility_binaries/) | [Event Triggered Execution](/tags/#event-triggered-execution), [Accessibility Features](/tags/#accessibility-features)| TTP | -| [Registry Keys Used For Privilege Escalation](/endpoint/registry_keys_used_for_privilege_escalation/) | [Image File Execution Options Injection](/tags/#image-file-execution-options-injection), [Event Triggered Execution](/tags/#event-triggered-execution)| TTP | -| [Runas Execution in CommandLine](/endpoint/runas_execution_in_commandline/) | [Access Token Manipulation](/tags/#access-token-manipulation), [Token Impersonation/Theft](/tags/#token-impersonation/theft)| Hunting | -| [Screensaver Event Trigger Execution](/endpoint/screensaver_event_trigger_execution/) | [Event Triggered Execution](/tags/#event-triggered-execution), [Screensaver](/tags/#screensaver)| TTP | -| [Time Provider Persistence Registry](/endpoint/time_provider_persistence_registry/) | [Time Providers](/tags/#time-providers), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution)| TTP | -| [Child Processes of Spoolsv exe](/endpoint/child_processes_of_spoolsv_exe/) | [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation)| TTP | -| [Print Processor Registry Autostart](/endpoint/print_processor_registry_autostart/) | [Print Processors](/tags/#print-processors), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution)| TTP | - -#### Reference - -* [https://attack.mitre.org/tactics/TA0004/](https://attack.mitre.org/tactics/TA0004/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/windows_privilege_escalation.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_stories/windows_registry_abuse.md b/docs/_stories/windows_registry_abuse.md deleted file mode 100644 index ba064f4e83..0000000000 --- a/docs/_stories/windows_registry_abuse.md +++ /dev/null @@ -1,106 +0,0 @@ ---- -title: "Windows Registry Abuse" -last_modified_at: 2022-03-17 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Actions on Objectives - - Delivery - - Exploitation - - Installation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Windows services are often used by attackers for persistence, privilege escalation, lateral movement, defense evasion, collection of data, a tool for recon, credential dumping and payload impact. This Analytic Story helps you monitor your environment for indications that Windows registry are being modified or created in a suspicious manner. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-03-17 -- **Author**: Teoderick Contreras, Splunk -- **ID**: 78df1df1-25f1-4387-90f9-c4ea31ce6b75 - -#### Narrative - -Windows Registry is one of the powerful and yet still mysterious Windows features that can tweak or manipulate Windows policies and low-level configuration settings. Because of this capability, most malware, adversaries or threat actors abuse this hierarchical database to do their malicious intent on a targeted host or network environment. In these cases, attackers often use tools to create or modify registry in ways that are not typical for most environments, providing opportunities for detection. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Allow Inbound Traffic By Firewall Rule Registry](/endpoint/allow_inbound_traffic_by_firewall_rule_registry/) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol), [Remote Services](/tags/#remote-services)| TTP | -| [Allow Operation with Consent Admin](/endpoint/allow_operation_with_consent_admin/) | [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism)| TTP | -| [Attempted Credential Dump From Registry via Reg exe](/endpoint/attempted_credential_dump_from_registry_via_reg_exe/) | [Security Account Manager](/tags/#security-account-manager), [OS Credential Dumping](/tags/#os-credential-dumping)| TTP | -| [Auto Admin Logon Registry Entry](/endpoint/auto_admin_logon_registry_entry/) | [Credentials in Registry](/tags/#credentials-in-registry), [Unsecured Credentials](/tags/#unsecured-credentials)| TTP | -| [Change Default File Association](/endpoint/change_default_file_association/) | [Change Default File Association](/tags/#change-default-file-association), [Event Triggered Execution](/tags/#event-triggered-execution)| TTP | -| [Disable AMSI Through Registry](/endpoint/disable_amsi_through_registry/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Disable Defender AntiVirus Registry](/endpoint/disable_defender_antivirus_registry/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Disable Defender BlockAtFirstSeen Feature](/endpoint/disable_defender_blockatfirstseen_feature/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Disable Defender Enhanced Notification](/endpoint/disable_defender_enhanced_notification/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Disable Defender MpEngine Registry](/endpoint/disable_defender_mpengine_registry/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Disable Defender Spynet Reporting](/endpoint/disable_defender_spynet_reporting/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Disable Defender Submit Samples Consent Feature](/endpoint/disable_defender_submit_samples_consent_feature/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Disable ETW Through Registry](/endpoint/disable_etw_through_registry/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Disable Registry Tool](/endpoint/disable_registry_tool/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Disable Security Logs Using MiniNt Registry](/endpoint/disable_security_logs_using_minint_registry/) | [Modify Registry](/tags/#modify-registry)| TTP | -| [Disable Show Hidden Files](/endpoint/disable_show_hidden_files/) | [Hidden Files and Directories](/tags/#hidden-files-and-directories), [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Hide Artifacts](/tags/#hide-artifacts), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Disable UAC Remote Restriction](/endpoint/disable_uac_remote_restriction/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism)| TTP | -| [Disable Windows App Hotkeys](/endpoint/disable_windows_app_hotkeys/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Disable Windows Behavior Monitoring](/endpoint/disable_windows_behavior_monitoring/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Disable Windows SmartScreen Protection](/endpoint/disable_windows_smartscreen_protection/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Disabling CMD Application](/endpoint/disabling_cmd_application/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Disabling ControlPanel](/endpoint/disabling_controlpanel/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Disabling Defender Services](/endpoint/disabling_defender_services/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Disabling FolderOptions Windows Feature](/endpoint/disabling_folderoptions_windows_feature/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Disabling NoRun Windows App](/endpoint/disabling_norun_windows_app/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Disabling Remote User Account Control](/endpoint/disabling_remote_user_account_control/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism)| TTP | -| [Disabling SystemRestore In Registry](/endpoint/disabling_systemrestore_in_registry/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery)| TTP | -| [Disabling Task Manager](/endpoint/disabling_task_manager/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Enable RDP In Other Port Number](/endpoint/enable_rdp_in_other_port_number/) | [Remote Services](/tags/#remote-services)| TTP | -| [Enable WDigest UseLogonCredential Registry](/endpoint/enable_wdigest_uselogoncredential_registry/) | [Modify Registry](/tags/#modify-registry), [OS Credential Dumping](/tags/#os-credential-dumping)| TTP | -| [ETW Registry Disabled](/endpoint/etw_registry_disabled/) | [Indicator Blocking](/tags/#indicator-blocking), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Eventvwr UAC Bypass](/endpoint/eventvwr_uac_bypass/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism)| TTP | -| [Hide User Account From Sign-In Screen](/endpoint/hide_user_account_from_sign-in_screen/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Modification Of Wallpaper](/endpoint/modification_of_wallpaper/) | [Defacement](/tags/#defacement)| TTP | -| [Monitor Registry Keys for Print Monitors](/endpoint/monitor_registry_keys_for_print_monitors/) | [Port Monitors](/tags/#port-monitors), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution)| TTP | -| [Registry Keys for Creating SHIM Databases](/endpoint/registry_keys_for_creating_shim_databases/) | [Application Shimming](/tags/#application-shimming), [Event Triggered Execution](/tags/#event-triggered-execution)| TTP | -| [Registry Keys Used For Persistence](/endpoint/registry_keys_used_for_persistence/) | [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution)| TTP | -| [Registry Keys Used For Privilege Escalation](/endpoint/registry_keys_used_for_privilege_escalation/) | [Image File Execution Options Injection](/tags/#image-file-execution-options-injection), [Event Triggered Execution](/tags/#event-triggered-execution)| TTP | -| [Remcos client registry install entry](/endpoint/remcos_client_registry_install_entry/) | [Modify Registry](/tags/#modify-registry)| TTP | -| [Revil Registry Entry](/endpoint/revil_registry_entry/) | [Modify Registry](/tags/#modify-registry)| TTP | -| [Screensaver Event Trigger Execution](/endpoint/screensaver_event_trigger_execution/) | [Event Triggered Execution](/tags/#event-triggered-execution), [Screensaver](/tags/#screensaver)| TTP | -| [Sdclt UAC Bypass](/endpoint/sdclt_uac_bypass/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism)| TTP | -| [SilentCleanup UAC Bypass](/endpoint/silentcleanup_uac_bypass/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism)| TTP | -| [Time Provider Persistence Registry](/endpoint/time_provider_persistence_registry/) | [Time Providers](/tags/#time-providers), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution)| TTP | -| [Windows Disable Lock Workstation Feature Through Registry](/endpoint/windows_disable_lock_workstation_feature_through_registry/) | [Modify Registry](/tags/#modify-registry)| Anomaly | -| [Windows Disable LogOff Button Through Registry](/endpoint/windows_disable_logoff_button_through_registry/) | [Modify Registry](/tags/#modify-registry)| Anomaly | -| [Windows Disable Memory Crash Dump](/endpoint/windows_disable_memory_crash_dump/) | [Data Destruction](/tags/#data-destruction)| TTP | -| [Windows Disable Notification Center](/endpoint/windows_disable_notification_center/) | [Modify Registry](/tags/#modify-registry)| Anomaly | -| [Windows Disable Shutdown Button Through Registry](/endpoint/windows_disable_shutdown_button_through_registry/) | [Modify Registry](/tags/#modify-registry)| Anomaly | -| [Windows Disable Windows Group Policy Features Through Registry](/endpoint/windows_disable_windows_group_policy_features_through_registry/) | [Modify Registry](/tags/#modify-registry)| Anomaly | -| [Windows DisableAntiSpyware Registry](/endpoint/windows_disableantispyware_registry/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Windows Hide Notification Features Through Registry](/endpoint/windows_hide_notification_features_through_registry/) | [Modify Registry](/tags/#modify-registry)| Anomaly | -| [Windows Impair Defense Delete Win Defender Context Menu](/endpoint/windows_impair_defense_delete_win_defender_context_menu/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| Hunting | -| [Windows Impair Defense Delete Win Defender Profile Registry](/endpoint/windows_impair_defense_delete_win_defender_profile_registry/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| Anomaly | -| [Windows Impair Defenses Disable Win Defender Auto Logging](/endpoint/windows_impair_defenses_disable_win_defender_auto_logging/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| Anomaly | -| [Windows Modify Show Compress Color And Info Tip Registry](/endpoint/windows_modify_show_compress_color_and_info_tip_registry/) | [Modify Registry](/tags/#modify-registry)| TTP | -| [Windows Registry Certificate Added](/endpoint/windows_registry_certificate_added/) | [Install Root Certificate](/tags/#install-root-certificate), [Subvert Trust Controls](/tags/#subvert-trust-controls)| TTP | -| [Windows Registry Delete Task SD](/endpoint/windows_registry_delete_task_sd/) | [Scheduled Task](/tags/#scheduled-task), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Windows Registry Modification for Safe Mode Persistence](/endpoint/windows_registry_modification_for_safe_mode_persistence/) | [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution)| TTP | -| [Windows Service Creation Using Registry Entry](/endpoint/windows_service_creation_using_registry_entry/) | [Services Registry Permissions Weakness](/tags/#services-registry-permissions-weakness)| TTP | -| [WSReset UAC Bypass](/endpoint/wsreset_uac_bypass/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism)| TTP | - -#### Reference - -* [https://attack.mitre.org/techniques/T1112/](https://attack.mitre.org/techniques/T1112/) -* [https://redcanary.com/blog/windows-registry-attacks-threat-detection/](https://redcanary.com/blog/windows-registry-attacks-threat-detection/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/windows_registry_abuse.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/windows_service_abuse.md b/docs/_stories/windows_service_abuse.md deleted file mode 100644 index 90161fbde7..0000000000 --- a/docs/_stories/windows_service_abuse.md +++ /dev/null @@ -1,46 +0,0 @@ ---- -title: "Windows Service Abuse" -last_modified_at: 2017-11-02 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Actions on Objectives - - Installation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Windows services are often used by attackers for persistence and the ability to load drivers or otherwise interact with the Windows kernel. This Analytic Story helps you monitor your environment for indications that Windows services are being modified or created in a suspicious manner. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2017-11-02 -- **Author**: Rico Valdez, Splunk -- **ID**: 6dbd810e-f66d-414b-8dfc-e46de55cbfe2 - -#### Narrative - -The Windows operating system uses a services architecture to allow for running code in the background, similar to a UNIX daemon. Attackers will often leverage Windows services for persistence, hiding in plain sight, seeking the ability to run privileged code that can interact with the kernel. In many cases, attackers will create a new service to host their malicious code. Attackers have also been observed modifying unnecessary or unused services to point to their own code, as opposed to what was intended. In these cases, attackers often use tools to create or modify services in ways that are not typical for most environments, providing opportunities for detection. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Reg exe Manipulating Windows Services Registry Keys](/endpoint/reg_exe_manipulating_windows_services_registry_keys/) | [Services Registry Permissions Weakness](/tags/#services-registry-permissions-weakness), [Hijack Execution Flow](/tags/#hijack-execution-flow)| TTP | -| [Sc exe Manipulating Windows Services](/endpoint/sc_exe_manipulating_windows_services/) | [Windows Service](/tags/#windows-service), [Create or Modify System Process](/tags/#create-or-modify-system-process)| TTP | -| [First Time Seen Running Windows Service](/endpoint/first_time_seen_running_windows_service/) | [System Services](/tags/#system-services), [Service Execution](/tags/#service-execution)| Anomaly | - -#### Reference - -* [https://attack.mitre.org/wiki/Technique/T1050](https://attack.mitre.org/wiki/Technique/T1050) -* [https://attack.mitre.org/wiki/Technique/T1031](https://attack.mitre.org/wiki/Technique/T1031) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/windows_service_abuse.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_stories/windows_system_binary_proxy_execution_msiexec.md b/docs/_stories/windows_system_binary_proxy_execution_msiexec.md deleted file mode 100644 index 059867b7e8..0000000000 --- a/docs/_stories/windows_system_binary_proxy_execution_msiexec.md +++ /dev/null @@ -1,46 +0,0 @@ ---- -title: "Windows System Binary Proxy Execution MSIExec" -last_modified_at: 2022-06-16 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Exploitation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Adversaries may abuse msiexec.exe to proxy execution of malicious payloads. Msiexec.exe is the command-line utility for the Windows Installer and is thus commonly associated with executing installation packages (.msi). - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2022-06-16 -- **Author**: Michael Haag, Splunk -- **ID**: bea2e16b-4599-46ad-a95b-116078726c68 - -#### Narrative - -Adversaries may abuse msiexec.exe to launch local or network accessible MSI files. Msiexec.exe can also execute DLLs. Since it may be signed and native on Windows systems, msiexec.exe can be used to bypass application control solutions that do not account for its potential abuse. Msiexec.exe execution may also be elevated to SYSTEM privileges if the AlwaysInstallElevated policy is enabled. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Windows MSIExec DLLRegisterServer](/endpoint/windows_msiexec_dllregisterserver/) | [Msiexec](/tags/#msiexec)| TTP | -| [Windows MSIExec Remote Download](/endpoint/windows_msiexec_remote_download/) | [Msiexec](/tags/#msiexec)| TTP | -| [Windows MSIExec Spawn Discovery Command](/endpoint/windows_msiexec_spawn_discovery_command/) | [Msiexec](/tags/#msiexec)| TTP | -| [Windows MSIExec Unregister DLLRegisterServer](/endpoint/windows_msiexec_unregister_dllregisterserver/) | [Msiexec](/tags/#msiexec)| TTP | -| [Windows MSIExec With Network Connections](/endpoint/windows_msiexec_with_network_connections/) | [Msiexec](/tags/#msiexec)| TTP | - -#### Reference - -* [https://attack.mitre.org/techniques/T1218/007/](https://attack.mitre.org/techniques/T1218/007/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/windows_system_binary_proxy_execution_msiexec.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/xmrig.md b/docs/_stories/xmrig.md deleted file mode 100644 index 03372557a8..0000000000 --- a/docs/_stories/xmrig.md +++ /dev/null @@ -1,68 +0,0 @@ ---- -title: "XMRig" -last_modified_at: 2021-05-07 -toc: true -toc_label: "" -tags: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - - Endpoint - - Actions on Objectives - - Command & Control - - Exploitation - - Installation ---- - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Leverage searches that allow you to detect and investigate unusual activities that might relate to the xmrig monero, including looking for file writes associated with its payload, process command-line, defense evasion (killing services, deleting users, modifying files or folder permission, killing other malware or other coin miner) and hacking tools including Telegram as mean of command and control (C2) to download other files. Adversaries may leverage the resources of co-opted systems in order to solve resource intensive problems which may impact system and/or hosted service availability. One common purpose for Resource Hijacking is to validate transactions of cryptocurrency networks and earn virtual currency. Adversaries may consume enough system resources to negatively impact and/or cause affected machines to become unresponsive. (1) Servers and cloud-based (2) systems are common targets because of the high potential for available resources, but user endpoint systems may also be compromised and used for Resource Hijacking and cryptocurrency mining. - -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-05-07 -- **Author**: Teoderick Contreras, Rod Soto Splunk -- **ID**: 06723e6a-6bd8-4817-ace2-5fb8a7b06628 - -#### Narrative - -XMRig is a high performance, open source, cross platform RandomX, KawPow, CryptoNight and AstroBWT unified CPU/GPU miner. This monero is seen in the wild on May 2017. - -#### Detections - -| Name | Technique | Type | -| ----------- | ----------- |--------------| -| [Attacker Tools On Endpoint](/endpoint/attacker_tools_on_endpoint/) | [Match Legitimate Name or Location](/tags/#match-legitimate-name-or-location), [Masquerading](/tags/#masquerading), [OS Credential Dumping](/tags/#os-credential-dumping), [Active Scanning](/tags/#active-scanning)| TTP | -| [Deleting Of Net Users](/endpoint/deleting_of_net_users/) | [Account Access Removal](/tags/#account-access-removal)| TTP | -| [Disable Windows App Hotkeys](/endpoint/disable_windows_app_hotkeys/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Disabling Net User Account](/endpoint/disabling_net_user_account/) | [Account Access Removal](/tags/#account-access-removal)| TTP | -| [Download Files Using Telegram](/endpoint/download_files_using_telegram/) | [Ingress Tool Transfer](/tags/#ingress-tool-transfer)| TTP | -| [Enumerate Users Local Group Using Telegram](/endpoint/enumerate_users_local_group_using_telegram/) | [Account Discovery](/tags/#account-discovery)| TTP | -| [Excessive Attempt To Disable Services](/endpoint/excessive_attempt_to_disable_services/) | [Service Stop](/tags/#service-stop)| Anomaly | -| [Excessive Service Stop Attempt](/endpoint/excessive_service_stop_attempt/) | [Service Stop](/tags/#service-stop)| Anomaly | -| [Excessive Usage Of Cacls App](/endpoint/excessive_usage_of_cacls_app/) | [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification)| Anomaly | -| [Excessive Usage Of Net App](/endpoint/excessive_usage_of_net_app/) | [Account Access Removal](/tags/#account-access-removal)| Anomaly | -| [Excessive Usage Of Taskkill](/endpoint/excessive_usage_of_taskkill/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| Anomaly | -| [Executables Or Script Creation In Suspicious Path](/endpoint/executables_or_script_creation_in_suspicious_path/) | [Masquerading](/tags/#masquerading)| TTP | -| [Hide User Account From Sign-In Screen](/endpoint/hide_user_account_from_sign-in_screen/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Icacls Deny Command](/endpoint/icacls_deny_command/) | [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification)| TTP | -| [ICACLS Grant Command](/endpoint/icacls_grant_command/) | [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification)| TTP | -| [Modify ACL permission To Files Or Folder](/endpoint/modify_acl_permission_to_files_or_folder/) | [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification)| Anomaly | -| [Process Kill Base On File Path](/endpoint/process_kill_base_on_file_path/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses)| TTP | -| [Schtasks Run Task On Demand](/endpoint/schtasks_run_task_on_demand/) | [Scheduled Task/Job](/tags/#scheduled-task/job)| TTP | -| [Suspicious Driver Loaded Path](/endpoint/suspicious_driver_loaded_path/) | [Windows Service](/tags/#windows-service), [Create or Modify System Process](/tags/#create-or-modify-system-process)| TTP | -| [Suspicious Process File Path](/endpoint/suspicious_process_file_path/) | [Create or Modify System Process](/tags/#create-or-modify-system-process)| TTP | -| [XMRIG Driver Loaded](/endpoint/xmrig_driver_loaded/) | [Windows Service](/tags/#windows-service), [Create or Modify System Process](/tags/#create-or-modify-system-process)| TTP | - -#### Reference - -* [https://github.com/xmrig/xmrig](https://github.com/xmrig/xmrig) -* [https://www.getmonero.org/resources/user-guides/mine-to-pool.html](https://www.getmonero.org/resources/user-guides/mine-to-pool.html) -* [https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/](https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/) -* [https://blog.checkpoint.com/2021/03/11/february-2021s-most-wanted-malware-trickbot-takes-over-following-emotet-shutdown/](https://blog.checkpoint.com/2021/03/11/february-2021s-most-wanted-malware-trickbot-takes-over-following-emotet-shutdown/) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/stories/xmrig.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/assets/css/main.scss b/docs/assets/css/main.scss deleted file mode 100644 index 98579fbbfb..0000000000 --- a/docs/assets/css/main.scss +++ /dev/null @@ -1,41 +0,0 @@ ---- -# Only the main Sass file needs front matter (the dashes are enough) ---- - -@charset "utf-8"; - -@import "minimal-mistakes/skins/{{ site.minimal_mistakes_skin | default: 'default' }}"; // skin -@import "minimal-mistakes"; // main partials - - -body { - word-wrap: break-word; - overflow-wrap: break-word; -} - -code, -samp { - white-space: pre-wrap; -} - -p > code, -li > code, -samp { - border-radius: .25em; - margin: 0 -.03125em; - padding: .0625em .25em 0; /* breathing room for inline code that has a different background or an outline */ -} - -article { - margin: 1em; -} - -.highlight { - margin: 1em -1em; /* -1em left/right margins for full-bleed code samples */ - padding: 1em; -} - -.code-header { - display: flex; - justify-content: flex-end; -} diff --git a/docs/assets/js/_main.js b/docs/assets/js/_main.js deleted file mode 100644 index 53fdccbbdc..0000000000 --- a/docs/assets/js/_main.js +++ /dev/null @@ -1,136 +0,0 @@ -/* ========================================================================== - jQuery plugin settings and other scripts - ========================================================================== */ - -$(document).ready(function() { - // FitVids init - $("#main").fitVids(); - - // Sticky sidebar - var stickySideBar = function() { - var show = - $(".author__urls-wrapper button").length === 0 - ? $(window).width() > 1024 // width should match $large Sass variable - : !$(".author__urls-wrapper button").is(":visible"); - if (show) { - // fix - $(".sidebar").addClass("sticky"); - } else { - // unfix - $(".sidebar").removeClass("sticky"); - } - }; - - stickySideBar(); - - $(window).resize(function() { - stickySideBar(); - }); - - // Follow menu drop down - $(".author__urls-wrapper button").on("click", function() { - $(".author__urls").toggleClass("is--visible"); - $(".author__urls-wrapper button").toggleClass("open"); - }); - - // Close search screen with Esc key - $(document).keyup(function(e) { - if (e.keyCode === 27) { - if ($(".initial-content").hasClass("is--hidden")) { - $(".search-content").toggleClass("is--visible"); - $(".initial-content").toggleClass("is--hidden"); - } - } - }); - - // Search toggle - $(".search__toggle").on("click", function() { - $(".search-content").toggleClass("is--visible"); - $(".initial-content").toggleClass("is--hidden"); - // set focus on input - setTimeout(function() { - $(".search-content input").focus(); - }, 400); - }); - - // Smooth scrolling - var scroll = new SmoothScroll('a[href*="#"]', { - offset: 20, - speed: 400, - speedAsDuration: true, - durationMax: 500 - }); - - // Gumshoe scroll spy init - if($("nav.toc").length > 0) { - var spy = new Gumshoe("nav.toc a", { - // Active classes - navClass: "active", // applied to the nav list item - contentClass: "active", // applied to the content - - // Nested navigation - nested: false, // if true, add classes to parents of active link - nestedClass: "active", // applied to the parent items - - // Offset & reflow - offset: 20, // how far from the top of the page to activate a content area - reflow: true, // if true, listen for reflows - - // Event support - events: true // if true, emit custom events - }); - } - - // add lightbox class to all image links - $( - "a[href$='.jpg'],a[href$='.jpeg'],a[href$='.JPG'],a[href$='.png'],a[href$='.gif'],a[href$='.webp']" - ).has("> img").addClass("image-popup"); - - // Magnific-Popup options - $(".image-popup").magnificPopup({ - // disableOn: function() { - // if( $(window).width() < 500 ) { - // return false; - // } - // return true; - // }, - type: "image", - tLoading: "Loading image #%curr%...", - gallery: { - enabled: true, - navigateByImgClick: true, - preload: [0, 1] // Will preload 0 - before current, and 1 after the current image - }, - image: { - tError: 'Image #%curr% could not be loaded.' - }, - removalDelay: 500, // Delay in milliseconds before popup is removed - // Class that is added to body when popup is open. - // make it unique to apply your CSS animations just to this exact popup - mainClass: "mfp-zoom-in", - callbacks: { - beforeOpen: function() { - // just a hack that adds mfp-anim class to markup - this.st.image.markup = this.st.image.markup.replace( - "mfp-figure", - "mfp-figure mfp-with-anim" - ); - } - }, - closeOnContentClick: true, - midClick: true // allow opening popup on middle mouse click. Always set it to true if you don't provide alternative source. - }); - - // Add anchors for headings - $('.page__content').find('h1, h2, h3, h4, h5, h6').each(function() { - var id = $(this).attr('id'); - if (id) { - var anchor = document.createElement("a"); - anchor.className = 'header-link'; - anchor.href = '#' + id; - anchor.innerHTML = 'Permalink'; - anchor.title = "Permalink"; - $(this).append(anchor); - } - }); -}); diff --git a/docs/assets/js/lunr/lunr-en.js b/docs/assets/js/lunr/lunr-en.js deleted file mode 100644 index 43429309fa..0000000000 --- a/docs/assets/js/lunr/lunr-en.js +++ /dev/null @@ -1,73 +0,0 @@ ---- -layout: none ---- - -var idx = lunr(function () { - this.field('title') - this.field('excerpt') - this.field('categories') - this.field('tags') - this.ref('id') - - this.pipeline.remove(lunr.trimmer) - - for (var item in store) { - this.add({ - title: store[item].title, - excerpt: store[item].excerpt, - categories: store[item].categories, - tags: store[item].tags, - id: item - }) - } -}); - -$(document).ready(function() { - $('input#search').on('keyup', function () { - var resultdiv = $('#results'); - var query = $(this).val().toLowerCase(); - var result = - idx.query(function (q) { - query.split(lunr.tokenizer.separator).forEach(function (term) { - q.term(term, { boost: 100 }) - if(query.lastIndexOf(" ") != query.length-1){ - q.term(term, { usePipeline: false, wildcard: lunr.Query.wildcard.TRAILING, boost: 10 }) - } - if (term != ""){ - q.term(term, { usePipeline: false, editDistance: 1, boost: 1 }) - } - }) - }); - resultdiv.empty(); - resultdiv.prepend('

'+result.length+' {{ site.data.ui-text[site.locale].results_found | default: "Result(s) found" }}

'); - for (var item in result) { - var ref = result[item].ref; - if(store[ref].teaser){ - var searchitem = - '
'+ - '
'+ - '

'+ - ''+store[ref].title+''+ - '

'+ - '
'+ - ''+ - '
'+ - '

'+store[ref].excerpt.split(" ").splice(0,20).join(" ")+'...

'+ - '
'+ - '
'; - } - else{ - var searchitem = - '
'+ - '
'+ - '

'+ - ''+store[ref].title+''+ - '

'+ - '

'+store[ref].excerpt.split(" ").splice(0,20).join(" ")+'...

'+ - '
'+ - '
'; - } - resultdiv.append(searchitem); - } - }); -}); diff --git a/docs/assets/js/lunr/lunr-gr.js b/docs/assets/js/lunr/lunr-gr.js deleted file mode 100644 index 10eb0e71ce..0000000000 --- a/docs/assets/js/lunr/lunr-gr.js +++ /dev/null @@ -1,526 +0,0 @@ ---- -layout: none ---- - -step1list = new Array(); -step1list["ΦΑΓΙΑ"] = "ΦΑ"; -step1list["ΦΑΓΙΟΥ"] = "ΦΑ"; -step1list["ΦΑΓΙΩΝ"] = "ΦΑ"; -step1list["ΣΚΑΓΙΑ"] = "ΣΚΑ"; -step1list["ΣΚΑΓΙΟΥ"] = "ΣΚΑ"; -step1list["ΣΚΑΓΙΩΝ"] = "ΣΚΑ"; -step1list["ΟΛΟΓΙΟΥ"] = "ΟΛΟ"; -step1list["ΟΛΟΓΙΑ"] = "ΟΛΟ"; -step1list["ΟΛΟΓΙΩΝ"] = "ΟΛΟ"; -step1list["ΣΟΓΙΟΥ"] = "ΣΟ"; -step1list["ΣΟΓΙΑ"] = "ΣΟ"; -step1list["ΣΟΓΙΩΝ"] = "ΣΟ"; -step1list["ΤΑΤΟΓΙΑ"] = "ΤΑΤΟ"; -step1list["ΤΑΤΟΓΙΟΥ"] = "ΤΑΤΟ"; -step1list["ΤΑΤΟΓΙΩΝ"] = "ΤΑΤΟ"; -step1list["ΚΡΕΑΣ"] = "ΚΡΕ"; -step1list["ΚΡΕΑΤΟΣ"] = "ΚΡΕ"; -step1list["ΚΡΕΑΤΑ"] = "ΚΡΕ"; -step1list["ΚΡΕΑΤΩΝ"] = "ΚΡΕ"; -step1list["ΠΕΡΑΣ"] = "ΠΕΡ"; -step1list["ΠΕΡΑΤΟΣ"] = "ΠΕΡ"; -step1list["ΠΕΡΑΤΑ"] = "ΠΕΡ"; -step1list["ΠΕΡΑΤΩΝ"] = "ΠΕΡ"; -step1list["ΤΕΡΑΣ"] = "ΤΕΡ"; -step1list["ΤΕΡΑΤΟΣ"] = "ΤΕΡ"; -step1list["ΤΕΡΑΤΑ"] = "ΤΕΡ"; -step1list["ΤΕΡΑΤΩΝ"] = "ΤΕΡ"; -step1list["ΦΩΣ"] = "ΦΩ"; -step1list["ΦΩΤΟΣ"] = "ΦΩ"; -step1list["ΦΩΤΑ"] = "ΦΩ"; -step1list["ΦΩΤΩΝ"] = "ΦΩ"; -step1list["ΚΑΘΕΣΤΩΣ"] = "ΚΑΘΕΣΤ"; -step1list["ΚΑΘΕΣΤΩΤΟΣ"] = "ΚΑΘΕΣΤ"; -step1list["ΚΑΘΕΣΤΩΤΑ"] = "ΚΑΘΕΣΤ"; -step1list["ΚΑΘΕΣΤΩΤΩΝ"] = "ΚΑΘΕΣΤ"; -step1list["ΓΕΓΟΝΟΣ"] = "ΓΕΓΟΝ"; -step1list["ΓΕΓΟΝΟΤΟΣ"] = "ΓΕΓΟΝ"; -step1list["ΓΕΓΟΝΟΤΑ"] = "ΓΕΓΟΝ"; -step1list["ΓΕΓΟΝΟΤΩΝ"] = "ΓΕΓΟΝ"; - -v = "[ΑΕΗΙΟΥΩ]"; -v2 = "[ΑΕΗΙΟΩ]" - -function stemWord(w) { - var stem; - var suffix; - var firstch; - var origword = w; - test1 = new Boolean(true); - - if(w.length < 4) { - return w; - } - - var re; - var re2; - var re3; - var re4; - - re = /(.*)(ΦΑΓΙΑ|ΦΑΓΙΟΥ|ΦΑΓΙΩΝ|ΣΚΑΓΙΑ|ΣΚΑΓΙΟΥ|ΣΚΑΓΙΩΝ|ΟΛΟΓΙΟΥ|ΟΛΟΓΙΑ|ΟΛΟΓΙΩΝ|ΣΟΓΙΟΥ|ΣΟΓΙΑ|ΣΟΓΙΩΝ|ΤΑΤΟΓΙΑ|ΤΑΤΟΓΙΟΥ|ΤΑΤΟΓΙΩΝ|ΚΡΕΑΣ|ΚΡΕΑΤΟΣ|ΚΡΕΑΤΑ|ΚΡΕΑΤΩΝ|ΠΕΡΑΣ|ΠΕΡΑΤΟΣ|ΠΕΡΑΤΑ|ΠΕΡΑΤΩΝ|ΤΕΡΑΣ|ΤΕΡΑΤΟΣ|ΤΕΡΑΤΑ|ΤΕΡΑΤΩΝ|ΦΩΣ|ΦΩΤΟΣ|ΦΩΤΑ|ΦΩΤΩΝ|ΚΑΘΕΣΤΩΣ|ΚΑΘΕΣΤΩΤΟΣ|ΚΑΘΕΣΤΩΤΑ|ΚΑΘΕΣΤΩΤΩΝ|ΓΕΓΟΝΟΣ|ΓΕΓΟΝΟΤΟΣ|ΓΕΓΟΝΟΤΑ|ΓΕΓΟΝΟΤΩΝ)$/; - - if(re.test(w)) { - var fp = re.exec(w); - stem = fp[1]; - suffix = fp[2]; - w = stem + step1list[suffix]; - test1 = false; - } - - re = /^(.+?)(ΑΔΕΣ|ΑΔΩΝ)$/; - - if(re.test(w)) { - var fp = re.exec(w); - stem = fp[1]; - w = stem; - - reg1 = /(ΟΚ|ΜΑΜ|ΜΑΝ|ΜΠΑΜΠ|ΠΑΤΕΡ|ΓΙΑΓΙ|ΝΤΑΝΤ|ΚΥΡ|ΘΕΙ|ΠΕΘΕΡ)$/; - - if(!(reg1.test(w))) { - w = w + "ΑΔ"; - } - } - - re2 = /^(.+?)(ΕΔΕΣ|ΕΔΩΝ)$/; - - if(re2.test(w)) { - var fp = re2.exec(w); - stem = fp[1]; - w = stem; - - exept2 = /(ΟΠ|ΙΠ|ΕΜΠ|ΥΠ|ΓΗΠ|ΔΑΠ|ΚΡΑΣΠ|ΜΙΛ)$/; - - if(exept2.test(w)) { - w = w + "ΕΔ"; - } - } - - re3 = /^(.+?)(ΟΥΔΕΣ|ΟΥΔΩΝ)$/; - - if(re3.test(w)) { - var fp = re3.exec(w); - stem = fp[1]; - w = stem; - - exept3 = /(ΑΡΚ|ΚΑΛΙΑΚ|ΠΕΤΑΛ|ΛΙΧ|ΠΛΕΞ|ΣΚ|Σ|ΦΛ|ΦΡ|ΒΕΛ|ΛΟΥΛ|ΧΝ|ΣΠ|ΤΡΑΓ|ΦΕ)$/; - - if(exept3.test(w)) { - w = w + "ΟΥΔ"; - } - } - - re4 = /^(.+?)(ΕΩΣ|ΕΩΝ)$/; - - if(re4.test(w)) { - var fp = re4.exec(w); - stem = fp[1]; - w = stem; - test1 = false; - - exept4 = /^(Θ|Δ|ΕΛ|ΓΑΛ|Ν|Π|ΙΔ|ΠΑΡ)$/; - - if(exept4.test(w)) { - w = w + "Ε"; - } - } - - re = /^(.+?)(ΙΑ|ΙΟΥ|ΙΩΝ)$/; - - if(re.test(w)) { - var fp = re.exec(w); - stem = fp[1]; - w = stem; - re2 = new RegExp(v + "$"); - test1 = false; - - if(re2.test(w)) { - w = stem + "Ι"; - } - } - - re = /^(.+?)(ΙΚΑ|ΙΚΟ|ΙΚΟΥ|ΙΚΩΝ)$/; - - if(re.test(w)) { - var fp = re.exec(w); - stem = fp[1]; - w = stem; - test1 = false; - - re2 = new RegExp(v + "$"); - exept5 = /^(ΑΛ|ΑΔ|ΕΝΔ|ΑΜΑΝ|ΑΜΜΟΧΑΛ|ΗΘ|ΑΝΗΘ|ΑΝΤΙΔ|ΦΥΣ|ΒΡΩΜ|ΓΕΡ|ΕΞΩΔ|ΚΑΛΠ|ΚΑΛΛΙΝ|ΚΑΤΑΔ|ΜΟΥΛ|ΜΠΑΝ|ΜΠΑΓΙΑΤ|ΜΠΟΛ|ΜΠΟΣ|ΝΙΤ|ΞΙΚ|ΣΥΝΟΜΗΛ|ΠΕΤΣ|ΠΙΤΣ|ΠΙΚΑΝΤ|ΠΛΙΑΤΣ|ΠΟΣΤΕΛΝ|ΠΡΩΤΟΔ|ΣΕΡΤ|ΣΥΝΑΔ|ΤΣΑΜ|ΥΠΟΔ|ΦΙΛΟΝ|ΦΥΛΟΔ|ΧΑΣ)$/; - - if((exept5.test(w)) || (re2.test(w))) { - w = w + "ΙΚ"; - } - } - - re = /^(.+?)(ΑΜΕ)$/; - re2 = /^(.+?)(ΑΓΑΜΕ|ΗΣΑΜΕ|ΟΥΣΑΜΕ|ΗΚΑΜΕ|ΗΘΗΚΑΜΕ)$/; - if(w == "ΑΓΑΜΕ") { - w = "ΑΓΑΜ"; - } - - if(re2.test(w)) { - var fp = re2.exec(w); - stem = fp[1]; - w = stem; - test1 = false; - } - - if(re.test(w)) { - var fp = re.exec(w); - stem = fp[1]; - w = stem; - test1 = false; - - exept6 = /^(ΑΝΑΠ|ΑΠΟΘ|ΑΠΟΚ|ΑΠΟΣΤ|ΒΟΥΒ|ΞΕΘ|ΟΥΛ|ΠΕΘ|ΠΙΚΡ|ΠΟΤ|ΣΙΧ|Χ)$/; - - if(exept6.test(w)) { - w = w + "ΑΜ"; - } - } - - re2 = /^(.+?)(ΑΝΕ)$/; - re3 = /^(.+?)(ΑΓΑΝΕ|ΗΣΑΝΕ|ΟΥΣΑΝΕ|ΙΟΝΤΑΝΕ|ΙΟΤΑΝΕ|ΙΟΥΝΤΑΝΕ|ΟΝΤΑΝΕ|ΟΤΑΝΕ|ΟΥΝΤΑΝΕ|ΗΚΑΝΕ|ΗΘΗΚΑΝΕ)$/; - - if(re3.test(w)) { - var fp = re3.exec(w); - stem = fp[1]; - w = stem; - test1 = false; - - re3 = /^(ΤΡ|ΤΣ)$/; - - if(re3.test(w)) { - w = w + "ΑΓΑΝ"; - } - } - - if(re2.test(w)) { - var fp = re2.exec(w); - stem = fp[1]; - w = stem; - test1 = false; - - re2 = new RegExp(v2 + "$"); - exept7 = /^(ΒΕΤΕΡ|ΒΟΥΛΚ|ΒΡΑΧΜ|Γ|ΔΡΑΔΟΥΜ|Θ|ΚΑΛΠΟΥΖ|ΚΑΣΤΕΛ|ΚΟΡΜΟΡ|ΛΑΟΠΛ|ΜΩΑΜΕΘ|Μ|ΜΟΥΣΟΥΛΜ|Ν|ΟΥΛ|Π|ΠΕΛΕΚ|ΠΛ|ΠΟΛΙΣ|ΠΟΡΤΟΛ|ΣΑΡΑΚΑΤΣ|ΣΟΥΛΤ|ΤΣΑΡΛΑΤ|ΟΡΦ|ΤΣΙΓΓ|ΤΣΟΠ|ΦΩΤΟΣΤΕΦ|Χ|ΨΥΧΟΠΛ|ΑΓ|ΟΡΦ|ΓΑΛ|ΓΕΡ|ΔΕΚ|ΔΙΠΛ|ΑΜΕΡΙΚΑΝ|ΟΥΡ|ΠΙΘ|ΠΟΥΡΙΤ|Σ|ΖΩΝΤ|ΙΚ|ΚΑΣΤ|ΚΟΠ|ΛΙΧ|ΛΟΥΘΗΡ|ΜΑΙΝΤ|ΜΕΛ|ΣΙΓ|ΣΠ|ΣΤΕΓ|ΤΡΑΓ|ΤΣΑΓ|Φ|ΕΡ|ΑΔΑΠ|ΑΘΙΓΓ|ΑΜΗΧ|ΑΝΙΚ|ΑΝΟΡΓ|ΑΠΗΓ|ΑΠΙΘ|ΑΤΣΙΓΓ|ΒΑΣ|ΒΑΣΚ|ΒΑΘΥΓΑΛ|ΒΙΟΜΗΧ|ΒΡΑΧΥΚ|ΔΙΑΤ|ΔΙΑΦ|ΕΝΟΡΓ|ΘΥΣ|ΚΑΠΝΟΒΙΟΜΗΧ|ΚΑΤΑΓΑΛ|ΚΛΙΒ|ΚΟΙΛΑΡΦ|ΛΙΒ|ΜΕΓΛΟΒΙΟΜΗΧ|ΜΙΚΡΟΒΙΟΜΗΧ|ΝΤΑΒ|ΞΗΡΟΚΛΙΒ|ΟΛΙΓΟΔΑΜ|ΟΛΟΓΑΛ|ΠΕΝΤΑΡΦ|ΠΕΡΗΦ|ΠΕΡΙΤΡ|ΠΛΑΤ|ΠΟΛΥΔΑΠ|ΠΟΛΥΜΗΧ|ΣΤΕΦ|ΤΑΒ|ΤΕΤ|ΥΠΕΡΗΦ|ΥΠΟΚΟΠ|ΧΑΜΗΛΟΔΑΠ|ΨΗΛΟΤΑΒ)$/; - - if((re2.test(w)) || (exept7.test(w))) { - w = w + "ΑΝ"; - } - } - - re3 = /^(.+?)(ΕΤΕ)$/; - re4 = /^(.+?)(ΗΣΕΤΕ)$/; - - if(re4.test(w)) { - var fp = re4.exec(w); - stem = fp[1]; - w = stem; - test1 = false; - } - - if(re3.test(w)) { - var fp = re3.exec(w); - stem = fp[1]; - w = stem; - test1 = false; - - re3 = new RegExp(v2 + "$"); - exept8 = /(ΟΔ|ΑΙΡ|ΦΟΡ|ΤΑΘ|ΔΙΑΘ|ΣΧ|ΕΝΔ|ΕΥΡ|ΤΙΘ|ΥΠΕΡΘ|ΡΑΘ|ΕΝΘ|ΡΟΘ|ΣΘ|ΠΥΡ|ΑΙΝ|ΣΥΝΔ|ΣΥΝ|ΣΥΝΘ|ΧΩΡ|ΠΟΝ|ΒΡ|ΚΑΘ|ΕΥΘ|ΕΚΘ|ΝΕΤ|ΡΟΝ|ΑΡΚ|ΒΑΡ|ΒΟΛ|ΩΦΕΛ)$/; - exept9 = /^(ΑΒΑΡ|ΒΕΝ|ΕΝΑΡ|ΑΒΡ|ΑΔ|ΑΘ|ΑΝ|ΑΠΛ|ΒΑΡΟΝ|ΝΤΡ|ΣΚ|ΚΟΠ|ΜΠΟΡ|ΝΙΦ|ΠΑΓ|ΠΑΡΑΚΑΛ|ΣΕΡΠ|ΣΚΕΛ|ΣΥΡΦ|ΤΟΚ|Υ|Δ|ΕΜ|ΘΑΡΡ|Θ)$/; - - if((re3.test(w)) || (exept8.test(w)) || (exept9.test(w))) { - w = w + "ΕΤ"; - } - } - - re = /^(.+?)(ΟΝΤΑΣ|ΩΝΤΑΣ)$/; - - if(re.test(w)) { - var fp = re.exec(w); - stem = fp[1]; - w = stem; - test1 = false; - - exept10 = /^(ΑΡΧ)$/; - exept11 = /(ΚΡΕ)$/; - if(exept10.test(w)) { - w = w + "ΟΝΤ"; - } - if(exept11.test(w)) { - w = w + "ΩΝΤ"; - } - } - - re = /^(.+?)(ΟΜΑΣΤΕ|ΙΟΜΑΣΤΕ)$/; - - if(re.test(w)) { - var fp = re.exec(w); - stem = fp[1]; - w = stem; - test1 = false; - - exept11 = /^(ΟΝ)$/; - - if(exept11.test(w)) { - w = w + "ΟΜΑΣΤ"; - } - } - - re = /^(.+?)(ΕΣΤΕ)$/; - re2 = /^(.+?)(ΙΕΣΤΕ)$/; - - if(re2.test(w)) { - var fp = re2.exec(w); - stem = fp[1]; - w = stem; - test1 = false; - - re2 = /^(Π|ΑΠ|ΣΥΜΠ|ΑΣΥΜΠ|ΑΚΑΤΑΠ|ΑΜΕΤΑΜΦ)$/; - - if(re2.test(w)) { - w = w + "ΙΕΣΤ"; - } - } - - if(re.test(w)) { - var fp = re.exec(w); - stem = fp[1]; - w = stem; - test1 = false; - - exept12 = /^(ΑΛ|ΑΡ|ΕΚΤΕΛ|Ζ|Μ|Ξ|ΠΑΡΑΚΑΛ|ΑΡ|ΠΡΟ|ΝΙΣ)$/; - - if(exept12.test(w)) { - w = w + "ΕΣΤ"; - } - } - - re = /^(.+?)(ΗΚΑ|ΗΚΕΣ|ΗΚΕ)$/; - re2 = /^(.+?)(ΗΘΗΚΑ|ΗΘΗΚΕΣ|ΗΘΗΚΕ)$/; - - if(re2.test(w)) { - var fp = re2.exec(w); - stem = fp[1]; - w = stem; - test1 = false; - } - - if(re.test(w)) { - var fp = re.exec(w); - stem = fp[1]; - w = stem; - test1 = false; - - exept13 = /(ΣΚΩΛ|ΣΚΟΥΛ|ΝΑΡΘ|ΣΦ|ΟΘ|ΠΙΘ)$/; - exept14 = /^(ΔΙΑΘ|Θ|ΠΑΡΑΚΑΤΑΘ|ΠΡΟΣΘ|ΣΥΝΘ|)$/; - - if((exept13.test(w)) || (exept14.test(w))) { - w = w + "ΗΚ"; - } - } - - re = /^(.+?)(ΟΥΣΑ|ΟΥΣΕΣ|ΟΥΣΕ)$/; - - if(re.test(w)) { - var fp = re.exec(w); - stem = fp[1]; - w = stem; - test1 = false; - - exept15 = /^(ΦΑΡΜΑΚ|ΧΑΔ|ΑΓΚ|ΑΝΑΡΡ|ΒΡΟΜ|ΕΚΛΙΠ|ΛΑΜΠΙΔ|ΛΕΧ|Μ|ΠΑΤ|Ρ|Λ|ΜΕΔ|ΜΕΣΑΖ|ΥΠΟΤΕΙΝ|ΑΜ|ΑΙΘ|ΑΝΗΚ|ΔΕΣΠΟΖ|ΕΝΔΙΑΦΕΡ|ΔΕ|ΔΕΥΤΕΡΕΥ|ΚΑΘΑΡΕΥ|ΠΛΕ|ΤΣΑ)$/; - exept16 = /(ΠΟΔΑΡ|ΒΛΕΠ|ΠΑΝΤΑΧ|ΦΡΥΔ|ΜΑΝΤΙΛ|ΜΑΛΛ|ΚΥΜΑΤ|ΛΑΧ|ΛΗΓ|ΦΑΓ|ΟΜ|ΠΡΩΤ)$/; - - if((exept15.test(w)) || (exept16.test(w))) { - w = w + "ΟΥΣ"; - } - } - - re = /^(.+?)(ΑΓΑ|ΑΓΕΣ|ΑΓΕ)$/; - - if(re.test(w)) { - var fp = re.exec(w); - stem = fp[1]; - w = stem; - test1 = false; - - exept17 = /^(ΨΟΦ|ΝΑΥΛΟΧ)$/; - exept20 = /(ΚΟΛΛ)$/; - exept18 = /^(ΑΒΑΣΤ|ΠΟΛΥΦ|ΑΔΗΦ|ΠΑΜΦ|Ρ|ΑΣΠ|ΑΦ|ΑΜΑΛ|ΑΜΑΛΛΙ|ΑΝΥΣΤ|ΑΠΕΡ|ΑΣΠΑΡ|ΑΧΑΡ|ΔΕΡΒΕΝ|ΔΡΟΣΟΠ|ΞΕΦ|ΝΕΟΠ|ΝΟΜΟΤ|ΟΛΟΠ|ΟΜΟΤ|ΠΡΟΣΤ|ΠΡΟΣΩΠΟΠ|ΣΥΜΠ|ΣΥΝΤ|Τ|ΥΠΟΤ|ΧΑΡ|ΑΕΙΠ|ΑΙΜΟΣΤ|ΑΝΥΠ|ΑΠΟΤ|ΑΡΤΙΠ|ΔΙΑΤ|ΕΝ|ΕΠΙΤ|ΚΡΟΚΑΛΟΠ|ΣΙΔΗΡΟΠ|Λ|ΝΑΥ|ΟΥΛΑΜ|ΟΥΡ|Π|ΤΡ|Μ)$/; - exept19 = /(ΟΦ|ΠΕΛ|ΧΟΡΤ|ΛΛ|ΣΦ|ΡΠ|ΦΡ|ΠΡ|ΛΟΧ|ΣΜΗΝ)$/; - - if(((exept18.test(w)) || (exept19.test(w))) && !((exept17.test(w)) || (exept20.test(w)))) { - w = w + "ΑΓ"; - } - } - - re = /^(.+?)(ΗΣΕ|ΗΣΟΥ|ΗΣΑ)$/; - - if(re.test(w)) { - var fp = re.exec(w); - stem = fp[1]; - w = stem; - test1 = false; - - exept21 = /^(Ν|ΧΕΡΣΟΝ|ΔΩΔΕΚΑΝ|ΕΡΗΜΟΝ|ΜΕΓΑΛΟΝ|ΕΠΤΑΝ)$/; - - if(exept21.test(w)) { - w = w + "ΗΣ"; - } - } - - re = /^(.+?)(ΗΣΤΕ)$/; - - if(re.test(w)) { - var fp = re.exec(w); - stem = fp[1]; - w = stem; - test1 = false; - - exept22 = /^(ΑΣΒ|ΣΒ|ΑΧΡ|ΧΡ|ΑΠΛ|ΑΕΙΜΝ|ΔΥΣΧΡ|ΕΥΧΡ|ΚΟΙΝΟΧΡ|ΠΑΛΙΜΨ)$/; - - if(exept22.test(w)) { - w = w + "ΗΣΤ"; - } - } - - re = /^(.+?)(ΟΥΝΕ|ΗΣΟΥΝΕ|ΗΘΟΥΝΕ)$/; - - if(re.test(w)) { - var fp = re.exec(w); - stem = fp[1]; - w = stem; - test1 = false; - - exept23 = /^(Ν|Ρ|ΣΠΙ|ΣΤΡΑΒΟΜΟΥΤΣ|ΚΑΚΟΜΟΥΤΣ|ΕΞΩΝ)$/; - - if(exept23.test(w)) { - w = w + "ΟΥΝ"; - } - } - - re = /^(.+?)(ΟΥΜΕ|ΗΣΟΥΜΕ|ΗΘΟΥΜΕ)$/; - - if(re.test(w)) { - var fp = re.exec(w); - stem = fp[1]; - w = stem; - test1 = false; - - exept24 = /^(ΠΑΡΑΣΟΥΣ|Φ|Χ|ΩΡΙΟΠΛ|ΑΖ|ΑΛΛΟΣΟΥΣ|ΑΣΟΥΣ)$/; - - if(exept24.test(w)) { - w = w + "ΟΥΜ"; - } - } - - re = /^(.+?)(ΜΑΤΑ|ΜΑΤΩΝ|ΜΑΤΟΣ)$/; - re2 = /^(.+?)(Α|ΑΓΑΤΕ|ΑΓΑΝ|ΑΕΙ|ΑΜΑΙ|ΑΝ|ΑΣ|ΑΣΑΙ|ΑΤΑΙ|ΑΩ|Ε|ΕΙ|ΕΙΣ|ΕΙΤΕ|ΕΣΑΙ|ΕΣ|ΕΤΑΙ|Ι|ΙΕΜΑΙ|ΙΕΜΑΣΤΕ|ΙΕΤΑΙ|ΙΕΣΑΙ|ΙΕΣΑΣΤΕ|ΙΟΜΑΣΤΑΝ|ΙΟΜΟΥΝ|ΙΟΜΟΥΝΑ|ΙΟΝΤΑΝ|ΙΟΝΤΟΥΣΑΝ|ΙΟΣΑΣΤΑΝ|ΙΟΣΑΣΤΕ|ΙΟΣΟΥΝ|ΙΟΣΟΥΝΑ|ΙΟΤΑΝ|ΙΟΥΜΑ|ΙΟΥΜΑΣΤΕ|ΙΟΥΝΤΑΙ|ΙΟΥΝΤΑΝ|Η|ΗΔΕΣ|ΗΔΩΝ|ΗΘΕΙ|ΗΘΕΙΣ|ΗΘΕΙΤΕ|ΗΘΗΚΑΤΕ|ΗΘΗΚΑΝ|ΗΘΟΥΝ|ΗΘΩ|ΗΚΑΤΕ|ΗΚΑΝ|ΗΣ|ΗΣΑΝ|ΗΣΑΤΕ|ΗΣΕΙ|ΗΣΕΣ|ΗΣΟΥΝ|ΗΣΩ|Ο|ΟΙ|ΟΜΑΙ|ΟΜΑΣΤΑΝ|ΟΜΟΥΝ|ΟΜΟΥΝΑ|ΟΝΤΑΙ|ΟΝΤΑΝ|ΟΝΤΟΥΣΑΝ|ΟΣ|ΟΣΑΣΤΑΝ|ΟΣΑΣΤΕ|ΟΣΟΥΝ|ΟΣΟΥΝΑ|ΟΤΑΝ|ΟΥ|ΟΥΜΑΙ|ΟΥΜΑΣΤΕ|ΟΥΝ|ΟΥΝΤΑΙ|ΟΥΝΤΑΝ|ΟΥΣ|ΟΥΣΑΝ|ΟΥΣΑΤΕ|Υ|ΥΣ|Ω|ΩΝ)$/; - - if(re.test(w)) { - var fp = re.exec(w); - stem = fp[1]; - w = stem + "ΜΑ"; - } - - if((re2.test(w)) && (test1)) { - var fp = re2.exec(w); - stem = fp[1]; - w = stem; - - } - - re = /^(.+?)(ΕΣΤΕΡ|ΕΣΤΑΤ|ΟΤΕΡ|ΟΤΑΤ|ΥΤΕΡ|ΥΤΑΤ|ΩΤΕΡ|ΩΤΑΤ)$/; - - if(re.test(w)) { - var fp = re.exec(w); - stem = fp[1]; - w = stem; - } - - return w; -}; - -var greekStemmer = function (token) { - return token.update(function (word) { - return stemWord(word); - }) -} - -var idx = lunr(function () { - this.field('title') - this.field('excerpt') - this.field('categories') - this.field('tags') - this.ref('id') - - this.pipeline.remove(lunr.trimmer) - this.pipeline.add(greekStemmer) - this.pipeline.remove(lunr.stemmer) - - for (var item in store) { - this.add({ - title: store[item].title, - excerpt: store[item].excerpt, - categories: store[item].categories, - tags: store[item].tags, - id: item - }) - } -}); - -$(document).ready(function() { - $('input#search').on('keyup', function () { - var resultdiv = $('#results'); - var query = $(this).val().toLowerCase(); - var result = - idx.query(function (q) { - query.split(lunr.tokenizer.separator).forEach(function (term) { - q.term(term, { boost: 100 }) - if(query.lastIndexOf(" ") != query.length-1){ - q.term(term, { usePipeline: false, wildcard: lunr.Query.wildcard.TRAILING, boost: 10 }) - } - if (term != ""){ - q.term(term, { usePipeline: false, editDistance: 1, boost: 1 }) - } - }) - }); - resultdiv.empty(); - resultdiv.prepend('

'+result.length+' {{ site.data.ui-text[site.locale].results_found | default: "Result(s) found" }}

'); - for (var item in result) { - var ref = result[item].ref; - if(store[ref].teaser){ - var searchitem = - '
'+ - '
'+ - '

'+ - ''+store[ref].title+''+ - '

'+ - '
'+ - ''+ - '
'+ - '

'+store[ref].excerpt.split(" ").splice(0,20).join(" ")+'...

'+ - '
'+ - '
'; - } - else{ - var searchitem = - '
'+ - '
'+ - '

'+ - ''+store[ref].title+''+ - '

'+ - '

'+store[ref].excerpt.split(" ").splice(0,20).join(" ")+'...

'+ - '
'+ - '
'; - } - resultdiv.append(searchitem); - } - }); -}); diff --git a/docs/assets/js/lunr/lunr-store.js b/docs/assets/js/lunr/lunr-store.js deleted file mode 100644 index ff5e2e60db..0000000000 --- a/docs/assets/js/lunr/lunr-store.js +++ /dev/null @@ -1,49 +0,0 @@ ---- -layout: none ---- - -var store = [ - {%- for c in site.collections -%} - {%- if forloop.last -%} - {%- assign l = true -%} - {%- endif -%} - {%- assign docs = c.docs | where_exp:'doc','doc.search != false' -%} - {%- for doc in docs -%} - {%- if doc.header.teaser -%} - {%- capture teaser -%}{{ doc.header.teaser }}{%- endcapture -%} - {%- else -%} - {%- assign teaser = site.teaser -%} - {%- endif -%} - { - "title": {{ doc.title | jsonify }}, - "excerpt": - {%- if site.search_full_content == true -%} - {{ doc.content | newline_to_br | - replace:"
", " " | - replace:"

", " " | - replace:"", " " | - replace:"", " " | - replace:"", " " | - replace:"", " " | - replace:"", " " | - replace:"", " "| - strip_html | strip_newlines | jsonify }}, - {%- else -%} - {{ doc.content | newline_to_br | - replace:"
", " " | - replace:"

", " " | - replace:"", " " | - replace:"", " " | - replace:"", " " | - replace:"", " " | - replace:"", " " | - replace:"", " "| - strip_html | strip_newlines | truncatewords: 50 | jsonify }}, - {%- endif -%} - "categories": {{ doc.categories | jsonify }}, - "tags": {{ doc.tags | jsonify }}, - "url": {{ doc.url | relative_url | jsonify }}, - "teaser": {{ teaser | relative_url | jsonify }} - }{%- unless forloop.last and l -%},{%- endunless -%} - {%- endfor -%} - {%- endfor -%}] diff --git a/docs/assets/js/lunr/lunr.js b/docs/assets/js/lunr/lunr.js deleted file mode 100644 index 6aa370fbcb..0000000000 --- a/docs/assets/js/lunr/lunr.js +++ /dev/null @@ -1,3475 +0,0 @@ -/** - * lunr - http://lunrjs.com - A bit like Solr, but much smaller and not as bright - 2.3.9 - * Copyright (C) 2020 Oliver Nightingale - * @license MIT - */ - -;(function(){ - -/** - * A convenience function for configuring and constructing - * a new lunr Index. - * - * A lunr.Builder instance is created and the pipeline setup - * with a trimmer, stop word filter and stemmer. - * - * This builder object is yielded to the configuration function - * that is passed as a parameter, allowing the list of fields - * and other builder parameters to be customised. - * - * All documents _must_ be added within the passed config function. - * - * @example - * var idx = lunr(function () { - * this.field('title') - * this.field('body') - * this.ref('id') - * - * documents.forEach(function (doc) { - * this.add(doc) - * }, this) - * }) - * - * @see {@link lunr.Builder} - * @see {@link lunr.Pipeline} - * @see {@link lunr.trimmer} - * @see {@link lunr.stopWordFilter} - * @see {@link lunr.stemmer} - * @namespace {function} lunr - */ -var lunr = function (config) { - var builder = new lunr.Builder - - builder.pipeline.add( - lunr.trimmer, - lunr.stopWordFilter, - lunr.stemmer - ) - - builder.searchPipeline.add( - lunr.stemmer - ) - - config.call(builder, builder) - return builder.build() -} - -lunr.version = "2.3.9" -/*! - * lunr.utils - * Copyright (C) 2020 Oliver Nightingale - */ - -/** - * A namespace containing utils for the rest of the lunr library - * @namespace lunr.utils - */ -lunr.utils = {} - -/** - * Print a warning message to the console. - * - * @param {String} message The message to be printed. - * @memberOf lunr.utils - * @function - */ -lunr.utils.warn = (function (global) { - /* eslint-disable no-console */ - return function (message) { - if (global.console && console.warn) { - console.warn(message) - } - } - /* eslint-enable no-console */ -})(this) - -/** - * Convert an object to a string. - * - * In the case of `null` and `undefined` the function returns - * the empty string, in all other cases the result of calling - * `toString` on the passed object is returned. - * - * @param {Any} obj The object to convert to a string. - * @return {String} string representation of the passed object. - * @memberOf lunr.utils - */ -lunr.utils.asString = function (obj) { - if (obj === void 0 || obj === null) { - return "" - } else { - return obj.toString() - } -} - -/** - * Clones an object. - * - * Will create a copy of an existing object such that any mutations - * on the copy cannot affect the original. - * - * Only shallow objects are supported, passing a nested object to this - * function will cause a TypeError. - * - * Objects with primitives, and arrays of primitives are supported. - * - * @param {Object} obj The object to clone. - * @return {Object} a clone of the passed object. - * @throws {TypeError} when a nested object is passed. - * @memberOf Utils - */ -lunr.utils.clone = function (obj) { - if (obj === null || obj === undefined) { - return obj - } - - var clone = Object.create(null), - keys = Object.keys(obj) - - for (var i = 0; i < keys.length; i++) { - var key = keys[i], - val = obj[key] - - if (Array.isArray(val)) { - clone[key] = val.slice() - continue - } - - if (typeof val === 'string' || - typeof val === 'number' || - typeof val === 'boolean') { - clone[key] = val - continue - } - - throw new TypeError("clone is not deep and does not support nested objects") - } - - return clone -} -lunr.FieldRef = function (docRef, fieldName, stringValue) { - this.docRef = docRef - this.fieldName = fieldName - this._stringValue = stringValue -} - -lunr.FieldRef.joiner = "/" - -lunr.FieldRef.fromString = function (s) { - var n = s.indexOf(lunr.FieldRef.joiner) - - if (n === -1) { - throw "malformed field ref string" - } - - var fieldRef = s.slice(0, n), - docRef = s.slice(n + 1) - - return new lunr.FieldRef (docRef, fieldRef, s) -} - -lunr.FieldRef.prototype.toString = function () { - if (this._stringValue == undefined) { - this._stringValue = this.fieldName + lunr.FieldRef.joiner + this.docRef - } - - return this._stringValue -} -/*! - * lunr.Set - * Copyright (C) 2020 Oliver Nightingale - */ - -/** - * A lunr set. - * - * @constructor - */ -lunr.Set = function (elements) { - this.elements = Object.create(null) - - if (elements) { - this.length = elements.length - - for (var i = 0; i < this.length; i++) { - this.elements[elements[i]] = true - } - } else { - this.length = 0 - } -} - -/** - * A complete set that contains all elements. - * - * @static - * @readonly - * @type {lunr.Set} - */ -lunr.Set.complete = { - intersect: function (other) { - return other - }, - - union: function () { - return this - }, - - contains: function () { - return true - } -} - -/** - * An empty set that contains no elements. - * - * @static - * @readonly - * @type {lunr.Set} - */ -lunr.Set.empty = { - intersect: function () { - return this - }, - - union: function (other) { - return other - }, - - contains: function () { - return false - } -} - -/** - * Returns true if this set contains the specified object. - * - * @param {object} object - Object whose presence in this set is to be tested. - * @returns {boolean} - True if this set contains the specified object. - */ -lunr.Set.prototype.contains = function (object) { - return !!this.elements[object] -} - -/** - * Returns a new set containing only the elements that are present in both - * this set and the specified set. - * - * @param {lunr.Set} other - set to intersect with this set. - * @returns {lunr.Set} a new set that is the intersection of this and the specified set. - */ - -lunr.Set.prototype.intersect = function (other) { - var a, b, elements, intersection = [] - - if (other === lunr.Set.complete) { - return this - } - - if (other === lunr.Set.empty) { - return other - } - - if (this.length < other.length) { - a = this - b = other - } else { - a = other - b = this - } - - elements = Object.keys(a.elements) - - for (var i = 0; i < elements.length; i++) { - var element = elements[i] - if (element in b.elements) { - intersection.push(element) - } - } - - return new lunr.Set (intersection) -} - -/** - * Returns a new set combining the elements of this and the specified set. - * - * @param {lunr.Set} other - set to union with this set. - * @return {lunr.Set} a new set that is the union of this and the specified set. - */ - -lunr.Set.prototype.union = function (other) { - if (other === lunr.Set.complete) { - return lunr.Set.complete - } - - if (other === lunr.Set.empty) { - return this - } - - return new lunr.Set(Object.keys(this.elements).concat(Object.keys(other.elements))) -} -/** - * A function to calculate the inverse document frequency for - * a posting. This is shared between the builder and the index - * - * @private - * @param {object} posting - The posting for a given term - * @param {number} documentCount - The total number of documents. - */ -lunr.idf = function (posting, documentCount) { - var documentsWithTerm = 0 - - for (var fieldName in posting) { - if (fieldName == '_index') continue // Ignore the term index, its not a field - documentsWithTerm += Object.keys(posting[fieldName]).length - } - - var x = (documentCount - documentsWithTerm + 0.5) / (documentsWithTerm + 0.5) - - return Math.log(1 + Math.abs(x)) -} - -/** - * A token wraps a string representation of a token - * as it is passed through the text processing pipeline. - * - * @constructor - * @param {string} [str=''] - The string token being wrapped. - * @param {object} [metadata={}] - Metadata associated with this token. - */ -lunr.Token = function (str, metadata) { - this.str = str || "" - this.metadata = metadata || {} -} - -/** - * Returns the token string that is being wrapped by this object. - * - * @returns {string} - */ -lunr.Token.prototype.toString = function () { - return this.str -} - -/** - * A token update function is used when updating or optionally - * when cloning a token. - * - * @callback lunr.Token~updateFunction - * @param {string} str - The string representation of the token. - * @param {Object} metadata - All metadata associated with this token. - */ - -/** - * Applies the given function to the wrapped string token. - * - * @example - * token.update(function (str, metadata) { - * return str.toUpperCase() - * }) - * - * @param {lunr.Token~updateFunction} fn - A function to apply to the token string. - * @returns {lunr.Token} - */ -lunr.Token.prototype.update = function (fn) { - this.str = fn(this.str, this.metadata) - return this -} - -/** - * Creates a clone of this token. Optionally a function can be - * applied to the cloned token. - * - * @param {lunr.Token~updateFunction} [fn] - An optional function to apply to the cloned token. - * @returns {lunr.Token} - */ -lunr.Token.prototype.clone = function (fn) { - fn = fn || function (s) { return s } - return new lunr.Token (fn(this.str, this.metadata), this.metadata) -} -/*! - * lunr.tokenizer - * Copyright (C) 2020 Oliver Nightingale - */ - -/** - * A function for splitting a string into tokens ready to be inserted into - * the search index. Uses `lunr.tokenizer.separator` to split strings, change - * the value of this property to change how strings are split into tokens. - * - * This tokenizer will convert its parameter to a string by calling `toString` and - * then will split this string on the character in `lunr.tokenizer.separator`. - * Arrays will have their elements converted to strings and wrapped in a lunr.Token. - * - * Optional metadata can be passed to the tokenizer, this metadata will be cloned and - * added as metadata to every token that is created from the object to be tokenized. - * - * @static - * @param {?(string|object|object[])} obj - The object to convert into tokens - * @param {?object} metadata - Optional metadata to associate with every token - * @returns {lunr.Token[]} - * @see {@link lunr.Pipeline} - */ -lunr.tokenizer = function (obj, metadata) { - if (obj == null || obj == undefined) { - return [] - } - - if (Array.isArray(obj)) { - return obj.map(function (t) { - return new lunr.Token( - lunr.utils.asString(t).toLowerCase(), - lunr.utils.clone(metadata) - ) - }) - } - - var str = obj.toString().toLowerCase(), - len = str.length, - tokens = [] - - for (var sliceEnd = 0, sliceStart = 0; sliceEnd <= len; sliceEnd++) { - var char = str.charAt(sliceEnd), - sliceLength = sliceEnd - sliceStart - - if ((char.match(lunr.tokenizer.separator) || sliceEnd == len)) { - - if (sliceLength > 0) { - var tokenMetadata = lunr.utils.clone(metadata) || {} - tokenMetadata["position"] = [sliceStart, sliceLength] - tokenMetadata["index"] = tokens.length - - tokens.push( - new lunr.Token ( - str.slice(sliceStart, sliceEnd), - tokenMetadata - ) - ) - } - - sliceStart = sliceEnd + 1 - } - - } - - return tokens -} - -/** - * The separator used to split a string into tokens. Override this property to change the behaviour of - * `lunr.tokenizer` behaviour when tokenizing strings. By default this splits on whitespace and hyphens. - * - * @static - * @see lunr.tokenizer - */ -lunr.tokenizer.separator = /[\s\-]+/ -/*! - * lunr.Pipeline - * Copyright (C) 2020 Oliver Nightingale - */ - -/** - * lunr.Pipelines maintain an ordered list of functions to be applied to all - * tokens in documents entering the search index and queries being ran against - * the index. - * - * An instance of lunr.Index created with the lunr shortcut will contain a - * pipeline with a stop word filter and an English language stemmer. Extra - * functions can be added before or after either of these functions or these - * default functions can be removed. - * - * When run the pipeline will call each function in turn, passing a token, the - * index of that token in the original list of all tokens and finally a list of - * all the original tokens. - * - * The output of functions in the pipeline will be passed to the next function - * in the pipeline. To exclude a token from entering the index the function - * should return undefined, the rest of the pipeline will not be called with - * this token. - * - * For serialisation of pipelines to work, all functions used in an instance of - * a pipeline should be registered with lunr.Pipeline. Registered functions can - * then be loaded. If trying to load a serialised pipeline that uses functions - * that are not registered an error will be thrown. - * - * If not planning on serialising the pipeline then registering pipeline functions - * is not necessary. - * - * @constructor - */ -lunr.Pipeline = function () { - this._stack = [] -} - -lunr.Pipeline.registeredFunctions = Object.create(null) - -/** - * A pipeline function maps lunr.Token to lunr.Token. A lunr.Token contains the token - * string as well as all known metadata. A pipeline function can mutate the token string - * or mutate (or add) metadata for a given token. - * - * A pipeline function can indicate that the passed token should be discarded by returning - * null, undefined or an empty string. This token will not be passed to any downstream pipeline - * functions and will not be added to the index. - * - * Multiple tokens can be returned by returning an array of tokens. Each token will be passed - * to any downstream pipeline functions and all will returned tokens will be added to the index. - * - * Any number of pipeline functions may be chained together using a lunr.Pipeline. - * - * @interface lunr.PipelineFunction - * @param {lunr.Token} token - A token from the document being processed. - * @param {number} i - The index of this token in the complete list of tokens for this document/field. - * @param {lunr.Token[]} tokens - All tokens for this document/field. - * @returns {(?lunr.Token|lunr.Token[])} - */ - -/** - * Register a function with the pipeline. - * - * Functions that are used in the pipeline should be registered if the pipeline - * needs to be serialised, or a serialised pipeline needs to be loaded. - * - * Registering a function does not add it to a pipeline, functions must still be - * added to instances of the pipeline for them to be used when running a pipeline. - * - * @param {lunr.PipelineFunction} fn - The function to check for. - * @param {String} label - The label to register this function with - */ -lunr.Pipeline.registerFunction = function (fn, label) { - if (label in this.registeredFunctions) { - lunr.utils.warn('Overwriting existing registered function: ' + label) - } - - fn.label = label - lunr.Pipeline.registeredFunctions[fn.label] = fn -} - -/** - * Warns if the function is not registered as a Pipeline function. - * - * @param {lunr.PipelineFunction} fn - The function to check for. - * @private - */ -lunr.Pipeline.warnIfFunctionNotRegistered = function (fn) { - var isRegistered = fn.label && (fn.label in this.registeredFunctions) - - if (!isRegistered) { - lunr.utils.warn('Function is not registered with pipeline. This may cause problems when serialising the index.\n', fn) - } -} - -/** - * Loads a previously serialised pipeline. - * - * All functions to be loaded must already be registered with lunr.Pipeline. - * If any function from the serialised data has not been registered then an - * error will be thrown. - * - * @param {Object} serialised - The serialised pipeline to load. - * @returns {lunr.Pipeline} - */ -lunr.Pipeline.load = function (serialised) { - var pipeline = new lunr.Pipeline - - serialised.forEach(function (fnName) { - var fn = lunr.Pipeline.registeredFunctions[fnName] - - if (fn) { - pipeline.add(fn) - } else { - throw new Error('Cannot load unregistered function: ' + fnName) - } - }) - - return pipeline -} - -/** - * Adds new functions to the end of the pipeline. - * - * Logs a warning if the function has not been registered. - * - * @param {lunr.PipelineFunction[]} functions - Any number of functions to add to the pipeline. - */ -lunr.Pipeline.prototype.add = function () { - var fns = Array.prototype.slice.call(arguments) - - fns.forEach(function (fn) { - lunr.Pipeline.warnIfFunctionNotRegistered(fn) - this._stack.push(fn) - }, this) -} - -/** - * Adds a single function after a function that already exists in the - * pipeline. - * - * Logs a warning if the function has not been registered. - * - * @param {lunr.PipelineFunction} existingFn - A function that already exists in the pipeline. - * @param {lunr.PipelineFunction} newFn - The new function to add to the pipeline. - */ -lunr.Pipeline.prototype.after = function (existingFn, newFn) { - lunr.Pipeline.warnIfFunctionNotRegistered(newFn) - - var pos = this._stack.indexOf(existingFn) - if (pos == -1) { - throw new Error('Cannot find existingFn') - } - - pos = pos + 1 - this._stack.splice(pos, 0, newFn) -} - -/** - * Adds a single function before a function that already exists in the - * pipeline. - * - * Logs a warning if the function has not been registered. - * - * @param {lunr.PipelineFunction} existingFn - A function that already exists in the pipeline. - * @param {lunr.PipelineFunction} newFn - The new function to add to the pipeline. - */ -lunr.Pipeline.prototype.before = function (existingFn, newFn) { - lunr.Pipeline.warnIfFunctionNotRegistered(newFn) - - var pos = this._stack.indexOf(existingFn) - if (pos == -1) { - throw new Error('Cannot find existingFn') - } - - this._stack.splice(pos, 0, newFn) -} - -/** - * Removes a function from the pipeline. - * - * @param {lunr.PipelineFunction} fn The function to remove from the pipeline. - */ -lunr.Pipeline.prototype.remove = function (fn) { - var pos = this._stack.indexOf(fn) - if (pos == -1) { - return - } - - this._stack.splice(pos, 1) -} - -/** - * Runs the current list of functions that make up the pipeline against the - * passed tokens. - * - * @param {Array} tokens The tokens to run through the pipeline. - * @returns {Array} - */ -lunr.Pipeline.prototype.run = function (tokens) { - var stackLength = this._stack.length - - for (var i = 0; i < stackLength; i++) { - var fn = this._stack[i] - var memo = [] - - for (var j = 0; j < tokens.length; j++) { - var result = fn(tokens[j], j, tokens) - - if (result === null || result === void 0 || result === '') continue - - if (Array.isArray(result)) { - for (var k = 0; k < result.length; k++) { - memo.push(result[k]) - } - } else { - memo.push(result) - } - } - - tokens = memo - } - - return tokens -} - -/** - * Convenience method for passing a string through a pipeline and getting - * strings out. This method takes care of wrapping the passed string in a - * token and mapping the resulting tokens back to strings. - * - * @param {string} str - The string to pass through the pipeline. - * @param {?object} metadata - Optional metadata to associate with the token - * passed to the pipeline. - * @returns {string[]} - */ -lunr.Pipeline.prototype.runString = function (str, metadata) { - var token = new lunr.Token (str, metadata) - - return this.run([token]).map(function (t) { - return t.toString() - }) -} - -/** - * Resets the pipeline by removing any existing processors. - * - */ -lunr.Pipeline.prototype.reset = function () { - this._stack = [] -} - -/** - * Returns a representation of the pipeline ready for serialisation. - * - * Logs a warning if the function has not been registered. - * - * @returns {Array} - */ -lunr.Pipeline.prototype.toJSON = function () { - return this._stack.map(function (fn) { - lunr.Pipeline.warnIfFunctionNotRegistered(fn) - - return fn.label - }) -} -/*! - * lunr.Vector - * Copyright (C) 2020 Oliver Nightingale - */ - -/** - * A vector is used to construct the vector space of documents and queries. These - * vectors support operations to determine the similarity between two documents or - * a document and a query. - * - * Normally no parameters are required for initializing a vector, but in the case of - * loading a previously dumped vector the raw elements can be provided to the constructor. - * - * For performance reasons vectors are implemented with a flat array, where an elements - * index is immediately followed by its value. E.g. [index, value, index, value]. This - * allows the underlying array to be as sparse as possible and still offer decent - * performance when being used for vector calculations. - * - * @constructor - * @param {Number[]} [elements] - The flat list of element index and element value pairs. - */ -lunr.Vector = function (elements) { - this._magnitude = 0 - this.elements = elements || [] -} - - -/** - * Calculates the position within the vector to insert a given index. - * - * This is used internally by insert and upsert. If there are duplicate indexes then - * the position is returned as if the value for that index were to be updated, but it - * is the callers responsibility to check whether there is a duplicate at that index - * - * @param {Number} insertIdx - The index at which the element should be inserted. - * @returns {Number} - */ -lunr.Vector.prototype.positionForIndex = function (index) { - // For an empty vector the tuple can be inserted at the beginning - if (this.elements.length == 0) { - return 0 - } - - var start = 0, - end = this.elements.length / 2, - sliceLength = end - start, - pivotPoint = Math.floor(sliceLength / 2), - pivotIndex = this.elements[pivotPoint * 2] - - while (sliceLength > 1) { - if (pivotIndex < index) { - start = pivotPoint - } - - if (pivotIndex > index) { - end = pivotPoint - } - - if (pivotIndex == index) { - break - } - - sliceLength = end - start - pivotPoint = start + Math.floor(sliceLength / 2) - pivotIndex = this.elements[pivotPoint * 2] - } - - if (pivotIndex == index) { - return pivotPoint * 2 - } - - if (pivotIndex > index) { - return pivotPoint * 2 - } - - if (pivotIndex < index) { - return (pivotPoint + 1) * 2 - } -} - -/** - * Inserts an element at an index within the vector. - * - * Does not allow duplicates, will throw an error if there is already an entry - * for this index. - * - * @param {Number} insertIdx - The index at which the element should be inserted. - * @param {Number} val - The value to be inserted into the vector. - */ -lunr.Vector.prototype.insert = function (insertIdx, val) { - this.upsert(insertIdx, val, function () { - throw "duplicate index" - }) -} - -/** - * Inserts or updates an existing index within the vector. - * - * @param {Number} insertIdx - The index at which the element should be inserted. - * @param {Number} val - The value to be inserted into the vector. - * @param {function} fn - A function that is called for updates, the existing value and the - * requested value are passed as arguments - */ -lunr.Vector.prototype.upsert = function (insertIdx, val, fn) { - this._magnitude = 0 - var position = this.positionForIndex(insertIdx) - - if (this.elements[position] == insertIdx) { - this.elements[position + 1] = fn(this.elements[position + 1], val) - } else { - this.elements.splice(position, 0, insertIdx, val) - } -} - -/** - * Calculates the magnitude of this vector. - * - * @returns {Number} - */ -lunr.Vector.prototype.magnitude = function () { - if (this._magnitude) return this._magnitude - - var sumOfSquares = 0, - elementsLength = this.elements.length - - for (var i = 1; i < elementsLength; i += 2) { - var val = this.elements[i] - sumOfSquares += val * val - } - - return this._magnitude = Math.sqrt(sumOfSquares) -} - -/** - * Calculates the dot product of this vector and another vector. - * - * @param {lunr.Vector} otherVector - The vector to compute the dot product with. - * @returns {Number} - */ -lunr.Vector.prototype.dot = function (otherVector) { - var dotProduct = 0, - a = this.elements, b = otherVector.elements, - aLen = a.length, bLen = b.length, - aVal = 0, bVal = 0, - i = 0, j = 0 - - while (i < aLen && j < bLen) { - aVal = a[i], bVal = b[j] - if (aVal < bVal) { - i += 2 - } else if (aVal > bVal) { - j += 2 - } else if (aVal == bVal) { - dotProduct += a[i + 1] * b[j + 1] - i += 2 - j += 2 - } - } - - return dotProduct -} - -/** - * Calculates the similarity between this vector and another vector. - * - * @param {lunr.Vector} otherVector - The other vector to calculate the - * similarity with. - * @returns {Number} - */ -lunr.Vector.prototype.similarity = function (otherVector) { - return this.dot(otherVector) / this.magnitude() || 0 -} - -/** - * Converts the vector to an array of the elements within the vector. - * - * @returns {Number[]} - */ -lunr.Vector.prototype.toArray = function () { - var output = new Array (this.elements.length / 2) - - for (var i = 1, j = 0; i < this.elements.length; i += 2, j++) { - output[j] = this.elements[i] - } - - return output -} - -/** - * A JSON serializable representation of the vector. - * - * @returns {Number[]} - */ -lunr.Vector.prototype.toJSON = function () { - return this.elements -} -/* eslint-disable */ -/*! - * lunr.stemmer - * Copyright (C) 2020 Oliver Nightingale - * Includes code from - http://tartarus.org/~martin/PorterStemmer/js.txt - */ - -/** - * lunr.stemmer is an english language stemmer, this is a JavaScript - * implementation of the PorterStemmer taken from http://tartarus.org/~martin - * - * @static - * @implements {lunr.PipelineFunction} - * @param {lunr.Token} token - The string to stem - * @returns {lunr.Token} - * @see {@link lunr.Pipeline} - * @function - */ -lunr.stemmer = (function(){ - var step2list = { - "ational" : "ate", - "tional" : "tion", - "enci" : "ence", - "anci" : "ance", - "izer" : "ize", - "bli" : "ble", - "alli" : "al", - "entli" : "ent", - "eli" : "e", - "ousli" : "ous", - "ization" : "ize", - "ation" : "ate", - "ator" : "ate", - "alism" : "al", - "iveness" : "ive", - "fulness" : "ful", - "ousness" : "ous", - "aliti" : "al", - "iviti" : "ive", - "biliti" : "ble", - "logi" : "log" - }, - - step3list = { - "icate" : "ic", - "ative" : "", - "alize" : "al", - "iciti" : "ic", - "ical" : "ic", - "ful" : "", - "ness" : "" - }, - - c = "[^aeiou]", // consonant - v = "[aeiouy]", // vowel - C = c + "[^aeiouy]*", // consonant sequence - V = v + "[aeiou]*", // vowel sequence - - mgr0 = "^(" + C + ")?" + V + C, // [C]VC... is m>0 - meq1 = "^(" + C + ")?" + V + C + "(" + V + ")?$", // [C]VC[V] is m=1 - mgr1 = "^(" + C + ")?" + V + C + V + C, // [C]VCVC... is m>1 - s_v = "^(" + C + ")?" + v; // vowel in stem - - var re_mgr0 = new RegExp(mgr0); - var re_mgr1 = new RegExp(mgr1); - var re_meq1 = new RegExp(meq1); - var re_s_v = new RegExp(s_v); - - var re_1a = /^(.+?)(ss|i)es$/; - var re2_1a = /^(.+?)([^s])s$/; - var re_1b = /^(.+?)eed$/; - var re2_1b = /^(.+?)(ed|ing)$/; - var re_1b_2 = /.$/; - var re2_1b_2 = /(at|bl|iz)$/; - var re3_1b_2 = new RegExp("([^aeiouylsz])\\1$"); - var re4_1b_2 = new RegExp("^" + C + v + "[^aeiouwxy]$"); - - var re_1c = /^(.+?[^aeiou])y$/; - var re_2 = /^(.+?)(ational|tional|enci|anci|izer|bli|alli|entli|eli|ousli|ization|ation|ator|alism|iveness|fulness|ousness|aliti|iviti|biliti|logi)$/; - - var re_3 = /^(.+?)(icate|ative|alize|iciti|ical|ful|ness)$/; - - var re_4 = /^(.+?)(al|ance|ence|er|ic|able|ible|ant|ement|ment|ent|ou|ism|ate|iti|ous|ive|ize)$/; - var re2_4 = /^(.+?)(s|t)(ion)$/; - - var re_5 = /^(.+?)e$/; - var re_5_1 = /ll$/; - var re3_5 = new RegExp("^" + C + v + "[^aeiouwxy]$"); - - var porterStemmer = function porterStemmer(w) { - var stem, - suffix, - firstch, - re, - re2, - re3, - re4; - - if (w.length < 3) { return w; } - - firstch = w.substr(0,1); - if (firstch == "y") { - w = firstch.toUpperCase() + w.substr(1); - } - - // Step 1a - re = re_1a - re2 = re2_1a; - - if (re.test(w)) { w = w.replace(re,"$1$2"); } - else if (re2.test(w)) { w = w.replace(re2,"$1$2"); } - - // Step 1b - re = re_1b; - re2 = re2_1b; - if (re.test(w)) { - var fp = re.exec(w); - re = re_mgr0; - if (re.test(fp[1])) { - re = re_1b_2; - w = w.replace(re,""); - } - } else if (re2.test(w)) { - var fp = re2.exec(w); - stem = fp[1]; - re2 = re_s_v; - if (re2.test(stem)) { - w = stem; - re2 = re2_1b_2; - re3 = re3_1b_2; - re4 = re4_1b_2; - if (re2.test(w)) { w = w + "e"; } - else if (re3.test(w)) { re = re_1b_2; w = w.replace(re,""); } - else if (re4.test(w)) { w = w + "e"; } - } - } - - // Step 1c - replace suffix y or Y by i if preceded by a non-vowel which is not the first letter of the word (so cry -> cri, by -> by, say -> say) - re = re_1c; - if (re.test(w)) { - var fp = re.exec(w); - stem = fp[1]; - w = stem + "i"; - } - - // Step 2 - re = re_2; - if (re.test(w)) { - var fp = re.exec(w); - stem = fp[1]; - suffix = fp[2]; - re = re_mgr0; - if (re.test(stem)) { - w = stem + step2list[suffix]; - } - } - - // Step 3 - re = re_3; - if (re.test(w)) { - var fp = re.exec(w); - stem = fp[1]; - suffix = fp[2]; - re = re_mgr0; - if (re.test(stem)) { - w = stem + step3list[suffix]; - } - } - - // Step 4 - re = re_4; - re2 = re2_4; - if (re.test(w)) { - var fp = re.exec(w); - stem = fp[1]; - re = re_mgr1; - if (re.test(stem)) { - w = stem; - } - } else if (re2.test(w)) { - var fp = re2.exec(w); - stem = fp[1] + fp[2]; - re2 = re_mgr1; - if (re2.test(stem)) { - w = stem; - } - } - - // Step 5 - re = re_5; - if (re.test(w)) { - var fp = re.exec(w); - stem = fp[1]; - re = re_mgr1; - re2 = re_meq1; - re3 = re3_5; - if (re.test(stem) || (re2.test(stem) && !(re3.test(stem)))) { - w = stem; - } - } - - re = re_5_1; - re2 = re_mgr1; - if (re.test(w) && re2.test(w)) { - re = re_1b_2; - w = w.replace(re,""); - } - - // and turn initial Y back to y - - if (firstch == "y") { - w = firstch.toLowerCase() + w.substr(1); - } - - return w; - }; - - return function (token) { - return token.update(porterStemmer); - } -})(); - -lunr.Pipeline.registerFunction(lunr.stemmer, 'stemmer') -/*! - * lunr.stopWordFilter - * Copyright (C) 2020 Oliver Nightingale - */ - -/** - * lunr.generateStopWordFilter builds a stopWordFilter function from the provided - * list of stop words. - * - * The built in lunr.stopWordFilter is built using this generator and can be used - * to generate custom stopWordFilters for applications or non English languages. - * - * @function - * @param {Array} token The token to pass through the filter - * @returns {lunr.PipelineFunction} - * @see lunr.Pipeline - * @see lunr.stopWordFilter - */ -lunr.generateStopWordFilter = function (stopWords) { - var words = stopWords.reduce(function (memo, stopWord) { - memo[stopWord] = stopWord - return memo - }, {}) - - return function (token) { - if (token && words[token.toString()] !== token.toString()) return token - } -} - -/** - * lunr.stopWordFilter is an English language stop word list filter, any words - * contained in the list will not be passed through the filter. - * - * This is intended to be used in the Pipeline. If the token does not pass the - * filter then undefined will be returned. - * - * @function - * @implements {lunr.PipelineFunction} - * @params {lunr.Token} token - A token to check for being a stop word. - * @returns {lunr.Token} - * @see {@link lunr.Pipeline} - */ -lunr.stopWordFilter = lunr.generateStopWordFilter([ - 'a', - 'able', - 'about', - 'across', - 'after', - 'all', - 'almost', - 'also', - 'am', - 'among', - 'an', - 'and', - 'any', - 'are', - 'as', - 'at', - 'be', - 'because', - 'been', - 'but', - 'by', - 'can', - 'cannot', - 'could', - 'dear', - 'did', - 'do', - 'does', - 'either', - 'else', - 'ever', - 'every', - 'for', - 'from', - 'get', - 'got', - 'had', - 'has', - 'have', - 'he', - 'her', - 'hers', - 'him', - 'his', - 'how', - 'however', - 'i', - 'if', - 'in', - 'into', - 'is', - 'it', - 'its', - 'just', - 'least', - 'let', - 'like', - 'likely', - 'may', - 'me', - 'might', - 'most', - 'must', - 'my', - 'neither', - 'no', - 'nor', - 'not', - 'of', - 'off', - 'often', - 'on', - 'only', - 'or', - 'other', - 'our', - 'own', - 'rather', - 'said', - 'say', - 'says', - 'she', - 'should', - 'since', - 'so', - 'some', - 'than', - 'that', - 'the', - 'their', - 'them', - 'then', - 'there', - 'these', - 'they', - 'this', - 'tis', - 'to', - 'too', - 'twas', - 'us', - 'wants', - 'was', - 'we', - 'were', - 'what', - 'when', - 'where', - 'which', - 'while', - 'who', - 'whom', - 'why', - 'will', - 'with', - 'would', - 'yet', - 'you', - 'your' -]) - -lunr.Pipeline.registerFunction(lunr.stopWordFilter, 'stopWordFilter') -/*! - * lunr.trimmer - * Copyright (C) 2020 Oliver Nightingale - */ - -/** - * lunr.trimmer is a pipeline function for trimming non word - * characters from the beginning and end of tokens before they - * enter the index. - * - * This implementation may not work correctly for non latin - * characters and should either be removed or adapted for use - * with languages with non-latin characters. - * - * @static - * @implements {lunr.PipelineFunction} - * @param {lunr.Token} token The token to pass through the filter - * @returns {lunr.Token} - * @see lunr.Pipeline - */ -lunr.trimmer = function (token) { - return token.update(function (s) { - return s.replace(/^\W+/, '').replace(/\W+$/, '') - }) -} - -lunr.Pipeline.registerFunction(lunr.trimmer, 'trimmer') -/*! - * lunr.TokenSet - * Copyright (C) 2020 Oliver Nightingale - */ - -/** - * A token set is used to store the unique list of all tokens - * within an index. Token sets are also used to represent an - * incoming query to the index, this query token set and index - * token set are then intersected to find which tokens to look - * up in the inverted index. - * - * A token set can hold multiple tokens, as in the case of the - * index token set, or it can hold a single token as in the - * case of a simple query token set. - * - * Additionally token sets are used to perform wildcard matching. - * Leading, contained and trailing wildcards are supported, and - * from this edit distance matching can also be provided. - * - * Token sets are implemented as a minimal finite state automata, - * where both common prefixes and suffixes are shared between tokens. - * This helps to reduce the space used for storing the token set. - * - * @constructor - */ -lunr.TokenSet = function () { - this.final = false - this.edges = {} - this.id = lunr.TokenSet._nextId - lunr.TokenSet._nextId += 1 -} - -/** - * Keeps track of the next, auto increment, identifier to assign - * to a new tokenSet. - * - * TokenSets require a unique identifier to be correctly minimised. - * - * @private - */ -lunr.TokenSet._nextId = 1 - -/** - * Creates a TokenSet instance from the given sorted array of words. - * - * @param {String[]} arr - A sorted array of strings to create the set from. - * @returns {lunr.TokenSet} - * @throws Will throw an error if the input array is not sorted. - */ -lunr.TokenSet.fromArray = function (arr) { - var builder = new lunr.TokenSet.Builder - - for (var i = 0, len = arr.length; i < len; i++) { - builder.insert(arr[i]) - } - - builder.finish() - return builder.root -} - -/** - * Creates a token set from a query clause. - * - * @private - * @param {Object} clause - A single clause from lunr.Query. - * @param {string} clause.term - The query clause term. - * @param {number} [clause.editDistance] - The optional edit distance for the term. - * @returns {lunr.TokenSet} - */ -lunr.TokenSet.fromClause = function (clause) { - if ('editDistance' in clause) { - return lunr.TokenSet.fromFuzzyString(clause.term, clause.editDistance) - } else { - return lunr.TokenSet.fromString(clause.term) - } -} - -/** - * Creates a token set representing a single string with a specified - * edit distance. - * - * Insertions, deletions, substitutions and transpositions are each - * treated as an edit distance of 1. - * - * Increasing the allowed edit distance will have a dramatic impact - * on the performance of both creating and intersecting these TokenSets. - * It is advised to keep the edit distance less than 3. - * - * @param {string} str - The string to create the token set from. - * @param {number} editDistance - The allowed edit distance to match. - * @returns {lunr.Vector} - */ -lunr.TokenSet.fromFuzzyString = function (str, editDistance) { - var root = new lunr.TokenSet - - var stack = [{ - node: root, - editsRemaining: editDistance, - str: str - }] - - while (stack.length) { - var frame = stack.pop() - - // no edit - if (frame.str.length > 0) { - var char = frame.str.charAt(0), - noEditNode - - if (char in frame.node.edges) { - noEditNode = frame.node.edges[char] - } else { - noEditNode = new lunr.TokenSet - frame.node.edges[char] = noEditNode - } - - if (frame.str.length == 1) { - noEditNode.final = true - } - - stack.push({ - node: noEditNode, - editsRemaining: frame.editsRemaining, - str: frame.str.slice(1) - }) - } - - if (frame.editsRemaining == 0) { - continue - } - - // insertion - if ("*" in frame.node.edges) { - var insertionNode = frame.node.edges["*"] - } else { - var insertionNode = new lunr.TokenSet - frame.node.edges["*"] = insertionNode - } - - if (frame.str.length == 0) { - insertionNode.final = true - } - - stack.push({ - node: insertionNode, - editsRemaining: frame.editsRemaining - 1, - str: frame.str - }) - - // deletion - // can only do a deletion if we have enough edits remaining - // and if there are characters left to delete in the string - if (frame.str.length > 1) { - stack.push({ - node: frame.node, - editsRemaining: frame.editsRemaining - 1, - str: frame.str.slice(1) - }) - } - - // deletion - // just removing the last character from the str - if (frame.str.length == 1) { - frame.node.final = true - } - - // substitution - // can only do a substitution if we have enough edits remaining - // and if there are characters left to substitute - if (frame.str.length >= 1) { - if ("*" in frame.node.edges) { - var substitutionNode = frame.node.edges["*"] - } else { - var substitutionNode = new lunr.TokenSet - frame.node.edges["*"] = substitutionNode - } - - if (frame.str.length == 1) { - substitutionNode.final = true - } - - stack.push({ - node: substitutionNode, - editsRemaining: frame.editsRemaining - 1, - str: frame.str.slice(1) - }) - } - - // transposition - // can only do a transposition if there are edits remaining - // and there are enough characters to transpose - if (frame.str.length > 1) { - var charA = frame.str.charAt(0), - charB = frame.str.charAt(1), - transposeNode - - if (charB in frame.node.edges) { - transposeNode = frame.node.edges[charB] - } else { - transposeNode = new lunr.TokenSet - frame.node.edges[charB] = transposeNode - } - - if (frame.str.length == 1) { - transposeNode.final = true - } - - stack.push({ - node: transposeNode, - editsRemaining: frame.editsRemaining - 1, - str: charA + frame.str.slice(2) - }) - } - } - - return root -} - -/** - * Creates a TokenSet from a string. - * - * The string may contain one or more wildcard characters (*) - * that will allow wildcard matching when intersecting with - * another TokenSet. - * - * @param {string} str - The string to create a TokenSet from. - * @returns {lunr.TokenSet} - */ -lunr.TokenSet.fromString = function (str) { - var node = new lunr.TokenSet, - root = node - - /* - * Iterates through all characters within the passed string - * appending a node for each character. - * - * When a wildcard character is found then a self - * referencing edge is introduced to continually match - * any number of any characters. - */ - for (var i = 0, len = str.length; i < len; i++) { - var char = str[i], - final = (i == len - 1) - - if (char == "*") { - node.edges[char] = node - node.final = final - - } else { - var next = new lunr.TokenSet - next.final = final - - node.edges[char] = next - node = next - } - } - - return root -} - -/** - * Converts this TokenSet into an array of strings - * contained within the TokenSet. - * - * This is not intended to be used on a TokenSet that - * contains wildcards, in these cases the results are - * undefined and are likely to cause an infinite loop. - * - * @returns {string[]} - */ -lunr.TokenSet.prototype.toArray = function () { - var words = [] - - var stack = [{ - prefix: "", - node: this - }] - - while (stack.length) { - var frame = stack.pop(), - edges = Object.keys(frame.node.edges), - len = edges.length - - if (frame.node.final) { - /* In Safari, at this point the prefix is sometimes corrupted, see: - * https://github.com/olivernn/lunr.js/issues/279 Calling any - * String.prototype method forces Safari to "cast" this string to what - * it's supposed to be, fixing the bug. */ - frame.prefix.charAt(0) - words.push(frame.prefix) - } - - for (var i = 0; i < len; i++) { - var edge = edges[i] - - stack.push({ - prefix: frame.prefix.concat(edge), - node: frame.node.edges[edge] - }) - } - } - - return words -} - -/** - * Generates a string representation of a TokenSet. - * - * This is intended to allow TokenSets to be used as keys - * in objects, largely to aid the construction and minimisation - * of a TokenSet. As such it is not designed to be a human - * friendly representation of the TokenSet. - * - * @returns {string} - */ -lunr.TokenSet.prototype.toString = function () { - // NOTE: Using Object.keys here as this.edges is very likely - // to enter 'hash-mode' with many keys being added - // - // avoiding a for-in loop here as it leads to the function - // being de-optimised (at least in V8). From some simple - // benchmarks the performance is comparable, but allowing - // V8 to optimize may mean easy performance wins in the future. - - if (this._str) { - return this._str - } - - var str = this.final ? '1' : '0', - labels = Object.keys(this.edges).sort(), - len = labels.length - - for (var i = 0; i < len; i++) { - var label = labels[i], - node = this.edges[label] - - str = str + label + node.id - } - - return str -} - -/** - * Returns a new TokenSet that is the intersection of - * this TokenSet and the passed TokenSet. - * - * This intersection will take into account any wildcards - * contained within the TokenSet. - * - * @param {lunr.TokenSet} b - An other TokenSet to intersect with. - * @returns {lunr.TokenSet} - */ -lunr.TokenSet.prototype.intersect = function (b) { - var output = new lunr.TokenSet, - frame = undefined - - var stack = [{ - qNode: b, - output: output, - node: this - }] - - while (stack.length) { - frame = stack.pop() - - // NOTE: As with the #toString method, we are using - // Object.keys and a for loop instead of a for-in loop - // as both of these objects enter 'hash' mode, causing - // the function to be de-optimised in V8 - var qEdges = Object.keys(frame.qNode.edges), - qLen = qEdges.length, - nEdges = Object.keys(frame.node.edges), - nLen = nEdges.length - - for (var q = 0; q < qLen; q++) { - var qEdge = qEdges[q] - - for (var n = 0; n < nLen; n++) { - var nEdge = nEdges[n] - - if (nEdge == qEdge || qEdge == '*') { - var node = frame.node.edges[nEdge], - qNode = frame.qNode.edges[qEdge], - final = node.final && qNode.final, - next = undefined - - if (nEdge in frame.output.edges) { - // an edge already exists for this character - // no need to create a new node, just set the finality - // bit unless this node is already final - next = frame.output.edges[nEdge] - next.final = next.final || final - - } else { - // no edge exists yet, must create one - // set the finality bit and insert it - // into the output - next = new lunr.TokenSet - next.final = final - frame.output.edges[nEdge] = next - } - - stack.push({ - qNode: qNode, - output: next, - node: node - }) - } - } - } - } - - return output -} -lunr.TokenSet.Builder = function () { - this.previousWord = "" - this.root = new lunr.TokenSet - this.uncheckedNodes = [] - this.minimizedNodes = {} -} - -lunr.TokenSet.Builder.prototype.insert = function (word) { - var node, - commonPrefix = 0 - - if (word < this.previousWord) { - throw new Error ("Out of order word insertion") - } - - for (var i = 0; i < word.length && i < this.previousWord.length; i++) { - if (word[i] != this.previousWord[i]) break - commonPrefix++ - } - - this.minimize(commonPrefix) - - if (this.uncheckedNodes.length == 0) { - node = this.root - } else { - node = this.uncheckedNodes[this.uncheckedNodes.length - 1].child - } - - for (var i = commonPrefix; i < word.length; i++) { - var nextNode = new lunr.TokenSet, - char = word[i] - - node.edges[char] = nextNode - - this.uncheckedNodes.push({ - parent: node, - char: char, - child: nextNode - }) - - node = nextNode - } - - node.final = true - this.previousWord = word -} - -lunr.TokenSet.Builder.prototype.finish = function () { - this.minimize(0) -} - -lunr.TokenSet.Builder.prototype.minimize = function (downTo) { - for (var i = this.uncheckedNodes.length - 1; i >= downTo; i--) { - var node = this.uncheckedNodes[i], - childKey = node.child.toString() - - if (childKey in this.minimizedNodes) { - node.parent.edges[node.char] = this.minimizedNodes[childKey] - } else { - // Cache the key for this node since - // we know it can't change anymore - node.child._str = childKey - - this.minimizedNodes[childKey] = node.child - } - - this.uncheckedNodes.pop() - } -} -/*! - * lunr.Index - * Copyright (C) 2020 Oliver Nightingale - */ - -/** - * An index contains the built index of all documents and provides a query interface - * to the index. - * - * Usually instances of lunr.Index will not be created using this constructor, instead - * lunr.Builder should be used to construct new indexes, or lunr.Index.load should be - * used to load previously built and serialized indexes. - * - * @constructor - * @param {Object} attrs - The attributes of the built search index. - * @param {Object} attrs.invertedIndex - An index of term/field to document reference. - * @param {Object} attrs.fieldVectors - Field vectors - * @param {lunr.TokenSet} attrs.tokenSet - An set of all corpus tokens. - * @param {string[]} attrs.fields - The names of indexed document fields. - * @param {lunr.Pipeline} attrs.pipeline - The pipeline to use for search terms. - */ -lunr.Index = function (attrs) { - this.invertedIndex = attrs.invertedIndex - this.fieldVectors = attrs.fieldVectors - this.tokenSet = attrs.tokenSet - this.fields = attrs.fields - this.pipeline = attrs.pipeline -} - -/** - * A result contains details of a document matching a search query. - * @typedef {Object} lunr.Index~Result - * @property {string} ref - The reference of the document this result represents. - * @property {number} score - A number between 0 and 1 representing how similar this document is to the query. - * @property {lunr.MatchData} matchData - Contains metadata about this match including which term(s) caused the match. - */ - -/** - * Although lunr provides the ability to create queries using lunr.Query, it also provides a simple - * query language which itself is parsed into an instance of lunr.Query. - * - * For programmatically building queries it is advised to directly use lunr.Query, the query language - * is best used for human entered text rather than program generated text. - * - * At its simplest queries can just be a single term, e.g. `hello`, multiple terms are also supported - * and will be combined with OR, e.g `hello world` will match documents that contain either 'hello' - * or 'world', though those that contain both will rank higher in the results. - * - * Wildcards can be included in terms to match one or more unspecified characters, these wildcards can - * be inserted anywhere within the term, and more than one wildcard can exist in a single term. Adding - * wildcards will increase the number of documents that will be found but can also have a negative - * impact on query performance, especially with wildcards at the beginning of a term. - * - * Terms can be restricted to specific fields, e.g. `title:hello`, only documents with the term - * hello in the title field will match this query. Using a field not present in the index will lead - * to an error being thrown. - * - * Modifiers can also be added to terms, lunr supports edit distance and boost modifiers on terms. A term - * boost will make documents matching that term score higher, e.g. `foo^5`. Edit distance is also supported - * to provide fuzzy matching, e.g. 'hello~2' will match documents with hello with an edit distance of 2. - * Avoid large values for edit distance to improve query performance. - * - * Each term also supports a presence modifier. By default a term's presence in document is optional, however - * this can be changed to either required or prohibited. For a term's presence to be required in a document the - * term should be prefixed with a '+', e.g. `+foo bar` is a search for documents that must contain 'foo' and - * optionally contain 'bar'. Conversely a leading '-' sets the terms presence to prohibited, i.e. it must not - * appear in a document, e.g. `-foo bar` is a search for documents that do not contain 'foo' but may contain 'bar'. - * - * To escape special characters the backslash character '\' can be used, this allows searches to include - * characters that would normally be considered modifiers, e.g. `foo\~2` will search for a term "foo~2" instead - * of attempting to apply a boost of 2 to the search term "foo". - * - * @typedef {string} lunr.Index~QueryString - * @example Simple single term query - * hello - * @example Multiple term query - * hello world - * @example term scoped to a field - * title:hello - * @example term with a boost of 10 - * hello^10 - * @example term with an edit distance of 2 - * hello~2 - * @example terms with presence modifiers - * -foo +bar baz - */ - -/** - * Performs a search against the index using lunr query syntax. - * - * Results will be returned sorted by their score, the most relevant results - * will be returned first. For details on how the score is calculated, please see - * the {@link https://lunrjs.com/guides/searching.html#scoring|guide}. - * - * For more programmatic querying use lunr.Index#query. - * - * @param {lunr.Index~QueryString} queryString - A string containing a lunr query. - * @throws {lunr.QueryParseError} If the passed query string cannot be parsed. - * @returns {lunr.Index~Result[]} - */ -lunr.Index.prototype.search = function (queryString) { - return this.query(function (query) { - var parser = new lunr.QueryParser(queryString, query) - parser.parse() - }) -} - -/** - * A query builder callback provides a query object to be used to express - * the query to perform on the index. - * - * @callback lunr.Index~queryBuilder - * @param {lunr.Query} query - The query object to build up. - * @this lunr.Query - */ - -/** - * Performs a query against the index using the yielded lunr.Query object. - * - * If performing programmatic queries against the index, this method is preferred - * over lunr.Index#search so as to avoid the additional query parsing overhead. - * - * A query object is yielded to the supplied function which should be used to - * express the query to be run against the index. - * - * Note that although this function takes a callback parameter it is _not_ an - * asynchronous operation, the callback is just yielded a query object to be - * customized. - * - * @param {lunr.Index~queryBuilder} fn - A function that is used to build the query. - * @returns {lunr.Index~Result[]} - */ -lunr.Index.prototype.query = function (fn) { - // for each query clause - // * process terms - // * expand terms from token set - // * find matching documents and metadata - // * get document vectors - // * score documents - - var query = new lunr.Query(this.fields), - matchingFields = Object.create(null), - queryVectors = Object.create(null), - termFieldCache = Object.create(null), - requiredMatches = Object.create(null), - prohibitedMatches = Object.create(null) - - /* - * To support field level boosts a query vector is created per - * field. An empty vector is eagerly created to support negated - * queries. - */ - for (var i = 0; i < this.fields.length; i++) { - queryVectors[this.fields[i]] = new lunr.Vector - } - - fn.call(query, query) - - for (var i = 0; i < query.clauses.length; i++) { - /* - * Unless the pipeline has been disabled for this term, which is - * the case for terms with wildcards, we need to pass the clause - * term through the search pipeline. A pipeline returns an array - * of processed terms. Pipeline functions may expand the passed - * term, which means we may end up performing multiple index lookups - * for a single query term. - */ - var clause = query.clauses[i], - terms = null, - clauseMatches = lunr.Set.empty - - if (clause.usePipeline) { - terms = this.pipeline.runString(clause.term, { - fields: clause.fields - }) - } else { - terms = [clause.term] - } - - for (var m = 0; m < terms.length; m++) { - var term = terms[m] - - /* - * Each term returned from the pipeline needs to use the same query - * clause object, e.g. the same boost and or edit distance. The - * simplest way to do this is to re-use the clause object but mutate - * its term property. - */ - clause.term = term - - /* - * From the term in the clause we create a token set which will then - * be used to intersect the indexes token set to get a list of terms - * to lookup in the inverted index - */ - var termTokenSet = lunr.TokenSet.fromClause(clause), - expandedTerms = this.tokenSet.intersect(termTokenSet).toArray() - - /* - * If a term marked as required does not exist in the tokenSet it is - * impossible for the search to return any matches. We set all the field - * scoped required matches set to empty and stop examining any further - * clauses. - */ - if (expandedTerms.length === 0 && clause.presence === lunr.Query.presence.REQUIRED) { - for (var k = 0; k < clause.fields.length; k++) { - var field = clause.fields[k] - requiredMatches[field] = lunr.Set.empty - } - - break - } - - for (var j = 0; j < expandedTerms.length; j++) { - /* - * For each term get the posting and termIndex, this is required for - * building the query vector. - */ - var expandedTerm = expandedTerms[j], - posting = this.invertedIndex[expandedTerm], - termIndex = posting._index - - for (var k = 0; k < clause.fields.length; k++) { - /* - * For each field that this query term is scoped by (by default - * all fields are in scope) we need to get all the document refs - * that have this term in that field. - * - * The posting is the entry in the invertedIndex for the matching - * term from above. - */ - var field = clause.fields[k], - fieldPosting = posting[field], - matchingDocumentRefs = Object.keys(fieldPosting), - termField = expandedTerm + "/" + field, - matchingDocumentsSet = new lunr.Set(matchingDocumentRefs) - - /* - * if the presence of this term is required ensure that the matching - * documents are added to the set of required matches for this clause. - * - */ - if (clause.presence == lunr.Query.presence.REQUIRED) { - clauseMatches = clauseMatches.union(matchingDocumentsSet) - - if (requiredMatches[field] === undefined) { - requiredMatches[field] = lunr.Set.complete - } - } - - /* - * if the presence of this term is prohibited ensure that the matching - * documents are added to the set of prohibited matches for this field, - * creating that set if it does not yet exist. - */ - if (clause.presence == lunr.Query.presence.PROHIBITED) { - if (prohibitedMatches[field] === undefined) { - prohibitedMatches[field] = lunr.Set.empty - } - - prohibitedMatches[field] = prohibitedMatches[field].union(matchingDocumentsSet) - - /* - * Prohibited matches should not be part of the query vector used for - * similarity scoring and no metadata should be extracted so we continue - * to the next field - */ - continue - } - - /* - * The query field vector is populated using the termIndex found for - * the term and a unit value with the appropriate boost applied. - * Using upsert because there could already be an entry in the vector - * for the term we are working with. In that case we just add the scores - * together. - */ - queryVectors[field].upsert(termIndex, clause.boost, function (a, b) { return a + b }) - - /** - * If we've already seen this term, field combo then we've already collected - * the matching documents and metadata, no need to go through all that again - */ - if (termFieldCache[termField]) { - continue - } - - for (var l = 0; l < matchingDocumentRefs.length; l++) { - /* - * All metadata for this term/field/document triple - * are then extracted and collected into an instance - * of lunr.MatchData ready to be returned in the query - * results - */ - var matchingDocumentRef = matchingDocumentRefs[l], - matchingFieldRef = new lunr.FieldRef (matchingDocumentRef, field), - metadata = fieldPosting[matchingDocumentRef], - fieldMatch - - if ((fieldMatch = matchingFields[matchingFieldRef]) === undefined) { - matchingFields[matchingFieldRef] = new lunr.MatchData (expandedTerm, field, metadata) - } else { - fieldMatch.add(expandedTerm, field, metadata) - } - - } - - termFieldCache[termField] = true - } - } - } - - /** - * If the presence was required we need to update the requiredMatches field sets. - * We do this after all fields for the term have collected their matches because - * the clause terms presence is required in _any_ of the fields not _all_ of the - * fields. - */ - if (clause.presence === lunr.Query.presence.REQUIRED) { - for (var k = 0; k < clause.fields.length; k++) { - var field = clause.fields[k] - requiredMatches[field] = requiredMatches[field].intersect(clauseMatches) - } - } - } - - /** - * Need to combine the field scoped required and prohibited - * matching documents into a global set of required and prohibited - * matches - */ - var allRequiredMatches = lunr.Set.complete, - allProhibitedMatches = lunr.Set.empty - - for (var i = 0; i < this.fields.length; i++) { - var field = this.fields[i] - - if (requiredMatches[field]) { - allRequiredMatches = allRequiredMatches.intersect(requiredMatches[field]) - } - - if (prohibitedMatches[field]) { - allProhibitedMatches = allProhibitedMatches.union(prohibitedMatches[field]) - } - } - - var matchingFieldRefs = Object.keys(matchingFields), - results = [], - matches = Object.create(null) - - /* - * If the query is negated (contains only prohibited terms) - * we need to get _all_ fieldRefs currently existing in the - * index. This is only done when we know that the query is - * entirely prohibited terms to avoid any cost of getting all - * fieldRefs unnecessarily. - * - * Additionally, blank MatchData must be created to correctly - * populate the results. - */ - if (query.isNegated()) { - matchingFieldRefs = Object.keys(this.fieldVectors) - - for (var i = 0; i < matchingFieldRefs.length; i++) { - var matchingFieldRef = matchingFieldRefs[i] - var fieldRef = lunr.FieldRef.fromString(matchingFieldRef) - matchingFields[matchingFieldRef] = new lunr.MatchData - } - } - - for (var i = 0; i < matchingFieldRefs.length; i++) { - /* - * Currently we have document fields that match the query, but we - * need to return documents. The matchData and scores are combined - * from multiple fields belonging to the same document. - * - * Scores are calculated by field, using the query vectors created - * above, and combined into a final document score using addition. - */ - var fieldRef = lunr.FieldRef.fromString(matchingFieldRefs[i]), - docRef = fieldRef.docRef - - if (!allRequiredMatches.contains(docRef)) { - continue - } - - if (allProhibitedMatches.contains(docRef)) { - continue - } - - var fieldVector = this.fieldVectors[fieldRef], - score = queryVectors[fieldRef.fieldName].similarity(fieldVector), - docMatch - - if ((docMatch = matches[docRef]) !== undefined) { - docMatch.score += score - docMatch.matchData.combine(matchingFields[fieldRef]) - } else { - var match = { - ref: docRef, - score: score, - matchData: matchingFields[fieldRef] - } - matches[docRef] = match - results.push(match) - } - } - - /* - * Sort the results objects by score, highest first. - */ - return results.sort(function (a, b) { - return b.score - a.score - }) -} - -/** - * Prepares the index for JSON serialization. - * - * The schema for this JSON blob will be described in a - * separate JSON schema file. - * - * @returns {Object} - */ -lunr.Index.prototype.toJSON = function () { - var invertedIndex = Object.keys(this.invertedIndex) - .sort() - .map(function (term) { - return [term, this.invertedIndex[term]] - }, this) - - var fieldVectors = Object.keys(this.fieldVectors) - .map(function (ref) { - return [ref, this.fieldVectors[ref].toJSON()] - }, this) - - return { - version: lunr.version, - fields: this.fields, - fieldVectors: fieldVectors, - invertedIndex: invertedIndex, - pipeline: this.pipeline.toJSON() - } -} - -/** - * Loads a previously serialized lunr.Index - * - * @param {Object} serializedIndex - A previously serialized lunr.Index - * @returns {lunr.Index} - */ -lunr.Index.load = function (serializedIndex) { - var attrs = {}, - fieldVectors = {}, - serializedVectors = serializedIndex.fieldVectors, - invertedIndex = Object.create(null), - serializedInvertedIndex = serializedIndex.invertedIndex, - tokenSetBuilder = new lunr.TokenSet.Builder, - pipeline = lunr.Pipeline.load(serializedIndex.pipeline) - - if (serializedIndex.version != lunr.version) { - lunr.utils.warn("Version mismatch when loading serialised index. Current version of lunr '" + lunr.version + "' does not match serialized index '" + serializedIndex.version + "'") - } - - for (var i = 0; i < serializedVectors.length; i++) { - var tuple = serializedVectors[i], - ref = tuple[0], - elements = tuple[1] - - fieldVectors[ref] = new lunr.Vector(elements) - } - - for (var i = 0; i < serializedInvertedIndex.length; i++) { - var tuple = serializedInvertedIndex[i], - term = tuple[0], - posting = tuple[1] - - tokenSetBuilder.insert(term) - invertedIndex[term] = posting - } - - tokenSetBuilder.finish() - - attrs.fields = serializedIndex.fields - - attrs.fieldVectors = fieldVectors - attrs.invertedIndex = invertedIndex - attrs.tokenSet = tokenSetBuilder.root - attrs.pipeline = pipeline - - return new lunr.Index(attrs) -} -/*! - * lunr.Builder - * Copyright (C) 2020 Oliver Nightingale - */ - -/** - * lunr.Builder performs indexing on a set of documents and - * returns instances of lunr.Index ready for querying. - * - * All configuration of the index is done via the builder, the - * fields to index, the document reference, the text processing - * pipeline and document scoring parameters are all set on the - * builder before indexing. - * - * @constructor - * @property {string} _ref - Internal reference to the document reference field. - * @property {string[]} _fields - Internal reference to the document fields to index. - * @property {object} invertedIndex - The inverted index maps terms to document fields. - * @property {object} documentTermFrequencies - Keeps track of document term frequencies. - * @property {object} documentLengths - Keeps track of the length of documents added to the index. - * @property {lunr.tokenizer} tokenizer - Function for splitting strings into tokens for indexing. - * @property {lunr.Pipeline} pipeline - The pipeline performs text processing on tokens before indexing. - * @property {lunr.Pipeline} searchPipeline - A pipeline for processing search terms before querying the index. - * @property {number} documentCount - Keeps track of the total number of documents indexed. - * @property {number} _b - A parameter to control field length normalization, setting this to 0 disabled normalization, 1 fully normalizes field lengths, the default value is 0.75. - * @property {number} _k1 - A parameter to control how quickly an increase in term frequency results in term frequency saturation, the default value is 1.2. - * @property {number} termIndex - A counter incremented for each unique term, used to identify a terms position in the vector space. - * @property {array} metadataWhitelist - A list of metadata keys that have been whitelisted for entry in the index. - */ -lunr.Builder = function () { - this._ref = "id" - this._fields = Object.create(null) - this._documents = Object.create(null) - this.invertedIndex = Object.create(null) - this.fieldTermFrequencies = {} - this.fieldLengths = {} - this.tokenizer = lunr.tokenizer - this.pipeline = new lunr.Pipeline - this.searchPipeline = new lunr.Pipeline - this.documentCount = 0 - this._b = 0.75 - this._k1 = 1.2 - this.termIndex = 0 - this.metadataWhitelist = [] -} - -/** - * Sets the document field used as the document reference. Every document must have this field. - * The type of this field in the document should be a string, if it is not a string it will be - * coerced into a string by calling toString. - * - * The default ref is 'id'. - * - * The ref should _not_ be changed during indexing, it should be set before any documents are - * added to the index. Changing it during indexing can lead to inconsistent results. - * - * @param {string} ref - The name of the reference field in the document. - */ -lunr.Builder.prototype.ref = function (ref) { - this._ref = ref -} - -/** - * A function that is used to extract a field from a document. - * - * Lunr expects a field to be at the top level of a document, if however the field - * is deeply nested within a document an extractor function can be used to extract - * the right field for indexing. - * - * @callback fieldExtractor - * @param {object} doc - The document being added to the index. - * @returns {?(string|object|object[])} obj - The object that will be indexed for this field. - * @example Extracting a nested field - * function (doc) { return doc.nested.field } - */ - -/** - * Adds a field to the list of document fields that will be indexed. Every document being - * indexed should have this field. Null values for this field in indexed documents will - * not cause errors but will limit the chance of that document being retrieved by searches. - * - * All fields should be added before adding documents to the index. Adding fields after - * a document has been indexed will have no effect on already indexed documents. - * - * Fields can be boosted at build time. This allows terms within that field to have more - * importance when ranking search results. Use a field boost to specify that matches within - * one field are more important than other fields. - * - * @param {string} fieldName - The name of a field to index in all documents. - * @param {object} attributes - Optional attributes associated with this field. - * @param {number} [attributes.boost=1] - Boost applied to all terms within this field. - * @param {fieldExtractor} [attributes.extractor] - Function to extract a field from a document. - * @throws {RangeError} fieldName cannot contain unsupported characters '/' - */ -lunr.Builder.prototype.field = function (fieldName, attributes) { - if (/\//.test(fieldName)) { - throw new RangeError ("Field '" + fieldName + "' contains illegal character '/'") - } - - this._fields[fieldName] = attributes || {} -} - -/** - * A parameter to tune the amount of field length normalisation that is applied when - * calculating relevance scores. A value of 0 will completely disable any normalisation - * and a value of 1 will fully normalise field lengths. The default is 0.75. Values of b - * will be clamped to the range 0 - 1. - * - * @param {number} number - The value to set for this tuning parameter. - */ -lunr.Builder.prototype.b = function (number) { - if (number < 0) { - this._b = 0 - } else if (number > 1) { - this._b = 1 - } else { - this._b = number - } -} - -/** - * A parameter that controls the speed at which a rise in term frequency results in term - * frequency saturation. The default value is 1.2. Setting this to a higher value will give - * slower saturation levels, a lower value will result in quicker saturation. - * - * @param {number} number - The value to set for this tuning parameter. - */ -lunr.Builder.prototype.k1 = function (number) { - this._k1 = number -} - -/** - * Adds a document to the index. - * - * Before adding fields to the index the index should have been fully setup, with the document - * ref and all fields to index already having been specified. - * - * The document must have a field name as specified by the ref (by default this is 'id') and - * it should have all fields defined for indexing, though null or undefined values will not - * cause errors. - * - * Entire documents can be boosted at build time. Applying a boost to a document indicates that - * this document should rank higher in search results than other documents. - * - * @param {object} doc - The document to add to the index. - * @param {object} attributes - Optional attributes associated with this document. - * @param {number} [attributes.boost=1] - Boost applied to all terms within this document. - */ -lunr.Builder.prototype.add = function (doc, attributes) { - var docRef = doc[this._ref], - fields = Object.keys(this._fields) - - this._documents[docRef] = attributes || {} - this.documentCount += 1 - - for (var i = 0; i < fields.length; i++) { - var fieldName = fields[i], - extractor = this._fields[fieldName].extractor, - field = extractor ? extractor(doc) : doc[fieldName], - tokens = this.tokenizer(field, { - fields: [fieldName] - }), - terms = this.pipeline.run(tokens), - fieldRef = new lunr.FieldRef (docRef, fieldName), - fieldTerms = Object.create(null) - - this.fieldTermFrequencies[fieldRef] = fieldTerms - this.fieldLengths[fieldRef] = 0 - - // store the length of this field for this document - this.fieldLengths[fieldRef] += terms.length - - // calculate term frequencies for this field - for (var j = 0; j < terms.length; j++) { - var term = terms[j] - - if (fieldTerms[term] == undefined) { - fieldTerms[term] = 0 - } - - fieldTerms[term] += 1 - - // add to inverted index - // create an initial posting if one doesn't exist - if (this.invertedIndex[term] == undefined) { - var posting = Object.create(null) - posting["_index"] = this.termIndex - this.termIndex += 1 - - for (var k = 0; k < fields.length; k++) { - posting[fields[k]] = Object.create(null) - } - - this.invertedIndex[term] = posting - } - - // add an entry for this term/fieldName/docRef to the invertedIndex - if (this.invertedIndex[term][fieldName][docRef] == undefined) { - this.invertedIndex[term][fieldName][docRef] = Object.create(null) - } - - // store all whitelisted metadata about this token in the - // inverted index - for (var l = 0; l < this.metadataWhitelist.length; l++) { - var metadataKey = this.metadataWhitelist[l], - metadata = term.metadata[metadataKey] - - if (this.invertedIndex[term][fieldName][docRef][metadataKey] == undefined) { - this.invertedIndex[term][fieldName][docRef][metadataKey] = [] - } - - this.invertedIndex[term][fieldName][docRef][metadataKey].push(metadata) - } - } - - } -} - -/** - * Calculates the average document length for this index - * - * @private - */ -lunr.Builder.prototype.calculateAverageFieldLengths = function () { - - var fieldRefs = Object.keys(this.fieldLengths), - numberOfFields = fieldRefs.length, - accumulator = {}, - documentsWithField = {} - - for (var i = 0; i < numberOfFields; i++) { - var fieldRef = lunr.FieldRef.fromString(fieldRefs[i]), - field = fieldRef.fieldName - - documentsWithField[field] || (documentsWithField[field] = 0) - documentsWithField[field] += 1 - - accumulator[field] || (accumulator[field] = 0) - accumulator[field] += this.fieldLengths[fieldRef] - } - - var fields = Object.keys(this._fields) - - for (var i = 0; i < fields.length; i++) { - var fieldName = fields[i] - accumulator[fieldName] = accumulator[fieldName] / documentsWithField[fieldName] - } - - this.averageFieldLength = accumulator -} - -/** - * Builds a vector space model of every document using lunr.Vector - * - * @private - */ -lunr.Builder.prototype.createFieldVectors = function () { - var fieldVectors = {}, - fieldRefs = Object.keys(this.fieldTermFrequencies), - fieldRefsLength = fieldRefs.length, - termIdfCache = Object.create(null) - - for (var i = 0; i < fieldRefsLength; i++) { - var fieldRef = lunr.FieldRef.fromString(fieldRefs[i]), - fieldName = fieldRef.fieldName, - fieldLength = this.fieldLengths[fieldRef], - fieldVector = new lunr.Vector, - termFrequencies = this.fieldTermFrequencies[fieldRef], - terms = Object.keys(termFrequencies), - termsLength = terms.length - - - var fieldBoost = this._fields[fieldName].boost || 1, - docBoost = this._documents[fieldRef.docRef].boost || 1 - - for (var j = 0; j < termsLength; j++) { - var term = terms[j], - tf = termFrequencies[term], - termIndex = this.invertedIndex[term]._index, - idf, score, scoreWithPrecision - - if (termIdfCache[term] === undefined) { - idf = lunr.idf(this.invertedIndex[term], this.documentCount) - termIdfCache[term] = idf - } else { - idf = termIdfCache[term] - } - - score = idf * ((this._k1 + 1) * tf) / (this._k1 * (1 - this._b + this._b * (fieldLength / this.averageFieldLength[fieldName])) + tf) - score *= fieldBoost - score *= docBoost - scoreWithPrecision = Math.round(score * 1000) / 1000 - // Converts 1.23456789 to 1.234. - // Reducing the precision so that the vectors take up less - // space when serialised. Doing it now so that they behave - // the same before and after serialisation. Also, this is - // the fastest approach to reducing a number's precision in - // JavaScript. - - fieldVector.insert(termIndex, scoreWithPrecision) - } - - fieldVectors[fieldRef] = fieldVector - } - - this.fieldVectors = fieldVectors -} - -/** - * Creates a token set of all tokens in the index using lunr.TokenSet - * - * @private - */ -lunr.Builder.prototype.createTokenSet = function () { - this.tokenSet = lunr.TokenSet.fromArray( - Object.keys(this.invertedIndex).sort() - ) -} - -/** - * Builds the index, creating an instance of lunr.Index. - * - * This completes the indexing process and should only be called - * once all documents have been added to the index. - * - * @returns {lunr.Index} - */ -lunr.Builder.prototype.build = function () { - this.calculateAverageFieldLengths() - this.createFieldVectors() - this.createTokenSet() - - return new lunr.Index({ - invertedIndex: this.invertedIndex, - fieldVectors: this.fieldVectors, - tokenSet: this.tokenSet, - fields: Object.keys(this._fields), - pipeline: this.searchPipeline - }) -} - -/** - * Applies a plugin to the index builder. - * - * A plugin is a function that is called with the index builder as its context. - * Plugins can be used to customise or extend the behaviour of the index - * in some way. A plugin is just a function, that encapsulated the custom - * behaviour that should be applied when building the index. - * - * The plugin function will be called with the index builder as its argument, additional - * arguments can also be passed when calling use. The function will be called - * with the index builder as its context. - * - * @param {Function} plugin The plugin to apply. - */ -lunr.Builder.prototype.use = function (fn) { - var args = Array.prototype.slice.call(arguments, 1) - args.unshift(this) - fn.apply(this, args) -} -/** - * Contains and collects metadata about a matching document. - * A single instance of lunr.MatchData is returned as part of every - * lunr.Index~Result. - * - * @constructor - * @param {string} term - The term this match data is associated with - * @param {string} field - The field in which the term was found - * @param {object} metadata - The metadata recorded about this term in this field - * @property {object} metadata - A cloned collection of metadata associated with this document. - * @see {@link lunr.Index~Result} - */ -lunr.MatchData = function (term, field, metadata) { - var clonedMetadata = Object.create(null), - metadataKeys = Object.keys(metadata || {}) - - // Cloning the metadata to prevent the original - // being mutated during match data combination. - // Metadata is kept in an array within the inverted - // index so cloning the data can be done with - // Array#slice - for (var i = 0; i < metadataKeys.length; i++) { - var key = metadataKeys[i] - clonedMetadata[key] = metadata[key].slice() - } - - this.metadata = Object.create(null) - - if (term !== undefined) { - this.metadata[term] = Object.create(null) - this.metadata[term][field] = clonedMetadata - } -} - -/** - * An instance of lunr.MatchData will be created for every term that matches a - * document. However only one instance is required in a lunr.Index~Result. This - * method combines metadata from another instance of lunr.MatchData with this - * objects metadata. - * - * @param {lunr.MatchData} otherMatchData - Another instance of match data to merge with this one. - * @see {@link lunr.Index~Result} - */ -lunr.MatchData.prototype.combine = function (otherMatchData) { - var terms = Object.keys(otherMatchData.metadata) - - for (var i = 0; i < terms.length; i++) { - var term = terms[i], - fields = Object.keys(otherMatchData.metadata[term]) - - if (this.metadata[term] == undefined) { - this.metadata[term] = Object.create(null) - } - - for (var j = 0; j < fields.length; j++) { - var field = fields[j], - keys = Object.keys(otherMatchData.metadata[term][field]) - - if (this.metadata[term][field] == undefined) { - this.metadata[term][field] = Object.create(null) - } - - for (var k = 0; k < keys.length; k++) { - var key = keys[k] - - if (this.metadata[term][field][key] == undefined) { - this.metadata[term][field][key] = otherMatchData.metadata[term][field][key] - } else { - this.metadata[term][field][key] = this.metadata[term][field][key].concat(otherMatchData.metadata[term][field][key]) - } - - } - } - } -} - -/** - * Add metadata for a term/field pair to this instance of match data. - * - * @param {string} term - The term this match data is associated with - * @param {string} field - The field in which the term was found - * @param {object} metadata - The metadata recorded about this term in this field - */ -lunr.MatchData.prototype.add = function (term, field, metadata) { - if (!(term in this.metadata)) { - this.metadata[term] = Object.create(null) - this.metadata[term][field] = metadata - return - } - - if (!(field in this.metadata[term])) { - this.metadata[term][field] = metadata - return - } - - var metadataKeys = Object.keys(metadata) - - for (var i = 0; i < metadataKeys.length; i++) { - var key = metadataKeys[i] - - if (key in this.metadata[term][field]) { - this.metadata[term][field][key] = this.metadata[term][field][key].concat(metadata[key]) - } else { - this.metadata[term][field][key] = metadata[key] - } - } -} -/** - * A lunr.Query provides a programmatic way of defining queries to be performed - * against a {@link lunr.Index}. - * - * Prefer constructing a lunr.Query using the {@link lunr.Index#query} method - * so the query object is pre-initialized with the right index fields. - * - * @constructor - * @property {lunr.Query~Clause[]} clauses - An array of query clauses. - * @property {string[]} allFields - An array of all available fields in a lunr.Index. - */ -lunr.Query = function (allFields) { - this.clauses = [] - this.allFields = allFields -} - -/** - * Constants for indicating what kind of automatic wildcard insertion will be used when constructing a query clause. - * - * This allows wildcards to be added to the beginning and end of a term without having to manually do any string - * concatenation. - * - * The wildcard constants can be bitwise combined to select both leading and trailing wildcards. - * - * @constant - * @default - * @property {number} wildcard.NONE - The term will have no wildcards inserted, this is the default behaviour - * @property {number} wildcard.LEADING - Prepend the term with a wildcard, unless a leading wildcard already exists - * @property {number} wildcard.TRAILING - Append a wildcard to the term, unless a trailing wildcard already exists - * @see lunr.Query~Clause - * @see lunr.Query#clause - * @see lunr.Query#term - * @example query term with trailing wildcard - * query.term('foo', { wildcard: lunr.Query.wildcard.TRAILING }) - * @example query term with leading and trailing wildcard - * query.term('foo', { - * wildcard: lunr.Query.wildcard.LEADING | lunr.Query.wildcard.TRAILING - * }) - */ - -lunr.Query.wildcard = new String ("*") -lunr.Query.wildcard.NONE = 0 -lunr.Query.wildcard.LEADING = 1 -lunr.Query.wildcard.TRAILING = 2 - -/** - * Constants for indicating what kind of presence a term must have in matching documents. - * - * @constant - * @enum {number} - * @see lunr.Query~Clause - * @see lunr.Query#clause - * @see lunr.Query#term - * @example query term with required presence - * query.term('foo', { presence: lunr.Query.presence.REQUIRED }) - */ -lunr.Query.presence = { - /** - * Term's presence in a document is optional, this is the default value. - */ - OPTIONAL: 1, - - /** - * Term's presence in a document is required, documents that do not contain - * this term will not be returned. - */ - REQUIRED: 2, - - /** - * Term's presence in a document is prohibited, documents that do contain - * this term will not be returned. - */ - PROHIBITED: 3 -} - -/** - * A single clause in a {@link lunr.Query} contains a term and details on how to - * match that term against a {@link lunr.Index}. - * - * @typedef {Object} lunr.Query~Clause - * @property {string[]} fields - The fields in an index this clause should be matched against. - * @property {number} [boost=1] - Any boost that should be applied when matching this clause. - * @property {number} [editDistance] - Whether the term should have fuzzy matching applied, and how fuzzy the match should be. - * @property {boolean} [usePipeline] - Whether the term should be passed through the search pipeline. - * @property {number} [wildcard=lunr.Query.wildcard.NONE] - Whether the term should have wildcards appended or prepended. - * @property {number} [presence=lunr.Query.presence.OPTIONAL] - The terms presence in any matching documents. - */ - -/** - * Adds a {@link lunr.Query~Clause} to this query. - * - * Unless the clause contains the fields to be matched all fields will be matched. In addition - * a default boost of 1 is applied to the clause. - * - * @param {lunr.Query~Clause} clause - The clause to add to this query. - * @see lunr.Query~Clause - * @returns {lunr.Query} - */ -lunr.Query.prototype.clause = function (clause) { - if (!('fields' in clause)) { - clause.fields = this.allFields - } - - if (!('boost' in clause)) { - clause.boost = 1 - } - - if (!('usePipeline' in clause)) { - clause.usePipeline = true - } - - if (!('wildcard' in clause)) { - clause.wildcard = lunr.Query.wildcard.NONE - } - - if ((clause.wildcard & lunr.Query.wildcard.LEADING) && (clause.term.charAt(0) != lunr.Query.wildcard)) { - clause.term = "*" + clause.term - } - - if ((clause.wildcard & lunr.Query.wildcard.TRAILING) && (clause.term.slice(-1) != lunr.Query.wildcard)) { - clause.term = "" + clause.term + "*" - } - - if (!('presence' in clause)) { - clause.presence = lunr.Query.presence.OPTIONAL - } - - this.clauses.push(clause) - - return this -} - -/** - * A negated query is one in which every clause has a presence of - * prohibited. These queries require some special processing to return - * the expected results. - * - * @returns boolean - */ -lunr.Query.prototype.isNegated = function () { - for (var i = 0; i < this.clauses.length; i++) { - if (this.clauses[i].presence != lunr.Query.presence.PROHIBITED) { - return false - } - } - - return true -} - -/** - * Adds a term to the current query, under the covers this will create a {@link lunr.Query~Clause} - * to the list of clauses that make up this query. - * - * The term is used as is, i.e. no tokenization will be performed by this method. Instead conversion - * to a token or token-like string should be done before calling this method. - * - * The term will be converted to a string by calling `toString`. Multiple terms can be passed as an - * array, each term in the array will share the same options. - * - * @param {object|object[]} term - The term(s) to add to the query. - * @param {object} [options] - Any additional properties to add to the query clause. - * @returns {lunr.Query} - * @see lunr.Query#clause - * @see lunr.Query~Clause - * @example adding a single term to a query - * query.term("foo") - * @example adding a single term to a query and specifying search fields, term boost and automatic trailing wildcard - * query.term("foo", { - * fields: ["title"], - * boost: 10, - * wildcard: lunr.Query.wildcard.TRAILING - * }) - * @example using lunr.tokenizer to convert a string to tokens before using them as terms - * query.term(lunr.tokenizer("foo bar")) - */ -lunr.Query.prototype.term = function (term, options) { - if (Array.isArray(term)) { - term.forEach(function (t) { this.term(t, lunr.utils.clone(options)) }, this) - return this - } - - var clause = options || {} - clause.term = term.toString() - - this.clause(clause) - - return this -} -lunr.QueryParseError = function (message, start, end) { - this.name = "QueryParseError" - this.message = message - this.start = start - this.end = end -} - -lunr.QueryParseError.prototype = new Error -lunr.QueryLexer = function (str) { - this.lexemes = [] - this.str = str - this.length = str.length - this.pos = 0 - this.start = 0 - this.escapeCharPositions = [] -} - -lunr.QueryLexer.prototype.run = function () { - var state = lunr.QueryLexer.lexText - - while (state) { - state = state(this) - } -} - -lunr.QueryLexer.prototype.sliceString = function () { - var subSlices = [], - sliceStart = this.start, - sliceEnd = this.pos - - for (var i = 0; i < this.escapeCharPositions.length; i++) { - sliceEnd = this.escapeCharPositions[i] - subSlices.push(this.str.slice(sliceStart, sliceEnd)) - sliceStart = sliceEnd + 1 - } - - subSlices.push(this.str.slice(sliceStart, this.pos)) - this.escapeCharPositions.length = 0 - - return subSlices.join('') -} - -lunr.QueryLexer.prototype.emit = function (type) { - this.lexemes.push({ - type: type, - str: this.sliceString(), - start: this.start, - end: this.pos - }) - - this.start = this.pos -} - -lunr.QueryLexer.prototype.escapeCharacter = function () { - this.escapeCharPositions.push(this.pos - 1) - this.pos += 1 -} - -lunr.QueryLexer.prototype.next = function () { - if (this.pos >= this.length) { - return lunr.QueryLexer.EOS - } - - var char = this.str.charAt(this.pos) - this.pos += 1 - return char -} - -lunr.QueryLexer.prototype.width = function () { - return this.pos - this.start -} - -lunr.QueryLexer.prototype.ignore = function () { - if (this.start == this.pos) { - this.pos += 1 - } - - this.start = this.pos -} - -lunr.QueryLexer.prototype.backup = function () { - this.pos -= 1 -} - -lunr.QueryLexer.prototype.acceptDigitRun = function () { - var char, charCode - - do { - char = this.next() - charCode = char.charCodeAt(0) - } while (charCode > 47 && charCode < 58) - - if (char != lunr.QueryLexer.EOS) { - this.backup() - } -} - -lunr.QueryLexer.prototype.more = function () { - return this.pos < this.length -} - -lunr.QueryLexer.EOS = 'EOS' -lunr.QueryLexer.FIELD = 'FIELD' -lunr.QueryLexer.TERM = 'TERM' -lunr.QueryLexer.EDIT_DISTANCE = 'EDIT_DISTANCE' -lunr.QueryLexer.BOOST = 'BOOST' -lunr.QueryLexer.PRESENCE = 'PRESENCE' - -lunr.QueryLexer.lexField = function (lexer) { - lexer.backup() - lexer.emit(lunr.QueryLexer.FIELD) - lexer.ignore() - return lunr.QueryLexer.lexText -} - -lunr.QueryLexer.lexTerm = function (lexer) { - if (lexer.width() > 1) { - lexer.backup() - lexer.emit(lunr.QueryLexer.TERM) - } - - lexer.ignore() - - if (lexer.more()) { - return lunr.QueryLexer.lexText - } -} - -lunr.QueryLexer.lexEditDistance = function (lexer) { - lexer.ignore() - lexer.acceptDigitRun() - lexer.emit(lunr.QueryLexer.EDIT_DISTANCE) - return lunr.QueryLexer.lexText -} - -lunr.QueryLexer.lexBoost = function (lexer) { - lexer.ignore() - lexer.acceptDigitRun() - lexer.emit(lunr.QueryLexer.BOOST) - return lunr.QueryLexer.lexText -} - -lunr.QueryLexer.lexEOS = function (lexer) { - if (lexer.width() > 0) { - lexer.emit(lunr.QueryLexer.TERM) - } -} - -// This matches the separator used when tokenising fields -// within a document. These should match otherwise it is -// not possible to search for some tokens within a document. -// -// It is possible for the user to change the separator on the -// tokenizer so it _might_ clash with any other of the special -// characters already used within the search string, e.g. :. -// -// This means that it is possible to change the separator in -// such a way that makes some words unsearchable using a search -// string. -lunr.QueryLexer.termSeparator = lunr.tokenizer.separator - -lunr.QueryLexer.lexText = function (lexer) { - while (true) { - var char = lexer.next() - - if (char == lunr.QueryLexer.EOS) { - return lunr.QueryLexer.lexEOS - } - - // Escape character is '\' - if (char.charCodeAt(0) == 92) { - lexer.escapeCharacter() - continue - } - - if (char == ":") { - return lunr.QueryLexer.lexField - } - - if (char == "~") { - lexer.backup() - if (lexer.width() > 0) { - lexer.emit(lunr.QueryLexer.TERM) - } - return lunr.QueryLexer.lexEditDistance - } - - if (char == "^") { - lexer.backup() - if (lexer.width() > 0) { - lexer.emit(lunr.QueryLexer.TERM) - } - return lunr.QueryLexer.lexBoost - } - - // "+" indicates term presence is required - // checking for length to ensure that only - // leading "+" are considered - if (char == "+" && lexer.width() === 1) { - lexer.emit(lunr.QueryLexer.PRESENCE) - return lunr.QueryLexer.lexText - } - - // "-" indicates term presence is prohibited - // checking for length to ensure that only - // leading "-" are considered - if (char == "-" && lexer.width() === 1) { - lexer.emit(lunr.QueryLexer.PRESENCE) - return lunr.QueryLexer.lexText - } - - if (char.match(lunr.QueryLexer.termSeparator)) { - return lunr.QueryLexer.lexTerm - } - } -} - -lunr.QueryParser = function (str, query) { - this.lexer = new lunr.QueryLexer (str) - this.query = query - this.currentClause = {} - this.lexemeIdx = 0 -} - -lunr.QueryParser.prototype.parse = function () { - this.lexer.run() - this.lexemes = this.lexer.lexemes - - var state = lunr.QueryParser.parseClause - - while (state) { - state = state(this) - } - - return this.query -} - -lunr.QueryParser.prototype.peekLexeme = function () { - return this.lexemes[this.lexemeIdx] -} - -lunr.QueryParser.prototype.consumeLexeme = function () { - var lexeme = this.peekLexeme() - this.lexemeIdx += 1 - return lexeme -} - -lunr.QueryParser.prototype.nextClause = function () { - var completedClause = this.currentClause - this.query.clause(completedClause) - this.currentClause = {} -} - -lunr.QueryParser.parseClause = function (parser) { - var lexeme = parser.peekLexeme() - - if (lexeme == undefined) { - return - } - - switch (lexeme.type) { - case lunr.QueryLexer.PRESENCE: - return lunr.QueryParser.parsePresence - case lunr.QueryLexer.FIELD: - return lunr.QueryParser.parseField - case lunr.QueryLexer.TERM: - return lunr.QueryParser.parseTerm - default: - var errorMessage = "expected either a field or a term, found " + lexeme.type - - if (lexeme.str.length >= 1) { - errorMessage += " with value '" + lexeme.str + "'" - } - - throw new lunr.QueryParseError (errorMessage, lexeme.start, lexeme.end) - } -} - -lunr.QueryParser.parsePresence = function (parser) { - var lexeme = parser.consumeLexeme() - - if (lexeme == undefined) { - return - } - - switch (lexeme.str) { - case "-": - parser.currentClause.presence = lunr.Query.presence.PROHIBITED - break - case "+": - parser.currentClause.presence = lunr.Query.presence.REQUIRED - break - default: - var errorMessage = "unrecognised presence operator'" + lexeme.str + "'" - throw new lunr.QueryParseError (errorMessage, lexeme.start, lexeme.end) - } - - var nextLexeme = parser.peekLexeme() - - if (nextLexeme == undefined) { - var errorMessage = "expecting term or field, found nothing" - throw new lunr.QueryParseError (errorMessage, lexeme.start, lexeme.end) - } - - switch (nextLexeme.type) { - case lunr.QueryLexer.FIELD: - return lunr.QueryParser.parseField - case lunr.QueryLexer.TERM: - return lunr.QueryParser.parseTerm - default: - var errorMessage = "expecting term or field, found '" + nextLexeme.type + "'" - throw new lunr.QueryParseError (errorMessage, nextLexeme.start, nextLexeme.end) - } -} - -lunr.QueryParser.parseField = function (parser) { - var lexeme = parser.consumeLexeme() - - if (lexeme == undefined) { - return - } - - if (parser.query.allFields.indexOf(lexeme.str) == -1) { - var possibleFields = parser.query.allFields.map(function (f) { return "'" + f + "'" }).join(', '), - errorMessage = "unrecognised field '" + lexeme.str + "', possible fields: " + possibleFields - - throw new lunr.QueryParseError (errorMessage, lexeme.start, lexeme.end) - } - - parser.currentClause.fields = [lexeme.str] - - var nextLexeme = parser.peekLexeme() - - if (nextLexeme == undefined) { - var errorMessage = "expecting term, found nothing" - throw new lunr.QueryParseError (errorMessage, lexeme.start, lexeme.end) - } - - switch (nextLexeme.type) { - case lunr.QueryLexer.TERM: - return lunr.QueryParser.parseTerm - default: - var errorMessage = "expecting term, found '" + nextLexeme.type + "'" - throw new lunr.QueryParseError (errorMessage, nextLexeme.start, nextLexeme.end) - } -} - -lunr.QueryParser.parseTerm = function (parser) { - var lexeme = parser.consumeLexeme() - - if (lexeme == undefined) { - return - } - - parser.currentClause.term = lexeme.str.toLowerCase() - - if (lexeme.str.indexOf("*") != -1) { - parser.currentClause.usePipeline = false - } - - var nextLexeme = parser.peekLexeme() - - if (nextLexeme == undefined) { - parser.nextClause() - return - } - - switch (nextLexeme.type) { - case lunr.QueryLexer.TERM: - parser.nextClause() - return lunr.QueryParser.parseTerm - case lunr.QueryLexer.FIELD: - parser.nextClause() - return lunr.QueryParser.parseField - case lunr.QueryLexer.EDIT_DISTANCE: - return lunr.QueryParser.parseEditDistance - case lunr.QueryLexer.BOOST: - return lunr.QueryParser.parseBoost - case lunr.QueryLexer.PRESENCE: - parser.nextClause() - return lunr.QueryParser.parsePresence - default: - var errorMessage = "Unexpected lexeme type '" + nextLexeme.type + "'" - throw new lunr.QueryParseError (errorMessage, nextLexeme.start, nextLexeme.end) - } -} - -lunr.QueryParser.parseEditDistance = function (parser) { - var lexeme = parser.consumeLexeme() - - if (lexeme == undefined) { - return - } - - var editDistance = parseInt(lexeme.str, 10) - - if (isNaN(editDistance)) { - var errorMessage = "edit distance must be numeric" - throw new lunr.QueryParseError (errorMessage, lexeme.start, lexeme.end) - } - - parser.currentClause.editDistance = editDistance - - var nextLexeme = parser.peekLexeme() - - if (nextLexeme == undefined) { - parser.nextClause() - return - } - - switch (nextLexeme.type) { - case lunr.QueryLexer.TERM: - parser.nextClause() - return lunr.QueryParser.parseTerm - case lunr.QueryLexer.FIELD: - parser.nextClause() - return lunr.QueryParser.parseField - case lunr.QueryLexer.EDIT_DISTANCE: - return lunr.QueryParser.parseEditDistance - case lunr.QueryLexer.BOOST: - return lunr.QueryParser.parseBoost - case lunr.QueryLexer.PRESENCE: - parser.nextClause() - return lunr.QueryParser.parsePresence - default: - var errorMessage = "Unexpected lexeme type '" + nextLexeme.type + "'" - throw new lunr.QueryParseError (errorMessage, nextLexeme.start, nextLexeme.end) - } -} - -lunr.QueryParser.parseBoost = function (parser) { - var lexeme = parser.consumeLexeme() - - if (lexeme == undefined) { - return - } - - var boost = parseInt(lexeme.str, 10) - - if (isNaN(boost)) { - var errorMessage = "boost must be numeric" - throw new lunr.QueryParseError (errorMessage, lexeme.start, lexeme.end) - } - - parser.currentClause.boost = boost - - var nextLexeme = parser.peekLexeme() - - if (nextLexeme == undefined) { - parser.nextClause() - return - } - - switch (nextLexeme.type) { - case lunr.QueryLexer.TERM: - parser.nextClause() - return lunr.QueryParser.parseTerm - case lunr.QueryLexer.FIELD: - parser.nextClause() - return lunr.QueryParser.parseField - case lunr.QueryLexer.EDIT_DISTANCE: - return lunr.QueryParser.parseEditDistance - case lunr.QueryLexer.BOOST: - return lunr.QueryParser.parseBoost - case lunr.QueryLexer.PRESENCE: - parser.nextClause() - return lunr.QueryParser.parsePresence - default: - var errorMessage = "Unexpected lexeme type '" + nextLexeme.type + "'" - throw new lunr.QueryParseError (errorMessage, nextLexeme.start, nextLexeme.end) - } -} - - /** - * export the module via AMD, CommonJS or as a browser global - * Export code from https://github.com/umdjs/umd/blob/master/returnExports.js - */ - ;(function (root, factory) { - if (typeof define === 'function' && define.amd) { - // AMD. Register as an anonymous module. - define(factory) - } else if (typeof exports === 'object') { - /** - * Node. Does not work with strict CommonJS, but - * only CommonJS-like enviroments that support module.exports, - * like Node. - */ - module.exports = factory() - } else { - // Browser globals (root is window) - root.lunr = factory() - } - }(this, function () { - /** - * Just return a value to define the module export. - * This example returns an object, but the module - * can return a function as the exported value. - */ - return lunr - })) -})(); diff --git a/docs/assets/js/lunr/lunr.min.js b/docs/assets/js/lunr/lunr.min.js deleted file mode 100644 index cdc94cd390..0000000000 --- a/docs/assets/js/lunr/lunr.min.js +++ /dev/null @@ -1,6 +0,0 @@ -/** - * lunr - http://lunrjs.com - A bit like Solr, but much smaller and not as bright - 2.3.9 - * Copyright (C) 2020 Oliver Nightingale - * @license MIT - */ -!function(){var e=function(t){var r=new e.Builder;return r.pipeline.add(e.trimmer,e.stopWordFilter,e.stemmer),r.searchPipeline.add(e.stemmer),t.call(r,r),r.build()};e.version="2.3.9",e.utils={},e.utils.warn=function(e){return function(t){e.console&&console.warn&&console.warn(t)}}(this),e.utils.asString=function(e){return void 0===e||null===e?"":e.toString()},e.utils.clone=function(e){if(null===e||void 0===e)return e;for(var t=Object.create(null),r=Object.keys(e),i=0;i0){var c=e.utils.clone(r)||{};c.position=[a,l],c.index=s.length,s.push(new e.Token(i.slice(a,o),c))}a=o+1}}return s},e.tokenizer.separator=/[\s\-]+/,e.Pipeline=function(){this._stack=[]},e.Pipeline.registeredFunctions=Object.create(null),e.Pipeline.registerFunction=function(t,r){r in this.registeredFunctions&&e.utils.warn("Overwriting existing registered function: "+r),t.label=r,e.Pipeline.registeredFunctions[t.label]=t},e.Pipeline.warnIfFunctionNotRegistered=function(t){var r=t.label&&t.label in this.registeredFunctions;r||e.utils.warn("Function is not registered with pipeline. This may cause problems when serialising the index.\n",t)},e.Pipeline.load=function(t){var r=new e.Pipeline;return t.forEach(function(t){var i=e.Pipeline.registeredFunctions[t];if(!i)throw new Error("Cannot load unregistered function: "+t);r.add(i)}),r},e.Pipeline.prototype.add=function(){var t=Array.prototype.slice.call(arguments);t.forEach(function(t){e.Pipeline.warnIfFunctionNotRegistered(t),this._stack.push(t)},this)},e.Pipeline.prototype.after=function(t,r){e.Pipeline.warnIfFunctionNotRegistered(r);var i=this._stack.indexOf(t);if(i==-1)throw new Error("Cannot find existingFn");i+=1,this._stack.splice(i,0,r)},e.Pipeline.prototype.before=function(t,r){e.Pipeline.warnIfFunctionNotRegistered(r);var i=this._stack.indexOf(t);if(i==-1)throw new Error("Cannot find existingFn");this._stack.splice(i,0,r)},e.Pipeline.prototype.remove=function(e){var t=this._stack.indexOf(e);t!=-1&&this._stack.splice(t,1)},e.Pipeline.prototype.run=function(e){for(var t=this._stack.length,r=0;r1&&(se&&(r=n),s!=e);)i=r-t,n=t+Math.floor(i/2),s=this.elements[2*n];return s==e?2*n:s>e?2*n:sa?l+=2:o==a&&(t+=r[u+1]*i[l+1],u+=2,l+=2);return t},e.Vector.prototype.similarity=function(e){return this.dot(e)/this.magnitude()||0},e.Vector.prototype.toArray=function(){for(var e=new Array(this.elements.length/2),t=1,r=0;t0){var o,a=s.str.charAt(0);a in s.node.edges?o=s.node.edges[a]:(o=new e.TokenSet,s.node.edges[a]=o),1==s.str.length&&(o["final"]=!0),n.push({node:o,editsRemaining:s.editsRemaining,str:s.str.slice(1)})}if(0!=s.editsRemaining){if("*"in s.node.edges)var u=s.node.edges["*"];else{var u=new e.TokenSet;s.node.edges["*"]=u}if(0==s.str.length&&(u["final"]=!0),n.push({node:u,editsRemaining:s.editsRemaining-1,str:s.str}),s.str.length>1&&n.push({node:s.node,editsRemaining:s.editsRemaining-1,str:s.str.slice(1)}),1==s.str.length&&(s.node["final"]=!0),s.str.length>=1){if("*"in s.node.edges)var l=s.node.edges["*"];else{var l=new e.TokenSet;s.node.edges["*"]=l}1==s.str.length&&(l["final"]=!0),n.push({node:l,editsRemaining:s.editsRemaining-1,str:s.str.slice(1)})}if(s.str.length>1){var c,h=s.str.charAt(0),d=s.str.charAt(1);d in s.node.edges?c=s.node.edges[d]:(c=new e.TokenSet,s.node.edges[d]=c),1==s.str.length&&(c["final"]=!0),n.push({node:c,editsRemaining:s.editsRemaining-1,str:h+s.str.slice(2)})}}}return i},e.TokenSet.fromString=function(t){for(var r=new e.TokenSet,i=r,n=0,s=t.length;n=e;t--){var r=this.uncheckedNodes[t],i=r.child.toString();i in this.minimizedNodes?r.parent.edges[r["char"]]=this.minimizedNodes[i]:(r.child._str=i,this.minimizedNodes[i]=r.child),this.uncheckedNodes.pop()}},e.Index=function(e){this.invertedIndex=e.invertedIndex,this.fieldVectors=e.fieldVectors,this.tokenSet=e.tokenSet,this.fields=e.fields,this.pipeline=e.pipeline},e.Index.prototype.search=function(t){return this.query(function(r){var i=new e.QueryParser(t,r);i.parse()})},e.Index.prototype.query=function(t){for(var r=new e.Query(this.fields),i=Object.create(null),n=Object.create(null),s=Object.create(null),o=Object.create(null),a=Object.create(null),u=0;u1?this._b=1:this._b=e},e.Builder.prototype.k1=function(e){this._k1=e},e.Builder.prototype.add=function(t,r){var i=t[this._ref],n=Object.keys(this._fields);this._documents[i]=r||{},this.documentCount+=1;for(var s=0;s=this.length)return e.QueryLexer.EOS;var t=this.str.charAt(this.pos);return this.pos+=1,t},e.QueryLexer.prototype.width=function(){return this.pos-this.start},e.QueryLexer.prototype.ignore=function(){this.start==this.pos&&(this.pos+=1),this.start=this.pos},e.QueryLexer.prototype.backup=function(){this.pos-=1},e.QueryLexer.prototype.acceptDigitRun=function(){var t,r;do t=this.next(),r=t.charCodeAt(0);while(r>47&&r<58);t!=e.QueryLexer.EOS&&this.backup()},e.QueryLexer.prototype.more=function(){return this.pos1&&(t.backup(),t.emit(e.QueryLexer.TERM)),t.ignore(),t.more())return e.QueryLexer.lexText},e.QueryLexer.lexEditDistance=function(t){return t.ignore(),t.acceptDigitRun(),t.emit(e.QueryLexer.EDIT_DISTANCE),e.QueryLexer.lexText},e.QueryLexer.lexBoost=function(t){return t.ignore(),t.acceptDigitRun(),t.emit(e.QueryLexer.BOOST),e.QueryLexer.lexText},e.QueryLexer.lexEOS=function(t){t.width()>0&&t.emit(e.QueryLexer.TERM)},e.QueryLexer.termSeparator=e.tokenizer.separator,e.QueryLexer.lexText=function(t){for(;;){var r=t.next();if(r==e.QueryLexer.EOS)return e.QueryLexer.lexEOS;if(92!=r.charCodeAt(0)){if(":"==r)return e.QueryLexer.lexField;if("~"==r)return t.backup(),t.width()>0&&t.emit(e.QueryLexer.TERM),e.QueryLexer.lexEditDistance;if("^"==r)return t.backup(),t.width()>0&&t.emit(e.QueryLexer.TERM),e.QueryLexer.lexBoost;if("+"==r&&1===t.width())return t.emit(e.QueryLexer.PRESENCE),e.QueryLexer.lexText;if("-"==r&&1===t.width())return t.emit(e.QueryLexer.PRESENCE),e.QueryLexer.lexText;if(r.match(e.QueryLexer.termSeparator))return e.QueryLexer.lexTerm}else t.escapeCharacter()}},e.QueryParser=function(t,r){this.lexer=new e.QueryLexer(t),this.query=r,this.currentClause={},this.lexemeIdx=0},e.QueryParser.prototype.parse=function(){this.lexer.run(),this.lexemes=this.lexer.lexemes;for(var t=e.QueryParser.parseClause;t;)t=t(this);return this.query},e.QueryParser.prototype.peekLexeme=function(){return this.lexemes[this.lexemeIdx]},e.QueryParser.prototype.consumeLexeme=function(){var e=this.peekLexeme();return this.lexemeIdx+=1,e},e.QueryParser.prototype.nextClause=function(){var e=this.currentClause;this.query.clause(e),this.currentClause={}},e.QueryParser.parseClause=function(t){var r=t.peekLexeme();if(void 0!=r)switch(r.type){case e.QueryLexer.PRESENCE:return e.QueryParser.parsePresence;case e.QueryLexer.FIELD:return e.QueryParser.parseField;case e.QueryLexer.TERM:return e.QueryParser.parseTerm;default:var i="expected either a field or a term, found "+r.type;throw r.str.length>=1&&(i+=" with value '"+r.str+"'"),new e.QueryParseError(i,r.start,r.end)}},e.QueryParser.parsePresence=function(t){var r=t.consumeLexeme();if(void 0!=r){switch(r.str){case"-":t.currentClause.presence=e.Query.presence.PROHIBITED;break;case"+":t.currentClause.presence=e.Query.presence.REQUIRED;break;default:var i="unrecognised presence operator'"+r.str+"'";throw new e.QueryParseError(i,r.start,r.end)}var n=t.peekLexeme();if(void 0==n){var i="expecting term or field, found nothing";throw new e.QueryParseError(i,r.start,r.end)}switch(n.type){case e.QueryLexer.FIELD:return e.QueryParser.parseField;case e.QueryLexer.TERM:return e.QueryParser.parseTerm;default:var i="expecting term or field, found '"+n.type+"'";throw new e.QueryParseError(i,n.start,n.end)}}},e.QueryParser.parseField=function(t){var r=t.consumeLexeme();if(void 0!=r){if(t.query.allFields.indexOf(r.str)==-1){var i=t.query.allFields.map(function(e){return"'"+e+"'"}).join(", "),n="unrecognised field '"+r.str+"', possible fields: "+i;throw new e.QueryParseError(n,r.start,r.end)}t.currentClause.fields=[r.str];var s=t.peekLexeme();if(void 0==s){var n="expecting term, found nothing";throw new e.QueryParseError(n,r.start,r.end)}switch(s.type){case e.QueryLexer.TERM:return e.QueryParser.parseTerm;default:var n="expecting term, found '"+s.type+"'";throw new e.QueryParseError(n,s.start,s.end)}}},e.QueryParser.parseTerm=function(t){var r=t.consumeLexeme();if(void 0!=r){t.currentClause.term=r.str.toLowerCase(),r.str.indexOf("*")!=-1&&(t.currentClause.usePipeline=!1);var i=t.peekLexeme();if(void 0==i)return void t.nextClause();switch(i.type){case e.QueryLexer.TERM:return t.nextClause(),e.QueryParser.parseTerm;case e.QueryLexer.FIELD:return t.nextClause(),e.QueryParser.parseField;case e.QueryLexer.EDIT_DISTANCE:return e.QueryParser.parseEditDistance;case e.QueryLexer.BOOST:return e.QueryParser.parseBoost;case e.QueryLexer.PRESENCE:return t.nextClause(),e.QueryParser.parsePresence;default:var n="Unexpected lexeme type '"+i.type+"'";throw new e.QueryParseError(n,i.start,i.end)}}},e.QueryParser.parseEditDistance=function(t){var r=t.consumeLexeme();if(void 0!=r){var i=parseInt(r.str,10);if(isNaN(i)){var n="edit distance must be numeric";throw new e.QueryParseError(n,r.start,r.end)}t.currentClause.editDistance=i;var s=t.peekLexeme();if(void 0==s)return void t.nextClause();switch(s.type){case e.QueryLexer.TERM:return t.nextClause(),e.QueryParser.parseTerm;case e.QueryLexer.FIELD:return t.nextClause(),e.QueryParser.parseField;case e.QueryLexer.EDIT_DISTANCE:return e.QueryParser.parseEditDistance;case e.QueryLexer.BOOST:return e.QueryParser.parseBoost;case e.QueryLexer.PRESENCE:return t.nextClause(),e.QueryParser.parsePresence;default:var n="Unexpected lexeme type '"+s.type+"'";throw new e.QueryParseError(n,s.start,s.end)}}},e.QueryParser.parseBoost=function(t){var r=t.consumeLexeme();if(void 0!=r){var i=parseInt(r.str,10);if(isNaN(i)){var n="boost must be numeric";throw new e.QueryParseError(n,r.start,r.end)}t.currentClause.boost=i;var s=t.peekLexeme();if(void 0==s)return void t.nextClause();switch(s.type){case e.QueryLexer.TERM:return t.nextClause(),e.QueryParser.parseTerm;case e.QueryLexer.FIELD:return t.nextClause(),e.QueryParser.parseField;case e.QueryLexer.EDIT_DISTANCE:return e.QueryParser.parseEditDistance;case e.QueryLexer.BOOST:return e.QueryParser.parseBoost;case e.QueryLexer.PRESENCE:return t.nextClause(),e.QueryParser.parsePresence;default:var n="Unexpected lexeme type '"+s.type+"'";throw new e.QueryParseError(n,s.start,s.end)}}},function(e,t){"function"==typeof define&&define.amd?define(t):"object"==typeof exports?module.exports=t():e.lunr=t()}(this,function(){return e})}(); diff --git a/docs/assets/js/main.min.js b/docs/assets/js/main.min.js deleted file mode 100644 index 0ea1b6922a..0000000000 --- a/docs/assets/js/main.min.js +++ /dev/null @@ -1,6 +0,0 @@ -/*! - * Minimal Mistakes Jekyll Theme 4.24.0 by Michael Rose - * Copyright 2013-2021 Michael Rose - mademistakes.com | @mmistakes - * Licensed under MIT - */ -!function(e,t){"use strict";"object"==typeof module&&"object"==typeof module.exports?module.exports=e.document?t(e,!0):function(e){if(!e.document)throw new Error("jQuery requires a window with a document");return t(e)}:t(e)}("undefined"!=typeof window?window:this,function(C,e){"use strict";function m(e){return null!=e&&e===e.window}var t=[],n=Object.getPrototypeOf,s=t.slice,g=t.flat?function(e){return t.flat.call(e)}:function(e){return t.concat.apply([],e)},u=t.push,o=t.indexOf,r={},i=r.toString,v=r.hasOwnProperty,a=v.toString,l=a.call(Object),y={},b=function(e){return"function"==typeof e&&"number"!=typeof e.nodeType},T=C.document,c={type:!0,src:!0,nonce:!0,noModule:!0};function x(e,t,n){var r,o,i=(n=n||T).createElement("script");if(i.text=e,t)for(r in c)(o=t[r]||t.getAttribute&&t.getAttribute(r))&&i.setAttribute(r,o);n.head.appendChild(i).parentNode.removeChild(i)}function h(e){return null==e?e+"":"object"==typeof e||"function"==typeof e?r[i.call(e)]||"object":typeof e}var f="3.5.1",E=function(e,t){return new E.fn.init(e,t)};function d(e){var t=!!e&&"length"in e&&e.length,n=h(e);return!b(e)&&!m(e)&&("array"===n||0===t||"number"==typeof t&&0>10|55296,1023&e|56320))}function r(){C()}var e,p,x,i,o,h,d,m,w,u,l,C,T,a,E,g,s,c,v,S="sizzle"+ +new Date,y=n.document,k=0,b=0,A=ue(),N=ue(),j=ue(),I=ue(),L=function(e,t){return e===t&&(l=!0),0},D={}.hasOwnProperty,t=[],O=t.pop,H=t.push,P=t.push,q=t.slice,M=function(e,t){for(var n=0,r=e.length;n+~]|"+$+")"+$+"*"),Q=new RegExp($+"|>"),Y=new RegExp(F),V=new RegExp("^"+R+"$"),G={ID:new RegExp("^#("+R+")"),CLASS:new RegExp("^\\.("+R+")"),TAG:new RegExp("^("+R+"|[*])"),ATTR:new RegExp("^"+B),PSEUDO:new RegExp("^"+F),CHILD:new RegExp("^:(only|first|last|nth|nth-last)-(child|of-type)(?:\\("+$+"*(even|odd|(([+-]|)(\\d*)n|)"+$+"*(?:([+-]|)"+$+"*(\\d+)|))"+$+"*\\)|)","i"),bool:new RegExp("^(?:"+_+")$","i"),needsContext:new RegExp("^"+$+"*[>+~]|:(even|odd|eq|gt|lt|nth|first|last)(?:\\("+$+"*((?:-\\d)?\\d*)"+$+"*\\)|)(?=[^-]|$)","i")},K=/HTML$/i,Z=/^(?:input|select|textarea|button)$/i,J=/^h\d$/i,ee=/^[^{]+\{\s*\[native \w/,te=/^(?:#([\w-]+)|(\w+)|\.([\w-]+))$/,ne=/[+~]/,re=new RegExp("\\\\[\\da-fA-F]{1,6}"+$+"?|\\\\([^\\r\\n\\f])","g"),oe=/([\0-\x1f\x7f]|^-?\d)|^-$|[^\0-\x1f\x7f-\uFFFF\w-]/g,ie=function(e,t){return t?"\0"===e?"�":e.slice(0,-1)+"\\"+e.charCodeAt(e.length-1).toString(16)+" ":"\\"+e},ae=ye(function(e){return!0===e.disabled&&"fieldset"===e.nodeName.toLowerCase()},{dir:"parentNode",next:"legend"});try{P.apply(t=q.call(y.childNodes),y.childNodes),t[y.childNodes.length].nodeType}catch(e){P={apply:t.length?function(e,t){H.apply(e,q.call(t))}:function(e,t){for(var n=e.length,r=0;e[n++]=t[r++];);e.length=n-1}}}function se(t,e,n,r){var o,i,a,s,u,l,c,f=e&&e.ownerDocument,d=e?e.nodeType:9;if(n=n||[],"string"!=typeof t||!t||1!==d&&9!==d&&11!==d)return n;if(!r&&(C(e),e=e||T,E)){if(11!==d&&(u=te.exec(t)))if(o=u[1]){if(9===d){if(!(a=e.getElementById(o)))return n;if(a.id===o)return n.push(a),n}else if(f&&(a=f.getElementById(o))&&v(e,a)&&a.id===o)return n.push(a),n}else{if(u[2])return P.apply(n,e.getElementsByTagName(t)),n;if((o=u[3])&&p.getElementsByClassName&&e.getElementsByClassName)return P.apply(n,e.getElementsByClassName(o)),n}if(p.qsa&&!I[t+" "]&&(!g||!g.test(t))&&(1!==d||"object"!==e.nodeName.toLowerCase())){if(c=t,f=e,1===d&&(Q.test(t)||X.test(t))){for((f=ne.test(t)&&me(e.parentNode)||e)===e&&p.scope||((s=e.getAttribute("id"))?s=s.replace(oe,ie):e.setAttribute("id",s=S)),i=(l=h(t)).length;i--;)l[i]=(s?"#"+s:":scope")+" "+ve(l[i]);c=l.join(",")}try{return P.apply(n,f.querySelectorAll(c)),n}catch(e){I(t,!0)}finally{s===S&&e.removeAttribute("id")}}}return m(t.replace(W,"$1"),e,n,r)}function ue(){var n=[];function r(e,t){return n.push(e+" ")>x.cacheLength&&delete r[n.shift()],r[e+" "]=t}return r}function le(e){return e[S]=!0,e}function ce(e){var t=T.createElement("fieldset");try{return!!e(t)}catch(e){return!1}finally{t.parentNode&&t.parentNode.removeChild(t),t=null}}function fe(e,t){for(var n=e.split("|"),r=n.length;r--;)x.attrHandle[n[r]]=t}function de(e,t){var n=t&&e,r=n&&1===e.nodeType&&1===t.nodeType&&e.sourceIndex-t.sourceIndex;if(r)return r;if(n)for(;n=n.nextSibling;)if(n===t)return-1;return e?1:-1}function pe(t){return function(e){return"form"in e?e.parentNode&&!1===e.disabled?"label"in e?"label"in e.parentNode?e.parentNode.disabled===t:e.disabled===t:e.isDisabled===t||e.isDisabled!==!t&&ae(e)===t:e.disabled===t:"label"in e&&e.disabled===t}}function he(a){return le(function(i){return i=+i,le(function(e,t){for(var n,r=a([],e.length,i),o=r.length;o--;)e[n=r[o]]&&(e[n]=!(t[n]=e[n]))})})}function me(e){return e&&void 0!==e.getElementsByTagName&&e}for(e in p=se.support={},o=se.isXML=function(e){var t=e.namespaceURI,e=(e.ownerDocument||e).documentElement;return!K.test(t||e&&e.nodeName||"HTML")},C=se.setDocument=function(e){var t,e=e?e.ownerDocument||e:y;return e!=T&&9===e.nodeType&&e.documentElement&&(a=(T=e).documentElement,E=!o(T),y!=T&&(t=T.defaultView)&&t.top!==t&&(t.addEventListener?t.addEventListener("unload",r,!1):t.attachEvent&&t.attachEvent("onunload",r)),p.scope=ce(function(e){return a.appendChild(e).appendChild(T.createElement("div")),void 0!==e.querySelectorAll&&!e.querySelectorAll(":scope fieldset div").length}),p.attributes=ce(function(e){return e.className="i",!e.getAttribute("className")}),p.getElementsByTagName=ce(function(e){return e.appendChild(T.createComment("")),!e.getElementsByTagName("*").length}),p.getElementsByClassName=ee.test(T.getElementsByClassName),p.getById=ce(function(e){return a.appendChild(e).id=S,!T.getElementsByName||!T.getElementsByName(S).length}),p.getById?(x.filter.ID=function(e){var t=e.replace(re,f);return function(e){return e.getAttribute("id")===t}},x.find.ID=function(e,t){if(void 0!==t.getElementById&&E){e=t.getElementById(e);return e?[e]:[]}}):(x.filter.ID=function(e){var t=e.replace(re,f);return function(e){e=void 0!==e.getAttributeNode&&e.getAttributeNode("id");return e&&e.value===t}},x.find.ID=function(e,t){if(void 0!==t.getElementById&&E){var n,r,o,i=t.getElementById(e);if(i){if((n=i.getAttributeNode("id"))&&n.value===e)return[i];for(o=t.getElementsByName(e),r=0;i=o[r++];)if((n=i.getAttributeNode("id"))&&n.value===e)return[i]}return[]}}),x.find.TAG=p.getElementsByTagName?function(e,t){return void 0!==t.getElementsByTagName?t.getElementsByTagName(e):p.qsa?t.querySelectorAll(e):void 0}:function(e,t){var n,r=[],o=0,i=t.getElementsByTagName(e);if("*"!==e)return i;for(;n=i[o++];)1===n.nodeType&&r.push(n);return r},x.find.CLASS=p.getElementsByClassName&&function(e,t){if(void 0!==t.getElementsByClassName&&E)return t.getElementsByClassName(e)},s=[],g=[],(p.qsa=ee.test(T.querySelectorAll))&&(ce(function(e){var t;a.appendChild(e).innerHTML="",e.querySelectorAll("[msallowcapture^='']").length&&g.push("[*^$]="+$+"*(?:''|\"\")"),e.querySelectorAll("[selected]").length||g.push("\\["+$+"*(?:value|"+_+")"),e.querySelectorAll("[id~="+S+"-]").length||g.push("~="),(t=T.createElement("input")).setAttribute("name",""),e.appendChild(t),e.querySelectorAll("[name='']").length||g.push("\\["+$+"*name"+$+"*="+$+"*(?:''|\"\")"),e.querySelectorAll(":checked").length||g.push(":checked"),e.querySelectorAll("a#"+S+"+*").length||g.push(".#.+[+~]"),e.querySelectorAll("\\\f"),g.push("[\\r\\n\\f]")}),ce(function(e){e.innerHTML="";var t=T.createElement("input");t.setAttribute("type","hidden"),e.appendChild(t).setAttribute("name","D"),e.querySelectorAll("[name=d]").length&&g.push("name"+$+"*[*^$|!~]?="),2!==e.querySelectorAll(":enabled").length&&g.push(":enabled",":disabled"),a.appendChild(e).disabled=!0,2!==e.querySelectorAll(":disabled").length&&g.push(":enabled",":disabled"),e.querySelectorAll("*,:x"),g.push(",.*:")})),(p.matchesSelector=ee.test(c=a.matches||a.webkitMatchesSelector||a.mozMatchesSelector||a.oMatchesSelector||a.msMatchesSelector))&&ce(function(e){p.disconnectedMatch=c.call(e,"*"),c.call(e,"[s!='']:x"),s.push("!=",F)}),g=g.length&&new RegExp(g.join("|")),s=s.length&&new RegExp(s.join("|")),t=ee.test(a.compareDocumentPosition),v=t||ee.test(a.contains)?function(e,t){var n=9===e.nodeType?e.documentElement:e,t=t&&t.parentNode;return e===t||!(!t||1!==t.nodeType||!(n.contains?n.contains(t):e.compareDocumentPosition&&16&e.compareDocumentPosition(t)))}:function(e,t){if(t)for(;t=t.parentNode;)if(t===e)return!0;return!1},L=t?function(e,t){if(e===t)return l=!0,0;var n=!e.compareDocumentPosition-!t.compareDocumentPosition;return n||(1&(n=(e.ownerDocument||e)==(t.ownerDocument||t)?e.compareDocumentPosition(t):1)||!p.sortDetached&&t.compareDocumentPosition(e)===n?e==T||e.ownerDocument==y&&v(y,e)?-1:t==T||t.ownerDocument==y&&v(y,t)?1:u?M(u,e)-M(u,t):0:4&n?-1:1)}:function(e,t){if(e===t)return l=!0,0;var n,r=0,o=e.parentNode,i=t.parentNode,a=[e],s=[t];if(!o||!i)return e==T?-1:t==T?1:o?-1:i?1:u?M(u,e)-M(u,t):0;if(o===i)return de(e,t);for(n=e;n=n.parentNode;)a.unshift(n);for(n=t;n=n.parentNode;)s.unshift(n);for(;a[r]===s[r];)r++;return r?de(a[r],s[r]):a[r]==y?-1:s[r]==y?1:0}),T},se.matches=function(e,t){return se(e,null,null,t)},se.matchesSelector=function(e,t){if(C(e),p.matchesSelector&&E&&!I[t+" "]&&(!s||!s.test(t))&&(!g||!g.test(t)))try{var n=c.call(e,t);if(n||p.disconnectedMatch||e.document&&11!==e.document.nodeType)return n}catch(e){I(t,!0)}return 0":{dir:"parentNode",first:!0}," ":{dir:"parentNode"},"+":{dir:"previousSibling",first:!0},"~":{dir:"previousSibling"}},preFilter:{ATTR:function(e){return e[1]=e[1].replace(re,f),e[3]=(e[3]||e[4]||e[5]||"").replace(re,f),"~="===e[2]&&(e[3]=" "+e[3]+" "),e.slice(0,4)},CHILD:function(e){return e[1]=e[1].toLowerCase(),"nth"===e[1].slice(0,3)?(e[3]||se.error(e[0]),e[4]=+(e[4]?e[5]+(e[6]||1):2*("even"===e[3]||"odd"===e[3])),e[5]=+(e[7]+e[8]||"odd"===e[3])):e[3]&&se.error(e[0]),e},PSEUDO:function(e){var t,n=!e[6]&&e[2];return G.CHILD.test(e[0])?null:(e[3]?e[2]=e[4]||e[5]||"":n&&Y.test(n)&&(t=h(n,!0))&&(t=n.indexOf(")",n.length-t)-n.length)&&(e[0]=e[0].slice(0,t),e[2]=n.slice(0,t)),e.slice(0,3))}},filter:{TAG:function(e){var t=e.replace(re,f).toLowerCase();return"*"===e?function(){return!0}:function(e){return e.nodeName&&e.nodeName.toLowerCase()===t}},CLASS:function(e){var t=A[e+" "];return t||(t=new RegExp("(^|"+$+")"+e+"("+$+"|$)"))&&A(e,function(e){return t.test("string"==typeof e.className&&e.className||void 0!==e.getAttribute&&e.getAttribute("class")||"")})},ATTR:function(t,n,r){return function(e){e=se.attr(e,t);return null==e?"!="===n:!n||(e+="","="===n?e===r:"!="===n?e!==r:"^="===n?r&&0===e.indexOf(r):"*="===n?r&&-1:\x20\t\r\n\f]*)[\x20\t\r\n\f]*\/?>(?:<\/\1>|)$/i;function j(e,n,r){return b(n)?E.grep(e,function(e,t){return!!n.call(e,t,e)!==r}):n.nodeType?E.grep(e,function(e){return e===n!==r}):"string"!=typeof n?E.grep(e,function(e){return-1)[^>]*|#([\w-]+))$/;(E.fn.init=function(e,t,n){if(!e)return this;if(n=n||I,"string"!=typeof e)return e.nodeType?(this[0]=e,this.length=1,this):b(e)?void 0!==n.ready?n.ready(e):e(E):E.makeArray(e,this);if(!(r="<"===e[0]&&">"===e[e.length-1]&&3<=e.length?[null,e,null]:L.exec(e))||!r[1]&&t)return(!t||t.jquery?t||n:this.constructor(t)).find(e);if(r[1]){if(t=t instanceof E?t[0]:t,E.merge(this,E.parseHTML(r[1],t&&t.nodeType?t.ownerDocument||t:T,!0)),N.test(r[1])&&E.isPlainObject(t))for(var r in t)b(this[r])?this[r](t[r]):this.attr(r,t[r]);return this}return(e=T.getElementById(r[2]))&&(this[0]=e,this.length=1),this}).prototype=E.fn,I=E(T);var D=/^(?:parents|prev(?:Until|All))/,O={children:!0,contents:!0,next:!0,prev:!0};function H(e,t){for(;(e=e[t])&&1!==e.nodeType;);return e}E.fn.extend({has:function(e){var t=E(e,this),n=t.length;return this.filter(function(){for(var e=0;e\x20\t\r\n\f]*)/i,de=/^$|^module$|\/(?:java|ecma)script/i;f=T.createDocumentFragment().appendChild(T.createElement("div")),(p=T.createElement("input")).setAttribute("type","radio"),p.setAttribute("checked","checked"),p.setAttribute("name","t"),f.appendChild(p),y.checkClone=f.cloneNode(!0).cloneNode(!0).lastChild.checked,f.innerHTML="",y.noCloneChecked=!!f.cloneNode(!0).lastChild.defaultValue,f.innerHTML="",y.option=!!f.lastChild;var pe={thead:[1,"","
"],col:[2,"","
"],tr:[2,"","
"],td:[3,"","
"],_default:[0,"",""]};function he(e,t){var n=void 0!==e.getElementsByTagName?e.getElementsByTagName(t||"*"):void 0!==e.querySelectorAll?e.querySelectorAll(t||"*"):[];return void 0===t||t&&A(e,t)?E.merge([e],n):n}function me(e,t){for(var n=0,r=e.length;n",""]);var ge=/<|&#?\w+;/;function ve(e,t,n,r,o){for(var i,a,s,u,l,c=t.createDocumentFragment(),f=[],d=0,p=e.length;d\s*$/g;function je(e,t){return A(e,"table")&&A(11!==t.nodeType?t:t.firstChild,"tr")&&E(e).children("tbody")[0]||e}function Ie(e){return e.type=(null!==e.getAttribute("type"))+"/"+e.type,e}function Le(e){return"true/"===(e.type||"").slice(0,5)?e.type=e.type.slice(5):e.removeAttribute("type"),e}function De(e,t){var n,r,o,i;if(1===t.nodeType){if(V.hasData(e)&&(i=V.get(e).events))for(o in V.remove(t,"handle events"),i)for(n=0,r=i[o].length;n").attr(n.scriptAttrs||{}).prop({charset:n.scriptCharset,src:n.url}).on("load error",o=function(e){r.remove(),o=null,e&&t("error"===e.type?404:200,e.type)}),T.head.appendChild(r[0])},abort:function(){o&&o()}}});var Gt=[],Kt=/(=)\?(?=&|$)|\?\?/;E.ajaxSetup({jsonp:"callback",jsonpCallback:function(){var e=Gt.pop()||E.expando+"_"+jt.guid++;return this[e]=!0,e}}),E.ajaxPrefilter("json jsonp",function(e,t,n){var r,o,i,a=!1!==e.jsonp&&(Kt.test(e.url)?"url":"string"==typeof e.data&&0===(e.contentType||"").indexOf("application/x-www-form-urlencoded")&&Kt.test(e.data)&&"data");if(a||"jsonp"===e.dataTypes[0])return r=e.jsonpCallback=b(e.jsonpCallback)?e.jsonpCallback():e.jsonpCallback,a?e[a]=e[a].replace(Kt,"$1"+r):!1!==e.jsonp&&(e.url+=(It.test(e.url)?"&":"?")+e.jsonp+"="+r),e.converters["script json"]=function(){return i||E.error(r+" was not called"),i[0]},e.dataTypes[0]="json",o=C[r],C[r]=function(){i=arguments},n.always(function(){void 0===o?E(C).removeProp(r):C[r]=o,e[r]&&(e.jsonpCallback=t.jsonpCallback,Gt.push(r)),i&&b(o)&&o(i[0]),i=o=void 0}),"script"}),y.createHTMLDocument=((f=T.implementation.createHTMLDocument("").body).innerHTML="
",2===f.childNodes.length),E.parseHTML=function(e,t,n){return"string"!=typeof e?[]:("boolean"==typeof t&&(n=t,t=!1),t||(y.createHTMLDocument?((r=(t=T.implementation.createHTMLDocument("")).createElement("base")).href=T.location.href,t.head.appendChild(r)):t=T),r=!n&&[],(n=N.exec(e))?[t.createElement(n[1])]:(n=ve([e],t,r),r&&r.length&&E(r).remove(),E.merge([],n.childNodes)));var r},E.fn.load=function(e,t,n){var r,o,i,a=this,s=e.indexOf(" ");return-1").append(E.parseHTML(e)).find(r):e)}).always(n&&function(e,t){a.each(function(){n.apply(this,i||[e.responseText,t,e])})}),this},E.expr.pseudos.animated=function(t){return E.grep(E.timers,function(e){return t===e.elem}).length},E.offset={setOffset:function(e,t,n){var r,o,i,a,s=E.css(e,"position"),u=E(e),l={};"static"===s&&(e.style.position="relative"),i=u.offset(),r=E.css(e,"top"),a=E.css(e,"left"),a=("absolute"===s||"fixed"===s)&&-1<(r+a).indexOf("auto")?(o=(s=u.position()).top,s.left):(o=parseFloat(r)||0,parseFloat(a)||0),null!=(t=b(t)?t.call(e,n,E.extend({},i)):t).top&&(l.top=t.top-i.top+o),null!=t.left&&(l.left=t.left-i.left+a),"using"in t?t.using.call(e,l):("number"==typeof l.top&&(l.top+="px"),"number"==typeof l.left&&(l.left+="px"),u.css(l))}},E.fn.extend({offset:function(t){if(arguments.length)return void 0===t?this:this.each(function(e){E.offset.setOffset(this,t,e)});var e,n=this[0];return n?n.getClientRects().length?(e=n.getBoundingClientRect(),n=n.ownerDocument.defaultView,{top:e.top+n.pageYOffset,left:e.left+n.pageXOffset}):{top:0,left:0}:void 0},position:function(){if(this[0]){var e,t,n,r=this[0],o={top:0,left:0};if("fixed"===E.css(r,"position"))t=r.getBoundingClientRect();else{for(t=this.offset(),n=r.ownerDocument,e=r.offsetParent||n.documentElement;e&&(e===n.body||e===n.documentElement)&&"static"===E.css(e,"position");)e=e.parentNode;e&&e!==r&&1===e.nodeType&&((o=E(e).offset()).top+=E.css(e,"borderTopWidth",!0),o.left+=E.css(e,"borderLeftWidth",!0))}return{top:t.top-o.top-E.css(r,"marginTop",!0),left:t.left-o.left-E.css(r,"marginLeft",!0)}}},offsetParent:function(){return this.map(function(){for(var e=this.offsetParent;e&&"static"===E.css(e,"position");)e=e.offsetParent;return e||re})}}),E.each({scrollLeft:"pageXOffset",scrollTop:"pageYOffset"},function(t,o){var i="pageYOffset"===o;E.fn[t]=function(e){return F(this,function(e,t,n){var r;return m(e)?r=e:9===e.nodeType&&(r=e.defaultView),void 0===n?r?r[o]:e[t]:void(r?r.scrollTo(i?r.pageXOffset:n,i?n:r.pageYOffset):e[t]=n)},t,e,arguments.length)}}),E.each(["top","left"],function(e,n){E.cssHooks[n]=Ge(y.pixelPosition,function(e,t){if(t)return t=Ve(e,n),We.test(t)?E(e).position()[n]+"px":t})}),E.each({Height:"height",Width:"width"},function(a,s){E.each({padding:"inner"+a,content:s,"":"outer"+a},function(r,i){E.fn[i]=function(e,t){var n=arguments.length&&(r||"boolean"!=typeof e),o=r||(!0===e||!0===t?"margin":"border");return F(this,function(e,t,n){var r;return m(e)?0===i.indexOf("outer")?e["inner"+a]:e.document.documentElement["client"+a]:9===e.nodeType?(r=e.documentElement,Math.max(e.body["scroll"+a],r["scroll"+a],e.body["offset"+a],r["offset"+a],r["client"+a])):void 0===n?E.css(e,t,o):E.style(e,t,n,o)},s,n?e:void 0,n)}})}),E.each(["ajaxStart","ajaxStop","ajaxComplete","ajaxError","ajaxSuccess","ajaxSend"],function(e,t){E.fn[t]=function(e){return this.on(t,e)}}),E.fn.extend({bind:function(e,t,n){return this.on(e,null,t,n)},unbind:function(e,t){return this.off(e,null,t)},delegate:function(e,t,n,r){return this.on(t,e,n,r)},undelegate:function(e,t,n){return 1===arguments.length?this.off(e,"**"):this.off(t,e||"**",n)},hover:function(e,t){return this.mouseenter(e).mouseleave(t||e)}}),E.each("blur focus focusin focusout resize scroll click dblclick mousedown mouseup mousemove mouseover mouseout mouseenter mouseleave change select submit keydown keypress keyup contextmenu".split(" "),function(e,n){E.fn[n]=function(e,t){return 0x

',t.appendChild(n.childNodes[1])),e&&i.extend(o,e),this.each(function(){var e=['iframe[src*="player.vimeo.com"]','iframe[src*="youtube.com"]','iframe[src*="youtube-nocookie.com"]','iframe[src*="kickstarter.com"][src*="video.html"]',"object","embed"];o.customSelector&&e.push(o.customSelector);var r=".fitvidsignore";o.ignore&&(r=r+", "+o.ignore);e=i(this).find(e.join(","));(e=(e=e.not("object object")).not(r)).each(function(e){var t,n=i(this);0').parent(".fluid-width-video-wrapper").css("padding-top",100*t+"%"),n.removeAttr("height").removeAttr("width"))})})}}(window.jQuery||window.Zepto),$(function(){var n,r,e,o,t=$("nav.greedy-nav .greedy-nav__toggle"),i=$("nav.greedy-nav .visible-links"),a=$("nav.greedy-nav .hidden-links"),s=$("nav.greedy-nav"),u=$("nav.greedy-nav .site-logo"),l=$("nav.greedy-nav .site-logo img"),c=$("nav.greedy-nav .site-title"),f=$("nav.greedy-nav button.search__toggle");function d(){function t(e,t){r+=t,n+=1,o.push(r)}r=n=0,e=1e3,o=[],i.children().outerWidth(t),a.children().each(function(){var e;(e=(e=$(this)).clone()).css("visibility","hidden"),i.append(e),t(0,e.outerWidth()),e.remove()})}d();var p,h,m,g,v=$(window).width(),y=v<768?0:v<1024?1:v<1280?2:3;function b(){var e=(v=$(window).width())<768?0:v<1024?1:v<1280?2:3;e!==y&&d(),y=e,h=i.children().length,p=s.innerWidth()-(0!==u.length?u.outerWidth(!0):0)-c.outerWidth(!0)-(0!==f.length?f.outerWidth(!0):0)-(h!==o.length?t.outerWidth(!0):0),m=o[h-1],po[h]&&(a.children().first().appendTo(i),h+=1,b()),t.attr("count",n-h),h===n?t.addClass("hidden"):t.removeClass("hidden")}$(window).resize(function(){b()}),t.on("click",function(){a.toggleClass("hidden"),$(this).toggleClass("close"),clearTimeout(g)}),a.on("mouseleave",function(){g=setTimeout(function(){a.addClass("hidden")},e)}).on("mouseenter",function(){clearTimeout(g)}),0===l.length||l[0].complete||0!==l[0].naturalWidth?b():l.one("load error",b)}),function(e){"function"==typeof define&&define.amd?define(["jquery"],e):"object"==typeof exports?e(require("jquery")):e(window.jQuery||window.Zepto)}(function(l){function e(){}function c(e,t){h.ev.on("mfp"+e+x,t)}function f(e,t,n,r){var o=document.createElement("div");return o.className="mfp-"+e,n&&(o.innerHTML=n),r?t&&t.appendChild(o):(o=l(o),t&&o.appendTo(t)),o}function d(e,t){h.ev.triggerHandler("mfp"+e,t),h.st.callbacks&&(e=e.charAt(0).toLowerCase()+e.slice(1),h.st.callbacks[e]&&h.st.callbacks[e].apply(h,l.isArray(t)?t:[t]))}function p(e){return e===t&&h.currTemplate.closeBtn||(h.currTemplate.closeBtn=l(h.st.closeMarkup.replace("%title%",h.st.tClose)),t=e),h.currTemplate.closeBtn}function i(){l.magnificPopup.instance||((h=new e).init(),l.magnificPopup.instance=h)}var h,r,m,o,g,t,u="Close",v="BeforeClose",y="MarkupParse",b="Open",x=".mfp",w="mfp-ready",n="mfp-removing",a="mfp-prevent-close",s=!!window.jQuery,C=l(window);e.prototype={constructor:e,init:function(){var e=navigator.appVersion;h.isLowIE=h.isIE8=document.all&&!document.addEventListener,h.isAndroid=/android/gi.test(e),h.isIOS=/iphone|ipad|ipod/gi.test(e),h.supportsTransition=function(){var e=document.createElement("p").style,t=["ms","O","Moz","Webkit"];if(void 0!==e.transition)return!0;for(;t.length;)if(t.pop()+"Transition"in e)return!0;return!1}(),h.probablyMobile=h.isAndroid||h.isIOS||/(Opera Mini)|Kindle|webOS|BlackBerry|(Opera Mobi)|(Windows Phone)|IEMobile/i.test(navigator.userAgent),m=l(document),h.popupsCache={}},open:function(e){if(!1===e.isObj){h.items=e.items.toArray(),h.index=0;for(var t,n=e.items,r=0;r(e||C.height())},_setFocus:function(){(h.st.focus?h.content.find(h.st.focus).eq(0):h.wrap).focus()},_onFocusIn:function(e){if(e.target!==h.wrap[0]&&!l.contains(h.wrap[0],e.target))return h._setFocus(),!1},_parseMarkup:function(o,e,t){var i;t.data&&(e=l.extend(t.data,e)),d(y,[o,e,t]),l.each(e,function(e,t){return void 0===t||!1===t||void(1<(i=e.split("_")).length?0<(n=o.find(x+"-"+i[0])).length&&("replaceWith"===(r=i[1])?n[0]!==t[0]&&n.replaceWith(t):"img"===r?n.is("img")?n.attr("src",t):n.replaceWith(l("").attr("src",t).attr("class",n.attr("class"))):n.attr(i[1],t)):o.find(x+"-"+e).html(t));var n,r})},_getScrollbarSize:function(){var e;return void 0===h.scrollbarSize&&((e=document.createElement("div")).style.cssText="width: 99px; height: 99px; overflow: scroll; position: absolute; top: -9999px;",document.body.appendChild(e),h.scrollbarSize=e.offsetWidth-e.clientWidth,document.body.removeChild(e)),h.scrollbarSize}},l.magnificPopup={instance:null,proto:e.prototype,modules:[],open:function(e,t){return i(),(e=e?l.extend(!0,{},e):{}).isObj=!0,e.index=t||0,this.instance.open(e)},close:function(){return l.magnificPopup.instance&&l.magnificPopup.instance.close()},registerModule:function(e,t){t.options&&(l.magnificPopup.defaults[e]=t.options),l.extend(this.proto,t.proto),this.modules.push(e)},defaults:{disableOn:0,key:null,midClick:!1,mainClass:"",preloader:!0,focus:"",closeOnContentClick:!1,closeOnBgClick:!0,closeBtnInside:!0,showCloseBtn:!0,enableEscapeKey:!0,modal:!1,alignTop:!1,removalDelay:0,prependTo:null,fixedContentPos:"auto",fixedBgPos:"auto",overflowY:"auto",closeMarkup:'',tClose:"Close (Esc)",tLoading:"Loading...",autoFocusLast:!0}},l.fn.magnificPopup=function(e){i();var t,n,r,o=l(this);return"string"==typeof e?"open"===e?(t=s?o.data("magnificPopup"):o[0].magnificPopup,n=parseInt(arguments[1],10)||0,r=t.items?t.items[n]:(r=o,(r=t.delegate?r.find(t.delegate):r).eq(n)),h._openClick({mfpEl:r},o,t)):h.isOpen&&h[e].apply(h,Array.prototype.slice.call(arguments,1)):(e=l.extend(!0,{},e),s?o.data("magnificPopup",e):o[0].magnificPopup=e,h.addGroup(o,e)),o};function T(){k&&(S.after(k.addClass(E)).detach(),k=null)}var E,S,k,A="inline";l.magnificPopup.registerModule(A,{options:{hiddenClass:"hide",markup:"",tNotFound:"Content not found"},proto:{initInline:function(){h.types.push(A),c(u+"."+A,function(){T()})},getInline:function(e,t){if(T(),e.src){var n,r=h.st.inline,o=l(e.src);return o.length?((n=o[0].parentNode)&&n.tagName&&(S||(E=r.hiddenClass,S=f(E),E="mfp-"+E),k=o.after(S).detach().removeClass(E)),h.updateStatus("ready")):(h.updateStatus("error",r.tNotFound),o=l("
")),e.inlineElement=o}return h.updateStatus("ready"),h._parseMarkup(t,{},e),t}}});function N(){I&&l(document.body).removeClass(I)}function j(){N(),h.req&&h.req.abort()}var I,L="ajax";l.magnificPopup.registerModule(L,{options:{settings:null,cursor:"mfp-ajax-cur",tError:'The content could not be loaded.'},proto:{initAjax:function(){h.types.push(L),I=h.st.ajax.cursor,c(u+"."+L,j),c("BeforeChange."+L,j)},getAjax:function(r){I&&l(document.body).addClass(I),h.updateStatus("loading");var e=l.extend({url:r.src,success:function(e,t,n){n={data:e,xhr:n};d("ParseAjax",n),h.appendContent(l(n.data),L),r.finished=!0,N(),h._setFocus(),setTimeout(function(){h.wrap.addClass(w)},16),h.updateStatus("ready"),d("AjaxContentAdded")},error:function(){N(),r.finished=r.loadError=!0,h.updateStatus("error",h.st.ajax.tError.replace("%url%",r.src))}},h.st.ajax.settings);return h.req=l.ajax(e),""}}});var D;l.magnificPopup.registerModule("image",{options:{markup:'
',cursor:"mfp-zoom-out-cur",titleSrc:"title",verticalFit:!0,tError:'The image could not be loaded.'},proto:{initImage:function(){var e=h.st.image,t=".image";h.types.push("image"),c(b+t,function(){"image"===h.currItem.type&&e.cursor&&l(document.body).addClass(e.cursor)}),c(u+t,function(){e.cursor&&l(document.body).removeClass(e.cursor),C.off("resize"+x)}),c("Resize"+t,h.resizeImage),h.isLowIE&&c("AfterChange",h.resizeImage)},resizeImage:function(){var e,t=h.currItem;t&&t.img&&h.st.image.verticalFit&&(e=0,h.isLowIE&&(e=parseInt(t.img.css("padding-top"),10)+parseInt(t.img.css("padding-bottom"),10)),t.img.css("max-height",h.wH-e))},_onImageHasSize:function(e){e.img&&(e.hasSize=!0,D&&clearInterval(D),e.isCheckingImgSize=!1,d("ImageHasSize",e),e.imgHidden&&(h.content&&h.content.removeClass("mfp-loading"),e.imgHidden=!1))},findImageSize:function(t){var n=0,r=t.img[0],o=function(e){D&&clearInterval(D),D=setInterval(function(){0
',srcAction:"iframe_src",patterns:{youtube:{index:"youtube.com",id:"v=",src:"//www.youtube.com/embed/%id%?autoplay=1"},vimeo:{index:"vimeo.com/",id:"/",src:"//player.vimeo.com/video/%id%?autoplay=1"},gmaps:{index:"//maps.google.",src:"%id%&output=embed"}}},proto:{initIframe:function(){h.types.push(P),c("BeforeChange",function(e,t,n){t!==n&&(t===P?H():n===P&&H(!0))}),c(u+"."+P,function(){H()})},getIframe:function(e,t){var n=e.src,r=h.st.iframe;l.each(r.patterns,function(){if(-1',preload:[0,2],navigateByImgClick:!0,arrows:!0,tPrev:"Previous (Left arrow key)",tNext:"Next (Right arrow key)",tCounter:"%curr% of %total%"},proto:{initGallery:function(){var i=h.st.gallery,e=".mfp-gallery";if(h.direction=!0,!i||!i.enabled)return!1;g+=" mfp-gallery",c(b+e,function(){i.navigateByImgClick&&h.wrap.on("click"+e,".mfp-img",function(){if(1=h.index,h.index=e,h.updateItemHTML()},preloadNearbyImages:function(){for(var e=h.st.gallery.preload,t=Math.min(e[0],h.items.length),n=Math.min(e[1],h.items.length),r=1;r<=(h.direction?n:t);r++)h._preloadItem(h.index+r);for(r=1;r<=(h.direction?t:n);r++)h._preloadItem(h.index-r)},_preloadItem:function(e){var t;e=q(e),h.items[e].preloaded||((t=h.items[e]).parsed||(t=h.parseEl(e)),d("LazyLoad",t),"image"===t.type&&(t.img=l('').on("load.mfploader",function(){t.hasSize=!0}).on("error.mfploader",function(){t.hasSize=!0,t.loadError=!0,d("LazyLoadError",t)}).attr("src",t.src)),t.preloaded=!0)}}});var _="retina";l.magnificPopup.registerModule(_,{options:{replaceSrc:function(e){return e.src.replace(/\.\w+$/,function(e){return"@2x"+e})},ratio:1},proto:{initRetina:function(){var n,r;1t.durationMax?t.durationMax:t.durationMin&&e=u)return b.cancelScroll(!0),e=t,n=g,0===(t=r)&&document.body.focus(),n||(t.focus(),document.activeElement!==t&&(t.setAttribute("tabindex","-1"),t.focus(),t.style.outline="none"),x.scrollTo(0,e)),E("scrollStop",m,r,o),!(y=f=null)},h=function(e){var t,n,r;l+=e-(f=f||e),d=i+s*(n=d=1<(d=0===c?0:l/c)?1:d,"easeInQuad"===(t=m).easing&&(r=n*n),"easeOutQuad"===t.easing&&(r=n*(2-n)),"easeInOutQuad"===t.easing&&(r=n<.5?2*n*n:(4-2*n)*n-1),"easeInCubic"===t.easing&&(r=n*n*n),"easeOutCubic"===t.easing&&(r=--n*n*n+1),"easeInOutCubic"===t.easing&&(r=n<.5?4*n*n*n:(n-1)*(2*n-2)*(2*n-2)+1),"easeInQuart"===t.easing&&(r=n*n*n*n),"easeOutQuart"===t.easing&&(r=1- --n*n*n*n),"easeInOutQuart"===t.easing&&(r=n<.5?8*n*n*n*n:1-8*--n*n*n*n),"easeInQuint"===t.easing&&(r=n*n*n*n*n),"easeOutQuint"===t.easing&&(r=1+--n*n*n*n*n),"easeInOutQuint"===t.easing&&(r=n<.5?16*n*n*n*n*n:1+16*--n*n*n*n*n),(r=t.customEasing?t.customEasing(n):r)||n),x.scrollTo(0,Math.floor(d)),p(d,a)||(y=x.requestAnimationFrame(h),f=e)},0===x.pageYOffset&&x.scrollTo(0,0),t=r,e=m,g||history.pushState&&e.updateURL&&history.pushState({smoothScroll:JSON.stringify(e),anchor:t.id},document.title,t===document.documentElement?"#top":"#"+t.id),"matchMedia"in x&&x.matchMedia("(prefers-reduced-motion)").matches?x.scrollTo(0,Math.floor(a)):(E("scrollStart",m,r,o),b.cancelScroll(!0),x.requestAnimationFrame(h)))};function t(e){if(!e.defaultPrevented&&!(0!==e.button||e.metaKey||e.ctrlKey||e.shiftKey)&&"closest"in e.target&&(i=e.target.closest(o),i&&"a"===i.tagName.toLowerCase()&&!e.target.closest(v.ignore)&&i.hostname===x.location.hostname&&i.pathname===x.location.pathname&&/#/.test(i.href))){var t,n,r;try{t=a(decodeURIComponent(i.hash))}catch(e){t=a(i.hash)}if("#"===t){if(!v.topOnEmptyHash)return;n=document.documentElement}else n=document.querySelector(t);(n=n||"#top"!==t?n:document.documentElement)&&(e.preventDefault(),r=v,history.replaceState&&r.updateURL&&!history.state&&(e=(e=x.location.hash)||"",history.replaceState({smoothScroll:JSON.stringify(r),anchor:e||x.pageYOffset},document.title,e||x.location.href)),b.animateScroll(n,i))}}function r(e){var t;null!==history.state&&history.state.smoothScroll&&history.state.smoothScroll===JSON.stringify(v)&&("string"==typeof(t=history.state.anchor)&&t&&!(t=document.querySelector(a(history.state.anchor)))||b.animateScroll(t,null,{updateURL:!1}))}b.destroy=function(){v&&(document.removeEventListener("click",t,!1),x.removeEventListener("popstate",r,!1),b.cancelScroll(),y=n=i=v=null)};return function(){if(!("querySelector"in document&&"addEventListener"in x&&"requestAnimationFrame"in x&&"closest"in x.Element.prototype))throw"Smooth Scroll: This browser does not support the required JavaScript methods and browser APIs.";b.destroy(),v=w(S,e||{}),n=v.header?document.querySelector(v.header):null,document.addEventListener("click",t,!1),v.updateURL&&v.popstate&&x.addEventListener("popstate",r,!1)}(),b}}),function(e,t){"function"==typeof define&&define.amd?define([],function(){return t(e)}):"object"==typeof exports?module.exports=t(e):e.Gumshoe=t(e)}("undefined"!=typeof global?global:"undefined"!=typeof window?window:this,function(c){"use strict";function f(e,t,n){n.settings.events&&(n=new CustomEvent(e,{bubbles:!0,cancelable:!0,detail:n}),t.dispatchEvent(n))}function n(e){var t=0;if(e.offsetParent)for(;e;)t+=e.offsetTop,e=e.offsetParent;return 0<=t?t:0}function d(e){e&&e.sort(function(e,t){return n(e.content)=Math.max(document.body.scrollHeight,document.documentElement.scrollHeight,document.body.offsetHeight,document.documentElement.offsetHeight,document.body.clientHeight,document.documentElement.clientHeight)}function p(e,t){var n,r,o=e[e.length-1];if(n=o,r=t,!(!s()||!a(n.content,r,!0)))return o;for(var i=e.length-1;0<=i;i--)if(a(e[i].content,t))return e[i]}function h(e,t){var n;!e||(n=e.nav.closest("li"))&&(n.classList.remove(t.navClass),e.content.classList.remove(t.contentClass),r(n,t),f("gumshoeDeactivate",n,{link:e.nav,content:e.content,settings:t}))}var m={navClass:"active",contentClass:"active",nested:!1,nestedClass:"active",offset:0,reflow:!1,events:!0},r=function(e,t){!t.nested||(e=e.parentNode.closest("li"))&&(e.classList.remove(t.nestedClass),r(e,t))},g=function(e,t){!t.nested||(e=e.parentNode.closest("li"))&&(e.classList.add(t.nestedClass),g(e,t))};return function(e,t){var n,o,i,r,a,s={setup:function(){n=document.querySelectorAll(e),o=[],Array.prototype.forEach.call(n,function(e){var t=document.getElementById(decodeURIComponent(e.hash.substr(1)));t&&o.push({nav:e,content:t})}),d(o)}};s.detect=function(){var e,t,n,r=p(o,a);r?i&&r.content===i.content||(h(i,a),t=a,!(e=r)||(n=e.nav.closest("li"))&&(n.classList.add(t.navClass),e.content.classList.add(t.contentClass),g(n,t),f("gumshoeActivate",n,{link:e.nav,content:e.content,settings:t})),i=r):i&&(h(i,a),i=null)};function u(e){r&&c.cancelAnimationFrame(r),r=c.requestAnimationFrame(s.detect)}function l(e){r&&c.cancelAnimationFrame(r),r=c.requestAnimationFrame(function(){d(o),s.detect()})}s.destroy=function(){i&&h(i,a),c.removeEventListener("scroll",u,!1),a.reflow&&c.removeEventListener("resize",l,!1),a=r=i=n=o=null};return a=function(){var n={};return Array.prototype.forEach.call(arguments,function(e){for(var t in e){if(!e.hasOwnProperty(t))return;n[t]=e[t]}}),n}(m,t||{}),s.setup(),s.detect(),c.addEventListener("scroll",u,!1),a.reflow&&c.addEventListener("resize",l,!1),s}}),$(document).ready(function(){$("#main").fitVids();function e(){(0===$(".author__urls-wrapper button").length?1024<$(window).width():!$(".author__urls-wrapper button").is(":visible"))?$(".sidebar").addClass("sticky"):$(".sidebar").removeClass("sticky")}e(),$(window).resize(function(){e()}),$(".author__urls-wrapper button").on("click",function(){$(".author__urls").toggleClass("is--visible"),$(".author__urls-wrapper button").toggleClass("open")}),$(document).keyup(function(e){27===e.keyCode&&$(".initial-content").hasClass("is--hidden")&&($(".search-content").toggleClass("is--visible"),$(".initial-content").toggleClass("is--hidden"))}),$(".search__toggle").on("click",function(){$(".search-content").toggleClass("is--visible"),$(".initial-content").toggleClass("is--hidden"),setTimeout(function(){$(".search-content input").focus()},400)});new SmoothScroll('a[href*="#"]',{offset:20,speed:400,speedAsDuration:!0,durationMax:500});0<$("nav.toc").length&&new Gumshoe("nav.toc a",{navClass:"active",contentClass:"active",nested:!1,nestedClass:"active",offset:20,reflow:!0,events:!0}),$("a[href$='.jpg'],a[href$='.jpeg'],a[href$='.JPG'],a[href$='.png'],a[href$='.gif'],a[href$='.webp']").has("> img").addClass("image-popup"),$(".image-popup").magnificPopup({type:"image",tLoading:"Loading image #%curr%...",gallery:{enabled:!0,navigateByImgClick:!0,preload:[0,1]},image:{tError:'Image #%curr% could not be loaded.'},removalDelay:500,mainClass:"mfp-zoom-in",callbacks:{beforeOpen:function(){this.st.image.markup=this.st.image.markup.replace("mfp-figure","mfp-figure mfp-with-anim")}},closeOnContentClick:!0,midClick:!0}),$(".page__content").find("h1, h2, h3, h4, h5, h6").each(function(){var e,t=$(this).attr("id");t&&((e=document.createElement("a")).className="header-link",e.href="#"+t,e.innerHTML='Permalink',e.title="Permalink",$(this).append(e))})}); \ No newline at end of file diff --git a/docs/assets/js/plugins/gumshoe.js b/docs/assets/js/plugins/gumshoe.js deleted file mode 100644 index 713b6eb303..0000000000 --- a/docs/assets/js/plugins/gumshoe.js +++ /dev/null @@ -1,484 +0,0 @@ -/*! - * gumshoejs v5.1.1 - * A simple, framework-agnostic scrollspy script. - * (c) 2019 Chris Ferdinandi - * MIT License - * http://github.com/cferdinandi/gumshoe - */ - -(function (root, factory) { - if ( typeof define === 'function' && define.amd ) { - define([], (function () { - return factory(root); - })); - } else if ( typeof exports === 'object' ) { - module.exports = factory(root); - } else { - root.Gumshoe = factory(root); - } -})(typeof global !== 'undefined' ? global : typeof window !== 'undefined' ? window : this, (function (window) { - - 'use strict'; - - // - // Defaults - // - - var defaults = { - - // Active classes - navClass: 'active', - contentClass: 'active', - - // Nested navigation - nested: false, - nestedClass: 'active', - - // Offset & reflow - offset: 0, - reflow: false, - - // Event support - events: true - - }; - - - // - // Methods - // - - /** - * Merge two or more objects together. - * @param {Object} objects The objects to merge together - * @returns {Object} Merged values of defaults and options - */ - var extend = function () { - var merged = {}; - Array.prototype.forEach.call(arguments, (function (obj) { - for (var key in obj) { - if (!obj.hasOwnProperty(key)) return; - merged[key] = obj[key]; - } - })); - return merged; - }; - - /** - * Emit a custom event - * @param {String} type The event type - * @param {Node} elem The element to attach the event to - * @param {Object} detail Any details to pass along with the event - */ - var emitEvent = function (type, elem, detail) { - - // Make sure events are enabled - if (!detail.settings.events) return; - - // Create a new event - var event = new CustomEvent(type, { - bubbles: true, - cancelable: true, - detail: detail - }); - - // Dispatch the event - elem.dispatchEvent(event); - - }; - - /** - * Get an element's distance from the top of the Document. - * @param {Node} elem The element - * @return {Number} Distance from the top in pixels - */ - var getOffsetTop = function (elem) { - var location = 0; - if (elem.offsetParent) { - while (elem) { - location += elem.offsetTop; - elem = elem.offsetParent; - } - } - return location >= 0 ? location : 0; - }; - - /** - * Sort content from first to last in the DOM - * @param {Array} contents The content areas - */ - var sortContents = function (contents) { - if(contents) { - contents.sort((function (item1, item2) { - var offset1 = getOffsetTop(item1.content); - var offset2 = getOffsetTop(item2.content); - if (offset1 < offset2) return -1; - return 1; - })); - } - }; - - /** - * Get the offset to use for calculating position - * @param {Object} settings The settings for this instantiation - * @return {Float} The number of pixels to offset the calculations - */ - var getOffset = function (settings) { - - // if the offset is a function run it - if (typeof settings.offset === 'function') { - return parseFloat(settings.offset()); - } - - // Otherwise, return it as-is - return parseFloat(settings.offset); - - }; - - /** - * Get the document element's height - * @private - * @returns {Number} - */ - var getDocumentHeight = function () { - return Math.max( - document.body.scrollHeight, document.documentElement.scrollHeight, - document.body.offsetHeight, document.documentElement.offsetHeight, - document.body.clientHeight, document.documentElement.clientHeight - ); - }; - - /** - * Determine if an element is in view - * @param {Node} elem The element - * @param {Object} settings The settings for this instantiation - * @param {Boolean} bottom If true, check if element is above bottom of viewport instead - * @return {Boolean} Returns true if element is in the viewport - */ - var isInView = function (elem, settings, bottom) { - var bounds = elem.getBoundingClientRect(); - var offset = getOffset(settings); - if (bottom) { - return parseInt(bounds.bottom, 10) < (window.innerHeight || document.documentElement.clientHeight); - } - return parseInt(bounds.top, 10) <= offset; - }; - - /** - * Check if at the bottom of the viewport - * @return {Boolean} If true, page is at the bottom of the viewport - */ - var isAtBottom = function () { - if (window.innerHeight + window.pageYOffset >= getDocumentHeight()) return true; - return false; - }; - - /** - * Check if the last item should be used (even if not at the top of the page) - * @param {Object} item The last item - * @param {Object} settings The settings for this instantiation - * @return {Boolean} If true, use the last item - */ - var useLastItem = function (item, settings) { - if (isAtBottom() && isInView(item.content, settings, true)) return true; - return false; - }; - - /** - * Get the active content - * @param {Array} contents The content areas - * @param {Object} settings The settings for this instantiation - * @return {Object} The content area and matching navigation link - */ - var getActive = function (contents, settings) { - var last = contents[contents.length-1]; - if (useLastItem(last, settings)) return last; - for (var i = contents.length - 1; i >= 0; i--) { - if (isInView(contents[i].content, settings)) return contents[i]; - } - }; - - /** - * Deactivate parent navs in a nested navigation - * @param {Node} nav The starting navigation element - * @param {Object} settings The settings for this instantiation - */ - var deactivateNested = function (nav, settings) { - - // If nesting isn't activated, bail - if (!settings.nested) return; - - // Get the parent navigation - var li = nav.parentNode.closest('li'); - if (!li) return; - - // Remove the active class - li.classList.remove(settings.nestedClass); - - // Apply recursively to any parent navigation elements - deactivateNested(li, settings); - - }; - - /** - * Deactivate a nav and content area - * @param {Object} items The nav item and content to deactivate - * @param {Object} settings The settings for this instantiation - */ - var deactivate = function (items, settings) { - - // Make sure their are items to deactivate - if (!items) return; - - // Get the parent list item - var li = items.nav.closest('li'); - if (!li) return; - - // Remove the active class from the nav and content - li.classList.remove(settings.navClass); - items.content.classList.remove(settings.contentClass); - - // Deactivate any parent navs in a nested navigation - deactivateNested(li, settings); - - // Emit a custom event - emitEvent('gumshoeDeactivate', li, { - link: items.nav, - content: items.content, - settings: settings - }); - - }; - - - /** - * Activate parent navs in a nested navigation - * @param {Node} nav The starting navigation element - * @param {Object} settings The settings for this instantiation - */ - var activateNested = function (nav, settings) { - - // If nesting isn't activated, bail - if (!settings.nested) return; - - // Get the parent navigation - var li = nav.parentNode.closest('li'); - if (!li) return; - - // Add the active class - li.classList.add(settings.nestedClass); - - // Apply recursively to any parent navigation elements - activateNested(li, settings); - - }; - - /** - * Activate a nav and content area - * @param {Object} items The nav item and content to activate - * @param {Object} settings The settings for this instantiation - */ - var activate = function (items, settings) { - - // Make sure their are items to activate - if (!items) return; - - // Get the parent list item - var li = items.nav.closest('li'); - if (!li) return; - - // Add the active class to the nav and content - li.classList.add(settings.navClass); - items.content.classList.add(settings.contentClass); - - // Activate any parent navs in a nested navigation - activateNested(li, settings); - - // Emit a custom event - emitEvent('gumshoeActivate', li, { - link: items.nav, - content: items.content, - settings: settings - }); - - }; - - /** - * Create the Constructor object - * @param {String} selector The selector to use for navigation items - * @param {Object} options User options and settings - */ - var Constructor = function (selector, options) { - - // - // Variables - // - - var publicAPIs = {}; - var navItems, contents, current, timeout, settings; - - - // - // Methods - // - - /** - * Set variables from DOM elements - */ - publicAPIs.setup = function () { - - // Get all nav items - navItems = document.querySelectorAll(selector); - - // Create contents array - contents = []; - - // Loop through each item, get it's matching content, and push to the array - Array.prototype.forEach.call(navItems, (function (item) { - - // Get the content for the nav item - var content = document.getElementById(decodeURIComponent(item.hash.substr(1))); - if (!content) return; - - // Push to the contents array - contents.push({ - nav: item, - content: content - }); - - })); - - // Sort contents by the order they appear in the DOM - sortContents(contents); - - }; - - /** - * Detect which content is currently active - */ - publicAPIs.detect = function () { - - // Get the active content - var active = getActive(contents, settings); - - // if there's no active content, deactivate and bail - if (!active) { - if (current) { - deactivate(current, settings); - current = null; - } - return; - } - - // If the active content is the one currently active, do nothing - if (current && active.content === current.content) return; - - // Deactivate the current content and activate the new content - deactivate(current, settings); - activate(active, settings); - - // Update the currently active content - current = active; - - }; - - /** - * Detect the active content on scroll - * Debounced for performance - */ - var scrollHandler = function (event) { - - // If there's a timer, cancel it - if (timeout) { - window.cancelAnimationFrame(timeout); - } - - // Setup debounce callback - timeout = window.requestAnimationFrame(publicAPIs.detect); - - }; - - /** - * Update content sorting on resize - * Debounced for performance - */ - var resizeHandler = function (event) { - - // If there's a timer, cancel it - if (timeout) { - window.cancelAnimationFrame(timeout); - } - - // Setup debounce callback - timeout = window.requestAnimationFrame((function () { - sortContents(contents); - publicAPIs.detect(); - })); - - }; - - /** - * Destroy the current instantiation - */ - publicAPIs.destroy = function () { - - // Undo DOM changes - if (current) { - deactivate(current, settings); - } - - // Remove event listeners - window.removeEventListener('scroll', scrollHandler, false); - if (settings.reflow) { - window.removeEventListener('resize', resizeHandler, false); - } - - // Reset variables - contents = null; - navItems = null; - current = null; - timeout = null; - settings = null; - - }; - - /** - * Initialize the current instantiation - */ - var init = function () { - - // Merge user options into defaults - settings = extend(defaults, options || {}); - - // Setup variables based on the current DOM - publicAPIs.setup(); - - // Find the currently active content - publicAPIs.detect(); - - // Setup event listeners - window.addEventListener('scroll', scrollHandler, false); - if (settings.reflow) { - window.addEventListener('resize', resizeHandler, false); - } - - }; - - - // - // Initialize and return the public APIs - // - - init(); - return publicAPIs; - - }; - - - // - // Return the Constructor - // - - return Constructor; - -})); \ No newline at end of file diff --git a/docs/assets/js/plugins/jquery.ba-throttle-debounce.js b/docs/assets/js/plugins/jquery.ba-throttle-debounce.js deleted file mode 100644 index fa30bdfffe..0000000000 --- a/docs/assets/js/plugins/jquery.ba-throttle-debounce.js +++ /dev/null @@ -1,252 +0,0 @@ -/*! - * jQuery throttle / debounce - v1.1 - 3/7/2010 - * http://benalman.com/projects/jquery-throttle-debounce-plugin/ - * - * Copyright (c) 2010 "Cowboy" Ben Alman - * Dual licensed under the MIT and GPL licenses. - * http://benalman.com/about/license/ - */ - -// Script: jQuery throttle / debounce: Sometimes, less is more! -// -// *Version: 1.1, Last updated: 3/7/2010* -// -// Project Home - http://benalman.com/projects/jquery-throttle-debounce-plugin/ -// GitHub - http://github.com/cowboy/jquery-throttle-debounce/ -// Source - http://github.com/cowboy/jquery-throttle-debounce/raw/master/jquery.ba-throttle-debounce.js -// (Minified) - http://github.com/cowboy/jquery-throttle-debounce/raw/master/jquery.ba-throttle-debounce.min.js (0.7kb) -// -// About: License -// -// Copyright (c) 2010 "Cowboy" Ben Alman, -// Dual licensed under the MIT and GPL licenses. -// http://benalman.com/about/license/ -// -// About: Examples -// -// These working examples, complete with fully commented code, illustrate a few -// ways in which this plugin can be used. -// -// Throttle - http://benalman.com/code/projects/jquery-throttle-debounce/examples/throttle/ -// Debounce - http://benalman.com/code/projects/jquery-throttle-debounce/examples/debounce/ -// -// About: Support and Testing -// -// Information about what version or versions of jQuery this plugin has been -// tested with, what browsers it has been tested in, and where the unit tests -// reside (so you can test it yourself). -// -// jQuery Versions - none, 1.3.2, 1.4.2 -// Browsers Tested - Internet Explorer 6-8, Firefox 2-3.6, Safari 3-4, Chrome 4-5, Opera 9.6-10.1. -// Unit Tests - http://benalman.com/code/projects/jquery-throttle-debounce/unit/ -// -// About: Release History -// -// 1.1 - (3/7/2010) Fixed a bug in where trailing callbacks -// executed later than they should. Reworked a fair amount of internal -// logic as well. -// 1.0 - (3/6/2010) Initial release as a stand-alone project. Migrated over -// from jquery-misc repo v0.4 to jquery-throttle repo v1.0, added the -// no_trailing throttle parameter and debounce functionality. -// -// Topic: Note for non-jQuery users -// -// jQuery isn't actually required for this plugin, because nothing internal -// uses any jQuery methods or properties. jQuery is just used as a namespace -// under which these methods can exist. -// -// Since jQuery isn't actually required for this plugin, if jQuery doesn't exist -// when this plugin is loaded, the method described below will be created in -// the `Cowboy` namespace. Usage will be exactly the same, but instead of -// $.method() or jQuery.method(), you'll need to use Cowboy.method(). - -(function(window,undefined){ - '$:nomunge'; // Used by YUI compressor. - - // Since jQuery really isn't required for this plugin, use `jQuery` as the - // namespace only if it already exists, otherwise use the `Cowboy` namespace, - // creating it if necessary. - var $ = window.jQuery || window.Cowboy || ( window.Cowboy = {} ), - - // Internal method reference. - jq_throttle; - - // Method: jQuery.throttle - // - // Throttle execution of a function. Especially useful for rate limiting - // execution of handlers on events like resize and scroll. If you want to - // rate-limit execution of a function to a single time, see the - // method. - // - // In this visualization, | is a throttled-function call and X is the actual - // callback execution: - // - // > Throttled with `no_trailing` specified as false or unspecified: - // > ||||||||||||||||||||||||| (pause) ||||||||||||||||||||||||| - // > X X X X X X X X X X X X - // > - // > Throttled with `no_trailing` specified as true: - // > ||||||||||||||||||||||||| (pause) ||||||||||||||||||||||||| - // > X X X X X X X X X X - // - // Usage: - // - // > var throttled = jQuery.throttle( delay, [ no_trailing, ] callback ); - // > - // > jQuery('selector').bind( 'someevent', throttled ); - // > jQuery('selector').unbind( 'someevent', throttled ); - // - // This also works in jQuery 1.4+: - // - // > jQuery('selector').bind( 'someevent', jQuery.throttle( delay, [ no_trailing, ] callback ) ); - // > jQuery('selector').unbind( 'someevent', callback ); - // - // Arguments: - // - // delay - (Number) A zero-or-greater delay in milliseconds. For event - // callbacks, values around 100 or 250 (or even higher) are most useful. - // no_trailing - (Boolean) Optional, defaults to false. If no_trailing is - // true, callback will only execute every `delay` milliseconds while the - // throttled-function is being called. If no_trailing is false or - // unspecified, callback will be executed one final time after the last - // throttled-function call. (After the throttled-function has not been - // called for `delay` milliseconds, the internal counter is reset) - // callback - (Function) A function to be executed after delay milliseconds. - // The `this` context and all arguments are passed through, as-is, to - // `callback` when the throttled-function is executed. - // - // Returns: - // - // (Function) A new, throttled, function. - - $.throttle = jq_throttle = function( delay, no_trailing, callback, debounce_mode ) { - // After wrapper has stopped being called, this timeout ensures that - // `callback` is executed at the proper times in `throttle` and `end` - // debounce modes. - var timeout_id, - - // Keep track of the last time `callback` was executed. - last_exec = 0; - - // `no_trailing` defaults to falsy. - if ( typeof no_trailing !== 'boolean' ) { - debounce_mode = callback; - callback = no_trailing; - no_trailing = undefined; - } - - // The `wrapper` function encapsulates all of the throttling / debouncing - // functionality and when executed will limit the rate at which `callback` - // is executed. - function wrapper() { - var that = this, - elapsed = +new Date() - last_exec, - args = arguments; - - // Execute `callback` and update the `last_exec` timestamp. - function exec() { - last_exec = +new Date(); - callback.apply( that, args ); - }; - - // If `debounce_mode` is true (at_begin) this is used to clear the flag - // to allow future `callback` executions. - function clear() { - timeout_id = undefined; - }; - - if ( debounce_mode && !timeout_id ) { - // Since `wrapper` is being called for the first time and - // `debounce_mode` is true (at_begin), execute `callback`. - exec(); - } - - // Clear any existing timeout. - timeout_id && clearTimeout( timeout_id ); - - if ( debounce_mode === undefined && elapsed > delay ) { - // In throttle mode, if `delay` time has been exceeded, execute - // `callback`. - exec(); - - } else if ( no_trailing !== true ) { - // In trailing throttle mode, since `delay` time has not been - // exceeded, schedule `callback` to execute `delay` ms after most - // recent execution. - // - // If `debounce_mode` is true (at_begin), schedule `clear` to execute - // after `delay` ms. - // - // If `debounce_mode` is false (at end), schedule `callback` to - // execute after `delay` ms. - timeout_id = setTimeout( debounce_mode ? clear : exec, debounce_mode === undefined ? delay - elapsed : delay ); - } - }; - - // Set the guid of `wrapper` function to the same of original callback, so - // it can be removed in jQuery 1.4+ .unbind or .die by using the original - // callback as a reference. - if ( $.guid ) { - wrapper.guid = callback.guid = callback.guid || $.guid++; - } - - // Return the wrapper function. - return wrapper; - }; - - // Method: jQuery.debounce - // - // Debounce execution of a function. Debouncing, unlike throttling, - // guarantees that a function is only executed a single time, either at the - // very beginning of a series of calls, or at the very end. If you want to - // simply rate-limit execution of a function, see the - // method. - // - // In this visualization, | is a debounced-function call and X is the actual - // callback execution: - // - // > Debounced with `at_begin` specified as false or unspecified: - // > ||||||||||||||||||||||||| (pause) ||||||||||||||||||||||||| - // > X X - // > - // > Debounced with `at_begin` specified as true: - // > ||||||||||||||||||||||||| (pause) ||||||||||||||||||||||||| - // > X X - // - // Usage: - // - // > var debounced = jQuery.debounce( delay, [ at_begin, ] callback ); - // > - // > jQuery('selector').bind( 'someevent', debounced ); - // > jQuery('selector').unbind( 'someevent', debounced ); - // - // This also works in jQuery 1.4+: - // - // > jQuery('selector').bind( 'someevent', jQuery.debounce( delay, [ at_begin, ] callback ) ); - // > jQuery('selector').unbind( 'someevent', callback ); - // - // Arguments: - // - // delay - (Number) A zero-or-greater delay in milliseconds. For event - // callbacks, values around 100 or 250 (or even higher) are most useful. - // at_begin - (Boolean) Optional, defaults to false. If at_begin is false or - // unspecified, callback will only be executed `delay` milliseconds after - // the last debounced-function call. If at_begin is true, callback will be - // executed only at the first debounced-function call. (After the - // throttled-function has not been called for `delay` milliseconds, the - // internal counter is reset) - // callback - (Function) A function to be executed after delay milliseconds. - // The `this` context and all arguments are passed through, as-is, to - // `callback` when the debounced-function is executed. - // - // Returns: - // - // (Function) A new, debounced, function. - - $.debounce = function( delay, at_begin, callback ) { - return callback === undefined - ? jq_throttle( delay, at_begin, false ) - : jq_throttle( delay, callback, at_begin !== false ); - }; - -})(this); diff --git a/docs/assets/js/plugins/jquery.fitvids.js b/docs/assets/js/plugins/jquery.fitvids.js deleted file mode 100644 index 5c2f85c992..0000000000 --- a/docs/assets/js/plugins/jquery.fitvids.js +++ /dev/null @@ -1,82 +0,0 @@ -/*jshint browser:true */ -/*! -* FitVids 1.1 -* -* Copyright 2013, Chris Coyier - http://css-tricks.com + Dave Rupert - http://daverupert.com -* Credit to Thierry Koblentz - http://www.alistapart.com/articles/creating-intrinsic-ratios-for-video/ -* Released under the WTFPL license - http://sam.zoy.org/wtfpl/ -* -*/ - -;(function( $ ){ - - 'use strict'; - - $.fn.fitVids = function( options ) { - var settings = { - customSelector: null, - ignore: null - }; - - if(!document.getElementById('fit-vids-style')) { - // appendStyles: https://github.com/toddmotto/fluidvids/blob/master/dist/fluidvids.js - var head = document.head || document.getElementsByTagName('head')[0]; - var css = '.fluid-width-video-wrapper{width:100%;position:relative;padding:0;}.fluid-width-video-wrapper iframe,.fluid-width-video-wrapper object,.fluid-width-video-wrapper embed {position:absolute;top:0;left:0;width:100%;height:100%;}'; - var div = document.createElement("div"); - div.innerHTML = '

x

'; - head.appendChild(div.childNodes[1]); - } - - if ( options ) { - $.extend( settings, options ); - } - - return this.each(function(){ - var selectors = [ - 'iframe[src*="player.vimeo.com"]', - 'iframe[src*="youtube.com"]', - 'iframe[src*="youtube-nocookie.com"]', - 'iframe[src*="kickstarter.com"][src*="video.html"]', - 'object', - 'embed' - ]; - - if (settings.customSelector) { - selectors.push(settings.customSelector); - } - - var ignoreList = '.fitvidsignore'; - - if(settings.ignore) { - ignoreList = ignoreList + ', ' + settings.ignore; - } - - var $allVideos = $(this).find(selectors.join(',')); - $allVideos = $allVideos.not('object object'); // SwfObj conflict patch - $allVideos = $allVideos.not(ignoreList); // Disable FitVids on this video. - - $allVideos.each(function(count){ - var $this = $(this); - if($this.parents(ignoreList).length > 0) { - return; // Disable FitVids on this video. - } - if (this.tagName.toLowerCase() === 'embed' && $this.parent('object').length || $this.parent('.fluid-width-video-wrapper').length) { return; } - if ((!$this.css('height') && !$this.css('width')) && (isNaN($this.attr('height')) || isNaN($this.attr('width')))) - { - $this.attr('height', 9); - $this.attr('width', 16); - } - var height = ( this.tagName.toLowerCase() === 'object' || ($this.attr('height') && !isNaN(parseInt($this.attr('height'), 10))) ) ? parseInt($this.attr('height'), 10) : $this.height(), - width = !isNaN(parseInt($this.attr('width'), 10)) ? parseInt($this.attr('width'), 10) : $this.width(), - aspectRatio = height / width; - if(!$this.attr('id')){ - var videoID = 'fitvid' + count; - $this.attr('id', videoID); - } - $this.wrap('
').parent('.fluid-width-video-wrapper').css('padding-top', (aspectRatio * 100)+'%'); - $this.removeAttr('height').removeAttr('width'); - }); - }); - }; -// Works with either jQuery or Zepto -})( window.jQuery || window.Zepto ); \ No newline at end of file diff --git a/docs/assets/js/plugins/jquery.greedy-navigation.js b/docs/assets/js/plugins/jquery.greedy-navigation.js deleted file mode 100644 index d8f323788b..0000000000 --- a/docs/assets/js/plugins/jquery.greedy-navigation.js +++ /dev/null @@ -1,127 +0,0 @@ -/* -GreedyNav.js - http://lukejacksonn.com/actuate -Licensed under the MIT license - http://opensource.org/licenses/MIT -Copyright (c) 2015 Luke Jackson -*/ - -$(function() { - - var $btn = $("nav.greedy-nav .greedy-nav__toggle"); - var $vlinks = $("nav.greedy-nav .visible-links"); - var $hlinks = $("nav.greedy-nav .hidden-links"); - var $nav = $("nav.greedy-nav"); - var $logo = $('nav.greedy-nav .site-logo'); - var $logoImg = $('nav.greedy-nav .site-logo img'); - var $title = $("nav.greedy-nav .site-title"); - var $search = $('nav.greedy-nav button.search__toggle'); - - var numOfItems, totalSpace, closingTime, breakWidths; - - // This function measures both hidden and visible links and sets the navbar breakpoints - // This is called the first time the script runs and everytime the "check()" function detects a change of window width that reached a different CSS width breakpoint, which affects the size of navbar Items - // Please note that "CSS width breakpoints" (which are only 4) !== "navbar breakpoints" (which are as many as the number of items on the navbar) - function measureLinks(){ - numOfItems = 0; - totalSpace = 0; - closingTime = 1000; - breakWidths = []; - - // Adds the width of a navItem in order to create breakpoints for the navbar - function addWidth(i, w) { - totalSpace += w; - numOfItems += 1; - breakWidths.push(totalSpace); - } - - // Measures the width of hidden links by making a temporary clone of them and positioning under visible links - function hiddenWidth(obj){ - var clone = obj.clone(); - clone.css("visibility","hidden"); - $vlinks.append(clone); - addWidth(0, clone.outerWidth()); - clone.remove(); - } - // Measure both visible and hidden links widths - $vlinks.children().outerWidth(addWidth); - $hlinks.children().each(function(){hiddenWidth($(this))}); - } - // Get initial state - measureLinks(); - - var winWidth = $( window ).width(); - // Set the last measured CSS width breakpoint: 0: <768px, 1: <1024px, 2: < 1280px, 3: >= 1280px. - var lastBreakpoint = winWidth < 768 ? 0 : winWidth < 1024 ? 1 : winWidth < 1280 ? 2 : 3; - - var availableSpace, numOfVisibleItems, requiredSpace, timer; - - function check() { - - winWidth = $( window ).width(); - // Set the current CSS width breakpoint: 0: <768px, 1: <1024px, 2: < 1280px, 3: >= 1280px. - var curBreakpoint = winWidth < 768 ? 0 : winWidth < 1024 ? 1 : winWidth < 1280 ? 2 : 3; - // If current breakpoint is different from last measured breakpoint, measureLinks again - if(curBreakpoint !== lastBreakpoint) measureLinks(); - // Set the last measured CSS width breakpoint with the current breakpoint - lastBreakpoint = curBreakpoint; - - // Get instant state - numOfVisibleItems = $vlinks.children().length; - // Decrease the width of visible elements from the nav innerWidth to find out the available space for navItems - availableSpace = /* nav */ $nav.innerWidth() - - /* logo */ ($logo.length !== 0 ? $logo.outerWidth(true) : 0) - - /* title */ $title.outerWidth(true) - - /* search */ ($search.length !== 0 ? $search.outerWidth(true) : 0) - - /* toggle */ (numOfVisibleItems !== breakWidths.length ? $btn.outerWidth(true) : 0); - requiredSpace = breakWidths[numOfVisibleItems - 1]; - - // There is not enought space - if (requiredSpace > availableSpace) { - $vlinks.children().last().prependTo($hlinks); - numOfVisibleItems -= 1; - check(); - // There is more than enough space. If only one element is hidden, add the toggle width to the available space - } else if (availableSpace + (numOfVisibleItems === breakWidths.length - 1?$btn.outerWidth(true):0) > breakWidths[numOfVisibleItems]) { - $hlinks.children().first().appendTo($vlinks); - numOfVisibleItems += 1; - check(); - } - // Update the button accordingly - $btn.attr("count", numOfItems - numOfVisibleItems); - if (numOfVisibleItems === numOfItems) { - $btn.addClass('hidden'); - } else $btn.removeClass('hidden'); - } - - // Window listeners - $(window).resize(function() { - check(); - }); - - $btn.on('click', function() { - $hlinks.toggleClass('hidden'); - $(this).toggleClass('close'); - clearTimeout(timer); - }); - - $hlinks.on('mouseleave', function() { - // Mouse has left, start the timer - timer = setTimeout(function() { - $hlinks.addClass('hidden'); - }, closingTime); - }).on('mouseenter', function() { - // Mouse is back, cancel the timer - clearTimeout(timer); - }) - - // check if page has a logo - if($logoImg.length !== 0){ - // check if logo is not loaded - if(!($logoImg[0].complete || $logoImg[0].naturalWidth !== 0)){ - // if logo is not loaded wait for logo to load or fail to check - $logoImg.one("load error", check); - // if logo is already loaded just check - } else check(); - // if page does not have a logo just check - } else check(); - -}); diff --git a/docs/assets/js/plugins/jquery.magnific-popup.js b/docs/assets/js/plugins/jquery.magnific-popup.js deleted file mode 100644 index 7d1d197849..0000000000 --- a/docs/assets/js/plugins/jquery.magnific-popup.js +++ /dev/null @@ -1,1860 +0,0 @@ -/*! Magnific Popup - v1.1.0 - 2016-02-20 -* http://dimsemenov.com/plugins/magnific-popup/ -* Copyright (c) 2016 Dmitry Semenov; */ -;(function (factory) { - if (typeof define === 'function' && define.amd) { - // AMD. Register as an anonymous module. - define(['jquery'], factory); - } else if (typeof exports === 'object') { - // Node/CommonJS - factory(require('jquery')); - } else { - // Browser globals - factory(window.jQuery || window.Zepto); - } - }(function($) { - - /*>>core*/ - /** - * - * Magnific Popup Core JS file - * - */ - - - /** - * Private static constants - */ - var CLOSE_EVENT = 'Close', - BEFORE_CLOSE_EVENT = 'BeforeClose', - AFTER_CLOSE_EVENT = 'AfterClose', - BEFORE_APPEND_EVENT = 'BeforeAppend', - MARKUP_PARSE_EVENT = 'MarkupParse', - OPEN_EVENT = 'Open', - CHANGE_EVENT = 'Change', - NS = 'mfp', - EVENT_NS = '.' + NS, - READY_CLASS = 'mfp-ready', - REMOVING_CLASS = 'mfp-removing', - PREVENT_CLOSE_CLASS = 'mfp-prevent-close'; - - - /** - * Private vars - */ - /*jshint -W079 */ - var mfp, // As we have only one instance of MagnificPopup object, we define it locally to not to use 'this' - MagnificPopup = function(){}, - _isJQ = !!(window.jQuery), - _prevStatus, - _window = $(window), - _document, - _prevContentType, - _wrapClasses, - _currPopupType; - - - /** - * Private functions - */ - var _mfpOn = function(name, f) { - mfp.ev.on(NS + name + EVENT_NS, f); - }, - _getEl = function(className, appendTo, html, raw) { - var el = document.createElement('div'); - el.className = 'mfp-'+className; - if(html) { - el.innerHTML = html; - } - if(!raw) { - el = $(el); - if(appendTo) { - el.appendTo(appendTo); - } - } else if(appendTo) { - appendTo.appendChild(el); - } - return el; - }, - _mfpTrigger = function(e, data) { - mfp.ev.triggerHandler(NS + e, data); - - if(mfp.st.callbacks) { - // converts "mfpEventName" to "eventName" callback and triggers it if it's present - e = e.charAt(0).toLowerCase() + e.slice(1); - if(mfp.st.callbacks[e]) { - mfp.st.callbacks[e].apply(mfp, $.isArray(data) ? data : [data]); - } - } - }, - _getCloseBtn = function(type) { - if(type !== _currPopupType || !mfp.currTemplate.closeBtn) { - mfp.currTemplate.closeBtn = $( mfp.st.closeMarkup.replace('%title%', mfp.st.tClose ) ); - _currPopupType = type; - } - return mfp.currTemplate.closeBtn; - }, - // Initialize Magnific Popup only when called at least once - _checkInstance = function() { - if(!$.magnificPopup.instance) { - /*jshint -W020 */ - mfp = new MagnificPopup(); - mfp.init(); - $.magnificPopup.instance = mfp; - } - }, - // CSS transition detection, http://stackoverflow.com/questions/7264899/detect-css-transitions-using-javascript-and-without-modernizr - supportsTransitions = function() { - var s = document.createElement('p').style, // 's' for style. better to create an element if body yet to exist - v = ['ms','O','Moz','Webkit']; // 'v' for vendor - - if( s['transition'] !== undefined ) { - return true; - } - - while( v.length ) { - if( v.pop() + 'Transition' in s ) { - return true; - } - } - - return false; - }; - - - - /** - * Public functions - */ - MagnificPopup.prototype = { - - constructor: MagnificPopup, - - /** - * Initializes Magnific Popup plugin. - * This function is triggered only once when $.fn.magnificPopup or $.magnificPopup is executed - */ - init: function() { - var appVersion = navigator.appVersion; - mfp.isLowIE = mfp.isIE8 = document.all && !document.addEventListener; - mfp.isAndroid = (/android/gi).test(appVersion); - mfp.isIOS = (/iphone|ipad|ipod/gi).test(appVersion); - mfp.supportsTransition = supportsTransitions(); - - // We disable fixed positioned lightbox on devices that don't handle it nicely. - // If you know a better way of detecting this - let me know. - mfp.probablyMobile = (mfp.isAndroid || mfp.isIOS || /(Opera Mini)|Kindle|webOS|BlackBerry|(Opera Mobi)|(Windows Phone)|IEMobile/i.test(navigator.userAgent) ); - _document = $(document); - - mfp.popupsCache = {}; - }, - - /** - * Opens popup - * @param data [description] - */ - open: function(data) { - - var i; - - if(data.isObj === false) { - // convert jQuery collection to array to avoid conflicts later - mfp.items = data.items.toArray(); - - mfp.index = 0; - var items = data.items, - item; - for(i = 0; i < items.length; i++) { - item = items[i]; - if(item.parsed) { - item = item.el[0]; - } - if(item === data.el[0]) { - mfp.index = i; - break; - } - } - } else { - mfp.items = $.isArray(data.items) ? data.items : [data.items]; - mfp.index = data.index || 0; - } - - // if popup is already opened - we just update the content - if(mfp.isOpen) { - mfp.updateItemHTML(); - return; - } - - mfp.types = []; - _wrapClasses = ''; - if(data.mainEl && data.mainEl.length) { - mfp.ev = data.mainEl.eq(0); - } else { - mfp.ev = _document; - } - - if(data.key) { - if(!mfp.popupsCache[data.key]) { - mfp.popupsCache[data.key] = {}; - } - mfp.currTemplate = mfp.popupsCache[data.key]; - } else { - mfp.currTemplate = {}; - } - - - - mfp.st = $.extend(true, {}, $.magnificPopup.defaults, data ); - mfp.fixedContentPos = mfp.st.fixedContentPos === 'auto' ? !mfp.probablyMobile : mfp.st.fixedContentPos; - - if(mfp.st.modal) { - mfp.st.closeOnContentClick = false; - mfp.st.closeOnBgClick = false; - mfp.st.showCloseBtn = false; - mfp.st.enableEscapeKey = false; - } - - - // Building markup - // main containers are created only once - if(!mfp.bgOverlay) { - - // Dark overlay - mfp.bgOverlay = _getEl('bg').on('click'+EVENT_NS, function() { - mfp.close(); - }); - - mfp.wrap = _getEl('wrap').attr('tabindex', -1).on('click'+EVENT_NS, function(e) { - if(mfp._checkIfClose(e.target)) { - mfp.close(); - } - }); - - mfp.container = _getEl('container', mfp.wrap); - } - - mfp.contentContainer = _getEl('content'); - if(mfp.st.preloader) { - mfp.preloader = _getEl('preloader', mfp.container, mfp.st.tLoading); - } - - - // Initializing modules - var modules = $.magnificPopup.modules; - for(i = 0; i < modules.length; i++) { - var n = modules[i]; - n = n.charAt(0).toUpperCase() + n.slice(1); - mfp['init'+n].call(mfp); - } - _mfpTrigger('BeforeOpen'); - - - if(mfp.st.showCloseBtn) { - // Close button - if(!mfp.st.closeBtnInside) { - mfp.wrap.append( _getCloseBtn() ); - } else { - _mfpOn(MARKUP_PARSE_EVENT, function(e, template, values, item) { - values.close_replaceWith = _getCloseBtn(item.type); - }); - _wrapClasses += ' mfp-close-btn-in'; - } - } - - if(mfp.st.alignTop) { - _wrapClasses += ' mfp-align-top'; - } - - - - if(mfp.fixedContentPos) { - mfp.wrap.css({ - overflow: mfp.st.overflowY, - overflowX: 'hidden', - overflowY: mfp.st.overflowY - }); - } else { - mfp.wrap.css({ - top: _window.scrollTop(), - position: 'absolute' - }); - } - if( mfp.st.fixedBgPos === false || (mfp.st.fixedBgPos === 'auto' && !mfp.fixedContentPos) ) { - mfp.bgOverlay.css({ - height: _document.height(), - position: 'absolute' - }); - } - - - - if(mfp.st.enableEscapeKey) { - // Close on ESC key - _document.on('keyup' + EVENT_NS, function(e) { - if(e.keyCode === 27) { - mfp.close(); - } - }); - } - - _window.on('resize' + EVENT_NS, function() { - mfp.updateSize(); - }); - - - if(!mfp.st.closeOnContentClick) { - _wrapClasses += ' mfp-auto-cursor'; - } - - if(_wrapClasses) - mfp.wrap.addClass(_wrapClasses); - - - // this triggers recalculation of layout, so we get it once to not to trigger twice - var windowHeight = mfp.wH = _window.height(); - - - var windowStyles = {}; - - if( mfp.fixedContentPos ) { - if(mfp._hasScrollBar(windowHeight)){ - var s = mfp._getScrollbarSize(); - if(s) { - windowStyles.marginRight = s; - } - } - } - - if(mfp.fixedContentPos) { - if(!mfp.isIE7) { - windowStyles.overflow = 'hidden'; - } else { - // ie7 double-scroll bug - $('body, html').css('overflow', 'hidden'); - } - } - - - - var classesToadd = mfp.st.mainClass; - if(mfp.isIE7) { - classesToadd += ' mfp-ie7'; - } - if(classesToadd) { - mfp._addClassToMFP( classesToadd ); - } - - // add content - mfp.updateItemHTML(); - - _mfpTrigger('BuildControls'); - - // remove scrollbar, add margin e.t.c - $('html').css(windowStyles); - - // add everything to DOM - mfp.bgOverlay.add(mfp.wrap).prependTo( mfp.st.prependTo || $(document.body) ); - - // Save last focused element - mfp._lastFocusedEl = document.activeElement; - - // Wait for next cycle to allow CSS transition - setTimeout(function() { - - if(mfp.content) { - mfp._addClassToMFP(READY_CLASS); - mfp._setFocus(); - } else { - // if content is not defined (not loaded e.t.c) we add class only for BG - mfp.bgOverlay.addClass(READY_CLASS); - } - - // Trap the focus in popup - _document.on('focusin' + EVENT_NS, mfp._onFocusIn); - - }, 16); - - mfp.isOpen = true; - mfp.updateSize(windowHeight); - _mfpTrigger(OPEN_EVENT); - - return data; - }, - - /** - * Closes the popup - */ - close: function() { - if(!mfp.isOpen) return; - _mfpTrigger(BEFORE_CLOSE_EVENT); - - mfp.isOpen = false; - // for CSS3 animation - if(mfp.st.removalDelay && !mfp.isLowIE && mfp.supportsTransition ) { - mfp._addClassToMFP(REMOVING_CLASS); - setTimeout(function() { - mfp._close(); - }, mfp.st.removalDelay); - } else { - mfp._close(); - } - }, - - /** - * Helper for close() function - */ - _close: function() { - _mfpTrigger(CLOSE_EVENT); - - var classesToRemove = REMOVING_CLASS + ' ' + READY_CLASS + ' '; - - mfp.bgOverlay.detach(); - mfp.wrap.detach(); - mfp.container.empty(); - - if(mfp.st.mainClass) { - classesToRemove += mfp.st.mainClass + ' '; - } - - mfp._removeClassFromMFP(classesToRemove); - - if(mfp.fixedContentPos) { - var windowStyles = {marginRight: ''}; - if(mfp.isIE7) { - $('body, html').css('overflow', ''); - } else { - windowStyles.overflow = ''; - } - $('html').css(windowStyles); - } - - _document.off('keyup' + EVENT_NS + ' focusin' + EVENT_NS); - mfp.ev.off(EVENT_NS); - - // clean up DOM elements that aren't removed - mfp.wrap.attr('class', 'mfp-wrap').removeAttr('style'); - mfp.bgOverlay.attr('class', 'mfp-bg'); - mfp.container.attr('class', 'mfp-container'); - - // remove close button from target element - if(mfp.st.showCloseBtn && - (!mfp.st.closeBtnInside || mfp.currTemplate[mfp.currItem.type] === true)) { - if(mfp.currTemplate.closeBtn) - mfp.currTemplate.closeBtn.detach(); - } - - - if(mfp.st.autoFocusLast && mfp._lastFocusedEl) { - $(mfp._lastFocusedEl).focus(); // put tab focus back - } - mfp.currItem = null; - mfp.content = null; - mfp.currTemplate = null; - mfp.prevHeight = 0; - - _mfpTrigger(AFTER_CLOSE_EVENT); - }, - - updateSize: function(winHeight) { - - if(mfp.isIOS) { - // fixes iOS nav bars https://github.com/dimsemenov/Magnific-Popup/issues/2 - var zoomLevel = document.documentElement.clientWidth / window.innerWidth; - var height = window.innerHeight * zoomLevel; - mfp.wrap.css('height', height); - mfp.wH = height; - } else { - mfp.wH = winHeight || _window.height(); - } - // Fixes #84: popup incorrectly positioned with position:relative on body - if(!mfp.fixedContentPos) { - mfp.wrap.css('height', mfp.wH); - } - - _mfpTrigger('Resize'); - - }, - - /** - * Set content of popup based on current index - */ - updateItemHTML: function() { - var item = mfp.items[mfp.index]; - - // Detach and perform modifications - mfp.contentContainer.detach(); - - if(mfp.content) - mfp.content.detach(); - - if(!item.parsed) { - item = mfp.parseEl( mfp.index ); - } - - var type = item.type; - - _mfpTrigger('BeforeChange', [mfp.currItem ? mfp.currItem.type : '', type]); - // BeforeChange event works like so: - // _mfpOn('BeforeChange', function(e, prevType, newType) { }); - - mfp.currItem = item; - - if(!mfp.currTemplate[type]) { - var markup = mfp.st[type] ? mfp.st[type].markup : false; - - // allows to modify markup - _mfpTrigger('FirstMarkupParse', markup); - - if(markup) { - mfp.currTemplate[type] = $(markup); - } else { - // if there is no markup found we just define that template is parsed - mfp.currTemplate[type] = true; - } - } - - if(_prevContentType && _prevContentType !== item.type) { - mfp.container.removeClass('mfp-'+_prevContentType+'-holder'); - } - - var newContent = mfp['get' + type.charAt(0).toUpperCase() + type.slice(1)](item, mfp.currTemplate[type]); - mfp.appendContent(newContent, type); - - item.preloaded = true; - - _mfpTrigger(CHANGE_EVENT, item); - _prevContentType = item.type; - - // Append container back after its content changed - mfp.container.prepend(mfp.contentContainer); - - _mfpTrigger('AfterChange'); - }, - - - /** - * Set HTML content of popup - */ - appendContent: function(newContent, type) { - mfp.content = newContent; - - if(newContent) { - if(mfp.st.showCloseBtn && mfp.st.closeBtnInside && - mfp.currTemplate[type] === true) { - // if there is no markup, we just append close button element inside - if(!mfp.content.find('.mfp-close').length) { - mfp.content.append(_getCloseBtn()); - } - } else { - mfp.content = newContent; - } - } else { - mfp.content = ''; - } - - _mfpTrigger(BEFORE_APPEND_EVENT); - mfp.container.addClass('mfp-'+type+'-holder'); - - mfp.contentContainer.append(mfp.content); - }, - - - /** - * Creates Magnific Popup data object based on given data - * @param {int} index Index of item to parse - */ - parseEl: function(index) { - var item = mfp.items[index], - type; - - if(item.tagName) { - item = { el: $(item) }; - } else { - type = item.type; - item = { data: item, src: item.src }; - } - - if(item.el) { - var types = mfp.types; - - // check for 'mfp-TYPE' class - for(var i = 0; i < types.length; i++) { - if( item.el.hasClass('mfp-'+types[i]) ) { - type = types[i]; - break; - } - } - - item.src = item.el.attr('data-mfp-src'); - if(!item.src) { - item.src = item.el.attr('href'); - } - } - - item.type = type || mfp.st.type || 'inline'; - item.index = index; - item.parsed = true; - mfp.items[index] = item; - _mfpTrigger('ElementParse', item); - - return mfp.items[index]; - }, - - - /** - * Initializes single popup or a group of popups - */ - addGroup: function(el, options) { - var eHandler = function(e) { - e.mfpEl = this; - mfp._openClick(e, el, options); - }; - - if(!options) { - options = {}; - } - - var eName = 'click.magnificPopup'; - options.mainEl = el; - - if(options.items) { - options.isObj = true; - el.off(eName).on(eName, eHandler); - } else { - options.isObj = false; - if(options.delegate) { - el.off(eName).on(eName, options.delegate , eHandler); - } else { - options.items = el; - el.off(eName).on(eName, eHandler); - } - } - }, - _openClick: function(e, el, options) { - var midClick = options.midClick !== undefined ? options.midClick : $.magnificPopup.defaults.midClick; - - - if(!midClick && ( e.which === 2 || e.ctrlKey || e.metaKey || e.altKey || e.shiftKey ) ) { - return; - } - - var disableOn = options.disableOn !== undefined ? options.disableOn : $.magnificPopup.defaults.disableOn; - - if(disableOn) { - if($.isFunction(disableOn)) { - if( !disableOn.call(mfp) ) { - return true; - } - } else { // else it's number - if( _window.width() < disableOn ) { - return true; - } - } - } - - if(e.type) { - e.preventDefault(); - - // This will prevent popup from closing if element is inside and popup is already opened - if(mfp.isOpen) { - e.stopPropagation(); - } - } - - options.el = $(e.mfpEl); - if(options.delegate) { - options.items = el.find(options.delegate); - } - mfp.open(options); - }, - - - /** - * Updates text on preloader - */ - updateStatus: function(status, text) { - - if(mfp.preloader) { - if(_prevStatus !== status) { - mfp.container.removeClass('mfp-s-'+_prevStatus); - } - - if(!text && status === 'loading') { - text = mfp.st.tLoading; - } - - var data = { - status: status, - text: text - }; - // allows to modify status - _mfpTrigger('UpdateStatus', data); - - status = data.status; - text = data.text; - - mfp.preloader.html(text); - - mfp.preloader.find('a').on('click', function(e) { - e.stopImmediatePropagation(); - }); - - mfp.container.addClass('mfp-s-'+status); - _prevStatus = status; - } - }, - - - /* - "Private" helpers that aren't private at all - */ - // Check to close popup or not - // "target" is an element that was clicked - _checkIfClose: function(target) { - - if($(target).hasClass(PREVENT_CLOSE_CLASS)) { - return; - } - - var closeOnContent = mfp.st.closeOnContentClick; - var closeOnBg = mfp.st.closeOnBgClick; - - if(closeOnContent && closeOnBg) { - return true; - } else { - - // We close the popup if click is on close button or on preloader. Or if there is no content. - if(!mfp.content || $(target).hasClass('mfp-close') || (mfp.preloader && target === mfp.preloader[0]) ) { - return true; - } - - // if click is outside the content - if( (target !== mfp.content[0] && !$.contains(mfp.content[0], target)) ) { - if(closeOnBg) { - // last check, if the clicked element is in DOM, (in case it's removed onclick) - if( $.contains(document, target) ) { - return true; - } - } - } else if(closeOnContent) { - return true; - } - - } - return false; - }, - _addClassToMFP: function(cName) { - mfp.bgOverlay.addClass(cName); - mfp.wrap.addClass(cName); - }, - _removeClassFromMFP: function(cName) { - this.bgOverlay.removeClass(cName); - mfp.wrap.removeClass(cName); - }, - _hasScrollBar: function(winHeight) { - return ( (mfp.isIE7 ? _document.height() : document.body.scrollHeight) > (winHeight || _window.height()) ); - }, - _setFocus: function() { - (mfp.st.focus ? mfp.content.find(mfp.st.focus).eq(0) : mfp.wrap).focus(); - }, - _onFocusIn: function(e) { - if( e.target !== mfp.wrap[0] && !$.contains(mfp.wrap[0], e.target) ) { - mfp._setFocus(); - return false; - } - }, - _parseMarkup: function(template, values, item) { - var arr; - if(item.data) { - values = $.extend(item.data, values); - } - _mfpTrigger(MARKUP_PARSE_EVENT, [template, values, item] ); - - $.each(values, function(key, value) { - if(value === undefined || value === false) { - return true; - } - arr = key.split('_'); - if(arr.length > 1) { - var el = template.find(EVENT_NS + '-'+arr[0]); - - if(el.length > 0) { - var attr = arr[1]; - if(attr === 'replaceWith') { - if(el[0] !== value[0]) { - el.replaceWith(value); - } - } else if(attr === 'img') { - if(el.is('img')) { - el.attr('src', value); - } else { - el.replaceWith( $('').attr('src', value).attr('class', el.attr('class')) ); - } - } else { - el.attr(arr[1], value); - } - } - - } else { - template.find(EVENT_NS + '-'+key).html(value); - } - }); - }, - - _getScrollbarSize: function() { - // thx David - if(mfp.scrollbarSize === undefined) { - var scrollDiv = document.createElement("div"); - scrollDiv.style.cssText = 'width: 99px; height: 99px; overflow: scroll; position: absolute; top: -9999px;'; - document.body.appendChild(scrollDiv); - mfp.scrollbarSize = scrollDiv.offsetWidth - scrollDiv.clientWidth; - document.body.removeChild(scrollDiv); - } - return mfp.scrollbarSize; - } - - }; /* MagnificPopup core prototype end */ - - - - - /** - * Public static functions - */ - $.magnificPopup = { - instance: null, - proto: MagnificPopup.prototype, - modules: [], - - open: function(options, index) { - _checkInstance(); - - if(!options) { - options = {}; - } else { - options = $.extend(true, {}, options); - } - - options.isObj = true; - options.index = index || 0; - return this.instance.open(options); - }, - - close: function() { - return $.magnificPopup.instance && $.magnificPopup.instance.close(); - }, - - registerModule: function(name, module) { - if(module.options) { - $.magnificPopup.defaults[name] = module.options; - } - $.extend(this.proto, module.proto); - this.modules.push(name); - }, - - defaults: { - - // Info about options is in docs: - // http://dimsemenov.com/plugins/magnific-popup/documentation.html#options - - disableOn: 0, - - key: null, - - midClick: false, - - mainClass: '', - - preloader: true, - - focus: '', // CSS selector of input to focus after popup is opened - - closeOnContentClick: false, - - closeOnBgClick: true, - - closeBtnInside: true, - - showCloseBtn: true, - - enableEscapeKey: true, - - modal: false, - - alignTop: false, - - removalDelay: 0, - - prependTo: null, - - fixedContentPos: 'auto', - - fixedBgPos: 'auto', - - overflowY: 'auto', - - closeMarkup: '', - - tClose: 'Close (Esc)', - - tLoading: 'Loading...', - - autoFocusLast: true - - } - }; - - - - $.fn.magnificPopup = function(options) { - _checkInstance(); - - var jqEl = $(this); - - // We call some API method of first param is a string - if (typeof options === "string" ) { - - if(options === 'open') { - var items, - itemOpts = _isJQ ? jqEl.data('magnificPopup') : jqEl[0].magnificPopup, - index = parseInt(arguments[1], 10) || 0; - - if(itemOpts.items) { - items = itemOpts.items[index]; - } else { - items = jqEl; - if(itemOpts.delegate) { - items = items.find(itemOpts.delegate); - } - items = items.eq( index ); - } - mfp._openClick({mfpEl:items}, jqEl, itemOpts); - } else { - if(mfp.isOpen) - mfp[options].apply(mfp, Array.prototype.slice.call(arguments, 1)); - } - - } else { - // clone options obj - options = $.extend(true, {}, options); - - /* - * As Zepto doesn't support .data() method for objects - * and it works only in normal browsers - * we assign "options" object directly to the DOM element. FTW! - */ - if(_isJQ) { - jqEl.data('magnificPopup', options); - } else { - jqEl[0].magnificPopup = options; - } - - mfp.addGroup(jqEl, options); - - } - return jqEl; - }; - - /*>>core*/ - - /*>>inline*/ - - var INLINE_NS = 'inline', - _hiddenClass, - _inlinePlaceholder, - _lastInlineElement, - _putInlineElementsBack = function() { - if(_lastInlineElement) { - _inlinePlaceholder.after( _lastInlineElement.addClass(_hiddenClass) ).detach(); - _lastInlineElement = null; - } - }; - - $.magnificPopup.registerModule(INLINE_NS, { - options: { - hiddenClass: 'hide', // will be appended with `mfp-` prefix - markup: '', - tNotFound: 'Content not found' - }, - proto: { - - initInline: function() { - mfp.types.push(INLINE_NS); - - _mfpOn(CLOSE_EVENT+'.'+INLINE_NS, function() { - _putInlineElementsBack(); - }); - }, - - getInline: function(item, template) { - - _putInlineElementsBack(); - - if(item.src) { - var inlineSt = mfp.st.inline, - el = $(item.src); - - if(el.length) { - - // If target element has parent - we replace it with placeholder and put it back after popup is closed - var parent = el[0].parentNode; - if(parent && parent.tagName) { - if(!_inlinePlaceholder) { - _hiddenClass = inlineSt.hiddenClass; - _inlinePlaceholder = _getEl(_hiddenClass); - _hiddenClass = 'mfp-'+_hiddenClass; - } - // replace target inline element with placeholder - _lastInlineElement = el.after(_inlinePlaceholder).detach().removeClass(_hiddenClass); - } - - mfp.updateStatus('ready'); - } else { - mfp.updateStatus('error', inlineSt.tNotFound); - el = $('
'); - } - - item.inlineElement = el; - return el; - } - - mfp.updateStatus('ready'); - mfp._parseMarkup(template, {}, item); - return template; - } - } - }); - - /*>>inline*/ - - /*>>ajax*/ - var AJAX_NS = 'ajax', - _ajaxCur, - _removeAjaxCursor = function() { - if(_ajaxCur) { - $(document.body).removeClass(_ajaxCur); - } - }, - _destroyAjaxRequest = function() { - _removeAjaxCursor(); - if(mfp.req) { - mfp.req.abort(); - } - }; - - $.magnificPopup.registerModule(AJAX_NS, { - - options: { - settings: null, - cursor: 'mfp-ajax-cur', - tError: 'The content could not be loaded.' - }, - - proto: { - initAjax: function() { - mfp.types.push(AJAX_NS); - _ajaxCur = mfp.st.ajax.cursor; - - _mfpOn(CLOSE_EVENT+'.'+AJAX_NS, _destroyAjaxRequest); - _mfpOn('BeforeChange.' + AJAX_NS, _destroyAjaxRequest); - }, - getAjax: function(item) { - - if(_ajaxCur) { - $(document.body).addClass(_ajaxCur); - } - - mfp.updateStatus('loading'); - - var opts = $.extend({ - url: item.src, - success: function(data, textStatus, jqXHR) { - var temp = { - data:data, - xhr:jqXHR - }; - - _mfpTrigger('ParseAjax', temp); - - mfp.appendContent( $(temp.data), AJAX_NS ); - - item.finished = true; - - _removeAjaxCursor(); - - mfp._setFocus(); - - setTimeout(function() { - mfp.wrap.addClass(READY_CLASS); - }, 16); - - mfp.updateStatus('ready'); - - _mfpTrigger('AjaxContentAdded'); - }, - error: function() { - _removeAjaxCursor(); - item.finished = item.loadError = true; - mfp.updateStatus('error', mfp.st.ajax.tError.replace('%url%', item.src)); - } - }, mfp.st.ajax.settings); - - mfp.req = $.ajax(opts); - - return ''; - } - } - }); - - /*>>ajax*/ - - /*>>image*/ - var _imgInterval, - _getTitle = function(item) { - if(item.data && item.data.title !== undefined) - return item.data.title; - - var src = mfp.st.image.titleSrc; - - if(src) { - if($.isFunction(src)) { - return src.call(mfp, item); - } else if(item.el) { - return item.el.attr(src) || ''; - } - } - return ''; - }; - - $.magnificPopup.registerModule('image', { - - options: { - markup: '
'+ - '
'+ - '
'+ - '
'+ - '
'+ - '
'+ - '
'+ - '
'+ - '
'+ - '
'+ - '
'+ - '
', - cursor: 'mfp-zoom-out-cur', - titleSrc: 'title', - verticalFit: true, - tError: 'The image could not be loaded.' - }, - - proto: { - initImage: function() { - var imgSt = mfp.st.image, - ns = '.image'; - - mfp.types.push('image'); - - _mfpOn(OPEN_EVENT+ns, function() { - if(mfp.currItem.type === 'image' && imgSt.cursor) { - $(document.body).addClass(imgSt.cursor); - } - }); - - _mfpOn(CLOSE_EVENT+ns, function() { - if(imgSt.cursor) { - $(document.body).removeClass(imgSt.cursor); - } - _window.off('resize' + EVENT_NS); - }); - - _mfpOn('Resize'+ns, mfp.resizeImage); - if(mfp.isLowIE) { - _mfpOn('AfterChange', mfp.resizeImage); - } - }, - resizeImage: function() { - var item = mfp.currItem; - if(!item || !item.img) return; - - if(mfp.st.image.verticalFit) { - var decr = 0; - // fix box-sizing in ie7/8 - if(mfp.isLowIE) { - decr = parseInt(item.img.css('padding-top'), 10) + parseInt(item.img.css('padding-bottom'),10); - } - item.img.css('max-height', mfp.wH-decr); - } - }, - _onImageHasSize: function(item) { - if(item.img) { - - item.hasSize = true; - - if(_imgInterval) { - clearInterval(_imgInterval); - } - - item.isCheckingImgSize = false; - - _mfpTrigger('ImageHasSize', item); - - if(item.imgHidden) { - if(mfp.content) - mfp.content.removeClass('mfp-loading'); - - item.imgHidden = false; - } - - } - }, - - /** - * Function that loops until the image has size to display elements that rely on it asap - */ - findImageSize: function(item) { - - var counter = 0, - img = item.img[0], - mfpSetInterval = function(delay) { - - if(_imgInterval) { - clearInterval(_imgInterval); - } - // decelerating interval that checks for size of an image - _imgInterval = setInterval(function() { - if(img.naturalWidth > 0) { - mfp._onImageHasSize(item); - return; - } - - if(counter > 200) { - clearInterval(_imgInterval); - } - - counter++; - if(counter === 3) { - mfpSetInterval(10); - } else if(counter === 40) { - mfpSetInterval(50); - } else if(counter === 100) { - mfpSetInterval(500); - } - }, delay); - }; - - mfpSetInterval(1); - }, - - getImage: function(item, template) { - - var guard = 0, - - // image load complete handler - onLoadComplete = function() { - if(item) { - if (item.img[0].complete) { - item.img.off('.mfploader'); - - if(item === mfp.currItem){ - mfp._onImageHasSize(item); - - mfp.updateStatus('ready'); - } - - item.hasSize = true; - item.loaded = true; - - _mfpTrigger('ImageLoadComplete'); - - } - else { - // if image complete check fails 200 times (20 sec), we assume that there was an error. - guard++; - if(guard < 200) { - setTimeout(onLoadComplete,100); - } else { - onLoadError(); - } - } - } - }, - - // image error handler - onLoadError = function() { - if(item) { - item.img.off('.mfploader'); - if(item === mfp.currItem){ - mfp._onImageHasSize(item); - mfp.updateStatus('error', imgSt.tError.replace('%url%', item.src) ); - } - - item.hasSize = true; - item.loaded = true; - item.loadError = true; - } - }, - imgSt = mfp.st.image; - - - var el = template.find('.mfp-img'); - if(el.length) { - var img = document.createElement('img'); - img.className = 'mfp-img'; - if(item.el && item.el.find('img').length) { - img.alt = item.el.find('img').attr('alt'); - } - item.img = $(img).on('load.mfploader', onLoadComplete).on('error.mfploader', onLoadError); - img.src = item.src; - - // without clone() "error" event is not firing when IMG is replaced by new IMG - // TODO: find a way to avoid such cloning - if(el.is('img')) { - item.img = item.img.clone(); - } - - img = item.img[0]; - if(img.naturalWidth > 0) { - item.hasSize = true; - } else if(!img.width) { - item.hasSize = false; - } - } - - mfp._parseMarkup(template, { - title: _getTitle(item), - img_replaceWith: item.img - }, item); - - mfp.resizeImage(); - - if(item.hasSize) { - if(_imgInterval) clearInterval(_imgInterval); - - if(item.loadError) { - template.addClass('mfp-loading'); - mfp.updateStatus('error', imgSt.tError.replace('%url%', item.src) ); - } else { - template.removeClass('mfp-loading'); - mfp.updateStatus('ready'); - } - return template; - } - - mfp.updateStatus('loading'); - item.loading = true; - - if(!item.hasSize) { - item.imgHidden = true; - template.addClass('mfp-loading'); - mfp.findImageSize(item); - } - - return template; - } - } - }); - - /*>>image*/ - - /*>>zoom*/ - var hasMozTransform, - getHasMozTransform = function() { - if(hasMozTransform === undefined) { - hasMozTransform = document.createElement('p').style.MozTransform !== undefined; - } - return hasMozTransform; - }; - - $.magnificPopup.registerModule('zoom', { - - options: { - enabled: false, - easing: 'ease-in-out', - duration: 300, - opener: function(element) { - return element.is('img') ? element : element.find('img'); - } - }, - - proto: { - - initZoom: function() { - var zoomSt = mfp.st.zoom, - ns = '.zoom', - image; - - if(!zoomSt.enabled || !mfp.supportsTransition) { - return; - } - - var duration = zoomSt.duration, - getElToAnimate = function(image) { - var newImg = image.clone().removeAttr('style').removeAttr('class').addClass('mfp-animated-image'), - transition = 'all '+(zoomSt.duration/1000)+'s ' + zoomSt.easing, - cssObj = { - position: 'fixed', - zIndex: 9999, - left: 0, - top: 0, - '-webkit-backface-visibility': 'hidden' - }, - t = 'transition'; - - cssObj['-webkit-'+t] = cssObj['-moz-'+t] = cssObj['-o-'+t] = cssObj[t] = transition; - - newImg.css(cssObj); - return newImg; - }, - showMainContent = function() { - mfp.content.css('visibility', 'visible'); - }, - openTimeout, - animatedImg; - - _mfpOn('BuildControls'+ns, function() { - if(mfp._allowZoom()) { - - clearTimeout(openTimeout); - mfp.content.css('visibility', 'hidden'); - - // Basically, all code below does is clones existing image, puts in on top of the current one and animated it - - image = mfp._getItemToZoom(); - - if(!image) { - showMainContent(); - return; - } - - animatedImg = getElToAnimate(image); - - animatedImg.css( mfp._getOffset() ); - - mfp.wrap.append(animatedImg); - - openTimeout = setTimeout(function() { - animatedImg.css( mfp._getOffset( true ) ); - openTimeout = setTimeout(function() { - - showMainContent(); - - setTimeout(function() { - animatedImg.remove(); - image = animatedImg = null; - _mfpTrigger('ZoomAnimationEnded'); - }, 16); // avoid blink when switching images - - }, duration); // this timeout equals animation duration - - }, 16); // by adding this timeout we avoid short glitch at the beginning of animation - - - // Lots of timeouts... - } - }); - _mfpOn(BEFORE_CLOSE_EVENT+ns, function() { - if(mfp._allowZoom()) { - - clearTimeout(openTimeout); - - mfp.st.removalDelay = duration; - - if(!image) { - image = mfp._getItemToZoom(); - if(!image) { - return; - } - animatedImg = getElToAnimate(image); - } - - animatedImg.css( mfp._getOffset(true) ); - mfp.wrap.append(animatedImg); - mfp.content.css('visibility', 'hidden'); - - setTimeout(function() { - animatedImg.css( mfp._getOffset() ); - }, 16); - } - - }); - - _mfpOn(CLOSE_EVENT+ns, function() { - if(mfp._allowZoom()) { - showMainContent(); - if(animatedImg) { - animatedImg.remove(); - } - image = null; - } - }); - }, - - _allowZoom: function() { - return mfp.currItem.type === 'image'; - }, - - _getItemToZoom: function() { - if(mfp.currItem.hasSize) { - return mfp.currItem.img; - } else { - return false; - } - }, - - // Get element postion relative to viewport - _getOffset: function(isLarge) { - var el; - if(isLarge) { - el = mfp.currItem.img; - } else { - el = mfp.st.zoom.opener(mfp.currItem.el || mfp.currItem); - } - - var offset = el.offset(); - var paddingTop = parseInt(el.css('padding-top'),10); - var paddingBottom = parseInt(el.css('padding-bottom'),10); - offset.top -= ( $(window).scrollTop() - paddingTop ); - - - /* - - Animating left + top + width/height looks glitchy in Firefox, but perfect in Chrome. And vice-versa. - - */ - var obj = { - width: el.width(), - // fix Zepto height+padding issue - height: (_isJQ ? el.innerHeight() : el[0].offsetHeight) - paddingBottom - paddingTop - }; - - // I hate to do this, but there is no another option - if( getHasMozTransform() ) { - obj['-moz-transform'] = obj['transform'] = 'translate(' + offset.left + 'px,' + offset.top + 'px)'; - } else { - obj.left = offset.left; - obj.top = offset.top; - } - return obj; - } - - } - }); - - - - /*>>zoom*/ - - /*>>iframe*/ - - var IFRAME_NS = 'iframe', - _emptyPage = '//about:blank', - - _fixIframeBugs = function(isShowing) { - if(mfp.currTemplate[IFRAME_NS]) { - var el = mfp.currTemplate[IFRAME_NS].find('iframe'); - if(el.length) { - // reset src after the popup is closed to avoid "video keeps playing after popup is closed" bug - if(!isShowing) { - el[0].src = _emptyPage; - } - - // IE8 black screen bug fix - if(mfp.isIE8) { - el.css('display', isShowing ? 'block' : 'none'); - } - } - } - }; - - $.magnificPopup.registerModule(IFRAME_NS, { - - options: { - markup: '
'+ - '
'+ - ''+ - '
', - - srcAction: 'iframe_src', - - // we don't care and support only one default type of URL by default - patterns: { - youtube: { - index: 'youtube.com', - id: 'v=', - src: '//www.youtube.com/embed/%id%?autoplay=1' - }, - vimeo: { - index: 'vimeo.com/', - id: '/', - src: '//player.vimeo.com/video/%id%?autoplay=1' - }, - gmaps: { - index: '//maps.google.', - src: '%id%&output=embed' - } - } - }, - - proto: { - initIframe: function() { - mfp.types.push(IFRAME_NS); - - _mfpOn('BeforeChange', function(e, prevType, newType) { - if(prevType !== newType) { - if(prevType === IFRAME_NS) { - _fixIframeBugs(); // iframe if removed - } else if(newType === IFRAME_NS) { - _fixIframeBugs(true); // iframe is showing - } - }// else { - // iframe source is switched, don't do anything - //} - }); - - _mfpOn(CLOSE_EVENT + '.' + IFRAME_NS, function() { - _fixIframeBugs(); - }); - }, - - getIframe: function(item, template) { - var embedSrc = item.src; - var iframeSt = mfp.st.iframe; - - $.each(iframeSt.patterns, function() { - if(embedSrc.indexOf( this.index ) > -1) { - if(this.id) { - if(typeof this.id === 'string') { - embedSrc = embedSrc.substr(embedSrc.lastIndexOf(this.id)+this.id.length, embedSrc.length); - } else { - embedSrc = this.id.call( this, embedSrc ); - } - } - embedSrc = this.src.replace('%id%', embedSrc ); - return false; // break; - } - }); - - var dataObj = {}; - if(iframeSt.srcAction) { - dataObj[iframeSt.srcAction] = embedSrc; - } - mfp._parseMarkup(template, dataObj, item); - - mfp.updateStatus('ready'); - - return template; - } - } - }); - - - - /*>>iframe*/ - - /*>>gallery*/ - /** - * Get looped index depending on number of slides - */ - var _getLoopedId = function(index) { - var numSlides = mfp.items.length; - if(index > numSlides - 1) { - return index - numSlides; - } else if(index < 0) { - return numSlides + index; - } - return index; - }, - _replaceCurrTotal = function(text, curr, total) { - return text.replace(/%curr%/gi, curr + 1).replace(/%total%/gi, total); - }; - - $.magnificPopup.registerModule('gallery', { - - options: { - enabled: false, - arrowMarkup: '', - preload: [0,2], - navigateByImgClick: true, - arrows: true, - - tPrev: 'Previous (Left arrow key)', - tNext: 'Next (Right arrow key)', - tCounter: '%curr% of %total%' - }, - - proto: { - initGallery: function() { - - var gSt = mfp.st.gallery, - ns = '.mfp-gallery'; - - mfp.direction = true; // true - next, false - prev - - if(!gSt || !gSt.enabled ) return false; - - _wrapClasses += ' mfp-gallery'; - - _mfpOn(OPEN_EVENT+ns, function() { - - if(gSt.navigateByImgClick) { - mfp.wrap.on('click'+ns, '.mfp-img', function() { - if(mfp.items.length > 1) { - mfp.next(); - return false; - } - }); - } - - _document.on('keydown'+ns, function(e) { - if (e.keyCode === 37) { - mfp.prev(); - } else if (e.keyCode === 39) { - mfp.next(); - } - }); - }); - - _mfpOn('UpdateStatus'+ns, function(e, data) { - if(data.text) { - data.text = _replaceCurrTotal(data.text, mfp.currItem.index, mfp.items.length); - } - }); - - _mfpOn(MARKUP_PARSE_EVENT+ns, function(e, element, values, item) { - var l = mfp.items.length; - values.counter = l > 1 ? _replaceCurrTotal(gSt.tCounter, item.index, l) : ''; - }); - - _mfpOn('BuildControls' + ns, function() { - if(mfp.items.length > 1 && gSt.arrows && !mfp.arrowLeft) { - var markup = gSt.arrowMarkup, - arrowLeft = mfp.arrowLeft = $( markup.replace(/%title%/gi, gSt.tPrev).replace(/%dir%/gi, 'left') ).addClass(PREVENT_CLOSE_CLASS), - arrowRight = mfp.arrowRight = $( markup.replace(/%title%/gi, gSt.tNext).replace(/%dir%/gi, 'right') ).addClass(PREVENT_CLOSE_CLASS); - - arrowLeft.click(function() { - mfp.prev(); - }); - arrowRight.click(function() { - mfp.next(); - }); - - mfp.container.append(arrowLeft.add(arrowRight)); - } - }); - - _mfpOn(CHANGE_EVENT+ns, function() { - if(mfp._preloadTimeout) clearTimeout(mfp._preloadTimeout); - - mfp._preloadTimeout = setTimeout(function() { - mfp.preloadNearbyImages(); - mfp._preloadTimeout = null; - }, 16); - }); - - - _mfpOn(CLOSE_EVENT+ns, function() { - _document.off(ns); - mfp.wrap.off('click'+ns); - mfp.arrowRight = mfp.arrowLeft = null; - }); - - }, - next: function() { - mfp.direction = true; - mfp.index = _getLoopedId(mfp.index + 1); - mfp.updateItemHTML(); - }, - prev: function() { - mfp.direction = false; - mfp.index = _getLoopedId(mfp.index - 1); - mfp.updateItemHTML(); - }, - goTo: function(newIndex) { - mfp.direction = (newIndex >= mfp.index); - mfp.index = newIndex; - mfp.updateItemHTML(); - }, - preloadNearbyImages: function() { - var p = mfp.st.gallery.preload, - preloadBefore = Math.min(p[0], mfp.items.length), - preloadAfter = Math.min(p[1], mfp.items.length), - i; - - for(i = 1; i <= (mfp.direction ? preloadAfter : preloadBefore); i++) { - mfp._preloadItem(mfp.index+i); - } - for(i = 1; i <= (mfp.direction ? preloadBefore : preloadAfter); i++) { - mfp._preloadItem(mfp.index-i); - } - }, - _preloadItem: function(index) { - index = _getLoopedId(index); - - if(mfp.items[index].preloaded) { - return; - } - - var item = mfp.items[index]; - if(!item.parsed) { - item = mfp.parseEl( index ); - } - - _mfpTrigger('LazyLoad', item); - - if(item.type === 'image') { - item.img = $('').on('load.mfploader', function() { - item.hasSize = true; - }).on('error.mfploader', function() { - item.hasSize = true; - item.loadError = true; - _mfpTrigger('LazyLoadError', item); - }).attr('src', item.src); - } - - - item.preloaded = true; - } - } - }); - - /*>>gallery*/ - - /*>>retina*/ - - var RETINA_NS = 'retina'; - - $.magnificPopup.registerModule(RETINA_NS, { - options: { - replaceSrc: function(item) { - return item.src.replace(/\.\w+$/, function(m) { return '@2x' + m; }); - }, - ratio: 1 // Function or number. Set to 1 to disable. - }, - proto: { - initRetina: function() { - if(window.devicePixelRatio > 1) { - - var st = mfp.st.retina, - ratio = st.ratio; - - ratio = !isNaN(ratio) ? ratio : ratio(); - - if(ratio > 1) { - _mfpOn('ImageHasSize' + '.' + RETINA_NS, function(e, item) { - item.img.css({ - 'max-width': item.img[0].naturalWidth / ratio, - 'width': '100%' - }); - }); - _mfpOn('ElementParse' + '.' + RETINA_NS, function(e, item) { - item.src = st.replaceSrc(item, ratio); - }); - } - } - - } - } - }); - - /*>>retina*/ - _checkInstance(); })); \ No newline at end of file diff --git a/docs/assets/js/plugins/smooth-scroll.js b/docs/assets/js/plugins/smooth-scroll.js deleted file mode 100644 index c4179a731f..0000000000 --- a/docs/assets/js/plugins/smooth-scroll.js +++ /dev/null @@ -1,650 +0,0 @@ -/*! - * smooth-scroll v16.1.2 - * Animate scrolling to anchor links - * (c) 2020 Chris Ferdinandi - * MIT License - * http://github.com/cferdinandi/smooth-scroll - */ - -(function (root, factory) { - if (typeof define === 'function' && define.amd) { - define([], (function () { - return factory(root); - })); - } else if (typeof exports === 'object') { - module.exports = factory(root); - } else { - root.SmoothScroll = factory(root); - } -})(typeof global !== 'undefined' ? global : typeof window !== 'undefined' ? window : this, (function (window) { - - 'use strict'; - - // - // Default settings - // - - var defaults = { - - // Selectors - ignore: '[data-scroll-ignore]', - header: null, - topOnEmptyHash: true, - - // Speed & Duration - speed: 500, - speedAsDuration: false, - durationMax: null, - durationMin: null, - clip: true, - offset: 0, - - // Easing - easing: 'easeInOutCubic', - customEasing: null, - - // History - updateURL: true, - popstate: true, - - // Custom Events - emitEvents: true - - }; - - - // - // Utility Methods - // - - /** - * Check if browser supports required methods - * @return {Boolean} Returns true if all required methods are supported - */ - var supports = function () { - return ( - 'querySelector' in document && - 'addEventListener' in window && - 'requestAnimationFrame' in window && - 'closest' in window.Element.prototype - ); - }; - - /** - * Merge two or more objects together. - * @param {Object} objects The objects to merge together - * @returns {Object} Merged values of defaults and options - */ - var extend = function () { - var merged = {}; - Array.prototype.forEach.call(arguments, (function (obj) { - for (var key in obj) { - if (!obj.hasOwnProperty(key)) return; - merged[key] = obj[key]; - } - })); - return merged; - }; - - /** - * Check to see if user prefers reduced motion - * @param {Object} settings Script settings - */ - var reduceMotion = function () { - if ('matchMedia' in window && window.matchMedia('(prefers-reduced-motion)').matches) { - return true; - } - return false; - }; - - /** - * Get the height of an element. - * @param {Node} elem The element to get the height of - * @return {Number} The element's height in pixels - */ - var getHeight = function (elem) { - return parseInt(window.getComputedStyle(elem).height, 10); - }; - - /** - * Escape special characters for use with querySelector - * @author Mathias Bynens - * @link https://github.com/mathiasbynens/CSS.escape - * @param {String} id The anchor ID to escape - */ - var escapeCharacters = function (id) { - - // Remove leading hash - if (id.charAt(0) === '#') { - id = id.substr(1); - } - - var string = String(id); - var length = string.length; - var index = -1; - var codeUnit; - var result = ''; - var firstCodeUnit = string.charCodeAt(0); - while (++index < length) { - codeUnit = string.charCodeAt(index); - // Note: there’s no need to special-case astral symbols, surrogate - // pairs, or lone surrogates. - - // If the character is NULL (U+0000), then throw an - // `InvalidCharacterError` exception and terminate these steps. - if (codeUnit === 0x0000) { - throw new InvalidCharacterError( - 'Invalid character: the input contains U+0000.' - ); - } - - if ( - // If the character is in the range [\1-\1F] (U+0001 to U+001F) or is - // U+007F, […] - (codeUnit >= 0x0001 && codeUnit <= 0x001F) || codeUnit == 0x007F || - // If the character is the first character and is in the range [0-9] - // (U+0030 to U+0039), […] - (index === 0 && codeUnit >= 0x0030 && codeUnit <= 0x0039) || - // If the character is the second character and is in the range [0-9] - // (U+0030 to U+0039) and the first character is a `-` (U+002D), […] - ( - index === 1 && - codeUnit >= 0x0030 && codeUnit <= 0x0039 && - firstCodeUnit === 0x002D - ) - ) { - // http://dev.w3.org/csswg/cssom/#escape-a-character-as-code-point - result += '\\' + codeUnit.toString(16) + ' '; - continue; - } - - // If the character is not handled by one of the above rules and is - // greater than or equal to U+0080, is `-` (U+002D) or `_` (U+005F), or - // is in one of the ranges [0-9] (U+0030 to U+0039), [A-Z] (U+0041 to - // U+005A), or [a-z] (U+0061 to U+007A), […] - if ( - codeUnit >= 0x0080 || - codeUnit === 0x002D || - codeUnit === 0x005F || - codeUnit >= 0x0030 && codeUnit <= 0x0039 || - codeUnit >= 0x0041 && codeUnit <= 0x005A || - codeUnit >= 0x0061 && codeUnit <= 0x007A - ) { - // the character itself - result += string.charAt(index); - continue; - } - - // Otherwise, the escaped character. - // http://dev.w3.org/csswg/cssom/#escape-a-character - result += '\\' + string.charAt(index); - - } - - // Return sanitized hash - return '#' + result; - - }; - - /** - * Calculate the easing pattern - * @link https://gist.github.com/gre/1650294 - * @param {String} type Easing pattern - * @param {Number} time Time animation should take to complete - * @returns {Number} - */ - var easingPattern = function (settings, time) { - var pattern; - - // Default Easing Patterns - if (settings.easing === 'easeInQuad') pattern = time * time; // accelerating from zero velocity - if (settings.easing === 'easeOutQuad') pattern = time * (2 - time); // decelerating to zero velocity - if (settings.easing === 'easeInOutQuad') pattern = time < 0.5 ? 2 * time * time : -1 + (4 - 2 * time) * time; // acceleration until halfway, then deceleration - if (settings.easing === 'easeInCubic') pattern = time * time * time; // accelerating from zero velocity - if (settings.easing === 'easeOutCubic') pattern = (--time) * time * time + 1; // decelerating to zero velocity - if (settings.easing === 'easeInOutCubic') pattern = time < 0.5 ? 4 * time * time * time : (time - 1) * (2 * time - 2) * (2 * time - 2) + 1; // acceleration until halfway, then deceleration - if (settings.easing === 'easeInQuart') pattern = time * time * time * time; // accelerating from zero velocity - if (settings.easing === 'easeOutQuart') pattern = 1 - (--time) * time * time * time; // decelerating to zero velocity - if (settings.easing === 'easeInOutQuart') pattern = time < 0.5 ? 8 * time * time * time * time : 1 - 8 * (--time) * time * time * time; // acceleration until halfway, then deceleration - if (settings.easing === 'easeInQuint') pattern = time * time * time * time * time; // accelerating from zero velocity - if (settings.easing === 'easeOutQuint') pattern = 1 + (--time) * time * time * time * time; // decelerating to zero velocity - if (settings.easing === 'easeInOutQuint') pattern = time < 0.5 ? 16 * time * time * time * time * time : 1 + 16 * (--time) * time * time * time * time; // acceleration until halfway, then deceleration - - // Custom Easing Patterns - if (!!settings.customEasing) pattern = settings.customEasing(time); - - return pattern || time; // no easing, no acceleration - }; - - /** - * Determine the document's height - * @returns {Number} - */ - var getDocumentHeight = function () { - return Math.max( - document.body.scrollHeight, document.documentElement.scrollHeight, - document.body.offsetHeight, document.documentElement.offsetHeight, - document.body.clientHeight, document.documentElement.clientHeight - ); - }; - - /** - * Calculate how far to scroll - * Clip support added by robjtede - https://github.com/cferdinandi/smooth-scroll/issues/405 - * @param {Element} anchor The anchor element to scroll to - * @param {Number} headerHeight Height of a fixed header, if any - * @param {Number} offset Number of pixels by which to offset scroll - * @param {Boolean} clip If true, adjust scroll distance to prevent abrupt stops near the bottom of the page - * @returns {Number} - */ - var getEndLocation = function (anchor, headerHeight, offset, clip) { - var location = 0; - if (anchor.offsetParent) { - do { - location += anchor.offsetTop; - anchor = anchor.offsetParent; - } while (anchor); - } - location = Math.max(location - headerHeight - offset, 0); - if (clip) { - location = Math.min(location, getDocumentHeight() - window.innerHeight); - } - return location; - }; - - /** - * Get the height of the fixed header - * @param {Node} header The header - * @return {Number} The height of the header - */ - var getHeaderHeight = function (header) { - return !header ? 0 : (getHeight(header) + header.offsetTop); - }; - - /** - * Calculate the speed to use for the animation - * @param {Number} distance The distance to travel - * @param {Object} settings The plugin settings - * @return {Number} How fast to animate - */ - var getSpeed = function (distance, settings) { - var speed = settings.speedAsDuration ? settings.speed : Math.abs(distance / 1000 * settings.speed); - if (settings.durationMax && speed > settings.durationMax) return settings.durationMax; - if (settings.durationMin && speed < settings.durationMin) return settings.durationMin; - return parseInt(speed, 10); - }; - - var setHistory = function (options) { - - // Make sure this should run - if (!history.replaceState || !options.updateURL || history.state) return; - - // Get the hash to use - var hash = window.location.hash; - hash = hash ? hash : ''; - - // Set a default history - history.replaceState( - { - smoothScroll: JSON.stringify(options), - anchor: hash ? hash : window.pageYOffset - }, - document.title, - hash ? hash : window.location.href - ); - - }; - - /** - * Update the URL - * @param {Node} anchor The anchor that was scrolled to - * @param {Boolean} isNum If true, anchor is a number - * @param {Object} options Settings for Smooth Scroll - */ - var updateURL = function (anchor, isNum, options) { - - // Bail if the anchor is a number - if (isNum) return; - - // Verify that pushState is supported and the updateURL option is enabled - if (!history.pushState || !options.updateURL) return; - - // Update URL - history.pushState( - { - smoothScroll: JSON.stringify(options), - anchor: anchor.id - }, - document.title, - anchor === document.documentElement ? '#top' : '#' + anchor.id - ); - - }; - - /** - * Bring the anchored element into focus - * @param {Node} anchor The anchor element - * @param {Number} endLocation The end location to scroll to - * @param {Boolean} isNum If true, scroll is to a position rather than an element - */ - var adjustFocus = function (anchor, endLocation, isNum) { - - // Is scrolling to top of page, blur - if (anchor === 0) { - document.body.focus(); - } - - // Don't run if scrolling to a number on the page - if (isNum) return; - - // Otherwise, bring anchor element into focus - anchor.focus(); - if (document.activeElement !== anchor) { - anchor.setAttribute('tabindex', '-1'); - anchor.focus(); - anchor.style.outline = 'none'; - } - window.scrollTo(0 , endLocation); - - }; - - /** - * Emit a custom event - * @param {String} type The event type - * @param {Object} options The settings object - * @param {Node} anchor The anchor element - * @param {Node} toggle The toggle element - */ - var emitEvent = function (type, options, anchor, toggle) { - if (!options.emitEvents || typeof window.CustomEvent !== 'function') return; - var event = new CustomEvent(type, { - bubbles: true, - detail: { - anchor: anchor, - toggle: toggle - } - }); - document.dispatchEvent(event); - }; - - - // - // SmoothScroll Constructor - // - - var SmoothScroll = function (selector, options) { - - // - // Variables - // - - var smoothScroll = {}; // Object for public APIs - var settings, anchor, toggle, fixedHeader, eventTimeout, animationInterval; - - - // - // Methods - // - - /** - * Cancel a scroll-in-progress - */ - smoothScroll.cancelScroll = function (noEvent) { - cancelAnimationFrame(animationInterval); - animationInterval = null; - if (noEvent) return; - emitEvent('scrollCancel', settings); - }; - - /** - * Start/stop the scrolling animation - * @param {Node|Number} anchor The element or position to scroll to - * @param {Element} toggle The element that toggled the scroll event - * @param {Object} options - */ - smoothScroll.animateScroll = function (anchor, toggle, options) { - - // Cancel any in progress scrolls - smoothScroll.cancelScroll(); - - // Local settings - var _settings = extend(settings || defaults, options || {}); // Merge user options with defaults - - // Selectors and variables - var isNum = Object.prototype.toString.call(anchor) === '[object Number]' ? true : false; - var anchorElem = isNum || !anchor.tagName ? null : anchor; - if (!isNum && !anchorElem) return; - var startLocation = window.pageYOffset; // Current location on the page - if (_settings.header && !fixedHeader) { - // Get the fixed header if not already set - fixedHeader = document.querySelector(_settings.header); - } - var headerHeight = getHeaderHeight(fixedHeader); - var endLocation = isNum ? anchor : getEndLocation(anchorElem, headerHeight, parseInt((typeof _settings.offset === 'function' ? _settings.offset(anchor, toggle) : _settings.offset), 10), _settings.clip); // Location to scroll to - var distance = endLocation - startLocation; // distance to travel - var documentHeight = getDocumentHeight(); - var timeLapsed = 0; - var speed = getSpeed(distance, _settings); - var start, percentage, position; - - /** - * Stop the scroll animation when it reaches its target (or the bottom/top of page) - * @param {Number} position Current position on the page - * @param {Number} endLocation Scroll to location - * @param {Number} animationInterval How much to scroll on this loop - */ - var stopAnimateScroll = function (position, endLocation) { - - // Get the current location - var currentLocation = window.pageYOffset; - - // Check if the end location has been reached yet (or we've hit the end of the document) - if (position == endLocation || currentLocation == endLocation || ((startLocation < endLocation && window.innerHeight + currentLocation) >= documentHeight)) { - - // Clear the animation timer - smoothScroll.cancelScroll(true); - - // Bring the anchored element into focus - adjustFocus(anchor, endLocation, isNum); - - // Emit a custom event - emitEvent('scrollStop', _settings, anchor, toggle); - - // Reset start - start = null; - animationInterval = null; - - return true; - - } - }; - - /** - * Loop scrolling animation - */ - var loopAnimateScroll = function (timestamp) { - if (!start) { start = timestamp; } - timeLapsed += timestamp - start; - percentage = speed === 0 ? 0 : (timeLapsed / speed); - percentage = (percentage > 1) ? 1 : percentage; - position = startLocation + (distance * easingPattern(_settings, percentage)); - window.scrollTo(0, Math.floor(position)); - if (!stopAnimateScroll(position, endLocation)) { - animationInterval = window.requestAnimationFrame(loopAnimateScroll); - start = timestamp; - } - }; - - /** - * Reset position to fix weird iOS bug - * @link https://github.com/cferdinandi/smooth-scroll/issues/45 - */ - if (window.pageYOffset === 0) { - window.scrollTo(0, 0); - } - - // Update the URL - updateURL(anchor, isNum, _settings); - - // If the user prefers reduced motion, jump to location - if (reduceMotion()) { - window.scrollTo(0, Math.floor(endLocation)); - return; - } - - // Emit a custom event - emitEvent('scrollStart', _settings, anchor, toggle); - - // Start scrolling animation - smoothScroll.cancelScroll(true); - window.requestAnimationFrame(loopAnimateScroll); - - }; - - /** - * If smooth scroll element clicked, animate scroll - */ - var clickHandler = function (event) { - - // Don't run if event was canceled but still bubbled up - // By @mgreter - https://github.com/cferdinandi/smooth-scroll/pull/462/ - if (event.defaultPrevented) return; - - // Don't run if right-click or command/control + click or shift + click - if (event.button !== 0 || event.metaKey || event.ctrlKey || event.shiftKey) return; - - // Check if event.target has closest() method - // By @totegi - https://github.com/cferdinandi/smooth-scroll/pull/401/ - if (!('closest' in event.target)) return; - - // Check if a smooth scroll link was clicked - toggle = event.target.closest(selector); - if (!toggle || toggle.tagName.toLowerCase() !== 'a' || event.target.closest(settings.ignore)) return; - - // Only run if link is an anchor and points to the current page - if (toggle.hostname !== window.location.hostname || toggle.pathname !== window.location.pathname || !/#/.test(toggle.href)) return; - - // Get an escaped version of the hash - var hash; - try { - hash = escapeCharacters(decodeURIComponent(toggle.hash)); - } catch(e) { - hash = escapeCharacters(toggle.hash); - } - - // Get the anchored element - var anchor; - if (hash === '#') { - if (!settings.topOnEmptyHash) return; - anchor = document.documentElement; - } else { - anchor = document.querySelector(hash); - } - anchor = !anchor && hash === '#top' ? document.documentElement : anchor; - - // If anchored element exists, scroll to it - if (!anchor) return; - event.preventDefault(); - setHistory(settings); - smoothScroll.animateScroll(anchor, toggle); - - }; - - /** - * Animate scroll on popstate events - */ - var popstateHandler = function (event) { - - // Stop if history.state doesn't exist (ex. if clicking on a broken anchor link). - // fixes `Cannot read property 'smoothScroll' of null` error getting thrown. - if (history.state === null) return; - - // Only run if state is a popstate record for this instantiation - if (!history.state.smoothScroll || history.state.smoothScroll !== JSON.stringify(settings)) return; - - // Only run if state includes an anchor - - // if (!history.state.anchor && history.state.anchor !== 0) return; - - // Get the anchor - var anchor = history.state.anchor; - if (typeof anchor === 'string' && anchor) { - anchor = document.querySelector(escapeCharacters(history.state.anchor)); - if (!anchor) return; - } - - // Animate scroll to anchor link - smoothScroll.animateScroll(anchor, null, {updateURL: false}); - - }; - - /** - * Destroy the current initialization. - */ - smoothScroll.destroy = function () { - - // If plugin isn't already initialized, stop - if (!settings) return; - - // Remove event listeners - document.removeEventListener('click', clickHandler, false); - window.removeEventListener('popstate', popstateHandler, false); - - // Cancel any scrolls-in-progress - smoothScroll.cancelScroll(); - - // Reset variables - settings = null; - anchor = null; - toggle = null; - fixedHeader = null; - eventTimeout = null; - animationInterval = null; - - }; - - /** - * Initialize Smooth Scroll - * @param {Object} options User settings - */ - var init = function () { - - // feature test - if (!supports()) throw 'Smooth Scroll: This browser does not support the required JavaScript methods and browser APIs.'; - - // Destroy any existing initializations - smoothScroll.destroy(); - - // Selectors and variables - settings = extend(defaults, options || {}); // Merge user options with defaults - fixedHeader = settings.header ? document.querySelector(settings.header) : null; // Get the fixed header - - // When a toggle is clicked, run the click handler - document.addEventListener('click', clickHandler, false); - - // If updateURL and popState are enabled, listen for pop events - if (settings.updateURL && settings.popstate) { - window.addEventListener('popstate', popstateHandler, false); - } - - }; - - - // - // Initialize plugin - // - - init(); - - - // - // Public APIs - // - - return smoothScroll; - - }; - - return SmoothScroll; - -})); diff --git a/docs/detections.wiki b/docs/detections.wiki deleted file mode 100644 index a4eb40c087..0000000000 --- a/docs/detections.wiki +++ /dev/null @@ -1,58930 +0,0 @@ -=Splunk Security Content Detections = - ----- -All the detections shipped to different Splunk products. Below is a breakdown by kind. - -==Application== - - -===Detect new login attempts to routers=== -The search queries the authentication logs for assets that are categorized as routers in the ES Assets and Identity Framework, to identify connections that have not been seen before in the last 30 days. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Authentication -* '''ATT&CK''': -* '''Last Updated''': 2017-09-12 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count earliest(_time) as earliest latest(_time) as latest from datamodel=Authentication where Authentication.dest_category=router by Authentication.dest Authentication.user -| eval isOutlier=if(earliest >= relative_time(now(), "-30d@d"), 1, 0) -| where isOutlier=1 -| `security_content_ctime(earliest)` -| `security_content_ctime(latest)` -| `drop_dm_object_name("Authentication")` -| `detect_new_login_attempts_to_routers_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Router_and_Infrastructure_Security|Router and Infrastructure Security]] - - -====How To Implement==== -To successfully implement this search, you must ensure the network router devices are categorized as "router" in the Assets and identity table. You must also populate the Authentication data model with logs related to users authenticating to routing infrastructure. - -====Required field==== - -* _time - -* Authentication.dest_category - -* Authentication.dest - -* Authentication.user - - - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Legitimate router connections may appear as new connections - -====Reference==== - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Email attachments with lots of spaces=== -Attackers often use spaces as a means to obfuscate an attachment's file extension. This search looks for messages with email attachments that have many spaces within the file names. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Email -* '''ATT&CK''': -* '''Last Updated''': 2017-09-19 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count values(All_Email.recipient) as recipient_address min(_time) as firstTime max(_time) as lastTime from datamodel=Email where All_Email.file_name="*" by All_Email.src_user, All_Email.file_name All_Email.message_id -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `drop_dm_object_name("All_Email")` -| eval space_ratio = (mvcount(split(file_name," "))-1)/len(file_name) -| search space_ratio >= 0.1 -| rex field=recipient_address "(?<recipient_user>.*)@" -| `email_attachments_with_lots_of_spaces_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Emotet_Malware__DHS_Report_TA18-201A_|Emotet Malware DHS Report TA18-201A ]] - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Emails|Suspicious Emails]] - - -====How To Implement==== -You need to ingest data from emails. Specifically, the sender's address and the file names of any attachments must be mapped to the Email data model. The threshold ratio is set to 10%, but this value can be configured to suit each environment. \ - **Splunk Phantom Playbook Integration**\ -If Splunk Phantom is also configured in your environment, a playbook called "Suspicious Email Attachment Investigate and Delete" can be configured to run when any results are found by this detection search. To use this integration, install the Phantom App for Splunk `https://splunkbase.splunk.com/app/3411/` and add the correct hostname to the "Phantom Instance" field in the Adaptive Response Actions when configuring this detection search. The notable event will be sent to Phantom and the playbook will gather further information about the file attachment and its network behaviors. If Phantom finds malicious behavior and an analyst approves of the results, the email will be deleted from the user's inbox. - -====Required field==== - -* _time - -* All_Email.recipient - -* All_Email.file_name - -* All_Email.src_user - -* All_Email.file_name - -* All_Email.message_id - - - - -====Kill Chain Phase==== - -* Delivery - - -====Known False Positives==== -None at this time - -====Reference==== - - -====Test Dataset==== - - -''version'': 2 -
-
- ----- - -===Email files written outside of the outlook directory=== -The search looks at the change-analysis data model and detects email files created outside the normal Outlook directory. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1114/ T1114], [https://attack.mitre.org/techniques/T1114/001/ T1114.001] -* '''Last Updated''': 2020-07-21 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count values(Filesystem.file_path) as file_path min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Filesystem where (Filesystem.file_name=*.pst OR Filesystem.file_name=*.ost) Filesystem.file_path != "C:\\Users\\*\\My Documents\\Outlook Files\\*" Filesystem.file_path!="C:\\Users\\*\\AppData\\Local\\Microsoft\\Outlook*" by Filesystem.action Filesystem.process_id Filesystem.file_name Filesystem.dest -| `drop_dm_object_name("Filesystem")` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `email_files_written_outside_of_the_outlook_directory_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Collection_and_Staging|Collection and Staging]] - - -====How To Implement==== -To successfully implement this search, you must be ingesting data that records the file-system activity from your hosts to populate the Endpoint.Filesystem data model node. This is typically populated via endpoint detection-and-response product, such as Carbon Black, or by other endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report file-system reads and writes. - -====Required field==== - -* _time - -* Filesystem.file_path - -* Filesystem.file_name - -* Filesystem.action - -* Filesystem.process_id - -* Filesystem.dest - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1114 -| Email Collection -| Collection -|- -| T1114.001 -| Local Email Collection -| Collection -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Administrators and users sometimes prefer backing up their email data by moving the email files into a different folder. These attempts will be detected by the search. - -====Reference==== - - -====Test Dataset==== - - -''version'': 3 -
-
- ----- - -===Email servers sending high volume traffic to hosts=== -This search looks for an increase of data transfers from your email server to your clients. This could be indicative of a malicious actor collecting data using your email server. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Network_Traffic -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1114/ T1114], [https://attack.mitre.org/techniques/T1114/002/ T1114.002] -* '''Last Updated''': 2020-07-21 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` sum(All_Traffic.bytes_out) as bytes_out from datamodel=Network_Traffic where All_Traffic.src_category=email_server by All_Traffic.dest_ip _time span=1d -| `drop_dm_object_name("All_Traffic")` -| eventstats avg(bytes_out) as avg_bytes_out stdev(bytes_out) as stdev_bytes_out -| eventstats count as num_data_samples avg(eval(if(_time < relative_time(now(), "@d"), bytes_out, null))) as per_source_avg_bytes_out stdev(eval(if(_time < relative_time(now(), "@d"), bytes_out, null))) as per_source_stdev_bytes_out by dest_ip -| eval minimum_data_samples = 4, deviation_threshold = 3 -| where num_data_samples >= minimum_data_samples AND bytes_out > (avg_bytes_out + (deviation_threshold * stdev_bytes_out)) AND bytes_out > (per_source_avg_bytes_out + (deviation_threshold * per_source_stdev_bytes_out)) AND _time >= relative_time(now(), "@d") -| eval num_standard_deviations_away_from_server_average = round(abs(bytes_out - avg_bytes_out) / stdev_bytes_out, 2), num_standard_deviations_away_from_client_average = round(abs(bytes_out - per_source_avg_bytes_out) / per_source_stdev_bytes_out, 2) -| table dest_ip, _time, bytes_out, avg_bytes_out, per_source_avg_bytes_out, num_standard_deviations_away_from_server_average, num_standard_deviations_away_from_client_average -| `email_servers_sending_high_volume_traffic_to_hosts_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Collection_and_Staging|Collection and Staging]] - -* [[Documentation:ESSOC:stories:UseCase#HAFNIUM_Group|HAFNIUM Group]] - - -====How To Implement==== -This search requires you to be ingesting your network traffic and populating the Network_Traffic data model. Your email servers must be categorized as "email_server" for the search to work, as well. You may need to adjust the deviation_threshold and minimum_data_samples values based on the network traffic in your environment. The "deviation_threshold" field is a multiplying factor to control how much variation you're willing to tolerate. The "minimum_data_samples" field is the minimum number of connections of data samples required for the statistic to be valid. - -====Required field==== - -* _time - -* All_Traffic.bytes_out - -* All_Traffic.src_category - -* All_Traffic.dest_ip - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1114 -| Email Collection -| Collection -|- -| T1114.002 -| Remote Email Collection -| Collection -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -The false-positive rate will vary based on how you set the deviation_threshold and data_samples values. Our recommendation is to adjust these values based on your network traffic to and from your email servers. - -====Reference==== - - -====Test Dataset==== - - -''version'': 2 -
-
- ----- - -===Monitor email for brand abuse=== -This search looks for emails claiming to be sent from a domain similar to one that you want to have monitored for abuse. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Email -* '''ATT&CK''': -* '''Last Updated''': 2018-01-05 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` values(All_Email.recipient) as recipients, min(_time) as firstTime, max(_time) as lastTime from datamodel=Email by All_Email.src_user, All_Email.message_id -| `drop_dm_object_name("All_Email")` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| eval temp=split(src_user, "@") -| eval email_domain=mvindex(temp, 1) -| lookup update=true brandMonitoring_lookup domain as email_domain OUTPUT domain_abuse -| search domain_abuse=true -| table message_id, src_user, email_domain, recipients, firstTime, lastTime -| `monitor_email_for_brand_abuse_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Brand_Monitoring|Brand Monitoring]] - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Emails|Suspicious Emails]] - - -====How To Implement==== -You need to ingest email header data. Specifically the sender's address (src_user) must be populated. You also need to have run the search "ESCU - DNSTwist Domain Names", which creates the permutations of the domain that will be checked for. - -====Required field==== - -* _time - -* All_Email.recipient - -* All_Email.src_user - -* All_Email.message_id - - - - -====Kill Chain Phase==== - -* Delivery - - -====Known False Positives==== -None at this time - -====Reference==== - - -====Test Dataset==== - - -''version'': 2 -
-
- ----- - -===Multiple okta users with invalid credentials from the same ip=== -This search detects Okta login failures due to bad credentials for multiple users originating from the same ip address. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/ T1078], [https://attack.mitre.org/techniques/T1078/001/ T1078.001] -* '''Last Updated''': 2020-07-21 - -
-
- -====Search==== -`okta` outcome.reason=INVALID_CREDENTIALS -| rename client.geographicalContext.country as country, client.geographicalContext.state as state, client.geographicalContext.city as city -| stats min(_time) as firstTime max(_time) as lastTime dc(user) as distinct_users values(user) as users by src_ip, displayMessage, outcome.reason, country, state, city -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| search distinct_users > 5 -| `multiple_okta_users_with_invalid_credentials_from_the_same_ip_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Okta_Activity|Suspicious Okta Activity]] - - -====How To Implement==== -This search is specific to Okta and requires Okta logs are being ingested in your Splunk deployment. - -====Required field==== - -* _time - -* outcome.reason - -* client.geographicalContext.country - -* client.geographicalContext.state - -* client.geographicalContext.city - -* user - -* src_ip - -* displayMessage - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1078 -| Valid Accounts -| Defense Evasion, Persistence, Privilege Escalation, Initial Access -|- -| T1078.001 -| Default Accounts -| Defense Evasion, Persistence, Privilege Escalation, Initial Access -|} - - -====Kill Chain Phase==== - - -====Known False Positives==== -A single public IP address servicing multiple legitmate users may trigger this search. In addition, the threshold of 5 distinct users may be too low for your needs. You may modify the included filter macro `multiple_okta_users_with_invalid_credentials_from_the_same_ip_filter` to raise the threshold or except specific IP adresses from triggering this search. - -====Reference==== - - -====Test Dataset==== - - -''version'': 2 -
-
- ----- - -===No windows updates in a time frame=== -This search looks for Windows endpoints that have not generated an event indicating a successful Windows update in the last 60 days. Windows updates are typically released monthly and applied shortly thereafter. An endpoint that has not successfully applied an update in this time frame indicates the endpoint is not regularly being patched for some reason. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Updates -* '''ATT&CK''': -* '''Last Updated''': 2017-09-15 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` max(_time) as lastTime from datamodel=Updates where Updates.status=Installed Updates.vendor_product="Microsoft Windows" by Updates.dest Updates.status Updates.vendor_product -| rename Updates.dest as Host -| rename Updates.status as "Update Status" -| rename Updates.vendor_product as Product -| eval isOutlier=if(lastTime <= relative_time(now(), "-60d@d"), 1, 0) -| `security_content_ctime(lastTime)` -| search isOutlier=1 -| rename lastTime as "Last Update Time", -| table Host, "Update Status", Product, "Last Update Time" -| `no_windows_updates_in_a_time_frame_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Monitor_for_Updates|Monitor for Updates]] - - -====How To Implement==== -To successfully implement this search, it requires that the 'Update' data model is being populated. This can be accomplished by ingesting Windows events or the Windows Update log via a universal forwarder on the Windows endpoints you wish to monitor. The Windows add-on should be also be installed and configured to properly parse Windows events in Splunk. There may be other data sources which can populate this data model, including vulnerability management systems. - -====Required field==== - -* _time - -* Updates.status - -* Updates.vendor_product - -* Updates.dest - - - - -====Kill Chain Phase==== - - -====Known False Positives==== -None identified - -====Reference==== - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Okta account lockout events=== -Detect Okta user lockout events - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/ T1078], [https://attack.mitre.org/techniques/T1078/001/ T1078.001] -* '''Last Updated''': 2020-07-21 - -
-
- -====Search==== -`okta` displayMessage="Max sign in attempts exceeded" -| rename client.geographicalContext.country as country, client.geographicalContext.state as state, client.geographicalContext.city as city -| table _time, user, country, state, city, src_ip -| `okta_account_lockout_events_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Okta_Activity|Suspicious Okta Activity]] - - -====How To Implement==== -This search is specific to Okta and requires Okta logs are being ingested in your Splunk deployment. - -====Required field==== - -* _time - -* displayMessage - -* client.geographicalContext.country - -* client.geographicalContext.state - -* client.geographicalContext.city - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1078 -| Valid Accounts -| Defense Evasion, Persistence, Privilege Escalation, Initial Access -|- -| T1078.001 -| Default Accounts -| Defense Evasion, Persistence, Privilege Escalation, Initial Access -|} - - -====Kill Chain Phase==== - - -====Known False Positives==== -None. Account lockouts should be followed up on to determine if the actual user was the one who caused the lockout, or if it was an unauthorized actor. - -====Reference==== - - -====Test Dataset==== - - -''version'': 2 -
-
- ----- - -===Okta failed sso attempts=== -Detect failed Okta SSO events - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/ T1078], [https://attack.mitre.org/techniques/T1078/001/ T1078.001] -* '''Last Updated''': 2020-07-21 - -
-
- -====Search==== -`okta` displayMessage="User attempted unauthorized access to app" -| stats min(_time) as firstTime max(_time) as lastTime values(app) as Apps count by user, result ,displayMessage, src_ip -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `okta_failed_sso_attempts_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Okta_Activity|Suspicious Okta Activity]] - - -====How To Implement==== -This search is specific to Okta and requires Okta logs are being ingested in your Splunk deployment. - -====Required field==== - -* _time - -* displayMessage - -* app - -* user - -* result - -* src_ip - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1078 -| Valid Accounts -| Defense Evasion, Persistence, Privilege Escalation, Initial Access -|- -| T1078.001 -| Default Accounts -| Defense Evasion, Persistence, Privilege Escalation, Initial Access -|} - - -====Kill Chain Phase==== - - -====Known False Positives==== -There may be a faulty config preventing legitmate users from accessing apps they should have access to. - -====Reference==== - - -====Test Dataset==== - - -''version'': 2 -
-
- ----- - -===Okta user logins from multiple cities=== -This search detects logins from the same user from different cities in a 24 hour period. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/ T1078], [https://attack.mitre.org/techniques/T1078/001/ T1078.001] -* '''Last Updated''': 2020-07-21 - -
-
- -====Search==== -`okta` displayMessage="User login to Okta" client.geographicalContext.city!=null -| stats min(_time) as firstTime max(_time) as lastTime dc(client.geographicalContext.city) as locations values(client.geographicalContext.city) as cities values(client.geographicalContext.state) as states by user -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `okta_user_logins_from_multiple_cities_filter` -| search locations > 1 - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Okta_Activity|Suspicious Okta Activity]] - - -====How To Implement==== -This search is specific to Okta and requires Okta logs are being ingested in your Splunk deployment. - -====Required field==== - -* _time - -* displayMessage - -* client.geographicalContext.city - -* client.geographicalContext.state - -* user - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1078 -| Valid Accounts -| Defense Evasion, Persistence, Privilege Escalation, Initial Access -|- -| T1078.001 -| Default Accounts -| Defense Evasion, Persistence, Privilege Escalation, Initial Access -|} - - -====Kill Chain Phase==== - - -====Known False Positives==== -Users in your enviornment may legitmately be travelling and loggin in from different locations. This search is useful for those users that should *not* be travelling for some reason, such as the COVID-19 pandemic. The search also relies on the geographical information being populated in the Okta logs. It is also possible that a connection from another region may be attributed to a login from a remote VPN endpoint. - -====Reference==== - - -====Test Dataset==== - - -''version'': 2 -
-
- ----- - -===Phishing email detection by machine learning method - ssa=== -Malicious mails can conduct phishing that induces readers to open attachment, click links or trigger third party service. This detect uses Natural Language Processing (NLP) approach to analyze an email message's content (Sender, Subject and Body) and judge whether it is a phishing email. The detection adopts a deep learning (neural network) model that employs character level embeddings plus LSTM layers to perform classification. The model is pre-trained and then published as ONNX format. Current sample model is trained using the dataset published at https://github.com/splunk/attack_data/tree/master/datasets/T1566_Phishing_Email/splunk_train.json User are expected to re-train the model by combining with their own training data for better accuracy using the provided model file (SMLE notebook). DSP pipeline then processes the email message and passes it as an event to Apply ML Models function, which returns the probability of a phishing email. Current implementation assumes the email is fed to DSP in JSON format contains at least email's sender, subject and its message body, including reply content, if any. - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/ T1566] -* '''Last Updated''': 2020-08-25 - -
-
- -====Search==== - -| from read_ssa_enriched_events() -| eval eventLine=concat(ucast(map_get(input_event, "From"), "string", " "), " ", ucast(map_get(input_event, "Subject"), "string", " "), " ", ucast(map_get(input_event, "Content"), "string", " "), " "), _time=map_get(input_event, "_time") -| where eventLine IS NOT NULL -| eval mapC={" ": 32, "!": 33, "\"": 34, "#": 35, "$": 36, "%": 37, "&": 38, "`": 39, "(": 40, ")": 41, "*": 42, "+": 43, ",": 44, "-": 45, ".": 46, "/": 47, "0": 48, "1": 49, "2": 50, "3": 51, "4": 52, "5": 53, "6": 54, "7": 55, "8": 56, "9": 57, ":": 58, ";": 59, "<": 60, "=": 61, ">": 62, "?": 63, "@": 64, "A": 65, "B": 66, "C": 67, "D": 68, "E": 69, "F": 70, "G": 71, "H": 72, "I": 73, "J": 74, "K": 75, "L": 76, "M": 77, "N": 78, "O": 79, "P": 80, "Q": 81, "R": 82, "S": 83, "T": 84, "U": 85, "V": 86, "W": 87, "X": 88, "Y": 89, "Z": 90, "[": 91, "\\": 92, "]": 93, "^": 94, "_": 95, "`": 96, "a": 97, "b": 98, "c": 99, "d": 100, "e": 101, "f": 102, "g": 103, "h": 104, "i": 105, "j": 106, "k": 107, "l": 108, "m": 109, "n": 110, "o": 111, "p": 112, "q": 113, "r": 114, "s": 115, "t": 116, "u": 117, "v": 118, "w": 119, "x": 120, "y": 121, "z": 122, "{": 123, " -|": 124, "}": 125, "~": 126}, ml_in = for_each(iterator(mvrange(1,129), "i"), cast(map_get(mapC, substr(eventLine, i, 1)), "float") ) -| apply_model connection_id="YOUR_S3_ONNX_CONNECTOR_ID" name="phishing_email_v8" path="s3://smle-experiments/models/phishing_email" -| eval probability = mvindex(ml_out, 0) -| where probability > 0.5 -| eval start_time=_time, end_time=_time, entities="TBD", body="TBD" -| select probability, body, entities, start_time, end_time -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - - -====How To Implement==== -Events are fed to DSP contains at least email's sender, subject and its message body. - -====Required field==== - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1566 -| Phishing -| Initial Access -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Because of imbalance of anomaly data in training, the model will less likely report false positive. Instead, the model is more prone to false negative. Current best recall score is ~85% - -====Reference==== - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Suspicious email attachment extensions=== -This search looks for emails that have attachments with suspicious file extensions. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Email -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/001/ T1566.001], [https://attack.mitre.org/techniques/T1566/ T1566] -* '''Last Updated''': 2020-07-22 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Email where All_Email.file_name="*" by All_Email.src_user, All_Email.file_name All_Email.message_id -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `drop_dm_object_name("All_Email")` -| `suspicious_email_attachments` -| `suspicious_email_attachment_extensions_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Emotet_Malware__DHS_Report_TA18-201A_|Emotet Malware DHS Report TA18-201A ]] - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Emails|Suspicious Emails]] - - -====How To Implement==== -You need to ingest data from emails. Specifically, the sender's address and the file names of any attachments must be mapped to the Email data model. \ - **Splunk Phantom Playbook Integration**\ -If Splunk Phantom is also configured in your environment, a Playbook called "Suspicious Email Attachment Investigate and Delete" can be configured to run when any results are found by this detection search. To use this integration, install the Phantom App for Splunk `https://splunkbase.splunk.com/app/3411/`, and add the correct hostname to the "Phantom Instance" field in the Adaptive Response Actions when configuring this detection search. The notable event will be sent to Phantom and the playbook will gather further information about the file attachment and its network behaviors. If Phantom finds malicious behavior and an analyst approves of the results, the email will be deleted from the user's inbox. - -====Required field==== - -* _time - -* All_Email.file_name - -* All_Email.src_user - -* All_Email.message_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1566.001 -| Spearphishing Attachment -| Initial Access -|- -| T1566 -| Phishing -| Initial Access -|} - - -====Kill Chain Phase==== - -* Delivery - - -====Known False Positives==== -None identified - -====Reference==== - - -====Test Dataset==== - - -''version'': 3 -
-
- ----- - -===Suspicious java classes=== -This search looks for suspicious Java classes that are often used to exploit remote command execution in common Java frameworks, such as Apache Struts. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': -* '''Last Updated''': 2018-12-06 - -
-
- -====Search==== -`stream_http` http_method=POST http_content_length>1 -| regex form_data="(?i)java\.lang\.(?:runtime -|processbuilder)" -| rename src_ip as src -| stats count earliest(_time) as firstTime, latest(_time) as lastTime, values(url) as uri, values(status) as status, values(http_user_agent) as http_user_agent by src, dest -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `suspicious_java_classes_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Apache_Struts_Vulnerability|Apache Struts Vulnerability]] - - -====How To Implement==== -In order to properly run this search, Splunk needs to ingest data from your web-traffic appliances that serve or sit in the path of your Struts application servers. This can be accomplished by indexing data from a web proxy, or by using network traffic-analysis tools, such as Splunk Stream or Bro. - -====Required field==== - -* _time - -* http_method - -* http_content_length - -* src_ip - -* url - -* status - -* http_user_agent - -* src - -* dest - - - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -There are no known false positives. - -====Reference==== - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Web servers executing suspicious processes=== -This search looks for suspicious processes on all systems labeled as web servers. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1082/ T1082] -* '''Last Updated''': 2019-04-01 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.dest_category="web_server" AND (Processes.process="*whoami*" OR Processes.process="*ping*" OR Processes.process="*iptables*" OR Processes.process="*wget*" OR Processes.process="*service*" OR Processes.process="*curl*") by Processes.process Processes.process_name, Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `web_servers_executing_suspicious_processes_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Apache_Struts_Vulnerability|Apache Struts Vulnerability]] - - -====How To Implement==== -You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. In addition, web servers will need to be identified in the Assets and Identity Framework of Enterprise Security. - -====Required field==== - -* _time - -* Processes.dest_category - -* Processes.process - -* Processes.process_name - -* Processes.dest - -* Processes.user - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1082 -| System Information Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Some of these processes may be used legitimately on web servers during maintenance or other administrative tasks. - -====Reference==== - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - - - -==Cloud== - - -===Aws create policy version to allow all resources=== -This search looks for AWS CloudTrail events where a user created a policy version that allows them to access any resource in their account - -* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/004/ T1078.004], [https://attack.mitre.org/techniques/T1078/ T1078] -* '''Last Updated''': 2021-02-22 - -
-
- -====Search==== -`cloudtrail` eventName=CreatePolicyVersion eventSource = iam.amazonaws.com errorCode = success -| spath input=requestParameters.policyDocument output=key_policy_statements path=Statement{} -| mvexpand key_policy_statements -| spath input=key_policy_statements output=key_policy_action_1 path=Action -| search key_policy_action_1 = "*" -| stats count min(_time) as firstTime max(_time) as lastTime values(key_policy_statements) as policy_added by eventName eventSource aws_account_id errorCode userAgent eventID awsRegion userIdentity.principalId user_arn -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -|`aws_create_policy_version_to_allow_all_resources_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#AWS_IAM_Privilege_Escalation|AWS IAM Privilege Escalation]] - - -====How To Implement==== -You must install splunk AWS add on and Splunk App for AWS. This search works with AWS CloudTrail logs. - -====Required field==== - -* _time - -* eventName - -* userAgent - -* errorCode - -* requestParameters.userName - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1078.004 -| Cloud Accounts -| Defense Evasion, Persistence, Privilege Escalation, Initial Access -|- -| T1078 -| Valid Accounts -| Defense Evasion, Persistence, Privilege Escalation, Initial Access -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -While this search has no known false positives, it is possible that an AWS admin has legitimately created a policy to allow a user to access all resources. That said, AWS strongly advises against granting full control to all AWS resources - -====Reference==== - - -* https://labs.bishopfox.com/tech-blog/privilege-escalation-in-aws - -* https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation-part-2/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_create_policy_version/aws_cloudtrail_events.json - - -''version'': 2 -
-
- ----- - -===Aws createaccesskey=== -This search looks for AWS CloudTrail events where a user A who has already permission to create access keys, makes an API call to create access keys for another user B. Attackers have been know to use this technique for Privilege Escalation in case new victim(user B) has more permissions than old victim(user B) - -* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1136/003/ T1136.003], [https://attack.mitre.org/techniques/T1136/ T1136] -* '''Last Updated''': 2021-07-19 - -
-
- -====Search==== -`cloudtrail` eventName = CreateAccessKey userAgent !=console.amazonaws.com errorCode = success -| search userIdentity.userName!=requestParameters.userName -| stats count min(_time) as firstTime max(_time) as lastTime by requestParameters.userName src eventName eventSource aws_account_id errorCode userAgent eventID awsRegion userIdentity.principalId user_arn -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -|`aws_createaccesskey_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#AWS_IAM_Privilege_Escalation|AWS IAM Privilege Escalation]] - - -====How To Implement==== -You must install splunk AWS add on and Splunk App for AWS. This search works with AWS CloudTrail logs. - -====Required field==== - -* _time - -* eventName - -* userAgent - -* errorCode - -* requestParameters.userName - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1136.003 -| Cloud Account -| Persistence -|- -| T1136 -| Create Account -| Persistence -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -While this search has no known false positives, it is possible that an AWS admin has legitimately created keys for another user. - -====Reference==== - - -* https://labs.bishopfox.com/tech-blog/privilege-escalation-in-aws - -* https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation-part-2/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_createaccesskey/aws_cloudtrail_events.json - - -''version'': 2 -
-
- ----- - -===Aws createloginprofile=== -This search looks for AWS CloudTrail events where a user A(victim A) creates a login profile for user B, followed by a AWS Console login event from user B from the same src_ip as user B. This correlated event can be indicative of privilege escalation since both events happened from the same src_ip - -* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1136/003/ T1136.003], [https://attack.mitre.org/techniques/T1136/ T1136] -* '''Last Updated''': 2021-07-19 - -
-
- -====Search==== -`cloudtrail` eventName = CreateLoginProfile -| rename requestParameters.userName as new_login_profile -| table src_ip eventName new_login_profile userIdentity.userName -| join new_login_profile src_ip [ -| search `cloudtrail` eventName = ConsoleLogin -| rename userIdentity.userName as new_login_profile -| stats count values(eventName) min(_time) as firstTime max(_time) as lastTime by eventSource aws_account_id errorCode userAgent eventID awsRegion userIdentity.principalId user_arn new_login_profile src_ip -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)`] -| `aws_createloginprofile_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#AWS_IAM_Privilege_Escalation|AWS IAM Privilege Escalation]] - - -====How To Implement==== -You must install splunk AWS add on and Splunk App for AWS. This search works with AWS CloudTrail logs. - -====Required field==== - -* _time - -* eventName - -* userAgent - -* errorCode - -* requestParameters.userName - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1136.003 -| Cloud Account -| Persistence -|- -| T1136 -| Create Account -| Persistence -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -While this search has no known false positives, it is possible that an AWS admin has legitimately created a login profile for another user. - -====Reference==== - - -* https://labs.bishopfox.com/tech-blog/privilege-escalation-in-aws - -* https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation-part-2/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_createloginprofile/aws_cloudtrail_events.json - - -''version'': 2 -
-
- ----- - -===Aws cross account activity from previously unseen account=== -This search looks for AssumeRole events where an IAM role in a different account is requested for the first time. - -* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Authentication -* '''ATT&CK''': -* '''Last Updated''': 2020-05-28 - -
-
- -====Search==== - -| tstats min(_time) as firstTime max(_time) as lastTime from datamodel=Authentication where Authentication.signature=AssumeRole by Authentication.vendor_account Authentication.user Authentication.src Authentication.user_role -| `drop_dm_object_name(Authentication)` -| rex field=user_role "arn:aws:sts:*:(?<dest_account>.*):" -| where vendor_account != dest_account -| rename vendor_account as requestingAccountId dest_account as requestedAccountId -| lookup previously_seen_aws_cross_account_activity requestingAccountId, requestedAccountId, OUTPUTNEW firstTime -| eval status = if(firstTime > relative_time(now(), "-24h@h"),"New Cross Account Activity","Previously Seen") -| where status = "New Cross Account Activity" -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `aws_cross_account_activity_from_previously_unseen_account_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Cloud_Authentication_Activities|Suspicious Cloud Authentication Activities]] - - -====How To Implement==== -You must be ingesting your cloud infrastructure logs from your cloud provider. You should run the baseline search `Previously Seen AWS Cross Account Activity - Initial` to build the initial table of source IP address, geographic locations, and times. You must also enable the second baseline search `Previously Seen AWS Cross Account Activity - Update` to keep this table up to date and to age out old data. You can also provide additional filtering for this search by customizing the `aws_cross_account_activity_from_previously_unseen_account_filter` macro. - -====Required field==== - -* _time - -* Authentication.signature - -* Authentication.vendor_account - -* Authentication.user - -* Authentication.user_role - -* Authentication.src - - - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Using multiple AWS accounts and roles is perfectly valid behavior. It's suspicious when an account requests privileges of an account it hasn't before. You should validate with the account owner that this is a legitimate request. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json - - -''version'': 1 -
-
- ----- - -===Aws detect users creating keys with encrypt policy without mfa=== -This search provides detection of KMS keys where action kms:Encrypt is accessible for everyone (also outside of your organization). This is an indicator that your account is compromised and the attacker uses the encryption key to compromise another company. - -* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1486/ T1486] -* '''Last Updated''': 2021-01-11 - -
-
- -====Search==== -`cloudtrail` eventName=CreateKey OR eventName=PutKeyPolicy -| spath input=requestParameters.policy output=key_policy_statements path=Statement{} -| mvexpand key_policy_statements -| spath input=key_policy_statements output=key_policy_action_1 path=Action -| spath input=key_policy_statements output=key_policy_action_2 path=Action{} -| eval key_policy_action=mvappend(key_policy_action_1, key_policy_action_2) -| spath input=key_policy_statements output=key_policy_principal path=Principal.AWS -| search key_policy_action="kms:Encrypt" AND key_policy_principal="*" -| stats count min(_time) as firstTime max(_time) as lastTime by eventName eventSource eventID awsRegion userIdentity.principalId -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -|`aws_detect_users_creating_keys_with_encrypt_policy_without_mfa_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Ransomware_Cloud|Ransomware Cloud]] - - -====How To Implement==== -You must install splunk AWS add on and Splunk App for AWS. This search works with AWS CloudTrail logs - -====Required field==== - -* _time - -* eventName - -* eventSource - -* eventID - -* awsRegion - -* requestParameters.policy - -* userIdentity.principalId - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1486 -| Data Encrypted for Impact -| Impact -|} - - -====Kill Chain Phase==== - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://rhinosecuritylabs.com/aws/s3-ransomware-part-1-attack-vector/ - -* https://github.com/d1vious/git-wild-hunt - -* https://www.youtube.com/watch?v=PgzNib37g0M - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1486/aws_kms_key/aws_cloudtrail_events.json - - -''version'': 1 -
-
- ----- - -===Aws detect users with kms keys performing encryption s3=== -This search provides detection of users with KMS keys performing encryption specifically against S3 buckets. - -* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1486/ T1486] -* '''Last Updated''': 2021-01-11 - -
-
- -====Search==== -`cloudtrail` eventName=CopyObject requestParameters.x-amz-server-side-encryption="aws:kms" -| rename requestParameters.bucketName AS bucket_name, requestParameters.x-amz-copy-source AS src_file, requestParameters.key AS dest_file -| stats count min(_time) as firstTime max(_time) as lastTime values(src_file) AS src_file values(dest_file) AS dest_file values(userAgent) AS userAgent values(region) AS region values(src) AS src by user -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -|`aws_detect_users_with_kms_keys_performing_encryption_s3_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Ransomware_Cloud|Ransomware Cloud]] - - -====How To Implement==== -You must install splunk AWS add on and Splunk App for AWS. This search works with AWS CloudTrail logs - -====Required field==== - -* _time - -* eventName - -* requestParameters.x-amz-server-side-encryption - -* requestParameters.bucketName - -* requestParameters.x-amz-copy-source - -* requestParameters.key - -* userAgent - -* region - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1486 -| Data Encrypted for Impact -| Impact -|} - - -====Kill Chain Phase==== - - -====Known False Positives==== -bucket with S3 encryption - -====Reference==== - - -* https://rhinosecuritylabs.com/aws/s3-ransomware-part-1-attack-vector/ - -* https://github.com/d1vious/git-wild-hunt - -* https://www.youtube.com/watch?v=PgzNib37g0M - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1486/s3_file_encryption/aws_cloudtrail_events.json - - -''version'': 1 -
-
- ----- - -===Aws ecr container scanning findings high=== -This search looks for AWS CloudTrail events from AWS Elastic Container Service (ECR). You need to activate image scanning in order to get the event DescribeImageScanFindings with the results. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud, Dev Sec Ops Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1204/003/ T1204.003], [https://attack.mitre.org/techniques/T1204/ T1204] -* '''Last Updated''': 2021-08-17 - -
-
- -====Search==== -`cloudtrail` eventSource=ecr.amazonaws.com eventName=DescribeImageScanFindings -| spath path=responseElements.imageScanFindings.findings{} output=findings -| mvexpand findings -| spath input=findings -| search severity=HIGH -| rename name as finding_name, description as finding_description, requestParameters.imageId.imageDigest as imageDigest, requestParameters.repositoryName as image -| eval finding = finding_name.", ".finding_description -| eval phase="release" -| eval severity="high" -| stats min(_time) as firstTime max(_time) as lastTime by awsRegion, eventName, eventSource, imageDigest, image, user, userName, src_ip, finding, phase, severity -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `aws_ecr_container_scanning_findings_high_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Dev_Sec_Ops|Dev Sec Ops]] - - -====How To Implement==== -You must install splunk AWS add on and Splunk App for AWS. This search works with AWS CloudTrail logs. - -====Required field==== - -* eventSource - -* eventName - -* responseElements.imageScanFindings.findings{} - -* awsRegion - -* requestParameters.imageId.imageDigest - -* requestParameters.repositoryName - -* user - -* userName - -* src_ip - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1204.003 -| Malicious Image -| Execution -|- -| T1204 -| User Execution -| Execution -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://docs.aws.amazon.com/AmazonECR/latest/userguide/image-scanning.html - - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Aws ecr container scanning findings low informational unknown=== -This search looks for AWS CloudTrail events from AWS Elastic Container Service (ECR). You need to activate image scanning in order to get the event DescribeImageScanFindings with the results. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud, Dev Sec Ops Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1204/003/ T1204.003], [https://attack.mitre.org/techniques/T1204/ T1204] -* '''Last Updated''': 2021-08-17 - -
-
- -====Search==== -`cloudtrail` eventSource=ecr.amazonaws.com eventName=DescribeImageScanFindings -| spath path=responseElements.imageScanFindings.findings{} output=findings -| mvexpand findings -| spath input=findings -| search severity IN (LOW, INFORMATIONAL, UNKNWON) -| rename name as finding_name, description as finding_description, requestParameters.imageId.imageDigest as imageDigest, requestParameters.repositoryName as repositoryName -| eval finding = finding_name.", ".finding_description -| eval phase="release" -| eval severity="low" -| stats min(_time) as firstTime max(_time) as lastTime by awsRegion, eventName, eventSource, imageDigest, repositoryName, user, userName, src_ip, finding, phase, severity -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `aws_ecr_container_scanning_findings_low_informational_unknown_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Dev_Sec_Ops|Dev Sec Ops]] - - -====How To Implement==== -You must install splunk AWS add on and Splunk App for AWS. This search works with AWS CloudTrail logs. - -====Required field==== - -* eventSource - -* eventName - -* responseElements.imageScanFindings.findings{} - -* awsRegion - -* requestParameters.imageId.imageDigest - -* requestParameters.repositoryName - -* user - -* userName - -* src_ip - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1204.003 -| Malicious Image -| Execution -|- -| T1204 -| User Execution -| Execution -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://docs.aws.amazon.com/AmazonECR/latest/userguide/image-scanning.html - - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Aws ecr container scanning findings medium=== -This search looks for AWS CloudTrail events from AWS Elastic Container Service (ECR). You need to activate image scanning in order to get the event DescribeImageScanFindings with the results. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud, Dev Sec Ops Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1204/003/ T1204.003], [https://attack.mitre.org/techniques/T1204/ T1204] -* '''Last Updated''': 2021-08-17 - -
-
- -====Search==== -`cloudtrail` eventSource=ecr.amazonaws.com eventName=DescribeImageScanFindings -| spath path=responseElements.imageScanFindings.findings{} output=findings -| mvexpand findings -| spath input=findings -| search severity=MEDIUM -| rename name as finding_name, description as finding_description, requestParameters.imageId.imageDigest as imageDigest, requestParameters.repositoryName as image -| eval finding = finding_name.", ".finding_description -| eval phase="release" -| eval severity="medium" -| stats min(_time) as firstTime max(_time) as lastTime by awsRegion, eventName, eventSource, imageDigest, image, user, userName, src_ip, finding, phase, severity -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `aws_ecr_container_scanning_findings_medium_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Dev_Sec_Ops|Dev Sec Ops]] - - -====How To Implement==== -You must install splunk AWS add on and Splunk App for AWS. This search works with AWS CloudTrail logs. - -====Required field==== - -* eventSource - -* eventName - -* responseElements.imageScanFindings.findings{} - -* awsRegion - -* requestParameters.imageId.imageDigest - -* requestParameters.repositoryName - -* user - -* userName - -* src_ip - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1204.003 -| Malicious Image -| Execution -|- -| T1204 -| User Execution -| Execution -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://docs.aws.amazon.com/AmazonECR/latest/userguide/image-scanning.html - - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Aws ecr container upload outside business hours=== -This search looks for AWS CloudTrail events from AWS Elastic Container Service (ECR). A upload of a new container is normally done during business hours. When done outside business hours, we want to take a look into it. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud, Dev Sec Ops Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1204/003/ T1204.003], [https://attack.mitre.org/techniques/T1204/ T1204] -* '''Last Updated''': 2021-08-19 - -
-
- -====Search==== -`cloudtrail` eventSource=ecr.amazonaws.com eventName=PutImage date_hour>=20 OR date_hour<8 NOT (date_wday=saturday OR date_wday=sunday) -| rename requestParameters.* as * -| rename repositoryName AS image -| eval phase="release" -| eval severity="medium" -| stats min(_time) as firstTime max(_time) as lastTime by awsRegion, eventName, eventSource, user, userName, src_ip, imageTag, registryId, image, phase, severity -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `aws_ecr_container_upload_outside_business_hours_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Dev_Sec_Ops|Dev Sec Ops]] - - -====How To Implement==== -You must install splunk AWS add on and Splunk App for AWS. This search works with AWS CloudTrail logs. - -====Required field==== - -* eventSource - -* eventName - -* awsRegion - -* requestParameters.imageTag - -* requestParameters.registryId - -* requestParameters.repositoryName - -* user - -* userName - -* src_ip - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1204.003 -| Malicious Image -| Execution -|- -| T1204 -| User Execution -| Execution -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -When your development is spreaded in different time zones, applying this rule can be difficult. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1204/003/ - - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Aws ecr container upload unknown user=== -This search looks for AWS CloudTrail events from AWS Elastic Container Service (ECR). A upload of a new container is normally done from only a few known users. When the user was never seen before, we should have a closer look into the event. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud, Dev Sec Ops Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1204/003/ T1204.003], [https://attack.mitre.org/techniques/T1204/ T1204] -* '''Last Updated''': 2021-08-19 - -
-
- -====Search==== -`cloudtrail` eventSource=ecr.amazonaws.com eventName=PutImage NOT `aws_ecr_users` -| rename requestParameters.* as * -| rename repositoryName AS image -| eval phase="release" -| eval severity="high" -| stats min(_time) as firstTime max(_time) as lastTime by awsRegion, eventName, eventSource, user, userName, src_ip, imageTag, registryId, image, phase, severity -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `aws_ecr_container_upload_unknown_user_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Dev_Sec_Ops|Dev Sec Ops]] - - -====How To Implement==== -You must install splunk AWS add on and Splunk App for AWS. This search works with AWS CloudTrail logs. - -====Required field==== - -* eventSource - -* eventName - -* awsRegion - -* requestParameters.imageTag - -* requestParameters.registryId - -* requestParameters.repositoryName - -* user - -* userName - -* src_ip - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1204.003 -| Malicious Image -| Execution -|- -| T1204 -| User Execution -| Execution -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://attack.mitre.org/techniques/T1204/003/ - - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Aws excessive security scanning=== -This search looks for AWS CloudTrail events and analyse the amount of eventNames which starts with Describe by a single user. This indicates that this user scans the configuration of your AWS cloud environment. - -* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1526/ T1526] -* '''Last Updated''': 2021-04-13 - -
-
- -====Search==== -`cloudtrail` eventName=Describe* OR eventName=List* OR eventName=Get* -| stats dc(eventName) as dc_events min(_time) as firstTime max(_time) as lastTime values(eventName) as eventName values(src) as src values(userAgent) as userAgent by user userIdentity.arn -| where dc_events > 50 -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -|`aws_excessive_security_scanning_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#AWS_User_Monitoring|AWS User Monitoring]] - - -====How To Implement==== -You must install splunk AWS add on and Splunk App for AWS. This search works with AWS CloudTrail logs. - -====Required field==== - -* _time - -* eventName - -* src - -* userAgent - -* user - -* userIdentity.arn - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1526 -| Cloud Service Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -While this search has no known false positives. - -====Reference==== - - -* https://github.com/aquasecurity/cloudsploit - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1526/aws_security_scanner/aws_security_scanner.json - - -''version'': 1 -
-
- ----- - -===Aws iam accessdenied discovery events=== -The following detection identifies excessive AccessDenied events within an hour timeframe. It is possible that an access key to AWS may have been stolen and is being misused to perform discovery events. In these instances, the access is not available with the key stolen therefore these events will be generated. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud, Splunk Security Analytics for AWS -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1580/ T1580] -* '''Last Updated''': 2021-04-05 - -
-
- -====Search==== -`cloudtrail` (errorCode = "AccessDenied") user_type=IAMUser (userAgent!=*.amazonaws.com) -| bucket _time span=1h -| stats count as failures min(_time) as firstTime max(_time) as lastTime, dc(eventName) as methods, dc(eventSource) as sources values(userIdentity.arn) by src_ip, userIdentity.arn, _time -| where failures >= 5 and methods >= 1 and sources >= 1 -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `aws_iam_accessdenied_discovery_events_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Cloud_User_Activities|Suspicious Cloud User Activities]] - - -====How To Implement==== -The Splunk AWS Add-on and Splunk App for AWS is required to utilize this data. The search requires AWS Cloudtrail logs. - -====Required field==== - -* _time - -* eventName - -* eventSource - -* userAgent - -* errorCode - -* userIdentity.type - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1580 -| Cloud Infrastructure Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -It is possible to start this detection will need to be tuned by source IP or user. In addition, change the count values to an upper threshold to restrict false positives. - -====Reference==== - - -* https://aws.amazon.com/premiumsupport/knowledge-center/troubleshoot-iam-permission-errors/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1580/aws_iam_accessdenied_discovery_events/aws_iam_accessdenied_discovery_events.json - - -''version'': 1 -
-
- ----- - -===Aws iam assume role policy brute force=== -The following detection identifies any malformed policy document exceptions with a status of `failure`. A malformed policy document exception occurs in instances where roles are attempted to be assumed, or brute forced. In a brute force attempt, using a tool like CloudSploit or Pacu, an attempt will look like `arn:aws:iam::111111111111:role/aws-service-role/rds.amazonaws.com/AWSServiceRoleForRDS`. Meaning, when an adversary is attempting to identify a role name, multiple failures will occur. This detection focuses on the errors of a remote attempt that is failing. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud, Splunk Security Analytics for AWS -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1580/ T1580], [https://attack.mitre.org/techniques/T1110/ T1110] -* '''Last Updated''': 2021-04-01 - -
-
- -====Search==== -`cloudtrail` (errorCode=MalformedPolicyDocumentException) status=failure (userAgent!=*.amazonaws.com) -| stats count min(_time) as firstTime max(_time) as lastTime values(requestParameters.policyName) as policy_name by src eventName eventSource aws_account_id errorCode requestParameters.policyDocument userAgent eventID awsRegion userIdentity.principalId user_arn -| where count >= 2 -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `aws_iam_assume_role_policy_brute_force_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#AWS_IAM_Privilege_Escalation|AWS IAM Privilege Escalation]] - - -====How To Implement==== -The Splunk AWS Add-on and Splunk App for AWS is required to utilize this data. The search requires AWS Cloudtrail logs. Set the `where count` greater than a value to identify suspicious activity in your environment. - -====Required field==== - -* _time - -* eventName - -* userAgent - -* errorCode - -* requestParameters.policyName - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1580 -| Cloud Infrastructure Discovery -| Discovery -|- -| T1110 -| Brute Force -| Credential Access -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -This detection will require tuning to provide high fidelity detection capabilties. Tune based on src addresses (corporate offices, VPN terminations) or by groups of users. - -====Reference==== - - -* https://www.praetorian.com/blog/aws-iam-assume-role-vulnerabilities - -* https://rhinosecuritylabs.com/aws/assume-worst-aws-assume-role-enumeration/ - -* https://www.elastic.co/guide/en/security/current/aws-iam-brute-force-of-assume-role-policy.html - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1580/aws_iam_assume_role_policy_brute_force/aws_iam_assume_role_policy_brute_force.json - - -''version'': 1 -
-
- ----- - -===Aws iam delete policy=== -The following detection identifes when a policy is deleted on AWS. This does not identify whether successful or failed, but the error messages tell a story of suspicious attempts. There is a specific process to follow when deleting a policy. First, detach the policy from all users, groups, and roles that the policy is attached to, using DetachUserPolicy , DetachGroupPolicy , or DetachRolePolicy. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud, Splunk Security Analytics for AWS -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1098/ T1098] -* '''Last Updated''': 2021-04-01 - -
-
- -====Search==== -`cloudtrail` eventName=DeletePolicy (userAgent!=*.amazonaws.com) -| stats count min(_time) as firstTime max(_time) as lastTime values(requestParameters.policyArn) as policyArn by src eventName eventSource aws_account_id errorCode errorMessage userAgent eventID awsRegion userIdentity.principalId userIdentity.arn -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `aws_iam_delete_policy_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#AWS_IAM_Privilege_Escalation|AWS IAM Privilege Escalation]] - - -====How To Implement==== -The Splunk AWS Add-on and Splunk App for AWS is required to utilize this data. The search requires AWS Cloudtrail logs. - -====Required field==== - -* _time - -* eventName - -* userAgent - -* errorCode - -* requestParameters.policyArn - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1098 -| Account Manipulation -| Persistence -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -This detection will require tuning to provide high fidelity detection capabilties. Tune based on src addresses (corporate offices, VPN terminations) or by groups of users. Not every user with AWS access should have permission to delete policies (least privilege). In addition, this may be saved seperately and tuned for failed or success attempts only. - -====Reference==== - - -* https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeletePolicy.html - -* https://docs.aws.amazon.com/cli/latest/reference/iam/delete-policy.html - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/aws_iam_delete_policy/aws_iam_delete_policy.json - - -''version'': 1 -
-
- ----- - -===Aws iam failure group deletion=== -This detection identifies failure attempts to delete groups. We want to identify when a group is attempting to be deleted, but either access is denied, there is a conflict or there is no group. This is indicative of administrators performing an action, but also could be suspicious behavior occurring. Review parallel IAM events - recently added users, new groups and so forth. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud, Splunk Security Analytics for AWS -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1098/ T1098] -* '''Last Updated''': 2021-04-01 - -
-
- -====Search==== -`cloudtrail` eventSource=iam.amazonaws.com eventName=DeleteGroup errorCode IN (NoSuchEntityException,DeleteConflictException, AccessDenied) (userAgent!=*.amazonaws.com) -| stats count min(_time) as firstTime max(_time) as lastTime values(requestParameters.groupName) as group_name by src eventName eventSource aws_account_id errorCode errorMessage userAgent eventID awsRegion userIdentity.principalId user_arn -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `aws_iam_failure_group_deletion_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#AWS_IAM_Privilege_Escalation|AWS IAM Privilege Escalation]] - - -====How To Implement==== -The Splunk AWS Add-on and Splunk App for AWS is required to utilize this data. The search requires AWS Cloudtrail logs. - -====Required field==== - -* _time - -* eventName - -* userAgent - -* errorCode - -* requestParameters.groupName - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1098 -| Account Manipulation -| Persistence -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -This detection will require tuning to provide high fidelity detection capabilties. Tune based on src addresses (corporate offices, VPN terminations) or by groups of users. Not every user with AWS access should have permission to delete groups (least privilege). - -====Reference==== - - -* https://awscli.amazonaws.com/v2/documentation/api/latest/reference/iam/delete-group.html - -* https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeleteGroup.html - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/aws_iam_failure_group_deletion/aws_iam_failure_group_deletion.json - - -''version'': 1 -
-
- ----- - -===Aws iam successful group deletion=== -The following query uses IAM events to track the success of a group being deleted on AWS. This is typically not indicative of malicious behavior, but a precurser to additional events thay may unfold. Review parallel IAM events - recently added users, new groups and so forth. Inversely, review failed attempts in a similar manner. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud, Splunk Security Analytics for AWS -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1069/003/ T1069.003], [https://attack.mitre.org/techniques/T1098/ T1098], [https://attack.mitre.org/techniques/T1069/ T1069] -* '''Last Updated''': 2021-03-31 - -
-
- -====Search==== -`cloudtrail` eventSource=iam.amazonaws.com eventName=DeleteGroup errorCode=success (userAgent!=*.amazonaws.com) -| stats count min(_time) as firstTime max(_time) as lastTime values(requestParameters.groupName) as group_deleted by src eventName eventSource errorCode user_agent awsRegion userIdentity.principalId user_arn -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `aws_iam_successful_group_deletion_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#AWS_IAM_Privilege_Escalation|AWS IAM Privilege Escalation]] - - -====How To Implement==== -The Splunk AWS Add-on and Splunk App for AWS is required to utilize this data. The search requires AWS Cloudtrail logs. - -====Required field==== - -* _time - -* eventName - -* userAgent - -* errorCode - -* requestParameters.groupName - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1069.003 -| Cloud Groups -| Discovery -|- -| T1098 -| Account Manipulation -| Persistence -|- -| T1069 -| Permission Groups Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -This detection will require tuning to provide high fidelity detection capabilties. Tune based on src addresses (corporate offices, VPN terminations) or by groups of users. Not every user with AWS access should have permission to delete groups (least privilege). - -====Reference==== - - -* https://awscli.amazonaws.com/v2/documentation/api/latest/reference/iam/delete-group.html - -* https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeleteGroup.html - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/aws_iam_successful_group_deletion/aws_iam_successful_group_deletion.json - - -''version'': 1 -
-
- ----- - -===Aws network access control list created with all open ports=== -The search looks for AWS CloudTrail events to detect if any network ACLs were created with all the ports open to a specified CIDR. - -* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/007/ T1562.007], [https://attack.mitre.org/techniques/T1562/ T1562] -* '''Last Updated''': 2021-01-11 - -
-
- -====Search==== -`cloudtrail` eventName=CreateNetworkAclEntry OR eventName=ReplaceNetworkAclEntry requestParameters.ruleAction=allow requestParameters.egress=false requestParameters.aclProtocol=-1 -| append [search `cloudtrail` eventName=CreateNetworkAclEntry OR eventName=ReplaceNetworkAclEntry requestParameters.ruleAction=allow requestParameters.egress=false requestParameters.aclProtocol!=-1 -| eval port_range='requestParameters.portRange.to' - 'requestParameters.portRange.from' -| where port_range>1024] -| fillnull -| stats count min(_time) as firstTime max(_time) as lastTime by userName userIdentity.principalId eventName requestParameters.ruleAction requestParameters.egress requestParameters.aclProtocol requestParameters.portRange.to requestParameters.portRange.from src userAgent requestParameters.cidrBlock -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `aws_network_access_control_list_created_with_all_open_ports_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#AWS_Network_ACL_Activity|AWS Network ACL Activity]] - - -====How To Implement==== -You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS, version 4.4.0 or later, and configure your AWS CloudTrail inputs. - -====Required field==== - -* _time - -* eventName - -* requestParameters.ruleAction - -* requestParameters.egress - -* requestParameters.aclProtocol - -* requestParameters.portRange.to - -* requestParameters.portRange.from - -* requestParameters.cidrBlock - -* userName - -* userIdentity.principalId - -* userAgent - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1562.007 -| Disable or Modify Cloud Firewall -| Defense Evasion -|- -| T1562 -| Impair Defenses -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -It's possible that an admin has created this ACL with all ports open for some legitimate purpose however, this should be scoped and not allowed in production environment. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.007/aws_create_acl/aws_cloudtrail_events.json - - -''version'': 2 -
-
- ----- - -===Aws network access control list deleted=== -Enforcing network-access controls is one of the defensive mechanisms used by cloud administrators to restrict access to a cloud instance. After the attacker has gained control of the AWS console by compromising an admin account, they can delete a network ACL and gain access to the instance from anywhere. This search will query the AWS CloudTrail logs to detect users deleting network ACLs. - -* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/007/ T1562.007], [https://attack.mitre.org/techniques/T1562/ T1562] -* '''Last Updated''': 2021-01-12 - -
-
- -====Search==== -`cloudtrail` eventName=DeleteNetworkAclEntry requestParameters.egress=false -| fillnull -| stats count min(_time) as firstTime max(_time) as lastTime by userName userIdentity.principalId eventName requestParameters.egress src userAgent -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `aws_network_access_control_list_deleted_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#AWS_Network_ACL_Activity|AWS Network ACL Activity]] - - -====How To Implement==== -You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your AWS CloudTrail inputs. - -====Required field==== - -* _time - -* eventName - -* requestParameters.egress - -* userName - -* userIdentity.principalId - -* src - -* userAgent - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1562.007 -| Disable or Modify Cloud Firewall -| Defense Evasion -|- -| T1562 -| Impair Defenses -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -It's possible that a user has legitimately deleted a network ACL. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.007/aws_delete_acl/aws_cloudtrail_events.json - - -''version'': 2 -
-
- ----- - -===Aws saml access by provider user and principal=== -This search provides specific SAML access from specific Service Provider, user and targeted principal at AWS. This search provides specific information to detect abnormal access or potential credential hijack or forgery, specially in federated environments using SAML protocol inside the perimeter or cloud provider. - -* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/ T1078] -* '''Last Updated''': 2021-01-26 - -
-
- -====Search==== -`cloudtrail` eventName=Assumerolewithsaml -| stats count min(_time) as firstTime max(_time) as lastTime by requestParameters.principalArn requestParameters.roleArn requestParameters.roleSessionName recipientAccountId responseElements.issuer sourceIPAddress userAgent -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -|`aws_saml_access_by_provider_user_and_principal_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Cloud_Federated_Credential_Abuse|Cloud Federated Credential Abuse]] - - -====How To Implement==== -You must install splunk AWS add on and Splunk App for AWS. This search works with AWS CloudTrail logs - -====Required field==== - -* _time - -* eventName - -* requestParameters.principalArn - -* requestParameters.roleArn - -* requestParameters.roleSessionName - -* recipientAccountId - -* responseElements.issuer - -* sourceIPAddress - -* userAgent - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1078 -| Valid Accounts -| Defense Evasion, Persistence, Privilege Escalation, Initial Access -|} - - -====Kill Chain Phase==== - - -====Known False Positives==== -Attacks using a Golden SAML or SAML assertion hijacks or forgeries are very difficult to detect as accessing cloud providers with these assertions looks exactly like normal access, however things such as source IP sourceIPAddress user, and principal targeted at receiving cloud provider along with endpoint credential access and abuse detection searches can provide the necessary context to detect these attacks. - -====Reference==== - - -* https://us-cert.cisa.gov/ncas/alerts/aa21-008a - -* https://www.splunk.com/en_us/blog/security/a-golden-saml-journey-solarwinds-continued.html - -* https://www.fireeye.com/content/dam/fireeye-www/blog/pdfs/wp-m-unc2452-2021-000343-01.pdf - -* https://www.cyberark.com/resources/threat-research-blog/golden-saml-newly-discovered-attack-technique-forges-authentication-to-cloud-apps - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/assume_role_with_saml/assume_role_with_saml.json - - -''version'': 1 -
-
- ----- - -===Aws saml update identity provider=== -This search provides detection of updates to SAML provider in AWS. Updates to SAML provider need to be monitored closely as they may indicate possible perimeter compromise of federated credentials, or backdoor access from another cloud provider set by attacker. - -* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/ T1078] -* '''Last Updated''': 2021-01-26 - -
-
- -====Search==== -`cloudtrail` eventName=UpdateSAMLProvider -| stats count min(_time) as firstTime max(_time) as lastTime by eventType eventName requestParameters.sAMLProviderArn userIdentity.sessionContext.sessionIssuer.arn sourceIPAddress userIdentity.accessKeyId userIdentity.principalId -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -|`aws_saml_update_identity_provider_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Cloud_Federated_Credential_Abuse|Cloud Federated Credential Abuse]] - - -====How To Implement==== -You must install splunk AWS add on and Splunk App for AWS. This search works with AWS CloudTrail logs. - -====Required field==== - -* _time - -* eventName - -* eventType - -* requestParameters.sAMLProviderArn - -* userIdentity.sessionContext.sessionIssuer.arn - -* sourceIPAddress - -* userIdentity.accessKeyId - -* userIdentity.principalId - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1078 -| Valid Accounts -| Defense Evasion, Persistence, Privilege Escalation, Initial Access -|} - - -====Kill Chain Phase==== - - -====Known False Positives==== -Updating a SAML provider or creating a new one may not necessarily be malicious however it needs to be closely monitored. - -====Reference==== - - -* https://us-cert.cisa.gov/ncas/alerts/aa21-008a - -* https://www.splunk.com/en_us/blog/security/a-golden-saml-journey-solarwinds-continued.html - -* https://www.fireeye.com/content/dam/fireeye-www/blog/pdfs/wp-m-unc2452-2021-000343-01.pdf - -* https://www.cyberark.com/resources/threat-research-blog/golden-saml-newly-discovered-attack-technique-forges-authentication-to-cloud-apps - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/update_saml_provider/update_saml_provider.json - - -''version'': 1 -
-
- ----- - -===Aws setdefaultpolicyversion=== -This search looks for AWS CloudTrail events where a user has set a default policy versions. Attackers have been know to use this technique for Privilege Escalation in case the previous versions of the policy had permissions to access more resources than the current version of the policy - -* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/004/ T1078.004], [https://attack.mitre.org/techniques/T1078/ T1078] -* '''Last Updated''': 2021-03-02 - -
-
- -====Search==== -`cloudtrail` eventName=SetDefaultPolicyVersion eventSource = iam.amazonaws.com -| stats count min(_time) as firstTime max(_time) as lastTime values(requestParameters.policyArn) as policy_arn by src requestParameters.versionId eventName eventSource aws_account_id errorCode userAgent eventID awsRegion userIdentity.principalId user_arn -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `aws_setdefaultpolicyversion_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#AWS_IAM_Privilege_Escalation|AWS IAM Privilege Escalation]] - - -====How To Implement==== -You must install splunk AWS add on and Splunk App for AWS. This search works with AWS CloudTrail logs. - -====Required field==== - -* _time - -* eventName - -* userAgent - -* errorCode - -* requestParameters.userName - -* eventSource - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1078.004 -| Cloud Accounts -| Defense Evasion, Persistence, Privilege Escalation, Initial Access -|- -| T1078 -| Valid Accounts -| Defense Evasion, Persistence, Privilege Escalation, Initial Access -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -While this search has no known false positives, it is possible that an AWS admin has legitimately set a default policy to allow a user to access all resources. That said, AWS strongly advises against granting full control to all AWS resources - -====Reference==== - - -* https://labs.bishopfox.com/tech-blog/privilege-escalation-in-aws - -* https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation-part-2/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_setdefaultpolicyversion/aws_cloudtrail_events.json - - -''version'': 1 -
-
- ----- - -===Aws updateloginprofile=== -This search looks for AWS CloudTrail events where a user A who has already permission to update login profile, makes an API call to update login profile for another user B . Attackers have been know to use this technique for Privilege Escalation in case new victim(user B) has more permissions than old victim(user B) - -* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1136/003/ T1136.003], [https://attack.mitre.org/techniques/T1136/ T1136] -* '''Last Updated''': 2021-07-19 - -
-
- -====Search==== -`cloudtrail` eventName = UpdateLoginProfile userAgent !=console.amazonaws.com errorCode = success -| search userIdentity.userName!=requestParameters.userName -| stats count min(_time) as firstTime max(_time) as lastTime by requestParameters.userName src eventName eventSource aws_account_id errorCode userAgent eventID awsRegion userIdentity.userName user_arn -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -|`aws_updateloginprofile_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#AWS_IAM_Privilege_Escalation|AWS IAM Privilege Escalation]] - - -====How To Implement==== -You must install splunk AWS add on and Splunk App for AWS. This search works with AWS CloudTrail logs. - -====Required field==== - -* _time - -* eventName - -* userAgent - -* errorCode - -* requestParameters.userName - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1136.003 -| Cloud Account -| Persistence -|- -| T1136 -| Create Account -| Persistence -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -While this search has no known false positives, it is possible that an AWS admin has legitimately created keys for another user. - -====Reference==== - - -* https://labs.bishopfox.com/tech-blog/privilege-escalation-in-aws - -* https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation-part-2/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_updateloginprofile/aws_cloudtrail_events.json - - -''version'': 2 -
-
- ----- - -===Abnormally high number of cloud infrastructure api calls=== -This search will detect a spike in the number of API calls made to your cloud infrastructure environment by a user. - -* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Change -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/004/ T1078.004], [https://attack.mitre.org/techniques/T1078/ T1078] -* '''Last Updated''': 2020-09-07 - -
-
- -====Search==== - -| tstats count as api_calls values(All_Changes.command) as command from datamodel=Change where All_Changes.user!=unknown All_Changes.status=success by All_Changes.user _time span=1h -| `drop_dm_object_name("All_Changes")` -| eval HourOfDay=strftime(_time, "%H") -| eval HourOfDay=floor(HourOfDay/4)*4 -| eval DayOfWeek=strftime(_time, "%w") -| eval isWeekend=if(DayOfWeek >= 1 AND DayOfWeek <= 5, 0, 1) -| join user HourOfDay isWeekend [ summary cloud_excessive_api_calls_v1] -| where cardinality >=16 -| apply cloud_excessive_api_calls_v1 threshold=0.005 -| rename "IsOutlier(api_calls)" as isOutlier -| where isOutlier=1 -| eval expected_upper_threshold = mvindex(split(mvindex(BoundaryRanges, -1), ":"), 0) -| where api_calls > expected_upper_threshold -| eval distance_from_threshold = api_calls - expected_upper_threshold -| table _time, user, command, api_calls, expected_upper_threshold, distance_from_threshold -| `abnormally_high_number_of_cloud_infrastructure_api_calls_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Cloud_User_Activities|Suspicious Cloud User Activities]] - - -====How To Implement==== -You must be ingesting your cloud infrastructure logs. You also must run the baseline search `Baseline Of Cloud Infrastructure API Calls Per User` to create the probability density function. - -====Required field==== - -* _time - -* All_Changes.command - -* All_Changes.user - -* All_Changes.status - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1078.004 -| Cloud Accounts -| Defense Evasion, Persistence, Privilege Escalation, Initial Access -|- -| T1078 -| Valid Accounts -| Defense Evasion, Persistence, Privilege Escalation, Initial Access -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== - - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json - - -''version'': 1 -
-
- ----- - -===Abnormally high number of cloud instances destroyed=== -This search finds for the number successfully destroyed cloud instances for every 4 hour block. This is split up between weekdays and the weekend. It then applies the probability densitiy model previously created and alerts on any outliers. - -* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Change -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/004/ T1078.004], [https://attack.mitre.org/techniques/T1078/ T1078] -* '''Last Updated''': 2020-08-21 - -
-
- -====Search==== - -| tstats count as instances_destroyed values(All_Changes.object_id) as object_id from datamodel=Change where All_Changes.action=deleted AND All_Changes.status=success AND All_Changes.object_category=instance by All_Changes.user _time span=1h -| `drop_dm_object_name("All_Changes")` -| eval HourOfDay=strftime(_time, "%H") -| eval HourOfDay=floor(HourOfDay/4)*4 -| eval DayOfWeek=strftime(_time, "%w") -| eval isWeekend=if(DayOfWeek >= 1 AND DayOfWeek <= 5, 0, 1) -| join HourOfDay isWeekend [summary cloud_excessive_instances_destroyed_v1] -| where cardinality >=16 -| apply cloud_excessive_instances_destroyed_v1 threshold=0.005 -| rename "IsOutlier(instances_destroyed)" as isOutlier -| where isOutlier=1 -| eval expected_upper_threshold = mvindex(split(mvindex(BoundaryRanges, -1), ":"), 0) -| eval distance_from_threshold = instances_destroyed - expected_upper_threshold -| table _time, user, instances_destroyed, expected_upper_threshold, distance_from_threshold, object_id -| `abnormally_high_number_of_cloud_instances_destroyed_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Cloud_Instance_Activities|Suspicious Cloud Instance Activities]] - - -====How To Implement==== -You must be ingesting your cloud infrastructure logs. You also must run the baseline search `Baseline Of Cloud Instances Destroyed` to create the probability density function. - -====Required field==== - -* _time - -* All_Changes.object_id - -* All_Changes.action - -* All_Changes.status - -* All_Changes.object_category - -* All_Changes.user - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1078.004 -| Cloud Accounts -| Defense Evasion, Persistence, Privilege Escalation, Initial Access -|- -| T1078 -| Valid Accounts -| Defense Evasion, Persistence, Privilege Escalation, Initial Access -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Many service accounts configured within a cloud infrastructure are known to exhibit this behavior. Please adjust the threshold values and filter out service accounts from the output. Always verify if this search alerted on a human user. - -====Reference==== - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Abnormally high number of cloud instances launched=== -This search finds for the number successfully created cloud instances for every 4 hour block. This is split up between weekdays and the weekend. It then applies the probability densitiy model previously created and alerts on any outliers. - -* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Change -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/004/ T1078.004], [https://attack.mitre.org/techniques/T1078/ T1078] -* '''Last Updated''': 2020-08-21 - -
-
- -====Search==== - -| tstats count as instances_launched values(All_Changes.object_id) as object_id from datamodel=Change where (All_Changes.action=created) AND All_Changes.status=success AND All_Changes.object_category=instance by All_Changes.user _time span=1h -| `drop_dm_object_name("All_Changes")` -| eval HourOfDay=strftime(_time, "%H") -| eval HourOfDay=floor(HourOfDay/4)*4 -| eval DayOfWeek=strftime(_time, "%w") -| eval isWeekend=if(DayOfWeek >= 1 AND DayOfWeek <= 5, 0, 1) -| join HourOfDay isWeekend [summary cloud_excessive_instances_created_v1] -| where cardinality >=16 -| apply cloud_excessive_instances_created_v1 threshold=0.005 -| rename "IsOutlier(instances_launched)" as isOutlier -| where isOutlier=1 -| eval expected_upper_threshold = mvindex(split(mvindex(BoundaryRanges, -1), ":"), 0) -| eval distance_from_threshold = instances_launched - expected_upper_threshold -| table _time, user, instances_launched, expected_upper_threshold, distance_from_threshold, object_id -| `abnormally_high_number_of_cloud_instances_launched_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Cloud_Cryptomining|Cloud Cryptomining]] - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Cloud_Instance_Activities|Suspicious Cloud Instance Activities]] - - -====How To Implement==== -You must be ingesting your cloud infrastructure logs. You also must run the baseline search `Baseline Of Cloud Instances Launched` to create the probability density function. - -====Required field==== - -* _time - -* All_Changes.object_id - -* All_Changes.action - -* All_Changes.status - -* All_Changes.object_category - -* All_Changes.user - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1078.004 -| Cloud Accounts -| Defense Evasion, Persistence, Privilege Escalation, Initial Access -|- -| T1078 -| Valid Accounts -| Defense Evasion, Persistence, Privilege Escalation, Initial Access -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Many service accounts configured within an AWS infrastructure are known to exhibit this behavior. Please adjust the threshold values and filter out service accounts from the output. Always verify if this search alerted on a human user. - -====Reference==== - - -====Test Dataset==== - - -''version'': 2 -
-
- ----- - -===Abnormally high number of cloud security group api calls=== -This search will detect a spike in the number of API calls made to your cloud infrastructure environment about security groups by a user. - -* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Change -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/004/ T1078.004], [https://attack.mitre.org/techniques/T1078/ T1078] -* '''Last Updated''': 2020-09-07 - -
-
- -====Search==== - -| tstats count as security_group_api_calls values(All_Changes.command) as command from datamodel=Change where All_Changes.object_category=firewall AND All_Changes.status=success by All_Changes.user _time span=1h -| `drop_dm_object_name("All_Changes")` -| eval HourOfDay=strftime(_time, "%H") -| eval HourOfDay=floor(HourOfDay/4)*4 -| eval DayOfWeek=strftime(_time, "%w") -| eval isWeekend=if(DayOfWeek >= 1 AND DayOfWeek <= 5, 0, 1) -| join user HourOfDay isWeekend [ summary cloud_excessive_security_group_api_calls_v1] -| where cardinality >=16 -| apply cloud_excessive_security_group_api_calls_v1 threshold=0.005 -| rename "IsOutlier(security_group_api_calls)" as isOutlier -| where isOutlier=1 -| eval expected_upper_threshold = mvindex(split(mvindex(BoundaryRanges, -1), ":"), 0) -| where security_group_api_calls > expected_upper_threshold -| eval distance_from_threshold = security_group_api_calls - expected_upper_threshold -| table _time, user, command, security_group_api_calls, expected_upper_threshold, distance_from_threshold -| `abnormally_high_number_of_cloud_security_group_api_calls_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Cloud_User_Activities|Suspicious Cloud User Activities]] - - -====How To Implement==== -You must be ingesting your cloud infrastructure logs. You also must run the baseline search `Baseline Of Cloud Security Group API Calls Per User` to create the probability density function model. - -====Required field==== - -* _time - -* All_Changes.command - -* All_Changes.object_category - -* All_Changes.status - -* All_Changes.user - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1078.004 -| Cloud Accounts -| Defense Evasion, Persistence, Privilege Escalation, Initial Access -|- -| T1078 -| Valid Accounts -| Defense Evasion, Persistence, Privilege Escalation, Initial Access -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== - - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json - - -''version'': 1 -
-
- ----- - -===Amazon eks kubernetes pod scan detection=== -This search provides detection information on unauthenticated requests against Kubernetes' Pods API - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1526/ T1526] -* '''Last Updated''': 2020-04-15 - -
-
- -====Search==== -`aws_cloudwatchlogs_eks` "user.username"="system:anonymous" verb=list objectRef.resource=pods requestURI="/api/v1/pods" -| rename source as cluster_name sourceIPs{} as src_ip -| stats count min(_time) as firstTime max(_time) as lastTime values(responseStatus.reason) values(responseStatus.code) values(userAgent) values(verb) values(requestURI) by src_ip cluster_name user.username user.groups{} -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `amazon_eks_kubernetes_pod_scan_detection_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Kubernetes_Scanning_Activity|Kubernetes Scanning Activity]] - - -====How To Implement==== -You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on forAWS (version 4.4.0 or later), then configure your AWS CloudWatch EKS Logs.Please also customize the `kubernetes_pods_aws_scan_fingerprint_detection` macro to filter out the false positives. - -====Required field==== - -* _time - -* user.username - -* verb - -* objectRef.resource - -* requestURI - -* source - -* sourceIPs{} - -* responseStatus.reason - -* responseStatus.code - -* userAgent - -* src_ip - -* user.groups{} - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1526 -| Cloud Service Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Not all unauthenticated requests are malicious, but frequency, UA and source IPs and direct request to API provide context. - -====Reference==== - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Amazon eks kubernetes cluster scan detection=== -This search provides information of unauthenticated requests via user agent, and authentication data against Kubernetes cluster in AWS - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1526/ T1526] -* '''Last Updated''': 2020-04-15 - -
-
- -====Search==== -`aws_cloudwatchlogs_eks` "user.username"="system:anonymous" userAgent!="AWS Security Scanner" -| rename sourceIPs{} as src_ip -| stats count min(_time) as firstTime max(_time) as lastTime values(responseStatus.reason) values(source) as cluster_name values(responseStatus.code) values(userAgent) as http_user_agent values(verb) values(requestURI) by src_ip user.username user.groups{} -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -|`amazon_eks_kubernetes_cluster_scan_detection_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Kubernetes_Scanning_Activity|Kubernetes Scanning Activity]] - - -====How To Implement==== -You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your CloudWatch EKS Logs inputs. - -====Required field==== - -* _time - -* user.username - -* userAgent - -* sourceIPs{} - -* responseStatus.reason - -* source - -* responseStatus.code - -* verb - -* requestURI - -* src_ip - -* user.groups{} - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1526 -| Cloud Service Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Not all unauthenticated requests are malicious, but frequency, UA and source IPs will provide context. - -====Reference==== - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Circle ci disable security job=== -This search looks for disable security job in CircleCI pipeline. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud, Dev Sec Ops Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1554/ T1554] -* '''Last Updated''': 2021-09-02 - -
-
- -====Search==== -`circleci` -| rename vcs.committer_name as user vcs.subject as commit_message vcs.url as url workflows.* as * -| stats values(job_name) as job_names by workflow_id workflow_name user commit_message url branch -| lookup mandatory_job_for_workflow workflow_name OUTPUTNEW job_name AS mandatory_job -| search mandatory_job=* -| eval mandatory_job_executed=if(like(job_names, "%".mandatory_job."%"), 1, 0) -| where mandatory_job_executed=0 -| eval phase="build" -| rex field=url "(?<repository>[^\/]*\/[^\/]*)$" -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `circle_ci_disable_security_job_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Dev_Sec_Ops|Dev Sec Ops]] - - -====How To Implement==== -You must index CircleCI logs. - -====Required field==== - -* _times - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1554 -| Compromise Client Software Binary -| Persistence -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -unknown - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1554/circle_ci_disable_security_job/circle_ci_disable_security_job.json - - -''version'': 1 -
-
- ----- - -===Circle ci disable security step=== -This search looks for disable security step in CircleCI pipeline. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud, Dev Sec Ops Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1554/ T1554] -* '''Last Updated''': 2021-09-01 - -
-
- -====Search==== -`circleci` -| rename workflows.job_id AS job_id -| join job_id [ -| search `circleci` -| stats values(name) as step_names count by job_id job_name ] -| stats count by step_names job_id job_name vcs.committer_name vcs.subject vcs.url owners{} -| rename vcs.* as * , owners{} as user -| lookup mandatory_step_for_job job_name OUTPUTNEW step_name AS mandatory_step -| search mandatory_step=* -| eval mandatory_step_executed=if(like(step_names, "%".mandatory_step."%"), 1, 0) -| where mandatory_step_executed=0 -| rex field=url "(?<repository>[^\/]*\/[^\/]*)$" -| eval phase="build" -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `circle_ci_disable_security_step_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Dev_Sec_Ops|Dev Sec Ops]] - - -====How To Implement==== -You must index CircleCI logs. - -====Required field==== - -* _times - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1554 -| Compromise Client Software Binary -| Persistence -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -unknown - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1554/circle_ci_disable_security_step/circle_ci_disable_security_step.json - - -''version'': 1 -
-
- ----- - -===Cloud api calls from previously unseen user roles=== -This search looks for new commands from each user role. - -* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Change -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/ T1078] -* '''Last Updated''': 2020-09-04 - -
-
- -====Search==== - -| tstats earliest(_time) as firstTime, latest(_time) as lastTime from datamodel=Change where All_Changes.user_type=AssumedRole AND All_Changes.status=success by All_Changes.user, All_Changes.command All_Changes.object -| `drop_dm_object_name("All_Changes")` -| lookup previously_seen_cloud_api_calls_per_user_role user as user, command as command OUTPUT firstTimeSeen, enough_data -| eventstats max(enough_data) as enough_data -| where enough_data=1 -| eval firstTimeSeenUserApiCall=min(firstTimeSeen) -| where isnull(firstTimeSeenUserApiCall) OR firstTimeSeenUserApiCall > relative_time(now(),"-24h@h") -| table firstTime, user, object, command -|`security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `cloud_api_calls_from_previously_unseen_user_roles_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Cloud_User_Activities|Suspicious Cloud User Activities]] - - -====How To Implement==== -You must be ingesting your cloud infrastructure logs from your cloud provider. You should run the baseline search `Previously Seen Cloud API Calls Per User Role - Initial` to build the initial table of user roles, commands, and times. You must also enable the second baseline search `Previously Seen Cloud API Calls Per User Role - Update` to keep this table up to date and to age out old data. You can adjust the time window for this search by updating the `cloud_api_calls_from_previously_unseen_user_roles_activity_window` macro. You can also provide additional filtering for this search by customizing the `cloud_api_calls_from_previously_unseen_user_roles_filter` - -====Required field==== - -* _time - -* All_Changes.user - -* All_Changes.user_type - -* All_Changes.status - -* All_Changes.command - -* All_Changes.object - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1078 -| Valid Accounts -| Defense Evasion, Persistence, Privilege Escalation, Initial Access -|} - - -====Kill Chain Phase==== - - -====Known False Positives==== -. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json - - -''version'': 1 -
-
- ----- - -===Cloud compute instance created by previously unseen user=== -This search looks for cloud compute instances created by users who have not created them before. - -* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Change -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/004/ T1078.004], [https://attack.mitre.org/techniques/T1078/ T1078] -* '''Last Updated''': 2021-07-13 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count earliest(_time) as firstTime, latest(_time) as lastTime values(All_Changes.object) as dest from datamodel=Change where All_Changes.action=created by All_Changes.user All_Changes.vendor_region -| `drop_dm_object_name("All_Changes")` -| lookup previously_seen_cloud_compute_creations_by_user user as user OUTPUTNEW firstTimeSeen, enough_data -| eventstats max(enough_data) as enough_data -| where enough_data=1 -| eval firstTimeSeenUser=min(firstTimeSeen) -| where isnull(firstTimeSeenUser) OR firstTimeSeenUser > relative_time(now(), "-24h@h") -| table firstTime, user, dest, count vendor_region -| `security_content_ctime(firstTime)` -| `cloud_compute_instance_created_by_previously_unseen_user_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Cloud_Cryptomining|Cloud Cryptomining]] - - -====How To Implement==== -You must be ingesting the appropriate cloud-infrastructure logs Run the "Previously Seen Cloud Compute Creations By User" support search to create of baseline of previously seen users. - -====Required field==== - -* _time - -* All_Changes.object - -* All_Changes.action - -* All_Changes.user - -* All_Changes.vendor_region - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1078.004 -| Cloud Accounts -| Defense Evasion, Persistence, Privilege Escalation, Initial Access -|- -| T1078 -| Valid Accounts -| Defense Evasion, Persistence, Privilege Escalation, Initial Access -|} - - -====Kill Chain Phase==== - - -====Known False Positives==== -It's possible that a user will start to create compute instances for the first time, for any number of reasons. Verify with the user launching instances that this is the intended behavior. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json - - -''version'': 2 -
-
- ----- - -===Cloud compute instance created in previously unused region=== -This search looks at cloud-infrastructure events where an instance is created in any region within the last hour and then compares it to a lookup file of previously seen regions where instances have been created. - -* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Change -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1535/ T1535] -* '''Last Updated''': 2020-09-02 - -
-
- -====Search==== - -| tstats earliest(_time) as firstTime latest(_time) as lastTime values(All_Changes.object_id) as dest, count from datamodel=Change where All_Changes.action=created by All_Changes.vendor_region, All_Changes.user -| `drop_dm_object_name("All_Changes")` -| lookup previously_seen_cloud_regions vendor_region as vendor_region OUTPUTNEW firstTimeSeen, enough_data -| eventstats max(enough_data) as enough_data -| where enough_data=1 -| eval firstTimeSeenRegion=min(firstTimeSeen) -| where isnull(firstTimeSeenRegion) OR firstTimeSeenRegion > relative_time(now(), "-24h@h") -| table firstTime, user, dest, count , vendor_region -| `security_content_ctime(firstTime)` -| `cloud_compute_instance_created_in_previously_unused_region_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Cloud_Cryptomining|Cloud Cryptomining]] - - -====How To Implement==== -You must be ingesting your cloud infrastructure logs from your cloud provider. You should run the baseline search `Previously Seen Cloud Regions - Initial` to build the initial table of images observed and times. You must also enable the second baseline search `Previously Seen Cloud Regions - Update` to keep this table up to date and to age out old data. You can also provide additional filtering for this search by customizing the `cloud_compute_instance_created_in_previously_unused_region_filter` macro. - -====Required field==== - -* _time - -* All_Changes.object_id - -* All_Changes.action - -* All_Changes.vendor_region - -* All_Changes.user - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1535 -| Unused/Unsupported Cloud Regions -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -It's possible that a user has unknowingly started an instance in a new region. Please verify that this activity is legitimate. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json - - -''version'': 1 -
-
- ----- - -===Cloud compute instance created with previously unseen image=== -This search looks for cloud compute instances being created with previously unseen image IDs. - -* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Change -* '''ATT&CK''': -* '''Last Updated''': 2018-10-12 - -
-
- -====Search==== - -| tstats count earliest(_time) as firstTime, latest(_time) as lastTime values(All_Changes.object_id) as dest from datamodel=Change where All_Changes.action=created by All_Changes.Instance_Changes.image_id, All_Changes.user -| `drop_dm_object_name("All_Changes")` -| `drop_dm_object_name("Instance_Changes")` -| where image_id != "unknown" -| lookup previously_seen_cloud_compute_images image_id as image_id OUTPUT firstTimeSeen, enough_data -| eventstats max(enough_data) as enough_data -| where enough_data=1 -| eval firstTimeSeenImage=min(firstTimeSeen) -| where isnull(firstTimeSeenImage) OR firstTimeSeenImage > relative_time(now(), "-24h@h") -| table firstTime, user, image_id, count, dest -| `security_content_ctime(firstTime)` -| `cloud_compute_instance_created_with_previously_unseen_image_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Cloud_Cryptomining|Cloud Cryptomining]] - - -====How To Implement==== -You must be ingesting your cloud infrastructure logs from your cloud provider. You should run the baseline search `Previously Seen Cloud Compute Images - Initial` to build the initial table of images observed and times. You must also enable the second baseline search `Previously Seen Cloud Compute Images - Update` to keep this table up to date and to age out old data. You can also provide additional filtering for this search by customizing the `cloud_compute_instance_created_with_previously_unseen_image_filter` macro. - -====Required field==== - -* _time - -* All_Changes.object_id - -* All_Changes.action - -* All_Changes.Instance_Changes.image_id - -* All_Changes.user - - - - -====Kill Chain Phase==== - - -====Known False Positives==== -After a new image is created, the first systems created with that image will cause this alert to fire. Verify that the image being used was created by a legitimate user. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json - - -''version'': 1 -
-
- ----- - -===Cloud compute instance created with previously unseen instance type=== -Find EC2 instances being created with previously unseen instance types. - -* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Change -* '''ATT&CK''': -* '''Last Updated''': 2020-09-12 - -
-
- -====Search==== - -| tstats earliest(_time) as firstTime, latest(_time) as lastTime values(All_Changes.object_id) as dest, count from datamodel=Change where All_Changes.action=created by All_Changes.Instance_Changes.instance_type, All_Changes.user -| `drop_dm_object_name("All_Changes")` -| `drop_dm_object_name("Instance_Changes")` -| where instance_type != "unknown" -| lookup previously_seen_cloud_compute_instance_types instance_type as instance_type OUTPUTNEW firstTimeSeen, enough_data -| eventstats max(enough_data) as enough_data -| where enough_data=1 -| eval firstTimeSeenInstanceType=min(firstTimeSeen) -| where isnull(firstTimeSeenInstanceType) OR firstTimeSeenInstanceType > relative_time(now(), "-24h@h") -| table firstTime, user, dest, count, instance_type -| `security_content_ctime(firstTime)` -| `cloud_compute_instance_created_with_previously_unseen_instance_type_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Cloud_Cryptomining|Cloud Cryptomining]] - - -====How To Implement==== -You must be ingesting your cloud infrastructure logs from your cloud provider. You should run the baseline search `Previously Seen Cloud Compute Instance Types - Initial` to build the initial table of instance types observed and times. You must also enable the second baseline search `Previously Seen Cloud Compute Instance Types - Update` to keep this table up to date and to age out old data. You can also provide additional filtering for this search by customizing the `cloud_compute_instance_created_with_previously_unseen_instance_type_filter` macro. - -====Required field==== - -* _time - -* All_Changes.object_id - -* All_Changes.action - -* All_Changes.Instance_Changes.instance_type - -* All_Changes.user - - - - -====Kill Chain Phase==== - - -====Known False Positives==== -It is possible that an admin will create a new system using a new instance type that has never been used before. Verify with the creator that they intended to create the system with the new instance type. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json - - -''version'': 1 -
-
- ----- - -===Cloud instance modified by previously unseen user=== -This search looks for cloud instances being modified by users who have not previously modified them. - -* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Change -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/004/ T1078.004], [https://attack.mitre.org/techniques/T1078/ T1078] -* '''Last Updated''': 2020-07-29 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count earliest(_time) as firstTime, latest(_time) as lastTime values(All_Changes.object_id) as object_id values(All_Changes.command) as command from datamodel=Change where All_Changes.action=modified All_Changes.change_type=EC2 All_Changes.status=success by All_Changes.user -| `drop_dm_object_name("All_Changes")` -| lookup previously_seen_cloud_instance_modifications_by_user user as user OUTPUTNEW firstTimeSeen, enough_data -| eventstats max(enough_data) as enough_data -| where enough_data=1 -| eval firstTimeSeenUser=min(firstTimeSeen) -| where isnull(firstTimeSeenUser) OR firstTimeSeenUser > relative_time(now(), "-24h@h") -| table firstTime user command object_id count -| `security_content_ctime(firstTime)` -| `cloud_instance_modified_by_previously_unseen_user_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Cloud_Instance_Activities|Suspicious Cloud Instance Activities]] - - -====How To Implement==== -This search has a dependency on other searches to create and update a baseline of users observed to be associated with this activity. The search "Previously Seen Cloud Instance Modifications By User - Update" should be enabled for this detection to properly work. - -====Required field==== - -* _time - -* All_Changes.object_id - -* All_Changes.command - -* All_Changes.action - -* All_Changes.change_type - -* All_Changes.status - -* All_Changes.user - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1078.004 -| Cloud Accounts -| Defense Evasion, Persistence, Privilege Escalation, Initial Access -|- -| T1078 -| Valid Accounts -| Defense Evasion, Persistence, Privilege Escalation, Initial Access -|} - - -====Kill Chain Phase==== - - -====Known False Positives==== -It's possible that a new user will start to modify EC2 instances when they haven't before for any number of reasons. Verify with the user that is modifying instances that this is the intended behavior. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json - - -''version'': 1 -
-
- ----- - -===Cloud provisioning activity from previously unseen city=== -This search looks for cloud provisioning activities from previously unseen cities. Provisioning activities are defined broadly as any event that runs or creates something. - -* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Change -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/ T1078] -* '''Last Updated''': 2020-10-09 - -
-
- -====Search==== - -| tstats earliest(_time) as firstTime, latest(_time) as lastTime from datamodel=Change where (All_Changes.action=started OR All_Changes.action=created) All_Changes.status=success by All_Changes.src, All_Changes.user, All_Changes.object, All_Changes.command -| `drop_dm_object_name("All_Changes")` -| iplocation src -| where isnotnull(City) -| lookup previously_seen_cloud_provisioning_activity_sources City as City OUTPUT firstTimeSeen, enough_data -| eventstats max(enough_data) as enough_data -| where enough_data=1 -| eval firstTimeSeenCity=min(firstTimeSeen) -| where isnull(firstTimeSeenCity) OR firstTimeSeenCity > relative_time(now(), `previously_unseen_cloud_provisioning_activity_window`) -| table firstTime, src, City, user, object, command -| `cloud_provisioning_activity_from_previously_unseen_city_filter` -| `security_content_ctime(firstTime)` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Cloud_Provisioning_Activities|Suspicious Cloud Provisioning Activities]] - - -====How To Implement==== -You must be ingesting your cloud infrastructure logs from your cloud provider. You should run the baseline search `Previously Seen Cloud Provisioning Activity Sources - Initial` to build the initial table of source IP address, geographic locations, and times. You must also enable the second baseline search `Previously Seen Cloud Provisioning Activity Sources - Update` to keep this table up to date and to age out old data. You can adjust the time window for this search by updating the `previously_unseen_cloud_provisioning_activity_window` macro. You can also provide additional filtering for this search by customizing the `cloud_provisioning_activity_from_previously_unseen_city_filter` macro. - -====Required field==== - -* _time - -* All_Changes.action - -* All_Changes.status - -* All_Changes.src - -* All_Changes.user - -* All_Changes.object - -* All_Changes.command - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1078 -| Valid Accounts -| Defense Evasion, Persistence, Privilege Escalation, Initial Access -|} - - -====Kill Chain Phase==== - - -====Known False Positives==== -This is a strictly behavioral search, so we define "false positive" slightly differently. Every time this fires, it will accurately reflect the first occurrence in the time period you're searching within, plus what is stored in the cache feature. But while there are really no "false positives" in a traditional sense, there is definitely lots of noise.\ - This search will fire any time a new IP address is seen in the **GeoIP** database for any kind of provisioning activity. If you typically do all provisioning from tools inside of your country, there should be few false positives. If you are located in countries where the free version of **MaxMind GeoIP** that ships by default with Splunk has weak resolution (particularly small countries in less economically powerful regions), this may be much less valuable to you. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json - - -''version'': 1 -
-
- ----- - -===Cloud provisioning activity from previously unseen country=== -This search looks for cloud provisioning activities from previously unseen countries. Provisioning activities are defined broadly as any event that runs or creates something. - -* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Change -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/ T1078] -* '''Last Updated''': 2020-10-09 - -
-
- -====Search==== - -| tstats earliest(_time) as firstTime, latest(_time) as lastTime from datamodel=Change where (All_Changes.action=started OR All_Changes.action=created) All_Changes.status=success by All_Changes.src, All_Changes.user, All_Changes.object, All_Changes.command -| `drop_dm_object_name("All_Changes")` -| iplocation src -| where isnotnull(Country) -| lookup previously_seen_cloud_provisioning_activity_sources Country as Country OUTPUT firstTimeSeen, enough_data -| eventstats max(enough_data) as enough_data -| where enough_data=1 -| eval firstTimeSeenCountry=min(firstTimeSeen) -| where isnull(firstTimeSeenCountry) OR firstTimeSeenCountry > relative_time(now(), "-24h@h") -| table firstTime, src, Country, user, object, command -| `cloud_provisioning_activity_from_previously_unseen_country_filter` -| `security_content_ctime(firstTime)` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Cloud_Provisioning_Activities|Suspicious Cloud Provisioning Activities]] - - -====How To Implement==== -You must be ingesting your cloud infrastructure logs from your cloud provider. You should run the baseline search `Previously Seen Cloud Provisioning Activity Sources - Initial` to build the initial table of source IP address, geographic locations, and times. You must also enable the second baseline search `Previously Seen Cloud Provisioning Activity Sources - Update` to keep this table up to date and to age out old data. You can adjust the time window for this search by updating the `previously_unseen_cloud_provisioning_activity_window` macro. You can also provide additional filtering for this search by customizing the `cloud_provisioning_activity_from_previously_unseen_country_filter` macro. - -====Required field==== - -* _time - -* All_Changes.action - -* All_Changes.status - -* All_Changes.src - -* All_Changes.user - -* All_Changes.object - -* All_Changes.command - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1078 -| Valid Accounts -| Defense Evasion, Persistence, Privilege Escalation, Initial Access -|} - - -====Kill Chain Phase==== - - -====Known False Positives==== -This is a strictly behavioral search, so we define "false positive" slightly differently. Every time this fires, it will accurately reflect the first occurrence in the time period you're searching within, plus what is stored in the cache feature. But while there are really no "false positives" in a traditional sense, there is definitely lots of noise.\ - This search will fire any time a new IP address is seen in the **GeoIP** database for any kind of provisioning activity. If you typically do all provisioning from tools inside of your country, there should be few false positives. If you are located in countries where the free version of **MaxMind GeoIP** that ships by default with Splunk has weak resolution (particularly small countries in less economically powerful regions), this may be much less valuable to you. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json - - -''version'': 1 -
-
- ----- - -===Cloud provisioning activity from previously unseen ip address=== -This search looks for cloud provisioning activities from previously unseen IP addresses. Provisioning activities are defined broadly as any event that runs or creates something. - -* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Change -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/ T1078] -* '''Last Updated''': 2020-08-16 - -
-
- -====Search==== - -| tstats earliest(_time) as firstTime, latest(_time) as lastTime, values(All_Changes.object_id) as object_id from datamodel=Change where (All_Changes.action=started OR All_Changes.action=created) All_Changes.status=success by All_Changes.src, All_Changes.user, All_Changes.command -| `drop_dm_object_name("All_Changes")` -| lookup previously_seen_cloud_provisioning_activity_sources src as src OUTPUT firstTimeSeen, enough_data -| eventstats max(enough_data) as enough_data -| where enough_data=1 -| eval firstTimeSeenSrc=min(firstTimeSeen) -| where isnull(firstTimeSeenSrc) OR firstTimeSeenSrc > relative_time(now(), `previously_unseen_cloud_provisioning_activity_window`) -| table firstTime, src, user, object_id, command -| `cloud_provisioning_activity_from_previously_unseen_ip_address_filter` -| `security_content_ctime(firstTime)` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Cloud_Provisioning_Activities|Suspicious Cloud Provisioning Activities]] - - -====How To Implement==== -You must be ingesting your cloud infrastructure logs from your cloud provider. You should run the baseline search `Previously Seen Cloud Provisioning Activity Sources - Initial` to build the initial table of source IP address, geographic locations, and times. You must also enable the second baseline search `Previously Seen Cloud Provisioning Activity Sources - Update` to keep this table up to date and to age out old data. You can adjust the time window for this search by updating the `previously_unseen_cloud_provisioning_activity_window` macro. You can also provide additional filtering for this search by customizing the `cloud_provisioning_activity_from_previously_unseen_ip_address_filter` macro. - -====Required field==== - -* _time - -* All_Changes.object_id - -* All_Changes.action - -* All_Changes.status - -* All_Changes.src - -* All_Changes.user - -* All_Changes.command - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1078 -| Valid Accounts -| Defense Evasion, Persistence, Privilege Escalation, Initial Access -|} - - -====Kill Chain Phase==== - - -====Known False Positives==== -This is a strictly behavioral search, so we define "false positive" slightly differently. Every time this fires, it will accurately reflect the first occurrence in the time period you're searching within, plus what is stored in the cache feature. But while there are really no "false positives" in a traditional sense, there is definitely lots of noise.\ - This search will fire any time a new IP address is seen in the **GeoIP** database for any kind of provisioning activity. If you typically do all provisioning from tools inside of your country, there should be few false positives. If you are located in countries where the free version of **MaxMind GeoIP** that ships by default with Splunk has weak resolution (particularly small countries in less economically powerful regions), this may be much less valuable to you. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json - - -''version'': 1 -
-
- ----- - -===Cloud provisioning activity from previously unseen region=== -This search looks for cloud provisioning activities from previously unseen regions. Provisioning activities are defined broadly as any event that runs or creates something. - -* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Change -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/ T1078] -* '''Last Updated''': 2020-08-16 - -
-
- -====Search==== - -| tstats earliest(_time) as firstTime, latest(_time) as lastTime from datamodel=Change where (All_Changes.action=started OR All_Changes.action=created) All_Changes.status=success by All_Changes.src, All_Changes.user, All_Changes.object, All_Changes.command -| `drop_dm_object_name("All_Changes")` -| iplocation src -| where isnotnull(Region) -| lookup previously_seen_cloud_provisioning_activity_sources Region as Region OUTPUT firstTimeSeen, enough_data -| eventstats max(enough_data) as enough_data -| where enough_data=1 -| eval firstTimeSeenRegion=min(firstTimeSeen) -| where isnull(firstTimeSeenRegion) OR firstTimeSeenRegion > relative_time(now(), `previously_unseen_cloud_provisioning_activity_window`) -| table firstTime, src, Region, user, object, command -| `cloud_provisioning_activity_from_previously_unseen_region_filter` -| `security_content_ctime(firstTime)` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Cloud_Provisioning_Activities|Suspicious Cloud Provisioning Activities]] - - -====How To Implement==== -You must be ingesting your cloud infrastructure logs from your cloud provider. You should run the baseline search `Previously Seen Cloud Provisioning Activity Sources - Initial` to build the initial table of source IP address, geographic locations, and times. You must also enable the second baseline search `Previously Seen Cloud Provisioning Activity Sources - Update` to keep this table up to date and to age out old data. You can adjust the time window for this search by updating the `previously_unseen_cloud_provisioning_activity_window` macro. You can also provide additional filtering for this search by customizing the `cloud_provisioning_activity_from_previously_unseen_region_filter` macro. - -====Required field==== - -* _time - -* All_Changes.action - -* All_Changes.status - -* All_Changes.src - -* All_Changes.user - -* All_Changes.object - -* All_Changes.command - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1078 -| Valid Accounts -| Defense Evasion, Persistence, Privilege Escalation, Initial Access -|} - - -====Kill Chain Phase==== - - -====Known False Positives==== -This is a strictly behavioral search, so we define "false positive" slightly differently. Every time this fires, it will accurately reflect the first occurrence in the time period you're searching within, plus what is stored in the cache feature. But while there are really no "false positives" in a traditional sense, there is definitely lots of noise.\ - This search will fire any time a new IP address is seen in the **GeoIP** database for any kind of provisioning activity. If you typically do all provisioning from tools inside of your country, there should be few false positives. If you are located in countries where the free version of **MaxMind GeoIP** that ships by default with Splunk has weak resolution (particularly small countries in less economically powerful regions), this may be much less valuable to you. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json - - -''version'': 1 -
-
- ----- - -===Correlation by repository and risk=== -This search correlations detections by repository and risk_score - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud, Dev Sec Ops Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1204/003/ T1204.003], [https://attack.mitre.org/techniques/T1204/ T1204] -* '''Last Updated''': 2021-09-06 - -
-
- -====Search==== -`signals` -| fillnull -| stats sum(risk_score) as risk_score values(source) as signals values(user) as user by repository -| sort - risk_score -| where risk_score > 80 -| `correlation_by_repository_and_risk_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Dev_Sec_Ops|Dev Sec Ops]] - - -====How To Implement==== -For Dev Sec Ops POC - -====Required field==== - -* _time - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1204.003 -| Malicious Image -| Execution -|- -| T1204 -| User Execution -| Execution -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -unknown - -====Reference==== - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Correlation by user and risk=== -This search correlations detections by user and risk_score - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud, Dev Sec Ops Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1204/003/ T1204.003], [https://attack.mitre.org/techniques/T1204/ T1204] -* '''Last Updated''': 2021-09-06 - -
-
- -====Search==== -`signals` -| fillnull -| stats sum(risk_score) as risk_score values(source) as signals values(repository) as repository by user -| sort - risk_score -| where risk_score > 80 -| `correlation_by_user_and_risk_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Dev_Sec_Ops|Dev Sec Ops]] - - -====How To Implement==== -For Dev Sec Ops POC - -====Required field==== - -* _time - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1204.003 -| Malicious Image -| Execution -|- -| T1204 -| User Execution -| Execution -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -unknown - -====Reference==== - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Detect aws console login by new user=== -This search looks for AWS CloudTrail events wherein a console login event by a user was recorded within the last hour, then compares the event to a lookup file of previously seen users (by ARN values) who have logged into the console. The alert is fired if the user has logged into the console for the first time within the last hour - -* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Authentication -* '''ATT&CK''': -* '''Last Updated''': 2020-05-28 - -
-
- -====Search==== - -| tstats earliest(_time) as firstTime latest(_time) as lastTime from datamodel=Authentication where Authentication.signature=ConsoleLogin by Authentication.user -| `drop_dm_object_name(Authentication)` -| inputlookup append=t previously_seen_users_console_logins -| stats min(firstTime) as firstTime max(lastTime) as lastTime by user -| eval userStatus=if(firstTime >=relative_time(now(),"-24h@h"), "First Time Logging into AWS Console", "Previously Seen User") -|where userStatus="First Time Logging into AWS Console" -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_aws_console_login_by_new_user_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Cloud_Authentication_Activities|Suspicious Cloud Authentication Activities]] - - -====How To Implement==== -You must install and configure the Splunk Add-on for AWS (version 5.1.0 or later) and Enterprise Security 6.2, which contains the required updates to the Authentication data model for cloud use cases. Run the `Previously Seen Users in AWS CloudTrail - Initial` support search only once to create a baseline of previously seen IAM users within the last 30 days. Run `Previously Seen Users in AWS CloudTrail - Update` hourly (or more frequently depending on how often you run the detection searches) to refresh the baselines. - -====Required field==== - -* _time - -* Authentication.signature - -* Authentication.user - - - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -When a legitimate new user logins for the first time, this activity will be detected. Check how old the account is and verify that the user activity is legitimate. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json - - -''version'': 1 -
-
- ----- - -===Detect aws console login by user from new city=== -This search looks for AWS CloudTrail events wherein a console login event by a user was recorded within the last hour, then compares the event to a lookup file of previously seen users (by ARN values) who have logged into the console. The alert is fired if the user has logged into the console for the first time within the last hour - -* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Authentication -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1535/ T1535] -* '''Last Updated''': 2020-10-07 - -
-
- -====Search==== - -| tstats earliest(_time) as firstTime latest(_time) as lastTime from datamodel=Authentication where Authentication.signature=ConsoleLogin by Authentication.user Authentication.src -| iplocation Authentication.src -| `drop_dm_object_name(Authentication)` -| table firstTime lastTime user City -| join user type=outer [ -| inputlookup previously_seen_users_console_logins -| stats earliest(firstTime) AS earliestseen by user City -| fields earliestseen user City] -| eval userCity=if(firstTime >= relative_time(now(), "-24h@h"), "New City","Previously Seen City") -| eval userStatus=if(earliestseen >= relative_time(now(), "-24h@h") OR isnull(earliestseen), "New User","Old User") -| where userCity = "New City" AND userStatus != "Old User" -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| table firstTime lastTime user City userStatus userCity -| `detect_aws_console_login_by_user_from_new_city_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_AWS_Login_Activities|Suspicious AWS Login Activities]] - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Cloud_Authentication_Activities|Suspicious Cloud Authentication Activities]] - - -====How To Implement==== -You must install and configure the Splunk Add-on for AWS (version 5.1.0 or later) and Enterprise Security 6.2, which contains the required updates to the Authentication data model for cloud use cases. Run the `Previously Seen Users in AWS CloudTrail - Initial` support search only once to create a baseline of previously seen IAM users within the last 30 days. Run `Previously Seen Users in AWS CloudTrail - Update` hourly (or more frequently depending on how often you run the detection searches) to refresh the baselines. You can also provide additional filtering for this search by customizing the `detect_aws_console_login_by_user_from_new_city_filter` macro. - -====Required field==== - -* _time - -* Authentication.signature - -* Authentication.user - -* Authentication.src - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1535 -| Unused/Unsupported Cloud Regions -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -When a legitimate new user logins for the first time, this activity will be detected. Check how old the account is and verify that the user activity is legitimate. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json - - -''version'': 1 -
-
- ----- - -===Detect aws console login by user from new country=== -This search looks for AWS CloudTrail events wherein a console login event by a user was recorded within the last hour, then compares the event to a lookup file of previously seen users (by ARN values) who have logged into the console. The alert is fired if the user has logged into the console for the first time within the last hour - -* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Authentication -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1535/ T1535] -* '''Last Updated''': 2020-10-07 - -
-
- -====Search==== - -| tstats earliest(_time) as firstTime latest(_time) as lastTime from datamodel=Authentication where Authentication.signature=ConsoleLogin by Authentication.user Authentication.src -| iplocation Authentication.src -| `drop_dm_object_name(Authentication)` -| table firstTime lastTime user Country -| join user type=outer [ -| inputlookup previously_seen_users_console_logins -| stats earliest(firstTime) AS earliestseen by user Country -| fields earliestseen user Country] -| eval userCountry=if(firstTime >= relative_time(now(), "-24h@h"), "New Country","Previously Seen Country") -| eval userStatus=if(earliestseen >= relative_time(now(),"-24h@h") OR isnull(earliestseen), "New User","Old User") -| where userCountry = "New Country" AND userStatus != "Old User" -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| table firstTime lastTime user Country userStatus userCountry -| `detect_aws_console_login_by_user_from_new_country_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_AWS_Login_Activities|Suspicious AWS Login Activities]] - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Cloud_Authentication_Activities|Suspicious Cloud Authentication Activities]] - - -====How To Implement==== -You must install and configure the Splunk Add-on for AWS (version 5.1.0 or later) and Enterprise Security 6.2, which contains the required updates to the Authentication data model for cloud use cases. Run the `Previously Seen Users in AWS CloudTrail - Initial` support search only once to create a baseline of previously seen IAM users within the last 30 days. Run `Previously Seen Users in AWS CloudTrail - Update` hourly (or more frequently depending on how often you run the detection searches) to refresh the baselines. You can also provide additional filtering for this search by customizing the `detect_aws_console_login_by_user_from_new_country_filter` macro. - -====Required field==== - -* _time - -* Authentication.signature - -* Authentication.user - -* Authentication.src - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1535 -| Unused/Unsupported Cloud Regions -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -When a legitimate new user logins for the first time, this activity will be detected. Check how old the account is and verify that the user activity is legitimate. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json - - -''version'': 1 -
-
- ----- - -===Detect aws console login by user from new region=== -This search looks for AWS CloudTrail events wherein a console login event by a user was recorded within the last hour, then compares the event to a lookup file of previously seen users (by ARN values) who have logged into the console. The alert is fired if the user has logged into the console for the first time within the last hour - -* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Authentication -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1535/ T1535] -* '''Last Updated''': 2020-10-07 - -
-
- -====Search==== - -| tstats earliest(_time) as firstTime latest(_time) as lastTime from datamodel=Authentication where Authentication.signature=ConsoleLogin by Authentication.user Authentication.src -| iplocation Authentication.src -| `drop_dm_object_name(Authentication)` -| table firstTime lastTime user Region -| join user type=outer [ -| inputlookup previously_seen_users_console_logins -| stats earliest(firstTime) AS earliestseen by user Region -| fields earliestseen user Region] -| eval userRegion=if(firstTime >= relative_time(now(), "-24h@h"), "New Region","Previously Seen Region") -| eval userStatus=if(earliestseen >= relative_time(now(), "-24h@h") OR isnull(earliestseen), "New User","Old User") -| where userRegion = "New Region" AND userStatus != "Old User" -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| table firstTime lastTime user Region userStatus userRegion -| `detect_aws_console_login_by_user_from_new_region_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_AWS_Login_Activities|Suspicious AWS Login Activities]] - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Cloud_Authentication_Activities|Suspicious Cloud Authentication Activities]] - - -====How To Implement==== -You must install and configure the Splunk Add-on for AWS (version 5.1.0 or later) and Enterprise Security 6.2, which contains the required updates to the Authentication data model for cloud use cases. Run the `Previously Seen Users in AWS CloudTrail - Initial` support search only once to create a baseline of previously seen IAM users within the last 30 days. Run `Previously Seen Users in AWS CloudTrail - Update` hourly (or more frequently depending on how often you run the detection searches) to refresh the baselines. You can also provide additional filtering for this search by customizing the `detect_aws_console_login_by_user_from_new_region_filter` macro. - -====Required field==== - -* _time - -* Authentication.signature - -* Authentication.user - -* Authentication.src - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1535 -| Unused/Unsupported Cloud Regions -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -When a legitimate new user logins for the first time, this activity will be detected. Check how old the account is and verify that the user activity is legitimate. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json - - -''version'': 1 -
-
- ----- - -===Detect gcp storage access from a new ip=== -This search looks at GCP Storage bucket-access logs and detects new or previously unseen remote IP addresses that have successfully accessed a GCP Storage bucket. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1530/ T1530] -* '''Last Updated''': 2020-08-10 - -
-
- -====Search==== -`google_gcp_pubsub_message` -| multikv -| rename sc_status_ as status -| rename cs_object_ as bucket_name -| rename c_ip_ as remote_ip -| rename cs_uri_ as request_uri -| rename cs_method_ as operation -| search status="\"200\"" -| stats earliest(_time) as firstTime latest(_time) as lastTime by bucket_name remote_ip operation request_uri -| table firstTime, lastTime, bucket_name, remote_ip, operation, request_uri -| inputlookup append=t previously_seen_gcp_storage_access_from_remote_ip.csv -| stats min(firstTime) as firstTime, max(lastTime) as lastTime by bucket_name remote_ip operation request_uri -| outputlookup previously_seen_gcp_storage_access_from_remote_ip.csv -| eval newIP=if(firstTime >= relative_time(now(),"-70m@m"), 1, 0) -| where newIP=1 -| eval first_time=strftime(firstTime,"%m/%d/%y %H:%M:%S") -| eval last_time=strftime(lastTime,"%m/%d/%y %H:%M:%S") -| table first_time last_time bucket_name remote_ip operation request_uri -| `detect_gcp_storage_access_from_a_new_ip_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_GCP_Storage_Activities|Suspicious GCP Storage Activities]] - - -====How To Implement==== -This search relies on the Splunk Add-on for Google Cloud Platform, setting up a Cloud Pub/Sub input, along with the relevant GCP PubSub topics and logging sink to capture GCP Storage Bucket events (https://cloud.google.com/logging/docs/routing/overview). In order to capture public GCP Storage Bucket access logs, you must also enable storage bucket logging to your PubSub Topic as per https://cloud.google.com/storage/docs/access-logs. These logs are deposited into the nominated Storage Bucket on an hourly basis and typically show up by 15 minutes past the hour. It is recommended to configure any saved searches or correlation searches in Enterprise Security to run on an hourly basis at 30 minutes past the hour (cron definition of 30 * * * *). A lookup table (previously_seen_gcp_storage_access_from_remote_ip.csv) stores the previously seen access requests, and is used by this search to determine any newly seen IP addresses accessing the Storage Buckets. - -====Required field==== - -* _time - -* sc_status_ - -* cs_object_ - -* c_ip_ - -* cs_uri_ - -* cs_method_ - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1530 -| Data from Cloud Storage Object -| Collection -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -GCP Storage buckets can be accessed from any IP (if the ACLs are open to allow it), as long as it can make a successful connection. This will be a false postive, since the search is looking for a new IP within the past two hours. - -====Reference==== - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Detect new open gcp storage buckets=== -This search looks for GCP PubSub events where a user has created an open/public GCP Storage bucket. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1530/ T1530] -* '''Last Updated''': 2020-08-05 - -
-
- -====Search==== -`google_gcp_pubsub_message` data.resource.type=gcs_bucket data.protoPayload.methodName=storage.setIamPermissions -| spath output=action path=data.protoPayload.serviceData.policyDelta.bindingDeltas{}.action -| spath output=user path=data.protoPayload.authenticationInfo.principalEmail -| spath output=location path=data.protoPayload.resourceLocation.currentLocations{} -| spath output=src path=data.protoPayload.requestMetadata.callerIp -| spath output=bucketName path=data.protoPayload.resourceName -| spath output=role path=data.protoPayload.serviceData.policyDelta.bindingDeltas{}.role -| spath output=member path=data.protoPayload.serviceData.policyDelta.bindingDeltas{}.member -| search (member=allUsers AND action=ADD) -| table _time, bucketName, src, user, location, action, role, member -| search `detect_new_open_gcp_storage_buckets_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_GCP_Storage_Activities|Suspicious GCP Storage Activities]] - - -====How To Implement==== -This search relies on the Splunk Add-on for Google Cloud Platform, setting up a Cloud Pub/Sub input, along with the relevant GCP PubSub topics and logging sink to capture GCP Storage Bucket events (https://cloud.google.com/logging/docs/routing/overview). - -====Required field==== - -* _time - -* data.resource.type - -* data.protoPayload.methodName - -* data.protoPayload.serviceData.policyDelta.bindingDeltas{}.action - -* data.protoPayload.authenticationInfo.principalEmail - -* data.protoPayload.resourceLocation.currentLocations{} - -* data.protoPayload.requestMetadata.callerIp - -* data.protoPayload.resourceName - -* data.protoPayload.serviceData.policyDelta.bindingDeltas{}.role - -* data.protoPayload.serviceData.policyDelta.bindingDeltas{}.member - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1530 -| Data from Cloud Storage Object -| Collection -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -While this search has no known false positives, it is possible that a GCP admin has legitimately created a public bucket for a specific purpose. That said, GCP strongly advises against granting full control to the "allUsers" group. - -====Reference==== - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Detect new open s3 buckets over aws cli=== -This search looks for AWS CloudTrail events where a user has created an open/public S3 bucket over the aws cli. - -* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1530/ T1530] -* '''Last Updated''': 2021-07-19 - -
-
- -====Search==== -`cloudtrail` eventSource="s3.amazonaws.com" (userAgent="[aws-cli*" OR userAgent=aws-cli* ) eventName=PutBucketAcl OR requestParameters.accessControlList.x-amz-grant-read-acp IN ("*AuthenticatedUsers","*AllUsers") OR requestParameters.accessControlList.x-amz-grant-write IN ("*AuthenticatedUsers","*AllUsers") OR requestParameters.accessControlList.x-amz-grant-write-acp IN ("*AuthenticatedUsers","*AllUsers") OR requestParameters.accessControlList.x-amz-grant-full-control IN ("*AuthenticatedUsers","*AllUsers") -| rename requestParameters.bucketName AS bucketName -| fillnull -| stats count min(_time) as firstTime max(_time) as lastTime by userIdentity.userName userIdentity.principalId userAgent bucketName requestParameters.accessControlList.x-amz-grant-read requestParameters.accessControlList.x-amz-grant-read-acp requestParameters.accessControlList.x-amz-grant-write requestParameters.accessControlList.x-amz-grant-write-acp requestParameters.accessControlList.x-amz-grant-full-control -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_new_open_s3_buckets_over_aws_cli_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_AWS_S3_Activities|Suspicious AWS S3 Activities]] - - -====How To Implement==== - - -====Required field==== - -* _time - -* eventSource - -* eventName - -* requestParameters.accessControlList.x-amz-grant-read-acp - -* requestParameters.accessControlList.x-amz-grant-write - -* requestParameters.accessControlList.x-amz-grant-write-acp - -* requestParameters.accessControlList.x-amz-grant-full-control - -* requestParameters.bucketName - -* userIdentity.userName - -* userIdentity.principalId - -* userAgent - -* bucketName - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1530 -| Data from Cloud Storage Object -| Collection -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -While this search has no known false positives, it is possible that an AWS admin has legitimately created a public bucket for a specific purpose. That said, AWS strongly advises against granting full control to the "All Users" group. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1530/aws_s3_public_bucket/aws_cloudtrail_events.json - - -''version'': 2 -
-
- ----- - -===Detect new open s3 buckets=== -This search looks for AWS CloudTrail events where a user has created an open/public S3 bucket. - -* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1530/ T1530] -* '''Last Updated''': 2021-07-19 - -
-
- -====Search==== -`cloudtrail` eventSource=s3.amazonaws.com eventName=PutBucketAcl -| rex field=_raw "(?<json_field>{.+})" -| spath input=json_field output=grantees path=requestParameters.AccessControlPolicy.AccessControlList.Grant{} -| search grantees=* -| mvexpand grantees -| spath input=grantees output=uri path=Grantee.URI -| spath input=grantees output=permission path=Permission -| search uri IN ("http://acs.amazonaws.com/groups/global/AllUsers","http://acs.amazonaws.com/groups/global/AuthenticatedUsers") -| search permission IN ("READ","READ_ACP","WRITE","WRITE_ACP","FULL_CONTROL") -| rename requestParameters.bucketName AS bucketName -| stats count min(_time) as firstTime max(_time) as lastTime by user_arn userIdentity.principalId userAgent uri permission bucketName -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_new_open_s3_buckets_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_AWS_S3_Activities|Suspicious AWS S3 Activities]] - - -====How To Implement==== -You must install the AWS App for Splunk. - -====Required field==== - -* _time - -* eventSource - -* eventName - -* requestParameters.bucketName - -* user_arn - -* userIdentity.principalId - -* userAgent - -* uri - -* permission - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1530 -| Data from Cloud Storage Object -| Collection -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -While this search has no known false positives, it is possible that an AWS admin has legitimately created a public bucket for a specific purpose. That said, AWS strongly advises against granting full control to the "All Users" group. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1530/aws_s3_public_bucket/aws_cloudtrail_events.json - - -''version'': 3 -
-
- ----- - -===Detect s3 access from a new ip=== -This search looks at S3 bucket-access logs and detects new or previously unseen remote IP addresses that have successfully accessed an S3 bucket. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1530/ T1530] -* '''Last Updated''': 2018-06-28 - -
-
- -====Search==== -`aws_s3_accesslogs` http_status=200 [search `aws_s3_accesslogs` http_status=200 -| stats earliest(_time) as firstTime latest(_time) as lastTime by bucket_name remote_ip -| inputlookup append=t previously_seen_S3_access_from_remote_ip.csv -| stats min(firstTime) as firstTime, max(lastTime) as lastTime by bucket_name remote_ip -| outputlookup previously_seen_S3_access_from_remote_ip.csv -| eval newIP=if(firstTime >= relative_time(now(), "-70m@m"), 1, 0) -| where newIP=1 -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| table bucket_name remote_ip] -| iplocation remote_ip -|rename remote_ip as src_ip -| table _time bucket_name src_ip City Country operation request_uri -| `detect_s3_access_from_a_new_ip_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_AWS_S3_Activities|Suspicious AWS S3 Activities]] - - -====How To Implement==== -You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your S3 access logs' inputs. This search works best when you run the "Previously Seen S3 Bucket Access by Remote IP" support search once to create a history of previously seen remote IPs and bucket names. - -====Required field==== - -* _time - -* http_status - -* bucket_name - -* remote_ip - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1530 -| Data from Cloud Storage Object -| Collection -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -S3 buckets can be accessed from any IP, as long as it can make a successful connection. This will be a false postive, since the search is looking for a new IP within the past hour - -====Reference==== - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Detect spike in aws security hub alerts for ec2 instance=== -This search looks for a spike in number of of AWS security Hub alerts for an EC2 instance in 4 hours intervals - -* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': -* '''Last Updated''': 2021-01-26 - -
-
- -====Search==== -`aws_securityhub_finding` "Resources{}.Type"=AWSEC2Instance -| bucket span=4h _time -| stats count AS alerts values(Title) as Title values(Types{}) as Types values(vendor_account) as vendor_account values(vendor_region) as vendor_region values(severity) as severity by _time dest -| eventstats avg(alerts) as total_alerts_avg, stdev(alerts) as total_alerts_stdev -| eval threshold_value = 3 -| eval isOutlier=if(alerts > total_alerts_avg+(total_alerts_stdev * threshold_value), 1, 0) -| search isOutlier=1 -| table _time dest alerts Title Types vendor_account vendor_region severity isOutlier total_alerts_avg -| `detect_spike_in_aws_security_hub_alerts_for_ec2_instance_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#AWS_Security_Hub_Alerts|AWS Security Hub Alerts]] - - -====How To Implement==== -You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your Security Hub inputs. The threshold_value should be tuned to your environment and schedule these searches according to the bucket span interval. - -====Required field==== - -* _time - -* Resources{}.Type - -* Title - -* Types{} - -* vendor_account - -* vendor_region - -* severity - -* dest - - - - -====Kill Chain Phase==== - - -====Known False Positives==== -None - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/security_hub_ec2_spike/security_hub_ec2_spike.json - - -''version'': 3 -
-
- ----- - -===Detect spike in aws security hub alerts for user=== -This search looks for a spike in number of of AWS security Hub alerts for an AWS IAM User in 4 hours intervals. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': -* '''Last Updated''': 2021-01-26 - -
-
- -====Search==== -`aws_securityhub_finding` "findings{}.Resources{}.Type"= AwsIamUser -| rename findings{}.Resources{}.Id as user -| bucket span=4h _time -| stats count AS alerts by _time user -| eventstats avg(alerts) as total_launched_avg, stdev(alerts) as total_launched_stdev -| eval threshold_value = 2 -| eval isOutlier=if(alerts > total_launched_avg+(total_launched_stdev * threshold_value), 1, 0) -| search isOutlier=1 -| table _time user alerts -|`detect_spike_in_aws_security_hub_alerts_for_user_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#AWS_Security_Hub_Alerts|AWS Security Hub Alerts]] - - -====How To Implement==== -You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your Security Hub inputs. The threshold_value should be tuned to your environment and schedule these searches according to the bucket span interval. - -====Required field==== - -* _time - -* findings{}.Resources{}.Type - -* indings{}.Resources{}.Id - -* user - - - - -====Kill Chain Phase==== - - -====Known False Positives==== -None - -====Reference==== - - -====Test Dataset==== - - -''version'': 3 -
-
- ----- - -===Detect spike in s3 bucket deletion=== -This search detects users creating spikes in API activity related to deletion of S3 buckets in your AWS environment. It will also update the cache file that factors in the latest data. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1530/ T1530] -* '''Last Updated''': 2018-11-27 - -
-
- -====Search==== -`cloudtrail` eventName=DeleteBucket [search `cloudtrail` eventName=DeleteBucket -| spath output=arn path=userIdentity.arn -| stats count as apiCalls by arn -| inputlookup s3_deletion_baseline append=t -| fields - latestCount -| stats values(*) as * by arn -| rename apiCalls as latestCount -| eval newAvgApiCalls=avgApiCalls + (latestCount-avgApiCalls)/720 -| eval newStdevApiCalls=sqrt(((pow(stdevApiCalls, 2)*719 + (latestCount-newAvgApiCalls)*(latestCount-avgApiCalls))/720)) -| eval avgApiCalls=coalesce(newAvgApiCalls, avgApiCalls), stdevApiCalls=coalesce(newStdevApiCalls, stdevApiCalls), numDataPoints=if(isnull(latestCount), numDataPoints, numDataPoints+1) -| table arn, latestCount, numDataPoints, avgApiCalls, stdevApiCalls -| outputlookup s3_deletion_baseline -| eval dataPointThreshold = 15, deviationThreshold = 3 -| eval isSpike=if((latestCount > avgApiCalls+deviationThreshold*stdevApiCalls) AND numDataPoints > dataPointThreshold, 1, 0) -| where isSpike=1 -| rename arn as userIdentity.arn -| table userIdentity.arn] -| spath output=user userIdentity.arn -| spath output=bucketName path=requestParameters.bucketName -| stats values(bucketName) as bucketName, count as numberOfApiCalls, dc(eventName) as uniqueApisCalled by user -| `detect_spike_in_s3_bucket_deletion_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_AWS_S3_Activities|Suspicious AWS S3 Activities]] - - -====How To Implement==== -You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your AWS CloudTrail inputs. You can modify `dataPointThreshold` and `deviationThreshold` to better fit your environment. The `dataPointThreshold` variable is the minimum number of data points required to have a statistically significant amount of data to determine. The `deviationThreshold` variable is the number of standard deviations away from the mean that the value must be to be considered a spike. This search works best when you run the "Baseline of S3 Bucket deletion activity by ARN" support search once to create a baseline of previously seen S3 bucket-deletion activity. - -====Required field==== - -* _time - -* eventName - -* userIdentity.arn - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1530 -| Data from Cloud Storage Object -| Collection -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Based on the values of`dataPointThreshold` and `deviationThreshold`, the false positive rate may vary. Please modify this according the your environment. - -====Reference==== - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Detect spike in blocked outbound traffic from your aws=== -This search will detect spike in blocked outbound network connections originating from within your AWS environment. It will also update the cache file that factors in the latest data. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': -* '''Last Updated''': 2018-05-07 - -
-
- -====Search==== -`cloudwatchlogs_vpcflow` action=blocked (src_ip=10.0.0.0/8 OR src_ip=172.16.0.0/12 OR src_ip=192.168.0.0/16) ( dest_ip!=10.0.0.0/8 AND dest_ip!=172.16.0.0/12 AND dest_ip!=192.168.0.0/16) [search `cloudwatchlogs_vpcflow` action=blocked (src_ip=10.0.0.0/8 OR src_ip=172.16.0.0/12 OR src_ip=192.168.0.0/16) ( dest_ip!=10.0.0.0/8 AND dest_ip!=172.16.0.0/12 AND dest_ip!=192.168.0.0/16) -| stats count as numberOfBlockedConnections by src_ip -| inputlookup baseline_blocked_outbound_connections append=t -| fields - latestCount -| stats values(*) as * by src_ip -| rename numberOfBlockedConnections as latestCount -| eval newAvgBlockedConnections=avgBlockedConnections + (latestCount-avgBlockedConnections)/720 -| eval newStdevBlockedConnections=sqrt(((pow(stdevBlockedConnections, 2)*719 + (latestCount-newAvgBlockedConnections)*(latestCount-avgBlockedConnections))/720)) -| eval avgBlockedConnections=coalesce(newAvgBlockedConnections, avgBlockedConnections), stdevBlockedConnections=coalesce(newStdevBlockedConnections, stdevBlockedConnections), numDataPoints=if(isnull(latestCount), numDataPoints, numDataPoints+1) -| table src_ip, latestCount, numDataPoints, avgBlockedConnections, stdevBlockedConnections -| outputlookup baseline_blocked_outbound_connections -| eval dataPointThreshold = 5, deviationThreshold = 3 -| eval isSpike=if((latestCount > avgBlockedConnections+deviationThreshold*stdevBlockedConnections) AND numDataPoints > dataPointThreshold, 1, 0) -| where isSpike=1 -| table src_ip] -| stats values(dest_ip) as "Blocked Destination IPs", values(interface_id) as "resourceId" count as numberOfBlockedConnections, dc(dest_ip) as uniqueDestConnections by src_ip -| `detect_spike_in_blocked_outbound_traffic_from_your_aws_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#AWS_Network_ACL_Activity|AWS Network ACL Activity]] - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_AWS_Traffic|Suspicious AWS Traffic]] - -* [[Documentation:ESSOC:stories:UseCase#Command_and_Control|Command and Control]] - - -====How To Implement==== -You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your VPC Flow logs. You can modify `dataPointThreshold` and `deviationThreshold` to better fit your environment. The `dataPointThreshold` variable is the number of data points required to meet the definition of "spike." The `deviationThreshold` variable is the number of standard deviations away from the mean that the value must be to be considered a spike. This search works best when you run the "Baseline of Blocked Outbound Connection" support search once to create a history of previously seen blocked outbound connections. - -====Required field==== - -* _time - -* action - -* src_ip - -* dest_ip - - - - -====Kill Chain Phase==== - -* Actions on Objectives - -* Command and Control - - -====Known False Positives==== -The false-positive rate may vary based on the values of`dataPointThreshold` and `deviationThreshold`. Additionally, false positives may result when AWS administrators roll out policies enforcing network blocks, causing sudden increases in the number of blocked outbound connections. - -====Reference==== - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Detect shared ec2 snapshot=== -The following analytic utilizes AWS CloudTrail events to identify when an EC2 snapshot permissions are modified to be shared with a different AWS account. This method is used by adversaries to exfiltrate the EC2 snapshot. - -* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1537/ T1537] -* '''Last Updated''': 2021-07-20 - -
-
- -====Search==== -`cloudtrail` eventName=ModifySnapshotAttribute -| rename requestParameters.createVolumePermission.add.items{}.userId as requested_account_id -| search requested_account_id != NULL -| eval match=if(requested_account_id==aws_account_id,"Match","No Match") -| table _time user_arn src_ip requestParameters.attributeType requested_account_id aws_account_id match vendor_region user_agent -| where match = "No Match" -| `detect_shared_ec2_snapshot_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Cloud_Instance_Activities|Suspicious Cloud Instance Activities]] - -* [[Documentation:ESSOC:stories:UseCase#Data_Exfiltration|Data Exfiltration]] - - -====How To Implement==== -You must install splunk AWS add on and Splunk App for AWS. This search works with AWS CloudTrail logs. - -====Required field==== - -* _time - -* eventName - -* user_arn - -* src_ip - -* requestParameters.attributeType - -* aws_account_id - -* vendor_region - -* user_agent - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1537 -| Transfer Data to Cloud Account -| Exfiltration -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -It is possible that an AWS admin has legitimately shared a snapshot with others for a specific purpose. - -====Reference==== - - -* https://labs.nettitude.com/blog/how-to-exfiltrate-aws-ec2-data/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1537/aws_snapshot_exfil/aws_cloudtrail_events.json - - -''version'': 2 -
-
- ----- - -===Gcp detect gcploit framework=== -This search provides detection of GCPloit exploitation framework. This framework can be used to escalate privileges and move laterally from compromised high privilege accounts. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/ T1078] -* '''Last Updated''': 2020-10-08 - -
-
- -====Search==== -`google_gcp_pubsub_message` data.protoPayload.request.function.timeout=539s -| table src src_user data.resource.labels.project_id data.protoPayload.request.function.serviceAccountEmail data.protoPayload.authorizationInfo{}.permission data.protoPayload.request.location http_user_agent -| `gcp_detect_gcploit_framework_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#GCP_Cross_Account_Activity|GCP Cross Account Activity]] - - -====How To Implement==== -You must install splunk GCP add-on. This search works with gcp:pubsub:message logs - -====Required field==== - -* _time - -* data.protoPayload.request.function.timeout - -* src - -* src_user - -* data.resource.labels.project_id - -* data.protoPayload.request.function.serviceAccountEmail - -* data.protoPayload.authorizationInfo{}.permission - -* data.protoPayload.request.location - -* http_user_agent - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1078 -| Valid Accounts -| Defense Evasion, Persistence, Privilege Escalation, Initial Access -|} - - -====Kill Chain Phase==== - -* Lateral Movement - - -====Known False Positives==== -Payload.request.function.timeout value can possibly be match with other functions or requests however the source user and target request account may indicate an attempt to move laterally accross acounts or projects - -====Reference==== - - -* https://github.com/dxa4481/gcploit - -* https://www.youtube.com/watch?v=Ml09R38jpok - - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Gcp kubernetes cluster pod scan detection=== -This search provides information of unauthenticated requests via user agent, and authentication data against Kubernetes cluster's pods - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1526/ T1526] -* '''Last Updated''': 2020-07-17 - -
-
- -====Search==== -`google_gcp_pubsub_message` category=kube-audit -|spath input=properties.log -|search responseStatus.code=401 -|table sourceIPs{} userAgent verb requestURI responseStatus.reason properties.pod -| `gcp_kubernetes_cluster_pod_scan_detection_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Kubernetes_Scanning_Activity|Kubernetes Scanning Activity]] - - -====How To Implement==== -You must install the GCP App for Splunk (version 2.0.0 or later), then configure stackdriver and set a Pub/Sub subscription to be imported to Splunk. - -====Required field==== - -* _time - -* category - -* responseStatus.code - -* sourceIPs{} - -* userAgent - -* verb - -* requestURI - -* responseStatus.reason - -* properties.pod - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1526 -| Cloud Service Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Not all unauthenticated requests are malicious, but frequency, User Agent, source IPs and pods will provide context. - -====Reference==== - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Gsuite email suspicious attachment=== -This search is to detect a suspicious attachment file extension in Gsuite email that may related to spear phishing attack. This file type is commonly used by malware to lure user to click on it to execute malicious code to compromised targetted machine. But this search can also catch some normal files related to this file type that maybe send by employee or network admin. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud, Dev Sec Ops Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/001/ T1566.001], [https://attack.mitre.org/techniques/T1566/ T1566] -* '''Last Updated''': 2021-08-16 - -
-
- -====Search==== -`gsuite_gmail` "attachment{}.file_extension_type" IN ("pl", "py", "rb", "sh", "bat", "exe", "dll", "cpl", "com", "js", "vbs", "ps1", "reg","swf", "cmd", "go") -| eval phase="plan" -| eval severity="medium" -| stats count min(_time) as firstTime max(_time) as lastTime values(attachment{}.file_extension_type) as email_attachments, values(attachment{}.sha256) as attachment_sha256, values(payload_size) as payload_size by destination{}.service num_message_attachments subject destination{}.address source.address phase severity -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `gsuite_email_suspicious_attachment_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Dev_Sec_Ops|Dev Sec Ops]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs related to gsuite having the file attachment metadata like file type, file extension, source email, destination email, num of attachment and etc. - -====Required field==== - -* _time - -* attachment{}.file_extension_type - -* attachment{}.sha256 - -* destination{}.service - -* num_message_attachments - -* payload_size - -* subject - -* destination{}.address - -* source.address - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1566.001 -| Spearphishing Attachment -| Initial Access -|- -| T1566 -| Phishing -| Initial Access -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -network admin and normal user may send this file attachment as part of their day to day work. having a good protocol in attaching this file type to an e-mail may reduce the risk of having a spear phishing attack. - -====Reference==== - - -* https://www.redhat.com/en/topics/devops/what-is-devsecops - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/gsuite_susp_attachment_ext/gsuite_gmail_file_ext.log - - -''version'': 1 -
-
- ----- - -===Github dependabot alert=== -This search looks for Dependabot Alerts in Github logs. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud, Dev Sec Ops Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1195/001/ T1195.001], [https://attack.mitre.org/techniques/T1195/ T1195] -* '''Last Updated''': 2021-09-01 - -
-
- -====Search==== -`github` alert.id=* action=create -| rename repository.full_name as repository, repository.html_url as repository_url sender.login as user -| stats min(_time) as firstTime max(_time) as lastTime by action alert.affected_package_name alert.affected_range alert.created_at alert.external_identifier alert.external_reference alert.fixed_in alert.severity repository repository_url user -| eval phase="code" -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `github_dependabot_alert_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Dev_Sec_Ops|Dev Sec Ops]] - - -====How To Implement==== -You must index GitHub logs. You can follow the url in reference to onboard GitHub logs. - -====Required field==== - -* _time - -* alert.id - -* repository.full_name - -* repository.html_url - -* action - -* alert.affected_package_name - -* alert.affected_range - -* alert.created_at - -* alert.external_identifier - -* alert.external_reference - -* alert.fixed_in - -* alert.severity - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1195.001 -| Compromise Software Dependencies and Development Tools -| Initial Access -|- -| T1195 -| Supply Chain Compromise -| Initial Access -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://www.splunk.com/en_us/blog/tips-and-tricks/getting-github-data-with-webhooks.html - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1195.001/github_security_advisor_alert/github_security_advisor_alert.json - - -''version'': 1 -
-
- ----- - -===Github pull request from unknown user=== -This search looks for Pull Request from unknown user. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud, Dev Sec Ops Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1195/001/ T1195.001], [https://attack.mitre.org/techniques/T1195/ T1195] -* '''Last Updated''': 2021-09-01 - -
-
- -====Search==== -`github` check_suite.pull_requests{}.id=* -| stats count by check_suite.head_commit.author.name repository.full_name check_suite.pull_requests{}.head.ref check_suite.head_commit.message -| rename check_suite.head_commit.author.name as user repository.full_name as repository check_suite.pull_requests{}.head.ref as ref_head check_suite.head_commit.message as commit_message -| search NOT `github_known_users` -| eval phase="code" -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `github_pull_request_from_unknown_user_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Dev_Sec_Ops|Dev Sec Ops]] - - -====How To Implement==== -You must index GitHub logs. You can follow the url in reference to onboard GitHub logs. - -====Required field==== - -* _time - -* alert.id - -* repository.full_name - -* repository.html_url - -* action - -* alert.affected_package_name - -* alert.affected_range - -* alert.created_at - -* alert.external_identifier - -* alert.external_reference - -* alert.fixed_in - -* alert.severity - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1195.001 -| Compromise Software Dependencies and Development Tools -| Initial Access -|- -| T1195 -| Supply Chain Compromise -| Initial Access -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://www.splunk.com/en_us/blog/tips-and-tricks/getting-github-data-with-webhooks.html - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1195.001/github_pull_request/github_pull_request.json - - -''version'': 1 -
-
- ----- - -===Github commit changes in master=== -This search is to detect a pushed or commit to master or main branch. This is to avoid unwanted modification to master without a review to the changes. Ideally in terms of devsecops the changes made in a branch and do a PR for review. of course in some cases admin of the project may did a changes directly to master branch - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud, Dev Sec Ops Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1199/ T1199] -* '''Last Updated''': 2021-08-20 - -
-
- -====Search==== -`github` branches{}.name = main OR branches{}.name = master -| eval severity="low" -| eval phase="code" -| stats count min(_time) as firstTime max(_time) as lastTime by commit.author.html_url commit.commit.author.email commit.author.login commit.commit.message repository.pushed_at commit.commit.committer.date, phase, severity -| eval phase="code" -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `github_commit_changes_in_master_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Dev_Sec_Ops|Dev Sec Ops]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs related to github logs having the fork, commit, push metadata that can be use to monitor the changes in a github project. - -====Required field==== - -* _time - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1199 -| Trusted Relationship -| Initial Access -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -admin can do changes directly to master branch - -====Reference==== - - -* https://www.redhat.com/en/topics/devops/what-is-devsecops - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1199/github_push_master/github_push_master.log - - -''version'': 1 -
-
- ----- - -===Github commit in develop=== -This search is to detect a pushed or commit to develop branch. This is to avoid unwanted modification to develop without a review to the changes. Ideally in terms of devsecops the changes made in a branch and do a PR for review. of course in some cases admin of the project may did a changes directly to master branch - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud, Dev Sec Ops Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1199/ T1199] -* '''Last Updated''': 2021-09-01 - -
-
- -====Search==== -`github` branches{}.name = main OR branches{}.name = develop -| stats count min(_time) as firstTime max(_time) as lastTime by commit.author.html_url commit.commit.author.email commit.author.login commit.commit.message repository.pushed_at commit.commit.committer.date -| eval phase="code" -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `github_commit_in_develop_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Dev_Sec_Ops|Dev Sec Ops]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs related to github logs having the fork, commit, push metadata that can be use to monitor the changes in a github project. - -====Required field==== - -* _time - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1199 -| Trusted Relationship -| Initial Access -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -admin can do changes directly to develop branch - -====Reference==== - - -* https://www.redhat.com/en/topics/devops/what-is-devsecops - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1199/github_push_master/github_push_develop.json - - -''version'': 1 -
-
- ----- - -===Gsuite drive share in external email=== -This search is to detect suspicious google drive or google docs files shared outside or externally. This behavior might be a good hunting query to monitor exfitration of data made by an attacker or insider to a targetted machine. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud, Dev Sec Ops Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1567/002/ T1567.002], [https://attack.mitre.org/techniques/T1567/ T1567] -* '''Last Updated''': 2021-08-16 - -
-
- -====Search==== -`gsuite_drive` NOT (email IN("", "null")) -| rex field=parameters.owner "[^@]+@(?<src_domain>[^@]+)" -| rex field=email "[^@]+@(?<dest_domain>[^@]+)" -| where src_domain = "internal_test_email.com" and not dest_domain = "internal_test_email.com" -| eval phase="plan" -| eval severity="low" -| stats values(parameters.doc_title) as doc_title, values(parameters.doc_type) as doc_types, values(email) as dst_email_list, values(parameters.visibility) as visibility, values(parameters.doc_id) as doc_id, count min(_time) as firstTime max(_time) as lastTime by parameters.owner ip_address phase severity -| rename parameters.owner as user ip_address as src_ip -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `gsuite_drive_share_in_external_email_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Dev_Sec_Ops|Dev Sec Ops]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs related to gsuite having the file attachment metadata like file type, file extension, source email, destination email, num of attachment and etc. In order for the search to work for your environment, please edit the query to use your company specific email domain instead of `internal_test_email.com`. - -====Required field==== - -* _time - -* parameters.doc_title - -* src_domain - -* dest_domain - -* email - -* parameters.visibility - -* parameters.owner - -* parameters.doc_type - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1567.002 -| Exfiltration to Cloud Storage -| Exfiltration -|- -| T1567 -| Exfiltration Over Web Service -| Exfiltration -|} - - -====Kill Chain Phase==== - -* Exfiltration - - -====Known False Positives==== -network admin or normal user may share files to customer and external team. - -====Reference==== - - -* https://www.redhat.com/en/topics/devops/what-is-devsecops - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1567.002/gsuite_share_drive/gdrive_share_external.log - - -''version'': 1 -
-
- ----- - -===Gsuite email suspicious subject with attachment=== -This search is to detect a gsuite email contains suspicious subject having known file type used in spear phishing. This technique is a common and effective entry vector of attacker to compromise a network by luring the user to click or execute the suspicious attachment send from external email account because of the effective social engineering of subject related to delivery, bank and so on. On the other hand this detection may catch a normal email traffic related to legitimate transaction so better to check the email sender, spelling and etc. avoid click link or opening the attachment if you are not expecting this type of e-mail. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud, Dev Sec Ops Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/001/ T1566.001], [https://attack.mitre.org/techniques/T1566/ T1566] -* '''Last Updated''': 2021-08-19 - -
-
- -====Search==== -`gsuite_gmail` num_message_attachments > 0 subject IN ("*dhl*", "* ups *", "*delivery*", "*parcel*", "*label*", "*invoice*", "*postal*", "* fedex *", "* usps *", "* express *", "*shipment*", "*Banking/Tax*","*shipment*", "*new order*") attachment{}.file_extension_type IN ("doc", "docx", "xls", "xlsx", "ppt", "pptx", "pdf", "zip", "rar", "html","htm","hta") -| rex field=source.from_header_address "[^@]+@(?<source_domain>[^@]+)" -| rex field=destination{}.address "[^@]+@(?<dest_domain>[^@]+)" -| where not source_domain="internal_test_email.com" and dest_domain="internal_test_email.com" -| eval phase="plan" -| eval severity="medium" -| stats count min(_time) as firstTime max(_time) as lastTime values(attachment{}.file_extension_type) as email_attachments, values(attachment{}.sha256) as attachment_sha256, values(payload_size) as payload_size by destination{}.service num_message_attachments subject destination{}.address source.address phase severity -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `gsuite_email_suspicious_subject_with_attachment_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Dev_Sec_Ops|Dev Sec Ops]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs related to gsuite having the file attachment metadata like file type, file extension, source email, destination email, num of attachment and etc. - -====Required field==== - -* _time - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1566.001 -| Spearphishing Attachment -| Initial Access -|- -| T1566 -| Phishing -| Initial Access -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -normal user or normal transaction may contain the subject and file type attachment that this detection try to search. - -====Reference==== - - -* https://www.redhat.com/en/topics/devops/what-is-devsecops - -* https://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/rpt-top-spear-phishing-words.pdf - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/gsuite_susp_subj/gsuite_susp_subj_attach.log - - -''version'': 1 -
-
- ----- - -===Gsuite email with known abuse web service link=== -This analytics is to detect a gmail containing a link that are known to be abused by malware or attacker like pastebin, telegram and discord to deliver malicious payload. This event can encounter some normal email traffic within organization and external email that normally using this application and services. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud, Dev Sec Ops Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/001/ T1566.001], [https://attack.mitre.org/techniques/T1566/ T1566] -* '''Last Updated''': 2021-08-23 - -
-
- -====Search==== -`gsuite_gmail` "link_domain{}" IN ("*pastebin.com*", "*discord*", "*telegram*","t.me") -| rex field=source.from_header_address "[^@]+@(?<source_domain>[^@]+)" -| rex field=destination{}.address "[^@]+@(?<dest_domain>[^@]+)" -| where not source_domain="internal_test_email.com" and dest_domain="internal_test_email.com" -| eval phase="plan" -| eval severity="low" -|stats values(link_domain{}) as link_domains min(_time) as firstTime max(_time) as lastTime count by is_spam source.address source.from_header_address subject destination{}.address phase severity -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `gsuite_email_with_known_abuse_web_service_link_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Dev_Sec_Ops|Dev Sec Ops]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs related to gsuite having the file attachment metadata like file type, file extension, source email, destination email, num of attachment and etc. - -====Required field==== - -* _time - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1566.001 -| Spearphishing Attachment -| Initial Access -|- -| T1566 -| Phishing -| Initial Access -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -normal email contains this link that are known application within the organization or network can be catched by this detection. - -====Reference==== - - -* https://news.sophos.com/en-us/2021/07/22/malware-increasingly-targets-discord-for-abuse/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/gsuite_susp_url/gsuite_susp_url.log - - -''version'': 1 -
-
- ----- - -===Gsuite outbound email with attachment to external domain=== -This search is to detect a suspicious outbound e-mail from internal email to external email domain. This can be a good hunting query to monitor insider or outbound email traffic for not common domain e-mail. The idea is to parse the domain of destination email check if there is a minimum outbound traffic < 20 with attachment. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud, Dev Sec Ops Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1048/003/ T1048.003], [https://attack.mitre.org/techniques/T1048/ T1048] -* '''Last Updated''': 2021-08-17 - -
-
- -====Search==== -`gsuite_gmail` num_message_attachments > 0 -| rex field=source.from_header_address "[^@]+@(?<source_domain>[^@]+)" -| rex field=destination{}.address "[^@]+@(?<dest_domain>[^@]+)" -| where source_domain="internal_test_email.com" and not dest_domain="internal_test_email.com" -| eval phase="plan" -| eval severity="low" -| stats values(subject) as subject, values(source.from_header_address) as src_domain_list, count as numEvents, dc(source.from_header_address) as numSrcAddresses, min(_time) as firstTime max(_time) as lastTime by dest_domain phase severity -| where numSrcAddresses < 20 -|sort - numSrcAddresses -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `gsuite_outbound_email_with_attachment_to_external_domain_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Dev_Sec_Ops|Dev Sec Ops]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs related to gsuite having the file attachment metadata like file type, file extension, source email, destination email, num of attachment and etc. - -====Required field==== - -* _time - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1048.003 -| Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol -| Exfiltration -|- -| T1048 -| Exfiltration Over Alternative Protocol -| Exfiltration -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -network admin and normal user may send this file attachment as part of their day to day work. having a good protocol in attaching this file type to an e-mail may reduce the risk of having a spear phishing attack. - -====Reference==== - - -* https://www.redhat.com/en/topics/devops/what-is-devsecops - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/gsuite_outbound_email_to_external/gsuite_external_domain.log - - -''version'': 1 -
-
- ----- - -===Gsuite suspicious shared file name=== -This search is to detect a shared file in google drive with suspicious file name that are commonly used by spear phishing campaign. This technique is very popular to lure the user by running a malicious document or click a malicious link within the shared file that will redirected to malicious website. This detection can also catch some normal email communication between organization and its external customer. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud, Dev Sec Ops Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/001/ T1566.001], [https://attack.mitre.org/techniques/T1566/ T1566] -* '''Last Updated''': 2021-08-23 - -
-
- -====Search==== -`gsuite_drive` parameters.owner_is_team_drive=false "parameters.doc_title" IN ("*dhl*", "* ups *", "*delivery*", "*parcel*", "*label*", "*invoice*", "*postal*", "*fedex*", "* usps *", "* express *", "*shipment*", "*Banking/Tax*","*shipment*", "*new order*") parameters.doc_type IN ("document","pdf", "msexcel", "msword", "spreadsheet", "presentation") -| rex field=parameters.owner "[^@]+@(?<source_domain>[^@]+)" -| rex field=parameters.target_user "[^@]+@(?<dest_domain>[^@]+)" -| where not source_domain="internal_test_email.com" and dest_domain="internal_test_email.com" -| eval phase="plan" -| eval severity="low" -| stats count min(_time) as firstTime max(_time) as lastTime by email parameters.owner parameters.target_user parameters.doc_title parameters.doc_type phase severity -| rename parameters.target_user AS user -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `gsuite_suspicious_shared_file_name_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Dev_Sec_Ops|Dev Sec Ops]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs related to gsuite having the file attachment metadata like file type, file extension, source email, destination email, num of attachment and etc. In order for the search to work for your environment, please edit the query to use your company specific email domain instead of `internal_test_email.com`. - -====Required field==== - -* _time - -* parameters.doc_title - -* src_domain - -* dest_domain - -* email - -* parameters.visibility - -* parameters.owner - -* parameters.doc_type - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1566.001 -| Spearphishing Attachment -| Initial Access -|- -| T1566 -| Phishing -| Initial Access -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -normal user or normal transaction may contain the subject and file type attachment that this detection try to search - -====Reference==== - - -* https://www.redhat.com/en/topics/devops/what-is-devsecops - -* https://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/rpt-top-spear-phishing-words.pdf - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/gdrive_susp_file_share/gdrive_susp_attach.log - - -''version'': 1 -
-
- ----- - -===High number of login failures from a single source=== -This search will detect more than 5 login failures in Office365 Azure Active Directory from a single source IP address. Please adjust the threshold value of 5 as suited for your environment. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1110/001/ T1110.001], [https://attack.mitre.org/techniques/T1110/ T1110] -* '''Last Updated''': 2020-12-16 - -
-
- -====Search==== -`o365_management_activity` Operation=UserLoginFailed record_type=AzureActiveDirectoryStsLogon app=AzureActiveDirectory -| stats count dc(user) as accounts_locked values(user) as user values(LogonError) as LogonError values(authentication_method) as authentication_method values(signature) as signature values(UserAgent) as UserAgent by src_ip record_type Operation app -| search accounts_locked >= 5 -| `high_number_of_login_failures_from_a_single_source_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Office_365_Detections|Office 365 Detections]] - - -====How To Implement==== - - -====Required field==== - -* _time - -* Operation - -* record_type - -* app - -* user - -* LogonError - -* authentication_method - -* signature - -* UserAgent - -* src_ip - -* record_type - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1110.001 -| Password Guessing -| Credential Access -|- -| T1110 -| Brute Force -| Credential Access -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -unknown - -====Reference==== - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Kubernetes aws detect suspicious kubectl calls=== -This search provides information on anonymous Kubectl calls with IP, verb namespace and object access context - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': -* '''Last Updated''': 2020-06-23 - -
-
- -====Search==== -`aws_cloudwatchlogs_eks` userAgent=kubectl* sourceIPs{}!=127.0.0.1 sourceIPs{}!=::1 src_user=system:anonymous -| table src_ip src_user verb userAgent requestURI -| stats count by src_ip src_user verb userAgent requestURI -|`kubernetes_aws_detect_suspicious_kubectl_calls_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Kubernetes_Sensitive_Object_Access_Activity|Kubernetes Sensitive Object Access Activity]] - - -====How To Implement==== -You must install splunk AWS add on and Splunk App for AWS. This search works with cloudwatch logs. - -====Required field==== - -* _time - -* userAgent - -* sourceIPs{} - -* src_user - -* src_ip - -* verb - -* requestURI - - - - -====Kill Chain Phase==== - -* Lateral Movement - - -====Known False Positives==== -Kubectl calls are not malicious by nature. However source IP, verb and Object can reveal potential malicious activity, specially anonymous suspicious IPs and sensitive objects such as configmaps or secrets - -====Reference==== - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Kubernetes nginx ingress lfi=== -This search uses the Kubernetes logs from a nginx ingress controller to detect local file inclusion attacks. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud, Dev Sec Ops Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1212/ T1212] -* '''Last Updated''': 2021-08-20 - -
-
- -====Search==== -`kubernetes_container_controller` -| rex field=_raw "^(?<remote_addr>\S+)\s+-\s+-\s+\[(?<time_local>[^\]]*)\]\s\"(?<request>[^\"]*)\"\s(?<status>\S*)\s(?<body_bytes_sent>\S*)\s\"(?<http_referer>[^\"]*)\"\s\"(?<http_user_agent>[^\"]*)\"\s(?<request_length>\S*)\s(?<request_time>\S*)\s\[(?<proxy_upstream_name>[^\]]*)\]\s\[(?<proxy_alternative_upstream_name>[^\]]*)\]\s(?<upstream_addr>\S*)\s(?<upstream_response_length>\S*)\s(?<upstream_response_time>\S*)\s(?<upstream_status>\S*)\s(?<req_id>\S*)" -| lookup local_file_inclusion_paths local_file_inclusion_paths AS request OUTPUT lfi_path -| search lfi_path=yes -| rename remote_addr AS src_ip, upstream_status as status, proxy_upstream_name as proxy -| rex field=request "^(?<http_method>\S+)\s(?<url>\S+)\s" -| eval phase="operate" -| eval severity="high" -| stats count min(_time) as firstTime max(_time) as lastTime by src_ip, status, url, http_method, host, http_user_agent, proxy, phase, severity -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `kubernetes_nginx_ingress_lfi_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Dev_Sec_Ops|Dev Sec Ops]] - - -====How To Implement==== -You must ingest Kubernetes logs through Splunk Connect for Kubernetes. - -====Required field==== - -* raw - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1212 -| Exploitation for Credential Access -| Credential Access -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://github.com/splunk/splunk-connect-for-kubernetes - -* https://www.offensive-security.com/metasploit-unleashed/file-inclusion-vulnerabilities/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1212/kubernetes_nginx_lfi_attack/kubernetes_nginx_lfi_attack.log - - -''version'': 1 -
-
- ----- - -===Kubernetes nginx ingress rfi=== -This search uses the Kubernetes logs from a nginx ingress controller to detect remote file inclusion attacks. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud, Dev Sec Ops Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1212/ T1212] -* '''Last Updated''': 2021-08-23 - -
-
- -====Search==== -`kubernetes_container_controller` -| rex field=_raw "^(?<remote_addr>\S+)\s+-\s+-\s+\[(?<time_local>[^\]]*)\]\s\"(?<request>[^\"]*)\"\s(?<status>\S*)\s(?<body_bytes_sent>\S*)\s\"(?<http_referer>[^\"]*)\"\s\"(?<http_user_agent>[^\"]*)\"\s(?<request_length>\S*)\s(?<request_time>\S*)\s\[(?<proxy_upstream_name>[^\]]*)\]\s\[(?<proxy_alternative_upstream_name>[^\]]*)\]\s(?<upstream_addr>\S*)\s(?<upstream_response_length>\S*)\s(?<upstream_response_time>\S*)\s(?<upstream_status>\S*)\s(?<req_id>\S*)" -| rex field=request "^(?<http_method>\S+)?\s(?<url>\S+)\s" -| rex field=url "(?<dest_ip>\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})" -| search dest_ip=* -| rename remote_addr AS src_ip, upstream_status as status, proxy_upstream_name as proxy -| eval phase="operate" -| eval severity="medium" -| stats count min(_time) as firstTime max(_time) as lastTime by src_ip, dest_ip status, url, http_method, host, http_user_agent, proxy, phase, severity -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `kubernetes_nginx_ingress_rfi_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Dev_Sec_Ops|Dev Sec Ops]] - - -====How To Implement==== -You must ingest Kubernetes logs through Splunk Connect for Kubernetes. - -====Required field==== - -* raw - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1212 -| Exploitation for Credential Access -| Credential Access -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://github.com/splunk/splunk-connect-for-kubernetes - -* https://www.netsparker.com/blog/web-security/remote-file-inclusion-vulnerability/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1212/kuberntest_nginx_rfi_attack/kubernetes_nginx_rfi_attack.log - - -''version'': 1 -
-
- ----- - -===Kubernetes scanner image pulling=== -This search uses the Kubernetes logs from Splunk Connect from Kubernetes to detect Kubernetes Security Scanner. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud, Dev Sec Ops Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1526/ T1526] -* '''Last Updated''': 2021-08-24 - -
-
- -====Search==== -`kube_objects_events` object.message IN ("Pulling image *kube-hunter*", "Pulling image *kube-bench*", "Pulling image *kube-recon*", "Pulling image *kube-recon*") -| rename object.* AS * -| rename involvedObject.* AS * -| rename source.host AS host -| eval phase="operate" -| eval severity="high" -| stats min(_time) as firstTime max(_time) as lastTime count by host, name, namespace, kind, reason, message, phase, severity -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `kubernetes_scanner_image_pulling_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Dev_Sec_Ops|Dev Sec Ops]] - - -====How To Implement==== -You must ingest Kubernetes logs through Splunk Connect for Kubernetes. - -====Required field==== - -* object.message - -* source.host - -* object.involvedObject.name - -* object.involvedObject.namespace - -* object.involvedObject.kind - -* object.message - -* object.reason - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1526 -| Cloud Service Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://github.com/splunk/splunk-connect-for-kubernetes - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1526/kubernetes_kube_hunter/kubernetes_kube_hunter.json - - -''version'': 1 -
-
- ----- - -===New container uploaded to aws ecr=== -This searches show information on uploaded containers including source user, image id, source IP user type, http user agent, region, first time, last time of operation (PutImage). These searches are based on Cloud Infrastructure Data Model. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1525/ T1525] -* '''Last Updated''': 2020-02-20 - -
-
- -====Search==== - -| tstats count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Cloud_Infrastructure.Compute where Compute.user_type!="AssumeRole" AND Compute.http_user_agent="AWS Internal" AND Compute.event_name="PutImage" by Compute.image_id Compute.src_user Compute.src Compute.region Compute.msg Compute.user_type -| `drop_dm_object_name("Compute")` -| `new_container_uploaded_to_aws_ecr_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Container_Implantation_Monitoring_and_Investigation|Container Implantation Monitoring and Investigation]] - - -====How To Implement==== -You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your AWS CloudTrail inputs. You must also install Cloud Infrastructure data model. Please also customize the `container_implant_aws_detection_filter` macro to filter out the false positives. - -====Required field==== - -* _time - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1525 -| Implant Internal Image -| Persistence -|} - - -====Kill Chain Phase==== - - -====Known False Positives==== -Uploading container is a normal behavior from developers or users with access to container registry. - -====Reference==== - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===O365 add app role assignment grant user=== -This search detects the creation of a new Federation setting by alerting about an specific event related to its creation. - -* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1136/003/ T1136.003], [https://attack.mitre.org/techniques/T1136/ T1136] -* '''Last Updated''': 2021-01-26 - -
-
- -====Search==== -`o365_management_activity` Workload=AzureActiveDirectory Operation="Add app role assignment grant to user." -| stats count min(_time) as firstTime max(_time) as lastTime values(Actor{}.ID) as Actor.ID values(Actor{}.Type) as Actor.Type by ActorIpAddress dest ResultStatus -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `o365_add_app_role_assignment_grant_user_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Office_365_Detections|Office 365 Detections]] - -* [[Documentation:ESSOC:stories:UseCase#Cloud_Federated_Credential_Abuse|Cloud Federated Credential Abuse]] - - -====How To Implement==== -You must install splunk Microsoft Office 365 add-on. This search works with o365:management:activity - -====Required field==== - -* _time - -* Workload - -* Operation - -* Actor{}.ID - -* Actor{}.Type - -* ActorIpAddress - -* dest - -* ResultStatus - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1136.003 -| Cloud Account -| Persistence -|- -| T1136 -| Create Account -| Persistence -|} - - -====Kill Chain Phase==== - -* Actions on Objective - - -====Known False Positives==== -The creation of a new Federation is not necessarily malicious, however this events need to be followed closely, as it may indicate federated credential abuse or backdoor via federated identities at a different cloud provider. - -====Reference==== - - -* https://www.fireeye.com/content/dam/fireeye-www/blog/pdfs/wp-m-unc2452-2021-000343-01.pdf - -* https://us-cert.cisa.gov/ncas/alerts/aa21-008a - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.003/o365_new_federation/o365_new_federation.json - - -''version'': 1 -
-
- ----- - -===O365 added service principal=== -This search detects the creation of a new Federation setting by alerting about an specific event related to its creation. - -* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1136/003/ T1136.003], [https://attack.mitre.org/techniques/T1136/ T1136] -* '''Last Updated''': 2021-01-26 - -
-
- -====Search==== -`o365_management_activity` Workload=AzureActiveDirectory signature="Add service principal credentials." -| stats min(_time) as firstTime max(_time) as lastTime values(Actor{}.ID) as Actor.ID values(ModifiedProperties{}.Name) as ModifiedProperties.Name values(ModifiedProperties{}.NewValue) as ModifiedProperties.NewValue values(Target{}.ID) as Target.ID by ActorIpAddress signature -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `o365_added_service_principal_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Office_365_Detections|Office 365 Detections]] - -* [[Documentation:ESSOC:stories:UseCase#Cloud_Federated_Credential_Abuse|Cloud Federated Credential Abuse]] - - -====How To Implement==== -You must install splunk Microsoft Office 365 add-on. This search works with o365:management:activity - -====Required field==== - -* _time - -* Workload - -* signature - -* Actor{}.ID - -* ModifiedProperties{}.Name - -* ModifiedProperties{}.NewValue - -* Target{}.ID - -* ActorIpAddress - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1136.003 -| Cloud Account -| Persistence -|- -| T1136 -| Create Account -| Persistence -|} - - -====Kill Chain Phase==== - -* Actions on Objective - - -====Known False Positives==== -The creation of a new Federation is not necessarily malicious, however these events need to be followed closely, as it may indicate federated credential abuse or backdoor via federated identities at a different cloud provider. - -====Reference==== - - -* https://www.fireeye.com/content/dam/fireeye-www/blog/pdfs/wp-m-unc2452-2021-000343-01.pdf - -* https://us-cert.cisa.gov/ncas/alerts/aa21-008a - -* https://www.splunk.com/en_us/blog/security/a-golden-saml-journey-solarwinds-continued.html - -* https://www.sygnia.co/golden-saml-advisory - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.003/o365_add_service_principal/o365_add_service_principal.json - - -''version'': 1 -
-
- ----- - -===O365 bypass mfa via trusted ip=== -This search detects newly added IP addresses/CIDR blocks to the list of MFA Trusted IPs to bypass multi factor authentication. Attackers are often known to use this technique so that they can bypass the MFA system. - -* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/007/ T1562.007], [https://attack.mitre.org/techniques/T1562/ T1562] -* '''Last Updated''': 2021-07-19 - -
-
- -====Search==== -`o365_management_activity` signature="Set Company Information." ModifiedProperties{}.Name=StrongAuthenticationPolicy -| rex max_match=100 field=ModifiedProperties{}.NewValue "(?<ip_addresses_new_added>\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\/\d{1,2})" -| rex max_match=100 field=ModifiedProperties{}.OldValue "(?<ip_addresses_old>\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\/\d{1,2})" -| eval ip_addresses_old=if(isnotnull(ip_addresses_old),ip_addresses_old,"0") -| mvexpand ip_addresses_new_added -| where isnull(mvfind(ip_addresses_old,ip_addresses_new_added)) -|stats count min(_time) as firstTime max(_time) as lastTime values(ip_addresses_old) as ip_addresses_old by user ip_addresses_new_added signature Workload vendor_account status user_id action -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `o365_bypass_mfa_via_trusted_ip_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Office_365_Detections|Office 365 Detections]] - - -====How To Implement==== -You must install Splunk Microsoft Office 365 add-on. This search works with o365:management:activity - -====Required field==== - -* _time - -* signature - -* ModifiedProperties{}.Name - -* ModifiedProperties{}.NewValue - -* ModifiedProperties{}.OldValue - -* user - -* vendor_account - -* status - -* user_id - -* action - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1562.007 -| Disable or Modify Cloud Firewall -| Defense Evasion -|- -| T1562 -| Impair Defenses -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Actions on Objective - - -====Known False Positives==== -Unless it is a special case, it is uncommon to continually update Trusted IPs to MFA configuration. - -====Reference==== - - -* https://i.blackhat.com/USA-20/Thursday/us-20-Bienstock-My-Cloud-Is-APTs-Cloud-Investigating-And-Defending-Office-365.pdf - -* https://attack.mitre.org/techniques/T1562/007/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.007/o365_bypass_mfa_via_trusted_ip/o365_bypass_mfa_via_trusted_ip.json - - -''version'': 2 -
-
- ----- - -===O365 disable mfa=== -This search detects when multi factor authentication has been disabled, what entitiy performed the action and against what user - -* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1556/ T1556] -* '''Last Updated''': 2020-12-16 - -
-
- -====Search==== -`o365_management_activity` Operation="Disable Strong Authentication." -| stats count earliest(_time) as firstTime latest(_time) as lastTime by UserType Operation user status signature dest ResultStatus -|`security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -| `o365_disable_mfa_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Office_365_Detections|Office 365 Detections]] - - -====How To Implement==== -You must install splunk Microsoft Office 365 add-on. This search works with o365:management:activity - -====Required field==== - -* _time - -* Operation - -* UserType - -* user - -* status - -* signature - -* dest - -* ResultStatus - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1556 -| Modify Authentication Process -| Credential Access, Defense Evasion, Persistence -|} - - -====Kill Chain Phase==== - -* Actions on Objective - - -====Known False Positives==== -Unless it is a special case, it is uncommon to disable MFA or Strong Authentication - -====Reference==== - - -* https://attack.mitre.org/techniques/T1556/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1556/o365_disable_mfa/o365_disable_mfa.json - - -''version'': 1 -
-
- ----- - -===O365 excessive authentication failures alert=== -This search detects when an excessive number of authentication failures occur this search also includes attempts against MFA prompt codes - -* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1110/ T1110] -* '''Last Updated''': 2020-12-16 - -
-
- -====Search==== -`o365_management_activity` Workload=AzureActiveDirectory UserAuthenticationMethod=* status=Failed -| stats count earliest(_time) as firstTime latest(_time) values(UserAuthenticationMethod) AS UserAuthenticationMethod values(UserAgent) AS UserAgent values(status) AS status values(src_ip) AS src_ip by user -| where count > 10 -|`security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -| `o365_excessive_authentication_failures_alert_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Office_365_Detections|Office 365 Detections]] - - -====How To Implement==== -You must install splunk Microsoft Office 365 add-on. This search works with o365:management:activity - -====Required field==== - -* _time - -* Workload - -* UserAuthenticationMethod - -* status - -* UserAgent - -* src_ip - -* user - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1110 -| Brute Force -| Credential Access -|} - - -====Kill Chain Phase==== - -* Not Applicable - - -====Known False Positives==== -The threshold for alert is above 10 attempts and this should reduce the number of false positives. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1110/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110/o365_brute_force_login/o365_brute_force_login.json - - -''version'': 1 -
-
- ----- - -===O365 excessive sso logon errors=== -This search detects accounts with high number of Single Sign ON (SSO) logon errors. Excessive logon errors may indicate attempts to bruteforce of password or single sign on token hijack or reuse. - -* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1556/ T1556] -* '''Last Updated''': 2021-01-26 - -
-
- -====Search==== -`o365_management_activity` Workload=AzureActiveDirectory LogonError=SsoArtifactInvalidOrExpired -| stats count min(_time) as firstTime max(_time) as lastTime by LogonError ActorIpAddress UserAgent UserId -| where count > 5 -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `o365_excessive_sso_logon_errors_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Office_365_Detections|Office 365 Detections]] - -* [[Documentation:ESSOC:stories:UseCase#Cloud_Federated_Credential_Abuse|Cloud Federated Credential Abuse]] - - -====How To Implement==== -You must install splunk Microsoft Office 365 add-on. This search works with o365:management:activity - -====Required field==== - -* _time - -* Workload - -* LogonError - -* ActorIpAddress - -* UserAgent - -* UserId - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1556 -| Modify Authentication Process -| Credential Access, Defense Evasion, Persistence -|} - - -====Kill Chain Phase==== - -* Actions on Objective - - -====Known False Positives==== -Logon errors may not be malicious in nature however it may indicate attempts to reuse a token or password obtained via credential access attack. - -====Reference==== - - -* https://stealthbits.com/blog/bypassing-mfa-with-pass-the-cookie/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1556/o365_sso_logon_errors/o365_sso_logon_errors.json - - -''version'': 1 -
-
- ----- - -===O365 new federated domain added=== -This search detects the addition of a new Federated domain. - -* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1136/003/ T1136.003], [https://attack.mitre.org/techniques/T1136/ T1136] -* '''Last Updated''': 2021-01-26 - -
-
- -====Search==== -`o365_management_activity` Workload=Exchange Operation="Add-FederatedDomain" -| stats count min(_time) as firstTime max(_time) as lastTime values(Parameters{}.Value) as Parameters.Value by ObjectId Operation OrganizationName OriginatingServer UserId UserKey -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `o365_new_federated_domain_added_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Office_365_Detections|Office 365 Detections]] - -* [[Documentation:ESSOC:stories:UseCase#Cloud_Federated_Credential_Abuse|Cloud Federated Credential Abuse]] - - -====How To Implement==== -You must install splunk Microsoft Office 365 add-on. This search works with o365:management:activity. - -====Required field==== - -* _time - -* Workload - -* Operation - -* Parameters{}.Value - -* ObjectId - -* OrganizationName - -* OriginatingServer - -* UserId - -* UserKey - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1136.003 -| Cloud Account -| Persistence -|- -| T1136 -| Create Account -| Persistence -|} - - -====Kill Chain Phase==== - -* Actions on Objective - - -====Known False Positives==== -The creation of a new Federated domain is not necessarily malicious, however these events need to be followed closely, as it may indicate federated credential abuse or backdoor via federated identities at a similar or different cloud provider. - -====Reference==== - - -* https://www.fireeye.com/content/dam/fireeye-www/blog/pdfs/wp-m-unc2452-2021-000343-01.pdf - -* https://us-cert.cisa.gov/ncas/alerts/aa21-008a - -* https://www.splunk.com/en_us/blog/security/a-golden-saml-journey-solarwinds-continued.html - -* https://www.sygnia.co/golden-saml-advisory - -* https://o365blog.com/post/aadbackdoor/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.003/o365_new_federated_domain/o365_new_federated_domain.json - - -''version'': 1 -
-
- ----- - -===O365 pst export alert=== -This search detects when a user has performed an Ediscovery search or exported a PST file from the search. This PST file usually has sensitive information including email body content - -* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1114/ T1114] -* '''Last Updated''': 2020-12-16 - -
-
- -====Search==== -`o365_management_activity` Category=ThreatManagement Name="eDiscovery search started or exported" -| stats count earliest(_time) as firstTime latest(_time) as lastTime by Source Severity AlertEntityId Operation Name -|`security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -| `o365_pst_export_alert_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Office_365_Detections|Office 365 Detections]] - -* [[Documentation:ESSOC:stories:UseCase#Data_Exfiltration|Data Exfiltration]] - - -====How To Implement==== -You must install splunk Microsoft Office 365 add-on. This search works with o365:management:activity - -====Required field==== - -* _time - -* Category - -* Name - -* Source - -* Severity - -* AlertEntityId - -* Operation - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1114 -| Email Collection -| Collection -|} - - -====Kill Chain Phase==== - -* Actions on Objective - - -====Known False Positives==== -PST export can be done for legitimate purposes but due to the sensitive nature of its content it must be monitored. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1114/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1114/o365_export_pst_file/o365_export_pst_file.json - - -''version'': 1 -
-
- ----- - -===O365 suspicious admin email forwarding=== -This search detects when an admin configured a forwarding rule for multiple mailboxes to the same destination. - -* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1114/003/ T1114.003], [https://attack.mitre.org/techniques/T1114/ T1114] -* '''Last Updated''': 2020-12-16 - -
-
- -====Search==== -`o365_management_activity` Operation=Set-Mailbox -| spath input=Parameters -| rename Identity AS src_user -| search ForwardingAddress=* -| stats dc(src_user) AS count_src_user earliest(_time) as firstTime latest(_time) as lastTime values(src_user) AS src_user values(user) AS user by ForwardingAddress -| where count_src_user > 1 -|`security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -|`o365_suspicious_admin_email_forwarding_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Office_365_Detections|Office 365 Detections]] - -* [[Documentation:ESSOC:stories:UseCase#Data_Exfiltration|Data Exfiltration]] - - -====How To Implement==== -You must install splunk Microsoft Office 365 add-on. This search works with o365:management:activity - -====Required field==== - -* _time - -* Operation - -* Parameters - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1114.003 -| Email Forwarding Rule -| Collection -|- -| T1114 -| Email Collection -| Collection -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -unknown - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1114.003/o365_email_forwarding_rule/o365_email_forwarding_rule.json - - -''version'': 1 -
-
- ----- - -===O365 suspicious rights delegation=== -This search detects the assignment of rights to accesss content from another mailbox. This is usually only assigned to a service account. - -* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1114/002/ T1114.002], [https://attack.mitre.org/techniques/T1114/ T1114] -* '''Last Updated''': 2020-12-15 - -
-
- -====Search==== -`o365_management_activity` Operation=Add-MailboxPermission -| spath input=Parameters -| rename User AS src_user, Identity AS dest_user -| search AccessRights=FullAccess OR AccessRights=SendAs OR AccessRights=SendOnBehalf -| stats count earliest(_time) as firstTime latest(_time) as lastTime by user src_user dest_user Operation AccessRights -|`security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -|`o365_suspicious_rights_delegation_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Office_365_Detections|Office 365 Detections]] - - -====How To Implement==== -You must install splunk Microsoft Office 365 add-on. This search works with o365:management:activity - -====Required field==== - -* _time - -* Operation - -* Parameters - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1114.002 -| Remote Email Collection -| Collection -|- -| T1114 -| Email Collection -| Collection -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Service Accounts - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1114.002/suspicious_rights_delegation/suspicious_rights_delegation.json - - -''version'': 1 -
-
- ----- - -===O365 suspicious user email forwarding=== -This search detects when multiple user configured a forwarding rule to the same destination. - -* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1114/003/ T1114.003], [https://attack.mitre.org/techniques/T1114/ T1114] -* '''Last Updated''': 2020-12-16 - -
-
- -====Search==== -`o365_management_activity` Operation=Set-Mailbox -| spath input=Parameters -| rename Identity AS src_user -| search ForwardingSmtpAddress=* -| stats dc(src_user) AS count_src_user earliest(_time) as firstTime latest(_time) as lastTime values(src_user) AS src_user values(user) AS user by ForwardingSmtpAddress -| where count_src_user > 1 -|`security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -|`o365_suspicious_user_email_forwarding_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Office_365_Detections|Office 365 Detections]] - -* [[Documentation:ESSOC:stories:UseCase#Data_Exfiltration|Data Exfiltration]] - - -====How To Implement==== -You must install splunk Microsoft Office 365 add-on. This search works with o365:management:activity - -====Required field==== - -* _time - -* Operation - -* Parameters - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1114.003 -| Email Forwarding Rule -| Collection -|- -| T1114 -| Email Collection -| Collection -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -unknown - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1114.003/o365_email_forwarding_rule/o365_email_forwarding_rule.json - - -''version'': 1 -
-
- ----- - -===Aws detect attach to role policy=== -This search provides detection of an user attaching itself to a different role trust policy. This can be used for lateral movement and escalation of privileges. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/ T1078] -* '''Last Updated''': 2020-07-27 - -
-
- -====Search==== -`aws_cloudwatchlogs_eks` attach policy -| spath requestParameters.policyArn -| table sourceIPAddress user_access_key userIdentity.arn userIdentity.sessionContext.sessionIssuer.arn eventName errorCode errorMessage status action requestParameters.policyArn userIdentity.sessionContext.attributes.mfaAuthenticated userIdentity.sessionContext.attributes.creationDate -| `aws_detect_attach_to_role_policy_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#AWS_Cross_Account_Activity|AWS Cross Account Activity]] - - -====How To Implement==== -You must install splunk AWS add-on and Splunk App for AWS. This search works with cloudwatch logs - -====Required field==== - -* _time - -* requestParameters.policyArn - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1078 -| Valid Accounts -| Defense Evasion, Persistence, Privilege Escalation, Initial Access -|} - - -====Kill Chain Phase==== - -* Lateral Movement - - -====Known False Positives==== -Attach to policy can create a lot of noise. This search can be adjusted to provide specific values to identify cases of abuse (i.e status=failure). The search can provide context for common users attaching themselves to higher privilege policies or even newly created policies. - -====Reference==== - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Aws detect permanent key creation=== -This search provides detection of accounts creating permanent keys. Permanent keys are not created by default and they are only needed for programmatic calls. Creation of Permanent key is an important event to monitor. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/ T1078] -* '''Last Updated''': 2020-07-27 - -
-
- -====Search==== -`aws_cloudwatchlogs_eks` CreateAccessKey -| spath eventName -| search eventName=CreateAccessKey "userIdentity.type"=IAMUser -| table sourceIPAddress userName userIdentity.type userAgent action status responseElements.accessKey.createDate responseElements.accessKey.status responseElements.accessKey.accessKeyId -|`aws_detect_permanent_key_creation_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#AWS_Cross_Account_Activity|AWS Cross Account Activity]] - - -====How To Implement==== -You must install splunk AWS add on and Splunk App for AWS. This search works with cloudwatch logs - -====Required field==== - -* _time - -* eventName - -* userIdentity.type - -* sourceIPAddress - -* userName userIdentity.type - -* userAgent - -* action - -* status - -* responseElements.accessKey.createDate - -* esponseElements.accessKey.status - -* responseElements.accessKey.accessKeyId - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1078 -| Valid Accounts -| Defense Evasion, Persistence, Privilege Escalation, Initial Access -|} - - -====Kill Chain Phase==== - -* Lateral Movement - - -====Known False Positives==== -Not all permanent key creations are malicious. If there is a policy of rotating keys this search can be adjusted to provide better context. - -====Reference==== - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Aws detect role creation=== -This search provides detection of role creation by IAM users. Role creation is an event by itself if user is creating a new role with trust policies different than the available in AWS and it can be used for lateral movement and escalation of privileges. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/ T1078] -* '''Last Updated''': 2020-07-27 - -
-
- -====Search==== -`aws_cloudwatchlogs_eks` event_name=CreateRole action=created userIdentity.type=AssumedRole requestParameters.description=Allows* -| table sourceIPAddress userIdentity.principalId userIdentity.arn action event_name awsRegion http_user_agent mfa_auth msg requestParameters.roleName requestParameters.description responseElements.role.arn responseElements.role.createDate -| `aws_detect_role_creation_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#AWS_Cross_Account_Activity|AWS Cross Account Activity]] - - -====How To Implement==== -You must install splunk AWS add-on and Splunk App for AWS. This search works with cloudwatch logs - -====Required field==== - -* _time - -* event_name - -* action - -* userIdentity.type - -* requestParameters.description - -* sourceIPAddress - -* userIdentity.principalId - -* userIdentity.arn - -* action - -* event_name - -* awsRegion - -* http_user_agent - -* mfa_auth - -* msg - -* requestParameters.roleName - -* requestParameters.description - -* responseElements.role.arn - -* responseElements.role.createDate - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1078 -| Valid Accounts -| Defense Evasion, Persistence, Privilege Escalation, Initial Access -|} - - -====Kill Chain Phase==== - -* Lateral Movement - - -====Known False Positives==== -CreateRole is not very common in common users. This search can be adjusted to provide specific values to identify cases of abuse. In general AWS provides plenty of trust policies that fit most use cases. - -====Reference==== - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Aws detect sts assume role abuse=== -This search provides detection of suspicious use of sts:AssumeRole. These tokens can be created on the go and used by attackers to move laterally and escalate privileges. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/ T1078] -* '''Last Updated''': 2020-07-27 - -
-
- -====Search==== -`cloudtrail` user_type=AssumedRole userIdentity.sessionContext.sessionIssuer.type=Role -| table sourceIPAddress userIdentity.arn user_agent user_access_key status action requestParameters.roleName responseElements.role.roleName responseElements.role.createDate -| `aws_detect_sts_assume_role_abuse_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#AWS_Cross_Account_Activity|AWS Cross Account Activity]] - - -====How To Implement==== -You must install splunk AWS add on and Splunk App for AWS. This search works with AWS CloudTrail logs - -====Required field==== - -* _time - -* user_type - -* userIdentity.sessionContext.sessionIssuer.type - -* sourceIPAddress - -* userIdentity.arn - -* user_agent - -* user_access_key - -* status - -* action - -* requestParameters.roleName - -* esponseElements.role.roleName - -* esponseElements.role.createDate - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1078 -| Valid Accounts -| Defense Evasion, Persistence, Privilege Escalation, Initial Access -|} - - -====Kill Chain Phase==== - -* Lateral Movement - - -====Known False Positives==== -Sts:AssumeRole can be very noisy as it is a standard mechanism to provide cross account and cross resources access. This search can be adjusted to provide specific values to identify cases of abuse. - -====Reference==== - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Aws detect sts get session token abuse=== -This search provides detection of suspicious use of sts:GetSessionToken. These tokens can be created on the go and used by attackers to move laterally and escalate privileges. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1550/ T1550] -* '''Last Updated''': 2020-07-27 - -
-
- -====Search==== -`aws_cloudwatchlogs_eks` ASIA userIdentity.type=IAMUser -| spath eventName -| search eventName=GetSessionToken -| table sourceIPAddress eventTime userIdentity.arn userName userAgent user_type status region -| `aws_detect_sts_get_session_token_abuse_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#AWS_Cross_Account_Activity|AWS Cross Account Activity]] - - -====How To Implement==== -You must install splunk AWS add-on and Splunk App for AWS. This search works with cloudwatch logs - -====Required field==== - -* _time - -* userIdentity.type - -* eventName - -* sourceIPAddress - -* eventTime - -* userIdentity.arn - -* userName - -* userAgent - -* user_type - -* status - -* region - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1550 -| Use Alternate Authentication Material -| Defense Evasion, Lateral Movement -|} - - -====Kill Chain Phase==== - -* Lateral Movement - - -====Known False Positives==== -Sts:GetSessionToken can be very noisy as in certain environments numerous calls of this type can be executed. This search can be adjusted to provide specific values to identify cases of abuse. In specific environments the use of field requestParameters.serialNumber will need to be used. - -====Reference==== - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - - - -==Endpoint== - - -===7zip commandline to smb share path=== -This search is to detect a suspicious 7z process with commandline pointing to SMB network share. This technique was seen in CONTI LEAK tools where it use 7z to archive a sensitive files and place it in network share tmp folder. This search is a good hunting query that may give analyst a hint why specific user try to archive a file pointing to SMB user which is un usual. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1560/001/ T1560.001], [https://attack.mitre.org/techniques/T1560/ T1560] -* '''Last Updated''': 2021-08-17 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name ="7z.exe" OR Processes.process_name = "7za.exe" OR Processes.original_file_name = "7z.exe" OR Processes.original_file_name = "7za.exe") AND (Processes.process="*\\C$\\*" OR Processes.process="*\\Admin$\\*" OR Processes.process="*\\IPC$\\*") by Processes.original_file_name Processes.parent_process_name Processes.parent_process Processes.process_name Processes.process Processes.parent_process_id Processes.process_id Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `7zip_commandline_to_smb_share_path_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed 7z.exe may be used. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process - -* Processes.parent_process_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1560.001 -| Archive via Utility -| Collection -|- -| T1560 -| Archive Collected Data -| Collection -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://threadreaderapp.com/thread/1423361119926816776.html - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/conti/conti_leak/windows-sysmon_7z.log - - -''version'': 1 -
-
- ----- - -===Access lsass memory for dump creation=== -Detect memory dumping of the LSASS process. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/001/ T1003.001], [https://attack.mitre.org/techniques/T1003/ T1003] -* '''Last Updated''': 2019-12-06 - -
-
- -====Search==== -`sysmon` EventCode=10 TargetImage=*lsass.exe CallTrace=*dbgcore.dll* OR CallTrace=*dbghelp.dll* -| stats count min(_time) as firstTime max(_time) as lastTime by Computer, TargetImage, TargetProcessId, SourceImage, SourceProcessId -| rename Computer as dest -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `access_lsass_memory_for_dump_creation_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Credential_Dumping|Credential Dumping]] - - -====How To Implement==== -This search requires Sysmon Logs and a Sysmon configuration, which includes EventCode 10 for lsass.exe. This search uses an input macro named `sysmon`. We strongly recommend that you specify your environment-specific configurations (index, source, sourcetype, etc.) for Windows Sysmon logs. Replace the macro definition with configurations for your Splunk environment. The search also uses a post-filter macro designed to filter out known false positives. - -====Required field==== - -* _time - -* EventCode - -* TargetImage - -* CallTrace - -* Computer - -* TargetProcessId - -* SourceImage - -* SourceProcessId - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1003.001 -| LSASS Memory -| Credential Access -|- -| T1003 -| OS Credential Dumping -| Credential Access -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Administrators can create memory dumps for debugging purposes, but memory dumps of the LSASS process would be unusual. - -====Reference==== - - -* https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.001/atomic_red_team/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Account discovery with net app=== -this search is to detect a potential account discovery series of command used by several malware or attack to recon the target machine. This technique is also seen in some note worthy malware like trickbot where it runs a cmd process, or even drop its module that will execute the said series of net command. This series of command are good correlation search and indicator of attacker recon if seen in the machines within a none technical user or department (HR, finance, ceo and etc) network. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/002/ T1087.002], [https://attack.mitre.org/techniques/T1087/ T1087] -* '''Last Updated''': 2021-09-16 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` values(Processes.process) as process values(Processes.parent_process) as parent_process values(Processes.process_id) as process_id count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_net` AND (Processes.process="*user*" OR Processes.process="*config*" OR Processes.process="*view /all*") by Processes.process_name Processes.dest Processes.user Processes.parent_process_name -| where count >=5 -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `account_discovery_with_net_app_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Trickbot|Trickbot]] - -* [[Documentation:ESSOC:stories:UseCase#IcedID|IcedID]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1087.002 -| Domain Account -| Discovery -|- -| T1087 -| Account Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -admin or power user may used this series of command. - -====Reference==== - - -* https://labs.vipre.com/trickbot-and-its-modules/ - -* https://blog.whitehat.eu/2019/05/incident-trickbot-ryuk-2.html - -* https://app.any.run/tasks/48414a33-3d66-4a46-afe5-c2003bb55ccf/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/trickbot/infection/windows-sysmon.log - - -''version'': 3 -
-
- ----- - -===Active setup registry autostart=== -This analytic is to detect a suspicious modification of the active setup registry for persistence and privilege escalation. This technique was seen in several malware (poisonIvy), adware and APT to gain persistence to the compromised machine upon boot up. This TTP is a good indicator to further check the process id that do the modification since modification of this registry is not commonly done. check the legitimacy of the file and process involve in this rules to check if it is a valid setup installer that creating or modifying this registry. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1547/014/ T1547.014], [https://attack.mitre.org/techniques/T1547/ T1547] -* '''Last Updated''': 2021-09-28 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_value_name = "StubPath" Registry.registry_key_name = "*\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components*" by Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `drop_dm_object_name(Registry)` -| `active_setup_registry_autostart_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Persistence_Techniques|Windows Persistence Techniques]] - -* [[Documentation:ESSOC:stories:UseCase#Windows_Privilege_Escalation|Windows Privilege Escalation]] - - -====How To Implement==== -To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. - -====Required field==== - -* _time - -* Registry.dest - -* Registry.user - -* Registry.registry_path - -* Registry.registry_key_name - -* Registry.registry_value_name - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1547.014 -| Active Setup -| Persistence, Privilege Escalation -|- -| T1547 -| Boot or Logon Autostart Execution -| Persistence, Privilege Escalation -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Active setup installer may add or modify this registry. - -====Reference==== - - -* https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Backdoor%3aWin32%2fPoisonivy.E - -* https://attack.mitre.org/techniques/T1547/014/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/t1547.014/active_setup_stubpath/sysmon.log - - -''version'': 1 -
-
- ----- - -===Add defaultuser and password in registry=== -this search is to detect a suspicious registry modification to implement auto admin logon to a host. This technique was seen in BlackMatter ransomware to automatically logon to the compromise host after triggering a safemode boot to continue encrypting the whole network. This behavior is not a common practice and really a suspicious TTP or alert need to be consider if found within then network premise. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1552/002/ T1552.002], [https://attack.mitre.org/techniques/T1552/ T1552] -* '''Last Updated''': 2021-09-06 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon*" AND Registry.registry_key_name= DefaultPassword OR Registry.registry_key_name= DefaultUserName by Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.dest -| `drop_dm_object_name(Registry)` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -| `add_defaultuser_and_password_in_registry_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#BlackMatter_Ransomware|BlackMatter Ransomware]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. - -====Required field==== - -* _time - -* Registry.registry_path - -* Registry.registry_key_name - -* Registry.registry_value_name - -* Registry.dest - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1552.002 -| Credentials in Registry -| Credential Access -|- -| T1552 -| Unsecured Credentials -| Credential Access -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://news.sophos.com/en-us/2021/08/09/blackmatter-ransomware-emerges-from-the-shadow-of-darkside/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1552.002/autoadminlogon/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Adsisearcher account discovery=== -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the `[Adsisearcher]` type accelerator being used to query Active Directory for domain groups. Red Teams and adversaries may leverage `[Adsisearcher]` to enumerate domain users for situational awareness and Active Directory Discovery. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/002/ T1087.002], [https://attack.mitre.org/techniques/T1087/ T1087] -* '''Last Updated''': 2021-08-24 - -
-
- -====Search==== -`powershell` EventCode=4104 Message = "*[adsisearcher]*" Message = "*objectcategory=user*" Message = "*.findAll()*" -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `adsisearcher_account_discovery_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -The following Hunting analytic requires PowerShell operational logs to be imported. Modify the powershell macro as needed to match the sourcetype or add index. This analytic is specific to 4104, or PowerShell Script Block Logging. - -====Required field==== - -* _time - -* EventCode - -* Message - -* ComputerName - -* User - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1087.002 -| Domain Account -| Discovery -|- -| T1087 -| Account Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use this command for troubleshooting. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1087/002/ - -* https://www.blackhillsinfosec.com/red-blue-purple/ - -* https://devblogs.microsoft.com/scripting/use-the-powershell-adsisearcher-type-accelerator-to-search-active-directory/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/AD_discovery/windows-powershell.log - - -''version'': 1 -
-
- ----- - -===Allow file and printing sharing in firewall=== -This search is to detect a suspicious modification of firewall to allow file and printer sharing. This technique was seen in ransomware to be able to discover more machine connected to the compromised host to encrypt more files - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/007/ T1562.007], [https://attack.mitre.org/techniques/T1562/ T1562] -* '''Last Updated''': 2021-06-23 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_netsh` Processes.process= "*firewall*" Processes.process= "*group=\"File and Printer Sharing\"*" Processes.process="*enable=Yes*" by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.parent_process_name Processes.original_file_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `allow_file_and_printing_sharing_in_firewall_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1562.007 -| Disable or Modify Cloud Firewall -| Defense Evasion -|- -| T1562 -| Impair Defenses -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -network admin may modify this firewall feature that may cause this rule to be triggered. - -====Reference==== - - -* https://kb.fortinet.com/kb/documentLink.do?externalID=FD52469 - -* https://app.any.run/tasks/c0f98850-af65-4352-9746-fbebadee4f05/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/data2/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Allow inbound traffic by firewall rule registry=== -This analytic detects a potential suspicious modification of firewall rule registry allowing inbound traffic in specific port with public profile. This technique was identified when an adversary wants to grant remote access to a machine by allowing the traffic in a firewall rule. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1021/001/ T1021.001], [https://attack.mitre.org/techniques/T1021/ T1021] -* '''Last Updated''': 2021-05-26 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*\\System\\CurrentControlSet\\Services\\SharedAccess\\Parameters\\FirewallPolicy\\FirewallRules\\*" Registry.registry_value_name = "* -|Action=Allow -|*" Registry.registry_value_name = "* -|Dir=In -|*" Registry.registry_value_name = "* -|Profile=Public -|*" Registry.registry_value_name = "* -|LPort=*" by Registry.registry_path Registry.registry_key_name Registry.user Registry.registry_value_name Registry.dest -| `drop_dm_object_name(Registry)` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -| `allow_inbound_traffic_by_firewall_rule_registry_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Prohibited_Traffic_Allowed_or_Protocol_Mismatch|Prohibited Traffic Allowed or Protocol Mismatch]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. - -====Required field==== - -* _time - -* Registry.registry_path - -* Registry.registry_value_name - -* Registry.registry_key_name - -* Registry.dest - -* Registry.user - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1021.001 -| Remote Desktop Protocol -| Lateral Movement -|- -| T1021 -| Remote Services -| Lateral Movement -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -network admin may add/remove/modify public inbound firewall rule that may cause this rule to be triggered. - -====Reference==== - - -* https://docs.microsoft.com/en-us/powershell/module/netsecurity/new-netfirewallrule?view=windowsserver2019-ps - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/casper/datasets1/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Allow inbound traffic in firewall rule=== -The following analytic identifies suspicious PowerShell command to allow inbound traffic inbound to a specific local port within the public profile. This technique was seen in some attacker want to have a remote access to a machine by allowing the traffic in firewall rule. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1021/001/ T1021.001], [https://attack.mitre.org/techniques/T1021/ T1021] -* '''Last Updated''': 2021-05-19 - -
-
- -====Search==== -`powershell` EventCode=4104 Message = "*firewall*" Message = "*Inbound*" Message = "*Allow*" Message = "*-LocalPort*" -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `allow_inbound_traffic_in_firewall_rule_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Prohibited_Traffic_Allowed_or_Protocol_Mismatch|Prohibited Traffic Allowed or Protocol Mismatch]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the powershell logs from your endpoints. make sure you enable needed registry to monitor this event. - -====Required field==== - -* _time - -* EventCode - -* Message - -* ComputerName - -* User - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1021.001 -| Remote Desktop Protocol -| Lateral Movement -|- -| T1021 -| Remote Services -| Lateral Movement -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -administrator may allow inbound traffic in certain network or machine. - -====Reference==== - - -* https://docs.microsoft.com/en-us/powershell/module/netsecurity/new-netfirewallrule?view=windowsserver2019-ps - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/casper/datasets1/windows-powershell.log - - -''version'': 1 -
-
- ----- - -===Allow network discovery in firewall=== -This search is to detect a suspicious modification to the firewall to allow network discovery on a machine. This technique was seen in couple of ransomware (revil, reddot) to discover other machine connected to the compromised host to encrypt more files. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/007/ T1562.007], [https://attack.mitre.org/techniques/T1562/ T1562] -* '''Last Updated''': 2021-06-23 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_netsh` Processes.process= "*firewall*" Processes.process= "*group=\"Network Discovery\"*" Processes.process="*enable*" Processes.process="*Yes*" by Processes.dest Processes.user Processes.parent_process Processes.original_file_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `allow_network_discovery_in_firewall_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - -* [[Documentation:ESSOC:stories:UseCase#Revil_Ransomware|Revil Ransomware]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1562.007 -| Disable or Modify Cloud Firewall -| Defense Evasion -|- -| T1562 -| Impair Defenses -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -network admin may modify this firewall feature that may cause this rule to be triggered. - -====Reference==== - - -* https://kb.fortinet.com/kb/documentLink.do?externalID=FD52469 - -* https://app.any.run/tasks/c0f98850-af65-4352-9746-fbebadee4f05/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/data2/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Allow operation with consent admin=== -This analytic identifies a potential privilege escalation attempt to perform malicious task. This registry modification is designed to allow the `Consent Admin` to perform an operation that requires elevation without consent or credentials. We also found this in some attacker to gain privilege escalation to the compromise machine. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1548/ T1548] -* '''Last Updated''': 2021-06-10 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path= "*\\Microsoft\\Windows\\CurrentVersion\\Policies\\System*" Registry.registry_key_name = ConsentPromptBehaviorAdmin Registry.registry_value_name = "DWORD (0x00000000)" by Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.dest -| `drop_dm_object_name(Registry)` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -| `allow_operation_with_consent_admin_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - - -====How To Implement==== -To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. - -====Required field==== - -* _time - -* Registry.registry_path - -* Registry.registry_key_name - -* Registry.registry_value_name - -* Registry.dest - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1548 -| Abuse Elevation Control Mechanism -| Privilege Escalation, Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://docs.microsoft.com/en-us/openspecs/windows_protocols/ms-gpsb/341747f5-6b5d-4d30-85fc-fa1cc04038d4 - -* https://www.trendmicro.com/vinfo/no/threat-encyclopedia/malware/Ransom.Win32.MRDEC.MRA/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/data1/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Anomalous usage of 7zip=== -The following detection identifies a 7z.exe spawned from `Rundll32.exe` or `Dllhost.exe`. It is assumed that the adversary has brought in `7z.exe` and `7z.dll`. It has been observed where an adversary will rename `7z.exe`. Additional coverage may be required to identify the behavior of renamed instances of `7z.exe`. During triage, identify the source of injection into `Rundll32.exe` or `Dllhost.exe`. Capture any files written to disk and analyze as needed. Review parallel processes for additional behaviors. Typically, archiving files will result in exfiltration. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1560/001/ T1560.001], [https://attack.mitre.org/techniques/T1560/ T1560] -* '''Last Updated''': 2021-04-22 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name IN ("rundll32.exe", "dllhost.exe") Processes.process_name=*7z* by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `anomalous_usage_of_7zip_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Cobalt_Strike|Cobalt Strike]] - -* [[Documentation:ESSOC:stories:UseCase#NOBELIUM_Group|NOBELIUM Group]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* _time - -* Processes.process_name - -* Processes.process - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.process_name - -* Processes.parent_process - -* Processes.process_id - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1560.001 -| Archive via Utility -| Collection -|- -| T1560 -| Archive Collected Data -| Collection -|} - - -====Kill Chain Phase==== - -* Actions on Objective - - -====Known False Positives==== -False positives should be limited as this behavior is not normal for `rundll32.exe` or `dllhost.exe` to spawn and run 7zip. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1560/001/ - -* https://www.microsoft.com/security/blog/2021/01/20/deep-dive-into-the-solorigate-second-stage-activation-from-sunburst-to-teardrop-and-raindrop/ - -* https://thedfirreport.com/2021/01/31/bazar-no-ryuk/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1560.001/archive_utility/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Any powershell downloadfile=== -The following analytic identifies the use of PowerShell downloading a file using `DownloadFile` method. This particular method is utilized in many different PowerShell frameworks to download files and output to disk. Identify the source (IP/domain) and destination file and triage appropriately. If AMSI logging or PowerShell transaction logs are available, review for further details of the implant. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/ T1059], [https://attack.mitre.org/techniques/T1059/001/ T1059.001] -* '''Last Updated''': 2021-03-01 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_powershell` Processes.process=*DownloadFile* by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `any_powershell_downloadfile_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Malicious_PowerShell|Malicious PowerShell]] - -* [[Documentation:ESSOC:stories:UseCase#Ingress_Tool_Transfer|Ingress Tool Transfer]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1059 -| Command and Scripting Interpreter -| Execution -|- -| T1059.001 -| PowerShell -| Execution -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -False positives may be present and filtering will need to occur by parent process or command line argument. It may be required to modify this query to an EDR product for more granular coverage. - -====Reference==== - - -* https://docs.microsoft.com/en-us/dotnet/api/system.net.webclient.downloadfile?view=net-5.0 - -* https://blog.malwarebytes.com/malwarebytes-news/2021/02/lazyscripter-from-empire-to-double-rat/ - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1059.001/T1059.001.md - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/atomic_red_team/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Any powershell downloadstring=== -The following analytic identifies the use of PowerShell downloading a file using `DownloadString` method. This particular method is utilized in many different PowerShell frameworks to download files and output to disk. Identify the source (IP/domain) and destination file and triage appropriately. If AMSI logging or PowerShell transaction logs are available, review for further details of the implant. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/ T1059], [https://attack.mitre.org/techniques/T1059/001/ T1059.001] -* '''Last Updated''': 2021-03-01 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_powershell` Processes.process=*.DownloadString* by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `any_powershell_downloadstring_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Malicious_PowerShell|Malicious PowerShell]] - -* [[Documentation:ESSOC:stories:UseCase#HAFNIUM_Group|HAFNIUM Group]] - -* [[Documentation:ESSOC:stories:UseCase#Ingress_Tool_Transfer|Ingress Tool Transfer]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1059 -| Command and Scripting Interpreter -| Execution -|- -| T1059.001 -| PowerShell -| Execution -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -False positives may be present and filtering will need to occur by parent process or command line argument. It may be required to modify this query to an EDR product for more granular coverage. - -====Reference==== - - -* https://docs.microsoft.com/en-us/dotnet/api/system.net.webclient.downloadstring?view=net-5.0 - -* https://blog.malwarebytes.com/malwarebytes-news/2021/02/lazyscripter-from-empire-to-double-rat/ - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1059.001/T1059.001.md - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/atomic_red_team/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Applying stolen credentials via mimikatz modules=== -This detection indicates use of Mimikatz modules that facilitate Pass-the-Token attack, Golden or Silver kerberos ticket attack, and Skeleton key attack. - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1055/ T1055], [https://attack.mitre.org/techniques/T1068/ T1068], [https://attack.mitre.org/techniques/T1078/ T1078], [https://attack.mitre.org/techniques/T1098/ T1098], [https://attack.mitre.org/techniques/T1134/ T1134], [https://attack.mitre.org/techniques/T1543/ T1543], [https://attack.mitre.org/techniques/T1547/ T1547], [https://attack.mitre.org/techniques/T1548/ T1548], [https://attack.mitre.org/techniques/T1554/ T1554], [https://attack.mitre.org/techniques/T1556/ T1556], [https://attack.mitre.org/techniques/T1558/ T1558] -* '''Last Updated''': 2020-11-03 - -
-
- -====Search==== - -| from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)kerberos::ptt/)=true OR match_regex(cmd_line, /(?i)kerberos::golden/)=true OR match_regex(cmd_line, /(?i)kerberos::silver/)=true OR match_regex(cmd_line, /(?i)misc::skeleton/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Credential_Dumping|Credential Dumping]] - - -====How To Implement==== -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -====Required field==== - -* dest_device_id - -* dest_user_id - -* process - -* _time - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1055 -| Process Injection -| Defense Evasion, Privilege Escalation -|- -| T1068 -| Exploitation for Privilege Escalation -| Privilege Escalation -|- -| T1078 -| Valid Accounts -| Defense Evasion, Persistence, Privilege Escalation, Initial Access -|- -| T1098 -| Account Manipulation -| Persistence -|- -| T1134 -| Access Token Manipulation -| Defense Evasion, Privilege Escalation -|- -| T1543 -| Create or Modify System Process -| Persistence, Privilege Escalation -|- -| T1547 -| Boot or Logon Autostart Execution -| Persistence, Privilege Escalation -|- -| T1548 -| Abuse Elevation Control Mechanism -| Privilege Escalation, Defense Evasion -|- -| T1554 -| Compromise Client Software Binary -| Persistence -|- -| T1556 -| Modify Authentication Process -| Credential Access, Defense Evasion, Persistence -|- -| T1558 -| Steal or Forge Kerberos Tickets -| Credential Access -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -None identified. - -====Reference==== - - -* https://github.com/gentilkiwi/mimikatz - -* https://adsecurity.org/?p=1275 - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1555/applying_stolen_credentials/logAllMimikatzModules.log - - -''version'': 1 -
-
- ----- - -===Applying stolen credentials via powersploit modules=== -Stolen credentials are applied by methods such as user impersonation, credential injection, spoofing of authentication processes or getting hold of critical accounts. This detection indicates such activities carried out by PowerSploit exploit kit APIs. - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1055/ T1055], [https://attack.mitre.org/techniques/T1068/ T1068], [https://attack.mitre.org/techniques/T1078/ T1078], [https://attack.mitre.org/techniques/T1098/ T1098], [https://attack.mitre.org/techniques/T1134/ T1134], [https://attack.mitre.org/techniques/T1543/ T1543], [https://attack.mitre.org/techniques/T1547/ T1547], [https://attack.mitre.org/techniques/T1548/ T1548], [https://attack.mitre.org/techniques/T1554/ T1554], [https://attack.mitre.org/techniques/T1555/ T1555], [https://attack.mitre.org/techniques/T1558/ T1558] -* '''Last Updated''': 2020-11-03 - -
-
- -====Search==== - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)Invoke-CredentialInjection/)=true OR match_regex(cmd_line, /(?i)Invoke-TokenManipulation/)=true OR match_regex(cmd_line, /(?i)Invoke-UserImpersonation/)=true OR match_regex(cmd_line, /(?i)Get-System/)=true OR match_regex(cmd_line, /(?i)Invoke-RevertToSelf/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Credential_Dumping|Credential Dumping]] - - -====How To Implement==== -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -====Required field==== - -* dest_device_id - -* dest_user_id - -* process - -* _time - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1055 -| Process Injection -| Defense Evasion, Privilege Escalation -|- -| T1068 -| Exploitation for Privilege Escalation -| Privilege Escalation -|- -| T1078 -| Valid Accounts -| Defense Evasion, Persistence, Privilege Escalation, Initial Access -|- -| T1098 -| Account Manipulation -| Persistence -|- -| T1134 -| Access Token Manipulation -| Defense Evasion, Privilege Escalation -|- -| T1543 -| Create or Modify System Process -| Persistence, Privilege Escalation -|- -| T1547 -| Boot or Logon Autostart Execution -| Persistence, Privilege Escalation -|- -| T1548 -| Abuse Elevation Control Mechanism -| Privilege Escalation, Defense Evasion -|- -| T1554 -| Compromise Client Software Binary -| Persistence -|- -| T1555 -| Credentials from Password Stores -| Credential Access -|- -| T1558 -| Steal or Forge Kerberos Tickets -| Credential Access -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -None identified. - -====Reference==== - - -* https://github.com/PowerShellMafia/PowerSploit - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1555/applying_stolen_credentials/logAllPowerSploitModulesWithOldNames.log - - -''version'': 1 -
-
- ----- - -===Assessment of credential strength via dsinternals modules=== -This detection identifies use of DSInternals modules that verify password strength, i.e., identify week accounts that would be easily compromised. - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/ T1078], [https://attack.mitre.org/techniques/T1098/ T1098], [https://attack.mitre.org/techniques/T1087/ T1087], [https://attack.mitre.org/techniques/T1201/ T1201], [https://attack.mitre.org/techniques/T1552/ T1552], [https://attack.mitre.org/techniques/T1555/ T1555] -* '''Last Updated''': 2020-11-03 - -
-
- -====Search==== - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)Test-PasswordQuality/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Credential_Dumping|Credential Dumping]] - - -====How To Implement==== -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -====Required field==== - -* _time - -* process - -* dest_device_id - -* dest_user_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1078 -| Valid Accounts -| Defense Evasion, Persistence, Privilege Escalation, Initial Access -|- -| T1098 -| Account Manipulation -| Persistence -|- -| T1087 -| Account Discovery -| Discovery -|- -| T1201 -| Password Policy Discovery -| Discovery -|- -| T1552 -| Unsecured Credentials -| Credential Access -|- -| T1555 -| Credentials from Password Stores -| Credential Access -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -None identified. - -====Reference==== - - -* https://github.com/MichaelGrafnetter/DSInternals - - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Attacker tools on endpoint=== -This search looks for execution of commonly used attacker tools on an endpoint. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1036/005/ T1036.005], [https://attack.mitre.org/techniques/T1036/ T1036], [https://attack.mitre.org/techniques/T1003/ T1003], [https://attack.mitre.org/techniques/T1595/ T1595] -* '''Last Updated''': 2021-06-21 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Processes.process) as process values(Processes.parent_process) as parent_process from datamodel=Endpoint.Processes where Processes.dest!=unknown Processes.user!=unknown by Processes.dest Processes.user Processes.process_name Processes.process -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `drop_dm_object_name(Processes)` -| lookup attacker_tools attacker_tool_names AS process_name OUTPUT description -| search description=* -| `attacker_tools_on_endpoint_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Monitor_for_Unauthorized_Software|Monitor for Unauthorized Software]] - -* [[Documentation:ESSOC:stories:UseCase#XMRig|XMRig]] - -* [[Documentation:ESSOC:stories:UseCase#SamSam_Ransomware|SamSam Ransomware]] - -* [[Documentation:ESSOC:stories:UseCase#Unusual_Processes|Unusual Processes]] - - -====How To Implement==== -To successfully implement this search, you must be ingesting data that records process activity from your hosts to populate the endpoint data model in the processes node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is usually generated via logs that report process tracking in your Windows audit settings. - -====Required field==== - -* Processes.dest - -* Processes.user - -* Processes.process_name - -* Processes.parent_process - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1036.005 -| Match Legitimate Name or Location -| Defense Evasion -|- -| T1036 -| Masquerading -| Defense Evasion -|- -| T1003 -| OS Credential Dumping -| Credential Access -|- -| T1595 -| Active Scanning -| Reconnaissance -|} - - -====Kill Chain Phase==== - -* Installation - -* Command and Control - -* Actions on Objectives - - -====Known False Positives==== -Some administrator activity can be potentially triggered, please add those users to the filter macro. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1595/attacker_scan_tools/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Attempt to add certificate to untrusted store=== -Attempt To Add Certificate To Untrusted Store - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1553/004/ T1553.004], [https://attack.mitre.org/techniques/T1553/ T1553] -* '''Last Updated''': 2021-09-16 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime values(Processes.process) as process max(_time) as lastTime from datamodel=Endpoint.Processes where `process_certutil` (Processes.process=*-addstore*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name("Processes")` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -| `attempt_to_add_certificate_to_untrusted_store_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Disabling_Security_Tools|Disabling Security Tools]] - - -====How To Implement==== -You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.process_name - -* Processes.process - -* Processes.parent_process - -* Processes.process_id - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1553.004 -| Install Root Certificate -| Defense Evasion -|- -| T1553 -| Subvert Trust Controls -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Installation - -* Actions on Objectives - - -====Known False Positives==== -There may be legitimate reasons for administrators to add a certificate to the untrusted certificate store. In such cases, this will typically be done on a large number of systems. - -====Reference==== - - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1553.004/T1553.004.md - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1553.004/atomic_red_team/windows-sysmon.log - - -''version'': 7 -
-
- ----- - -===Attempt to disable services=== -This analytic will identify suspicious series of command-line to disable several services. This technique is seen where the adversary attempts to disable security app services or other malware services to complete the objective on the compromised system. - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1489/ T1489] -* '''Last Updated''': 2021-06-18 - -
-
- -====Search==== - -| from read_ssa_enriched_events() -| eval _datamodels=ucast(map_get(input_event, "_datamodels"), "collection<string>", []), body={} -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line IS NOT NULL AND like(cmd_line, "%disabled%") AND like(cmd_line, "%config%") AND process_name="sc.exe" -| eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#XMRig|XMRig]] - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed sc.exe may be used. - -====Required field==== - -* _time - -* dest_device_id - -* process_name - -* parent_process_name - -* process_path - -* dest_user_id - -* process - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1489 -| Service Stop -| Impact -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ - -* https://app.any.run/tasks/c0f98850-af65-4352-9746-fbebadee4f05/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/ssa_data1/sc_disable.log - - -''version'': 2 -
-
- ----- - -===Attempt to stop security service=== -This search looks for attempts to stop security-related services on the endpoint. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001], [https://attack.mitre.org/techniques/T1562/ T1562] -* '''Last Updated''': 2020-07-21 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_net` OR Processes.process_name = sc.exe Processes.process="* stop *" by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -|lookup security_services_lookup service as process OUTPUTNEW category, description -| search category=security -| `attempt_to_stop_security_service_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Disabling_Security_Tools|Disabling Security Tools]] - -* [[Documentation:ESSOC:stories:UseCase#Trickbot|Trickbot]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1562.001 -| Disable or Modify Tools -| Defense Evasion -|- -| T1562 -| Impair Defenses -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Installation - -* Actions on Objectives - - -====Known False Positives==== -None identified. Attempts to disable security-related services should be identified and understood. - -====Reference==== - - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1562.001/T1562.001.md#atomic-test-14---disable-arbitrary-security-windows-service - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_defend_service_stop/windows-sysmon.log - - -''version'': 4 -
-
- ----- - -===Attempt to delete services=== -This analytic identifies suspicious series of attempt to kill multiple services on a system using either `net.exe` or `sc.exe`. This technique is use by adversaries to terminate security services or other related services to continue there objective and evade detections. - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1489/ T1489] -* '''Last Updated''': 2021-06-18 - -
-
- -====Search==== - -| from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line IS NOT NULL AND like(cmd_line, "%delete%") AND process_name = "sc.exe" -| eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#XMRig|XMRig]] - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed sc.exe may be used. - -====Required field==== - -* _time - -* dest_device_id - -* process_name - -* parent_process_name - -* process_path - -* dest_user_id - -* process - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1489 -| Service Stop -| Impact -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/ssa_data1/sc_del.log - - -''version'': 2 -
-
- ----- - -===Attempted credential dump from registry via reg exe=== -Monitor for execution of reg.exe with parameters specifying an export of keys that contain hashed credentials that attackers may try to crack offline. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/002/ T1003.002], [https://attack.mitre.org/techniques/T1003/ T1003] -* '''Last Updated''': 2021-09-16 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_reg` OR `process_cmd` Processes.process=*save* (Processes.process=*HKEY_LOCAL_MACHINE\\Security* OR Processes.process=*HKEY_LOCAL_MACHINE\\SAM* OR Processes.process=*HKEY_LOCAL_MACHINE\\System* OR Processes.process=*HKLM\\Security* OR Processes.process=*HKLM\\System* OR Processes.process=*HKLM\\SAM*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `attempted_credential_dump_from_registry_via_reg_exe_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Credential_Dumping|Credential Dumping]] - -* [[Documentation:ESSOC:stories:UseCase#DarkSide_Ransomware|DarkSide Ransomware]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1003.002 -| Security Account Manager -| Credential Access -|- -| T1003 -| OS Credential Dumping -| Credential Access -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -None identified. - -====Reference==== - - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1003.002/T1003.002.md#atomic-test-1---registry-dump-of-sam-creds-and-secrets - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.002/atomic_red_team/windows-sysmon.log - - -''version'': 6 -
-
- ----- - -===Attempted credential dump from registry via reg exe=== -Monitor for execution of reg.exe with parameters specifying an export of keys that contain hashed credentials that attackers may try to crack offline. - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/ T1003] -* '''Last Updated''': 2020-6-04 - -
-
- -====Search==== - -| from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)) -| eval process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), dest_user_id=ucast(map_get(input_event, "dest_user_id"), "string", null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where process_name="cmd.exe" OR process_name="reg.exe" -| where cmd_line != null AND match_regex(cmd_line, /(?i)save\s+/)=true AND ( match_regex(cmd_line, /(?i)HKLM\\Security/)=true OR match_regex(cmd_line, /(?i)HKLM\\SAM/)=true OR match_regex(cmd_line, /(?i)HKLM\\System/)=true OR match_regex(cmd_line, /(?i)HKEY_LOCAL_MACHINE\\Security/)=true OR match_regex(cmd_line, /(?i)HKEY_LOCAL_MACHINE\\SAM/)=true OR match_regex(cmd_line, /(?i)HKEY_LOCAL_MACHINE\\System/)=true ) -| eval start_time = timestamp, end_time = timestamp, entities = mvappend(dest_device_id, dest_user_id), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name]) -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Credential_Dumping|Credential Dumping]] - - -====How To Implement==== -You must be ingesting windows endpoint data that tracks process activity, including parent-child relationships from your endpoints. - -====Required field==== - -* process_name - -* _time - -* dest_device_id - -* dest_user_id - -* process - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1003 -| OS Credential Dumping -| Credential Access -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -None identified. - -====Reference==== - - -* https://github.com/splunk/security_content/blob/55a17c65f9f56c2220000b62701765422b46125d/detections/attempted_credential_dump_from_registry_via_reg_exe.yml - - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Auto admin logon registry entry=== -this search is to detect a suspicious registry modification to implement auto admin logon to a host. This technique was seen in BlackMatter ransomware to automatically logon to the compromise host after triggering a safemode boot to continue encrypting the whole network. This behavior is not a common practice and really a suspicious TTP or alert need to be consider if found within then network premise. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1552/002/ T1552.002], [https://attack.mitre.org/techniques/T1552/ T1552] -* '''Last Updated''': 2021-09-06 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon*" AND Registry.registry_key_name=AutoAdminLogon AND Registry.registry_value_name=1 by Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.dest -| `drop_dm_object_name(Registry)` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -| `auto_admin_logon_registry_entry_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#BlackMatter_Ransomware|BlackMatter Ransomware]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. - -====Required field==== - -* _time - -* Registry.registry_path - -* Registry.registry_key_name - -* Registry.registry_value_name - -* Registry.dest - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1552.002 -| Credentials in Registry -| Credential Access -|- -| T1552 -| Unsecured Credentials -| Credential Access -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://news.sophos.com/en-us/2021/08/09/blackmatter-ransomware-emerges-from-the-shadow-of-darkside/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1552.002/autoadminlogon/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Bcdedit failure recovery modification=== -This search looks for flags passed to bcdedit.exe modifications to the built-in Windows error recovery boot configurations. This is typically used by ransomware to prevent recovery. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1490/ T1490] -* '''Last Updated''': 2020-12-21 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = bcdedit.exe Processes.process="*recoveryenabled*" (Processes.process="* no*") by Processes.process_name Processes.process Processes.parent_process_name Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `bcdedit_failure_recovery_modification_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Ryuk_Ransomware|Ryuk Ransomware]] - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - - -====How To Implement==== -You must be ingesting endpoint data that tracks process activity, including parent-child relationships from your endpoints to populate the Endpoint data model in the Processes node. Tune based on parent process names. - -====Required field==== - -* _time - -* Processes.process_name - -* Processes.process - -* Processes.parent_process_name - -* Processes.dest - -* Processes.user - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1490 -| Inhibit System Recovery -| Impact -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Administrators may modify the boot configuration. - -====Reference==== - - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1490/T1490.md#atomic-test-4---windows---disable-windows-recovery-console-repair - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1490/atomic_red_team/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Bits job persistence=== -The following query identifies Microsoft Background Intelligent Transfer Service utility `bitsadmin.exe` scheduling a BITS job to persist on an endpoint. The query identifies the parameters used to create, resume or add a file to a BITS job. Typically seen combined in a oneliner or ran in sequence. If identified, review the BITS job created and capture any files written to disk. It is possible for BITS to be used to upload files and this may require further network data analysis to identify. You can use `bitsadmin /list /verbose` to list out the jobs during investigation. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1197/ T1197] -* '''Last Updated''': 2021-09-16 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_bitsadmin` Processes.process IN (*create*, *addfile*, *setnotifyflags*, *setnotifycmdline*, *setminretrydelay*, *setcustomheaders*, *resume* ) by Processes.dest Processes.user Processes.original_file_name Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `bits_job_persistence_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#BITS_Jobs|BITS Jobs]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1197 -| BITS Jobs -| Defense Evasion, Persistence -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Limited false positives will be present. Typically, applications will use `BitsAdmin.exe`. Any filtering should be done based on command-line arguments (legitimate applications) or parent process. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1197/ - -* https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/bitsadmin - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1197/T1197.md#atomic-test-3---persist-download--execute - -* https://lolbas-project.github.io/lolbas/Binaries/Bitsadmin/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1197/atomic_red_team/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Bitsadmin download file=== -The following query identifies Microsoft Background Intelligent Transfer Service utility `bitsadmin.exe` using the `transfer` parameter to download a remote object. In addition, look for `download` or `upload` on the command-line, the switches are not required to perform a transfer. Capture any files downloaded. Review the reputation of the IP or domain used. Typically once executed, a follow on command will be used to execute the dropped file. Note that the network connection or file modification events related will not spawn or create from `bitsadmin.exe`, but the artifacts will appear in a parallel process of `svchost.exe` with a command-line similar to `svchost.exe -k netsvcs -s BITS`. It's important to review all parallel and child processes to capture any behaviors and artifacts. In some suspicious and malicious instances, BITS jobs will be created. You can use `bitsadmin /list /verbose` to list out the jobs during investigation. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1197/ T1197], [https://attack.mitre.org/techniques/T1105/ T1105] -* '''Last Updated''': 2021-09-16 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_bitsadmin` Processes.process=*transfer* by Processes.dest Processes.user Processes.parent_process Processes.original_file_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `bitsadmin_download_file_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Ingress_Tool_Transfer|Ingress Tool Transfer]] - -* [[Documentation:ESSOC:stories:UseCase#BITS_Jobs|BITS Jobs]] - -* [[Documentation:ESSOC:stories:UseCase#DarkSide_Ransomware|DarkSide Ransomware]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1197 -| BITS Jobs -| Defense Evasion, Persistence -|- -| T1105 -| Ingress Tool Transfer -| Command And Control -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Limited false positives, however it may be required to filter based on parent process name or network connection. - -====Reference==== - - -* https://github.com/redcanaryco/atomic-red-team/blob/8eb52117b748d378325f7719554a896e37bccec7/atomics/T1105/T1105.md#atomic-test-9---windows---bitsadmin-bits-download - -* https://github.com/redcanaryco/atomic-red-team/blob/bc705cb7aaa5f26f2d96585fac8e4c7052df0ff9/atomics/T1197/T1197.md - -* https://docs.microsoft.com/en-us/windows/win32/bits/bitsadmin-tool - -* https://thedfirreport.com/2021/03/29/sodinokibi-aka-revil-ransomware/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1197/atomic_red_team/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Batch file write to system32=== -The search looks for a batch file (.bat) written to the Windows system directory tree. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1204/ T1204], [https://attack.mitre.org/techniques/T1204/002/ T1204.002] -* '''Last Updated''': 2021-09-16 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name=* by _time span=1h Processes.process_id Processes.process_name Processes.dest -| `drop_dm_object_name(Processes)` -| join process_guid, _time [ -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_path IN ("*\\system32\\*", "*\\syswow64\\*") Filesystem.file_name="*.bat" by _time span=1h Filesystem.dest Filesystem.file_create_time Filesystem.file_name Filesystem.file_path -| `drop_dm_object_name(Filesystem)` -| fields _time dest file_create_time file_name file_path process_name process_path process] -| dedup file_create_time -| table dest file_create_time, file_name, file_path, process_name -| `batch_file_write_to_system32_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#SamSam_Ransomware|SamSam Ransomware]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Filesystem.dest - -* Filesystem.file_name - -* Filesystem.user - -* Filesystem.file_path - -* Processes.process_id - -* Processes.process_name - -* Processes.dest - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1204 -| User Execution -| Execution -|- -| T1204.002 -| Malicious File -| Execution -|} - - -====Kill Chain Phase==== - -* Delivery - - -====Known False Positives==== -It is possible for this search to generate a notable event for a batch file write to a path that includes the string "system32", but is not the actual Windows system directory. As such, you should confirm the path of the batch file identified by the search. In addition, a false positive may be generated by an administrator copying a legitimate batch file in this directory tree. You should confirm that the activity is legitimate and modify the search to add exclusions, as necessary. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1204.002/batch_file_in_system32/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Bcdedit command back to normal mode boot=== -This search is to detect a suspicious bcdedit commandline to configure the host from safe mode back to normal boot configuration. This technique was seen in blackMatter ransomware where it force the compromised host to boot in safe mode to continue its encryption and bring back to normal boot using bcdedit deletevalue command. This TTP can be a good alert for host that booted from safe mode forcefully since it need to modify the boot configuration to bring it back to normal. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1490/ T1490] -* '''Last Updated''': 2021-09-06 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = bcdedit.exe Processes.process="*/deletevalue*" Processes.process="*{current}*" Processes.process="*safeboot*" by Processes.process_name Processes.process Processes.parent_process_name Processes.dest Processes.user -|`drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `bcdedit_command_back_to_normal_mode_boot_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#BlackMatter_Ransomware|BlackMatter Ransomware]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed rundll32.exe may be used. - -====Required field==== - -* _time - -* Processes.process_name - -* Processes.process - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.dest - -* Processes.user - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1490 -| Inhibit System Recovery -| Impact -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://news.sophos.com/en-us/2021/08/09/blackmatter-ransomware-emerges-from-the-shadow-of-darkside/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1552.002/autoadminlogon/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Chcp command execution=== -This search is to detect execution of chcp.exe application. this utility is used to change the active code page of the console. This technique was seen in icedid malware to know the locale region/language/country of the compromise host. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/ T1059] -* '''Last Updated''': 2021-07-27 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=chcp.com Processes.parent_process_name = cmd.exe Processes.parent_process=*/c* by Processes.process_name Processes.process Processes.parent_process_name Processes.parent_process Processes.process_id Processes.parent_process_id Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `chcp_command_execution_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#IcedID|IcedID]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed chcp.com may be used. - -====Required field==== - -* _time - -* process_name - -* process - -* parent_process_name - -* parent_process - -* process_id - -* parent_process_id - -* dest - -* user - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1059 -| Command and Scripting Interpreter -| Execution -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -other tools or script may used this to change code page to UTF-* or others - -====Reference==== - - -* https://ss64.com/nt/chcp.html - -* https://twitter.com/tccontre18/status/1419941156633329665?s=20 - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/simulated_icedid/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Cmd echo pipe - escalation=== -This analytic identifies a common behavior by Cobalt Strike and other frameworks where the adversary will escalate privileges, either via `jump` (Cobalt Strike PTH) or `getsystem`, using named-pipe impersonation. A suspicious event will look like `cmd.exe /c echo 4sgryt3436 > \\.\Pipe\5erg53`. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/ T1059], [https://attack.mitre.org/techniques/T1059/003/ T1059.003], [https://attack.mitre.org/techniques/T1543/003/ T1543.003], [https://attack.mitre.org/techniques/T1543/ T1543] -* '''Last Updated''': 2021-05-20 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_cmd` OR Processes.process=*%comspec%* (Processes.process=*echo* AND Processes.process=*pipe*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `cmd_echo_pipe___escalation_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Cobalt_Strike|Cobalt Strike]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1059 -| Command and Scripting Interpreter -| Execution -|- -| T1059.003 -| Windows Command Shell -| Execution -|- -| T1543.003 -| Windows Service -| Persistence, Privilege Escalation -|- -| T1543 -| Create or Modify System Process -| Persistence, Privilege Escalation -|} - - -====Kill Chain Phase==== - -* Exploitation - -* Privilege Escalation - - -====Known False Positives==== -Unknown. It is possible filtering may be required to ensure fidelity. - -====Reference==== - - -* https://redcanary.com/threat-detection-report/threats/cobalt-strike/ - -* https://github.com/rapid7/meterpreter/blob/master/source/extensions/priv/server/elevate/namedpipe.c - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Cmlua or cmstplua uac bypass=== -This analytic detects a potential process using COM Object like CMLUA or CMSTPLUA to bypass UAC. This technique has been used by ransomware adversaries to gain administrative privileges to its running process. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/003/ T1218.003] -* '''Last Updated''': 2021-05-13 - -
-
- -====Search==== -`sysmon` EventCode=7 ImageLoaded IN ("*\\CMLUA.dll", "*\\CMSTPLUA.dll", "*\\CMLUAUTIL.dll") NOT(process_name IN("CMSTP.exe", "CMMGR32.exe")) NOT(Image IN("*\\windows\\*", "*\\program files*")) -| stats count min(_time) as firstTime max(_time) as lastTime by Image ImageLoaded process_name Computer EventCode Signed ProcessId -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `cmlua_or_cmstplua_uac_bypass_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#DarkSide_Ransomware|DarkSide Ransomware]] - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name and imageloaded executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -====Required field==== - -* _time - -* Image - -* ImageLoaded - -* process_name - -* Computer - -* EventCode - -* Signed - -* ProcessId - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1218 -| Signed Binary Proxy Execution -| Defense Evasion -|- -| T1218.003 -| CMSTP -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Legitimate windows application that are not on the list loading this dll. Filter as needed. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1218/003/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/darkside_cmstp_com/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Certutil download with urlcache and split arguments=== -Certutil.exe may download a file from a remote destination using `-urlcache`. This behavior does require a URL to be passed on the command-line. In addition, `-f` (force) and `-split` (Split embedded ASN.1 elements, and save to files) will be used. It is not entirely common for `certutil.exe` to contact public IP space. However, it is uncommon for `certutil.exe` to write files to world writeable paths.\ During triage, capture any files on disk and review. Review the reputation of the remote IP or domain in question. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1105/ T1105] -* '''Last Updated''': 2021-03-23 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_certutil` Processes.process=*urlcache* Processes.process=*split* by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.original_file_name Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `certutil_download_with_urlcache_and_split_arguments_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Ingress_Tool_Transfer|Ingress Tool Transfer]] - -* [[Documentation:ESSOC:stories:UseCase#DarkSide_Ransomware|DarkSide Ransomware]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1105 -| Ingress Tool Transfer -| Command And Control -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Limited false positives in most environments, however tune as needed based on parent-child relationship or network connection. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1105/ - -* https://www.avira.com/en/blog/certutil-abused-by-attackers-to-spread-threats - -* https://www.fireeye.com/blog/threat-research/2019/10/certutil-qualms-they-came-to-drop-fombs.html - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1105/atomic_red_team/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Certutil download with verifyctl and split arguments=== -Certutil.exe may download a file from a remote destination using `-VerifyCtl`. This behavior does require a URL to be passed on the command-line. In addition, `-f` (force) and `-split` (Split embedded ASN.1 elements, and save to files) will be used. It is not entirely common for `certutil.exe` to contact public IP space. \ During triage, capture any files on disk and review. Review the reputation of the remote IP or domain in question. Using `-VerifyCtl`, the file will either be written to the current working directory or `%APPDATA%\..\LocalLow\Microsoft\CryptnetUrlCache\Content\<hash>`. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1105/ T1105] -* '''Last Updated''': 2021-03-23 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_certutil` Processes.process=*verifyctl* Processes.process=*split* by Processes.dest Processes.user Processes.original_file_name Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `certutil_download_with_verifyctl_and_split_arguments_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Ingress_Tool_Transfer|Ingress Tool Transfer]] - -* [[Documentation:ESSOC:stories:UseCase#DarkSide_Ransomware|DarkSide Ransomware]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1105 -| Ingress Tool Transfer -| Command And Control -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Limited false positives in most environments, however tune as needed based on parent-child relationship or network connection. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1105/ - -* https://www.hexacorn.com/blog/2020/08/23/certutil-one-more-gui-lolbin/ - -* https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-R2-and-2012/cc732443(v=ws.11)#-verifyctl - -* https://www.avira.com/en/blog/certutil-abused-by-attackers-to-spread-threats - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1105/atomic_red_team/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Certutil with decode argument=== -CertUtil.exe may be used to `encode` and `decode` a file, including PE and script code. Encoding will convert a file to base64 with `-----BEGIN CERTIFICATE-----` and `-----END CERTIFICATE-----` tags. Malicious usage will include decoding a encoded file that was downloaded. Once decoded, it will be loaded by a parallel process. Note that there are two additional command switches that may be used - `encodehex` and `decodehex`. Similarly, the file will be encoded in HEX and later decoded for further execution. During triage, identify the source of the file being decoded. Review its contents or execution behavior for further analysis. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1140/ T1140] -* '''Last Updated''': 2021-03-23 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_certutil` Processes.process=*decode* by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `certutil_with_decode_argument_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Deobfuscate-Decode_Files_or_Information|Deobfuscate-Decode Files or Information]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1140 -| Deobfuscate/Decode Files or Information -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Typically seen used to `encode` files, but it is possible to see legitimate use of `decode`. Filter based on parent-child relationship, file paths, endpoint or user. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1140/ - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1140/T1140.md - -* https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/certutil - -* https://www.bleepingcomputer.com/news/security/certutilexe-could-allow-attackers-to-download-malware-while-bypassing-av/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1140/atomic_red_team/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Certutil exe certificate extraction=== -This search looks for arguments to certutil.exe indicating the manipulation or extraction of Certificate. This certificate can then be used to sign new authentication tokens specially inside Federated environments such as Windows ADFS. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': -* '''Last Updated''': 2021-01-26 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=certutil.exe Processes.process = "*-exportPFX*" by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `certutil_exe_certificate_extraction_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Persistence_Techniques|Windows Persistence Techniques]] - -* [[Documentation:ESSOC:stories:UseCase#Cloud_Federated_Credential_Abuse|Cloud Federated Credential Abuse]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - - -====Kill Chain Phase==== - -* Installation - - -====Known False Positives==== -Unless there are specific use cases, manipulating or exporting certificates using certutil is uncommon. Extraction of certificate has been observed during attacks such as Golden SAML and other campaigns targeting Federated services. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/certutil_exe_certificate_extraction/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Change default file association=== -This analytic is developed to detect suspicious registry modification to change the default file association of windows to malicious payload. This techninique was seen in some APT where it modify the default process to run file association, like .txt to notepad.exe. Instead notepad.exe it will point to a Script or other payload that will load malicious command to the compromised host. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1546/001/ T1546.001], [https://attack.mitre.org/techniques/T1546/ T1546] -* '''Last Updated''': 2021-09-27 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path ="*\\shell\\open\\command\\*" Registry.registry_path = "*HKCR\\*" by Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `drop_dm_object_name(Registry)` -| `change_default_file_association_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Persistence_Techniques|Windows Persistence Techniques]] - -* [[Documentation:ESSOC:stories:UseCase#Windows_Privilege_Escalation|Windows Privilege Escalation]] - - -====How To Implement==== -To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. - -====Required field==== - -* _time - -* Registry.dest - -* Registry.user - -* Registry.registry_path - -* Registry.registry_key_name - -* Registry.registry_value_name - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1546.001 -| Change Default File Association -| Privilege Escalation, Persistence -|- -| T1546 -| Event Triggered Execution -| Privilege Escalation, Persistence -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/privilege-escalation/untitled-3/accessibility-features - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.001/txtfile_reg/sysmon.log - - -''version'': 1 -
-
- ----- - -===Change to safe mode with network config=== -This search is to detect a suspicious bcdedit commandline to configure the host to boot in safe mode with network config. This technique was seen in blackMatter ransomware where it force the compromised host to boot in safe mode to continue its encryption and bring back to normal boot using bcdedit deletevalue command. This TTP can be a good alert for host that booted from safe mode forcefully since it need to modify the boot configuration to bring it back to normal. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1490/ T1490] -* '''Last Updated''': 2021-09-06 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = bcdedit.exe Processes.process="*/set*" Processes.process="*{current}*" Processes.process="*safeboot*" Processes.process="*network*" by Processes.process_name Processes.process Processes.parent_process_name Processes.dest Processes.user -|`drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `change_to_safe_mode_with_network_config_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#BlackMatter_Ransomware|BlackMatter Ransomware]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed rundll32.exe may be used. - -====Required field==== - -* _time - -* Processes.process_name - -* Processes.process - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.dest - -* Processes.user - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1490 -| Inhibit System Recovery -| Impact -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://news.sophos.com/en-us/2021/08/09/blackmatter-ransomware-emerges-from-the-shadow-of-darkside/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1552.002/autoadminlogon/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Check elevated cmd using whoami=== -This search is to detect a suspicious whoami execution to check if the cmd or shell instance process is with elevated privileges. This technique was seen in FIN7 js implant where it execute this as part of its data collection to the infected machine to check if the running shell cmd process is elevated or not. This TTP is really a good alert for known attacker that recon on the targetted host. This command is not so commonly executed by a normal user or even an admin to check if a process is elevated. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1033/ T1033] -* '''Last Updated''': 2021-09-15 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process = "*whoami*" Processes.process = "*/group*" Processes.process = "* find *" Processes.process = "*12288*" by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `check_elevated_cmd_using_whoami_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#FIN7|FIN7]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed rundll32.exe may be used. - -====Required field==== - -* _time - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.process_name - -* Processes.process_id - -* Processes.process - -* Processes.dest - -* Processes.user - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1033 -| System Owner/User Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/fin7/fin7_js_2/sysmon.log - - -''version'': 1 -
-
- ----- - -===Child processes of spoolsv exe=== -This search looks for child processes of spoolsv.exe. This activity is associated with a POC privilege-escalation exploit associated with CVE-2018-8440. Spoolsv.exe is the process associated with the Print Spooler service in Windows and typically runs as SYSTEM. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1068/ T1068] -* '''Last Updated''': 2020-03-16 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count values(Processes.process_name) as process_name values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=spoolsv.exe AND Processes.process_name!=regsvr32.exe by Processes.dest Processes.parent_process Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `child_processes_of_spoolsv_exe_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Privilege_Escalation|Windows Privilege Escalation]] - - -====How To Implement==== -You must be ingesting endpoint data that tracks process activity, including parent-child relationships from your endpoints to populate the Endpoint data model in the Processes node. The command-line arguments are mapped to the "process" field in the Endpoint data model. Update the `children_of_spoolsv_filter` macro to filter out legitimate child processes spawned by spoolsv.exe. - -====Required field==== - -* _time - -* Processes.process_name - -* Processes.process - -* Processes.parent_process_name - -* Processes.process_name - -* Processes.dest - -* Processes.parent_process - -* Processes.user - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1068 -| Exploitation for Privilege Escalation -| Privilege Escalation -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Some legitimate printer-related processes may show up as children of spoolsv.exe. You should confirm that any activity as legitimate and may be added as exclusions in the search. - -====Reference==== - - -====Test Dataset==== - - -''version'': 3 -
-
- ----- - -===Clear unallocated sector using cipher app=== -this search is to detect execution of `cipher.exe` to clear the unallocated sectors of a specific disk. This technique was seen in some ransomware to make it impossible to forensically recover deleted files. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1070/004/ T1070.004], [https://attack.mitre.org/techniques/T1070/ T1070] -* '''Last Updated''': 2021-06-10 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = "cipher.exe" Processes.process = "*/w:*" by Processes.parent_process_name Processes.parent_process Processes.process_name Processes.process Processes.dest Processes.user Processes.process_id Processes.process_guid -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `clear_unallocated_sector_using_cipher_app_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1070.004 -| File Deletion -| Defense Evasion -|- -| T1070 -| Indicator Removal on Host -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -administrator may execute this app to manage disk - -====Reference==== - - -* https://unit42.paloaltonetworks.com/vatet-pyxie-defray777/3/ - -* https://www.sophos.com/en-us/medialibrary/PDFs/technical-papers/sophoslabs-ransomware-behavior-report.pdf - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/data1/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Clop common exec parameter=== -The following analytics are designed to identifies some CLOP ransomware variant that using arguments to execute its main code or feature of its code. In this variant if the parameter is "runrun", CLOP ransomware will try to encrypt files in network shares and if it is "temp.dat", it will try to read from some stream pipe or file start encrypting files within the infected local machines. This technique can be also identified as an anti-sandbox technique to make its code non-responsive since it is waiting for some parameter to execute properly. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1204/ T1204] -* '''Last Updated''': 2021-03-17 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` values(Processes.process) as cmdline values(Processes.parent_process_name) as parent_process values(Processes.process_name) count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name != "*temp.dat*" Processes.process = "*runrun*" OR Processes.process = "*temp.dat*" by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `clop_common_exec_parameter_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Clop_Ransomware|Clop Ransomware]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1204 -| User Execution -| Execution -|} - - -====Kill Chain Phase==== - -* Obfuscation - - -====Known False Positives==== -Operators can execute third party tools using these parameters. - -====Reference==== - - -* https://www.fireeye.com/blog/threat-research/2020/10/fin11-email-campaigns-precursor-for-ransomware-data-theft.html - -* https://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_b/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Clop ransomware known service name=== -This detection is to identify the common service name created by the CLOP ransomware as part of its persistence and high privilege code execution in the infected machine. Ussually CLOP ransomware use StartServiceCtrlDispatcherW API in creating this service entry. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1543/ T1543] -* '''Last Updated''': 2021-03-17 - -
-
- -====Search==== -`wineventlog_system` EventCode=7045 Service_Name IN ("SecurityCenterIBM", "WinCheckDRVs") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Service_File_Name Service_Name Service_Start_Type Service_Type -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `clop_ransomware_known_service_name_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Clop_Ransomware|Clop Ransomware]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the Service name, Service File Name Service Start type, and Service Type from your endpoints. - -====Required field==== - -* EventCode - -* cmdline - -* _time - -* parent_process_name - -* process_name - -* OriginalFileName - -* process_path - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1543 -| Create or Modify System Process -| Persistence, Privilege Escalation -|} - - -====Kill Chain Phase==== - -* Privilege Escalation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://www.fireeye.com/blog/threat-research/2020/10/fin11-email-campaigns-precursor-for-ransomware-data-theft.html - -* https://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_a/windows-system.log - - -''version'': 1 -
-
- ----- - -===Cmdline tool not executed in cmd shell=== -This search is to detect a suspicious parent process execution of commandline tool not in shell commandline. This technique was seen in FIN7 JSSLoader .net compile payload where it run ipconfig.exe and systeminfo.exe using .net application. This event cause some good TTP since those tool are commonly run in commandline not by another application. This TTP is a good indicator for application gather host information either an attacker or an automated tool made by admin. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/ T1059], [https://attack.mitre.org/techniques/T1059/007/ T1059.007] -* '''Last Updated''': 2021-09-14 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name = "ipconfig.exe" OR Processes.process_name = "systeminfo.exe") AND NOT (Processes.parent_process_name = "cmd.exe" OR Processes.parent_process_name = "powershell*" OR Processes.parent_process_name = "explorer.exe") by Processes.parent_process_name Processes.parent_process Processes.process_name Processes.process_id Processes.process Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `cmdline_tool_not_executed_in_cmd_shell_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#FIN7|FIN7]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -====Required field==== - -* _time - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.process_name - -* Processes.process_id - -* Processes.process - -* Processes.dest - -* Processes.user - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1059 -| Command and Scripting Interpreter -| Execution -|- -| T1059.007 -| JavaScript -| Execution -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -network operator or admin may create this type of tool to gather host information - -====Reference==== - - -* https://www.fireeye.com/blog/threat-research/2018/08/fin7-pursuing-an-enigmatic-and-evasive-global-criminal-operation.html - -* https://attack.mitre.org/groups/G0046/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/fin7/jssloader/sysmon.log - - -''version'': 1 -
-
- ----- - -===Cobalt strike named pipes=== -The following analytic identifies the use of default or publicly known named pipes used with Cobalt Strike. A named pipe is a named, one-way or duplex pipe for communication between the pipe server and one or more pipe clients. Cobalt Strike uses named pipes in many ways and has default values used with the Artifact Kit and Malleable C2 Profiles. The following query assists with identifying these default named pipes. Each EDR product presents named pipes a little different. Consider taking the values and generating a query based on the product of choice. \ -Upon triage, review the process performing the named pipe. If it is explorer.exe, It is possible it was injected into by another process. Review recent parallel processes to identify suspicious patterns or behaviors. A parallel process may have a network connection, review and follow the connection back to identify any file modifications. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1055/ T1055] -* '''Last Updated''': 2021-02-22 - -
-
- -====Search==== -`sysmon` EventID=17 OR EventID=18 PipeName IN (\\msagent_*, \\wkssvc*, \\DserNamePipe*, \\srvsvc_*, \\mojo.*, \\postex_*, \\status_*, \\MSSE-*, \\spoolss_*, \\win_svc*, \\ntsvcs*, \\winsock*, \\UIA_PIPE*) -| stats count min(_time) as firstTime max(_time) as lastTime by Computer, process_name, process_id process_path, PipeName -| rename Computer as dest -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `cobalt_strike_named_pipes_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Cobalt_Strike|Cobalt Strike]] - -* [[Documentation:ESSOC:stories:UseCase#Trickbot|Trickbot]] - -* [[Documentation:ESSOC:stories:UseCase#DarkSide_Ransomware|DarkSide Ransomware]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -====Required field==== - -* _time - -* EventID - -* PipeName - -* Computer - -* process_name - -* process_path - -* process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1055 -| Process Injection -| Defense Evasion, Privilege Escalation -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -The idea of using named pipes with Cobalt Strike is to blend in. Therefore, some of the named pipes identified and added may cause false positives. Filter by process name or pipe name to reduce false positives. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1218/009/ - -* https://docs.microsoft.com/en-us/windows/win32/ipc/named-pipes - -* https://www.cobaltstrike.com/help-smb-beacon - -* https://blog.cobaltstrike.com/2021/02/09/learn-pipe-fitting-for-all-of-your-offense-projects/ - -* https://gist.github.com/MHaggis/6c600e524045a6d49c35291a21e10752 - -* https://www.mandiant.com/resources/shining-a-light-on-darkside-ransomware-operations - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Common ransomware extensions=== -The search looks for file modifications with extensions commonly used by Ransomware - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1485/ T1485] -* '''Last Updated''': 2020-11-09 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Filesystem.user) as user values(Filesystem.dest) as dest values(Filesystem.file_path) as file_path from datamodel=Endpoint.Filesystem by Filesystem.file_name -| `drop_dm_object_name(Filesystem)` -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| rex field=file_name "(?<file_extension>\.[^\.]+)$" -| `ransomware_extensions` -| `common_ransomware_extensions_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#SamSam_Ransomware|SamSam Ransomware]] - -* [[Documentation:ESSOC:stories:UseCase#Ryuk_Ransomware|Ryuk Ransomware]] - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - -* [[Documentation:ESSOC:stories:UseCase#Clop_Ransomware|Clop Ransomware]] - - -====How To Implement==== -You must be ingesting data that records the filesystem activity from your hosts to populate the Endpoint file-system data model node. If you are using Sysmon, you will need a Splunk Universal Forwarder on each endpoint from which you want to collect data.\ -This search produces fields (`query`,`query_length`,`count`) that are not yet supported by ES Incident Review and therefore cannot be viewed when a notable event is raised. These fields contribute additional context to the notable. To see the additional metadata, add the following fields, if not already present, to Incident Review - Event Attributes (Configure > Incident Management > Incident Review Settings > Add New Entry):\\n1. **Label:** Name, **Field:** Name\ -1. \ -1. **Label:** File Extension, **Field:** file_extension\ -Detailed documentation on how to create a new field within Incident Review may be found here: `https://docs.splunk.com/Documentation/ES/5.3.0/Admin/Customizenotables#Add_a_field_to_the_notable_event_details` - -====Required field==== - -* _time - -* Filesystem.user - -* Filesystem.dest - -* Filesystem.file_path - -* Filesystem.file_name - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1485 -| Data Destruction -| Impact -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -It is possible for a legitimate file with these extensions to be created. If this is a true ransomware attack, there will be a large number of files created with these extensions. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/ransomware_extensions/windows-sysmon.log - - -''version'': 4 -
-
- ----- - -===Common ransomware notes=== -The search looks for files created with names matching those typically used in ransomware notes that tell the victim how to get their data back. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1485/ T1485] -* '''Last Updated''': 2020-11-09 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Filesystem.user) as user values(Filesystem.dest) as dest values(Filesystem.file_path) as file_path from datamodel=Endpoint.Filesystem by Filesystem.file_name -| `drop_dm_object_name(Filesystem)` -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `ransomware_notes` -| `common_ransomware_notes_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#SamSam_Ransomware|SamSam Ransomware]] - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - -* [[Documentation:ESSOC:stories:UseCase#Ryuk_Ransomware|Ryuk Ransomware]] - -* [[Documentation:ESSOC:stories:UseCase#Clop_Ransomware|Clop Ransomware]] - - -====How To Implement==== -You must be ingesting data that records file-system activity from your hosts to populate the Endpoint Filesystem data-model node. This is typically populated via endpoint detection-and-response product, such as Carbon Black, or via other endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report file-system reads and writes. - -====Required field==== - -* _time - -* Filesystem.user - -* Filesystem.dest - -* Filesystem.file_path - -* Filesystem.file_name - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1485 -| Data Destruction -| Impact -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -It's possible that a legitimate file could be created with the same name used by ransomware note files. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/ransomware_notes/windows-sysmon.log - - -''version'': 4 -
-
- ----- - -===Conti common exec parameter=== -This search detects the suspicious commandline argument of revil ransomware to encrypt specific or all local drive and network shares of the compromised machine or host. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1204/ T1204] -* '''Last Updated''': 2021-06-02 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process = "*-m local*" OR Processes.process = "*-m net*" OR Processes.process = "*-m all*" OR Processes.process = "*-nomutex*" by Processes.process_name Processes.process Processes.parent_process_name Processes.parent_process Processes.dest Processes.user Processes.process_id Processes.process_guid -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `conti_common_exec_parameter_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1204 -| User Execution -| Execution -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -3rd party tool may have commandline parameter that can trigger this detection. - -====Reference==== - - -* https://malpedia.caad.fkie.fraunhofer.de/details/win.conti - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/conti/inf1/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Control loading from world writable directory=== -The following detection identifies control.exe loading either a .cpl or .inf from a writable directory. This is related to CVE-2021-40444. During triage, review parallel processes, parent and child, for further suspicious behaviors. In addition, capture file modifications and analyze. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/002/ T1218.002] -* '''Last Updated''': 2021-09-08 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name=control.exe OR Processes.original_file_name=CONTROL.EXE) AND Processes.process IN ("*\\appdata\\*", "*\\windows\\temp\\*", "*\\programdata\\*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.original_file_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `control_loading_from_world_writable_directory_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Microsoft_MSHTML_Remote_Code_Execution_CVE-2021-40444|Microsoft MSHTML Remote Code Execution CVE-2021-40444]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1218 -| Signed Binary Proxy Execution -| Defense Evasion -|- -| T1218.002 -| Control Panel -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Limited false positives will be present as control.exe does not natively load from writable paths as defined. One may add .cpl or .inf to the command-line if there is any false positives. Tune as needed. - -====Reference==== - - -* https://strontic.github.io/xcyclopedia/library/rundll32.exe-111474C61232202B5B588D2B512CBB25.html - -* https://app.any.run/tasks/36c14029-9df8-439c-bba0-45f2643b0c70/ - -* https://attack.mitre.org/techniques/T1218/011/ - -* https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40444 - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.002/T1218.002.yaml - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.002/atomic_red_team/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Create remote thread in shell application=== -This search is to detect suspicious process injection in command shell. This technique was seen in IcedID where it execute cmd.exe process to inject its shellcode as part of its execution as banking trojan. It is really uncommon to have a create remote thread execution in the following application. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1055/ T1055] -* '''Last Updated''': 2021-08-04 - -
-
- -====Search==== -`sysmon` EventCode=8 TargetImage IN ("*\\cmd.exe", "*\\powershell*") -| stats count min(_time) as firstTime max(_time) as lastTime by TargetImage TargetProcessId SourceProcessId EventCode StartAddress SourceImage Computer -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `create_remote_thread_in_shell_application_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#IcedID|IcedID]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -====Required field==== - -* _time - -* SourceImage - -* TargetImage - -* TargetProcessId - -* SourceProcessId - -* StartAddress - -* EventCode - -* Computer - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1055 -| Process Injection -| Defense Evasion, Privilege Escalation -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://thedfirreport.com/2021/07/19/icedid-and-cobalt-strike-vs-antivirus/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/simulated_icedid/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Create remote thread into lsass=== -Detect remote thread creation into LSASS consistent with credential dumping. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/001/ T1003.001], [https://attack.mitre.org/techniques/T1003/ T1003] -* '''Last Updated''': 2019-12-06 - -
-
- -====Search==== -`sysmon` EventID=8 TargetImage=*lsass.exe -| stats count min(_time) as firstTime max(_time) as lastTime by Computer, EventCode, TargetImage, TargetProcessId -| rename Computer as dest -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `create_remote_thread_into_lsass_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Credential_Dumping|Credential Dumping]] - - -====How To Implement==== -This search needs Sysmon Logs with a Sysmon configuration, which includes EventCode 8 with lsass.exe. This search uses an input macro named `sysmon`. We strongly recommend that you specify your environment-specific configurations (index, source, sourcetype, etc.) for Windows Sysmon logs. Replace the macro definition with configurations for your Splunk environment. The search also uses a post-filter macro designed to filter out known false positives. - -====Required field==== - -* _time - -* EventID - -* TargetImage - -* Computer - -* EventCode - -* TargetImage - -* TargetProcessId - -* dest - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1003.001 -| LSASS Memory -| Credential Access -|- -| T1003 -| OS Credential Dumping -| Credential Access -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Other tools can access LSASS for legitimate reasons and generate an event. In these cases, tweaking the search may help eliminate noise. - -====Reference==== - - -* https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.001/atomic_red_team/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Create service in suspicious file path=== -This detection is to identify a creation of "user mode service" where the service file path is located in non-common service folder in windows. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1569/ T1569], [https://attack.mitre.org/techniques/T1569/002/ T1569.002] -* '''Last Updated''': 2021-03-12 - -
-
- -====Search==== - `wineventlog_system` EventCode=7045 Service_File_Name = "*\.exe" NOT (Service_File_Name IN ("C:\\Windows\\*", "C:\\Program File*", "C:\\Programdata\\*", "%systemroot%\\*")) Service_Type = "user mode service" -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Service_File_Name Service_Name Service_Start_Type Service_Type -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `create_service_in_suspicious_file_path_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Clop_Ransomware|Clop Ransomware]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the Service name, Service File Name Service Start type, and Service Type from your endpoints. - -====Required field==== - -* EventCode - -* Service_File_Name - -* Service_Type - -* _time - -* Service_Name - -* Service_Start_Type - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1569 -| System Services -| Execution -|- -| T1569.002 -| Service Execution -| Execution -|} - - -====Kill Chain Phase==== - -* Privilege Escalation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://www.fireeye.com/blog/threat-research/2020/10/fin11-email-campaigns-precursor-for-ransomware-data-theft.html - -* https://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_a/windows-system.log - - -''version'': 1 -
-
- ----- - -===Create local admin accounts using net exe=== -This search looks for the creation of local administrator accounts using net.exe . - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1136/001/ T1136.001], [https://attack.mitre.org/techniques/T1136/ T1136] -* '''Last Updated''': 2021-09-08 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count values(Processes.user) as user values(Processes.parent_process) as parent_process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name=net.exe OR Processes.process_name=net1.exe) AND Processes.process=*/add* AND (Processes.process=*administrators* OR Processes.process=*administratoren* OR Processes.process=*administrateurs* OR Processes.process=*administrador* OR Processes.process=*amministratori* OR Processes.process=*administratorer*) by Processes.process Processes.process_name Processes.dest -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `create_local_admin_accounts_using_net_exe_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#DHS_Report_TA18-074A|DHS Report TA18-074A]] - - -====How To Implement==== -You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1136.001 -| Local Account -| Persistence -|- -| T1136 -| Create Account -| Persistence -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Administrators often leverage net.exe to create admin accounts. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.001/atomic_red_team/windows-security.log - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.001/atomic_red_team/windows-system.log - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.001/atomic_red_team/windows-sysmon.log - - -''version'': 6 -
-
- ----- - -===Create or delete windows shares using net exe=== -This search looks for the creation or deletion of hidden shares using net.exe. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1070/ T1070], [https://attack.mitre.org/techniques/T1070/005/ T1070.005] -* '''Last Updated''': 2020-09-16 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count values(Processes.user) as user values(Processes.parent_process) as parent_process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_net` by Processes.process Processes.process_name Processes.original_file_name Processes.dest -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| search process=*share* -| `create_or_delete_windows_shares_using_net_exe_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Hidden_Cobra_Malware|Hidden Cobra Malware]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1070 -| Indicator Removal on Host -| Defense Evasion -|- -| T1070.005 -| Network Share Connection Removal -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Administrators often leverage net.exe to create or delete network shares. You should verify that the activity was intentional and is legitimate. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1070/005 - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070.005/atomic_red_team/windows-sysmon.log - - -''version'': 6 -
-
- ----- - -===Creation of shadow copy=== -Monitor for signs that Vssadmin or Wmic has been used to create a shadow copy. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/003/ T1003.003], [https://attack.mitre.org/techniques/T1003/ T1003] -* '''Last Updated''': 2019-12-10 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name=vssadmin.exe Processes.process=*create* Processes.process=*shadow*) OR (Processes.process_name=wmic.exe Processes.process=*shadowcopy* Processes.process=*create*) by Processes.dest Processes.user Processes.process_name Processes.process Processes.parent_process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `creation_of_shadow_copy_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Credential_Dumping|Credential Dumping]] - - -====How To Implement==== -You must be ingesting endpoint data that tracks process activity, including parent-child relationships from your endpoints, to populate the Endpoint data model in the Processes node. The command-line arguments are mapped to the "process" field in the Endpoint data model. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1003.003 -| NTDS -| Credential Access -|- -| T1003 -| OS Credential Dumping -| Credential Access -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Legitimate administrator usage of Vssadmin or Wmic will create false positives. - -====Reference==== - - -* https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.003/atomic_red_team/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Creation of shadow copy with wmic and powershell=== -This search detects the use of wmic and Powershell to create a shadow copy. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/003/ T1003.003], [https://attack.mitre.org/techniques/T1003/ T1003] -* '''Last Updated''': 2021-09-16 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_wmic` OR `process_powershell` Processes.process=*shadowcopy* Processes.process=*create* by Processes.user Processes.process_name Processes.original_file_name Processes.process Processes.dest -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `creation_of_shadow_copy_with_wmic_and_powershell_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Credential_Dumping|Credential Dumping]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1003.003 -| NTDS -| Credential Access -|- -| T1003 -| OS Credential Dumping -| Credential Access -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Legtimate administrator usage of wmic to create a shadow copy. - -====Reference==== - - -* https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.003/atomic_red_team/windows-sysmon.log - - -''version'': 3 -
-
- ----- - -===Creation of lsass dump with taskmgr=== -Detect the hands on keyboard behavior of Windows Task Manager creating a process dump of lsass.exe. Upon this behavior occurring, a file write/modification will occur in the users profile under \AppData\Local\Temp. The dump file, lsass.dmp, cannot be renamed, however if the dump occurs more than once, it will be named lsass (2).dmp. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/001/ T1003.001], [https://attack.mitre.org/techniques/T1003/ T1003] -* '''Last Updated''': 2020-02-03 - -
-
- -====Search==== -`sysmon` EventID=11 process_name=taskmgr.exe TargetFilename=*lsass*.dmp -| stats count min(_time) as firstTime max(_time) as lastTime by Computer, object_category, process_name, TargetFilename -| rename Computer as dest -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `creation_of_lsass_dump_with_taskmgr_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Credential_Dumping|Credential Dumping]] - - -====How To Implement==== -This search requires Sysmon Logs and a Sysmon configuration, which includes EventCode 11 for detecting file create of lsass.dmp. This search uses an input macro named `sysmon`. We strongly recommend that you specify your environment-specific configurations (index, source, sourcetype, etc.) for Windows Sysmon logs. Replace the macro definition with configurations for your Splunk environment. The search also uses a post-filter macro designed to filter out known false positives. - -====Required field==== - -* _time - -* EventID - -* process_name - -* TargetFilename - -* Computer - -* object_category - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1003.001 -| LSASS Memory -| Credential Access -|- -| T1003 -| OS Credential Dumping -| Credential Access -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Administrators can create memory dumps for debugging purposes, but memory dumps of the LSASS process would be unusual. - -====Reference==== - - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1003.001/T1003.001.md#atomic-test-5---dump-lsassexe-memory-using-windows-task-manager - -* https://attack.mitre.org/techniques/T1003/001/ - -* https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.001/atomic_red_team/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Credential dumping via copy command from shadow copy=== -This search detects credential dumping using copy command from a shadow copy. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/003/ T1003.003], [https://attack.mitre.org/techniques/T1003/ T1003] -* '''Last Updated''': 2021-09-16 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_cmd` (Processes.process=*\\system32\\config\\sam* OR Processes.process=*\\system32\\config\\security* OR Processes.process=*\\system32\\config\\system* OR Processes.process=*\\windows\\ntds\\ntds.dit*) by Processes.dest Processes.user Processes.process_name Processes.process Processes.parent_process Processes.original_file_name Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `credential_dumping_via_copy_command_from_shadow_copy_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Credential_Dumping|Credential Dumping]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1003.003 -| NTDS -| Credential Access -|- -| T1003 -| OS Credential Dumping -| Credential Access -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.003/atomic_red_team/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Credential dumping via symlink to shadow copy=== -This search detects the creation of a symlink to a shadow copy. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/003/ T1003.003], [https://attack.mitre.org/techniques/T1003/ T1003] -* '''Last Updated''': 2021-09-16 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_cmd` Processes.process=*mklink* Processes.process=*HarddiskVolumeShadowCopy* by Processes.dest Processes.user Processes.process_name Processes.process Processes.parent_process Processes.original_file_name Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `credential_dumping_via_symlink_to_shadow_copy_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Credential_Dumping|Credential Dumping]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1003.003 -| NTDS -| Credential Access -|- -| T1003 -| OS Credential Dumping -| Credential Access -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.003/atomic_red_team/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Credential extraction indicative of fgdump and cachedump with s option=== -Credential extraction is often an illegal recovery of credential material from secured authentication resources and repositories. This process may also involve decryption or other transformations of the stored credential material. FGdump is a newer version of pwdump tool that extracts NTLM and LanMan password hashes from Windows. Cachedump is a publicly-available tool that extracts cached password hashes from a system's registry. - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/ T1003] -* '''Last Updated''': 2020-10-18 - -
-
- -====Search==== - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND process_name != null AND parent_process_name != null AND match_regex(parent_process_name, /(?i)System32\\services.exe/)=true AND match_regex(process_name, /(?i)cachedump\d{0,2}.exe/)=true AND match_regex(process_path, /(?i)\\Temp/)=true AND match_regex(cmd_line, /(?i)\-s/)=true - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name]) -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Unusual_Processes|Unusual Processes]] - -* [[Documentation:ESSOC:stories:UseCase#Credential_Dumping|Credential Dumping]] - - -====How To Implement==== -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -====Required field==== - -* dest_device_id - -* process_name - -* parent_process_name - -* _time - -* process_path - -* dest_user_id - -* process - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1003 -| OS Credential Dumping -| Credential Access -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -None identified. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logFgdump.log - - -''version'': 1 -
-
- ----- - -===Credential extraction indicative of fgdump and cachedump with v option=== -Credential extraction is often an illegal recovery of credential material from secured authentication resources and repositories. This process may also involve decryption or other transformations of the stored credential material. FGdump is a newer version of pwdump tool that extracts NTLM and LanMan password hashes from Windows. Cachedump is a publicly-available tool that extracts cached password hashes from a system's registry. - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/ T1003] -* '''Last Updated''': 2020-10-18 - -
-
- -====Search==== - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND process_name != null AND process_path != null AND match_regex(process_name, /(?i)cachedump\d{0,2}.exe/)=true AND match_regex(process_path, /(?i)\\Temp/)=true AND match_regex(cmd_line, /(?i)\-v/)=true - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name]) -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Unusual_Processes|Unusual Processes]] - -* [[Documentation:ESSOC:stories:UseCase#Credential_Dumping|Credential Dumping]] - - -====How To Implement==== -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -====Required field==== - -* dest_device_id - -* process_name - -* _time - -* process_path - -* dest_user_id - -* process - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1003 -| OS Credential Dumping -| Credential Access -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -None identified. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logFgdump.log - - -''version'': 1 -
-
- ----- - -===Credential extraction indicative of lazagne command line options=== -Credential extraction is often an illegal recovery of credential material from secured authentication resources and repositories. This process may also involve decryption or other transformations of the stored credential material. LaZagne is a tool that extracts various kinds of credentials from a local computer, including account passwords, domain passwords, browser passwords, etc. - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/ T1003], [https://attack.mitre.org/techniques/T1555/ T1555] -* '''Last Updated''': 2020-10-18 - -
-
- -====Search==== - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND match_regex(cmd_line, /(?i)all\s+\-oA\s+\-output/)=true - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Credential_Dumping|Credential Dumping]] - - -====How To Implement==== -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -====Required field==== - -* dest_device_id - -* dest_user_id - -* process - -* _time - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1003 -| OS Credential Dumping -| Credential Access -|- -| T1555 -| Credentials from Password Stores -| Credential Access -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -None identified. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logLazagneCredDump.log - - -''version'': 1 -
-
- ----- - -===Credential extraction indicative of use of dsinternals credential conversion modules=== -Credential extraction is often an illegal recovery of credential material from secured authentication resources and repositories. This process may also involve decryption or other transformations of the stored credential material. DSInternals is a collection of PowerShell modules commonly employed in exploits. - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/ T1003] -* '''Last Updated''': 2020-10-21 - -
-
- -====Search==== - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), "string", null), cmd_line=ucast(map_get(input_event, "process"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)ConvertFrom-ADManagedPasswordBlob/)=true OR match_regex(cmd_line, /(?i)ConvertFrom-GPPrefPassword/)=true OR match_regex(cmd_line, /(?i)ConvertFrom-UnicodePassword/)=true OR match_regex(cmd_line, /(?i)ConvertTo-GPPrefPassword/)=true OR match_regex(cmd_line, /(?i)ConvertTo-KerberosKey/)=true OR match_regex(cmd_line, /(?i)ConvertTo-LMHash/)=true OR match_regex(cmd_line, /(?i)ConvertTo-NTHash/)=true OR match_regex(cmd_line, /(?i)ConvertTo-OrgIdHash/)=true OR match_regex(cmd_line, /(?i)ConvertTo-UnicodePassword/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name]) -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Credential_Dumping|Credential Dumping]] - -* [[Documentation:ESSOC:stories:UseCase#Malicious_PowerShell|Malicious PowerShell]] - - -====How To Implement==== -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -====Required field==== - -* dest_device_id - -* process_name - -* parent_process_name - -* _time - -* process_path - -* dest_user_id - -* process - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1003 -| OS Credential Dumping -| Credential Access -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -None identified. - -====Reference==== - - -* https://github.com/MichaelGrafnetter/DSInternals - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllDSInternalsModules.log - - -''version'': 1 -
-
- ----- - -===Credential extraction indicative of use of dsinternals modules=== -Credential extraction is often an illegal recovery of credential material from secured authentication resources and repositories. This process may also involve decryption or other transformations of the stored credential material. DSInternals is a collection of PowerShell modules commonly employed in exploits. - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/ T1003] -* '''Last Updated''': 2020-10-21 - -
-
- -====Search==== - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), "string", null), cmd_line=ucast(map_get(input_event, "process"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)Get-ADDBBackupKey/)=true OR match_regex(cmd_line, /(?i)Get-ADDBDomainController/)=true OR match_regex(cmd_line, /(?i)Get-ADDBKdsRootKey/)=true OR match_regex(cmd_line, /(?i)Get-ADDBSchemaAttribute/)=true OR match_regex(cmd_line, /(?i)Get-ADKeyCredential/)=true OR match_regex(cmd_line, /(?i)Get-ADReplAccount/)=true OR match_regex(cmd_line, /(?i)Get-ADReplBackupKey/)=true OR match_regex(cmd_line, /(?i)Get-ADSIAccount/)=true OR match_regex(cmd_line, /(?i)Get-AzureADUserEx/)=true OR match_regex(cmd_line, /(?i)Get-BootKey/)=true OR match_regex(cmd_line, /(?i)Get-LsaBackupKey/)=true OR match_regex(cmd_line, /(?i)Get-LsaPolicyInformation/)=true OR match_regex(cmd_line, /(?i)Get-SamPasswordPolicy/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name]) -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Credential_Dumping|Credential Dumping]] - -* [[Documentation:ESSOC:stories:UseCase#Malicious_PowerShell|Malicious PowerShell]] - - -====How To Implement==== -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -====Required field==== - -* dest_device_id - -* process_name - -* parent_process_name - -* _time - -* process_path - -* dest_user_id - -* process - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1003 -| OS Credential Dumping -| Credential Access -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -None identified. - -====Reference==== - - -* https://github.com/MichaelGrafnetter/DSInternals - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllDSInternalsModules.log - - -''version'': 1 -
-
- ----- - -===Credential extraction indicative of use of mimikatz modules=== -Credential extraction is often an illegal recovery of credential material from secured authentication resources and repositories. This process may also involve decryption or other transformations of the stored credential material. Mimikatz is a collection of tools and modules commonly employed in Windows exploits. - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/ T1003] -* '''Last Updated''': 2020-10-21 - -
-
- -====Search==== - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)CRYPTO::Certificates/)=true OR match_regex(cmd_line, /(?i)CRYPTO::keys/)=true OR match_regex(cmd_line, /(?i)kerberos::list/)=true OR match_regex(cmd_line, /(?i)kerberos::tgt/)=true OR match_regex(cmd_line, /(?i)lsadump::sam/)=true OR match_regex(cmd_line, /(?i)lsadump::secrets/)=true OR match_regex(cmd_line, /(?i)lsadump::cache/)=true OR match_regex(cmd_line, /(?i)lsadump::lsa/)=true OR match_regex(cmd_line, /(?i)lsadump::trust/)=true OR match_regex(cmd_line, /(?i)lsadump::backupkeys/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Credential_Dumping|Credential Dumping]] - -* [[Documentation:ESSOC:stories:UseCase#Unusual_Processes|Unusual Processes]] - - -====How To Implement==== -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -====Required field==== - -* dest_device_id - -* dest_user_id - -* process - -* _time - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1003 -| OS Credential Dumping -| Credential Access -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -None identified. - -====Reference==== - - -* https://github.com/gentilkiwi/mimikatz - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllMimikatzModules.log - - -''version'': 1 -
-
- ----- - -===Credential extraction indicative of use of powersploit modules=== -Credential extraction is often an illegal recovery of credential material from secured authentication resources and repositories. This process may also involve decryption or other transformations of the stored credential material. PowerSploit is a collection of Microsoft PowerShell modules commonly employed in exploits. - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/ T1003] -* '''Last Updated''': 2020-10-21 - -
-
- -====Search==== - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)Get-ApplicationHost/)=true OR match_regex(cmd_line, /(?i)Get-CachedGPPPassword/)=true OR match_regex(cmd_line, /(?i)Get-GPPAutologon/)=true OR match_regex(cmd_line, /(?i)Get-GPPPassword/)=true OR match_regex(cmd_line, /(?i)Get-RegistryAutoLogon/)=true OR match_regex(cmd_line, /(?i)Get-SiteListPassword/)=true OR match_regex(cmd_line, /(?i)Get-SPNTicket/)=true OR match_regex(cmd_line, /(?i)Request-SPNTicket/)=true OR match_regex(cmd_line, /(?i)Get-VaultCredential/)=true OR match_regex(cmd_line, /(?i)Invoke-Kerberoast/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Credential_Dumping|Credential Dumping]] - -* [[Documentation:ESSOC:stories:UseCase#Malicious_PowerShell|Malicious PowerShell]] - - -====How To Implement==== -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -====Required field==== - -* dest_device_id - -* dest_user_id - -* process - -* _time - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1003 -| OS Credential Dumping -| Credential Access -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -None identified. - -====Reference==== - - -* https://github.com/PowerShellMafia/PowerSploit - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllPowerSploitModulesWithOldNames.log - - -''version'': 1 -
-
- ----- - -===Credential extraction native microsoft debuggers peek into the kernel=== -Credential extraction is often an illegal recovery of credential material from secured authentication resources and repositories. This process may also involve decryption or other transformations of the stored credential material. Native Microsoft debuggers, such as kd, ntkd, livekd and windbg, can be leveraged to read credential material directly from memory and process dumps. - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/ T1003] -* '''Last Updated''': 2020-10-18 - -
-
- -====Search==== - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, "process_name"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND parent_process_name != null AND process_name != null AND ( match_regex(parent_process_name, /(?i)ntkd\.exe/)=true OR match_regex(parent_process_name, /(?i)livekd\.exe/)=true ) AND match_regex(process_name, /(?i)conhost\.exe/)=true AND match_regex(cmd_line, /(?i)0xffffffff/)=true AND match_regex(cmd_line, /(?i)\-ForceV1/)=true - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name]) -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Credential_Dumping|Credential Dumping]] - -* [[Documentation:ESSOC:stories:UseCase#Unusual_Processes|Unusual Processes]] - - -====How To Implement==== -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -====Required field==== - -* process_name - -* parent_process_name - -* _time - -* dest_device_id - -* dest_user_id - -* process - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1003 -| OS Credential Dumping -| Credential Access -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Although unlikely, using debuggers this way may be indicative of developers analyzing crash dumps of their code. Note, even for developers this is an unusual way of working on code - debuggers are mostly used to step through code, not analyze its crash dumps. - -====Reference==== - - -* https://medium.com/@clermont1050/covid-19-cyber-infection-c615ead7c29 - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logLiveKDFullKernelDump.log - - -''version'': 1 -
-
- ----- - -===Credential extraction native microsoft debuggers via z command line option=== -Credential extraction is often an illegal recovery of credential material from secured authentication resources and repositories. This process may also involve decryption or other transformations of the stored credential material. Native Microsoft debuggers, such as kd, ntkd, livekd and windbg, can be leveraged to read credential material directly from memory and process dumps. - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/ T1003] -* '''Last Updated''': 2020-10-18 - -
-
- -====Search==== - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, "process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND process_name != null AND ( match_regex(process_name, /^(?i)ntkd\.exe/)=true OR match_regex(process_name, /^(?i)kd\.exe/)=true ) AND match_regex(cmd_line, /(?i)\-z\s+/)=true - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name]) -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Credential_Dumping|Credential Dumping]] - -* [[Documentation:ESSOC:stories:UseCase#Unusual_Processes|Unusual Processes]] - - -====How To Implement==== -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -====Required field==== - -* process_name - -* _time - -* dest_device_id - -* dest_user_id - -* process - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1003 -| OS Credential Dumping -| Credential Access -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Although unlikely, using debuggers this way may be indicative of developers analyzing crash dumps of their code. Note, even for developers this is an unusual way of working on code - debuggers are mostly used to step through code, not analyze its crash dumps. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logLiveKDFullKernelDump.log - - -''version'': 1 -
-
- ----- - -===Credential extraction via get-addbaccount module present in powersploit and dsinternals=== -Credential extraction is often an illegal recovery of credential material from secured authentication resources and repositories. This process may also involve decryption or other transformations of the stored credential material. PowerSploit and DSInternals are common exploit APIs offering PowerShell modules for various exploits of Windows and Active Directory environments. - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/ T1003] -* '''Last Updated''': 2020-10-18 - -
-
- -====Search==== - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND match_regex(cmd_line, /(?i)Get-ADDBAccount/)=true AND match_regex(cmd_line, /(?i)\-dbpath[\s;:\.\ -|]+/)=true - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Credential_Dumping|Credential Dumping]] - -* [[Documentation:ESSOC:stories:UseCase#Malicious_PowerShell|Malicious PowerShell]] - - -====How To Implement==== -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -====Required field==== - -* dest_device_id - -* dest_user_id - -* process - -* _time - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1003 -| OS Credential Dumping -| Credential Access -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -None identified. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logPowerShellModule.log - - -''version'': 1 -
-
- ----- - -===Dllhost with no command line arguments with network=== -The following analytic identifies DLLHost.exe with no command line arguments with a network connection. It is unusual for DLLHost.exe to execute with no command line arguments present. This particular behavior is common with malicious software, including Cobalt Strike. During investigation, triage any network connections and parallel processes. Identify any suspicious module loads related to credential dumping or file writes. DLLHost.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1055/ T1055] -* '''Last Updated''': 2021-10-13 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name=dllhost.exe by _time span=1h Processes.process_guid Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| regex process="(dllhost\.exe.{0,4}$)" -| join process_guid [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Ports where Ports.dest_port !="0" by Ports.process_guid Ports.dest Ports.dest_port -| `drop_dm_object_name(Ports)` -| rename dest as connection_to_CNC] -| table _time dest parent_process_name process_name process_path process process_guid connection_to_CNC dest_port -| `dllhost_with_no_command_line_arguments_with_network_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Cobalt_Strike|Cobalt Strike]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` and `port` node. - -====Required field==== - -* _time - -* EventID - -* process_name - -* process_id - -* parent_process_name - -* dest_port - -* process_path - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1055 -| Process Injection -| Defense Evasion, Privilege Escalation -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Although unlikely, some legitimate third party applications may use a moved copy of dllhost, triggering a false positive. - -====Reference==== - - -* https://raw.githubusercontent.com/threatexpress/malleable-c2/c3385e481159a759f79b8acfe11acf240893b830/jquery-c2.4.2.profile - -* https://blog.cobaltstrike.com/2021/02/09/learn-pipe-fitting-for-all-of-your-offense-projects/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon_dllhost.log - - -''version'': 2 -
-
- ----- - -===Dns exfiltration using nslookup app=== -this search is to detect potential DNS exfiltration using nslookup application. This technique are seen in couple of malware and APT group to exfiltrated collected data in a infected machine or infected network. This detection is looking for unique use of nslookup where it tries to use specific record type, TXT, A, AAAA, that are commonly used by attacker and also the retry parameter which is designed to query C2 DNS multiple tries. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1048/ T1048] -* '''Last Updated''': 2021-04-15 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` values(Processes.process) as process values(Processes.process_id) as process_id values(Processes.parent_process) as parent_process count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = "nslookup.exe" Processes.process = "*-querytype=*" OR Processes.process="*-qt=*" OR Processes.process="*-q=*" OR Processes.process="-type=*" OR Processes.process="*-retry=*" by Processes.dest Processes.user Processes.process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `dns_exfiltration_using_nslookup_app_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_DNS_Traffic|Suspicious DNS Traffic]] - -* [[Documentation:ESSOC:stories:UseCase#Dynamic_DNS|Dynamic DNS]] - -* [[Documentation:ESSOC:stories:UseCase#Command_and_Control|Command and Control]] - -* [[Documentation:ESSOC:stories:UseCase#Data_Exfiltration|Data Exfiltration]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances of nslookup.exe may be used. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1048 -| Exfiltration Over Alternative Protocol -| Exfiltration -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -admin nslookup usage - -====Reference==== - - -* https://www.fireeye.com/blog/threat-research/2017/03/fin7_spear_phishing.html - -* https://www.varonis.com/blog/dns-tunneling/ - -* https://www.microsoft.com/security/blog/2021/01/20/deep-dive-into-the-solorigate-second-stage-activation-from-sunburst-to-teardrop-and-raindrop/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1048.003/nslookup_exfil/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Dsquery domain discovery=== -The following analytic identifies "dsquery.exe" execution with arguments looking for `TrustedDomain` query directly on the command-line. This is typically indicative of an Administrator or adversary perform domain trust discovery. Note that this query does not identify any other variations of "Dsquery.exe" usage.\ -Within this detection, it is assumed `dsquery.exe` is not moved or renamed.\ -The search will return the first time and last time these command-line arguments were used for these executions, as well as the target system, the user, process "dsquery.exe" and its parent process.\ -DSQuery.exe is natively found in `C:\Windows\system32` and `C:\Windows\syswow64` and only on Server operating system.\ -The following DLL(s) are loaded when DSQuery.exe is launched `dsquery.dll`. If found loaded by another process, it is possible dsquery is running within that process context in memory.\ -In addition to trust discovery, review parallel processes for additional behaviors performed. Identify the parent process and capture any files (batch files, for example) being used. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1482/ T1482] -* '''Last Updated''': 2021-03-31 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=dsquery.exe Processes.process=*trustedDomain* by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `dsquery_domain_discovery_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Domain_Trust_Discovery|Domain Trust Discovery]] - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1482 -| Domain Trust Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Limited false positives. If there is a true false positive, filter based on command-line or parent process. - -====Reference==== - - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1482/T1482.md - -* http://www.harmj0y.net/blog/redteaming/a-guide-to-attacking-domain-trusts/ - -* https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-R2-and-2012/cc732952(v=ws.11) - -* https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-R2-and-2012/cc754232(v=ws.11) - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1482/atomic_red_team/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Delete a net user=== -This analytic will detect a suspicious net.exe/net1.exe command-line to delete a user on a system. This technique may be use by an administrator for legitimate purposes, however this behavior has been used in the wild to impair some user or deleting adversaries tracks created during its lateral movement additional systems. During triage, review parallel processes for additional behavior. Identify any other user accounts created before or after. - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1489/ T1489] -* '''Last Updated''': 2021-06-21 - -
-
- -====Search==== - -| from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line IS NOT NULL AND like(cmd_line, "%/delete%") AND (process_name="net1.exe" OR process_name="net.exe") -| eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#XMRig|XMRig]] - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - - -====How To Implement==== -o successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed net.exe may be used. - -====Required field==== - -* _time - -* dest_device_id - -* process_name - -* parent_process_name - -* process_path - -* dest_user_id - -* process - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1489 -| Service Stop -| Impact -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -System administrators or scripts may delete user accounts via this technique. Filter as needed. - -====Reference==== - - -* https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/ssa_data1/net_user_del.log - - -''version'': 2 -
-
- ----- - -===Delete shadowcopy with powershell=== -This following analytic detects PowerShell command to delete shadow copy using the WMIC PowerShell module. This technique was seen used by a recent adversary to deploy DarkSide Ransomware where it executed a child process of PowerShell to execute a hex encoded command to delete shadow copy. This hex encoded command was able to be decrypted by PowerShell log. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1490/ T1490] -* '''Last Updated''': 2021-05-12 - -
-
- -====Search==== -`powershell` EventCode=4104 Message= "*ShadowCopy*" (Message = "*Delete*" OR Message = "*Remove*") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `delete_shadowcopy_with_powershell_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#DarkSide_Ransomware|DarkSide Ransomware]] - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - -* [[Documentation:ESSOC:stories:UseCase#Revil_Ransomware|Revil Ransomware]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the powershell logs from your endpoints. make sure you enable needed registry to monitor this event. - -====Required field==== - -* _time - -* EventCode - -* Message - -* ComputerName - -* User - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1490 -| Inhibit System Recovery -| Impact -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://www.mandiant.com/resources/shining-a-light-on-darkside-ransomware-operations - -* https://searchwindowsserver.techtarget.com/tutorial/Set-up-PowerShell-script-block-logging-for-added-security - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/revil/inf1/windows-powershell.log - - -''version'': 1 -
-
- ----- - -===Deleting of net users=== -This analytic will detect a suspicious net.exe/net1.exe command-line to delete a user on a system. This technique may be use by an administrator for legitimate purposes, however this behavior has been used in the wild to impair some user or deleting adversaries tracks created during its lateral movement additional systems. During triage, review parallel processes for additional behavior. Identify any other user accounts created before or after. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1531/ T1531] -* '''Last Updated''': 2021-05-04 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` values(Processes.process) as process values(Processes.parent_process) as parent_process values(Processes.process_id) as process_id count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_net` AND Processes.process="*user*" AND Processes.process="*/delete*" by Processes.process_name Processes.original_file_name Processes.dest Processes.user Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `deleting_of_net_users_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#XMRig|XMRig]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1531 -| Account Access Removal -| Impact -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -System administrators or scripts may delete user accounts via this technique. Filter as needed. - -====Reference==== - - -* https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Deleting shadow copies=== -The vssadmin.exe utility is used to interact with the Volume Shadow Copy Service. Wmic is an interface to the Windows Management Instrumentation. This search looks for either of these tools being used to delete shadow copies. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1490/ T1490] -* '''Last Updated''': 2020-11-09 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count values(Processes.process) as process values(Processes.parent_process) as parent_process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name=vssadmin.exe OR Processes.process_name=wmic.exe) Processes.process=*delete* Processes.process=*shadow* by Processes.user Processes.process_name Processes.parent_process_name Processes.dest -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `deleting_shadow_copies_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Log_Manipulation|Windows Log Manipulation]] - -* [[Documentation:ESSOC:stories:UseCase#SamSam_Ransomware|SamSam Ransomware]] - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - -* [[Documentation:ESSOC:stories:UseCase#Clop_Ransomware|Clop Ransomware]] - - -====How To Implement==== -You must be ingesting endpoint data that tracks process activity, including parent-child relationships from your endpoints to populate the Endpoint data model in the Processes node. The command-line arguments are mapped to the "process" field in the Endpoint data model. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1490 -| Inhibit System Recovery -| Impact -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -vssadmin.exe and wmic.exe are standard applications shipped with modern versions of windows. They may be used by administrators to legitimately delete old backup copies, although this is typically rare. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1490/atomic_red_team/windows-sysmon.log - - -''version'': 4 -
-
- ----- - -===Deny permission using cacls utility=== -This analytic identifies a potential adversary that changes the security permission of a specific file or directory. This technique is commonly seen in APT tradecraft, ransomware or coinminer scripts. This behavior is meant to evade detection and prevent access to their component files. - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1222/ T1222] -* '''Last Updated''': 2021-06-14 - -
-
- -====Search==== - -| from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line IS NOT NULL AND match_regex(cmd_line, /(?i)deny/)=true AND (process_name="cacls.exe" OR process_name="xcacls.exe" OR process_name="icacls.exe") -| eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#XMRig|XMRig]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed icacls.exe may be used. - -====Required field==== - -* _time - -* dest_device_id - -* process_name - -* parent_process_name - -* process_path - -* dest_user_id - -* process - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1222 -| File and Directory Permissions Modification -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -network administrator may use this windows utility but this is not a common practice. - -====Reference==== - - -* https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.001/ssa_cacls/all_icalc.log - - -''version'': 2 -
-
- ----- - -===Detect activity related to pass the hash attacks=== -This search looks for specific authentication events from the Windows Security Event logs to detect potential attempts at using the Pass-the-Hash technique. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1550/ T1550], [https://attack.mitre.org/techniques/T1550/002/ T1550.002] -* '''Last Updated''': 2020-10-15 - -
-
- -====Search==== -`wineventlog_security` EventCode=4624 (Logon_Type=3 Logon_Process=NtLmSsp WorkstationName=WORKSTATION NOT AccountName="ANONYMOUS LOGON") OR (Logon_Type=9 Logon_Process=seclogo) -| fillnull -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode, Logon_Type, WorkstationName, user, dest -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_activity_related_to_pass_the_hash_attacks_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Lateral_Movement|Lateral Movement]] - - -====How To Implement==== -To successfully implement this search, you must ingest your Windows Security Event logs and leverage the latest TA for Windows. - -====Required field==== - -* _time - -* EventCode - -* Logon_Type - -* Logon_Process - -* WorkstationName - -* user - -* dest - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1550 -| Use Alternate Authentication Material -| Defense Evasion, Lateral Movement -|- -| T1550.002 -| Pass the Hash -| Defense Evasion, Lateral Movement -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Legitimate logon activity by authorized NTLM systems may be detected by this search. Please investigate as appropriate. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1550.002/atomic_red_team/windows-security.log - - -''version'': 5 -
-
- ----- - -===Detect azurehound command-line arguments=== -The following analytic identifies the common command-line argument used by AzureHound `Invoke-AzureHound`. Being the script is FOSS, function names may be modified, but these changes are dependent upon the operator. In most instances the defaults are used. This analytic works to identify the common command-line attributes used. It does not cover the entirety of every argument in order to avoid false positives. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/002/ T1087.002], [https://attack.mitre.org/techniques/T1069/001/ T1069.001], [https://attack.mitre.org/techniques/T1482/ T1482], [https://attack.mitre.org/techniques/T1087/001/ T1087.001], [https://attack.mitre.org/techniques/T1087/ T1087], [https://attack.mitre.org/techniques/T1069/002/ T1069.002], [https://attack.mitre.org/techniques/T1069/ T1069] -* '''Last Updated''': 2021-06-01 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process IN ("*invoke-azurehound*") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_azurehound_command_line_arguments_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Discovery_Techniques|Discovery Techniques]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1087.002 -| Domain Account -| Discovery -|- -| T1069.001 -| Local Groups -| Discovery -|- -| T1482 -| Domain Trust Discovery -| Discovery -|- -| T1087.001 -| Local Account -| Discovery -|- -| T1087 -| Account Discovery -| Discovery -|- -| T1069.002 -| Domain Groups -| Discovery -|- -| T1069 -| Permission Groups Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Unknown. - -====Reference==== - - -* https://attack.mitre.org/software/S0521/ - -* https://github.com/BloodHoundAD/BloodHound/tree/master/Collectors - -* https://posts.specterops.io/introducing-bloodhound-4-0-the-azure-update-9b2b26c5e350 - -* https://github.com/BloodHoundAD/BloodHound/blob/master/Collectors/AzureHound.ps1 - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/sharphound/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Detect azurehound file modifications=== -The following analytic is similar to SharpHound file modifications, but this instance covers the use of Invoke-AzureHound. AzureHound is the SharpHound equivilent but for Azure. It's possible this may never be seen in an environment as most attackers may execute this tool remotely. Once execution is complete, a zip file with a similar name will drop `20210601090751-azurecollection.zip`. In addition to the zip, multiple .json files will be written to disk, which are in the zip. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/002/ T1087.002], [https://attack.mitre.org/techniques/T1069/001/ T1069.001], [https://attack.mitre.org/techniques/T1482/ T1482], [https://attack.mitre.org/techniques/T1087/001/ T1087.001], [https://attack.mitre.org/techniques/T1087/ T1087], [https://attack.mitre.org/techniques/T1069/002/ T1069.002], [https://attack.mitre.org/techniques/T1069/ T1069] -* '''Last Updated''': 2021-06-01 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Filesystem where Filesystem.file_name IN ("*-azurecollection.zip", "*-azprivroleadminrights.json", "*-azglobaladminrights.json", "*-azcloudappadmins.json", "*-azapplicationadmins.json") by Filesystem.file_create_time Filesystem.process_id Filesystem.file_name Filesystem.file_path Filesystem.dest -| `drop_dm_object_name(Filesystem)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_azurehound_file_modifications_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Discovery_Techniques|Discovery Techniques]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on file modifications that include the name of the process, and file, responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Filesystem` node. - -====Required field==== - -* _time - -* file_path - -* dest - -* file_name - -* process_id - -* file_create_time - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1087.002 -| Domain Account -| Discovery -|- -| T1069.001 -| Local Groups -| Discovery -|- -| T1482 -| Domain Trust Discovery -| Discovery -|- -| T1087.001 -| Local Account -| Discovery -|- -| T1087 -| Account Discovery -| Discovery -|- -| T1069.002 -| Domain Groups -| Discovery -|- -| T1069 -| Permission Groups Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -False positives should be limited as the analytic is specific to a filename with extension .zip. Filter as needed. - -====Reference==== - - -* https://posts.specterops.io/introducing-bloodhound-4-0-the-azure-update-9b2b26c5e350 - -* https://raw.githubusercontent.com/BloodHoundAD/BloodHound/master/Collectors/AzureHound.ps1 - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/sharphound/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Detect baron samedit cve-2021-3156=== -This search detects the heap-based buffer overflow of sudoedit - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1068/ T1068] -* '''Last Updated''': 2021-01-27 - -
-
- -====Search==== -`linux_hosts` -| search "sudoedit -s \\" -| `detect_baron_samedit_cve_2021_3156_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Baron_Samedit_CVE-2021-3156|Baron Samedit CVE-2021-3156]] - - -====How To Implement==== -Splunk Universal Forwarder running on Linux systems, capturing logs from the /var/log directory. The vulnerability is exposed when a non privledged user tries passing in a single \ character at the end of the command while using the shell and edit flags. - -====Required field==== - -* _time - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1068 -| Exploitation for Privilege Escalation -| Privilege Escalation -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://blog.qualys.com/vulnerabilities-research/2021/01/26/cve-2021-3156-heap-based-buffer-overflow-in-sudo-baron-samedit - - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Detect baron samedit cve-2021-3156 segfault=== -This search detects the heap-based buffer overflow of sudoedit - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1068/ T1068] -* '''Last Updated''': 2021-01-29 - -
-
- -====Search==== -`linux_hosts` -| search sudoedit segfault -| stats count min(_time) as firstTime max(_time) as lastTime by host -| search count > 5 -| `detect_baron_samedit_cve_2021_3156_segfault_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Baron_Samedit_CVE-2021-3156|Baron Samedit CVE-2021-3156]] - - -====How To Implement==== -Splunk Universal Forwarder running on Linux systems (tested on Centos and Ubuntu), where segfaults are being logged. This also captures instances where the exploit has been compiled into a binary. The detection looks for greater than 5 instances of sudoedit combined with segfault over your search time period on a single host - -====Required field==== - -* _time - -* host - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1068 -| Exploitation for Privilege Escalation -| Privilege Escalation -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -If sudoedit is throwing segfaults for other reasons this will pick those up too. - -====Reference==== - - -* https://blog.qualys.com/vulnerabilities-research/2021/01/26/cve-2021-3156-heap-based-buffer-overflow-in-sudo-baron-samedit - - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Detect baron samedit cve-2021-3156 via osquery=== -This search detects the heap-based buffer overflow of sudoedit - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1068/ T1068] -* '''Last Updated''': 2021-01-28 - -
-
- -====Search==== -`osquery_process` -| search "columns.cmdline"="sudoedit -s \\*" -| `detect_baron_samedit_cve_2021_3156_via_osquery_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Baron_Samedit_CVE-2021-3156|Baron Samedit CVE-2021-3156]] - - -====How To Implement==== -OSQuery installed and configured to pick up process events (info at https://osquery.io) as well as using the Splunk OSQuery Add-on https://splunkbase.splunk.com/app/4402. The vulnerability is exposed when a non privledged user tries passing in a single \ character at the end of the command while using the shell and edit flags. - -====Required field==== - -* _time - -* columns.cmdline - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1068 -| Exploitation for Privilege Escalation -| Privilege Escalation -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://blog.qualys.com/vulnerabilities-research/2021/01/26/cve-2021-3156-heap-based-buffer-overflow-in-sudo-baron-samedit - - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Detect computer changed with anonymous account=== -This search looks for Event Code 4742 (Computer Change) or EventCode 4624 (An account was successfully logged on) with an anonymous account. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1210/ T1210] -* '''Last Updated''': 2020-09-18 - -
-
- -====Search==== -`wineventlog_security` EventCode=4624 OR EventCode=4742 TargetUserName="ANONYMOUS LOGON" LogonType=3 -| stats count values(host) as host, values(TargetDomainName) as Domain, values(user) as user -| `detect_computer_changed_with_anonymous_account_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Detect_Zerologon_Attack|Detect Zerologon Attack]] - - -====How To Implement==== -This search requires audit computer account management to be enabled on the system in order to generate Event ID 4742. We strongly recommend that you specify your environment-specific configurations (index, source, sourcetype, etc.) for Windows Event Logs. Replace the macro definition with configurations for your Splunk environment. The search also uses a post-filter macro designed to filter out known false positives. - -====Required field==== - -* _time - -* EventCode - -* TargetUserName - -* LogonType - -* TargetDomainName - -* user - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1210 -| Exploitation of Remote Services -| Lateral Movement -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -None thus far found - -====Reference==== - - -* https://www.lares.com/blog/from-lares-labs-defensive-guidance-for-zerologon-cve-2020-1472/ - - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Detect copy of shadowcopy with script block logging=== -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify suspicious PowerShell execution. Script Block Logging captures the command sent to PowerShell, the full command to be executed. Upon enabling, logs will output to Windows event logs. Dependent upon volume, enable on critical endpoints or all. \ -This analytic identifies `copy` or `[System.IO.File]::Copy` being used to capture the SAM, SYSTEM or SECURITY hives identified in script block. This will catch the most basic use cases for credentials being taken for offline cracking. \ -During triage, review parallel processes using an EDR product or 4688 events. It will be important to understand the timeline of events around this activity. Review the entire logged PowerShell script block. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/002/ T1003.002], [https://attack.mitre.org/techniques/T1003/ T1003] -* '''Last Updated''': 2021-07-21 - -
-
- -====Search==== -`powershell` EventCode=4104 Message IN ("*copy*","*[System.IO.File]::Copy*") AND Message IN ("*System32\\config\\SAM*", "*System32\\config\\SYSTEM*","*System32\\config\\SECURITY*") -| stats count min(_time) as firstTime max(_time) as lastTime by OpCode ComputerName User EventCode Message -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_copy_of_shadowcopy_with_script_block_logging_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Credential_Dumping|Credential Dumping]] - - -====How To Implement==== -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -====Required field==== - -* _time - -* Message - -* OpCode - -* ComputerName - -* User - -* EventCode - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1003.002 -| Security Account Manager -| Credential Access -|- -| T1003 -| OS Credential Dumping -| Credential Access -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Limited false positives as the scope is limited to SAM, SYSTEM and SECURITY hives. - -====Reference==== - - -* https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36934 - -* https://github.com/GossiTheDog/HiveNightmare - -* https://github.com/JumpsecLabs/Guidance-Advice/tree/main/SAM_Permissions - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.002/serioussam/windows-powershell.log - - -''version'': 1 -
-
- ----- - -===Detect credential dumping through lsass access=== -This search looks for reading lsass memory consistent with credential dumping. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/001/ T1003.001], [https://attack.mitre.org/techniques/T1003/ T1003] -* '''Last Updated''': 2019-12-03 - -
-
- -====Search==== -`sysmon` EventCode=10 TargetImage=*lsass.exe (GrantedAccess=0x1010 OR GrantedAccess=0x1410) -| stats count min(_time) as firstTime max(_time) as lastTime by Computer, SourceImage, SourceProcessId, TargetImage, TargetProcessId, EventCode, GrantedAccess -| rename Computer as dest -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_credential_dumping_through_lsass_access_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Credential_Dumping|Credential Dumping]] - -* [[Documentation:ESSOC:stories:UseCase#Detect_Zerologon_Attack|Detect Zerologon Attack]] - - -====How To Implement==== -This search needs Sysmon Logs and a sysmon configuration, which includes EventCode 10 with lsass.exe. This search uses an input macro named `sysmon`. We strongly recommend that you specify your environment-specific configurations (index, source, sourcetype, etc.) for Windows Sysmon logs. Replace the macro definition with configurations for your Splunk environment. The search also uses a post-filter macro designed to filter out known false positives. - -====Required field==== - -* _time - -* EventCode - -* TargetImage - -* GrantedAccess - -* Computer - -* SourceImage - -* SourceProcessId - -* TargetImage - -* TargetProcessId - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1003.001 -| LSASS Memory -| Credential Access -|- -| T1003 -| OS Credential Dumping -| Credential Access -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -The activity may be legitimate. Other tools can access lsass for legitimate reasons, and it's possible this event could be generated in those cases. In these cases, false positives should be fairly obvious and you may need to tweak the search to eliminate noise. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.001/atomic_red_team/windows-sysmon.log - - -''version'': 3 -
-
- ----- - -===Detect dump lsass memory using comsvcs=== -This search detects the memory of lsass.exe being dumped for offline credential theft attack. - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/003/ T1003.003], [https://attack.mitre.org/techniques/T1003/ T1003] -* '''Last Updated''': 2020-09-15 - -
-
- -====Search==== - -| from read_ssa_enriched_events() -| eval tenant=ucast(map_get(input_event, "_tenant"), "string", null), machine=ucast(map_get(input_event, "dest_device_id"), "string", null), process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), process=lower(ucast(map_get(input_event, "process"), "string", null)), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where process_name LIKE "%rundll32.exe%" AND match_regex(process, /(?i)comsvcs.dll[,\s]+MiniDump/)=true -| eval start_time = timestamp, end_time = timestamp, entities = mvappend(machine), body=create_map(["event_id", event_id, "process_name", process_name, "process", process]) -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Credential_Dumping|Credential Dumping]] - - -====How To Implement==== -You must be ingesting endpoint data that tracks process activity, including Windows command line logging. You can see how we test this with [Event Code 4688](https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=4688a) on the [attack_range](https://github.com/splunk/attack_range/blob/develop/ansible/roles/windows_common/tasks/windows-enable-4688-cmd-line-audit.yml). - -====Required field==== - -* process_name - -* _tenant - -* _time - -* dest_device_id - -* process - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1003.003 -| NTDS -| Credential Access -|- -| T1003 -| OS Credential Dumping -| Credential Access -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -None identified. - -====Reference==== - - -* https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.001/atomic_red_team/windows-security.log - - -''version'': 1 -
-
- ----- - -===Detect empire with powershell script block logging=== -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify suspicious PowerShell execution. Script Block Logging captures the command sent to PowerShell, the full command to be executed. Upon enabling, logs will output to Windows event logs. Dependent upon volume, enable on critical endpoints or all. \ -This analytic identifies the common PowerShell stager used by PowerShell-Empire. Each stager that may use PowerShell all uses the same pattern. The initial HTTP will be base64 encoded and use `system.net.webclient`. Note that some obfuscation may evade the analytic. \ -During triage, review parallel processes using an EDR product or 4688 events. It will be important to understand the timeline of events around this activity. Review the entire logged PowerShell script block. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/ T1059], [https://attack.mitre.org/techniques/T1059/001/ T1059.001] -* '''Last Updated''': 2021-06-09 - -
-
- -====Search==== -`powershell` EventCode=4104 (Message=*system.net.webclient* AND Message=*frombase64string*) -| stats count min(_time) as firstTime max(_time) as lastTime by OpCode ComputerName User EventCode Message -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_empire_with_powershell_script_block_logging_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Malicious_PowerShell|Malicious PowerShell]] - - -====How To Implement==== -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -====Required field==== - -* _time - -* Message - -* OpCode - -* ComputerName - -* User - -* EventCode - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1059 -| Command and Scripting Interpreter -| Execution -|- -| T1059.001 -| PowerShell -| Execution -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -False positives may only pertain to it not being related to Empire, but another framework. Filter as needed if any applications use the same pattern. - -====Reference==== - - -* https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -* https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63 - -* https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf - -* https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/ - -* https://github.com/BC-SECURITY/Empire - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/windows-powershell.log - - -''version'': 1 -
-
- ----- - -===Detect excessive account lockouts from endpoint=== -This search identifies endpoints that have caused a relatively high number of account lockouts in a short period. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Change -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/ T1078], [https://attack.mitre.org/techniques/T1078/002/ T1078.002] -* '''Last Updated''': 2020-11-09 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(All_Changes.user) as user from datamodel=Change.All_Changes where nodename=All_Changes.Account_Management All_Changes.result="lockout" by All_Changes.dest All_Changes.result -|`drop_dm_object_name("All_Changes")` -|`drop_dm_object_name("Account_Management")` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| search count > 5 -| `detect_excessive_account_lockouts_from_endpoint_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Account_Monitoring_and_Controls|Account Monitoring and Controls]] - - -====How To Implement==== -You must ingest your Windows security event logs in the `Change` datamodel under the nodename is `Account_Management`, for this search to execute successfully. Please consider updating the cron schedule and the count of lockouts you want to monitor, according to your environment. \ - **Splunk>Phantom Playbook Integration**\ -If Splunk>Phantom is also configured in your environment, a Playbook called "Excessive Account Lockouts Enrichment and Response" can be configured to run when any results are found by this detection search. The Playbook executes the Contextual and Investigative searches in this Story, conducts additional information gathering on Windows endpoints, and takes a response action to shut down the affected endpoint. To use this integration, install the Phantom App for Splunk `https://splunkbase.splunk.com/app/3411/`, add the correct hostname to the "Phantom Instance" field in the Adaptive Response Actions when configuring this detection search, and set the corresponding Playbook to active. \ -(Playbook Link:`https://my.phantom.us/4.1/playbook/excessive-account-lockouts-enrichment-and-response/`).\ - - -====Required field==== - -* _time - -* All_Changes.user - -* nodename - -* All_Changes.result - -* All_Changes.dest - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1078 -| Valid Accounts -| Defense Evasion, Persistence, Privilege Escalation, Initial Access -|- -| T1078.002 -| Domain Accounts -| Defense Evasion, Persistence, Privilege Escalation, Initial Access -|} - - -====Kill Chain Phase==== - - -====Known False Positives==== -It's possible that a widely used system, such as a kiosk, could cause a large number of account lockouts. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078.002/account_lockout/windows-security.log - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078.002/account_lockout/windows-system.log - - -''version'': 5 -
-
- ----- - -===Detect excessive user account lockouts=== -This search detects user accounts that have been locked out a relatively high number of times in a short period. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Change -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/ T1078], [https://attack.mitre.org/techniques/T1078/003/ T1078.003] -* '''Last Updated''': 2020-07-21 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Change.All_Changes where nodename=All_Changes.Account_Management All_Changes.result="lockout" by All_Changes.user All_Changes.result -|`drop_dm_object_name("All_Changes")` -|`drop_dm_object_name("Account_Management")` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| search count > 5 -| `detect_excessive_user_account_lockouts_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Account_Monitoring_and_Controls|Account Monitoring and Controls]] - - -====How To Implement==== -ou must ingest your Windows security event logs in the `Change` datamodel under the nodename is `Account_Management`, for this search to execute successfully. Please consider updating the cron schedule and the count of lockouts you want to monitor, according to your environment. - -====Required field==== - -* _time - -* All_Changes.result - -* nodename - -* All_Changes.user - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1078 -| Valid Accounts -| Defense Evasion, Persistence, Privilege Escalation, Initial Access -|- -| T1078.003 -| Local Accounts -| Defense Evasion, Persistence, Privilege Escalation, Initial Access -|} - - -====Kill Chain Phase==== - - -====Known False Positives==== -It is possible that a legitimate user is experiencing an issue causing multiple account login failures leading to lockouts. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078.002/account_lockout/windows-security.log - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078.002/account_lockout/windows-system.log - - -''version'': 3 -
-
- ----- - -===Detect exchange web shell=== -The following query identifies suspicious .aspx created in 3 paths identified by Microsoft as known drop locations for Exchange exploitation related to HAFNIUM group and recently disclosed vulnerablity named ProxyShell. Paths include: `\HttpProxy\owa\auth\`, `\inetpub\wwwroot\aspnet_client\`, and `\HttpProxy\OAB\`. Upon triage, the suspicious .aspx file will likely look obvious on the surface. inspect the contents for script code inside. Identify additional log sources, IIS included, to review source and other potential exploitation. It is often the case that a particular threat is only applicable to a specific subset of systems in your environment. Typically analytics to detect those threats are written without the benefit of being able to only target those systems as well. Writing analytics against all systems when those behaviors are limited to identifiable subsets of those systems is suboptimal. Consider the case ProxyShell vulnerability on Microsoft Exchange Servers. With asset information, a hunter can limit their analytics to systems that have been identified as Exchange servers. A hunter may start with the theory that the exchange server is communicating with new systems that it has not previously. If this theory is run against all publicly facing systems, the amount of noise it will generate will likely render this theory untenable. However, using the asset information to limit this analytic to just the Exchange servers will reduce the noise allowing the hunter to focus only on the systems where this behavioral change is relevant. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1505/ T1505], [https://attack.mitre.org/techniques/T1505/003/ T1505.003] -* '''Last Updated''': 2021-10-05 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name=System by _time span=1h Processes.process_id Processes.process_name Processes.dest -| `drop_dm_object_name(Processes)` -| join process_guid, _time [ -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_path IN ("*\\HttpProxy\\owa\\auth\\*", "*\\inetpub\\wwwroot\\aspnet_client\\*", "*\\HttpProxy\\OAB\\*") Filesystem.file_name="*.aspx" by _time span=1h Filesystem.dest Filesystem.file_create_time Filesystem.file_name Filesystem.file_path -| `drop_dm_object_name(Filesystem)` -| fields _time dest file_create_time file_name file_path process_name process_path process] -| dedup file_create_time -| table dest file_create_time, file_name, file_path, process_name -| `detect_exchange_web_shell_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#HAFNIUM_Group|HAFNIUM Group]] - -* [[Documentation:ESSOC:stories:UseCase#ProxyShell|ProxyShell]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node and `Filesystem` node. - -====Required field==== - -* _time - -* Filesystem.file_path - -* Filesystem.process_id - -* Filesystem.file_name - -* Filesystem.file_hash - -* Filesystem.user - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1505 -| Server Software Component -| Persistence -|- -| T1505.003 -| Web Shell -| Persistence -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -The query is structured in a way that `action` (read, create) is not defined. Review the results of this query, filter, and tune as necessary. It may be necessary to generate this query specific to your endpoint product. - -====Reference==== - - -* https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Sample%20Data/Feeds/MSTICIoCs-ExchangeServerVulnerabilitiesDisclosedMarch2021.csv - -* https://www.zerodayinitiative.com/blog/2021/8/17/from-pwn2own-2021-a-new-attack-surface-on-microsoft-exchange-proxyshell - -* https://www.youtube.com/watch?v=FC6iHw258RI - -* https://www.huntress.com/blog/rapid-response-microsoft-exchange-servers-still-vulnerable-to-proxyshell-exploit#what-should-you-do - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1505.003/windows-sysmon_proxylogon.log - - -''version'': 3 -
-
- ----- - -===Detect html help renamed=== -The following analytic identifies a renamed instance of hh.exe (HTML Help) executing a Compiled HTML Help (CHM). This particular technique will load Windows script code from a compiled help file. CHM files may contain nearly any file type embedded, but only execute html/htm. Upon a successful execution, the following script engines may be used for execution - JScript, VBScript, VBScript.Encode, JScript.Encode, JScript.Compact. Analyst may identify vbscript.dll or jscript.dll loading into hh.exe upon execution. The "htm" and "html" file extensions were the only extensions observed to be supported for the execution of Shortcut commands or WSH script code. During investigation, identify script content origination. Validate it is the legitimate version of hh.exe by reviewing the PE metadata. hh.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/001/ T1218.001] -* '''Last Updated''': 2021-09-16 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_hh` by Processes.dest Processes.user Processes.parent_process_name Processes.original_file_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.original_file_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_html_help_renamed_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Compiled_HTML_Activity|Suspicious Compiled HTML Activity]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1218 -| Signed Binary Proxy Execution -| Defense Evasion -|- -| T1218.001 -| Compiled HTML File -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Although unlikely a renamed instance of hh.exe will be used legitimately, filter as needed. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1218/001/ - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.001/T1218.001.md - -* https://lolbas-project.github.io/lolbas/Binaries/Hh/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.001/atomic_red_team/windows-sysmon.log - - -''version'': 3 -
-
- ----- - -===Detect html help spawn child process=== -The following analytic identifies hh.exe (HTML Help) execution of a Compiled HTML Help (CHM) that spawns a child process. This particular technique will load Windows script code from a compiled help file. CHM files may contain nearly any file type embedded, but only execute html/htm. Upon a successful execution, the following script engines may be used for execution - JScript, VBScript, VBScript.Encode, JScript.Encode, JScript.Compact. Analyst may identify vbscript.dll or jscript.dll loading into hh.exe upon execution. The "htm" and "html" file extensions were the only extensions observed to be supported for the execution of Shortcut commands or WSH script code. During investigation, identify script content origination. Review child process events and investigate further. hh.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/001/ T1218.001] -* '''Last Updated''': 2021-02-11 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=hh.exe by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_html_help_spawn_child_process_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Compiled_HTML_Activity|Suspicious Compiled HTML Activity]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1218 -| Signed Binary Proxy Execution -| Defense Evasion -|- -| T1218.001 -| Compiled HTML File -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Although unlikely, some legitimate applications (ex. web browsers) may spawn a child process. Filter as needed. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1218/001/ - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.001/T1218.001.md - -* https://lolbas-project.github.io/lolbas/Binaries/Hh/ - -* https://gist.github.com/mgeeky/cce31c8602a144d8f2172a73d510e0e7 - -* https://cyberforensicator.com/2019/01/20/silence-dissecting-malicious-chm-files-and-performing-forensic-analysis/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.001/atomic_red_team/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Detect html help url in command line=== -The following analytic identifies hh.exe (HTML Help) execution of a Compiled HTML Help (CHM) file from a remote url. This particular technique will load Windows script code from a compiled help file. CHM files may contain nearly any file type embedded, but only execute html/htm. Upon a successful execution, the following script engines may be used for execution - JScript, VBScript, VBScript.Encode, JScript.Encode, JScript.Compact. Analyst may identify vbscript.dll or jscript.dll loading into hh.exe upon execution. The "htm" and "html" file extensions were the only extensions observed to be supported for the execution of Shortcut commands or WSH script code. During investigation, identify script content origination. Review reputation of remote IP and domain. Some instances, it is worth decompiling the .chm file to review its original contents. hh.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/001/ T1218.001] -* '''Last Updated''': 2021-09-16 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_hh` Processes.process=*http* by Processes.dest Processes.user Processes.parent_process Processes.original_file_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_html_help_url_in_command_line_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Compiled_HTML_Activity|Suspicious Compiled HTML Activity]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1218 -| Signed Binary Proxy Execution -| Defense Evasion -|- -| T1218.001 -| Compiled HTML File -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Although unlikely, some legitimate applications may retrieve a CHM remotely, filter as needed. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1218/001/ - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.001/T1218.001.md - -* https://lolbas-project.github.io/lolbas/Binaries/Hh/ - -* https://blog.sevagas.com/?Hacking-around-HTA-files - -* https://gist.github.com/mgeeky/cce31c8602a144d8f2172a73d510e0e7 - -* https://cyberforensicator.com/2019/01/20/silence-dissecting-malicious-chm-files-and-performing-forensic-analysis/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.001/atomic_red_team/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Detect html help using infotech storage handlers=== -The following analytic identifies hh.exe (HTML Help) execution of a Compiled HTML Help (CHM) file using InfoTech Storage Handlers. This particular technique will load Windows script code from a compiled help file, using InfoTech Storage Handlers. itss.dll will load upon execution. Three InfoTech Storage handlers are supported - ms-its, its, mk:@MSITStore. ITSS may be used to launch a specific html/htm file from within a CHM file. CHM files may contain nearly any file type embedded. Upon a successful execution, the following script engines may be used for execution - JScript, VBScript, VBScript.Encode, JScript.Encode, JScript.Compact. Analyst may identify vbscript.dll or jscript.dll loading into hh.exe upon execution. The "htm" and "html" file extensions were the only extensions observed to be supported for the execution of Shortcut commands or WSH script code. During investigation, identify script content origination. hh.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/001/ T1218.001] -* '''Last Updated''': 2021-09-16 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_hh` Processes.process IN ("*its:*", "*mk:@MSITStore:*") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_html_help_using_infotech_storage_handlers_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Compiled_HTML_Activity|Suspicious Compiled HTML Activity]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1218 -| Signed Binary Proxy Execution -| Defense Evasion -|- -| T1218.001 -| Compiled HTML File -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -It is rare to see instances of InfoTech Storage Handlers being used, but it does happen in some legitimate instances. Filter as needed. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1218/001/ - -* https://www.kb.cert.org/vuls/id/851869 - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.001/T1218.001.md - -* https://lolbas-project.github.io/lolbas/Binaries/Hh/ - -* https://gist.github.com/mgeeky/cce31c8602a144d8f2172a73d510e0e7 - -* https://cyberforensicator.com/2019/01/20/silence-dissecting-malicious-chm-files-and-performing-forensic-analysis/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.001/atomic_red_team/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Detect kerberoasting=== -This search detects a potential kerberoasting attack via service principal name requests - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1558/003/ T1558.003], [https://attack.mitre.org/techniques/T1558/ T1558] -* '''Last Updated''': 2020-10-21 - -
-
- -====Search==== - -| from read_ssa_enriched_events() -| eval _time=map_get(input_event, "_time"), EventCode=map_get(input_event, "event_code"), TicketOptions=map_get(input_event, "ticket_options"), TicketEncryptionType=map_get(input_event, "ticket_encryption_type"), ServiceName=map_get(input_event, "service_name"), ServiceID=map_get(input_event, "service_id"), dest_user_id=ucast(map_get(input_event, "dest_user_id"), "string", null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where EventCode="4769" AND TicketOptions="0x40810000" AND TicketEncryptionType="0x17" -| first_time_event input_columns=["EventCode","TicketOptions","TicketEncryptionType","ServiceName","ServiceID"] -| where first_time_EventCode_TicketOptions_TicketEncryptionType_ServiceName_ServiceID -| eval start_time=_time, end_time=_time, body=create_map(["event_id", event_id, "EventCode", EventCode, "ServiceName", ServiceName, "TicketOptions", TicketOptions, "TicketEncryptionType", TicketEncryptionType]), entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)) -| select start_time, end_time, entities, body -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Credential_Dumping|Credential Dumping]] - - -====How To Implement==== -The test data is converted from Windows Security Event logs generated from Attach Range simulation and used in SPL search and extended to SPL2 - -====Required field==== - -* service_name - -* _time - -* event_code - -* ticket_encryption_type - -* service_id - -* ticket_options - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1558.003 -| Kerberoasting -| Credential Access -|- -| T1558 -| Steal or Forge Kerberos Tickets -| Credential Access -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Older systems that support kerberos RC4 by default NetApp may generate false positives - -====Reference==== - - -* Initial ESCU implementation by Jose Hernandez and Patrick Bareiss - - - -====Test Dataset==== - - -''version'': 2 -
-
- ----- - -===Detect mshta url in command line=== -This analytic identifies when Microsoft HTML Application Host (mshta.exe) utility is used to make remote http connections. Adversaries may use mshta.exe to proxy the download and execution of remote .hta files. The analytic identifies command line arguments of http and https being used. This technique is commonly used by malicious software to bypass preventative controls. The search will return the first time and last time these command-line arguments were used for these executions, as well as the target system, the user, process "rundll32.exe" and its parent process. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/005/ T1218.005] -* '''Last Updated''': 2021-09-16 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count values(Processes.process) as process values(Processes.parent_process) as parent_process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_mshta` (Processes.process="*http://*" OR Processes.process="*https://*") by Processes.user Processes.process_name Processes.parent_process_name Processes.original_file_name Processes.dest -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_mshta_url_in_command_line_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_MSHTA_Activity|Suspicious MSHTA Activity]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1218 -| Signed Binary Proxy Execution -| Defense Evasion -|- -| T1218.005 -| Mshta -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -It is possible legitimate applications may perform this behavior and will need to be filtered. - -====Reference==== - - -* https://github.com/redcanaryco/AtomicTestHarnesses - -* https://redcanary.com/blog/introducing-atomictestharnesses/ - -* https://docs.microsoft.com/en-us/windows/win32/search/-search-3x-wds-extidx-prot-implementing - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.005/atomic_red_team/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Detect mimikatz using loaded images=== -This search looks for reading loaded Images unique to credential dumping with Mimikatz. Deprecated because mimikatz libraries changed and very noisy sysmon Event Code. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/001/ T1003.001], [https://attack.mitre.org/techniques/T1003/ T1003] -* '''Last Updated''': 2019-12-03 - -
-
- -====Search==== -`sysmon` EventCode=7 -| stats values(ImageLoaded) as ImageLoaded values(ProcessId) as ProcessId by Computer, Image -| search ImageLoaded=*WinSCard.dll ImageLoaded=*cryptdll.dll ImageLoaded=*hid.dll ImageLoaded=*samlib.dll ImageLoaded=*vaultcli.dll -| rename Computer as dest -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_mimikatz_using_loaded_images_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Credential_Dumping|Credential Dumping]] - -* [[Documentation:ESSOC:stories:UseCase#Detect_Zerologon_Attack|Detect Zerologon Attack]] - -* [[Documentation:ESSOC:stories:UseCase#Cloud_Federated_Credential_Abuse|Cloud Federated Credential Abuse]] - -* [[Documentation:ESSOC:stories:UseCase#DarkSide_Ransomware|DarkSide Ransomware]] - - -====How To Implement==== -This search needs Sysmon Logs and a sysmon configuration, which includes EventCode 7 with powershell.exe. This search uses an input macro named `sysmon`. We strongly recommend that you specify your environment-specific configurations (index, source, sourcetype, etc.) for Windows Sysmon logs. Replace the macro definition with configurations for your Splunk environment. The search also uses a post-filter macro designed to filter out known false positives. - -====Required field==== - -* _time - -* EventCode - -* ImageLoaded - -* ProcessId - -* Computer - -* Image - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1003.001 -| LSASS Memory -| Credential Access -|- -| T1003 -| OS Credential Dumping -| Credential Access -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Other tools can import the same DLLs. These tools should be part of a whitelist. False positives may be present with any process that authenticates or uses credentials, PowerShell included. Filter based on parent process. - -====Reference==== - - -* https://cyberwardog.blogspot.com/2017/03/chronicles-of-threat-hunter-hunting-for.html - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/atomic_red_team/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Detect mimikatz with powershell script block logging=== -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify suspicious PowerShell execution. Script Block Logging captures the command sent to PowerShell, the full command to be executed. Upon enabling, logs will output to Windows event logs. Dependent upon volume, enable no critical endpoints or all. \ -This analytic identifies common Mimikatz functions that may be identified in the script block, including `mimikatz`. This will catch the most basic use cases for Pass the Ticket, Pass the Hash and `-DumprCreds`. \ -During triage, review parallel processes using an EDR product or 4688 events. It will be important to understand the timeline of events around this activity. Review the entire logged PowerShell script block. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/ T1003] -* '''Last Updated''': 2021-06-09 - -
-
- -====Search==== -`powershell` EventCode=4104 Message IN (*mimikatz*, *-dumpcr*, *sekurlsa::pth*, *kerberos::ptt*, *kerberos::golden*) -| stats count min(_time) as firstTime max(_time) as lastTime by OpCode ComputerName User EventCode Message -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_mimikatz_with_powershell_script_block_logging_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Malicious_PowerShell|Malicious PowerShell]] - - -====How To Implement==== -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -====Required field==== - -* _time - -* Message - -* OpCode - -* ComputerName - -* User - -* EventCode - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1003 -| OS Credential Dumping -| Credential Access -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -False positives should be limited as the commands being identifies are quite specific to EventCode 4104 and Mimikatz. Filter as needed. - -====Reference==== - - -* https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -* https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63 - -* https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf - -* https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/windows-powershell.log - - -''version'': 1 -
-
- ----- - -===Detect new local admin account=== -This search looks for newly created accounts that have been elevated to local administrators. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1136/001/ T1136.001], [https://attack.mitre.org/techniques/T1136/ T1136] -* '''Last Updated''': 2020-07-08 - -
-
- -====Search==== -`wineventlog_security` EventCode=4720 OR (EventCode=4732 Group_Name=Administrators) -| transaction member_id connected=false maxspan=180m -| rename member_id as user -| stats count min(_time) as firstTime max(_time) as lastTime by user dest -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_new_local_admin_account_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#DHS_Report_TA18-074A|DHS Report TA18-074A]] - -* [[Documentation:ESSOC:stories:UseCase#HAFNIUM_Group|HAFNIUM Group]] - - -====How To Implement==== -You must be ingesting Windows event logs using the Splunk Windows TA and collecting event code 4720 and 4732 - -====Required field==== - -* _time - -* EventCode - -* Group_Name - -* member_id - -* dest - -* user - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1136.001 -| Local Account -| Persistence -|- -| T1136 -| Create Account -| Persistence -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - -* Command and Control - - -====Known False Positives==== -The activity may be legitimate. For this reason, it's best to verify the account with an administrator and ask whether there was a valid service request for the account creation. If your local administrator group name is not "Administrators", this search may generate an excessive number of false positives - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.001/atomic_red_team/windows-security.log - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.001/atomic_red_team/windows-system.log - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.001/atomic_red_team/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Detect outlook exe writing a zip file=== -This search looks for execution of process `outlook.exe` where the process is writing a `.zip` file to the disk. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/ T1566], [https://attack.mitre.org/techniques/T1566/001/ T1566.001] -* '''Last Updated''': 2020-07-21 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes where Processes.process_name=outlook.exe OR Processes.process_name=explorer.exe by _time span=5m Processes.parent_process_id Processes.process_id Processes.dest Processes.process_name Processes.parent_process_name Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| rename process_id as malicious_id -| rename parent_process_id as outlook_id -| join malicious_id type=inner[ -| tstats `security_content_summariesonly` count values(Filesystem.file_path) as file_path values(Filesystem.file_name) as file_name FROM datamodel=Endpoint.Filesystem where (Filesystem.file_path=*zip* OR Filesystem.file_name=*.lnk ) AND (Filesystem.file_path=C:\\Users* OR Filesystem.file_path=*Local\\Temp*) by _time span=5m Filesystem.process_id Filesystem.file_hash Filesystem.dest -| `drop_dm_object_name(Filesystem)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| rename process_id as malicious_id -| fields malicious_id outlook_id dest file_path file_name file_hash count file_id] -| table firstTime lastTime user malicious_id outlook_id process_name parent_process_name file_name file_path -| where file_name != "" -| `detect_outlook_exe_writing_a_zip_file_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Spearphishing_Attachments|Spearphishing Attachments]] - - -====How To Implement==== -You must be ingesting data that records filesystem and process activity from your hosts to populate the Endpoint data model. This is typically populated via endpoint detection-and-response product, such as Carbon Black, or endpoint data sources, such as Sysmon. - -====Required field==== - -* _time - -* Processes.process_name - -* Processes.parent_process_id - -* Processes.process_id - -* Processes.dest - -* Processes.parent_process_name - -* Processes.user - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1566 -| Phishing -| Initial Access -|- -| T1566.001 -| Spearphishing Attachment -| Initial Access -|} - - -====Kill Chain Phase==== - -* Installation - -* Actions on Objectives - - -====Known False Positives==== -It is not uncommon for outlook to write legitimate zip files to the disk. - -====Reference==== - - -====Test Dataset==== - - -''version'': 3 -
-
- ----- - -===Detect pass the hash=== -This search looks for specific authentication events from the Windows Security Event logs to detect potential attempts using Pass-the-Hash technique. - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1550/ T1550], [https://attack.mitre.org/techniques/T1550/002/ T1550.002] -* '''Last Updated''': 2020-10-21 - -
-
- -====Search==== - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)) -| eval signature_id=map_get(input_event, "signature_id"), authentication_type=map_get(input_event, "authentication_type"), authentication_method=map_get(input_event, "authentication_method"), origin_device_domain=map_get(input_event, "origin_device_domain"), dest_user_id=ucast(map_get(input_event, "dest_user_id"), "string", null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) - -| where (authentication_type="3" AND authentication_method="NtLmSsp") OR (authentication_type="9" AND authentication_method="seclogo") - -| eval start_time=timestamp, end_time=timestamp, entities=mvappend(dest_device_id, dest_user_id), body=create_map(["event_id", event_id, "authentication_type", authentication_type, "authentication_method", authentication_method]) -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Lateral_Movement|Lateral Movement]] - - -====How To Implement==== -The test data is converted from Windows Security Event logs generated from Attach Range simulation and used in SPL search and extended to SPL2 - -====Required field==== - -* signature_id - -* authentication_type - -* _time - -* authentication_method - -* origin_device_domain - -* dest_user_id - -* dest_device_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1550 -| Use Alternate Authentication Material -| Defense Evasion, Lateral Movement -|- -| T1550.002 -| Pass the Hash -| Defense Evasion, Lateral Movement -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Legitimate logon activity by authorized NTLM systems may be detected by this search. Please investigate as appropriate. - -====Reference==== - - -* Initial ESCU implementation by Bhavin Patel and Patrick Bareiss - - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Detect path interception by creation of program exe=== -The detection Detect Path Interception By Creation Of program exe is detecting the abuse of unquoted service paths, which is a popular technique for privilege escalation. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1574/009/ T1574.009], [https://attack.mitre.org/techniques/T1574/ T1574] -* '''Last Updated''': 2020-07-03 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=services.exe by Processes.user Processes.process_name Processes.process Processes.dest -| `drop_dm_object_name(Processes)` -| rex field=process "^.*?\\\\(?<service_process>[^\\\\]*\.(?:exe -|bat -|com -|ps1))" -| eval process_name = lower(process_name) -| eval service_process = lower(service_process) -| where process_name != service_process -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_path_interception_by_creation_of_program_exe_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Persistence_Techniques|Windows Persistence Techniques]] - - -====How To Implement==== -You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1574.009 -| Path Interception by Unquoted Path -| Persistence, Privilege Escalation, Defense Evasion -|- -| T1574 -| Hijack Execution Flow -| Persistence, Privilege Escalation, Defense Evasion -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://medium.com/@SumitVerma101/windows-privilege-escalation-part-1-unquoted-service-path-c7a011a8d8ae - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1574.009/atomic_red_team/windows-sysmon.log - - -''version'': 3 -
-
- ----- - -===Detect prohibited applications spawning cmd exe=== -This search looks for executions of cmd.exe spawned by a process that is often abused by attackers and that does not typically launch cmd.exe. This is a SPL2 implementation of the rule `Detect Prohibited Applications Spawning cmd.exe` by @bpatel. - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/ T1059] -* '''Last Updated''': 2020-7-13 - -
-
- -====Search==== - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)) -| eval process_name=ucast(map_get(input_event, "process_name"), "string", null), parent_process=lower(ucast(map_get(input_event, "parent_process_name"), "string", null)), dest_user_id=ucast(map_get(input_event, "dest_user_id"), "string", null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) - -| where process_name="cmd.exe" -| rex field=parent_process "(?<field0>[^\\\\]+)$" -| where field0="winword.exe" OR field0="excel.exe" OR field0="outlook.exe" OR field0="powerpnt.exe" OR field0="visio.exe" OR field0="mspub.exe" OR field0="acrobat.exe" OR field0="acrord32.exe" OR field0="chrome.exe" OR field0="iexplore.exe" OR field0="opera.exe" OR field0="firefox.exe" OR field0="java.exe" OR field0="powershell.exe" - -| eval start_time=timestamp, end_time=timestamp, entities=mvappend(dest_device_id, dest_user_id), body=create_map(["event_id", event_id, "process_name", process_name, "parent_process_name", parent_process]) -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Command-Line_Executions|Suspicious Command-Line Executions]] - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_MSHTA_Activity|Suspicious MSHTA Activity]] - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Zoom_Child_Processes|Suspicious Zoom Child Processes]] - -* [[Documentation:ESSOC:stories:UseCase#Sunburst_Malware|Sunburst Malware]] - - -====How To Implement==== -You must be ingesting sysmon logs. This search has been modified to process raw sysmon data from attack_range's nxlogs on DSP. - -====Required field==== - -* process_name - -* parent_process_name - -* _time - -* dest_device_id - -* dest_user_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1059 -| Command and Scripting Interpreter -| Execution -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -There are circumstances where an application may legitimately execute and interact with the Windows command-line interface. Investigate and modify the lookup file, as appropriate. - -====Reference==== - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Detect prohibited applications spawning cmd exe=== -This search looks for executions of cmd.exe spawned by a process that is often abused by attackers and that does not typically launch cmd.exe. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/ T1059], [https://attack.mitre.org/techniques/T1059/003/ T1059.003] -* '''Last Updated''': 2020-11-10 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_cmd` by Processes.parent_process_name Processes.process_name Processes.original_file_name Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -|search [`prohibited_apps_launching_cmd`] -| `detect_prohibited_applications_spawning_cmd_exe_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Command-Line_Executions|Suspicious Command-Line Executions]] - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_MSHTA_Activity|Suspicious MSHTA Activity]] - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Zoom_Child_Processes|Suspicious Zoom Child Processes]] - -* [[Documentation:ESSOC:stories:UseCase#NOBELIUM_Group|NOBELIUM Group]] - - -====How To Implement==== -You must be ingesting data that records process activity from your hosts and populates the Endpoint data model with the resultant dataset. This search includes a lookup file, `prohibited_apps_launching_cmd.csv`, that contains a list of processes that should not be spawning cmd.exe. You can modify this lookup to better suit your environment. To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1059 -| Command and Scripting Interpreter -| Execution -|- -| T1059.003 -| Windows Command Shell -| Execution -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -There are circumstances where an application may legitimately execute and interact with the Windows command-line interface. Investigate and modify the lookup file, as appropriate. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.003/powershell_spawn_cmd/windows-sysmon.log - - -''version'': 6 -
-
- ----- - -===Detect psexec with accepteula flag=== -This search looks for events where `PsExec.exe` is run with the `accepteula` flag in the command line. PsExec is a built-in Windows utility that enables you to execute processes on other systems. It is fully interactive for console applications. This tool is widely used for launching interactive command prompts on remote systems. Threat actors leverage this extensively for executing code on compromised systems. If an attacker is running PsExec for the first time, they will be prompted to accept the end-user license agreement (EULA), which can be passed as the argument `accepteula` within the command line. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1021/ T1021], [https://attack.mitre.org/techniques/T1021/002/ T1021.002] -* '''Last Updated''': 2021-09-16 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_psexec` Processes.process=*accepteula* by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_psexec_with_accepteula_flag_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#SamSam_Ransomware|SamSam Ransomware]] - -* [[Documentation:ESSOC:stories:UseCase#DHS_Report_TA18-074A|DHS Report TA18-074A]] - -* [[Documentation:ESSOC:stories:UseCase#HAFNIUM_Group|HAFNIUM Group]] - -* [[Documentation:ESSOC:stories:UseCase#DarkSide_Ransomware|DarkSide Ransomware]] - -* [[Documentation:ESSOC:stories:UseCase#Lateral_Movement|Lateral Movement]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1021 -| Remote Services -| Lateral Movement -|- -| T1021.002 -| SMB/Windows Admin Shares -| Lateral Movement -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Administrators can leverage PsExec for accessing remote systems and might pass `accepteula` as an argument if they are running this tool for the first time. However, it is not likely that you'd see multiple occurrences of this event on a machine - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021.002/atomic_red_team/windows-sysmon.log - - -''version'': 4 -
-
- ----- - -===Detect rclone command-line usage=== -This analytic identifies commonly used command-line arguments used by `rclone.exe` to initiate a file transfer. Some arguments were negated as they are specific to the configuration used by adversaries. In particular, an adversary may list the files or directories of the remote file share using `ls` or `lsd`, which is not indicative of malicious behavior. During triage, at this stage of a ransomware event, exfiltration is about to occur or has already. Isolate the endpoint and continue investigating by review file modifications and parallel processes. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1020/ T1020] -* '''Last Updated''': 2021-05-13 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process IN ("*copy*", "*mega*", "*pcloud*", "*ftp*", "*--config*", "*--progress*", "*--no-check-certificate*", "*--ignore-existing*", "*--auto-confirm*", "*--transfers*", "*--multi-thread-streams*") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_rclone_command_line_usage_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#DarkSide_Ransomware|DarkSide Ransomware]] - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1020 -| Automated Exfiltration -| Exfiltration -|} - - -====Kill Chain Phase==== - -* Exfiltration - - -====Known False Positives==== -There is potential for false positives as these arguments may be used by other applications. Filter or tune the analytic as needed. - -====Reference==== - - -* https://redcanary.com/blog/rclone-mega-extortion/ - -* https://www.mandiant.com/resources/shining-a-light-on-darkside-ransomware-operations - -* https://thedfirreport.com/2021/03/29/sodinokibi-aka-revil-ransomware/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1020/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Detect rare executables=== -This search will return a table of rare processes, the names of the systems running them, and the users who initiated each process. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': -* '''Last Updated''': 2020-03-16 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count values(Processes.dest) as dest values(Processes.user) as user min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes by Processes.process_name -| rename Processes.process_name as process -| rex field=user "(?<user_domain>.*)\\\\(?<user_name>.*)" -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| search [ -| tstats count from datamodel=Endpoint.Processes by Processes.process_name -| rare Processes.process_name limit=30 -| rename Processes.process_name as process -| `filter_rare_process_allow_list` -| table process ] -| `detect_rare_executables_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Emotet_Malware__DHS_Report_TA18-201A_|Emotet Malware DHS Report TA18-201A ]] - -* [[Documentation:ESSOC:stories:UseCase#Unusual_Processes|Unusual Processes]] - -* [[Documentation:ESSOC:stories:UseCase#Cloud_Federated_Credential_Abuse|Cloud Federated Credential Abuse]] - - -====How To Implement==== -To successfully implement this search, you must be ingesting data that records process activity from your hosts and populating the endpoint data model with the resultant dataset. The macro `filter_rare_process_allow_list` searches two lookup files for allowed processes. These consist of `rare_process_allow_list_default.csv` and `rare_process_allow_list_local.csv`. To add your own processes to the allow list, add them to `rare_process_allow_list_local.csv`. If you wish to remove an entry from the default lookup file, you will have to modify the macro itself to set the allow_list value for that process to false. You can modify the limit parameter and search scheduling to better suit your environment. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.process_name - - - - -====Kill Chain Phase==== - -* Installation - -* Command and Control - -* Actions on Objectives - - -====Known False Positives==== -Some legitimate processes may be only rarely executed in your environment. As these are identified, update `rare_process_allow_list_local.csv` to filter them out of your search results. - -====Reference==== - - -====Test Dataset==== - - -''version'': 5 -
-
- ----- - -===Detect regasm spawning a process=== -The following analytic identifies regasm.exe spawning a process. This particular technique has been used in the wild to bypass application control products. Regasm.exe and Regsvcs.exe are signed by Microsoft. Spawning of a child process is rare from either process and should be investigated further. During investigation, identify and retrieve the content being loaded. Review parallel processes for additional suspicious behavior. Gather any other file modifications and review accordingly. regsvcs.exe and regasm.exe are natively found in C:\Windows\Microsoft.NET\Framework\v*\regasm|regsvcs.exe and C:\Windows\Microsoft.NET\Framework64\v*\regasm|regsvcs.exe. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/009/ T1218.009] -* '''Last Updated''': 2021-02-12 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=regasm.exe by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_regasm_spawning_a_process_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Regsvcs_Regasm_Activity|Suspicious Regsvcs Regasm Activity]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* _time - -* Processes.parent_process_name - -* Processes.dest - -* Processes.user - -* Processes.parent_process - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1218 -| Signed Binary Proxy Execution -| Defense Evasion -|- -| T1218.009 -| Regsvcs/Regasm -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Although unlikely, limited instances of regasm.exe or regsvcs.exe may cause a false positive. Filter based endpoint usage, command line arguments, or process lineage. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1218/009/ - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.009/T1218.009.md - -* https://lolbas-project.github.io/lolbas/Binaries/Regsvcs/ - -* https://lolbas-project.github.io/lolbas/Binaries/Regasm/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.009/atomic_red_team/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Detect regasm with network connection=== -The following analytic identifies regasm.exe with a network connection to a public IP address, exluding private IP space. This particular technique has been used in the wild to bypass application control products. Regasm.exe and Regsvcs.exe are signed by Microsoft. By contacting a remote command and control server, the adversary will have the ability to escalate privileges and complete the objectives. During investigation, identify and retrieve the content being loaded. Review parallel processes for additional suspicious behavior. Gather any other file modifications and review accordingly. Review the reputation of the remote IP or domain and block as needed. regsvcs.exe and regasm.exe are natively found in C:\Windows\Microsoft.NET\Framework\v*\regasm|regsvcs.exe and C:\Windows\Microsoft.NET\Framework64\v*\regasm|regsvcs.exe. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/009/ T1218.009] -* '''Last Updated''': 2021-02-16 - -
-
- -====Search==== -`sysmon` EventID=3 dest_ip!=10.0.0.0/12 dest_ip!=172.16.0.0/12 dest_ip!=192.168.0.0/16 process_name=regasm.exe -| rename Computer as dest -| stats count min(_time) as firstTime max(_time) as lastTime by dest, User, process_name, src_ip, dest_host, dest_ip -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_regasm_with_network_connection_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Regsvcs_Regasm_Activity|Suspicious Regsvcs Regasm Activity]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -====Required field==== - -* _time - -* EventID - -* dest_ip - -* process_name - -* Computer - -* User - -* src_ip - -* dest_host - -* dest_ip - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1218 -| Signed Binary Proxy Execution -| Defense Evasion -|- -| T1218.009 -| Regsvcs/Regasm -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Although unlikely, limited instances of regasm.exe with a network connection may cause a false positive. Filter based endpoint usage, command line arguments, or process lineage. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1218/009/ - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.009/T1218.009.md - -* https://lolbas-project.github.io/lolbas/Binaries/Regasm/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.009/atomic_red_team/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Detect regasm with no command line arguments=== -The following analytic identifies regasm.exe with no command line arguments. This particular behavior occurs when another process injects into regasm.exe, no command line arguments will be present. During investigation, identify any network connections and parallel processes. Identify any suspicious module loads related to credential dumping or file writes. Regasm.exe are natively found in C:\Windows\Microsoft.NET\Framework\v*\regasm|regsvcs.exe and C:\Windows\Microsoft.NET\Framework64\v*\regasm|regsvcs.exe. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/009/ T1218.009] -* '''Last Updated''': 2021-09-20 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where `process_regasm` by _time span=1h Processes.process_id Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| regex process="(regasm\.exe.{0,4}$)" -| `detect_regasm_with_no_command_line_arguments_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Regsvcs_Regasm_Activity|Suspicious Regsvcs Regasm Activity]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1218 -| Signed Binary Proxy Execution -| Defense Evasion -|- -| T1218.009 -| Regsvcs/Regasm -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Although unlikely, limited instances of regasm.exe or may cause a false positive. Filter based endpoint usage, command line arguments, or process lineage. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1218/009/ - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.009/T1218.009.md - -* https://lolbas-project.github.io/lolbas/Binaries/Regasm/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.009/atomic_red_team/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Detect regsvcs spawning a process=== -The following analytic identifies regsvcs.exe spawning a process. This particular technique has been used in the wild to bypass application control products. Regasm.exe and Regsvcs.exe are signed by Microsoft. Spawning of a child process is rare from either process and should be investigated further. During investigation, identify and retrieve the content being loaded. Review parallel processes for additional suspicious behavior. Gather any other file modifications and review accordingly. regsvcs.exe and regasm.exe are natively found in C:\Windows\Microsoft.NET\Framework\v*\regasm|regsvcs.exe and C:\Windows\Microsoft.NET\Framework64\v*\regasm|regsvcs.exe. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/009/ T1218.009] -* '''Last Updated''': 2021-02-12 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=regsvcs.exe by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_regsvcs_spawning_a_process_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Regsvcs_Regasm_Activity|Suspicious Regsvcs Regasm Activity]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* _time - -* Processes.parent_process_name - -* Processes.dest - -* Processes.user - -* Processes.parent_process - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1218 -| Signed Binary Proxy Execution -| Defense Evasion -|- -| T1218.009 -| Regsvcs/Regasm -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Although unlikely, limited instances of regasm.exe or regsvcs.exe may cause a false positive. Filter based endpoint usage, command line arguments, or process lineage. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1218/009/ - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.009/T1218.009.md - -* https://lolbas-project.github.io/lolbas/Binaries/Regsvcs/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.009/atomic_red_team/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Detect regsvcs with network connection=== -The following analytic identifies Regsvcs.exe with a network connection to a public IP address, exluding private IP space. This particular technique has been used in the wild to bypass application control products. Regasm.exe and Regsvcs.exe are signed by Microsoft. By contacting a remote command and control server, the adversary will have the ability to escalate privileges and complete the objectives. During investigation, identify and retrieve the content being loaded. Review parallel processes for additional suspicious behavior. Gather any other file modifications and review accordingly. Review the reputation of the remote IP or domain and block as needed. regsvcs.exe and regasm.exe are natively found in C:\Windows\Microsoft.NET\Framework\v*\regasm|regsvcs.exe and C:\Windows\Microsoft.NET\Framework64\v*\regasm|regsvcs.exe. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/009/ T1218.009] -* '''Last Updated''': 2021-02-16 - -
-
- -====Search==== -`sysmon` EventID=3 dest_ip!=10.0.0.0/12 dest_ip!=172.16.0.0/12 dest_ip!=192.168.0.0/16 process_name=regsvcs.exe -| rename Computer as dest -| stats count min(_time) as firstTime max(_time) as lastTime by dest, User, process_name, src_ip, dest_host, dest_ip -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_regsvcs_with_network_connection_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Regsvcs_Regasm_Activity|Suspicious Regsvcs Regasm Activity]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -====Required field==== - -* _time - -* EventID - -* dest_ip - -* process_name - -* Computer - -* User - -* src_ip - -* dest_host - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1218 -| Signed Binary Proxy Execution -| Defense Evasion -|- -| T1218.009 -| Regsvcs/Regasm -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Although unlikely, limited instances of regsvcs.exe may cause a false positive. Filter based endpoint usage, command line arguments, or process lineage. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1218/009/ - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.009/T1218.009.md - -* https://lolbas-project.github.io/lolbas/Binaries/Regsvcs/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.009/atomic_red_team/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Detect regsvcs with no command line arguments=== -The following analytic identifies regsvcs.exe with no command line arguments. This particular behavior occurs when another process injects into regsvcs.exe, no command line arguments will be present. During investigation, identify any network connections and parallel processes. Identify any suspicious module loads related to credential dumping or file writes. Regasm.exe are natively found in C:\Windows\Microsoft.NET\Framework\v*\regasm|regsvcs.exe and C:\Windows\Microsoft.NET\Framework64\v*\regasm|regsvcs.exe. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/009/ T1218.009] -* '''Last Updated''': 2021-09-20 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where `process_regsvcs` by _time span=1h Processes.process_id Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| regex process="(regsvcs\.exe.{0,4}$)" -| `detect_regsvcs_with_no_command_line_arguments_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Regsvcs_Regasm_Activity|Suspicious Regsvcs Regasm Activity]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1218 -| Signed Binary Proxy Execution -| Defense Evasion -|- -| T1218.009 -| Regsvcs/Regasm -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Although unlikely, limited instances of regsvcs.exe may cause a false positive. Filter based endpoint usage, command line arguments, or process lineage. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1218/009/ - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.009/T1218.009.md - -* https://lolbas-project.github.io/lolbas/Binaries/Regsvcs/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.009/atomic_red_team/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Detect regsvr32 application control bypass=== -Adversaries may abuse Regsvr32.exe to proxy execution of malicious code. Regsvr32.exe is a command-line program used to register and unregister object linking and embedding controls, including dynamic link libraries (DLLs), on Windows systems. Regsvr32.exe is also a Microsoft signed binary.This variation of the technique is often referred to as a "Squiblydoo" attack. \ -Upon investigating, look for network connections to remote destinations (internal or external). Be cautious to modify the query to look for "scrobj.dll", the ".dll" is not required to load scrobj. "scrobj.dll" will be loaded by "regsvr32.exe" upon execution. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/010/ T1218.010] -* '''Last Updated''': 2021-01-28 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_regsvr32` Processes.process=*scrobj* by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.original_file_name Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_regsvr32_application_control_bypass_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Regsvr32_Activity|Suspicious Regsvr32 Activity]] - -* [[Documentation:ESSOC:stories:UseCase#Cobalt_Strike|Cobalt Strike]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1218 -| Signed Binary Proxy Execution -| Defense Evasion -|- -| T1218.010 -| Regsvr32 -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Limited false positives related to third party software registering .DLL's. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1218/010/ - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.010/T1218.010.md - -* https://lolbas-project.github.io/lolbas/Binaries/Regsvr32/ - -* https://support.microsoft.com/en-us/topic/how-to-use-the-regsvr32-tool-and-troubleshoot-regsvr32-error-messages-a98d960a-7392-e6fe-d90a-3f4e0cb543e5 - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.010/atomic_red_team/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Detect renamed 7-zip=== -The following analytic identifies renamed 7-Zip usage using Sysmon. At this stage of an attack, review parallel processes and file modifications for data that is staged or potentially have been exfiltrated. This analytic utilizes the OriginalFileName to capture the renamed process. During triage, validate this is the legitimate version of `7zip` by reviewing the PE metadata. In addition, review parallel processes for further suspicious behavior. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1560/001/ T1560.001], [https://attack.mitre.org/techniques/T1560/ T1560] -* '''Last Updated''': 2021-09-16 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.original_file_name=7z*.exe AND Processes.process_name!=7z*.exe) by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.original_file_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_renamed_7_zip_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Collection_and_Staging|Collection and Staging]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1560.001 -| Archive via Utility -| Collection -|- -| T1560 -| Archive Collected Data -| Collection -|} - - -====Kill Chain Phase==== - -* Exfiltration - - -====Known False Positives==== -Limited false positives, however this analytic will need to be modified for each environment if Sysmon is not used. - -====Reference==== - - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1560.001/T1560.001.md - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1560.001/archive_utility/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Detect renamed psexec=== -The following analytic identifies renamed instances of `PsExec.exe` being utilized on an endpoint. Most instances, it is highly probable to capture `Psexec.exe` or other SysInternal utility usage with the command-line argument of `-accepteula`. During triage, validate this is the legitimate version of `PsExec` by reviewing the PE metadata. In addition, review parallel processes for further suspicious behavior. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1569/ T1569], [https://attack.mitre.org/techniques/T1569/002/ T1569.002] -* '''Last Updated''': 2021-09-16 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_psexec` by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.original_file_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_renamed_psexec_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#SamSam_Ransomware|SamSam Ransomware]] - -* [[Documentation:ESSOC:stories:UseCase#DHS_Report_TA18-074A|DHS Report TA18-074A]] - -* [[Documentation:ESSOC:stories:UseCase#HAFNIUM_Group|HAFNIUM Group]] - -* [[Documentation:ESSOC:stories:UseCase#DarkSide_Ransomware|DarkSide Ransomware]] - -* [[Documentation:ESSOC:stories:UseCase#Lateral_Movement|Lateral Movement]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1569 -| System Services -| Execution -|- -| T1569.002 -| Service Execution -| Execution -|} - - -====Kill Chain Phase==== - -* Exploitation - -* Lateral Movement - -* Execution - - -====Known False Positives==== -Limited false positives should be present. It is possible some third party applications may use older versions of PsExec, filter as needed. - -====Reference==== - - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1569.002/T1569.002.yaml - -* https://redcanary.com/blog/threat-hunting-psexec-lateral-movement/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1569.002/atomic_red_team/windows-sysmon.log - - -''version'': 3 -
-
- ----- - -===Detect renamed rclone=== -The following analytic identifies the usage of `rclone.exe`, renamed, being used to exfiltrate data to a remote destination. RClone has been used by multiple ransomware groups to exfiltrate data. In many instances, it will be downloaded from the legitimate site and executed accordingly. During triage, isolate the endpoint and begin to review parallel processes for additional behavior. At this stage, the adversary may have staged data to be exfiltrated. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1020/ T1020] -* '''Last Updated''': 2021-09-16 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.original_file_name=rclone.exe AND Processes.process_name!=rclone.exe) by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.original_file_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_renamed_rclone_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#DarkSide_Ransomware|DarkSide Ransomware]] - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1020 -| Automated Exfiltration -| Exfiltration -|} - - -====Kill Chain Phase==== - -* Exfiltration - - -====Known False Positives==== -False positives should be limited as this analytic identifies renamed instances of `rclone.exe`. Filter as needed if there is a legitimate business use case. - -====Reference==== - - -* https://redcanary.com/blog/rclone-mega-extortion/ - -* https://www.mandiant.com/resources/shining-a-light-on-darkside-ransomware-operations - -* https://thedfirreport.com/2021/03/29/sodinokibi-aka-revil-ransomware/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1020/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Detect renamed winrar=== -The following analtyic identifies renamed instances of `WinRAR.exe`. In most cases, it is not common for WinRAR to be used renamed, however it is common to be installed by a third party application and executed from a non-standard path. During triage, validate additional metadata from the binary that this is `WinRAR`. Review parallel processes and file modifications. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1560/001/ T1560.001], [https://attack.mitre.org/techniques/T1560/ T1560] -* '''Last Updated''': 2021-09-16 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.original_file_name=WinRAR.exe (Processes.process_name!=rar.exe OR Processes.process_name!=winrar.exe) by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.original_file_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_renamed_winrar_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Collection_and_Staging|Collection and Staging]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1560.001 -| Archive via Utility -| Collection -|- -| T1560 -| Archive Collected Data -| Collection -|} - - -====Kill Chain Phase==== - -* Exploitation - -* Exfiltration - - -====Known False Positives==== -Unknown. It is possible third party applications use renamed instances of WinRAR. - -====Reference==== - - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1560.001/T1560.001.md - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1560.001/archive_utility/windows-sysmon.log - - -''version'': 3 -
-
- ----- - -===Detect rundll32 application control bypass - advpack=== -The following analytic identifies rundll32.exe loading advpack.dll and ieadvpack.dll by calling the LaunchINFSection function on the command line. This particular technique will load script code from a file. Upon a successful execution, the following module loads may occur - clr.dll, jscript.dll and scrobj.dll. During investigation, identify script content origination. Generally, a child process will spawn from rundll32.exe, but that may be bypassed based on script code contents. Rundll32.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. During investigation, review any network connections and obtain the script content executed. It's possible other files are on disk. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/011/ T1218.011] -* '''Last Updated''': 2021-02-04 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_rundll32` Processes.process=*advpack* by Processes.dest Processes.user Processes.parent_process_name Processes.original_file_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_rundll32_application_control_bypass___advpack_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Rundll32_Activity|Suspicious Rundll32 Activity]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1218 -| Signed Binary Proxy Execution -| Defense Evasion -|- -| T1218.011 -| Rundll32 -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Although unlikely, some legitimate applications may use advpack.dll or ieadvpack.dll, triggering a false positive. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1218/011/ - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.011/T1218.011.md - -* https://lolbas-project.github.io/lolbas/Binaries/Rundll32 - -* https://lolbas-project.github.io/lolbas/Libraries/Advpack/ - -* https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.011/atomic_red_team/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Detect rundll32 application control bypass - setupapi=== -The following analytic identifies rundll32.exe loading setupapi.dll and iesetupapi.dll by calling the LaunchINFSection function on the command line. This particular technique will load script code from a file. Upon a successful execution, the following module loads may occur - clr.dll, jscript.dll and scrobj.dll. During investigation, identify script content origination. Generally, a child process will spawn from rundll32.exe, but that may be bypassed based on script code contents. Rundll32.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. During investigation, review any network connections and obtain the script content executed. It's possible other files are on disk. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/011/ T1218.011] -* '''Last Updated''': 2021-02-04 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_rundll32` Processes.process=*setupapi* by Processes.dest Processes.user Processes.parent_process_name Processes.original_file_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_rundll32_application_control_bypass___setupapi_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Rundll32_Activity|Suspicious Rundll32 Activity]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1218 -| Signed Binary Proxy Execution -| Defense Evasion -|- -| T1218.011 -| Rundll32 -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Although unlikely, some legitimate applications may use setupapi triggering a false positive. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1218/011/ - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.011/T1218.011.md - -* https://lolbas-project.github.io/lolbas/Binaries/Rundll32 - -* https://lolbas-project.github.io/lolbas/Libraries/Setupapi/ - -* https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.011/atomic_red_team/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Detect rundll32 application control bypass - syssetup=== -The following analytic identifies rundll32.exe loading syssetup.dll by calling the LaunchINFSection function on the command line. This particular technique will load script code from a file. Upon a successful execution, the following module loads may occur - clr.dll, jscript.dll and scrobj.dll. During investigation, identify script content origination. Generally, a child process will spawn from rundll32.exe, but that may be bypassed based on script code contents. Rundll32.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. During investigation, review any network connections and obtain the script content executed. It's possible other files are on disk. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/011/ T1218.011] -* '''Last Updated''': 2021-02-04 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_rundll32` Processes.process=*syssetup* by Processes.dest Processes.user Processes.parent_process_name Processes.original_file_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_rundll32_application_control_bypass___syssetup_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Rundll32_Activity|Suspicious Rundll32 Activity]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1218 -| Signed Binary Proxy Execution -| Defense Evasion -|- -| T1218.011 -| Rundll32 -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Although unlikely, some legitimate applications may use syssetup.dll, triggering a false positive. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1218/011/ - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.011/T1218.011.md - -* https://lolbas-project.github.io/lolbas/Binaries/Rundll32 - -* https://lolbas-project.github.io/lolbas/Libraries/Syssetup/ - -* https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.011/atomic_red_team/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Detect rundll32 inline hta execution=== -The following analytic identifies "rundll32.exe" execution with inline protocol handlers. "JavaScript", "VBScript", and "About" are the only supported options when invoking HTA content directly on the command-line. This type of behavior is commonly observed with fileless malware or application whitelisting bypass techniques. The search will return the first time and last time these command-line arguments were used for these executions, as well as the target system, the user, process "rundll32.exe" and its parent process. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/005/ T1218.005] -* '''Last Updated''': 2021-01-20 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count values(Processes.process) as process values(Processes.parent_process) as parent_process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_rundll32` (Processes.process=*vbscript* OR Processes.process=*javascript* OR Processes.process=*about*) by Processes.user Processes.process_name Processes.parent_process_name Processes.original_file_name Processes.dest -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_rundll32_inline_hta_execution_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_MSHTA_Activity|Suspicious MSHTA Activity]] - -* [[Documentation:ESSOC:stories:UseCase#NOBELIUM_Group|NOBELIUM Group]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1218 -| Signed Binary Proxy Execution -| Defense Evasion -|- -| T1218.005 -| Mshta -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Although unlikely, some legitimate applications may exhibit this behavior, triggering a false positive. - -====Reference==== - - -* https://github.com/redcanaryco/AtomicTestHarnesses - -* https://redcanary.com/blog/introducing-atomictestharnesses/ - -* https://docs.microsoft.com/en-us/windows/win32/search/-search-3x-wds-extidx-prot-implementing - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.005/atomic_red_team/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Detect sharphound command-line arguments=== -The following analytic identifies common command-line arguments used by SharpHound `-collectionMethod` and `invoke-bloodhound`. Being the script is FOSS, function names may be modified, but these changes are dependent upon the operator. In most instances the defaults are used. This analytic works to identify the common command-line attributes used. It does not cover the entirety of every argument in order to avoid false positives. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/002/ T1087.002], [https://attack.mitre.org/techniques/T1069/001/ T1069.001], [https://attack.mitre.org/techniques/T1482/ T1482], [https://attack.mitre.org/techniques/T1087/001/ T1087.001], [https://attack.mitre.org/techniques/T1087/ T1087], [https://attack.mitre.org/techniques/T1069/002/ T1069.002], [https://attack.mitre.org/techniques/T1069/ T1069] -* '''Last Updated''': 2021-06-01 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process IN ("*-collectionMethod*","*invoke-bloodhound*") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_sharphound_command_line_arguments_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Discovery_Techniques|Discovery Techniques]] - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1087.002 -| Domain Account -| Discovery -|- -| T1069.001 -| Local Groups -| Discovery -|- -| T1482 -| Domain Trust Discovery -| Discovery -|- -| T1087.001 -| Local Account -| Discovery -|- -| T1087 -| Account Discovery -| Discovery -|- -| T1069.002 -| Domain Groups -| Discovery -|- -| T1069 -| Permission Groups Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -False positives should be limited as the arguments used are specific to SharpHound. Filter as needed or add more command-line arguments as needed. - -====Reference==== - - -* https://attack.mitre.org/software/S0521/ - -* https://thedfirreport.com/?s=bloodhound - -* https://github.com/BloodHoundAD/BloodHound/tree/master/Collectors - -* https://github.com/BloodHoundAD/SharpHound3 - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1059.001/T1059.001.md#atomic-test-2---run-bloodhound-from-local-disk - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/sharphound/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Detect sharphound file modifications=== -SharpHound is used as a reconnaissance collector, ingestor, for BloodHound. SharpHound will query the domain controller and begin gathering all the data related to the domain and trusts. For output, it will drop a .zip file upon completion following a typical pattern that is often not changed. This analytic focuses on the default file name scheme. Note that this may be evaded with different parameters within SharpHound, but that depends on the operator. `-randomizefilenames` and `-encryptzip` are two examples. In addition, executing SharpHound via .exe or .ps1 without any command-line arguments will still perform activity and dump output to the default filename. Example default filename `20210601181553_BloodHound.zip`. SharpHound creates multiple temp files following the same pattern `20210601182121_computers.json`, `domains.json`, `gpos.json`, `ous.json` and `users.json`. Tuning may be required, or remove these json's entirely if it is too noisy. During traige, review parallel processes for further suspicious behavior. Typically, the process executing the `.ps1` ingestor will be PowerShell. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/002/ T1087.002], [https://attack.mitre.org/techniques/T1069/001/ T1069.001], [https://attack.mitre.org/techniques/T1482/ T1482], [https://attack.mitre.org/techniques/T1087/001/ T1087.001], [https://attack.mitre.org/techniques/T1087/ T1087], [https://attack.mitre.org/techniques/T1069/002/ T1069.002], [https://attack.mitre.org/techniques/T1069/ T1069] -* '''Last Updated''': 2021-05-27 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Filesystem where Filesystem.file_name IN ("*bloodhound.zip", "*_computers.json", "*_gpos.json", "*_domains.json", "*_users.json", "*_groups.json") by Filesystem.file_create_time Filesystem.process_id Filesystem.file_name Filesystem.file_path Filesystem.dest -| `drop_dm_object_name(Filesystem)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_sharphound_file_modifications_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Discovery_Techniques|Discovery Techniques]] - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on file modifications that include the name of the process, and file, responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Filesystem` node. - -====Required field==== - -* _time - -* file_path - -* dest - -* file_name - -* process_id - -* file_create_time - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1087.002 -| Domain Account -| Discovery -|- -| T1069.001 -| Local Groups -| Discovery -|- -| T1482 -| Domain Trust Discovery -| Discovery -|- -| T1087.001 -| Local Account -| Discovery -|- -| T1087 -| Account Discovery -| Discovery -|- -| T1069.002 -| Domain Groups -| Discovery -|- -| T1069 -| Permission Groups Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -False positives should be limited as the analytic is specific to a filename with extension .zip. Filter as needed. - -====Reference==== - - -* https://attack.mitre.org/software/S0521/ - -* https://thedfirreport.com/?s=bloodhound - -* https://github.com/BloodHoundAD/BloodHound/tree/master/Collectors - -* https://github.com/BloodHoundAD/SharpHound3 - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1059.001/T1059.001.md#atomic-test-2---run-bloodhound-from-local-disk - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/sharphound/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Detect sharphound usage=== -The following analytic identifies SharpHound binary usage by using the original filena,e. In addition to renaming the PE, other coverage is available to detect command-line arguments. This particular analytic looks for the original_file_name of `SharpHound.exe` and the process name. It is possible older instances of SharpHound.exe have different original filenames. Dependent upon the operator, the code may be re-compiled and the attributes removed or changed to anything else. During triage, review the metadata of the binary in question. Review parallel processes for suspicious behavior. Identify the source of this binary. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/002/ T1087.002], [https://attack.mitre.org/techniques/T1069/001/ T1069.001], [https://attack.mitre.org/techniques/T1482/ T1482], [https://attack.mitre.org/techniques/T1087/001/ T1087.001], [https://attack.mitre.org/techniques/T1087/ T1087], [https://attack.mitre.org/techniques/T1069/002/ T1069.002], [https://attack.mitre.org/techniques/T1069/ T1069] -* '''Last Updated''': 2021-05-27 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name=sharphound.exe OR Processes.original_file_name=SharpHound.exe) by Processes.dest Processes.user Processes.parent_process_name Processes.original_file_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_sharphound_usage_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Discovery_Techniques|Discovery Techniques]] - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1087.002 -| Domain Account -| Discovery -|- -| T1069.001 -| Local Groups -| Discovery -|- -| T1482 -| Domain Trust Discovery -| Discovery -|- -| T1087.001 -| Local Account -| Discovery -|- -| T1087 -| Account Discovery -| Discovery -|- -| T1069.002 -| Domain Groups -| Discovery -|- -| T1069 -| Permission Groups Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -False positives should be limited as this is specific to a file attribute not used by anything else. Filter as needed. - -====Reference==== - - -* https://attack.mitre.org/software/S0521/ - -* https://thedfirreport.com/?s=bloodhound - -* https://github.com/BloodHoundAD/BloodHound/tree/master/Collectors - -* https://github.com/BloodHoundAD/SharpHound3 - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1059.001/T1059.001.md#atomic-test-2---run-bloodhound-from-local-disk - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/sharphound/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Detect use of cmd exe to launch script interpreters=== -This search looks for the execution of the cscript.exe or wscript.exe processes, with a parent of cmd.exe. The search will return the count, the first and last time this execution was seen on a machine, the user, and the destination of the machine - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/ T1059], [https://attack.mitre.org/techniques/T1059/003/ T1059.003] -* '''Last Updated''': 2020-07-21 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count values(Processes.process) min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name="cmd.exe" (Processes.process_name=cscript.exe OR Processes.process_name =wscript.exe) by Processes.parent_process Processes.process_name Processes.user Processes.dest -| `drop_dm_object_name("Processes")` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -| `detect_use_of_cmd_exe_to_launch_script_interpreters_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Emotet_Malware__DHS_Report_TA18-201A_|Emotet Malware DHS Report TA18-201A ]] - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Command-Line_Executions|Suspicious Command-Line Executions]] - - -====How To Implement==== -To successfully implement this search, you must be ingesting data that records process activity from your hosts to populate the endpoint data model in the processes node. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -====Required field==== - -* _time - -* Processes.process - -* Processes.parent_process_name - -* Processes.process_name - -* Processes.parent_process - -* Processes.user - -* Processes.dest - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1059 -| Command and Scripting Interpreter -| Execution -|- -| T1059.003 -| Windows Command Shell -| Execution -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Some legitimate applications may exhibit this behavior. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.003/cmd_spawns_cscript/windows-sysmon.log - - -''version'': 4 -
-
- ----- - -===Detect wmi event subscription persistence=== -The following analytic identifies the use of WMI Event Subscription to establish persistence or perform privilege escalation. WMI can be used to install event filters, providers, consumers, and bindings that execute code when a defined event occurs. WMI subscription execution is proxied by the WMI Provider Host process (WmiPrvSe.exe) and thus may result in elevated SYSTEM privileges. This analytic is restricted by commonly added process execution and a path. If the volume is low enough, remove the values and flag on any new subscriptions.\ -All event subscriptions have three components \ -1. Filter - WQL Query for the events we want. EventID equals 19 \ -1. Consumer - An action to take upon triggering the filter. EventID equals 20 \ -1. Binding - Registers a filter to a consumer. EventID equals 21 \ -Monitor for the creation of new WMI EventFilter, EventConsumer, and FilterToConsumerBinding. It may be pertinent to review all 3 to identify the flow of execution. In addition, EventCode 4104 may assist with any other PowerShell script usage that registered the subscription. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1546/003/ T1546.003], [https://attack.mitre.org/techniques/T1546/ T1546] -* '''Last Updated''': 2021-06-16 - -
-
- -====Search==== -`sysmon` EventID=20 -| stats count min(_time) as firstTime max(_time) as lastTime by Computer User Destination -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_wmi_event_subscription_persistence_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_WMI_Use|Suspicious WMI Use]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with that provide WMI Event Subscription from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA and have enabled EventID 19, 20 and 21. Tune and filter known good to limit the volume. - -====Required field==== - -* _time - -* Destination - -* Computer - -* User - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1546.003 -| Windows Management Instrumentation Event Subscription -| Privilege Escalation, Persistence -|- -| T1546 -| Event Triggered Execution -| Privilege Escalation, Persistence -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -It is possible some applications will create a consumer and may be required to be filtered. For tuning, add any additional LOLBin's for further depth of coverage. - -====Reference==== - - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1546.003/T1546.003.md - -* https://www.eideon.com/2018-03-02-THL03-WMIBackdoors/ - -* https://github.com/trustedsec/SysmonCommunityGuide/blob/master/WMI-events.md - -* https://in.security/an-intro-into-abusing-and-identifying-wmi-event-subscriptions-for-persistence/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.003/atomic_red_team/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Detect mshta inline hta execution=== -The following analytic identifies "mshta.exe" execution with inline protocol handlers. "JavaScript", "VBScript", and "About" are the only supported options when invoking HTA content directly on the command-line. The search will return the first time and last time these command-line arguments were used for these executions, as well as the target system, the user, process "mshta.exe" and its parent process. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/005/ T1218.005] -* '''Last Updated''': 2021-09-16 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count values(Processes.process) as process values(Processes.parent_process) as parent_process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_mshta` (Processes.process=*vbscript* OR Processes.process=*javascript* OR Processes.process=*about*) by Processes.user Processes.process_name Processes.original_file_name Processes.parent_process_name Processes.dest -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_mshta_inline_hta_execution_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_MSHTA_Activity|Suspicious MSHTA Activity]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1218 -| Signed Binary Proxy Execution -| Defense Evasion -|- -| T1218.005 -| Mshta -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Although unlikely, some legitimate applications may exhibit this behavior, triggering a false positive. - -====Reference==== - - -* https://github.com/redcanaryco/AtomicTestHarnesses - -* https://redcanary.com/blog/introducing-atomictestharnesses/ - -* https://docs.microsoft.com/en-us/windows/win32/search/-search-3x-wds-extidx-prot-implementing - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.005/atomic_red_team/windows-sysmon.log - - -''version'': 6 -
-
- ----- - -===Detect mshta renamed=== -The following analytic identifies renamed instances of mshta.exe executing. Mshta.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. This analytic utilizes the internal name of the PE to identify if is the legitimate mshta binary. Further analysis should be performed to review the executed content and validation it is the real mshta. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/005/ T1218.005] -* '''Last Updated''': 2021-09-16 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_mshta` by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.original_file_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_mshta_renamed_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_MSHTA_Activity|Suspicious MSHTA Activity]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1218 -| Signed Binary Proxy Execution -| Defense Evasion -|- -| T1218.005 -| Mshta -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Although unlikely, some legitimate applications may use a moved copy of mshta.exe, but never renamed, triggering a false positive. - -====Reference==== - - -* https://github.com/redcanaryco/AtomicTestHarnesses - -* https://redcanary.com/blog/introducing-atomictestharnesses/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.005/atomic_red_team/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Detect processes used for system network configuration discovery=== -This search looks for fast execution of processes used for system network configuration discovery on the endpoint. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1016/ T1016] -* '''Last Updated''': 2020-11-10 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count values(Processes.process) as process values(Processes.parent_process) as parent_process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where NOT Processes.user IN ("","unknown") by Processes.dest Processes.process_name Processes.user _time -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `drop_dm_object_name(Processes)` -| search `system_network_configuration_discovery_tools` -| transaction dest connected=false maxpause=5m -|where eventcount>=5 -| table firstTime lastTime dest user process_name process parent_process eventcount -| `detect_processes_used_for_system_network_configuration_discovery_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Unusual_Processes|Unusual Processes]] - - -====How To Implement==== -You must be ingesting data that records registry activity from your hosts to populate the Endpoint data model in the processes node. This is typically populated via endpoint detection-and-response product, such as Carbon Black, or endpoint data sources, such as Sysmon. The data used for this search is usually generated via logs that report reads and writes to the registry or that are populated via Windows event logs, after enabling process tracking in your Windows audit settings. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1016 -| System Network Configuration Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Installation - -* Command and Control - -* Actions on Objectives - - -====Known False Positives==== -It is uncommon for normal users to execute a series of commands used for network discovery. System administrators often use scripts to execute these commands. These can generate false positives. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1016/discovery_commands/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Detection of tools built by nirsoft=== -This search looks for specific command-line arguments that may indicate the execution of tools made by Nirsoft, which are legitimate, but may be abused by attackers. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1072/ T1072] -* '''Last Updated''': 2020-07-21 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) values(Processes.process) as process max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process="* /stext *" OR Processes.process="* /scomma *" ) by Processes.parent_process Processes.process_name Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -| `detection_of_tools_built_by_nirsoft_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Emotet_Malware__DHS_Report_TA18-201A_|Emotet Malware DHS Report TA18-201A ]] - - -====How To Implement==== -You must be ingesting endpoint data that tracks process activity, including parent-child relationships from your endpoints to populate the Endpoint data model in the Processes node. The command-line arguments are mapped to the "process" field in the Endpoint data model. - -====Required field==== - -* _time - -* Processes.process - -* Processes.parent_process - -* Processes.process_name - -* Processes.user - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1072 -| Software Deployment Tools -| Execution, Lateral Movement -|} - - -====Kill Chain Phase==== - -* Installation - -* Actions on Objectives - - -====Known False Positives==== -While legitimate, these NirSoft tools are prone to abuse. You should verfiy that the tool was used for a legitimate purpose. - -====Reference==== - - -====Test Dataset==== - - -''version'': 3 -
-
- ----- - -===Disable amsi through registry=== -this search is to identify modification in registry to disable AMSI windows feature to evade detections. This technique was seen in several ransomware, RAT and even APT to impaire defenses of the compromise machine and to be able to execute payload with minimal alert as much as possible. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001], [https://attack.mitre.org/techniques/T1562/ T1562] -* '''Last Updated''': 2021-06-22 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows Script\\Settings\\AmsiEnable" Registry.registry_value_name = "DWORD (0x00000000)" by Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.dest -| `drop_dm_object_name(Registry)` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -| `disable_amsi_through_registry_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. - -====Required field==== - -* _time - -* Registry.registry_key_name - -* Registry.registry_path - -* Registry.user - -* Registry.dest - -* Registry.registry_value_name - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1562.001 -| Disable or Modify Tools -| Defense Evasion -|- -| T1562 -| Impair Defenses -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -network operator may disable this feature of windows but not so common. - -====Reference==== - - -* https://blog.f-secure.com/hunting-for-amsi-bypasses/ - -* https://gist.github.com/rxwx/8955e5abf18dc258fd6b43a3a7f4dbf9 - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/data2/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Disable etw through registry=== -this search is to identify modification in registry to disable ETW windows feature to evade detections. This technique was seen in several ransomware, RAT and even APT to impaire defenses of the compromise machine and to be able to execute payload with minimal alert as much as possible. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001], [https://attack.mitre.org/techniques/T1562/ T1562] -* '''Last Updated''': 2021-06-22 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\.NETFramework\\ETWEnabled" Registry.registry_value_name = "DWORD (0x00000000)" by Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.dest -| `drop_dm_object_name(Registry)` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -| `disable_etw_through_registry_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. - -====Required field==== - -* _time - -* Registry.registry_key_name - -* Registry.registry_path - -* Registry.user - -* Registry.dest - -* Registry.registry_value_name - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1562.001 -| Disable or Modify Tools -| Defense Evasion -|- -| T1562 -| Impair Defenses -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -network operator may disable this feature of windows but not so common. - -====Reference==== - - -* https://app.any.run/tasks/c0f98850-af65-4352-9746-fbebadee4f05/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/data2/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Disable logs using wevtutil=== -This search is to detect execution of wevtutil.exe to disable logs. This technique was seen in several ransomware to disable the event logs to evade alerts and detections. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1070/ T1070], [https://attack.mitre.org/techniques/T1070/001/ T1070.001] -* '''Last Updated''': 2021-06-10 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = "wevtutil.exe" Processes.process = "*sl*" Processes.process = "*/e:false*" by Processes.parent_process_name Processes.parent_process Processes.process_name Processes.process Processes.dest Processes.user Processes.process_id Processes.process_guid -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `disable_logs_using_wevtutil_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -====Required field==== - -* _time - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.process_name - -* Processes.process - -* Processes.dest - -* Processes.user - -* Processes.process_id - -* Processes.process_guid - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1070 -| Indicator Removal on Host -| Defense Evasion -|- -| T1070.001 -| Clear Windows Event Logs -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -network operator may disable audit event logs for debugging purposes. - -====Reference==== - - -* https://www.bleepingcomputer.com/news/security/new-ransom-x-ransomware-used-in-texas-txdot-cyberattack/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/data1/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Disable net user account=== -This analytic will identify a suspicious command-line that disables a user account using the `net.exe` utility native to Windows. This technique may used by the adversaries to interrupt availability of such users to do their malicious act. - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1489/ T1489] -* '''Last Updated''': 2021-06-21 - -
-
- -====Search==== - -| from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line IS NOT NULL AND like(cmd_line, "%/active:no%") AND (process_name="net1.exe" OR process_name="net.exe") -| eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#XMRig|XMRig]] - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed net.exe/net1.exe may be used. - -====Required field==== - -* _time - -* dest_device_id - -* process_name - -* parent_process_name - -* process_path - -* dest_user_id - -* process - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1489 -| Service Stop -| Impact -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -network operator may use this approach to quickly disable an account but not a common practice. - -====Reference==== - - -* https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/ssa_data1/net_user_dis.log - - -''version'': 2 -
-
- ----- - -===Disable registry tool=== -This search identifies modification of registry to disable the regedit or registry tools of the windows operating system. Since registry tool is a swiss knife in analyzing registry, malware such as RAT or trojan Spy disable this application to prevent the removal of their registry entry such as persistence, file less components and defense evasion. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001], [https://attack.mitre.org/techniques/T1562/ T1562] -* '''Last Updated''': 2021-03-31 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\DisableRegistryTools" Registry.registry_value_name = "DWORD (0x00000001)" by Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.dest -| `drop_dm_object_name(Registry)` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -| `disable_registry_tool_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Defense_Evasion_Tactics|Windows Defense Evasion Tactics]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. - -====Required field==== - -* _time - -* Registry.registry_key_name - -* Registry.registry_path - -* Registry.user - -* Registry.dest - -* Registry.registry_value_name - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1562.001 -| Disable or Modify Tools -| Defense Evasion -|- -| T1562 -| Impair Defenses -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -admin may disable this application for non technical user. - -====Reference==== - - -* https://any.run/report/ea4ea08407d4ee72e009103a3b77e5a09412b722fdef67315ea63f22011152af/a866d7b1-c236-4f26-a391-5ae32213dfc4#registry - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-security.log - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-system.log - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Disable security logs using minint registry=== -This analytic is to detect a suspicious registry modification to disable security audit logs. This technique was shared by a researcher to disable Security logs of windows by adding this registry. The Windows will think it is WinPE and will not log any event to the Security Log - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1112/ T1112] -* '''Last Updated''': 2021-10-05 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*\\Control\\MiniNt\\*" by Registry.dest Registry.user Registry.registry_value_name Registry.registry_key_name Registry.registry_path Registry.registry_value_data -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `disable_security_logs_using_minint_registry_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Defense_Evasion_Tactics|Windows Defense Evasion Tactics]] - - -====How To Implement==== -To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. - -====Required field==== - -* _time - -* Registry.dest - -* Registry.user - -* Registry.registry_value_name - -* Registry.registry_key_name - -* Registry.registry_path - -* Registry.registry_value_data - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1112 -| Modify Registry -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Unknown. - -====Reference==== - - -* https://twitter.com/0gtweet/status/1182516740955226112 - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1112/minint_reg/sysmon.log - - -''version'': 1 -
-
- ----- - -===Disable show hidden files=== -The following analytic is to identify a modification in the Windows registry to prevent users from seeing all the files with hidden attributes. This event or techniques are known on some worm and trojan spy malware that will drop hidden files on the infected machine. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1564/001/ T1564.001], [https://attack.mitre.org/techniques/T1562/001/ T1562.001], [https://attack.mitre.org/techniques/T1564/ T1564], [https://attack.mitre.org/techniques/T1562/ T1562] -* '''Last Updated''': 2021-03-31 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where (Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Hidden" OR Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\HideFileExt" Registry.registry_value_name = "DWORD (0x00000001)") OR (Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowSuperHidden" Registry.registry_value_name = "DWORD (0x00000000)") by Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.dest -| `drop_dm_object_name(Registry)` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -| `disable_show_hidden_files_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Defense_Evasion_Tactics|Windows Defense Evasion Tactics]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. - -====Required field==== - -* _time - -* Registry.registry_key_name - -* Registry.registry_path - -* Registry.user - -* Registry.dest - -* Registry.registry_value_nam - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1564.001 -| Hidden Files and Directories -| Defense Evasion -|- -| T1562.001 -| Disable or Modify Tools -| Defense Evasion -|- -| T1564 -| Hide Artifacts -| Defense Evasion -|- -| T1562 -| Impair Defenses -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://www.sophos.com/en-us/threat-center/threat-analyses/viruses-and-spyware/W32~Tiotua-P/detailed-analysis.aspx - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-security.log - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-system.log - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Disable uac remote restriction=== -This analytic is to detect a suspicious modification of registry to disable UAC remote restriction. This technique was well documented in Microsoft page where attacker may modify this registry value to bypassed UAC feature of windows host. This is a good indicator that some tries to bypassed UAC to suspicious process or gain privilege escalation. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1548/002/ T1548.002], [https://attack.mitre.org/techniques/T1548/ T1548] -* '''Last Updated''': 2021-09-29 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path ="*\\CurrentVersion\\Policies\\System*" Registry.registry_value_name="LocalAccountTokenFilterPolicy" Registry.registry_value_data="0x00000001" by Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `drop_dm_object_name(Registry)` -| `disable_uac_remote_restriction_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Defense_Evasion_Tactics|Windows Defense Evasion Tactics]] - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Windows_Registry_Activities|Suspicious Windows Registry Activities]] - - -====How To Implement==== -To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. - -====Required field==== - -* _time - -* Registry.dest - -* Registry.user - -* Registry.registry_path - -* Registry.registry_key_name - -* Registry.registry_value_name - -* Registry.registry_value_data - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1548.002 -| Bypass User Account Control -| Privilege Escalation, Defense Evasion -|- -| T1548 -| Abuse Elevation Control Mechanism -| Privilege Escalation, Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -admin may set this policy for non-critical machine. - -====Reference==== - - -* https://docs.microsoft.com/en-us/troubleshoot/windows-server/windows-security/user-account-control-and-remote-restriction - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.002/LocalAccountTokenFilterPolicy/sysmon.log - - -''version'': 1 -
-
- ----- - -===Disable windows app hotkeys=== -This analytic detects a suspicious registry modification to disable Windows hotkey (shortcut keys) for native Windows applications. This technique is commonly used to disable certain or several Windows applications like `taskmgr.exe` and `cmd.exe`. This technique is used to impair the analyst in analyzing and removing the attacker implant in compromised systems. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001], [https://attack.mitre.org/techniques/T1562/ T1562] -* '''Last Updated''': 2021-05-05 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count values(Registry.registry_key_name) as registry_key_name values(Registry.registry_path) as registry_path min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*\\Windows NT\\CurrentVersion\\Image File Execution Options\\*" AND Registry.registry_value_name = "HotKey Disabled" AND Registry.registry_key_name = "Debugger" by Registry.dest Registry.user Registry.registry_value_name -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `drop_dm_object_name(Registry)` -| `disable_windows_app_hotkeys_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#XMRig|XMRig]] - - -====How To Implement==== -To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as CarbonBlack or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. - -====Required field==== - -* _time - -* Registry.registry_key_name - -* Registry.registry_path - -* Registry.registry_value_name - -* Registry.dest Registry.user - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1562.001 -| Disable or Modify Tools -| Defense Evasion -|- -| T1562 -| Impair Defenses -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/hotkey_disabled_hidden_user/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Disable windows behavior monitoring=== -This search is to identifies a modification in registry to disable the windows denfender real time behavior monitoring. This event or technique is commonly seen in RAT, bot, or Trojan to disable AV to evade detections. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001], [https://attack.mitre.org/techniques/T1562/ T1562] -* '''Last Updated''': 2021-03-31 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableBehaviorMonitoring" OR Registry.registry_path= "*\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableOnAccessProtection" OR Registry.registry_path= "*\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableScanOnRealtimeEnable" OR Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableRealtimeMonitoring" OR Registry.registry_path= "*\\Real-Time Protection\\DisableIntrusionPreventionSystem" OR Registry.registry_path= "*\\Real-Time Protection\\DisableIOAVProtection" OR Registry.registry_path= "*\\Real-Time Protection\\DisableScriptScanning" Registry.registry_value_name = "DWORD (0x00000001)" by Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.dest -| `drop_dm_object_name(Registry)` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -| `disable_windows_behavior_monitoring_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Defense_Evasion_Tactics|Windows Defense Evasion Tactics]] - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - -* [[Documentation:ESSOC:stories:UseCase#Revil_Ransomware|Revil Ransomware]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. - -====Required field==== - -* _time - -* Registry.registry_key_name - -* Registry.registry_path - -* Registry.user - -* Registry.dest - -* Registry.registry_value_name - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1562.001 -| Disable or Modify Tools -| Defense Evasion -|- -| T1562 -| Impair Defenses -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -admin or user may choose to disable this windows features. - -====Reference==== - - -* https://tccontre.blogspot.com/2020/01/remcos-rat-evading-windows-defender-av.html - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-security.log - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-system.log - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Disable windows smartscreen protection=== -The following search identifies a modification of registry to disable the smartscreen protection of windows machine. This is windows feature provide an early warning system against website that might engage in phishing attack or malware distribution. This modification are seen in RAT malware to cover their tracks upon downloading other of its component or other payload. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001], [https://attack.mitre.org/techniques/T1562/ T1562] -* '''Last Updated''': 2021-03-31 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\SmartScreenEnabled" Registry.registry_value_name = "Off" by Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.dest -| `drop_dm_object_name(Registry)` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -| `disable_windows_smartscreen_protection_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Defense_Evasion_Tactics|Windows Defense Evasion Tactics]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. - -====Required field==== - -* _time - -* Registry.registry_key_name - -* Registry.registry_path - -* Registry.user - -* Registry.dest - -* Registry.registry_value_nam - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1562.001 -| Disable or Modify Tools -| Defense Evasion -|- -| T1562 -| Impair Defenses -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -admin or user may choose to disable this windows features. - -====Reference==== - - -* https://tccontre.blogspot.com/2020/01/remcos-rat-evading-windows-defender-av.html - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-security.log - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-system.log - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Disabling cmd application=== -this search is to identify modification in registry to disable cmd prompt application. This technique is commonly seen in RAT, Trojan or WORM to prevent triaging or deleting there samples through cmd application which is one of the tool of analyst to traverse on directory and files. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001], [https://attack.mitre.org/techniques/T1562/ T1562] -* '''Last Updated''': 2021-03-31 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Policies\\Microsoft\\Windows\\System\\DisableCMD" Registry.registry_value_name = "DWORD (0x00000001)" by Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.dest -| `drop_dm_object_name(Registry)` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -| `disabling_cmd_application_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Defense_Evasion_Tactics|Windows Defense Evasion Tactics]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. - -====Required field==== - -* _time - -* Registry.registry_key_name - -* Registry.registry_path - -* Registry.user - -* Registry.dest - -* Registry.registry_value_name - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1562.001 -| Disable or Modify Tools -| Defense Evasion -|- -| T1562 -| Impair Defenses -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -admin may disable this application for non technical user. - -====Reference==== - - -* https://any.run/report/ea4ea08407d4ee72e009103a3b77e5a09412b722fdef67315ea63f22011152af/a866d7b1-c236-4f26-a391-5ae32213dfc4#registry - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-security.log - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-system.log - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Disabling controlpanel=== -this search is to identify registry modification to disable control panel window. This technique is commonly seen in malware to prevent their artifacts , persistence removed on the infected machine. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001], [https://attack.mitre.org/techniques/T1562/ T1562] -* '''Last Updated''': 2021-03-31 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoControlPanel" Registry.registry_value_name = "DWORD (0x00000001)" by Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.dest -| `drop_dm_object_name(Registry)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `disabling_controlpanel_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Defense_Evasion_Tactics|Windows Defense Evasion Tactics]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. - -====Required field==== - -* _time - -* Registry.registry_key_name - -* Registry.registry_path - -* Registry.user - -* Registry.dest - -* Registry.registry_value_name - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1562.001 -| Disable or Modify Tools -| Defense Evasion -|- -| T1562 -| Impair Defenses -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -admin may disable this application for non technical user. - -====Reference==== - - -* https://any.run/report/ea4ea08407d4ee72e009103a3b77e5a09412b722fdef67315ea63f22011152af/a866d7b1-c236-4f26-a391-5ae32213dfc4#registry - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-security.log - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-system.log - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Disabling firewall with netsh=== -This search is to identifies suspicious firewall disabling using netsh application. this technique is commonly seen in malware that tries to communicate or download its component or other payload to its C2 server. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001], [https://attack.mitre.org/techniques/T1562/ T1562] -* '''Last Updated''': 2021-03-31 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_netsh` Processes.process= "*firewall*" (Processes.process= "*off*" OR Processes.process= "*disable*") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `disabling_firewall_with_netsh_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Defense_Evasion_Tactics|Windows Defense Evasion Tactics]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1562.001 -| Disable or Modify Tools -| Defense Evasion -|- -| T1562 -| Impair Defenses -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -admin may disable firewall during testing or fixing network problem. - -====Reference==== - - -* https://tccontre.blogspot.com/2020/01/remcos-rat-evading-windows-defender-av.htm - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-security.log - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-system.log - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Disabling folderoptions windows feature=== -This search is to identify registry modification to disable folder options feature of windows to show hidden files, file extension and etc. This technique used by malware in combination if disabling show hidden files feature to hide their files and also to hide the file extension to lure the user base on file icons or fake file extensions. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001], [https://attack.mitre.org/techniques/T1562/ T1562] -* '''Last Updated''': 2021-03-31 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoFolderOptions" Registry.registry_value_name = "DWORD (0x00000001)" by Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.dest -| `drop_dm_object_name(Registry)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `disabling_folderoptions_windows_feature_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Defense_Evasion_Tactics|Windows Defense Evasion Tactics]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. - -====Required field==== - -* _time - -* Registry.registry_key_name - -* Registry.registry_path - -* Registry.user - -* Registry.dest - -* Registry.registry_value_name - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1562.001 -| Disable or Modify Tools -| Defense Evasion -|- -| T1562 -| Impair Defenses -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -admin may disable this application for non technical user. - -====Reference==== - - -* https://any.run/report/ea4ea08407d4ee72e009103a3b77e5a09412b722fdef67315ea63f22011152af/a866d7b1-c236-4f26-a391-5ae32213dfc4#registry - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-security.log - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-system.log - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Disabling net user account=== -This analytic will identify a suspicious command-line that disables a user account using the `net.exe` utility native to Windows. This technique may used by the adversaries to interrupt availability of such users to do their malicious act. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1531/ T1531] -* '''Last Updated''': 2021-05-04 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` values(Processes.process) as process values(Processes.parent_process) as parent_process values(Processes.process_id) as process_id count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_net` AND Processes.process="*user*" AND Processes.process="*/active:no*" by Processes.process_name Processes.original_file_name Processes.dest Processes.user Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `disabling_net_user_account_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#XMRig|XMRig]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1531 -| Account Access Removal -| Impact -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Disabling norun windows app=== -This search is to identify modification of registry to disable run application in window start menu. this application is known to be a helpful shortcut to windows OS user to run known application and also to execute some reg or batch script. This technique is used malware to make cleaning of its infection more harder by preventing known application run easily through run shortcut. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001], [https://attack.mitre.org/techniques/T1562/ T1562] -* '''Last Updated''': 2021-03-31 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoRun" Registry.registry_value_name = "DWORD (0x00000001)" by Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.dest -| `drop_dm_object_name(Registry)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `disabling_norun_windows_app_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Defense_Evasion_Tactics|Windows Defense Evasion Tactics]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. - -====Required field==== - -* _time - -* Registry.registry_key_name - -* Registry.registry_path - -* Registry.user - -* Registry.dest - -* Registry.registry_value_name - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1562.001 -| Disable or Modify Tools -| Defense Evasion -|- -| T1562 -| Impair Defenses -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -admin may disable this application for non technical user. - -====Reference==== - - -* https://any.run/report/ea4ea08407d4ee72e009103a3b77e5a09412b722fdef67315ea63f22011152af/a866d7b1-c236-4f26-a391-5ae32213dfc4#registry - -* https://blog.malwarebytes.com/detections/pum-optional-norun/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-security.log - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-system.log - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Disabling remote user account control=== -The search looks for modifications to registry keys that control the enforcement of Windows User Account Control (UAC). - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1548/002/ T1548.002], [https://attack.mitre.org/techniques/T1548/ T1548] -* '''Last Updated''': 2020-11-18 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path=*HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\EnableLUA* Registry.registry_value_name="DWORD (0x00000000)" by Registry.dest, Registry.registry_key_name Registry.user Registry.registry_path Registry.registry_value_name Registry.action -| `drop_dm_object_name(Registry)` -| `disabling_remote_user_account_control_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Defense_Evasion_Tactics|Windows Defense Evasion Tactics]] - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Windows_Registry_Activities|Suspicious Windows Registry Activities]] - -* [[Documentation:ESSOC:stories:UseCase#Remcos|Remcos]] - - -====How To Implement==== -To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black, or via other endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report registry modifications. - -====Required field==== - -* _time - -* Registry.registry_path - -* Registry.registry_value_name - -* Registry.dest - -* Registry.registry_key_name - -* Registry.user - -* Registry.action - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1548.002 -| Bypass User Account Control -| Privilege Escalation, Defense Evasion -|- -| T1548 -| Abuse Elevation Control Mechanism -| Privilege Escalation, Defense Evasion -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -This registry key may be modified via administrators to implement a change in system policy. This type of change should be a very rare occurrence. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.002/atomic_red_team/windows-sysmon.log - - -''version'': 4 -
-
- ----- - -===Disabling systemrestore in registry=== -The following search identifies the modification of registry related in disabling the system restore of a machine. This event or behavior are seen in some RAT malware to make the restore of the infected machine difficult and keep their infection on the box. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001], [https://attack.mitre.org/techniques/T1562/ T1562] -* '''Last Updated''': 2021-03-31 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\SystemRestore\\DisableSR" OR Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\SystemRestore\\DisableConfig" Registry.registry_value_name = "DWORD (0x00000001)" by Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.dest -| `drop_dm_object_name(Registry)` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -| `disabling_systemrestore_in_registry_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Defense_Evasion_Tactics|Windows Defense Evasion Tactics]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. - -====Required field==== - -* _time - -* Registry.registry_key_name - -* Registry.registry_path - -* Registry.user - -* Registry.dest - -* Registry.registry_value_name - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1562.001 -| Disable or Modify Tools -| Defense Evasion -|- -| T1562 -| Impair Defenses -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -in some cases admin can disable systemrestore on a machine. - -====Reference==== - - -* https://tccontre.blogspot.com/2020/01/remcos-rat-evading-windows-defender-av.html - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-security.log - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-system.log - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Disabling task manager=== -This search is to identifies modification of registry to disable the task manager of windows operating system. this event or technique are commonly seen in malware such as RAT, Trojan, TrojanSpy or worm to prevent the user to terminate their process. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001], [https://attack.mitre.org/techniques/T1562/ T1562] -* '''Last Updated''': 2021-03-31 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\DisableTaskMgr" Registry.registry_value_name = "DWORD (0x00000001)" by Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.dest -| `drop_dm_object_name(Registry)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `disabling_task_manager_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Defense_Evasion_Tactics|Windows Defense Evasion Tactics]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. - -====Required field==== - -* _time - -* Registry.registry_key_name - -* Registry.registry_path - -* Registry.user - -* Registry.dest - -* Registry.registry_value_name - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1562.001 -| Disable or Modify Tools -| Defense Evasion -|- -| T1562 -| Impair Defenses -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -admin may disable this application for non technical user. - -====Reference==== - - -* https://any.run/report/ea4ea08407d4ee72e009103a3b77e5a09412b722fdef67315ea63f22011152af/a866d7b1-c236-4f26-a391-5ae32213dfc4#registry - -* https://blog.talosintelligence.com/2020/05/threat-roundup-0424-0501.html - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-security.log - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-system.log - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Domain account discovery with net app=== -This analytic looks for the execution of `net.exe` or `net1.exe` with command-line arguments utilized to query for domain users. Red Teams and adversaries alike may use net.exe to enumerate domain users for situational awareness and Active Directory Discovery. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/002/ T1087.002], [https://attack.mitre.org/techniques/T1087/ T1087] -* '''Last Updated''': 2021-08-24 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_net` AND Processes.process = "* user*" AND Processes.process = "*/do*" by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `domain_account_discovery_with_net_app_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_id - -* Processes.parent_process_name - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1087.002 -| Domain Account -| Discovery -|- -| T1087 -| Account Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use this command for troubleshooting. - -====Reference==== - - -* https://docs.microsoft.com/en-us/defender-for-identity/playbook-domain-dominance - -* https://attack.mitre.org/techniques/T1087/002/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/AD_discovery/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Domain account discovery with dsquery=== -This analytic looks for the execution of `dsquery.exe` with command-line arguments utilized to discover domain users. The `user` argument returns a list of all users registered in the domain. Red Teams and adversaries alike engage in remote system discovery for situational awareness and Active Directory Discovery. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/002/ T1087.002], [https://attack.mitre.org/techniques/T1087/ T1087] -* '''Last Updated''': 2021-08-24 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name="dsquery.exe" AND Processes.process = "*user*" by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `domain_account_discovery_with_dsquery_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_id - -* Processes.parent_process_name - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1087.002 -| Domain Account -| Discovery -|- -| T1087 -| Account Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use this command for troubleshooting. - -====Reference==== - - -* https://jpcertcc.github.io/ToolAnalysisResultSheet/details/dsquery.htm - -* https://attack.mitre.org/techniques/T1087/002/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/AD_discovery/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Domain account discovery with wmic=== -This analytic looks for the execution of `wmic.exe` with command-line arguments utilized to query for domain users. Red Teams and adversaries alike use wmic.exe to enumerate domain users for situational awareness and Active Directory Discovery. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/002/ T1087.002], [https://attack.mitre.org/techniques/T1087/ T1087] -* '''Last Updated''': 2021-08-24 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name="wmic.exe" AND Processes.process = "*/NAMESPACE:\\\\root\\directory\\ldap*" AND Processes.process = "*ds_user*" AND Processes.process = "*GET*" AND Processes.process = "*ds_samaccountname*" by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `domain_account_discovery_with_wmic_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_id - -* Processes.parent_process_name - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1087.002 -| Domain Account -| Discovery -|- -| T1087 -| Account Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use this command for troubleshooting. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1087/002/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/AD_discovery/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Domain controller discovery with nltest=== -This analytic looks for the execution of `nltest.exe` with command-line arguments utilized to discover remote systems. The arguments `/dclist:` and '/dsgetdc:', can be used to return a list of all domain controllers. Red Teams and adversaries alike may use nltest.exe to identify domain controllers in a Windows Domain for situational awareness and Active Directory Discovery. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1018/ T1018] -* '''Last Updated''': 2021-08-30 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="nltest.exe") (Processes.process="*/dclist:*" OR Processes.process="*/dsgetdc:*") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `domain_controller_discovery_with_nltest_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1018 -| Remote System Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use this command for troubleshooting. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1018/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/AD_discovery/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Domain controller discovery with wmic=== -This analytic looks for the execution of `wmic.exe` with command-line arguments utilized to discover remote systems. The arguments utilized in this command line return a list of all domain controllers in a Windows domain. Red Teams and adversaries alike use *.exe to identify remote systems for situational awareness and Active Directory Discovery. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1018/ T1018] -* '''Last Updated''': 2021-09-01 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="wmic.exe") (Processes.process="" OR Processes.process="*DomainControllerAddress*") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `domain_controller_discovery_with_wmic_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1018 -| Remote System Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use this command for troubleshooting. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1018/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/AD_discovery/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Domain group discovery with dsquery=== -This analytic looks for the execution of `dsquery.exe` with command-line arguments utilized to query for domain groups. The argument `group`, returns a list of all domain groups. Red Teams and adversaries alike use may leverage dsquery.exe to enumerate domain groups for situational awareness and Active Directory Discovery. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1069/ T1069], [https://attack.mitre.org/techniques/T1069/002/ T1069.002] -* '''Last Updated''': 2021-09-01 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="dsquery.exe") (Processes.process="*group*") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `domain_group_discovery_with_dsquery_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1069 -| Permission Groups Discovery -| Discovery -|- -| T1069.002 -| Domain Groups -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use this command for troubleshooting. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1069/002/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.002/AD_discovery/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Domain group discovery with net=== -This analytic looks for the execution of `net.exe` with command-line arguments utilized to query for domain groups. The argument `group /domain`, returns a list of all domain groups. Red Teams and adversaries alike use net.exe to enumerate domain groups for situational awareness and Active Directory Discovery. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1069/ T1069], [https://attack.mitre.org/techniques/T1069/002/ T1069.002] -* '''Last Updated''': 2021-08-25 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="net.exe" OR Processes.process_name="net1.exe") (Processes.process=*group* AND Processes.process=*/do*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `domain_group_discovery_with_net_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1069 -| Permission Groups Discovery -| Discovery -|- -| T1069.002 -| Domain Groups -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use this command for troubleshooting. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1069/002/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.002/AD_discovery/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Domain group discovery with wmic=== -This analytic looks for the execution of `wmic.exe` with command-line arguments utilized to query for domain groups. The arguments utilized in this command return a list of all domain groups. Red Teams and adversaries alike use wmic.exe to enumerate domain groups for situational awareness and Active Directory Discovery. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1069/ T1069], [https://attack.mitre.org/techniques/T1069/002/ T1069.002] -* '''Last Updated''': 2021-08-25 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="wmic.exe") (Processes.process=*/NAMESPACE:\\\\root\\directory\\ldap* AND Processes.process=*ds_group* AND Processes.process="*GET ds_samaccountname*") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `domain_group_discovery_with_wmic_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1069 -| Permission Groups Discovery -| Discovery -|- -| T1069.002 -| Domain Groups -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use this command for troubleshooting. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1069/002/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.002/AD_discovery/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Domain group discovery with adsisearcher=== -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the `[Adsisearcher]` type accelerator being used to query Active Directory for domain groups. Red Teams and adversaries may leverage `[Adsisearcher]` to enumerate domain groups for situational awareness and Active Directory Discovery. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1069/ T1069], [https://attack.mitre.org/techniques/T1069/002/ T1069.002] -* '''Last Updated''': 2021-08-25 - -
-
- -====Search==== -`powershell` EventCode=4104 (Message = "*[adsisearcher]*" AND Message = "*(objectcategory=group)*" AND Message = "*findAll()*") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `domain_group_discovery_with_adsisearcher_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -====Required field==== - -* _time - -* EventCode - -* Message - -* ComputerName - -* User - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1069 -| Permission Groups Discovery -| Discovery -|- -| T1069.002 -| Domain Groups -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use Adsisearcher for troubleshooting. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1069/002/ - -* https://devblogs.microsoft.com/scripting/use-the-powershell-adsisearcher-type-accelerator-to-search-active-directory/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.002/AD_discovery/windows-powershell.log - - -''version'': 1 -
-
- ----- - -===Download files using telegram=== -The following analytic will identify a suspicious download by the Telegram application on a Windows system. This behavior was identified on a honeypot where the adversary gained access, installed Telegram and followed through with downloading different network scanners (port, bruteforcer, masscan) to the system and later used to mapped the whole network and further move laterally. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1105/ T1105] -* '''Last Updated''': 2021-05-06 - -
-
- -====Search==== -`sysmon` EventCode= 15 process_name = "telegram.exe" TargetFilename = "*:Zone.Identifier" -|stats count min(_time) as firstTime max(_time) as lastTime by Computer EventCode Image process_id TargetFilename Hash -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `download_files_using_telegram_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#XMRig|XMRig]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name and TargetFilename from your endpoints or Events that monitor filestream events which is happened when process download something. (EventCode 15) If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -====Required field==== - -* _time - -* Computer - -* EventCode - -* Image - -* process_id - -* TargetFilename - -* Hash - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1105 -| Ingress Tool Transfer -| Command And Control -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -normal download of file in telegram app. (if it was a common app in network) - -====Reference==== - - -* https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/minergate/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Drop icedid license dat=== -This search is to detect dropping a suspicious file named as "license.dat" in %appdata%. This behavior seen in latest IcedID malware that contain the actual core bot that will be injected in other process to do banking stealing. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1204/ T1204], [https://attack.mitre.org/techniques/T1204/002/ T1204.002] -* '''Last Updated''': 2021-07-30 - -
-
- -====Search==== -`sysmon` EventCode= 11 TargetFilename = "*\\license.dat" AND (TargetFilename="*\\appdata\\*" OR TargetFilename="*\\programdata\\*") -|stats count min(_time) as firstTime max(_time) as lastTime by TargetFilename EventCode process_id process_name Computer -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `drop_icedid_license_dat_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#IcedID|IcedID]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -====Required field==== - -* _time - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1204 -| User Execution -| Execution -|- -| T1204.002 -| Malicious File -| Execution -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://www.cisecurity.org/white-papers/security-primer-icedid/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/simulated_icedid/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Dump lsass via comsvcs dll=== -Detect the usage of comsvcs.dll for dumping the lsass process. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/001/ T1003.001], [https://attack.mitre.org/techniques/T1003/ T1003] -* '''Last Updated''': 2020-02-21 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_rundll32` Processes.process=*comsvcs.dll* Processes.process=*MiniDump* by Processes.user Processes.process_name Processes.original_file_name Processes.process Processes.dest -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `dump_lsass_via_comsvcs_dll_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Credential_Dumping|Credential Dumping]] - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Rundll32_Activity|Suspicious Rundll32 Activity]] - -* [[Documentation:ESSOC:stories:UseCase#HAFNIUM_Group|HAFNIUM Group]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1003.001 -| LSASS Memory -| Credential Access -|- -| T1003 -| OS Credential Dumping -| Credential Access -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -None identified. - -====Reference==== - - -* https://modexp.wordpress.com/2019/08/30/minidumpwritedump-via-com-services-dll/ - -* https://twitter.com/SBousseaden/status/1167417096374050817 - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.001/atomic_red_team/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Dump lsass via procdump=== -Detect procdump.exe dumping the lsass process. This query looks for both -mm and -ma usage. -mm will produce a mini dump file and -ma will write a dump file with all process memory. Both are highly suspect and should be reviewed. This query does not monitor for the internal name (original_file_name=procdump) of the PE or look for procdump64.exe. Modify the query as needed.\ -During triage, confirm this is procdump.exe executing. If it is the first time a Sysinternals utility has been ran, it is possible there will be a -accepteula on the command line. Review other endpoint data sources for cross process (injection) into lsass.exe. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/001/ T1003.001], [https://attack.mitre.org/techniques/T1003/ T1003] -* '''Last Updated''': 2021-09-16 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_procdump` (Processes.process=*-ma* OR Processes.process=*-mm*) Processes.process=*lsass* by Processes.user Processes.process_name Processes.process Processes.original_file_name Processes.dest -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `dump_lsass_via_procdump_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Credential_Dumping|Credential Dumping]] - -* [[Documentation:ESSOC:stories:UseCase#HAFNIUM_Group|HAFNIUM Group]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1003.001 -| LSASS Memory -| Credential Access -|- -| T1003 -| OS Credential Dumping -| Credential Access -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -None identified. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1003/001/ - -* https://docs.microsoft.com/en-us/sysinternals/downloads/procdump - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1003.001/T1003.001.md#atomic-test-2---dump-lsassexe-memory-using-procdump - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.001/atomic_red_team/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Etw registry disabled=== -This analytic is to detect a registry modification to disable ETW feature of windows. This technique is to evade EDR appliance to evade detections and hide its execution from audit logs. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/006/ T1562.006], [https://attack.mitre.org/techniques/T1127/ T1127], [https://attack.mitre.org/techniques/T1562/ T1562] -* '''Last Updated''': 2021-10-07 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where (Registry.registry_path="*\\SOFTWARE\\Microsoft\\.NETFramework*") Registry.registry_value_name = ETWEnabled Registry.registry_value_data=0x00000000 by Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `etw_registry_disabled_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Persistence_Techniques|Windows Persistence Techniques]] - -* [[Documentation:ESSOC:stories:UseCase#Windows_Privilege_Escalation|Windows Privilege Escalation]] - - -====How To Implement==== -To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. - -====Required field==== - -* _time - -* Registry.dest - -* Registry.user - -* Registry.registry_path - -* Registry.registry_key_name - -* Registry.registry_value_name - -* Registry.registry_value_data - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1562.006 -| Indicator Blocking -| Defense Evasion -|- -| T1127 -| Trusted Developer Utilities Proxy Execution -| Defense Evasion -|- -| T1562 -| Impair Defenses -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://gist.github.com/Cyb3rWard0g/a4a115fd3ab518a0e593525a379adee3 - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127/etw_disable/sysmon.log - - -''version'': 1 -
-
- ----- - -===Elevated group discovery with net=== -This analytic looks for the execution of `net.exe` or `net1.exe` with command-line arguments utilized to query for specific elevated domain groups. Red Teams and adversaries alike use net.exe to enumerate elevated domain groups for situational awareness and Active Directory Discovery to identify high privileged users. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1069/ T1069], [https://attack.mitre.org/techniques/T1069/002/ T1069.002] -* '''Last Updated''': 2021-08-25 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="net.exe" OR Processes.process_name="net1.exe") (Processes.process="*group*" AND Processes.process="*/do*") (Processes.process="*Domain Admins*" OR Processes.process="*Enterprise Admins*" OR Processes.process="*Schema Admins*" OR Processes.process="*Account Operators*" OR Processes.process="*Server Operators*" OR Processes.process="*Protected Users*" OR Processes.process="*Dns Admins*") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `elevated_group_discovery_with_net_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1069 -| Permission Groups Discovery -| Discovery -|- -| T1069.002 -| Domain Groups -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use this command for troubleshooting. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1069/002/ - -* https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/plan/security-best-practices/appendix-b--privileged-accounts-and-groups-in-active-directory - -* https://adsecurity.org/?p=3658 - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.002/AD_discovery/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Elevated group discovery with wmic=== -This analytic looks for the execution of `wmic.exe` with command-line arguments utilized to query for specific domain groups. Red Teams and adversaries alike use net.exe to enumerate elevated domain groups for situational awareness and Active Directory Discovery to identify high privileged users. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1069/ T1069], [https://attack.mitre.org/techniques/T1069/002/ T1069.002] -* '''Last Updated''': 2021-08-25 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="wmic.exe") (Processes.process=*/NAMESPACE:\\\\root\\directory\\ldap*) (Processes.process="*Domain Admins*" OR Processes.process="*Enterprise Admins*" OR Processes.process="*Schema Admins*" OR Processes.process="*Account Operators*" OR Processes.process="*Server Operators*" OR Processes.process="*Protected Users*" OR Processes.process="*Dns Admins*") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `elevated_group_discovery_with_wmic_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1069 -| Permission Groups Discovery -| Discovery -|- -| T1069.002 -| Domain Groups -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use this command for troubleshooting. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1069/002/ - -* https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/plan/security-best-practices/appendix-b--privileged-accounts-and-groups-in-active-directory - -* https://adsecurity.org/?p=3658 - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.002/AD_discovery/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Elevated group discovery with powerview=== -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-DomainGroupMember` commandlet. `Get-DomainGroupMember` is part of PowerView, a PowerShell tool used to perform enumeration on Windows domains. As the name suggests, `Get-DomainGroupMember` is used to list the members of an specific domain group. Red Teams and adversaries alike use PowerView to enumerate elevated domain groups for situational awareness and Active Directory Discovery to identify high privileged users. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1069/ T1069], [https://attack.mitre.org/techniques/T1069/002/ T1069.002] -* '''Last Updated''': 2021-08-25 - -
-
- -====Search==== -`powershell` EventCode=4104 (Message = "*Get-DomainGroupMember*") AND Message IN ("*Domain Admins*","*Enterprise Admins*", "*Schema Admins*", "*Account Operators*" , "*Server Operators*", "*Protected Users*", "*Dns Admins*") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `elevated_group_discovery_with_powerview_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -====Required field==== - -* _time - -* EventCode - -* Message - -* ComputerName - -* User - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1069 -| Permission Groups Discovery -| Discovery -|- -| T1069.002 -| Domain Groups -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use this PowerView for troubleshooting. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1069/002/ - -* https://powersploit.readthedocs.io/en/latest/Recon/Get-DomainGroupMember/ - -* https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/plan/security-best-practices/appendix-b--privileged-accounts-and-groups-in-active-directory - -* https://attack.mitre.org/techniques/T1069/002/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.002/AD_discovery/windows-powershell.log - - -''version'': 1 -
-
- ----- - -===Enable rdp in other port number=== -This search is to detect a modification to registry to enable rdp to a machine with different port number. This technique was seen in some atttacker tries to do lateral movement and remote access to a compromised machine to gain control of it. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1021/ T1021] -* '''Last Updated''': 2021-05-19 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count values(Registry.registry_key_name) as registry_key_name values(Registry.registry_path) as registry_path min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*HKLM\\SYSTEM\\CurrentControlSet\\Control\\Terminal Server\\WinStations\\RDP-Tcp*" Registry.registry_key_name = "PortNumber" by Registry.dest Registry.user Registry.registry_value_name -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `drop_dm_object_name(Registry)` -| `enable_rdp_in_other_port_number_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Prohibited_Traffic_Allowed_or_Protocol_Mismatch|Prohibited Traffic Allowed or Protocol Mismatch]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -====Required field==== - -* _time - -* Registry.registry_path - -* Registry.dest - -* Registry.user - -* Registry.registry_value_name - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1021 -| Remote Services -| Lateral Movement -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://www.mvps.net/docs/how-to-secure-remote-desktop-rdp/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/casper/datasets1/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Enable wdigest uselogoncredential registry=== -This analytic is to detect a suspicious registry modification to enable plain text credential feature of windows. This technique was used by several malware and also by mimikatz to be able to dumpe the a plain text credential to the compromised or target host. This TTP is really a good indicator that someone wants to dump the crendential of the host so it must be a good pivot for credential dumping techniques. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1112/ T1112], [https://attack.mitre.org/techniques/T1003/ T1003] -* '''Last Updated''': 2021-10-05 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*\\System\\CurrentControlSet\\Control\\SecurityProviders\\WDigest\\*" Registry.registry_value_name = "UseLogonCredential" Registry.registry_value_data = 0x00000001 by Registry.dest Registry.user Registry.registry_value_name Registry.registry_key_name Registry.registry_path Registry.registry_value_data -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `enable_wdigest_uselogoncredential_registry_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Credential_Dumping|Credential Dumping]] - - -====How To Implement==== -To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. - -====Required field==== - -* _time - -* Registry.dest - -* Registry.user - -* Registry.registry_value_name - -* Registry.registry_key_name - -* Registry.registry_path - -* Registry.registry_value_data - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1112 -| Modify Registry -| Defense Evasion -|- -| T1003 -| OS Credential Dumping -| Credential Access -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://www.csoonline.com/article/3438824/how-to-detect-and-halt-credential-theft-via-windows-wdigest.html - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/wdigest_enable/sysmon.log - - -''version'': 1 -
-
- ----- - -===Enumerate users local group using telegram=== -This analytic will detect a suspicious Telegram process enumerating all network users in a local group. This technique was seen in a Monero infected honeypot to mapped all the users on the compromised system. EventCode 4798 is generated when a process enumerates a user's security-enabled local groups on a computer or device. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/ T1087] -* '''Last Updated''': 2021-05-06 - -
-
- -====Search==== -`wineventlog_security` EventCode=4798 Process_Name = "*\\telegram.exe" -| stats count min(_time) as firstTime max(_time) as lastTime by ComputerName EventCode Process_Name Process_ID Account_Name Account_Domain Logon_ID Security_ID Message -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `enumerate_users_local_group_using_telegram_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#XMRig|XMRig]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the Task Schedule (Exa. Security Log EventCode 4798) endpoints. Tune and filter known instances of process like logonUI used in your environment. - -====Required field==== - -* _time - -* ComputerName - -* EventCode - -* Process_Name - -* Process_ID - -* Account_Name - -* Account_Domain - -* Logon_ID - -* Security_ID - -* Message - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1087 -| Account Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ - -* https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4798 - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/minergate/windows-security.log - - -''version'': 1 -
-
- ----- - -===Esentutl sam copy=== -The following analytic identifies the process - `esentutl.exe` - being used to capture credentials stored in ntds.dit or the SAM file on disk. During triage, review parallel processes and determine if legitimate activity. Upon determination of illegitimate activity, take further action to isolate and contain the threat. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/002/ T1003.002], [https://attack.mitre.org/techniques/T1003/ T1003] -* '''Last Updated''': 2021-08-18 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_esentutl` Processes.process IN ("*ntds*", "*SAM*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `esentutl_sam_copy_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Credential_Dumping|Credential Dumping]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1003.002 -| Security Account Manager -| Credential Access -|- -| T1003 -| OS Credential Dumping -| Credential Access -|} - - -====Kill Chain Phase==== - -* Privilege Escalation - -* Lateral Movement - - -====Known False Positives==== -False positives should be limited. Filter as needed. - -====Reference==== - - -* https://github.com/redcanaryco/atomic-red-team/blob/6a570c2a4630cf0c2bd41a2e8375b5d5ab92f700/atomics/T1003.002/T1003.002.md - -* https://attack.mitre.org/software/S0404/ - - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Eventvwr uac bypass=== -The following search identifies Eventvwr bypass by identifying the registry modification into a specific path that eventvwr.msc looks to (but is not valid) upon execution. A successful attack will include a suspicious command to be executed upon eventvwr.msc loading. Upon triage, review the parallel processes that have executed. Identify any additional registry modifications on the endpoint that may look suspicious. Remediate as necessary. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1548/002/ T1548.002], [https://attack.mitre.org/techniques/T1548/ T1548] -* '''Last Updated''': 2021-03-01 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count values(Registry.registry_key_name) as registry_key_name values(Registry.registry_path) as registry_path min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*mscfile\\shell\\open\\command\\*" by Registry.user, Registry.dest , Registry.registry_value_name -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `drop_dm_object_name(Registry)` -| `eventvwr_uac_bypass_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Defense_Evasion_Tactics|Windows Defense Evasion Tactics]] - -* [[Documentation:ESSOC:stories:UseCase#IcedID|IcedID]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. - -====Required field==== - -* _time - -* Registry.registry_key_name - -* Registry.registry_path - -* Registry.user - -* Registry.dest - -* Registry.registry_value_name - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1548.002 -| Bypass User Account Control -| Privilege Escalation, Defense Evasion -|- -| T1548 -| Abuse Elevation Control Mechanism -| Privilege Escalation, Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - -* Privilege Escalation - - -====Known False Positives==== -Some false positives may be present and will need to be filtered. - -====Reference==== - - -* https://blog.malwarebytes.com/malwarebytes-news/2021/02/lazyscripter-from-empire-to-double-rat/ - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1548.002/T1548.002.md - -* https://attack.mitre.org/techniques/T1548/002 - -* https://enigma0x3.net/2016/08/15/fileless-uac-bypass-using-eventvwr-exe-and-registry-hijacking/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.002/atomic_red_team/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Excel spawning powershell=== -The following detection identifies Microsoft Excel spawning PowerShell. Typically, this is not common behavior and not default with Excel.exe. Excel.exe will generally be found in the following path `C:\Program Files\Microsoft Office\root\Office16` (version will vary). PowerShell spawning from Excel.exe is common for a spearphishing attachment and is actively used. Albeit, the command executed will most likely be encoded and captured via another detection. During triage, review parallel processes and identify any files that may have been written. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/002/ T1003.002], [https://attack.mitre.org/techniques/T1003/ T1003] -* '''Last Updated''': 2021-04-12 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count values(Processes.process) min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name="excel.exe" `process_powershell` by Processes.parent_process Processes.process_name Processes.user Processes.dest Processes.original_file_name -| `drop_dm_object_name("Processes")` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -| `excel_spawning_powershell_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Spearphishing_Attachments|Spearphishing Attachments]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1003.002 -| Security Account Manager -| Credential Access -|- -| T1003 -| OS Credential Dumping -| Credential Access -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -False positives should be limited, but if any are present, filter as needed. - -====Reference==== - - -* https://redcanary.com/threat-detection-report/techniques/powershell/ - -* https://attack.mitre.org/techniques/T1566/001/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Excel spawning windows script host=== -The following detection identifies Microsoft Excel spawning Windows Script Host - `cscript.exe` or `wscript.exe`. Typically, this is not common behavior and not default with Excel.exe. Excel.exe will generally be found in the following path `C:\Program Files\Microsoft Office\root\Office16` (version will vary). `cscript.exe` or `wscript.exe` default location is `c:\windows\system32\` or c:windows\syswow64`. `cscript.exe` or `wscript.exe` spawning from Excel.exe is common for a spearphishing attachment and is actively used. Albeit, the command-line executed will most likely be obfuscated and captured via another detection. During triage, review parallel processes and identify any files that may have been written. Review the reputation of the remote destination and block accordingly. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/002/ T1003.002], [https://attack.mitre.org/techniques/T1003/ T1003] -* '''Last Updated''': 2021-04-12 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count values(Processes.process) min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name="excel.exe" Processes.process_name IN ("cscript.exe", "wscript.exe") by Processes.parent_process Processes.process_name Processes.user Processes.dest -| `drop_dm_object_name("Processes")` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -| `excel_spawning_windows_script_host_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Spearphishing_Attachments|Spearphishing Attachments]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* _time - -* process_name - -* process_id - -* parent_process_name - -* dest - -* user - -* parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1003.002 -| Security Account Manager -| Credential Access -|- -| T1003 -| OS Credential Dumping -| Credential Access -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -False positives should be limited, but if any are present, filter as needed. In some instances, `cscript.exe` is used for legitimate business practices. - -====Reference==== - - -* https://app.any.run/tasks/8ecfbc29-03d0-421c-a5bf-3905d29192a2/ - -* https://attack.mitre.org/techniques/T1566/001/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Excessive attempt to disable services=== -This analytic will identify suspicious series of command-line to disable several services. This technique is seen where the adversary attempts to disable security app services or other malware services to complete the objective on the compromised system. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1489/ T1489] -* '''Last Updated''': 2021-05-04 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` values(Processes.process) as process values(Processes.process_id) as process_id count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = "sc.exe" AND Processes.process="*config*" OR Processes.process="*Disabled*" by Processes.process_name Processes.parent_process_name Processes.dest Processes.user _time span=1m -| where count >=5 -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `excessive_attempt_to_disable_services_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#XMRig|XMRig]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed sc.exe may be used. - -====Required field==== - -* _time - -* Processes.process - -* Processes.process_id - -* Processes.process_name - -* Processes.parent_process_name - -* Processes.dest - -* Processes.user - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1489 -| Service Stop -| Impact -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Excessive service stop attempt=== -This analytic identifies suspicious series of attempt to kill multiple services on a system using either `net.exe` or `sc.exe`. This technique is use by adversaries to terminate security services or other related services to continue there objective and evade detections. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1489/ T1489] -* '''Last Updated''': 2021-05-04 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` values(Processes.process) as process values(Processes.process_id) as process_id count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_net` OR Processes.process_name = "sc.exe" OR Processes.process_name = "net1.exe" AND Processes.process="*stop*" OR Processes.process="*delete*" by Processes.process_name Processes.original_file_name Processes.parent_process_name Processes.dest Processes.user _time span=1m -| where count >=5 -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `excessive_service_stop_attempt_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#XMRig|XMRig]] - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1489 -| Service Stop -| Impact -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Excessive usage of cacls app=== -The following analytic identifies excessive usage of `cacls.exe`, `xcacls.exe` or `icacls.exe` application to change file or folder permission. This behavior is commonly seen where the adversary attempts to impair some users from deleting or accessing its malware components or artifact from the compromised system. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1222/ T1222] -* '''Last Updated''': 2021-05-07 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` values(Processes.process) as process values(Processes.process_id) as process_id values(Processes.process_name) as process_name count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = "cacls.exe" OR Processes.process_name = "icacls.exe" OR Processes.process_name = "XCACLS.exe" by Processes.parent_process_name Processes.parent_process Processes.dest Processes.user _time span=1m -| where count >=10 -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `excessive_usage_of_cacls_app_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#XMRig|XMRig]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* _time - -* Processes.process - -* Processes.process_id - -* Processes.process_name - -* Processes.parent_process_name - -* Processes.dest - -* Processes.user - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1222 -| File and Directory Permissions Modification -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Administrators or administrative scripts may use this application. Filter as needed. - -====Reference==== - - -* https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Excessive usage of net app=== -This analytic identifies excessive usage of `net.exe` or `net1.exe` within a bucket of time (1 minute). This behavior was seen in a Monero incident where the adversary attempts to create many users, delete and disable users as part of its malicious behavior. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1531/ T1531] -* '''Last Updated''': 2021-05-06 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` values(Processes.process) as process values(Processes.process_id) as process_id count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_net` by Processes.process_name Processes.parent_process_name Processes.original_file_name Processes.dest Processes.user _time span=1m -| where count >=10 -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `excessive_usage_of_net_app_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#XMRig|XMRig]] - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1531 -| Account Access Removal -| Impact -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown. Filter as needed. Modify the time span as needed. - -====Reference==== - - -* https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Excessive usage of sc service utility=== -This search is to detect a suspicious excessive usage of sc.exe in a host machine. This technique was seen in several ransomware , xmrig and other malware to create, modify, delete or disable a service may related to security application or to gain privilege escalation. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1569/ T1569], [https://attack.mitre.org/techniques/T1569/002/ T1569.002] -* '''Last Updated''': 2021-06-24 - -
-
- -====Search==== -`sysmon` EventCode = 1 process_name = "sc.exe" -| bucket _time span=15m -| stats values(process) as process count as numScExe by Computer, _time -| eventstats avg(numScExe) as avgScExe, stdev(numScExe) as stdScExe, count as numSlots by Computer -| eval upperThreshold=(avgScExe + stdScExe *3) -| eval isOutlier=if(avgScExe > 5 and avgScExe >= upperThreshold, 1, 0) -| search isOutlier=1 -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `excessive_usage_of_sc_service_utility_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed taskkill.exe may be used. - -====Required field==== - -* _time - -* EventCode - -* process_name - -* process - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1569 -| System Services -| Execution -|- -| T1569.002 -| Service Execution -| Execution -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -excessive execution of sc.exe is quite suspicious since it can modify or execute app in high privilege permission. - -====Reference==== - - -* https://app.any.run/tasks/c0f98850-af65-4352-9746-fbebadee4f05/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/data2/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Excessive usage of taskkill=== -This analytic identifies excessive usage of `taskkill.exe` application. This application is commonly used by adversaries to evade detections by killing security product processes or even other processes to evade detection. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001], [https://attack.mitre.org/techniques/T1562/ T1562] -* '''Last Updated''': 2021-05-04 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` values(Processes.process) as process values(Processes.process_id) as process_id count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = "taskkill.exe" by Processes.parent_process_name Processes.process_name Processes.dest Processes.user _time span=1m -| where count >=10 -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `excessive_usage_of_taskkill_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#XMRig|XMRig]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed taskkill.exe may be used. - -====Required field==== - -* _time - -* Processes.parent_process_name - -* Processes.process_name - -* Processes.dest - -* Processes.user - -* Processes.process - -* Processes.process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1562.001 -| Disable or Modify Tools -| Defense Evasion -|- -| T1562 -| Impair Defenses -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Unknown. Filter as needed. - -====Reference==== - - -* https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Excessive usage of nslookup app=== -This search is to detect potential DNS exfiltration using nslookup application. This technique are seen in couple of malware and APT group to exfiltrated collected data in a infected machine or infected network. This detection is looking for unique use of nslookup where it tries to use specific record type (TXT, A, AAAA) that are commonly used by attacker and also the retry parameter which is designed to query C2 DNS multiple tries. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1048/ T1048] -* '''Last Updated''': 2021-04-21 - -
-
- -====Search==== -`sysmon` EventCode = 1 process_name = "nslookup.exe" -| bucket _time span=15m -| stats count as numNsLookup by Computer, _time -| eventstats avg(numNsLookup) as avgNsLookup, stdev(numNsLookup) as stdNsLookup, count as numSlots by Computer -| eval upperThreshold=(avgNsLookup + stdNsLookup *3) -| eval isOutlier=if(avgNsLookup > 20 and avgNsLookup >= upperThreshold, 1, 0) -| search isOutlier=1 -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `excessive_usage_of_nslookup_app_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_DNS_Traffic|Suspicious DNS Traffic]] - -* [[Documentation:ESSOC:stories:UseCase#Dynamic_DNS|Dynamic DNS]] - -* [[Documentation:ESSOC:stories:UseCase#Command_and_Control|Command and Control]] - -* [[Documentation:ESSOC:stories:UseCase#Data_Exfiltration|Data Exfiltration]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances of nslookup.exe may be used. - -====Required field==== - -* _time - -* Computer - -* process_name - -* EventCode - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1048 -| Exfiltration Over Alternative Protocol -| Exfiltration -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://www.fireeye.com/blog/threat-research/2017/03/fin7_spear_phishing.html - -* https://www.varonis.com/blog/dns-tunneling/ - -* https://www.microsoft.com/security/blog/2021/01/20/deep-dive-into-the-solorigate-second-stage-activation-from-sunburst-to-teardrop-and-raindrop/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1048.003/nslookup_exfil/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Excessive number of distinct processes created in windows temp folder=== -This analytic will identify suspicious series of process executions. We have observed that post exploit framework tools like Koadic and Meterpreter will launch an excessive number of processes with distinct file paths from Windows\Temp to execute actions on objective. This behavior is extremely anomalous compared to typical application behaviors that use Windows\Temp. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/ T1059] -* '''Last Updated''': 2021-06-03 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` values(Processes.process) as process distinct_count(Processes.process) as distinct_process_count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process = "*\\Windows\\Temp\\*" by Processes.dest Processes.user _time span=20m -| where distinct_process_count > 37 -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `excessive_number_of_distinct_processes_created_in_windows_temp_folder_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Meterpreter|Meterpreter]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the full process path in the process field of CIM's Process data model. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed sc.exe may be used. - -====Required field==== - -* _time - -* Processes.process - -* Processes.dest - -* Processes.user - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1059 -| Command and Scripting Interpreter -| Execution -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Many benign applications will create processes from executables in Windows\Temp, although unlikely to exceed the given threshold. Filter as needed. - -====Reference==== - - -* https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059/meterpreter/windows_temp_processes/logExcessiveWindowsTemp.log - - -''version'': 1 -
-
- ----- - -===Excessive number of service control start as disabled=== -This detection targets behaviors observed when threat actors have used sc.exe to modify services. We observed malware in a honey pot spawning numerous sc.exe processes in a short period of time, presumably to impair defenses, possibly to block others from compromising the same machine. This detection will alert when we see both an excessive number of sc.exe processes launched with specific commandline arguments to disable the start of certain services. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001], [https://attack.mitre.org/techniques/T1562/ T1562] -* '''Last Updated''': 2021-06-25 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` distinct_count(Processes.process) as distinct_cmdlines values(Processes.process_id) as process_ids min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes WHERE Processes.process_name = "sc.exe" AND Processes.process="*start= disabled*" by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.parent_process_id, _time span=30m -| where distinct_cmdlines >= 8 -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `excessive_number_of_service_control_start_as_disabled_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Defense_Evasion_Tactics|Windows Defense Evasion Tactics]] - - -====How To Implement==== -You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must be ingesting logs with both the process name and command line from your endpoints. The complete process name with command-line arguments are mapped to the "process" field in the Endpoint data model. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1562.001 -| Disable or Modify Tools -| Defense Evasion -|- -| T1562 -| Impair Defenses -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Legitimate programs and administrators will execute sc.exe with the start disabled flag. It is possible, but unlikely from the telemetry of normal Windows operation we observed, that sc.exe will be called more than seven times in a short period of time. - -====Reference==== - - -* https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/sc-create - -* https://attack.mitre.org/techniques/T1562/001/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/sc_service_start_disabled/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Excessive number of taskhost processes=== -This detection targets behaviors observed in post exploit kits like Meterpreter and Koadic that are run in memory. We have observed that these tools must invoke an excessive number of taskhost.exe and taskhostex.exe processes to complete various actions (discovery, lateral movement, etc.). It is extremely uncommon in the course of normal operations to see so many distinct taskhost and taskhostex processes running concurrently in a short time frame. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1033/ T1033] -* '''Last Updated''': 2021-06-07 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` values(Processes.process_id) as process_ids min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes WHERE Processes.process_name = "taskhost.exe" OR Processes.process_name = "taskhostex.exe" BY Processes.dest Processes.process_name _time span=1h -| `drop_dm_object_name(Processes)` -| eval pid_count=mvcount(process_ids) -| eval taskhost_count_=if(process_name == "taskhost.exe", pid_count, 0) -| eval taskhostex_count_=if(process_name == "taskhostex.exe", pid_count, 0) -| stats sum(taskhost_count_) as taskhost_count, sum(taskhostex_count_) as taskhostex_count by _time, dest, firstTime, lastTime -| where taskhost_count > 10 and taskhostex_count > 10 -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `excessive_number_of_taskhost_processes_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Meterpreter|Meterpreter]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting events related to processes on the endpoints that include the name of the process and process id into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* _time - -* Processes.process_id - -* Processes.process_name - -* Processes.dest - -* Processes.user - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1033 -| System Owner/User Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Administrators, administrative actions or certain applications may run many instances of taskhost and taskhostex concurrently. Filter as needed. - -====Reference==== - - -* https://attack.mitre.org/software/S0250/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059/meterpreter/taskhost_processes/logExcessiveTaskHost.log - - -''version'': 1 -
-
- ----- - -===Exchange powershell abuse via ssrf=== -This analytic identifies suspicious behavior related to ProxyShell against on-premise Microsoft Exchange servers. \ -Modification of this analytic is requried to ensure fields are mapped accordingly. \ -A suspicious event will have `PowerShell`, the method `POST` and `autodiscover.json`. This is indicative of accessing PowerShell on the back end of Exchange with SSRF. \ -An event will look similar to `POST /autodiscover/autodiscover.json a=dsxvu@fnsso.flq/powershell/?X-Rps-CAT=VgEAVAdXaW5kb3d...` (abbreviated) \ -Review the source attempting to perform this activity against your environment. In addition, review PowerShell logs and access recently granted to Exchange roles. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1190/ T1190] -* '''Last Updated''': 2021-08-27 - -
-
- -====Search==== - -| `exchange` c_uri="*//autodiscover.json*" cs_uri_query="*PowerShell*" cs_method="POST" -| stats count min(_time) as firstTime max(_time) as lastTime by dest, cs_uri_query, cs_method, c_uri -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `exchange_powershell_abuse_via_ssrf_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#ProxyShell|ProxyShell]] - - -====How To Implement==== -The following analytic requires on-premise Exchange to be logging to Splunk using the TA - https://splunkbase.splunk.com/app/3225. Ensure logs are parsed correctly, or tune the analytic for your environment. - -====Required field==== - -* _time - -* dest - -* cs_uri_query - -* cs_method - -* c_uri - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1190 -| Exploit Public-Facing Application -| Initial Access -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Limited false positives, however, tune as needed. - -====Reference==== - - -* https://github.com/GossiTheDog/ThreatHunting/blob/master/AzureSentinel/Exchange-Powershell-via-SSRF - -* https://blog.orange.tw/2021/08/proxylogon-a-new-attack-surface-on-ms-exchange-part-1.html - -* https://peterjson.medium.com/reproducing-the-proxyshell-pwn2own-exploit-49743a4ea9a1 - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/exchange-events.json - - -''version'': 1 -
-
- ----- - -===Exchange powershell module usage=== -The following analytic identifies the usage of Exchange PowerShell modules that were recently used for a proof of concept related to ProxyShell. Currently, there is no active data shared or data we could re-produce relate to this part of the ProxyShell chain of exploits. \ -Inherently, the usage of the modules is not malicious, but reviewing parallel processes, and user, of the session will assist with determining the intent. \ -Module - New-MailboxExportRequest will begin the process of exporting contents of a primary mailbox or archive to a .pst file. \ -Module - New-managementroleassignment can assign a management role to a management role group, management role assignment policy, user, or universal security group (USG). - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/ T1059], [https://attack.mitre.org/techniques/T1059/001/ T1059.001] -* '''Last Updated''': 2021-08-27 - -
-
- -====Search==== -`powershell` EventCode=4104 Message IN ("*New-MailboxExportRequest*", "*New-ManagementRoleAssignment*") -| stats count min(_time) as firstTime max(_time) as lastTime by Path Message OpCode ComputerName User EventCode -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `exchange_powershell_module_usage_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#ProxyShell|ProxyShell]] - - -====How To Implement==== -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -====Required field==== - -* _time - -* Path - -* Message - -* OpCode - -* ComputerName - -* User - -* EventCode - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1059 -| Command and Scripting Interpreter -| Execution -|- -| T1059.001 -| PowerShell -| Execution -|} - - -====Kill Chain Phase==== - -* Reconnaissance - -* Exploitation - - -====Known False Positives==== -Administrators or power users may use this PowerShell commandlet for troubleshooting. - -====Reference==== - - -* https://docs.microsoft.com/en-us/powershell/module/exchange/new-mailboxexportrequest?view=exchange-ps - -* https://docs.microsoft.com/en-us/powershell/module/exchange/new-managementroleassignment?view=exchange-ps - -* https://blog.orange.tw/2021/08/proxyshell-a-new-attack-surface-on-ms-exchange-part-3.html - -* https://www.zerodayinitiative.com/blog/2021/8/17/from-pwn2own-2021-a-new-attack-surface-on-microsoft-exchange-proxyshell - - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Executables or script creation in suspicious path=== -This analytic will identify suspicious executable or scripts (known file extensions) in list of suspicious file path in Windows. This technique is used by adversaries to evade detection. The suspicious file path are known paths used in the wild and are not common to have executable or scripts. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1036/ T1036] -* '''Last Updated''': 2021-05-06 - -
-
- -====Search==== - -|tstats `security_content_summariesonly` values(Filesystem.file_path) as file_path count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Filesystem where (Filesystem.file_name = *.exe OR Filesystem.file_name = *.dll OR Filesystem.file_name = *.sys OR Filesystem.file_name = *.com OR Filesystem.file_name = *.vbs OR Filesystem.file_name = *.vbe OR Filesystem.file_name = *.js OR Filesystem.file_name = *.ps1 OR Filesystem.file_name = *.bat OR Filesystem.file_name = *.cmd OR Filesystem.file_name = *.pif) AND ( Filesystem.file_path = *\\windows\\fonts\\* OR Filesystem.file_path = *\\windows\\temp\\* OR Filesystem.file_path = *\\users\\public\\* OR Filesystem.file_path = *\\windows\\debug\\* OR Filesystem.file_path = *\\Users\\Administrator\\Music\\* OR Filesystem.file_path = *\\Windows\\servicing\\* OR Filesystem.file_path = *\\Users\\Default\\* OR Filesystem.file_path = *Recycle.bin* OR Filesystem.file_path = *\\Windows\\Media\\* OR Filesystem.file_path = *\\Windows\\repair\\* OR Filesystem.file_path = *\\AppData\\Local\\Temp*) by Filesystem.file_create_time Filesystem.process_id Filesystem.file_name Filesystem.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `executables_or_script_creation_in_suspicious_path_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#XMRig|XMRig]] - -* [[Documentation:ESSOC:stories:UseCase#Remcos|Remcos]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the Filesystem responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Filesystem` node. - -====Required field==== - -* _time - -* Filesystem.file_path - -* Filesystem.file_create_time - -* Filesystem.process_id - -* Filesystem.file_name - -* Filesystem.user - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1036 -| Masquerading -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Administrators may allow creation of script or exe in the paths specified. Filter as needed. - -====Reference==== - - -* https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Execute javascript with jscript com clsid=== -This analytic will identify suspicious process of cscript.exe where it tries to execute javascript using jscript.encode CLSID (COM OBJ). This technique was seen in ransomware (reddot ransomware) where it execute javascript with this com object with combination of amsi disabling technique. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/ T1059], [https://attack.mitre.org/techniques/T1059/005/ T1059.005] -* '''Last Updated''': 2021-06-22 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = "cscript.exe" Processes.process="*-e:{F414C262-6AC0-11CF-B6D1-00AA00BBBB58}*" by Processes.parent_process_name Processes.process_name Processes.process Processes.parent_process Processes.process_id Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `execute_javascript_with_jscript_com_clsid_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the Filesystem responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Filesystem` node. - -====Required field==== - -* _time - -* Processes.parent_process_name - -* Processes.process_name - -* Processes.process - -* Processes.parent_process - -* Processes.process_id - -* Processes.dest - -* Processes.user - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1059 -| Command and Scripting Interpreter -| Execution -|- -| T1059.005 -| Visual Basic -| Execution -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://app.any.run/tasks/c0f98850-af65-4352-9746-fbebadee4f05/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/data2/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Execution of file with multiple extensions=== -This search looks for processes launched from files that have double extensions in the file name. This is typically done to obscure the "real" file extension and make it appear as though the file being accessed is a data file, as opposed to executable content. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1036/ T1036], [https://attack.mitre.org/techniques/T1036/003/ T1036.003] -* '''Last Updated''': 2020-11-18 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process = *.doc.exe OR Processes.process = *.htm.exe OR Processes.process = *.html.exe OR Processes.process = *.txt.exe OR Processes.process = *.pdf.exe OR Processes.process = *.doc.exe by Processes.dest Processes.user Processes.process Processes.parent_process -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `drop_dm_object_name(Processes)` -| `execution_of_file_with_multiple_extensions_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_File_Extension_and_Association_Abuse|Windows File Extension and Association Abuse]] - -* [[Documentation:ESSOC:stories:UseCase#Masquerading_-_Rename_System_Utilities|Masquerading - Rename System Utilities]] - - -====How To Implement==== -To successfully implement this search, you must be ingesting data that records process activity from your hosts to populate the endpoint data model in the processes node. - -====Required field==== - -* _time - -* Processes.process - -* Processes.dest - -* Processes.user - -* Processes.parent_process - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1036 -| Masquerading -| Defense Evasion -|- -| T1036.003 -| Rename System Utilities -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -None identified. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036.003/atomic_red_team/windows-sysmon.log - - -''version'': 3 -
-
- ----- - -===Extraction of registry hives=== -The following analytic identifies the use of `reg.exe` exporting Windows Registry hives containing credentials. Adversaries may use this technique to export registry hives for offline credential access attacks. Typically found executed from a untrusted process or script. Upon execution, a file will be written to disk. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/002/ T1003.002], [https://attack.mitre.org/techniques/T1003/ T1003] -* '''Last Updated''': 2021-09-09 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_reg` (Processes.process=*save* OR Processes.process=*export*) AND (Processes.process="*\sam *" OR Processes.process="*\system *" OR Processes.process="*\security *") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `extraction_of_registry_hives_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#DarkSide_Ransomware|DarkSide Ransomware]] - -* [[Documentation:ESSOC:stories:UseCase#Credential_Dumping|Credential Dumping]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1003.002 -| Security Account Manager -| Credential Access -|- -| T1003 -| OS Credential Dumping -| Credential Access -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -It is possible some agent based products will generate false positives. Filter as needed. - -====Reference==== - - -* https://www.mandiant.com/resources/shining-a-light-on-darkside-ransomware-operations - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1003.002/T1003.002.md - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.002/atomic_red_team/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===File with samsam extension=== -The search looks for file writes with extensions consistent with a SamSam ransomware attack. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': -* '''Last Updated''': 2018-12-14 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Filesystem.user) as user values(Filesystem.dest) as dest values(Filesystem.file_path) as file_path from datamodel=Endpoint.Filesystem by Filesystem.file_name -| `drop_dm_object_name(Filesystem)` -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| rex field=file_name "(?<file_extension>\.[^\.]+)$" -| search file_extension=.stubbin OR file_extension=.berkshire OR file_extension=.satoshi OR file_extension=.sophos OR file_extension=.keyxml -| `file_with_samsam_extension_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#SamSam_Ransomware|SamSam Ransomware]] - - -====How To Implement==== -You must be ingesting data that records file-system activity from your hosts to populate the Endpoint file-system data-model node. If you are using Sysmon, you will need a Splunk Universal Forwarder on each endpoint from which you want to collect data. - -====Required field==== - -* _time - -* Filesystem.user - -* Filesystem.dest - -* Filesystem.file_path - -* Filesystem.file_name - - - - -====Kill Chain Phase==== - -* Installation - - -====Known False Positives==== -Because these extensions are not typically used in normal operations, you should investigate all results. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036.003/samsam_extension/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===First time seen child process of zoom=== -This search looks for child processes spawned by zoom.exe or zoom.us that has not previously been seen. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1068/ T1068] -* '''Last Updated''': 2020-05-20 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` min(_time) as firstTime values(Processes.parent_process_name) as parent_process_name values(Processes.parent_process_id) as parent_process_id values(Processes.process_name) as process_name values(Processes.process) as process from datamodel=Endpoint.Processes where (Processes.parent_process_name=zoom.exe OR Processes.parent_process_name=zoom.us) by Processes.process_id Processes.dest -| `drop_dm_object_name(Processes)` -| lookup zoom_first_time_child_process dest as dest process_name as process_name OUTPUT firstTimeSeen -| where isnull(firstTimeSeen) OR firstTimeSeen > relative_time(now(), "`previously_seen_zoom_child_processes_window`") -| `security_content_ctime(firstTime)` -| table firstTime dest, process_id, process_name, parent_process_id, parent_process_name -|`first_time_seen_child_process_of_zoom_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Zoom_Child_Processes|Suspicious Zoom Child Processes]] - - -====How To Implement==== -You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You should run the baseline search `Previously Seen Zoom Child Processes - Initial` to build the initial table of child processes and hostnames for this search to work. You should also schedule at the same interval as this search the second baseline search `Previously Seen Zoom Child Processes - Update` to keep this table up to date and to age out old child processes. Please update the `previously_seen_zoom_child_processes_window` macro to adjust the time window. - -====Required field==== - -* _time - -* Processes.parent_process_name - -* Processes.parent_process_id - -* Processes.process_name - -* Processes.process - -* Processes.parent_process_name - -* Processes.process_id - -* Processes.dest - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1068 -| Exploitation for Privilege Escalation -| Privilege Escalation -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -A new child process of zoom isn't malicious by that fact alone. Further investigation of the actions of the child process is needed to verify any malicious behavior is taken. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1068/zoom_child_process/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===First time seen running windows service=== -This search looks for the first and last time a Windows service is seen running in your environment. This table is then cached. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1569/ T1569], [https://attack.mitre.org/techniques/T1569/002/ T1569.002] -* '''Last Updated''': 2020-07-21 - -
-
- -====Search==== -`wineventlog_system` EventCode=7036 -| rex field=Message "The (?<service>[-\(\)\s\w]+) service entered the (?<state>\w+) state" -| where state="running" -| lookup previously_seen_running_windows_services service as service OUTPUT firstTimeSeen -| where isnull(firstTimeSeen) OR firstTimeSeen > relative_time(now(), `previously_seen_windows_services_window`) -| table _time dest service -| `first_time_seen_running_windows_service_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Service_Abuse|Windows Service Abuse]] - -* [[Documentation:ESSOC:stories:UseCase#Orangeworm_Attack_Group|Orangeworm Attack Group]] - -* [[Documentation:ESSOC:stories:UseCase#NOBELIUM_Group|NOBELIUM Group]] - - -====How To Implement==== -While this search does not require you to adhere to Splunk CIM, you must be ingesting your Windows system event logs in order for this search to execute successfully. You should run the baseline search `Previously Seen Running Windows Services - Initial` to build the initial table of child processes and hostnames for this search to work. You should also schedule at the same interval as this search the second baseline search `Previously Seen Running Windows Services - Update` to keep this table up to date and to age out old Windows Services. Please update the `previously_seen_windows_services_window` macro to adjust the time window. Please ensure that the Splunk Add-on for Microsoft Windows is version 8.0.0 or above. - -====Required field==== - -* _time - -* EventCode - -* Message - -* dest - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1569 -| System Services -| Execution -|- -| T1569.002 -| Service Execution -| Execution -|} - - -====Kill Chain Phase==== - -* Installation - -* Actions on Objectives - - -====Known False Positives==== -A previously unseen service is not necessarily malicious. Verify that the service is legitimate and that was installed by a legitimate process. - -====Reference==== - - -====Test Dataset==== - - -''version'': 4 -
-
- ----- - -===First time seen command line argument=== -This search looks for command-line arguments that use a `/c` parameter to execute a command that has not previously been seen. This is an implementation on SPL2 of the rule `First time seen command line argument` by @bpatel. - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/ T1059], [https://attack.mitre.org/techniques/T1117/ T1117], [https://attack.mitre.org/techniques/T1202/ T1202] -* '''Last Updated''': 2021-2-1 - -
-
- -====Search==== - -| from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)) -| eval dest_user_id=ucast(map_get(input_event, "dest_user_id"), "string", null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), "string", null), process_name=ucast(map_get(input_event, "process_name"), "string", null), cmd_line=ucast(map_get(input_event, "process"), "string", null), cmd_line_norm=lower(cmd_line), cmd_line_norm=replace(cmd_line_norm, /[0-9a-f]{8}-[0-9a-f]{4}-[1-5][0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}/, "GUID"), cmd_line_norm=replace(cmd_line_norm, /(?<=\s)+\\[^:]*(?=\\.*\.\w{3}(\s -|$)+)/, "\\PATH"), /* replaces " \\Something\\Something\\command.ext" => "PATH\\command.ext" */ cmd_line_norm=replace(cmd_line_norm, /\w:\\[^:]*(?=\\.*\.\w{3}(\s -|$)+)/, "\\PATH"), /* replaces "C:\\Something\\Something\\command.ext" => "PATH\\command.ext" */ cmd_line_norm=replace(cmd_line_norm, /\d+/, "N"), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where process_name="cmd.exe" AND match_regex(ucast(cmd_line, "string", ""), /.* \/[cC] .*/)=true -| select process_name, cmd_line, cmd_line_norm, timestamp, dest_device_id, dest_user_id -| first_time_event input_columns=["cmd_line_norm"] -| where first_time_cmd_line_norm -| eval start_time = timestamp, end_time = timestamp, entities = mvappend(dest_device_id, dest_user_id), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name]) -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Unusual_Processes|Unusual Processes]] - - -====How To Implement==== -You must be populating the endpoint data model for SSA and specifically the process_name and the process fields - -====Required field==== - -* process_name - -* _time - -* dest_device_id - -* dest_user_id - -* process - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1059 -| Command and Scripting Interpreter -| Execution -|- -| T1117 -| Regsvr32 -| -|- -| T1202 -| Indirect Command Execution -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Command and Control - -* Actions on Objectives - - -====Known False Positives==== -Legitimate programs can also use command-line arguments to execute. Please verify the command-line arguments to check what command/program is being executed. We recommend customizing the `first_time_seen_cmd_line_filter` macro to exclude legitimate parent_process_name - -====Reference==== - - -====Test Dataset==== - - -''version'': 3 -
-
- ----- - -===Fodhelper uac bypass=== -Fodhelper.exe has a known UAC bypass as it attempts to look for specific registry keys upon execution, that do not exist. Therefore, an attacker can write its malicious commands in these registry keys to be executed by fodhelper.exe with the highest privilege. \ -1. `HKCU:\Software\Classes\ms-settings\shell\open\command`\ -1. `HKCU:\Software\Classes\ms-settings\shell\open\command\DelegateExecute`\ -1. `HKCU:\Software\Classes\ms-settings\shell\open\command\(default)`\ -Upon triage, fodhelper.exe will have a child process and read access will occur on the registry keys. Isolate the endpoint and review parallel processes for additional behavior. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1112/ T1112], [https://attack.mitre.org/techniques/T1548/002/ T1548.002], [https://attack.mitre.org/techniques/T1548/ T1548] -* '''Last Updated''': 2021-03-01 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=fodhelper.exe by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `fodhelper_uac_bypass_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Defense_Evasion_Tactics|Windows Defense Evasion Tactics]] - -* [[Documentation:ESSOC:stories:UseCase#IcedID|IcedID]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* _time - -* Processes.parent_process_name - -* Processes.dest - -* Processes.user - -* Processes.parent_process - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1112 -| Modify Registry -| Defense Evasion -|- -| T1548.002 -| Bypass User Account Control -| Privilege Escalation, Defense Evasion -|- -| T1548 -| Abuse Elevation Control Mechanism -| Privilege Escalation, Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - -* Privilege Escalation - - -====Known False Positives==== -Limited to no false positives are expected. - -====Reference==== - - -* https://blog.malwarebytes.com/malwarebytes-news/2021/02/lazyscripter-from-empire-to-double-rat/ - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1548.002/T1548.002.md - -* https://github.com/gushmazuko/WinBypass/blob/master/FodhelperBypass.ps1 - -* https://attack.mitre.org/techniques/T1548/002 - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.002/atomic_red_team/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Fsutil zeroing file=== -This search is to detect a suspicious fsutil process to zeroing a target file. This technique was seen in lockbit ransomware where it tries to zero out its malware path as part of its defense evasion after encrypting the compromised host. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1070/ T1070] -* '''Last Updated''': 2021-08-11 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count values(Processes.process) as process values(Processes.parent_process) as parent_process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=fsutil.exe Processes.process="*setzerodata*" by Processes.user Processes.process_name Processes.parent_process_name Processes.dest Processes.process Processes.parent_process -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `fsutil_zeroing_file_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -====Required field==== - -* _time - -* Processes.user - -* Processes.process_name - -* Processes.parent_process_name - -* Processes.dest - -* Processes.process - -* Processes.parent_process - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1070 -| Indicator Removal on Host -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://app.any.run/tasks/e0ac072d-58c9-4f53-8a3b-3e491c7ac5db/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070/fsutil_file_zero/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Gpupdate with no command line arguments with network=== -The following analytic identifies gpupdate.exe with no command line arguments and with a network connection. It is unusual for gpupdate.exe to execute with no command line arguments present. This particular behavior is common with malicious software, including Cobalt Strike. During investigation, triage any network connections and parallel processes. Identify any suspicious module loads related to credential dumping or file writes. gpupdate.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1055/ T1055] -* '''Last Updated''': 2021-04-19 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name=gpupdate.exe by _time span=1h Processes.process_guid Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| regex process="(gpupdate\.exe.{0,4}$)" -| join process_guid [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Ports where Ports.dest_port !="0" by Ports.process_guid Ports.dest Ports.dest_port -| `drop_dm_object_name(Ports)` -| rename dest as connection_to_CNC] -| table _time dest parent_process_name process_name process_path process process_guid connection_to_CNC dest_port -| `gpupdate_with_no_command_line_arguments_with_network_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Cobalt_Strike|Cobalt Strike]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* _time - -* EventID - -* process_name - -* process_id - -* parent_process_name - -* dest_port - -* process_path - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1055 -| Process Injection -| Defense Evasion, Privilege Escalation -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Limited false positives may be present in small environments. Tuning may be required based on parent process. - -====Reference==== - - -* https://raw.githubusercontent.com/xx0hcd/Malleable-C2-Profiles/0ef8cf4556e26f6d4190c56ba697c2159faa5822/crimeware/trick_ryuk.profile - -* https://blog.cobaltstrike.com/2021/02/09/learn-pipe-fitting-for-all-of-your-offense-projects/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Get addefaultdomainpasswordpolicy with powershell=== -This analytic looks for the execution of `powershell.exe` executing the Get-ADDefaultDomainPasswordPolicy commandlet used to obtain the password policy in a Windows domain. Red Teams and adversaries alike may use PowerShell to enumerate domain policies for situational awareness and Active Directory Discovery. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1201/ T1201] -* '''Last Updated''': 2021-08-26 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="cmd.exe" OR Processes.process_name="powershell*") AND Processes.process = "*Get-ADDefaultDomainPasswordPolicy*" by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `get_addefaultdomainpasswordpolicy_with_powershell_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed rundll32.exe may be used. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_id - -* Processes.parent_process_name - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1201 -| Password Policy Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use this command for troubleshooting. - -====Reference==== - - -* https://github.com/S1ckB0y1337/Active-Directory-Exploitation-Cheat-Sheet - -* https://attack.mitre.org/techniques/T1201/ - -* https://docs.microsoft.com/en-us/powershell/module/activedirectory/get-addefaultdomainpasswordpolicy?view=windowsserver2019-ps - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1201/pwd_policy_discovery/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Get addefaultdomainpasswordpolicy with powershell script block=== -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-ADDefaultDomainPasswordPolicy` commandlet used to obtain the password policy in a Windows domain. Red Teams and adversaries alike may use PowerShell to enumerate domain policies for situational awareness and Active Directory Discovery. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1201/ T1201] -* '''Last Updated''': 2021-08-26 - -
-
- -====Search==== -`powershell` EventCode=4104 Message ="*Get-ADDefaultDomainPasswordPolicy*" -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `get_addefaultdomainpasswordpolicy_with_powershell_script_block_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -The following Hunting analytic requires PowerShell operational logs to be imported. Modify the powershell macro as needed to match the sourcetype or add index. This analytic is specific to 4104, or PowerShell Script Block Logging. - -====Required field==== - -* _time - -* EventCode - -* Message - -* ComputerName - -* User - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1201 -| Password Policy Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use this command for troubleshooting. - -====Reference==== - - -* https://github.com/S1ckB0y1337/Active-Directory-Exploitation-Cheat-Sheet - -* https://attack.mitre.org/techniques/T1201/ - -* https://docs.microsoft.com/en-us/powershell/module/activedirectory/get-addefaultdomainpasswordpolicy?view=windowsserver2019-ps - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1201/pwd_policy_discovery/windows-powershell.log - - -''version'': 1 -
-
- ----- - -===Get aduser with powershell=== -This analytic looks for the execution of `powershell.exe` with command-line arguments utilized to enumerate domain users. The `Get-AdUser' commandlet returns a list of all domain users. Red Teams and adversaries alike may use this commandlet to identify remote systems for situational awareness and Active Directory Discovery. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/002/ T1087.002], [https://attack.mitre.org/techniques/T1087/ T1087] -* '''Last Updated''': 2021-08-24 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="cmd.exe" OR Processes.process_name="powershell*") AND Processes.process = "*Get-ADUser*" AND Processes.process = "*-filter*" by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `get_aduser_with_powershell_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_id - -* Processes.parent_process_name - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1087.002 -| Domain Account -| Discovery -|- -| T1087 -| Account Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use this command for troubleshooting. - -====Reference==== - - -* https://www.blackhillsinfosec.com/red-blue-purple/ - -* https://attack.mitre.org/techniques/T1087/002/ - -* https://docs.microsoft.com/en-us/powershell/module/activedirectory/get-aduser?view=windowsserver2019-ps - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/AD_discovery/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Get aduser with powershell script block=== -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-AdGUser` commandlet. The `Get-AdUser` commandlet is used to return a list of all domain users. Red Teams and adversaries may leverage this commandlet to enumerate domain groups for situational awareness and Active Directory Discovery. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/002/ T1087.002], [https://attack.mitre.org/techniques/T1087/ T1087] -* '''Last Updated''': 2021-08-24 - -
-
- -====Search==== -`powershell` EventCode=4104 Message = "*get-aduser*" Message = "*-filter*" -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `get_aduser_with_powershell_script_block_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -The following Hunting analytic requires PowerShell operational logs to be imported. Modify the powershell macro as needed to match the sourcetype or add index. This analytic is specific to 4104, or PowerShell Script Block Logging. - -====Required field==== - -* _time - -* EventCode - -* Message - -* ComputerName - -* User - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1087.002 -| Domain Account -| Discovery -|- -| T1087 -| Account Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use this command for troubleshooting. - -====Reference==== - - -* https://www.blackhillsinfosec.com/red-blue-purple/ - -* https://attack.mitre.org/techniques/T1087/002/ - -* https://docs.microsoft.com/en-us/powershell/module/activedirectory/get-aduser?view=windowsserver2019-ps - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/AD_discovery/windows-powershell.log - - -''version'': 1 -
-
- ----- - -===Get aduserresultantpasswordpolicy with powershell=== -This analytic looks for the execution of `powershell.exe` executing the Get ADUserResultantPasswordPolicy commandlet used to obtain the password policy in a Windows domain. Red Teams and adversaries alike may use PowerShell to enumerate domain policies for situational awareness and Active Directory Discovery. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1201/ T1201] -* '''Last Updated''': 2021-08-26 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="cmd.exe" OR Processes.process_name="powershell*") AND Processes.process = "*Get-ADUserResultantPasswordPolicy*" by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `get_aduserresultantpasswordpolicy_with_powershell_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed rundll32.exe may be used. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_id - -* Processes.parent_process_name - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1201 -| Password Policy Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use this command for troubleshooting. - -====Reference==== - - -* https://github.com/S1ckB0y1337/Active-Directory-Exploitation-Cheat-Sheet - -* https://attack.mitre.org/techniques/T1201/ - -* https://docs.microsoft.com/en-us/powershell/module/activedirectory/get-aduserresultantpasswordpolicy?view=windowsserver2019-ps - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1201/pwd_policy_discovery/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Get aduserresultantpasswordpolicy with powershell script block=== -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-ADUserResultantPasswordPolicy` commandlet used to obtain the password policy in a Windows domain. Red Teams and adversaries alike may use PowerShell to enumerate domain policies for situational awareness and Active Directory Discovery. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1201/ T1201] -* '''Last Updated''': 2021-08-26 - -
-
- -====Search==== -`powershell` EventCode=4104 Message ="*Get-ADUserResultantPasswordPolicy*" -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `get_aduserresultantpasswordpolicy_with_powershell_script_block_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -The following Hunting analytic requires PowerShell operational logs to be imported. Modify the powershell macro as needed to match the sourcetype or add index. This analytic is specific to 4104, or PowerShell Script Block Logging. - -====Required field==== - -* _time - -* EventCode - -* Message - -* ComputerName - -* User - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1201 -| Password Policy Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use this command for troubleshooting. - -====Reference==== - - -* https://github.com/S1ckB0y1337/Active-Directory-Exploitation-Cheat-Sheet - -* https://attack.mitre.org/techniques/T1201/ - -* https://docs.microsoft.com/en-us/powershell/module/activedirectory/get-aduserresultantpasswordpolicy?view=windowsserver2019-ps - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1201/pwd_policy_discovery/windows-powershell.log - - -''version'': 1 -
-
- ----- - -===Get domainpolicy with powershell=== -This analytic looks for the execution of `powershell.exe` executing the `Get-DomainPolicy` commandlet used to obtain the password policy in a Windows domain. Red Teams and adversaries alike may use PowerShell to enumerate domain policies for situational awareness and Active Directory Discovery. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1201/ T1201] -* '''Last Updated''': 2021-08-26 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="cmd.exe" OR Processes.process_name="powershell*") AND Processes.process = "*Get-DomainPolicy*" by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `get_domainpolicy_with_powershell_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed rundll32.exe may be used. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_id - -* Processes.parent_process_name - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1201 -| Password Policy Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use this command for troubleshooting. - -====Reference==== - - -* https://github.com/S1ckB0y1337/Active-Directory-Exploitation-Cheat-Sheet - -* https://powersploit.readthedocs.io/en/latest/Recon/Get-DomainPolicy/ - -* https://attack.mitre.org/techniques/T1201/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1201/pwd_policy_discovery/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Get domainpolicy with powershell script block=== -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get DomainPolicy` commandlet used to obtain the password policy in a Windows domain. Red Teams and adversaries alike may use PowerShell to enumerate domain policies for situational awareness and Active Directory Discovery. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1201/ T1201] -* '''Last Updated''': 2021-08-26 - -
-
- -====Search==== -`powershell` EventCode=4104 Message ="*Get-DomainPolicy*" -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `get_domainpolicy_with_powershell_script_block_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -The following Hunting analytic requires PowerShell operational logs to be imported. Modify the powershell macro as needed to match the sourcetype or add index. This analytic is specific to 4104, or PowerShell Script Block Logging. - -====Required field==== - -* _time - -* EventCode - -* Message - -* ComputerName - -* User - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1201 -| Password Policy Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use this command for troubleshooting. - -====Reference==== - - -* https://github.com/S1ckB0y1337/Active-Directory-Exploitation-Cheat-Sheet - -* https://powersploit.readthedocs.io/en/latest/Recon/Get-DomainPolicy/ - -* https://attack.mitre.org/techniques/T1201/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1201/pwd_policy_discovery/windows-powershell.log - - -''version'': 1 -
-
- ----- - -===Get domainuser with powershell=== -This analytic looks for the execution of `powershell.exe` with command-line arguments utilized to enumerate domain users. `Get-DomainUser` is part of PowerView, a PowerShell tool used to perform enumeration on Windows domains. Red Teams and adversaries alike may leverage PowerView to enumerate domain users for situational awareness and Active Directory Discovery. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/002/ T1087.002], [https://attack.mitre.org/techniques/T1087/ T1087] -* '''Last Updated''': 2021-08-24 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="cmd.exe" OR Processes.process_name="powershell*") AND Processes.process = "*Get-DomainUser*" by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `get_domainuser_with_powershell_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_id - -* Processes.parent_process_name - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1087.002 -| Domain Account -| Discovery -|- -| T1087 -| Account Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use this command for troubleshooting. - -====Reference==== - - -* https://powersploit.readthedocs.io/en/latest/Recon/Get-DomainUser/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/AD_discovery/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Get domainuser with powershell script block=== -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-DomainUser` commandlet. `GetDomainUser` is part of PowerView, a PowerShell tool used to perform enumeration on Windows domains. Red Teams and adversaries alike may use PowerView to enumerate domain users for situational awareness and Active Directory Discovery. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/002/ T1087.002], [https://attack.mitre.org/techniques/T1087/ T1087] -* '''Last Updated''': 2021-08-24 - -
-
- -====Search==== -`powershell` EventCode=4104 Message = "*Get-DomainUser*" -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `get_domainuser_with_powershell_script_block_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -The following Hunting analytic requires PowerShell operational logs to be imported. Modify the powershell macro as needed to match the sourcetype or add index. This analytic is specific to 4104, or PowerShell Script Block Logging. - -====Required field==== - -* _time - -* EventCode - -* Message - -* ComputerName - -* User - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1087.002 -| Domain Account -| Discovery -|- -| T1087 -| Account Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use this command for troubleshooting. - -====Reference==== - - -* https://powersploit.readthedocs.io/en/latest/Recon/Get-DomainUser/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/AD_discovery/windows-powershell.log - - -''version'': 1 -
-
- ----- - -===Get wmiobject group discovery=== -The following hunting analytic identifies the use of `Get-WMIObject Win32_Group` being used with PowerShell to identify local groups on the endpoint. \ Typically, by itself, is not malicious but may raise suspicion based on time of day, endpoint and username. \ During triage, review parallel processes and identify any further suspicious behavior. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1069/ T1069], [https://attack.mitre.org/techniques/T1069/001/ T1069.001] -* '''Last Updated''': 2021-09-14 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name=powershell.exe OR processes.process_name=cmd.exe) (Processes.process="*Get-WMIObject*" AND Processes.process="*Win32_Group*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.original_file_name Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `get_wmiobject_group_discovery_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1069 -| Permission Groups Discovery -| Discovery -|- -| T1069.001 -| Local Groups -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -False positives may be present. Tune as needed. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1069/001/ - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1069.001/T1069.001.md - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.001/atomic_red_team/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Get wmiobject group discovery with script block logging=== -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify suspicious PowerShell execution. Script Block Logging captures the command sent to PowerShell, the full command to be executed. Upon enabling, logs will output to Windows event logs. Dependent upon volume, enable on critical endpoints or all. \ -This analytic identifies the usage of `Get-WMIObject Win32_Group`, which is typically used as a way to identify groups on the endpoint. Typically, by itself, is not malicious but may raise suspicion based on time of day, endpoint and username. \ -During triage, review parallel processes using an EDR product or 4688 events. It will be important to understand the timeline of events around this activity. Review the entire logged PowerShell script block. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1069/ T1069], [https://attack.mitre.org/techniques/T1069/001/ T1069.001] -* '''Last Updated''': 2021-09-14 - -
-
- -====Search==== -`powershell` EventCode=4104 Message = "*Get-WMIObject*" AND Message = "*Win32_Group*" -| stats count min(_time) as firstTime max(_time) as lastTime by Message OpCode ComputerName User EventCode -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `get_wmiobject_group_discovery_with_script_block_logging_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -====Required field==== - -* _time - -* EventCode - -* Message - -* ComputerName - -* User - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1069 -| Permission Groups Discovery -| Discovery -|- -| T1069.001 -| Local Groups -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -False positives may be present. Tune as needed. - -====Reference==== - - -* https://www.splunk.com/en_us/blog/security/powershell-detections-threat-research-release-august-2021.html - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1069.001/T1069.001.md - -* https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -* https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63 - -* https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf - -* https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.001/atomic_red_team/windows-powershell.log - - -''version'': 1 -
-
- ----- - -===Get-domaintrust with powershell=== -This analytic identifies Get-DomainTrust from PowerView in order to gather domain trust information. Typically, this is utilized within a script being executed and used to enumerate the domain trust information. This grants the adversary an understanding of how large or small the domain is. During triage, review parallel processes using an EDR product or 4688 events. It will be important to understand the timeline of events around this activity. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1482/ T1482] -* '''Last Updated''': 2021-08-24 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process=*get-domaintrust* by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `get_domaintrust_with_powershell_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1482 -| Domain Trust Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Limited false positives as this requires an active Administrator or adversary to bring in, import, and execute. - -====Reference==== - - -* http://www.harmj0y.net/blog/redteaming/a-guide-to-attacking-domain-trusts/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1482/discovery/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Get-domaintrust with powershell script block=== -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify suspicious PowerShell execution. Script Block Logging captures the command sent to PowerShell, the full command to be executed. Upon enabling, logs will output to Windows event logs. Dependent upon volume, enable on critical endpoints or all. \ -This analytic identifies Get-DomainTrust from PowerView in order to gather domain trust information. \ -During triage, review parallel processes using an EDR product or 4688 events. It will be important to understand the timeline of events around this activity. Review the entire logged PowerShell script block. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1482/ T1482] -* '''Last Updated''': 2021-08-24 - -
-
- -====Search==== -`powershell` EventCode=4104 Message = "*get-foresttrust*" -| stats count min(_time) as firstTime max(_time) as lastTime by Message ComputerName User EventCode -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `get_domaintrust_with_powershell_script_block_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -====Required field==== - -* _time - -* EventCode - -* Message - -* Path - -* OpCode - -* ComputerName - -* User - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1482 -| Domain Trust Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -It is possible certain system management frameworks utilize this command to gather trust information. - -====Reference==== - - -* http://www.harmj0y.net/blog/redteaming/a-guide-to-attacking-domain-trusts/ - -* https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -* https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63 - -* https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf - -* https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1482/discovery/windows-powershell.log - - -''version'': 1 -
-
- ----- - -===Get-foresttrust with powershell=== -This analytic identifies Get-ForestTrust from PowerSploit in order to gather domain trust information. Typically, this is utilized within a script being executed and used to enumerate the domain trust information. This grants the adversary an understanding of how large or small the domain is. During triage, review parallel processes using an EDR product or 4688 events. It will be important to understand the timeline of events around this activity. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1482/ T1482] -* '''Last Updated''': 2021-09-02 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=powershell.exe OR Processes.process_name=cmd.exe Processes.process=*get-foresttrust* by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `get_foresttrust_with_powershell_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1482 -| Domain Trust Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Limited false positives as this requires an active Administrator or adversary to bring in, import, and execute. - -====Reference==== - - -* https://powersploit.readthedocs.io/en/latest/Recon/Get-ForestTrust/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1482/discovery/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Get-foresttrust with powershell script block=== -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify suspicious PowerShell execution. Script Block Logging captures the command sent to PowerShell, the full command to be executed. Upon enabling, logs will output to Windows event logs. Dependent upon volume, enable on critical endpoints or all. \ -This analytic identifies Get-ForestTrust from PowerSploit in order to gather domain trust information. \ -During triage, review parallel processes using an EDR product or 4688 events. It will be important to understand the timeline of events around this activity. Review the entire logged PowerShell script block. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1482/ T1482] -* '''Last Updated''': 2021-09-02 - -
-
- -====Search==== -`powershell` EventCode=4104 Message = "*get-foresttrust*" -| stats count min(_time) as firstTime max(_time) as lastTime by Message OpCode ComputerName User EventCode -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `get_foresttrust_with_powershell_script_block_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -====Required field==== - -* _time - -* EventCode - -* Message - -* Path - -* OpCode - -* ComputerName - -* User - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1482 -| Domain Trust Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -UPDATE_KNOWN_FALSE_POSITIVES - -====Reference==== - - -* https://powersploit.readthedocs.io/en/latest/Recon/Get-ForestTrust/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1482/discovery/windows-powershell.log - - -''version'': 1 -
-
- ----- - -===Getadcomputer with powershell=== -This analytic looks for the execution of `powershell.exe` with command-line arguments utilized to discover remote systems. The `Get-AdComputer' commandlet returns a list of all domain computers. Red Teams and adversaries alike may use this commandlet to identify remote systems for situational awareness and Active Directory Discovery. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1018/ T1018] -* '''Last Updated''': 2021-09-07 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="powershell.exe") (Processes.process=*Get-AdComputer*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `getadcomputer_with_powershell_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1018 -| Remote System Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use this command for troubleshooting. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1018/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/AD_discovery/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Getadcomputer with powershell script block=== -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-AdGroup` commandlet. The `Get-AdGroup` commandlet is used to return a list of all domain computers. Red Teams and adversaries may leverage this commandlet to enumerate domain computers for situational awareness and Active Directory Discovery. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1018/ T1018] -* '''Last Updated''': 2021-09-01 - -
-
- -====Search==== -`powershell` EventCode=4104 (Message = "*Get-AdComputer*") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `getadcomputer_with_powershell_script_block_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -====Required field==== - -* _time - -* EventCode - -* Message - -* ComputerName - -* User - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1018 -| Remote System Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use this PowerShell commandlet for troubleshooting. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1018/ - -* https://docs.microsoft.com/en-us/powershell/module/activedirectory/get-adgroup?view=windowsserver2019-ps - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/AD_discovery/windows-powershell.log - - -''version'': 1 -
-
- ----- - -===Getadgroup with powershell=== -This analytic looks for the execution of `powershell.exe` with command-line arguments utilized to query for domain groups. The `Get-AdGroup` commandlnet is used to return a list of all groups available in a Windows Domain. Red Teams and adversaries alike may leverage this commandlet to enumerate domain groups for situational awareness and Active Directory Discovery. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1069/ T1069], [https://attack.mitre.org/techniques/T1069/002/ T1069.002] -* '''Last Updated''': 2021-08-25 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="powershell.exe") (Processes.process=*Get-AdGroup*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `getadgroup_with_powershell_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1069 -| Permission Groups Discovery -| Discovery -|- -| T1069.002 -| Domain Groups -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use this command for troubleshooting. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1069/002/ - -* https://docs.microsoft.com/en-us/powershell/module/activedirectory/get-adgroup?view=windowsserver2019-ps - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.002/AD_discovery/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Getadgroup with powershell script block=== -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-AdGroup` commandlet. The `Get-AdGroup` commandlet is used to return a list of all domain groups. Red Teams and adversaries may leverage this commandlet to enumerate domain groups for situational awareness and Active Directory Discovery. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1069/ T1069], [https://attack.mitre.org/techniques/T1069/002/ T1069.002] -* '''Last Updated''': 2021-08-25 - -
-
- -====Search==== -`powershell` EventCode=4104 (Message = "*Get-ADGroup*") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `getadgroup_with_powershell_script_block_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -====Required field==== - -* _time - -* EventCode - -* Message - -* ComputerName - -* User - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1069 -| Permission Groups Discovery -| Discovery -|- -| T1069.002 -| Domain Groups -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use this PowerShell commandlet for troubleshooting. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1069/002/ - -* https://docs.microsoft.com/en-us/powershell/module/activedirectory/get-adgroup?view=windowsserver2019-ps - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.002/AD_discovery/windows-powershell.log - - -''version'': 1 -
-
- ----- - -===Getcurrent user with powershell=== -This analytic looks for the execution of `powerhsell.exe` with command-line arguments that execute the `GetCurrent` method of the WindowsIdentity .NET class. This method returns an object that represents the current Windows user. Red Teams and adversaries may leverage this method to identify the logged user on a compromised endpoint for situational awareness and Active Directory Discovery. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1033/ T1033] -* '''Last Updated''': 2021-09-13 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="powershell.exe") (Processes.process=*System.Security.Principal.WindowsIdentity* OR Processes.process=*GetCurrent()*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `getcurrent_user_with_powershell_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1033 -| System Owner/User Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use this command for troubleshooting. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1033/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1033/AD_discovery/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Getcurrent user with powershell script block=== -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `GetCurrent` method of the WindowsIdentity .NET class. This method returns an object that represents the current Windows user. Red Teams and adversaries may leverage this method to identify the logged user on a compromised endpoint for situational awareness and Active Directory Discovery. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1033/ T1033] -* '''Last Updated''': 2021-09-13 - -
-
- -====Search==== -`powershell` EventCode=4104 (Message = "*[System.Security.Principal.WindowsIdentity]*" AND Message = "*GetCurrent()*") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `getcurrent_user_with_powershell_script_block_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -====Required field==== - -* _time - -* Path - -* Message - -* OpCode - -* ComputerName - -* User - -* EventCode - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1033 -| System Owner/User Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use this PowerShell commandlet for troubleshooting. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1033/ - -* https://docs.microsoft.com/en-us/dotnet/api/system.security.principal.windowsidentity.getcurrent?view=net-5.0 - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1033/AD_discovery/windows-powershell.log - - -''version'': 1 -
-
- ----- - -===Getdomaincomputer with powershell=== -This analytic looks for the execution of `powershell.exe` with command-line arguments utilized to discover remote systems. `Get-DomainComputer` is part of PowerView, a PowerShell tool used to perform enumeration on Windows domains. Red Teams and adversaries alike may leverage PowerView to enumerate domain groups for situational awareness and Active Directory Discovery. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1018/ T1018] -* '''Last Updated''': 2021-09-07 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="powershell.exe") (Processes.process=*Get-DomainComputer*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `getdomaincomputer_with_powershell_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1018 -| Remote System Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use PowerView for troubleshooting. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1018/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/AD_discovery/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Getdomaincomputer with powershell script block=== -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-DomainComputer` commandlet. `GetDomainComputer` is part of PowerView, a PowerShell tool used to perform enumeration on Windows domains. Red Teams and adversaries alike may use PowerView to enumerate domain computers for situational awareness and Active Directory Discovery. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1018/ T1018] -* '''Last Updated''': 2021-09-02 - -
-
- -====Search==== -`powershell` EventCode=4104 (Message = "*Get-DomainComputer*") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `getdomaincomputer_with_powershell_script_block_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -====Required field==== - -* _time - -* EventCode - -* Message - -* ComputerName - -* User - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1018 -| Remote System Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use PowerView for troubleshooting. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1018/ - -* https://powersploit.readthedocs.io/en/latest/Recon/Get-DomainComputer/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/AD_discovery/windows-powershell.log - - -''version'': 1 -
-
- ----- - -===Getdomaincontroller with powershell=== -This analytic looks for the execution of `powershell.exe` with command-line arguments utilized to discover remote systems. `Get-DomainController` is part of PowerView, a PowerShell tool used to perform enumeration on Windows domains. Red Teams and adversaries alike may leverage PowerView to enumerate domain groups for situational awareness and Active Directory Discovery. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1018/ T1018] -* '''Last Updated''': 2021-09-07 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="powershell.exe") (Processes.process=*Get-DomainController*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `getdomaincontroller_with_powershell_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1018 -| Remote System Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use PowerView for troubleshooting. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1018/ - -* https://powersploit.readthedocs.io/en/latest/Recon/Get-DomainController/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/AD_discovery/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Getdomaincontroller with powershell script block=== -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-DomainController` commandlet. `Get-DomainController` is part of PowerView, a PowerShell tool used to perform enumeration on Windows domains. Red Teams and adversaries alike may use PowerView to enumerate domain computers for situational awareness and Active Directory Discovery. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1018/ T1018] -* '''Last Updated''': 2021-09-02 - -
-
- -====Search==== -`powershell` EventCode=4104 (Message = "*Get-DomainController*") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `getdomaincontroller_with_powershell_script_block_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -====Required field==== - -* _time - -* EventCode - -* Message - -* ComputerName - -* User - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1018 -| Remote System Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use this PowerShell commandlet for troubleshooting. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1018/ - -* https://powersploit.readthedocs.io/en/latest/Recon/Get-DomainController/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/AD_discovery/windows-powershell.log - - -''version'': 1 -
-
- ----- - -===Getdomaingroup with powershell=== -This analytic looks for the execution of `powershell.exe` with command-line arguments utilized to query for domain groups. `Get-DomainGroup` is part of PowerView, a PowerShell tool used to perform enumeration on Windows domains. Red Teams and adversaries alike may leverage PowerView to enumerate domain groups for situational awareness and Active Directory Discovery. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1069/ T1069], [https://attack.mitre.org/techniques/T1069/002/ T1069.002] -* '''Last Updated''': 2021-08-25 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="powershell.exe") (Processes.process=*Get-DomainGroup*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `getdomaingroup_with_powershell_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1069 -| Permission Groups Discovery -| Discovery -|- -| T1069.002 -| Domain Groups -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use this command for troubleshooting. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1069/002/ - -* https://powersploit.readthedocs.io/en/latest/Recon/Get-DomainGroup/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.002/AD_discovery/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Getdomaingroup with powershell script block=== -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-DomainGroup` commandlet. `Get-DomainGroup` is part of PowerView, a PowerShell tool used to perform enumeration on Windows domains. As the name suggests, `Get-DomainGroup` is used to query domain groups. Red Teams and adversaries may leverage this function to enumerate domain groups for situational awareness and Active Directory Discovery. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1069/ T1069], [https://attack.mitre.org/techniques/T1069/002/ T1069.002] -* '''Last Updated''': 2021-08-26 - -
-
- -====Search==== -`powershell` EventCode=4104 (Message = "*Get-DomainGroup*") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `getdomaingroup_with_powershell_script_block_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -====Required field==== - -* _time - -* EventCode - -* Message - -* ComputerName - -* User - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1069 -| Permission Groups Discovery -| Discovery -|- -| T1069.002 -| Domain Groups -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use this PowerView functions for troubleshooting. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1069/002/ - -* https://powersploit.readthedocs.io/en/latest/Recon/Get-DomainGroup/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.002/AD_discovery/windows-powershell.log - - -''version'': 1 -
-
- ----- - -===Getlocaluser with powershell=== -This analytic looks for the execution of `powershell.exe` with command-line arguments utilized to query for local users. The `Get-LocalUser` commandlet is used to return a list of all local users. Red Teams and adversaries may leverage this commandlet to enumerate users for situational awareness and Active Directory Discovery. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/ T1087], [https://attack.mitre.org/techniques/T1087/001/ T1087.001] -* '''Last Updated''': 2021-08-23 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="powershell.exe") (Processes.process=*Get-LocalUser*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `getlocaluser_with_powershell_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* _time - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1087 -| Account Discovery -| Discovery -|- -| T1087.001 -| Local Account -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use this PowerShell commandlet for troubleshooting. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1087/001/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.001/AD_discovery/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Getlocaluser with powershell script block=== -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-LocalUser` commandlet. The `Get-LocalUser` commandlet is used to return a list of all local users. Red Teams and adversaries may leverage this commandlet to enumerate users for situational awareness and Active Directory Discovery. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/ T1087], [https://attack.mitre.org/techniques/T1087/001/ T1087.001] -* '''Last Updated''': 2021-08-23 - -
-
- -====Search==== -`powershell` EventCode=4104 (Message = "*Get-LocalUser*") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `getlocaluser_with_powershell_script_block_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -====Required field==== - -* _time - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1087 -| Account Discovery -| Discovery -|- -| T1087.001 -| Local Account -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use this PowerShell commandlet for troubleshooting. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1087/001/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.001/AD_discovery/windows-powershell.log - - -''version'': 1 -
-
- ----- - -===Getnettcpconnection with powershell=== -This analytic looks for the execution of `powershell.exe` with command-line utilized to get a listing of network connections on a compromised system. The `Get-NetTcpConnection` commandlet lists the current TCP connections. Red Teams and adversaries alike may use this commandlet for situational awareness and Active Directory Discovery. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1049/ T1049] -* '''Last Updated''': 2021-08-25 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="powershell.exe") (Processes.process=*Get-NetTcpConnection*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `getnettcpconnection_with_powershell_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1049 -| System Network Connections Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use this command for troubleshooting. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1049/ - -* https://docs.microsoft.com/en-us/powershell/module/nettcpip/get-nettcpconnection?view=windowsserver2019-ps - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1049/AD_discovery/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Getnettcpconnection with powershell script block=== -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-NetTcpconnection ` commandlet. This commandlet is used to return a listing of network connections on a compromised system. Red Teams and adversaries alike may use this commandlet for situational awareness and Active Directory Discovery. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1049/ T1049] -* '''Last Updated''': 2021-09-10 - -
-
- -====Search==== -`powershell` EventCode=4104 (Message = "*Get-NetTcpconnection*") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `getnettcpconnection_with_powershell_script_block_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -====Required field==== - -* _time - -* EventCode - -* Message - -* ComputerName - -* User - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1049 -| System Network Connections Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use this PowerShell commandlet for troubleshooting. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1049/ - -* https://docs.microsoft.com/en-us/powershell/module/nettcpip/get-nettcpconnection?view=windowsserver2019-ps - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1049/AD_discovery/windows-powershell.log - - -''version'': 1 -
-
- ----- - -===Getwmiobject ds user with powershell=== -This analytic looks for the execution of `powershell.exe` with command-line arguments utilized to query for domain users. The `Get-WmiObject` commandlet combined with the `-class ds_user` parameter can be used to return the full list of users in a Windows domain. Red Teams and adversaries alike may leverage WMI in this case, using PowerShell, to enumerate domain users for situational awareness and Active Directory Discovery. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/002/ T1087.002], [https://attack.mitre.org/techniques/T1087/ T1087] -* '''Last Updated''': 2021-08-24 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="cmd.exe" OR Processes.process_name="powershell*") AND Processes.process = "*get-wmiobject*" AND Processes.process = "*ds_user*" AND Processes.process = "*root\\directory\\ldap*" AND Processes.process = "*-namespace*" by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `getwmiobject_ds_user_with_powershell_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_id - -* Processes.parent_process_name - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1087.002 -| Domain Account -| Discovery -|- -| T1087 -| Account Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use this command for troubleshooting. - -====Reference==== - - -* https://jpcertcc.github.io/ToolAnalysisResultSheet/details/dsquery.htm - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/AD_discovery/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Getwmiobject ds user with powershell script block=== -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-WmiObject` commandlet. The `DS_User` class parameter leverages WMI to query for all domain users. Red Teams and adversaries may leverage this commandlet to enumerate domain users for situational awareness and Active Directory Discovery. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/002/ T1087.002], [https://attack.mitre.org/techniques/T1087/ T1087] -* '''Last Updated''': 2021-08-24 - -
-
- -====Search==== -`powershell` EventCode=4104 Message = "*get-wmiobject*" Message = "*ds_user*" Message = "*-namespace*" Message = "*root\\directory\\ldap*" -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `getwmiobject_ds_user_with_powershell_script_block_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -he following Hunting analytic requires PowerShell operational logs to be imported. Modify the powershell macro as needed to match the sourcetype or add index. This analytic is specific to 4104, or PowerShell Script Block Logging. - -====Required field==== - -* _time - -* EventCode - -* Message - -* ComputerName - -* User - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1087.002 -| Domain Account -| Discovery -|- -| T1087 -| Account Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use this command for troubleshooting. - -====Reference==== - - -* https://www.blackhillsinfosec.com/red-blue-purple/ - -* https://docs.microsoft.com/en-us/windows/win32/wmisdk/describing-the-ldap-namespace - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/AD_discovery/windows-powershell.log - - -''version'': 1 -
-
- ----- - -===Getwmiobject ds computer with powershell=== -This analytic looks for the execution of `powershell.exe` with command-line arguments utilized to discover remote systems. The `Get-WmiObject` commandlet combined with the `DS_Computer` parameter can be used to return a list of all domain computers. Red Teams and adversaries alike may leverage WMI in this case, using PowerShell, to enumerate domain groups for situational awareness and Active Directory Discovery. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1018/ T1018] -* '''Last Updated''': 2021-09-07 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="powershell.exe") (Processes.process=*Get-WmiObject* AND Processes.process="*namespace root\\directory\\ldap*" AND Processes.process="*class ds_computer*") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `getwmiobject_ds_computer_with_powershell_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1018 -| Remote System Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use this command for troubleshooting. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1018/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/AD_discovery/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Getwmiobject ds computer with powershell script block=== -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-WmiObject` commandlet. The `DS_Computer` class parameter leverages WMI to query for all domain computers. Red Teams and adversaries may leverage this commandlet to enumerate domain computers for situational awareness and Active Directory Discovery. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1018/ T1018] -* '''Last Updated''': 2021-09-01 - -
-
- -====Search==== -`powershell` EventCode=4104 (Message=*Get-WmiObject* AND Message=*"namespace root\\directory\\ldap"* AND Message=*"class ds_computer"*) -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `getwmiobject_ds_computer_with_powershell_script_block_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -====Required field==== - -* _time - -* EventCode - -* Message - -* ComputerName - -* User - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1018 -| Remote System Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use this PowerShell commandlet for troubleshooting. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1018/ - -* https://docs.microsoft.com/en-us/powershell/module/microsoft.powershell.management/get-wmiobject?view=powershell-5.1 - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/AD_discovery/windows-powershell.log - - -''version'': 1 -
-
- ----- - -===Getwmiobject ds group with powershell=== -This analytic looks for the execution of `powershell.exe` with command-line arguments utilized to query for domain groups. The `Get-WmiObject` commandlet combined with the `-class ds_group` parameter can be used to return the full list of groups in a Windows domain. Red Teams and adversaries alike may leverage WMI in this case, using PowerShell, to enumerate domain groups for situational awareness and Active Directory Discovery. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1069/ T1069], [https://attack.mitre.org/techniques/T1069/002/ T1069.002] -* '''Last Updated''': 2021-08-25 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="powershell.exe") (Processes.process=*Get-WmiObject* AND Processes.process="*namespace root\\directory\\ldap*" AND Processes.process="*class ds_group*") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `getwmiobject_ds_group_with_powershell_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1069 -| Permission Groups Discovery -| Discovery -|- -| T1069.002 -| Domain Groups -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use this command for troubleshooting. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1069/002/ - -* https://docs.microsoft.com/en-us/powershell/module/microsoft.powershell.management/get-wmiobject?view=powershell-5.1 - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.002/AD_discovery/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Getwmiobject ds group with powershell script block=== -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-WmiObject` commandlet used with specific parameters . The `DS_Group` parameter leverages WMI to query for all domain groups. Red Teams and adversaries may leverage this commandlet to enumerate domain groups for situational awareness and Active Directory Discovery. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1069/ T1069], [https://attack.mitre.org/techniques/T1069/002/ T1069.002] -* '''Last Updated''': 2021-08-25 - -
-
- -====Search==== -`powershell` EventCode=4104 (Message=*Get-WmiObject* AND Message=*"namespace root\\directory\\ldap"* AND Message=*"class ds_group"*) -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `getwmiobject_ds_group_with_powershell_script_block_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -====Required field==== - -* _time - -* EventCode - -* Message - -* ComputerName - -* User - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1069 -| Permission Groups Discovery -| Discovery -|- -| T1069.002 -| Domain Groups -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use this PowerShell commandlet for troubleshooting. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1069/002/ - -* https://docs.microsoft.com/en-us/powershell/module/microsoft.powershell.management/get-wmiobject?view=powershell-5.1 - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.002/AD_discovery/windows-powershell.log - - -''version'': 1 -
-
- ----- - -===Getwmiobject user account with powershell=== -This analytic looks for the execution of `powershell.exe` with command-line arguments utilized to query local users. The `Get-WmiObject` commandlet combined with the `Win32_UserAccount` parameter is used to return a list of all local users. Red Teams and adversaries may leverage this commandlet to enumerate users for situational awareness and Active Directory Discovery. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/ T1087], [https://attack.mitre.org/techniques/T1087/001/ T1087.001] -* '''Last Updated''': 2021-08-23 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="powershell.exe") (Processes.process=*Get-WmiObject* AND Processes.process=*Win32_UserAccount*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `getwmiobject_user_account_with_powershell_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* _time - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1087 -| Account Discovery -| Discovery -|- -| T1087.001 -| Local Account -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use this PowerShell commandlet for troubleshooting. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1087/001/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.001/AD_discovery/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Getwmiobject user account with powershell script block=== -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-WmiObject` commandlet used with specific parameters. The `Win32_UserAccount` parameter is used to return a list of all local users. Red Teams and adversaries may leverage this commandlet to enumerate users for situational awareness and Active Directory Discovery. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/ T1087], [https://attack.mitre.org/techniques/T1087/001/ T1087.001] -* '''Last Updated''': 2021-08-23 - -
-
- -====Search==== -`powershell` EventCode=4104 (Message="*Get-WmiObject*" AND Message="*Win32_UserAccount*") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `getwmiobject_user_account_with_powershell_script_block_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -====Required field==== - -* _time - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1087 -| Account Discovery -| Discovery -|- -| T1087.001 -| Local Account -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use this PowerShell commandlet for troubleshooting. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1087/001/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.001/AD_discovery/windows-powershell.log - - -''version'': 1 -
-
- ----- - -===Grant permission using cacls utility=== -This analytic identifies potential adversaries that modify the security permission of a specific file or directory. This technique is commonly seen in APT tradecraft, ransomware and coinminer scripts to evade detections and restrict access to their component files. - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1222/ T1222] -* '''Last Updated''': 2021-06-14 - -
-
- -====Search==== - -| from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line IS NOT NULL AND match_regex(cmd_line, /(?i)grant/)=true AND (process_name="cacls.exe" OR process_name="xcacls.exe" OR process_name="icacls.exe") -| eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#XMRig|XMRig]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed icacls.exe may be used. - -====Required field==== - -* _time - -* dest_device_id - -* process_name - -* parent_process_name - -* process_path - -* dest_user_id - -* process - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1222 -| File and Directory Permissions Modification -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -network administrator may use this windows utility but this is not a common practice. - -====Reference==== - - -* https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.001/ssa_cacls/all_icalc.log - - -''version'': 2 -
-
- ----- - -===Hide user account from sign-in screen=== -This analytic identifies a suspicious registry modification to hide a user account on the Windows Login screen. This technique was seen in some tradecraft where the adversary will create a hidden user account with Admin privileges in login screen to avoid noticing by the user that they already compromise and to persist on that said machine. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001], [https://attack.mitre.org/techniques/T1562/ T1562] -* '''Last Updated''': 2021-05-05 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count values(Registry.registry_key_name) as registry_key_name values(Registry.registry_path) as registry_path min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*\\Windows NT\\CurrentVersion\\Winlogon\\SpecialAccounts\\Userlist*" AND Registry.registry_value_name = "DWORD (0x00000000)" by Registry.dest Registry.user Registry.registry_value_name -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `drop_dm_object_name(Registry)` -| `hide_user_account_from_sign_in_screen_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#XMRig|XMRig]] - - -====How To Implement==== -To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as CarbonBlack or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. - -====Required field==== - -* _time - -* Registry.registry_key_name - -* Registry.registry_path - -* Registry.registry_value_name - -* Registry.dest Registry.user - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1562.001 -| Disable or Modify Tools -| Defense Evasion -|- -| T1562 -| Impair Defenses -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Unknown. Filter as needed. - -====Reference==== - - -* https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/hotkey_disabled_hidden_user/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Hiding files and directories with attrib exe=== -Attackers leverage an existing Windows binary, attrib.exe, to mark specific as hidden by using specific flags so that the victim does not see the file. The search looks for specific command-line arguments to detect the use of attrib.exe to hide files. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1222/ T1222], [https://attack.mitre.org/techniques/T1222/001/ T1222.001] -* '''Last Updated''': 2020-07-21 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) values(Processes.process) as process max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=attrib.exe (Processes.process=*+h*) by Processes.parent_process Processes.process_name Processes.user Processes.dest -| `drop_dm_object_name("Processes")` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -| `hiding_files_and_directories_with_attrib_exe_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Defense_Evasion_Tactics|Windows Defense Evasion Tactics]] - -* [[Documentation:ESSOC:stories:UseCase#Windows_Persistence_Techniques|Windows Persistence Techniques]] - - -====How To Implement==== -You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. - -====Required field==== - -* _time - -* Processes.process - -* Processes.process_name - -* Processes.parent_process - -* Processes.user - -* Processes.dest - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1222 -| File and Directory Permissions Modification -| Defense Evasion -|- -| T1222.001 -| Windows File and Directory Permissions Modification -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Some applications and users may legitimately use attrib.exe to interact with the files. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.001/atomic_red_team/windows-sysmon.log - - -''version'': 4 -
-
- ----- - -===High file deletion frequency=== -This search looks for high frequency of file deletion relative to process name and process id. These events usually happen when the ransomware tries to encrypt the files with the ransomware file extensions and sysmon treat the original files to be deleted as soon it was replace as encrypted data. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1485/ T1485] -* '''Last Updated''': 2021-03-16 - -
-
- -====Search==== -`sysmon` EventCode=23 TargetFilename IN ("*\.cmd", "*\.ini","*\.gif", "*\.jpg", "*\.jpeg", "*\.db", "*\.ps1", "*\.doc*", "*\.xls*", "*\.ppt*", "*\.bmp","*\.zip", "*\.rar", "*\.7z", "*\.chm", "*\.png", "*\.log", "*\.vbs", "*\.js") -| stats values(TargetFilename) as deleted_files min(_time) as firstTime max(_time) as lastTime count by Computer user EventCode Image ProcessID -|where count >=100 -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `high_file_deletion_frequency_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Clop_Ransomware|Clop Ransomware]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the deleted target file name, process name and process id from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -====Required field==== - -* EventCode - -* TargetFilename - -* Computer - -* user - -* Image - -* ProcessID - -* _time - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1485 -| Data Destruction -| Impact -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -user may delete bunch of pictures or files in a folder. - -====Reference==== - - -* https://www.fireeye.com/blog/threat-research/2020/10/fin11-email-campaigns-precursor-for-ransomware-data-theft.html - -* https://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_a/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===High process termination frequency=== -This analytics are designed to indentify a high frequency of process termination on a machine which is a common behavior of ransomware malware before encrypting files. This technique is designed to avoid an exception error while accessing (docs, images, database and etc..) in the infected machine for encryption. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1486/ T1486] -* '''Last Updated''': 2021-03-16 - -
-
- -====Search==== -`sysmon` EventCode=5 -|bin _time span=3s -|stats values(Image) as proc_terminated min(_time) as firstTime max(_time) as lastTime count by Computer EventCode ProcessID -| where count >= 15 -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `high_process_termination_frequency_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Clop_Ransomware|Clop Ransomware]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the Image (process full path of terminated process) from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -====Required field==== - -* EventCode - -* Image - -* Computer - -* _time - -* ProcessID - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1486 -| Data Encrypted for Impact -| Impact -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -admin or user tool that can terminate multiple process. - -====Reference==== - - -* https://www.fireeye.com/blog/threat-research/2020/10/fin11-email-campaigns-precursor-for-ransomware-data-theft.html - -* https://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_a/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Icacls grant command=== -This analytic identifies potential adversaries that modify the security permission of a specific file or directory. This technique is commonly seen in APT tradecraft and coinminer scripts to evade detections and restrict access to their component files. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1222/ T1222] -* '''Last Updated''': 2021-05-04 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` values(Processes.process) as process values(Processes.process_id) as process_id count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = "icacls.exe" OR Processes.process_name = "cacls.exe" OR Processes.process_name = "xcacls.exe" AND Processes.process = "*/grant*" by Processes.parent_process_name Processes.process_name Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `icacls_grant_command_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#XMRig|XMRig]] - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed icacls.exe may be used. - -====Required field==== - -* _time - -* Processes.parent_process_name - -* Processes.process_name - -* Processes.dest - -* Processes.user - -* Processes.process_id - -* Processes.process - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1222 -| File and Directory Permissions Modification -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Unknown. Filter as needed. - -====Reference==== - - -* https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Icacls deny command=== -This analytic identifies a potential adversary that changes the security permission of a specific file or directory. This technique is commonly seen in APT tradecraft or coinminer scripts. This behavior is meant to evade detection and prevent access to their component files. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1222/ T1222] -* '''Last Updated''': 2021-04-29 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` values(Processes.process) as process values(Processes.process_id) as process_id count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = "icacls.exe" OR Processes.process_name = "cacls.exe" OR Processes.process_name = "xcacls.exe" AND Processes.process = "*/deny*" by Processes.parent_process_name Processes.process_name Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `icacls_deny_command_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#XMRig|XMRig]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed icacls.exe may be used. - -====Required field==== - -* _time - -* Processes.parent_process_name - -* Processes.process_name - -* Processes.dest - -* Processes.user - -* Processes.process_id - -* Processes.process - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1222 -| File and Directory Permissions Modification -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Unknown. It is possible some administrative scripts use ICacls. Filter as needed. - -====Reference==== - - -* https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Icedid exfiltrated archived file creation=== -This search is to detect a suspicious file creation namely passff.tar and cookie.tar. This files are possible archived of stolen browser information like history and cookies in a compromised machine with IcedID. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1560/001/ T1560.001], [https://attack.mitre.org/techniques/T1560/ T1560] -* '''Last Updated''': 2021-07-30 - -
-
- -====Search==== -`sysmon` EventCode= 11 (TargetFilename = "*\\passff.tar" OR TargetFilename = "*\\cookie.tar") -|stats count min(_time) as firstTime max(_time) as lastTime by TargetFilename EventCode process_id process_name Computer -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `icedid_exfiltrated_archived_file_creation_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#IcedID|IcedID]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -====Required field==== - -* _time - -* TargetFilename - -* EventCode - -* process_id - -* process_name - -* Computer - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1560.001 -| Archive via Utility -| Collection -|- -| T1560 -| Archive Collected Data -| Collection -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://www.cisecurity.org/white-papers/security-primer-icedid/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/simulated_icedid/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Illegal access to user content via powersploit modules=== -This detection identifies access to PowerSploit modules that enable illegaly access user content, such as key logging, audio recording, screenshots, tapping into http and RDP sessions, etc. - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1021/ T1021], [https://attack.mitre.org/techniques/T1113/ T1113], [https://attack.mitre.org/techniques/T1123/ T1123], [https://attack.mitre.org/techniques/T1563/ T1563] -* '''Last Updated''': 2020-11-09 - -
-
- -====Search==== - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)Get-HttpStatus/)=true OR match_regex(cmd_line, /(?i)Get-Keystrokes/)=true OR match_regex(cmd_line, /(?i)Get-MicrophoneAudio/)=true OR match_regex(cmd_line, /(?i)Get-NetRDPSession/)=true OR match_regex(cmd_line, /(?i)Get-TimedScreenshot/)=true OR match_regex(cmd_line, /(?i)Get-WebConfig/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Malicious_PowerShell|Malicious PowerShell]] - - -====How To Implement==== -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -====Required field==== - -* dest_device_id - -* dest_user_id - -* process - -* _time - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1021 -| Remote Services -| Lateral Movement -|- -| T1113 -| Screen Capture -| Collection -|- -| T1123 -| Audio Capture -| Collection -|- -| T1563 -| Remote Service Session Hijacking -| Lateral Movement -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -None identified. - -====Reference==== - - -* https://github.com/PowerShellMafia/PowerSploit - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021/illegal_access_to_content/logAllPowerSploitModulesWithOldNames.log - - -''version'': 1 -
-
- ----- - -===Illegal account creation via powersploit modules=== -This detection identifies access to PowerSploit modules that create accounts illegaly. - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1585/ T1585] -* '''Last Updated''': 2020-11-09 - -
-
- -====Search==== - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)New-DomainUser/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Persistence_Techniques|Windows Persistence Techniques]] - - -====How To Implement==== -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -====Required field==== - -* dest_device_id - -* dest_user_id - -* process - -* _time - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1585 -| Establish Accounts -| Resource Development -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -None identified. - -====Reference==== - - -* https://github.com/PowerShellMafia/PowerSploit - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1585/illegal_account_creation/logAllPowerSploitModulesWithOldNames.log - - -''version'': 1 -
-
- ----- - -===Illegal deletion of logs via mimikatz modules=== -This detection identifies access to PowerSploit modules that delete event logs. - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1070/ T1070] -* '''Last Updated''': 2020-11-09 - -
-
- -====Search==== - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)event::drop/)=true OR match_regex(cmd_line, /(?i)event::clear/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Log_Manipulation|Windows Log Manipulation]] - - -====How To Implement==== -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -====Required field==== - -* dest_device_id - -* dest_user_id - -* process - -* _time - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1070 -| Indicator Removal on Host -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -None identified. - -====Reference==== - - -* https://github.com/gentilkiwi/mimikatz - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070/illegal_log_deletion/logAllMimikatzModules.log - - -''version'': 1 -
-
- ----- - -===Illegal enabling or disabling of accounts via dsinternals modules=== -This detection identifies use of DSInternals modules that enable or disable accounts illegaly. - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/ T1078], [https://attack.mitre.org/techniques/T1098/ T1098] -* '''Last Updated''': 2020-11-09 - -
-
- -====Search==== - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)Disable-ADDBAccount/)=true OR match_regex(cmd_line, /(?i)Enable-ADDBAccount/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Persistence_Techniques|Windows Persistence Techniques]] - - -====How To Implement==== -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -====Required field==== - -* dest_device_id - -* dest_user_id - -* process - -* _time - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1078 -| Valid Accounts -| Defense Evasion, Persistence, Privilege Escalation, Initial Access -|- -| T1098 -| Account Manipulation -| Persistence -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -None identified. - -====Reference==== - - -* https://github.com/MichaelGrafnetter/DSInternals - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/account_manipulation/logAllDSInternalsModules.log - - -''version'': 1 -
-
- ----- - -===Illegal management of active directory elements and policies via dsinternals modules=== -This detection identifies use of DSInternals modules for illegal management of Active Directoty elements and policies. - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1098/ T1098], [https://attack.mitre.org/techniques/T1207/ T1207], [https://attack.mitre.org/techniques/T1484/ T1484] -* '''Last Updated''': 2020-11-09 - -
-
- -====Search==== - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)Remove-ADDBObject/)=true OR match_regex(cmd_line, /(?i)Set-ADDBDomainController/)=true OR match_regex(cmd_line, /(?i)Set-ADDBPrimaryGroup/)=true OR match_regex(cmd_line, /(?i)Set-LsaPolicyInformation/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Persistence_Techniques|Windows Persistence Techniques]] - - -====How To Implement==== -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -====Required field==== - -* dest_device_id - -* dest_user_id - -* process - -* _time - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1098 -| Account Manipulation -| Persistence -|- -| T1207 -| Rogue Domain Controller -| Defense Evasion -|- -| T1484 -| Domain Policy Modification -| Defense Evasion, Privilege Escalation -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -None identified. - -====Reference==== - - -* https://github.com/MichaelGrafnetter/DSInternals - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1484/logAllDSInternalsModules.log - - -''version'': 1 -
-
- ----- - -===Illegal management of computers and active directory elements via powersploit modules=== -This detection identifies access to PowerSploit modules that enable illegal management of computers and Active Directory elements. - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1098/ T1098], [https://attack.mitre.org/techniques/T1207/ T1207], [https://attack.mitre.org/techniques/T1484/ T1484] -* '''Last Updated''': 2020-11-09 - -
-
- -====Search==== - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)Set-DomainObject/)=true OR match_regex(cmd_line, /(?i)Set-ADObject/)=true OR match_regex(cmd_line, /(?i)Set-DomainObjectOwner/)=true OR match_regex(cmd_line, /(?i)Set-MasterBootRecord/)=true ) - - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Persistence_Techniques|Windows Persistence Techniques]] - - -====How To Implement==== -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -====Required field==== - -* dest_device_id - -* dest_user_id - -* process - -* _time - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1098 -| Account Manipulation -| Persistence -|- -| T1207 -| Rogue Domain Controller -| Defense Evasion -|- -| T1484 -| Domain Policy Modification -| Defense Evasion, Privilege Escalation -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -None identified. - -====Reference==== - - -* https://github.com/PowerShellMafia/PowerSploit - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1484/logAllPowerSploitModulesWithOldNames.log - - -''version'': 1 -
-
- ----- - -===Illegal privilege elevation and persistence via powersploit modules=== -This detection identifies access to PowerSploit modules that illegaly elevate general privileges or ensure persistence, e.g., enable manipulation of registry, task scheduling, persistent WMI, access to OS objects under desired identities. - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1053/ T1053], [https://attack.mitre.org/techniques/T1134/ T1134], [https://attack.mitre.org/techniques/T1548/ T1548] -* '''Last Updated''': 2020-11-09 - -
-
- -====Search==== - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)Add-DomainObjectAcl/)=true OR match_regex(cmd_line, /(?i)Add-ObjectAcl/)=true OR match_regex(cmd_line, /(?i)Enable-Privilege/)=true OR match_regex(cmd_line, /(?i)New-ElevatedPersistenceOption/)=true OR match_regex(cmd_line, /(?i)New-UserPersistenceOption/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Malicious_PowerShell|Malicious PowerShell]] - -* [[Documentation:ESSOC:stories:UseCase#Windows_Persistence_Techniques|Windows Persistence Techniques]] - - -====How To Implement==== -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -====Required field==== - -* dest_device_id - -* dest_user_id - -* process - -* _time - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1053 -| Scheduled Task/Job -| Execution, Persistence, Privilege Escalation -|- -| T1134 -| Access Token Manipulation -| Defense Evasion, Privilege Escalation -|- -| T1548 -| Abuse Elevation Control Mechanism -| Privilege Escalation, Defense Evasion -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -None identified. - -====Reference==== - - -* https://github.com/PowerShellMafia/PowerSploit - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/logAllPowerSploitModulesWithOldNames.log - - -''version'': 1 -
-
- ----- - -===Illegal privilege elevation via mimikatz modules=== -This detection identifies use of Mimikatz modules for illegal privilege elevation. - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1134/ T1134], [https://attack.mitre.org/techniques/T1548/ T1548] -* '''Last Updated''': 2020-11-09 - -
-
- -====Search==== - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)privilege::debug/)=true OR match_regex(cmd_line, /(?i)token::elevate/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Privilege_Escalation|Windows Privilege Escalation]] - - -====How To Implement==== -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -====Required field==== - -* dest_device_id - -* dest_user_id - -* process - -* _time - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1134 -| Access Token Manipulation -| Defense Evasion, Privilege Escalation -|- -| T1548 -| Abuse Elevation Control Mechanism -| Privilege Escalation, Defense Evasion -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -None identified. - -====Reference==== - - -* https://github.com/gentilkiwi/mimikatz - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/logAllMimikatzModules.log - - -''version'': 1 -
-
- ----- - -===Illegal service and process control via mimikatz modules=== -This detection identifies use of Mimikatz modules for illegal control over services and processes, including the authentication service. - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1055/ T1055], [https://attack.mitre.org/techniques/T1106/ T1106], [https://attack.mitre.org/techniques/T1569/ T1569] -* '''Last Updated''': 2020-11-09 - -
-
- -====Search==== - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)process::start/)=true OR match_regex(cmd_line, /(?i)service::\+/)=true OR match_regex(cmd_line, /(?i)service::\-/)=true OR match_regex(cmd_line, /(?i)service::start/)=true OR match_regex(cmd_line, /(?i)service::stop/)=true OR match_regex(cmd_line, /(?i)service::suspend/)=true OR match_regex(cmd_line, /(?i)misc::memssp/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Service_Abuse|Windows Service Abuse]] - - -====How To Implement==== -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -====Required field==== - -* dest_device_id - -* dest_user_id - -* process - -* _time - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1055 -| Process Injection -| Defense Evasion, Privilege Escalation -|- -| T1106 -| Native API -| Execution -|- -| T1569 -| System Services -| Execution -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -None identified. - -====Reference==== - - -* https://github.com/gentilkiwi/mimikatz - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllMimikatzModules.log - - -''version'': 1 -
-
- ----- - -===Illegal service and process control via powersploit modules=== -This detection identifies access to PowerSploit modules that enable illegal control of services and processes, such as installing or spoofing of malicious services, injecting malicious code in DLLs and EXEs, invoking shell code and WMI commands, modifying access to service objects, etc. - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1055/ T1055], [https://attack.mitre.org/techniques/T1106/ T1106], [https://attack.mitre.org/techniques/T1569/ T1569] -* '''Last Updated''': 2020-11-09 - -
-
- -====Search==== - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)Install-SSP/)=true OR match_regex(cmd_line, /(?i)Set-CriticalProcess/)=true OR match_regex(cmd_line, /(?i)Install-ServiceBinary/)=true OR match_regex(cmd_line, /(?i)Restore-ServiceBinary/)=true OR match_regex(cmd_line, /(?i)Write-ServiceBinary/)=true OR match_regex(cmd_line, /(?i)Set-ServiceBinaryPath/)=true OR match_regex(cmd_line, /(?i)Invoke-ReflectivePEInjection/)=true OR match_regex(cmd_line, /(?i)Invoke-DllInjection/)=true OR match_regex(cmd_line, /(?i)Invoke-ServiceAbuse/)=true OR match_regex(cmd_line, /(?i)Invoke-Shellcode/)=true OR match_regex(cmd_line, /(?i)Invoke-WScriptUACBypass/)=true OR match_regex(cmd_line, /(?i)Invoke-WmiCommand/)=true OR match_regex(cmd_line, /(?i)Write-HijackDll/)=true OR match_regex(cmd_line, /(?i)Add-ServiceDacl/)=true ) - - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Service_Abuse|Windows Service Abuse]] - -* [[Documentation:ESSOC:stories:UseCase#Malicious_PowerShell|Malicious PowerShell]] - - -====How To Implement==== -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -====Required field==== - -* dest_device_id - -* dest_user_id - -* process - -* _time - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1055 -| Process Injection -| Defense Evasion, Privilege Escalation -|- -| T1106 -| Native API -| Execution -|- -| T1569 -| System Services -| Execution -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -None identified. - -====Reference==== - - -* https://github.com/PowerShellMafia/PowerSploit - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllPowerSploitModulesWithOldNames.log - - -''version'': 1 -
-
- ----- - -===Jscript execution using cscript app=== -This search is to detect a execution of jscript using cscript process. Commonly when a user run jscript file it was executed by wscript.exe application. This technique was seen in FIN7 js implant to execute its malicious script using cscript process. This behavior is uncommon and a good artifacts to check further anomalies within the network - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/ T1059], [https://attack.mitre.org/techniques/T1059/007/ T1059.007] -* '''Last Updated''': 2021-09-13 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.parent_process_name = "cscript.exe" AND Processes.parent_process = "*//e:jscript*") OR (Processes.process_name = "cscript.exe" AND Processes.process = "*//e:jscript*") by Processes.parent_process_name Processes.parent_process Processes.process_name Processes.process_id Processes.process Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `jscript_execution_using_cscript_app_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#FIN7|FIN7]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -====Required field==== - -* _time - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.process_name - -* Processes.process_id - -* Processes.process - -* Processes.dest - -* Processes.user - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1059 -| Command and Scripting Interpreter -| Execution -|- -| T1059.007 -| JavaScript -| Execution -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://www.fireeye.com/blog/threat-research/2018/08/fin7-pursuing-an-enigmatic-and-evasive-global-criminal-operation.html - -* https://attack.mitre.org/groups/G0046/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/fin7/fin7_macro_js_1/sysmon.log - - -''version'': 1 -
-
- ----- - -===Kerberoasting spn request with rc4 encryption=== -This search detects a potential kerberoasting attack via service principal name requests - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1558/003/ T1558.003], [https://attack.mitre.org/techniques/T1558/ T1558] -* '''Last Updated''': 2020-10-16 - -
-
- -====Search==== -`wineventlog_security` EventCode=4769 Ticket_Options=0x40810000 Ticket_Encryption_Type=0x17 -| stats count min(_time) as firstTime max(_time) as lastTime by dest, service, service_id, Ticket_Encryption_Type, Ticket_Options -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `kerberoasting_spn_request_with_rc4_encryption_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Lateral_Movement|Lateral Movement]] - - -====How To Implement==== -You must be ingesting endpoint data that tracks process activity, and include the windows security event logs that contain kerberos - -====Required field==== - -* _time - -* EventCode - -* Ticket_Options - -* Ticket_Encryption_Type - -* dest - -* service - -* service_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1558.003 -| Kerberoasting -| Credential Access -|- -| T1558 -| Steal or Forge Kerberos Tickets -| Credential Access -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Older systems that support kerberos RC4 by default NetApp may generate false positives - -====Reference==== - - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1208/T1208.md - -* https://www.trimarcsecurity.com/post/trimarcresearch-detecting-kerberoasting-activity - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1558.003/atomic_red_team/windows-security.log - - -''version'': 3 -
-
- ----- - -===Known services killed by ransomware=== -This search detects a suspicioous termination of known services killed by ransomware before encrypting files in a compromised machine. This technique is commonly seen in most of ransomware now a days to avoid exception error while accessing the targetted files it wants to encrypts because of the open handle of those services to the targetted file. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1490/ T1490] -* '''Last Updated''': 2021-06-04 - -
-
- -====Search==== -`wineventlog_system` EventCode=7036 Message IN ("*Volume Shadow Copy*","*VSS*", "*backup*", "*sophos*", "*sql*", "*memtas*", "*mepocs*", "*veeam*", "*svc$*") Message="*service entered the stopped state*" -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message dest Type -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `known_services_killed_by_ransomware_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - -* [[Documentation:ESSOC:stories:UseCase#BlackMatter_Ransomware|BlackMatter Ransomware]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the 7036 EventCode ScManager in System audit Logs from your endpoints. - -====Required field==== - -* _time - -* EventCode - -* Message - -* dest - -* Type - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1490 -| Inhibit System Recovery -| Impact -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Admin activities or installing related updates may do a sudden stop to list of services we monitor. - -====Reference==== - - -* https://krebsonsecurity.com/2021/05/a-closer-look-at-the-darkside-ransomware-gang/ - -* https://www.mcafee.com/blogs/other-blogs/mcafee-labs/mcafee-atr-analyzes-sodinokibi-aka-revil-ransomware-as-a-service-what-the-code-tells-us/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/revil/inf3/windows-system.log - - -''version'': 1 -
-
- ----- - -===Local account discovery with wmic=== -This analytic looks for the execution of `wmic.exe` with command-line arguments utilized to query for local users. The argument `useraccount` is used to leverage WMI to return a list of all local users. Red Teams and adversaries alike use net.exe to enumerate users for situational awareness and Active Directory Discovery. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/ T1087], [https://attack.mitre.org/techniques/T1087/001/ T1087.001] -* '''Last Updated''': 2021-09-16 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_wmic` (Processes.process=*useraccount*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `local_account_discovery_with_wmic_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* _time - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1087 -| Account Discovery -| Discovery -|- -| T1087.001 -| Local Account -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use this command for troubleshooting. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1087/001/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.001/AD_discovery/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Local account discovery with net=== -This analytic looks for the execution of `net.exe` or `net1.exe` with command-line arguments utilized to query for local users. The two arguments `user` and 'users', return a list of all local users. Red Teams and adversaries alike use net.exe to enumerate users for situational awareness and Active Directory Discovery. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/ T1087], [https://attack.mitre.org/techniques/T1087/001/ T1087.001] -* '''Last Updated''': 2021-09-16 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_net` (Processes.process=*user OR Processes.process=*users) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `local_account_discovery_with_net_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* _time - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1087 -| Account Discovery -| Discovery -|- -| T1087.001 -| Local Account -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use this command for troubleshooting. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1087/001/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.001/AD_discovery/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Logon script event trigger execution=== -This search is to detect a suspicious modification of registry entry to persist and gain privilege escalation upon booting up of compromised host. This technique was seen in several APT and malware where it modify UserInitMprLogonScript registry entry to its malicious payload to be executed upon boot up of the machine. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1037/ T1037], [https://attack.mitre.org/techniques/T1037/001/ T1037.001] -* '''Last Updated''': 2021-09-27 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path IN ("*\\Environment\\UserInitMprLogonScript") by Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `drop_dm_object_name(Registry)` -| `logon_script_event_trigger_execution_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Persistence_Techniques|Windows Persistence Techniques]] - -* [[Documentation:ESSOC:stories:UseCase#Windows_Privilege_Escalation|Windows Privilege Escalation]] - - -====How To Implement==== -To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. - -====Required field==== - -* _time - -* Registry.dest - -* Registry.user - -* Registry.registry_path - -* Registry.registry_key_name - -* Registry.registry_value_name - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1037 -| Boot or Logon Initialization Scripts -| Persistence, Privilege Escalation -|- -| T1037.001 -| Logon Script (Windows) -| Persistence, Privilege Escalation -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://attack.mitre.org/techniques/T1037/001 - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1037.001/logonscript_reg/sysmon.log - - -''version'': 1 -
-
- ----- - -===Ms scripting process loading ldap module=== -This search is to detect a suspicious MS scripting process such as wscript.exe or cscript.exe that loading ldap module to process ldap query. This behavior was seen in FIN7 implant where it uses javascript to execute ldap query to parse host information that will send to its C2 server. this anomaly detections is a good initial step to hunt further a suspicious ldap query or ldap related events to the host that may give you good information regarding ldap or AD information processing or might be a attacker. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/ T1059], [https://attack.mitre.org/techniques/T1059/007/ T1059.007] -* '''Last Updated''': 2021-09-13 - -
-
- -====Search==== -`sysmon` EventCode =7 Image IN ("*\\wscript.exe", "*\\cscript.exe") ImageLoaded IN ("*\\Wldap32.dll", "*\\adsldp.dll", "*\\adsldpc.dll") -| stats min(_time) as firstTime max(_time) as lastTime count by Image EventCode process_name ProcessId ProcessGuid Computer ImageLoaded -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `ms_scripting_process_loading_ldap_module_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#FIN7|FIN7]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed rundll32.exe may be used. - -====Required field==== - -* _time - -* Image - -* EventCode - -* process_name - -* ProcessId - -* ProcessGuid - -* Computer - -* ImageLoaded - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1059 -| Command and Scripting Interpreter -| Execution -|- -| T1059.007 -| JavaScript -| Execution -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -automation scripting language may used by network operator to do ldap query. - -====Reference==== - - -* https://www.fireeye.com/blog/threat-research/2018/08/fin7-pursuing-an-enigmatic-and-evasive-global-criminal-operation.html - -* https://attack.mitre.org/groups/G0046/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/fin7/fin7_js_2/sysmon.log - - -''version'': 1 -
-
- ----- - -===Ms scripting process loading wmi module=== -This search is to detect a suspicious MS scripting process such as wscript.exe or cscript.exe that loading wmi module to process wmi query. This behavior was seen in FIN7 implant where it uses javascript to execute wmi query to parse host information that will send to its C2 server. this anomaly detections is a good initial step to hunt further a suspicious wmi query or wmi related events to the host that may give you good information regarding process that are commonly using wmi query or modules or might be an attacker using this technique. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/ T1059], [https://attack.mitre.org/techniques/T1059/007/ T1059.007] -* '''Last Updated''': 2021-09-13 - -
-
- -====Search==== -`sysmon` EventCode =7 Image IN ("*\\wscript.exe", "*\\cscript.exe") ImageLoaded IN ("*\\fastprox.dll", "*\\wbemdisp.dll", "*\\wbemprox.dll", "*\\wbemsvc.dll" , "*\\wmiutils.dll", "*\\wbemcomn.dll") -| stats min(_time) as firstTime max(_time) as lastTime count by Image EventCode process_name ProcessId ProcessGuid Computer ImageLoaded -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `ms_scripting_process_loading_wmi_module_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#FIN7|FIN7]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed rundll32.exe may be used. - -====Required field==== - -* _time - -* Image - -* EventCode - -* process_name - -* ProcessId - -* ProcessGuid - -* Computer - -* ImageLoaded - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1059 -| Command and Scripting Interpreter -| Execution -|- -| T1059.007 -| JavaScript -| Execution -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -automation scripting language may used by network operator to do ldap query. - -====Reference==== - - -* https://www.fireeye.com/blog/threat-research/2018/08/fin7-pursuing-an-enigmatic-and-evasive-global-criminal-operation.html - -* https://attack.mitre.org/groups/G0046/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/fin7/fin7_js_2/sysmon.log - - -''version'': 1 -
-
- ----- - -===Msbuild suspicious spawned by script process=== -This analytic is to detect a suspicious child process of MSBuild spawned by Windows Script Host - cscript or wscript. This behavior or event are commonly seen and used by malware or adversaries to execute malicious msbuild process using malicious script in the compromised host. During triage, review parallel processes and identify any file modifications. MSBuild may load a script from the same path without having command-line arguments. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1127/001/ T1127.001], [https://attack.mitre.org/techniques/T1127/ T1127] -* '''Last Updated''': 2021-10-04 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count values(Processes.process_name) as process_name values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name IN ("wscript.exe", "cscript.exe") AND `process_msbuild` by Processes.dest Processes.parent_process Processes.parent_process_name Processes.process_name Processes.original_file_name Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `msbuild_suspicious_spawned_by_script_process_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Trusted_Developer_Utilities_Proxy_Execution_MSBuild|Trusted Developer Utilities Proxy Execution MSBuild]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.parent_process - -* Processes.parent_process_name - -* Processes.process_name - -* Processes.original_file_name - -* Processes.user - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1127.001 -| MSBuild -| Defense Evasion -|- -| T1127 -| Trusted Developer Utilities Proxy Execution -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -False positives should be limited as developers do not spawn MSBuild via a WSH. - -====Reference==== - - -* https://app.any.run/tasks/dc93ee63-050c-4ff8-b07e-8277af9ab939/# - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127.001/regsvr32_silent/sysmon.log - - -''version'': 1 -
-
- ----- - -===Mshtml module load in office product=== -The following detection identifies the module load of mshtml.dll into an Office product. This behavior has been related to CVE-2021-40444, whereas the malicious document will load ActiveX, which activates the MSHTML component. The vulnerability resides in the MSHTML component. During triage, identify parallel processes and capture any file modifications for analysis. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/ T1566], [https://attack.mitre.org/techniques/T1566/001/ T1566.001] -* '''Last Updated''': 2021-09-09 - -
-
- -====Search==== -`sysmon` EventID=7 process_name IN ("winword.exe","excel.exe","powerpnt.exe","mspub.exe","visio.exe","wordpad.exe","wordview.exe") ImageLoaded IN ("*\\mshtml.dll", "*\\Microsoft.mshtml.dll","*\\IE.Interop.MSHTML.dll","*\\MshtmlDac.dll","*\\MshtmlDed.dll","*\\MshtmlDer.dll") -| stats count min(_time) as firstTime max(_time) as lastTime by Computer, process_name, ImageLoaded, OriginalFileName, process_id -| rename Computer as dest -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `mshtml_module_load_in_office_product_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Spearphishing_Attachments|Spearphishing Attachments]] - -* [[Documentation:ESSOC:stories:UseCase#Microsoft_MSHTML_Remote_Code_Execution_CVE-2021-40444|Microsoft MSHTML Remote Code Execution CVE-2021-40444]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process names and image loads from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -====Required field==== - -* _time - -* ImageLoaded - -* process_name - -* OriginalFileName - -* process_id - -* dest - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1566 -| Phishing -| Initial Access -|- -| T1566.001 -| Spearphishing Attachment -| Initial Access -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Limited false positives will be present, however, tune as necessary. - -====Reference==== - - -* https://app.any.run/tasks/36c14029-9df8-439c-bba0-45f2643b0c70/ - -* https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40444 - -* https://strontic.github.io/xcyclopedia/index-dll - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_mshtml.log - - -''version'': 1 -
-
- ----- - -===Macos - re-opened applications=== -This search looks for processes referencing the plist files that determine which applications are re-opened when a user reboots their machine. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': -* '''Last Updated''': 2020-02-07 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count values(Processes.process) as process values(Processes.parent_process) as parent_process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process="*com.apple.loginwindow*" by Processes.user Processes.process_name Processes.parent_process_name Processes.dest -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `macos___re_opened_applications_filter` - -====Associated Analytic Story==== - - -====How To Implement==== -In order to properly run this search, Splunk needs to ingest process data from your osquery deployed agents with the [splunk.conf](https://github.com/splunk/TA-osquery/blob/master/config/splunk.conf) pack enabled. Also the [TA-OSquery](https://github.com/splunk/TA-osquery) must be deployed across your indexers and universal forwarders in order to have the data populate the Endpoint data model. - -====Required field==== - -* _time - -* Processes.process - -* Processes.parent_process - -* Processes.user - -* Processes.process_name - -* Processes.parent_process_name - -* Processes.dest - - - - -====Kill Chain Phase==== - -* Installation - -* Command and Control - - -====Known False Positives==== -At this stage, there are no known false positives. During testing, no process events refering the com.apple.loginwindow.plist files were observed during normal operation of re-opening applications on reboot. Therefore, it can be asumed that any occurences of this in the process events would be worth investigating. In the event that the legitimate modification by the system of these files is in fact logged to the process log, then the process_name of that process can be added to an allow list. - -====Reference==== - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Mailsniper invoke functions=== -This search is to detect known mailsniper.ps1 functions executed in a machine. This technique was seen in some attacker to harvest some sensitive e-mail in a compromised exchange server. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1114/ T1114], [https://attack.mitre.org/techniques/T1114/001/ T1114.001] -* '''Last Updated''': 2021-05-19 - -
-
- -====Search==== -`powershell` EventCode=4104 Message IN ("*Invoke-GlobalO365MailSearch*", "*Invoke-GlobalMailSearch*", "*Invoke-SelfSearch*", "*Invoke-PasswordSprayOWA*", "*Invoke-PasswordSprayEWS*","*Invoke-DomainHarvestOWA*", "*Invoke-UsernameHarvestOWA*","*Invoke-OpenInboxFinder*","*Invoke-InjectGEventAPI*","*Invoke-InjectGEvent*","*Invoke-SearchGmail*", "*Invoke-MonitorCredSniper*", "*Invoke-AddGmailRule*","*Invoke-PasswordSprayEAS*","*Invoke-UsernameHarvestEAS*") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `mailsniper_invoke_functions_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Data_Exfiltration|Data Exfiltration]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the powershell logs from your endpoints. make sure you enable needed registry to monitor this event. - -====Required field==== - -* _time - -* EventCode - -* Message - -* ComputerName - -* User - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1114 -| Email Collection -| Collection -|- -| T1114.001 -| Local Email Collection -| Collection -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://www.blackhillsinfosec.com/introducing-mailsniper-a-tool-for-searching-every-users-email-for-sensitive-data/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/casper/datasets1/windows-powershell.log - - -''version'': 1 -
-
- ----- - -===Malicious inprocserver32 modification=== -The following analytic identifies a process modifying the registry with a known malicious CLSID under InProcServer32. Most COM classes are registered with the operating system and are identified by a GUID that represents the Class Identifier (CLSID) within the registry (usually under HKLM\\Software\\Classes\\CLSID or HKCU\\Software\\Classes\\CLSID). Behind the implementation of a COM class is the server (some binary) that is referenced within registry keys under the CLSID. The LocalServer32 key represents a path to an executable (exe) implementation, and the InprocServer32 key represents a path to a dynamic link library (DLL) implementation (Bohops). During triage, review parallel processes for suspicious activity. Pivot on the process GUID to see the full timeline of events. Analyze the value and look for file modifications. Being this is looking for inprocserver32, a DLL found in the value will most likely be loaded by a parallel process. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/010/ T1218.010], [https://attack.mitre.org/techniques/T1112/ T1112] -* '''Last Updated''': 2021-10-05 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time Processes.process_id Processes.process_name Processes.dest Processes.process_guid Processes.user -| `drop_dm_object_name(Processes)` -| join process_guid [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry where Registry.registry_path= "*\\CLSID\\{89565275-A714-4a43-912E-978B935EDCCC}\\InProcServer32\\(Default)" by Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.dest Registry.process_guid Registry.user -| `drop_dm_object_name(Registry)` -| fields _time dest registry_path registry_key_name registry_value_name process_name process_path process process_guid user] -| stats count min(_time) as firstTime max(_time) as lastTime by dest, process_name registry_path registry_key_name registry_value_name user -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `malicious_inprocserver32_modification_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Regsvr32_Activity|Suspicious Regsvr32 Activity]] - -* [[Documentation:ESSOC:stories:UseCase#Remcos|Remcos]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* dest - -* process_name - -* registry_path - -* registry_key_name - -* registry_value_name - -* user - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1218.010 -| Regsvr32 -| Defense Evasion -|- -| T1112 -| Modify Registry -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -False positives should be limited, filter as needed. In our test case, Remcos used regsvr32.exe to modify the registry. It may be required, dependent upon the EDR tool producing registry events, to remove (Default) from the command-line. - -====Reference==== - - -* https://bohops.com/2018/06/28/abusing-com-registry-structure-clsid-localserver32-inprocserver32/ - -* https://tria.ge/210929-ap75vsddan - -* https://www.virustotal.com/gui/file/cb77b93150cb0f7fe65ce8a7e2a5781e727419451355a7736db84109fa215a89 - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Malicious powershell process - connect to internet with hidden window=== -The following hunting analytic identifies PowerShell commands utilizing the WindowStyle parameter to hide the window on the compromised endpoint. This combination of command-line options is suspicious because it is overriding the default PowerShell execution policy, attempts to hide its activity from the user, and connects to the Internet. Removed in this version of the query is New-Object. The analytic identifies all variations of WindowStyle, as PowerShell allows the ability to shorten the parameter. For example w, win, windowsty and so forth. In addition, through our research it was identified that PowerShell will interpret different command switch types beyond the hyphen. We have added endash, emdash, horizontal bar, and forward slash. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/001/ T1059.001], [https://attack.mitre.org/techniques/T1059/ T1059] -* '''Last Updated''': 2021-10-05 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_powershell` by Processes.user Processes.process_name Processes.process Processes.parent_process_name Processes.original_file_name Processes.dest Processes.process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| where match(process,"(?i)[\- -|\/ -|– -|— -|―]w(in*d*o*w*s*t*y*l*e*)*\s+[^-]") -| `malicious_powershell_process___connect_to_internet_with_hidden_window_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Malicious_PowerShell|Malicious PowerShell]] - -* [[Documentation:ESSOC:stories:UseCase#Possible_Backdoor_Activity_Associated_With_MUDCARP_Espionage_Campaigns|Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns]] - -* [[Documentation:ESSOC:stories:UseCase#HAFNIUM_Group|HAFNIUM Group]] - - -====How To Implement==== -You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. - -====Required field==== - -* _time - -* Processes.process - -* Processes.process_name - -* Processes.user - -* Processes.parent_process_name - -* Processes.dest - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1059.001 -| PowerShell -| Execution -|- -| T1059 -| Command and Scripting Interpreter -| Execution -|} - - -====Kill Chain Phase==== - -* Command and Control - -* Actions on Objectives - - -====Known False Positives==== -Legitimate process can have this combination of command-line options, but it's not common. - -====Reference==== - - -* https://regexr.com/663rr - -* https://github.com/redcanaryco/AtomicTestHarnesses/blob/master/TestHarnesses/T1059.001_PowerShell/OutPowerShellCommandLineParameter.ps1 - -* https://ss64.com/ps/powershell.html - -* https://twitter.com/M_haggis/status/1440758396534214658?s=20 - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/hidden_powershell/windows-sysmon.log - - -''version'': 7 -
-
- ----- - -===Malicious powershell process - encoded command=== -The following analytic identifies the use of the EncodedCommand PowerShell parameter. This is typically used by Administrators to run complex scripts, but commonly used by adversaries to hide their code. \ -The analytic identifies all variations of EncodedCommand, as PowerShell allows the ability to shorten the parameter. For example enc, enco, encod and so forth. In addition, through our research it was identified that PowerShell will interpret different command switch types beyond the hyphen. We have added endash, emdash, horizontal bar, and forward slash. \ -During triage, review parallel events to determine legitimacy. Tune as needed based on admin scripts in use. \ -Alternatively, may use regex per matching here https://regexr.com/662ov. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1027/ T1027] -* '''Last Updated''': 2021-10-05 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_powershell` by Processes.user Processes.process_name Processes.process Processes.parent_process_name Processes.original_file_name Processes.dest Processes.process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| where match(process,"(?i)[\- -|\/ -|– -|— -|―]e(nc*o*d*e*d*c*o*m*m*a*n*d*)*\s+[^-]") -| `malicious_powershell_process___encoded_command_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Malicious_PowerShell|Malicious PowerShell]] - -* [[Documentation:ESSOC:stories:UseCase#NOBELIUM_Group|NOBELIUM Group]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.process_name - -* Processes.process - -* Processes.user - -* Processes.parent_process_name - -* Processes.dest - -* Processes.process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1027 -| Obfuscated Files or Information -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Command and Control - -* Actions on Objectives - - -====Known False Positives==== -System administrators may use this option, but it's not common. - -====Reference==== - - -* https://regexr.com/662ov - -* https://github.com/redcanaryco/AtomicTestHarnesses/blob/master/TestHarnesses/T1059.001_PowerShell/OutPowerShellCommandLineParameter.ps1 - -* https://ss64.com/ps/powershell.html - -* https://twitter.com/M_haggis/status/1440758396534214658?s=20 - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1027/atomic_red_team/windows-sysmon.log - - -''version'': 6 -
-
- ----- - -===Malicious powershell process - execution policy bypass=== -This search looks for PowerShell processes started with parameters used to bypass the local execution policy for scripts. These parameters are often observed in attacks leveraging PowerShell scripts as they override the default PowerShell execution policy. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/ T1059], [https://attack.mitre.org/techniques/T1059/001/ T1059.001] -* '''Last Updated''': 2020-07-21 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` values(Processes.process_id) as process_id, values(Processes.parent_process_id) as parent_process_id values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_powershell` (Processes.process="* -ex*" OR Processes.process="* bypass *") by Processes.process_id, Processes.user, Processes.dest -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `malicious_powershell_process___execution_policy_bypass_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#DHS_Report_TA18-074A|DHS Report TA18-074A]] - -* [[Documentation:ESSOC:stories:UseCase#HAFNIUM_Group|HAFNIUM Group]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1059 -| Command and Scripting Interpreter -| Execution -|- -| T1059.001 -| PowerShell -| Execution -|} - - -====Kill Chain Phase==== - -* Command and Control - -* Actions on Objectives - - -====Known False Positives==== -There may be legitimate reasons to bypass the PowerShell execution policy. The PowerShell script being run with this parameter should be validated to ensure that it is legitimate. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/encoded_powershell/windows-sysmon.log - - -''version'': 5 -
-
- ----- - -===Malicious powershell process with obfuscation techniques=== -This search looks for PowerShell processes launched with arguments that have characters indicative of obfuscation on the command-line. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/ T1059], [https://attack.mitre.org/techniques/T1059/001/ T1059.001] -* '''Last Updated''': 2021-01-19 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count values(Processes.process) as process values(Processes.parent_process) as parent_process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_powershell` by Processes.user Processes.process_name Processes.original_file_name Processes.parent_process_name Processes.dest Processes.process -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| eval num_obfuscation = (mvcount(split(process,"`"))-1) + (mvcount(split(process, "^"))-1) + (mvcount(split(process, "'"))-1) -| `malicious_powershell_process_with_obfuscation_techniques_filter` -| search num_obfuscation > 10 - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Malicious_PowerShell|Malicious PowerShell]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1059 -| Command and Scripting Interpreter -| Execution -|- -| T1059.001 -| PowerShell -| Execution -|} - - -====Kill Chain Phase==== - -* Command and Control - -* Actions on Objectives - - -====Known False Positives==== -These characters might be legitimately on the command-line, but it is not common. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/obfuscated_powershell/windows-sysmon.log - - -''version'': 5 -
-
- ----- - -===Malicious powershell executed as a service=== -This detection is to identify the abuse the Windows SC.exe to execute malicious commands or payloads via PowerShell. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1569/ T1569], [https://attack.mitre.org/techniques/T1569/002/ T1569.002] -* '''Last Updated''': 2021-04-07 - -
-
- -====Search==== - `wineventlog_system` EventCode=7045 -| eval l_Service_File_Name=lower(Service_File_Name) -| regex l_Service_File_Name="powershell[.\s] -|powershell_ise[.\s] -|pwsh[.\s] -|psexec[.\s]" -| regex l_Service_File_Name="-nop[rofile\s]+ -|-w[indowstyle]*\s+hid[den]* -|-noe[xit\s]+ -|-enc[odedcommand\s]+" -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Service_File_Name Service_Name Service_Start_Type Service_Type Service_Account user -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `malicious_powershell_executed_as_a_service_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Malicious_Powershell|Malicious Powershell]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting Windows System logs with the Service name, Service File Name Service Start type, and Service Type from your endpoints. - -====Required field==== - -* EventCode - -* Service_File_Name - -* Service_Type - -* _time - -* Service_Name - -* Service_Start_Type - -* Service_Account - -* user - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1569 -| System Services -| Execution -|- -| T1569.002 -| Service Execution -| Execution -|} - - -====Kill Chain Phase==== - -* Privilege Escalation - - -====Known False Positives==== -Creating a hidden powershell service is rare and could key off of those instances. - -====Reference==== - - -* https://www.fireeye.com/content/dam/fireeye-www/blog/pdfs/dosfuscation-report.pdf - -* http://az4n6.blogspot.com/2017/ - -* https://www.danielbohannon.com/blog-1/2017/3/12/powershell-execution-argument-obfuscation-how-it-can-make-detection-easier - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1569.002/atomic_red_team/windows-system.log - - -''version'': 1 -
-
- ----- - -===Modification of wallpaper=== -This analytic identifies suspicious modification of registry to deface or change the wallpaper of a compromised machines as part of its payload. This technique was commonly seen in ransomware like REVIL where it create a bitmap file contain a note that the machine was compromised and make it as a wallpaper. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1491/ T1491] -* '''Last Updated''': 2021-06-02 - -
-
- -====Search==== -`sysmon` EventCode =13 (TargetObject= "*\\Control Panel\\Desktop\\Wallpaper" AND Image != "*\\explorer.exe") OR (TargetObject= "*\\Control Panel\\Desktop\\Wallpaper" AND Details = "*\\temp\\*") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Image TargetObject Details Computer process_guid process_id user_id -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `modification_of_wallpaper_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - -* [[Documentation:ESSOC:stories:UseCase#Revil_Ransomware|Revil Ransomware]] - -* [[Documentation:ESSOC:stories:UseCase#BlackMatter_Ransomware|BlackMatter Ransomware]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the Image, TargetObject registry key, registry Details from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -====Required field==== - -* _time - -* EventCode - -* Image - -* TargetObject - -* Details - -* Computer - -* process_guid - -* process_id - -* user_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1491 -| Defacement -| Impact -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -3rd party tool may used to changed the wallpaper of the machine - -====Reference==== - - -* https://krebsonsecurity.com/2021/05/a-closer-look-at-the-darkside-ransomware-gang/ - -* https://www.mcafee.com/blogs/other-blogs/mcafee-labs/mcafee-atr-analyzes-sodinokibi-aka-revil-ransomware-as-a-service-what-the-code-tells-us/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/revil/inf1/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Modify acl permission to files or folder=== -This analytic identifies suspicious modification of ACL permission to a files or folder to make it available to everyone. This technique may be used by the adversary to evade ACLs or protected files access. This changes is commonly configured by the file or directory owner with appropriate permission. This behavior is a good indicator if this command seen on a machine utilized by an account with no permission to do so. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1222/ T1222] -* '''Last Updated''': 2021-05-04 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` values(Processes.process) as process values(Processes.process_id) as process_id count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = "cacls.exe" OR Processes.process_name = "icacls.exe" OR Processes.process_name = "xcacls.exe" AND (Processes.process = "*/G everyone:*" OR Processes.process = "*/G SYSTEM:*") by Processes.parent_process_name Processes.process_name Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `modify_acl_permission_to_files_or_folder_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#XMRig|XMRig]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed cacls.exe may be used. - -====Required field==== - -* _time - -* Processes.parent_process_name - -* Processes.process_name - -* Processes.dest - -* Processes.user - -* Processes.process - -* Processes.process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1222 -| File and Directory Permissions Modification -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -administrators may use this command. Filter as needed. - -====Reference==== - - -* https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Modify acls permission of files or folders=== -This analytic identifies suspicious modification of ACL permission to a files or folder to make it available to everyone or to a specific user. This technique may be used by the adversary to evade ACLs or protected files access. This changes is commonly configured by the file or directory owner with appropriate permission. This behavior is a good indicator if this command seen on a machine utilized by an account with no permission to do so. - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1222/ T1222] -* '''Last Updated''': 2021-06-15 - -
-
- -====Search==== - -| from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line IS NOT NULL AND like(cmd_line, "%/G%") AND (match_regex(cmd_line, /(?i)everyone:/)=true OR match_regex(cmd_line, /(?i)SYSTEM:/)=true) AND (process_name="cacls.exe" OR process_name="xcacls.exe" OR process_name="icacls.exe") -| eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#XMRig|XMRig]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed cacls.exe may be used. - -====Required field==== - -* _time - -* dest_device_id - -* process_name - -* parent_process_name - -* process_path - -* dest_user_id - -* process - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1222 -| File and Directory Permissions Modification -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -network administrator may use this windows utility. filter is needed. - -====Reference==== - - -* https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.001/ssa_cacls/all_icalc.log - - -''version'': 1 -
-
- ----- - -===Monitor registry keys for print monitors=== -This search looks for registry activity associated with modifications to the registry key `HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors`. In this scenario, an attacker can load an arbitrary .dll into the print-monitor registry by giving the full path name to the after.dll. The system will execute the .dll with elevated (SYSTEM) permissions and will persist after reboot. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1547/010/ T1547.010], [https://attack.mitre.org/techniques/T1547/ T1547] -* '''Last Updated''': 2020-11-23 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.action=modified AND Registry.registry_path="*CurrentControlSet\\Control\\Print\\Monitors*" by Registry.dest, Registry.registry_key_name Registry.user Registry.registry_path Registry.registry_value_name Registry.action -| `drop_dm_object_name(Registry)` -| `monitor_registry_keys_for_print_monitors_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Windows_Registry_Activities|Suspicious Windows Registry Activities]] - -* [[Documentation:ESSOC:stories:UseCase#Windows_Persistence_Techniques|Windows Persistence Techniques]] - - -====How To Implement==== -To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black, or via other endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report registry modifications. - -====Required field==== - -* _time - -* Registry.action - -* Registry.registry_path - -* Registry.dest - -* Registry.registry_key_name - -* Registry.user - -* Registry.registry_value_name - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1547.010 -| Port Monitors -| Persistence, Privilege Escalation -|- -| T1547 -| Boot or Logon Autostart Execution -| Persistence, Privilege Escalation -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -You will encounter noise from legitimate print-monitor registry entries. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.010/atomic_red_team/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===More than usual number of lolbas applications in short time period=== -Attacker activity may compromise executing several LOLBAS applications in conjunction to accomplish their objectives. We are looking for more than usual LOLBAS applications over a window of time, by building profiles per machine. - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/ T1059], [https://attack.mitre.org/techniques/T1053/ T1053] -* '''Last Updated''': 2020-08-25 - -
-
- -====Search==== - -| from read_ssa_enriched_events() -| eval device=ucast(map_get(input_event, "dest_device_id"), "string", null), process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)) -| where process_name=="regsvcs.exe" OR process_name=="ftp.exe" OR process_name=="dfsvc.exe" OR process_name=="rasautou.exe" OR process_name=="schtasks.exe" OR process_name=="xwizard.exe" OR process_name=="findstr.exe" OR process_name=="esentutl.exe" OR process_name=="cscript.exe" OR process_name=="reg.exe" OR process_name=="csc.exe" OR process_name=="atbroker.exe" OR process_name=="print.exe" OR process_name=="pcwrun.exe" OR process_name=="vbc.exe" OR process_name=="rpcping.exe" OR process_name=="wsreset.exe" OR process_name=="ilasm.exe" OR process_name=="certutil.exe" OR process_name=="replace.exe" OR process_name=="mshta.exe" OR process_name=="bitsadmin.exe" OR process_name=="wscript.exe" OR process_name=="ieexec.exe" OR process_name=="cmd.exe" OR process_name=="microsoft.workflow.compiler.exe" OR process_name=="runscripthelper.exe" OR process_name=="makecab.exe" OR process_name=="forfiles.exe" OR process_name=="desktopimgdownldr.exe" OR process_name=="control.exe" OR process_name=="msbuild.exe" OR process_name=="register-cimprovider.exe" OR process_name=="tttracer.exe" OR process_name=="ie4uinit.exe" OR process_name=="sc.exe" OR process_name=="bash.exe" OR process_name=="hh.exe" OR process_name=="cmstp.exe" OR process_name=="mmc.exe" OR process_name=="jsc.exe" OR process_name=="scriptrunner.exe" OR process_name=="odbcconf.exe" OR process_name=="extexport.exe" OR process_name=="msdt.exe" OR process_name=="diskshadow.exe" OR process_name=="extrac32.exe" OR process_name=="eventvwr.exe" OR process_name=="mavinject.exe" OR process_name=="regasm.exe" OR process_name=="gpscript.exe" OR process_name=="rundll32.exe" OR process_name=="regsvr32.exe" OR process_name=="regedit.exe" OR process_name=="msiexec.exe" OR process_name=="gfxdownloadwrapper.exe" OR process_name=="presentationhost.exe" OR process_name=="regini.exe" OR process_name=="wmic.exe" OR process_name=="runonce.exe" OR process_name=="syncappvpublishingserver.exe" OR process_name=="verclsid.exe" OR process_name=="psr.exe" OR process_name=="infdefaultinstall.exe" OR process_name=="explorer.exe" OR process_name=="expand.exe" OR process_name=="installutil.exe" OR process_name=="netsh.exe" OR process_name=="wab.exe" OR process_name=="dnscmd.exe" OR process_name=="at.exe" OR process_name=="pcalua.exe" OR process_name=="cmdkey.exe" OR process_name=="msconfig.exe" -| stats count(process_name) as lolbas_counter by device,span(timestamp, 300s) -| eval lolbas_counter=lolbas_counter*1.0 -| rename window_end as timestamp -| adaptive_threshold algorithm="quantile" value="lolbas_counter" entity="device" window=2419200000L -| where label AND quantile>0.99 -| eval start_time = window_start, end_time = timestamp, entities = mvappend(device), body=create_map(["lolbas_counter", lolbas_counter, "quantile", quantile, "device", device]) -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Unusual_Processes|Unusual Processes]] - - -====How To Implement==== -Collect endpoint data such as sysmon or 4688 events. - -====Required field==== - -* dest_device_id - -* _time - -* process_name - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1059 -| Command and Scripting Interpreter -| Execution -|- -| T1053 -| Scheduled Task/Job -| Execution, Persistence, Privilege Escalation -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Some administrative tasks may involve multiple use of LOLBAS applications in a short period of time. This might trigger false positives at the beginning when it hasn't collected yet enough data to construct the baseline. - - -====Reference==== - - -* https://github.com/LOLBAS-Project/LOLBAS/tree/master/yml/OSBinaries - - - -====Test Dataset==== - - -''version'': 2 -
-
- ----- - -===Mshta spawning rundll32 or regsvr32 process=== -This search is to detect a suspicious mshta.exe process that spawn rundll32 or regsvr32 child process. This technique was seen in several malware nowadays like trickbot to load its initial .dll stage loader to execute and download the the actual trickbot payload. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/005/ T1218.005] -* '''Last Updated''': 2021-07-19 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name = "mshta.exe" `process_rundll32` OR `process_regsvr32` by Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.process_guid Processes.user Processes.dest -| `drop_dm_object_name("Processes")` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -| `mshta_spawning_rundll32_or_regsvr32_process_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Trickbot|Trickbot]] - -* [[Documentation:ESSOC:stories:UseCase#IcedID|IcedID]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1218 -| Signed Binary Proxy Execution -| Defense Evasion -|- -| T1218.005 -| Mshta -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -limitted. this anomaly behavior is not commonly seen in clean host. - -====Reference==== - - -* https://twitter.com/cyb3rops/status/1416050325870587910?s=21 - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/trickbot/spear_phish/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Msmpeng application dll side loading=== -This search is to detect a suspicious creation of msmpeng.exe or mpsvc.dll in non default windows defender folder. This technique was seen couple days ago with revil ransomware in Kaseya Supply chain. The approach is to drop an old version of msmpeng.exe to load the actual payload name as mspvc.dll which will load the revil ransomware to the compromise machine - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1574/002/ T1574.002], [https://attack.mitre.org/techniques/T1574/ T1574] -* '''Last Updated''': 2021-07-05 - -
-
- -====Search==== - -|tstats `security_content_summariesonly` values(Filesystem.file_path) as file_path count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Filesystem where (Filesystem.file_name = "msmpeng.exe" OR Filesystem.file_name = "mpsvc.dll") AND Filesystem.file_path != "*\\Program Files\\windows defender\\*" by Filesystem.file_create_time Filesystem.process_id Filesystem.file_name Filesystem.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `msmpeng_application_dll_side_loading_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - -* [[Documentation:ESSOC:stories:UseCase#Revil_Ransomware|Revil Ransomware]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the Filesystem responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Filesystem` node. - -====Required field==== - -* _time - -* Filesystem.file_create_time - -* Filesystem.process_id - -* Filesystem.file_name - -* Filesystem.user - -* Filesystem.file_path - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1574.002 -| DLL Side-Loading -| Persistence, Privilege Escalation, Defense Evasion -|- -| T1574 -| Hijack Execution Flow -| Persistence, Privilege Escalation, Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -quite minimal false positive expected. - -====Reference==== - - -* https://community.sophos.com/b/security-blog/posts/active-ransomware-attack-on-kaseya-customers - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets//malware/revil/msmpeng_side/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Multiple disabled users failing to authenticate from host using kerberos=== -The following analytic identifies one source endpoint failing to authenticate with multiple disabled domain users using the Kerberos protocol. This behavior could represent an adversary performing a Password Spraying attack against an Active Directory environment using Kerberos to obtain initial access or elevate privileges. As attackers progress in a breach, mistakes will be made. In certain scenarios, adversaries may execute a password spraying attack against disabled users. Event 4768 is generated every time the Key Distribution Center issues a Kerberos Ticket Granting Ticket (TGT). Failure code `0x12` stands for `clients credentials have been revoked` (account disabled, expired or locked out).\ -The detection calculates the standard deviation for each host and leverages the 3-sigma statistical rule to identify an unusual number of users. To customize this analytic, users can try different combinations of the `bucket` span time and the calculation of the `upperBound` field. This logic can be used for real time security monitoring as well as threat hunting exercises.\ -This detection will only trigger on domain controllers, not on member servers or workstations.\ -The analytics returned fields allow analysts to investigate the event further by providing fields like source ip and attempted user accounts. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1110/003/ T1110.003], [https://attack.mitre.org/techniques/T1110/ T1110] -* '''Last Updated''': 2021-04-14 - -
-
- -====Search==== -`wineventlog_security` EventCode=4768 Account_Name!="*$" Result_Code=0x12 -| bucket span=2m _time -| stats dc(Account_Name) AS unique_accounts values(Account_Name) as tried_accounts by _time, Client_Address -| eventstats avg(unique_accounts) as comp_avg , stdev(unique_accounts) as comp_std by Client_Address -| eval upperBound=(comp_avg+comp_std*3) -| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0) -| search isOutlier=1 -| `multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Password_Spraying|Active Directory Password Spraying]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting Domain Controller and Kerberos events. The Advanced Security Audit policy setting `Audit Kerberos Authentication Service` within `Account Logon` needs to be enabled. - -====Required field==== - -* _time - -* EventCode - -* Result_Code - -* Account_Name - -* Client_Address - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1110.003 -| Password Spraying -| Credential Access -|- -| T1110 -| Brute Force -| Credential Access -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -A host failing to authenticate with multiple disabled domain users is not a common behavior for legitimate systems. Possible false positive scenarios include but are not limited to vulnerability scanners, multi-user systems missconfigured systems. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1110/003/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_disabled_users_kerberos/windows-security.log - - -''version'': 1 -
-
- ----- - -===Multiple invalid users failing to authenticate from host using kerberos=== -The following analytic identifies one source endpoint failing to authenticate with multiple invalid domain users using the Kerberos protocol. This behavior could represent an adversary performing a Password Spraying attack against an Active Directory environment using Kerberos to obtain initial access or elevate privileges. As attackers progress in a breach, mistakes will be made. In certain scenarios, adversaries may execute a password spraying attack using an invalid list of users. Event 4768 is generated every time the Key Distribution Center issues a Kerberos Ticket Granting Ticket (TGT). Failure code 0x6 stands for `client not found in Kerberos database` (the attempted user is not a valid domain user).\ -The detection calculates the standard deviation for each host and leverages the 3-sigma statistical rule to identify an unusual number of users. To customize this analytic, users can try different combinations of the `bucket` span time and the calculation of the `upperBound` field. This logic can be used for real time security monitoring as well as threat hunting exercises.\ -This detection will only trigger on domain controllers, not on member servers or workstations.\ -The analytics returned fields allow analysts to investigate the event further by providing fields like source ip and attempted user accounts. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1110/003/ T1110.003], [https://attack.mitre.org/techniques/T1110/ T1110] -* '''Last Updated''': 2021-04-14 - -
-
- -====Search==== -`wineventlog_security` EventCode=4768 Result_Code=0x6 Account_Name!="*$" -| bucket span=2m _time -| stats dc(Account_Name) AS unique_accounts values(Account_Name) as tried_accounts by _time, Client_Address -| eventstats avg(unique_accounts) as comp_avg , stdev(unique_accounts) as comp_std by Client_Address -| eval upperBound=(comp_avg+comp_std*3) -| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0) -| search isOutlier=1 -| `multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Password_Spraying|Active Directory Password Spraying]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting Domain Controller and Kerberos events. The Advanced Security Audit policy setting `Audit Kerberos Authentication Service` within `Account Logon` needs to be enabled. - -====Required field==== - -* _time - -* EventCode - -* Result_Code - -* Account_Name - -* Client_Address - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1110.003 -| Password Spraying -| Credential Access -|- -| T1110 -| Brute Force -| Credential Access -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -A host failing to authenticate with multiple invalid domain users is not a common behavior for legitimate systems. Possible false positive scenarios include but are not limited to vulnerability scanners, multi-user systems and missconfigured systems. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1110/003/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_invalid_users_kerberos/windows-security.log - - -''version'': 1 -
-
- ----- - -===Multiple invalid users failing to authenticate from host using ntlm=== -The following analytic identifies one source endpoint failing to authenticate with multiple invalid users using the NTLM protocol. This behavior could represent an adversary performing a Password Spraying attack against an Active Directory environment using NTLM to obtain initial access or elevate privileges. As attackers progress in a breach, mistakes will be made. In certain scenarios, adversaries may execute a password spraying attack using an invalid list of users. Event 4776 is generated on the computer that is authoritative for the provided credentials. For domain accounts, the domain controller is authoritative. For local accounts, the local computer is authoritative. Error code 0xC0000064 stands for `The username you typed does not exist` (the attempted user is a legitimate domain user).\ -The detection calculates the standard deviation for each host and leverages the 3-sigma statistical rule to identify an unusual number of users. To customize this analytic, users can try different combinations of the `bucket` span time and the calculation of the `upperBound` field. This logic can be used for real time security monitoring as well as threat hunting exercises.\ -This detection will only trigger on domain controllers, not on member servers or workstations.\ -The analytics returned fields allow analysts to investigate the event further by providing fields like source workstation name and attempted user accounts. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1110/003/ T1110.003], [https://attack.mitre.org/techniques/T1110/ T1110] -* '''Last Updated''': 2021-04-15 - -
-
- -====Search==== - `wineventlog_security` EventCode=4776 Logon_Account!="*$" 0xC0000064 action=failure -| bucket span=2m _time -| stats dc(Logon_Account) AS unique_accounts values(Logon_Account) as tried_accounts by _time, Source_Workstation -| eventstats avg(unique_accounts) as comp_avg , stdev(unique_accounts) as comp_std by Source_Workstation -| eval upperBound=(comp_avg+comp_std*3) -| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0) -| search isOutlier=1 -| `multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Password_Spraying|Active Directory Password Spraying]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting Domain Controller events. The Advanced Security Audit policy setting `Audit Credential Validation' within `Account Logon` needs to be enabled. - -====Required field==== - -* _time - -* EventCode - -* action - -* Logon_Account - -* Source_Workstation - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1110.003 -| Password Spraying -| Credential Access -|- -| T1110 -| Brute Force -| Credential Access -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -A host failing to authenticate with multiple invalid domain users is not a common behavior for legitimate systems. Possible false positive scenarios include but are not limited to vulnerability scanners and missconfigured systems. If this detection triggers on a host other than a Domain Controller, the behavior could represent a password spraying attack against the host's local accounts. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1110/003/ - -* https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-credential-validation - -* https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4776 - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_invalid_users_ntlm/windows-security.log - - -''version'': 1 -
-
- ----- - -===Multiple users attempting to authenticate using explicit credentials=== -The following analytic identifies a source user failing to authenticate with multiple users using explicit credentials on a host. This behavior could represent an adversary performing a Password Spraying attack against an Active Directory environment to obtain initial access or elevate privileges. Event 4648 is generated when a process attempts an account logon by explicitly specifying that accounts credentials. This event generates on domain controllers, member servers, and workstations.\ -The detection calculates the standard deviation for each host and leverages the 3-sigma statistical rule to identify an unusual number of users. To customize this analytic, users can try different combinations of the `bucket` span time and the calculation of the `upperBound` field. This logic can be used for real time security monitoring as well as threat hunting exercises.\ -This detection will trigger on the potenfially malicious host, perhaps controlled via a trojan or operated by an insider threat, from where a password spraying attack is being executed.\ -The analytics returned fields allow analysts to investigate the event further by providing fields like source account, attempted user accounts and the endpoint were the behavior was identified. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1110/003/ T1110.003], [https://attack.mitre.org/techniques/T1110/ T1110] -* '''Last Updated''': 2021-04-13 - -
-
- -====Search==== - `wineventlog_security` EventCode=4648 -| bucket span=2m _time -| eval Source_Account = mvindex(Account_Name, 0) -| eval Destination_Account = mvindex(Account_Name, 1) -| search Source_Account != "*$" Source_Account !="-" Destination_Account !="*$" -| stats dc(Destination_Account) AS unique_accounts values(Destination_Account) as tried_account by _time, ComputerName, Source_Account -| eventstats avg(unique_accounts) as comp_avg , stdev(unique_accounts) as comp_std by ComputerName -| eval upperBound=(comp_avg+comp_std*3) -| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0) -| search isOutlier=1 -| `multiple_users_attempting_to_authenticate_using_explicit_credentials_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Password_Spraying|Active Directory Password Spraying]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting Windows Event Logs from domain controllers as well as member servers and workstations. The Advanced Security Audit policy setting `Audit Logon` within `Logon/Logoff` needs to be enabled. - -====Required field==== - -* _time - -* EventCode - -* Security_ID - -* Account_Name - -* ComputerName - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1110.003 -| Password Spraying -| Credential Access -|- -| T1110 -| Brute Force -| Credential Access -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -A source user failing attempting to authenticate multiple users on a host is not a common behavior for regular systems. Some applications, however, may exhibit this behavior in which case sets of users hosts can be added to an allow list. Possible false positive scenarios include systems where several users connect to like Mail servers, identity providers, remote desktop services, Citrix, etc. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1110/003/ - -* https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4648 - -* https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/basic-audit-logon-events - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_explicit_credential_spray/windows-security.log - - -''version'': 1 -
-
- ----- - -===Multiple users failing to authenticate from host using kerberos=== -The following analytic identifies one source endpoint failing to authenticate with multiple valid users using the Kerberos protocol. This behavior could represent an adversary performing a Password Spraying attack against an Active Directory environment using Kerberos to obtain initial access or elevate privileges. Event 4771 is generated when the Key Distribution Center fails to issue a Kerberos Ticket Granting Ticket (TGT). Failure code 0x18 stands for `wrong password provided` (the attempted user is a legitimate domain user).\ -The detection calculates the standard deviation for each host and leverages the 3-sigma statistical rule to identify an unusual number of users. To customize this analytic, users can try different combinations of the `bucket` span time and the calculation of the `upperBound` field. This logic can be used for real time security monitoring as well as threat hunting exercises.\ -This detection will only trigger on domain controllers, not on member servers or workstations.\ -The analytics returned fields allow analysts to investigate the event further by providing fields like source ip and attempted user accounts. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1110/003/ T1110.003], [https://attack.mitre.org/techniques/T1110/ T1110] -* '''Last Updated''': 2021-04-08 - -
-
- -====Search==== -`wineventlog_security` EventCode=4771 Failure_Code=0x18 Account_Name!="*$" -| bucket span=2m _time -| stats dc(Account_Name) AS unique_accounts values(Account_Name) as tried_accounts by _time, Client_Address -| eventstats avg(unique_accounts) as comp_avg , stdev(unique_accounts) as comp_std by Client_Address -| eval upperBound=(comp_avg+comp_std*3) -| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0) -| search isOutlier=1 -| `multiple_users_failing_to_authenticate_from_host_using_kerberos_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Password_Spraying|Active Directory Password Spraying]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting Domain Controller and Kerberos events. The Advanced Security Audit policy setting `Audit Kerberos Authentication Service` within `Account Logon` needs to be enabled. - -====Required field==== - -* _time - -* EventCode - -* Result_Code - -* Account_Name - -* Client_Address - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1110.003 -| Password Spraying -| Credential Access -|- -| T1110 -| Brute Force -| Credential Access -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -A host failing to authenticate with multiple valid domain users is not a common behavior for legitimate systems. Possible false positive scenarios include but are not limited to vulnerability scanners, missconfigured systems and multi-user systems like Citrix farms. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1110/003/ - -* https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/dn319109(v=ws.11) - -* https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4771 - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_valid_users_kerberos/windows-security.log - - -''version'': 1 -
-
- ----- - -===Multiple users failing to authenticate from host using ntlm=== -The following analytic identifies one source endpoint failing to authenticate with multiple valid users using the NTLM protocol. This behavior could represent an adversary performing a Password Spraying attack against an Active Directory environment using NTLM to obtain initial access or elevate privileges. Event 4776 is generated on the computer that is authoritative for the provided credentials. For domain accounts, the domain controller is authoritative. For local accounts, the local computer is authoritative. Error code 0xC000006A means: misspelled or bad password (the attempted user is a legitimate domain user).\ -The detection calculates the standard deviation for each host and leverages the 3-sigma statistical rule to identify an unusual number of users. To customize this analytic, users can try different combinations of the `bucket` span time and the calculation of the `upperBound` field. This logic can be used for real time security monitoring as well as threat hunting exercises.\ -This detection will only trigger on domain controllers, not on member servers or workstations.\ -The analytics returned fields allow analysts to investigate the event further by providing fields like source workstation name and attempted user accounts. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1110/003/ T1110.003], [https://attack.mitre.org/techniques/T1110/ T1110] -* '''Last Updated''': 2021-04-13 - -
-
- -====Search==== - `wineventlog_security` EventCode=4776 Logon_Account!="*$" 0xC000006A action=failure -| bucket span=2m _time -| stats dc(Logon_Account) AS unique_accounts values(Logon_Account) as tried_accounts by _time, Source_Workstation -| eventstats avg(unique_accounts) as comp_avg , stdev(unique_accounts) as comp_std by Source_Workstation -| eval upperBound=(comp_avg+comp_std*3) -| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0) -| search isOutlier=1 -| `multiple_users_failing_to_authenticate_from_host_using_ntlm_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Password_Spraying|Active Directory Password Spraying]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting Domain Controller events. The Advanced Security Audit policy setting `Audit Credential Validation` within `Account Logon` needs to be enabled. - -====Required field==== - -* _time - -* EventCode - -* action - -* Logon_Account - -* Source_Workstation - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1110.003 -| Password Spraying -| Credential Access -|- -| T1110 -| Brute Force -| Credential Access -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -A host failing to authenticate with multiple valid domain users is not a common behavior for legitimate systems. Possible false positive scenarios include but are not limited to vulnerability scanners and missconfigured systems. If this detection triggers on a host other than a Domain Controller, the behavior could represent a password spraying attack against the host's local accounts. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1110/003/ - -* https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-credential-validation - -* https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4776 - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_valid_users_ntlm/windows-security.log - - -''version'': 1 -
-
- ----- - -===Multiple users failing to authenticate from process=== -The following analytic identifies a source process name failing to authenticate with multiple users. This behavior could represent an adversary performing a Password Spraying attack against an Active Directory environment to obtain initial access or elevate privileges. Event 4625 generates on domain controllers, member servers, and workstations when an account fails to logon. Logon Type 2 describes an iteractive logon attempt.\ -The detection calculates the standard deviation for each host and leverages the 3-sigma statistical rule to identify an unusual number of users. To customize this analytic, users can try different combinations of the `bucket` span time and the calculation of the `upperBound` field. This logic can be used for real time security monitoring as well as threat hunting exercises.\ -This detection will trigger on the potenfially malicious host, perhaps controlled via a trojan or operated by an insider threat, from where a password spraying attack is being executed. This could be a domain controller as well as a member server or workstation.\ -The analytics returned fields allow analysts to investigate the event further by providing fields like source process name, source account and attempted user accounts. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1110/003/ T1110.003], [https://attack.mitre.org/techniques/T1110/ T1110] -* '''Last Updated''': 2021-04-13 - -
-
- -====Search==== - `wineventlog_security` EventCode=4625 Logon_Type=2 Caller_Process_Name!="-" -| bucket span=2m _time -| eval Source_Account = mvindex(Account_Name, 0) -| eval Destination_Account = mvindex(Account_Name, 1) -| stats dc(Destination_Account) AS unique_accounts values(Account_Name) as tried_accounts by _time, Caller_Process_Name, Source_Account, ComputerName -| eventstats avg(unique_accounts) as comp_avg , stdev(unique_accounts) as comp_std by Caller_Process_Name, Source_Account, ComputerName -| eval upperBound=(comp_avg+comp_std*3) -| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0) -| search isOutlier=1 -| `multiple_users_failing_to_authenticate_from_process_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Password_Spraying|Active Directory Password Spraying]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting Windows Event Logs from domain controllers aas well as member servers and workstations. The Advanced Security Audit policy setting `Audit Logon` within `Logon/Logoff` needs to be enabled. - -====Required field==== - -* _time - -* EventCode - -* Logon_Type - -* Caller_Process_Name - -* Security_ID - -* Account_Name - -* ComputerName - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1110.003 -| Password Spraying -| Credential Access -|- -| T1110 -| Brute Force -| Credential Access -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -A process failing to authenticate with multiple users is not a common behavior for legitimate user sessions. Possible false positive scenarios include but are not limited to vulnerability scanners and missconfigured systems. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1110/003/ - -* https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4625 - -* https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=4625 - -* https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/basic-audit-logon-events - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_multiple_users_from_process/windows-security.log - - -''version'': 1 -
-
- ----- - -===Multiple users remotely failing to authenticate from host=== -The following analytic identifies a source host failing to authenticate against a remote host with multiple users. This behavior could represent an adversary performing a Password Spraying attack against an Active Directory environment to obtain initial access or elevate privileges. Event 4625 documents each and every failed attempt to logon to the local computer. This event generates on domain controllers, member servers, and workstations. Logon Type 3 describes an remote authentication attempt.\ -The detection calculates the standard deviation for each host and leverages the 3-sigma statistical rule to identify an unusual number of users. To customize this analytic, users can try different combinations of the `bucket` span time and the calculation of the `upperBound` field. This logic can be used for real time security monitoring as well as threat hunting exercises.\ -This detection will trigger on the host that is the target of the password spraying attack. This could be a domain controller as well as a member server or workstation.\ -The analytics returned fields allow analysts to investigate the event further by providing fields like source process name, source account and attempted user accounts. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1110/003/ T1110.003], [https://attack.mitre.org/techniques/T1110/ T1110] -* '''Last Updated''': 2021-04-13 - -
-
- -====Search==== - `wineventlog_security` EventCode=4625 Logon_Type=3 Source_Network_Address!="-" -| bucket span=2m _time -| eval Destination_Account = mvindex(Account_Name, 1) -| stats dc(Destination_Account) AS unique_accounts values(Destination_Account) as tried_accounts by _time, Source_Network_Address, ComputerName -| eventstats avg(unique_accounts) as comp_avg , stdev(unique_accounts) as comp_std by Source_Network_Address, ComputerName -| eval upperBound=(comp_avg+comp_std*3) -| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0) -| search isOutlier=1 -| `multiple_users_remotely_failing_to_authenticate_from_host_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Password_Spraying|Active Directory Password Spraying]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting Windows Event Logs from domain controllers as as well as member servers and workstations. The Advanced Security Audit policy setting `Audit Logon` within `Logon/Logoff` needs to be enabled. - -====Required field==== - -* _time - -* EventCode - -* Logon_Type - -* Security_ID - -* Account_Name - -* ComputerName - -* Source_Network_Address - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1110.003 -| Password Spraying -| Credential Access -|- -| T1110 -| Brute Force -| Credential Access -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -A host failing to authenticate with multiple valid users against a remote host is not a common behavior for legitimate systems. Possible false positive scenarios include but are not limited to vulnerability scanners, remote administration tools, missconfigyred systems, etc. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1110/003/ - -* https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4625 - -* https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=4625 - -* https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/basic-audit-logon-events - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_remote_spray/windows-security.log - - -''version'': 1 -
-
- ----- - -===Net profiler uac bypass=== -This search is to detect modification of registry to bypass UAC windows feature. This technique is to add a payload dll path on .NET COR file path that will be loaded by mmc.exe as soon it was executed. This detection rely on monitoring the registry key and values in the detection area. It may happened that windows update some dll related to mmc.exe and add dll path in this registry. In this case filtering is needed. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1548/002/ T1548.002], [https://attack.mitre.org/techniques/T1548/ T1548] -* '''Last Updated''': 2021-07-12 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*\\Environment\\COR_PROFILER_PATH" Registry.registry_value_name = "*.dll" by Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.dest -| `drop_dm_object_name(Registry)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `net_profiler_uac_bypass_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Defense_Evasion_Tactics|Windows Defense Evasion Tactics]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. - -====Required field==== - -* _time - -* Registry.registry_path - -* Registry.registry_key_name - -* Registry.registry_value_name - -* Registry.dest - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1548.002 -| Bypass User Account Control -| Privilege Escalation, Defense Evasion -|- -| T1548 -| Abuse Elevation Control Mechanism -| Privilege Escalation, Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -limited false positive. It may trigger by some windows update that will modify this registry. - -====Reference==== - - -* https://offsec.almond.consulting/UAC-bypass-dotnet.html - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/uac_bypass/windows-sysmon2.log - - -''version'': 1 -
-
- ----- - -===Nltest domain trust discovery=== -This search looks for the execution of `nltest.exe` with command-line arguments utilized to query for Domain Trust information. Two arguments `/domain trusts`, returns a list of trusted domains, and `/all_trusts`, returns all trusted domains. Red Teams and adversaries alike use NLTest.exe to enumerate the current domain to assist with further understanding where to pivot next. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1482/ T1482] -* '''Last Updated''': 2021-01-25 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name=nltest.exe OR Processes.process_name!=nltest.exe) (Processes.process=*/domain_trusts* OR Processes.process=*/all_trusts*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `nltest_domain_trust_discovery_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Ryuk_Ransomware|Ryuk Ransomware]] - -* [[Documentation:ESSOC:stories:UseCase#Domain_Trust_Discovery|Domain Trust Discovery]] - -* [[Documentation:ESSOC:stories:UseCase#IcedID|IcedID]] - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* _time - -* Processes.process_name - -* Processes.process - -* Processes.dest - -* Processes.user - -* Processes.parent_process - -* Processes.process_id - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1482 -| Domain Trust Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Administrators may use nltest for troubleshooting purposes, otherwise, rarely used. - -====Reference==== - - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1482/T1482.md - -* https://malware.news/t/lets-learn-trickbot-implements-network-collector-module-leveraging-cmd-wmi-ldap/19104 - -* https://attack.mitre.org/techniques/T1482/ - -* https://www.owasp.org/images/4/4b/Red_Team_Operating_in_a_Modern_Environment.pdf - -* https://ss64.com/nt/nltest.html - -* https://redcanary.com/threat-detection-report/techniques/domain-trust-discovery/ - -* https://thedfirreport.com/2020/10/08/ryuks-return/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1482/atomic_red_team/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Net localgroup discovery=== -The following hunting analytic will identify the use of localgroup discovery using `net localgroup`. During triage, review parallel processes and identify any further suspicious behavior. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1069/ T1069], [https://attack.mitre.org/techniques/T1069/001/ T1069.001] -* '''Last Updated''': 2021-09-14 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=net.exe OR Processes.process_name=net1.exe (Processes.process="*localgroup*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.original_file_name Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `net_localgroup_discovery_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1069 -| Permission Groups Discovery -| Discovery -|- -| T1069.001 -| Local Groups -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -False positives may be present. Tune as needed. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1069/001/ - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1069.001/T1069.001.md - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.001/atomic_red_team/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Network connection discovery with arp=== -This analytic looks for the execution of `arp.exe` utilized to get a listing of network connections on a compromised system. Red Teams and adversaries alike may use arp.exe for situational awareness and Active Directory Discovery. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1049/ T1049] -* '''Last Updated''': 2021-09-10 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="arp.exe") (Processes.process=*-a*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `network_connection_discovery_with_arp_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1049 -| System Network Connections Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use this command for troubleshooting. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1049/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1049/AD_discovery/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Network connection discovery with net=== -This analytic looks for the execution of `net.exe` with command-line arguments utilized to get a listing of network connections on a compromised system. Red Teams and adversaries alike may use net.exe for situational awareness and Active Directory Discovery. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1049/ T1049] -* '''Last Updated''': 2021-09-10 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="net.exe" OR Processes.process_name="net1.exe") (Processes.process=*use*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `network_connection_discovery_with_net_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1049 -| System Network Connections Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use this command for troubleshooting. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1049/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1049/AD_discovery/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Network connection discovery with netstat=== -This analytic looks for the execution of `netstat.exe` with command-line arguments utilized to get a listing of network connections on a compromised system. Red Teams and adversaries alike may use netstat.exe for situational awareness and Active Directory Discovery. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1049/ T1049] -* '''Last Updated''': 2021-09-10 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="netstat.exe") (Processes.process=*-a*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `network_connection_discovery_with_netstat_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1049 -| System Network Connections Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use this command for troubleshooting. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1049/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1049/AD_discovery/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Nishang powershelltcponeline=== -This query detects the Nishang Invoke-PowerShellTCPOneLine utility that spawns a call back to a remote command and control server. This is a powershell oneliner. In addition, this will capture on the command-line additional utilities used by Nishang. Triage the endpoint and identify any parallel processes that look suspicious. Review the reputation of the remote IP or domain contacted by the powershell process. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/ T1059], [https://attack.mitre.org/techniques/T1059/001/ T1059.001] -* '''Last Updated''': 2021-03-03 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_powershell` (Processes.process=*Net.Sockets.TCPClient* AND Processes.process=*System.Text.ASCIIEncoding*) by Processes.dest Processes.user Processes.parent_process Processes.original_file_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `nishang_powershelltcponeline_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#HAFNIUM_Group|HAFNIUM Group]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1059 -| Command and Scripting Interpreter -| Execution -|- -| T1059.001 -| PowerShell -| Execution -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Limited false positives may be present. Filter as needed based on initial analysis. - -====Reference==== - - -* https://github.com/samratashok/nishang/blob/master/Shells/Invoke-PowerShellTcpOneLine.ps1 - -* https://www.volexity.com/blog/2021/03/02/active-exploitation-of-microsoft-exchange-zero-day-vulnerabilities/ - -* https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/ - -* https://blog.rapid7.com/2021/03/03/rapid7s-insightidr-enables-detection-and-response-to-microsoft-exchange-0-day/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/atomic_red_team/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Non chrome process accessing chrome default dir=== -This search is to detect an anomaly event of non-chrome process accessing the files in chrome user default folder. This folder contains all the sqlite database of the chrome browser related to users login, history, cookies and etc. Most of the RAT, trojan spy as well as FIN7 jssloader try to parse the those sqlite database to collect information on the compromised host. This SACL Event (4663) need to be enabled to tthe firefox profile directory to be eable to use this. Since you monitoring this access to the folder a noise coming from firefox need to be filter and also sqlite db browser and explorer .exe to make this detection more stable. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1555/ T1555], [https://attack.mitre.org/techniques/T1555/003/ T1555.003] -* '''Last Updated''': 2021-09-15 - -
-
- -====Search==== -`wineventlog_security` EventCode=4663 NOT (process_name IN ("*\\chrome.exe", "*\\explorer.exe", "*sql*")) Object_Name="*\\Google\\Chrome\\User Data\\Default*" -| stats count min(_time) as firstTime max(_time) as lastTime by Object_Name Object_Type process_name Access_Mask Accesses process_id EventCode dest user -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `non_chrome_process_accessing_chrome_default_dir_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#FIN7|FIN7]] - - -====How To Implement==== -To successfully implement this search, you must ingest Windows Security Event logs and track event code 4663. For 4663, enable "Audit Object Access" in Group Policy. Then check the two boxes listed for both "Success" and "Failure." - -====Required field==== - -* _time - -* Object_Name - -* Object_Type - -* process_name - -* Access_Mask - -* Accesses - -* process_id - -* EventCode - -* dest - -* user - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1555 -| Credentials from Password Stores -| Credential Access -|- -| T1555.003 -| Credentials from Web Browsers -| Credential Access -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -other browser not listed related to firefox may catch by this rule. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/fin7/fin7_sacl/security2.log - - -''version'': 1 -
-
- ----- - -===Non firefox process access firefox profile dir=== -This search is to detect an anomaly event of non-firefox process accessing the files in profile folder. This folder contains all the sqlite database of the firefox browser related to users login, history, cookies and etc. Most of the RAT, trojan spy as well as FIN7 jssloader try to parse the those sqlite database to collect information on the compromised host. This SACL Event (4663) need to be enabled to tthe firefox profile directory to be eable to use this. Since you monitoring this access to the folder a noise coming from firefox need to be filter and also sqlite db browser and explorer .exe to make this detection more stable. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1555/ T1555], [https://attack.mitre.org/techniques/T1555/003/ T1555.003] -* '''Last Updated''': 2021-09-15 - -
-
- -====Search==== -`wineventlog_security` EventCode=4663 NOT (process_name IN ("*\\firefox.exe", "*\\explorer.exe", "*sql*")) Object_Name="*\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles*" -| stats count min(_time) as firstTime max(_time) as lastTime by Object_Name Object_Type process_name Access_Mask Accesses process_id EventCode dest user -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `non_firefox_process_access_firefox_profile_dir_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#FIN7|FIN7]] - - -====How To Implement==== -To successfully implement this search, you must ingest Windows Security Event logs and track event code 4663. For 4663, enable "Audit Object Access" in Group Policy. Then check the two boxes listed for both "Success" and "Failure." - -====Required field==== - -* _time - -* Object_Name - -* Object_Type - -* process_name - -* Access_Mask - -* Accesses - -* process_id - -* EventCode - -* dest - -* user - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1555 -| Credentials from Password Stores -| Credential Access -|- -| T1555.003 -| Credentials from Web Browsers -| Credential Access -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -other browser not listed related to firefox may catch by this rule. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/fin7/fin7_sacl/security.log - - -''version'': 1 -
-
- ----- - -===Ntdsutil export ntds=== -Monitor for signs that Ntdsutil is being used to Extract Active Directory database - NTDS.dit, typically used for offline password cracking. It may be used in normal circumstances with no command line arguments or shorthand variations of more common arguments. Ntdsutil.exe is typically seen run on a Windows Server. Typical command used to dump ntds.dit \ -ntdsutil "ac i ntds" "ifm" "create full C:\Temp" q q \ -This technique uses "Install from Media" (IFM), which will extract a copy of the Active Directory database. A successful export of the Active Directory database will yield a file modification named ntds.dit to the destination. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/003/ T1003.003], [https://attack.mitre.org/techniques/T1003/ T1003] -* '''Last Updated''': 2021-01-28 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name=ntdsutil.exe Processes.process=*ntds* Processes.process=*create*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `ntdsutil_export_ntds_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Credential_Dumping|Credential Dumping]] - -* [[Documentation:ESSOC:stories:UseCase#HAFNIUM_Group|HAFNIUM Group]] - - -====How To Implement==== -You must be ingesting endpoint data that tracks process activity, including parent-child relationships from your endpoints, to populate the Endpoint data model in the Processes node. The command-line arguments are mapped to the "process" field in the Endpoint data model. - -====Required field==== - -* _time - -* Processes.process_name - -* Processes.process - -* Processes.dest - -* Processes.user - -* Processes.parent_process - -* Processes.process_id - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1003.003 -| NTDS -| Credential Access -|- -| T1003 -| OS Credential Dumping -| Credential Access -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Highly possible Server Administrators will troubleshoot with ntdsutil.exe, generating false positives. - -====Reference==== - - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1003.003/T1003.003.md#atomic-test-3---dump-active-directory-database-with-ntdsutil - -* https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-R2-and-2012/cc753343(v=ws.11) - -* https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf - -* https://strontic.github.io/xcyclopedia/library/vss_ps.dll-97B15BDAE9777F454C9A6BA25E938DB3.html - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.003/atomic_red_team/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Office application drop executable=== -This search is to detect a suspicious MS office application that drop or create executables or script in the host. This behavior is commonly seen in spear phishing office attachment where it drop malicious files or script to compromised the host. It might be some normal macro may drop script or tools as part of automation but still this behavior is reallly suspicious and not commonly seen in normal office application - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/ T1566], [https://attack.mitre.org/techniques/T1566/001/ T1566.001] -* '''Last Updated''': 2021-09-13 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name IN ("winword.exe","excel.exe","powerpnt.exe","mspub.exe","visio.exe","wordpad.exe","wordview.exe") by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest -| `drop_dm_object_name(Processes)` -| join process_guid, _time [ -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_name IN ("*.exe","*.dll","*.pif","*.scr","*.js","*.vbs","*.vbe","*.ps1") by _time span=1h Filesystem.dest Filesystem.file_create_time Filesystem.file_name Filesystem.file_path -| `drop_dm_object_name(Filesystem)` -| fields _time dest file_create_time file_name file_path process_name process_path process] -| dedup file_create_time -| table dest, process_name, process, file_create_time, file_name, file_path -| `office_application_drop_executable_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#FIN7|FIN7]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed rundll32.exe may be used. - -====Required field==== - -* _time - -* Image - -* TargetFilename - -* ProcessGuid - -* dest - -* user_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1566 -| Phishing -| Initial Access -|- -| T1566.001 -| Spearphishing Attachment -| Initial Access -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -office macro for automation may do this behavior - -====Reference==== - - -* https://www.fireeye.com/blog/threat-research/2018/08/fin7-pursuing-an-enigmatic-and-evasive-global-criminal-operation.html - -* https://attack.mitre.org/groups/G0046/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/fin7/fin7_macro_js_1/sysmon.log - - -''version'': 1 -
-
- ----- - -===Office application spawn regsvr32 process=== -this detection was designed to identifies suspicious spawned process of known MS office application due to macro or malicious code. this technique can be seen in so many malware like IcedID that used MS office as its weapon or attack vector to initially infect the machines. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/ T1566], [https://attack.mitre.org/techniques/T1566/001/ T1566.001] -* '''Last Updated''': 2021-07-30 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.parent_process_name = "winword.exe" OR Processes.parent_process_name = "excel.exe" OR Processes.parent_process_name = "powerpnt.exe" OR Processes.parent_process_name = "outlook.exe") `process_regsvr32` by Processes.parent_process_name Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.process_guid Processes.user Processes.dest -| `drop_dm_object_name("Processes")` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -| `office_application_spawn_regsvr32_process_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#IcedID|IcedID]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1566 -| Phishing -| Initial Access -|- -| T1566.001 -| Spearphishing Attachment -| Initial Access -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://www.joesandbox.com/analysis/380662/0/html - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/phish_icedid/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Office application spawn rundll32 process=== -this detection was designed to identifies suspicious spawned process of known MS office application due to macro or malicious code. this technique can be seen in so many malware like trickbot that used MS office as its weapon or attack vector to initially infect the machines. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/ T1566], [https://attack.mitre.org/techniques/T1566/001/ T1566.001] -* '''Last Updated''': 2021-04-13 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count values(Processes.process) min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.parent_process_name = "winword.exe" OR Processes.parent_process_name = "excel.exe" OR Processes.parent_process_name = "powerpnt.exe") `process_rundll32` by Processes.parent_process Processes.process_name Processes.process_id Processes.process_guid Processes.user Processes.dest -| `drop_dm_object_name("Processes")` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -| `office_application_spawn_rundll32_process_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Spearphishing_Attachments|Spearphishing Attachments]] - -* [[Documentation:ESSOC:stories:UseCase#Trickbot|Trickbot]] - -* [[Documentation:ESSOC:stories:UseCase#IcedID|IcedID]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1566 -| Phishing -| Initial Access -|- -| T1566.001 -| Spearphishing Attachment -| Initial Access -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://any.run/malware-trends/trickbot - -* https://any.run/report/47561b4e949041eff0a0f4693c59c81726591779fe21183ae9185b5eb6a69847/aba3722a-b373-4dae-8273-8730fb40cdbe - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/datasets/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Office document creating schedule task=== -this search detects a potential malicious office document that create schedule task entry through macro VBA api or through loading taskschd.dll. This technique was seen in so many malicious macro malware that create persistence , beaconing using task schedule malware entry The search will return the first time and last time the task was registered, as well as the `Command` to be executed, `Task Name`, `Author`, `Enabled`, and whether it is `Hidden` or not. schtasks.exe is natively found in `C:\Windows\system32` and `C:\Windows\syswow64`. The following DLL(s) are loaded when schtasks.exe or TaskService is launched -`taskschd.dll`. If found loaded by another process, it's possible a scheduled task is being registered within that process context in memory. Upon triage, identify the task scheduled source. Was it schtasks.exe or via TaskService? Review the job created and the Command to be executed. Capture any artifacts on disk and review. Identify any parallel processes within the same timeframe to identify source.' - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/ T1566], [https://attack.mitre.org/techniques/T1566/001/ T1566.001] -* '''Last Updated''': 2021-04-14 - -
-
- -====Search==== -`sysmon` EventCode=7 process_name IN ("WINWORD.EXE", "EXCEL.EXE", "POWERPNT.EXE") ImageLoaded = "*\\taskschd.dll" -| stats min(_time) as firstTime max(_time) as lastTime values(ImageLoaded) as AllImageLoaded count by Computer EventCode Image process_name ProcessId ProcessGuid -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `office_document_creating_schedule_task_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Spearphishing_Attachments|Spearphishing Attachments]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name and ImageLoaded (Like sysmon EventCode 7) from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Also be sure to include those monitored dll to your own sysmon config. - -====Required field==== - -* ImageLoaded - -* AllImageLoaded - -* Computer - -* EventCode - -* Image - -* process_name - -* ProcessId - -* ProcessGuid - -* _time - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1566 -| Phishing -| Initial Access -|- -| T1566.001 -| Spearphishing Attachment -| Initial Access -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://research.checkpoint.com/2021/irans-apt34-returns-with-an-updated-arsenal/ - -* https://redcanary.com/threat-detection-report/techniques/scheduled-task-job/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/datasets/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Office document executing macro code=== -this detection was designed to identifies suspicious office documents that using macro code. Macro code is known to be one of the prevalent weaponization or attack vector of threat actor. This malicious macro code is embed to a office document as an attachment that may execute malicious payload, download malware payload or other malware component. It is really good practice to disable macro by default to avoid automatically execute macro code while opening or closing a office document files. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/ T1566], [https://attack.mitre.org/techniques/T1566/001/ T1566.001] -* '''Last Updated''': 2021-04-14 - -
-
- -====Search==== -`sysmon` EventCode=7 process_name IN ("WINWORD.EXE", "EXCEL.EXE", "POWERPNT.EXE") ImageLoaded IN ("*\\VBE7INTL.DLL","*\\VBE7.DLL", "*\\VBEUI.DLL") -| stats min(_time) as firstTime max(_time) as lastTime values(ImageLoaded) as AllImageLoaded count by Computer EventCode Image process_name ProcessId ProcessGuid -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `office_document_executing_macro_code_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Spearphishing_Attachments|Spearphishing Attachments]] - -* [[Documentation:ESSOC:stories:UseCase#Trickbot|Trickbot]] - -* [[Documentation:ESSOC:stories:UseCase#IcedID|IcedID]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name and ImageLoaded (Like sysmon EventCode 7) from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Also be sure to include those monitored dll to your own sysmon config. - -====Required field==== - -* ImageLoaded - -* AllImageLoaded - -* Computer - -* EventCode - -* Image - -* process_name - -* ProcessId - -* ProcessGuid - -* _time - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1566 -| Phishing -| Initial Access -|- -| T1566.001 -| Spearphishing Attachment -| Initial Access -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Normal Office Document macro use for automation - -====Reference==== - - -* https://www.joesandbox.com/analysis/386500/0/html - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/datasets/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Office document spawned child process to download=== -This search is to detect potential malicious office document executing lolbin child process to download payload or other malware. Since most of the attacker abused the capability of office document to execute living on land application to blend it to the normal noise in the infected machine to cover its track. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/ T1566], [https://attack.mitre.org/techniques/T1566/001/ T1566.001] -* '''Last Updated''': 2021-09-20 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name IN ("winword.exe","excel.exe","powerpnt.exe","mspub.exe","visio.exe") Processes.process IN ("*http:*","*https:*") NOT (Processes.original_file_name IN("firefox.exe", "chrome.exe","iexplore.exe","msedge.exe")) by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.original_file_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `office_document_spawned_child_process_to_download_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Spearphishing_Attachments|Spearphishing Attachments]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances office application and browser may be used. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1566 -| Phishing -| Initial Access -|- -| T1566.001 -| Spearphishing Attachment -| Initial Access -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Default browser not in the filter list. - -====Reference==== - - -* https://app.any.run/tasks/92d7ef61-bfd7-4c92-bc15-322172b4ebec/# - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/datasets2/windows-sysmon.log - - -''version'': 3 -
-
- ----- - -===Office product spawn cmd process=== -this search is to detect a suspicious office product process that spawn cmd child process. This is commonly seen in a ms office product having macro to execute shell command to download or execute malicious lolbin relative to its malicious code. This is seen in trickbot spear phishing doc where it execute shell cmd to run mshta payload. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/005/ T1218.005] -* '''Last Updated''': 2021-07-19 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.parent_process_name = "winword.exe" OR Processes.parent_process_name= "excel.exe" OR Processes.parent_process_name = "powerpnt.exe") `process_cmd` by Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.process_guid Processes.user Processes.dest Processes.original_file_name -| `drop_dm_object_name("Processes")` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -| `office_product_spawn_cmd_process_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Trickbot|Trickbot]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1218 -| Signed Binary Proxy Execution -| Defense Evasion -|- -| T1218.005 -| Mshta -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -IT or network admin may create an document automation that will run shell script. - -====Reference==== - - -* https://twitter.com/cyb3rops/status/1416050325870587910?s=21 - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/trickbot/spear_phish/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Office product spawning bitsadmin=== -The following detection identifies the latest behavior utilized by different malware families (including TA551, IcedID). This detection identifies any Windows Office Product spawning `bitsadmin.exe`. In malicious instances, the command-line of `bitsadmin.exe` will contain a URL to a remote destination or similar command-line arguments as transfer, Download, priority, Foreground. In addition, Threat Research has released a detections identifying suspicious use of `bitsadmin.exe`. In this instance, we narrow our detection down to the Office suite as a parent process. During triage, review all file modifications. Capture and analyze any artifacts on disk. The Office Product, or `bitsadmin.exe` will have reached out to a remote destination, capture and block the IPs or domain. Review additional parallel processes for further activity. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/ T1566], [https://attack.mitre.org/techniques/T1566/001/ T1566.001] -* '''Last Updated''': 2021-04-26 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name IN ("winword.exe","excel.exe","powerpnt.exe","mspub.exe","visio.exe") `process_bitsadmin` by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `office_product_spawning_bitsadmin_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Spearphishing_Attachments|Spearphishing Attachments]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1566 -| Phishing -| Initial Access -|- -| T1566.001 -| Spearphishing Attachment -| Initial Access -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -No false positives known. Filter as needed. - -====Reference==== - - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1197/T1197.md - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_macros.log - - -''version'': 2 -
-
- ----- - -===Office product spawning certutil=== -The following detection identifies the latest behavior utilized by different malware families (including TA551, IcedID). This detection identifies any Windows Office Product spawning `certutil.exe`. In malicious instances, the command-line of `certutil.exe` will contain a URL to a remote destination. In addition, Threat Research has released a detections identifying suspicious use of `certutil.exe`. In this instance, we narrow our detection down to the Office suite as a parent process. During triage, review all file modifications. Capture and analyze any artifacts on disk. The Office Product, or `certutil.exe` will have reached out to a remote destination, capture and block the IPs or domain. Review additional parallel processes for further activity. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/ T1566], [https://attack.mitre.org/techniques/T1566/001/ T1566.001] -* '''Last Updated''': 2021-04-26 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name IN ("winword.exe","excel.exe","powerpnt.exe","mspub.exe","visio.exe") `process_certutil` by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `office_product_spawning_certutil_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Spearphishing_Attachments|Spearphishing Attachments]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1566 -| Phishing -| Initial Access -|- -| T1566.001 -| Spearphishing Attachment -| Initial Access -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -No false positives known. Filter as needed. - -====Reference==== - - -* https://redcanary.com/threat-detection-report/threats/TA551/ - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1105/T1105.md - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_macros.log - - -''version'': 2 -
-
- ----- - -===Office product spawning mshta=== -The following detection identifies the latest behavior utilized by different malware families (including TA551, IcedID). This detection identifies any Windows Office Product spawning `mshta.exe`. In malicious instances, the command-line of `mshta.exe` will contain the `hta` file locally, or a URL to the remote destination. In addition, Threat Research has released a detections identifying suspicious use of `mshta.exe`. In this instance, we narrow our detection down to the Office suite as a parent process. During triage, review all file modifications. Capture and analyze any artifacts on disk. The Office Product, or `mshta.exe` will have reached out to a remote destination, capture and block the IPs or domain. Review additional parallel processes for further activity. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/ T1566], [https://attack.mitre.org/techniques/T1566/001/ T1566.001] -* '''Last Updated''': 2021-04-26 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name IN ("winword.exe","excel.exe","powerpnt.exe","mspub.exe","visio.exe") `process_mshta` by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `office_product_spawning_mshta_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Spearphishing_Attachments|Spearphishing Attachments]] - -* [[Documentation:ESSOC:stories:UseCase#IcedID|IcedID]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1566 -| Phishing -| Initial Access -|- -| T1566.001 -| Spearphishing Attachment -| Initial Access -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -No false positives known. Filter as needed. - -====Reference==== - - -* https://redcanary.com/threat-detection-report/threats/TA551/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_macros.log - - -''version'': 2 -
-
- ----- - -===Office product spawning rundll32 with no dll=== -The following detection identifies the latest behavior utilized by IcedID malware family. This detection identifies any Windows Office Product spawning `rundll32.exe` without a `.dll` file extension. In malicious instances, the command-line of `rundll32.exe` will look like `rundll32 ..\oepddl.igk2,DllRegisterServer`. In addition, Threat Research has released a detection identifying the use of `DllRegisterServer` on the command-line of `rundll32.exe`. In this instance, we narrow our detection down to the Office suite as a parent process. During triage, review all file modifications. Capture and analyze the `DLL` that was dropped to disk. The Office Product will have reached out to a remote destination, capture and block the IPs or domain. Review additional parallel processes for further activity. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/ T1566], [https://attack.mitre.org/techniques/T1566/001/ T1566.001] -* '''Last Updated''': 2021-04-22 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name IN ("winword.exe","excel.exe","powerpnt.exe","mspub.exe","visio.exe") `process_rundll32` (Processes.process!=*.dll*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `office_product_spawning_rundll32_with_no_dll_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Spearphishing_Attachments|Spearphishing Attachments]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1566 -| Phishing -| Initial Access -|- -| T1566.001 -| Spearphishing Attachment -| Initial Access -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -False positives should be limited, but if any are present, filter as needed. - -====Reference==== - - -* https://www.joesandbox.com/analysis/395471/0/html - -* https://app.any.run/tasks/cef4b8ba-023c-4b3b-b2ef-6486a44f6ed9/ - -* https://any.run/malware-trends/icedid - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_icedid.log - - -''version'': 2 -
-
- ----- - -===Office product spawning wmic=== -The following detection identifies the latest behavior utilized by Ursnif malware family. This detection identifies any Windows Office Product spawning `wmic.exe`. In malicious instances, the command-line of `wmic.exe` will contain `wmic process call create`. In addition, Threat Research has released a detection identifying the use of `wmic process call create` on the command-line of `wmic.exe`. In this instance, we narrow our detection down to the Office suite as a parent process. During triage, review all file modifications. Capture and analyze any artifacts on disk. The Office Product, or `wmic.exe` will have reached out to a remote destination, capture and block the IPs or domain. Review additional parallel processes for further activity. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/ T1566], [https://attack.mitre.org/techniques/T1566/001/ T1566.001] -* '''Last Updated''': 2021-09-16 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name IN ("winword.exe","excel.exe","powerpnt.exe","mspub.exe","visio.exe") `process_wmic` by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `office_product_spawning_wmic_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Spearphishing_Attachments|Spearphishing Attachments]] - -* [[Documentation:ESSOC:stories:UseCase#FIN7|FIN7]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1566 -| Phishing -| Initial Access -|- -| T1566.001 -| Spearphishing Attachment -| Initial Access -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -No false positives known. Filter as needed. - -====Reference==== - - -* https://app.any.run/tasks/fb894ab8-a966-4b72-920b-935f41756afd/ - -* https://attack.mitre.org/techniques/T1047/ - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1047/T1047.md - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_macros.log - - -''version'': 3 -
-
- ----- - -===Office product writing cab or inf=== -The following analytic identifies behavior related to CVE-2021-40444. Whereas the malicious document will load ActiveX and download the remote payload (.inf, .cab). During triage, review parallel processes and further activity on endpoint to identify additional patterns. Retrieve the file modifications and analyze further. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/ T1566], [https://attack.mitre.org/techniques/T1566/001/ T1566.001] -* '''Last Updated''': 2021-09-10 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name IN ("winword.exe","excel.exe","powerpnt.exe","mspub.exe","visio.exe","wordpad.exe","wordview.exe") by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest -| `drop_dm_object_name(Processes)` -| join process_guid, _time [ -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_name IN ("*.inf","*.cab") by _time span=1h Filesystem.dest Filesystem.file_create_time Filesystem.file_name Filesystem.file_path -| `drop_dm_object_name(Filesystem)` -| fields _time dest file_create_time file_name file_path process_name process_path process] -| dedup file_create_time -| table dest, process_name, process, file_create_time, file_name, file_path -| `office_product_writing_cab_or_inf_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Spearphishing_Attachments|Spearphishing Attachments]] - -* [[Documentation:ESSOC:stories:UseCase#Microsoft_MSHTML_Remote_Code_Execution_CVE-2021-40444|Microsoft MSHTML Remote Code Execution CVE-2021-40444]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node and `Filesystem` node. - -====Required field==== - -* _time - -* dest - -* process_name - -* process - -* file_create_time - -* file_name - -* file_path - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1566 -| Phishing -| Initial Access -|- -| T1566.001 -| Spearphishing Attachment -| Initial Access -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -The query is structured in a way that `action` (read, create) is not defined. Review the results of this query, filter, and tune as necessary. It may be necessary to generate this query specific to your endpoint product. - -====Reference==== - - -* https://twitter.com/vxunderground/status/1436326057179860992?s=20 - -* https://app.any.run/tasks/36c14029-9df8-439c-bba0-45f2643b0c70/ - -* https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40444 - -* https://twitter.com/RonnyTNL/status/1436334640617373699?s=20 - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_cabinf.log - - -''version'': 1 -
-
- ----- - -===Office spawning control=== -The following detection identifies control.exe spawning from an office product. This detection identifies any Windows Office Product spawning `control.exe`. In malicious instances, the command-line of `control.exe` will contain a file path to a .cpl or .inf, related to CVE-2021-40444. In this instance, we narrow our detection down to the Office suite as a parent process. During triage, review all file modifications. Capture and analyze any artifacts on disk. review parallel and child processes to identify further suspicious behavior - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/ T1566], [https://attack.mitre.org/techniques/T1566/001/ T1566.001] -* '''Last Updated''': 2021-09-08 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name IN ("winword.exe","excel.exe","powerpnt.exe","mspub.exe","visio.exe","wordpad.exe","wordview.exe") Processes.process_name=control.exe by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `office_spawning_control_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Spearphishing_Attachments|Spearphishing Attachments]] - -* [[Documentation:ESSOC:stories:UseCase#Microsoft_MSHTML_Remote_Code_Execution_CVE-2021-40444|Microsoft MSHTML Remote Code Execution CVE-2021-40444]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1566 -| Phishing -| Initial Access -|- -| T1566.001 -| Spearphishing Attachment -| Initial Access -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Limited false positives should be present. - -====Reference==== - - -* https://strontic.github.io/xcyclopedia/library/control.exe-1F13E714A0FEA8887707DFF49287996F.html - -* https://app.any.run/tasks/36c14029-9df8-439c-bba0-45f2643b0c70/ - -* https://attack.mitre.org/techniques/T1218/011/ - -* https://www.echotrail.io/insights/search/control.exe - -* https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40444 - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.002/T1218.002.yaml - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_control.log - - -''version'': 1 -
-
- ----- - -===Overwriting accessibility binaries=== -Microsoft Windows contains accessibility features that can be launched with a key combination before a user has logged in. An adversary can modify or replace these programs so they can get a command prompt or backdoor without logging in to the system. This search looks for modifications to these binaries. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1546/ T1546], [https://attack.mitre.org/techniques/T1546/008/ T1546.008] -* '''Last Updated''': 2020-07-21 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Filesystem.user) as user values(Filesystem.dest) as dest values(Filesystem.file_path) as file_path from datamodel=Endpoint.Filesystem where (Filesystem.file_path=*\\Windows\\System32\\sethc.exe* OR Filesystem.file_path=*\\Windows\\System32\\utilman.exe* OR Filesystem.file_path=*\\Windows\\System32\\osk.exe* OR Filesystem.file_path=*\\Windows\\System32\\Magnify.exe* OR Filesystem.file_path=*\\Windows\\System32\\Narrator.exe* OR Filesystem.file_path=*\\Windows\\System32\\DisplaySwitch.exe* OR Filesystem.file_path=*\\Windows\\System32\\AtBroker.exe*) by Filesystem.file_name Filesystem.dest -| `drop_dm_object_name(Filesystem)` -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `overwriting_accessibility_binaries_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Privilege_Escalation|Windows Privilege Escalation]] - - -====How To Implement==== -You must be ingesting data that records the filesystem activity from your hosts to populate the Endpoint file-system data model node. If you are using Sysmon, you will need a Splunk Universal Forwarder on each endpoint from which you want to collect data. - -====Required field==== - -* _time - -* Filesystem.dest - -* Filesystem.file_path - -* Filesystem.file_name - -* Filesystem.dest - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1546 -| Event Triggered Execution -| Privilege Escalation, Persistence -|- -| T1546.008 -| Accessibility Features -| Privilege Escalation, Persistence -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Microsoft may provide updates to these binaries. Verify that these changes do not correspond with your normal software update cycle. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.008/atomic_red_team/windows-sysmon.log - - -''version'': 4 -
-
- ----- - -===Password policy discovery with net=== -This analytic looks for the execution of `net.exe` or `net1.exe` with command line arguments used to obtain the domain password policy. Red Teams and adversaries may leverage `net.exe` for situational awareness and Active Directory Discovery. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1201/ T1201] -* '''Last Updated''': 2021-08-26 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="net.exe" OR Processes.process_name="net1.exe") AND Processes.process = "*accounts*" AND Processes.process = "*/domain*" by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `password_policy_discovery_with_net_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed rundll32.exe may be used. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_id - -* Processes.parent_process_name - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1201 -| Password Policy Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use this command for troubleshooting. - -====Reference==== - - -* https://github.com/S1ckB0y1337/Active-Directory-Exploitation-Cheat-Sheet - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1201/pwd_policy_discovery/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Permission modification using takeown app=== -This search is to detect a modification of file or directory permission using takeown.exe windows app. This technique was seen in some ransomware that take the ownership of a folder or files to encrypt or delete it. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1222/ T1222] -* '''Last Updated''': 2021-06-10 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = "takeown.exe" Processes.process = "*/f*" by Processes.parent_process_name Processes.parent_process Processes.process_name Processes.process Processes.dest Processes.user Processes.process_id Processes.process_guid -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `permission_modification_using_takeown_app_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -====Required field==== - -* _time - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.process_name - -* Processes.process - -* Processes.dest - -* Processes.user - -* Processes.process_id - -* Processes.process_guid - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1222 -| File and Directory Permissions Modification -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -takeown.exe is a normal windows application that may used by network operator. - -====Reference==== - - -* https://research.nccgroup.com/2020/06/23/wastedlocker-a-new-ransomware-variant-developed-by-the-evil-corp-group/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/data1/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Petitpotam network share access request=== -The following analytic utilizes Windows Event Code 5145, "A network share object was checked to see whether client can be granted desired access". During our research into PetitPotam, CVE-2021-36942, we identified the ocurrence of this event on the target host with specific values. \ -To enable 5145 events via Group Policy - Computer Configuration->Polices->Windows Settings->Security Settings->Advanced Audit Policy Configuration. Expand this node, go to Object Access (Audit Polices->Object Access), then select the Setting Audit Detailed File Share Audit \ -It is possible this is not enabled by default and may need to be reviewed and enabled. \ -During triage, review parallel security events to identify further suspicious activity. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1187/ T1187] -* '''Last Updated''': 2021-08-31 - -
-
- -====Search==== -`wineventlog_security` Account_Name="ANONYMOUS LOGON" EventCode=5145 Relative_Target_Name=lsarpc -| stats count min(_time) as firstTime max(_time) as lastTime by dest, Security_ID, Share_Name, Source_Address, Accesses, Message -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `petitpotam_network_share_access_request_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#PetitPotam_NTLM_Relay_on_Active_Directory_Certificate_Services|PetitPotam NTLM Relay on Active Directory Certificate Services]] - - -====How To Implement==== -Windows Event Code 5145 is required to utilize this analytic and it may not be enabled in most environments. - -====Required field==== - -* _time - -* dest - -* Security_ID - -* Share_Name - -* Source_Address - -* Accesses - -* Message - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1187 -| Forced Authentication -| Credential Access -|} - - -====Kill Chain Phase==== - -* Exploitation - -* Lateral Movement - - -====Known False Positives==== -False positives have been limited when the Anonymous Logon is used for Account Name. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1187/ - -* https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5145 - -* https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-5145 - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1187/petitpotam/windows-security.log - - -''version'': 1 -
-
- ----- - -===Petitpotam suspicious kerberos tgt request=== -The following analytic identifes Event Code 4768, A `Kerberos authentication ticket (TGT) was requested`, successfull occurs. This behavior has been identified to assist with detecting PetitPotam, CVE-2021-36942. Once an attacer obtains a computer certificate by abusing Active Directory Certificate Services in combination with PetitPotam, the next step would be to leverage the certificate for malicious purposes. One way of doing this is to request a Kerberos Ticket Granting Ticket using a tool like Rubeus. This request will generate a 4768 event with some unusual fields depending on the environment. This analytic will require tuning, we recommend filtering Account_Name to Domain Controllers for your environment. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/ T1003] -* '''Last Updated''': 2021-08-31 - -
-
- -====Search==== -`wineventlog_security` EventCode=4768 Client_Address!="::1" Certificate_Thumbprint!="" Account_Name=*$ -| stats count min(_time) as firstTime max(_time) as lastTime by dest, Account_Name, Client_Address, action, Message -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `petitpotam_suspicious_kerberos_tgt_request_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#PetitPotam_NTLM_Relay_on_Active_Directory_Certificate_Services|PetitPotam NTLM Relay on Active Directory Certificate Services]] - - -====How To Implement==== -The following analytic requires Event Code 4768. Ensure that it is logging no Domain Controllers and appearing in Splunk. - -====Required field==== - -* _time - -* dest - -* Account_Name - -* Client_Address - -* action - -* Message - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1003 -| OS Credential Dumping -| Credential Access -|} - - -====Kill Chain Phase==== - -* Exploitation - -* Lateral Movement - - -====Known False Positives==== -False positives are possible if the environment is using certificates for authentication. - -====Reference==== - - -* https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4768 - -* https://isc.sans.edu/forums/diary/Active+Directory+Certificate+Services+ADCS+PKI+domain+admin+vulnerability/27668/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1187/petitpotam/windows-security.log - - -''version'': 1 -
-
- ----- - -===Potential pass the token or hash observed at the destination device=== -This detection identifies potential Pass the Token or Pass the Hash credential exploits. We detect the main side effect of these attacks, which is a transition from the dominant Kerberos logins to rare NTLM logins for a given user, as reported by a detination device. - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1550/ T1550], [https://attack.mitre.org/techniques/T1550/002/ T1550.002] -* '''Last Updated''': 2021-09-01 - -
-
- -====Search==== - -| from read_ssa_enriched_events() -| eval timestamp= parse_long(ucast(map_get(input_event, "_time"), "string", null)), dest_user= lower(ucast(map_get(input_event, "dest_user_primary_artifact"), "string", null)), dest_user_id= lower(ucast(map_get(input_event, "dest_user_id"), "string", null)), dest_device_id= lower(ucast(map_get(input_event, "dest_device_id"), "string", null)), signature_id= lower(ucast(map_get(input_event, "signature_id"), "string", null)), authentication_method= lower(ucast(map_get(input_event, "authentication_method"), "string", null)) - -| where signature_id = "4624" AND (authentication_method="ntlmssp" OR authentication_method="kerberos") AND dest_user_id != null AND dest_device_id != null - -| eval isKerberos=if(authentication_method == "kerberos", 1, 0), isNtlm=if(authentication_method == "ntlmssp", 1, 0), timeNTLM=if(isNtlm > 0, timestamp, null) - -| stats sum(isKerberos) as totalKerberos, sum(isNtlm) as totalNtlm, min(timestamp) as startTime, min(timeNTLM) as startNTLMTime, max(timestamp) as endTime, max(timeNTLM) as endNTLMTime by dest_user_id, dest_user, dest_device_id, span(timestamp, 86400s) - -| where NOT dest_user="-" AND totalKerberos > 0 AND totalNtlm > 0 AND endTime - startTime > 1800000 AND (totalKerberos > 10 * totalNtlm AND totalKerberos > 50) AND (endTime - startTime) > 3 * (endNTLMTime - startNTLMTime) - -| eval start_time=ucast(startNTLMTime, "long", null), end_time=ucast(endNTLMTime, "long", null), entities=mvappend(dest_user_id, dest_device_id), body=create_map(["total_kerberos", totalKerberos, "total_ntlm", totalNtlm, "analysis_start_time", startTime, "analysis_end_time", endTime, "pth_start_time", startNTLMTime, "pth_end_time", endNTLMTime]) - -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Lateral_Movement|Lateral Movement]] - - -====How To Implement==== -You must be ingesting Windows Security logs from endpoint devices, i.e., destinations of interest. Please make sure that event ID 4624 is being logged. - -====Required field==== - -* _time - -* signature_id - -* dest_user - -* dest_user_id - -* dest_device_id - -* authentication_method - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1550 -| Use Alternate Authentication Material -| Defense Evasion, Lateral Movement -|- -| T1550.002 -| Pass the Hash -| Defense Evasion, Lateral Movement -|} - - -====Kill Chain Phase==== - -* Lateral Movement - - -====Known False Positives==== -Environments in which NTLM is used extremely rarely and for benign purposes (such as a rare use of SMB shares). - -====Reference==== - - -* https://attack.mitre.org/techniques/T1550/002/ - - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Potential pass the token or hash observed by an event collecting device=== -This detection identifies potential Pass the Token or Pass the Hash credential exploits. We detect the main side effect of these attacks, which is a transition from the dominant Kerberos logins to rare NTLM logins for a given user, as reported by an event-collecting device (i.e., a specific domain controller or an endpoint destination). - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1550/ T1550], [https://attack.mitre.org/techniques/T1550/002/ T1550.002] -* '''Last Updated''': 2021-09-01 - -
-
- -====Search==== - -| from read_ssa_enriched_events() -| eval timestamp= parse_long(ucast(map_get(input_event, "_time"), "string", null)), dest_user= lower(ucast(map_get(input_event, "dest_user_primary_artifact"), "string", null)), dest_user_id= lower(ucast(map_get(input_event, "dest_user_id"), "string", null)), origin_device_id= lower(ucast(map_get(input_event, "origin_device_id"), "string", null)), signature_id= lower(ucast(map_get(input_event, "signature_id"), "string", null)), authentication_method= lower(ucast(map_get(input_event, "authentication_method"), "string", null)) - -| where signature_id = "4624" AND (authentication_method="ntlmssp" OR authentication_method="kerberos") AND dest_user_id != null AND origin_device_id != null - -| eval isKerberos=if(authentication_method == "kerberos", 1, 0), isNtlm=if(authentication_method == "ntlmssp", 1, 0), timeNTLM=if(isNtlm > 0, timestamp, null) - -| stats sum(isKerberos) as totalKerberos, sum(isNtlm) as totalNtlm, min(timestamp) as startTime, min(timeNTLM) as startNTLMTime, max(timestamp) as endTime, max(timeNTLM) as endNTLMTime by dest_user_id, dest_user, origin_device_id, span(timestamp, 86400s) - -| where NOT dest_user="-" AND totalKerberos > 0 AND totalNtlm > 0 AND endTime - startTime > 1800000 AND (totalKerberos > 10 * totalNtlm AND totalKerberos > 50) AND (endTime - startTime) > 3 * (endNTLMTime - startNTLMTime) - -| eval start_time=startNTLMTime, end_time=endNTLMTime, entities=mvappend(dest_user_id, origin_device_id), body=create_map(["total_kerberos", totalKerberos, "total_ntlm", totalNtlm, "analysis_start_time", startTime, "analysis_end_time", endTime, "detection_start_time", startNTLMTime, "detection_end_time", endNTLMTime]) - -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Lateral_Movement|Lateral Movement]] - - -====How To Implement==== -You must be ingesting Windows Security logs from devices of interest - at least from domain controllers. Please make sure that event ID 4624 is being logged. - -====Required field==== - -* _time - -* signature_id - -* dest_user - -* dest_user_id - -* origin_device_id - -* authentication_method - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1550 -| Use Alternate Authentication Material -| Defense Evasion, Lateral Movement -|- -| T1550.002 -| Pass the Hash -| Defense Evasion, Lateral Movement -|} - - -====Kill Chain Phase==== - -* Lateral Movement - - -====Known False Positives==== -Environments in which NTLM is used extremely rarely and for benign purposes (such as a rare use of SMB shares). - -====Reference==== - - -* https://attack.mitre.org/techniques/T1550/002/ - - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Powershell 4104 hunting=== -The following Hunting analytic assists with identifying suspicious PowerShell execution using Script Block Logging, or EventCode 4104. This analytic is not meant to be ran hourly, but occasionally to identify malicious or suspicious PowerShell. This analytic is a combination of work completed by Alex Teixeira and Splunk Threat Research Team. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/ T1059], [https://attack.mitre.org/techniques/T1059/001/ T1059.001] -* '''Last Updated''': 2021-08-18 - -
-
- -====Search==== -`powershell` EventCode=4104 -| eval DoIt = if(match(Message,"(?i)(\$doit)"), "4", 0) -| eval enccom=if(match(Message,"[A-Za-z0-9+\/]{44,}([A-Za-z0-9+\/]{4} -|[A-Za-z0-9+\/]{3}= -|[A-Za-z0-9+\/]{2}==)") OR match(Message, "(?i)[-]e(nc*o*d*e*d*c*o*m*m*a*n*d*)*\s+[^-]"),4,0) -| eval suspcmdlet=if(match(Message, "(?i)Add-Exfiltration -|Add-Persistence -|Add-RegBackdoor -|Add-ScrnSaveBackdoor -|Check-VM -|Do-Exfiltration -|Enabled-DuplicateToken -|Exploit-Jboss -|Find-Fruit -|Find-GPOLocation -|Find-TrustedDocuments -|Get-ApplicationHost -|Get-ChromeDump -|Get-ClipboardContents -|Get-FoxDump -|Get-GPPPassword -|Get-IndexedItem -|Get-Keystrokes -|LSASecret -|Get-PassHash -|Get-RegAlwaysInstallElevated -|Get-RegAutoLogon -|Get-RickAstley -|Get-Screenshot -|Get-SecurityPackages -|Get-ServiceFilePermission -|Get-ServicePermission -|Get-ServiceUnquoted -|Get-SiteListPassword -|Get-System -|Get-TimedScreenshot -|Get-UnattendedInstallFile -|Get-Unconstrained -|Get-VaultCredential -|Get-VulnAutoRun -|Get-VulnSchTask -|Gupt-Backdoor -|HTTP-Login -|Install-SSP -|Install-ServiceBinary -|Invoke-ACLScanner -|Invoke-ADSBackdoor -|Invoke-ARPScan -|Invoke-AllChecks -|Invoke-BackdoorLNK -|Invoke-BypassUAC -|Invoke-CredentialInjection -|Invoke-DCSync -|Invoke-DllInjection -|Invoke-DowngradeAccount -|Invoke-EgressCheck -|Invoke-Inveigh -|Invoke-InveighRelay -|Invoke-Mimikittenz -|Invoke-NetRipper -|Invoke-NinjaCopy -|Invoke-PSInject -|Invoke-Paranoia -|Invoke-PortScan -|Invoke-PoshRat -|Invoke-PostExfil -|Invoke-PowerDump -|Invoke-PowerShellTCP -|Invoke-PsExec -|Invoke-PsUaCme -|Invoke-ReflectivePEInjection -|Invoke-ReverseDNSLookup -|Invoke-RunAs -|Invoke-SMBScanner -|Invoke-SSHCommand -|Invoke-Service -|Invoke-Shellcode -|Invoke-Tater -|Invoke-ThunderStruck -|Invoke-Token -|Invoke-UserHunter -|Invoke-VoiceTroll -|Invoke-WScriptBypassUAC -|Invoke-WinEnum -|MailRaider -|New-HoneyHash -|Out-Minidump -|Port-Scan -|PowerBreach -|PowerUp -|PowerView -|Remove-Update -|Set-MacAttribute -|Set-Wallpaper -|Show-TargetScreen -|Start-CaptureServer -|VolumeShadowCopyTools -|NEEEEWWW -|(Computer -|User)Property -|CachedRDPConnection -|get-net\S+ -|invoke-\S+hunter -|Install-Service -|get-\S+(credent -|password) -|remoteps -|Kerberos.*(policy -|ticket) -|netfirewall -|Uninstall-Windows -|Verb\s+Runas -|AmsiBypass -|nishang -|Invoke-Interceptor -|EXEonRemote -|NetworkRelay -|PowerShelludp -|PowerShellIcmp -|CreateShortcut -|copy-vss -|invoke-dll -|invoke-mass -|out-shortcut -|Invoke-ShellCommand"),1,0) -| eval base64 = if(match(lower(Message),"frombase64"), "4", 0) -| eval empire=if(match(lower(Message),"system.net.webclient") AND match(lower(Message), "frombase64string") ,5,0) -| eval mimikatz=if(match(lower(Message),"mimikatz") OR match(lower(Message), "-dumpcr") OR match(lower(Message), "SEKURLSA::Pth") OR match(lower(Message), "kerberos::ptt") OR match(lower(Message), "kerberos::golden") ,5,0) -| eval iex = if(match(lower(Message),"iex"), "2", 0) -| eval webclient=if(match(lower(Message),"http") OR match(lower(Message),"web(client -|request)") OR match(lower(Message),"socket") OR match(lower(Message),"download(file -|string)") OR match(lower(Message),"bitstransfer") OR match(lower(Message),"internetexplorer.application") OR match(lower(Message),"xmlhttp"),5,0) -| eval get = if(match(lower(Message),"get-"), "1", 0) -| eval rundll32 = if(match(lower(Message),"rundll32"), "4", 0) -| eval suspkeywrd=if(match(Message, "(?i)(bitstransfer -|mimik -|metasp -|AssemblyBuilderAccess -|Reflection\.Assembly -|shellcode -|injection -|cnvert -|shell\.application -|start-process -|Rc4ByteStream -|System\.Security\.Cryptography -|lsass\.exe -|localadmin -|LastLoggedOn -|hijack -|BackupPrivilege -|ngrok -|comsvcs -|backdoor -|brute.?force -|Port.?Scan -|Exfiltration -|exploit -|DisableRealtimeMonitoring -|beacon)"),1,0) -| eval syswow64 = if(match(lower(Message),"syswow64"), "3", 0) -| eval httplocal = if(match(lower(Message),"http://127.0.0.1"), "4", 0) -| eval reflection = if(match(lower(Message),"reflection"), "1", 0) -| eval invokewmi=if(match(lower(Message), "(?i)(wmiobject -|WMIMethod -|RemoteWMI -|PowerShellWmi -|wmicommand)"),5,0) -| eval downgrade=if(match(Message, "(?i)([-]ve*r*s*i*o*n*\s+2)") OR match(lower(Message),"powershell -version"),3,0) -| eval compressed=if(match(Message, "(?i)GZipStream -|::Decompress -|IO.Compression -|write-zip -|(expand -|compress)-Archive"),5,0) -| eval invokecmd = if(match(lower(Message),"invoke-command"), "4", 0) -| addtotals fieldname=Score DoIt, enccom, suspcmdlet, suspkeywrd, compressed, downgrade, mimikatz, iex, empire, rundll32, webclient, syswow64, httplocal, reflection, invokewmi, invokecmd, base64, get -| stats values(Score) by DoIt, enccom, compressed, downgrade, iex, mimikatz, rundll32, empire, webclient, syswow64, httplocal, reflection, invokewmi, invokecmd, base64, get, suspcmdlet, suspkeywrd -| `powershell_4104_hunting_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Malicious_PowerShell|Malicious PowerShell]] - - -====How To Implement==== -The following Hunting analytic requires PowerShell operational logs to be imported. Modify the powershell macro as needed to match the sourcetype or add index. This analytic is specific to 4104, or PowerShell Script Block Logging. - -====Required field==== - -* _time - -* Message - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1059 -| Command and Scripting Interpreter -| Execution -|- -| T1059.001 -| PowerShell -| Execution -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Limited false positives. May filter as needed. - -====Reference==== - - -* https://github.com/inodee/threathunting-spl/blob/master/hunt-queries/powershell_qualifiers.md - -* https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell - -* https://github.com/marcurdy/dfir-toolset/blob/master/Powershell%20Blueteam.txt - -* https://devblogs.microsoft.com/powershell/powershell-the-blue-team/ - -* https://docs.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_logging?view=powershell-5.1 - -* https://www.fireeye.com/blog/threat-research/2016/02/greater_visibilityt.html - -* https://hurricanelabs.com/splunk-tutorials/how-to-use-powershell-transcription-logs-in-splunk/ - - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Powershell domain enumeration=== -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify suspicious PowerShell execution. Script Block Logging captures the command sent to PowerShell, the full command to be executed. Upon enabling, logs will output to Windows event logs. Dependent upon volume, enable on critical endpoints or all. \ -This analytic identifies specific PowerShell modules typically used to enumerate an organizations domain or users. \ -During triage, review parallel processes using an EDR product or 4688 events. It will be important to understand the timeline of events around this activity. Review the entire logged PowerShell script block. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/ T1059], [https://attack.mitre.org/techniques/T1059/001/ T1059.001] -* '''Last Updated''': 2021-06-10 - -
-
- -====Search==== -`powershell` EventCode=4104 Message IN (*get-netdomaintrust*, *get-netforesttrust*, *get-addomain*, *get-adgroupmember*, *get-domainuser*) -| stats count min(_time) as firstTime max(_time) as lastTime by ComputerName EventCode Message -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `powershell_domain_enumeration_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Malicious_PowerShell|Malicious PowerShell]] - - -====How To Implement==== -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -====Required field==== - -* _time - -* Message - -* ComputerName - -* EventCode - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1059 -| Command and Scripting Interpreter -| Execution -|- -| T1059.001 -| PowerShell -| Execution -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -It is possible there will be false positives, filter as needed. - -====Reference==== - - -* https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -* https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63 - -* https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf - -* https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/windows-powershell.log - - -''version'': 1 -
-
- ----- - -===Powershell get localgroup discovery=== -The following hunting analytic identifies the use of `get-localgroup` being used with PowerShell to identify local groups on the endpoint. During triage, review parallel processes and identify any further suspicious behavior. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1069/ T1069], [https://attack.mitre.org/techniques/T1069/001/ T1069.001] -* '''Last Updated''': 2021-09-14 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name=powershell.exe OR Processes.process_name=cmd.exe) (Processes.process="*get-localgroup*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `powershell_get_localgroup_discovery_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1069 -| Permission Groups Discovery -| Discovery -|- -| T1069.001 -| Local Groups -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -False positives may be present. Tune as needed. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1069/001/ - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1069.001/T1069.001.md - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.001/atomic_red_team/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Powershell loading dotnet into memory via system reflection assembly=== -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify suspicious PowerShell execution. Script Block Logging captures the command sent to PowerShell, the full command to be executed. Upon enabling, logs will output to Windows event logs. Dependent upon volume, enable no critical endpoints or all. \ -This analytic identifies the use of PowerShell loading .net assembly via reflection. This is commonly found in malicious PowerShell usage, including Empire and Cobalt Strike. In addition, the `load(` value may be modifed by removing `(` and it will identify more events to review. \ -During triage, review parallel processes using an EDR product or 4688 events. It will be important to understand the timeline of events around this activity. Review the entire logged PowerShell script block. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/ T1059], [https://attack.mitre.org/techniques/T1059/001/ T1059.001] -* '''Last Updated''': 2021-06-10 - -
-
- -====Search==== -`powershell` EventCode=4104 Message IN ("*[system.reflection.assembly]::load(*","*[reflection.assembly]*") -| stats count min(_time) as firstTime max(_time) as lastTime by OpCode ComputerName User EventCode Message -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `powershell_loading_dotnet_into_memory_via_system_reflection_assembly_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Malicious_PowerShell|Malicious PowerShell]] - - -====How To Implement==== -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -====Required field==== - -* _time - -* Message - -* OpCode - -* ComputerName - -* User - -* EventCode - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1059 -| Command and Scripting Interpreter -| Execution -|- -| T1059.001 -| PowerShell -| Execution -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -False positives should be limited as day to day scripts do not use this method. - -====Reference==== - - -* https://docs.microsoft.com/en-us/dotnet/api/system.reflection.assembly?view=net-5.0 - -* https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -* https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63 - -* https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf - -* https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/windows-powershell.log - - -''version'': 1 -
-
- ----- - -===Powershell start-bitstransfer=== -Start-BitsTransfer is the PowerShell "version" of BitsAdmin.exe. Similar functionality is present. This technique variation is not as commonly used by adversaries, but has been abused in the past. Lesser known uses include the ability to set the `-TransferType` to `Upload` for exfiltration of files. In an instance where `Upload` is used, it is highly possible files will be archived. During triage, review parallel processes and process lineage. Capture any files on disk and review. For the remote domain or IP, what is the reputation? - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1197/ T1197] -* '''Last Updated''': 2021-03-29 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_powershell` Processes.process=*start-bitstransfer* by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.original_file_name Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `powershell_start_bitstransfer_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#BITS_Jobs|BITS Jobs]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1197 -| BITS Jobs -| Defense Evasion, Persistence -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Limited false positives. It is possible administrators will utilize Start-BitsTransfer for administrative tasks, otherwise filter based parent process or command-line arguments. - -====Reference==== - - -* https://isc.sans.edu/diary/Investigating+Microsoft+BITS+Activity/23281 - -* https://docs.microsoft.com/en-us/windows/win32/bits/using-windows-powershell-to-create-bits-transfer-jobs - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1197/atomic_red_team/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Powershell creating thread mutex=== -The following analytic identifies suspicious PowerShell script execution via EventCode 4104 that is using the `mutex` function. This function is commonly seen in some obfuscated PowerShell scripts to make sure that only one instance of there process is running on a compromise machine. During triage, review parallel processes within the same timeframe. Review the full script block to identify other related artifacts. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1027/ T1027], [https://attack.mitre.org/techniques/T1027/005/ T1027.005] -* '''Last Updated''': 2021-06-10 - -
-
- -====Search==== -`powershell` EventCode=4104 Message = "*Threading.Mutex*" -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `powershell_creating_thread_mutex_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Malicious_PowerShell|Malicious PowerShell]] - - -====How To Implement==== -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -====Required field==== - -* _time - -* EventCode - -* Message - -* ComputerName - -* User - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1027 -| Obfuscated Files or Information -| Defense Evasion -|- -| T1027.005 -| Indicator Removal from Tools -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -powershell developer may used this function in their script for instance checking too. - -====Reference==== - - -* https://isc.sans.edu/forums/diary/Some+Powershell+Malicious+Code/22988/ - -* https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -* https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63 - -* https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf - -* https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/pwsh/windows-powershell.log - - -''version'': 1 -
-
- ----- - -===Powershell disable security monitoring=== -This search is to identifies a modification in registry to disable the windows denfender real time behavior monitoring. This event or technique is commonly seen in RAT, bot, or Trojan to disable AV to evade detections. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001], [https://attack.mitre.org/techniques/T1562/ T1562] -* '''Last Updated''': 2021-07-05 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_powershell` Processes.process="*set-mppreference*" AND Processes.process IN ("*disablerealtimemonitoring*","*disableioavprotection*","*disableintrusionpreventionsystem*","*disablescriptscanning*","*disableblockatfirstseen*") by Processes.dest Processes.user Processes.parent_process Processes.original_file_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `powershell_disable_security_monitoring_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - -* [[Documentation:ESSOC:stories:UseCase#Revil_Ransomware|Revil Ransomware]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1562.001 -| Disable or Modify Tools -| Defense Evasion -|- -| T1562 -| Impair Defenses -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Limited false positives. However, tune based on scripts that may perform this action. - -====Reference==== - - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1562.001/T1562.001.md#atomic-test-15---tamper-with-windows-defender-atp-powershell - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/pwh_defender_disabling/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Powershell enable smb1protocol feature=== -This search is to detect a suspicious enabling of smb1protocol through "powershell.exe". This technique was seen in some ransomware (like reddot) where it enable smb share to do the lateral movement and encrypt other files within the compromise network system. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1027/ T1027], [https://attack.mitre.org/techniques/T1027/005/ T1027.005] -* '''Last Updated''': 2021-06-22 - -
-
- -====Search==== -`powershell` EventCode=4104 Message = "*Enable-WindowsOptionalFeature*" Message = "*SMB1Protocol*" -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `powershell_enable_smb1protocol_feature_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Malicious_PowerShell|Malicious PowerShell]] - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the powershell logs from your endpoints. make sure you enable needed registry to monitor this event. - -====Required field==== - -* _time - -* EventCode - -* Message - -* ComputerName - -* User - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1027 -| Obfuscated Files or Information -| Defense Evasion -|- -| T1027.005 -| Indicator Removal from Tools -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -network operator may enable or disable this windows feature. - -====Reference==== - - -* https://app.any.run/tasks/c0f98850-af65-4352-9746-fbebadee4f05/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/data2/windows-powershell.log - - -''version'': 1 -
-
- ----- - -===Powershell execute com object=== -This search is to detect a COM CLSID execution through powershell. This technique was seen in several adversaries and malware like ransomware conti where it has a feature to execute command using COM Object. This technique may use by network operator at some cases but a good indicator if some application want to gain privilege escalation or bypass uac. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1546/015/ T1546.015], [https://attack.mitre.org/techniques/T1546/ T1546] -* '''Last Updated''': 2021-08-10 - -
-
- -====Search==== -`powershell` EventCode=4104 Message = "*CreateInstance([type]::GetTypeFromCLSID*" OR Message = "*CreateInstance([Type]::GetTypeFromProgID*" -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `powershell_execute_com_object_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Malicious_PowerShell|Malicious PowerShell]] - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -====Required field==== - -* _time - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1546.015 -| Component Object Model Hijacking -| Privilege Escalation, Persistence -|- -| T1546 -| Event Triggered Execution -| Privilege Escalation, Persistence -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -network operrator may use this command. - -====Reference==== - - -* https://threadreaderapp.com/thread/1423361119926816776.html - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/conti/conti_leak/windows-powershell.log - - -''version'': 1 -
-
- ----- - -===Powershell fileless process injection via getprocaddress=== -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify suspicious PowerShell execution. Script Block Logging captures the command sent to PowerShell, the full command to be executed. Upon enabling, logs will output to Windows event logs. Dependent upon volume, enable no critical endpoints or all. \ -This analytic identifies `GetProcAddress` in the script block. This is not normal to be used by most PowerShell scripts and is typically unsafe/malicious. Many attack toolkits use GetProcAddress to obtain code execution. \ -In use, `$var_gpa = $var_unsafe_native_methods.GetMethod(GetProcAddress` and later referenced/executed elsewhere. \ -During triage, review parallel processes using an EDR product or 4688 events. It will be important to understand the timeline of events around this activity. Review the entire logged PowerShell script block. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/ T1059], [https://attack.mitre.org/techniques/T1055/ T1055], [https://attack.mitre.org/techniques/T1059/001/ T1059.001] -* '''Last Updated''': 2021-06-08 - -
-
- -====Search==== -`powershell` EventCode=4104 Message=*getprocaddress* -| stats count min(_time) as firstTime max(_time) as lastTime by OpCode ComputerName User EventCode Message -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `powershell_fileless_process_injection_via_getprocaddress_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Malicious_PowerShell|Malicious PowerShell]] - - -====How To Implement==== -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -====Required field==== - -* _time - -* Message - -* OpCode - -* ComputerName - -* User - -* EventCode - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1059 -| Command and Scripting Interpreter -| Execution -|- -| T1055 -| Process Injection -| Defense Evasion, Privilege Escalation -|- -| T1059.001 -| PowerShell -| Execution -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Limited false positives. Filter as needed. - -====Reference==== - - -* https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -* https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63 - -* https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf - -* https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/windows-powershell.log - - -''version'': 1 -
-
- ----- - -===Powershell fileless script contains base64 encoded content=== -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify suspicious PowerShell execution. Script Block Logging captures the command sent to PowerShell, the full command to be executed. Upon enabling, logs will output to Windows event logs. Dependent upon volume, enable on critical endpoints or all. \ -This analytic identifies `FromBase64String` within the script block. A typical malicious instance will include additional code. \ -Command example - `[Byte[]]$var_code = [System.Convert]::FromBase64String(38uqIyMjQ6rG....` \ -During triage, review parallel processes using an EDR product or 4688 events. It will be important to understand the timeline of events around this activity. Review the entire logged PowerShell script block. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/ T1059], [https://attack.mitre.org/techniques/T1027/ T1027], [https://attack.mitre.org/techniques/T1059/001/ T1059.001] -* '''Last Updated''': 2021-06-08 - -
-
- -====Search==== -`powershell` EventCode=4104 Message=*frombase64string* -| stats count min(_time) as firstTime max(_time) as lastTime by OpCode ComputerName User EventCode Message -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `powershell_fileless_script_contains_base64_encoded_content_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Malicious_PowerShell|Malicious PowerShell]] - - -====How To Implement==== -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -====Required field==== - -* _time - -* Message - -* OpCode - -* ComputerName - -* User - -* EventCode - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1059 -| Command and Scripting Interpreter -| Execution -|- -| T1027 -| Obfuscated Files or Information -| Defense Evasion -|- -| T1059.001 -| PowerShell -| Execution -|} - - -====Kill Chain Phase==== - -* Exploitation - -* Privilege Escalation - - -====Known False Positives==== -False positives should be limited. Filter as needed. - -====Reference==== - - -* https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -* https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63 - -* https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf - -* https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/windows-powershell.log - - -''version'': 1 -
-
- ----- - -===Powershell get localgroup discovery with script block logging=== -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify suspicious PowerShell execution. Script Block Logging captures the command sent to PowerShell, the full command to be executed. Upon enabling, logs will output to Windows event logs. Dependent upon volume, enable on critical endpoints or all. \ -This analytic identifies PowerShell cmdlet - `get-localgroup` being ran. Typically, by itself, is not malicious but may raise suspicion based on time of day, endpoint and username. \ -During triage, review parallel processes using an EDR product or 4688 events. It will be important to understand the timeline of events around this activity. Review the entire logged PowerShell script block. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1069/ T1069], [https://attack.mitre.org/techniques/T1069/001/ T1069.001] -* '''Last Updated''': 2021-09-14 - -
-
- -====Search==== -`powershell` EventCode=4104 Message = "*get-localgroup*" -| stats count min(_time) as firstTime max(_time) as lastTime by Message OpCode ComputerName User EventCode -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `powershell_get_localgroup_discovery_with_script_block_logging_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -====Required field==== - -* _time - -* EventCode - -* Message - -* ComputerName - -* User - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1069 -| Permission Groups Discovery -| Discovery -|- -| T1069.001 -| Local Groups -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -False positives may be present. Tune as needed. - -====Reference==== - - -* https://www.splunk.com/en_us/blog/security/powershell-detections-threat-research-release-august-2021.html - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1069.001/T1069.001.md - -* https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell - -* https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63 - -* https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf - -* https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.001/atomic_red_team/windows-powershell.log - - -''version'': 1 -
-
- ----- - -===Powershell processing stream of data=== -The following analytic identifies suspicious PowerShell script execution via EventCode 4104 that is processing compressed stream data. This is typically found in obfuscated PowerShell or PowerShell executing embedded .NET or binary files that are stream flattened and will be deflated durnig execution. During triage, review parallel processes within the same timeframe. Review the full script block to identify other related artifacts. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/ T1059], [https://attack.mitre.org/techniques/T1059/001/ T1059.001] -* '''Last Updated''': 2021-06-10 - -
-
- -====Search==== -`powershell` EventCode=4104 Message = "*IO.Compression.*" OR Message = "*IO.StreamReader*" OR Message = "*]::Decompress*" -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `powershell_processing_stream_of_data_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Malicious_PowerShell|Malicious PowerShell]] - - -====How To Implement==== -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -====Required field==== - -* _time - -* EventCode - -* Message - -* ComputerName - -* User - -* Score - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1059 -| Command and Scripting Interpreter -| Execution -|- -| T1059.001 -| PowerShell -| Execution -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -powershell may used this function to process compressed data. - -====Reference==== - - -* https://medium.com/@ahmedjouini99/deobfuscating-emotets-powershell-payload-e39fb116f7b9 - -* https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell - -* https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63 - -* https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf - -* https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/pwsh/windows-powershell.log - - -''version'': 1 -
-
- ----- - -===Powershell remote thread to known windows process=== -this search is designed to detect suspicious powershell process that tries to inject code and to known/critical windows process and execute it using CreateRemoteThread. This technique is seen in several malware like trickbot and offensive tooling like cobaltstrike where it load a shellcode to svchost.exe to execute reverse shell to c2 and download another payload - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1055/ T1055] -* '''Last Updated''': 2021-04-19 - -
-
- -====Search==== -`sysmon` EventCode = 8 process_name IN ("powershell_ise.exe", "powershell.exe") TargetImage IN ("*\\svchost.exe","*\\csrss.exe" "*\\gpupdate.exe", "*\\explorer.exe","*\\services.exe","*\\winlogon.exe","*\\smss.exe","*\\wininit.exe","*\\userinit.exe","*\\spoolsv.exe","*\\taskhost.exe") -| stats min(_time) as firstTime max(_time) as lastTime count by SourceImage process_name SourceProcessId SourceProcessGuid TargetImage TargetProcessId NewThreadId StartAddress Computer EventCode -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `powershell_remote_thread_to_known_windows_process_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Trickbot|Trickbot]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, Create Remote thread from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances of create remote thread may be used. - -====Required field==== - -* _time - -* SourceImage - -* process_name - -* SourceProcessId - -* SourceProcessGuid - -* TargetImage - -* TargetProcessId - -* NewThreadId - -* StartAddress - -* Computer - -* EventCode - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1055 -| Process Injection -| Defense Evasion, Privilege Escalation -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://thedfirreport.com/2021/01/11/trickbot-still-alive-and-well/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/trickbot/infection/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Powershell using memory as backing store=== -The following analytic identifies suspicious PowerShell script execution via EventCode 4104 that is using memory stream as new object backstore. The malicious PowerShell script will contain stream flate data and will be decompressed in memory to run or drop the actual payload. During triage, review parallel processes within the same timeframe. Review the full script block to identify other related artifacts. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1140/ T1140] -* '''Last Updated''': 2021-06-10 - -
-
- -====Search==== -`powershell` EventCode=4104 Message = "*New-Object IO.MemoryStream*" -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `powershell_using_memory_as_backing_store_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Malicious_PowerShell|Malicious PowerShell]] - - -====How To Implement==== -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -====Required field==== - -* _time - -* EventCode - -* Message - -* ComputerName - -* User - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1140 -| Deobfuscate/Decode Files or Information -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -powershell may used this function to store out object into memory. - -====Reference==== - - -* https://www.carbonblack.com/blog/decoding-malicious-powershell-streams/ - -* https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -* https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63 - -* https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf - -* https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/pwsh/windows-powershell.log - - -''version'': 1 -
-
- ----- - -===Prevent automatic repair mode using bcdedit=== -This search is to detect a suspicious bcdedit.exe execution to ignore all failures. This technique was used by ransomware to prevent the compromise machine automatically boot in repair mode. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1490/ T1490] -* '''Last Updated''': 2021-06-10 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = "bcdedit.exe" Processes.process = "*bootstatuspolicy*" Processes.process = "*ignoreallfailures*" by Processes.parent_process_name Processes.parent_process Processes.process_name Processes.process Processes.dest Processes.user Processes.process_id Processes.process_guid -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `prevent_automatic_repair_mode_using_bcdedit_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed bcdedit.exe may be used. - -====Required field==== - -* _time - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.process_name - -* Processes.process - -* Processes.dest - -* Processes.user - -* Processes.process_id - -* Processes.process_guid - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1490 -| Inhibit System Recovery -| Impact -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Administrators may modify the boot configuration ignore failure during testing and debugging. - -====Reference==== - - -* https://jsac.jpcert.or.jp/archive/2020/pdf/JSAC2020_1_tamada-yamazaki-nakatsuru_en.pdf - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/data1/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Print processor registry autostart=== -This analytic is to detect a suspicious modification or new registry entry regarding print processor. This registry is known to be abuse by turla or other APT to gain persistence and privilege escalation to the compromised machine. This is done by adding the malicious dll payload on the new created key in this registry that will be executed as it restarted the spoolsv.exe process and services. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1547/012/ T1547.012], [https://attack.mitre.org/techniques/T1547/ T1547] -* '''Last Updated''': 2021-09-28 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path ="*\\Control\\Print\\Environments\\Windows x64\\Print Processors*" by Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `drop_dm_object_name(Registry)` -| `print_processor_registry_autostart_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Persistence_Techniques|Windows Persistence Techniques]] - -* [[Documentation:ESSOC:stories:UseCase#Windows_Privilege_Escalation|Windows Privilege Escalation]] - - -====How To Implement==== -To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. - -====Required field==== - -* _time - -* Registry.dest - -* Registry.user - -* Registry.registry_path - -* Registry.registry_key_name - -* Registry.registry_value_name - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1547.012 -| Print Processors -| Persistence, Privilege Escalation -|- -| T1547 -| Boot or Logon Autostart Execution -| Persistence, Privilege Escalation -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -possible new printer installation may add driver component on this registry. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1547/012/ - -* https://www.welivesecurity.com/2020/05/21/no-game-over-winnti-group/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.012/print_reg/sysmon_print.log - - -''version'': 1 -
-
- ----- - -===Print spooler adding a printer driver=== -The following analytic identifies new printer drivers being load by utilizing the Windows PrintService operational logs, EventCode 316. This was identified during our testing of CVE-2021-34527 previously (CVE-2021-1675) or PrintNightmare. \ -Within the proof of concept code, the following event will occur - "Printer driver 1234 for Windows x64 Version-3 was added or updated. Files:- UNIDRV.DLL, kernelbase.dll, evil.dll. No user action is required." \ -During triage, isolate the endpoint and review for source of exploitation. Capture any additional file modification events and review the source of where the exploitation began. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1547/012/ T1547.012], [https://attack.mitre.org/techniques/T1547/ T1547] -* '''Last Updated''': 2021-07-01 - -
-
- -====Search==== -`printservice` EventCode=316 category = "Adding a printer driver" Message = "*kernelbase.dll,*" Message = "*UNIDRV.DLL,*" Message = "*.DLL.*" -| stats count min(_time) as firstTime max(_time) as lastTime by OpCode EventCode ComputerName Message -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `print_spooler_adding_a_printer_driver_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#PrintNightmare_CVE-2021-34527|PrintNightmare CVE-2021-34527]] - - -====How To Implement==== -You will need to ensure PrintService Admin and Operational logs are being logged to Splunk from critical or all systems. - -====Required field==== - -* _time - -* OpCode - -* EventCode - -* ComputerName - -* Message - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1547.012 -| Print Processors -| Persistence, Privilege Escalation -|- -| T1547 -| Boot or Logon Autostart Execution -| Persistence, Privilege Escalation -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Unknown. This may require filtering. - -====Reference==== - - -* https://twitter.com/MalwareJake/status/1410421445608476679?s=20 - -* https://blog.truesec.com/2021/06/30/fix-for-printnightmare-cve-2021-1675-exploit-to-keep-your-print-servers-running-while-a-patch-is-not-available/ - -* https://blog.truesec.com/2021/06/30/exploitable-critical-rce-vulnerability-allows-regular-users-to-fully-compromise-active-directory-printnightmare-cve-2021-1675/ - -* https://www.reddit.com/r/msp/comments/ob6y02/critical_vulnerability_printnightmare_exposes - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.012/printnightmare/windows-printservice_operational.log - - -''version'': 1 -
-
- ----- - -===Print spooler failed to load a plug-in=== -The following analytic identifies driver load errors utilizing the Windows PrintService Admin logs. This was identified during our testing of CVE-2021-34527 previously (CVE-2021-1675) or PrintNightmare. \ -Within the proof of concept code, the following error will occur - "The print spooler failed to load a plug-in module C:\Windows\system32\spool\DRIVERS\x64\3\meterpreter.dll, error code 0x45A. See the event user data for context information." \ -The analytic is based on file path and failure to load the plug-in. \ -During triage, isolate the endpoint and review for source of exploitation. Capture any additional file modification events. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1547/012/ T1547.012], [https://attack.mitre.org/techniques/T1547/ T1547] -* '''Last Updated''': 2021-07-01 - -
-
- -====Search==== -`printservice` ((ErrorCode="0x45A" (EventCode="808" OR EventCode="4909")) OR ("The print spooler failed to load a plug-in module" OR "\\drivers\\x64\\")) -| stats count min(_time) as firstTime max(_time) as lastTime by OpCode EventCode ComputerName Message -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `print_spooler_failed_to_load_a_plug_in_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#PrintNightmare_CVE-2021-34527|PrintNightmare CVE-2021-34527]] - - -====How To Implement==== -You will need to ensure PrintService Admin and Operational logs are being logged to Splunk from critical or all systems. - -====Required field==== - -* _time - -* OpCode - -* EventCode - -* ComputerName - -* Message - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1547.012 -| Print Processors -| Persistence, Privilege Escalation -|- -| T1547 -| Boot or Logon Autostart Execution -| Persistence, Privilege Escalation -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -False positives are unknown and filtering may be required. - -====Reference==== - - -* https://blog.truesec.com/2021/06/30/fix-for-printnightmare-cve-2021-1675-exploit-to-keep-your-print-servers-running-while-a-patch-is-not-available/ - -* https://blog.truesec.com/2021/06/30/exploitable-critical-rce-vulnerability-allows-regular-users-to-fully-compromise-active-directory-printnightmare-cve-2021-1675/ - -* https://www.reddit.com/r/msp/comments/ob6y02/critical_vulnerability_printnightmare_exposes - - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Probing access with stolen credentials via powersploit modules=== -This detection identifies use of PowerSploit modules that facilitate access probing with admin credentials as well as probing access to system services. - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/ T1078], [https://attack.mitre.org/techniques/T1098/ T1098] -* '''Last Updated''': 2020-11-04 - -
-
- -====Search==== - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)Test-AdminAccess/)=true OR match_regex(cmd_line, /(?i)Invoke-CheckLocalAdminAccess/)=true OR match_regex(cmd_line, /(?i)Test-ServiceDaclPermission/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Privilege_Escalation|Windows Privilege Escalation]] - - -====How To Implement==== -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -====Required field==== - -* _time - -* process - -* dest_user_id - -* dest_device_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1078 -| Valid Accounts -| Defense Evasion, Persistence, Privilege Escalation, Initial Access -|- -| T1098 -| Account Manipulation -| Persistence -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -None identified. - -====Reference==== - - -* https://github.com/PowerShellMafia/PowerSploit - - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Process creating lnk file in suspicious location=== -This search looks for a process launching an `*.lnk` file under `C:\User*` or `*\Local\Temp\*`. This is common behavior used by various spear phishing tools. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/ T1566], [https://attack.mitre.org/techniques/T1566/002/ T1566.002] -* '''Last Updated''': 2021-08-26 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_name="*.lnk" AND (Filesystem.file_path="C:\\User\\*" OR Filesystem.file_path="*\\Temp\\*") by _time span=1h Filesystem.process_guid Filesystem.file_name Filesystem.file_path Filesystem.file_hash Filesystem.user -| `drop_dm_object_name(Filesystem)` -| rename process_guid as lnk_guid -| join lnk_guid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name=* by _time span=1h Processes.parent_process_guid Processes.process_id Processes.process_name Processes.dest Processes.process_path Processes.process -| `drop_dm_object_name(Processes)` -| rename parent_process_guid as lnk_guid -| fields _time lnk_guid process_id dest process_name process_path process] -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| table firstTime, lastTime, lnk_guid, process_id, user, dest, file_name, file_path, process_name, process, process_path, file_hash -| `process_creating_lnk_file_in_suspicious_location_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Spearphishing_Attachments|Spearphishing Attachments]] - - -====How To Implement==== -You must be ingesting data that records filesystem and process activity from your hosts to populate the Endpoint data model. This is typically populated via endpoint detection-and-response product, such as Carbon Black, or endpoint data sources, such as Sysmon. - -====Required field==== - -* _time - -* Filesystem.file_name - -* Filesystem.file_path - -* Filesystem.process_id - -* Filesystem.file_name - -* Filesystem.file_path - -* Filesystem.file_hash - -* Filesystem.user - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1566 -| Phishing -| Initial Access -|- -| T1566.002 -| Spearphishing Link -| Initial Access -|} - - -====Kill Chain Phase==== - -* Installation - -* Actions on Objectives - - -====Known False Positives==== -This detection should yield little or no false positive results. It is uncommon for LNK files to be executed from temporary or user directories. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1566/001/ - -* https://www.trendmicro.com/en_us/research/17/e/rising-trend-attackers-using-lnk-files-download-malware.html - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.002/lnk_file_temp_folder/windows-sysmon.log - - -''version'': 5 -
-
- ----- - -===Process deleting its process file path=== -This detection is to identify a suspicious process that tries to delete the process file path related to its process. This technique is known to be defense evasion once a certain condition of malware is satisfied or not. Clop ransomware use this technique where it will try to delete its process file path using a .bat command if the keyboard layout is not the layout it tries to infect. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1070/ T1070] -* '''Last Updated''': 2021-03-17 - -
-
- -====Search==== -`sysmon` EventCode=1 cmdline = "*/c del*" Image = "*\\cmd.exe" -|eval result = if(like(process,"%".parent_process."%"), "Found", "Not Found") -| stats min(_time) as firstTime max(_time) as lastTime count by Computer user ParentImage ParentCommandLine Image cmdline EventCode ProcessID result -| where result = "Found" -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `process_deleting_its_process_file_path_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Clop_Ransomware|Clop Ransomware]] - -* [[Documentation:ESSOC:stories:UseCase#Remcos|Remcos]] - - -====How To Implement==== -You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. - -====Required field==== - -* EventCode - -* Computer - -* user - -* ParentImage - -* ParentCommandLine - -* Image - -* cmdline - -* ProcessID - -* result - -* _time - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1070 -| Indicator Removal on Host -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://www.fireeye.com/blog/threat-research/2020/10/fin11-email-campaigns-precursor-for-ransomware-data-theft.html - -* https://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_a/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Process execution via wmi=== -The following analytic identifies `WmiPrvSE.exe` spawning a process. This typically occurs when a process is instantiated from a local or remote process using `wmic.exe`. During triage, review parallel processes for suspicious behavior or commands executed. Review the process and command-line spawning from `wmiprvse.exe`. Contain and remediate the endpoint as necessary. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1047/ T1047] -* '''Last Updated''': 2020-03-16 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=WmiPrvSE.exe by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `process_execution_via_wmi_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_WMI_Use|Suspicious WMI Use]] - - -====How To Implement==== -You must be ingesting endpoint data that tracks process activity, including parent-child relationships from your endpoints to populate the Endpoint data model in the Processes node. The command-line arguments are mapped to the "process" field in the Endpoint data model. - -====Required field==== - -* _time - -* Processes.process - -* Processes.parent_process_name - -* Processes.user - -* Processes.dest - -* Processes.process_name - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1047 -| Windows Management Instrumentation -| Execution -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Although unlikely, administrators may use wmi to execute commands for legitimate purposes. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1047/atomic_red_team/windows-sysmon.log - - -''version'': 4 -
-
- ----- - -===Process kill base on file path=== -The following analytic identifies the use of `wmic.exe` using `delete` to remove a executable path. This is typically ran via a batch file during beginning stages of an adversary setting up for mining on an endpoint. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001], [https://attack.mitre.org/techniques/T1562/ T1562] -* '''Last Updated''': 2021-05-04 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` values(Processes.process) as process values(Processes.process_id) as process_id count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_wmic` AND Processes.process="*process*" AND Processes.process="*executablepath*" AND Processes.process="*delete*" by Processes.parent_process_name Processes.process_name Processes.original_file_name Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `process_kill_base_on_file_path_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#XMRig|XMRig]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1562.001 -| Disable or Modify Tools -| Defense Evasion -|- -| T1562 -| Impair Defenses -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Unknown. - -====Reference==== - - -* https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Process writing dynamicwrapperx=== -DynamicWrapperX is an ActiveX component that can be used in a script to call Windows API functions, but it requires the dynwrapx.dll to be installed and registered. With that, a binary writing dynwrapx.dll to disk and registering it into the registry is highly suspect. Why is it needed? In most malicious instances, it will be written to disk at a non-standard location. During triage, review parallel processes and pivot on the process_guid. Review the registry for any suspicious modifications meant to load dynwrapx.dll. Identify any suspicious module loads of dynwrapx.dll. This will identify the process that will invoke vbs/wscript/cscript. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/ T1059], [https://attack.mitre.org/techniques/T1559/001/ T1559.001] -* '''Last Updated''': 2021-10-05 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time Processes.process_id Processes.process_name Processes.dest Processes.process_guid Processes.user -| `drop_dm_object_name(Processes)` -| join process_guid [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Filesystem where Filesystem.file_name="dynwrapx.dll" by _time Filesystem.dest Filesystem.file_create_time Filesystem.file_name Filesystem.file_path Filesystem.process_guid Filesystem.user -| `drop_dm_object_name(Filesystem)` -| fields _time process_guid file_path file_name file_create_time user dest process_name] -| stats count min(_time) as firstTime max(_time) as lastTime by dest process_name process_guid file_name file_path file_create_time user -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `process_writing_dynamicwrapperx_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Remcos|Remcos]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` and `Filesystem` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* dest - -* process_name - -* process_guid - -* file_name - -* file_path - -* file_create_time user - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1059 -| Command and Scripting Interpreter -| Execution -|- -| T1559.001 -| Component Object Model -| Execution -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -False positives should be limited, however it is possible to filter by Processes.process_name and specific processes (ex. wscript.exe). Filter as needed. This may need modification based on EDR telemetry and how it brings in registry data. For example, removal of (Default). - -====Reference==== - - -* https://blog.f-secure.com/hunting-for-koadic-a-com-based-rootkit/ - -* https://www.script-coding.com/dynwrapx_eng.html - -* https://bohops.com/2018/06/28/abusing-com-registry-structure-clsid-localserver32-inprocserver32/ - -* https://tria.ge/210929-ap75vsddan - -* https://www.virustotal.com/gui/file/cb77b93150cb0f7fe65ce8a7e2a5781e727419451355a7736db84109fa215a89 - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Processes tapping keyboard events=== -This search looks for processes in an MacOS system that is tapping keyboard events in MacOS, and essentially monitoring all keystrokes made by a user. This is a common technique used by RATs to log keystrokes from a victim, although it can also be used by legitimate processes like Siri to react on human input - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': -* '''Last Updated''': 2019-01-25 - -
-
- -====Search==== - -| from datamodel Alerts.Alerts -| search app=osquery:results name=pack_osx-attacks_Keyboard_Event_Taps -| rename columns.cmdline as cmd, columns.name as process_name, columns.pid as process_id -| dedup host,process_name -| table host,process_name, cmd, process_id -| `processes_tapping_keyboard_events_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#ColdRoot_MacOS_RAT|ColdRoot MacOS RAT]] - - -====How To Implement==== -In order to properly run this search, Splunk needs to ingest data from your osquery deployed agents with the [osx-attacks.conf](https://github.com/facebook/osquery/blob/experimental/packs/osx-attacks.conf#L599) pack enabled. Also the [TA-OSquery](https://github.com/d1vious/TA-osquery) must be deployed across your indexers and universal forwarders in order to have the osquery data populate the Alerts data model. - -====Required field==== - -* _time - -* app - -* name - -* columns.cmdline - -* columns.name - -* columns.pid - -* host - - - - -====Kill Chain Phase==== - -* Command and Control - - -====Known False Positives==== -There might be some false positives as keyboard event taps are used by processes like Siri and Zoom video chat, for some good examples of processes to exclude please see [this](https://github.com/facebook/osquery/pull/5345#issuecomment-454639161) comment. - -====Reference==== - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Processes launching netsh=== -This search looks for processes launching netsh.exe. Netsh is a command-line scripting utility that allows you to, either locally or remotely, display or modify the network configuration of a computer that is currently running. Netsh can be used as a persistence proxy technique to execute a helper DLL when netsh.exe is executed. In this search, we are looking for processes spawned by netsh.exe and executing commands via the command line. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/004/ T1562.004], [https://attack.mitre.org/techniques/T1562/ T1562] -* '''Last Updated''': 2021-09-16 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count values(Processes.process) AS Processes.process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_netsh` by Processes.parent_process_name Processes.parent_process Processes.original_file_name Processes.process_name Processes.user Processes.dest -|`drop_dm_object_name("Processes")` -|`security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -|`processes_launching_netsh_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Netsh_Abuse|Netsh Abuse]] - -* [[Documentation:ESSOC:stories:UseCase#Disabling_Security_Tools|Disabling Security Tools]] - -* [[Documentation:ESSOC:stories:UseCase#DHS_Report_TA18-074A|DHS Report TA18-074A]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.process - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.process_name - -* Processes.user - -* Processes.dest - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1562.004 -| Disable or Modify System Firewall -| Defense Evasion -|- -| T1562 -| Impair Defenses -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Some VPN applications are known to launch netsh.exe. Outside of these instances, it is unusual for an executable to launch netsh.exe and run commands. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.004/atomic_red_team/windows-sysmon.log - - -''version'': 4 -
-
- ----- - -===Ransomware notes bulk creation=== -The following analytics identifies a big number of instance of ransomware notes (filetype e.g .txt, .html, .hta) file creation to the infected machine. This behavior is a good sensor if the ransomware note filename is quite new for security industry or the ransomware note filename is not in your ransomware lookup table list for monitoring. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1486/ T1486] -* '''Last Updated''': 2021-03-12 - -
-
- -====Search==== -`sysmon` EventCode=11 file_name IN ("*\.txt","*\.html","*\.hta") -|bin _time span=10s -| stats min(_time) as firstTime max(_time) as lastTime dc(TargetFilename) as unique_readme_path_count values(TargetFilename) as list_of_readme_path by Computer Image file_name -| where unique_readme_path_count >= 15 -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `ransomware_notes_bulk_creation_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Clop_Ransomware|Clop Ransomware]] - -* [[Documentation:ESSOC:stories:UseCase#DarkSide_Ransomware|DarkSide Ransomware]] - -* [[Documentation:ESSOC:stories:UseCase#BlackMatter_Ransomware|BlackMatter Ransomware]] - - -====How To Implement==== -You must be ingesting data that records the filesystem activity from your hosts to populate the Endpoint file-system data model node. If you are using Sysmon, you will need a Splunk Universal Forwarder on each endpoint from which you want to collect data. - -====Required field==== - -* EventCode - -* file_name - -* _time - -* TargetFilename - -* Computer - -* Image - -* user - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1486 -| Data Encrypted for Impact -| Impact -|} - - -====Kill Chain Phase==== - -* Obfuscation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://www.fireeye.com/blog/threat-research/2020/10/fin11-email-campaigns-precursor-for-ransomware-data-theft.html - -* https://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_a/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Rare parent-child process relationship=== -An attacker may use LOLBAS tools spawned from vulnerable applications not typically used by system administrators. This search leverages the Splunk Streaming ML DSP plugin to find rare parent/child relationships. The list of application has been extracted from https://github.com/LOLBAS-Project/LOLBAS/tree/master/yml/OSBinaries - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1203/ T1203], [https://attack.mitre.org/techniques/T1059/ T1059], [https://attack.mitre.org/techniques/T1053/ T1053], [https://attack.mitre.org/techniques/T1072/ T1072] -* '''Last Updated''': 2021-05-20 - -
-
- -====Search==== - -| from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)) -| eval parent_process=lower(ucast(map_get(input_event, "parent_process_name"), "string", null)), parent_process_name=mvindex(split(parent_process, "\\"), -1), process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), dest_user_id=ucast(map_get(input_event, "dest_user_id"), "string", null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where parent_process_name!=null -| select parent_process_name, process_name, cmd_line, timestamp, dest_device_id, dest_user_id -| conditional_anomaly conditional="parent_process_name" target="process_name" -| where (process_name="powershell.exe" OR process_name="regsvcs.exe" OR process_name="ftp.exe" OR process_name="dfsvc.exe" OR process_name="rasautou.exe" OR process_name="schtasks.exe" OR process_name="xwizard.exe" OR process_name="findstr.exe" OR process_name="esentutl.exe" OR process_name="cscript.exe" OR process_name="reg.exe" OR process_name="csc.exe" OR process_name="atbroker.exe" OR process_name="print.exe" OR process_name="pcwrun.exe" OR process_name="vbc.exe" OR process_name="rpcping.exe" OR process_name="wsreset.exe" OR process_name="ilasm.exe" OR process_name="certutil.exe" OR process_name="replace.exe" OR process_name="mshta.exe" OR process_name="bitsadmin.exe" OR process_name="wscript.exe" OR process_name="ieexec.exe" OR process_name="cmd.exe" OR process_name="microsoft.workflow.compiler.exe" OR process_name="runscripthelper.exe" OR process_name="makecab.exe" OR process_name="forfiles.exe" OR process_name="desktopimgdownldr.exe" OR process_name="control.exe" OR process_name="msbuild.exe" OR process_name="register-cimprovider.exe" OR process_name="tttracer.exe" OR process_name="ie4uinit.exe" OR process_name="sc.exe" OR process_name="bash.exe" OR process_name="hh.exe" OR process_name="cmstp.exe" OR process_name="mmc.exe" OR process_name="jsc.exe" OR process_name="scriptrunner.exe" OR process_name="odbcconf.exe" OR process_name="extexport.exe" OR process_name="msdt.exe" OR process_name="diskshadow.exe" OR process_name="extrac32.exe" OR process_name="eventvwr.exe" OR process_name="mavinject.exe" OR process_name="regasm.exe" OR process_name="gpscript.exe" OR process_name="rundll32.exe" OR process_name="regsvr32.exe" OR process_name="regedit.exe" OR process_name="msiexec.exe" OR process_name="gfxdownloadwrapper.exe" OR process_name="presentationhost.exe" OR process_name="regini.exe" OR process_name="wmic.exe" OR process_name="runonce.exe" OR process_name="syncappvpublishingserver.exe" OR process_name="verclsid.exe" OR process_name="psr.exe" OR process_name="infdefaultinstall.exe" OR process_name="explorer.exe" OR process_name="expand.exe" OR process_name="installutil.exe" OR process_name="netsh.exe" OR process_name="wab.exe" OR process_name="dnscmd.exe" OR process_name="at.exe" OR process_name="pcalua.exe" OR process_name="cmdkey.exe" OR process_name="msconfig.exe") -| eval input = (-1)*log(output) -| adaptive_threshold algorithm="gaussian" threshold=0.001 window=604800000L -| where label AND input > mean -| eval start_time = timestamp, end_time = timestamp, entities = mvappend(dest_device_id, dest_user_id), body = create_map(["process_name", process_name, "parent_process_name", parent_process_name, "input", input, "mean", mean, "variance", variance, "output", output, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Unusual_Processes|Unusual Processes]] - - -====How To Implement==== -Collect endpoint data such as sysmon or 4688 events. - -====Required field==== - -* process - -* process_name - -* parent_process_name - -* _time - -* dest_device_id - -* dest_user_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1203 -| Exploitation for Client Execution -| Execution -|- -| T1059 -| Command and Scripting Interpreter -| Execution -|- -| T1053 -| Scheduled Task/Job -| Execution, Persistence, Privilege Escalation -|- -| T1072 -| Software Deployment Tools -| Execution, Lateral Movement -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Some custom tools used by admins could be used rarely to launch remotely applications. This might trigger false positives at the beginning when it hasn't collected yet enough data to construct the baseline. - - -====Reference==== - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Recon avproduct through pwh or wmi=== -The following analytic identifies suspicious PowerShell script execution via EventCode 4104 performing checks to identify anti-virus products installed on the endpoint. This technique is commonly found in malware and APT events where the adversary will map all running security applications or services. During triage, review parallel processes within the same timeframe. Review the full script block to identify other related artifacts. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1592/ T1592] -* '''Last Updated''': 2021-06-10 - -
-
- -====Search==== -`powershell` EventCode=4104 (Message = "*SELECT*" OR Message = "*WMIC*") AND (Message = "*AntiVirusProduct*" OR Message = "*AntiSpywareProduct*") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `recon_avproduct_through_pwh_or_wmi_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - -* [[Documentation:ESSOC:stories:UseCase#Malicious_PowerShell|Malicious PowerShell]] - - -====How To Implement==== -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -====Required field==== - -* _time - -* EventCode - -* Message - -* ComputerName - -* User - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1592 -| Gather Victim Host Information -| Reconnaissance -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -network administrator may used this command for checking purposes - -====Reference==== - - -* https://news.sophos.com/en-us/2020/05/12/maze-ransomware-1-year-counting/ - -* https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -* https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63 - -* https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf - -* https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/pwsh/windows-powershell.log - - -''version'': 1 -
-
- ----- - -===Recon using wmi class=== -The following analytic identifies suspicious PowerShell via EventCode 4104, where WMI is performing an event query looking for running processes or running services. This technique is commonly found where the adversary will identify services and system information on the compromised machine. During triage, review parallel processes within the same timeframe. Review the full script block to identify other related artifacts. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1592/ T1592] -* '''Last Updated''': 2021-06-10 - -
-
- -====Search==== -`powershell` EventCode=4104 (Message= "*SELECT*" OR Message= "*Get-WmiObject*") AND (Message= "*Win32_Bios*" OR Message= "*Win32_OperatingSystem*" OR Message= "*Win32_Processor*" OR Message= "*Win32_ComputerSystem*" OR Message= "*Win32_ComputerSystemProduct*" OR Message= "*Win32_ShadowCopy*") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `recon_using_wmi_class_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Malicious_PowerShell|Malicious PowerShell]] - - -====How To Implement==== -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -====Required field==== - -* _time - -* EventCode - -* Message - -* ComputerName - -* User - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1592 -| Gather Victim Host Information -| Reconnaissance -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -network administrator may used this command for checking purposes - -====Reference==== - - -* https://news.sophos.com/en-us/2020/05/12/maze-ransomware-1-year-counting/ - -* https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -* https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63 - -* https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf - -* https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/pwsh/windows-powershell.log - - -''version'': 1 -
-
- ----- - -===Reconnaissance and access to accounts groups and policies via powersploit modules=== -This detection identifies access to PowerSploit modules that discover accounts, groups and policies that can be accessed or taken over. - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/ T1078], [https://attack.mitre.org/techniques/T1087/ T1087], [https://attack.mitre.org/techniques/T1484/ T1484] -* '''Last Updated''': 2020-11-05 - -
-
- -====Search==== - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)Find-DomainLocalGroupMember/)=true OR match_regex(cmd_line, /(?i)Invoke-EnumerateLocalAdmin/)=true OR match_regex(cmd_line, /(?i)Find-DomainUserEvent/)=true OR match_regex(cmd_line, /(?i)Invoke-EventHunter/)=true OR match_regex(cmd_line, /(?i)Find-DomainUserLocation/)=true OR match_regex(cmd_line, /(?i)Invoke-UserHunter/)=true OR match_regex(cmd_line, /(?i)Get-DomainForeignGroupMember/)=true OR match_regex(cmd_line, /(?i)Find-ForeignGroup/)=true OR match_regex(cmd_line, /(?i)Get-DomainForeignUser/)=true OR match_regex(cmd_line, /(?i)Find-ForeignUser/)=true OR match_regex(cmd_line, /(?i)Get-DomainGPO/)=true OR match_regex(cmd_line, /(?i)Get-NetGPO/)=true OR match_regex(cmd_line, /(?i)Get-DomainGPOComputerLocalGroupMapping/)=true OR match_regex(cmd_line, /(?i)Find-GPOComputerAdmin/)=true OR match_regex(cmd_line, /(?i)Get-DomainGPOLocalGroup/)=true OR match_regex(cmd_line, /(?i)Get-NetGPOGroup/)=true OR match_regex(cmd_line, /(?i)Get-DomainGPOUserLocalGroupMapping/)=true OR match_regex(cmd_line, /(?i)Find-GPOLocation/)=true OR match_regex(cmd_line, /(?i)Get-DomainGroup/)=true OR match_regex(cmd_line, /(?i)Get-NetGroup/)=true OR match_regex(cmd_line, /(?i)Get-DomainGroupMember/)=true OR match_regex(cmd_line, /(?i)Get-NetGroupMember/)=true OR match_regex(cmd_line, /(?i)Get-DomainManagedSecurityGroup/)=true OR match_regex(cmd_line, /(?i)Find-ManagedSecurityGroups/)=true OR match_regex(cmd_line, /(?i)Get-DomainOU/)=true OR match_regex(cmd_line, /(?i)Get-NetOU/)=true OR match_regex(cmd_line, /(?i)Get-DomainUser/)=true OR match_regex(cmd_line, /(?i)Get-NetUser/)=true OR match_regex(cmd_line, /(?i)Get-DomainUserEvent/)=true OR match_regex(cmd_line, /(?i)Get-UserEvent/)=true OR match_regex(cmd_line, /(?i)Get-NetLocalGroup/)=true OR match_regex(cmd_line, /(?i)Get-NetLocalGroupMember/)=true OR match_regex(cmd_line, /(?i)Get-NetLoggedon/)=true OR match_regex(cmd_line, /(?i)Get-RegLoggedOn/)=true OR match_regex(cmd_line, /(?i)Get-WMIRegLastLoggedOn/)=true OR match_regex(cmd_line, /(?i)Get-LastLoggedOn/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Discovery_Techniques|Windows Discovery Techniques]] - - -====How To Implement==== -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -====Required field==== - -* _time - -* process - -* dest_device_id - -* dest_user_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1078 -| Valid Accounts -| Defense Evasion, Persistence, Privilege Escalation, Initial Access -|- -| T1087 -| Account Discovery -| Discovery -|- -| T1484 -| Domain Policy Modification -| Defense Evasion, Privilege Escalation -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -None identified. - -====Reference==== - - -* https://github.com/PowerShellMafia/PowerSploit - - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Reconnaissance and access to accounts and groups via mimikatz modules=== -This detection identifies use of Mimikatz modules for discovery of accounts and groups and access to them. - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/ T1078], [https://attack.mitre.org/techniques/T1087/ T1087], [https://attack.mitre.org/techniques/T1484/ T1484] -* '''Last Updated''': 2020-11-05 - -
-
- -====Search==== - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)net::user/)=true OR match_regex(cmd_line, /(?i)net::group/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Discovery_Techniques|Windows Discovery Techniques]] - - -====How To Implement==== -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -====Required field==== - -* _time - -* process - -* dest_device_id - -* dest_user_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1078 -| Valid Accounts -| Defense Evasion, Persistence, Privilege Escalation, Initial Access -|- -| T1087 -| Account Discovery -| Discovery -|- -| T1484 -| Domain Policy Modification -| Defense Evasion, Privilege Escalation -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -None identified. - -====Reference==== - - -* https://github.com/gentilkiwi/mimikatz - - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Reconnaissance and access to active directoty infrastructure via powersploit modules=== -This detection identifies access to PowerSploit modules for reconnaissance and access to elements of Active Directory infrastructure, such as domain identifiers, AD sites and forests, and trust relations. - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1199/ T1199], [https://attack.mitre.org/techniques/T1482/ T1482], [https://attack.mitre.org/techniques/T1590/ T1590], [https://attack.mitre.org/techniques/T1591/ T1591], [https://attack.mitre.org/techniques/T1595/ T1595] -* '''Last Updated''': 2020-11-06 - -
-
- -====Search==== - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)Get-DomainSID/)=true OR match_regex(cmd_line, /(?i)Get-DomainSite/)=true OR match_regex(cmd_line, /(?i)Get-NetSite/)=true OR match_regex(cmd_line, /(?i)Get-DomainSubnet/)=true OR match_regex(cmd_line, /(?i)Get-NetSubnet/)=true OR match_regex(cmd_line, /(?i)Get-DomainTrust/)=true OR match_regex(cmd_line, /(?i)Get-NetDomainTrust/)=true OR match_regex(cmd_line, /(?i)Get-DomainTrustMapping/)=true OR match_regex(cmd_line, /(?i)Invoke-MapDomainTrust/)=true OR match_regex(cmd_line, /(?i)Get-Forest/)=true OR match_regex(cmd_line, /(?i)Get-NetForest/)=true OR match_regex(cmd_line, /(?i)Get-ForestDomain/)=true OR match_regex(cmd_line, /(?i)Get-NetForestDomain/)=true OR match_regex(cmd_line, /(?i)Get-ForestGlobalCatalog/)=true OR match_regex(cmd_line, /(?i)Get-NetForestCatalog/)=true OR match_regex(cmd_line, /(?i)Get-ForestTrust/)=true OR match_regex(cmd_line, /(?i)Get-NetForestTrust/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Discovery_Techniques|Windows Discovery Techniques]] - - -====How To Implement==== -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -====Required field==== - -* _time - -* process - -* dest_device_id - -* dest_user_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1199 -| Trusted Relationship -| Initial Access -|- -| T1482 -| Domain Trust Discovery -| Discovery -|- -| T1590 -| Gather Victim Network Information -| Reconnaissance -|- -| T1591 -| Gather Victim Org Information -| Reconnaissance -|- -| T1595 -| Active Scanning -| Reconnaissance -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -None identified. - -====Reference==== - - -* https://github.com/PowerShellMafia/PowerSploit - - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Reconnaissance and access to computers and domains via powersploit modules=== -This detection identifies access to PowerSploit modules that discover computers, servers and domains that can be accessed or taken over. - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1592/ T1592], [https://attack.mitre.org/techniques/T1590/ T1590], [https://attack.mitre.org/techniques/T1087/ T1087] -* '''Last Updated''': 2020-11-06 - -
-
- -====Search==== - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)Get-ComputerDetail/)=true OR match_regex(cmd_line, /(?i)Get-Domain/)=true OR match_regex(cmd_line, /(?i)Get-NetDomain/)=true OR match_regex(cmd_line, /(?i)Get-DomainComputer/)=true OR match_regex(cmd_line, /(?i)Get-NetComputer/)=true OR match_regex(cmd_line, /(?i)Get-DomainController/)=true OR match_regex(cmd_line, /(?i)Get-NetDomainController/)=true OR match_regex(cmd_line, /(?i)Get-DomainFileServer/)=true OR match_regex(cmd_line, /(?i)Get-NetFileServer/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Discovery_Techniques|Windows Discovery Techniques]] - - -====How To Implement==== -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -====Required field==== - -* _time - -* process - -* dest_device_id - -* dest_user_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1592 -| Gather Victim Host Information -| Reconnaissance -|- -| T1590 -| Gather Victim Network Information -| Reconnaissance -|- -| T1087 -| Account Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -None identified. - -====Reference==== - - -* https://github.com/PowerShellMafia/PowerSploit - - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Reconnaissance and access to computers via mimikatz modules=== -This detection identifies use of Mimikatz modules for discovery of computers and servers and access to them. - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1592/ T1592] -* '''Last Updated''': 2020-11-06 - -
-
- -====Search==== - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)net::ServerInfo/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Discovery_Techniques|Windows Discovery Techniques]] - - -====How To Implement==== -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -====Required field==== - -* _time - -* process - -* dest_device_id - -* dest_user_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1592 -| Gather Victim Host Information -| Reconnaissance -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -None identified. - -====Reference==== - - -* https://github.com/gentilkiwi/mimikatz - - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Reconnaissance and access to operating system elements via powersploit modules=== -This detection identifies access to PowerSploit modules that discover and access operating system elements, such as processes, services, registry locations, security packages and files. - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1057/ T1057], [https://attack.mitre.org/techniques/T1083/ T1083], [https://attack.mitre.org/techniques/T1592/002/ T1592.002], [https://attack.mitre.org/techniques/T1046/ T1046], [https://attack.mitre.org/techniques/T1012/ T1012], [https://attack.mitre.org/techniques/T1007/ T1007], [https://attack.mitre.org/techniques/T1047/ T1047], [https://attack.mitre.org/techniques/T1592/ T1592], [https://attack.mitre.org/techniques/T1518/ T1518] -* '''Last Updated''': 2020-11-06 - -
-
- -====Search==== - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)Find-DomainProcess/)=true OR match_regex(cmd_line, /(?i)Invoke-ProcessHunter/)=true OR match_regex(cmd_line, /(?i)Get-ServiceDetail/)=true OR match_regex(cmd_line, /(?i)Get-WMIProcess/)=true OR match_regex(cmd_line, /(?i)Get-NetProcess/)=true OR match_regex(cmd_line, /(?i)Get-SecurityPackage/)=true OR match_regex(cmd_line, /(?i)Find-DomainObjectPropertyOutlier/)=true OR match_regex(cmd_line, /(?i)Get-DomainObject/)=true OR match_regex(cmd_line, /(?i)Get-ADObject/)=true OR match_regex(cmd_line, /(?i)Get-WMIRegMountedDrive/)=true OR match_regex(cmd_line, /(?i)Get-RegistryMountedDrive/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Discovery_Techniques|Windows Discovery Techniques]] - - -====How To Implement==== -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -====Required field==== - -* _time - -* process - -* dest_device_id - -* dest_user_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1057 -| Process Discovery -| Discovery -|- -| T1083 -| File and Directory Discovery -| Discovery -|- -| T1592.002 -| Software -| Reconnaissance -|- -| T1046 -| Network Service Scanning -| Discovery -|- -| T1012 -| Query Registry -| Discovery -|- -| T1007 -| System Service Discovery -| Discovery -|- -| T1047 -| Windows Management Instrumentation -| Execution -|- -| T1592 -| Gather Victim Host Information -| Reconnaissance -|- -| T1518 -| Software Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -None identified. - -====Reference==== - - -* https://github.com/PowerShellMafia/PowerSploit - - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Reconnaissance and access to processes and services via mimikatz modules=== -This detection identifies use of Mimikatz modules for discovery and access to services and processes. - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1007/ T1007], [https://attack.mitre.org/techniques/T1046/ T1046], [https://attack.mitre.org/techniques/T1057/ T1057] -* '''Last Updated''': 2020-11-06 - -
-
- -====Search==== - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)process::list/)=true OR match_regex(cmd_line, /(?i)service::list/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Discovery_Techniques|Windows Discovery Techniques]] - - -====How To Implement==== -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -====Required field==== - -* _time - -* process - -* dest_device_id - -* dest_user_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1007 -| System Service Discovery -| Discovery -|- -| T1046 -| Network Service Scanning -| Discovery -|- -| T1057 -| Process Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -None identified. - -====Reference==== - - -* https://github.com/gentilkiwi/mimikatz - - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Reconnaissance and access to shared resources via mimikatz modules=== -This detection identifies use of Mimikatz modules for discovery and access to network shares. - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1021/ T1021], [https://attack.mitre.org/techniques/T1039/ T1039], [https://attack.mitre.org/techniques/T1135/ T1135], [https://attack.mitre.org/techniques/T1021/002/ T1021.002] -* '''Last Updated''': 2020-11-06 - -
-
- -====Search==== - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)net::share/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Discovery_Techniques|Windows Discovery Techniques]] - - -====How To Implement==== -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -====Required field==== - -* _time - -* process - -* dest_device_id - -* dest_user_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1021 -| Remote Services -| Lateral Movement -|- -| T1039 -| Data from Network Shared Drive -| Collection -|- -| T1135 -| Network Share Discovery -| Discovery -|- -| T1021.002 -| SMB/Windows Admin Shares -| Lateral Movement -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -None identified. - -====Reference==== - - -* https://github.com/gentilkiwi/mimikatz - - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Reconnaissance and access to shared resources via powersploit modules=== -This detection identifies access to PowerSploit modules that discover and access network and distributed file system shares. - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1021/ T1021], [https://attack.mitre.org/techniques/T1039/ T1039], [https://attack.mitre.org/techniques/T1135/ T1135], [https://attack.mitre.org/techniques/T1021/002/ T1021.002] -* '''Last Updated''': 2020-11-06 - -
-
- -====Search==== - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)Find-DomainShare/)=true OR match_regex(cmd_line, /(?i)Invoke-ShareFinder/)=true OR match_regex(cmd_line, /(?i)Find-InterestingDomainShareFile/)=true OR match_regex(cmd_line, /(?i)Invoke-FileFinder/)=true OR match_regex(cmd_line, /(?i)Find-InterestingFile/)=true OR match_regex(cmd_line, /(?i)Get-DomainDFSShare/)=true OR match_regex(cmd_line, /(?i)Get-DFSshare/)=true OR match_regex(cmd_line, /(?i)Get-NetShare/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Discovery_Techniques|Windows Discovery Techniques]] - - -====How To Implement==== -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -====Required field==== - -* _time - -* process - -* dest_device_id - -* dest_user_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1021 -| Remote Services -| Lateral Movement -|- -| T1039 -| Data from Network Shared Drive -| Collection -|- -| T1135 -| Network Share Discovery -| Discovery -|- -| T1021.002 -| SMB/Windows Admin Shares -| Lateral Movement -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -None identified. - -====Reference==== - - -* https://github.com/PowerShellMafia/PowerSploit - - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Reconnaissance of access and persistence opportunities via powersploit modules=== -This detection identifies use of PowerSploit modules that discover opportunities for malicious access and persistence. Some examples include access to admin accounts, weak access control policies, landing paths for dropping malicious software or data to exfiltrate, registry locations to land autorun parameters, task scheduling opportunities, as well as services and system files that can be compromised. - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1053/ T1053], [https://attack.mitre.org/techniques/T1068/ T1068], [https://attack.mitre.org/techniques/T1078/ T1078], [https://attack.mitre.org/techniques/T1543/ T1543], [https://attack.mitre.org/techniques/T1547/ T1547], [https://attack.mitre.org/techniques/T1574/ T1574] -* '''Last Updated''': 2020-11-05 - -
-
- -====Search==== - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)Find-LocalAdminAccess/)=true OR match_regex(cmd_line, /(?i)Find-InterestingDomainAcl/)=true OR match_regex(cmd_line, /(?i)Invoke-ACLScanner/)=true OR match_regex(cmd_line, /(?i)Find-PathDLLHijack/)=true OR match_regex(cmd_line, /(?i)Find-ProcessDLLHijack/)=true OR match_regex(cmd_line, /(?i)Get-DomainObjectAcl/)=true OR match_regex(cmd_line, /(?i)Get-ObjectAcl/)=true OR match_regex(cmd_line, /(?i)Get-DomainPolicy/)=true OR match_regex(cmd_line, /(?i)Get-ModifiablePath/)=true OR match_regex(cmd_line, /(?i)Get-ModifiableRegistryAutoRun/)=true OR match_regex(cmd_line, /(?i)Get-ModifiableScheduledTaskFile/)=true OR match_regex(cmd_line, /(?i)Get-ModifiableService/)=true OR match_regex(cmd_line, /(?i)Get-ModifiableServiceFile/)=true OR match_regex(cmd_line, /(?i)Get-PathAcl/)=true OR match_regex(cmd_line, /(?i)Get-UnattendedInstallFile/)=true OR match_regex(cmd_line, /(?i)Get-UnquotedService/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Discovery_Techniques|Windows Discovery Techniques]] - - -====How To Implement==== -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -====Required field==== - -* _time - -* process - -* dest_device_id - -* dest_user_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1053 -| Scheduled Task/Job -| Execution, Persistence, Privilege Escalation -|- -| T1068 -| Exploitation for Privilege Escalation -| Privilege Escalation -|- -| T1078 -| Valid Accounts -| Defense Evasion, Persistence, Privilege Escalation, Initial Access -|- -| T1543 -| Create or Modify System Process -| Persistence, Privilege Escalation -|- -| T1547 -| Boot or Logon Autostart Execution -| Persistence, Privilege Escalation -|- -| T1574 -| Hijack Execution Flow -| Persistence, Privilege Escalation, Defense Evasion -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -None identified. - -====Reference==== - - -* https://github.com/PowerShellMafia/PowerSploit - - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Reconnaissance of connectivity via powersploit modules=== -This detection identifies access to PowerSploit modules for reconnaissance of connectivity. - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1021/ T1021], [https://attack.mitre.org/techniques/T1039/ T1039], [https://attack.mitre.org/techniques/T1135/ T1135], [https://attack.mitre.org/techniques/T1021/002/ T1021.002] -* '''Last Updated''': 2020-11-06 - -
-
- -====Search==== - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)Get-DomainDNSRecord/)=true OR match_regex(cmd_line, /(?i)Get-DNSRecord/)=true OR match_regex(cmd_line, /(?i)Get-DomainDNSZone/)=true OR match_regex(cmd_line, /(?i)Get-DNSZone/)=true OR match_regex(cmd_line, /(?i)Invoke-ReverseDnsLookup/)=true OR match_regex(cmd_line, /(?i)Get-WMIRegCachedRDPConnection/)=true OR match_regex(cmd_line, /(?i)Get-CachedRDPConnection/)=true OR match_regex(cmd_line, /(?i)Get-WMIRegProxy/)=true OR match_regex(cmd_line, /(?i)Get-Proxy/)=true OR match_regex(cmd_line, /(?i)Invoke-Portscan/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Discovery_Techniques|Windows Discovery Techniques]] - - -====How To Implement==== -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -====Required field==== - -* _time - -* process - -* dest_device_id - -* dest_user_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1021 -| Remote Services -| Lateral Movement -|- -| T1039 -| Data from Network Shared Drive -| Collection -|- -| T1135 -| Network Share Discovery -| Discovery -|- -| T1021.002 -| SMB/Windows Admin Shares -| Lateral Movement -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -None identified. - -====Reference==== - - -* https://github.com/PowerShellMafia/PowerSploit - - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Reconnaissance of credential stores and services via mimikatz modules=== -This detection identifies reconnaissance of credential stores and use of CryptoAPI services by Mimikatz modules. - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1098/ T1098], [https://attack.mitre.org/techniques/T1590/001/ T1590.001], [https://attack.mitre.org/techniques/T1078/ T1078], [https://attack.mitre.org/techniques/T1589/001/ T1589.001], [https://attack.mitre.org/techniques/T1590/ T1590], [https://attack.mitre.org/techniques/T1068/ T1068], [https://attack.mitre.org/techniques/T1589/ T1589], [https://attack.mitre.org/techniques/T1590/003/ T1590.003] -* '''Last Updated''': 2020-11-03 - -
-
- -====Search==== - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)crypto::capi/)=true OR match_regex(cmd_line, /(?i)crypto::cng/)=true OR match_regex(cmd_line, /(?i)crypto::providers/)=true OR match_regex(cmd_line, /(?i)crypto::stores/)=true OR match_regex(cmd_line, /(?i)crypto::sc/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Discovery_Techniques|Windows Discovery Techniques]] - - -====How To Implement==== -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -====Required field==== - -* _time - -* process - -* dest_device_id - -* dest_user_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1098 -| Account Manipulation -| Persistence -|- -| T1590.001 -| Domain Properties -| Reconnaissance -|- -| T1078 -| Valid Accounts -| Defense Evasion, Persistence, Privilege Escalation, Initial Access -|- -| T1589.001 -| Credentials -| Reconnaissance -|- -| T1590 -| Gather Victim Network Information -| Reconnaissance -|- -| T1068 -| Exploitation for Privilege Escalation -| Privilege Escalation -|- -| T1589 -| Gather Victim Identity Information -| Reconnaissance -|- -| T1590.003 -| Network Trust Dependencies -| Reconnaissance -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -None identified. - -====Reference==== - - -* https://github.com/gentilkiwi/mimikatz - - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Reconnaissance of defensive tools via powersploit modules=== -This detection identifies use of PowerSploit modules for assessment of presence of defensive tools. - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1592/002/ T1592.002], [https://attack.mitre.org/techniques/T1595/002/ T1595.002], [https://attack.mitre.org/techniques/T1592/ T1592], [https://attack.mitre.org/techniques/T1595/ T1595] -* '''Last Updated''': 2020-11-05 - -
-
- -====Search==== - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)Find-AVSignature/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Discovery_Techniques|Windows Discovery Techniques]] - - -====How To Implement==== -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -====Required field==== - -* _time - -* process - -* dest_device_id - -* dest_user_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1592.002 -| Software -| Reconnaissance -|- -| T1595.002 -| Vulnerability Scanning -| Reconnaissance -|- -| T1592 -| Gather Victim Host Information -| Reconnaissance -|- -| T1595 -| Active Scanning -| Reconnaissance -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -None identified. - -====Reference==== - - -* https://github.com/PowerShellMafia/PowerSploit - - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Reconnaissance of privilege escalation opportunities via powersploit modules=== -This detection identifies use of PowerSploit modules for assessment of privilege escalation opportunities. - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1068/ T1068], [https://attack.mitre.org/techniques/T1078/ T1078], [https://attack.mitre.org/techniques/T1098/ T1098] -* '''Last Updated''': 2020-11-05 - -
-
- -====Search==== - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)Invoke-PrivescAudit/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Discovery_Techniques|Windows Discovery Techniques]] - - -====How To Implement==== -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -====Required field==== - -* _time - -* process - -* dest_device_id - -* dest_user_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1068 -| Exploitation for Privilege Escalation -| Privilege Escalation -|- -| T1078 -| Valid Accounts -| Defense Evasion, Persistence, Privilege Escalation, Initial Access -|- -| T1098 -| Account Manipulation -| Persistence -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -None identified. - -====Reference==== - - -* https://github.com/PowerShellMafia/PowerSploit - - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Reconnaissance of process or service hijacking opportunities via mimikatz modules=== -This detection identifies use of Mimikatz modules for discovery of process or service hijacking opportunities via Microsoft Detours compatibility. Microsoft Detours is an open source library for intercepting, monitoring and instrumenting binary functions on Microsoft Windows. Detours intercepts Win32 functions by re-writing the in-memory code for target functions. The Detours package also contains utilities to attach arbitrary DLLs and data segments called payloads to any Win32 binary. - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1543/ T1543], [https://attack.mitre.org/techniques/T1055/ T1055], [https://attack.mitre.org/techniques/T1574/ T1574] -* '''Last Updated''': 2020-11-05 - -
-
- -====Search==== - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)misc::detours/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Discovery_Techniques|Windows Discovery Techniques]] - - -====How To Implement==== -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -====Required field==== - -* _time - -* process - -* dest_device_id - -* dest_user_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1543 -| Create or Modify System Process -| Persistence, Privilege Escalation -|- -| T1055 -| Process Injection -| Defense Evasion, Privilege Escalation -|- -| T1574 -| Hijack Execution Flow -| Persistence, Privilege Escalation, Defense Evasion -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -None identified. - -====Reference==== - - -* https://github.com/gentilkiwi/mimikatz - -* https://en.wikipedia.org/wiki/Microsoft_Detours - - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Recursive delete of directory in batch cmd=== -This search is to detect a suspicious commandline designed to delete files or directory recursive using batch command. This technique was seen in ransomware (reddot) where it it tries to delete the files in recycle bin to impaire user from recovering deleted files. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1070/004/ T1070.004], [https://attack.mitre.org/techniques/T1070/ T1070] -* '''Last Updated''': 2021-06-22 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_cmd` Processes.process=*/c* Processes.process=* rd * Processes.process="*/s*" Processes.process="*/q*" by Processes.user Processes.process_name Processes.parent_process_name Processes.parent_process Processes.process Processes.process_id Processes.dest -|`drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `recursive_delete_of_directory_in_batch_cmd_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1070.004 -| File Deletion -| Defense Evasion -|- -| T1070 -| Indicator Removal on Host -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -network operator may use this batch command to delete recursively a directory or files within directory - -====Reference==== - - -* https://app.any.run/tasks/c0f98850-af65-4352-9746-fbebadee4f05/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/data2/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Reg exe manipulating windows services registry keys=== -The search looks for reg.exe modifying registry keys that define Windows services and their configurations. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1574/011/ T1574.011], [https://attack.mitre.org/techniques/T1574/ T1574] -* '''Last Updated''': 2020-11-26 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Processes.process_name) as process_name values(Processes.parent_process_name) as parent_process_name values(Processes.user) as user FROM datamodel=Endpoint.Processes where Processes.process_name=reg.exe Processes.process=*reg* Processes.process=*add* Processes.process=*Services* by Processes.process_id Processes.dest Processes.process -| `drop_dm_object_name("Processes")` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `reg_exe_manipulating_windows_services_registry_keys_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Service_Abuse|Windows Service Abuse]] - -* [[Documentation:ESSOC:stories:UseCase#Windows_Persistence_Techniques|Windows Persistence Techniques]] - - -====How To Implement==== -To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. - -====Required field==== - -* _time - -* Processes.process_name - -* Processes.parent_process_name - -* Processes.user - -* Processes.process - -* Processes.process_id - -* Processes.dest - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1574.011 -| Services Registry Permissions Weakness -| Persistence, Privilege Escalation, Defense Evasion -|- -| T1574 -| Hijack Execution Flow -| Persistence, Privilege Escalation, Defense Evasion -|} - - -====Kill Chain Phase==== - -* Installation - - -====Known False Positives==== -It is unusual for a service to be created or modified by directly manipulating the registry. However, there may be legitimate instances of this behavior. It is important to validate and investigate, as appropriate. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1574.011/change_registry_path_service/windows-sysmon.log - - -''version'': 5 -
-
- ----- - -===Registry keys used for persistence=== -The search looks for modifications to registry keys that can be used to launch an application or service at system startup. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1547/001/ T1547.001], [https://attack.mitre.org/techniques/T1547/ T1547] -* '''Last Updated''': 2021-09-07 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count values(Registry.registry_key_name) as registry_key_name values(Registry.registry_path) as registry_path min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where (Registry.registry_path=*\\currentversion\\run* OR Registry.registry_path=*\\currentVersion\\Windows\\Appinit_Dlls* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Shell* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Notify* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Userinit* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\VmApplet* OR Registry.registry_path=*\\currentversion\\policies\\explorer\\run* OR Registry.registry_path=*\\currentversion\\runservices* OR Registry.registry_path=HKLM\\SOFTWARE\\Microsoft\\Netsh\\* OR (Registry.registry_path="*Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options*" AND Registry.registry_key_name=Debugger) OR (Registry.registry_path="*\\CurrentControlSet\\Control\\Lsa" AND Registry.registry_key_name="Security Packages") OR (Registry.registry_path="*\\CurrentControlSet\\Control\\Lsa\\OSConfig" AND Registry.registry_key_name="Security Packages") OR (Registry.registry_path="*\\Microsoft\\Windows NT\\CurrentVersion\\SilentProcessExit\\*") OR (Registry.registry_path="*currentVersion\\Windows" AND Registry.registry_key_name="Load") OR (Registry.registry_path="*\\CurrentVersion" AND Registry.registry_key_name="Svchost") OR (Registry.registry_path="*\\CurrentControlSet\Control\Session Manager"AND Registry.registry_key_name="BootExecute") OR (Registry.registry_path="*\\Software\\Run" AND Registry.registry_key_name="auto_update")) by Registry.dest Registry.user -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `drop_dm_object_name(Registry)` -| `registry_keys_used_for_persistence_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Windows_Registry_Activities|Suspicious Windows Registry Activities]] - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_MSHTA_Activity|Suspicious MSHTA Activity]] - -* [[Documentation:ESSOC:stories:UseCase#DHS_Report_TA18-074A|DHS Report TA18-074A]] - -* [[Documentation:ESSOC:stories:UseCase#Possible_Backdoor_Activity_Associated_With_MUDCARP_Espionage_Campaigns|Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns]] - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - -* [[Documentation:ESSOC:stories:UseCase#Windows_Persistence_Techniques|Windows Persistence Techniques]] - -* [[Documentation:ESSOC:stories:UseCase#Emotet_Malware__DHS_Report_TA18-201A_|Emotet Malware DHS Report TA18-201A ]] - -* [[Documentation:ESSOC:stories:UseCase#IcedID|IcedID]] - -* [[Documentation:ESSOC:stories:UseCase#Remcos|Remcos]] - - -====How To Implement==== -To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. - -====Required field==== - -* _time - -* Registry.registry_key_name - -* Registry.registry_path - -* Registry.dest - -* Registry.user - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1547.001 -| Registry Run Keys / Startup Folder -| Persistence, Privilege Escalation -|- -| T1547 -| Boot or Logon Autostart Execution -| Persistence, Privilege Escalation -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -There are many legitimate applications that must execute on system startup and will use these registry keys to accomplish that task. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.001/atomic_red_team/windows-sysmon.log - - -''version'': 6 -
-
- ----- - -===Registry keys used for privilege escalation=== -This search looks for modifications to registry keys that can be used to elevate privileges. The registry keys under "Image File Execution Options" are used to intercept calls to an executable and can be used to attach malicious binaries to benign system binaries. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1546/012/ T1546.012], [https://attack.mitre.org/techniques/T1546/ T1546] -* '''Last Updated''': 2020-11-27 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where (Registry.registry_path="*Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options*") AND (Registry.registry_key_name=GlobalFlag OR Registry.registry_key_name=Debugger) by Registry.dest Registry.user Registry.registry_path Registry.registry_key_name -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `drop_dm_object_name(Registry)` -| `registry_keys_used_for_privilege_escalation_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Privilege_Escalation|Windows Privilege Escalation]] - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Windows_Registry_Activities|Suspicious Windows Registry Activities]] - -* [[Documentation:ESSOC:stories:UseCase#Cloud_Federated_Credential_Abuse|Cloud Federated Credential Abuse]] - - -====How To Implement==== -To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black, or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. - -====Required field==== - -* _time - -* Registry.registry_path - -* Registry.registry_key_name - -* Registry.dest - -* Registry.user - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1546.012 -| Image File Execution Options Injection -| Privilege Escalation, Persistence -|- -| T1546 -| Event Triggered Execution -| Privilege Escalation, Persistence -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -There are many legitimate applications that must execute upon system startup and will use these registry keys to accomplish that task. - -====Reference==== - - -* https://blog.malwarebytes.com/101/2015/12/an-introduction-to-image-file-execution-options/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.012/atomic_red_team/windows-sysmon.log - - -''version'': 4 -
-
- ----- - -===Registry keys for creating shim databases=== -This search looks for registry activity associated with application compatibility shims, which can be leveraged by attackers for various nefarious purposes. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1546/011/ T1546.011], [https://attack.mitre.org/techniques/T1546/ T1546] -* '''Last Updated''': 2020-11-26 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count values(Registry.registry_key_name) as registry_key_name min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path=*CurrentVersion\\AppCompatFlags\\Custom* OR Registry.registry_path=*CurrentVersion\\AppCompatFlags\\InstalledSDB* by Registry.dest Registry.user -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `drop_dm_object_name(Registry)` -| `registry_keys_for_creating_shim_databases_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Windows_Registry_Activities|Suspicious Windows Registry Activities]] - -* [[Documentation:ESSOC:stories:UseCase#Windows_Persistence_Techniques|Windows Persistence Techniques]] - - -====How To Implement==== -To successfully implement this search, you must populate the Change_Analysis data model. This is typically populated via endpoint detection and response product, such as Carbon Black or other endpoint data sources such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. - -====Required field==== - -* _time - -* Registry.registry_key_name - -* Registry.registry_path - -* Registry.dest - -* Registry.user - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1546.011 -| Application Shimming -| Privilege Escalation, Persistence -|- -| T1546 -| Event Triggered Execution -| Privilege Escalation, Persistence -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -There are many legitimate applications that leverage shim databases for compatibility purposes for legacy applications - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.011/atomic_red_team/windows-sysmon.log - - -''version'': 3 -
-
- ----- - -===Regsvr32 silent param dll loading=== -This analytic is to detect a loading of dll using regsvr32 application with silent parameter and dllinstall execution. This technique was seen in several RAT malware like remcos, njrat and APT's to load their malicious dll in the compromised machine. This TTP may executed by normal 3rd party application so it is better to pivot the parent process, parent commandline and commandline of the file that execute this regsvr32. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/010/ T1218.010] -* '''Last Updated''': 2021-10-04 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = regsvr32.exe Processes.process="*/i*" Processes.process="*/s*" by Processes.dest Processes.parent_process Processes.process Processes.parent_process_name Processes.process_name Processes.original_file_name Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `regsvr32_silent_param_dll_loading_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Regsvr32_Activity|Suspicious Regsvr32 Activity]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1218 -| Signed Binary Proxy Execution -| Defense Evasion -|- -| T1218.010 -| Regsvr32 -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Other third part application may used this parameter but not so common in base windows environment. - -====Reference==== - - -* https://app.any.run/tasks/dc93ee63-050c-4ff8-b07e-8277af9ab939/# - -* https://attack.mitre.org/techniques/T1218/010/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.005/vbs_wscript/sysmon.log - - -''version'': 1 -
-
- ----- - -===Remcos rat file creation in remcos folder=== -This search is to detect file creation in remcos folder in appdata which is the keylog and clipboard logs that will be send to its c2 server. This is really a good TTP indicator that there is a remcos rat in the system that do keylogging, clipboard grabbing and audio recording. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1113/ T1113] -* '''Last Updated''': 2021-09-21 - -
-
- -====Search==== - -|tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_name IN ("*.dat") Filesystem.file_path = "*\\remcos\\*" by _time Filesystem.file_name Filesystem.file_path Filesystem.dest Filesystem.file_create_time -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `remcos_rat_file_creation_in_remcos_folder_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Remcos|Remcos]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -====Required field==== - -* _time - -* dest - -* file_create_time - -* file_name - -* file_path - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1113 -| Screen Capture -| Collection -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://success.trendmicro.com/solution/1123281-remcos-malware-information - -* https://blog.malwarebytes.com/threat-intelligence/2021/07/remcos-rat-delivered-via-visual-basic/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos_agent/sysmon.log - - -''version'': 1 -
-
- ----- - -===Remcos client registry install entry=== -This search detects registry key license at host where Remcos RAT agent is installed. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1112/ T1112] -* '''Last Updated''': 2021-09-24 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Registry.registry_path) as registry_path FROM datamodel=Endpoint.Registry where (Registry.registry_key_name=*\\Software\\Remcos*) by Registry.dest Registry.user Registry.registry_key_name Registry.process_id -| `drop_dm_object_name(Registry)` -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -|`remcos_client_registry_install_entry_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Remcos|Remcos]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. - -====Required field==== - -* _time - -* Registry.registry_path - -* Registry.registry_key_name - -* Registry.process_id - -* Registry.dest - -* Registry.user - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1112 -| Modify Registry -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://attack.mitre.org/software/S0332/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos_panel_client/remcos_registry_entry.log - - -''version'': 1 -
-
- ----- - -===Remote desktop process running on system=== -This search looks for the remote desktop process mstsc.exe running on systems upon which it doesn't typically run. This is accomplished by filtering out all systems that are noted in the `common_rdp_source category` in the Assets and Identity framework. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1021/001/ T1021.001], [https://attack.mitre.org/techniques/T1021/ T1021] -* '''Last Updated''': 2020-07-21 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process=*mstsc.exe AND Processes.dest_category!=common_rdp_source by Processes.dest Processes.user Processes.process -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `drop_dm_object_name(Processes)` -| `remote_desktop_process_running_on_system_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Hidden_Cobra_Malware|Hidden Cobra Malware]] - -* [[Documentation:ESSOC:stories:UseCase#Lateral_Movement|Lateral Movement]] - - -====How To Implement==== -To successfully implement this search, you must be ingesting data that records process activity from your hosts to populate the endpoint data model in the processes node. The search requires you to identify systems that do not commonly use remote desktop. You can use the included support search "Identify Systems Using Remote Desktop" to identify these systems. After identifying them, you will need to add the "common_rdp_source" category to that system using the Enterprise Security Assets and Identities framework. This can be done by adding an entry in the assets.csv file located in `SA-IdentityManagement/lookups`. - -====Required field==== - -* _time - -* Processes.process - -* Processes.dest_category - -* Processes.dest - -* Processes.user - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1021.001 -| Remote Desktop Protocol -| Lateral Movement -|- -| T1021 -| Remote Services -| Lateral Movement -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Remote Desktop may be used legitimately by users on the network. - -====Reference==== - - -====Test Dataset==== - - -''version'': 5 -
-
- ----- - -===Remote process instantiation via wmi=== -This analytic identifies wmic.exe being launched with parameters to spawn a process on a remote system. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1047/ T1047] -* '''Last Updated''': 2020-11-30 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_wmic` Processes.process="*/node*" Processes.process="*process*" Processes.process="*call*" Processes.process="*create*" by Processes.process_name Processes.original_file_name Processes.parent_process_name Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -| `remote_process_instantiation_via_wmi_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_WMI_Use|Suspicious WMI Use]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1047 -| Windows Management Instrumentation -| Execution -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -The wmic.exe utility is a benign Windows application. It may be used legitimately by Administrators with these parameters for remote system administration, but it's relatively uncommon. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1047/atomic_red_team/windows-sysmon.log - - -''version'': 6 -
-
- ----- - -===Remote system discovery with adsisearcher=== -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the `[Adsisearcher]` type accelerator being used to query Active Directory for domain computers. Red Teams and adversaries may leverage `[Adsisearcher]` to enumerate domain computers for situational awareness and Active Directory Discovery. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1018/ T1018] -* '''Last Updated''': 2021-09-01 - -
-
- -====Search==== -`powershell` EventCode=4104 (Message = "*[adsisearcher]*" AND Message = "*objectclass=computer*" AND Message = "*findAll()*") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `remote_system_discovery_with_adsisearcher_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -====Required field==== - -* _time - -* EventCode - -* Message - -* ComputerName - -* User - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1018 -| Remote System Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use Adsisearcher for troubleshooting. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1018/ - -* https://devblogs.microsoft.com/scripting/use-the-powershell-adsisearcher-type-accelerator-to-search-active-directory/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/AD_discovery/windows-powershell.log - - -''version'': 1 -
-
- ----- - -===Remote system discovery with dsquery=== -This analytic looks for the execution of `dsquery.exe` with command-line arguments utilized to discover remote systems. The `computer` argument returns a list of all computers registered in the domain. Red Teams and adversaries alike engage in remote system discovery for situational awareness and Active Directory Discovery. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1018/ T1018] -* '''Last Updated''': 2021-08-31 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="dsquery.exe") (Processes.process="*computer*") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `remote_system_discovery_with_dsquery_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1018 -| Remote System Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use this command for troubleshooting. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1018/ - -* https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/cc732952(v=ws.11) - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/AD_discovery/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Remote system discovery with net=== -This analytic looks for the execution of `net.exe` or `net1.exe` with command-line arguments utilized to discover remote systems. The argument `domain computers /domain` returns a list of all domain computers. Red Teams and adversaries alike use net.exe to identify remote systems for situational awareness and Active Directory Discovery. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1018/ T1018] -* '''Last Updated''': 2021-08-30 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="net.exe" OR Processes.process_name="net1.exe") (Processes.process="*domain computers*" AND Processes.process=*/do*) OR (Processes.process="*view*" AND Processes.process=*/do*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `remote_system_discovery_with_net_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1018 -| Remote System Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use this command for troubleshooting. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1018/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/AD_discovery/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Remote system discovery with wmic=== -This analytic looks for the execution of `wmic.exe` with command-line arguments utilized to discover remote systems. The arguments utilized in this command return a list of all the systems registered in the domain. Red Teams and adversaries alike may leverage WMI and wmic.exe to identify remote systems for situational awareness and Active Directory Discovery. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1018/ T1018] -* '''Last Updated''': 2021-09-01 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="wmic.exe") (Processes.process=*/NAMESPACE:\\\\root\\directory\\ldap* AND Processes.process=*ds_computer* AND Processes.process="*GET ds_samaccountname*") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `remote_system_discovery_with_wmic_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1018 -| Remote System Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use this command for troubleshooting. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1018/ - -* https://docs.microsoft.com/en-us/windows/win32/wmisdk/wmic - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/AD_discovery/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Remote wmi command attempt=== -The following analytic identifies usage of `wmic.exe` spawning a local or remote process, identified by the `node` switch. During triage, review parallel processes for additional commands executed. Look for any file modifications before and after `wmic.exe` execution. In addition, identify the remote endpoint and confirm execution or file modifications. Contain and isolate the endpoint as needed. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1047/ T1047] -* '''Last Updated''': 2018-12-03 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_wmic` Processes.process=*node* by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `remote_wmi_command_attempt_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_WMI_Use|Suspicious WMI Use]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. Deprecated because duplicate of Remote Process Instantiation via WMI. - -====Required field==== - -* _time - -* Processes.user - -* Processes.process_name - -* Processes.parent_process_name - -* Processes.dest - -* Processes.parent_process - -* Processes.parent_process_id - -* Processes.process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1047 -| Windows Management Instrumentation -| Execution -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Administrators may use this legitimately to gather info from remote systems. Filter as needed. - -====Reference==== - - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1047/T1047.yaml - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1047/atomic_red_team/windows-sysmon.log - - -''version'': 4 -
-
- ----- - -===Resize shadowstorage volume=== -The following analytics identifies the resizing of shadowstorage by ransomware malware to avoid the shadow volumes being made again. this technique is an alternative by ransomware attacker than deleting the shadowstorage which is known alert in defensive team. one example of ransomware that use this technique is CLOP ransomware where it drops a .bat file that will resize the shadowstorage to minimum size as much as possible - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1490/ T1490] -* '''Last Updated''': 2021-03-12 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` values(Processes.process) as cmdline values(Processes.parent_process_name) as parent_process values(Processes.process_name) as process_name min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name = "cmd.exe" OR Processes.parent_process_name = "powershell.exe" OR Processes.parent_process_name = "powershell_ise.exe" OR Processes.parent_process_name = "wmic.exe" Processes.process_name = "vssadmin.exe" Processes.process="*resize*" Processes.process="*shadowstorage*" Processes.process="*/maxsize*" by Processes.parent_process_name Processes.parent_process Processes.process_name Processes.process Processes.dest Processes.user Processes.process_id Processes.process_guid -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -| `resize_shadowstorage_volume_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Clop_Ransomware|Clop Ransomware]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -====Required field==== - -* Processes.process - -* Process.parent_process_name - -* _time - -* Processes.process_name - -* Processes.parent_process - -* Processes.dest - -* Processes.user - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1490 -| Inhibit System Recovery -| Impact -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -network admin can resize the shadowstorage for valid purposes. - -====Reference==== - - -* https://www.fireeye.com/blog/threat-research/2020/10/fin11-email-campaigns-precursor-for-ransomware-data-theft.html - -* https://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_a/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Resize shadowstorage volume=== -The following analytics identifies the resizing of shadowstorage by ransomware malware to avoid the shadow volumes being made again. this technique is an alternative by ransomware attacker than deleting the shadowstorage which is known alert in defensive team. one example of ransomware that use this technique is CLOP ransomware where it drops a .bat file that will resize the shadowstorage to minimum size as much as possible - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1489/ T1489] -* '''Last Updated''': 2021-06-21 - -
-
- -====Search==== - -| from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line IS NOT NULL AND like(cmd_line, "%resize%") AND like(cmd_line, "%shadowstorage%") AND like(cmd_line, "%maxsize%") AND process_name="vssadmin.exe" -| eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Clop_Ransomware|Clop Ransomware]] - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -====Required field==== - -* _time - -* dest_device_id - -* process_name - -* parent_process_name - -* process_path - -* dest_user_id - -* process - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1489 -| Service Stop -| Impact -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -network admin can resize the shadowstorage for valid purposes. - -====Reference==== - - -* https://www.fireeye.com/blog/threat-research/2020/10/fin11-email-campaigns-precursor-for-ransomware-data-theft.html - -* https://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/ssa_data1/windows-security.log - - -''version'': 2 -
-
- ----- - -===Revil common exec parameter=== -This analytic identifies suspicious commandline parameter that are commonly used by REVIL ransomware to encrypts the compromise machine. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1204/ T1204] -* '''Last Updated''': 2021-06-02 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process = "* -nolan *" OR Processes.process = "* -nolocal *" OR Processes.process = "* -fast *" OR Processes.process = "* -full *" by Processes.process_name Processes.process Processes.parent_process_name Processes.parent_process Processes.dest Processes.user Processes.process_id Processes.process_guid -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `revil_common_exec_parameter_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - -* [[Documentation:ESSOC:stories:UseCase#Revil_Ransomware|Revil Ransomware]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -====Required field==== - -* _time - -* Processes.process_name - -* Processes.process - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.dest - -* Processes.user - -* Processes.process_id - -* Processes.process_guid - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1204 -| User Execution -| Execution -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -third party tool may have same command line parameters as revil ransomware. - -====Reference==== - - -* https://krebsonsecurity.com/2021/05/a-closer-look-at-the-darkside-ransomware-gang/ - -* https://www.mcafee.com/blogs/other-blogs/mcafee-labs/mcafee-atr-analyzes-sodinokibi-aka-revil-ransomware-as-a-service-what-the-code-tells-us/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/revil/inf1/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Revil registry entry=== -This analytic identifies suspicious modification in registry entry to keep some malware data during its infection. This technique seen in several apt implant, malware and ransomware like REVIL where it keep some information like the random generated file extension it uses for all the encrypted files and ransomware notes file name in the compromised host. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1112/ T1112] -* '''Last Updated''': 2021-06-02 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count values(Registry.registry_key_name) as registry_key_name values(Registry.registry_path) as registry_path min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where (Registry.registry_path="*\\SOFTWARE\\WOW6432Node\\Facebook_Assistant\\*" OR Registry.registry_path="*\\SOFTWARE\\WOW6432Node\\BlackLivesMatter*") AND (Registry.registry_value_name = "\.*" OR Registry.registry_value_name = "Binary Data") by Registry.registry_value_name Registry.dest Registry.user -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `drop_dm_object_name(Registry)` -| `revil_registry_entry_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - -* [[Documentation:ESSOC:stories:UseCase#Revil_Ransomware|Revil Ransomware]] - - -====How To Implement==== -to successfully implement this search, you need to be ingesting logs with the Image, TargetObject registry key, registry Details from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -====Required field==== - -* _time - -* Registry.dest - -* Registry.user - -* Registry.registry_value_name - -* Registry.registry_path - -* Registry.registry_key_name - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1112 -| Modify Registry -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://krebsonsecurity.com/2021/05/a-closer-look-at-the-darkside-ransomware-gang/ - -* https://www.mcafee.com/blogs/other-blogs/mcafee-labs/mcafee-atr-analyzes-sodinokibi-aka-revil-ransomware-as-a-service-what-the-code-tells-us/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/revil/inf1/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Rundll loading dll by ordinal=== -This search looks for executing scripts with rundll32. Adversaries may abuse rundll32.exe to proxy execution of malicious code. Using rundll32.exe, vice executing directly, may avoid triggering security tools that may not monitor execution of the rundll32.exe process because of allowlists or false positives from normal operations. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/011/ T1218.011] -* '''Last Updated''': 2020-11-30 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_rundll32` by Processes.process_name Processes.parent_process_name Processes.original_file_name Processes.process Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `rundll_loading_dll_by_ordinal_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Unusual_Processes|Unusual Processes]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1218 -| Signed Binary Proxy Execution -| Defense Evasion -|- -| T1218.011 -| Rundll32 -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Installation - - -====Known False Positives==== -While not common, loading a DLL under %AppData% and calling a function by ordinal is possible by a legitimate process - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.011/atomic_red_team/windows-sysmon.log - - -''version'': 5 -
-
- ----- - -===Rundll32 control rundll hunt=== -The following hunting detection identifies rundll32.exe with `control_rundll` within the command-line, loading a .cpl or another file type. Developed in relation to CVE-2021-40444. Rundll32.exe can also be used to execute Control Panel Item files (.cpl) through the undocumented shell32.dll functions Control_RunDLL and Control_RunDLLAsUser. Double-clicking a .cpl file also causes rundll32.exe to execute. \ This is written to be a bit more broad by not including .cpl. \ During triage, review parallel processes to identify any further suspicious behavior. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/011/ T1218.011] -* '''Last Updated''': 2021-09-08 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name=rundll32.exe OR Processes.original_file_name=RUNDLL32.EXE) Processes.process=*Control_RunDLL* by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.original_file_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `rundll32_control_rundll_hunt_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Rundll32_Activity|Suspicious Rundll32 Activity]] - -* [[Documentation:ESSOC:stories:UseCase#Microsoft_MSHTML_Remote_Code_Execution_CVE-2021-40444|Microsoft MSHTML Remote Code Execution CVE-2021-40444]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1218 -| Signed Binary Proxy Execution -| Defense Evasion -|- -| T1218.011 -| Rundll32 -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -This is a hunting detection, meant to provide a understanding of how voluminous control_rundll is within the environment. - -====Reference==== - - -* https://strontic.github.io/xcyclopedia/library/rundll32.exe-111474C61232202B5B588D2B512CBB25.html - -* https://app.any.run/tasks/36c14029-9df8-439c-bba0-45f2643b0c70/ - -* https://attack.mitre.org/techniques/T1218/011/ - -* https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40444 - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.002/T1218.002.yaml - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.002/atomic_red_team/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Rundll32 control rundll world writable directory=== -The following detection identifies rundll32.exe with `control_rundll` within the command-line, loading a .cpl or another file type from windows\temp, programdata, or appdata. Developed in relation to CVE-2021-40444. Rundll32.exe can also be used to execute Control Panel Item files (.cpl) through the undocumented shell32.dll functions Control_RunDLL and Control_RunDLLAsUser. Double-clicking a .cpl file also causes rundll32.exe to execute. This is written to be a bit more broad by not including .cpl. The paths are specified, add more as needed. During triage, review parallel processes to identify any further suspicious behavior. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/011/ T1218.011] -* '''Last Updated''': 2021-09-08 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name=rundll32.exe OR Processes.original_file_name=RUNDLL32.EXE) Processes.process=*Control_RunDLL* AND Processes.process IN ("*\\appdata\\*", "*\\windows\\temp\\*", "*\\programdata\\*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.original_file_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `rundll32_control_rundll_world_writable_directory_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Rundll32_Activity|Suspicious Rundll32 Activity]] - -* [[Documentation:ESSOC:stories:UseCase#Microsoft_MSHTML_Remote_Code_Execution_CVE-2021-40444|Microsoft MSHTML Remote Code Execution CVE-2021-40444]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1218 -| Signed Binary Proxy Execution -| Defense Evasion -|- -| T1218.011 -| Rundll32 -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -This may be tuned, or a new one related, by adding .cpl to command-line. However, it's important to look for both. Tune/filter as needed. - -====Reference==== - - -* https://strontic.github.io/xcyclopedia/library/rundll32.exe-111474C61232202B5B588D2B512CBB25.html - -* https://app.any.run/tasks/36c14029-9df8-439c-bba0-45f2643b0c70/ - -* https://attack.mitre.org/techniques/T1218/011/ - -* https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40444 - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.002/T1218.002.yaml - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.002/atomic_red_team/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Rundll32 create remote thread to a process=== -This analytic identifies the suspicious Remote Thread execution of rundll32.exe process to cmd.exe process. This technique was seen in IcedID malware to execute its malicious code in normal process for defense evasion and to steal sensitive information the the compromised host. browser process. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1055/ T1055] -* '''Last Updated''': 2021-07-29 - -
-
- -====Search==== -`sysmon` EventCode=8 SourceImage = "*\\rundll32.exe" TargetImage = "*.exe" -| stats count min(_time) as firstTime max(_time) as lastTime by SourceImage TargetImage TargetProcessId SourceProcessId StartAddress EventCode Computer -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `rundll32_create_remote_thread_to_a_process_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#IcedID|IcedID]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the SourceImage, TargetImage, and EventCode executions from your endpoints related to create remote thread or injecting codes. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -====Required field==== - -* _time - -* SourceImage - -* TargetImage - -* TargetProcessId - -* SourceProcessId - -* StartAddress - -* EventCode - -* Computer - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1055 -| Process Injection -| Defense Evasion, Privilege Escalation -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://www.joesandbox.com/analysis/380662/0/html - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/inf_icedid/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Rundll32 createremotethread in browser=== -This analytic identifies the suspicious Remote Thread execution of rundll32.exe process to "firefox.exe" and "chrome.exe" browser. This technique was seen in IcedID malware where it hooks the browser to parse banking information as user used the targetted browser process. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1055/ T1055] -* '''Last Updated''': 2021-07-26 - -
-
- -====Search==== -`sysmon` EventCode=8 SourceImage = "*\\rundll32.exe" TargetImage IN ("*\\firefox.exe", "*\\chrome.exe", "*\\iexplore.exe","*\\microsoftedgecp.exe") -| stats count min(_time) as firstTime max(_time) as lastTime by SourceImage TargetImage TargetProcessId SourceProcessId StartAddress EventCode Computer -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `rundll32_createremotethread_in_browser_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#IcedID|IcedID]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the SourceImage, TargetImage, and EventCode executions from your endpoints related to create remote thread or injecting codes. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -====Required field==== - -* _time - -* SourceImage - -* TargetImage - -* TargetProcessId - -* SourceProcessId - -* StartAddress - -* EventCode - -* Computer - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1055 -| Process Injection -| Defense Evasion, Privilege Escalation -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://www.joesandbox.com/analysis/380662/0/html - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/inf_icedid/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Rundll32 dnsquery=== -This search is to detect a suspicious rundll32.exe process having a http connection and do a dns query in some web domain. This technique was seen in IcedID malware where the rundll32 that execute its payload will contact amazon.com to check internet connect and to communicate to its C&C server to download config and other file component. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/011/ T1218.011] -* '''Last Updated''': 2021-07-26 - -
-
- -====Search==== -`sysmon` EventCode=22 process_name="rundll32.exe" -| stats count min(_time) as firstTime max(_time) as lastTime by Image QueryName QueryStatus ProcessId direction Computer -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `rundll32_dnsquery_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#IcedID|IcedID]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name and eventcode = 22 dnsquery executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed rundll32.exe may be used. - -====Required field==== - -* _time - -* Image - -* QueryName - -* QueryStatus - -* ProcessId - -* direction - -* Computer - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1218 -| Signed Binary Proxy Execution -| Defense Evasion -|- -| T1218.011 -| Rundll32 -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://any.run/malware-trends/icedid - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/inf_icedid/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Rundll32 process creating exe dll files=== -This search is to detect a suspicious rundll32 process that drops executable (.exe or .dll) files. this behavior seen in rundll32 process of IcedID that tries to drop copy of itself in temp folder or download executable drop it either appdata or programdata as part of its execution. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/011/ T1218.011] -* '''Last Updated''': 2021-07-26 - -
-
- -====Search==== -`sysmon` EventCode=11 process_name="rundll32.exe" TargetFilename IN ("*.exe", "*.dll",) -| stats count min(_time) as firstTime max(_time) as lastTime by Image TargetFilename ProcessGuid dest user_id -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `rundll32_process_creating_exe_dll_files_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#IcedID|IcedID]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, TargetFilename, and eventcode 11 executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed rundll32.exe may be used. - -====Required field==== - -* _time - -* Image - -* TargetFilename - -* ProcessGuid - -* dest - -* user_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1218 -| Signed Binary Proxy Execution -| Defense Evasion -|- -| T1218.011 -| Rundll32 -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://any.run/malware-trends/icedid - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/inf_icedid/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Rundll32 shimcache flush=== -This analytic is to detect a suspicious rundll32 commandline to clear shim cache. This technique is a anti-forensic technique to clear the cache taht are one important artifacts in terms of digital forensic during attacks or incident. This TTP is a good indicator that someone tries to evade some tools and clear foothold on the machine. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1112/ T1112] -* '''Last Updated''': 2021-10-05 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_rundll32` AND Processes.process = "*apphelp.dll,ShimFlushCache*" by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.original_file_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `rundll32_shimcache_flush_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Unusual_Processes|Unusual Processes]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1112 -| Modify Registry -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://blueteamops.medium.com/shimcache-flush-89daff28d15e - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1112/shimcache_flush/sysmon.log - - -''version'': 1 -
-
- ----- - -===Rundll32 with no command line arguments with network=== -The following analytic identifies rundll32.exe with no command line arguments and performing a network connection. It is unusual for rundll32.exe to execute with no command line arguments present. This particular behavior is common with malicious software, including Cobalt Strike. During investigation, triage any network connections and parallel processes. Identify any suspicious module loads related to credential dumping or file writes. Rundll32.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/011/ T1218.011] -* '''Last Updated''': 2021-10-13 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where `process_rundll32` by _time span=1h Processes.process_guid Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name Processes.original_file_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| regex process="(rundll32\.exe.{0,4}$)" -| join process_guid [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Ports where Ports.dest_port !="0" by Ports.process_guid Ports.dest Ports.dest_port -| `drop_dm_object_name(Ports)` -| rename dest as connection_to_CNC] -| table _time dest parent_process_name process_name process_path process process_guid connection_to_CNC dest_port -| `rundll32_with_no_command_line_arguments_with_network_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Rundll32_Activity|Suspicious Rundll32 Activity]] - -* [[Documentation:ESSOC:stories:UseCase#Cobalt_Strike|Cobalt Strike]] - -* [[Documentation:ESSOC:stories:UseCase#PrintNightmare_CVE-2021-34527|PrintNightmare CVE-2021-34527]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` and `port` node. To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1218 -| Signed Binary Proxy Execution -| Defense Evasion -|- -| T1218.011 -| Rundll32 -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Although unlikely, some legitimate applications may use a moved copy of rundll32, triggering a false positive. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1218/011/ - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.011/T1218.011.md - -* https://lolbas-project.github.io/lolbas/Binaries/Rundll32 - -* https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon.log - - -''version'': 3 -
-
- ----- - -===Ryuk test files detected=== -The search looks for files that contain the key word *Ryuk* under any folder in the C drive, which is consistent with Ryuk propagation. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1486/ T1486] -* '''Last Updated''': 2020-11-06 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem WHERE "Filesystem.file_path"=C:\\*Ryuk* BY "Filesystem.dest", "Filesystem.user", "Filesystem.file_path" -| `drop_dm_object_name(Filesystem)` -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `ryuk_test_files_detected_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Ryuk_Ransomware|Ryuk Ransomware]] - - -====How To Implement==== -You must be ingesting data that records the filesystem activity from your hosts to populate the Endpoint Filesystem data-model object. If you are using Sysmon, you will need a Splunk Universal Forwarder on each endpoint from which you want to collect data. - -====Required field==== - -* _time - -* Filesystem.file_path - -* Filesystem.dest - -* Filesystem.user - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1486 -| Data Encrypted for Impact -| Impact -|} - - -====Kill Chain Phase==== - -* Delivery - - -====Known False Positives==== -If there are files with this keywoord as file names it might trigger false possitives, please make use of our filters to tune out potential FPs. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ryuk/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Ryuk wake on lan command=== -This Splunk query identifies the use of Wake-on-LAN utilized by Ryuk ransomware. The Ryuk Ransomware uses the Wake-on-Lan feature to turn on powered off devices on a compromised network to have greater success encrypting them. This is a high fidelity indicator of Ryuk ransomware executing on an endpoint. Upon triage, isolate the endpoint. Additional file modification events will be within the users profile (\appdata\roaming) and in public directories (users\public\). Review all Scheduled Tasks on the isolated endpoint and across the fleet. Suspicious Scheduled Tasks will include a path to a unknown binary and those endpoints should be isolated until triaged. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/ T1059], [https://attack.mitre.org/techniques/T1059/003/ T1059.003] -* '''Last Updated''': 2021-03-01 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process="*8 LAN*" OR Processes.process="*9 REP*") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `ryuk_wake_on_lan_command_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Ryuk_Ransomware|Ryuk Ransomware]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* _time - -* Processes.process - -* Processes.dest - -* Processes.user - -* Processes.parent_process - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1059 -| Command and Scripting Interpreter -| Execution -|- -| T1059.003 -| Windows Command Shell -| Execution -|} - - -====Kill Chain Phase==== - -* Exploitation - -* Lateral Movement - - -====Known False Positives==== -Limited to no known false positives. - -====Reference==== - - -* https://www.bleepingcomputer.com/news/security/ryuk-ransomware-uses-wake-on-lan-to-encrypt-offline-devices/ - -* https://www.bleepingcomputer.com/news/security/ryuk-ransomware-now-self-spreads-to-other-windows-lan-devices/ - -* https://www.cert.ssi.gouv.fr/uploads/CERTFR-2021-CTI-006.pdf - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.003/ryuk/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Sam database file access attempt=== -The following analytic identifies access to SAM, SYSTEM or SECURITY databases' within the file path of `windows\system32\config` using Windows Security EventCode 4663. This particular behavior is related to credential access, an attempt to either use a Shadow Copy or recent CVE-2021-36934 to access the SAM database. The Security Account Manager (SAM) is a database file in Windows XP, Windows Vista, Windows 7, 8.1 and 10 that stores users' passwords. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/002/ T1003.002], [https://attack.mitre.org/techniques/T1003/ T1003] -* '''Last Updated''': 2021-07-23 - -
-
- -====Search==== -`wineventlog_security` (EventCode=4663) process_name!=*\\dllhost.exe Object_Name IN ("*\\Windows\\System32\\config\\SAM*","*\\Windows\\System32\\config\\SYSTEM*","*\\Windows\\System32\\config\\SECURITY*") -| stats values(Accesses) count by process_name Object_Name dest user -| `sam_database_file_access_attempt_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Credential_Dumping|Credential Dumping]] - - -====How To Implement==== -To successfully implement this search, you must ingest Windows Security Event logs and track event code 4663. For 4663, enable "Audit Object Access" in Group Policy. Then check the two boxes listed for both "Success" and "Failure." - -====Required field==== - -* _time - -* process_name - -* Object_Name - -* dest - -* user - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1003.002 -| Security Account Manager -| Credential Access -|- -| T1003 -| OS Credential Dumping -| Credential Access -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Natively, `dllhost.exe` will access the files. Every environment will have additional native processes that do as well. Filter by process_name. As an aside, one can remove process_name entirely and add `Object_Name=*ShadowCopy*`. - -====Reference==== - - -* https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=4663 - -* https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4663 - -* https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36934 - -* https://github.com/GossiTheDog/HiveNightmare - -* https://github.com/JumpsecLabs/Guidance-Advice/tree/main/SAM_Permissions - -* https://en.wikipedia.org/wiki/Security_Account_Manager - - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Slui runas elevated=== -The following analytic identifies the Microsoft Software Licensing User Interface Tool, `slui.exe`, elevating access using the `-verb runas` function. This particular bypass utilizes a registry key/value. Identified by two sources, the registry keys are `HKCU\Software\Classes\exefile\shell` and `HKCU\Software\Classes\launcher.Systemsettings\Shell\open\command`. To simulate this behavior, multiple POC are available. The analytic identifies the use of `runas` by `slui.exe`. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1548/002/ T1548.002], [https://attack.mitre.org/techniques/T1548/ T1548] -* '''Last Updated''': 2021-05-13 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=slui.exe (Processes.process=*-verb* Processes.process=*runas*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `slui_runas_elevated_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#DarkSide_Ransomware|DarkSide Ransomware]] - -* [[Documentation:ESSOC:stories:UseCase#Windows_Defense_Evasion_Tactics|Windows Defense Evasion Tactics]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1548.002 -| Bypass User Account Control -| Privilege Escalation, Defense Evasion -|- -| T1548 -| Abuse Elevation Control Mechanism -| Privilege Escalation, Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Limited false positives should be present as this is not commonly used by legitimate applications. - -====Reference==== - - -* https://www.exploit-db.com/exploits/46998 - -* https://medium.com/@mattharr0ey/privilege-escalation-uac-bypass-in-changepk-c40b92818d1b - -* https://gist.github.com/r00t-3xp10it/0c92cd554d3156fd74f6c25660ccc466 - -* https://www.rapid7.com/db/modules/exploit/windows/local/bypassuac_sluihijack/ - -* https://www.mandiant.com/resources/shining-a-light-on-darkside-ransomware-operations - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.002/slui/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Slui spawning a process=== -The following analytic identifies the Microsoft Software Licensing User Interface Tool, `slui.exe`, spawning a child process. This behavior is associated with publicly known UAC bypass. `slui.exe` is commonly associated with software updates and is most often spawned by `svchost.exe`. The `slui.exe` process should not have child processes, and any processes spawning from it will be running with elevated privileges. During triage, review the child process and additional parallel processes. Identify any file modifications that may have lead to the bypass. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1548/002/ T1548.002], [https://attack.mitre.org/techniques/T1548/ T1548] -* '''Last Updated''': 2021-05-13 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=slui.exe by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `slui_spawning_a_process_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#DarkSide_Ransomware|DarkSide Ransomware]] - -* [[Documentation:ESSOC:stories:UseCase#Windows_Defense_Evasion_Tactics|Windows Defense Evasion Tactics]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1548.002 -| Bypass User Account Control -| Privilege Escalation, Defense Evasion -|- -| T1548 -| Abuse Elevation Control Mechanism -| Privilege Escalation, Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Certain applications may spawn from `slui.exe` that are legitimate. Filtering will be needed to ensure proper monitoring. - -====Reference==== - - -* https://www.exploit-db.com/exploits/46998 - -* https://www.rapid7.com/db/modules/exploit/windows/local/bypassuac_sluihijack/ - -* https://www.mandiant.com/resources/shining-a-light-on-darkside-ransomware-operations - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.002/slui/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Samsam test file write=== -The search looks for a file named "test.txt" written to the windows system directory tree, which is consistent with Samsam propagation. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1486/ T1486] -* '''Last Updated''': 2018-12-14 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Filesystem.user) as user values(Filesystem.dest) as dest values(Filesystem.file_name) as file_name from datamodel=Endpoint.Filesystem where Filesystem.file_path=*\\windows\\system32\\test.txt by Filesystem.file_path -| `drop_dm_object_name(Filesystem)` -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `samsam_test_file_write_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#SamSam_Ransomware|SamSam Ransomware]] - - -====How To Implement==== -You must be ingesting data that records the file-system activity from your hosts to populate the Endpoint file-system data-model node. If you are using Sysmon, you will need a Splunk Universal Forwarder on each endpoint from which you want to collect data. - -====Required field==== - -* _time - -* Filesystem.user - -* Filesystem.dest - -* Filesystem.file_name - -* Filesystem.file_path - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1486 -| Data Encrypted for Impact -| Impact -|} - - -====Kill Chain Phase==== - -* Delivery - - -====Known False Positives==== -No false positives have been identified. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1486/sam_sam_note/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Sc exe manipulating windows services=== -This search looks for arguments to sc.exe indicating the creation or modification of a Windows service. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1543/003/ T1543.003], [https://attack.mitre.org/techniques/T1543/ T1543] -* '''Last Updated''': 2020-07-21 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = sc.exe (Processes.process="* create *" OR Processes.process="* config *") by Processes.process_name Processes.parent_process_name Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `sc_exe_manipulating_windows_services_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Service_Abuse|Windows Service Abuse]] - -* [[Documentation:ESSOC:stories:UseCase#DHS_Report_TA18-074A|DHS Report TA18-074A]] - -* [[Documentation:ESSOC:stories:UseCase#Orangeworm_Attack_Group|Orangeworm Attack Group]] - -* [[Documentation:ESSOC:stories:UseCase#Windows_Persistence_Techniques|Windows Persistence Techniques]] - -* [[Documentation:ESSOC:stories:UseCase#Disabling_Security_Tools|Disabling Security Tools]] - -* [[Documentation:ESSOC:stories:UseCase#NOBELIUM_Group|NOBELIUM Group]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* _time - -* Processes.process_name - -* Processes.process - -* Processes.parent_process_name - -* Processes.dest - -* Processes.user - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1543.003 -| Windows Service -| Persistence, Privilege Escalation -|- -| T1543 -| Create or Modify System Process -| Persistence, Privilege Escalation -|} - - -====Kill Chain Phase==== - -* Installation - - -====Known False Positives==== -Using sc.exe to manipulate Windows services is uncommon. However, there may be legitimate instances of this behavior. It is important to validate and investigate as appropriate. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1543.003/atomic_red_team/windows-sysmon.log - - -''version'': 4 -
-
- ----- - -===Schcache change by app connect and create adsi object=== -This analytic is to detect an application try to connect and create ADSI Object to do LDAP query. Every time an application connects to the directory and attempts to create an ADSI object, the Active Directory Schema is checked for changes. If it has changed since the last connection, the schema is downloaded and stored in a cache on the local computer either in %LOCALAPPDATA%\Microsoft\Windows\SchCache or %systemroot%\SchCache. We found this a good anomaly use case to detect suspicious application like blackmatter ransomware that use ADS object api to execute ldap query. having a good list of ldap or normal AD query tool used within the network is a good start to reduce the noise. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/002/ T1087.002], [https://attack.mitre.org/techniques/T1087/ T1087] -* '''Last Updated''': 2021-09-07 - -
-
- -====Search==== -`sysmon` EventCode=11 TargetFilename = "*\\Windows\\SchCache\\*" TargetFilename = "*.sch*" NOT (Image IN ("*\\Windows\\system32\\mmc.exe")) -|stats count min(_time) as firstTime max(_time) as lastTime by Image TargetFilename EventCode process_id process_name Computer -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `schcache_change_by_app_connect_and_create_adsi_object_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#blackMatter_ransomware|blackMatter ransomware]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -====Required field==== - -* _time - -* Image - -* TargetFilename - -* EventCode - -* process_id - -* process_name - -* Computer - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1087.002 -| Domain Account -| Discovery -|- -| T1087 -| Account Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -normal application like mmc.exe and other ldap query tool may trigger this detections. - -====Reference==== - - -* https://docs.microsoft.com/en-us/windows/win32/adsi/adsi-and-uac - -* https://news.sophos.com/en-us/2021/08/09/blackmatter-ransomware-emerges-from-the-shadow-of-darkside/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/blackmatter_schcache/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Schedule task with http command arguments=== -The following query utilizes Windows Security EventCode 4698, `A scheduled task was created`, to identify suspicious tasks registered on Windows either via schtasks.exe OR TaskService with an arguments "HTTP" string that are unique entry of malware or attack that uses lolbin to download other file or payload to the infected machine. The search will return the first time and last time the task was registered, as well as the `Command` to be executed, `Task Name`, `Author`, `Enabled`, and whether it is `Hidden` or not. schtasks.exe is natively found in `C:\Windows\system32` and `C:\Windows\syswow64`. The following DLL(s) are loaded when schtasks.exe or TaskService is launched -`taskschd.dll`. If found loaded by another process, it is possible a scheduled task is being registered within that process context in memory. Upon triage, identify the task scheduled source. Was it schtasks.exe or via TaskService? Review the job created and the Command to be executed. Capture any artifacts on disk and review. Identify any parallel processes within the same timeframe to identify source.' - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1053/ T1053] -* '''Last Updated''': 2021-04-19 - -
-
- -====Search==== -`wineventlog_security` EventCode=4698 -| xmlkv Message -| search Arguments IN ("*http*") -| stats count min(_time) as firstTime max(_time) as lastTime by dest, Task_Name, Command, Author, Enabled, Hidden, Arguments -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `schedule_task_with_http_command_arguments_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Persistence_Techniques|Windows Persistence Techniques]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the task schedule (Exa. Security Log EventCode 4698) endpoints. Tune and filter known instances of Task schedule used in your environment. - -====Required field==== - -* _time - -* dest - -* Task_Name - -* Command - -* Author - -* Enabled - -* Hidden - -* Arguments - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1053 -| Scheduled Task/Job -| Execution, Persistence, Privilege Escalation -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://app.any.run/tasks/92d7ef61-bfd7-4c92-bc15-322172b4ebec/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/tasksched/windows-security.log - - -''version'': 1 -
-
- ----- - -===Schedule task with rundll32 command trigger=== -The following query utilizes Windows Security EventCode 4698, `A scheduled task was created`, to identify suspicious tasks registered on Windows either via schtasks.exe OR TaskService with a command to be executed with a Rundll32. This technique is common in new trickbot that uses rundll32 to load is trickbot downloader. The search will return the first time and last time the task was registered, as well as the `Command` to be executed, `Task Name`, `Author`, `Enabled`, and whether it is `Hidden` or not. schtasks.exe is natively found in `C:\Windows\system32` and `C:\Windows\syswow64`. The following DLL(s) are loaded when schtasks.exe or TaskService is launched -`taskschd.dll`. If found loaded by another process, it is possible a scheduled task is being registered within that process context in memory. Upon triage, identify the task scheduled source. Was it schtasks.exe or via TaskService? Review the job created and the Command to be executed. Capture any artifacts on disk and review. Identify any parallel processes within the same timeframe to identify source.' - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1053/ T1053] -* '''Last Updated''': 2021-04-19 - -
-
- -====Search==== -`wineventlog_security` EventCode=4698 -| xmlkv Message -| search Command IN ("*rundll32*") -| stats count min(_time) as firstTime max(_time) as lastTime by dest, Task_Name, Command, Author, Enabled, Hidden, Arguments -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `schedule_task_with_rundll32_command_trigger_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Persistence_Techniques|Windows Persistence Techniques]] - -* [[Documentation:ESSOC:stories:UseCase#Trickbot|Trickbot]] - -* [[Documentation:ESSOC:stories:UseCase#IcedID|IcedID]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the task schedule (Exa. Security Log EventCode 4698) endpoints. Tune and filter known instances of Task schedule used in your environment. - -====Required field==== - -* _time - -* dest - -* Task_Name - -* Command - -* Author - -* Enabled - -* Hidden - -* Arguments - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1053 -| Scheduled Task/Job -| Execution, Persistence, Privilege Escalation -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://labs.vipre.com/trickbot-and-its-modules/ - -* https://blog.whitehat.eu/2019/05/incident-trickbot-ryuk-2.html - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/trickbot/tasksched/windows-security.log - - -''version'': 1 -
-
- ----- - -===Scheduled task deleted or created via cmd=== -This search looks for flags passed to schtasks.exe on the command-line that indicate a task was created via command like. This has been associated with the Dragonfly threat actor, and the SUNBURST attack against Solarwinds. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1053/005/ T1053.005], [https://attack.mitre.org/techniques/T1053/ T1053] -* '''Last Updated''': 2020-12-17 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count values(Processes.process) as process values(Processes.parent_process) as parent_process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=schtasks.exe (Processes.process=*delete* OR Processes.process=*create*) by Processes.user Processes.process_name Processes.parent_process_name Processes.dest -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `scheduled_task_deleted_or_created_via_cmd_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#DHS_Report_TA18-074A|DHS Report TA18-074A]] - -* [[Documentation:ESSOC:stories:UseCase#NOBELIUM_Group|NOBELIUM Group]] - - -====How To Implement==== -You must be ingesting endpoint data that tracks process activity, including parent-child relationships from your endpoints to populate the Endpoint data model in the Processes node. The command-line arguments are mapped to the "process" field in the Endpoint data model. - -====Required field==== - -* _time - -* Processes.process - -* Processes.parent_process - -* Processes.process_name - -* Processes.user - -* Processes.parent_process_name - -* Processes.dest - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1053.005 -| Scheduled Task -| Execution, Persistence, Privilege Escalation -|- -| T1053 -| Scheduled Task/Job -| Execution, Persistence, Privilege Escalation -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Tasks should not be manually created via CLI, this is rarely done by admins as well - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/atomic_red_team/windows-sysmon.log - - -''version'': 5 -
-
- ----- - -===Schtasks run task on demand=== -This analytic identifies an on demand run of a Windows Schedule Task through shell or command-line. This technique has been used by adversaries that force to run their created Schedule Task as their persistence mechanism or for lateral movement as part of their malicious attack to the compromised machine. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1053/ T1053] -* '''Last Updated''': 2021-05-07 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` values(Processes.process) as process values(Processes.process_id) as process_id count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = "schtasks.exe" Processes.process = "*/run*" by Processes.process_name Processes.parent_process_name Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `schtasks_run_task_on_demand_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#XMRig|XMRig]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed schtasks.exe may be used. - -====Required field==== - -* _time - -* Processes.process - -* Processes.process_id - -* Processes.process_name - -* Processes.parent_process_name - -* Processes.dest - -* Processes.user - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1053 -| Scheduled Task/Job -| Execution, Persistence, Privilege Escalation -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Administrators may use to debug Schedule Task entries. Filter as needed. - -====Reference==== - - -* https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Schtasks scheduling job on remote system=== -This search looks for flags passed to schtasks.exe on the command-line that indicate a job is being scheduled on a remote system. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1053/005/ T1053.005], [https://attack.mitre.org/techniques/T1053/ T1053] -* '''Last Updated''': 2020-07-21 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = schtasks.exe Processes.process="*/create*" (Processes.process="* /s *" OR Processes.process="* /S *") by Processes.process_name Processes.process Processes.parent_process_name Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `schtasks_scheduling_job_on_remote_system_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Lateral_Movement|Lateral Movement]] - -* [[Documentation:ESSOC:stories:UseCase#NOBELIUM_Group|NOBELIUM Group]] - - -====How To Implement==== -You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. - -====Required field==== - -* _time - -* Processes.process_name - -* Processes.process - -* Processes.parent_process_name - -* Processes.dest - -* Processes.user - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1053.005 -| Scheduled Task -| Execution, Persistence, Privilege Escalation -|- -| T1053 -| Scheduled Task/Job -| Execution, Persistence, Privilege Escalation -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Administrators may create jobs on remote systems, but this activity is usually limited to a small set of hosts or users. It is important to validate and investigate as appropriate. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/atomic_red_team/windows-sysmon.log - - -''version'': 4 -
-
- ----- - -===Schtasks used for forcing a reboot=== -This search looks for flags passed to schtasks.exe on the command-line that indicate that a forced reboot of system is scheduled. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1053/005/ T1053.005], [https://attack.mitre.org/techniques/T1053/ T1053] -* '''Last Updated''': 2020-12-07 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=schtasks.exe Processes.process="*shutdown*" Processes.process="*/create *" by Processes.process_name Processes.parent_process_name Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `schtasks_used_for_forcing_a_reboot_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Persistence_Techniques|Windows Persistence Techniques]] - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.process - -* Processes.process_name - -* Processes.parent_process_name - -* Processes.dest - -* Processes.user - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1053.005 -| Scheduled Task -| Execution, Persistence, Privilege Escalation -|- -| T1053 -| Scheduled Task/Job -| Execution, Persistence, Privilege Escalation -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Administrators may create jobs on systems forcing reboots to perform updates, maintenance, etc. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/schtask_shutdown/windows-sysmon.log - - -''version'': 4 -
-
- ----- - -===Screensaver event trigger execution=== -This analytic is developed to detect possible event trigger execution through screensaver registry entry modification for persistence or privilege escalation. This technique was seen in several APT and malware where they put the malicious payload path to the SCRNSAVE.EXE registry key to redirect the execution to their malicious payload path. This TTP is a good indicator that some attacker may modify this entry for their persistence and privilege escalation. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1546/ T1546], [https://attack.mitre.org/techniques/T1546/002/ T1546.002] -* '''Last Updated''': 2021-09-27 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where (Registry.registry_path="*\\Control Panel\\Desktop\\SCRNSAVE.EXE*") by Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `drop_dm_object_name(Registry)` -| `screensaver_event_trigger_execution_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Persistence_Techniques|Windows Persistence Techniques]] - -* [[Documentation:ESSOC:stories:UseCase#Windows_Privilege_Escalation|Windows Privilege Escalation]] - - -====How To Implement==== -To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. - -====Required field==== - -* _time - -* Registry.dest - -* Registry.user - -* Registry.registry_path - -* Registry.registry_key_name - -* Registry.registry_value_name - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1546 -| Event Triggered Execution -| Privilege Escalation, Persistence -|- -| T1546.002 -| Screensaver -| Privilege Escalation, Persistence -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://attack.mitre.org/techniques/T1546/002/ - -* https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/privilege-escalation/untitled-3/screensaver - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.002/scrnsave_reg/sysmon.log - - -''version'': 1 -
-
- ----- - -===Script execution via wmi=== -This search looks for scripts launched via WMI. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1047/ T1047] -* '''Last Updated''': 2020-03-16 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=scrcons.exe by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `script_execution_via_wmi_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_WMI_Use|Suspicious WMI Use]] - - -====How To Implement==== -You must be ingesting endpoint data that tracks process activity, including parent-child relationships from your endpoints to populate the Endpoint data model in the Processes node. The command-line arguments are mapped to the "process" field in the Endpoint data model. - -====Required field==== - -* _time - -* Processes.process_name - -* Processes.user - -* Processes.dest - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1047 -| Windows Management Instrumentation -| Execution -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Although unlikely, administrators may use wmi to launch scripts for legitimate purposes. Filter as needed. - -====Reference==== - - -* https://redcanary.com/blog/child-processes/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1047/execution_scrcons/windows-sysmon.log - - -''version'': 4 -
-
- ----- - -===Sdclt uac bypass=== -This search is to detect a suspicious sdclt.exe registry modification. This technique is commonly seen when attacker try to bypassed UAC by using sdclt.exe application by modifying some registry that sdclt.exe tries to open or query with payload file path on it to be executed. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1548/002/ T1548.002], [https://attack.mitre.org/techniques/T1548/ T1548] -* '''Last Updated''': 2021-07-01 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where (Registry.registry_path= "*\\Windows\\CurrentVersion\\App Paths\\control.exe*" OR Registry.registry_path= "*\\exefile\\shell\\runas\\command\\*") (Registry.registry_key_name = "(Default)" OR Registry.registry_key_name = "IsolatedCommand") by Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.dest -| `drop_dm_object_name(Registry)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `sdclt_uac_bypass_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Defense_Evasion_Tactics|Windows Defense Evasion Tactics]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* _time - -* Registry.registry_path - -* Registry.registry_key_name - -* Registry.registry_value_name - -* Registry.dest - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1548.002 -| Bypass User Account Control -| Privilege Escalation, Defense Evasion -|- -| T1548 -| Abuse Elevation Control Mechanism -| Privilege Escalation, Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Limited to no false positives are expected. - -====Reference==== - - -* https://enigma0x3.net/2017/03/17/fileless-uac-bypass-using-sdclt-exe/ - -* https://github.com/hfiref0x/UACME - -* https://www.cyborgsecurity.com/cyborg_labs/threat-hunt-deep-dives-user-account-control-bypass-via-registry-modification/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/uac_bypass/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Sdelete application execution=== -This analytic is to detect the execution of sdelete.exe application sysinternal tools. This tool is one of the most use tool of malware and adversaries to remove or clear their tracks and artifact in the targetted host. This tool is designed to delete securely a file in file system that remove the forensic evidence on the machine. A good TTP query to check why user execute this application which is not a common practice. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1485/ T1485], [https://attack.mitre.org/techniques/T1070/004/ T1070.004], [https://attack.mitre.org/techniques/T1070/ T1070] -* '''Last Updated''': 2021-10-06 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` values(Processes.process) as process values(Processes.parent_process) as parent_process values(Processes.process_id) as process_id count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_sdelete` by Processes.process_name Processes.original_file_name Processes.dest Processes.user Processes.parent_process_name Processes.parent_process -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `sdelete_application_execution_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Masquerading_-_Rename_System_Utilities|Masquerading - Rename System Utilities]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1485 -| Data Destruction -| Impact -|- -| T1070.004 -| File Deletion -| Defense Evasion -|- -| T1070 -| Indicator Removal on Host -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -user may execute and use this application - -====Reference==== - - -* https://app.any.run/tasks/956f50be-2c13-465a-ac00-6224c14c5f89/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/sdelete/sysmon.log - - -''version'': 1 -
-
- ----- - -===Searchprotocolhost with no command line with network=== -The following analytic identifies searchprotocolhost.exe with no command line arguments and with a network connection. It is unusual for searchprotocolhost.exe to execute with no command line arguments present. This particular behavior is common with malicious software, including Cobalt Strike. During investigation, identify any network connections and parallel processes. Identify any suspicious module loads related to credential dumping or file writes. searchprotocolhost.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1055/ T1055] -* '''Last Updated''': 2021-10-13 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name=searchprotocolhost.exe by _time span=1h Processes.process_guid Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| regex process="(searchprotocolhost\.exe.{0,4}$)" -| join process_guid [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Ports where Ports.dest_port !="0" by Ports.process_guid Ports.dest Ports.dest_port -| `drop_dm_object_name(Ports)` -| rename dest as connection_to_CNC] -| table _time dest parent_process_name process_name process_path process process_guid connection_to_CNC dest_port -| `searchprotocolhost_with_no_command_line_with_network_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Cobalt_Strike|Cobalt Strike]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` and `ports` node. - -====Required field==== - -* _time - -* process_name - -* process_id - -* parent_process_name - -* dest_port - -* process_path - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1055 -| Process Injection -| Defense Evasion, Privilege Escalation -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Limited false positives may be present in small environments. Tuning may be required based on parent process. - -====Reference==== - - -* https://github.com/fireeye/red_team_tool_countermeasures/blob/master/rules/PGF/supplemental/hxioc/SUSPICIOUS%20EXECUTION%20OF%20SEARCHPROTOCOLHOST%20(METHODOLOGY).ioc - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon_searchprotocolhost.log - - -''version'': 2 -
-
- ----- - -===Secretdumps offline ntds dumping tool=== -This analytic detects a potential usage of secretsdump.py tool for dumping credentials (ntlm hash) from a copy of ntds.dit and SAM.Security,SYSTEM registrry hive. This technique was seen in some attacker that dump ntlm hashes offline after having a copy of ntds.dit and SAM/SYSTEM/SECURITY registry hive. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/003/ T1003.003], [https://attack.mitre.org/techniques/T1003/ T1003] -* '''Last Updated''': 2021-05-26 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = "python*.exe" Processes.process = "*.py*" Processes.process = "*-ntds*" (Processes.process = "*-system*" OR Processes.process = "*-sam*" OR Processes.process = "*-security*" OR Processes.process = "*-bootkey*") by Processes.process_name Processes.process Processes.parent_process_name Processes.parent_process Processes.dest Processes.user Processes.process_id Processes.process_guid -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `secretdumps_offline_ntds_dumping_tool_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Credential_Dumping|Credential Dumping]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -====Required field==== - -* _time - -* Processes.process_name - -* Processes.process - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.dest - -* Processes.user - -* Processes.process_id - -* Processes.process_guid - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1003.003 -| NTDS -| Credential Access -|- -| T1003 -| OS Credential Dumping -| Credential Access -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://github.com/SecureAuthCorp/impacket/blob/master/examples/secretsdump.py - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/casper/datasets1/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Serviceprincipalnames discovery with powershell=== -The following analytic identifies `powershell.exe` usage, using Script Block Logging EventCode 4104, related to querying the domain for Service Principle Names. typically, this is a precursor activity related to kerberoasting or the silver ticket attack. \ -What is a ServicePrincipleName? \ -A service principal name (SPN) is a unique identifier of a service instance. SPNs are used by Kerberos authentication to associate a service instance with a service logon account. This allows a client application to request that the service authenticate an account even if the client does not have the account name.\ -The following analytic identifies the use of KerberosRequestorSecurityToken class within the script block. Using .NET System.IdentityModel.Tokens.KerberosRequestorSecurityToken class in PowerShell is the equivelant of using setspn.exe. \ -During triage, review parallel processes for further suspicious activity. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1558/003/ T1558.003] -* '''Last Updated''': 2021-10-14 - -
-
- -====Search==== -`powershell` EventCode=4104 Message="*KerberosRequestorSecurityToken*" -| stats count min(_time) as firstTime max(_time) as lastTime by Message OpCode ComputerName User EventCode -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `serviceprincipalnames_discovery_with_powershell_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - -* [[Documentation:ESSOC:stories:UseCase#Lateral_Movement|Lateral Movement]] - - -====How To Implement==== -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1558.003 -| Kerberoasting -| Credential Access -|} - - -====Kill Chain Phase==== - -* Lateral Movement - - -====Known False Positives==== -False positives should be limited, however filter as needed. - -====Reference==== - - -* https://docs.microsoft.com/en-us/windows/win32/ad/service-principal-names - -* https://docs.microsoft.com/en-us/dotnet/api/system.identitymodel.tokens.kerberosrequestorsecuritytoken?view=netframework-4.8 - -* https://www.ired.team/offensive-security-experiments/active-directory-kerberos-abuse/t1208-kerberoasting - -* https://strontic.github.io/xcyclopedia/library/setspn.exe-5C184D581524245DAD7A0A02B51FD2C2.html - -* https://attack.mitre.org/techniques/T1558/003/ - -* https://social.technet.microsoft.com/wiki/contents/articles/717.service-principal-names-spn-setspn-syntax.aspx - -* https://www.harmj0y.net/blog/powershell/kerberoasting-without-mimikatz/ - -* https://blog.zsec.uk/paving-2-da-wholeset/ - -* https://msitpros.com/?p=3113 - -* https://adsecurity.org/?p=3466 - -* https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -* https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63 - -* https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf - -* https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1558.003/atomic_red_team/windows-powershell_kerberos.log - - -''version'': 1 -
-
- ----- - -===Serviceprincipalnames discovery with setspn=== -The following analytic identifies `setspn.exe` usage related to querying the domain for Service Principle Names. typically, this is a precursor activity related to kerberoasting or the silver ticket attack. \ -What is a ServicePrincipleName? \ -A service principal name (SPN) is a unique identifier of a service instance. SPNs are used by Kerberos authentication to associate a service instance with a service logon account. This allows a client application to request that the service authenticate an account even if the client does not have the account name.\ -Example usage includes the following \ -1. setspn -T offense -Q */* 1. setspn -T attackrange.local -F -Q MSSQLSvc/* 1. setspn -Q */* > allspns.txt 1. setspn -q \ -Values \ -1. -F = perform queries at the forest, rather than domain level 1. -T = perform query on the specified domain or forest (when -F is also used) 1. -Q = query for existence of SPN \ -During triage, review parallel processes for further suspicious activity. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1558/003/ T1558.003] -* '''Last Updated''': 2021-10-14 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_setspn` (Processes.process="*-t*" AND Processes.process="*-f*") OR (Processes.process="*-q*" AND Processes.process="**/**") OR (Processes.process="*-q*") OR (Processes.process="*-s*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `serviceprincipalnames_discovery_with_setspn_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - -* [[Documentation:ESSOC:stories:UseCase#Lateral_Movement|Lateral Movement]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1558.003 -| Kerberoasting -| Credential Access -|} - - -====Kill Chain Phase==== - -* Lateral Movement - - -====Known False Positives==== -False positives may be caused by Administrators resetting SPNs or querying for SPNs. Filter as needed. - -====Reference==== - - -* https://docs.microsoft.com/en-us/windows/win32/ad/service-principal-names - -* https://www.ired.team/offensive-security-experiments/active-directory-kerberos-abuse/t1208-kerberoasting - -* https://strontic.github.io/xcyclopedia/library/setspn.exe-5C184D581524245DAD7A0A02B51FD2C2.html - -* https://attack.mitre.org/techniques/T1558/003/ - -* https://social.technet.microsoft.com/wiki/contents/articles/717.service-principal-names-spn-setspn-syntax.aspx - -* https://www.harmj0y.net/blog/powershell/kerberoasting-without-mimikatz/ - -* https://blog.zsec.uk/paving-2-da-wholeset/ - -* https://msitpros.com/?p=3113 - -* https://adsecurity.org/?p=3466 - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1558.003/atomic_red_team/windows-sysmon_setspn.log - - -''version'': 1 -
-
- ----- - -===Services escalate exe=== -The following analytic identifies the use of `svc-exe` with Cobalt Strike. The behavior typically follows after an adversary has already gained initial access and is escalating privileges. Using `svc-exe`, a randomly named binary will be downloaded from the remote Teamserver and placed on disk within `C:\Windows\400619a.exe`. Following, the binary will be added to the registry under key `HKLM\System\CurrentControlSet\Services\400619a\` with multiple keys and values added to look like a legitimate service. Upon loading, `services.exe` will spawn the randomly named binary from `\\127.0.0.1\ADMIN$\400619a.exe`. The process lineage is completed with `400619a.exe` spawning rundll32.exe, which is the default `spawnto_` value for Cobalt Strike. The `spawnto_` value is arbitrary and may be any process on disk (typically system32/syswow64 binary). The `spawnto_` process will also contain a network connection. During triage, review parallel procesess and identify any additional file modifications. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1548/ T1548] -* '''Last Updated''': 2021-05-18 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=services.exe Processes.process_path=*admin$* by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `services_escalate_exe_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Cobalt_Strike|Cobalt Strike]] - - -====How To Implement==== -To successfully implement this search, you will need to ensure that DNS data is populating the Network_Resolution data model. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1548 -| Abuse Elevation Control Mechanism -| Privilege Escalation, Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - -* Privilege Escalation - - -====Known False Positives==== -False positives should be limited as `services.exe` should never spawn a process from `ADMIN$`. Filter as needed. - -====Reference==== - - -* https://thedfirreport.com/2021/03/29/sodinokibi-aka-revil-ransomware/ - -* https://attack.mitre.org/techniques/T1548/ - -* https://www.cobaltstrike.com/help-beacon - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Set default powershell execution policy to unrestricted or bypass=== -Monitor for changes of the ExecutionPolicy in the registry to the values "unrestricted" or "bypass," which allows the execution of malicious scripts. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/ T1059], [https://attack.mitre.org/techniques/T1059/001/ T1059.001] -* '''Last Updated''': 2020-11-06 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path=*Software\\Microsoft\\Powershell\\1\\ShellIds\\Microsoft.PowerShell* Registry.registry_key_name=ExecutionPolicy (Registry.registry_value_name=Unrestricted OR Registry.registry_value_name=Bypass) by Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.dest -| `drop_dm_object_name(Registry)` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -| `set_default_powershell_execution_policy_to_unrestricted_or_bypass_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Malicious_PowerShell|Malicious PowerShell]] - -* [[Documentation:ESSOC:stories:UseCase#Credential_Dumping|Credential Dumping]] - -* [[Documentation:ESSOC:stories:UseCase#HAFNIUM_Group|HAFNIUM Group]] - - -====How To Implement==== -You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Registry node. You must also be ingesting logs with the fields registry_path, registry_key_name, and registry_value_name from your endpoints. - -====Required field==== - -* _time - -* Registry.registry_path - -* Registry.registry_key_name - -* Registry.registry_value_name - -* Registry.dest - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1059 -| Command and Scripting Interpreter -| Execution -|- -| T1059.001 -| PowerShell -| Execution -|} - - -====Kill Chain Phase==== - -* Installation - -* Actions on Objectives - - -====Known False Positives==== -Administrators may attempt to change the default execution policy on a system for a variety of reasons. However, setting the policy to "unrestricted" or "bypass" as this search is designed to identify, would be unusual. Hits should be reviewed and investigated as appropriate. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_execution_policy/windows-sysmon.log - - -''version'': 6 -
-
- ----- - -===Setting credentials via dsinternals modules=== -This detection identifies illegal setting of credentials via DSInternals modules. - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1068/ T1068], [https://attack.mitre.org/techniques/T1078/ T1078], [https://attack.mitre.org/techniques/T1098/ T1098] -* '''Last Updated''': 2020-11-03 - -
-
- -====Search==== - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), "string", null), cmd_line=ucast(map_get(input_event, "process"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)Add-ADDBSidHistory/)=true OR match_regex(cmd_line, /(?i)Add-ADReplNgcKey/)=true OR match_regex(cmd_line, /(?i)Set-ADDBAccountPassword/)=true OR match_regex(cmd_line, /(?i)Set-ADDBAccountPasswordHash/)=true OR match_regex(cmd_line, /(?i)Set-ADDBBootKey/)=true OR match_regex(cmd_line, /(?i)Set-SamAccountPasswordHash/)=true OR match_regex(cmd_line, /(?i)Set-AzureADUserEx/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Persistence_Techniques|Windows Persistence Techniques]] - - -====How To Implement==== -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -====Required field==== - -* dest_device_id - -* process_name - -* parent_process_name - -* _time - -* process_path - -* dest_user_id - -* process - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1068 -| Exploitation for Privilege Escalation -| Privilege Escalation -|- -| T1078 -| Valid Accounts -| Defense Evasion, Persistence, Privilege Escalation, Initial Access -|- -| T1098 -| Account Manipulation -| Persistence -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -None identified. - -====Reference==== - - -* https://github.com/MichaelGrafnetter/DSInternals - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/account_manipulation/logAllDSInternalsModules.log - - -''version'': 1 -
-
- ----- - -===Setting credentials via mimikatz modules=== -This detection identifies illegal setting of credentials via Mimikatz modules. - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1068/ T1068], [https://attack.mitre.org/techniques/T1078/ T1078], [https://attack.mitre.org/techniques/T1098/ T1098] -* '''Last Updated''': 2020-11-03 - -
-
- -====Search==== - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)misc::addsid/)=true OR match_regex(cmd_line, /(?i)CRYPTO::scauth/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Persistence_Techniques|Windows Persistence Techniques]] - - -====How To Implement==== -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -====Required field==== - -* dest_device_id - -* dest_user_id - -* process - -* _time - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1068 -| Exploitation for Privilege Escalation -| Privilege Escalation -|- -| T1078 -| Valid Accounts -| Defense Evasion, Persistence, Privilege Escalation, Initial Access -|- -| T1098 -| Account Manipulation -| Persistence -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -None identified. - -====Reference==== - - -* https://github.com/gentilkiwi/mimikatz - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/account_manipulation/logAllMimikatzModules.log - - -''version'': 1 -
-
- ----- - -===Setting credentials via powersploit modules=== -This detection identifies illegal setting of credentials via PowerSploit modules. - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1068/ T1068], [https://attack.mitre.org/techniques/T1078/ T1078], [https://attack.mitre.org/techniques/T1098/ T1098] -* '''Last Updated''': 2020-11-03 - -
-
- -====Search==== - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)Set-DomainUserPassword/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Persistence_Techniques|Windows Persistence Techniques]] - - -====How To Implement==== -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -====Required field==== - -* dest_device_id - -* dest_user_id - -* process - -* _time - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1068 -| Exploitation for Privilege Escalation -| Privilege Escalation -|- -| T1078 -| Valid Accounts -| Defense Evasion, Persistence, Privilege Escalation, Initial Access -|- -| T1098 -| Account Manipulation -| Persistence -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -None identified. - -====Reference==== - - -* https://github.com/PowerShellMafia/PowerSploit - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/account_manipulation/logAllPowerSploitModulesWithOldNames.log - - -''version'': 1 -
-
- ----- - -===Shim database file creation=== -This search looks for shim database files being written to default directories. The sdbinst.exe application is used to install shim database files (.sdb). According to Microsoft, a shim is a small library that transparently intercepts an API, changes the parameters passed, handles the operation itself, or redirects the operation elsewhere. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1546/011/ T1546.011], [https://attack.mitre.org/techniques/T1546/ T1546] -* '''Last Updated''': 2020-12-08 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count values(Filesystem.action) values(Filesystem.file_hash) as file_hash values(Filesystem.file_path) as file_path min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_path=*Windows\\AppPatch\\Custom* by Filesystem.file_name Filesystem.dest -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -|`drop_dm_object_name(Filesystem)` -| `shim_database_file_creation_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Persistence_Techniques|Windows Persistence Techniques]] - - -====How To Implement==== -You must be ingesting data that records the filesystem activity from your hosts to populate the Endpoint file-system data model node. If you are using Sysmon, you will need a Splunk Universal Forwarder on each endpoint from which you want to collect data. - -====Required field==== - -* _time - -* Filesystem.file_hash - -* Filesystem.file_path - -* Filesystem.file_name - -* Filesystem.dest - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1546.011 -| Application Shimming -| Privilege Escalation, Persistence -|- -| T1546 -| Event Triggered Execution -| Privilege Escalation, Persistence -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Because legitimate shim files are created and used all the time, this event, in itself, is not suspicious. However, if there are other correlating events, it may warrant further investigation. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.011/atomic_red_team/windows-sysmon.log - - -''version'': 3 -
-
- ----- - -===Shim database installation with suspicious parameters=== -This search detects the process execution and arguments required to silently create a shim database. The sdbinst.exe application is used to install shim database files (.sdb). A shim is a small library which transparently intercepts an API, changes the parameters passed, handles the operation itself, or redirects the operation elsewhere. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1546/011/ T1546.011], [https://attack.mitre.org/techniques/T1546/ T1546] -* '''Last Updated''': 2020-11-23 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = sdbinst.exe by Processes.process_name Processes.parent_process_name Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `shim_database_installation_with_suspicious_parameters_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Persistence_Techniques|Windows Persistence Techniques]] - - -====How To Implement==== -You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. - -====Required field==== - -* _time - -* Processes.process_name - -* Processes.parent_process_name - -* Processes.dest - -* Processes.user - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1546.011 -| Application Shimming -| Privilege Escalation, Persistence -|- -| T1546 -| Event Triggered Execution -| Privilege Escalation, Persistence -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -None identified - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.011/atomic_red_team/windows-sysmon.log - - -''version'': 4 -
-
- ----- - -===Short lived windows accounts=== -This search detects accounts that were created and deleted in a short time period. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Change -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1136/001/ T1136.001], [https://attack.mitre.org/techniques/T1136/ T1136] -* '''Last Updated''': 2020-07-06 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` values(All_Changes.result_id) as result_id count min(_time) as firstTime max(_time) as lastTime from datamodel=Change where All_Changes.result_id=4720 OR All_Changes.result_id=4726 by _time span=4h All_Changes.user All_Changes.dest -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `drop_dm_object_name("All_Changes")` -| search result_id = 4720 result_id=4726 -| transaction user connected=false maxspan=240m -| table firstTime lastTime count user dest result_id -| `short_lived_windows_accounts_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Account_Monitoring_and_Controls|Account Monitoring and Controls]] - - -====How To Implement==== -This search requires you to have enabled your Group Management Audit Logs in your Local Windows Security Policy and be ingesting those logs. More information on how to enable them can be found here: http://whatevernetworks.com/auditing-group-membership-changes-in-active-directory/ - -====Required field==== - -* _time - -* All_Changes.result_id - -* All_Changes.user - -* All_Changes.dest - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1136.001 -| Local Account -| Persistence -|- -| T1136 -| Create Account -| Persistence -|} - - -====Kill Chain Phase==== - - -====Known False Positives==== -It is possible that an administrator created and deleted an account in a short time period. Verifying activity with an administrator is advised. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.001/atomic_red_team/windows-security.log - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.001/atomic_red_team/windows-system.log - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.001/atomic_red_team/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Silentcleanup uac bypass=== -This search is to detect a suspicious modification of registry that may related to UAC bypassed. This registry will be trigger once the attacker abuse the silentcleanup task schedule to gain high privilege execution that will bypass User control account. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1548/002/ T1548.002], [https://attack.mitre.org/techniques/T1548/ T1548] -* '''Last Updated''': 2021-07-01 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*\\Environment\\windir" Registry.registry_value_name = "*.exe*" by Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.dest -| `drop_dm_object_name(Registry)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `silentcleanup_uac_bypass_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Defense_Evasion_Tactics|Windows Defense Evasion Tactics]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. - -====Required field==== - -* _time - -* Registry.registry_path - -* Registry.registry_key_name - -* Registry.registry_value_name - -* Registry.dest - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1548.002 -| Bypass User Account Control -| Privilege Escalation, Defense Evasion -|- -| T1548 -| Abuse Elevation Control Mechanism -| Privilege Escalation, Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://github.com/hfiref0x/UACME - -* https://www.intezer.com/blog/malware-analysis/klingon-rat-holding-on-for-dear-life/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/uac_bypass/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Single letter process on endpoint=== -This search looks for process names that consist only of a single letter. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1204/ T1204], [https://attack.mitre.org/techniques/T1204/002/ T1204.002] -* '''Last Updated''': 2020-12-08 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes by Processes.dest, Processes.user, Processes.process, Processes.process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| eval process_name_length = len(process_name), endExe = if(substr(process_name, -4) == ".exe", 1, 0) -| search process_name_length=5 AND endExe=1 -| table count, firstTime, lastTime, dest, user, process, process_name -| `single_letter_process_on_endpoint_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#DHS_Report_TA18-074A|DHS Report TA18-074A]] - - -====How To Implement==== -You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.process - -* Processes.process_name - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1204 -| User Execution -| Execution -|- -| T1204.002 -| Malicious File -| Execution -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Single-letter executables are not always malicious. Investigate this activity with your normal incident-response process. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1204.002/single_letter_exe/windows-sysmon.log - - -''version'': 3 -
-
- ----- - -===Spike in file writes=== -The search looks for a sharp increase in the number of files written to a particular host - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': -* '''Last Updated''': 2020-03-16 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Filesystem where Filesystem.action=created by _time span=1h, Filesystem.dest -| `drop_dm_object_name(Filesystem)` -| eventstats max(_time) as maxtime -| stats count as num_data_samples max(eval(if(_time >= relative_time(maxtime, "-1d@d"), count, null))) as "count" avg(eval(if(_time<relative_time(maxtime, "-1d@d"), count,null))) as avg stdev(eval(if(_time<relative_time(maxtime, "-1d@d"), count, null))) as stdev by "dest" -| eval upperBound=(avg+stdev*4), isOutlier=if((count > upperBound) AND num_data_samples >=20, 1, 0) -| search isOutlier=1 -| `spike_in_file_writes_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#SamSam_Ransomware|SamSam Ransomware]] - -* [[Documentation:ESSOC:stories:UseCase#Ryuk_Ransomware|Ryuk Ransomware]] - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - - -====How To Implement==== -In order to implement this search, you must populate the Endpoint file-system data model node. This is typically populated via endpoint detection and response product, such as Carbon Black or endpoint data sources such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the file system. - -====Required field==== - -* _time - -* Filesystem.action - -* Filesystem.dest - - - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -It is important to understand that if you happen to install any new applications on your hosts or are copying a large number of files, you can expect to see a large increase of file modifications. - -====Reference==== - - -====Test Dataset==== - - -''version'': 3 -
-
- ----- - -===Spoolsv spawning rundll32=== -The following analytic identifies a suspicious child process, `rundll32.exe`, with no command-line arguments being spawned from `spoolsv.exe`. This was identified during our testing of CVE-2021-34527 previously (CVE-2021-1675) or PrintNightmare. Typically, this is not normal behavior for `spoolsv.exe` to spawn a process. During triage, isolate the endpoint and review for source of exploitation. Capture any additional file modification events. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1547/012/ T1547.012], [https://attack.mitre.org/techniques/T1547/ T1547] -* '''Last Updated''': 2021-07-01 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=spoolsv.exe `process_rundll32` by Processes.dest Processes.user Processes.parent_process Processes.original_file_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `spoolsv_spawning_rundll32_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#PrintNightmare_CVE-2021-34527|PrintNightmare CVE-2021-34527]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1547.012 -| Print Processors -| Persistence, Privilege Escalation -|- -| T1547 -| Boot or Logon Autostart Execution -| Persistence, Privilege Escalation -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Limited false positives have been identified. There are limited instances where `rundll32.exe` may be spawned by a legitimate print driver. - -====Reference==== - - -* https://blog.truesec.com/2021/06/30/fix-for-printnightmare-cve-2021-1675-exploit-to-keep-your-print-servers-running-while-a-patch-is-not-available/ - -* https://blog.truesec.com/2021/06/30/exploitable-critical-rce-vulnerability-allows-regular-users-to-fully-compromise-active-directory-printnightmare-cve-2021-1675/ - -* https://www.reddit.com/r/msp/comments/ob6y02/critical_vulnerability_printnightmare_exposes - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.012/printnightmare/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Spoolsv suspicious loaded modules=== -This search is to detect suspicious loading of dll in specific path relative to printnightmare exploitation. In this search we try to detect the loaded modules made by spoolsv.exe after the exploitation. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1547/012/ T1547.012], [https://attack.mitre.org/techniques/T1547/ T1547] -* '''Last Updated''': 2021-07-01 - -
-
- -====Search==== -`sysmon` EventCode=7 Image ="*\\spoolsv.exe" ImageLoaded="*\\Windows\\System32\\spool\\drivers\\x64\\*" ImageLoaded = "*.dll" -| stats dc(ImageLoaded) as countImgloaded values(ImageLoaded) as ImgLoaded count min(_time) as firstTime max(_time) as lastTime by Image Computer process_id EventCode -| where countImgloaded >= 3 -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `spoolsv_suspicious_loaded_modules_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#PrintNightmare_CVE-2021-34527|PrintNightmare CVE-2021-34527]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name and imageloaded executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -====Required field==== - -* _time - -* Image - -* Computer - -* EventCode - -* ImageLoaded - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1547.012 -| Print Processors -| Persistence, Privilege Escalation -|- -| T1547 -| Boot or Logon Autostart Execution -| Persistence, Privilege Escalation -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://raw.githubusercontent.com/hieuttmmo/sigma/dceb13fe3f1821b119ae495b41e24438bd97e3d0/rules/windows/image_load/sysmon_cve_2021_1675_print_nightmare.yml - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.012/printnightmare/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Spoolsv suspicious process access=== -This analytic identifies a suspicious behavior related to PrintNightmare, or CVE-2021-34527 previously (CVE-2021-1675), to gain privilege escalation on the vulnerable machine. This exploit attacks a critical Windows Print Spooler Vulnerability to elevate privilege. This detection is to look for suspicious process access made by the spoolsv.exe that may related to the attack. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1068/ T1068] -* '''Last Updated''': 2021-07-01 - -
-
- -====Search==== -`sysmon` EventCode=10 SourceImage = "*\\spoolsv.exe" CallTrace = "*\\Windows\\system32\\spool\\DRIVERS\\x64\\*" TargetImage IN ("*\\rundll32.exe", "*\\spoolsv.exe") GrantedAccess = 0x1fffff -| stats count min(_time) as firstTime max(_time) as lastTime by Computer SourceImage TargetImage GrantedAccess CallTrace EventCode ProcessID -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `spoolsv_suspicious_process_access_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#PrintNightmare_CVE-2021-34527|PrintNightmare CVE-2021-34527]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with process access event where SourceImage, TargetImage, GrantedAccess and CallTrace executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances of spoolsv.exe. - -====Required field==== - -* _time - -* SourceImage - -* TargetImage - -* GrantedAccess - -* CallTrace - -* EventCode - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1068 -| Exploitation for Privilege Escalation -| Privilege Escalation -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Unknown. Filter as needed. - -====Reference==== - - -* https://github.com/cube0x0/impacket/commit/73b9466c17761384ece11e1028ec6689abad6818 - -* https://blog.truesec.com/2021/06/30/fix-for-printnightmare-cve-2021-1675-exploit-to-keep-your-print-servers-running-while-a-patch-is-not-available/ - -* https://blog.truesec.com/2021/06/30/exploitable-critical-rce-vulnerability-allows-regular-users-to-fully-compromise-active-directory-printnightmare-cve-2021-1675/ - -* https://www.reddit.com/r/msp/comments/ob6y02/critical_vulnerability_printnightmare_exposes - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.012/printnightmare/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Spoolsv writing a dll=== -The following analytic identifies a `.dll` being written by `spoolsv.exe`. This was identified during our testing of CVE-2021-34527 previously (CVE-2021-1675) or PrintNightmare. Typically, this is not normal behavior for `spoolsv.exe` to write a `.dll`. Current POC code used will write the suspicious DLL to disk within a path of `\spool\drivers\x64\`. During triage, isolate the endpoint and review for source of exploitation. Capture any additional file modification events. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1547/012/ T1547.012], [https://attack.mitre.org/techniques/T1547/ T1547] -* '''Last Updated''': 2021-07-01 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name=spoolsv.exe by _time Processes.process_id Processes.process_name Processes.dest -| `drop_dm_object_name(Processes)` -| join process_guid, _time [ -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_path="*\\spool\\drivers\\x64\\*" Filesystem.file_name="*.dll" by _time Filesystem.dest Filesystem.file_create_time Filesystem.file_name Filesystem.file_path -| `drop_dm_object_name(Filesystem)` -| fields _time dest file_create_time file_name file_path process_name process_path process] -| dedup file_create_time -| table dest file_create_time, file_name, file_path, process_name -| `spoolsv_writing_a_dll_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#PrintNightmare_CVE-2021-34527|PrintNightmare CVE-2021-34527]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node and `Filesystem` node. - -====Required field==== - -* _time - -* Filesystem.dest - -* Filesystem.file_create_time - -* Filesystem.file_name - -* Filesystem.file_path - -* Processes.process_name - -* Processes.process_id - -* Processes.process_name - -* Processes.dest - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1547.012 -| Print Processors -| Persistence, Privilege Escalation -|- -| T1547 -| Boot or Logon Autostart Execution -| Persistence, Privilege Escalation -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Unknown. - -====Reference==== - - -* https://blog.truesec.com/2021/06/30/fix-for-printnightmare-cve-2021-1675-exploit-to-keep-your-print-servers-running-while-a-patch-is-not-available/ - -* https://blog.truesec.com/2021/06/30/exploitable-critical-rce-vulnerability-allows-regular-users-to-fully-compromise-active-directory-printnightmare-cve-2021-1675/ - -* https://www.reddit.com/r/msp/comments/ob6y02/critical_vulnerability_printnightmare_exposes - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.012/printnightmare/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Spoolsv writing a dll - sysmon=== -The following analytic identifies a `.dll` being written by `spoolsv.exe`. This was identified during our testing of CVE-2021-34527 previously(CVE-2021-1675) or PrintNightmare. Typically, this is not normal behavior for `spoolsv.exe` to write a `.dll`. Current POC code used will write the suspicious DLL to disk within a path of `\spool\drivers\x64\`. During triage, isolate the endpoint and review for source of exploitation. Capture any additional file modification events. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1547/012/ T1547.012], [https://attack.mitre.org/techniques/T1547/ T1547] -* '''Last Updated''': 2021-07-01 - -
-
- -====Search==== -`sysmon` EventID=11 process_name=spoolsv.exe file_path="*\\spool\\drivers\\x64\\*" file_name=*.dll -| stats count min(_time) as firstTime max(_time) as lastTime by dest, UserID, process_name, file_path, file_name, TargetFilename, process_id -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `spoolsv_writing_a_dll___sysmon_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#PrintNightmare_CVE-2021-34527|PrintNightmare CVE-2021-34527]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed rundll32.exe may be used. - -====Required field==== - -* _time - -* dest - -* UserID - -* process_name - -* file_path - -* file_name - -* TargetFilename - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1547.012 -| Print Processors -| Persistence, Privilege Escalation -|- -| T1547 -| Boot or Logon Autostart Execution -| Persistence, Privilege Escalation -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Limited false positives. Filter as needed. - -====Reference==== - - -* https://github.com/cube0x0/impacket/commit/73b9466c17761384ece11e1028ec6689abad6818 - -* https://blog.truesec.com/2021/06/30/fix-for-printnightmare-cve-2021-1675-exploit-to-keep-your-print-servers-running-while-a-patch-is-not-available/ - -* https://blog.truesec.com/2021/06/30/exploitable-critical-rce-vulnerability-allows-regular-users-to-fully-compromise-active-directory-printnightmare-cve-2021-1675/ - -* https://www.reddit.com/r/msp/comments/ob6y02/critical_vulnerability_printnightmare_exposes - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.012/printnightmare/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Sqlite module in temp folder=== -This search is to detect a suspicious file creation of sqlite3.dll in %temp% folder. This behavior was seen in IcedID malware where it download sqlite module to parse browser database like for chrome or firefox to stole browser information related to bank, credit card or credentials. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1005/ T1005] -* '''Last Updated''': 2021-08-03 - -
-
- -====Search==== -`sysmon` EventCode=11 (TargetFilename = "*\\sqlite32.dll" OR TargetFilename = "*\\sqlite64.dll") (TargetFilename = "*\\temp\\*") -|stats count min(_time) as firstTime max(_time) as lastTime by process_name TargetFilename EventCode ProcessId Image -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `sqlite_module_in_temp_folder_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#IcedID|IcedID]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -====Required field==== - -* _time - -* process_name - -* TargetFilename - -* EventCode - -* ProcessId - -* Image - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1005 -| Data from Local System -| Collection -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://www.cisecurity.org/white-papers/security-primer-icedid/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/simulated_icedid/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Start up during safe mode boot=== -This search is to detect a modification or registry add to the safeboot registry as an autostart mechanism. This technique was seen in some ransomware to automatically execute its code upon a safe mode boot. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1547/001/ T1547.001], [https://attack.mitre.org/techniques/T1547/ T1547] -* '''Last Updated''': 2021-06-10 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*\\System\\CurrentControlSet\\Control\\SafeBoot\\Minimal\*" by Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.dest -| `drop_dm_object_name(Registry)` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -| `start_up_during_safe_mode_boot_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - - -====How To Implement==== -To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. - -====Required field==== - -* _time - -* Registry.registry_path - -* Registry.registry_key_name - -* Registry.registry_value_name - -* Registry.dest - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1547.001 -| Registry Run Keys / Startup Folder -| Persistence, Privilege Escalation -|- -| T1547 -| Boot or Logon Autostart Execution -| Persistence, Privilege Escalation -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -updated windows application needed in safe boot may used this registry - -====Reference==== - - -* https://malware.news/t/threat-analysis-unit-tau-threat-intelligence-notification-snatch-ransomware/36365 - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/data1/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Sunburst correlation dll and network event=== -The malware sunburst will load the malicious dll by SolarWinds.BusinessLayerHost.exe. After a period of 12-14 days, the malware will attempt to resolve a subdomain of avsvmcloud.com. This detections will correlate both events. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1203/ T1203] -* '''Last Updated''': 2020-12-14 - -
-
- -====Search==== -(`sysmon` EventCode=7 ImageLoaded=*SolarWinds.Orion.Core.BusinessLayer.dll) OR (`sysmon` EventCode=22 QueryName=*avsvmcloud.com) -| eventstats dc(EventCode) AS dc_events -| where dc_events=2 -| stats min(_time) as firstTime max(_time) as lastTime values(ImageLoaded) AS ImageLoaded values(QueryName) AS QueryName by host -| rename host as dest -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `sunburst_correlation_dll_and_network_event_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#NOBELIUM_Group|NOBELIUM Group]] - - -====How To Implement==== -This detection relies on sysmon logs with the Event ID 7, Driver loaded. Please tune your sysmon config that you DriverLoad event for SolarWinds.Orion.Core.BusinessLayer.dll is captured by Sysmon. Additionally, you need sysmon logs for Event ID 22, DNS Query. We suggest to run this detection at least once a day over the last 14 days. - -====Required field==== - -* _time - -* EventCode - -* ImageLoaded - -* QueryName - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1203 -| Exploitation for Client Execution -| Execution -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://www.fireeye.com/blog/threat-research/2020/12/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor.html - - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Suspicious copy on system32=== -This analytic is to detect a suspicious copy of file from systemroot folder of the windows OS. This technique is commonly used by APT or other malware as part of execution (LOLBIN) to run its malicious code using the available legitimate tool in OS. this type of event may seen or may execute of normal user in some instance but this is really a anomaly that needs to be check within the network. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1036/003/ T1036.003], [https://attack.mitre.org/techniques/T1036/ T1036] -* '''Last Updated''': 2021-10-05 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name IN("cmd.exe", "powershell*","pwsh.exe", "sqlps.exe", "sqltoolsps.exe", "powershell_ise.exe") AND `process_copy` AND Processes.process IN("*\\Windows\\System32\*", "*\\Windows\\SysWow64\\*") AND Processes.process = "*copy*" by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `suspicious_copy_on_system32_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Unusual_Processes|Unusual Processes]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1036.003 -| Rename System Utilities -| Defense Evasion -|- -| T1036 -| Masquerading -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -every user may do this event but very un-ussual. - -====Reference==== - - -* https://www.hybrid-analysis.com/sample/8da5b75b6380a41eee3a399c43dfe0d99eeefaa1fd21027a07b1ecaa4cd96fdd?environmentId=120 - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036.003/copy_sysmon/sysmon.log - - -''version'': 1 -
-
- ----- - -===Suspicious curl network connection=== -The following analytic identifies the use of a curl contacting suspicious remote domains to checkin to command and control servers or download further implants. In the context of Silver Sparrow, curl is identified contacting s3.amazonaws.com. This particular behavior is common with MacOS adware-malicious software. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1105/ T1105] -* '''Last Updated''': 2021-02-22 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=curl Processes.process=s3.amazonaws.com by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `suspicious_curl_network_connection_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Silver_Sparrow|Silver Sparrow]] - -* [[Documentation:ESSOC:stories:UseCase#Ingress_Tool_Transfer|Ingress Tool Transfer]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* _time - -* Processes.process_name - -* Processes.process - -* Processes.dest - -* Processes.user - -* Processes.parent_process - -* Processes.process_id - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1105 -| Ingress Tool Transfer -| Command And Control -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Unknown. Filter as needed. - -====Reference==== - - -* https://redcanary.com/blog/clipping-silver-sparrows-wings/ - -* https://marcosantadev.com/manage-plist-files-plistbuddy/ - - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Suspicious dllhost no command line arguments=== -The following analytic identifies DLLHost.exe with no command line arguments. It is unusual for DLLHost.exe to execute with no command line arguments present. This particular behavior is common with malicious software, including Cobalt Strike. During investigation, identify any network connections and parallel processes. Identify any suspicious module loads related to credential dumping or file writes. DLLHost.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1055/ T1055] -* '''Last Updated''': 2021-09-20 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where `process_dllhost` by _time span=1h Processes.process_id Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| regex process="(dllhost\.exe.{0,4}$)" -| `suspicious_dllhost_no_command_line_arguments_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Cobalt_Strike|Cobalt Strike]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1055 -| Process Injection -| Defense Evasion, Privilege Escalation -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Limited false positives may be present in small environments. Tuning may be required based on parent process. - -====Reference==== - - -* https://raw.githubusercontent.com/threatexpress/malleable-c2/c3385e481159a759f79b8acfe11acf240893b830/jquery-c2.4.2.profile - -* https://blog.cobaltstrike.com/2021/02/09/learn-pipe-fitting-for-all-of-your-offense-projects/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Suspicious driver loaded path=== -This analytic will detect suspicious driver loaded paths. This technique is commonly used by malicious software like coin miners (xmrig) to register its malicious driver from notable directories where executable or drivers do not commonly exist. During triage, validate this driver is for legitimate business use. Review the metadata and certificate information. Unsigned drivers from non-standard paths is not normal, but occurs. In addition, review driver loads into `ntoskrnl.exe` for possible other drivers of interest. Long tail analyze drivers by path (outside of default, and in default) for further review. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1543/003/ T1543.003], [https://attack.mitre.org/techniques/T1543/ T1543] -* '''Last Updated''': 2021-04-29 - -
-
- -====Search==== -`sysmon` EventCode=6 ImageLoaded = "*.sys" NOT (ImageLoaded IN("*\\WINDOWS\\inf","*\\WINDOWS\\System32\\drivers\\*", "*\\WINDOWS\\System32\\DriverStore\\FileRepository\\*")) -| stats min(_time) as firstTime max(_time) as lastTime count by Computer ImageLoaded Hashes IMPHASH Signature Signed -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `suspicious_driver_loaded_path_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#XMRig|XMRig]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the driver loaded and Signature from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -====Required field==== - -* _time - -* Computer - -* ImageLoaded - -* Hashes - -* IMPHASH - -* Signature - -* Signed - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1543.003 -| Windows Service -| Persistence, Privilege Escalation -|- -| T1543 -| Create or Modify System Process -| Persistence, Privilege Escalation -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Limited false positives will be present. Some applications do load drivers - -====Reference==== - - -* https://www.trendmicro.com/vinfo/hk/threat-encyclopedia/malware/trojan.ps1.powtran.a/ - -* https://redcanary.com/blog/tracking-driver-inventory-to-expose-rootkits/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Suspicious event log service behavior=== -The following analytic utilizes Windows Event ID 1100 to identify when Windows event log service is shutdown. Note that this is a voluminous analytic that will require tuning or restricted to specific endpoints based on criticality. This event generates every time Windows Event Log service has shut down. It also generates during normal system shutdown. During triage, based on time of day and user, determine if this was planned. If not planned, follow through with reviewing parallel alerts and other data sources to determine what else may have occurred. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1070/ T1070], [https://attack.mitre.org/techniques/T1070/001/ T1070.001] -* '''Last Updated''': 2021-06-17 - -
-
- -====Search==== -(`wineventlog_security` EventCode=1100) -| stats count min(_time) as firstTime max(_time) as lastTime by dest Message EventCode -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `suspicious_event_log_service_behavior_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Log_Manipulation|Windows Log Manipulation]] - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - -* [[Documentation:ESSOC:stories:UseCase#Clop_Ransomware|Clop Ransomware]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting Windows event logs from your hosts. In addition, the Splunk Windows TA is needed. - -====Required field==== - -* _time - -* EventCode - -* dest - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1070 -| Indicator Removal on Host -| Defense Evasion -|- -| T1070.001 -| Clear Windows Event Logs -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -It is possible the Event Logging service gets shut down due to system errors or legitimately administration tasks. Filter as needed. - -====Reference==== - - -* https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-1100 - -* https://www.ired.team/offensive-security/defense-evasion/disabling-windows-event-logs-by-suspending-eventlog-service-threads - -* https://attack.mitre.org/techniques/T1070/001/ - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1070.001/T1070.001.md - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070.001/atomic_red_team/windows-security.log - - -''version'': 1 -
-
- ----- - -===Suspicious gpupdate no command line arguments=== -The following analytic identifies gpupdate.exe with no command line arguments. It is unusual for gpupdate.exe to execute with no command line arguments present. This particular behavior is common with malicious software, including Cobalt Strike. During investigation, identify any network connections and parallel processes. Identify any suspicious module loads related to credential dumping or file writes. gpupdate.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1055/ T1055] -* '''Last Updated''': 2021-09-20 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where `process_gpupdate` by _time span=1h Processes.process_id Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| regex process="(gpupdate\.exe.{0,4}$)" -| `suspicious_gpupdate_no_command_line_arguments_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Cobalt_Strike|Cobalt Strike]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1055 -| Process Injection -| Defense Evasion, Privilege Escalation -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Limited false positives may be present in small environments. Tuning may be required based on parent process. - -====Reference==== - - -* https://raw.githubusercontent.com/xx0hcd/Malleable-C2-Profiles/0ef8cf4556e26f6d4190c56ba697c2159faa5822/crimeware/trick_ryuk.profile - -* https://blog.cobaltstrike.com/2021/02/09/learn-pipe-fitting-for-all-of-your-offense-projects/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Suspicious icedid regsvr32 cmdline=== -this search is to detect a suspicious regsvr32 commandline "-s" to execute a dll files. This technique was seen in IcedID malware to execute its initial downloader dll that will download the 2nd stage loader that will download and decrypt the config payload. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/010/ T1218.010] -* '''Last Updated''': 2021-07-27 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_regsvr32` Processes.process=*-s* by Processes.process_name Processes.process Processes.parent_process_name Processes.original_file_name Processes.parent_process Processes.process_id Processes.parent_process_id Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `suspicious_icedid_regsvr32_cmdline_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#IcedID|IcedID]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1218 -| Signed Binary Proxy Execution -| Defense Evasion -|- -| T1218.010 -| Regsvr32 -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -minimal. but network operator can use this application to load dll. - -====Reference==== - - -* https://app.any.run/tasks/56680cba-2bbc-4b34-8633-5f7878ddf858/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/inf_icedid/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Suspicious icedid rundll32 cmdline=== -This search is to detect a suspicious rundll32.exe commandline to execute dll file. This technique was seen in IcedID malware to load its payload dll with the following parameter to load encrypted dll payload which is the license.dat. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/011/ T1218.011] -* '''Last Updated''': 2021-07-26 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_rundll32` Processes.process=*/i:* by Processes.process_name Processes.process Processes.parent_process_name Processes.parent_process Processes.process_id Processes.parent_process_id Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `suspicious_icedid_rundll32_cmdline_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#IcedID|IcedID]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1218 -| Signed Binary Proxy Execution -| Defense Evasion -|- -| T1218.011 -| Rundll32 -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -limitted. this parameter is not commonly used by windows application but can be used by the network operator. - -====Reference==== - - -* https://threatpost.com/icedid-banking-trojan-surges-emotet/165314/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/inf_icedid/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Suspicious image creation in appdata folder=== -This search is to detect a suspicious creation of image in appdata folder made by process that also has a file reference in appdata folder. This technique was seen in remcos rat that capture screenshot of the compromised machine and place it in the appdata and will be send to its C2 server. This TTP is really a good indicator to check that process because it is in suspicious folder path and image files are not commonly created by user in this folder path. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1113/ T1113] -* '''Last Updated''': 2021-09-21 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name=*.exe Processes.process_path="*\\appdata\\Roaming\\*" by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest -| `drop_dm_object_name(Processes)` -| join process_guid, _time [ -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_name IN ("*.png","*.jpg","*.bmp","*.gif","*.tiff") Filesystem.file_path = "*\\appdata\\Roaming\\*" by _time span=1h Filesystem.dest Filesystem.file_create_time Filesystem.file_name Filesystem.file_path -| `drop_dm_object_name(Filesystem)` -| fields _time dest file_create_time file_name file_path process_name process_path process] -| `suspicious_image_creation_in_appdata_folder_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Remcos|Remcos]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -====Required field==== - -* _time - -* dest - -* file_create_time - -* file_name - -* file_path - -* process_name - -* process_path - -* process - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1113 -| Screen Capture -| Collection -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://success.trendmicro.com/solution/1123281-remcos-malware-information - -* https://blog.malwarebytes.com/threat-intelligence/2021/07/remcos-rat-delivered-via-visual-basic/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos_agent/sysmon.log - - -''version'': 1 -
-
- ----- - -===Suspicious msbuild rename=== -The following analytic identifies renamed instances of msbuild.exe executing. Msbuild.exe is natively found in C:\Windows\Microsoft.NET\Framework\v4.0.30319 and C:\Windows\Microsoft.NET\Framework64\v4.0.30319. During investigation, identify the code executed and what is executing a renamed instance of MSBuild. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1036/ T1036], [https://attack.mitre.org/techniques/T1127/ T1127], [https://attack.mitre.org/techniques/T1036/003/ T1036.003], [https://attack.mitre.org/techniques/T1127/001/ T1127.001] -* '''Last Updated''': 2021-01-12 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_msbuild` by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.original_file_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `suspicious_msbuild_rename_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Trusted_Developer_Utilities_Proxy_Execution_MSBuild|Trusted Developer Utilities Proxy Execution MSBuild]] - -* [[Documentation:ESSOC:stories:UseCase#Cobalt_Strike|Cobalt Strike]] - -* [[Documentation:ESSOC:stories:UseCase#Masquerading_-_Rename_System_Utilities|Masquerading - Rename System Utilities]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1036 -| Masquerading -| Defense Evasion -|- -| T1127 -| Trusted Developer Utilities Proxy Execution -| Defense Evasion -|- -| T1036.003 -| Rename System Utilities -| Defense Evasion -|- -| T1127.001 -| MSBuild -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Although unlikely, some legitimate applications may use a moved copy of msbuild, triggering a false positive. - -====Reference==== - - -* https://lolbas-project.github.io/lolbas/Binaries/Msbuild/ - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1127.001/T1127.001.md - -* https://github.com/infosecn1nja/MaliciousMacroMSBuild/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127.001/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Suspicious msbuild spawn=== -The following analytic identifies wmiprvse.exe spawning msbuild.exe. This behavior is indicative of a COM object being utilized to spawn msbuild from wmiprvse.exe. It is common for MSBuild.exe to be spawned from devenv.exe while using Visual Studio. In this instance, there will be command line arguments and file paths. In a malicious instance, MSBuild.exe will spawn from non-standard processes and have no command line arguments. For example, MSBuild.exe spawning from explorer.exe, powershell.exe is far less common and should be investigated. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1127/ T1127], [https://attack.mitre.org/techniques/T1127/001/ T1127.001] -* '''Last Updated''': 2021-01-12 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count values(Processes.process_name) as process_name values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=wmiprvse.exe AND `process_msbuild` by Processes.dest Processes.parent_process Processes.original_file_name Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `suspicious_msbuild_spawn_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Trusted_Developer_Utilities_Proxy_Execution_MSBuild|Trusted Developer Utilities Proxy Execution MSBuild]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1127 -| Trusted Developer Utilities Proxy Execution -| Defense Evasion -|- -| T1127.001 -| MSBuild -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Although unlikely, some legitimate applications may exhibit this behavior, triggering a false positive. - -====Reference==== - - -* https://lolbas-project.github.io/lolbas/Binaries/Msbuild/ - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1127.001/T1127.001.md - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127.001/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Suspicious plistbuddy usage=== -The following analytic identifies the use of a native MacOS utility, PlistBuddy, creating or modifying a properly list (.plist) file. In the instance of Silver Sparrow, the following commands were executed:\ -- PlistBuddy -c "Add :Label string init_verx" ~/Library/Launchagents/init_verx.plist \ -- PlistBuddy -c "Add :RunAtLoad bool true" ~/Library/Launchagents/init_verx.plist \ -- PlistBuddy -c "Add :StartInterval integer 3600" ~/Library/Launchagents/init_verx.plist \ -- PlistBuddy -c "Add :ProgramArguments array" ~/Library/Launchagents/init_verx.plist \ -- PlistBuddy -c "Add :ProgramArguments:0 string /bin/sh" ~/Library/Launchagents/init_verx.plist \ -- PlistBuddy -c "Add :ProgramArguments:1 string -c" ~/Library/Launchagents/init_verx.plist \ -Upon triage, capture the property list file being written to disk and review for further indicators. Contain the endpoint and triage further. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1543/001/ T1543.001], [https://attack.mitre.org/techniques/T1543/ T1543] -* '''Last Updated''': 2021-02-22 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=PlistBuddy (Processes.process=*LaunchAgents* OR Processes.process=*RunAtLoad* OR Processes.process=*true*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `suspicious_plistbuddy_usage_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Silver_Sparrow|Silver Sparrow]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* _time - -* Processes.process_name - -* Processes.process - -* Processes.dest - -* Processes.user - -* Processes.parent_process - -* Processes.process_id - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1543.001 -| Launch Agent -| Persistence, Privilege Escalation -|- -| T1543 -| Create or Modify System Process -| Persistence, Privilege Escalation -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Some legitimate applications may use PlistBuddy to create or modify property lists and possibly generate false positives. Review the property list being modified or created to confirm. - -====Reference==== - - -* https://redcanary.com/blog/clipping-silver-sparrows-wings/ - -* https://marcosantadev.com/manage-plist-files-plistbuddy/ - - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Suspicious plistbuddy usage via osquery=== -The following analytic identifies the use of a native MacOS utility, PlistBuddy, creating or modifying a properly list (.plist) file. In the instance of Silver Sparrow, the following commands were executed:\ -- PlistBuddy -c "Add :Label string init_verx" ~/Library/Launchagents/init_verx.plist \ -- PlistBuddy -c "Add :RunAtLoad bool true" ~/Library/Launchagents/init_verx.plist \ -- PlistBuddy -c "Add :StartInterval integer 3600" ~/Library/Launchagents/init_verx.plist \ -- PlistBuddy -c "Add :ProgramArguments array" ~/Library/Launchagents/init_verx.plist \ -- PlistBuddy -c "Add :ProgramArguments:0 string /bin/sh" ~/Library/Launchagents/init_verx.plist \ -- PlistBuddy -c "Add :ProgramArguments:1 string -c" ~/Library/Launchagents/init_verx.plist \ -Upon triage, capture the property list file being written to disk and review for further indicators. Contain the endpoint and triage further. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1543/001/ T1543.001], [https://attack.mitre.org/techniques/T1543/ T1543] -* '''Last Updated''': 2021-02-22 - -
-
- -====Search==== -`osquery_process` "columns.cmdline"="*LaunchAgents*" OR "columns.cmdline"="*RunAtLoad*" OR "columns.cmdline"="*true*" -| `suspicious_plistbuddy_usage_via_osquery_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Silver_Sparrow|Silver Sparrow]] - - -====How To Implement==== -OSQuery must be installed and configured to pick up process events (info at https://osquery.io) as well as using the Splunk OSQuery Add-on https://splunkbase.splunk.com/app/4402. Modify the macro and validate fields are correct. - -====Required field==== - -* _time - -* columns.cmdline - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1543.001 -| Launch Agent -| Persistence, Privilege Escalation -|- -| T1543 -| Create or Modify System Process -| Persistence, Privilege Escalation -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Some legitimate applications may use PlistBuddy to create or modify property lists and possibly generate false positives. Review the property list being modified or created to confirm. - -====Reference==== - - -* https://redcanary.com/blog/clipping-silver-sparrows-wings/ - -* https://marcosantadev.com/manage-plist-files-plistbuddy/ - - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Suspicious process file path=== -The following analytic will detect a suspicious process running in a file path where a process is not commonly seen and is most commonly used by malicious softtware. This behavior has been used by adversaries where they drop and run an exe in a path that is accessible without admin privileges. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1543/ T1543] -* '''Last Updated''': 2021-05-05 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count values(Processes.process_name) as process_name values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_path = "*\\windows\\fonts\\*" OR Processes.process_path = "*\\windows\\temp\\*" OR Processes.process_path = "*\\users\\public\\*" OR Processes.process_path = "*\\windows\\debug\\*" OR Processes.process_path.file_path = "*\\Users\\Administrator\\Music\\*" OR Processes.process_path.file_path = "*\\Windows\\servicing\\*" OR Processes.process_path.file_path = "*\\Users\\Default\\*" OR Processes.process_path.file_path = "*Recycle.bin*" OR Processes.process_path = "*\\Windows\\Media\\*" OR Processes.process_path = "\\Windows\\repair\\*" OR Processes.process_path = "*\\temp\\*" by Processes.parent_process_name Processes.parent_process Processes.process_path Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `suspicious_process_file_path_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#XMRig|XMRig]] - -* [[Documentation:ESSOC:stories:UseCase#Remcos|Remcos]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* _time - -* Processes.process_name - -* Processes.process - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.process_path - -* Processes.dest - -* Processes.user - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1543 -| Create or Modify System Process -| Persistence, Privilege Escalation -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Administrators may allow execution of specific binaries in non-standard paths. Filter as needed. - -====Reference==== - - -* https://www.trendmicro.com/vinfo/hk/threat-encyclopedia/malware/trojan.ps1.powtran.a/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Suspicious reg exe process=== -This search looks for reg.exe being launched from a command prompt not started by the user. When a user launches cmd.exe, the parent process is usually explorer.exe. This search filters out those instances. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1112/ T1112] -* '''Last Updated''': 2020-07-22 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes where Processes.parent_process_name != explorer.exe Processes.process_name =cmd.exe by Processes.user Processes.process_name Processes.parent_process_name Processes.dest Processes.process_id Processes.parent_process_id -| `drop_dm_object_name("Processes")` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| search [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.parent_process_name=cmd.exe Processes.process_name= reg.exe by Processes.parent_process_id Processes.dest Processes.process_name -| `drop_dm_object_name("Processes")` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| rename parent_process_id as process_id -|dedup process_id -| table process_id dest] -| `suspicious_reg_exe_process_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Defense_Evasion_Tactics|Windows Defense Evasion Tactics]] - -* [[Documentation:ESSOC:stories:UseCase#Disabling_Security_Tools|Disabling Security Tools]] - -* [[Documentation:ESSOC:stories:UseCase#DHS_Report_TA18-074A|DHS Report TA18-074A]] - - -====How To Implement==== -You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. - -====Required field==== - -* _time - -* Processes.parent_process_name - -* Processes.process_name - -* Processes.user - -* Processes.parent_process_name - -* Processes.dest - -* Processes.process_id - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1112 -| Modify Registry -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -It's possible for system administrators to write scripts that exhibit this behavior. If this is the case, the search will need to be modified to filter them out. - -====Reference==== - - -* https://car.mitre.org/wiki/CAR-2013-03-001 - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1112/atomic_red_team/windows-sysmon.log - - -''version'': 4 -
-
- ----- - -===Suspicious regsvr32 register suspicious path=== -Adversaries may abuse Regsvr32.exe to proxy execution of malicious code by using non-standard file extensions to load malciious DLLs. Upon investigating, look for network connections to remote destinations (internal or external). Review additional parrallel processes and child processes for additional activity. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/010/ T1218.010] -* '''Last Updated''': 2021-01-28 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_regsvr32` (Processes.process=*appdata* OR Processes.process=*programdata* OR Processes.process=*windows\temp*) (Processes.process!=*.dll Processes.process!=*.ax Processes.process!=*.ocx) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.original_file_name Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `suspicious_regsvr32_register_suspicious_path_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Regsvr32_Activity|Suspicious Regsvr32 Activity]] - -* [[Documentation:ESSOC:stories:UseCase#Iceid|Iceid]] - - -====How To Implement==== -You must be ingesting endpoint data that tracks process activity, including parent-child relationships from your endpoints, to populate the Endpoint data model in the Processes node. The command-line arguments are mapped to the "process" field in the Endpoint data model. Tune the query by filtering additional extensions found to be used by legitimate processes. To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1218 -| Signed Binary Proxy Execution -| Defense Evasion -|- -| T1218.010 -| Regsvr32 -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Limited false positives with the query restricted to specified paths. Add more world writeable paths as tuning continues. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1218/010/ - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.010/T1218.010.md - -* https://lolbas-project.github.io/lolbas/Binaries/Regsvr32/ - -* https://support.microsoft.com/en-us/topic/how-to-use-the-regsvr32-tool-and-troubleshoot-regsvr32-error-messages-a98d960a-7392-e6fe-d90a-3f4e0cb543e5 - -* https://any.run/report/f29a7d2ecd3585e1e4208e44bcc7156ab5388725f1d29d03e7699da0d4598e7c/0826458b-5367-45cf-b841-c95a33a01718 - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.010/atomic_red_team/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Suspicious rundll32 plugininit=== -This search is to detect a suspicious rundll32.exe process with plugininit parameter. This technique is commonly seen in IceID malware to execute its initial dll stager to download another payload to the compromised machine. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/011/ T1218.011] -* '''Last Updated''': 2021-07-26 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_rundll32` Processes.process=*PluginInit* by Processes.process_name Processes.process Processes.parent_process_name Processes.original_file_name Processes.parent_process Processes.process_id Processes.parent_process_id Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `suspicious_rundll32_plugininit_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#IcedID|IcedID]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1218 -| Signed Binary Proxy Execution -| Defense Evasion -|- -| T1218.011 -| Rundll32 -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -third party application may used this dll export name to execute function. - -====Reference==== - - -* https://threatpost.com/icedid-banking-trojan-surges-emotet/165314/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/inf_icedid/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Suspicious rundll32 rename=== -The following analytic identifies renamed instances of rundll32.exe executing. rundll32.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. During investigation, validate it is the legitimate rundll32.exe executing and what script content it is loading. This query relies on the original filename or internal name from the PE meta data. Expand the query as needed by looking for specific command line arguments outlined in other analytics. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1036/ T1036], [https://attack.mitre.org/techniques/T1218/011/ T1218.011], [https://attack.mitre.org/techniques/T1036/003/ T1036.003] -* '''Last Updated''': 2021-02-04 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_rundll32` by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.original_file_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `suspicious_rundll32_rename_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Rundll32_Activity|Suspicious Rundll32 Activity]] - -* [[Documentation:ESSOC:stories:UseCase#Masquerading_-_Rename_System_Utilities|Masquerading - Rename System Utilities]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1218 -| Signed Binary Proxy Execution -| Defense Evasion -|- -| T1036 -| Masquerading -| Defense Evasion -|- -| T1218.011 -| Rundll32 -| Defense Evasion -|- -| T1036.003 -| Rename System Utilities -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Although unlikely, some legitimate applications may use a moved copy of rundll32, triggering a false positive. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1218/011/ - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.011/T1218.011.md - -* https://lolbas-project.github.io/lolbas/Binaries/Rundll32 - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.011/atomic_red_team/windows-sysmon.log - - -''version'': 3 -
-
- ----- - -===Suspicious rundll32 startw=== -The following analytic identifies rundll32.exe executing a DLL function name, Start and StartW, on the command line that is commonly observed with Cobalt Strike x86 and x64 DLL payloads. Rundll32.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. Typically, the DLL will be written and loaded from a world writeable path or user location. In most instances it will not have a valid certificate (Unsigned). During investigation, review the parent process and other parallel application execution. Capture and triage the DLL in question. In the instance of Cobalt Strike, rundll32.exe is the default process it opens and injects shellcode into. This default process can be changed, but typically is not. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/011/ T1218.011] -* '''Last Updated''': 2021-02-04 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_rundll32` Processes.process=*start* by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.original_file_name Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `suspicious_rundll32_startw_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Rundll32_Activity|Suspicious Rundll32 Activity]] - -* [[Documentation:ESSOC:stories:UseCase#Cobalt_Strike|Cobalt Strike]] - -* [[Documentation:ESSOC:stories:UseCase#Trickbot|Trickbot]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1218 -| Signed Binary Proxy Execution -| Defense Evasion -|- -| T1218.011 -| Rundll32 -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Although unlikely, some legitimate applications may use Start as a function and call it via the command line. Filter as needed. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1218/011/ - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.011/T1218.011.md - -* https://www.cobaltstrike.com/help-windows-executable - -* https://lolbas-project.github.io/lolbas/Binaries/Rundll32 - -* https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.011/atomic_red_team/windows-sysmon.log - - -''version'': 3 -
-
- ----- - -===Suspicious rundll32 dllregisterserver=== -The following analytic identifies rundll32.exe using dllregisterserver on the command line to load a DLL. When a DLL is registered, the DllRegisterServer method entry point in the DLL is invoked. This is typically seen when a DLL is being registered on the system. Not every instance is considered malicious, but it will capture malicious use of it. During investigation, review the parent process and parrellel processes executing. Capture the DLL being loaded and inspect further. Rundll32.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/011/ T1218.011] -* '''Last Updated''': 2021-02-09 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_rundll32` Processes.process=*dllregisterserver* by Processes.dest Processes.user Processes.parent_process Processes.original_file_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `suspicious_rundll32_dllregisterserver_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Rundll32_Activity|Suspicious Rundll32 Activity]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1218 -| Signed Binary Proxy Execution -| Defense Evasion -|- -| T1218.011 -| Rundll32 -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -This is likely to produce false positives and will require some filtering. Tune the query by adding command line paths to known good DLLs, or filtering based on parent process names. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1218/011/ - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.011/T1218.011.md - -* https://lolbas-project.github.io/lolbas/Binaries/Rundll32 - -* https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/seedworm-apt-iran-middle-east - -* https://github.com/pan-unit42/tweets/blob/master/2020-12-10-IOCs-from-Ursnif-infection-with-Delf-variant.txt - -* https://www.crowdstrike.com/blog/duck-hunting-with-falcon-complete-qakbot-zip-based-campaign/ - -* https://msdn.microsoft.com/en-us/library/windows/desktop/ms682162(v=vs.85).aspx - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.011/atomic_red_team/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Suspicious rundll32 no command line arguments=== -The following analytic identifies rundll32.exe with no command line arguments. It is unusual for rundll32.exe to execute with no command line arguments present. This particular behavior is common with malicious software, including Cobalt Strike. During investigation, identify any network connections and parallel processes. Identify any suspicious module loads related to credential dumping or file writes. Rundll32.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/011/ T1218.011] -* '''Last Updated''': 2021-09-20 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where `process_rundll32` by _time span=1h Processes.process_id Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| regex process="(rundll32\.exe.{0,4}$)" -| `suspicious_rundll32_no_command_line_arguments_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Rundll32_Activity|Suspicious Rundll32 Activity]] - -* [[Documentation:ESSOC:stories:UseCase#Cobalt_Strike|Cobalt Strike]] - -* [[Documentation:ESSOC:stories:UseCase#PrintNightmare_CVE-2021-34527|PrintNightmare CVE-2021-34527]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1218 -| Signed Binary Proxy Execution -| Defense Evasion -|- -| T1218.011 -| Rundll32 -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Although unlikely, some legitimate applications may use a moved copy of rundll32, triggering a false positive. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1218/011/ - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.011/T1218.011.md - -* https://lolbas-project.github.io/lolbas/Binaries/Rundll32 - -* https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.011/atomic_red_team/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Suspicious sqlite3 lsquarantine behavior=== -The following analytic identifies the use of a SQLite3 querying the MacOS preferences to identify the original URL the pkg was downloaded from. This particular behavior is common with MacOS adware-malicious software. Upon triage, review other processes in parallel for suspicious activity. Identify any recent package installations. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1074/ T1074] -* '''Last Updated''': 2021-02-22 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=sqlite3 Processes.process=*LSQuarantine* by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `suspicious_sqlite3_lsquarantine_behavior_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Silver_Sparrow|Silver Sparrow]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* _time - -* Processes.process_name - -* Processes.process - -* Processes.dest - -* Processes.user - -* Processes.parent_process - -* Processes.process_id - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1074 -| Data Staged -| Collection -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Unknown. - -====Reference==== - - -* https://redcanary.com/blog/clipping-silver-sparrows-wings/ - -* https://marcosantadev.com/manage-plist-files-plistbuddy/ - - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Suspicious scheduled task from public directory=== -The following detection identifies Scheduled Tasks registering (creating a new task) a binary or script to run from a public directory which includes users\public, \programdata\ and \windows\temp. Upon triage, review the binary or script in the command line for legitimacy, whether an approved binary/script or not. In addition, capture the binary or script in question and analyze for further behaviors. Identify the source and contain the endpoint. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1053/005/ T1053.005], [https://attack.mitre.org/techniques/T1053/ T1053] -* '''Last Updated''': 2021-03-01 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=schtasks.exe (Processes.process=*\\users\\public\\* OR Processes.process=*\\programdata\\* OR Processes.process=*windows\\temp*) Processes.process=*/create* by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `suspicious_scheduled_task_from_public_directory_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - -* [[Documentation:ESSOC:stories:UseCase#Ryuk_Ransomware|Ryuk Ransomware]] - -* [[Documentation:ESSOC:stories:UseCase#Windows_Persistence_Techniques|Windows Persistence Techniques]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* _time - -* Processes.process_name - -* Processes.process - -* Processes.dest - -* Processes.user - -* Processes.parent_process - -* Processes.process_name - -* Processes.process_id - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1053.005 -| Scheduled Task -| Execution, Persistence, Privilege Escalation -|- -| T1053 -| Scheduled Task/Job -| Execution, Persistence, Privilege Escalation -|} - - -====Kill Chain Phase==== - -* Exploitation - -* Privilege Escalation - - -====Known False Positives==== -Limited false positives may be present. Filter as needed by parent process or command line argument. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1053/005/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/schtasks/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Suspicious searchprotocolhost no command line arguments=== -The following analytic identifies searchprotocolhost.exe with no command line arguments. It is unusual for searchprotocolhost.exe to execute with no command line arguments present. This particular behavior is common with malicious software, including Cobalt Strike. During investigation, identify any network connections and parallel processes. Identify any suspicious module loads related to credential dumping or file writes. searchprotocolhost.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1055/ T1055] -* '''Last Updated''': 2021-09-20 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name=searchprotocolhost.exe by _time span=1h Processes.process_id Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| regex process="(searchprotocolhost\.exe.{0,4}$)" -| `suspicious_searchprotocolhost_no_command_line_arguments_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Cobalt_Strike|Cobalt Strike]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1055 -| Process Injection -| Defense Evasion, Privilege Escalation -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Limited false positives may be present in small environments. Tuning may be required based on parent process. - -====Reference==== - - -* https://github.com/fireeye/red_team_tool_countermeasures/blob/master/rules/PGF/supplemental/hxioc/SUSPICIOUS%20EXECUTION%20OF%20SEARCHPROTOCOLHOST%20(METHODOLOGY).ioc - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Suspicious wav file in appdata folder=== -This analytic is to detect a suspicious creation of .wav file in appdata folder. This behavior was seen in Remcos RAT malware where it put the audio recording in the appdata\audio folde as part of data collection. this recording can be send to its C2 server as part of its exfiltration to the compromised machine. creation of wav files in this folder path is not a ussual disk place used by user to save audio format file. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1113/ T1113] -* '''Last Updated''': 2021-09-21 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name=*.exe Processes.process_path="*\\appdata\\Roaming\\*" by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest -| `drop_dm_object_name(Processes)` -| join process_guid, _time [ -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_name IN ("*.wav") Filesystem.file_path = "*\\appdata\\Roaming\\*" by _time span=1h Filesystem.dest Filesystem.file_create_time Filesystem.file_name Filesystem.file_path -| `drop_dm_object_name(Filesystem)` -| fields file_name file_path process_name process_path process dest file_create_time _time ] -| `suspicious_wav_file_in_appdata_folder_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Remcos|Remcos]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, file_name, file_path and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -====Required field==== - -* _time - -* dest - -* file_create_time - -* file_name - -* file_path - -* process_name - -* process_path - -* process - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1113 -| Screen Capture -| Collection -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://success.trendmicro.com/solution/1123281-remcos-malware-information - -* https://blog.malwarebytes.com/threat-intelligence/2021/07/remcos-rat-delivered-via-visual-basic/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos_agent/sysmon_wav.log - - -''version'': 1 -
-
- ----- - -===Suspicious microsoft workflow compiler rename=== -The following analytic identifies a renamed instance of microsoft.workflow.compiler.exe. Microsoft.workflow.compiler.exe is natively found in C:\Windows\Microsoft.NET\Framework64\v4.0.30319 and is rarely utilized. When investigating, identify the executed code on disk and review. A spawned child process from microsoft.workflow.compiler.exe is uncommon. In any instance, microsoft.workflow.compiler.exe spawning from an Office product or any living off the land binary is highly suspect. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1036/ T1036], [https://attack.mitre.org/techniques/T1127/ T1127], [https://attack.mitre.org/techniques/T1036/003/ T1036.003] -* '''Last Updated''': 2021-09-20 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_microsoftworkflowcompiler` by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.original_file_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `suspicious_microsoft_workflow_compiler_rename_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Trusted_Developer_Utilities_Proxy_Execution|Trusted Developer Utilities Proxy Execution]] - -* [[Documentation:ESSOC:stories:UseCase#Cobalt_Strike|Cobalt Strike]] - -* [[Documentation:ESSOC:stories:UseCase#Masquerading_-_Rename_System_Utilities|Masquerading - Rename System Utilities]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1036 -| Masquerading -| Defense Evasion -|- -| T1127 -| Trusted Developer Utilities Proxy Execution -| Defense Evasion -|- -| T1036.003 -| Rename System Utilities -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Although unlikely, some legitimate applications may use a moved copy of microsoft.workflow.compiler.exe, triggering a false positive. - -====Reference==== - - -* https://lolbas-project.github.io/lolbas/Binaries/Microsoft.Workflow.Compiler/ - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218/T1218.md#atomic-test-6---microsoftworkflowcompilerexe-payload-execution - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127/atomic_red_team/windows-sysmon.log - - -''version'': 3 -
-
- ----- - -===Suspicious microsoft workflow compiler usage=== -The following analytic identifies microsoft.workflow.compiler.exe usage. microsoft.workflow.compiler.exe is natively found in C:\Windows\Microsoft.NET\Framework64\v4.0.30319 and is rarely utilized. When investigating, identify the executed code on disk and review. It is not a commonly used process by many applications. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1127/ T1127] -* '''Last Updated''': 2021-01-12 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_microsoftworkflowcompiler` by Processes.dest Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `suspicious_microsoft_workflow_compiler_usage_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Trusted_Developer_Utilities_Proxy_Execution|Trusted Developer Utilities Proxy Execution]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1127 -| Trusted Developer Utilities Proxy Execution -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Although unlikely, limited instances have been identified coming from native Microsoft utilities similar to SCCM. - -====Reference==== - - -* https://lolbas-project.github.io/lolbas/Binaries/Msbuild/ - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218/T1218.md#atomic-test-6---microsoftworkflowcompilerexe-payload-execution - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127/atomic_red_team/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Suspicious msbuild path=== -The following analytic identifies msbuild.exe executing from a non-standard path. Msbuild.exe is natively found in C:\Windows\Microsoft.NET\Framework\v4.0.30319 and C:\Windows\Microsoft.NET\Framework64\v4.0.30319. Instances of Visual Studio will run a copy of msbuild.exe. A moved instance of MSBuild is suspicious, however there are instances of build applications that will move or use a copy of MSBuild. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1036/ T1036], [https://attack.mitre.org/techniques/T1127/ T1127], [https://attack.mitre.org/techniques/T1036/003/ T1036.003], [https://attack.mitre.org/techniques/T1127/001/ T1127.001] -* '''Last Updated''': 2021-01-12 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count values(Processes.process_name) as process_name values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_msbuild` AND (Processes.process_path!=c:\\windows\\microsoft.net\\framework*\\v*\\*) by Processes.dest Processes.original_file_name Processes.parent_process Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `suspicious_msbuild_path_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Trusted_Developer_Utilities_Proxy_Execution_MSBuild|Trusted Developer Utilities Proxy Execution MSBuild]] - -* [[Documentation:ESSOC:stories:UseCase#Cobalt_Strike|Cobalt Strike]] - -* [[Documentation:ESSOC:stories:UseCase#Masquerading_-_Rename_System_Utilities|Masquerading - Rename System Utilities]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1036 -| Masquerading -| Defense Evasion -|- -| T1127 -| Trusted Developer Utilities Proxy Execution -| Defense Evasion -|- -| T1036.003 -| Rename System Utilities -| Defense Evasion -|- -| T1127.001 -| MSBuild -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Some legitimate applications may use a moved copy of msbuild.exe, triggering a false positive. Baselining of MSBuild.exe usage is recommended to better understand it's path usage. Visual Studio runs an instance out of a path that will need to be filtered on. - -====Reference==== - - -* https://lolbas-project.github.io/lolbas/Binaries/Msbuild/ - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1127.001/T1127.001.md - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127.001/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Suspicious mshta child process=== -The following analytic identifies child processes spawning from "mshta.exe". The search will return the first time and last time these command-line arguments were used for these executions, as well as the target system, the user, parent process "mshta.exe" and its child process. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/005/ T1218.005] -* '''Last Updated''': 2021-01-12 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count values(Processes.process_name) as process_name values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=mshta.exe AND (Processes.process_name=powershell.exe OR Processes.process_name=colorcpl.exe OR Processes.process_name=msbuild.exe OR Processes.process_name=microsoft.workflow.compiler.exe OR Processes.process_name=searchprotocolhost.exe OR Processes.process_name=scrcons.exe OR Processes.process_name=cscript.exe OR Processes.process_name=wscript.exe OR Processes.process_name=powershell.exe OR Processes.process_name=cmd.exe) by Processes.dest Processes.parent_process Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `suspicious_mshta_child_process_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_MSHTA_Activity|Suspicious MSHTA Activity]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -====Required field==== - -* _time - -* Processes.process_name - -* Processes.process - -* Processes.parent_process_name - -* Processes.dest - -* Processes.parent_process - -* Processes.user - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1218 -| Signed Binary Proxy Execution -| Defense Evasion -|- -| T1218.005 -| Mshta -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Although unlikely, some legitimate applications may exhibit this behavior, triggering a false positive. - -====Reference==== - - -* https://github.com/redcanaryco/AtomicTestHarnesses - -* https://redcanary.com/blog/introducing-atomictestharnesses/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.005/atomic_red_team/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Suspicious mshta spawn=== -The following analytic identifies wmiprvse.exe spawning mshta.exe. This behavior is indicative of a DCOM object being utilized to spawn mshta from wmiprvse.exe or svchost.exe. In this instance, adversaries may use LethalHTA that will spawn mshta.exe from svchost.exe. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/005/ T1218.005] -* '''Last Updated''': 2021-01-20 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count values(Processes.process_name) as process_name values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.parent_process_name=svchost.exe OR Processes.parent_process_name=wmiprvse.exe) AND `process_mshta` by Processes.dest Processes.parent_process Processes.user Processes.original_file_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `suspicious_mshta_spawn_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_MSHTA_Activity|Suspicious MSHTA Activity]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1218 -| Signed Binary Proxy Execution -| Defense Evasion -|- -| T1218.005 -| Mshta -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Although unlikely, some legitimate applications may exhibit this behavior, triggering a false positive. - -====Reference==== - - -* https://codewhitesec.blogspot.com/2018/07/lethalhta.html - -* https://github.com/redcanaryco/AtomicTestHarnesses - -* https://redcanary.com/blog/introducing-atomictestharnesses/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.005/atomic_red_team/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Suspicious wevtutil usage=== -The wevtutil.exe application is the windows event log utility. This searches for wevtutil.exe with parameters for clearing the application, security, setup, trace or system event logs. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1070/001/ T1070.001], [https://attack.mitre.org/techniques/T1070/ T1070] -* '''Last Updated''': 2021-10-11 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=wevtutil.exe Processes.process IN ("* cl *", "*clear-log*") (Processes.process="*System*" OR Processes.process="*Security*" OR Processes.process="*Setup*" OR Processes.process="*Application*" OR Processes.process="*trace*") by Processes.process_name Processes.parent_process_name Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -| `suspicious_wevtutil_usage_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Log_Manipulation|Windows Log Manipulation]] - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - -* [[Documentation:ESSOC:stories:UseCase#Clop_Ransomware|Clop Ransomware]] - - -====How To Implement==== -You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. - -====Required field==== - -* _time - -* Processes.process - -* Processes.process_name - -* Processes.parent_process_name - -* Processes.dest - -* Processes.user - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1070.001 -| Clear Windows Event Logs -| Defense Evasion -|- -| T1070 -| Indicator Removal on Host -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -The wevtutil.exe application is a legitimate Windows event log utility. Administrators may use it to manage Windows event logs. - -====Reference==== - - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1070.001/T1070.001.md - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070.001/atomic_red_team/windows-sysmon.log - - -''version'': 4 -
-
- ----- - -===Suspicious writes to windows recycle bin=== -This search detects writes to the recycle bin by a process other than explorer.exe. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1036/ T1036] -* '''Last Updated''': 2020-07-22 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Filesystem.file_path) as file_path values(Filesystem.file_name) as file_name FROM datamodel=Endpoint.Filesystem where Filesystem.file_path = "*$Recycle.Bin*" by Filesystem.process_id Filesystem.dest -| `drop_dm_object_name("Filesystem")` -| search [ -| tstats `security_content_summariesonly` values(Processes.user) as user values(Processes.process_name) as process_name values(Processes.parent_process_name) as parent_process_name FROM datamodel=Endpoint.Processes where Processes.process_name != "explorer.exe" by Processes.process_id Processes.dest -| `drop_dm_object_name("Processes")` -| table process_id dest] -| `suspicious_writes_to_windows_recycle_bin_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Collection_and_Staging|Collection and Staging]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on filesystem and process logs responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` and `Filesystem` nodes. - -====Required field==== - -* _time - -* Filesystem.file_path - -* Filesystem.file_name - -* Filesystem.process_id - -* Filesystem.dest - -* Processes.user - -* Processes.process_name - -* Processes.parent_process_name - -* Processes.process_id - -* Processes.dest - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1036 -| Masquerading -| Defense Evasion -|} - - -====Kill Chain Phase==== - - -====Known False Positives==== -Because the Recycle Bin is a hidden folder in modern versions of Windows, it would be unusual for a process other than explorer.exe to write to it. Incidents should be investigated as appropriate. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036/write_to_recycle_bin/windows-sysmon.log - - -''version'': 4 -
-
- ----- - -===System information discovery detection=== -Detect system information discovery techniques used by attackers to understand configurations of the system to further exploit it. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1082/ T1082] -* '''Last Updated''': 2021-09-07 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process="*wmic* qfe*" OR Processes.process=*systeminfo* OR Processes.process=*hostname*) by Processes.user Processes.process_name Processes.process Processes.dest Processes.parent_process_name -| `drop_dm_object_name(Processes)` -| eventstats dc(process) as dc_processes_by_dest by dest -| where dc_processes_by_dest > 2 -| stats values(process) as processes min(firstTime) as firstTime max(lastTime) as lastTime by user, dest parent_process_name -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `system_information_discovery_detection_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Discovery_Techniques|Discovery Techniques]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* _time - -* Processes.process - -* Processes.user - -* Processes.process_name - -* Processes.dest - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1082 -| System Information Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Administrators debugging servers - -====Reference==== - - -* https://oscp.infosecsanyam.in/priv-escalation/windows-priv-escalation - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1082/atomic_red_team/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===System process running from unexpected location=== -An attacker tries might try to use different version of a system command without overriding original, or they might try to avoid some detection running the process from a different folder. This detection checks that a list of system processes run inside C:\\Windows\System32 or C:\\Windows\SysWOW64 The list of system processes has been extracted from https://github.com/splunk/security_content/blob/develop/lookups/is_windows_system_file.csv and the original detection https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1036/ T1036] -* '''Last Updated''': 2020-08-25 - -
-
- -====Search==== - $ssa_input = -| from read_ssa_enriched_events() -| eval device=ucast(map_get(input_event, "dest_device_id"), "string", null), user=ucast(map_get(input_event, "dest_user_id"), "string", null), timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), process_path=lower(ucast(map_get(input_event, "process_path"), "string", null)), event_id=ucast(map_get(input_event, "event_id"), "string", null); -$cond_1 = -| from $ssa_input -| where process_name="arp.exe" OR process_name="adaptertroubleshooter.exe" OR process_name="applicationframehost.exe" OR process_name="atbroker.exe" OR process_name="authhost.exe" OR process_name="autoworkplace.exe" OR process_name="axinstui.exe" OR process_name="backgroundtransferhost.exe" OR process_name="bdehdcfg.exe" OR process_name="bdeuisrv.exe" OR process_name="bdeunlockwizard.exe" OR process_name="bitlockerdeviceencryption.exe" OR process_name="bitlockerwizard.exe" OR process_name="bitlockerwizardelev.exe" OR process_name="bytecodegenerator.exe" OR process_name="camerasettingsuihost.exe" OR process_name="castsrv.exe" OR process_name="certenrollctrl.exe" OR process_name="checknetisolation.exe" OR process_name="clipup.exe" OR process_name="cloudexperiencehostbroker.exe" OR process_name="cloudnotifications.exe" OR process_name="cloudstoragewizard.exe" OR process_name="compmgmtlauncher.exe" OR process_name="compattelrunner.exe" OR process_name="computerdefaults.exe" OR process_name="credentialuibroker.exe" OR process_name="dfdwiz.exe" OR process_name="dwwin.exe" OR process_name="dataexchangehost.exe" OR process_name="defrag.exe" OR process_name="devicedisplayobjectprovider.exe" OR process_name="deviceeject.exe" OR process_name="deviceenroller.exe" OR process_name="devicepairingwizard.exe" OR process_name="deviceproperties.exe" OR process_name="disksnapshot.exe" OR process_name="dism.exe" OR process_name="displayswitch.exe" OR process_name="dmnotificationbroker.exe" OR process_name="dmomacpmo.exe" OR process_name="dpiscaling.exe" OR process_name="dsmusertask.exe" OR process_name="dxpserver.exe" OR process_name="edpcleanup.exe" OR process_name="eosnotify.exe" OR process_name="eap3host.exe" OR process_name="easpoliciesbrokerhost.exe" OR process_name="easeofaccessdialog.exe" OR process_name="ehstorauthn.exe" OR process_name="fxscover.exe" OR process_name="fxssvc.exe" OR process_name="fxsunatd.exe" OR process_name="filehistory.exe" OR process_name="fondue.exe" OR process_name="gamepanel.exe" OR process_name="genvalobj.exe" OR process_name="gettingstarted.exe" OR process_name="hostname.exe" OR process_name="icsentitlementhost.exe" OR process_name="infdefaultinstall.exe" OR process_name="installagent.exe" OR process_name="languagecomponentsinstallercomhandler.exe" OR process_name="launchtm.exe" OR process_name="launchwinapp.exe" OR process_name="legacynetuxhost.exe" OR process_name="licensemanagershellext.exe" OR process_name="licensingui.exe" OR process_name="locationnotificationwindows.exe" OR process_name="locationnotifications.exe" OR process_name="locator.exe" OR process_name="lockapphost.exe" OR process_name="lockscreencontentserver.exe" OR process_name="logonui.exe" OR process_name="lsaiso.exe" OR process_name="mdeserver.exe" OR process_name="mdmagent.exe" OR process_name="mdmappinstaller.exe" OR process_name="mrinfo.exe" OR process_name="mrt.exe" OR process_name="mschedexe.exe" OR process_name="magnify.exe" OR process_name="mbaeparsertask.exe" OR process_name="mdres.exe" OR process_name="mdsched.exe" OR process_name="migautoplay.exe" OR process_name="mpsigstub.exe" OR process_name="msspellcheckinghost.exe" OR process_name="muiunattend.exe" OR process_name="multidigimon.exe" OR process_name="musnotification.exe" OR process_name="musnotificationux.exe" OR process_name="napstat.exe" OR process_name="netstat.exe" OR process_name="narrator.exe" OR process_name="netcfgnotifyobjecthost.exe" OR process_name="netevtfwdr.exe" OR process_name="netproj.exe" OR process_name="netplwiz.exe" OR process_name="networkuxbroker.exe"; -$cond_2 = -| from $ssa_input -| where process_name="openwith.exe" OR process_name="optionalfeatures.exe" OR process_name="pathping.exe" OR process_name="ping.exe" OR process_name="passwordonwakesettingflyout.exe" OR process_name="pickerhost.exe" OR process_name="pkgmgr.exe" OR process_name="pnpunattend.exe" OR process_name="pnputil.exe" OR process_name="presentationhost.exe" OR process_name="presentationsettings.exe" OR process_name="printbrmui.exe" OR process_name="printdialoghost.exe" OR process_name="printdialoghost3d.exe" OR process_name="printisolationhost.exe" OR process_name="proximityuxhost.exe" OR process_name="rdspnf.exe" OR process_name="rmactivate.exe" OR process_name="rmactivate_isv.exe" OR process_name="rmactivate_ssp.exe" OR process_name="rmactivate_ssp_isv.exe" OR process_name="route.exe" OR process_name="rdpsa.exe" OR process_name="rdpsaproxy.exe" OR process_name="rdpsauachelper.exe" OR process_name="reagentc.exe" OR process_name="recoverydrive.exe" OR process_name="register-cimprovider.exe" OR process_name="registeriepkeys.exe" OR process_name="relpost.exe" OR process_name="remoteposworker.exe" OR process_name="rmclient.exe" OR process_name="robocopy.exe" OR process_name="rpcping.exe" OR process_name="runlegacycplelevated.exe" OR process_name="runtimebroker.exe" OR process_name="sihclient.exe" OR process_name="searchfilterhost.exe" OR process_name="searchindexer.exe" OR process_name="searchprotocolhost.exe" OR process_name="secedit.exe" OR process_name="sensordataservice.exe" OR process_name="setieinstalleddate.exe" OR process_name="settingsynchost.exe" OR process_name="slidetoshutdown.exe" OR process_name="smartscreensettings.exe" OR process_name="sndvol.exe" OR process_name="snippingtool.exe" OR process_name="soundrecorder.exe" OR process_name="spaceagent.exe" OR process_name="sppextcomobj.exe" OR process_name="srtasks.exe" OR process_name="stikynot.exe" OR process_name="synchost.exe" OR process_name="sysreseterr.exe" OR process_name="systempropertiesadvanced.exe" OR process_name="systempropertiescomputername.exe" OR process_name="systempropertiesdataexecutionprevention.exe" OR process_name="systempropertieshardware.exe" OR process_name="systempropertiesperformance.exe" OR process_name="systempropertiesprotection.exe" OR process_name="systempropertiesremote.exe" OR process_name="systemsettingsadminflows.exe" OR process_name="systemsettingsbroker.exe" OR process_name="systemsettingsremovedevice.exe" OR process_name="tcpsvcs.exe" OR process_name="tracert.exe" OR process_name="tstheme.exe" OR process_name="tswbprxy.exe" OR process_name="tapiunattend.exe" OR process_name="taskmgr.exe" OR process_name="thumbnailextractionhost.exe" OR process_name="tokenbrokercookies.exe" OR process_name="tpminit.exe" OR process_name="tswpfwrp.exe" OR process_name="ui0detect.exe" OR process_name="upgraderesultsui.exe" OR process_name="useraccountbroker.exe" OR process_name="useraccountcontrolsettings.exe" OR process_name="usoclient.exe" OR process_name="utilman.exe" OR process_name="vssvc.exe" OR process_name="vaultcmd.exe" OR process_name="vaultsysui.exe" OR process_name="wfs.exe" OR process_name="wmpdmc.exe" OR process_name="wpdshextautoplay.exe" OR process_name="wscollect.exe" OR process_name="wsmanhttpconfig.exe" OR process_name="wsreset.exe" OR process_name="wudfhost.exe" OR process_name="wwahost.exe" OR process_name="wallpaperhost.exe" OR process_name="webcache.exe" OR process_name="werfault.exe" OR process_name="werfaultsecure.exe" OR process_name="winsat.exe" OR process_name="windows.media.backgroundplayback.exe" OR process_name="windowsactiondialog.exe" OR process_name="windowsanytimeupgrade.exe" OR process_name="windowsanytimeupgraderesults.exe"; -$cond_3 = -| from $ssa_input -| where process_name="windowsanytimeupgradeui.exe" OR process_name="windowsupdateelevatedinstaller.exe" OR process_name="workfolders.exe" OR process_name="wpcmon.exe" OR process_name="acu.exe" OR process_name="aitagent.exe" OR process_name="aitstatic.exe" OR process_name="alg.exe" OR process_name="appidcertstorecheck.exe" OR process_name="appidpolicyconverter.exe" OR process_name="at.exe" OR process_name="attrib.exe" OR process_name="audiodg.exe" OR process_name="auditpol.exe" OR process_name="autochk.exe" OR process_name="autoconv.exe" OR process_name="autofmt.exe" OR process_name="baaupdate.exe" OR process_name="backgroundtaskhost.exe" OR process_name="bcastdvr.exe" OR process_name="bcdboot.exe" OR process_name="bcdedit.exe" OR process_name="bdechangepin.exe" OR process_name="bdeunlock.exe" OR process_name="bitsadmin.exe" OR process_name="bootcfg.exe" OR process_name="bootim.exe" OR process_name="bootsect.exe" OR process_name="bridgeunattend.exe" OR process_name="browser_broker.exe" OR process_name="bthudtask.exe" OR process_name="cacls.exe" OR process_name="calc.exe" OR process_name="cdpreference.exe" OR process_name="certreq.exe" OR process_name="certutil.exe" OR process_name="change.exe" OR process_name="changepk.exe" OR process_name="charmap.exe" OR process_name="chglogon.exe" OR process_name="chgport.exe" OR process_name="chgusr.exe" OR process_name="chkdsk.exe" OR process_name="chkntfs.exe" OR process_name="choice.exe" OR process_name="cipher.exe" OR process_name="cleanmgr.exe" OR process_name="cliconfg.exe" OR process_name="clip.exe" OR process_name="cmd.exe" OR process_name="cmdkey.exe" OR process_name="cmdl32.exe" OR process_name="cmmon32.exe" OR process_name="cmstp.exe" OR process_name="cofire.exe" OR process_name="colorcpl.exe" OR process_name="comp.exe" OR process_name="compact.exe" OR process_name="conhost.exe" OR process_name="consent.exe" OR process_name="control.exe" OR process_name="convert.exe" OR process_name="credwiz.exe" OR process_name="cscript.exe" OR process_name="csrss.exe" OR process_name="ctfmon.exe" OR process_name="cttune.exe" OR process_name="cttunesvr.exe" OR process_name="dashost.exe" OR process_name="dccw.exe" OR process_name="dcomcnfg.exe" OR process_name="ddodiag.exe" OR process_name="dfrgui.exe" OR process_name="dialer.exe" OR process_name="diantz.exe" OR process_name="dinotify.exe" OR process_name="diskpart.exe" OR process_name="diskperf.exe" OR process_name="diskraid.exe" OR process_name="dispdiag.exe" OR process_name="djoin.exe" OR process_name="dllhost.exe" OR process_name="dllhst3g.exe" OR process_name="dmcertinst.exe" OR process_name="dmcfghost.exe" OR process_name="dmclient.exe" OR process_name="dnscacheugc.exe" OR process_name="doskey.exe" OR process_name="dpapimig.exe" OR process_name="dpnsvr.exe" OR process_name="driverquery.exe" OR process_name="drvcfg.exe" OR process_name="drvinst.exe" OR process_name="dsregcmd.exe" OR process_name="dstokenclean.exe" OR process_name="dvdplay.exe" OR process_name="dvdupgrd.exe" OR process_name="dwm.exe" OR process_name="dxdiag.exe" OR process_name="easinvoker.exe" OR process_name="efsui.exe"; -$cond_4 = -| from $ssa_input -| where process_name="embeddedapplauncher.exe" OR process_name="esentutl.exe" OR process_name="eudcedit.exe" OR process_name="eventcreate.exe" OR process_name="eventvwr.exe" OR process_name="expand.exe" OR process_name="extrac32.exe" OR process_name="fc.exe" OR process_name="fhmanagew.exe" OR process_name="find.exe" OR process_name="findstr.exe" OR process_name="finger.exe" OR process_name="fixmapi.exe" OR process_name="fltmc.exe" OR process_name="fodhelper.exe" OR process_name="fontdrvhost.exe" OR process_name="fontview.exe" OR process_name="forfiles.exe" OR process_name="fsavailux.exe" OR process_name="fsquirt.exe" OR process_name="fsutil.exe" OR process_name="ftp.exe" OR process_name="fvenotify.exe" OR process_name="fveprompt.exe" OR process_name="getmac.exe" OR process_name="gpresult.exe" OR process_name="gpscript.exe" OR process_name="gpupdate.exe" OR process_name="grpconv.exe" OR process_name="hdwwiz.exe" OR process_name="help.exe" OR process_name="hwrcomp.exe" OR process_name="hwrreg.exe" OR process_name="icacls.exe" OR process_name="icardagt.exe" OR process_name="icsunattend.exe" OR process_name="ie4uinit.exe" OR process_name="ieunatt.exe" OR process_name="ieetwcollector.exe" OR process_name="iexpress.exe" OR process_name="immersivetpmvscmgrsvr.exe" OR process_name="ipconfig.exe" OR process_name="irftp.exe" OR process_name="iscsicli.exe" OR process_name="iscsicpl.exe" OR process_name="isoburn.exe" OR process_name="klist.exe" OR process_name="ksetup.exe" OR process_name="ktmutil.exe" OR process_name="label.exe" OR process_name="licensingdiag.exe" OR process_name="lodctr.exe" OR process_name="logagent.exe" OR process_name="logman.exe" OR process_name="logoff.exe" OR process_name="lpkinstall.exe" OR process_name="lpksetup.exe" OR process_name="lpremove.exe" OR process_name="lsass.exe" OR process_name="lsm.exe" OR process_name="makecab.exe" OR process_name="manage-bde.exe" OR process_name="mblctr.exe" OR process_name="mcbuilder.exe" OR process_name="mctadmin.exe" OR process_name="mfpmp.exe" OR process_name="mmc.exe" OR process_name="mobsync.exe" OR process_name="mountvol.exe" OR process_name="mpnotify.exe" OR process_name="msconfig.exe" OR process_name="msdt.exe" OR process_name="msdtc.exe" OR process_name="msfeedssync.exe" OR process_name="msg.exe" OR process_name="mshta.exe" OR process_name="msiexec.exe" OR process_name="msinfo32.exe" OR process_name="mspaint.exe" OR process_name="msra.exe" OR process_name="mstsc.exe" OR process_name="mtstocom.exe" OR process_name="nbtstat.exe" OR process_name="ndadmin.exe" OR process_name="net.exe" OR process_name="net1.exe" OR process_name="netbtugc.exe" OR process_name="netcfg.exe" OR process_name="netiougc.exe" OR process_name="netsh.exe" OR process_name="newdev.exe" OR process_name="nltest.exe" OR process_name="notepad.exe" OR process_name="nslookup.exe" OR process_name="ntoskrnl.exe" OR process_name="ntprint.exe" OR process_name="ocsetup.exe" OR process_name="odbcad32.exe" OR process_name="odbcconf.exe" OR process_name="omadmclient.exe" OR process_name="omadmprc.exe"; -$cond_5 = -| from $ssa_input -| where process_name="openfiles.exe" OR process_name="osk.exe" OR process_name="p2phost.exe" OR process_name="pcalua.exe" OR process_name="pcaui.exe" OR process_name="pcawrk.exe" OR process_name="pcwrun.exe" OR process_name="perfmon.exe" OR process_name="phoneactivate.exe" OR process_name="plasrv.exe" OR process_name="poqexec.exe" OR process_name="powercfg.exe" OR process_name="prevhost.exe" OR process_name="print.exe" OR process_name="printfilterpipelinesvc.exe" OR process_name="printui.exe" OR process_name="proquota.exe" OR process_name="provtool.exe" OR process_name="psr.exe" OR process_name="pwlauncher.exe" OR process_name="qappsrv.exe" OR process_name="qprocess.exe" OR process_name="query.exe" OR process_name="quser.exe" OR process_name="qwinsta.exe" OR process_name="rasautou.exe" OR process_name="rasdial.exe" OR process_name="raserver.exe" OR process_name="rasphone.exe" OR process_name="rdpclip.exe" OR process_name="rdpinput.exe" OR process_name="rdrleakdiag.exe" OR process_name="recdisc.exe" OR process_name="recover.exe" OR process_name="reg.exe" OR process_name="regedt32.exe" OR process_name="regini.exe" OR process_name="regsvr32.exe" OR process_name="rekeywiz.exe" OR process_name="relog.exe" OR process_name="repair-bde.exe" OR process_name="replace.exe" OR process_name="reset.exe" OR process_name="resmon.exe" OR process_name="rmttpmvscmgrsvr.exe" OR process_name="rrinstaller.exe" OR process_name="rstrui.exe" OR process_name="runas.exe" OR process_name="rundll32.exe" OR process_name="runonce.exe" OR process_name="rwinsta.exe" OR process_name="sbunattend.exe" OR process_name="sc.exe" OR process_name="schtasks.exe" OR process_name="sdbinst.exe" OR process_name="sdchange.exe" OR process_name="sdclt.exe" OR process_name="sdiagnhost.exe" OR process_name="secinit.exe" OR process_name="services.exe" OR process_name="sessionmsg.exe" OR process_name="sethc.exe" OR process_name="setspn.exe" OR process_name="setupcl.exe" OR process_name="setupugc.exe" OR process_name="setx.exe" OR process_name="sfc.exe" OR process_name="shadow.exe" OR process_name="shrpubw.exe" OR process_name="shutdown.exe" OR process_name="sigverif.exe" OR process_name="sihost.exe" OR process_name="slui.exe" OR process_name="smss.exe" OR process_name="snmptrap.exe" OR process_name="sort.exe" OR process_name="spinstall.exe" OR process_name="spoolsv.exe" OR process_name="sppsvc.exe" OR process_name="spreview.exe" OR process_name="srdelayed.exe" OR process_name="subst.exe" OR process_name="svchost.exe" OR process_name="sxstrace.exe" OR process_name="syskey.exe" OR process_name="systeminfo.exe" OR process_name="systemreset.exe" OR process_name="systray.exe" OR process_name="tabcal.exe" OR process_name="takeown.exe" OR process_name="taskeng.exe" OR process_name="taskhost.exe" OR process_name="taskhostw.exe" OR process_name="taskkill.exe" OR process_name="tasklist.exe" OR process_name="taskmgr.exe" OR process_name="tcmsetup.exe" OR process_name="timeout.exe" OR process_name="tpmvscmgr.exe" OR process_name="tpmvscmgrsvr.exe"; -$cond_6 = -| from $ssa_input -| where process_name="tracerpt.exe" OR process_name="tscon.exe" OR process_name="tsdiscon.exe" OR process_name="tskill.exe" OR process_name="typeperf.exe" OR process_name="tzsync.exe" OR process_name="tzutil.exe" OR process_name="ucsvc.exe" OR process_name="unlodctr.exe" OR process_name="unregmp2.exe" OR process_name="upnpcont.exe" OR process_name="userinit.exe" OR process_name="vds.exe" OR process_name="vdsldr.exe" OR process_name="verclsid.exe" OR process_name="verifier.exe" OR process_name="verifiergui.exe" OR process_name="vmicsvc.exe" OR process_name="vssadmin.exe" OR process_name="w32tm.exe" OR process_name="waitfor.exe" OR process_name="wbadmin.exe" OR process_name="wbengine.exe" OR process_name="wecutil.exe" OR process_name="wermgr.exe" OR process_name="wevtutil.exe" OR process_name="wextract.exe" OR process_name="where.exe" OR process_name="whoami.exe" OR process_name="wiaacmgr.exe" OR process_name="wiawow64.exe" OR process_name="wifitask.exe" OR process_name="wimserv.exe" OR process_name="wininit.exe" OR process_name="winload.exe" OR process_name="winlogon.exe" OR process_name="winresume.exe" OR process_name="winrs.exe" OR process_name="winrshost.exe" OR process_name="winver.exe" OR process_name="wisptis.exe" OR process_name="wkspbroker.exe" OR process_name="wksprt.exe" OR process_name="wlanext.exe" OR process_name="wlrmdr.exe" OR process_name="wowreg32.exe" OR process_name="wpnpinst.exe" OR process_name="wpr.exe" OR process_name="write.exe" OR process_name="wscript.exe" OR process_name="wsmprovhost.exe" OR process_name="wsqmcons.exe" OR process_name="wuapihost.exe" OR process_name="wuapp.exe" OR process_name="wuauclt.exe" OR process_name="wusa.exe" OR process_name="xcopy.exe" OR process_name="xpsrchvw.exe" OR process_name="xwizard.exe"; - -| from $cond_1 -| union $cond_2 -| union $cond_3 -| union $cond_4 -| union $cond_5 -| union $cond_6 -| where match_regex(process_path, /(?i)\\windows\\system32/)=false AND match_regex(process_path, /(?i)\\windows\\syswow64/)=false -| eval start_time=timestamp, end_time=timestamp, entities=mvappend(device, user), body=create_map(["event_id", event_id, "process_path", process_path, "process_name", process_name]) -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Defense_Evasion_Tactics|Windows Defense Evasion Tactics]] - -* [[Documentation:ESSOC:stories:UseCase#Masquerading_-_Rename_System_Utilities|Masquerading - Rename System Utilities]] - - -====How To Implement==== -Collect endpoint data such as sysmon or 4688 events. - -====Required field==== - -* dest_device_id - -* process_name - -* _time - -* dest_user_id - -* process_path - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1036 -| Masquerading -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -None - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036/system_process_running_unexpected_location/windows-security.log - - -''version'': 3 -
-
- ----- - -===System processes run from unexpected locations=== -This search looks for system processes that typically execute from `C:\Windows\System32\` or `C:\Windows\SysWOW64`. This may indicate a malicious process that is trying to hide as a legitimate process.\ -This detection utilizes a lookup that is deduped `system32` and `syswow64` directories from Server 2016 and Windows 10.\ -During triage, review the parallel processes - what process moved the native Windows binary? identify any artifacts on disk and review. If a remote destination is contacted, what is the reputation? - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1036/ T1036], [https://attack.mitre.org/techniques/T1036/003/ T1036.003] -* '''Last Updated''': 2020-12-08 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes where Processes.process_path !="C:\\Windows\\System32*" Processes.process_path !="C:\\Windows\\SysWOW64*" by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.process_hash -| `drop_dm_object_name("Processes")` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `is_windows_system_file` -| `system_processes_run_from_unexpected_locations_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Command-Line_Executions|Suspicious Command-Line Executions]] - -* [[Documentation:ESSOC:stories:UseCase#Unusual_Processes|Unusual Processes]] - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - -* [[Documentation:ESSOC:stories:UseCase#Masquerading_-_Rename_System_Utilities|Masquerading - Rename System Utilities]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* _time - -* Processes.process_path - -* Processes.user - -* Processes.dest - -* Processes.process_name - -* Processes.process_id - -* Processes.parent_process_name - -* Processes.process_hash - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1036 -| Masquerading -| Defense Evasion -|- -| T1036.003 -| Rename System Utilities -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -This detection may require tuning based on third party applications utilizing native Windows binaries in non-standard paths. - -====Reference==== - - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1036.003/T1036.003.yaml - -* https://attack.mitre.org/techniques/T1036/003/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036.003/atomic_red_team/windows-sysmon.log - - -''version'': 6 -
-
- ----- - -===System user discovery with query=== -This analytic looks for the execution of `query.exe` with command-line arguments utilized to discover the logged user. Red Teams and adversaries alike may leverage `query.exe` to identify system users on a compromised endpoint for situational awareness and Active Directory Discovery. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1033/ T1033] -* '''Last Updated''': 2021-09-13 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="query.exe") (Processes.process=*user*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `system_user_discovery_with_query_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1033 -| System Owner/User Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use this command for troubleshooting. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1033/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1033/AD_discovery/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===System user discovery with whoami=== -This analytic looks for the execution of `whoami.exe` without any arguments. This windows native binary prints out the current logged user. Red Teams and adversaries alike may leverage `whoami.exe` to identify system users on a compromised endpoint for situational awareness and Active Directory Discovery. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1033/ T1033] -* '''Last Updated''': 2021-09-13 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="whoami.exe") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `system_user_discovery_with_whoami_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1033 -| System Owner/User Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use this command for troubleshooting. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1033/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1033/AD_discovery/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Time provider persistence registry=== -This analytic is to detect a suspiciouos modification of time provider registry for persistence and autostart. This technique can allow the attacker to persist on the compromised host and autostart as soon as the machine boot up. This TTP can be a good indicator of suspicious behavior since this registry is not commonly modified by normal user or even an admin. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1547/003/ T1547.003], [https://attack.mitre.org/techniques/T1547/ T1547] -* '''Last Updated''': 2021-09-29 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path ="*\\CurrentControlSet\\Services\\W32Time\\TimeProviders*" by Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `drop_dm_object_name(Registry)` -| `time_provider_persistence_registry_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Persistence_Techniques|Windows Persistence Techniques]] - -* [[Documentation:ESSOC:stories:UseCase#Windows_Privilege_Escalation|Windows Privilege Escalation]] - - -====How To Implement==== -To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. - -====Required field==== - -* _time - -* Registry.dest - -* Registry.user - -* Registry.registry_path - -* Registry.registry_key_name - -* Registry.registry_value_name - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1547.003 -| Time Providers -| Persistence, Privilege Escalation -|- -| T1547 -| Boot or Logon Autostart Execution -| Persistence, Privilege Escalation -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://pentestlab.blog/2019/10/22/persistence-time-providers/ - -* https://attack.mitre.org/techniques/T1547/003/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.003/timeprovider_reg/sysmon.log - - -''version'': 1 -
-
- ----- - -===Trickbot named pipe=== -this search is to detect potential trickbot infection through the create/connected named pipe to the system. This technique is used by trickbot to communicate to its c2 to post or get command during infection. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1055/ T1055] -* '''Last Updated''': 2021-04-26 - -
-
- -====Search==== -`sysmon` EventCode IN (17,18) PipeName="\\pipe\\*lacesomepipe" -| stats min(_time) as firstTime max(_time) as lastTime count by Computer user_id EventCode PipeName signature Image process_id -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `trickbot_named_pipe_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Trickbot|Trickbot]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name and pipename from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. . - -====Required field==== - -* _time - -* Computer - -* user_id - -* EventCode - -* PipeName - -* signature - -* Image - -* process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1055 -| Process Injection -| Defense Evasion, Privilege Escalation -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://labs.vipre.com/trickbot-and-its-modules/ - -* https://blog.whitehat.eu/2019/05/incident-trickbot-ryuk-2.html - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/trickbot/namedpipe/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Uac bypass mmc load unsigned dll=== -This search is to detect a suspicious loaded unsigned dll by MMC.exe application. This technique is commonly seen in attacker that tries to bypassed UAC feature or gain privilege escalation. This is done by modifying some CLSID registry that will trigger the mmc.exe to load the dll path - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1548/002/ T1548.002], [https://attack.mitre.org/techniques/T1548/ T1548] -* '''Last Updated''': 2021-07-12 - -
-
- -====Search==== -`sysmon` EventCode=7 ImageLoaded = "*.dll" Image = "*\\mmc.exe" Signed=false Company != "Microsoft Corporation" -| stats count min(_time) as firstTime max(_time) as lastTime by Image ImageLoaded Signed ProcessId OriginalFileName Computer EventCode Company -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `uac_bypass_mmc_load_unsigned_dll_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Defense_Evasion_Tactics|Windows Defense Evasion Tactics]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name and imageloaded executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -====Required field==== - -* _time - -* Image - -* ImageLoaded - -* Signed - -* ProcessId - -* OriginalFileName - -* Computer - -* EventCode - -* Company - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1548.002 -| Bypass User Account Control -| Privilege Escalation, Defense Evasion -|- -| T1548 -| Abuse Elevation Control Mechanism -| Privilege Escalation, Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown. all of the dll loaded by mmc.exe is microsoft signed dll. - -====Reference==== - - -* https://offsec.almond.consulting/UAC-bypass-dotnet.html - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/uac_bypass/windows-sysmon2.log - - -''version'': 1 -
-
- ----- - -===Uac bypass with colorui com object=== -This search is to detect a possible uac bypass using the colorui.dll COM Object. this technique was seen in so many malware and ransomware like lockbit where it make use of the colorui.dll COM CLSID to bypass UAC. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/003/ T1218.003] -* '''Last Updated''': 2021-08-13 - -
-
- -====Search==== -`sysmon` EventCode=7 ImageLoaded="*\\colorui.dll" process_name != "colorcpl.exe" NOT(Image IN("*\\windows\\*", "*\\program files*")) -| stats count min(_time) as firstTime max(_time) as lastTime by Image ImageLoaded process_name Computer EventCode Signed ProcessId -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `uac_bypass_with_colorui_com_object_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -====Required field==== - -* _time - -* Image - -* ImageLoaded - -* process_name - -* Computer - -* EventCode - -* Signed - -* ProcessId - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1218 -| Signed Binary Proxy Execution -| Defense Evasion -|- -| T1218.003 -| CMSTP -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -not so common. but 3rd part app may load this dll. - -====Reference==== - - -* https://news.sophos.com/en-us/2020/04/24/lockbit-ransomware-borrows-tricks-to-keep-up-with-revil-and-maze/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.015/uac_colorui/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Usn journal deletion=== -The fsutil.exe application is a legitimate Windows utility used to perform tasks related to the file allocation table (FAT) and NTFS file systems. The update sequence number (USN) change journal provides a log of all changes made to the files on the disk. This search looks for fsutil.exe deleting the USN journal. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1070/ T1070] -* '''Last Updated''': 2018-12-03 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count values(Processes.process) as process values(Processes.parent_process) as parent_process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=fsutil.exe by Processes.user Processes.process_name Processes.parent_process_name Processes.dest -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| search process="*deletejournal*" AND process="*usn*" -| `usn_journal_deletion_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Log_Manipulation|Windows Log Manipulation]] - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - - -====How To Implement==== -You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. - -====Required field==== - -* _time - -* Processes.process - -* Processes.parent_process - -* Processes.process_name - -* Processes.user - -* Processes.parent_process_name - -* Processes.dest - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1070 -| Indicator Removal on Host -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -None identified - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070/atomic_red_team/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Unified messaging service spawning a process=== -This detection identifies Microsoft Exchange Server's Unified Messaging services, umworkerprocess.exe and umservice.exe, spawning a child process, indicating possible exploitation of CVE-2021-26857 vulnerability. The query filters out werfault.exe and wermgr.exe mostly due to potential false positives, however, if there is an excessive amount of "wermgr.exe" or "WerFault.exe" failures, it may be due to the active exploitation. During triage, identify any additional suspicious parallel processes. Identify any recent out of place file modifications. Review Exchange logs following Microsofts guide. To contain, perform egress filtering or restrict public access to Exchange. In final, patch the vulnerablity and monitor. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1190/ T1190] -* '''Last Updated''': 2021-03-02 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name="umworkerprocess.exe" OR Processes.parent_process_name="UMService.exe" (Processes.process_name!="wermgr.exe" OR Processes.process_name!="werfault.exe") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `unified_messaging_service_spawning_a_process_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#HAFNIUM_Group|HAFNIUM Group]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -====Required field==== - -* _time - -* Processes.process_name - -* Processes.process - -* Processes.dest - -* Processes.user - -* Processes.parent_process - -* Processes.process_id - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1190 -| Exploit Public-Facing Application -| Initial Access -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Unknown. Tune out child processes as needed to limit volume of false positives. - -====Reference==== - - -* https://www.volexity.com/blog/2021/03/02/active-exploitation-of-microsoft-exchange-zero-day-vulnerabilities/ - -* https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/ - -* https://blog.rapid7.com/2021/03/03/rapid7s-insightidr-enables-detection-and-response-to-microsoft-exchange-0-day/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1505.003/windows-sysmon_umservices.log - - -''version'': 1 -
-
- ----- - -===Uninstall app using msiexec=== -This search is to detect a suspicious un-installation of application using msiexec. This technique was seen in conti leak tool and script where it tries to uninstall AV product using this commandline. This commandline to uninstall product is not a common practice in enterprise network. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/007/ T1218.007], [https://attack.mitre.org/techniques/T1218/ T1218] -* '''Last Updated''': 2021-08-09 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=msiexec.exe Processes.process= "* /qn *" Processes.process= "*/X*" Processes.process= "*REBOOT=*" by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `uninstall_app_using_msiexec_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process - -* Processes.parent_process_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1218.007 -| Msiexec -| Defense Evasion -|- -| T1218 -| Signed Binary Proxy Execution -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown. - -====Reference==== - - -* https://threadreaderapp.com/thread/1423361119926816776.html - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/conti/conti_leak/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Unload sysmon filter driver=== -Attackers often disable security tools to avoid detection. This search looks for the usage of process `fltMC.exe` to unload a Sysmon Driver that will stop sysmon from collecting the data. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001], [https://attack.mitre.org/techniques/T1562/ T1562] -* '''Last Updated''': 2020-07-22 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime values(Processes.process) as process max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=fltMC.exe AND Processes.process=*unload* AND Processes.process=*SysmonDrv* by Processes.process_name Processes.process_id Processes.parent_process_name Processes.process Processes.dest Processes.user -| `drop_dm_object_name("Processes")` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -|`unload_sysmon_filter_driver_filter` -| table firstTime lastTime dest user count process_name process_id parent_process_name process - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Disabling_Security_Tools|Disabling Security Tools]] - - -====How To Implement==== -You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. This search is also shipped with `unload_sysmon_filter_driver_filter` macro, update this macro to filter out false positives. - -====Required field==== - -* _time - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_name - -* Processes.dest - -* Processes.user - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1562.001 -| Disable or Modify Tools -| Defense Evasion -|- -| T1562 -| Impair Defenses -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== - - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/atomic_red_team/windows-sysmon.log - - -''version'': 3 -
-
- ----- - -===Unloading amsi via reflection=== -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify suspicious PowerShell execution. Script Block Logging captures the command sent to PowerShell, the full command to be executed. Upon enabling, logs will output to Windows event logs. Dependent upon volume, enable on critical endpoints or all. \ -This analytic identifies the behavior of AMSI being tampered with. Implemented natively in many frameworks, the command will look similar to `SEtValuE($Null,(New-OBJEct COLlECtionS.GenerIC.HAshSEt{[StrINg]))}$ReF=[ReF].AsSeMbLY.GeTTyPe("System.Management.Automation.Amsi"+"Utils")` taken from Powershell-Empire. \ -During triage, review parallel processes using an EDR product or 4688 events. It will be important to understand the timeline of events around this activity. Review the entire logged PowerShell script block. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/ T1562] -* '''Last Updated''': 2021-06-09 - -
-
- -====Search==== -`powershell` EventCode=4104 Message=*system.management.automation.amsi* -| stats count min(_time) as firstTime max(_time) as lastTime by OpCode ComputerName User EventCode Message -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `unloading_amsi_via_reflection_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Malicious_PowerShell|Malicious PowerShell]] - - -====How To Implement==== -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -====Required field==== - -* _time - -* Message - -* OpCode - -* ComputerName - -* User - -* EventCode - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1562 -| Impair Defenses -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Potential for some third party applications to disable AMSI upon invocation. Filter as needed. - -====Reference==== - - -* https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -* https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63 - -* https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf - -* https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/windows-powershell.log - - -''version'': 1 -
-
- ----- - -===Unusually long command line=== -Command lines that are extremely long may be indicative of malicious activity on your hosts. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': -* '''Last Updated''': 2020-12-08 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes by Processes.user Processes.dest Processes.process_name Processes.process -| `drop_dm_object_name("Processes")` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| eval processlen=len(process) -| eventstats stdev(processlen) as stdev, avg(processlen) as avg by dest -| stats max(processlen) as maxlen, values(stdev) as stdevperhost, values(avg) as avgperhost by dest, user, process_name, process -| `unusually_long_command_line_filter` -|eval threshold = 3 -| where maxlen > ((threshold*stdevperhost) + avgperhost) - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Command-Line_Executions|Suspicious Command-Line Executions]] - -* [[Documentation:ESSOC:stories:UseCase#Unusual_Processes|Unusual Processes]] - -* [[Documentation:ESSOC:stories:UseCase#Possible_Backdoor_Activity_Associated_With_MUDCARP_Espionage_Campaigns|Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns]] - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - - -====How To Implement==== -You must be ingesting endpoint data that tracks process activity, including parent-child relationships, from your endpoints to populate the Endpoint data model in the Processes node. The command-line arguments are mapped to the process field in the Endpoint data model. - -====Required field==== - -* _time - -* Processes.user - -* Processes.dest - -* Processes.process_name - -* Processes.process - - - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Some legitimate applications start with long command lines. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036.003/atomic_red_team/windows-sysmon.log - - -''version'': 5 -
-
- ----- - -===Unusually long command line=== -Command lines that are extremely long may be indicative of malicious activity on your hosts. This search leverages the Splunk Streaming ML DSP plugin to help identify command lines with lengths that are unusual for a given user. This detection is inspired on Unusually Long Command Line authored by Rico Valdez. - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': -* '''ATT&CK''': -* '''Last Updated''': 2020-10-06 - -
-
- -====Search==== - -| from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)) -| eval cmd_line=ucast(map_get(input_event, "process"), "string", null), dest_user_id=ucast(map_get(input_event, "dest_user_id"), "string", null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), "string", null), process_name=ucast(map_get(input_event, "process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line!=null and dest_user_id!=null -| eval cmd_line_norm=replace(cast(cmd_line, "string"), /\s(--?\w+) -|(\/\w+)/, " ARG"), cmd_line_norm=replace(cmd_line_norm, /\w:\\[^\s]+/, "PATH"), cmd_line_norm=replace(cmd_line_norm, /\d+/, "N"), input=parse_double(len(coalesce(cmd_line_norm, ""))) -| select timestamp, process_name, dest_device_id, dest_user_id, cmd_line, input -| adaptive_threshold algorithm="quantile" entity="process_name" window=60480000 -| where label AND quantile>0.99 -| first_time_event input_columns=["dest_device_id", "cmd_line"] -| where first_time_dest_device_id_cmd_line -| eval start_time = timestamp, end_time = timestamp, entities = mvappend(dest_device_id, dest_user_id), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name]) -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Unusual_Processes|Unusual Processes]] - - -====How To Implement==== -You must be ingesting sysmon endpoint data that monitors command lines. - -====Required field==== - -* process_name - -* _time - -* dest_device_id - -* dest_user_id - -* process - - - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -This detection may flag suspiciously long command lines when there is not sufficient evidence (samples) for a given process that this detection is tracking; or when there is high variability in the length of the command line for the tracked process. Also, some legitimate applications may use long command lines. Such is the case of Ansible, that encodes Powershell scripts using long base64. Attackers may use this technique to obfuscate their payloads. - -====Reference==== - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Unusually long command line - mltk=== -Command lines that are extremely long may be indicative of malicious activity on your hosts. This search leverages the Machine Learning Toolkit (MLTK) to help identify command lines with lengths that are unusual for a given user. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': -* '''Last Updated''': 2019-05-08 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes by Processes.user Processes.dest Processes.process_name Processes.process -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| eval processlen=len(process) -| search user!=unknown -| apply cmdline_pdfmodel threshold=0.01 -| rename "IsOutlier(processlen)" as isOutlier -| search isOutlier > 0 -| table firstTime lastTime user dest process_name process processlen count -| `unusually_long_command_line___mltk_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Command-Line_Executions|Suspicious Command-Line Executions]] - -* [[Documentation:ESSOC:stories:UseCase#Unusual_Processes|Unusual Processes]] - -* [[Documentation:ESSOC:stories:UseCase#Possible_Backdoor_Activity_Associated_With_MUDCARP_Espionage_Campaigns|Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns]] - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - - -====How To Implement==== -You must be ingesting endpoint data that monitors command lines and populates the Endpoint data model in the Processes node. The command-line arguments are mapped to the "process" field in the Endpoint data model. In addition, MLTK version >= 4.2 must be installed on your search heads, along with any required dependencies. Finally, the support search "Baseline of Command Line Length - MLTK" must be executed before this detection search, as it builds an ML model over the historical data used by this search. It is important that this search is run in the same app context as the associated support search, so that the model created by the support search is available for use. You should periodically re-run the support search to rebuild the model with the latest data available in your environment. - -====Required field==== - -* _time - -* Processes.user - -* Processes.dest - -* Processes.process_name - -* Processes.process - - - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Some legitimate applications use long command lines for installs or updates. You should review identified command lines for legitimacy. You may modify the first part of the search to omit legitimate command lines from consideration. If you are seeing more results than desired, you may consider changing the value of threshold in the search to a smaller value. You should also periodically re-run the support search to re-build the ML model on the latest data. You may get unexpected results if the user identified in the results is not present in the data used to build the associated model. - -====Reference==== - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===User discovery with env vars powershell=== -This analytic looks for the execution of `powershell.exe` with command-line arguments that leverage PowerShell environment variables to identify the current logged user. Red Teams and adversaries may leverage this method to identify the logged user on a compromised endpoint for situational awareness and Active Directory Discovery. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1033/ T1033] -* '''Last Updated''': 2021-09-13 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="powershell.exe") (Processes.process="*$env:UserName*" OR Processes.process="*[System.Environment]::UserName*") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `user_discovery_with_env_vars_powershell_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1033 -| System Owner/User Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use this command for troubleshooting. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1033/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1033/AD_discovery/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===User discovery with env vars powershell script block=== -The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the use of PowerShell environment variables to identify the current logged user. Red Teams and adversaries may leverage this method to identify the logged user on a compromised endpoint for situational awareness and Active Directory Discovery. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1033/ T1033] -* '''Last Updated''': 2021-09-13 - -
-
- -====Search==== -`powershell` EventCode=4104 (Message = "*$env:UserName*" OR Message = "*[System.Environment]::UserName*") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `user_discovery_with_env_vars_powershell_script_block_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -====Required field==== - -* _time - -* Path - -* Message - -* OpCode - -* ComputerName - -* User - -* EventCode - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1033 -| System Owner/User Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use this PowerShell commandlet for troubleshooting. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1033/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1033/AD_discovery/windows-powershell.log - - -''version'': 1 -
-
- ----- - -===Vbscript execution using wscript app=== -This analytic is to detect a suspicious wscript commandline to execute vbscript. This technique was seen in several malware to execute malicious vbs file using wscript application. commonly vbs script is associated to cscript process and this can be a technique to evade process parent child detections or even some av script emulation system. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/005/ T1059.005], [https://attack.mitre.org/techniques/T1059/ T1059] -* '''Last Updated''': 2021-10-01 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.parent_process_name = "wscript.exe" AND Processes.parent_process = "*//e:vbscript*") OR (Processes.process_name = "wscript.exe" AND Processes.process = "*//e:vbscript*") by Processes.parent_process_name Processes.parent_process Processes.process_name Processes.process_id Processes.process Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `vbscript_execution_using_wscript_app_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#FIN7|FIN7]] - -* [[Documentation:ESSOC:stories:UseCase#Remcos|Remcos]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1059.005 -| Visual Basic -| Execution -|- -| T1059 -| Command and Scripting Interpreter -| Execution -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://www.joesandbox.com/analysis/369332/0/html - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.005/vbs_wscript/sysmon.log - - -''version'': 1 -
-
- ----- - -===Verclsid clsid execution=== -This analytic is to detect a possible abuse of verclsid to execute malicious file through generate CLSID. This process is a normal application of windows to verify the CLSID COM object before it is instantiated by Windows Explorer. This hunting query can be a good pivot point to analyze what is he CLSID or COM object pointing too to check if it is a valid application or not. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/012/ T1218.012], [https://attack.mitre.org/techniques/T1218/ T1218] -* '''Last Updated''': 2021-09-29 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` values(Processes.process) as process values(Processes.parent_process) as parent_process values(Processes.process_id) as process_id count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_verclsid` AND Processes.process="*/S*" Processes.process="*/C*" AND Processes.process="*{*" AND Processes.process="*}*" by Processes.process_name Processes.original_file_name Processes.dest Processes.user Processes.parent_process_name Processes.parent_process -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `verclsid_clsid_execution_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Unusual_Processes|Unusual Processes]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1218.012 -| Verclsid -| Defense Evasion -|- -| T1218 -| Signed Binary Proxy Execution -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -windows can used this application for its normal COM object validation. - -====Reference==== - - -* https://gist.github.com/NickTyrer/0598b60112eaafe6d07789f7964290d5 - -* https://bohops.com/2018/08/18/abusing-the-com-registry-structure-part-2-loading-techniques-for-evasion-and-persistence/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.012/verclsid_exec/sysmon.log - - -''version'': 1 -
-
- ----- - -===W3wp spawning shell=== -This query identifies a shell, PowerShell.exe or Cmd.exe, spawning from W3WP.exe, or IIS. In addition to IIS logs, this behavior with an EDR product will capture potential webshell activity, similar to the HAFNIUM Group abusing CVEs, on publicly available Exchange mail servers. During triage, review the parent process and child process of the shell being spawned. Review the command-line arguments and any file modifications that may occur. Identify additional parallel process, child processes, that may highlight further commands executed. After triaging, work to contain the threat and patch the system that is vulnerable. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1505/ T1505], [https://attack.mitre.org/techniques/T1505/003/ T1505.003] -* '''Last Updated''': 2021-03-03 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count values(Processes.process_name) as process_name values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=w3wp.exe AND `process_cmd` OR `process_powershell` by Processes.dest Processes.parent_process Processes.original_file_name Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `w3wp_spawning_shell_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#HAFNIUM_Group|HAFNIUM Group]] - -* [[Documentation:ESSOC:stories:UseCase#ProxyShell|ProxyShell]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1505 -| Server Software Component -| Persistence -|- -| T1505.003 -| Web Shell -| Persistence -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -Baseline your environment before production. It is possible build systems using IIS will spawn cmd.exe to perform a software build. Filter as needed. - -====Reference==== - - -* https://www.microsoft.com/security/blog/2020/02/04/ghost-in-the-shell-investigating-web-shell-attacks/ - -* https://www.zerodayinitiative.com/blog/2021/8/17/from-pwn2own-2021-a-new-attack-surface-on-microsoft-exchange-proxyshell - -* https://www.youtube.com/watch?v=FC6iHw258RI - -* https://www.huntress.com/blog/rapid-response-microsoft-exchange-servers-still-vulnerable-to-proxyshell-exploit#what-should-you-do - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1505.003/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Wbadmin delete system backups=== -This search looks for flags passed to wbadmin.exe (Windows Backup Administrator Tool) that delete backup files. This is typically used by ransomware to prevent recovery. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1490/ T1490] -* '''Last Updated''': 2021-01-22 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=wbadmin.exe Processes.process="*delete*" AND (Processes.process="*catalog*" OR Processes.process="*systemstatebackup*") by Processes.process_name Processes.process Processes.parent_process_name Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `wbadmin_delete_system_backups_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Ryuk_Ransomware|Ryuk Ransomware]] - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - - -====How To Implement==== -You must be ingesting endpoint data that tracks process activity, including parent-child relationships from your endpoints to populate the Endpoint data model in the Processes node. Tune based on parent process names. - -====Required field==== - -* _time - -* Processes.process_name - -* Processes.process - -* Processes.parent_process_name - -* Processes.dest - -* Processes.user - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1490 -| Inhibit System Recovery -| Impact -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Administrators may modify the boot configuration. - -====Reference==== - - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1490/T1490.md - -* https://thedfirreport.com/2020/10/08/ryuks-return/ - -* https://attack.mitre.org/techniques/T1490/ - -* https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/wbadmin - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1490/atomic_red_team/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Wmi permanent event subscription=== -This search looks for the creation of WMI permanent event subscriptions. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1047/ T1047] -* '''Last Updated''': 2018-10-23 - -
-
- -====Search==== -`wmi` EventCode=5861 Binding -| rex field=Message "Consumer =\s+(?<consumer>[^; -|^$]+)" -| search consumer!="NTEventLogEventConsumer=\"SCM Event Log Consumer\"" -| stats count min(_time) as firstTime max(_time) as lastTime by ComputerName, consumer, Message -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| rename ComputerName as dest -| `wmi_permanent_event_subscription_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_WMI_Use|Suspicious WMI Use]] - - -====How To Implement==== -To successfully implement this search, you must be ingesting the Windows WMI activity logs. This can be done by adding a stanza to inputs.conf on the system generating logs with a title of [WinEventLog://Microsoft-Windows-WMI-Activity/Operational]. - -====Required field==== - -* _time - -* EventCode - -* Message - -* consumer - -* ComputerName - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1047 -| Windows Management Instrumentation -| Execution -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Although unlikely, administrators may use event subscriptions for legitimate purposes. - -====Reference==== - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Wmi permanent event subscription - sysmon=== -This analytic looks for the creation of WMI permanent event subscriptions. The following analytic identifies the use of WMI Event Subscription to establish persistence or perform privilege escalation. WMI can be used to install event filters, providers, consumers, and bindings that execute code when a defined event occurs. WMI subscription execution is proxied by the WMI Provider Host process (WmiPrvSe.exe) and thus may result in elevated SYSTEM privileges. This analytic is restricted by commonly added process execution and a path. If the volume is low enough, remove the values and flag on any new subscriptions.\ -All event subscriptions have three components \ -1. Filter - WQL Query for the events we want. EventID = 19 \ -1. Consumer - An action to take upon triggering the filter. EventID = 20 \ -1. Binding - Registers a filter to a consumer. EventID = 21 \ -Monitor for the creation of new WMI EventFilter, EventConsumer, and FilterToConsumerBinding. It may be pertinent to review all 3 to identify the flow of execution. In addition, EventCode 4104 may assist with any other PowerShell script usage that registered the subscription. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1546/003/ T1546.003], [https://attack.mitre.org/techniques/T1546/ T1546] -* '''Last Updated''': 2020-12-08 - -
-
- -====Search==== -`sysmon` EventCode=21 -| rename host as dest -| table _time, dest, user, Operation, EventType, Query, Consumer, Filter -| `wmi_permanent_event_subscription___sysmon_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_WMI_Use|Suspicious WMI Use]] - - -====How To Implement==== -To successfully implement this search, you must be collecting Sysmon data using Sysmon version 6.1 or greater and have Sysmon configured to generate alerts for WMI activity (eventID= 19, 20, 21). In addition, you must have at least version 6.0.4 of the Sysmon TA installed to properly parse the fields. - -====Required field==== - -* _time - -* EventCode - -* host - -* user - -* Operation - -* EventType - -* Query - -* Consumer - -* Filter - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1546.003 -| Windows Management Instrumentation Event Subscription -| Privilege Escalation, Persistence -|- -| T1546 -| Event Triggered Execution -| Privilege Escalation, Persistence -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Although unlikely, administrators may use event subscriptions for legitimate purposes. - -====Reference==== - - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1546.003/T1546.003.md - -* https://www.eideon.com/2018-03-02-THL03-WMIBackdoors/ - -* https://github.com/trustedsec/SysmonCommunityGuide/blob/master/WMI-events.md - -* https://in.security/an-intro-into-abusing-and-identifying-wmi-event-subscriptions-for-persistence/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.003/atomic_red_team/windows-sysmon.log - - -''version'': 3 -
-
- ----- - -===Wmi recon running process or services=== -The following analytic identifies suspicious PowerShell script execution via EventCode 4104, where WMI is performing an event query looking for running processes or running services. This technique is commonly found in malware and APT events where the adversary will map all running security applications or services on the compromised machine. During triage, review parallel processes within the same timeframe. Review the full script block to identify other related artifacts. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1592/ T1592] -* '''Last Updated''': 2021-06-14 - -
-
- -====Search==== -`powershell` EventCode=4104 Message= "*SELECT*" AND (Message="*Win32_Process*" OR Message="*Win32_Service*") -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `wmi_recon_running_process_or_services_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Malicious_PowerShell|Malicious PowerShell]] - - -====How To Implement==== -To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. - -====Required field==== - -* _time - -* EventCode - -* Message - -* ComputerName - -* User - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1592 -| Gather Victim Host Information -| Reconnaissance -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -network administrator may used this command for checking purposes - -====Reference==== - - -* https://news.sophos.com/en-us/2020/05/12/maze-ransomware-1-year-counting/ - -* https://www.eideon.com/2018-03-02-THL03-WMIBackdoors/ - -* https://github.com/trustedsec/SysmonCommunityGuide/blob/master/WMI-events.md - -* https://in.security/an-intro-into-abusing-and-identifying-wmi-event-subscriptions-for-persistence/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/pwsh/windows-powershell.log - - -''version'': 1 -
-
- ----- - -===Wmi temporary event subscription=== -This search looks for the creation of WMI temporary event subscriptions. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1047/ T1047] -* '''Last Updated''': 2018-10-23 - -
-
- -====Search==== -`wmi` EventCode=5860 Temporary -| rex field=Message "NotificationQuery =\s+(?<query>[^; -|^$]+)" -| search query!="SELECT * FROM Win32_ProcessStartTrace WHERE ProcessName = 'wsmprovhost.exe'" AND query!="SELECT * FROM __InstanceOperationEvent WHERE TargetInstance ISA 'AntiVirusProduct' OR TargetInstance ISA 'FirewallProduct' OR TargetInstance ISA 'AntiSpywareProduct'" -| stats count min(_time) as firstTime max(_time) as lastTime by ComputerName, query -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `wmi_temporary_event_subscription_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_WMI_Use|Suspicious WMI Use]] - - -====How To Implement==== -To successfully implement this search, you must be ingesting the Windows WMI activity logs. This can be done by adding a stanza to inputs.conf on the system generating logs with a title of [WinEventLog://Microsoft-Windows-WMI-Activity/Operational]. - -====Required field==== - -* _time - -* EventCode - -* Message - -* query - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1047 -| Windows Management Instrumentation -| Execution -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Some software may create WMI temporary event subscriptions for various purposes. The included search contains an exception for two of these that occur by default on Windows 10 systems. You may need to modify the search to create exceptions for other legitimate events. - -====Reference==== - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Wsreset uac bypass=== -This search is to detect a suspicious modification of registry related to UAC bypass. This technique is to modify the registry in this detection, create a registry value with the path of the payload and run WSreset.exe to bypass User account Control. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1548/002/ T1548.002], [https://attack.mitre.org/techniques/T1548/ T1548] -* '''Last Updated''': 2021-07-01 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*\\AppX82a6gwre4fdg3bt635tn5ctqjf8msdd2\\Shell\\open\\command*" (Registry.registry_key_name = "(Default)" OR Registry.registry_key_name = "DelegateExecute") by Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.dest -| `drop_dm_object_name(Registry)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `wsreset_uac_bypass_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Defense_Evasion_Tactics|Windows Defense Evasion Tactics]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. - -====Required field==== - -* _time - -* Registry.registry_path - -* Registry.registry_key_name - -* Registry.registry_value_name - -* Registry.dest - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1548.002 -| Bypass User Account Control -| Privilege Escalation, Defense Evasion -|- -| T1548 -| Abuse Elevation Control Mechanism -| Privilege Escalation, Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://github.com/hfiref0x/UACME - -* https://blog.morphisec.com/trickbot-uses-a-new-windows-10-uac-bypass - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/uac_bypass/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Wbemprox com object execution=== -this search is designed to detect potential malicious process loading COM object to wbemprox.dll, - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/003/ T1218.003] -* '''Last Updated''': 2021-06-02 - -
-
- -====Search==== -`sysmon` EventCode=7 ImageLoaded IN ("*\\fastprox.dll", "*\\wbemprox.dll", "*\\wbemcomn.dll") NOT (process_name IN ("wmiprvse.exe", "WmiApSrv.exe", "unsecapp.exe")) NOT(Image IN("*\\windows\\*","*\\program files*", "*\\wbem\\*")) -| stats count min(_time) as firstTime max(_time) as lastTime by Image ImageLoaded process_name Computer EventCode Signed ProcessId Hashes IMPHASH -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `wbemprox_com_object_execution_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - -* [[Documentation:ESSOC:stories:UseCase#Revil_Ransomware|Revil Ransomware]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name and imageloaded executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -====Required field==== - -* _time - -* Image - -* ImageLoaded - -* process_name - -* Computer - -* EventCode - -* Signed - -* ProcessId - -* Hashes - -* IMPHASH - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1218 -| Signed Binary Proxy Execution -| Defense Evasion -|- -| T1218.003 -| CMSTP -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -legitimate process that are not in the exception list may trigger this event. - -====Reference==== - - -* https://krebsonsecurity.com/2021/05/a-closer-look-at-the-darkside-ransomware-gang/ - -* https://www.mcafee.com/blogs/other-blogs/mcafee-labs/mcafee-atr-analyzes-sodinokibi-aka-revil-ransomware-as-a-service-what-the-code-tells-us/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/revil/inf2/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Wermgr process connecting to ip check web services=== -this search is designed to detect suspicious wermgr.exe process that tries to connect to known IP web services. This technique is know for trickbot and other trojan spy malware to recon the infected machine and look for its ip address without so much finger print on the commandline process. Since wermgr.exe is designed for error handling process of windows it is really suspicious that this process is trying to connect to this IP web services cause that maybe cause of some malicious code injection. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1590/ T1590], [https://attack.mitre.org/techniques/T1590/005/ T1590.005] -* '''Last Updated''': 2021-04-19 - -
-
- -====Search==== -`sysmon` EventCode =22 process_name = wermgr.exe QueryName IN ("*wtfismyip.com", "*checkip.amazonaws.com", "*ipecho.net", "*ipinfo.io", "*api.ipify.org", "*icanhazip.com", "*ip.anysrc.com","*api.ip.sb", "ident.me", "www.myexternalip.com", "*zen.spamhaus.org", "*cbl.abuseat.org", "*b.barracudacentral.org","*dnsbl-1.uceprotect.net", "*spam.dnsbl.sorbs.net") -| stats min(_time) as firstTime max(_time) as lastTime count by process_path process_name process_id QueryName QueryStatus QueryResults Computer EventCode -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `wermgr_process_connecting_to_ip_check_web_services_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Trickbot|Trickbot]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, dns query name process path , and query ststus from your endpoints like EventCode 22. If you are using Sysmon, you must have at least version 12 of the Sysmon TA. - -====Required field==== - -* _time - -* process_path - -* process_name - -* process_id - -* QueryName - -* QueryStatus - -* QueryResults - -* Computer - -* EventCode - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1590 -| Gather Victim Network Information -| Reconnaissance -|- -| T1590.005 -| IP Addresses -| Reconnaissance -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://labs.vipre.com/trickbot-and-its-modules/ - -* https://blog.whitehat.eu/2019/05/incident-trickbot-ryuk-2.html - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/trickbot/infection/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Wermgr process create executable file=== -this search is designed to detect potential malicious wermgr.exe process that drops or create executable file. Since wermgr.exe is an application trigger when error encountered in a process, it is really un ussual to this process to drop executable file. This technique is commonly seen in trickbot malware where it injects it code to this process to execute it malicious behavior like downloading other payload - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1027/ T1027] -* '''Last Updated''': 2021-04-19 - -
-
- -====Search==== -`sysmon` EventCode=11 process_name = "wermgr.exe" TargetFilename = "*.exe" -| stats min(_time) as firstTime max(_time) as lastTime count by Image TargetFilename process_name dest EventCode ProcessId -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `wermgr_process_create_executable_file_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Trickbot|Trickbot]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances of wermgr.exe may be used. - -====Required field==== - -* _time - -* Image - -* TargetFilename - -* process_name - -* dest - -* EventCode - -* ProcessId - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1027 -| Obfuscated Files or Information -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://labs.vipre.com/trickbot-and-its-modules/ - -* https://blog.whitehat.eu/2019/05/incident-trickbot-ryuk-2.html - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/trickbot/infection/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Wermgr process spawned cmd or powershell process=== -This search is designed to detect suspicious cmd and powershell process spawned by wermgr.exe process. This suspicious behavior are commonly seen in code injection technique technique like trickbot to execute a shellcode, dll modules to run malicious behavior. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/ T1059] -* '''Last Updated''': 2021-04-19 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` values(Processes.process) as cmdline min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name = "wermgr.exe" `process_cmd` OR `process_powershell` by Processes.parent_process_name Processes.original_file_name Processes.parent_process_id Processes.process_name Processes.process Processes.process_id Processes.process_guid Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `wermgr_process_spawned_cmd_or_powershell_process_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Trickbot|Trickbot]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1059 -| Command and Scripting Interpreter -| Execution -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://labs.vipre.com/trickbot-and-its-modules/ - -* https://blog.whitehat.eu/2019/05/incident-trickbot-ryuk-2.html - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/trickbot/infection/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Wevtutil usage to clear logs=== -The wevtutil.exe application is the windows event log utility. This searches for wevtutil.exe with parameters for clearing the application, security, setup, powershell, sysmon, or system event logs. - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1070/ T1070], [https://attack.mitre.org/techniques/T1070/001/ T1070.001] -* '''Last Updated''': 2021-06-15 - -
-
- -====Search==== - -| from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line IS NOT NULL AND like(cmd_line, "% cl %") AND (match_regex(cmd_line, /(?i)security/)=true OR match_regex(cmd_line, /(?i)system/)=true OR match_regex(cmd_line, /(?i)sysmon/)=true OR match_regex(cmd_line, /(?i)application/)=true OR match_regex(cmd_line, /(?i)setup/)=true OR match_regex(cmd_line, /(?i)powershell/)=true) AND process_name="wevtutil.exe" -| eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Log_Manipulation|Windows Log Manipulation]] - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - -* [[Documentation:ESSOC:stories:UseCase#Clop_Ransomware|Clop Ransomware]] - - -====How To Implement==== -You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. - -====Required field==== - -* _time - -* dest_device_id - -* process_name - -* parent_process_name - -* process_path - -* dest_user_id - -* process - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1070 -| Indicator Removal on Host -| Defense Evasion -|- -| T1070.001 -| Clear Windows Event Logs -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -The wevtutil.exe application is a legitimate Windows event log utility. Administrators may use it to manage Windows event logs. - -====Reference==== - - -* https://www.splunk.com/en_us/blog/security/detecting-clop-ransomware.html - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070.001/ssa_wevtutil/clear_evt.log - - -''version'': 2 -
-
- ----- - -===Wevtutil usage to disable logs=== -This search is to detect execution of wevtutil.exe to disable logs. This technique was seen in several ransomware to disable the event logs to evade alerts and detections in compromised host. - -* '''Product''': Splunk Behavioral Analytics -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1070/ T1070], [https://attack.mitre.org/techniques/T1070/001/ T1070.001] -* '''Last Updated''': 2021-06-15 - -
-
- -====Search==== - -| from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line IS NOT NULL AND like(cmd_line, "% sl %") AND like(cmd_line, "%/e:false%") AND process_name="wevtutil.exe" -| eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) -| into write_ssa_detected_events(); - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Log_Manipulation|Windows Log Manipulation]] - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - - -====How To Implement==== -You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. - -====Required field==== - -* _time - -* dest_device_id - -* process_name - -* parent_process_name - -* process_path - -* dest_user_id - -* process - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1070 -| Indicator Removal on Host -| Defense Evasion -|- -| T1070.001 -| Clear Windows Event Logs -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -network operator may disable audit event logs for debugging purposes. - -====Reference==== - - -* https://www.bleepingcomputer.com/news/security/new-ransom-x-ransomware-used-in-texas-txdot-cyberattack/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070.001/ssa_wevtutil/disable_evt.log - - -''version'': 2 -
-
- ----- - -===Winevent scheduled task created within public path=== -The following query utilizes Windows Security EventCode 4698, `A scheduled task was created`, to identify suspicious tasks registered on Windows either via schtasks.exe OR TaskService with a command to be executed from a user writeable file path.\ -The search will return the first time and last time the task was registered, as well as the `Command` to be executed, `Task Name`, `Author`, `Enabled`, and whether it is `Hidden` or not.\ -schtasks.exe is natively found in `C:\Windows\system32` and `C:\Windows\syswow64`.\ -The following DLL(s) are loaded when schtasks.exe or TaskService is launched -`taskschd.dll`. If found loaded by another process, it is possible a scheduled task is being registered within that process context in memory.\ -Upon triage, identify the task scheduled source. Was it schtasks.exe or was it via TaskService. Review the job created and the Command to be executed. Capture any artifacts on disk and review. Identify any parallel processes within the same timeframe to identify source. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1053/005/ T1053.005], [https://attack.mitre.org/techniques/T1053/ T1053] -* '''Last Updated''': 2021-04-08 - -
-
- -====Search==== -`wineventlog_security` EventCode=4698 -| xmlkv Message -| search Command IN ("*\\users\\public\\*", "*\\programdata\\*", "*\\temp\\*", "*\\Windows\\Tasks\\*", "*\\appdata\\*") -| stats count min(_time) as firstTime max(_time) as lastTime by dest, Task_Name, Command, Author, Enabled, Hidden -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `winevent_scheduled_task_created_within_public_path_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Persistence_Techniques|Windows Persistence Techniques]] - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - -* [[Documentation:ESSOC:stories:UseCase#Ryuk_Ransomware|Ryuk Ransomware]] - -* [[Documentation:ESSOC:stories:UseCase#IcedID|IcedID]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting Windows Security Event Logs with 4698 EventCode enabled. The Windows TA is also required. - -====Required field==== - -* _time - -* dest - -* Task_Name - -* Description - -* Command - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1053.005 -| Scheduled Task -| Execution, Persistence, Privilege Escalation -|- -| T1053 -| Scheduled Task/Job -| Execution, Persistence, Privilege Escalation -|} - - -====Kill Chain Phase==== - -* Privilege Escalation - - -====Known False Positives==== -False positives are possible if legitimate applications are allowed to register tasks in public paths. Filter as needed based on paths that are used legitimately. - -====Reference==== - - -* https://research.checkpoint.com/2021/irans-apt34-returns-with-an-updated-arsenal/ - -* https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=4698 - -* https://redcanary.com/threat-detection-report/techniques/scheduled-task-job/ - -* https://docs.microsoft.com/en-us/windows/win32/taskschd/time-trigger-example--scripting-?redirectedfrom=MSDN - -* https://app.any.run/tasks/e26f1b2e-befa-483b-91d2-e18636e2faf3/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/taskschedule/windows-security.log - - -''version'': 1 -
-
- ----- - -===Winevent scheduled task created to spawn shell=== -The following query utilizes Windows Security EventCode 4698, `A scheduled task was created`, to identify suspicious tasks registered on Windows either via schtasks.exe OR TaskService with a command to be executed with a native Windows shell (PowerShell, Cmd, Wscript, Cscript).\ -The search will return the first time and last time the task was registered, as well as the `Command` to be executed, `Task Name`, `Author`, `Enabled`, and whether it is `Hidden` or not.\ -schtasks.exe is natively found in `C:\Windows\system32` and `C:\Windows\syswow64`.\ -The following DLL(s) are loaded when schtasks.exe or TaskService is launched -`taskschd.dll`. If found loaded by another process, it is possible a scheduled task is being registered within that process context in memory.\ -Upon triage, identify the task scheduled source. Was it schtasks.exe or via TaskService? Review the job created and the Command to be executed. Capture any artifacts on disk and review. Identify any parallel processes within the same timeframe to identify source. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1053/005/ T1053.005], [https://attack.mitre.org/techniques/T1053/ T1053] -* '''Last Updated''': 2021-04-12 - -
-
- -====Search==== -`wineventlog_security` EventCode=4698 -| xmlkv Message -| search Command IN ("*powershell.exe*", "*wscript.exe*", "*cscript.exe*", "*cmd.exe*", "*sh.exe*", "*ksh.exe*", "*zsh.exe*", "*bash.exe*", "*scrcons.exe*", "*pwsh.exe*") -| stats count min(_time) as firstTime max(_time) as lastTime by dest, Task_Name, Command, Author, Enabled, Hidden -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `winevent_scheduled_task_created_to_spawn_shell_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Persistence_Techniques|Windows Persistence Techniques]] - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - -* [[Documentation:ESSOC:stories:UseCase#Ryuk_Ransomware|Ryuk Ransomware]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting Windows Security Event Logs with 4698 EventCode enabled. The Windows TA is also required. - -====Required field==== - -* _time - -* dest - -* Task_Name - -* Description - -* Command - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1053.005 -| Scheduled Task -| Execution, Persistence, Privilege Escalation -|- -| T1053 -| Scheduled Task/Job -| Execution, Persistence, Privilege Escalation -|} - - -====Kill Chain Phase==== - -* Privilege Escalation - - -====Known False Positives==== -False positives are possible if legitimate applications are allowed to register tasks that call a shell to be spawned. Filter as needed based on command-line or processes that are used legitimately. - -====Reference==== - - -* https://research.checkpoint.com/2021/irans-apt34-returns-with-an-updated-arsenal/ - -* https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=4698 - -* https://redcanary.com/threat-detection-report/techniques/scheduled-task-job/ - -* https://docs.microsoft.com/en-us/windows/win32/taskschd/time-trigger-example--scripting-?redirectedfrom=MSDN - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/atomic_red_team/windows-security.log - - -''version'': 1 -
-
- ----- - -===Winrm spawning a process=== -The following analytic identifies suspicious processes spawning from WinRM (wsmprovhost.exe). This analytic is related to potential exploitation of CVE-2021-31166. which is a kernel-mode device driver http.sys vulnerability. Current proof of concept code will blue-screen the operating system. However, http.sys used by many different Windows processes, including WinRM. In this case, identifying suspicious process create (child processes) from `wsmprovhost.exe` is what this analytic is identifying. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1190/ T1190] -* '''Last Updated''': 2021-05-21 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=wsmprovhost.exe Processes.process_name IN ("cmd.exe","sh.exe","bash.exe","powershell.exe","pwsh.exe","schtasks.exe","certutil.exe","whoami.exe","bitsadmin.exe","scp.exe") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `winrm_spawning_a_process_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Unusual_Processes|Unusual Processes]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1190 -| Exploit Public-Facing Application -| Initial Access -|} - - -====Kill Chain Phase==== - -* Exploitation - -* Privilege Escalation - -* Denial of Service - - -====Known False Positives==== -Unknown. Add new processes or filter as needed. It is possible system management software may spawn processes from `wsmprovhost.exe`. - -====Reference==== - - -* https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_access/win_susp_shell_spawn_from_winrm.yml - -* https://www.zerodayinitiative.com/blog/2021/5/17/cve-2021-31166-a-wormable-code-execution-bug-in-httpsys - -* https://github.com/0vercl0k/CVE-2021-31166/blob/main/cve-2021-31166.py - - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Windows adfind exe=== -This search looks for the execution of `adfind.exe` with command-line arguments that it uses by default. Specifically the filter or search functions. It also considers the arguments necessary like objectcategory, see readme for more details: https://www.joeware.net/freetools/tools/adfind/usage.htm. This has been seen used before by Wizard Spider, FIN6 and actors whom also launched SUNBURST. AdFind.exe is usually used a recon tool to enumare a domain controller. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1018/ T1018] -* '''Last Updated''': 2020-12-16 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process=*-f* OR Processes.process=*-b*) AND (Processes.process=*objectcategory* OR Processes.process=*-gcb* OR Processes.process=*-sc*) by Processes.dest Processes.user Processes.process_name Processes.process Processes.parent_process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_adfind_exe_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#NOBELIUM_Group|NOBELIUM Group]] - -* [[Documentation:ESSOC:stories:UseCase#Domain_Trust_Discovery|Domain Trust Discovery]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -====Required field==== - -* _time - -* Processes.process - -* Processes.dest - -* Processes.user - -* Processes.process_name - -* Processes.parent_process - -* Processes.process_id - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1018 -| Remote System Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -administrators rarely use adfind, usually not used for legitimate reasons - -====Reference==== - - -* https://www.volexity.com/blog/2020/12/14/dark-halo-leverages-solarwinds-compromise-to-breach-organizations/ - -* https://www.fireeye.com/blog/threat-research/2019/01/a-nasty-trick-from-credential-theft-malware-to-business-disruption.html - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/atomic_red_team/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Windows disableantispyware registry=== -The search looks for the Registry Key DisableAntiSpyware set to disable. This is consistent with Ryuk infections across a fleet of endpoints. This particular behavior is typically executed when an ransomware actor gains access to an endpoint and beings to perform execution. Usually, a batch (.bat) will be executed and multiple registry and scheduled task modifications will occur. During triage, review parallel processes and identify any further file modifications. Endpoint should be isolated. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001], [https://attack.mitre.org/techniques/T1562/ T1562] -* '''Last Updated''': 2021-03-02 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_key_name="DisableAntiSpyware" AND Registry.registry_value_name="DWORD (0x00000001)" by Registry.dest Registry.user Registry.registry_path Registry.registry_value_name -| `drop_dm_object_name(Registry)` -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `windows_disableantispyware_registry_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Ryuk_Ransomware|Ryuk Ransomware]] - -* [[Documentation:ESSOC:stories:UseCase#Windows_Defense_Evasion_Tactics|Windows Defense Evasion Tactics]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. - -====Required field==== - -* _time - -* Registry.registry_key_name - -* Registry.registry_value_name - -* Registry.dest - -* Registry.user - -* Registry.registry_path - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1562.001 -| Disable or Modify Tools -| Defense Evasion -|- -| T1562 -| Impair Defenses -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Delivery - - -====Known False Positives==== -It is unusual to turn this feature off a Windows system since it is a default security control, although it is not rare for some policies to disable it. Although no false positives have been identified, use the provided filter macro to tune the search. - -====Reference==== - - -* https://blog.malwarebytes.com/malwarebytes-news/2021/02/lazyscripter-from-empire-to-double-rat/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/atomic_red_team/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Windows event log cleared=== -The following analytic utilizes Windows Security Event ID 1102 or System log event 104 to identify when a Windows event log is cleared. Note that this analytic will require tuning or restricted to specific endpoints based on criticality. During triage, based on time of day and user, determine if this was planned. If not planned, follow through with reviewing parallel alerts and other data sources to determine what else may have occurred. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1070/ T1070], [https://attack.mitre.org/techniques/T1070/001/ T1070.001] -* '''Last Updated''': 2020-07-06 - -
-
- -====Search==== -(`wineventlog_security` EventCode=1102) OR (`wineventlog_system` EventCode=104) -| stats count min(_time) as firstTime max(_time) as lastTime by dest Message EventCode -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_event_log_cleared_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_Log_Manipulation|Windows Log Manipulation]] - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - -* [[Documentation:ESSOC:stories:UseCase#Clop_Ransomware|Clop Ransomware]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting Windows event logs from your hosts. In addition, the Splunk Windows TA is needed. - -====Required field==== - -* _time - -* EventCode - -* dest - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1070 -| Indicator Removal on Host -| Defense Evasion -|- -| T1070.001 -| Clear Windows Event Logs -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -It is possible that these logs may be legitimately cleared by Administrators. Filter as needed. - -====Reference==== - - -* https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-1102 - -* https://www.ired.team/offensive-security/defense-evasion/disabling-windows-event-logs-by-suspending-eventlog-service-threads - -* https://attack.mitre.org/techniques/T1070/001/ - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1070.001/T1070.001.md - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070.001/atomic_red_team/windows-security.log - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070.001/atomic_red_team/windows-system.log - - -''version'': 6 -
-
- ----- - -===Windows security account manager stopped=== -The search looks for a Windows Security Account Manager (SAM) was stopped via command-line. This is consistent with Ryuk infections across a fleet of endpoints. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1489/ T1489] -* '''Last Updated''': 2020-11-06 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes WHERE ("Processes.process_name"="net*.exe" "Processes.process"="*stop \"samss\"*") BY "Processes.dest", "Processes.user", "Processes.process" -| `drop_dm_object_name(Processes)` -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `windows_security_account_manager_stopped_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Ryuk_Ransomware|Ryuk Ransomware]] - - -====How To Implement==== -You must be ingesting data that records the process-system activity from your hosts to populate the Endpoint Processes data-model object. If you are using Sysmon, you will need a Splunk Universal Forwarder on each endpoint from which you want to collect data. - -====Required field==== - -* _time - -* Processes.process_name - -* Processes.process - -* Processes.dest - -* Processes.user - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1489 -| Service Stop -| Impact -|} - - -====Kill Chain Phase==== - -* Delivery - - -====Known False Positives==== -SAM is a critical windows service, stopping it would cause major issues on an endpoint this makes false positive rare. AlthoughNo false positives have been identified. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ryuk/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Winhlp32 spawning a process=== -The following analytic identifies winhlp32.exe, found natively in `c:\windows\`, spawning a child process that loads a file out of appdata, programdata, or temp. Winhlp32.exe has a rocky past in that multiple vulnerabilities were found and added to MetaSploit. WinHlp32.exe is required to display 32-bit Help files that have the ".hlp" file name extension. This particular instance is related to a Remcos sample where dynwrapx.dll is added to the registry under inprocserver32, and later module loaded by winhlp32.exe to spawn wscript.exe and load a vbs or file from disk. During triage, review parallel processes to identify further suspicious behavior. Review module loads for unsuspecting unsigned modules. Capture any file modifications and analyze. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1055/ T1055] -* '''Last Updated''': 2021-10-05 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=winhlp32.exe Processes.process IN ("*\\appdata\\*","*\\programdata\\*", "*\\temp\\*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `winhlp32_spawning_a_process_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Remcos|Remcos]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1055 -| Process Injection -| Defense Evasion, Privilege Escalation -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -False positives should be limited as winhlp32.exe is typically not used with the latest flavors of Windows OS. However, filter as needed. - -====Reference==== - - -* https://www.exploit-db.com/exploits/16541 - -* https://tria.ge/210929-ap75vsddan - -* https://www.virustotal.com/gui/file/cb77b93150cb0f7fe65ce8a7e2a5781e727419451355a7736db84109fa215a89 - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Winword spawning cmd=== -The following detection identifies Microsoft Word spawning `cmd.exe`. Typically, this is not common behavior and not default with winword.exe. Winword.exe will generally be found in the following path `C:\Program Files\Microsoft Office\root\Office16` (version will vary). Cmd.exe spawning from winword.exe is common for a spearphishing attachment and is actively used. Albeit, the command-line will indicate what is being executed. During triage, review parallel processes and identify any files that may have been written. It is possible that COM is utilized to trampoline the child process to `explorer.exe` or `wmiprvse.exe`. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/ T1566], [https://attack.mitre.org/techniques/T1566/001/ T1566.001] -* '''Last Updated''': 2021-04-22 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=winword.exe `process_cmd` by Processes.dest Processes.user Processes.parent_process Processes.original_file_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `winword_spawning_cmd_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Spearphishing_Attachments|Spearphishing Attachments]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1566 -| Phishing -| Initial Access -|- -| T1566.001 -| Spearphishing Attachment -| Initial Access -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -False positives should be limited, but if any are present, filter as needed. - -====Reference==== - - -* https://app.any.run/tasks/73af0064-a785-4c0a-ab0d-cde593fe16ef/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Winword spawning powershell=== -The following detection identifies Microsoft Word spawning PowerShell. Typically, this is not common behavior and not default with winword.exe. Winword.exe will generally be found in the following path `C:\Program Files\Microsoft Office\root\Office16` (version will vary). PowerShell spawning from winword.exe is common for a spearphishing attachment and is actively used. Albeit, the command executed will most likely be encoded and captured via another detection. During triage, review parallel processes and identify any files that may have been written. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/ T1566], [https://attack.mitre.org/techniques/T1566/001/ T1566.001] -* '''Last Updated''': 2021-04-12 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name="winword.exe" `process_powershell` by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `winword_spawning_powershell_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Spearphishing_Attachments|Spearphishing Attachments]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1566 -| Phishing -| Initial Access -|- -| T1566.001 -| Spearphishing Attachment -| Initial Access -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -False positives should be limited, but if any are present, filter as needed. - -====Reference==== - - -* https://redcanary.com/threat-detection-report/techniques/powershell/ - -* https://attack.mitre.org/techniques/T1566/001/ - -* https://app.any.run/tasks/b79fa381-f35c-4b3e-8d02-507e7ee7342f/ - -* https://app.any.run/tasks/181ac90b-0898-4631-8701-b778a30610ad/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon.log - - -''version'': 2 -
-
- ----- - -===Winword spawning windows script host=== -The following detection identifies Microsoft Winword.exe spawning Windows Script Host - `cscript.exe` or `wscript.exe`. Typically, this is not common behavior and not default with Winword.exe. Winword.exe will generally be found in the following path `C:\Program Files\Microsoft Office\root\Office16` (version will vary). `cscript.exe` or `wscript.exe` default location is `c:\windows\system32\` or c:windows\syswow64\`. `cscript.exe` or `wscript.exe` spawning from Winword.exe is common for a spearphishing attachment and is actively used. Albeit, the command-line executed will most likely be obfuscated and captured via another detection. During triage, review parallel processes and identify any files that may have been written. Review the reputation of the remote destination and block accordingly. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/ T1566], [https://attack.mitre.org/techniques/T1566/001/ T1566.001] -* '''Last Updated''': 2021-04-12 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name="winword.exe" Processes.process_name IN ("cscript.exe", "wscript.exe") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `winword_spawning_windows_script_host_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Spearphishing_Attachment|Spearphishing Attachment]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. - -====Required field==== - -* _time - -* process_name - -* process_id - -* parent_process_name - -* dest - -* user - -* parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1566 -| Phishing -| Initial Access -|- -| T1566.001 -| Spearphishing Attachment -| Initial Access -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -There will be limited false positives and it will be different for every environment. Tune by child process or command-line as needed. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1566/001/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_wsh.log - - -''version'': 1 -
-
- ----- - -===Wmic group discovery=== -The following hunting analytic identifies the use of `wmic.exe` enumerating local groups on the endpoint. \ -Typically, by itself, is not malicious but may raise suspicion based on time of day, endpoint and username. \ -During triage, review parallel processes and identify any further suspicious behavior. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1069/ T1069], [https://attack.mitre.org/techniques/T1069/001/ T1069.001] -* '''Last Updated''': 2021-09-14 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=wmic.exe (Processes.process="*group get name*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.original_file_name Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `wmic_group_discovery_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Active_Directory_Discovery|Active Directory Discovery]] - - -====How To Implement==== -To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1069 -| Permission Groups Discovery -| Discovery -|- -| T1069.001 -| Local Groups -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Administrators or power users may use this command for troubleshooting. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1069/001/ - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1069.001/T1069.001.md - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.001/atomic_red_team/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Write executable in smb share=== -This search is to detect suspicious dropping or creating an executable file in known sensitive SMB share. This technique is commonly used for lateral movement like how trickbot try to infect other machine in the infected network. This detection catch the access event (FILE WRITE) access to a share. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1021/ T1021], [https://attack.mitre.org/techniques/T1021/002/ T1021.002] -* '''Last Updated''': 2021-04-23 - -
-
- -====Search==== -`wineventlog_security` EventCode=5145 Relative_Target_Name IN ("*.exe","*.dll") Object_Type=File Share_Name IN ("\\\\*\\C$","\\\\*\\IPC$","\\\\*\\admin$") Access_Mask= "0x2" -| stats min(_time) as firstTime max(_time) as lastTime count by EventCode Share_Name Relative_Target_Name Object_Type Access_Mask user src_port Source_Address -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `write_executable_in_smb_share_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Trickbot|Trickbot]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting Windows Security Event Logs with 5145 EventCode enabled. The Windows TA is also required. Also enable the object Audit access success/failure in your group policy. - -====Required field==== - -* _time - -* EventCode - -* Share_Name - -* Relative_Target_Name - -* Object_Type - -* Access_Mask - -* user - -* src_port - -* Source_Address - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1021 -| Remote Services -| Lateral Movement -|- -| T1021.002 -| SMB/Windows Admin Shares -| Lateral Movement -|} - - -====Kill Chain Phase==== - -* Lateral Movement - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://labs.vipre.com/trickbot-and-its-modules/ - -* https://blog.whitehat.eu/2019/05/incident-trickbot-ryuk-2.html - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/trickbot/exe_smbshare/windows-security.log - - -''version'': 1 -
-
- ----- - -===Wscript or cscript suspicious child process=== -This analytic is to detect a suspicious spawned process by wscript or cscript process. This technique was a common technique used by adversaries and malware to execute different LOLBIN, other script like powershell or create a suspended process to inject its code as a defense evasion. This TTP may detect some normal script that using several application tool that are in the list of the child process it detects but a good pivot and indicator that a script is may execute suspicious code. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1055/ T1055], [https://attack.mitre.org/techniques/T1543/ T1543], [https://attack.mitre.org/techniques/T1134/004/ T1134.004], [https://attack.mitre.org/techniques/T1134/ T1134] -* '''Last Updated''': 2021-10-06 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name IN ("cscript.exe", "wscript.exe") Processes.process_name IN ("regsvr32.exe", "rundll32.exe","winhlp32.exe","certutil.exe","msbuild.exe","cmd.exe","powershell*","wmic.exe","mshta.exe") by Processes.dest Processes.user Processes.parent_process_name Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `wscript_or_cscript_suspicious_child_process_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#FIN7|FIN7]] - -* [[Documentation:ESSOC:stories:UseCase#Remcos|Remcos]] - -* [[Documentation:ESSOC:stories:UseCase#Unusual_Processes|Unusual Processes]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -====Required field==== - -* _time - -* Processes.dest - -* Processes.user - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.original_file_name - -* Processes.process_name - -* Processes.process - -* Processes.process_id - -* Processes.parent_process_path - -* Processes.process_path - -* Processes.parent_process_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1055 -| Process Injection -| Defense Evasion, Privilege Escalation -|- -| T1543 -| Create or Modify System Process -| Persistence, Privilege Escalation -|- -| T1134.004 -| Parent PID Spoofing -| Defense Evasion, Privilege Escalation -|- -| T1134 -| Access Token Manipulation -| Defense Evasion, Privilege Escalation -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -user may create vbs or js script that use several tool as part of its execution. - -====Reference==== - - -* https://www.hybrid-analysis.com/sample/8da5b75b6380a41eee3a399c43dfe0d99eeefaa1fd21027a07b1ecaa4cd96fdd?environmentId=120 - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.005/vbs_wscript/sysmon.log - - -''version'': 1 -
-
- ----- - -===Xmrig driver loaded=== -This analytic identifies XMRIG coinminer driver installation on the system. The XMRIG driver name by default is `WinRing0x64.sys`. This cpu miner is an open source project that is commonly abused by adversaries to infect and mine bitcoin. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1543/003/ T1543.003], [https://attack.mitre.org/techniques/T1543/ T1543] -* '''Last Updated''': 2021-04-29 - -
-
- -====Search==== -`sysmon` EventCode=6 Signature="Noriyuki MIYAZAKI" OR ImageLoaded= "*\\WinRing0x64.sys" -| stats min(_time) as firstTime max(_time) as lastTime count by Computer ImageLoaded Hashes IMPHASH Signature Signed -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `xmrig_driver_loaded_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#XMRig|XMRig]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the driver loaded and Signature from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -====Required field==== - -* _time - -* Computer - -* ImageLoaded - -* Hashes - -* IMPHASH - -* Signature - -* Signed - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1543.003 -| Windows Service -| Persistence, Privilege Escalation -|- -| T1543 -| Create or Modify System Process -| Persistence, Privilege Escalation -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -False positives should be limited. - -====Reference==== - - -* https://www.trendmicro.com/vinfo/hk/threat-encyclopedia/malware/trojan.ps1.powtran.a/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log - - -''version'': 1 -
-
- ----- - -===Xsl script execution with wmic=== -This search is to detect a suspicious wmic.exe process or renamed wmic process to execute malicious xsl file. This technique was seen in FIN7 to execute its malicous jscript using the .xsl as the loader with the help of wmic.exe process. This TTP is really a good indicator for you to hunt further for FIN7 or other attacker that known to used this technique. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1220/ T1220] -* '''Last Updated''': 2021-09-13 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process = "*os get*" Processes.process="*/format:*" Processes.process = "*.xsl*" by Processes.parent_process_name Processes.parent_process Processes.process_name Processes.process_id Processes.process Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `xsl_script_execution_with_wmic_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#FIN7|FIN7]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - -====Required field==== - -* _time - -* Processes.parent_process_name - -* Processes.parent_process - -* Processes.process_name - -* Processes.process_id - -* Processes.process - -* Processes.dest - -* Processes.user - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1220 -| XSL Script Processing -| Defense Evasion -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://www.fireeye.com/blog/threat-research/2018/08/fin7-pursuing-an-enigmatic-and-evasive-global-criminal-operation.html - -* https://attack.mitre.org/groups/G0046/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/fin7/fin7_macro_js_1/sysmon.log - - -''version'': 1 -
-
- ----- - - - -==Network== - - -===Dns query length outliers - mltk=== -This search allows you to identify DNS requests that are unusually large for the record type being requested in your environment. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Network_Resolution -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1071/004/ T1071.004], [https://attack.mitre.org/techniques/T1071/ T1071] -* '''Last Updated''': 2020-01-22 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as start_time max(_time) as end_time values(DNS.src) as src values(DNS.dest) as dest from datamodel=Network_Resolution by DNS.query DNS.record_type -| search DNS.record_type=* -| `drop_dm_object_name(DNS)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| eval query_length = len(query) -| apply dns_query_pdfmodel threshold=0.01 -| rename "IsOutlier(query_length)" as isOutlier -| search isOutlier > 0 -| sort -query_length -| table start_time end_time query record_type count src dest query_length -| `dns_query_length_outliers___mltk_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Hidden_Cobra_Malware|Hidden Cobra Malware]] - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_DNS_Traffic|Suspicious DNS Traffic]] - -* [[Documentation:ESSOC:stories:UseCase#Command_and_Control|Command and Control]] - - -====How To Implement==== -To successfully implement this search, you will need to ensure that DNS data is populating the Network_Resolution data model. In addition, the Machine Learning Toolkit (MLTK) version 4.2 or greater must be installed on your search heads, along with any required dependencies. Finally, the support search "Baseline of DNS Query Length - MLTK" must be executed before this detection search, because it builds a machine-learning (ML) model over the historical data used by this search. It is important that this search is run in the same app context as the associated support search, so that the model created by the support search is available for use. You should periodically re-run the support search to rebuild the model with the latest data available in your environment.\ -This search produces fields (`query`,`query_length`,`count`) that are not yet supported by ES Incident Review and therefore cannot be viewed when a notable event is raised. These fields contribute additional context to the notable. To see the additional metadata, add the following fields, if not already present, to Incident Review - Event Attributes (Configure > Incident Management > Incident Review Settings > Add New Entry):\\n1. **Label:** DNS Query, **Field:** query\ -1. \ -1. **Label:** DNS Query Length, **Field:** query_length\ -1. \ -1. **Label:** Number of events, **Field:** count\ -Detailed documentation on how to create a new field within Incident Review may be found here: `https://docs.splunk.com/Documentation/ES/5.3.0/Admin/Customizenotables#Add_a_field_to_the_notable_event_details` - -====Required field==== - -* _time - -* DNS.src - -* DNS.dest - -* DNS.query - -* DNS.record_type - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1071.004 -| DNS -| Command And Control -|- -| T1071 -| Application Layer Protocol -| Command And Control -|} - - -====Kill Chain Phase==== - -* Command and Control - - -====Known False Positives==== -If you are seeing more results than desired, you may consider reducing the value for threshold in the search. You should also periodically re-run the support search to re-build the ML model on the latest data. - -====Reference==== - - -====Test Dataset==== - - -''version'': 2 -
-
- ----- - -===Dns query length with high standard deviation=== -This search allows you to identify DNS requests and compute the standard deviation on the length of the names being resolved, then filter on two times the standard deviation to show you those queries that are unusually large for your environment. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Network_Resolution -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1048/003/ T1048.003], [https://attack.mitre.org/techniques/T1048/ T1048] -* '''Last Updated''': 2021-10-06 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count from datamodel=Network_Resolution where NOT DNS.message_type IN("Pointer","PTR") by DNS.query -| `drop_dm_object_name("DNS")` -| eval tlds=split(query,".") -| eval tld=mvindex(tlds,-1) -| eval tld_len=len(tld) -| search tld_len<=24 -| eval query_length = len(query) -| table query query_length record_type count -| eventstats stdev(query_length) AS stdev avg(query_length) AS avg p50(query_length) AS p50 -| where query_length>(avg+stdev*2) -| eval z_score=(query_length-avg)/stdev -| `dns_query_length_with_high_standard_deviation_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Hidden_Cobra_Malware|Hidden Cobra Malware]] - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_DNS_Traffic|Suspicious DNS Traffic]] - -* [[Documentation:ESSOC:stories:UseCase#Command_and_Control|Command and Control]] - - -====How To Implement==== -To successfully implement this search, you will need to ensure that DNS data is populating the Network_Resolution data model. - -====Required field==== - -* _time - -* DNS.query - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1048.003 -| Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol -| Exfiltration -|- -| T1048 -| Exfiltration Over Alternative Protocol -| Exfiltration -|} - - -====Kill Chain Phase==== - -* Command and Control - - -====Known False Positives==== -It's possible there can be long domain names that are legitimate. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1048.003/long_dns_queries/windows-sysmon.log - - -''version'': 4 -
-
- ----- - -===Detect arp poisoning=== -By enabling Dynamic ARP Inspection as a Layer 2 Security measure on the organization's network devices, we will be able to detect ARP Poisoning attacks in the Infrastructure. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1200/ T1200], [https://attack.mitre.org/techniques/T1498/ T1498], [https://attack.mitre.org/techniques/T1557/ T1557], [https://attack.mitre.org/techniques/T1557/002/ T1557.002] -* '''Last Updated''': 2020-08-11 - -
-
- -====Search==== -`cisco_networks` facility="PM" mnemonic="ERR_DISABLE" disable_cause="arp-inspection" -| eval src_interface=src_int_prefix_long+src_int_suffix -| stats min(_time) AS firstTime max(_time) AS lastTime count BY host src_interface -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -| `detect_arp_poisoning_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Router_and_Infrastructure_Security|Router and Infrastructure Security]] - - -====How To Implement==== -This search uses a standard SPL query on logs from Cisco Network devices. The network devices must be configured with DHCP Snooping (see https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst2960x/software/15-0_2_EX/security/configuration_guide/b_sec_152ex_2960-x_cg/b_sec_152ex_2960-x_cg_chapter_01101.html) and Dynamic ARP Inspection (see https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst2960x/software/15-2_2_e/security/configuration_guide/b_sec_1522e_2960x_cg/b_sec_1522e_2960x_cg_chapter_01111.html) and log with a severity level of minimum "5 - notification". The search also requires that the Cisco Networks Add-on for Splunk (https://splunkbase.splunk.com/app/1467) is used to parse the logs from the Cisco network devices. - -====Required field==== - -* _time - -* facility - -* mnemonic - -* disable_cause - -* src_int_prefix_long - -* src_int_suffix - -* host - -* src_interface - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1200 -| Hardware Additions -| Initial Access -|- -| T1498 -| Network Denial of Service -| Impact -|- -| T1557 -| Adversary-in-the-Middle -| Credential Access, Collection -|- -| T1557.002 -| ARP Cache Poisoning -| Credential Access, Collection -|} - - -====Kill Chain Phase==== - -* Reconnaissance - -* Delivery - -* Actions on Objectives - - -====Known False Positives==== -This search might be prone to high false positives if DHCP Snooping or ARP inspection has been incorrectly configured, or if a device normally sends many ARP packets (unlikely). - -====Reference==== - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Detect ipv6 network infrastructure threats=== -By enabling IPv6 First Hop Security as a Layer 2 Security measure on the organization's network devices, we will be able to detect various attacks such as packet forging in the Infrastructure. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1200/ T1200], [https://attack.mitre.org/techniques/T1498/ T1498], [https://attack.mitre.org/techniques/T1557/ T1557], [https://attack.mitre.org/techniques/T1557/002/ T1557.002] -* '''Last Updated''': 2020-10-28 - -
-
- -====Search==== -`cisco_networks` facility="SISF" mnemonic IN ("IP_THEFT","MAC_THEFT","MAC_AND_IP_THEFT","PAK_DROP") -| eval src_interface=src_int_prefix_long+src_int_suffix -| eval dest_interface=dest_int_prefix_long+dest_int_suffix -| stats min(_time) AS firstTime max(_time) AS lastTime values(src_mac) AS src_mac values(src_vlan) AS src_vlan values(mnemonic) AS mnemonic values(vendor_explanation) AS vendor_explanation values(src_ip) AS src_ip values(dest_ip) AS dest_ip values(dest_interface) AS dest_interface values(action) AS action count BY host src_interface -| table host src_interface dest_interface src_mac src_ip dest_ip src_vlan mnemonic vendor_explanation action count -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -| `detect_ipv6_network_infrastructure_threats_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Router_and_Infrastructure_Security|Router and Infrastructure Security]] - - -====How To Implement==== -This search uses a standard SPL query on logs from Cisco Network devices. The network devices must be configured with one or more First Hop Security measures such as RA Guard, DHCP Guard and/or device tracking. See References for more information. The search also requires that the Cisco Networks Add-on for Splunk (https://splunkbase.splunk.com/app/1467) is used to parse the logs from the Cisco network devices. - -====Required field==== - -* _time - -* facility - -* mnemonic - -* src_int_prefix_long - -* src_int_suffix - -* dest_int_prefix_long - -* dest_int_suffix - -* src_mac - -* src_vlan - -* vendor_explanation - -* action - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1200 -| Hardware Additions -| Initial Access -|- -| T1498 -| Network Denial of Service -| Impact -|- -| T1557 -| Adversary-in-the-Middle -| Credential Access, Collection -|- -| T1557.002 -| ARP Cache Poisoning -| Credential Access, Collection -|} - - -====Kill Chain Phase==== - -* Reconnaissance - -* Delivery - -* Actions on Objectives - - -====Known False Positives==== -None currently known - -====Reference==== - - -* https://www.ciscolive.com/c/dam/r/ciscolive/emea/docs/2019/pdf/BRKSEC-3200.pdf - -* https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/ipv6_fhsec/configuration/xe-16-12/ip6f-xe-16-12-book/ip6-ra-guard.html - -* https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/ipv6_fhsec/configuration/xe-16-12/ip6f-xe-16-12-book/ip6-snooping.html - -* https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/ipv6_fhsec/configuration/xe-16-12/ip6f-xe-16-12-book/ip6-dad-proxy.html - -* https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/ipv6_fhsec/configuration/xe-16-12/ip6f-xe-16-12-book/ip6-nd-mcast-supp.html - -* https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/ipv6_fhsec/configuration/xe-16-12/ip6f-xe-16-12-book/ip6-dhcpv6-guard.html - -* https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/ipv6_fhsec/configuration/xe-16-12/ip6f-xe-16-12-book/ip6-src-guard.html - -* https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/ipv6_fhsec/configuration/xe-16-12/ip6f-xe-16-12-book/ipv6-dest-guard.html - - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Detect large outbound icmp packets=== -This search looks for outbound ICMP packets with a packet size larger than 1,000 bytes. Various threat actors have been known to use ICMP as a command and control channel for their attack infrastructure. Large ICMP packets from an endpoint to a remote host may be indicative of this activity. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Network_Traffic -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1095/ T1095] -* '''Last Updated''': 2018-06-01 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count earliest(_time) as firstTime latest(_time) as lastTime values(All_Traffic.action) values(All_Traffic.bytes) from datamodel=Network_Traffic where All_Traffic.action !=blocked All_Traffic.dest_category !=internal (All_Traffic.protocol=icmp OR All_Traffic.transport=icmp) All_Traffic.bytes > 1000 by All_Traffic.src_ip All_Traffic.dest_ip -| `drop_dm_object_name("All_Traffic")` -| search ( dest_ip!=10.0.0.0/8 AND dest_ip!=172.16.0.0/12 AND dest_ip!=192.168.0.0/16) -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -| `detect_large_outbound_icmp_packets_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Command_and_Control|Command and Control]] - - -====How To Implement==== -In order to run this search effectively, we highly recommend that you leverage the Assets and Identity framework. It is important that you have a good understanding of how your network segments are designed and that you are able to distinguish internal from external address space. Add a category named `internal` to the CIDRs that host the company's assets in the `assets_by_cidr.csv` lookup file, which is located in `$SPLUNK_HOME/etc/apps/SA-IdentityManagement/lookups/`. More information on updating this lookup can be found here: https://docs.splunk.com/Documentation/ES/5.0.0/Admin/Addassetandidentitydata. This search also requires you to be ingesting your network traffic and populating the Network_Traffic data model - -====Required field==== - -* _time - -* All_Traffic.action - -* All_Traffic.bytes - -* All_Traffic.dest_category - -* All_Traffic.protocol - -* All_Traffic.transport - -* All_Traffic.src_ip - -* All_Traffic.dest_ip - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1095 -| Non-Application Layer Protocol -| Command And Control -|} - - -====Kill Chain Phase==== - -* Command and Control - - -====Known False Positives==== -ICMP packets are used in a variety of ways to help troubleshoot networking issues and ensure the proper flow of traffic. As such, it is possible that a large ICMP packet could be perfectly legitimate. If large ICMP packets are associated with command and control traffic, there will typically be a large number of these packets observed over time. If the search is providing a large number of false positives, you can modify the macro `detect_large_outbound_icmp_packets_filter` to adjust the byte threshold or add specific IP addresses to an allow list. - -====Reference==== - - -====Test Dataset==== - - -''version'': 2 -
-
- ----- - -===Detect outbound smb traffic=== -This search looks for outbound SMB connections made by hosts within your network to the Internet. SMB traffic is used for Windows file-sharing activity. One of the techniques often used by attackers involves retrieving the credential hash using an SMB request made to a compromised server controlled by the threat actor. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Network_Traffic -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1071/002/ T1071.002], [https://attack.mitre.org/techniques/T1071/ T1071] -* '''Last Updated''': 2020-07-21 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` earliest(_time) as start_time latest(_time) as end_time values(All_Traffic.action) as action values(All_Traffic.app) as app values(All_Traffic.dest_ip) as dest_ip values(All_Traffic.dest_port) as dest_port values(sourcetype) as sourcetype count from datamodel=Network_Traffic where ((All_Traffic.dest_port=139 OR All_Traffic.dest_port=445 OR All_Traffic.app="smb") AND NOT (All_Traffic.action="blocked" OR All_Traffic.dest_category="internal" OR All_Traffic.dest_ip=10.0.0.0/8 OR All_Traffic.dest_ip=172.16.0.0/12 OR All_Traffic.dest_ip=192.168.0.0/16 OR All_Traffic.dest_ip=100.64.0.0/10)) by All_Traffic.src_ip -| `drop_dm_object_name("All_Traffic")` -| `security_content_ctime(start_time)` -| `security_content_ctime(end_time)` -| `detect_outbound_smb_traffic_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Hidden_Cobra_Malware|Hidden Cobra Malware]] - -* [[Documentation:ESSOC:stories:UseCase#DHS_Report_TA18-074A|DHS Report TA18-074A]] - -* [[Documentation:ESSOC:stories:UseCase#NOBELIUM_Group|NOBELIUM Group]] - - -====How To Implement==== -In order to run this search effectively, we highly recommend that you leverage the Assets and Identity framework. It is important that you have good understanding of how your network segments are designed, and be able to distinguish internal from external address space. Add a category named `internal` to the CIDRs that host the companys assets in `assets_by_cidr.csv` lookup file, which is located in `$SPLUNK_HOME/etc/apps/SA-IdentityManagement/lookups/`. More information on updating this lookup can be found here: https://docs.splunk.com/Documentation/ES/5.0.0/Admin/Addassetandidentitydata. This search also requires you to be ingesting your network traffic and populating the Network_Traffic data model - -====Required field==== - -* _time - -* All_Traffic.action - -* All_Traffic.app - -* All_Traffic.dest_ip - -* All_Traffic.dest_port - -* sourcetype - -* All_Traffic.dest_category - -* All_Traffic.src_ip - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1071.002 -| File Transfer Protocols -| Command And Control -|- -| T1071 -| Application Layer Protocol -| Command And Control -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - -* Command and Control - - -====Known False Positives==== -It is likely that the outbound Server Message Block (SMB) traffic is legitimate, if the company's internal networks are not well-defined in the Assets and Identity Framework. Categorize the internal CIDR blocks as `internal` in the lookup file to avoid creating notable events for traffic destined to those CIDR blocks. Any other network connection that is going out to the Internet should be investigated and blocked. Best practices suggest preventing external communications of all SMB versions and related protocols at the network boundary. - -====Reference==== - - -====Test Dataset==== - - -''version'': 3 -
-
- ----- - -===Detect port security violation=== -By enabling Port Security on a Cisco switch you can restrict input to an interface by limiting and identifying MAC addresses of the workstations that are allowed to access the port. When you assign secure MAC addresses to a secure port, the port does not forward packets with source addresses outside the group of defined addresses. If you limit the number of secure MAC addresses to one and assign a single secure MAC address, the workstation attached to that port is assured the full bandwidth of the port. If a port is configured as a secure port and the maximum number of secure MAC addresses is reached, when the MAC address of a workstation attempting to access the port is different from any of the identified secure MAC addresses, a security violation occurs. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1200/ T1200], [https://attack.mitre.org/techniques/T1498/ T1498], [https://attack.mitre.org/techniques/T1557/ T1557], [https://attack.mitre.org/techniques/T1557/002/ T1557.002] -* '''Last Updated''': 2020-10-28 - -
-
- -====Search==== -`cisco_networks` (facility="PM" mnemonic="ERR_DISABLE" disable_cause="psecure-violation") OR (facility="PORT_SECURITY" mnemonic="PSECURE_VIOLATION" OR mnemonic="PSECURE_VIOLATION_VLAN") -| eval src_interface=src_int_prefix_long+src_int_suffix -| stats min(_time) AS firstTime max(_time) AS lastTime values(disable_cause) AS disable_cause values(src_mac) AS src_mac values(src_vlan) AS src_vlan values(action) AS action count by host src_interface -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_port_security_violation_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Router_and_Infrastructure_Security|Router and Infrastructure Security]] - - -====How To Implement==== -This search uses a standard SPL query on logs from Cisco Network devices. The network devices must be configured with Port Security and Error Disable for this to work (see https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst4500/12-2/25ew/configuration/guide/conf/port_sec.html) and log with a severity level of minimum "5 - notification". The search also requires that the Cisco Networks Add-on for Splunk (https://splunkbase.splunk.com/app/1467) is used to parse the logs from the Cisco network devices. - -====Required field==== - -* _time - -* facility - -* mnemonic - -* disable_cause - -* src_int_prefix_long - -* src_int_suffix - -* src_mac - -* src_vlan - -* action - -* host - -* src_interface - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1200 -| Hardware Additions -| Initial Access -|- -| T1498 -| Network Denial of Service -| Impact -|- -| T1557 -| Adversary-in-the-Middle -| Credential Access, Collection -|- -| T1557.002 -| ARP Cache Poisoning -| Credential Access, Collection -|} - - -====Kill Chain Phase==== - -* Reconnaissance - -* Delivery - -* Exploitation - -* Actions on Objectives - - -====Known False Positives==== -This search might be prone to high false positives if you have malfunctioning devices connected to your ethernet ports or if end users periodically connect physical devices to the network. - -====Reference==== - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Detect rogue dhcp server=== -By enabling DHCP Snooping as a Layer 2 Security measure on the organization's network devices, we will be able to detect unauthorized DHCP servers handing out DHCP leases to devices on the network (Man in the Middle attack). - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1200/ T1200], [https://attack.mitre.org/techniques/T1498/ T1498], [https://attack.mitre.org/techniques/T1557/ T1557] -* '''Last Updated''': 2020-08-11 - -
-
- -====Search==== -`cisco_networks` facility="DHCP_SNOOPING" mnemonic="DHCP_SNOOPING_UNTRUSTED_PORT" -| stats min(_time) AS firstTime max(_time) AS lastTime count values(message_type) AS message_type values(src_mac) AS src_mac BY host -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -| `detect_rogue_dhcp_server_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Router_and_Infrastructure_Security|Router and Infrastructure Security]] - - -====How To Implement==== -This search uses a standard SPL query on logs from Cisco Network devices. The network devices must be configured with DHCP Snooping enabled (see https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst2960x/software/15-0_2_EX/security/configuration_guide/b_sec_152ex_2960-x_cg/b_sec_152ex_2960-x_cg_chapter_01101.html) and log with a severity level of minimum "5 - notification". The search also requires that the Cisco Networks Add-on for Splunk (https://splunkbase.splunk.com/app/1467) is used to parse the logs from the Cisco network devices. - -====Required field==== - -* _time - -* facility - -* mnemonic - -* message_type - -* src_mac - -* host - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1200 -| Hardware Additions -| Initial Access -|- -| T1498 -| Network Denial of Service -| Impact -|- -| T1557 -| Adversary-in-the-Middle -| Credential Access, Collection -|} - - -====Kill Chain Phase==== - -* Reconnaissance - -* Delivery - -* Actions on Objectives - - -====Known False Positives==== -This search might be prone to high false positives if DHCP Snooping has been incorrectly configured or in the unlikely event that the DHCP server has been moved to another network interface. - -====Reference==== - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Detect snicat sni exfiltration=== -This search looks for commands that the SNICat tool uses in the TLS SNI field. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1041/ T1041] -* '''Last Updated''': 2020-10-21 - -
-
- -====Search==== -`zeek_ssl` -| rex field=server_name "(?<snicat>(LIST -|LS -|SIZE -|LD -|CB -|CD -|EX -|ALIVE -|EXIT -|WHERE -|finito)-[A-Za-z0-9]{16}\.)" -| stats count by src_ip dest_ip server_name snicat -| where count>0 -| table src_ip dest_ip server_name snicat -| `detect_snicat_sni_exfiltration_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Data_Exfiltration|Data Exfiltration]] - - -====How To Implement==== -You must be ingesting Zeek SSL data into Splunk. Zeek data should also be getting ingested in JSON format. We are detecting when any of the predefined SNICat commands are found within the server_name (SNI) field. These commands are LIST, LS, SIZE, LD, CB, EX, ALIVE, EXIT, WHERE, and finito. You can go further once this has been detected, and run other searches to decode the SNI data to prove or disprove if any data exfiltration has taken place. - -====Required field==== - -* _time - -* server_name - -* src_ip - -* dest_ip - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1041 -| Exfiltration Over C2 Channel -| Exfiltration -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Unknown - -====Reference==== - - -* https://www.mnemonic.no/blog/introducing-snicat/ - -* https://github.com/mnemonic-no/SNIcat - -* https://attack.mitre.org/techniques/T1041/ - - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Detect software download to network device=== -Adversaries may abuse netbooting to load an unauthorized network device operating system from a Trivial File Transfer Protocol (TFTP) server. TFTP boot (netbooting) is commonly used by network administrators to load configuration-controlled network device images from a centralized management server. Netbooting is one option in the boot sequence and can be used to centralize, manage, and control device images. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Network_Traffic -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1542/005/ T1542.005], [https://attack.mitre.org/techniques/T1542/ T1542] -* '''Last Updated''': 2020-10-28 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Network_Traffic where (All_Traffic.transport=udp AND All_Traffic.dest_port=69) OR (All_Traffic.transport=tcp AND All_Traffic.dest_port=21) OR (All_Traffic.transport=tcp AND All_Traffic.dest_port=22) AND All_Traffic.dest_category!=common_software_repo_destination AND All_Traffic.src_category=network OR All_Traffic.src_category=router OR All_Traffic.src_category=switch by All_Traffic.src All_Traffic.dest All_Traffic.dest_port -| `drop_dm_object_name("All_Traffic")` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_software_download_to_network_device_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Router_and_Infrastructure_Security|Router and Infrastructure Security]] - - -====How To Implement==== -This search looks for Network Traffic events to TFTP, FTP or SSH/SCP ports from network devices. Make sure to tag any network devices as network, router or switch in order for this detection to work. If the TFTP traffic doesn't traverse a firewall nor packet inspection, these events will not be logged. This is typically an issue if the TFTP server is on the same subnet as the network device. There is also a chance of the network device loading software using a DHCP assigned IP address (netboot) which is not in the Asset inventory. - -====Required field==== - -* _time - -* All_Traffic.transport - -* All_Traffic.dest_port - -* All_Traffic.dest_category - -* All_Traffic.src_category - -* All_Traffic.src - -* All_Traffic.dest - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1542.005 -| TFTP Boot -| Defense Evasion, Persistence -|- -| T1542 -| Pre-OS Boot -| Defense Evasion, Persistence -|} - - -====Kill Chain Phase==== - -* Delivery - - -====Known False Positives==== -This search will also report any legitimate attempts of software downloads to network devices as well as outbound SSH sessions from network devices. - -====Reference==== - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Detect traffic mirroring=== -Adversaries may leverage traffic mirroring in order to automate data exfiltration over compromised network infrastructure. Traffic mirroring is a native feature for some network devices and used for network analysis and may be configured to duplicate traffic and forward to one or more destinations for analysis by a network analyzer or other monitoring device. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1200/ T1200], [https://attack.mitre.org/techniques/T1020/ T1020], [https://attack.mitre.org/techniques/T1498/ T1498], [https://attack.mitre.org/techniques/T1020/001/ T1020.001] -* '''Last Updated''': 2020-10-28 - -
-
- -====Search==== -`cisco_networks` (facility="MIRROR" mnemonic="ETH_SPAN_SESSION_UP") OR (facility="SPAN" mnemonic="SESSION_UP") OR (facility="SPAN" mnemonic="PKTCAP_START") OR (mnemonic="CFGLOG_LOGGEDCMD" command="monitor session*") -| stats min(_time) AS firstTime max(_time) AS lastTime count BY host facility mnemonic -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -| `detect_traffic_mirroring_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Router_and_Infrastructure_Security|Router and Infrastructure Security]] - - -====How To Implement==== -This search uses a standard SPL query on logs from Cisco Network devices. The network devices must log with a severity level of minimum "5 - notification". The search also requires that the Cisco Networks Add-on for Splunk (https://splunkbase.splunk.com/app/1467) is used to parse the logs from the Cisco network devices and that the devices have been configured according to the documentation of the Cisco Networks Add-on. Also note that an attacker may disable logging from the device prior to enabling traffic mirroring. - -====Required field==== - -* _time - -* facility - -* mnemonic - -* host - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1200 -| Hardware Additions -| Initial Access -|- -| T1020 -| Automated Exfiltration -| Exfiltration -|- -| T1498 -| Network Denial of Service -| Impact -|- -| T1020.001 -| Traffic Duplication -| Exfiltration -|} - - -====Kill Chain Phase==== - -* Delivery - -* Actions on Objectives - - -====Known False Positives==== -This search will return false positives for any legitimate traffic captures by network administrators. - -====Reference==== - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Detect unauthorized assets by mac address=== -By populating the organization's assets within the assets_by_str.csv, we will be able to detect unauthorized devices that are trying to connect with the organization's network by inspecting DHCP request packets, which are issued by devices when they attempt to obtain an IP address from the DHCP server. The MAC address associated with the source of the DHCP request is checked against the list of known devices, and reports on those that are not found. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Network_Sessions -* '''ATT&CK''': -* '''Last Updated''': 2017-09-13 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count from datamodel=Network_Sessions where nodename=All_Sessions.DHCP All_Sessions.signature=DHCPREQUEST by All_Sessions.src_ip All_Sessions.dest_mac -| dedup All_Sessions.dest_mac -| `drop_dm_object_name("Network_Sessions")` -|`drop_dm_object_name("All_Sessions")` -| search NOT [ -| inputlookup asset_lookup_by_str -|rename mac as dest_mac -| fields + dest_mac] -| `detect_unauthorized_assets_by_mac_address_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Asset_Tracking|Asset Tracking]] - - -====How To Implement==== -This search uses the Network_Sessions data model shipped with Enterprise Security. It leverages the Assets and Identity framework to populate the assets_by_str.csv file located in SA-IdentityManagement, which will contain a list of known authorized organizational assets including their MAC addresses. Ensure that all inventoried systems have their MAC address populated. - -====Required field==== - -* _time - -* All_Sessions.signature - -* All_Sessions.src_ip - -* All_Sessions.dest_mac - - - - -====Kill Chain Phase==== - -* Reconnaissance - -* Delivery - -* Actions on Objectives - - -====Known False Positives==== -This search might be prone to high false positives. Please consider this when conducting analysis or investigations. Authorized devices may be detected as unauthorized. If this is the case, verify the MAC address of the system responsible for the false positive and add it to the Assets and Identity framework with the proper information. - -====Reference==== - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Detect windows dns sigred via splunk stream=== -This search detects SIGRed via Splunk Stream. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1203/ T1203] -* '''Last Updated''': 2020-07-28 - -
-
- -====Search==== -`stream_dns` -| spath "query_type{}" -| search "query_type{}" IN (SIG,KEY) -| spath protocol_stack -| search protocol_stack="ip:tcp:dns" -| append [search `stream_tcp` bytes_out>65000] -| `detect_windows_dns_sigred_via_splunk_stream_filter` -| stats count by flow_id -| where count>1 -| fields - count - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_DNS_SIGRed_CVE-2020-1350|Windows DNS SIGRed CVE-2020-1350]] - - -====How To Implement==== -You must be ingesting Splunk Stream DNS and Splunk Stream TCP. We are detecting SIG and KEY records via stream:dns and TCP payload over 65KB in size via stream:tcp. Replace the macro definitions ('stream:dns' and 'stream:tcp') with configurations for your Splunk environment. - -====Required field==== - -* _time - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1203 -| Exploitation for Client Execution -| Execution -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://research.checkpoint.com/2020/resolving-your-way-into-domain-admin-exploiting-a-17-year-old-bug-in-windows-dns-servers/ - - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Detect windows dns sigred via zeek=== -This search detects SIGRed via Zeek DNS and Zeek Conn data. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Network_Resolution -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1203/ T1203] -* '''Last Updated''': 2020-07-28 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count from datamodel=Network_Resolution where DNS.query_type IN (SIG,KEY) by DNS.flow_id -| rename DNS.flow_id as flow_id -| append [ -| tstats `security_content_summariesonly` count from datamodel=Network_Traffic where All_Traffic.bytes_in>65000 by All_Traffic.flow_id -| rename All_Traffic.flow_id as flow_id] -| `detect_windows_dns_sigred_via_zeek_filter` -| stats count by flow_id -| where count>1 -| fields - count - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Windows_DNS_SIGRed_CVE-2020-1350|Windows DNS SIGRed CVE-2020-1350]] - - -====How To Implement==== -You must be ingesting Zeek DNS and Zeek Conn data into Splunk. Zeek data should also be getting ingested in JSON format. We are detecting SIG and KEY records via bro:dns:json and TCP payload over 65KB in size via bro:conn:json. The Network Resolution and Network Traffic datamodels are in use for this search. - -====Required field==== - -* _time - -* DNS.query_type - -* DNS.flow_id - -* All_Traffic.bytes_in - -* All_Traffic.flow_id - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1203 -| Exploitation for Client Execution -| Execution -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://research.checkpoint.com/2020/resolving-your-way-into-domain-admin-exploiting-a-17-year-old-bug-in-windows-dns-servers/ - - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Detect zerologon via zeek=== -This search detects attempts to run exploits for the Zerologon CVE-2020-1472 vulnerability via Zeek RPC - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1190/ T1190] -* '''Last Updated''': 2020-09-15 - -
-
- -====Search==== -`zeek_rpc` operation IN (NetrServerPasswordSet2,NetrServerReqChallenge,NetrServerAuthenticate3) -| bin span=5m _time -| stats values(operation) dc(operation) as opscount count(eval(operation=="NetrServerReqChallenge")) as challenge count(eval(operation=="NetrServerAuthenticate3")) as authcount count(eval(operation=="NetrServerPasswordSet2")) as passcount count as totalcount by _time,src_ip,dest_ip -| search opscount=3 authcount>4 passcount>0 -| search `detect_zerologon_via_zeek_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Detect_Zerologon_Attack|Detect Zerologon Attack]] - - -====How To Implement==== -You must be ingesting Zeek DCE-RPC data into Splunk. Zeek data should also be getting ingested in JSON format. We are detecting when all three RPC operations (NetrServerReqChallenge, NetrServerAuthenticate3, NetrServerPasswordSet2) are splunk_security_essentials_app via bro:rpc:json. These three operations are then correlated on the Zeek UID field. - -====Required field==== - -* _time - -* operation - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1190 -| Exploit Public-Facing Application -| Initial Access -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://www.secura.com/blog/zero-logon - -* https://github.com/SecuraBV/CVE-2020-1472 - -* https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1472 - - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Detect hosts connecting to dynamic domain providers=== -Malicious actors often abuse legitimate Dynamic DNS services to host malicious payloads or interactive command and control nodes. Attackers will automate domain resolution changes by routing dynamic domains to countless IP addresses to circumvent firewall blocks, block lists as well as frustrate a network defenders analytic and investigative processes. This search will look for DNS queries made from within your infrastructure to suspicious dynamic domains. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Network_Resolution -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1189/ T1189] -* '''Last Updated''': 2021-01-14 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count values(DNS.answer) as answer min(_time) as firstTime from datamodel=Network_Resolution by DNS.query host -| `drop_dm_object_name("DNS")` -| `security_content_ctime(firstTime)` -| `dynamic_dns_providers` -| `detect_hosts_connecting_to_dynamic_domain_providers_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Data_Protection|Data Protection]] - -* [[Documentation:ESSOC:stories:UseCase#Prohibited_Traffic_Allowed_or_Protocol_Mismatch|Prohibited Traffic Allowed or Protocol Mismatch]] - -* [[Documentation:ESSOC:stories:UseCase#DNS_Hijacking|DNS Hijacking]] - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_DNS_Traffic|Suspicious DNS Traffic]] - -* [[Documentation:ESSOC:stories:UseCase#Dynamic_DNS|Dynamic DNS]] - -* [[Documentation:ESSOC:stories:UseCase#Command_and_Control|Command and Control]] - - -====How To Implement==== -First, you'll need to ingest data from your DNS operations. This can be done by ingesting logs from your server or data, collected passively by Splunk Stream or a similar solution. Specifically, data that contains the domain that is being queried and the IP of the host originating the request must be populating the `Network_Resolution` data model. This search also leverages a lookup file, `dynamic_dns_providers_default.csv`, which contains a non-exhaustive list of Dynamic DNS providers. Please consider updating the local lookup periodically by adding new domains to the list of `dynamic_dns_providers_local.csv`.\ -This search produces fields (query, answer, isDynDNS) that are not yet supported by ES Incident Review and therefore cannot be viewed when a notable event is raised. These fields contribute additional context to the notable event. To see the additional metadata, add the following fields, if not already present, to Incident Review. Event Attributes (Configure > Incident Management > Incident Review Settings > Add New Entry):\\n1. **Label:** DNS Query, **Field:** query\ -1. \ -1. **Label:** DNS Answer, **Field:** answer\ -1. \ -1. **Label:** IsDynamicDNS, **Field:** isDynDNS\ -Detailed documentation on how to create a new field within Incident Review may be found here: `https://docs.splunk.com/Documentation/ES/5.3.0/Admin/Customizenotables#Add_a_field_to_the_notable_event_details` - -====Required field==== - -* _time - -* DNS.answer - -* DNS.query - -* host - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1189 -| Drive-by Compromise -| Initial Access -|} - - -====Kill Chain Phase==== - -* Command and Control - -* Actions on Objectives - - -====Known False Positives==== -Some users and applications may leverage Dynamic DNS to reach out to some domains on the Internet since dynamic DNS by itself is not malicious, however this activity must be verified. - -====Reference==== - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1189/dyn_dns_site/windows-sysmon.log - - -''version'': 3 -
-
- ----- - -===Excessive dns failures=== -This search identifies DNS query failures by counting the number of DNS responses that do not indicate success, and trigger on more than 50 occurrences. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Network_Resolution -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1071/004/ T1071.004], [https://attack.mitre.org/techniques/T1071/ T1071] -* '''Last Updated''': 2020-07-21 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count values("DNS.query") as queries from datamodel=Network_Resolution where nodename=DNS "DNS.reply_code"!="No Error" "DNS.reply_code"!="NoError" DNS.reply_code!="unknown" NOT "DNS.query"="*.arpa" "DNS.query"="*.*" by "DNS.src","DNS.query" -| `drop_dm_object_name("DNS")` -| lookup cim_corporate_web_domain_lookup domain as query OUTPUT domain -| where isnull(domain) -| lookup update=true alexa_lookup_by_str domain as query OUTPUT rank -| where isnull(rank) -| stats sum(count) as count mode(queries) as queries by src -| `get_asset(src)` -| where count>50 -| `excessive_dns_failures_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_DNS_Traffic|Suspicious DNS Traffic]] - -* [[Documentation:ESSOC:stories:UseCase#Command_and_Control|Command and Control]] - - -====How To Implement==== -To successfully implement this search you must ensure that DNS data is populating the Network_Resolution data model. - -====Required field==== - -* _time - -* DNS.query - -* DNS.reply_code - -* DNS.src - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1071.004 -| DNS -| Command And Control -|- -| T1071 -| Application Layer Protocol -| Command And Control -|} - - -====Kill Chain Phase==== - -* Command and Control - - -====Known False Positives==== -It is possible legitimate traffic can trigger this rule. Please investigate as appropriate. The threshold for generating an event can also be customized to better suit your environment. - -====Reference==== - - -====Test Dataset==== - - -''version'': 2 -
-
- ----- - -===Hosts receiving high volume of network traffic from email server=== -This search looks for an increase of data transfers from your email server to your clients. This could be indicative of a malicious actor collecting data using your email server. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Network_Traffic -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1114/002/ T1114.002], [https://attack.mitre.org/techniques/T1114/ T1114] -* '''Last Updated''': 2020-07-21 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` sum(All_Traffic.bytes_in) as bytes_in from datamodel=Network_Traffic where All_Traffic.dest_category=email_server by All_Traffic.src_ip _time span=1d -| `drop_dm_object_name("All_Traffic")` -| eventstats avg(bytes_in) as avg_bytes_in stdev(bytes_in) as stdev_bytes_in -| eventstats count as num_data_samples avg(eval(if(_time < relative_time(now(), "@d"), bytes_in, null))) as per_source_avg_bytes_in stdev(eval(if(_time < relative_time(now(), "@d"), bytes_in, null))) as per_source_stdev_bytes_in by src_ip -| eval minimum_data_samples = 4, deviation_threshold = 3 -| where num_data_samples >= minimum_data_samples AND bytes_in > (avg_bytes_in + (deviation_threshold * stdev_bytes_in)) AND bytes_in > (per_source_avg_bytes_in + (deviation_threshold * per_source_stdev_bytes_in)) AND _time >= relative_time(now(), "@d") -| eval num_standard_deviations_away_from_server_average = round(abs(bytes_in - avg_bytes_in) / stdev_bytes_in, 2), num_standard_deviations_away_from_client_average = round(abs(bytes_in - per_source_avg_bytes_in) / per_source_stdev_bytes_in, 2) -| table src_ip, _time, bytes_in, avg_bytes_in, per_source_avg_bytes_in, num_standard_deviations_away_from_server_average, num_standard_deviations_away_from_client_average -| `hosts_receiving_high_volume_of_network_traffic_from_email_server_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Collection_and_Staging|Collection and Staging]] - - -====How To Implement==== -This search requires you to be ingesting your network traffic and populating the Network_Traffic data model. Your email servers must be categorized as "email_server" for the search to work, as well. You may need to adjust the deviation_threshold and minimum_data_samples values based on the network traffic in your environment. The "deviation_threshold" field is a multiplying factor to control how much variation you're willing to tolerate. The "minimum_data_samples" field is the minimum number of connections of data samples required for the statistic to be valid. - -====Required field==== - -* _time - -* All_Traffic.bytes_in - -* All_Traffic.dest_category - -* All_Traffic.src_ip - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1114.002 -| Remote Email Collection -| Collection -|- -| T1114 -| Email Collection -| Collection -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -The false-positive rate will vary based on how you set the deviation_threshold and data_samples values. Our recommendation is to adjust these values based on your network traffic to and from your email servers. - -====Reference==== - - -====Test Dataset==== - - -''version'': 2 -
-
- ----- - -===Large volume of dns any queries=== -The search is used to identify attempts to use your DNS Infrastructure for DDoS purposes via a DNS amplification attack leveraging ANY queries. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Network_Resolution -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1498/ T1498], [https://attack.mitre.org/techniques/T1498/002/ T1498.002] -* '''Last Updated''': 2017-09-20 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count from datamodel=Network_Resolution where nodename=DNS "DNS.message_type"="QUERY" "DNS.record_type"="ANY" by "DNS.dest" -| `drop_dm_object_name("DNS")` -| where count>200 -| `large_volume_of_dns_any_queries_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#DNS_Amplification_Attacks|DNS Amplification Attacks]] - - -====How To Implement==== -To successfully implement this search you must ensure that DNS data is populating the Network_Resolution data model. - -====Required field==== - -* _time - -* DNS.message_type - -* DNS.record_type - -* DNS.dest - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1498 -| Network Denial of Service -| Impact -|- -| T1498.002 -| Reflection Amplification -| Impact -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Legitimate ANY requests may trigger this search, however it is unusual to see a large volume of them under typical circumstances. You may modify the threshold in the search to better suit your environment. - -====Reference==== - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Multiple archive files http post traffic=== -This search is designed to detect high frequency of archive files data exfiltration through HTTP POST method protocol. This are one of the common techniques used by APT or trojan spy after doing the data collection like screenshot, recording, sensitive data to the infected machines. The attacker may execute archiving command to the collected data, save it a temp folder with a hidden attribute then send it to its C2 through HTTP POST. Sometimes adversaries will rename the archive files or encode/encrypt to cover their tracks. This detection can detect a renamed archive files transfer to HTTP POST since it checks the request body header. Unfortunately this detection cannot support archive that was encrypted or encoded before doing the exfiltration. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Network_Traffic -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1048/003/ T1048.003], [https://attack.mitre.org/techniques/T1048/ T1048] -* '''Last Updated''': 2021-04-21 - -
-
- -====Search==== -`stream_http` http_method=POST -|eval archive_hdr1=substr(form_data,1,2) -| eval archive_hdr2 = substr(form_data,1,4) -|stats values(form_data) as http_request_body min(_time) as firstTime max(_time) as lastTime count by http_method http_user_agent uri_path url bytes_in bytes_out archive_hdr1 archive_hdr2 -|where count >20 AND (archive_hdr1 = "7z" OR archive_hdr1 = "PK" OR archive_hdr2="Rar!") -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `multiple_archive_files_http_post_traffic_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Command_and_Control|Command and Control]] - -* [[Documentation:ESSOC:stories:UseCase#Data_Exfiltration|Data Exfiltration]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the stream HTTP logs or network logs that catch network traffic. Make sure that the http-request-body, payload, or request field is enabled in stream http configuration. - -====Required field==== - -* _time - -* http_method - -* http_user_agent - -* uri_path - -* url - -* bytes_in - -* bytes_out - -* archive_hdr1 - -* archive_hdr2 - -* form_data - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1048.003 -| Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol -| Exfiltration -|- -| T1048 -| Exfiltration Over Alternative Protocol -| Exfiltration -|} - - -====Kill Chain Phase==== - -* Exfiltration - - -====Known False Positives==== -Normal archive transfer via HTTP protocol may trip this detection. - -====Reference==== - - -* https://attack.mitre.org/techniques/T1560/001/ - -* https://www.fireeye.com/blog/threat-research/2019/01/apt39-iranian-cyber-espionage-group-focused-on-personal-information.html - -* https://www.microsoft.com/security/blog/2021/01/20/deep-dive-into-the-solorigate-second-stage-activation-from-sunburst-to-teardrop-and-raindrop/ - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1048.003/archive_http_post/stream_http_events.log - - -''version'': 1 -
-
- ----- - -===Plain http post exfiltrated data=== -This search is to detect potential plain HTTP POST method data exfiltration. This network traffic is commonly used by trickbot, trojanspy, keylogger or APT adversary where arguments or commands are sent in plain text to the remote C2 server using HTTP POST method as part of data exfiltration. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Network_Traffic -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1048/003/ T1048.003], [https://attack.mitre.org/techniques/T1048/ T1048] -* '''Last Updated''': 2021-04-22 - -
-
- -====Search==== -`stream_http` http_method=POST form_data IN ("*wermgr.exe*","*svchost.exe*", "*name=\"proclist\"*","*ipconfig*", "*name=\"sysinfo\"*", "*net view*") -|stats values(form_data) as http_request_body min(_time) as firstTime max(_time) as lastTime count by http_method http_user_agent uri_path url bytes_in bytes_out -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `plain_http_post_exfiltrated_data_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Command_and_Control|Command and Control]] - -* [[Documentation:ESSOC:stories:UseCase#Data_Exfiltration|Data Exfiltration]] - - -====How To Implement==== -To successfully implement this search, you need to be ingesting logs with the stream HTTP logs or network logs that catch network traffic. Make sure that the http-request-body, payload, or request field is enabled. - -====Required field==== - -* _time - -* http_method - -* http_user_agent - -* uri_path - -* url - -* bytes_in - -* bytes_out - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1048.003 -| Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol -| Exfiltration -|- -| T1048 -| Exfiltration Over Alternative Protocol -| Exfiltration -|} - - -====Kill Chain Phase==== - -* Exfiltration - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://blog.talosintelligence.com/2020/03/trickbot-primer.html - - - -====Test Dataset==== - -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1048.003/plain_exfil_data/stream_http_events.log - - -''version'': 1 -
-
- ----- - -===Prohibited network traffic allowed=== -This search looks for network traffic defined by port and transport layer protocol in the Enterprise Security lookup table "lookup_interesting_ports", that is marked as prohibited, and has an associated 'allow' action in the Network_Traffic data model. This could be indicative of a misconfigured network device. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Network_Traffic -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1048/ T1048] -* '''Last Updated''': 2020-07-21 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Network_Traffic where All_Traffic.action = allowed by All_Traffic.src_ip All_Traffic.dest_ip All_Traffic.dest_port All_Traffic.action -| lookup update=true interesting_ports_lookup dest_port as All_Traffic.dest_port OUTPUT app is_prohibited note transport -| search is_prohibited=true -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `drop_dm_object_name("All_Traffic")` -| `prohibited_network_traffic_allowed_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Prohibited_Traffic_Allowed_or_Protocol_Mismatch|Prohibited Traffic Allowed or Protocol Mismatch]] - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - -* [[Documentation:ESSOC:stories:UseCase#Command_and_Control|Command and Control]] - - -====How To Implement==== -In order to properly run this search, Splunk needs to ingest data from firewalls or other network control devices that mediate the traffic allowed into an environment. This is necessary so that the search can identify an 'action' taken on the traffic of interest. The search requires the Network_Traffic data model be populated. - -====Required field==== - -* _time - -* All_Traffic.action - -* All_Traffic.src_ip - -* All_Traffic.dest_ip - -* All_Traffic.dest_port - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1048 -| Exfiltration Over Alternative Protocol -| Exfiltration -|} - - -====Kill Chain Phase==== - -* Delivery - -* Command and Control - - -====Known False Positives==== -None identified - -====Reference==== - - -====Test Dataset==== - - -''version'': 2 -
-
- ----- - -===Protocol or port mismatch=== -This search looks for network traffic on common ports where a higher layer protocol does not match the port that is being used. For example, this search should identify cases where protocols other than HTTP are running on TCP port 80. This can be used by attackers to circumvent firewall restrictions, or as an attempt to hide malicious communications over ports and protocols that are typically allowed and not well inspected. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Network_Traffic -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1048/003/ T1048.003], [https://attack.mitre.org/techniques/T1048/ T1048] -* '''Last Updated''': 2020-07-21 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Network_Traffic where (All_Traffic.app=dns NOT All_Traffic.dest_port=53) OR ((All_Traffic.app=web-browsing OR All_Traffic.app=http) NOT (All_Traffic.dest_port=80 OR All_Traffic.dest_port=8080 OR All_Traffic.dest_port=8000)) OR (All_Traffic.app=ssl NOT (All_Traffic.dest_port=443 OR All_Traffic.dest_port=8443)) OR (All_Traffic.app=smtp NOT All_Traffic.dest_port=25) by All_Traffic.src_ip, All_Traffic.dest_ip, All_Traffic.app, All_Traffic.dest_port -|`security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `drop_dm_object_name("All_Traffic")` -| `protocol_or_port_mismatch_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Prohibited_Traffic_Allowed_or_Protocol_Mismatch|Prohibited Traffic Allowed or Protocol Mismatch]] - -* [[Documentation:ESSOC:stories:UseCase#Command_and_Control|Command and Control]] - - -====How To Implement==== -Running this search properly requires a technology that can inspect network traffic and identify common protocols. Technologies such as Bro and Palo Alto Networks firewalls are two examples that will identify protocols via inspection, and not just assume a specific protocol based on the transport protocol and ports. - -====Required field==== - -* _time - -* All_Traffic.app - -* All_Traffic.dest_port - -* All_Traffic.src_ip - -* All_Traffic.dest_ip - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1048.003 -| Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol -| Exfiltration -|- -| T1048 -| Exfiltration Over Alternative Protocol -| Exfiltration -|} - - -====Kill Chain Phase==== - -* Command and Control - - -====Known False Positives==== -None identified - -====Reference==== - - -====Test Dataset==== - - -''version'': 2 -
-
- ----- - -===Protocols passing authentication in cleartext=== -The following analytic identifies cleartext protocols at risk of leaking sensitive information. Currently, this consists of legacy protocols such as telnet (port 23), POP3 (port 110), IMAP (port 143), and non-anonymous FTP (port 21) sessions. While some of these protocols may be used over SSL, they typically are found on different assigned ports in those instances. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Network_Traffic -* '''ATT&CK''': -* '''Last Updated''': 2021-08-19 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Network_Traffic where All_Traffic.action!=blocked AND All_Traffic.transport="tcp" AND (All_Traffic.dest_port="23" OR All_Traffic.dest_port="143" OR All_Traffic.dest_port="110" OR (All_Traffic.dest_port="21" AND All_Traffic.user != "anonymous")) by All_Traffic.user All_Traffic.src All_Traffic.dest All_Traffic.dest_port -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `drop_dm_object_name("All_Traffic")` -| `protocols_passing_authentication_in_cleartext_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Use_of_Cleartext_Protocols|Use of Cleartext Protocols]] - - -====How To Implement==== -This search requires you to be ingesting your network traffic, and populating the Network_Traffic data model. For more accurate result it's better to limit destination to organization private and public IP range, like All_Traffic.dest IN(192.168.0.0/16,172.16.0.0/12,10.0.0.0/8, x.x.x.x/22) - -====Required field==== - -* _time - -* All_Traffic.transport - -* All_Traffic.dest_port - -* All_Traffic.user - -* All_Traffic.src - -* All_Traffic.dest - -* All_Traffic.action - - - - -====Kill Chain Phase==== - -* Reconnaissance - -* Actions on Objectives - - -====Known False Positives==== -Some networks may use kerberized FTP or telnet servers, however, this is rare. - -====Reference==== - - -* https://www.rackaid.com/blog/secure-your-email-and-file-transfers/ - -* https://www.infosecmatter.com/capture-passwords-using-wireshark/ - - - -====Test Dataset==== - - -''version'': 3 -
-
- ----- - -===Remote desktop network bruteforce=== -This search looks for RDP application network traffic and filters any source/destination pair generating more than twice the standard deviation of the average traffic. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Network_Traffic -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1021/001/ T1021.001], [https://attack.mitre.org/techniques/T1021/ T1021] -* '''Last Updated''': 2020-07-21 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Network_Traffic where All_Traffic.app=rdp by All_Traffic.src All_Traffic.dest All_Traffic.dest_port -| eventstats stdev(count) AS stdev avg(count) AS avg p50(count) AS p50 -| where count>(avg + stdev*2) -| rename All_Traffic.src AS src All_Traffic.dest AS dest -| table firstTime lastTime src dest count avg p50 stdev -| `remote_desktop_network_bruteforce_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#SamSam_Ransomware|SamSam Ransomware]] - -* [[Documentation:ESSOC:stories:UseCase#Ryuk_Ransomware|Ryuk Ransomware]] - - -====How To Implement==== -You must ensure that your network traffic data is populating the Network_Traffic data model. - -====Required field==== - -* _time - -* All_Traffic.app - -* All_Traffic.src - -* All_Traffic.dest - -* All_Traffic.dest_port - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1021.001 -| Remote Desktop Protocol -| Lateral Movement -|- -| T1021 -| Remote Services -| Lateral Movement -|} - - -====Kill Chain Phase==== - -* Reconnaissance - -* Delivery - - -====Known False Positives==== -RDP gateways may have unusually high amounts of traffic from all other hosts' RDP applications in the network. - -====Reference==== - - -====Test Dataset==== - - -''version'': 2 -
-
- ----- - -===Remote desktop network traffic=== -This search looks for network traffic on TCP/3389, the default port used by remote desktop. While remote desktop traffic is not uncommon on a network, it is usually associated with known hosts. This search will ignore common RDP sources and common RDP destinations so you can focus on the uncommon uses of remote desktop on your network. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Network_Traffic -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1021/001/ T1021.001], [https://attack.mitre.org/techniques/T1021/ T1021] -* '''Last Updated''': 2020-07-07 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Network_Traffic where All_Traffic.dest_port=3389 AND All_Traffic.dest_category!=common_rdp_destination AND All_Traffic.src_category!=common_rdp_source by All_Traffic.src All_Traffic.dest All_Traffic.dest_port -| `drop_dm_object_name("All_Traffic")` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `remote_desktop_network_traffic_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#SamSam_Ransomware|SamSam Ransomware]] - -* [[Documentation:ESSOC:stories:UseCase#Ryuk_Ransomware|Ryuk Ransomware]] - -* [[Documentation:ESSOC:stories:UseCase#Hidden_Cobra_Malware|Hidden Cobra Malware]] - -* [[Documentation:ESSOC:stories:UseCase#Lateral_Movement|Lateral Movement]] - - -====How To Implement==== -To successfully implement this search you need to identify systems that commonly originate remote desktop traffic and that commonly receive remote desktop traffic. You can use the included support search "Identify Systems Creating Remote Desktop Traffic" to identify systems that originate the traffic and the search "Identify Systems Receiving Remote Desktop Traffic" to identify systems that receive a lot of remote desktop traffic. After identifying these systems, you will need to add the "common_rdp_source" or "common_rdp_destination" category to that system depending on the usage, using the Enterprise Security Assets and Identities framework. This can be done by adding an entry in the assets.csv file located in SA-IdentityManagement/lookups. - -====Required field==== - -* _time - -* All_Traffic.dest_port - -* All_Traffic.dest_category - -* All_Traffic.src_category - -* All_Traffic.src - -* All_Traffic.dest - -* All_Traffic.dest_port - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1021.001 -| Remote Desktop Protocol -| Lateral Movement -|- -| T1021 -| Remote Services -| Lateral Movement -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Remote Desktop may be used legitimately by users on the network. - -====Reference==== - - -====Test Dataset==== - - -''version'': 3 -
-
- ----- - -===Smb traffic spike=== -This search looks for spikes in the number of Server Message Block (SMB) traffic connections. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Network_Traffic -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1021/002/ T1021.002], [https://attack.mitre.org/techniques/T1021/ T1021] -* '''Last Updated''': 2020-07-22 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count from datamodel=Network_Traffic where All_Traffic.dest_port=139 OR All_Traffic.dest_port=445 OR All_Traffic.app=smb by _time span=1h, All_Traffic.src -| `drop_dm_object_name("All_Traffic")` -| eventstats max(_time) as maxtime -| stats count as num_data_samples max(eval(if(_time >= relative_time(maxtime, "-70m@m"), count, null))) as count avg(eval(if(_time<relative_time(maxtime, "-70m@m"), count, null))) as avg stdev(eval(if(_time<relative_time(maxtime, "-70m@m"), count, null))) as stdev by src -| eval upperBound=(avg+stdev*2), isOutlier=if(count > upperBound AND num_data_samples >=50, 1, 0) -| where isOutlier=1 -| table src count -| `smb_traffic_spike_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Emotet_Malware__DHS_Report_TA18-201A_|Emotet Malware DHS Report TA18-201A ]] - -* [[Documentation:ESSOC:stories:UseCase#Hidden_Cobra_Malware|Hidden Cobra Malware]] - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - -* [[Documentation:ESSOC:stories:UseCase#DHS_Report_TA18-074A|DHS Report TA18-074A]] - - -====How To Implement==== -This search requires you to be ingesting your network traffic logs and populating the `Network_Traffic` data model. - -====Required field==== - -* _time - -* All_Traffic.dest_port - -* All_Traffic.app - -* All_Traffic.src - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1021.002 -| SMB/Windows Admin Shares -| Lateral Movement -|- -| T1021 -| Remote Services -| Lateral Movement -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -A file server may experience high-demand loads that could cause this analytic to trigger. - -====Reference==== - - -====Test Dataset==== - - -''version'': 3 -
-
- ----- - -===Smb traffic spike - mltk=== -This search uses the Machine Learning Toolkit (MLTK) to identify spikes in the number of Server Message Block (SMB) connections. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Network_Traffic -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1021/002/ T1021.002], [https://attack.mitre.org/techniques/T1021/ T1021] -* '''Last Updated''': 2020-07-22 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count values(All_Traffic.dest_ip) as dest values(All_Traffic.dest_port) as port from datamodel=Network_Traffic where All_Traffic.dest_port=139 OR All_Traffic.dest_port=445 OR All_Traffic.app=smb by _time span=1h, All_Traffic.src -| eval HourOfDay=strftime(_time, "%H") -| eval DayOfWeek=strftime(_time, "%A") -| `drop_dm_object_name(All_Traffic)` -| apply smb_pdfmodel threshold=0.001 -| rename "IsOutlier(count)" as isOutlier -| search isOutlier > 0 -| sort -count -| table _time src dest port count -| `smb_traffic_spike___mltk_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Emotet_Malware__DHS_Report_TA18-201A_|Emotet Malware DHS Report TA18-201A ]] - -* [[Documentation:ESSOC:stories:UseCase#Hidden_Cobra_Malware|Hidden Cobra Malware]] - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - -* [[Documentation:ESSOC:stories:UseCase#DHS_Report_TA18-074A|DHS Report TA18-074A]] - - -====How To Implement==== -To successfully implement this search, you will need to ensure that DNS data is populating the Network_Resolution data model. In addition, the Machine Learning Toolkit (MLTK) version 4.2 or greater must be installed on your search heads, along with any required dependencies. Finally, the support search "Baseline of SMB Traffic - MLTK" must be executed before this detection search, because it builds a machine-learning (ML) model over the historical data used by this search. It is important that this search is run in the same app context as the associated support search, so that the model created by the support search is available for use. You should periodically re-run the support search to rebuild the model with the latest data available in your environment.\ -This search produces a field (Number of events,count) that are not yet supported by ES Incident Review and therefore cannot be viewed when a notable event is raised. This field contributes additional context to the notable. To see the additional metadata, add the following field, if not already present, to Incident Review - Event Attributes (Configure > Incident Management > Incident Review Settings > Add New Entry): \ -1. **Label:** Number of events, **Field:** count\ -Detailed documentation on how to create a new field within Incident Review is found here: `https://docs.splunk.com/Documentation/ES/5.3.0/Admin/Customizenotables#Add_a_field_to_the_notable_event_details` - -====Required field==== - -* _time - -* All_Traffic.dest_ip - -* All_Traffic.dest_port - -* All_Traffic.app - -* All_Traffic.src - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1021.002 -| SMB/Windows Admin Shares -| Lateral Movement -|- -| T1021 -| Remote Services -| Lateral Movement -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -If you are seeing more results than desired, you may consider reducing the value of the threshold in the search. You should also periodically re-run the support search to re-build the ML model on the latest data. Please update the `smb_traffic_spike_mltk_filter` macro to filter out false positive results - -====Reference==== - - -====Test Dataset==== - - -''version'': 3 -
-
- ----- - -===Tor traffic=== -This search looks for network traffic identified as The Onion Router (TOR), a benign anonymity network which can be abused for a variety of nefarious purposes. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Network_Traffic -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1071/ T1071], [https://attack.mitre.org/techniques/T1071/001/ T1071.001] -* '''Last Updated''': 2020-07-22 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Network_Traffic where All_Traffic.app=tor AND All_Traffic.action=allowed by All_Traffic.src_ip All_Traffic.dest_ip All_Traffic.dest_port All_Traffic.action -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `drop_dm_object_name("All_Traffic")` -| `tor_traffic_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Prohibited_Traffic_Allowed_or_Protocol_Mismatch|Prohibited Traffic Allowed or Protocol Mismatch]] - -* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] - -* [[Documentation:ESSOC:stories:UseCase#Command_and_Control|Command and Control]] - -* [[Documentation:ESSOC:stories:UseCase#NOBELIUM_Group|NOBELIUM Group]] - - -====How To Implement==== -In order to properly run this search, Splunk needs to ingest data from firewalls or other network control devices that mediate the traffic allowed into an environment. This is necessary so that the search can identify an 'action' taken on the traffic of interest. The search requires the Network_Traffic data model be populated. - -====Required field==== - -* _time - -* All_Traffic.app - -* All_Traffic.action - -* All_Traffic.src_ip - -* All_Traffic.dest_ip - -* All_Traffic.dest_port - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1071 -| Application Layer Protocol -| Command And Control -|- -| T1071.001 -| Web Protocols -| Command And Control -|} - - -====Kill Chain Phase==== - -* Command and Control - - -====Known False Positives==== -None at this time - -====Reference==== - - -====Test Dataset==== - - -''version'': 2 -
-
- ----- - -===Unusually long content-type length=== -This search looks for unusually long strings in the Content-Type http header that the client sends the server. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': -* '''Last Updated''': 2017-10-13 - -
-
- -====Search==== -`stream_http` -| eval cs_content_type_length = len(cs_content_type) -| where cs_content_type_length > 100 -| table endtime src_ip dest_ip cs_content_type_length cs_content_type url -| `unusually_long_content_type_length_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Apache_Struts_Vulnerability|Apache Struts Vulnerability]] - - -====How To Implement==== -This particular search leverages data extracted from Stream:HTTP. You must configure the http stream using the Splunk Stream App on your Splunk Stream deployment server to extract the cs_content_type field. - -====Required field==== - -* _time - -* cs_content_type - -* endtime - -* src_ip - -* dest_ip - -* url - - - - -====Kill Chain Phase==== - -* Delivery - - -====Known False Positives==== -Very few legitimate Content-Type fields will have a length greater than 100 characters. - -====Reference==== - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - - - -==Web== - - -===Detect f5 tmui rce cve-2020-5902=== -This search detects remote code exploit attempts on F5 BIG-IP, BIG-IQ, and Traffix SDC devices - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1190/ T1190] -* '''Last Updated''': 2020-08-02 - -
-
- -====Search==== -`f5_bigip_rogue` -| regex _raw="(hsqldb; -|.*\\.\\.;.*)" -| search `detect_f5_tmui_rce_cve_2020_5902_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#F5_TMUI_RCE_CVE-2020-5902|F5 TMUI RCE CVE-2020-5902]] - - -====How To Implement==== -To consistently detect exploit attempts on F5 devices using the vulnerabilities contained within CVE-2020-5902 it is recommended to ingest logs via syslog. As many BIG-IP devices will have SSL enabled on their management interfaces, detections via wire data may not pick anything up unless you are decrypting SSL traffic in order to inspect it. I am using a regex string from a Cloudflare mitigation technique to try and always catch the offending string (..;), along with the other exploit of using (hsqldb;). - -====Required field==== - -* _time - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1190 -| Exploit Public-Facing Application -| Initial Access -|} - - -====Kill Chain Phase==== - -* Exploitation - - -====Known False Positives==== -unknown - -====Reference==== - - -* https://www.ptsecurity.com/ww-en/about/news/f5-fixes-critical-vulnerability-discovered-by-positive-technologies-in-big-ip-application-delivery-controller/ - -* https://support.f5.com/csp/article/K52145254 - -* https://blog.cloudflare.com/cve-2020-5902-helping-to-protect-against-the-f5-tmui-rce-vulnerability/ - - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Detect attackers scanning for vulnerable jboss servers=== -This search looks for specific GET or HEAD requests to web servers that are indicative of reconnaissance attempts to identify vulnerable JBoss servers. JexBoss is described as the exploit tool of choice for this malicious activity. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Web -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1082/ T1082] -* '''Last Updated''': 2017-09-23 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Web where (Web.http_method="GET" OR Web.http_method="HEAD") AND (Web.url="*/web-console/ServerInfo.jsp*" OR Web.url="*web-console*" OR Web.url="*jmx-console*" OR Web.url = "*invoker*") by Web.http_method, Web.url, Web.src, Web.dest -| `drop_dm_object_name("Web")` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_attackers_scanning_for_vulnerable_jboss_servers_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#JBoss_Vulnerability|JBoss Vulnerability]] - -* [[Documentation:ESSOC:stories:UseCase#SamSam_Ransomware|SamSam Ransomware]] - - -====How To Implement==== -You must be ingesting data from the web server or network traffic that contains web specific information, and populating the Web data model. - -====Required field==== - -* _time - -* Web.http_method - -* Web.url - -* Web.src - -* Web.dest - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1082 -| System Information Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -It's possible for legitimate HTTP requests to be made to URLs containing the suspicious paths. - -====Reference==== - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Detect malicious requests to exploit jboss servers=== -This search is used to detect malicious HTTP requests crafted to exploit jmx-console in JBoss servers. The malicious requests have a long URL length, as the payload is embedded in the URL. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Web -* '''ATT&CK''': -* '''Last Updated''': 2017-09-23 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Web where (Web.http_method="GET" OR Web.http_method="HEAD") by Web.http_method, Web.url,Web.url_length Web.src, Web.dest -| search Web.url="*jmx-console/HtmlAdaptor?action=invokeOpByName&name=jboss.admin*import*" AND Web.url_length > 200 -| `drop_dm_object_name("Web")` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| table src, dest_ip, http_method, url, firstTime, lastTime -| `detect_malicious_requests_to_exploit_jboss_servers_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#JBoss_Vulnerability|JBoss Vulnerability]] - -* [[Documentation:ESSOC:stories:UseCase#SamSam_Ransomware|SamSam Ransomware]] - - -====How To Implement==== -You must ingest data from the web server or capture network data that contains web specific information with solutions such as Bro or Splunk Stream, and populating the Web data model - -====Required field==== - -* _time - -* Web.http_method - -* Web.url - -* Web.url_length - -* Web.src - -* Web.dest - - - - -====Kill Chain Phase==== - -* Delivery - - -====Known False Positives==== -No known false positives for this detection. - -====Reference==== - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Monitor web traffic for brand abuse=== -This search looks for Web requests to faux domains similar to the one that you want to have monitored for abuse. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Web -* '''ATT&CK''': -* '''Last Updated''': 2017-09-23 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` values(Web.url) as urls min(_time) as firstTime from datamodel=Web by Web.src -| `drop_dm_object_name("Web")` -| `security_content_ctime(firstTime)` -| `brand_abuse_web` -| `monitor_web_traffic_for_brand_abuse_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Brand_Monitoring|Brand Monitoring]] - - -====How To Implement==== -You need to ingest data from your web traffic. This can be accomplished by indexing data from a web proxy, or using a network traffic analysis tool, such as Bro or Splunk Stream. You also need to have run the search "ESCU - DNSTwist Domain Names", which creates the permutations of the domain that will be checked for. - -====Required field==== - -* _time - -* Web.url - -* Web.src - - - - -====Kill Chain Phase==== - -* Delivery - - -====Known False Positives==== -None at this time - -====Reference==== - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Sql injection with long urls=== -This search looks for long URLs that have several SQL commands visible within them. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Web -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1190/ T1190] -* '''Last Updated''': 2020-07-21 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count from datamodel=Web where Web.dest_category=web_server AND (Web.url_length > 1024 OR Web.http_user_agent_length > 200) by Web.src Web.dest Web.url Web.url_length Web.http_user_agent -| `drop_dm_object_name("Web")` -| eval num_sql_cmds=mvcount(split(url, "alter%20table")) + mvcount(split(url, "between")) + mvcount(split(url, "create%20table")) + mvcount(split(url, "create%20database")) + mvcount(split(url, "create%20index")) + mvcount(split(url, "create%20view")) + mvcount(split(url, "delete")) + mvcount(split(url, "drop%20database")) + mvcount(split(url, "drop%20index")) + mvcount(split(url, "drop%20table")) + mvcount(split(url, "exists")) + mvcount(split(url, "exec")) + mvcount(split(url, "group%20by")) + mvcount(split(url, "having")) + mvcount(split(url, "insert%20into")) + mvcount(split(url, "inner%20join")) + mvcount(split(url, "left%20join")) + mvcount(split(url, "right%20join")) + mvcount(split(url, "full%20join")) + mvcount(split(url, "select")) + mvcount(split(url, "distinct")) + mvcount(split(url, "select%20top")) + mvcount(split(url, "union")) + mvcount(split(url, "xp_cmdshell")) - 24 -| where num_sql_cmds > 3 -| `sql_injection_with_long_urls_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#SQL_Injection|SQL Injection]] - - -====How To Implement==== -To successfully implement this search, you need to be monitoring network communications to your web servers or ingesting your HTTP logs and populating the Web data model. You must also identify your web servers in the Enterprise Security assets table. - -====Required field==== - -* _time - -* Web.dest_category - -* Web.url_length - -* Web.http_user_agent_length - -* Web.src - -* Web.dest - -* Web.url - -* Web.http_user_agent - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1190 -| Exploit Public-Facing Application -| Initial Access -|} - - -====Kill Chain Phase==== - -* Delivery - - -====Known False Positives==== -It's possible that legitimate traffic will have long URLs or long user agent strings and that common SQL commands may be found within the URL. Please investigate as appropriate. - -====Reference==== - - -====Test Dataset==== - - -''version'': 2 -
-
- ----- - -===Supernova webshell=== -This search aims to detect the Supernova webshell used in the SUNBURST attack. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Web -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1505/003/ T1505.003] -* '''Last Updated''': 2021-01-06 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` count from datamodel=Web.Web where web.url=*logoimagehandler.ashx*codes* OR Web.url=*logoimagehandler.ashx*clazz* OR Web.url=*logoimagehandler.ashx*method* OR Web.url=*logoimagehandler.ashx*args* by Web.src Web.dest Web.url Web.vendor_product Web.user Web.http_user_agent _time span=1s -| `supernova_webshell_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#NOBELIUM_Group|NOBELIUM Group]] - - -====How To Implement==== -To successfully implement this search, you need to be monitoring web traffic to your Solarwinds Orion. The logs should be ingested into splunk and populating/mapped to the Web data model. - -====Required field==== - -* _time - -* Web.url - -* Web.src - -* Web.dest - -* Web.vendor_product - -* Web.user - -* Web.http_user_agent - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1505.003 -| Web Shell -| Persistence -|} - - -====Kill Chain Phase==== - -* Exfiltration - - -====Known False Positives==== -There might be false positives associted with this detection since items like args as a web argument is pretty generic. - -====Reference==== - - -* https://www.splunk.com/en_us/blog/security/detecting-supernova-malware-solarwinds-continued.html - -* https://www.guidepointsecurity.com/supernova-solarwinds-net-webshell-analysis/ - - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - - - - -
-#############
-# Automatically generated by doc_gen.py in https://github.com/splunk/security_content''
-# On Date: 2021-10-28 22:45:59.991457 UTC''
-# Author: Splunk Security Research''
-# Contact: research@splunk.com''
-#############
-
diff --git a/docs/favicon.ico b/docs/favicon.ico deleted file mode 100644 index d8c8cf21a9eb8e68a689e35ae8d9dd1d463a8592..0000000000000000000000000000000000000000 GIT binary patch literal 0 HcmV?d00001 literal 15406 zcmeI3d3coPdG3Yl6fbEpiSa@((r7l#Xf%>$g!X+0Ng%NbNi0G_AV6#e%U}bFlNdV= zPU^-9aR?-7)12(5c2nD@OX@VIJxiVDoRZ{3Nz)|MHbL`!^UaKeK*D;?@A;%50^=OJ zar(!(s_Pm?8foUe-{-xb?S5WTQs$)mPRbp3r0|@Uvi;_il>C&Gl(e+zpEKsCq@3op zoSd28ds0&VZb3>)27kj_c*peXJiVo_?F%mC_T4>lvfURMuC0wu$mBq71>=u|fLI6T)l`S9;X zeLJ?rBn{lDL!*-Vfl@saqq6sKLZ0}ei}L6nUzD%${$}?2$-llVk34@#p8l^B^6|g8ES1===czHt*%z0h zE%Aw!71nTlttDlgch>T0-2QG$+CPk))ZToi+PnH=V^VoEA-?T!0_@@5nAEje!!<4O zlXb5NJGhM2fHFUQWA_ktny{iC-19Gt%!dxknJscp7ob%}YhwkVogU2IGh zw3rfFV~P)+1iPXV*vYvc<-Nyw?}G{Z{4&>p5xZ8^fiK&f8o1+v&F6w<^O;=EIkY}1 zOV*l_vkmTXUS8Ht<1^Ckk4wfTOY$2HSy~83gQo1d)3EuY99pzSZVhg>UJ7inBuCE% zo`hL52yQRumW~~=`0R=bL)u*t*>R`w(!P{)*Z6??M4&hNY0u%rRNmgWl<+9r!@36( z;(T`PdeeRr`sC$u8*G1SQjVi{@cEWQeM4nD8)Fj=Z?ta=2Szv7aP*yGGsY%q^=6i z5KHpb$0Vx-)Ko5IVeCp^sLgIjo;a4)b=f4(n+i z)O_e92HWS*$IrW1TkWp-=@EPH_Ok<9WcS2Q%;v(*_r*N}cbk((${-6K=kDm~!*hSNwqiJVYef3)CN6tTS(YD_%1X|C8RyQ~`&rw=!`aTd*xX(p4mj|A zNB=Clv!2!kYInuqCU*oi7vP`S9oA{J!60#M@b<{Ku6g8LV1W0BdEWURLpI>|ZPXq0 zg{G8H1B8h;0c@`|gw_G}+SuK$CA1zOAJ{d){p?%wD|rUaUA23F-;<9d*hw8S5Fbw; zlzE45F+0@Ps5fNr_YE0*w;_A(Fl5X7$Y;9uuql<)T?KVuCXf4A-?qEfFuHf_o<3uD zJ2xloer$T*$~)zscXv!O$$?q?z2^GBKuk*3nVmx^Bd3nS^ZV~KNd``=Mn~$!vvlzs~MjSCAL&T2Ae*d&llBUh{2-v&19+7UCip3pNtNwpgdI z`^)>`_}+U>+08@itL%lCOc^_Q3B{y!O)!beBt zhrfJXKFaGuFJ6+<|7}7JeQ{iNd}>S{I&)F{#6lnZ46$~2M@$NPVv%j`=v2QmD!rU_ zM|M7uAud1v=@ohG#F+g3KTb$sg(au{^CkKG3zy`FKffZUsrw!{bx|ttukW9` zBA@xzWjXL=)~B``9(i3p_MHiN=_ix&7iTBMO$^dHWj(+9=F1bZdWiZ58-&48)DxTP z^+)v~o%ncLQB;;zS@Oy&ugf-mzk$ckUb$k|W`9cE`G?f4_WIyB@R^HJimku@udL60 zpZ=T6(sc5ooITI_e>)-H{NI!E=ii%@40u;I7?)Gjs82r&My9*T$t9|5dwhqt0!`);R~`^60ad zq>sNj`prx7rT;Z4n>njL0M8@T+`Z3Slsf#N{Uc+NPp#<1=6<-BLk*k1EiTpVu}Eiu z_42B6OO{c4*69OZFD2H5$uj{s=T%>yi8Ez;V)puW?N6<2`}z%H>>p5@e*nx*)^TF{ zLUKT6AHKs`Wbs;YWJ(45&nM3X;k=Kv-5O_Rd_4pI zX{5)o`Hl_K4)93kHq9+s7ZdXec`ksfPB^c*$OG@a>ht8JF#b|Z&T7E7o9eAoOPgbz zH7lt3*>eqbRS|J67hm`5+FJL6^ZFQ@mh^LCoE_gax8dvhy&dzhvBsiw*4A3UOJ2(4 z`w+RRn7W~kwU<|0(pG79)~=CxRn4*S`U2{zBEzo5gV@~zMy+M++{SY{b$&K|1U;`E zV^R;Xmc}@ZGmo=(d|h*$<~%(Y+eXAi&57EphOlD^@vD~nxtyM8eb^lDOP{V&8w#SQ zYq5Q8G3!?vvZRgulhcCqCEC~MdHdN%Xq_q9)D;<;*EP3%fOU0k?Patd;hY_ui{>CV zcwKyk=Hmc+E@+KO4KaKz+B^+`a^9H4!?R^PG{_Fkh9KX z{ZI${#fD*?)fORoKR^DT3Fou1vmeg6o){CSa!&WIbr#s%oKMag-rsCW8E3gP&p)b_gO^H`G5LH}F23u-wm#MflFP#I-v2o9 zoVqH5y*uHZLwQFI%7iDuwb-2XYv5CB7Bzf&M7At6WcMAB3kT<3__cL-u-gjxx5h5` zh#NU@FBjkSv1c!P^z$gh#$omxg8RAnfdAo9p*OYl7cYCy)Y=BjrPbIx9Feu2h-|u# zdS-s)!v5RdTql}si;S%!p3H5rvsx$l*sq)YdD&+HyelTh7J#Fevsl9SLE^a^yEyq> z2C+r`W(gdwr5|s@?p=d=7AU@HzTv2@)&IE3{uRWS!fX+<2dHLTmf$KmV=%oPH?o@gE*N zQ@bHHUd`v%!pVB-t}*>}%K)0V}NsuS$1 zv%pS`SVvD*rFsatJ>02%?X(W2S`<1Q+RqGrVwSA~kw?LgW)=p(zx^&1`fOdsztWK{s{B~htGN2;P0Dtj~DfZa8NKRKgt z6W2Y|CLZ#uUC(aeJhsMOa1BH&eslaoH+8s;zJ2qI^Yo)ryP0<+b+`3y^e=khHZ-WE z)QGCTRf4^o{-B7OE~K_c2lJDgylQ)LfLrw^#n1P)CWg)3V7E0n^100?_~qFin{w<+ zoL@XRwl!sF=-=eu11_1n!4=)ReW8(14P%gb$42^h)$NklSD=eG;;&WocIDK8WvXK} zkw4d>AySiP!krBAnMb)!{bk!;vFn3;KCS8TI{VV|&>G84o#)g#nEac1IFXr(v*U$wC-{&n=ks=qADGo>1TEyeD|=x?P<>D}?!5c*dZ zc>QqPs~WIk=V9Ak&w#zznw;)IU)TMB-KE&6Wo^AcH7c#;-#==kJvzGg?VLkzn$g$e zFcbHqld0`h$5G8pd9Su#&hq2M|DM~Y8})=cFp?`^)L0H-3J}Nm{|NMT>5{0$(*fe(TZM2^!!fj zeQcKQXLAVct&=^p!g=LQC7dt8_C???SM3=cECl{6)nLJ@I;e;5)yArY+IxWSHh%oo z{+TndGok5a8F`E-(us%{`Z+v536Q} z?Pot8LOcGYpguNtQ6N>0Up9dDfE zg>-7ZtGv;^M>Rghty-7%phriis0m-l9njc%S&I~T%v?5ljAjsF<_q zV=?hwIn*$1`<%9E4cWgA+s|kmYHtT;VQabA{i?QyzosX7qwz-d7VY=cXOp_N+FyHM zdLj3IVjB6H9xjo4U7pr@X5gOanLP_kc^Hn&#;)J1-mkOf?RTO5qC>8N|4sDjb>!P} zw5dYkPKbOP1hXIQTXkU7Vw3uiYVh_0{@7=MzuG#4&LLDY*$-~|1zR6g-puGGGrW;> zewRhBnZ235o8F85`^@ZmY44p@XwO~dx$CuZ#ja=Z0I`1;8g38T@p|HCYqp7|gzeFG zO3?0?pu5<%N5fTZNwwUho_bZw#$RneAXe&J*VfaO^YmJ_&n9`3^jX!H*^BC|KD3D- zex6N_q`E=Q`slf=UMs9T(i(XGdn1E`w;K~lytCtu&N?)9_7RV|n7OQmJ9g|ulPZJ% z1;m~Zvj?63XDap?+dF5pv8x)D+8!UaX94tN+LNm$WAi2%>yx~h(dLy)9{Sk;+7kV@ z1hGLj^%6bsq;LP|pw`|GQoj%0Za!;c#@4FWAG+NTy<_kYG3b8gMmnp}y9Vos{W`PK zI|o(7{u1!(-Gdxv#mV`B-eIuk7fJled9}UzFgCoFH{e&Fh2QpFg(PoO@56`F*_RJ( zGoboD^@YyaRlo4UH|Finm3CP3AD;V5CwDPkvw05Q2e7q0Z}>e!_EGQbWcJiUz1cyn zwvxQn#LP)GF}*)fNbFJlKSX>}-%($#s6|?osJh+qHj7^9;NuRxnog8apXI*=Kr9P{?(O8*`H#59RQ{E(F zJ>M&D+-Ngudq3Ko&Nl+gH8S|wi@$_=$oFVTMH}PI$5JjFS0A-8-)+i%V$ePwI~JL? zCe{J&)#(4r(dQmP&lo|+?^cb0yp_{5twrnXM|q?1<|=-*{cPUAVZ9S$YtvV21Z=N0 z0$QD&r)KfSOI*@MJ+Ijbc6(j} z_KoD(jv6%lLhh_QFe(=!uggaAWi41k*xlxh`Yib>Ik(H=vxC^}ns`HfbJb_xq((@` z_73VEo#%NurwsP2v)~N4??E5(@miR3SfXxGAYH}WIJKERx3_kE`9wC6oh z*_aiTPYsR9zx?EioPYIo`N|i@<%9ejPfW?Tm^}?M@A=uQS7aAj=V~}?#9o)}Pmanl z<~bKHP05d$m3;ZzmnAkfCHH^!q73u5UuN#3H9{kIYfN6>@zrtp!TBrlEoL(Q$4BJ_ z?)*H*Tqnf*;t6IdD~Y9HYEloly#r`!_zAfGemR9Yh}WuG>FWbIu)GQjSGGx%vcGb^2!HJ4lR$gwdQ9i5Ut`aCl#;`~8; z&4NEWz@>S%msyoQ~pqhVsF&bOZB%>D{awSEwr;TPHLFH9ULB!-ld4|@X9I1kyF1NJ2r z^HoclD=cZiXNS;{r>1FU&5z;5q({jF{>Qr_3!+c`5fQ>2tVuj1ZMy@PQs_pu};s& zMkNT}eZ;K5-h|{(bL1(0`npPVvF;pecq4piF93Tf*y&~KsfTrL)m+XzWoJT;V#jsF zoEqxL&CJP~iNOOO9g}Sz!M|9m^+?>tzYAWh;cpv`p&etxATfMBXOmA{S;ZZ^7Ur0% z@#Xvf?2L4R&KOJ4#Om6t z;SEcy=i7@cSyg693$w3=dbDI}vc`OB1Y&0i_3@HqtS8Uvto!;{pTxf%zr10MVAqz@ z_1NrK?|_fP`1QB(ckS7=2XlhW#d8O|52+szf4tZ|0QPKN&*S&pBa~`%y~dW<^Xp2i zOx;?5CR0Iw(MYeoY+3yH z%Gy}d@;ZKA#vG1#srs4D9QAI6&OEQy2-rP?9IJWiYF$55BdCt1@eSQ(x-Q0E4(393 zZD#i*Gk0xf*9bZnC9@4&>giorTqO(z*UHEwf;d&U{1@vuY%nTdA-b~N5 zydl=KbgAWRY>L08v)XE2ZvcA@eN`#ExmqJoUuN(=o!dHfcB{Dcaea*dZ_|ixb|0JU z1-S!i-<#0da#lZR*KPVY_@&kqb}xp_RiE(i*&g7~oCd!1shwPZ!L z^;&DSSCQEtM;co zNm{Z8S6n&=rVg|F@FaGv>u35wyWb)gYyV}}MamoS>*v|CY0g3K#OU4C0@g2s?>ZxH zh7)b@eN9pHxsK9l{k?o`e6YUKnrOghYvF!9Gp_1VW}~%+1c>tbuAQmJ?3ze1j(k->U7 z;4UIhR#4;CD0Vo}2CvuUM<=$WnS5m)k!U7*YcdJ`dH37=D~Ug7hemgen#z*n(Rk(4zAdB9;~x)_G8cD^?bs*?7#&mD5wHo`#g0Feh>813hwP;LD^c!vPdTqWXeT&U=2j69d6uW+DFI-b-oUv#1 z;IAx$Kg>DvSAd_Hr#_bG+?wZX=H}i_?1MF#i`n?IwYSrF5B@CfKY1U(uG)vIzbf|R zJp%S+-($FrHyM16&ei>TFMxfh{t_l$6ob7=V>xw9E4E!rZLo#Aq6cq@oKekT8vXRY z)y2`&x?&?y1$OTKN+EON5H)fx+I%5%_LAky{a0dVe%42rwe)w{)UyHdqt+&hU2}}i z;WL@Tr>Va(3r{7k+Pu+T3)|cCc;c1jI2U^lfjzHsn>X5T!7uwR1-U34pAW*lFmvU+CTzyN zf^s-p&DmF1;fLh^mIAO-3wLpsY1aZ{VsP%r4fQMCL)p^Af}(okMeIJ6jX&mauKD0E zfH!*A-0uI03Hhv9+7gk1PR@uvB6BZVxz;D-c#Y-R#B~q0cbvE=Y3j4;%bEuiKXrok zj}Fc(gEexoO$hu;mNM((PK3t3W%=lPOLQK^i~+5tlfJuekui1P7UP9O%z={je&e&u z$z7kQVD4}}h!2Ipp9gOH&IEp?|A#?eQ$7`N1|i~ofO^qSuFAx&Sv*2u41n1Ub~nE3 z!uIKUe}?~Wkg9crYE^Jdb8VKMG51J9Ev6J=ca0g1;BF0auOb7j*sBkEL3Eq_w?)n$ zym_QTXIXE=eeEm$UaJqiWi&*O9HQ6Md;0dh3%HsGe+pK^FSwfpcD--!=aC7v5YJ(1 z0{@3EiVxoSsM~zni-SKM{0@GvdX>gZz4NDc{DXS7+$$=n!S=+CmYfLpny2q4Y-XmZ zv$j3+B8kCwjl2c@Jh_jdo3b}W_vLJgnyOuJZ-YCQItPV2*ejQsFaT$~_+ke3_Q8!D zc#)6&a~~O#AaO_kFG3LPnPB(e3vPVZsrccJ_9g*%sPS0ubmS8&)b@I(MekOuXAZk5 z)xKXLyXP6k{#%W`Ln&`>j^rAUxnSOl29VG@Cjs^lCfq#!dc4?@apOq2Bw-!X9e-D)Ob?sacsBkq-VJ!Y2MtRo?>R{J=cr z%-gej68Y@sto}qrc9;2L=0JQx`Qm~P9&D<1U4q>!sBKH&buqZh__+*z7vZCdKL_0U z|6BAPlFoMQn9n3Y<_NC0}>kIfl1o-SakA1Iwf;&ks^xyeT%ukcMkU7B(=kMaa z(m~gev4oo%#=|2Ud{y)kmEbQ!->4w}R^um?U@W4R(|bJX7f!W3@zqVtSNvY;jx6ff z0<_1f64fM`A#;zb!)YYC?i)GK%^WD@EyS55y0`P}cqp3cIU4_L#>1okTD2)QSxcQ& zMSWfcu6j68M|`aWUlF#>=M20L68qVwlkeTsI_kSV>>tARdLOAi-<((xG|sK_7-u>h zH_oeX2j5%y+sYxixnQ>yZs@QEYd6N8?c4;^=xH4${yWQWoW`F4KO&v17n!7MfO|hot7VCITr}aWb zckIV`1Mzq|ew#`y=iC>II|pLJt{t)GnP(r*Sz|U8SO3yks`dL!4Sdb#{>KmhVS#@q G3;bWT*IG>g diff --git a/docs/index.html b/docs/index.html deleted file mode 100644 index 126f6453b7..0000000000 --- a/docs/index.html +++ /dev/null @@ -1,8 +0,0 @@ ---- -# You don't need to edit this file, it's empty on purpose. -# Edit theme's home layout instead if you wanna make some changes -# See: https://jekyllrb.com/docs/themes/#overriding-theme-defaults -layout: home -author_profile: true ---- - diff --git a/docs/index.markdown b/docs/index.markdown deleted file mode 100644 index 94a55d07c0..0000000000 --- a/docs/index.markdown +++ /dev/null @@ -1,62 +0,0 @@ ---- -# Feel free to add content and custom Front Matter to this file. -# To modify the layout, see https://jekyllrb.com/docs/themes/#overriding-theme-defaults -layout: splash -header: - overlay_color: "#000" - overlay_filter: "0.5" - overlay_image: /static/splunk_banner.png - actions: - - label: "Download" - url: "https://splunkbase.splunk.com/app/3449/" -excerpt: "Get the latest **FREE** Enterprise Security Content Update (ESCU) App with **795** detections for Splunk." -feature_row: - - image_path: /static/feature_detection.png - alt: "customizable" - title: "Detections" - excerpt: "See all **795** Splunk Analytics built to find evil 😈." - url: "/detections" - btn_class: "btn--primary" - btn_label: "Explore" - - image_path: /static/feature_stories.png - alt: "fully responsive" - title: "Analytic Stories" - excerpt: "See all **117** use cases, 📦 of detections built to address a threat." - url: "/stories" - btn_class: "btn--primary" - btn_label: "Explore" - - image_path: /static/feature_playbooks.png - alt: "100% free" - title: "Playbooks" - excerpt: "See all **31** automated investigation 🔭 and response 🛠 playbooks." - url: "/playbooks" - btn_class: "btn--primary" - btn_label: "Explore" ---- - - -{% include feature_row %} - -# Welcome to Splunk Security Content - -This project gives you access to our repository of Analytic Stories that are security guides which provide background on TTPs, mapped to the MITRE framework, the Lockheed Martin Kill Chain, and CIS controls. They include Splunk searches, machine-learning algorithms, and Splunk SOAR playbooks (where available)—all designed to work together to detect, investigate, and respond to threats. - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success} - -## [Detection Coverage](https://mitremap.splunkresearch.com/) 🗺 -Below is a snapshot in time of what technique we currently have some detection coverage for. The darker the shade of blue the more detections we have for this particular technique. - -[![](mitre-map/coverage.png)](https://mitremap.splunkresearch.com/) - -## Questions? 📞 -Please use the [GitHub issue tracker](https://github.com/splunk/attack_range/issues) to submit bugs or request features. - -If you have questions or need support, you can: - -* Join the [#security-research](https://splunk-usergroups.slack.com/archives/C1S5BEF38) room in the [Splunk Slack channel](http://splunk-usergroups.slack.com) -* Post a question to [Splunk Answers](http://answers.splunk.com) -* If you are a Splunk Enterprise customer with a valid support entitlement contract and have a Splunk-related question, you can also open a support case on the https://www.splunk.com/ support portal - - -## Contribute Content 🥰 -If you want to help the rest of the security community by sharing your own detections, see our [contributor guide](https://github.com/splunk/security_content/wiki/Contributing-to-the-Project) for more information on how to get involved! diff --git a/docs/stories.wiki b/docs/stories.wiki deleted file mode 100644 index 523da94235..0000000000 --- a/docs/stories.wiki +++ /dev/null @@ -1,16516 +0,0 @@ -=Splunk Security Content Analytic Story = - ----- -All the Analytic Stories shipped to different Splunk products. Below is a breakdown by Category. - -==Abuse== - - -===Brand monitoring=== -Detect and investigate activity that may indicate that an adversary is using faux domains to mislead users into interacting with malicious infrastructure. Monitor DNS, email, and web traffic for permutations of your brand name. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Email Email], [https://docs.splunk.com/Documentation/CIM/latest/User/Web Web] -* '''Last Updated''': 2017-12-19 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Monitor_email_for_brand_abuse|Monitor Email For Brand Abuse]] - -| -| -| - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Monitor_web_traffic_for_brand_abuse|Monitor Web Traffic For Brand Abuse]] - -| -| -| - -| TTP -|} - -====Kill Chain Phase==== - -* Delivery - - -====Reference==== - -* https://www.zerofox.com/blog/what-is-digital-risk-monitoring/ - -* https://securingtomorrow.mcafee.com/consumer/family-safety/what-is-typosquatting/ - -* https://blog.malwarebytes.com/cybercrime/2016/06/explained-typosquatting/ - - -''version'': 1 -
-
- ----- - -===Dns amplification attacks=== -DNS poses a serious threat as a Denial of Service (DOS) amplifier, if it responds to `ANY` queries. This Analytic Story can help you detect attackers who may be abusing your company's DNS infrastructure to launch amplification attacks, causing Denial of Service to other victims. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/NetworkResolution Network_Resolution] -* '''Last Updated''': 2016-09-13 -* '''Use Case''': Security Monitoring - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Large_volume_of_dns_any_queries|Large Volume of DNS ANY Queries]] - -| -[https://attack.mitre.org/techniques/T1498/ T1498], -[https://attack.mitre.org/techniques/T1498.002/ T1498.002] -| -Network Denial of Service, -Reflection Amplification -| -Impact, -Impact - -| Anomaly -|} - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Reference==== - -* https://www.us-cert.gov/ncas/alerts/TA13-088A - -* https://www.imperva.com/learn/application-security/dns-amplification/ - - -''version'': 1 -
-
- ----- - -===Data protection=== -Fortify your data-protection arsenal--while continuing to ensure data confidentiality and integrity--with searches that monitor for and help you investigate possible signs of data exfiltration. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/NetworkResolution Network_Resolution] -* '''Last Updated''': 2017-09-14 -* '''Use Case''': Security Monitoring - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Detect_hosts_connecting_to_dynamic_domain_providers|Detect hosts connecting to dynamic domain providers]] - -| -[https://attack.mitre.org/techniques/T1189/ T1189] -| -Drive-by Compromise -| -Initial Access - -| TTP -|} - -====Kill Chain Phase==== - -* Actions on Objectives - -* Command and Control - - -====Reference==== - -* https://www.cisecurity.org/controls/data-protection/ - -* https://www.sans.org/reading-room/whitepapers/dns/splunk-detect-dns-tunneling-37022 - -* https://umbrella.cisco.com/blog/2013/04/15/on-the-trail-of-malicious-dynamic-dns-domains/ - - -''version'': 1 -
-
- ----- - -===Netsh abuse=== -Detect activities and various techniques associated with the abuse of `netsh.exe`, which can disable local firewall settings or set up a remote connection to a host from an infected system. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint] -* '''Last Updated''': 2017-01-05 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Processes_launching_netsh|Processes launching netsh]] - -| -[https://attack.mitre.org/techniques/T1562.004/ T1562.004], -[https://attack.mitre.org/techniques/T1562/ T1562] -| -Disable or Modify System Firewall, -Impair Defenses -| -Defense Evasion, -Defense Evasion - -| TTP -|} - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Reference==== - -* https://docs.microsoft.com/en-us/previous-versions/tn-archive/bb490939(v=technet.10) - -* https://htmlpreview.github.io/?https://github.com/MatthewDemaske/blogbackup/blob/master/netshell.html - -* http://blog.jpcert.or.jp/2016/01/windows-commands-abused-by-attackers.html - - -''version'': 1 -
-
- ----- - - - -==Adversary Tactics== - - -===Active directory discovery=== -Monitor for activities and techniques associated with Discovery and Reconnaissance within with Active Directory environments. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint] -* '''Last Updated''': 2021-08-20 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Adsisearcher_account_discovery|AdsiSearcher Account Discovery]] - -| -[https://attack.mitre.org/techniques/T1087.002/ T1087.002], -[https://attack.mitre.org/techniques/T1087/ T1087] -| -Domain Account, -Account Discovery -| -Discovery, -Discovery - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Dsquery_domain_discovery|DSQuery Domain Discovery]] - -| -[https://attack.mitre.org/techniques/T1482/ T1482] -| -Domain Trust Discovery -| -Discovery - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Domain_account_discovery_with_net_app|Domain Account Discovery With Net App]] - -| -[https://attack.mitre.org/techniques/T1087.002/ T1087.002], -[https://attack.mitre.org/techniques/T1087/ T1087] -| -Domain Account, -Account Discovery -| -Discovery, -Discovery - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Domain_account_discovery_with_dsquery|Domain Account Discovery with Dsquery]] - -| -[https://attack.mitre.org/techniques/T1087.002/ T1087.002], -[https://attack.mitre.org/techniques/T1087/ T1087] -| -Domain Account, -Account Discovery -| -Discovery, -Discovery - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Domain_account_discovery_with_wmic|Domain Account Discovery with Wmic]] - -| -[https://attack.mitre.org/techniques/T1087.002/ T1087.002], -[https://attack.mitre.org/techniques/T1087/ T1087] -| -Domain Account, -Account Discovery -| -Discovery, -Discovery - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Domain_controller_discovery_with_nltest|Domain Controller Discovery with Nltest]] - -| -[https://attack.mitre.org/techniques/T1018/ T1018] -| -Remote System Discovery -| -Discovery - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Domain_controller_discovery_with_wmic|Domain Controller Discovery with Wmic]] - -| -[https://attack.mitre.org/techniques/T1018/ T1018] -| -Remote System Discovery -| -Discovery - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Domain_group_discovery_with_dsquery|Domain Group Discovery With Dsquery]] - -| -[https://attack.mitre.org/techniques/T1069/ T1069], -[https://attack.mitre.org/techniques/T1069.002/ T1069.002] -| -Permission Groups Discovery, -Domain Groups -| -Discovery, -Discovery - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Domain_group_discovery_with_net|Domain Group Discovery With Net]] - -| -[https://attack.mitre.org/techniques/T1069/ T1069], -[https://attack.mitre.org/techniques/T1069.002/ T1069.002] -| -Permission Groups Discovery, -Domain Groups -| -Discovery, -Discovery - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Domain_group_discovery_with_wmic|Domain Group Discovery With Wmic]] - -| -[https://attack.mitre.org/techniques/T1069/ T1069], -[https://attack.mitre.org/techniques/T1069.002/ T1069.002] -| -Permission Groups Discovery, -Domain Groups -| -Discovery, -Discovery - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Domain_group_discovery_with_adsisearcher|Domain Group Discovery with Adsisearcher]] - -| -[https://attack.mitre.org/techniques/T1069/ T1069], -[https://attack.mitre.org/techniques/T1069.002/ T1069.002] -| -Permission Groups Discovery, -Domain Groups -| -Discovery, -Discovery - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Elevated_group_discovery_with_net|Elevated Group Discovery With Net]] - -| -[https://attack.mitre.org/techniques/T1069/ T1069], -[https://attack.mitre.org/techniques/T1069.002/ T1069.002] -| -Permission Groups Discovery, -Domain Groups -| -Discovery, -Discovery - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Elevated_group_discovery_with_wmic|Elevated Group Discovery With Wmic]] - -| -[https://attack.mitre.org/techniques/T1069/ T1069], -[https://attack.mitre.org/techniques/T1069.002/ T1069.002] -| -Permission Groups Discovery, -Domain Groups -| -Discovery, -Discovery - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Elevated_group_discovery_with_powerview|Elevated Group Discovery with PowerView]] - -| -[https://attack.mitre.org/techniques/T1069/ T1069], -[https://attack.mitre.org/techniques/T1069.002/ T1069.002] -| -Permission Groups Discovery, -Domain Groups -| -Discovery, -Discovery - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Get_addefaultdomainpasswordpolicy_with_powershell|Get ADDefaultDomainPasswordPolicy with Powershell]] - -| -[https://attack.mitre.org/techniques/T1201/ T1201] -| -Password Policy Discovery -| -Discovery - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Get_addefaultdomainpasswordpolicy_with_powershell_script_block|Get ADDefaultDomainPasswordPolicy with Powershell Script Block]] - -| -[https://attack.mitre.org/techniques/T1201/ T1201] -| -Password Policy Discovery -| -Discovery - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Get_aduser_with_powershell|Get ADUser with PowerShell]] - -| -[https://attack.mitre.org/techniques/T1087.002/ T1087.002], -[https://attack.mitre.org/techniques/T1087/ T1087] -| -Domain Account, -Account Discovery -| -Discovery, -Discovery - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Get_aduser_with_powershell_script_block|Get ADUser with PowerShell Script Block]] - -| -[https://attack.mitre.org/techniques/T1087.002/ T1087.002], -[https://attack.mitre.org/techniques/T1087/ T1087] -| -Domain Account, -Account Discovery -| -Discovery, -Discovery - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Get_aduserresultantpasswordpolicy_with_powershell|Get ADUserResultantPasswordPolicy with Powershell]] - -| -[https://attack.mitre.org/techniques/T1201/ T1201] -| -Password Policy Discovery -| -Discovery - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Get_aduserresultantpasswordpolicy_with_powershell_script_block|Get ADUserResultantPasswordPolicy with Powershell Script Block]] - -| -[https://attack.mitre.org/techniques/T1201/ T1201] -| -Password Policy Discovery -| -Discovery - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Get_domainpolicy_with_powershell|Get DomainPolicy with Powershell]] - -| -[https://attack.mitre.org/techniques/T1201/ T1201] -| -Password Policy Discovery -| -Discovery - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Get_domainpolicy_with_powershell_script_block|Get DomainPolicy with Powershell Script Block]] - -| -[https://attack.mitre.org/techniques/T1201/ T1201] -| -Password Policy Discovery -| -Discovery - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Get_domainuser_with_powershell|Get DomainUser with PowerShell]] - -| -[https://attack.mitre.org/techniques/T1087.002/ T1087.002], -[https://attack.mitre.org/techniques/T1087/ T1087] -| -Domain Account, -Account Discovery -| -Discovery, -Discovery - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Get_domainuser_with_powershell_script_block|Get DomainUser with PowerShell Script Block]] - -| -[https://attack.mitre.org/techniques/T1087.002/ T1087.002], -[https://attack.mitre.org/techniques/T1087/ T1087] -| -Domain Account, -Account Discovery -| -Discovery, -Discovery - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Get_wmiobject_group_discovery|Get WMIObject Group Discovery]] - -| -[https://attack.mitre.org/techniques/T1069/ T1069], -[https://attack.mitre.org/techniques/T1069.001/ T1069.001] -| -Permission Groups Discovery, -Local Groups -| -Discovery, -Discovery - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Get_wmiobject_group_discovery_with_script_block_logging|Get WMIObject Group Discovery with Script Block Logging]] - -| -[https://attack.mitre.org/techniques/T1069/ T1069], -[https://attack.mitre.org/techniques/T1069.001/ T1069.001] -| -Permission Groups Discovery, -Local Groups -| -Discovery, -Discovery - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Get-domaintrust_with_powershell|Get-DomainTrust with PowerShell]] - -| -[https://attack.mitre.org/techniques/T1482/ T1482] -| -Domain Trust Discovery -| -Discovery - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Get-domaintrust_with_powershell_script_block|Get-DomainTrust with PowerShell Script Block]] - -| -[https://attack.mitre.org/techniques/T1482/ T1482] -| -Domain Trust Discovery -| -Discovery - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Get-foresttrust_with_powershell|Get-ForestTrust with PowerShell]] - -| -[https://attack.mitre.org/techniques/T1482/ T1482] -| -Domain Trust Discovery -| -Discovery - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Get-foresttrust_with_powershell_script_block|Get-ForestTrust with PowerShell Script Block]] - -| -[https://attack.mitre.org/techniques/T1482/ T1482] -| -Domain Trust Discovery -| -Discovery - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Getadcomputer_with_powershell|GetAdComputer with PowerShell]] - -| -[https://attack.mitre.org/techniques/T1018/ T1018] -| -Remote System Discovery -| -Discovery - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Getadcomputer_with_powershell_script_block|GetAdComputer with PowerShell Script Block]] - -| -[https://attack.mitre.org/techniques/T1018/ T1018] -| -Remote System Discovery -| -Discovery - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Getadgroup_with_powershell|GetAdGroup with PowerShell]] - -| -[https://attack.mitre.org/techniques/T1069/ T1069], -[https://attack.mitre.org/techniques/T1069.002/ T1069.002] -| -Permission Groups Discovery, -Domain Groups -| -Discovery, -Discovery - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Getadgroup_with_powershell_script_block|GetAdGroup with PowerShell Script Block]] - -| -[https://attack.mitre.org/techniques/T1069/ T1069], -[https://attack.mitre.org/techniques/T1069.002/ T1069.002] -| -Permission Groups Discovery, -Domain Groups -| -Discovery, -Discovery - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Getcurrent_user_with_powershell|GetCurrent User with PowerShell]] - -| -[https://attack.mitre.org/techniques/T1033/ T1033] -| -System Owner/User Discovery -| -Discovery - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Getcurrent_user_with_powershell_script_block|GetCurrent User with PowerShell Script Block]] - -| -[https://attack.mitre.org/techniques/T1033/ T1033] -| -System Owner/User Discovery -| -Discovery - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Getdomaincomputer_with_powershell|GetDomainComputer with PowerShell]] - -| -[https://attack.mitre.org/techniques/T1018/ T1018] -| -Remote System Discovery -| -Discovery - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Getdomaincomputer_with_powershell_script_block|GetDomainComputer with PowerShell Script Block]] - -| -[https://attack.mitre.org/techniques/T1018/ T1018] -| -Remote System Discovery -| -Discovery - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Getdomaincontroller_with_powershell|GetDomainController with PowerShell]] - -| -[https://attack.mitre.org/techniques/T1018/ T1018] -| -Remote System Discovery -| -Discovery - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Getdomaincontroller_with_powershell_script_block|GetDomainController with PowerShell Script Block]] - -| -[https://attack.mitre.org/techniques/T1018/ T1018] -| -Remote System Discovery -| -Discovery - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Getdomaingroup_with_powershell|GetDomainGroup with PowerShell]] - -| -[https://attack.mitre.org/techniques/T1069/ T1069], -[https://attack.mitre.org/techniques/T1069.002/ T1069.002] -| -Permission Groups Discovery, -Domain Groups -| -Discovery, -Discovery - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Getdomaingroup_with_powershell_script_block|GetDomainGroup with PowerShell Script Block]] - -| -[https://attack.mitre.org/techniques/T1069/ T1069], -[https://attack.mitre.org/techniques/T1069.002/ T1069.002] -| -Permission Groups Discovery, -Domain Groups -| -Discovery, -Discovery - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Getlocaluser_with_powershell|GetLocalUser with PowerShell]] - -| -[https://attack.mitre.org/techniques/T1087/ T1087], -[https://attack.mitre.org/techniques/T1087.001/ T1087.001] -| -Account Discovery, -Local Account -| -Discovery, -Discovery - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Getlocaluser_with_powershell_script_block|GetLocalUser with PowerShell Script Block]] - -| -[https://attack.mitre.org/techniques/T1087/ T1087], -[https://attack.mitre.org/techniques/T1087.001/ T1087.001] -| -Account Discovery, -Local Account -| -Discovery, -Discovery - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Getnettcpconnection_with_powershell|GetNetTcpconnection with PowerShell]] - -| -[https://attack.mitre.org/techniques/T1049/ T1049] -| -System Network Connections Discovery -| -Discovery - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Getnettcpconnection_with_powershell_script_block|GetNetTcpconnection with PowerShell Script Block]] - -| -[https://attack.mitre.org/techniques/T1049/ T1049] -| -System Network Connections Discovery -| -Discovery - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Getwmiobject_ds_user_with_powershell|GetWmiObject DS User with PowerShell]] - -| -[https://attack.mitre.org/techniques/T1087.002/ T1087.002], -[https://attack.mitre.org/techniques/T1087/ T1087] -| -Domain Account, -Account Discovery -| -Discovery, -Discovery - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Getwmiobject_ds_user_with_powershell_script_block|GetWmiObject DS User with PowerShell Script Block]] - -| -[https://attack.mitre.org/techniques/T1087.002/ T1087.002], -[https://attack.mitre.org/techniques/T1087/ T1087] -| -Domain Account, -Account Discovery -| -Discovery, -Discovery - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Getwmiobject_ds_computer_with_powershell|GetWmiObject Ds Computer with PowerShell]] - -| -[https://attack.mitre.org/techniques/T1018/ T1018] -| -Remote System Discovery -| -Discovery - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Getwmiobject_ds_computer_with_powershell_script_block|GetWmiObject Ds Computer with PowerShell Script Block]] - -| -[https://attack.mitre.org/techniques/T1018/ T1018] -| -Remote System Discovery -| -Discovery - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Getwmiobject_ds_group_with_powershell|GetWmiObject Ds Group with PowerShell]] - -| -[https://attack.mitre.org/techniques/T1069/ T1069], -[https://attack.mitre.org/techniques/T1069.002/ T1069.002] -| -Permission Groups Discovery, -Domain Groups -| -Discovery, -Discovery - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Getwmiobject_ds_group_with_powershell_script_block|GetWmiObject Ds Group with PowerShell Script Block]] - -| -[https://attack.mitre.org/techniques/T1069/ T1069], -[https://attack.mitre.org/techniques/T1069.002/ T1069.002] -| -Permission Groups Discovery, -Domain Groups -| -Discovery, -Discovery - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Getwmiobject_user_account_with_powershell|GetWmiObject User Account with PowerShell]] - -| -[https://attack.mitre.org/techniques/T1087/ T1087], -[https://attack.mitre.org/techniques/T1087.001/ T1087.001] -| -Account Discovery, -Local Account -| -Discovery, -Discovery - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Getwmiobject_user_account_with_powershell_script_block|GetWmiObject User Account with PowerShell Script Block]] - -| -[https://attack.mitre.org/techniques/T1087/ T1087], -[https://attack.mitre.org/techniques/T1087.001/ T1087.001] -| -Account Discovery, -Local Account -| -Discovery, -Discovery - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Local_account_discovery_with_wmic|Local Account Discovery With Wmic]] - -| -[https://attack.mitre.org/techniques/T1087/ T1087], -[https://attack.mitre.org/techniques/T1087.001/ T1087.001] -| -Account Discovery, -Local Account -| -Discovery, -Discovery - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Local_account_discovery_with_net|Local Account Discovery with Net]] - -| -[https://attack.mitre.org/techniques/T1087/ T1087], -[https://attack.mitre.org/techniques/T1087.001/ T1087.001] -| -Account Discovery, -Local Account -| -Discovery, -Discovery - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Nltest_domain_trust_discovery|NLTest Domain Trust Discovery]] - -| -[https://attack.mitre.org/techniques/T1482/ T1482] -| -Domain Trust Discovery -| -Discovery - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Net_localgroup_discovery|Net Localgroup Discovery]] - -| -[https://attack.mitre.org/techniques/T1069/ T1069], -[https://attack.mitre.org/techniques/T1069.001/ T1069.001] -| -Permission Groups Discovery, -Local Groups -| -Discovery, -Discovery - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Network_connection_discovery_with_arp|Network Connection Discovery With Arp]] - -| -[https://attack.mitre.org/techniques/T1049/ T1049] -| -System Network Connections Discovery -| -Discovery - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Network_connection_discovery_with_net|Network Connection Discovery With Net]] - -| -[https://attack.mitre.org/techniques/T1049/ T1049] -| -System Network Connections Discovery -| -Discovery - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Network_connection_discovery_with_netstat|Network Connection Discovery With Netstat]] - -| -[https://attack.mitre.org/techniques/T1049/ T1049] -| -System Network Connections Discovery -| -Discovery - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Password_policy_discovery_with_net|Password Policy Discovery with Net]] - -| -[https://attack.mitre.org/techniques/T1201/ T1201] -| -Password Policy Discovery -| -Discovery - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Powershell_get_localgroup_discovery|PowerShell Get LocalGroup Discovery]] - -| -[https://attack.mitre.org/techniques/T1069/ T1069], -[https://attack.mitre.org/techniques/T1069.001/ T1069.001] -| -Permission Groups Discovery, -Local Groups -| -Discovery, -Discovery - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Powershell_get_localgroup_discovery_with_script_block_logging|Powershell Get LocalGroup Discovery with Script Block Logging]] - -| -[https://attack.mitre.org/techniques/T1069/ T1069], -[https://attack.mitre.org/techniques/T1069.001/ T1069.001] -| -Permission Groups Discovery, -Local Groups -| -Discovery, -Discovery - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Remote_system_discovery_with_adsisearcher|Remote System Discovery with Adsisearcher]] - -| -[https://attack.mitre.org/techniques/T1018/ T1018] -| -Remote System Discovery -| -Discovery - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Remote_system_discovery_with_dsquery|Remote System Discovery with Dsquery]] - -| -[https://attack.mitre.org/techniques/T1018/ T1018] -| -Remote System Discovery -| -Discovery - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Remote_system_discovery_with_net|Remote System Discovery with Net]] - -| -[https://attack.mitre.org/techniques/T1018/ T1018] -| -Remote System Discovery -| -Discovery - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Remote_system_discovery_with_wmic|Remote System Discovery with Wmic]] - -| -[https://attack.mitre.org/techniques/T1018/ T1018] -| -Remote System Discovery -| -Discovery - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Serviceprincipalnames_discovery_with_powershell|ServicePrincipalNames Discovery with PowerShell]] - -| -[https://attack.mitre.org/techniques/T1558.003/ T1558.003] -| -Kerberoasting -| -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Serviceprincipalnames_discovery_with_setspn|ServicePrincipalNames Discovery with SetSPN]] - -| -[https://attack.mitre.org/techniques/T1558.003/ T1558.003] -| -Kerberoasting -| -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#System_user_discovery_with_query|System User Discovery With Query]] - -| -[https://attack.mitre.org/techniques/T1033/ T1033] -| -System Owner/User Discovery -| -Discovery - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#System_user_discovery_with_whoami|System User Discovery With Whoami]] - -| -[https://attack.mitre.org/techniques/T1033/ T1033] -| -System Owner/User Discovery -| -Discovery - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#User_discovery_with_env_vars_powershell|User Discovery With Env Vars PowerShell]] - -| -[https://attack.mitre.org/techniques/T1033/ T1033] -| -System Owner/User Discovery -| -Discovery - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#User_discovery_with_env_vars_powershell_script_block|User Discovery With Env Vars PowerShell Script Block]] - -| -[https://attack.mitre.org/techniques/T1033/ T1033] -| -System Owner/User Discovery -| -Discovery - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Wmic_group_discovery|Wmic Group Discovery]] - -| -[https://attack.mitre.org/techniques/T1069/ T1069], -[https://attack.mitre.org/techniques/T1069.001/ T1069.001] -| -Permission Groups Discovery, -Local Groups -| -Discovery, -Discovery - -| Hunting -|} - -====Kill Chain Phase==== - -* Exploitation - -* Lateral Movement - -* Reconnaissance - - -====Reference==== - -* https://attack.mitre.org/tactics/TA0007/ - -* https://adsecurity.org/?p=2535 - -* https://attack.mitre.org/techniques/T1087/001/ - -* https://attack.mitre.org/techniques/T1087/002/ - -* https://attack.mitre.org/techniques/T1087/003/ - -* https://attack.mitre.org/techniques/T1482/ - -* https://attack.mitre.org/techniques/T1201/ - -* https://attack.mitre.org/techniques/T1069/001/ - -* https://attack.mitre.org/techniques/T1069/002/ - -* https://attack.mitre.org/techniques/T1018/ - -* https://attack.mitre.org/techniques/T1049/ - -* https://attack.mitre.org/techniques/T1033/ - - -''version'': 1 -
-
- ----- - -===Active directory password spraying=== -Monitor for activities and techniques associated with Password Spraying attacks within Active Directory environments. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint] -* '''Last Updated''': 2021-04-07 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos|Multiple Disabled Users Failing To Authenticate From Host Using Kerberos]] - -| -[https://attack.mitre.org/techniques/T1110.003/ T1110.003], -[https://attack.mitre.org/techniques/T1110/ T1110] -| -Password Spraying, -Brute Force -| -Credential Access, -Credential Access - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos|Multiple Invalid Users Failing To Authenticate From Host Using Kerberos]] - -| -[https://attack.mitre.org/techniques/T1110.003/ T1110.003], -[https://attack.mitre.org/techniques/T1110/ T1110] -| -Password Spraying, -Brute Force -| -Credential Access, -Credential Access - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm|Multiple Invalid Users Failing To Authenticate From Host Using NTLM]] - -| -[https://attack.mitre.org/techniques/T1110.003/ T1110.003], -[https://attack.mitre.org/techniques/T1110/ T1110] -| -Password Spraying, -Brute Force -| -Credential Access, -Credential Access - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Multiple_users_attempting_to_authenticate_using_explicit_credentials|Multiple Users Attempting To Authenticate Using Explicit Credentials]] - -| -[https://attack.mitre.org/techniques/T1110.003/ T1110.003], -[https://attack.mitre.org/techniques/T1110/ T1110] -| -Password Spraying, -Brute Force -| -Credential Access, -Credential Access - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Multiple_users_failing_to_authenticate_from_host_using_kerberos|Multiple Users Failing To Authenticate From Host Using Kerberos]] - -| -[https://attack.mitre.org/techniques/T1110.003/ T1110.003], -[https://attack.mitre.org/techniques/T1110/ T1110] -| -Password Spraying, -Brute Force -| -Credential Access, -Credential Access - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Multiple_users_failing_to_authenticate_from_host_using_ntlm|Multiple Users Failing To Authenticate From Host Using NTLM]] - -| -[https://attack.mitre.org/techniques/T1110.003/ T1110.003], -[https://attack.mitre.org/techniques/T1110/ T1110] -| -Password Spraying, -Brute Force -| -Credential Access, -Credential Access - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Multiple_users_failing_to_authenticate_from_process|Multiple Users Failing To Authenticate From Process]] - -| -[https://attack.mitre.org/techniques/T1110.003/ T1110.003], -[https://attack.mitre.org/techniques/T1110/ T1110] -| -Password Spraying, -Brute Force -| -Credential Access, -Credential Access - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Multiple_users_remotely_failing_to_authenticate_from_host|Multiple Users Remotely Failing To Authenticate From Host]] - -| -[https://attack.mitre.org/techniques/T1110.003/ T1110.003], -[https://attack.mitre.org/techniques/T1110/ T1110] -| -Password Spraying, -Brute Force -| -Credential Access, -Credential Access - -| Anomaly -|} - -====Kill Chain Phase==== - -* Exploitation - - -====Reference==== - -* https://attack.mitre.org/techniques/T1110/003/ - -* https://www.microsoft.com/security/blog/2020/04/23/protecting-organization-password-spray-attacks/ - -* https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/dn452415(v=ws.11) - - -''version'': 1 -
-
- ----- - -===Bits jobs=== -Adversaries may abuse BITS jobs to persistently execute or clean up after malicious payloads. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint] -* '''Last Updated''': 2021-03-26 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Bits_job_persistence|BITS Job Persistence]] - -| -[https://attack.mitre.org/techniques/T1197/ T1197] -| -BITS Jobs -| -Defense Evasion, Persistence - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Bitsadmin_download_file|BITSAdmin Download File]] - -| -[https://attack.mitre.org/techniques/T1197/ T1197], -[https://attack.mitre.org/techniques/T1105/ T1105] -| -BITS Jobs, -Ingress Tool Transfer -| -Defense Evasion, Persistence, -Command And Control - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Powershell_start-bitstransfer|PowerShell Start-BitsTransfer]] - -| -[https://attack.mitre.org/techniques/T1197/ T1197] -| -BITS Jobs -| -Defense Evasion, Persistence - -| TTP -|} - -====Kill Chain Phase==== - -* Exploitation - - -====Reference==== - -* https://attack.mitre.org/techniques/T1197/ - -* https://docs.microsoft.com/en-us/windows/win32/bits/bitsadmin-tool - - -''version'': 1 -
-
- ----- - -===Baron samedit cve-2021-3156=== -Uncover activity consistent with CVE-2021-3156. Discovered by the Qualys Research Team, this vulnerability has been found to affect sudo across multiple Linux distributions (Ubuntu 20.04 and prior, Debian 10 and prior, Fedora 33 and prior). As this vulnerability was committed to code in July 2011, there will be many distributions affected. Successful exploitation of this vulnerability allows any unprivileged user to gain root privileges on the vulnerable host. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''Last Updated''': 2021-01-27 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Detect_baron_samedit_cve-2021-3156|Detect Baron Samedit CVE-2021-3156]] - -| -[https://attack.mitre.org/techniques/T1068/ T1068] -| -Exploitation for Privilege Escalation -| -Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_baron_samedit_cve-2021-3156_segfault|Detect Baron Samedit CVE-2021-3156 Segfault]] - -| -[https://attack.mitre.org/techniques/T1068/ T1068] -| -Exploitation for Privilege Escalation -| -Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_baron_samedit_cve-2021-3156_via_osquery|Detect Baron Samedit CVE-2021-3156 via OSQuery]] - -| -[https://attack.mitre.org/techniques/T1068/ T1068] -| -Exploitation for Privilege Escalation -| -Privilege Escalation - -| TTP -|} - -====Kill Chain Phase==== - -* Exploitation - - -====Reference==== - -* https://blog.qualys.com/vulnerabilities-research/2021/01/26/cve-2021-3156-heap-based-buffer-overflow-in-sudo-baron-samedit - - -''version'': 1 -
-
- ----- - -===Cobalt strike=== -Cobalt Strike is threat emulation software. Red teams and penetration testers use Cobalt Strike to demonstrate the risk of a breach and evaluate mature security programs. Most recently, Cobalt Strike has become the choice tool by threat groups due to its ease of use and extensibility. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint] -* '''Last Updated''': 2021-02-16 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Anomalous_usage_of_7zip|Anomalous usage of 7zip]] - -| -[https://attack.mitre.org/techniques/T1560.001/ T1560.001], -[https://attack.mitre.org/techniques/T1560/ T1560] -| -Archive via Utility, -Archive Collected Data -| -Collection, -Collection - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Cmd_echo_pipe_-_escalation|CMD Echo Pipe - Escalation]] - -| -[https://attack.mitre.org/techniques/T1059/ T1059], -[https://attack.mitre.org/techniques/T1059.003/ T1059.003], -[https://attack.mitre.org/techniques/T1543.003/ T1543.003], -[https://attack.mitre.org/techniques/T1543/ T1543] -| -Command and Scripting Interpreter, -Windows Command Shell, -Windows Service, -Create or Modify System Process -| -Execution, -Execution, -Persistence, Privilege Escalation, -Persistence, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Cobalt_strike_named_pipes|Cobalt Strike Named Pipes]] - -| -[https://attack.mitre.org/techniques/T1055/ T1055] -| -Process Injection -| -Defense Evasion, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Dllhost_with_no_command_line_arguments_with_network|DLLHost with no Command Line Arguments with Network]] - -| -[https://attack.mitre.org/techniques/T1055/ T1055] -| -Process Injection -| -Defense Evasion, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_regsvr32_application_control_bypass|Detect Regsvr32 Application Control Bypass]] - -| -[https://attack.mitre.org/techniques/T1218/ T1218], -[https://attack.mitre.org/techniques/T1218.010/ T1218.010] -| -Signed Binary Proxy Execution, -Regsvr32 -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Gpupdate_with_no_command_line_arguments_with_network|GPUpdate with no Command Line Arguments with Network]] - -| -[https://attack.mitre.org/techniques/T1055/ T1055] -| -Process Injection -| -Defense Evasion, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Rundll32_with_no_command_line_arguments_with_network|Rundll32 with no Command Line Arguments with Network]] - -| -[https://attack.mitre.org/techniques/T1218/ T1218], -[https://attack.mitre.org/techniques/T1218.011/ T1218.011] -| -Signed Binary Proxy Execution, -Rundll32 -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Searchprotocolhost_with_no_command_line_with_network|SearchProtocolHost with no Command Line with Network]] - -| -[https://attack.mitre.org/techniques/T1055/ T1055] -| -Process Injection -| -Defense Evasion, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Services_escalate_exe|Services Escalate Exe]] - -| -[https://attack.mitre.org/techniques/T1548/ T1548] -| -Abuse Elevation Control Mechanism -| -Privilege Escalation, Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Suspicious_dllhost_no_command_line_arguments|Suspicious DLLHost no Command Line Arguments]] - -| -[https://attack.mitre.org/techniques/T1055/ T1055] -| -Process Injection -| -Defense Evasion, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Suspicious_gpupdate_no_command_line_arguments|Suspicious GPUpdate no Command Line Arguments]] - -| -[https://attack.mitre.org/techniques/T1055/ T1055] -| -Process Injection -| -Defense Evasion, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Suspicious_msbuild_rename|Suspicious MSBuild Rename]] - -| -[https://attack.mitre.org/techniques/T1036/ T1036], -[https://attack.mitre.org/techniques/T1127/ T1127], -[https://attack.mitre.org/techniques/T1036.003/ T1036.003], -[https://attack.mitre.org/techniques/T1127.001/ T1127.001] -| -Masquerading, -Trusted Developer Utilities Proxy Execution, -Rename System Utilities, -MSBuild -| -Defense Evasion, -Defense Evasion, -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Suspicious_rundll32_startw|Suspicious Rundll32 StartW]] - -| -[https://attack.mitre.org/techniques/T1218/ T1218], -[https://attack.mitre.org/techniques/T1218.011/ T1218.011] -| -Signed Binary Proxy Execution, -Rundll32 -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Suspicious_rundll32_no_command_line_arguments|Suspicious Rundll32 no Command Line Arguments]] - -| -[https://attack.mitre.org/techniques/T1218/ T1218], -[https://attack.mitre.org/techniques/T1218.011/ T1218.011] -| -Signed Binary Proxy Execution, -Rundll32 -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Suspicious_searchprotocolhost_no_command_line_arguments|Suspicious SearchProtocolHost no Command Line Arguments]] - -| -[https://attack.mitre.org/techniques/T1055/ T1055] -| -Process Injection -| -Defense Evasion, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Suspicious_microsoft_workflow_compiler_rename|Suspicious microsoft workflow compiler rename]] - -| -[https://attack.mitre.org/techniques/T1036/ T1036], -[https://attack.mitre.org/techniques/T1127/ T1127], -[https://attack.mitre.org/techniques/T1036.003/ T1036.003] -| -Masquerading, -Trusted Developer Utilities Proxy Execution, -Rename System Utilities -| -Defense Evasion, -Defense Evasion, -Defense Evasion - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Suspicious_msbuild_path|Suspicious msbuild path]] - -| -[https://attack.mitre.org/techniques/T1036/ T1036], -[https://attack.mitre.org/techniques/T1127/ T1127], -[https://attack.mitre.org/techniques/T1036.003/ T1036.003], -[https://attack.mitre.org/techniques/T1127.001/ T1127.001] -| -Masquerading, -Trusted Developer Utilities Proxy Execution, -Rename System Utilities, -MSBuild -| -Defense Evasion, -Defense Evasion, -Defense Evasion, -Defense Evasion - -| TTP -|} - -====Kill Chain Phase==== - -* Actions on Objective - -* Actions on Objectives - -* Exploitation - -* Privilege Escalation - - -====Reference==== - -* https://www.cobaltstrike.com/ - -* https://www.infocyte.com/blog/2020/09/02/cobalt-strike-the-new-favorite-among-thieves/ - -* https://bluescreenofjeff.com/2017-01-24-how-to-write-malleable-c2-profiles-for-cobalt-strike/ - -* https://blog.talosintelligence.com/2020/09/coverage-strikes-back-cobalt-strike-paper.html - -* https://www.fireeye.com/blog/threat-research/2020/12/unauthorized-access-of-fireeye-red-team-tools.html - -* https://github.com/MichaelKoczwara/Awesome-CobaltStrike-Defence - -* https://github.com/zer0yu/Awesome-CobaltStrike - - -''version'': 1 -
-
- ----- - -===Collection and staging=== -Monitor for and investigate activities--such as suspicious writes to the Windows Recycling Bin or email servers sending high amounts of traffic to specific hosts, for example--that may indicate that an adversary is harvesting and exfiltrating sensitive data. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint], [https://docs.splunk.com/Documentation/CIM/latest/User/NetworkTraffic Network_Traffic] -* '''Last Updated''': 2020-02-03 -* '''Use Case''': Security Monitoring - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Detect_renamed_7-zip|Detect Renamed 7-Zip]] - -| -[https://attack.mitre.org/techniques/T1560.001/ T1560.001], -[https://attack.mitre.org/techniques/T1560/ T1560] -| -Archive via Utility, -Archive Collected Data -| -Collection, -Collection - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Detect_renamed_winrar|Detect Renamed WinRAR]] - -| -[https://attack.mitre.org/techniques/T1560.001/ T1560.001], -[https://attack.mitre.org/techniques/T1560/ T1560] -| -Archive via Utility, -Archive Collected Data -| -Collection, -Collection - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Email_files_written_outside_of_the_outlook_directory|Email files written outside of the Outlook directory]] - -| -[https://attack.mitre.org/techniques/T1114/ T1114], -[https://attack.mitre.org/techniques/T1114.001/ T1114.001] -| -Email Collection, -Local Email Collection -| -Collection, -Collection - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Email_servers_sending_high_volume_traffic_to_hosts|Email servers sending high volume traffic to hosts]] - -| -[https://attack.mitre.org/techniques/T1114/ T1114], -[https://attack.mitre.org/techniques/T1114.002/ T1114.002] -| -Email Collection, -Remote Email Collection -| -Collection, -Collection - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Hosts_receiving_high_volume_of_network_traffic_from_email_server|Hosts receiving high volume of network traffic from email server]] - -| -[https://attack.mitre.org/techniques/T1114.002/ T1114.002], -[https://attack.mitre.org/techniques/T1114/ T1114] -| -Remote Email Collection, -Email Collection -| -Collection, -Collection - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Suspicious_writes_to_windows_recycle_bin|Suspicious writes to windows Recycle Bin]] - -| -[https://attack.mitre.org/techniques/T1036/ T1036] -| -Masquerading -| -Defense Evasion - -| TTP -|} - -====Kill Chain Phase==== - -* Actions on Objectives - -* Exfiltration - -* Exploitation - - -====Reference==== - -* https://attack.mitre.org/wiki/Collection - -* https://attack.mitre.org/wiki/Technique/T1074 - - -''version'': 1 -
-
- ----- - -===Command and control=== -Detect and investigate tactics, techniques, and procedures leveraged by attackers to establish and operate command and control channels. Implants installed by attackers on compromised endpoints use these channels to receive instructions and send data back to the malicious operators. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint], [https://docs.splunk.com/Documentation/CIM/latest/User/NetworkResolution Network_Resolution], [https://docs.splunk.com/Documentation/CIM/latest/User/NetworkTraffic Network_Traffic] -* '''Last Updated''': 2018-06-01 -* '''Use Case''': Security Monitoring - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Dns_exfiltration_using_nslookup_app|DNS Exfiltration Using Nslookup App]] - -| -[https://attack.mitre.org/techniques/T1048/ T1048] -| -Exfiltration Over Alternative Protocol -| -Exfiltration - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Dns_query_length_outliers_-_mltk|DNS Query Length Outliers - MLTK]] - -| -[https://attack.mitre.org/techniques/T1071.004/ T1071.004], -[https://attack.mitre.org/techniques/T1071/ T1071] -| -DNS, -Application Layer Protocol -| -Command And Control, -Command And Control - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Dns_query_length_with_high_standard_deviation|DNS Query Length With High Standard Deviation]] - -| -[https://attack.mitre.org/techniques/T1048.003/ T1048.003], -[https://attack.mitre.org/techniques/T1048/ T1048] -| -Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol, -Exfiltration Over Alternative Protocol -| -Exfiltration, -Exfiltration - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Detect_large_outbound_icmp_packets|Detect Large Outbound ICMP Packets]] - -| -[https://attack.mitre.org/techniques/T1095/ T1095] -| -Non-Application Layer Protocol -| -Command And Control - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_spike_in_blocked_outbound_traffic_from_your_aws|Detect Spike in blocked Outbound Traffic from your AWS]] - -| -| -| - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Detect_hosts_connecting_to_dynamic_domain_providers|Detect hosts connecting to dynamic domain providers]] - -| -[https://attack.mitre.org/techniques/T1189/ T1189] -| -Drive-by Compromise -| -Initial Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Excessive_dns_failures|Excessive DNS Failures]] - -| -[https://attack.mitre.org/techniques/T1071.004/ T1071.004], -[https://attack.mitre.org/techniques/T1071/ T1071] -| -DNS, -Application Layer Protocol -| -Command And Control, -Command And Control - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Excessive_usage_of_nslookup_app|Excessive Usage of NSLOOKUP App]] - -| -[https://attack.mitre.org/techniques/T1048/ T1048] -| -Exfiltration Over Alternative Protocol -| -Exfiltration - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Multiple_archive_files_http_post_traffic|Multiple Archive Files Http Post Traffic]] - -| -[https://attack.mitre.org/techniques/T1048.003/ T1048.003], -[https://attack.mitre.org/techniques/T1048/ T1048] -| -Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol, -Exfiltration Over Alternative Protocol -| -Exfiltration, -Exfiltration - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Plain_http_post_exfiltrated_data|Plain HTTP POST Exfiltrated Data]] - -| -[https://attack.mitre.org/techniques/T1048.003/ T1048.003], -[https://attack.mitre.org/techniques/T1048/ T1048] -| -Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol, -Exfiltration Over Alternative Protocol -| -Exfiltration, -Exfiltration - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Prohibited_network_traffic_allowed|Prohibited Network Traffic Allowed]] - -| -[https://attack.mitre.org/techniques/T1048/ T1048] -| -Exfiltration Over Alternative Protocol -| -Exfiltration - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Protocol_or_port_mismatch|Protocol or Port Mismatch]] - -| -[https://attack.mitre.org/techniques/T1048.003/ T1048.003], -[https://attack.mitre.org/techniques/T1048/ T1048] -| -Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol, -Exfiltration Over Alternative Protocol -| -Exfiltration, -Exfiltration - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Tor_traffic|TOR Traffic]] - -| -[https://attack.mitre.org/techniques/T1071/ T1071], -[https://attack.mitre.org/techniques/T1071.001/ T1071.001] -| -Application Layer Protocol, -Web Protocols -| -Command And Control, -Command And Control - -| TTP -|} - -====Kill Chain Phase==== - -* Actions on Objectives - -* Command and Control - -* Delivery - -* Exfiltration - -* Exploitation - - -====Reference==== - -* https://attack.mitre.org/wiki/Command_and_Control - -* https://searchsecurity.techtarget.com/feature/Command-and-control-servers-The-puppet-masters-that-govern-malware - - -''version'': 1 -
-
- ----- - -===Credential dumping=== -Uncover activity consistent with credential dumping, a technique wherein attackers compromise systems and attempt to obtain and exfiltrate passwords. The threat actors use these pilfered credentials to further escalate privileges and spread throughout a target environment. The included searches in this Analytic Story are designed to identify attempts to credential dumping. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint] -* '''Last Updated''': 2020-02-04 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Access_lsass_memory_for_dump_creation|Access LSASS Memory for Dump Creation]] - -| -[https://attack.mitre.org/techniques/T1003.001/ T1003.001], -[https://attack.mitre.org/techniques/T1003/ T1003] -| -LSASS Memory, -OS Credential Dumping -| -Credential Access, -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Applying_stolen_credentials_via_mimikatz_modules|Applying Stolen Credentials via Mimikatz modules]] - -| -[https://attack.mitre.org/techniques/T1055/ T1055], -[https://attack.mitre.org/techniques/T1068/ T1068], -[https://attack.mitre.org/techniques/T1078/ T1078], -[https://attack.mitre.org/techniques/T1098/ T1098], -[https://attack.mitre.org/techniques/T1134/ T1134], -[https://attack.mitre.org/techniques/T1543/ T1543], -[https://attack.mitre.org/techniques/T1547/ T1547], -[https://attack.mitre.org/techniques/T1548/ T1548], -[https://attack.mitre.org/techniques/T1554/ T1554], -[https://attack.mitre.org/techniques/T1556/ T1556], -[https://attack.mitre.org/techniques/T1558/ T1558] -| -Process Injection, -Exploitation for Privilege Escalation, -Valid Accounts, -Account Manipulation, -Access Token Manipulation, -Create or Modify System Process, -Boot or Logon Autostart Execution, -Abuse Elevation Control Mechanism, -Compromise Client Software Binary, -Modify Authentication Process, -Steal or Forge Kerberos Tickets -| -Defense Evasion, Privilege Escalation, -Privilege Escalation, -Defense Evasion, Persistence, Privilege Escalation, Initial Access, -Persistence, -Defense Evasion, Privilege Escalation, -Persistence, Privilege Escalation, -Persistence, Privilege Escalation, -Privilege Escalation, Defense Evasion, -Persistence, -Credential Access, Defense Evasion, Persistence, -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Applying_stolen_credentials_via_powersploit_modules|Applying Stolen Credentials via PowerSploit modules]] - -| -[https://attack.mitre.org/techniques/T1055/ T1055], -[https://attack.mitre.org/techniques/T1068/ T1068], -[https://attack.mitre.org/techniques/T1078/ T1078], -[https://attack.mitre.org/techniques/T1098/ T1098], -[https://attack.mitre.org/techniques/T1134/ T1134], -[https://attack.mitre.org/techniques/T1543/ T1543], -[https://attack.mitre.org/techniques/T1547/ T1547], -[https://attack.mitre.org/techniques/T1548/ T1548], -[https://attack.mitre.org/techniques/T1554/ T1554], -[https://attack.mitre.org/techniques/T1555/ T1555], -[https://attack.mitre.org/techniques/T1558/ T1558] -| -Process Injection, -Exploitation for Privilege Escalation, -Valid Accounts, -Account Manipulation, -Access Token Manipulation, -Create or Modify System Process, -Boot or Logon Autostart Execution, -Abuse Elevation Control Mechanism, -Compromise Client Software Binary, -Credentials from Password Stores, -Steal or Forge Kerberos Tickets -| -Defense Evasion, Privilege Escalation, -Privilege Escalation, -Defense Evasion, Persistence, Privilege Escalation, Initial Access, -Persistence, -Defense Evasion, Privilege Escalation, -Persistence, Privilege Escalation, -Persistence, Privilege Escalation, -Privilege Escalation, Defense Evasion, -Persistence, -Credential Access, -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Assessment_of_credential_strength_via_dsinternals_modules|Assessment of Credential Strength via DSInternals modules]] - -| -[https://attack.mitre.org/techniques/T1078/ T1078], -[https://attack.mitre.org/techniques/T1098/ T1098], -[https://attack.mitre.org/techniques/T1087/ T1087], -[https://attack.mitre.org/techniques/T1201/ T1201], -[https://attack.mitre.org/techniques/T1552/ T1552], -[https://attack.mitre.org/techniques/T1555/ T1555] -| -Valid Accounts, -Account Manipulation, -Account Discovery, -Password Policy Discovery, -Unsecured Credentials, -Credentials from Password Stores -| -Defense Evasion, Persistence, Privilege Escalation, Initial Access, -Persistence, -Discovery, -Discovery, -Credential Access, -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Attempted_credential_dump_from_registry_via_reg_exe|Attempted Credential Dump From Registry via Reg exe]] - -| -[https://attack.mitre.org/techniques/T1003.002/ T1003.002], -[https://attack.mitre.org/techniques/T1003/ T1003] -| -Security Account Manager, -OS Credential Dumping -| -Credential Access, -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Attempted_credential_dump_from_registry_via_reg_exe|Attempted Credential Dump From Registry via Reg exe]] - -| -[https://attack.mitre.org/techniques/T1003/ T1003] -| -OS Credential Dumping -| -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Create_remote_thread_into_lsass|Create Remote Thread into LSASS]] - -| -[https://attack.mitre.org/techniques/T1003.001/ T1003.001], -[https://attack.mitre.org/techniques/T1003/ T1003] -| -LSASS Memory, -OS Credential Dumping -| -Credential Access, -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Creation_of_shadow_copy|Creation of Shadow Copy]] - -| -[https://attack.mitre.org/techniques/T1003.003/ T1003.003], -[https://attack.mitre.org/techniques/T1003/ T1003] -| -NTDS, -OS Credential Dumping -| -Credential Access, -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Creation_of_shadow_copy_with_wmic_and_powershell|Creation of Shadow Copy with wmic and powershell]] - -| -[https://attack.mitre.org/techniques/T1003.003/ T1003.003], -[https://attack.mitre.org/techniques/T1003/ T1003] -| -NTDS, -OS Credential Dumping -| -Credential Access, -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Creation_of_lsass_dump_with_taskmgr|Creation of lsass Dump with Taskmgr]] - -| -[https://attack.mitre.org/techniques/T1003.001/ T1003.001], -[https://attack.mitre.org/techniques/T1003/ T1003] -| -LSASS Memory, -OS Credential Dumping -| -Credential Access, -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Credential_dumping_via_copy_command_from_shadow_copy|Credential Dumping via Copy Command from Shadow Copy]] - -| -[https://attack.mitre.org/techniques/T1003.003/ T1003.003], -[https://attack.mitre.org/techniques/T1003/ T1003] -| -NTDS, -OS Credential Dumping -| -Credential Access, -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Credential_dumping_via_symlink_to_shadow_copy|Credential Dumping via Symlink to Shadow Copy]] - -| -[https://attack.mitre.org/techniques/T1003.003/ T1003.003], -[https://attack.mitre.org/techniques/T1003/ T1003] -| -NTDS, -OS Credential Dumping -| -Credential Access, -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Credential_extraction_indicative_of_fgdump_and_cachedump_with_s_option|Credential Extraction indicative of FGDump and CacheDump with s option]] - -| -[https://attack.mitre.org/techniques/T1003/ T1003] -| -OS Credential Dumping -| -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Credential_extraction_indicative_of_fgdump_and_cachedump_with_v_option|Credential Extraction indicative of FGDump and CacheDump with v option]] - -| -[https://attack.mitre.org/techniques/T1003/ T1003] -| -OS Credential Dumping -| -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Credential_extraction_indicative_of_lazagne_command_line_options|Credential Extraction indicative of Lazagne command line options]] - -| -[https://attack.mitre.org/techniques/T1003/ T1003], -[https://attack.mitre.org/techniques/T1555/ T1555] -| -OS Credential Dumping, -Credentials from Password Stores -| -Credential Access, -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Credential_extraction_indicative_of_use_of_dsinternals_credential_conversion_modules|Credential Extraction indicative of use of DSInternals credential conversion modules]] - -| -[https://attack.mitre.org/techniques/T1003/ T1003] -| -OS Credential Dumping -| -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Credential_extraction_indicative_of_use_of_dsinternals_modules|Credential Extraction indicative of use of DSInternals modules]] - -| -[https://attack.mitre.org/techniques/T1003/ T1003] -| -OS Credential Dumping -| -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Credential_extraction_indicative_of_use_of_mimikatz_modules|Credential Extraction indicative of use of Mimikatz modules]] - -| -[https://attack.mitre.org/techniques/T1003/ T1003] -| -OS Credential Dumping -| -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Credential_extraction_indicative_of_use_of_powersploit_modules|Credential Extraction indicative of use of PowerSploit modules]] - -| -[https://attack.mitre.org/techniques/T1003/ T1003] -| -OS Credential Dumping -| -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Credential_extraction_native_microsoft_debuggers_peek_into_the_kernel|Credential Extraction native Microsoft debuggers peek into the kernel]] - -| -[https://attack.mitre.org/techniques/T1003/ T1003] -| -OS Credential Dumping -| -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Credential_extraction_native_microsoft_debuggers_via_z_command_line_option|Credential Extraction native Microsoft debuggers via z command line option]] - -| -[https://attack.mitre.org/techniques/T1003/ T1003] -| -OS Credential Dumping -| -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Credential_extraction_via_get-addbaccount_module_present_in_powersploit_and_dsinternals|Credential Extraction via Get-ADDBAccount module present in PowerSploit and DSInternals]] - -| -[https://attack.mitre.org/techniques/T1003/ T1003] -| -OS Credential Dumping -| -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_copy_of_shadowcopy_with_script_block_logging|Detect Copy of ShadowCopy with Script Block Logging]] - -| -[https://attack.mitre.org/techniques/T1003.002/ T1003.002], -[https://attack.mitre.org/techniques/T1003/ T1003] -| -Security Account Manager, -OS Credential Dumping -| -Credential Access, -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_credential_dumping_through_lsass_access|Detect Credential Dumping through LSASS access]] - -| -[https://attack.mitre.org/techniques/T1003.001/ T1003.001], -[https://attack.mitre.org/techniques/T1003/ T1003] -| -LSASS Memory, -OS Credential Dumping -| -Credential Access, -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_dump_lsass_memory_using_comsvcs|Detect Dump LSASS Memory using comsvcs]] - -| -[https://attack.mitre.org/techniques/T1003.003/ T1003.003], -[https://attack.mitre.org/techniques/T1003/ T1003] -| -NTDS, -OS Credential Dumping -| -Credential Access, -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_kerberoasting|Detect Kerberoasting]] - -| -[https://attack.mitre.org/techniques/T1558.003/ T1558.003], -[https://attack.mitre.org/techniques/T1558/ T1558] -| -Kerberoasting, -Steal or Forge Kerberos Tickets -| -Credential Access, -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_mimikatz_using_loaded_images|Detect Mimikatz Using Loaded Images]] - -| -[https://attack.mitre.org/techniques/T1003.001/ T1003.001], -[https://attack.mitre.org/techniques/T1003/ T1003] -| -LSASS Memory, -OS Credential Dumping -| -Credential Access, -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Dump_lsass_via_comsvcs_dll|Dump LSASS via comsvcs DLL]] - -| -[https://attack.mitre.org/techniques/T1003.001/ T1003.001], -[https://attack.mitre.org/techniques/T1003/ T1003] -| -LSASS Memory, -OS Credential Dumping -| -Credential Access, -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Dump_lsass_via_procdump|Dump LSASS via procdump]] - -| -[https://attack.mitre.org/techniques/T1003.001/ T1003.001], -[https://attack.mitre.org/techniques/T1003/ T1003] -| -LSASS Memory, -OS Credential Dumping -| -Credential Access, -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Enable_wdigest_uselogoncredential_registry|Enable WDigest UseLogonCredential Registry]] - -| -[https://attack.mitre.org/techniques/T1112/ T1112], -[https://attack.mitre.org/techniques/T1003/ T1003] -| -Modify Registry, -OS Credential Dumping -| -Defense Evasion, -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Esentutl_sam_copy|Esentutl SAM Copy]] - -| -[https://attack.mitre.org/techniques/T1003.002/ T1003.002], -[https://attack.mitre.org/techniques/T1003/ T1003] -| -Security Account Manager, -OS Credential Dumping -| -Credential Access, -Credential Access - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Extraction_of_registry_hives|Extraction of Registry Hives]] - -| -[https://attack.mitre.org/techniques/T1003.002/ T1003.002], -[https://attack.mitre.org/techniques/T1003/ T1003] -| -Security Account Manager, -OS Credential Dumping -| -Credential Access, -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Ntdsutil_export_ntds|Ntdsutil Export NTDS]] - -| -[https://attack.mitre.org/techniques/T1003.003/ T1003.003], -[https://attack.mitre.org/techniques/T1003/ T1003] -| -NTDS, -OS Credential Dumping -| -Credential Access, -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Sam_database_file_access_attempt|SAM Database File Access Attempt]] - -| -[https://attack.mitre.org/techniques/T1003.002/ T1003.002], -[https://attack.mitre.org/techniques/T1003/ T1003] -| -Security Account Manager, -OS Credential Dumping -| -Credential Access, -Credential Access - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Secretdumps_offline_ntds_dumping_tool|SecretDumps Offline NTDS Dumping Tool]] - -| -[https://attack.mitre.org/techniques/T1003.003/ T1003.003], -[https://attack.mitre.org/techniques/T1003/ T1003] -| -NTDS, -OS Credential Dumping -| -Credential Access, -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Set_default_powershell_execution_policy_to_unrestricted_or_bypass|Set Default PowerShell Execution Policy To Unrestricted or Bypass]] - -| -[https://attack.mitre.org/techniques/T1059/ T1059], -[https://attack.mitre.org/techniques/T1059.001/ T1059.001] -| -Command and Scripting Interpreter, -PowerShell -| -Execution, -Execution - -| TTP -|} - -====Kill Chain Phase==== - -* Actions on Objectives - -* Exploitation - -* Installation - -* Lateral Movement - -* Privilege Escalation - - -====Reference==== - -* https://attack.mitre.org/wiki/Technique/T1003 - -* https://cyberwardog.blogspot.com/2017/03/chronicles-of-threat-hunter-hunting-for.html - - -''version'': 3 -
-
- ----- - -===Dns hijacking=== -Secure your environment against DNS hijacks with searches that help you detect and investigate unauthorized changes to DNS records. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/NetworkResolution Network_Resolution] -* '''Last Updated''': 2020-02-04 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Detect_hosts_connecting_to_dynamic_domain_providers|Detect hosts connecting to dynamic domain providers]] - -| -[https://attack.mitre.org/techniques/T1189/ T1189] -| -Drive-by Compromise -| -Initial Access - -| TTP -|} - -====Kill Chain Phase==== - -* Actions on Objectives - -* Command and Control - - -====Reference==== - -* https://www.fireeye.com/blog/threat-research/2017/09/apt33-insights-into-iranian-cyber-espionage.html - -* https://umbrella.cisco.com/blog/2013/04/15/on-the-trail-of-malicious-dynamic-dns-domains/ - -* http://www.noip.com/blog/2014/07/11/dynamic-dns-can-use-2/ - -* https://www.splunk.com/blog/2015/08/04/detecting-dynamic-dns-domains-in-splunk.html - - -''version'': 1 -
-
- ----- - -===Data exfiltration=== -The stealing of data by an adversary. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint], [https://docs.splunk.com/Documentation/CIM/latest/User/NetworkTraffic Network_Traffic] -* '''Last Updated''': 2020-10-21 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Dns_exfiltration_using_nslookup_app|DNS Exfiltration Using Nslookup App]] - -| -[https://attack.mitre.org/techniques/T1048/ T1048] -| -Exfiltration Over Alternative Protocol -| -Exfiltration - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_snicat_sni_exfiltration|Detect SNICat SNI Exfiltration]] - -| -[https://attack.mitre.org/techniques/T1041/ T1041] -| -Exfiltration Over C2 Channel -| -Exfiltration - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_shared_ec2_snapshot|Detect shared ec2 snapshot]] - -| -[https://attack.mitre.org/techniques/T1537/ T1537] -| -Transfer Data to Cloud Account -| -Exfiltration - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Excessive_usage_of_nslookup_app|Excessive Usage of NSLOOKUP App]] - -| -[https://attack.mitre.org/techniques/T1048/ T1048] -| -Exfiltration Over Alternative Protocol -| -Exfiltration - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Mailsniper_invoke_functions|Mailsniper Invoke functions]] - -| -[https://attack.mitre.org/techniques/T1114/ T1114], -[https://attack.mitre.org/techniques/T1114.001/ T1114.001] -| -Email Collection, -Local Email Collection -| -Collection, -Collection - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Multiple_archive_files_http_post_traffic|Multiple Archive Files Http Post Traffic]] - -| -[https://attack.mitre.org/techniques/T1048.003/ T1048.003], -[https://attack.mitre.org/techniques/T1048/ T1048] -| -Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol, -Exfiltration Over Alternative Protocol -| -Exfiltration, -Exfiltration - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#O365_pst_export_alert|O365 PST export alert]] - -| -[https://attack.mitre.org/techniques/T1114/ T1114] -| -Email Collection -| -Collection - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#O365_suspicious_admin_email_forwarding|O365 Suspicious Admin Email Forwarding]] - -| -[https://attack.mitre.org/techniques/T1114.003/ T1114.003], -[https://attack.mitre.org/techniques/T1114/ T1114] -| -Email Forwarding Rule, -Email Collection -| -Collection, -Collection - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#O365_suspicious_user_email_forwarding|O365 Suspicious User Email Forwarding]] - -| -[https://attack.mitre.org/techniques/T1114.003/ T1114.003], -[https://attack.mitre.org/techniques/T1114/ T1114] -| -Email Forwarding Rule, -Email Collection -| -Collection, -Collection - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Plain_http_post_exfiltrated_data|Plain HTTP POST Exfiltrated Data]] - -| -[https://attack.mitre.org/techniques/T1048.003/ T1048.003], -[https://attack.mitre.org/techniques/T1048/ T1048] -| -Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol, -Exfiltration Over Alternative Protocol -| -Exfiltration, -Exfiltration - -| TTP -|} - -====Kill Chain Phase==== - -* Actions on Objective - -* Actions on Objectives - -* Exfiltration - -* Exploitation - - -====Reference==== - -* https://attack.mitre.org/tactics/TA0010/ - - -''version'': 1 -
-
- ----- - -===Deobfuscate-decode files or information=== -Adversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint] -* '''Last Updated''': 2021-03-24 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Certutil_with_decode_argument|CertUtil With Decode Argument]] - -| -[https://attack.mitre.org/techniques/T1140/ T1140] -| -Deobfuscate/Decode Files or Information -| -Defense Evasion - -| TTP -|} - -====Kill Chain Phase==== - -* Exploitation - - -====Reference==== - -* https://attack.mitre.org/techniques/T1140/ - - -''version'': 1 -
-
- ----- - -===Detect zerologon attack=== -Uncover activity related to the execution of Zerologon CVE-2020-11472, a technique wherein attackers target a Microsoft Windows Domain Controller to reset its computer account password. The result from this attack is attackers can now provide themselves high privileges and take over Domain Controller. The included searches in this Analytic Story are designed to identify attempts to reset Domain Controller Computer Account via exploit code remotely or via the use of tool Mimikatz as payload carrier. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''Last Updated''': 2020-09-18 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Detect_computer_changed_with_anonymous_account|Detect Computer Changed with Anonymous Account]] - -| -[https://attack.mitre.org/techniques/T1210/ T1210] -| -Exploitation of Remote Services -| -Lateral Movement - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Detect_credential_dumping_through_lsass_access|Detect Credential Dumping through LSASS access]] - -| -[https://attack.mitre.org/techniques/T1003.001/ T1003.001], -[https://attack.mitre.org/techniques/T1003/ T1003] -| -LSASS Memory, -OS Credential Dumping -| -Credential Access, -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_mimikatz_using_loaded_images|Detect Mimikatz Using Loaded Images]] - -| -[https://attack.mitre.org/techniques/T1003.001/ T1003.001], -[https://attack.mitre.org/techniques/T1003/ T1003] -| -LSASS Memory, -OS Credential Dumping -| -Credential Access, -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_zerologon_via_zeek|Detect Zerologon via Zeek]] - -| -[https://attack.mitre.org/techniques/T1190/ T1190] -| -Exploit Public-Facing Application -| -Initial Access - -| TTP -|} - -====Kill Chain Phase==== - -* Actions on Objectives - -* Exploitation - - -====Reference==== - -* https://attack.mitre.org/wiki/Technique/T1003 - -* https://github.com/SecuraBV/CVE-2020-1472 - -* https://www.secura.com/blog/zero-logon - -* https://nvd.nist.gov/vuln/detail/CVE-2020-1472 - - -''version'': 1 -
-
- ----- - -===Disabling security tools=== -Looks for activities and techniques associated with the disabling of security tools on a Windows system, such as suspicious `reg.exe` processes, processes launching netsh, and many others. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint] -* '''Last Updated''': 2020-02-04 -* '''Use Case''': Security Monitoring - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Attempt_to_add_certificate_to_untrusted_store|Attempt To Add Certificate To Untrusted Store]] - -| -[https://attack.mitre.org/techniques/T1553.004/ T1553.004], -[https://attack.mitre.org/techniques/T1553/ T1553] -| -Install Root Certificate, -Subvert Trust Controls -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Attempt_to_stop_security_service|Attempt To Stop Security Service]] - -| -[https://attack.mitre.org/techniques/T1562.001/ T1562.001], -[https://attack.mitre.org/techniques/T1562/ T1562] -| -Disable or Modify Tools, -Impair Defenses -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Processes_launching_netsh|Processes launching netsh]] - -| -[https://attack.mitre.org/techniques/T1562.004/ T1562.004], -[https://attack.mitre.org/techniques/T1562/ T1562] -| -Disable or Modify System Firewall, -Impair Defenses -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Sc_exe_manipulating_windows_services|Sc exe Manipulating Windows Services]] - -| -[https://attack.mitre.org/techniques/T1543.003/ T1543.003], -[https://attack.mitre.org/techniques/T1543/ T1543] -| -Windows Service, -Create or Modify System Process -| -Persistence, Privilege Escalation, -Persistence, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Suspicious_reg_exe_process|Suspicious Reg exe Process]] - -| -[https://attack.mitre.org/techniques/T1112/ T1112] -| -Modify Registry -| -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Unload_sysmon_filter_driver|Unload Sysmon Filter Driver]] - -| -[https://attack.mitre.org/techniques/T1562.001/ T1562.001], -[https://attack.mitre.org/techniques/T1562/ T1562] -| -Disable or Modify Tools, -Impair Defenses -| -Defense Evasion, -Defense Evasion - -| TTP -|} - -====Kill Chain Phase==== - -* Actions on Objectives - -* Installation - - -====Reference==== - -* https://attack.mitre.org/wiki/Technique/T1089 - -* https://blog.malwarebytes.com/cybercrime/2015/11/vonteera-adware-uses-certificates-to-disable-anti-malware/ - -* https://www.operationblockbuster.com/wp-content/uploads/2016/02/Operation-Blockbuster-Tools-Report.pdf - - -''version'': 2 -
-
- ----- - -===Domain trust discovery=== -Adversaries may attempt to gather information on domain trust relationships that may be used to identify lateral movement opportunities in Windows multi-domain/forest environments. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint] -* '''Last Updated''': 2021-03-25 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Dsquery_domain_discovery|DSQuery Domain Discovery]] - -| -[https://attack.mitre.org/techniques/T1482/ T1482] -| -Domain Trust Discovery -| -Discovery - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Nltest_domain_trust_discovery|NLTest Domain Trust Discovery]] - -| -[https://attack.mitre.org/techniques/T1482/ T1482] -| -Domain Trust Discovery -| -Discovery - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Windows_adfind_exe|Windows AdFind Exe]] - -| -[https://attack.mitre.org/techniques/T1018/ T1018] -| -Remote System Discovery -| -Discovery - -| TTP -|} - -====Kill Chain Phase==== - -* Exploitation - - -====Reference==== - -* https://attack.mitre.org/techniques/T1482/ - - -''version'': 1 -
-
- ----- - -===F5 tmui rce cve-2020-5902=== -Uncover activity consistent with CVE-2020-5902. Discovered by Positive Technologies researchers, this vulnerability affects F5 BIG-IP, BIG-IQ. and Traffix SDC devices (vulnerable versions in F5 support link below). This vulnerability allows unauthenticated users, along with authenticated users, who have access to the configuration utility to execute system commands, create/delete files, disable services, and/or execute Java code. This vulnerability can result in full system compromise. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''Last Updated''': 2020-08-02 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Detect_f5_tmui_rce_cve-2020-5902|Detect F5 TMUI RCE CVE-2020-5902]] - -| -[https://attack.mitre.org/techniques/T1190/ T1190] -| -Exploit Public-Facing Application -| -Initial Access - -| TTP -|} - -====Kill Chain Phase==== - -* Exploitation - - -====Reference==== - -* https://www.ptsecurity.com/ww-en/about/news/f5-fixes-critical-vulnerability-discovered-by-positive-technologies-in-big-ip-application-delivery-controller/ - -* https://support.f5.com/csp/article/K52145254 - -* https://blog.cloudflare.com/cve-2020-5902-helping-to-protect-against-the-f5-tmui-rce-vulnerability/ - - -''version'': 1 -
-
- ----- - -===Hafnium group=== -HAFNIUM group was identified by Microsoft as exploiting 4 Microsoft Exchange CVEs in the wild - CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint], [https://docs.splunk.com/Documentation/CIM/latest/User/NetworkTraffic Network_Traffic] -* '''Last Updated''': 2021-03-03 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Any_powershell_downloadstring|Any Powershell DownloadString]] - -| -[https://attack.mitre.org/techniques/T1059/ T1059], -[https://attack.mitre.org/techniques/T1059.001/ T1059.001] -| -Command and Scripting Interpreter, -PowerShell -| -Execution, -Execution - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_exchange_web_shell|Detect Exchange Web Shell]] - -| -[https://attack.mitre.org/techniques/T1505/ T1505], -[https://attack.mitre.org/techniques/T1505.003/ T1505.003] -| -Server Software Component, -Web Shell -| -Persistence, -Persistence - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_new_local_admin_account|Detect New Local Admin account]] - -| -[https://attack.mitre.org/techniques/T1136.001/ T1136.001], -[https://attack.mitre.org/techniques/T1136/ T1136] -| -Local Account, -Create Account -| -Persistence, -Persistence - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_psexec_with_accepteula_flag|Detect PsExec With accepteula Flag]] - -| -[https://attack.mitre.org/techniques/T1021/ T1021], -[https://attack.mitre.org/techniques/T1021.002/ T1021.002] -| -Remote Services, -SMB/Windows Admin Shares -| -Lateral Movement, -Lateral Movement - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_renamed_psexec|Detect Renamed PSExec]] - -| -[https://attack.mitre.org/techniques/T1569/ T1569], -[https://attack.mitre.org/techniques/T1569.002/ T1569.002] -| -System Services, -Service Execution -| -Execution, -Execution - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Dump_lsass_via_comsvcs_dll|Dump LSASS via comsvcs DLL]] - -| -[https://attack.mitre.org/techniques/T1003.001/ T1003.001], -[https://attack.mitre.org/techniques/T1003/ T1003] -| -LSASS Memory, -OS Credential Dumping -| -Credential Access, -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Dump_lsass_via_procdump|Dump LSASS via procdump]] - -| -[https://attack.mitre.org/techniques/T1003.001/ T1003.001], -[https://attack.mitre.org/techniques/T1003/ T1003] -| -LSASS Memory, -OS Credential Dumping -| -Credential Access, -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Email_servers_sending_high_volume_traffic_to_hosts|Email servers sending high volume traffic to hosts]] - -| -[https://attack.mitre.org/techniques/T1114/ T1114], -[https://attack.mitre.org/techniques/T1114.002/ T1114.002] -| -Email Collection, -Remote Email Collection -| -Collection, -Collection - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Malicious_powershell_process_-_connect_to_internet_with_hidden_window|Malicious PowerShell Process - Connect To Internet With Hidden Window]] - -| -[https://attack.mitre.org/techniques/T1059.001/ T1059.001], -[https://attack.mitre.org/techniques/T1059/ T1059] -| -PowerShell, -Command and Scripting Interpreter -| -Execution, -Execution - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Malicious_powershell_process_-_execution_policy_bypass|Malicious PowerShell Process - Execution Policy Bypass]] - -| -[https://attack.mitre.org/techniques/T1059/ T1059], -[https://attack.mitre.org/techniques/T1059.001/ T1059.001] -| -Command and Scripting Interpreter, -PowerShell -| -Execution, -Execution - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Nishang_powershelltcponeline|Nishang PowershellTCPOneLine]] - -| -[https://attack.mitre.org/techniques/T1059/ T1059], -[https://attack.mitre.org/techniques/T1059.001/ T1059.001] -| -Command and Scripting Interpreter, -PowerShell -| -Execution, -Execution - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Ntdsutil_export_ntds|Ntdsutil Export NTDS]] - -| -[https://attack.mitre.org/techniques/T1003.003/ T1003.003], -[https://attack.mitre.org/techniques/T1003/ T1003] -| -NTDS, -OS Credential Dumping -| -Credential Access, -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Set_default_powershell_execution_policy_to_unrestricted_or_bypass|Set Default PowerShell Execution Policy To Unrestricted or Bypass]] - -| -[https://attack.mitre.org/techniques/T1059/ T1059], -[https://attack.mitre.org/techniques/T1059.001/ T1059.001] -| -Command and Scripting Interpreter, -PowerShell -| -Execution, -Execution - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Unified_messaging_service_spawning_a_process|Unified Messaging Service Spawning a Process]] - -| -[https://attack.mitre.org/techniques/T1190/ T1190] -| -Exploit Public-Facing Application -| -Initial Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#W3wp_spawning_shell|W3WP Spawning Shell]] - -| -[https://attack.mitre.org/techniques/T1505/ T1505], -[https://attack.mitre.org/techniques/T1505.003/ T1505.003] -| -Server Software Component, -Web Shell -| -Persistence, -Persistence - -| TTP -|} - -====Kill Chain Phase==== - -* Actions on Objectives - -* Command and Control - -* Execution - -* Exploitation - -* Installation - -* Lateral Movement - - -====Reference==== - -* https://www.splunk.com/en_us/blog/security/detecting-hafnium-exchange-server-zero-day-activity-in-splunk.html - -* https://www.volexity.com/blog/2021/03/02/active-exploitation-of-microsoft-exchange-zero-day-vulnerabilities/ - -* https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/ - -* https://blog.rapid7.com/2021/03/03/rapid7s-insightidr-enables-detection-and-response-to-microsoft-exchange-0-day/ - - -''version'': 1 -
-
- ----- - -===Ingress tool transfer=== -Adversaries may transfer tools or other files from an external system into a compromised environment. Files may be copied from an external adversary controlled system through the command and control channel to bring tools into the victim network or through alternate protocols with another tool such as FTP. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint] -* '''Last Updated''': 2021-03-24 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Any_powershell_downloadfile|Any Powershell DownloadFile]] - -| -[https://attack.mitre.org/techniques/T1059/ T1059], -[https://attack.mitre.org/techniques/T1059.001/ T1059.001] -| -Command and Scripting Interpreter, -PowerShell -| -Execution, -Execution - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Any_powershell_downloadstring|Any Powershell DownloadString]] - -| -[https://attack.mitre.org/techniques/T1059/ T1059], -[https://attack.mitre.org/techniques/T1059.001/ T1059.001] -| -Command and Scripting Interpreter, -PowerShell -| -Execution, -Execution - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Bitsadmin_download_file|BITSAdmin Download File]] - -| -[https://attack.mitre.org/techniques/T1197/ T1197], -[https://attack.mitre.org/techniques/T1105/ T1105] -| -BITS Jobs, -Ingress Tool Transfer -| -Defense Evasion, Persistence, -Command And Control - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Certutil_download_with_urlcache_and_split_arguments|CertUtil Download With URLCache and Split Arguments]] - -| -[https://attack.mitre.org/techniques/T1105/ T1105] -| -Ingress Tool Transfer -| -Command And Control - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Certutil_download_with_verifyctl_and_split_arguments|CertUtil Download With VerifyCtl and Split Arguments]] - -| -[https://attack.mitre.org/techniques/T1105/ T1105] -| -Ingress Tool Transfer -| -Command And Control - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Suspicious_curl_network_connection|Suspicious Curl Network Connection]] - -| -[https://attack.mitre.org/techniques/T1105/ T1105] -| -Ingress Tool Transfer -| -Command And Control - -| TTP -|} - -====Kill Chain Phase==== - -* Actions on Objectives - -* Exploitation - - -====Reference==== - -* https://attack.mitre.org/techniques/T1105/ - - -''version'': 1 -
-
- ----- - -===Lateral movement=== -Detect and investigate tactics, techniques, and procedures around how attackers move laterally within the enterprise. Because lateral movement can expose the adversary to detection, it should be an important focus for security analysts. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint], [https://docs.splunk.com/Documentation/CIM/latest/User/NetworkTraffic Network_Traffic] -* '''Last Updated''': 2020-02-04 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Detect_activity_related_to_pass_the_hash_attacks|Detect Activity Related to Pass the Hash Attacks]] - -| -[https://attack.mitre.org/techniques/T1550/ T1550], -[https://attack.mitre.org/techniques/T1550.002/ T1550.002] -| -Use Alternate Authentication Material, -Pass the Hash -| -Defense Evasion, Lateral Movement, -Defense Evasion, Lateral Movement - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_pass_the_hash|Detect Pass the Hash]] - -| -[https://attack.mitre.org/techniques/T1550/ T1550], -[https://attack.mitre.org/techniques/T1550.002/ T1550.002] -| -Use Alternate Authentication Material, -Pass the Hash -| -Defense Evasion, Lateral Movement, -Defense Evasion, Lateral Movement - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_psexec_with_accepteula_flag|Detect PsExec With accepteula Flag]] - -| -[https://attack.mitre.org/techniques/T1021/ T1021], -[https://attack.mitre.org/techniques/T1021.002/ T1021.002] -| -Remote Services, -SMB/Windows Admin Shares -| -Lateral Movement, -Lateral Movement - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_renamed_psexec|Detect Renamed PSExec]] - -| -[https://attack.mitre.org/techniques/T1569/ T1569], -[https://attack.mitre.org/techniques/T1569.002/ T1569.002] -| -System Services, -Service Execution -| -Execution, -Execution - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Kerberoasting_spn_request_with_rc4_encryption|Kerberoasting spn request with RC4 encryption]] - -| -[https://attack.mitre.org/techniques/T1558.003/ T1558.003], -[https://attack.mitre.org/techniques/T1558/ T1558] -| -Kerberoasting, -Steal or Forge Kerberos Tickets -| -Credential Access, -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Potential_pass_the_token_or_hash_observed_at_the_destination_device|Potential Pass the Token or Hash Observed at the Destination Device]] - -| -[https://attack.mitre.org/techniques/T1550/ T1550], -[https://attack.mitre.org/techniques/T1550.002/ T1550.002] -| -Use Alternate Authentication Material, -Pass the Hash -| -Defense Evasion, Lateral Movement, -Defense Evasion, Lateral Movement - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Potential_pass_the_token_or_hash_observed_by_an_event_collecting_device|Potential Pass the Token or Hash Observed by an Event Collecting Device]] - -| -[https://attack.mitre.org/techniques/T1550/ T1550], -[https://attack.mitre.org/techniques/T1550.002/ T1550.002] -| -Use Alternate Authentication Material, -Pass the Hash -| -Defense Evasion, Lateral Movement, -Defense Evasion, Lateral Movement - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Remote_desktop_network_traffic|Remote Desktop Network Traffic]] - -| -[https://attack.mitre.org/techniques/T1021.001/ T1021.001], -[https://attack.mitre.org/techniques/T1021/ T1021] -| -Remote Desktop Protocol, -Remote Services -| -Lateral Movement, -Lateral Movement - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Remote_desktop_process_running_on_system|Remote Desktop Process Running On System]] - -| -[https://attack.mitre.org/techniques/T1021.001/ T1021.001], -[https://attack.mitre.org/techniques/T1021/ T1021] -| -Remote Desktop Protocol, -Remote Services -| -Lateral Movement, -Lateral Movement - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Schtasks_scheduling_job_on_remote_system|Schtasks scheduling job on remote system]] - -| -[https://attack.mitre.org/techniques/T1053.005/ T1053.005], -[https://attack.mitre.org/techniques/T1053/ T1053] -| -Scheduled Task, -Scheduled Task/Job -| -Execution, Persistence, Privilege Escalation, -Execution, Persistence, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Serviceprincipalnames_discovery_with_powershell|ServicePrincipalNames Discovery with PowerShell]] - -| -[https://attack.mitre.org/techniques/T1558.003/ T1558.003] -| -Kerberoasting -| -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Serviceprincipalnames_discovery_with_setspn|ServicePrincipalNames Discovery with SetSPN]] - -| -[https://attack.mitre.org/techniques/T1558.003/ T1558.003] -| -Kerberoasting -| -Credential Access - -| TTP -|} - -====Kill Chain Phase==== - -* Actions on Objectives - -* Execution - -* Exploitation - -* Lateral Movement - - -====Reference==== - -* https://www.fireeye.com/blog/executive-perspective/2015/08/malware_lateral_move.html - - -''version'': 2 -
-
- ----- - -===Malicious powershell=== -Attackers are finding stealthy ways "live off the land," leveraging utilities and tools that come standard on the endpoint--such as PowerShell--to achieve their goals without downloading binary files. These searches can help you detect and investigate PowerShell command-line options that may be indicative of malicious intent. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint] -* '''Last Updated''': 2017-08-23 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Any_powershell_downloadfile|Any Powershell DownloadFile]] - -| -[https://attack.mitre.org/techniques/T1059/ T1059], -[https://attack.mitre.org/techniques/T1059.001/ T1059.001] -| -Command and Scripting Interpreter, -PowerShell -| -Execution, -Execution - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Any_powershell_downloadstring|Any Powershell DownloadString]] - -| -[https://attack.mitre.org/techniques/T1059/ T1059], -[https://attack.mitre.org/techniques/T1059.001/ T1059.001] -| -Command and Scripting Interpreter, -PowerShell -| -Execution, -Execution - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Credential_extraction_indicative_of_use_of_dsinternals_credential_conversion_modules|Credential Extraction indicative of use of DSInternals credential conversion modules]] - -| -[https://attack.mitre.org/techniques/T1003/ T1003] -| -OS Credential Dumping -| -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Credential_extraction_indicative_of_use_of_dsinternals_modules|Credential Extraction indicative of use of DSInternals modules]] - -| -[https://attack.mitre.org/techniques/T1003/ T1003] -| -OS Credential Dumping -| -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Credential_extraction_indicative_of_use_of_powersploit_modules|Credential Extraction indicative of use of PowerSploit modules]] - -| -[https://attack.mitre.org/techniques/T1003/ T1003] -| -OS Credential Dumping -| -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Credential_extraction_via_get-addbaccount_module_present_in_powersploit_and_dsinternals|Credential Extraction via Get-ADDBAccount module present in PowerSploit and DSInternals]] - -| -[https://attack.mitre.org/techniques/T1003/ T1003] -| -OS Credential Dumping -| -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_empire_with_powershell_script_block_logging|Detect Empire with PowerShell Script Block Logging]] - -| -[https://attack.mitre.org/techniques/T1059/ T1059], -[https://attack.mitre.org/techniques/T1059.001/ T1059.001] -| -Command and Scripting Interpreter, -PowerShell -| -Execution, -Execution - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_mimikatz_with_powershell_script_block_logging|Detect Mimikatz With PowerShell Script Block Logging]] - -| -[https://attack.mitre.org/techniques/T1003/ T1003] -| -OS Credential Dumping -| -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Illegal_access_to_user_content_via_powersploit_modules|Illegal Access To User Content via PowerSploit modules]] - -| -[https://attack.mitre.org/techniques/T1021/ T1021], -[https://attack.mitre.org/techniques/T1113/ T1113], -[https://attack.mitre.org/techniques/T1123/ T1123], -[https://attack.mitre.org/techniques/T1563/ T1563] -| -Remote Services, -Screen Capture, -Audio Capture, -Remote Service Session Hijacking -| -Lateral Movement, -Collection, -Collection, -Lateral Movement - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Illegal_privilege_elevation_and_persistence_via_powersploit_modules|Illegal Privilege Elevation and Persistence via PowerSploit modules]] - -| -[https://attack.mitre.org/techniques/T1053/ T1053], -[https://attack.mitre.org/techniques/T1134/ T1134], -[https://attack.mitre.org/techniques/T1548/ T1548] -| -Scheduled Task/Job, -Access Token Manipulation, -Abuse Elevation Control Mechanism -| -Execution, Persistence, Privilege Escalation, -Defense Evasion, Privilege Escalation, -Privilege Escalation, Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Illegal_service_and_process_control_via_powersploit_modules|Illegal Service and Process Control via PowerSploit modules]] - -| -[https://attack.mitre.org/techniques/T1055/ T1055], -[https://attack.mitre.org/techniques/T1106/ T1106], -[https://attack.mitre.org/techniques/T1569/ T1569] -| -Process Injection, -Native API, -System Services -| -Defense Evasion, Privilege Escalation, -Execution, -Execution - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Malicious_powershell_process_-_connect_to_internet_with_hidden_window|Malicious PowerShell Process - Connect To Internet With Hidden Window]] - -| -[https://attack.mitre.org/techniques/T1059.001/ T1059.001], -[https://attack.mitre.org/techniques/T1059/ T1059] -| -PowerShell, -Command and Scripting Interpreter -| -Execution, -Execution - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Malicious_powershell_process_-_encoded_command|Malicious PowerShell Process - Encoded Command]] - -| -[https://attack.mitre.org/techniques/T1027/ T1027] -| -Obfuscated Files or Information -| -Defense Evasion - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Malicious_powershell_process_with_obfuscation_techniques|Malicious PowerShell Process With Obfuscation Techniques]] - -| -[https://attack.mitre.org/techniques/T1059/ T1059], -[https://attack.mitre.org/techniques/T1059.001/ T1059.001] -| -Command and Scripting Interpreter, -PowerShell -| -Execution, -Execution - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Powershell_4104_hunting|PowerShell 4104 Hunting]] - -| -[https://attack.mitre.org/techniques/T1059/ T1059], -[https://attack.mitre.org/techniques/T1059.001/ T1059.001] -| -Command and Scripting Interpreter, -PowerShell -| -Execution, -Execution - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Powershell_domain_enumeration|PowerShell Domain Enumeration]] - -| -[https://attack.mitre.org/techniques/T1059/ T1059], -[https://attack.mitre.org/techniques/T1059.001/ T1059.001] -| -Command and Scripting Interpreter, -PowerShell -| -Execution, -Execution - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Powershell_loading_dotnet_into_memory_via_system_reflection_assembly|PowerShell Loading DotNET into Memory via System Reflection Assembly]] - -| -[https://attack.mitre.org/techniques/T1059/ T1059], -[https://attack.mitre.org/techniques/T1059.001/ T1059.001] -| -Command and Scripting Interpreter, -PowerShell -| -Execution, -Execution - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Powershell_creating_thread_mutex|Powershell Creating Thread Mutex]] - -| -[https://attack.mitre.org/techniques/T1027/ T1027], -[https://attack.mitre.org/techniques/T1027.005/ T1027.005] -| -Obfuscated Files or Information, -Indicator Removal from Tools -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Powershell_enable_smb1protocol_feature|Powershell Enable SMB1Protocol Feature]] - -| -[https://attack.mitre.org/techniques/T1027/ T1027], -[https://attack.mitre.org/techniques/T1027.005/ T1027.005] -| -Obfuscated Files or Information, -Indicator Removal from Tools -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Powershell_execute_com_object|Powershell Execute COM Object]] - -| -[https://attack.mitre.org/techniques/T1546.015/ T1546.015], -[https://attack.mitre.org/techniques/T1546/ T1546] -| -Component Object Model Hijacking, -Event Triggered Execution -| -Privilege Escalation, Persistence, -Privilege Escalation, Persistence - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Powershell_fileless_process_injection_via_getprocaddress|Powershell Fileless Process Injection via GetProcAddress]] - -| -[https://attack.mitre.org/techniques/T1059/ T1059], -[https://attack.mitre.org/techniques/T1055/ T1055], -[https://attack.mitre.org/techniques/T1059.001/ T1059.001] -| -Command and Scripting Interpreter, -Process Injection, -PowerShell -| -Execution, -Defense Evasion, Privilege Escalation, -Execution - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Powershell_fileless_script_contains_base64_encoded_content|Powershell Fileless Script Contains Base64 Encoded Content]] - -| -[https://attack.mitre.org/techniques/T1059/ T1059], -[https://attack.mitre.org/techniques/T1027/ T1027], -[https://attack.mitre.org/techniques/T1059.001/ T1059.001] -| -Command and Scripting Interpreter, -Obfuscated Files or Information, -PowerShell -| -Execution, -Defense Evasion, -Execution - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Powershell_processing_stream_of_data|Powershell Processing Stream Of Data]] - -| -[https://attack.mitre.org/techniques/T1059/ T1059], -[https://attack.mitre.org/techniques/T1059.001/ T1059.001] -| -Command and Scripting Interpreter, -PowerShell -| -Execution, -Execution - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Powershell_using_memory_as_backing_store|Powershell Using memory As Backing Store]] - -| -[https://attack.mitre.org/techniques/T1140/ T1140] -| -Deobfuscate/Decode Files or Information -| -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Recon_avproduct_through_pwh_or_wmi|Recon AVProduct Through Pwh or WMI]] - -| -[https://attack.mitre.org/techniques/T1592/ T1592] -| -Gather Victim Host Information -| -Reconnaissance - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Recon_using_wmi_class|Recon Using WMI Class]] - -| -[https://attack.mitre.org/techniques/T1592/ T1592] -| -Gather Victim Host Information -| -Reconnaissance - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Set_default_powershell_execution_policy_to_unrestricted_or_bypass|Set Default PowerShell Execution Policy To Unrestricted or Bypass]] - -| -[https://attack.mitre.org/techniques/T1059/ T1059], -[https://attack.mitre.org/techniques/T1059.001/ T1059.001] -| -Command and Scripting Interpreter, -PowerShell -| -Execution, -Execution - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Unloading_amsi_via_reflection|Unloading AMSI via Reflection]] - -| -[https://attack.mitre.org/techniques/T1562/ T1562] -| -Impair Defenses -| -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Wmi_recon_running_process_or_services|WMI Recon Running Process Or Services]] - -| -[https://attack.mitre.org/techniques/T1592/ T1592] -| -Gather Victim Host Information -| -Reconnaissance - -| TTP -|} - -====Kill Chain Phase==== - -* Actions on Objectives - -* Command and Control - -* Exploitation - -* Installation - -* Privilege Escalation - -* Reconnaissance - - -====Reference==== - -* https://blogs.mcafee.com/mcafee-labs/malware-employs-powershell-to-infect-systems/ - -* https://www.crowdstrike.com/blog/bears-midst-intrusion-democratic-national-committee/ - - -''version'': 5 -
-
- ----- - -===Masquerading - rename system utilities=== -Adversaries may rename legitimate system utilities to try to evade security mechanisms concerning the usage of those utilities. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint] -* '''Last Updated''': 2021-04-26 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Execution_of_file_with_multiple_extensions|Execution of File with Multiple Extensions]] - -| -[https://attack.mitre.org/techniques/T1036/ T1036], -[https://attack.mitre.org/techniques/T1036.003/ T1036.003] -| -Masquerading, -Rename System Utilities -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Sdelete_application_execution|Sdelete Application Execution]] - -| -[https://attack.mitre.org/techniques/T1485/ T1485], -[https://attack.mitre.org/techniques/T1070.004/ T1070.004], -[https://attack.mitre.org/techniques/T1070/ T1070] -| -Data Destruction, -File Deletion, -Indicator Removal on Host -| -Impact, -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Suspicious_msbuild_rename|Suspicious MSBuild Rename]] - -| -[https://attack.mitre.org/techniques/T1036/ T1036], -[https://attack.mitre.org/techniques/T1127/ T1127], -[https://attack.mitre.org/techniques/T1036.003/ T1036.003], -[https://attack.mitre.org/techniques/T1127.001/ T1127.001] -| -Masquerading, -Trusted Developer Utilities Proxy Execution, -Rename System Utilities, -MSBuild -| -Defense Evasion, -Defense Evasion, -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Suspicious_rundll32_rename|Suspicious Rundll32 Rename]] - -| -[https://attack.mitre.org/techniques/T1218/ T1218], -[https://attack.mitre.org/techniques/T1036/ T1036], -[https://attack.mitre.org/techniques/T1218.011/ T1218.011], -[https://attack.mitre.org/techniques/T1036.003/ T1036.003] -| -Signed Binary Proxy Execution, -Masquerading, -Rundll32, -Rename System Utilities -| -Defense Evasion, -Defense Evasion, -Defense Evasion, -Defense Evasion - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Suspicious_microsoft_workflow_compiler_rename|Suspicious microsoft workflow compiler rename]] - -| -[https://attack.mitre.org/techniques/T1036/ T1036], -[https://attack.mitre.org/techniques/T1127/ T1127], -[https://attack.mitre.org/techniques/T1036.003/ T1036.003] -| -Masquerading, -Trusted Developer Utilities Proxy Execution, -Rename System Utilities -| -Defense Evasion, -Defense Evasion, -Defense Evasion - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Suspicious_msbuild_path|Suspicious msbuild path]] - -| -[https://attack.mitre.org/techniques/T1036/ T1036], -[https://attack.mitre.org/techniques/T1127/ T1127], -[https://attack.mitre.org/techniques/T1036.003/ T1036.003], -[https://attack.mitre.org/techniques/T1127.001/ T1127.001] -| -Masquerading, -Trusted Developer Utilities Proxy Execution, -Rename System Utilities, -MSBuild -| -Defense Evasion, -Defense Evasion, -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#System_process_running_from_unexpected_location|System Process Running from Unexpected Location]] - -| -[https://attack.mitre.org/techniques/T1036/ T1036] -| -Masquerading -| -Defense Evasion - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#System_processes_run_from_unexpected_locations|System Processes Run From Unexpected Locations]] - -| -[https://attack.mitre.org/techniques/T1036/ T1036], -[https://attack.mitre.org/techniques/T1036.003/ T1036.003] -| -Masquerading, -Rename System Utilities -| -Defense Evasion, -Defense Evasion - -| TTP -|} - -====Kill Chain Phase==== - -* Actions on Objectives - -* Exploitation - - -====Reference==== - -* https://attack.mitre.org/techniques/T1036/003/ - - -''version'': 1 -
-
- ----- - -===Meterpreter=== -Meterpreter provides red teams, pen testers and threat actors interactive access to a compromised host to run commands, upload payloads, download files, and other actions. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint] -* '''Last Updated''': 2021-06-08 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Excessive_number_of_distinct_processes_created_in_windows_temp_folder|Excessive number of distinct processes created in Windows Temp folder]] - -| -[https://attack.mitre.org/techniques/T1059/ T1059] -| -Command and Scripting Interpreter -| -Execution - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Excessive_number_of_taskhost_processes|Excessive number of taskhost processes]] - -| -[https://attack.mitre.org/techniques/T1033/ T1033] -| -System Owner/User Discovery -| -Discovery - -| Anomaly -|} - -====Kill Chain Phase==== - -* Exploitation - - -====Reference==== - -* https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/ - -* https://doubleoctopus.com/security-wiki/threats-and-tools/meterpreter/ - -* https://www.rapid7.com/products/metasploit/ - - -''version'': 1 -
-
- ----- - -===Microsoft mshtml remote code execution cve-2021-40444=== -CVE-2021-40444 is a remote code execution vulnerability in MSHTML, recently used to delivery targeted spearphishing documents. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint] -* '''Last Updated''': 2021-09-08 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Control_loading_from_world_writable_directory|Control Loading from World Writable Directory]] - -| -[https://attack.mitre.org/techniques/T1218/ T1218], -[https://attack.mitre.org/techniques/T1218.002/ T1218.002] -| -Signed Binary Proxy Execution, -Control Panel -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Mshtml_module_load_in_office_product|MSHTML Module Load in Office Product]] - -| -[https://attack.mitre.org/techniques/T1566/ T1566], -[https://attack.mitre.org/techniques/T1566.001/ T1566.001] -| -Phishing, -Spearphishing Attachment -| -Initial Access, -Initial Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Office_product_writing_cab_or_inf|Office Product Writing cab or inf]] - -| -[https://attack.mitre.org/techniques/T1566/ T1566], -[https://attack.mitre.org/techniques/T1566.001/ T1566.001] -| -Phishing, -Spearphishing Attachment -| -Initial Access, -Initial Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Office_spawning_control|Office Spawning Control]] - -| -[https://attack.mitre.org/techniques/T1566/ T1566], -[https://attack.mitre.org/techniques/T1566.001/ T1566.001] -| -Phishing, -Spearphishing Attachment -| -Initial Access, -Initial Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Rundll32_control_rundll_hunt|Rundll32 Control RunDLL Hunt]] - -| -[https://attack.mitre.org/techniques/T1218/ T1218], -[https://attack.mitre.org/techniques/T1218.011/ T1218.011] -| -Signed Binary Proxy Execution, -Rundll32 -| -Defense Evasion, -Defense Evasion - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Rundll32_control_rundll_world_writable_directory|Rundll32 Control RunDLL World Writable Directory]] - -| -[https://attack.mitre.org/techniques/T1218/ T1218], -[https://attack.mitre.org/techniques/T1218.011/ T1218.011] -| -Signed Binary Proxy Execution, -Rundll32 -| -Defense Evasion, -Defense Evasion - -| TTP -|} - -====Kill Chain Phase==== - -* Exploitation - - -====Reference==== - -* https://blog.malwarebytes.com/exploits-and-vulnerabilities/2021/09/windows-mshtml-zero-day-actively-exploited-mitigations-required/ - -* https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40444 - -* https://www.echotrail.io/insights/search/control.exe - - -''version'': 1 -
-
- ----- - -===Nobelium group=== -Sunburst is a trojanized updates to SolarWinds Orion IT monitoring and management software. It was discovered by FireEye in December 2020. The actors behind this campaign gained access to numerous public and private organizations around the world. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint], [https://docs.splunk.com/Documentation/CIM/latest/User/NetworkTraffic Network_Traffic], [https://docs.splunk.com/Documentation/CIM/latest/User/Web Web] -* '''Last Updated''': 2020-12-14 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Anomalous_usage_of_7zip|Anomalous usage of 7zip]] - -| -[https://attack.mitre.org/techniques/T1560.001/ T1560.001], -[https://attack.mitre.org/techniques/T1560/ T1560] -| -Archive via Utility, -Archive Collected Data -| -Collection, -Collection - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Detect_outbound_smb_traffic|Detect Outbound SMB Traffic]] - -| -[https://attack.mitre.org/techniques/T1071.002/ T1071.002], -[https://attack.mitre.org/techniques/T1071/ T1071] -| -File Transfer Protocols, -Application Layer Protocol -| -Command And Control, -Command And Control - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_prohibited_applications_spawning_cmd_exe|Detect Prohibited Applications Spawning cmd exe]] - -| -[https://attack.mitre.org/techniques/T1059/ T1059], -[https://attack.mitre.org/techniques/T1059.003/ T1059.003] -| -Command and Scripting Interpreter, -Windows Command Shell -| -Execution, -Execution - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Detect_rundll32_inline_hta_execution|Detect Rundll32 Inline HTA Execution]] - -| -[https://attack.mitre.org/techniques/T1218/ T1218], -[https://attack.mitre.org/techniques/T1218.005/ T1218.005] -| -Signed Binary Proxy Execution, -Mshta -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#First_time_seen_running_windows_service|First Time Seen Running Windows Service]] - -| -[https://attack.mitre.org/techniques/T1569/ T1569], -[https://attack.mitre.org/techniques/T1569.002/ T1569.002] -| -System Services, -Service Execution -| -Execution, -Execution - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Malicious_powershell_process_-_encoded_command|Malicious PowerShell Process - Encoded Command]] - -| -[https://attack.mitre.org/techniques/T1027/ T1027] -| -Obfuscated Files or Information -| -Defense Evasion - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Sc_exe_manipulating_windows_services|Sc exe Manipulating Windows Services]] - -| -[https://attack.mitre.org/techniques/T1543.003/ T1543.003], -[https://attack.mitre.org/techniques/T1543/ T1543] -| -Windows Service, -Create or Modify System Process -| -Persistence, Privilege Escalation, -Persistence, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Scheduled_task_deleted_or_created_via_cmd|Scheduled Task Deleted Or Created via CMD]] - -| -[https://attack.mitre.org/techniques/T1053.005/ T1053.005], -[https://attack.mitre.org/techniques/T1053/ T1053] -| -Scheduled Task, -Scheduled Task/Job -| -Execution, Persistence, Privilege Escalation, -Execution, Persistence, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Schtasks_scheduling_job_on_remote_system|Schtasks scheduling job on remote system]] - -| -[https://attack.mitre.org/techniques/T1053.005/ T1053.005], -[https://attack.mitre.org/techniques/T1053/ T1053] -| -Scheduled Task, -Scheduled Task/Job -| -Execution, Persistence, Privilege Escalation, -Execution, Persistence, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Sunburst_correlation_dll_and_network_event|Sunburst Correlation DLL and Network Event]] - -| -[https://attack.mitre.org/techniques/T1203/ T1203] -| -Exploitation for Client Execution -| -Execution - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Supernova_webshell|Supernova Webshell]] - -| -[https://attack.mitre.org/techniques/T1505.003/ T1505.003] -| -Web Shell -| -Persistence - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Tor_traffic|TOR Traffic]] - -| -[https://attack.mitre.org/techniques/T1071/ T1071], -[https://attack.mitre.org/techniques/T1071.001/ T1071.001] -| -Application Layer Protocol, -Web Protocols -| -Command And Control, -Command And Control - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Windows_adfind_exe|Windows AdFind Exe]] - -| -[https://attack.mitre.org/techniques/T1018/ T1018] -| -Remote System Discovery -| -Discovery - -| TTP -|} - -====Kill Chain Phase==== - -* Actions on Objective - -* Actions on Objectives - -* Command and Control - -* Exfiltration - -* Exploitation - -* Installation - - -====Reference==== - -* https://www.microsoft.com/security/blog/2021/03/04/goldmax-goldfinder-sibot-analyzing-nobelium-malware/ - -* https://www.fireeye.com/blog/threat-research/2020/12/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor.html - -* https://msrc-blog.microsoft.com/2020/12/13/customer-guidance-on-recent-nation-state-cyber-attacks/ - - -''version'': 2 -
-
- ----- - -===Petitpotam ntlm relay on active directory certificate services=== -PetitPotam (CVE-2021-36942,) is a vulnerablity identified in Microsofts EFSRPC Protocol that can allow an unauthenticated account to escalate privileges to domain administrator given the right circumstances. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''Last Updated''': 2021-08-31 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Petitpotam_network_share_access_request|PetitPotam Network Share Access Request]] - -| -[https://attack.mitre.org/techniques/T1187/ T1187] -| -Forced Authentication -| -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Petitpotam_suspicious_kerberos_tgt_request|PetitPotam Suspicious Kerberos TGT Request]] - -| -[https://attack.mitre.org/techniques/T1003/ T1003] -| -OS Credential Dumping -| -Credential Access - -| TTP -|} - -====Kill Chain Phase==== - -* Exploitation - -* Lateral Movement - - -====Reference==== - -* https://us-cert.cisa.gov/ncas/current-activity/2021/07/27/microsoft-releases-guidance-mitigating-petitpotam-ntlm-relay - -* https://support.microsoft.com/en-us/topic/kb5005413-mitigating-ntlm-relay-attacks-on-active-directory-certificate-services-ad-cs-3612b773-4043-4aa9-b23d-b87910cd3429 - -* https://www.specterops.io/assets/resources/Certified_Pre-Owned.pdf - -* https://github.com/topotam/PetitPotam/ - -* https://github.com/gentilkiwi/mimikatz/releases/tag/2.2.0-20210723 - -* https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36942 - -* https://attack.mitre.org/techniques/T1187/ - - -''version'': 1 -
-
- ----- - -===Possible backdoor activity associated with mudcarp espionage campaigns=== -Monitor your environment for suspicious behaviors that resemble the techniques employed by the MUDCARP threat group. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint] -* '''Last Updated''': 2020-01-22 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Malicious_powershell_process_-_connect_to_internet_with_hidden_window|Malicious PowerShell Process - Connect To Internet With Hidden Window]] - -| -[https://attack.mitre.org/techniques/T1059.001/ T1059.001], -[https://attack.mitre.org/techniques/T1059/ T1059] -| -PowerShell, -Command and Scripting Interpreter -| -Execution, -Execution - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Registry_keys_used_for_persistence|Registry Keys Used For Persistence]] - -| -[https://attack.mitre.org/techniques/T1547.001/ T1547.001], -[https://attack.mitre.org/techniques/T1547/ T1547] -| -Registry Run Keys / Startup Folder, -Boot or Logon Autostart Execution -| -Persistence, Privilege Escalation, -Persistence, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Unusually_long_command_line|Unusually Long Command Line]] - -| -| -| - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Unusually_long_command_line_-_mltk|Unusually Long Command Line - MLTK]] - -| -| -| - -| Anomaly -|} - -====Kill Chain Phase==== - -* Actions on Objectives - -* Command and Control - - -====Reference==== - -* https://www.infosecurity-magazine.com/news/scope-of-mudcarp-attacks-highlight-1/ - -* http://blog.amossys.fr/badflick-is-not-so-bad.html - - -''version'': 1 -
-
- ----- - -===Proxyshell=== -ProxyShell is a chain of exploits targeting on-premise Microsoft Exchange Server - CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint] -* '''Last Updated''': 2021-08-24 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Detect_exchange_web_shell|Detect Exchange Web Shell]] - -| -[https://attack.mitre.org/techniques/T1505/ T1505], -[https://attack.mitre.org/techniques/T1505.003/ T1505.003] -| -Server Software Component, -Web Shell -| -Persistence, -Persistence - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Exchange_powershell_abuse_via_ssrf|Exchange PowerShell Abuse via SSRF]] - -| -[https://attack.mitre.org/techniques/T1190/ T1190] -| -Exploit Public-Facing Application -| -Initial Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Exchange_powershell_module_usage|Exchange PowerShell Module Usage]] - -| -[https://attack.mitre.org/techniques/T1059/ T1059], -[https://attack.mitre.org/techniques/T1059.001/ T1059.001] -| -Command and Scripting Interpreter, -PowerShell -| -Execution, -Execution - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#W3wp_spawning_shell|W3WP Spawning Shell]] - -| -[https://attack.mitre.org/techniques/T1505/ T1505], -[https://attack.mitre.org/techniques/T1505.003/ T1505.003] -| -Server Software Component, -Web Shell -| -Persistence, -Persistence - -| TTP -|} - -====Kill Chain Phase==== - -* Exploitation - -* Reconnaissance - - -====Reference==== - -* https://y4y.space/2021/08/12/my-steps-of-reproducing-proxyshell/ - -* https://www.zerodayinitiative.com/blog/2021/8/17/from-pwn2own-2021-a-new-attack-surface-on-microsoft-exchange-proxyshell - -* https://www.youtube.com/watch?v=FC6iHw258RI - -* https://www.huntress.com/blog/rapid-response-microsoft-exchange-servers-still-vulnerable-to-proxyshell-exploit#what-should-you-do - -* https://i.blackhat.com/USA21/Wednesday-Handouts/us-21-ProxyLogon-Is-Just-The-Tip-Of-The-Iceberg-A-New-Attack-Surface-On-Microsoft-Exchange-Server.pdf - - -''version'': 1 -
-
- ----- - -===Sql injection=== -Use the searches in this Analytic Story to help you detect structured query language (SQL) injection attempts characterized by long URLs that contain malicious parameters. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Web Web] -* '''Last Updated''': 2017-09-19 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Sql_injection_with_long_urls|SQL Injection with Long URLs]] - -| -[https://attack.mitre.org/techniques/T1190/ T1190] -| -Exploit Public-Facing Application -| -Initial Access - -| TTP -|} - -====Kill Chain Phase==== - -* Delivery - - -====Reference==== - -* https://capec.mitre.org/data/definitions/66.html - -* https://www.incapsula.com/web-application-security/sql-injection.html - - -''version'': 1 -
-
- ----- - -===Silver sparrow=== -Silver Sparrow, identified by Red Canary Intelligence, is a new forward looking MacOS (Intel and M1) malicious software downloader utilizing JavaScript for execution and a launchAgent to establish persistence. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint] -* '''Last Updated''': 2021-02-24 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Suspicious_curl_network_connection|Suspicious Curl Network Connection]] - -| -[https://attack.mitre.org/techniques/T1105/ T1105] -| -Ingress Tool Transfer -| -Command And Control - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Suspicious_plistbuddy_usage|Suspicious PlistBuddy Usage]] - -| -[https://attack.mitre.org/techniques/T1543.001/ T1543.001], -[https://attack.mitre.org/techniques/T1543/ T1543] -| -Launch Agent, -Create or Modify System Process -| -Persistence, Privilege Escalation, -Persistence, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Suspicious_plistbuddy_usage_via_osquery|Suspicious PlistBuddy Usage via OSquery]] - -| -[https://attack.mitre.org/techniques/T1543.001/ T1543.001], -[https://attack.mitre.org/techniques/T1543/ T1543] -| -Launch Agent, -Create or Modify System Process -| -Persistence, Privilege Escalation, -Persistence, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Suspicious_sqlite3_lsquarantine_behavior|Suspicious SQLite3 LSQuarantine Behavior]] - -| -[https://attack.mitre.org/techniques/T1074/ T1074] -| -Data Staged -| -Collection - -| TTP -|} - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Reference==== - -* https://redcanary.com/blog/clipping-silver-sparrows-wings/ - -* https://www.sentinelone.com/blog/5-things-you-need-to-know-about-silver-sparrow/ - - -''version'': 1 -
-
- ----- - -===Spearphishing attachments=== -Detect signs of malicious payloads that may indicate that your environment has been breached via a phishing attack. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint] -* '''Last Updated''': 2019-04-29 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Detect_outlook_exe_writing_a_zip_file|Detect Outlook exe writing a zip file]] - -| -[https://attack.mitre.org/techniques/T1566/ T1566], -[https://attack.mitre.org/techniques/T1566.001/ T1566.001] -| -Phishing, -Spearphishing Attachment -| -Initial Access, -Initial Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Excel_spawning_powershell|Excel Spawning PowerShell]] - -| -[https://attack.mitre.org/techniques/T1003.002/ T1003.002], -[https://attack.mitre.org/techniques/T1003/ T1003] -| -Security Account Manager, -OS Credential Dumping -| -Credential Access, -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Excel_spawning_windows_script_host|Excel Spawning Windows Script Host]] - -| -[https://attack.mitre.org/techniques/T1003.002/ T1003.002], -[https://attack.mitre.org/techniques/T1003/ T1003] -| -Security Account Manager, -OS Credential Dumping -| -Credential Access, -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Mshtml_module_load_in_office_product|MSHTML Module Load in Office Product]] - -| -[https://attack.mitre.org/techniques/T1566/ T1566], -[https://attack.mitre.org/techniques/T1566.001/ T1566.001] -| -Phishing, -Spearphishing Attachment -| -Initial Access, -Initial Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Office_application_spawn_rundll32_process|Office Application Spawn rundll32 process]] - -| -[https://attack.mitre.org/techniques/T1566/ T1566], -[https://attack.mitre.org/techniques/T1566.001/ T1566.001] -| -Phishing, -Spearphishing Attachment -| -Initial Access, -Initial Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Office_document_creating_schedule_task|Office Document Creating Schedule Task]] - -| -[https://attack.mitre.org/techniques/T1566/ T1566], -[https://attack.mitre.org/techniques/T1566.001/ T1566.001] -| -Phishing, -Spearphishing Attachment -| -Initial Access, -Initial Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Office_document_executing_macro_code|Office Document Executing Macro Code]] - -| -[https://attack.mitre.org/techniques/T1566/ T1566], -[https://attack.mitre.org/techniques/T1566.001/ T1566.001] -| -Phishing, -Spearphishing Attachment -| -Initial Access, -Initial Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Office_document_spawned_child_process_to_download|Office Document Spawned Child Process To Download]] - -| -[https://attack.mitre.org/techniques/T1566/ T1566], -[https://attack.mitre.org/techniques/T1566.001/ T1566.001] -| -Phishing, -Spearphishing Attachment -| -Initial Access, -Initial Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Office_product_spawning_bitsadmin|Office Product Spawning BITSAdmin]] - -| -[https://attack.mitre.org/techniques/T1566/ T1566], -[https://attack.mitre.org/techniques/T1566.001/ T1566.001] -| -Phishing, -Spearphishing Attachment -| -Initial Access, -Initial Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Office_product_spawning_certutil|Office Product Spawning CertUtil]] - -| -[https://attack.mitre.org/techniques/T1566/ T1566], -[https://attack.mitre.org/techniques/T1566.001/ T1566.001] -| -Phishing, -Spearphishing Attachment -| -Initial Access, -Initial Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Office_product_spawning_mshta|Office Product Spawning MSHTA]] - -| -[https://attack.mitre.org/techniques/T1566/ T1566], -[https://attack.mitre.org/techniques/T1566.001/ T1566.001] -| -Phishing, -Spearphishing Attachment -| -Initial Access, -Initial Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Office_product_spawning_rundll32_with_no_dll|Office Product Spawning Rundll32 with no DLL]] - -| -[https://attack.mitre.org/techniques/T1566/ T1566], -[https://attack.mitre.org/techniques/T1566.001/ T1566.001] -| -Phishing, -Spearphishing Attachment -| -Initial Access, -Initial Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Office_product_spawning_wmic|Office Product Spawning Wmic]] - -| -[https://attack.mitre.org/techniques/T1566/ T1566], -[https://attack.mitre.org/techniques/T1566.001/ T1566.001] -| -Phishing, -Spearphishing Attachment -| -Initial Access, -Initial Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Office_product_writing_cab_or_inf|Office Product Writing cab or inf]] - -| -[https://attack.mitre.org/techniques/T1566/ T1566], -[https://attack.mitre.org/techniques/T1566.001/ T1566.001] -| -Phishing, -Spearphishing Attachment -| -Initial Access, -Initial Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Office_spawning_control|Office Spawning Control]] - -| -[https://attack.mitre.org/techniques/T1566/ T1566], -[https://attack.mitre.org/techniques/T1566.001/ T1566.001] -| -Phishing, -Spearphishing Attachment -| -Initial Access, -Initial Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Process_creating_lnk_file_in_suspicious_location|Process Creating LNK file in Suspicious Location]] - -| -[https://attack.mitre.org/techniques/T1566/ T1566], -[https://attack.mitre.org/techniques/T1566.002/ T1566.002] -| -Phishing, -Spearphishing Link -| -Initial Access, -Initial Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Winword_spawning_cmd|Winword Spawning Cmd]] - -| -[https://attack.mitre.org/techniques/T1566/ T1566], -[https://attack.mitre.org/techniques/T1566.001/ T1566.001] -| -Phishing, -Spearphishing Attachment -| -Initial Access, -Initial Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Winword_spawning_powershell|Winword Spawning PowerShell]] - -| -[https://attack.mitre.org/techniques/T1566/ T1566], -[https://attack.mitre.org/techniques/T1566.001/ T1566.001] -| -Phishing, -Spearphishing Attachment -| -Initial Access, -Initial Access - -| TTP -|} - -====Kill Chain Phase==== - -* Actions on Objectives - -* Exploitation - -* Installation - - -====Reference==== - -* https://www.fireeye.com/blog/threat-research/2019/04/spear-phishing-campaign-targets-ukraine-government.html - - -''version'': 1 -
-
- ----- - -===Suspicious command-line executions=== -Leveraging the Windows command-line interface (CLI) is one of the most common attack techniques--one that is also detailed in the MITRE ATT&CK framework. Use this Analytic Story to help you identify unusual or suspicious use of the CLI on Windows systems. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint] -* '''Last Updated''': 2020-02-03 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Detect_prohibited_applications_spawning_cmd_exe|Detect Prohibited Applications Spawning cmd exe]] - -| -[https://attack.mitre.org/techniques/T1059/ T1059] -| -Command and Scripting Interpreter -| -Execution - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_prohibited_applications_spawning_cmd_exe|Detect Prohibited Applications Spawning cmd exe]] - -| -[https://attack.mitre.org/techniques/T1059/ T1059], -[https://attack.mitre.org/techniques/T1059.003/ T1059.003] -| -Command and Scripting Interpreter, -Windows Command Shell -| -Execution, -Execution - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Detect_use_of_cmd_exe_to_launch_script_interpreters|Detect Use of cmd exe to Launch Script Interpreters]] - -| -[https://attack.mitre.org/techniques/T1059/ T1059], -[https://attack.mitre.org/techniques/T1059.003/ T1059.003] -| -Command and Scripting Interpreter, -Windows Command Shell -| -Execution, -Execution - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#System_processes_run_from_unexpected_locations|System Processes Run From Unexpected Locations]] - -| -[https://attack.mitre.org/techniques/T1036/ T1036], -[https://attack.mitre.org/techniques/T1036.003/ T1036.003] -| -Masquerading, -Rename System Utilities -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Unusually_long_command_line|Unusually Long Command Line]] - -| -| -| - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Unusually_long_command_line_-_mltk|Unusually Long Command Line - MLTK]] - -| -| -| - -| Anomaly -|} - -====Kill Chain Phase==== - -* Actions on Objectives - -* Exploitation - - -====Reference==== - -* https://attack.mitre.org/wiki/Technique/T1059 - -* https://www.microsoft.com/en-us/wdsi/threats/macro-malware - -* https://www.fireeye.com/content/dam/fireeye-www/services/pdfs/mandiant-apt1-report.pdf - - -''version'': 2 -
-
- ----- - -===Suspicious compiled html activity=== -Monitor and detect techniques used by attackers who leverage the mshta.exe process to execute malicious code. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint] -* '''Last Updated''': 2021-02-11 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Detect_html_help_renamed|Detect HTML Help Renamed]] - -| -[https://attack.mitre.org/techniques/T1218/ T1218], -[https://attack.mitre.org/techniques/T1218.001/ T1218.001] -| -Signed Binary Proxy Execution, -Compiled HTML File -| -Defense Evasion, -Defense Evasion - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Detect_html_help_spawn_child_process|Detect HTML Help Spawn Child Process]] - -| -[https://attack.mitre.org/techniques/T1218/ T1218], -[https://attack.mitre.org/techniques/T1218.001/ T1218.001] -| -Signed Binary Proxy Execution, -Compiled HTML File -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_html_help_url_in_command_line|Detect HTML Help URL in Command Line]] - -| -[https://attack.mitre.org/techniques/T1218/ T1218], -[https://attack.mitre.org/techniques/T1218.001/ T1218.001] -| -Signed Binary Proxy Execution, -Compiled HTML File -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_html_help_using_infotech_storage_handlers|Detect HTML Help Using InfoTech Storage Handlers]] - -| -[https://attack.mitre.org/techniques/T1218/ T1218], -[https://attack.mitre.org/techniques/T1218.001/ T1218.001] -| -Signed Binary Proxy Execution, -Compiled HTML File -| -Defense Evasion, -Defense Evasion - -| TTP -|} - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Reference==== - -* https://redcanary.com/blog/introducing-atomictestharnesses/ - -* https://attack.mitre.org/techniques/T1218/001/ - -* https://docs.microsoft.com/en-us/windows/win32/api/htmlhelp/nf-htmlhelp-htmlhelpa - - -''version'': 1 -
-
- ----- - -===Suspicious dns traffic=== -Attackers often attempt to hide within or otherwise abuse the domain name system (DNS). You can thwart attempts to manipulate this omnipresent protocol by monitoring for these types of abuses. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint], [https://docs.splunk.com/Documentation/CIM/latest/User/NetworkResolution Network_Resolution] -* '''Last Updated''': 2017-09-18 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Dns_exfiltration_using_nslookup_app|DNS Exfiltration Using Nslookup App]] - -| -[https://attack.mitre.org/techniques/T1048/ T1048] -| -Exfiltration Over Alternative Protocol -| -Exfiltration - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Dns_query_length_outliers_-_mltk|DNS Query Length Outliers - MLTK]] - -| -[https://attack.mitre.org/techniques/T1071.004/ T1071.004], -[https://attack.mitre.org/techniques/T1071/ T1071] -| -DNS, -Application Layer Protocol -| -Command And Control, -Command And Control - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Dns_query_length_with_high_standard_deviation|DNS Query Length With High Standard Deviation]] - -| -[https://attack.mitre.org/techniques/T1048.003/ T1048.003], -[https://attack.mitre.org/techniques/T1048/ T1048] -| -Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol, -Exfiltration Over Alternative Protocol -| -Exfiltration, -Exfiltration - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Detect_hosts_connecting_to_dynamic_domain_providers|Detect hosts connecting to dynamic domain providers]] - -| -[https://attack.mitre.org/techniques/T1189/ T1189] -| -Drive-by Compromise -| -Initial Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Excessive_dns_failures|Excessive DNS Failures]] - -| -[https://attack.mitre.org/techniques/T1071.004/ T1071.004], -[https://attack.mitre.org/techniques/T1071/ T1071] -| -DNS, -Application Layer Protocol -| -Command And Control, -Command And Control - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Excessive_usage_of_nslookup_app|Excessive Usage of NSLOOKUP App]] - -| -[https://attack.mitre.org/techniques/T1048/ T1048] -| -Exfiltration Over Alternative Protocol -| -Exfiltration - -| Anomaly -|} - -====Kill Chain Phase==== - -* Actions on Objectives - -* Command and Control - -* Exploitation - - -====Reference==== - -* http://blogs.splunk.com/2015/10/01/random-words-on-entropy-and-dns/ - -* http://www.darkreading.com/analytics/security-monitoring/got-malware-three-signs-revealed-in-dns-traffic/d/d-id/1139680 - -* https://live.paloaltonetworks.com/t5/Threat-Vulnerability-Articles/What-are-suspicious-DNS-queries/ta-p/71454 - - -''version'': 1 -
-
- ----- - -===Suspicious emails=== -Email remains one of the primary means for attackers to gain an initial foothold within the modern enterprise. Detect and investigate suspicious emails in your environment with the help of the searches in this Analytic Story. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Email Email] -* '''Last Updated''': 2020-01-27 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Email_attachments_with_lots_of_spaces|Email Attachments With Lots Of Spaces]] - -| -| -| - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Monitor_email_for_brand_abuse|Monitor Email For Brand Abuse]] - -| -| -| - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Suspicious_email_attachment_extensions|Suspicious Email Attachment Extensions]] - -| -[https://attack.mitre.org/techniques/T1566.001/ T1566.001], -[https://attack.mitre.org/techniques/T1566/ T1566] -| -Spearphishing Attachment, -Phishing -| -Initial Access, -Initial Access - -| Anomaly -|} - -====Kill Chain Phase==== - -* Delivery - - -====Reference==== - -* https://www.splunk.com/blog/2015/06/26/phishing-hits-a-new-level-of-quality/ - - -''version'': 1 -
-
- ----- - -===Suspicious mshta activity=== -Monitor and detect techniques used by attackers who leverage the mshta.exe process to execute malicious code. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint] -* '''Last Updated''': 2021-01-20 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Detect_mshta_url_in_command_line|Detect MSHTA Url in Command Line]] - -| -[https://attack.mitre.org/techniques/T1218/ T1218], -[https://attack.mitre.org/techniques/T1218.005/ T1218.005] -| -Signed Binary Proxy Execution, -Mshta -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_prohibited_applications_spawning_cmd_exe|Detect Prohibited Applications Spawning cmd exe]] - -| -[https://attack.mitre.org/techniques/T1059/ T1059] -| -Command and Scripting Interpreter -| -Execution - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_prohibited_applications_spawning_cmd_exe|Detect Prohibited Applications Spawning cmd exe]] - -| -[https://attack.mitre.org/techniques/T1059/ T1059], -[https://attack.mitre.org/techniques/T1059.003/ T1059.003] -| -Command and Scripting Interpreter, -Windows Command Shell -| -Execution, -Execution - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Detect_rundll32_inline_hta_execution|Detect Rundll32 Inline HTA Execution]] - -| -[https://attack.mitre.org/techniques/T1218/ T1218], -[https://attack.mitre.org/techniques/T1218.005/ T1218.005] -| -Signed Binary Proxy Execution, -Mshta -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_mshta_inline_hta_execution|Detect mshta inline hta execution]] - -| -[https://attack.mitre.org/techniques/T1218/ T1218], -[https://attack.mitre.org/techniques/T1218.005/ T1218.005] -| -Signed Binary Proxy Execution, -Mshta -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_mshta_renamed|Detect mshta renamed]] - -| -[https://attack.mitre.org/techniques/T1218/ T1218], -[https://attack.mitre.org/techniques/T1218.005/ T1218.005] -| -Signed Binary Proxy Execution, -Mshta -| -Defense Evasion, -Defense Evasion - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Registry_keys_used_for_persistence|Registry Keys Used For Persistence]] - -| -[https://attack.mitre.org/techniques/T1547.001/ T1547.001], -[https://attack.mitre.org/techniques/T1547/ T1547] -| -Registry Run Keys / Startup Folder, -Boot or Logon Autostart Execution -| -Persistence, Privilege Escalation, -Persistence, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Suspicious_mshta_child_process|Suspicious mshta child process]] - -| -[https://attack.mitre.org/techniques/T1218/ T1218], -[https://attack.mitre.org/techniques/T1218.005/ T1218.005] -| -Signed Binary Proxy Execution, -Mshta -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Suspicious_mshta_spawn|Suspicious mshta spawn]] - -| -[https://attack.mitre.org/techniques/T1218/ T1218], -[https://attack.mitre.org/techniques/T1218.005/ T1218.005] -| -Signed Binary Proxy Execution, -Mshta -| -Defense Evasion, -Defense Evasion - -| TTP -|} - -====Kill Chain Phase==== - -* Actions on Objectives - -* Exploitation - - -====Reference==== - -* https://redcanary.com/blog/introducing-atomictestharnesses/ - -* https://redcanary.com/blog/windows-registry-attacks-threat-detection/ - -* https://attack.mitre.org/techniques/T1218/005/ - -* https://medium.com/@mbromileyDFIR/malware-monday-aebb456356c5 - - -''version'': 2 -
-
- ----- - -===Suspicious okta activity=== -Monitor your Okta environment for suspicious activities. Due to the Covid outbreak, many users are migrating over to leverage cloud services more and more. Okta is a popular tool to manage multiple users and the web-based applications they need to stay productive. The searches in this story will help monitor your Okta environment for suspicious activities and associated user behaviors. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''Last Updated''': 2020-04-02 -* '''Use Case''': Security Monitoring - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Multiple_okta_users_with_invalid_credentials_from_the_same_ip|Multiple Okta Users With Invalid Credentials From The Same IP]] - -| -[https://attack.mitre.org/techniques/T1078/ T1078], -[https://attack.mitre.org/techniques/T1078.001/ T1078.001] -| -Valid Accounts, -Default Accounts -| -Defense Evasion, Persistence, Privilege Escalation, Initial Access, -Defense Evasion, Persistence, Privilege Escalation, Initial Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Okta_account_lockout_events|Okta Account Lockout Events]] - -| -[https://attack.mitre.org/techniques/T1078/ T1078], -[https://attack.mitre.org/techniques/T1078.001/ T1078.001] -| -Valid Accounts, -Default Accounts -| -Defense Evasion, Persistence, Privilege Escalation, Initial Access, -Defense Evasion, Persistence, Privilege Escalation, Initial Access - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Okta_failed_sso_attempts|Okta Failed SSO Attempts]] - -| -[https://attack.mitre.org/techniques/T1078/ T1078], -[https://attack.mitre.org/techniques/T1078.001/ T1078.001] -| -Valid Accounts, -Default Accounts -| -Defense Evasion, Persistence, Privilege Escalation, Initial Access, -Defense Evasion, Persistence, Privilege Escalation, Initial Access - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Okta_user_logins_from_multiple_cities|Okta User Logins From Multiple Cities]] - -| -[https://attack.mitre.org/techniques/T1078/ T1078], -[https://attack.mitre.org/techniques/T1078.001/ T1078.001] -| -Valid Accounts, -Default Accounts -| -Defense Evasion, Persistence, Privilege Escalation, Initial Access, -Defense Evasion, Persistence, Privilege Escalation, Initial Access - -| Anomaly -|} - -====Kill Chain Phase==== - - -====Reference==== - -* https://attack.mitre.org/wiki/Technique/T1078 - -* https://owasp.org/www-community/attacks/Credential_stuffing - -* https://searchsecurity.techtarget.com/answer/What-is-a-password-spraying-attack-and-how-does-it-work - - -''version'': 1 -
-
- ----- - -===Suspicious regsvcs regasm activity=== -Monitor and detect techniques used by attackers who leverage the mshta.exe process to execute malicious code. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint] -* '''Last Updated''': 2021-02-11 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Detect_regasm_spawning_a_process|Detect Regasm Spawning a Process]] - -| -[https://attack.mitre.org/techniques/T1218/ T1218], -[https://attack.mitre.org/techniques/T1218.009/ T1218.009] -| -Signed Binary Proxy Execution, -Regsvcs/Regasm -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_regasm_with_network_connection|Detect Regasm with Network Connection]] - -| -[https://attack.mitre.org/techniques/T1218/ T1218], -[https://attack.mitre.org/techniques/T1218.009/ T1218.009] -| -Signed Binary Proxy Execution, -Regsvcs/Regasm -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_regasm_with_no_command_line_arguments|Detect Regasm with no Command Line Arguments]] - -| -[https://attack.mitre.org/techniques/T1218/ T1218], -[https://attack.mitre.org/techniques/T1218.009/ T1218.009] -| -Signed Binary Proxy Execution, -Regsvcs/Regasm -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_regsvcs_spawning_a_process|Detect Regsvcs Spawning a Process]] - -| -[https://attack.mitre.org/techniques/T1218/ T1218], -[https://attack.mitre.org/techniques/T1218.009/ T1218.009] -| -Signed Binary Proxy Execution, -Regsvcs/Regasm -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_regsvcs_with_network_connection|Detect Regsvcs with Network Connection]] - -| -[https://attack.mitre.org/techniques/T1218/ T1218], -[https://attack.mitre.org/techniques/T1218.009/ T1218.009] -| -Signed Binary Proxy Execution, -Regsvcs/Regasm -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_regsvcs_with_no_command_line_arguments|Detect Regsvcs with No Command Line Arguments]] - -| -[https://attack.mitre.org/techniques/T1218/ T1218], -[https://attack.mitre.org/techniques/T1218.009/ T1218.009] -| -Signed Binary Proxy Execution, -Regsvcs/Regasm -| -Defense Evasion, -Defense Evasion - -| TTP -|} - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Reference==== - -* https://attack.mitre.org/techniques/T1218/009/ - -* https://github.com/rapid7/metasploit-framework/blob/master/documentation/modules/evasion/windows/applocker_evasion_regasm_regsvcs.md - -* https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/ - - -''version'': 1 -
-
- ----- - -===Suspicious regsvr32 activity=== -Monitor and detect techniques used by attackers who leverage the regsvr32.exe process to execute malicious code. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint] -* '''Last Updated''': 2021-01-29 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Detect_regsvr32_application_control_bypass|Detect Regsvr32 Application Control Bypass]] - -| -[https://attack.mitre.org/techniques/T1218/ T1218], -[https://attack.mitre.org/techniques/T1218.010/ T1218.010] -| -Signed Binary Proxy Execution, -Regsvr32 -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Malicious_inprocserver32_modification|Malicious InProcServer32 Modification]] - -| -[https://attack.mitre.org/techniques/T1218.010/ T1218.010], -[https://attack.mitre.org/techniques/T1112/ T1112] -| -Regsvr32, -Modify Registry -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Regsvr32_silent_param_dll_loading|Regsvr32 Silent Param Dll Loading]] - -| -[https://attack.mitre.org/techniques/T1218/ T1218], -[https://attack.mitre.org/techniques/T1218.010/ T1218.010] -| -Signed Binary Proxy Execution, -Regsvr32 -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Suspicious_regsvr32_register_suspicious_path|Suspicious Regsvr32 Register Suspicious Path]] - -| -[https://attack.mitre.org/techniques/T1218/ T1218], -[https://attack.mitre.org/techniques/T1218.010/ T1218.010] -| -Signed Binary Proxy Execution, -Regsvr32 -| -Defense Evasion, -Defense Evasion - -| TTP -|} - -====Kill Chain Phase==== - -* Actions on Objectives - -* Exploitation - - -====Reference==== - -* https://attack.mitre.org/techniques/T1218/010/ - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.010/T1218.010.md - -* https://lolbas-project.github.io/lolbas/Binaries/Regsvr32/ - - -''version'': 1 -
-
- ----- - -===Suspicious rundll32 activity=== -Monitor and detect techniques used by attackers who leverage rundll32.exe to execute arbitrary malicious code. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint] -* '''Last Updated''': 2021-02-03 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Detect_rundll32_application_control_bypass_-_advpack|Detect Rundll32 Application Control Bypass - advpack]] - -| -[https://attack.mitre.org/techniques/T1218/ T1218], -[https://attack.mitre.org/techniques/T1218.011/ T1218.011] -| -Signed Binary Proxy Execution, -Rundll32 -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_rundll32_application_control_bypass_-_setupapi|Detect Rundll32 Application Control Bypass - setupapi]] - -| -[https://attack.mitre.org/techniques/T1218/ T1218], -[https://attack.mitre.org/techniques/T1218.011/ T1218.011] -| -Signed Binary Proxy Execution, -Rundll32 -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_rundll32_application_control_bypass_-_syssetup|Detect Rundll32 Application Control Bypass - syssetup]] - -| -[https://attack.mitre.org/techniques/T1218/ T1218], -[https://attack.mitre.org/techniques/T1218.011/ T1218.011] -| -Signed Binary Proxy Execution, -Rundll32 -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Dump_lsass_via_comsvcs_dll|Dump LSASS via comsvcs DLL]] - -| -[https://attack.mitre.org/techniques/T1003.001/ T1003.001], -[https://attack.mitre.org/techniques/T1003/ T1003] -| -LSASS Memory, -OS Credential Dumping -| -Credential Access, -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Rundll32_control_rundll_hunt|Rundll32 Control RunDLL Hunt]] - -| -[https://attack.mitre.org/techniques/T1218/ T1218], -[https://attack.mitre.org/techniques/T1218.011/ T1218.011] -| -Signed Binary Proxy Execution, -Rundll32 -| -Defense Evasion, -Defense Evasion - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Rundll32_control_rundll_world_writable_directory|Rundll32 Control RunDLL World Writable Directory]] - -| -[https://attack.mitre.org/techniques/T1218/ T1218], -[https://attack.mitre.org/techniques/T1218.011/ T1218.011] -| -Signed Binary Proxy Execution, -Rundll32 -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Rundll32_with_no_command_line_arguments_with_network|Rundll32 with no Command Line Arguments with Network]] - -| -[https://attack.mitre.org/techniques/T1218/ T1218], -[https://attack.mitre.org/techniques/T1218.011/ T1218.011] -| -Signed Binary Proxy Execution, -Rundll32 -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Suspicious_rundll32_rename|Suspicious Rundll32 Rename]] - -| -[https://attack.mitre.org/techniques/T1218/ T1218], -[https://attack.mitre.org/techniques/T1036/ T1036], -[https://attack.mitre.org/techniques/T1218.011/ T1218.011], -[https://attack.mitre.org/techniques/T1036.003/ T1036.003] -| -Signed Binary Proxy Execution, -Masquerading, -Rundll32, -Rename System Utilities -| -Defense Evasion, -Defense Evasion, -Defense Evasion, -Defense Evasion - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Suspicious_rundll32_startw|Suspicious Rundll32 StartW]] - -| -[https://attack.mitre.org/techniques/T1218/ T1218], -[https://attack.mitre.org/techniques/T1218.011/ T1218.011] -| -Signed Binary Proxy Execution, -Rundll32 -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Suspicious_rundll32_dllregisterserver|Suspicious Rundll32 dllregisterserver]] - -| -[https://attack.mitre.org/techniques/T1218/ T1218], -[https://attack.mitre.org/techniques/T1218.011/ T1218.011] -| -Signed Binary Proxy Execution, -Rundll32 -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Suspicious_rundll32_no_command_line_arguments|Suspicious Rundll32 no Command Line Arguments]] - -| -[https://attack.mitre.org/techniques/T1218/ T1218], -[https://attack.mitre.org/techniques/T1218.011/ T1218.011] -| -Signed Binary Proxy Execution, -Rundll32 -| -Defense Evasion, -Defense Evasion - -| TTP -|} - -====Kill Chain Phase==== - -* Actions on Objectives - -* Exploitation - - -====Reference==== - -* https://attack.mitre.org/techniques/T1218/011/ - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.011/T1218.011.md - -* https://lolbas-project.github.io/lolbas/Binaries/Rundll32 - - -''version'': 1 -
-
- ----- - -===Suspicious wmi use=== -Attackers are increasingly abusing Windows Management Instrumentation (WMI), a framework and associated utilities available on all modern Windows operating systems. Because WMI can be leveraged to manage both local and remote systems, it is important to identify the processes executed and the user context within which the activity occurred. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint] -* '''Last Updated''': 2018-10-23 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Detect_wmi_event_subscription_persistence|Detect WMI Event Subscription Persistence]] - -| -[https://attack.mitre.org/techniques/T1546.003/ T1546.003], -[https://attack.mitre.org/techniques/T1546/ T1546] -| -Windows Management Instrumentation Event Subscription, -Event Triggered Execution -| -Privilege Escalation, Persistence, -Privilege Escalation, Persistence - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Process_execution_via_wmi|Process Execution via WMI]] - -| -[https://attack.mitre.org/techniques/T1047/ T1047] -| -Windows Management Instrumentation -| -Execution - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Remote_process_instantiation_via_wmi|Remote Process Instantiation via WMI]] - -| -[https://attack.mitre.org/techniques/T1047/ T1047] -| -Windows Management Instrumentation -| -Execution - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Remote_wmi_command_attempt|Remote WMI Command Attempt]] - -| -[https://attack.mitre.org/techniques/T1047/ T1047] -| -Windows Management Instrumentation -| -Execution - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Script_execution_via_wmi|Script Execution via WMI]] - -| -[https://attack.mitre.org/techniques/T1047/ T1047] -| -Windows Management Instrumentation -| -Execution - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Wmi_permanent_event_subscription|WMI Permanent Event Subscription]] - -| -[https://attack.mitre.org/techniques/T1047/ T1047] -| -Windows Management Instrumentation -| -Execution - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Wmi_permanent_event_subscription_-_sysmon|WMI Permanent Event Subscription - Sysmon]] - -| -[https://attack.mitre.org/techniques/T1546.003/ T1546.003], -[https://attack.mitre.org/techniques/T1546/ T1546] -| -Windows Management Instrumentation Event Subscription, -Event Triggered Execution -| -Privilege Escalation, Persistence, -Privilege Escalation, Persistence - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Wmi_temporary_event_subscription|WMI Temporary Event Subscription]] - -| -[https://attack.mitre.org/techniques/T1047/ T1047] -| -Windows Management Instrumentation -| -Execution - -| TTP -|} - -====Kill Chain Phase==== - -* Actions on Objectives - -* Exploitation - - -====Reference==== - -* https://www.blackhat.com/docs/us-15/materials/us-15-Graeber-Abusing-Windows-Management-Instrumentation-WMI-To-Build-A-Persistent%20Asynchronous-And-Fileless-Backdoor-wp.pdf - -* https://www.fireeye.com/blog/threat-research/2017/03/wmimplant_a_wmi_ba.html - - -''version'': 2 -
-
- ----- - -===Suspicious windows registry activities=== -Monitor and detect registry changes initiated from remote locations, which can be a sign that an attacker has infiltrated your system. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint] -* '''Last Updated''': 2018-05-31 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Disable_uac_remote_restriction|Disable UAC Remote Restriction]] - -| -[https://attack.mitre.org/techniques/T1548.002/ T1548.002], -[https://attack.mitre.org/techniques/T1548/ T1548] -| -Bypass User Account Control, -Abuse Elevation Control Mechanism -| -Privilege Escalation, Defense Evasion, -Privilege Escalation, Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Disabling_remote_user_account_control|Disabling Remote User Account Control]] - -| -[https://attack.mitre.org/techniques/T1548.002/ T1548.002], -[https://attack.mitre.org/techniques/T1548/ T1548] -| -Bypass User Account Control, -Abuse Elevation Control Mechanism -| -Privilege Escalation, Defense Evasion, -Privilege Escalation, Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Monitor_registry_keys_for_print_monitors|Monitor Registry Keys for Print Monitors]] - -| -[https://attack.mitre.org/techniques/T1547.010/ T1547.010], -[https://attack.mitre.org/techniques/T1547/ T1547] -| -Port Monitors, -Boot or Logon Autostart Execution -| -Persistence, Privilege Escalation, -Persistence, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Registry_keys_used_for_persistence|Registry Keys Used For Persistence]] - -| -[https://attack.mitre.org/techniques/T1547.001/ T1547.001], -[https://attack.mitre.org/techniques/T1547/ T1547] -| -Registry Run Keys / Startup Folder, -Boot or Logon Autostart Execution -| -Persistence, Privilege Escalation, -Persistence, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Registry_keys_used_for_privilege_escalation|Registry Keys Used For Privilege Escalation]] - -| -[https://attack.mitre.org/techniques/T1546.012/ T1546.012], -[https://attack.mitre.org/techniques/T1546/ T1546] -| -Image File Execution Options Injection, -Event Triggered Execution -| -Privilege Escalation, Persistence, -Privilege Escalation, Persistence - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Registry_keys_for_creating_shim_databases|Registry Keys for Creating SHIM Databases]] - -| -[https://attack.mitre.org/techniques/T1546.011/ T1546.011], -[https://attack.mitre.org/techniques/T1546/ T1546] -| -Application Shimming, -Event Triggered Execution -| -Privilege Escalation, Persistence, -Privilege Escalation, Persistence - -| TTP -|} - -====Kill Chain Phase==== - -* Actions on Objectives - -* Exploitation - - -====Reference==== - -* https://redcanary.com/blog/windows-registry-attacks-threat-detection/ - -* https://attack.mitre.org/wiki/Technique/T1112 - - -''version'': 1 -
-
- ----- - -===Suspicious zoom child processes=== -Attackers are using Zoom as an vector to increase privileges on a sytems. This story detects new child processes of zoom and provides investigative actions for this detection. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint] -* '''Last Updated''': 2020-04-13 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Detect_prohibited_applications_spawning_cmd_exe|Detect Prohibited Applications Spawning cmd exe]] - -| -[https://attack.mitre.org/techniques/T1059/ T1059] -| -Command and Scripting Interpreter -| -Execution - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_prohibited_applications_spawning_cmd_exe|Detect Prohibited Applications Spawning cmd exe]] - -| -[https://attack.mitre.org/techniques/T1059/ T1059], -[https://attack.mitre.org/techniques/T1059.003/ T1059.003] -| -Command and Scripting Interpreter, -Windows Command Shell -| -Execution, -Execution - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#First_time_seen_child_process_of_zoom|First Time Seen Child Process of Zoom]] - -| -[https://attack.mitre.org/techniques/T1068/ T1068] -| -Exploitation for Privilege Escalation -| -Privilege Escalation - -| Anomaly -|} - -====Kill Chain Phase==== - -* Actions on Objectives - -* Exploitation - - -====Reference==== - -* https://blog.rapid7.com/2020/04/02/dispelling-zoom-bugbears-what-you-need-to-know-about-the-latest-zoom-vulnerabilities/ - -* https://threatpost.com/two-zoom-zero-day-flaws-uncovered/154337/ - - -''version'': 1 -
-
- ----- - -===Trusted developer utilities proxy execution=== -Monitor and detect behaviors used by attackers who leverage trusted developer utilities to execute malicious code. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint] -* '''Last Updated''': 2021-01-12 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Suspicious_microsoft_workflow_compiler_rename|Suspicious microsoft workflow compiler rename]] - -| -[https://attack.mitre.org/techniques/T1036/ T1036], -[https://attack.mitre.org/techniques/T1127/ T1127], -[https://attack.mitre.org/techniques/T1036.003/ T1036.003] -| -Masquerading, -Trusted Developer Utilities Proxy Execution, -Rename System Utilities -| -Defense Evasion, -Defense Evasion, -Defense Evasion - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Suspicious_microsoft_workflow_compiler_usage|Suspicious microsoft workflow compiler usage]] - -| -[https://attack.mitre.org/techniques/T1127/ T1127] -| -Trusted Developer Utilities Proxy Execution -| -Defense Evasion - -| TTP -|} - -====Kill Chain Phase==== - -* Exploitation - - -====Reference==== - -* https://attack.mitre.org/techniques/T1127/ - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218/T1218.md - -* https://lolbas-project.github.io/lolbas/Binaries/Microsoft.Workflow.Compiler/ - - -''version'': 1 -
-
- ----- - -===Trusted developer utilities proxy execution msbuild=== -Monitor and detect techniques used by attackers who leverage the msbuild.exe process to execute malicious code. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint] -* '''Last Updated''': 2021-01-21 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Msbuild_suspicious_spawned_by_script_process|MSBuild Suspicious Spawned By Script Process]] - -| -[https://attack.mitre.org/techniques/T1127.001/ T1127.001], -[https://attack.mitre.org/techniques/T1127/ T1127] -| -MSBuild, -Trusted Developer Utilities Proxy Execution -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Suspicious_msbuild_rename|Suspicious MSBuild Rename]] - -| -[https://attack.mitre.org/techniques/T1036/ T1036], -[https://attack.mitre.org/techniques/T1127/ T1127], -[https://attack.mitre.org/techniques/T1036.003/ T1036.003], -[https://attack.mitre.org/techniques/T1127.001/ T1127.001] -| -Masquerading, -Trusted Developer Utilities Proxy Execution, -Rename System Utilities, -MSBuild -| -Defense Evasion, -Defense Evasion, -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Suspicious_msbuild_spawn|Suspicious MSBuild Spawn]] - -| -[https://attack.mitre.org/techniques/T1127/ T1127], -[https://attack.mitre.org/techniques/T1127.001/ T1127.001] -| -Trusted Developer Utilities Proxy Execution, -MSBuild -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Suspicious_msbuild_path|Suspicious msbuild path]] - -| -[https://attack.mitre.org/techniques/T1036/ T1036], -[https://attack.mitre.org/techniques/T1127/ T1127], -[https://attack.mitre.org/techniques/T1036.003/ T1036.003], -[https://attack.mitre.org/techniques/T1127.001/ T1127.001] -| -Masquerading, -Trusted Developer Utilities Proxy Execution, -Rename System Utilities, -MSBuild -| -Defense Evasion, -Defense Evasion, -Defense Evasion, -Defense Evasion - -| TTP -|} - -====Kill Chain Phase==== - -* Exploitation - - -====Reference==== - -* https://attack.mitre.org/techniques/T1127/001/ - -* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1127.001/T1127.001.md - -* https://github.com/infosecn1nja/MaliciousMacroMSBuild - -* https://github.com/xorrior/RandomPS-Scripts/blob/master/Invoke-ExecuteMSBuild.ps1 - -* https://lolbas-project.github.io/lolbas/Binaries/Msbuild/ - -* https://github.com/MHaggis/CBR-Queries/blob/master/msbuild.md - - -''version'': 1 -
-
- ----- - -===Windows dns sigred cve-2020-1350=== -Uncover activity consistent with CVE-2020-1350, or SIGRed. Discovered by Checkpoint researchers, this vulnerability affects Windows 2003 to 2019, and is triggered by a malicious DNS response (only affects DNS over TCP). An attacker can use the malicious payload to cause a buffer overflow on the vulnerable system, leading to compromise. The included searches in this Analytic Story are designed to identify the large response payload for SIG and KEY DNS records which can be used for the exploit. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/NetworkResolution Network_Resolution] -* '''Last Updated''': 2020-07-28 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Detect_windows_dns_sigred_via_splunk_stream|Detect Windows DNS SIGRed via Splunk Stream]] - -| -[https://attack.mitre.org/techniques/T1203/ T1203] -| -Exploitation for Client Execution -| -Execution - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_windows_dns_sigred_via_zeek|Detect Windows DNS SIGRed via Zeek]] - -| -[https://attack.mitre.org/techniques/T1203/ T1203] -| -Exploitation for Client Execution -| -Execution - -| TTP -|} - -====Kill Chain Phase==== - -* Exploitation - - -====Reference==== - -* https://research.checkpoint.com/2020/resolving-your-way-into-domain-admin-exploiting-a-17-year-old-bug-in-windows-dns-servers/ - -* https://support.microsoft.com/en-au/help/4569509/windows-dns-server-remote-code-execution-vulnerability - - -''version'': 1 -
-
- ----- - -===Windows defense evasion tactics=== -Detect tactics used by malware to evade defenses on Windows endpoints. A few of these include suspicious `reg.exe` processes, files hidden with `attrib.exe` and disabling user-account control, among many others - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint] -* '''Last Updated''': 2018-05-31 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Disable_registry_tool|Disable Registry Tool]] - -| -[https://attack.mitre.org/techniques/T1562.001/ T1562.001], -[https://attack.mitre.org/techniques/T1562/ T1562] -| -Disable or Modify Tools, -Impair Defenses -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Disable_security_logs_using_minint_registry|Disable Security Logs Using MiniNt Registry]] - -| -[https://attack.mitre.org/techniques/T1112/ T1112] -| -Modify Registry -| -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Disable_show_hidden_files|Disable Show Hidden Files]] - -| -[https://attack.mitre.org/techniques/T1564.001/ T1564.001], -[https://attack.mitre.org/techniques/T1562.001/ T1562.001], -[https://attack.mitre.org/techniques/T1564/ T1564], -[https://attack.mitre.org/techniques/T1562/ T1562] -| -Hidden Files and Directories, -Disable or Modify Tools, -Hide Artifacts, -Impair Defenses -| -Defense Evasion, -Defense Evasion, -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Disable_uac_remote_restriction|Disable UAC Remote Restriction]] - -| -[https://attack.mitre.org/techniques/T1548.002/ T1548.002], -[https://attack.mitre.org/techniques/T1548/ T1548] -| -Bypass User Account Control, -Abuse Elevation Control Mechanism -| -Privilege Escalation, Defense Evasion, -Privilege Escalation, Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Disable_windows_behavior_monitoring|Disable Windows Behavior Monitoring]] - -| -[https://attack.mitre.org/techniques/T1562.001/ T1562.001], -[https://attack.mitre.org/techniques/T1562/ T1562] -| -Disable or Modify Tools, -Impair Defenses -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Disable_windows_smartscreen_protection|Disable Windows SmartScreen Protection]] - -| -[https://attack.mitre.org/techniques/T1562.001/ T1562.001], -[https://attack.mitre.org/techniques/T1562/ T1562] -| -Disable or Modify Tools, -Impair Defenses -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Disabling_cmd_application|Disabling CMD Application]] - -| -[https://attack.mitre.org/techniques/T1562.001/ T1562.001], -[https://attack.mitre.org/techniques/T1562/ T1562] -| -Disable or Modify Tools, -Impair Defenses -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Disabling_controlpanel|Disabling ControlPanel]] - -| -[https://attack.mitre.org/techniques/T1562.001/ T1562.001], -[https://attack.mitre.org/techniques/T1562/ T1562] -| -Disable or Modify Tools, -Impair Defenses -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Disabling_firewall_with_netsh|Disabling Firewall with Netsh]] - -| -[https://attack.mitre.org/techniques/T1562.001/ T1562.001], -[https://attack.mitre.org/techniques/T1562/ T1562] -| -Disable or Modify Tools, -Impair Defenses -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Disabling_folderoptions_windows_feature|Disabling FolderOptions Windows Feature]] - -| -[https://attack.mitre.org/techniques/T1562.001/ T1562.001], -[https://attack.mitre.org/techniques/T1562/ T1562] -| -Disable or Modify Tools, -Impair Defenses -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Disabling_norun_windows_app|Disabling NoRun Windows App]] - -| -[https://attack.mitre.org/techniques/T1562.001/ T1562.001], -[https://attack.mitre.org/techniques/T1562/ T1562] -| -Disable or Modify Tools, -Impair Defenses -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Disabling_remote_user_account_control|Disabling Remote User Account Control]] - -| -[https://attack.mitre.org/techniques/T1548.002/ T1548.002], -[https://attack.mitre.org/techniques/T1548/ T1548] -| -Bypass User Account Control, -Abuse Elevation Control Mechanism -| -Privilege Escalation, Defense Evasion, -Privilege Escalation, Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Disabling_systemrestore_in_registry|Disabling SystemRestore In Registry]] - -| -[https://attack.mitre.org/techniques/T1562.001/ T1562.001], -[https://attack.mitre.org/techniques/T1562/ T1562] -| -Disable or Modify Tools, -Impair Defenses -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Disabling_task_manager|Disabling Task Manager]] - -| -[https://attack.mitre.org/techniques/T1562.001/ T1562.001], -[https://attack.mitre.org/techniques/T1562/ T1562] -| -Disable or Modify Tools, -Impair Defenses -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Eventvwr_uac_bypass|Eventvwr UAC Bypass]] - -| -[https://attack.mitre.org/techniques/T1548.002/ T1548.002], -[https://attack.mitre.org/techniques/T1548/ T1548] -| -Bypass User Account Control, -Abuse Elevation Control Mechanism -| -Privilege Escalation, Defense Evasion, -Privilege Escalation, Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Excessive_number_of_service_control_start_as_disabled|Excessive number of service control start as disabled]] - -| -[https://attack.mitre.org/techniques/T1562.001/ T1562.001], -[https://attack.mitre.org/techniques/T1562/ T1562] -| -Disable or Modify Tools, -Impair Defenses -| -Defense Evasion, -Defense Evasion - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Fodhelper_uac_bypass|FodHelper UAC Bypass]] - -| -[https://attack.mitre.org/techniques/T1112/ T1112], -[https://attack.mitre.org/techniques/T1548.002/ T1548.002], -[https://attack.mitre.org/techniques/T1548/ T1548] -| -Modify Registry, -Bypass User Account Control, -Abuse Elevation Control Mechanism -| -Defense Evasion, -Privilege Escalation, Defense Evasion, -Privilege Escalation, Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Hiding_files_and_directories_with_attrib_exe|Hiding Files And Directories With Attrib exe]] - -| -[https://attack.mitre.org/techniques/T1222/ T1222], -[https://attack.mitre.org/techniques/T1222.001/ T1222.001] -| -File and Directory Permissions Modification, -Windows File and Directory Permissions Modification -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Net_profiler_uac_bypass|NET Profiler UAC bypass]] - -| -[https://attack.mitre.org/techniques/T1548.002/ T1548.002], -[https://attack.mitre.org/techniques/T1548/ T1548] -| -Bypass User Account Control, -Abuse Elevation Control Mechanism -| -Privilege Escalation, Defense Evasion, -Privilege Escalation, Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Slui_runas_elevated|SLUI RunAs Elevated]] - -| -[https://attack.mitre.org/techniques/T1548.002/ T1548.002], -[https://attack.mitre.org/techniques/T1548/ T1548] -| -Bypass User Account Control, -Abuse Elevation Control Mechanism -| -Privilege Escalation, Defense Evasion, -Privilege Escalation, Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Slui_spawning_a_process|SLUI Spawning a Process]] - -| -[https://attack.mitre.org/techniques/T1548.002/ T1548.002], -[https://attack.mitre.org/techniques/T1548/ T1548] -| -Bypass User Account Control, -Abuse Elevation Control Mechanism -| -Privilege Escalation, Defense Evasion, -Privilege Escalation, Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Sdclt_uac_bypass|Sdclt UAC Bypass]] - -| -[https://attack.mitre.org/techniques/T1548.002/ T1548.002], -[https://attack.mitre.org/techniques/T1548/ T1548] -| -Bypass User Account Control, -Abuse Elevation Control Mechanism -| -Privilege Escalation, Defense Evasion, -Privilege Escalation, Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Silentcleanup_uac_bypass|SilentCleanup UAC Bypass]] - -| -[https://attack.mitre.org/techniques/T1548.002/ T1548.002], -[https://attack.mitre.org/techniques/T1548/ T1548] -| -Bypass User Account Control, -Abuse Elevation Control Mechanism -| -Privilege Escalation, Defense Evasion, -Privilege Escalation, Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Suspicious_reg_exe_process|Suspicious Reg exe Process]] - -| -[https://attack.mitre.org/techniques/T1112/ T1112] -| -Modify Registry -| -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#System_process_running_from_unexpected_location|System Process Running from Unexpected Location]] - -| -[https://attack.mitre.org/techniques/T1036/ T1036] -| -Masquerading -| -Defense Evasion - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Uac_bypass_mmc_load_unsigned_dll|UAC Bypass MMC Load Unsigned Dll]] - -| -[https://attack.mitre.org/techniques/T1548.002/ T1548.002], -[https://attack.mitre.org/techniques/T1548/ T1548] -| -Bypass User Account Control, -Abuse Elevation Control Mechanism -| -Privilege Escalation, Defense Evasion, -Privilege Escalation, Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Wsreset_uac_bypass|WSReset UAC Bypass]] - -| -[https://attack.mitre.org/techniques/T1548.002/ T1548.002], -[https://attack.mitre.org/techniques/T1548/ T1548] -| -Bypass User Account Control, -Abuse Elevation Control Mechanism -| -Privilege Escalation, Defense Evasion, -Privilege Escalation, Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Windows_disableantispyware_registry|Windows DisableAntiSpyware Registry]] - -| -[https://attack.mitre.org/techniques/T1562.001/ T1562.001], -[https://attack.mitre.org/techniques/T1562/ T1562] -| -Disable or Modify Tools, -Impair Defenses -| -Defense Evasion, -Defense Evasion - -| TTP -|} - -====Kill Chain Phase==== - -* Actions on Objectives - -* Delivery - -* Exploitation - -* Privilege Escalation - - -====Reference==== - -* https://attack.mitre.org/wiki/Defense_Evasion - - -''version'': 1 -
-
- ----- - -===Windows discovery techniques=== -Monitors for behaviors associated with adversaries discovering objects in the environment that can be leveraged in the progression of the attack. - -* '''Product''': Splunk Behavioral Analytics, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''Last Updated''': 2021-03-04 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Reconnaissance_and_access_to_accounts_groups_and_policies_via_powersploit_modules|Reconnaissance and Access to Accounts Groups and Policies via PowerSploit modules]] - -| -[https://attack.mitre.org/techniques/T1078/ T1078], -[https://attack.mitre.org/techniques/T1087/ T1087], -[https://attack.mitre.org/techniques/T1484/ T1484] -| -Valid Accounts, -Account Discovery, -Domain Policy Modification -| -Defense Evasion, Persistence, Privilege Escalation, Initial Access, -Discovery, -Defense Evasion, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Reconnaissance_and_access_to_accounts_and_groups_via_mimikatz_modules|Reconnaissance and Access to Accounts and Groups via Mimikatz modules]] - -| -[https://attack.mitre.org/techniques/T1078/ T1078], -[https://attack.mitre.org/techniques/T1087/ T1087], -[https://attack.mitre.org/techniques/T1484/ T1484] -| -Valid Accounts, -Account Discovery, -Domain Policy Modification -| -Defense Evasion, Persistence, Privilege Escalation, Initial Access, -Discovery, -Defense Evasion, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Reconnaissance_and_access_to_active_directoty_infrastructure_via_powersploit_modules|Reconnaissance and Access to Active Directoty Infrastructure via PowerSploit modules]] - -| -[https://attack.mitre.org/techniques/T1199/ T1199], -[https://attack.mitre.org/techniques/T1482/ T1482], -[https://attack.mitre.org/techniques/T1590/ T1590], -[https://attack.mitre.org/techniques/T1591/ T1591], -[https://attack.mitre.org/techniques/T1595/ T1595] -| -Trusted Relationship, -Domain Trust Discovery, -Gather Victim Network Information, -Gather Victim Org Information, -Active Scanning -| -Initial Access, -Discovery, -Reconnaissance, -Reconnaissance, -Reconnaissance - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Reconnaissance_and_access_to_computers_and_domains_via_powersploit_modules|Reconnaissance and Access to Computers and Domains via PowerSploit modules]] - -| -[https://attack.mitre.org/techniques/T1592/ T1592], -[https://attack.mitre.org/techniques/T1590/ T1590], -[https://attack.mitre.org/techniques/T1087/ T1087] -| -Gather Victim Host Information, -Gather Victim Network Information, -Account Discovery -| -Reconnaissance, -Reconnaissance, -Discovery - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Reconnaissance_and_access_to_computers_via_mimikatz_modules|Reconnaissance and Access to Computers via Mimikatz modules]] - -| -[https://attack.mitre.org/techniques/T1592/ T1592] -| -Gather Victim Host Information -| -Reconnaissance - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Reconnaissance_and_access_to_operating_system_elements_via_powersploit_modules|Reconnaissance and Access to Operating System Elements via PowerSploit modules]] - -| -[https://attack.mitre.org/techniques/T1057/ T1057], -[https://attack.mitre.org/techniques/T1083/ T1083], -[https://attack.mitre.org/techniques/T1592.002/ T1592.002], -[https://attack.mitre.org/techniques/T1046/ T1046], -[https://attack.mitre.org/techniques/T1012/ T1012], -[https://attack.mitre.org/techniques/T1007/ T1007], -[https://attack.mitre.org/techniques/T1047/ T1047], -[https://attack.mitre.org/techniques/T1592/ T1592], -[https://attack.mitre.org/techniques/T1518/ T1518] -| -Process Discovery, -File and Directory Discovery, -Software, -Network Service Scanning, -Query Registry, -System Service Discovery, -Windows Management Instrumentation, -Gather Victim Host Information, -Software Discovery -| -Discovery, -Discovery, -Reconnaissance, -Discovery, -Discovery, -Discovery, -Execution, -Reconnaissance, -Discovery - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Reconnaissance_and_access_to_processes_and_services_via_mimikatz_modules|Reconnaissance and Access to Processes and Services via Mimikatz modules]] - -| -[https://attack.mitre.org/techniques/T1007/ T1007], -[https://attack.mitre.org/techniques/T1046/ T1046], -[https://attack.mitre.org/techniques/T1057/ T1057] -| -System Service Discovery, -Network Service Scanning, -Process Discovery -| -Discovery, -Discovery, -Discovery - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Reconnaissance_and_access_to_shared_resources_via_mimikatz_modules|Reconnaissance and Access to Shared Resources via Mimikatz modules]] - -| -[https://attack.mitre.org/techniques/T1021/ T1021], -[https://attack.mitre.org/techniques/T1039/ T1039], -[https://attack.mitre.org/techniques/T1135/ T1135], -[https://attack.mitre.org/techniques/T1021.002/ T1021.002] -| -Remote Services, -Data from Network Shared Drive, -Network Share Discovery, -SMB/Windows Admin Shares -| -Lateral Movement, -Collection, -Discovery, -Lateral Movement - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Reconnaissance_and_access_to_shared_resources_via_powersploit_modules|Reconnaissance and Access to Shared Resources via PowerSploit modules]] - -| -[https://attack.mitre.org/techniques/T1021/ T1021], -[https://attack.mitre.org/techniques/T1039/ T1039], -[https://attack.mitre.org/techniques/T1135/ T1135], -[https://attack.mitre.org/techniques/T1021.002/ T1021.002] -| -Remote Services, -Data from Network Shared Drive, -Network Share Discovery, -SMB/Windows Admin Shares -| -Lateral Movement, -Collection, -Discovery, -Lateral Movement - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Reconnaissance_of_access_and_persistence_opportunities_via_powersploit_modules|Reconnaissance of Access and Persistence Opportunities via PowerSploit modules]] - -| -[https://attack.mitre.org/techniques/T1053/ T1053], -[https://attack.mitre.org/techniques/T1068/ T1068], -[https://attack.mitre.org/techniques/T1078/ T1078], -[https://attack.mitre.org/techniques/T1543/ T1543], -[https://attack.mitre.org/techniques/T1547/ T1547], -[https://attack.mitre.org/techniques/T1574/ T1574] -| -Scheduled Task/Job, -Exploitation for Privilege Escalation, -Valid Accounts, -Create or Modify System Process, -Boot or Logon Autostart Execution, -Hijack Execution Flow -| -Execution, Persistence, Privilege Escalation, -Privilege Escalation, -Defense Evasion, Persistence, Privilege Escalation, Initial Access, -Persistence, Privilege Escalation, -Persistence, Privilege Escalation, -Persistence, Privilege Escalation, Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Reconnaissance_of_connectivity_via_powersploit_modules|Reconnaissance of Connectivity via PowerSploit modules]] - -| -[https://attack.mitre.org/techniques/T1021/ T1021], -[https://attack.mitre.org/techniques/T1039/ T1039], -[https://attack.mitre.org/techniques/T1135/ T1135], -[https://attack.mitre.org/techniques/T1021.002/ T1021.002] -| -Remote Services, -Data from Network Shared Drive, -Network Share Discovery, -SMB/Windows Admin Shares -| -Lateral Movement, -Collection, -Discovery, -Lateral Movement - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Reconnaissance_of_credential_stores_and_services_via_mimikatz_modules|Reconnaissance of Credential Stores and Services via Mimikatz modules]] - -| -[https://attack.mitre.org/techniques/T1098/ T1098], -[https://attack.mitre.org/techniques/T1590.001/ T1590.001], -[https://attack.mitre.org/techniques/T1078/ T1078], -[https://attack.mitre.org/techniques/T1589.001/ T1589.001], -[https://attack.mitre.org/techniques/T1590/ T1590], -[https://attack.mitre.org/techniques/T1068/ T1068], -[https://attack.mitre.org/techniques/T1589/ T1589], -[https://attack.mitre.org/techniques/T1590.003/ T1590.003] -| -Account Manipulation, -Domain Properties, -Valid Accounts, -Credentials, -Gather Victim Network Information, -Exploitation for Privilege Escalation, -Gather Victim Identity Information, -Network Trust Dependencies -| -Persistence, -Reconnaissance, -Defense Evasion, Persistence, Privilege Escalation, Initial Access, -Reconnaissance, -Reconnaissance, -Privilege Escalation, -Reconnaissance, -Reconnaissance - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Reconnaissance_of_defensive_tools_via_powersploit_modules|Reconnaissance of Defensive Tools via PowerSploit modules]] - -| -[https://attack.mitre.org/techniques/T1592.002/ T1592.002], -[https://attack.mitre.org/techniques/T1595.002/ T1595.002], -[https://attack.mitre.org/techniques/T1592/ T1592], -[https://attack.mitre.org/techniques/T1595/ T1595] -| -Software, -Vulnerability Scanning, -Gather Victim Host Information, -Active Scanning -| -Reconnaissance, -Reconnaissance, -Reconnaissance, -Reconnaissance - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Reconnaissance_of_privilege_escalation_opportunities_via_powersploit_modules|Reconnaissance of Privilege Escalation Opportunities via PowerSploit modules]] - -| -[https://attack.mitre.org/techniques/T1068/ T1068], -[https://attack.mitre.org/techniques/T1078/ T1078], -[https://attack.mitre.org/techniques/T1098/ T1098] -| -Exploitation for Privilege Escalation, -Valid Accounts, -Account Manipulation -| -Privilege Escalation, -Defense Evasion, Persistence, Privilege Escalation, Initial Access, -Persistence - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Reconnaissance_of_process_or_service_hijacking_opportunities_via_mimikatz_modules|Reconnaissance of Process or Service Hijacking Opportunities via Mimikatz modules]] - -| -[https://attack.mitre.org/techniques/T1543/ T1543], -[https://attack.mitre.org/techniques/T1055/ T1055], -[https://attack.mitre.org/techniques/T1574/ T1574] -| -Create or Modify System Process, -Process Injection, -Hijack Execution Flow -| -Persistence, Privilege Escalation, -Defense Evasion, Privilege Escalation, -Persistence, Privilege Escalation, Defense Evasion - -| TTP -|} - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Reference==== - -* https://attack.mitre.org/tactics/TA0007/ - -* https://cyberd.us/penetration-testing - -* https://attack.mitre.org/software/S0521/ - - -''version'': 1 -
-
- ----- - -===Windows log manipulation=== -Adversaries often try to cover their tracks by manipulating Windows logs. Use these searches to help you monitor for suspicious activity surrounding log files--an essential component of an effective defense. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint] -* '''Last Updated''': 2017-09-12 -* '''Use Case''': Security Monitoring - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Deleting_shadow_copies|Deleting Shadow Copies]] - -| -[https://attack.mitre.org/techniques/T1490/ T1490] -| -Inhibit System Recovery -| -Impact - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Illegal_deletion_of_logs_via_mimikatz_modules|Illegal Deletion of Logs via Mimikatz modules]] - -| -[https://attack.mitre.org/techniques/T1070/ T1070] -| -Indicator Removal on Host -| -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Suspicious_event_log_service_behavior|Suspicious Event Log Service Behavior]] - -| -[https://attack.mitre.org/techniques/T1070/ T1070], -[https://attack.mitre.org/techniques/T1070.001/ T1070.001] -| -Indicator Removal on Host, -Clear Windows Event Logs -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Suspicious_wevtutil_usage|Suspicious wevtutil Usage]] - -| -[https://attack.mitre.org/techniques/T1070.001/ T1070.001], -[https://attack.mitre.org/techniques/T1070/ T1070] -| -Clear Windows Event Logs, -Indicator Removal on Host -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Usn_journal_deletion|USN Journal Deletion]] - -| -[https://attack.mitre.org/techniques/T1070/ T1070] -| -Indicator Removal on Host -| -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Wevtutil_usage_to_clear_logs|WevtUtil Usage To Clear Logs]] - -| -[https://attack.mitre.org/techniques/T1070/ T1070], -[https://attack.mitre.org/techniques/T1070.001/ T1070.001] -| -Indicator Removal on Host, -Clear Windows Event Logs -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Wevtutil_usage_to_disable_logs|Wevtutil Usage To Disable Logs]] - -| -[https://attack.mitre.org/techniques/T1070/ T1070], -[https://attack.mitre.org/techniques/T1070.001/ T1070.001] -| -Indicator Removal on Host, -Clear Windows Event Logs -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Windows_event_log_cleared|Windows Event Log Cleared]] - -| -[https://attack.mitre.org/techniques/T1070/ T1070], -[https://attack.mitre.org/techniques/T1070.001/ T1070.001] -| -Indicator Removal on Host, -Clear Windows Event Logs -| -Defense Evasion, -Defense Evasion - -| TTP -|} - -====Kill Chain Phase==== - -* Actions on Objectives - -* Exploitation - - -====Reference==== - -* https://www.crowdstrike.com/blog/bears-midst-intrusion-democratic-national-committee/ - -* https://zeltser.com/security-incident-log-review-checklist/ - -* http://journeyintoir.blogspot.com/2013/01/re-introducing-usnjrnl.html - - -''version'': 2 -
-
- ----- - -===Windows persistence techniques=== -Monitor for activities and techniques associated with maintaining persistence on a Windows system--a sign that an adversary may have compromised your environment. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint] -* '''Last Updated''': 2018-05-31 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Active_setup_registry_autostart|Active Setup Registry Autostart]] - -| -[https://attack.mitre.org/techniques/T1547.014/ T1547.014], -[https://attack.mitre.org/techniques/T1547/ T1547] -| -Active Setup, -Boot or Logon Autostart Execution -| -Persistence, Privilege Escalation, -Persistence, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Certutil_exe_certificate_extraction|Certutil exe certificate extraction]] - -| -| -| - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Change_default_file_association|Change Default File Association]] - -| -[https://attack.mitre.org/techniques/T1546.001/ T1546.001], -[https://attack.mitre.org/techniques/T1546/ T1546] -| -Change Default File Association, -Event Triggered Execution -| -Privilege Escalation, Persistence, -Privilege Escalation, Persistence - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_path_interception_by_creation_of_program_exe|Detect Path Interception By Creation Of program exe]] - -| -[https://attack.mitre.org/techniques/T1574.009/ T1574.009], -[https://attack.mitre.org/techniques/T1574/ T1574] -| -Path Interception by Unquoted Path, -Hijack Execution Flow -| -Persistence, Privilege Escalation, Defense Evasion, -Persistence, Privilege Escalation, Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Etw_registry_disabled|ETW Registry Disabled]] - -| -[https://attack.mitre.org/techniques/T1562.006/ T1562.006], -[https://attack.mitre.org/techniques/T1127/ T1127], -[https://attack.mitre.org/techniques/T1562/ T1562] -| -Indicator Blocking, -Trusted Developer Utilities Proxy Execution, -Impair Defenses -| -Defense Evasion, -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Hiding_files_and_directories_with_attrib_exe|Hiding Files And Directories With Attrib exe]] - -| -[https://attack.mitre.org/techniques/T1222/ T1222], -[https://attack.mitre.org/techniques/T1222.001/ T1222.001] -| -File and Directory Permissions Modification, -Windows File and Directory Permissions Modification -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Illegal_account_creation_via_powersploit_modules|Illegal Account Creation via PowerSploit modules]] - -| -[https://attack.mitre.org/techniques/T1585/ T1585] -| -Establish Accounts -| -Resource Development - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Illegal_enabling_or_disabling_of_accounts_via_dsinternals_modules|Illegal Enabling or Disabling of Accounts via DSInternals modules]] - -| -[https://attack.mitre.org/techniques/T1078/ T1078], -[https://attack.mitre.org/techniques/T1098/ T1098] -| -Valid Accounts, -Account Manipulation -| -Defense Evasion, Persistence, Privilege Escalation, Initial Access, -Persistence - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Illegal_management_of_active_directory_elements_and_policies_via_dsinternals_modules|Illegal Management of Active Directory Elements and Policies via DSInternals modules]] - -| -[https://attack.mitre.org/techniques/T1098/ T1098], -[https://attack.mitre.org/techniques/T1207/ T1207], -[https://attack.mitre.org/techniques/T1484/ T1484] -| -Account Manipulation, -Rogue Domain Controller, -Domain Policy Modification -| -Persistence, -Defense Evasion, -Defense Evasion, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Illegal_management_of_computers_and_active_directory_elements_via_powersploit_modules|Illegal Management of Computers and Active Directory Elements via PowerSploit modules]] - -| -[https://attack.mitre.org/techniques/T1098/ T1098], -[https://attack.mitre.org/techniques/T1207/ T1207], -[https://attack.mitre.org/techniques/T1484/ T1484] -| -Account Manipulation, -Rogue Domain Controller, -Domain Policy Modification -| -Persistence, -Defense Evasion, -Defense Evasion, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Illegal_privilege_elevation_and_persistence_via_powersploit_modules|Illegal Privilege Elevation and Persistence via PowerSploit modules]] - -| -[https://attack.mitre.org/techniques/T1053/ T1053], -[https://attack.mitre.org/techniques/T1134/ T1134], -[https://attack.mitre.org/techniques/T1548/ T1548] -| -Scheduled Task/Job, -Access Token Manipulation, -Abuse Elevation Control Mechanism -| -Execution, Persistence, Privilege Escalation, -Defense Evasion, Privilege Escalation, -Privilege Escalation, Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Logon_script_event_trigger_execution|Logon Script Event Trigger Execution]] - -| -[https://attack.mitre.org/techniques/T1037/ T1037], -[https://attack.mitre.org/techniques/T1037.001/ T1037.001] -| -Boot or Logon Initialization Scripts, -Logon Script (Windows) -| -Persistence, Privilege Escalation, -Persistence, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Monitor_registry_keys_for_print_monitors|Monitor Registry Keys for Print Monitors]] - -| -[https://attack.mitre.org/techniques/T1547.010/ T1547.010], -[https://attack.mitre.org/techniques/T1547/ T1547] -| -Port Monitors, -Boot or Logon Autostart Execution -| -Persistence, Privilege Escalation, -Persistence, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Print_processor_registry_autostart|Print Processor Registry Autostart]] - -| -[https://attack.mitre.org/techniques/T1547.012/ T1547.012], -[https://attack.mitre.org/techniques/T1547/ T1547] -| -Print Processors, -Boot or Logon Autostart Execution -| -Persistence, Privilege Escalation, -Persistence, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Reg_exe_manipulating_windows_services_registry_keys|Reg exe Manipulating Windows Services Registry Keys]] - -| -[https://attack.mitre.org/techniques/T1574.011/ T1574.011], -[https://attack.mitre.org/techniques/T1574/ T1574] -| -Services Registry Permissions Weakness, -Hijack Execution Flow -| -Persistence, Privilege Escalation, Defense Evasion, -Persistence, Privilege Escalation, Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Registry_keys_used_for_persistence|Registry Keys Used For Persistence]] - -| -[https://attack.mitre.org/techniques/T1547.001/ T1547.001], -[https://attack.mitre.org/techniques/T1547/ T1547] -| -Registry Run Keys / Startup Folder, -Boot or Logon Autostart Execution -| -Persistence, Privilege Escalation, -Persistence, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Registry_keys_for_creating_shim_databases|Registry Keys for Creating SHIM Databases]] - -| -[https://attack.mitre.org/techniques/T1546.011/ T1546.011], -[https://attack.mitre.org/techniques/T1546/ T1546] -| -Application Shimming, -Event Triggered Execution -| -Privilege Escalation, Persistence, -Privilege Escalation, Persistence - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Sc_exe_manipulating_windows_services|Sc exe Manipulating Windows Services]] - -| -[https://attack.mitre.org/techniques/T1543.003/ T1543.003], -[https://attack.mitre.org/techniques/T1543/ T1543] -| -Windows Service, -Create or Modify System Process -| -Persistence, Privilege Escalation, -Persistence, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Schedule_task_with_http_command_arguments|Schedule Task with HTTP Command Arguments]] - -| -[https://attack.mitre.org/techniques/T1053/ T1053] -| -Scheduled Task/Job -| -Execution, Persistence, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Schedule_task_with_rundll32_command_trigger|Schedule Task with Rundll32 Command Trigger]] - -| -[https://attack.mitre.org/techniques/T1053/ T1053] -| -Scheduled Task/Job -| -Execution, Persistence, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Schtasks_used_for_forcing_a_reboot|Schtasks used for forcing a reboot]] - -| -[https://attack.mitre.org/techniques/T1053.005/ T1053.005], -[https://attack.mitre.org/techniques/T1053/ T1053] -| -Scheduled Task, -Scheduled Task/Job -| -Execution, Persistence, Privilege Escalation, -Execution, Persistence, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Screensaver_event_trigger_execution|Screensaver Event Trigger Execution]] - -| -[https://attack.mitre.org/techniques/T1546/ T1546], -[https://attack.mitre.org/techniques/T1546.002/ T1546.002] -| -Event Triggered Execution, -Screensaver -| -Privilege Escalation, Persistence, -Privilege Escalation, Persistence - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Setting_credentials_via_dsinternals_modules|Setting Credentials via DSInternals modules]] - -| -[https://attack.mitre.org/techniques/T1068/ T1068], -[https://attack.mitre.org/techniques/T1078/ T1078], -[https://attack.mitre.org/techniques/T1098/ T1098] -| -Exploitation for Privilege Escalation, -Valid Accounts, -Account Manipulation -| -Privilege Escalation, -Defense Evasion, Persistence, Privilege Escalation, Initial Access, -Persistence - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Setting_credentials_via_mimikatz_modules|Setting Credentials via Mimikatz modules]] - -| -[https://attack.mitre.org/techniques/T1068/ T1068], -[https://attack.mitre.org/techniques/T1078/ T1078], -[https://attack.mitre.org/techniques/T1098/ T1098] -| -Exploitation for Privilege Escalation, -Valid Accounts, -Account Manipulation -| -Privilege Escalation, -Defense Evasion, Persistence, Privilege Escalation, Initial Access, -Persistence - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Setting_credentials_via_powersploit_modules|Setting Credentials via PowerSploit modules]] - -| -[https://attack.mitre.org/techniques/T1068/ T1068], -[https://attack.mitre.org/techniques/T1078/ T1078], -[https://attack.mitre.org/techniques/T1098/ T1098] -| -Exploitation for Privilege Escalation, -Valid Accounts, -Account Manipulation -| -Privilege Escalation, -Defense Evasion, Persistence, Privilege Escalation, Initial Access, -Persistence - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Shim_database_file_creation|Shim Database File Creation]] - -| -[https://attack.mitre.org/techniques/T1546.011/ T1546.011], -[https://attack.mitre.org/techniques/T1546/ T1546] -| -Application Shimming, -Event Triggered Execution -| -Privilege Escalation, Persistence, -Privilege Escalation, Persistence - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Shim_database_installation_with_suspicious_parameters|Shim Database Installation With Suspicious Parameters]] - -| -[https://attack.mitre.org/techniques/T1546.011/ T1546.011], -[https://attack.mitre.org/techniques/T1546/ T1546] -| -Application Shimming, -Event Triggered Execution -| -Privilege Escalation, Persistence, -Privilege Escalation, Persistence - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Suspicious_scheduled_task_from_public_directory|Suspicious Scheduled Task from Public Directory]] - -| -[https://attack.mitre.org/techniques/T1053.005/ T1053.005], -[https://attack.mitre.org/techniques/T1053/ T1053] -| -Scheduled Task, -Scheduled Task/Job -| -Execution, Persistence, Privilege Escalation, -Execution, Persistence, Privilege Escalation - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Time_provider_persistence_registry|Time Provider Persistence Registry]] - -| -[https://attack.mitre.org/techniques/T1547.003/ T1547.003], -[https://attack.mitre.org/techniques/T1547/ T1547] -| -Time Providers, -Boot or Logon Autostart Execution -| -Persistence, Privilege Escalation, -Persistence, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Winevent_scheduled_task_created_within_public_path|WinEvent Scheduled Task Created Within Public Path]] - -| -[https://attack.mitre.org/techniques/T1053.005/ T1053.005], -[https://attack.mitre.org/techniques/T1053/ T1053] -| -Scheduled Task, -Scheduled Task/Job -| -Execution, Persistence, Privilege Escalation, -Execution, Persistence, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Winevent_scheduled_task_created_to_spawn_shell|WinEvent Scheduled Task Created to Spawn Shell]] - -| -[https://attack.mitre.org/techniques/T1053.005/ T1053.005], -[https://attack.mitre.org/techniques/T1053/ T1053] -| -Scheduled Task, -Scheduled Task/Job -| -Execution, Persistence, Privilege Escalation, -Execution, Persistence, Privilege Escalation - -| TTP -|} - -====Kill Chain Phase==== - -* Actions on Objectives - -* Exploitation - -* Installation - -* Privilege Escalation - - -====Reference==== - -* http://www.fuzzysecurity.com/tutorials/19.html - -* https://www.fireeye.com/blog/threat-research/2010/07/malware-persistence-windows-registry.html - -* http://resources.infosecinstitute.com/common-malware-persistence-mechanisms/ - -* https://www.fireeye.com/blog/threat-research/2017/05/fin7-shim-databases-persistence.html - -* https://www.youtube.com/watch?v=dq2Hv7J9fvk - - -''version'': 2 -
-
- ----- - -===Windows privilege escalation=== -Monitor for and investigate activities that may be associated with a Windows privilege-escalation attack, including unusual processes running on endpoints, modified registry keys, and more. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint] -* '''Last Updated''': 2020-02-04 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Active_setup_registry_autostart|Active Setup Registry Autostart]] - -| -[https://attack.mitre.org/techniques/T1547.014/ T1547.014], -[https://attack.mitre.org/techniques/T1547/ T1547] -| -Active Setup, -Boot or Logon Autostart Execution -| -Persistence, Privilege Escalation, -Persistence, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Change_default_file_association|Change Default File Association]] - -| -[https://attack.mitre.org/techniques/T1546.001/ T1546.001], -[https://attack.mitre.org/techniques/T1546/ T1546] -| -Change Default File Association, -Event Triggered Execution -| -Privilege Escalation, Persistence, -Privilege Escalation, Persistence - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Child_processes_of_spoolsv_exe|Child Processes of Spoolsv exe]] - -| -[https://attack.mitre.org/techniques/T1068/ T1068] -| -Exploitation for Privilege Escalation -| -Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Etw_registry_disabled|ETW Registry Disabled]] - -| -[https://attack.mitre.org/techniques/T1562.006/ T1562.006], -[https://attack.mitre.org/techniques/T1127/ T1127], -[https://attack.mitre.org/techniques/T1562/ T1562] -| -Indicator Blocking, -Trusted Developer Utilities Proxy Execution, -Impair Defenses -| -Defense Evasion, -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Illegal_privilege_elevation_via_mimikatz_modules|Illegal Privilege Elevation via Mimikatz modules]] - -| -[https://attack.mitre.org/techniques/T1134/ T1134], -[https://attack.mitre.org/techniques/T1548/ T1548] -| -Access Token Manipulation, -Abuse Elevation Control Mechanism -| -Defense Evasion, Privilege Escalation, -Privilege Escalation, Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Logon_script_event_trigger_execution|Logon Script Event Trigger Execution]] - -| -[https://attack.mitre.org/techniques/T1037/ T1037], -[https://attack.mitre.org/techniques/T1037.001/ T1037.001] -| -Boot or Logon Initialization Scripts, -Logon Script (Windows) -| -Persistence, Privilege Escalation, -Persistence, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Overwriting_accessibility_binaries|Overwriting Accessibility Binaries]] - -| -[https://attack.mitre.org/techniques/T1546/ T1546], -[https://attack.mitre.org/techniques/T1546.008/ T1546.008] -| -Event Triggered Execution, -Accessibility Features -| -Privilege Escalation, Persistence, -Privilege Escalation, Persistence - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Print_processor_registry_autostart|Print Processor Registry Autostart]] - -| -[https://attack.mitre.org/techniques/T1547.012/ T1547.012], -[https://attack.mitre.org/techniques/T1547/ T1547] -| -Print Processors, -Boot or Logon Autostart Execution -| -Persistence, Privilege Escalation, -Persistence, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Probing_access_with_stolen_credentials_via_powersploit_modules|Probing Access with Stolen Credentials via PowerSploit modules]] - -| -[https://attack.mitre.org/techniques/T1078/ T1078], -[https://attack.mitre.org/techniques/T1098/ T1098] -| -Valid Accounts, -Account Manipulation -| -Defense Evasion, Persistence, Privilege Escalation, Initial Access, -Persistence - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Registry_keys_used_for_privilege_escalation|Registry Keys Used For Privilege Escalation]] - -| -[https://attack.mitre.org/techniques/T1546.012/ T1546.012], -[https://attack.mitre.org/techniques/T1546/ T1546] -| -Image File Execution Options Injection, -Event Triggered Execution -| -Privilege Escalation, Persistence, -Privilege Escalation, Persistence - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Screensaver_event_trigger_execution|Screensaver Event Trigger Execution]] - -| -[https://attack.mitre.org/techniques/T1546/ T1546], -[https://attack.mitre.org/techniques/T1546.002/ T1546.002] -| -Event Triggered Execution, -Screensaver -| -Privilege Escalation, Persistence, -Privilege Escalation, Persistence - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Time_provider_persistence_registry|Time Provider Persistence Registry]] - -| -[https://attack.mitre.org/techniques/T1547.003/ T1547.003], -[https://attack.mitre.org/techniques/T1547/ T1547] -| -Time Providers, -Boot or Logon Autostart Execution -| -Persistence, Privilege Escalation, -Persistence, Privilege Escalation - -| TTP -|} - -====Kill Chain Phase==== - -* Actions on Objectives - -* Exploitation - - -====Reference==== - -* https://attack.mitre.org/tactics/TA0004/ - - -''version'': 2 -
-
- ----- - - - -==Best Practices== - - -===Asset tracking=== -Keep a careful inventory of every asset on your network to make it easier to detect rogue devices. Unauthorized/unmanaged devices could be an indication of malicious behavior that should be investigated further. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/NetworkSessions Network_Sessions] -* '''Last Updated''': 2017-09-13 -* '''Use Case''': Security Monitoring - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Detect_unauthorized_assets_by_mac_address|Detect Unauthorized Assets by MAC address]] - -| -| -| - -| TTP -|} - -====Kill Chain Phase==== - -* Actions on Objectives - -* Delivery - -* Reconnaissance - - -====Reference==== - -* https://www.cisecurity.org/controls/inventory-of-authorized-and-unauthorized-devices/ - - -''version'': 1 -
-
- ----- - -===Monitor for updates=== -Monitor your enterprise to ensure that your endpoints are being patched and updated. Adversaries notoriously exploit known vulnerabilities that could be mitigated by applying routine security patches. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Updates Updates] -* '''Last Updated''': 2017-09-15 -* '''Use Case''': Compliance - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#No_windows_updates_in_a_time_frame|No Windows Updates in a time frame]] - -| -| -| - -| Hunting -|} - -====Kill Chain Phase==== - - -====Reference==== - -* https://learn.cisecurity.org/20-controls-download - - -''version'': 1 -
-
- ----- - -===Prohibited traffic allowed or protocol mismatch=== -Detect instances of prohibited network traffic allowed in the environment, as well as protocols running on non-standard ports. Both of these types of behaviors typically violate policy and can be leveraged by attackers. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint], [https://docs.splunk.com/Documentation/CIM/latest/User/NetworkResolution Network_Resolution], [https://docs.splunk.com/Documentation/CIM/latest/User/NetworkTraffic Network_Traffic] -* '''Last Updated''': 2017-09-11 -* '''Use Case''': Security Monitoring - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Allow_inbound_traffic_by_firewall_rule_registry|Allow Inbound Traffic By Firewall Rule Registry]] - -| -[https://attack.mitre.org/techniques/T1021.001/ T1021.001], -[https://attack.mitre.org/techniques/T1021/ T1021] -| -Remote Desktop Protocol, -Remote Services -| -Lateral Movement, -Lateral Movement - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Allow_inbound_traffic_in_firewall_rule|Allow Inbound Traffic In Firewall Rule]] - -| -[https://attack.mitre.org/techniques/T1021.001/ T1021.001], -[https://attack.mitre.org/techniques/T1021/ T1021] -| -Remote Desktop Protocol, -Remote Services -| -Lateral Movement, -Lateral Movement - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_hosts_connecting_to_dynamic_domain_providers|Detect hosts connecting to dynamic domain providers]] - -| -[https://attack.mitre.org/techniques/T1189/ T1189] -| -Drive-by Compromise -| -Initial Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Enable_rdp_in_other_port_number|Enable RDP In Other Port Number]] - -| -[https://attack.mitre.org/techniques/T1021/ T1021] -| -Remote Services -| -Lateral Movement - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Prohibited_network_traffic_allowed|Prohibited Network Traffic Allowed]] - -| -[https://attack.mitre.org/techniques/T1048/ T1048] -| -Exfiltration Over Alternative Protocol -| -Exfiltration - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Protocol_or_port_mismatch|Protocol or Port Mismatch]] - -| -[https://attack.mitre.org/techniques/T1048.003/ T1048.003], -[https://attack.mitre.org/techniques/T1048/ T1048] -| -Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol, -Exfiltration Over Alternative Protocol -| -Exfiltration, -Exfiltration - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Tor_traffic|TOR Traffic]] - -| -[https://attack.mitre.org/techniques/T1071/ T1071], -[https://attack.mitre.org/techniques/T1071.001/ T1071.001] -| -Application Layer Protocol, -Web Protocols -| -Command And Control, -Command And Control - -| TTP -|} - -====Kill Chain Phase==== - -* Actions on Objectives - -* Command and Control - -* Delivery - -* Exploitation - - -====Reference==== - -* http://www.novetta.com/2015/02/advanced-methods-to-detect-advanced-cyber-attacks-protocol-abuse/ - - -''version'': 1 -
-
- ----- - -===Router and infrastructure security=== -Validate the security configuration of network infrastructure and verify that only authorized users and systems are accessing critical assets. Core routing and switching infrastructure are common strategic targets for attackers. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Authentication Authentication], [https://docs.splunk.com/Documentation/CIM/latest/User/NetworkTraffic Network_Traffic] -* '''Last Updated''': 2017-09-12 -* '''Use Case''': Security Monitoring - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Detect_arp_poisoning|Detect ARP Poisoning]] - -| -[https://attack.mitre.org/techniques/T1200/ T1200], -[https://attack.mitre.org/techniques/T1498/ T1498], -[https://attack.mitre.org/techniques/T1557/ T1557], -[https://attack.mitre.org/techniques/T1557.002/ T1557.002] -| -Hardware Additions, -Network Denial of Service, -Adversary-in-the-Middle, -ARP Cache Poisoning -| -Initial Access, -Impact, -Credential Access, Collection, -Credential Access, Collection - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_ipv6_network_infrastructure_threats|Detect IPv6 Network Infrastructure Threats]] - -| -[https://attack.mitre.org/techniques/T1200/ T1200], -[https://attack.mitre.org/techniques/T1498/ T1498], -[https://attack.mitre.org/techniques/T1557/ T1557], -[https://attack.mitre.org/techniques/T1557.002/ T1557.002] -| -Hardware Additions, -Network Denial of Service, -Adversary-in-the-Middle, -ARP Cache Poisoning -| -Initial Access, -Impact, -Credential Access, Collection, -Credential Access, Collection - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_new_login_attempts_to_routers|Detect New Login Attempts to Routers]] - -| -| -| - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_port_security_violation|Detect Port Security Violation]] - -| -[https://attack.mitre.org/techniques/T1200/ T1200], -[https://attack.mitre.org/techniques/T1498/ T1498], -[https://attack.mitre.org/techniques/T1557/ T1557], -[https://attack.mitre.org/techniques/T1557.002/ T1557.002] -| -Hardware Additions, -Network Denial of Service, -Adversary-in-the-Middle, -ARP Cache Poisoning -| -Initial Access, -Impact, -Credential Access, Collection, -Credential Access, Collection - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_rogue_dhcp_server|Detect Rogue DHCP Server]] - -| -[https://attack.mitre.org/techniques/T1200/ T1200], -[https://attack.mitre.org/techniques/T1498/ T1498], -[https://attack.mitre.org/techniques/T1557/ T1557] -| -Hardware Additions, -Network Denial of Service, -Adversary-in-the-Middle -| -Initial Access, -Impact, -Credential Access, Collection - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_software_download_to_network_device|Detect Software Download To Network Device]] - -| -[https://attack.mitre.org/techniques/T1542.005/ T1542.005], -[https://attack.mitre.org/techniques/T1542/ T1542] -| -TFTP Boot, -Pre-OS Boot -| -Defense Evasion, Persistence, -Defense Evasion, Persistence - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_traffic_mirroring|Detect Traffic Mirroring]] - -| -[https://attack.mitre.org/techniques/T1200/ T1200], -[https://attack.mitre.org/techniques/T1020/ T1020], -[https://attack.mitre.org/techniques/T1498/ T1498], -[https://attack.mitre.org/techniques/T1020.001/ T1020.001] -| -Hardware Additions, -Automated Exfiltration, -Network Denial of Service, -Traffic Duplication -| -Initial Access, -Exfiltration, -Impact, -Exfiltration - -| TTP -|} - -====Kill Chain Phase==== - -* Actions on Objectives - -* Delivery - -* Exploitation - -* Reconnaissance - - -====Reference==== - -* https://www.fireeye.com/blog/executive-perspective/2015/09/the_new_route_toper.html - -* https://www.cisco.com/c/en/us/about/security-center/event-response/synful-knock.html - - -''version'': 1 -
-
- ----- - -===Use of cleartext protocols=== -Leverage searches that detect cleartext network protocols that may leak credentials or should otherwise be encrypted. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/NetworkTraffic Network_Traffic] -* '''Last Updated''': 2017-09-15 -* '''Use Case''': Security Monitoring - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Protocols_passing_authentication_in_cleartext|Protocols passing authentication in cleartext]] - -| -| -| - -| TTP -|} - -====Kill Chain Phase==== - -* Actions on Objectives - -* Reconnaissance - - -====Reference==== - -* https://www.monkey.org/~dugsong/dsniff/ - - -''version'': 1 -
-
- ----- - - - -==Cloud Security== - - -===Aws cross account activity=== -Track when a user assumes an IAM role in another AWS account to obtain cross-account access to services and resources in that account. Accessing new roles could be an indication of malicious activity. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''Last Updated''': 2018-06-04 -* '''Use Case''': Security Monitoring - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Aws_detect_attach_to_role_policy|aws detect attach to role policy]] - -| -[https://attack.mitre.org/techniques/T1078/ T1078] -| -Valid Accounts -| -Defense Evasion, Persistence, Privilege Escalation, Initial Access - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Aws_detect_permanent_key_creation|aws detect permanent key creation]] - -| -[https://attack.mitre.org/techniques/T1078/ T1078] -| -Valid Accounts -| -Defense Evasion, Persistence, Privilege Escalation, Initial Access - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Aws_detect_role_creation|aws detect role creation]] - -| -[https://attack.mitre.org/techniques/T1078/ T1078] -| -Valid Accounts -| -Defense Evasion, Persistence, Privilege Escalation, Initial Access - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Aws_detect_sts_assume_role_abuse|aws detect sts assume role abuse]] - -| -[https://attack.mitre.org/techniques/T1078/ T1078] -| -Valid Accounts -| -Defense Evasion, Persistence, Privilege Escalation, Initial Access - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Aws_detect_sts_get_session_token_abuse|aws detect sts get session token abuse]] - -| -[https://attack.mitre.org/techniques/T1550/ T1550] -| -Use Alternate Authentication Material -| -Defense Evasion, Lateral Movement - -| Hunting -|} - -====Kill Chain Phase==== - -* Lateral Movement - - -====Reference==== - -* https://aws.amazon.com/blogs/security/aws-cloudtrail-now-tracks-cross-account-activity-to-its-origin/ - - -''version'': 1 -
-
- ----- - -===Aws iam privilege escalation=== -This analytic story contains detections that query your AWS Cloudtrail for activities related to privilege escalation. - -* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''Last Updated''': 2021-03-08 -* '''Use Case''': Security Monitoring - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Aws_create_policy_version_to_allow_all_resources|AWS Create Policy Version to allow all resources]] - -| -[https://attack.mitre.org/techniques/T1078.004/ T1078.004], -[https://attack.mitre.org/techniques/T1078/ T1078] -| -Cloud Accounts, -Valid Accounts -| -Defense Evasion, Persistence, Privilege Escalation, Initial Access, -Defense Evasion, Persistence, Privilege Escalation, Initial Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Aws_createaccesskey|AWS CreateAccessKey]] - -| -[https://attack.mitre.org/techniques/T1136.003/ T1136.003], -[https://attack.mitre.org/techniques/T1136/ T1136] -| -Cloud Account, -Create Account -| -Persistence, -Persistence - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Aws_createloginprofile|AWS CreateLoginProfile]] - -| -[https://attack.mitre.org/techniques/T1136.003/ T1136.003], -[https://attack.mitre.org/techniques/T1136/ T1136] -| -Cloud Account, -Create Account -| -Persistence, -Persistence - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Aws_iam_assume_role_policy_brute_force|AWS IAM Assume Role Policy Brute Force]] - -| -[https://attack.mitre.org/techniques/T1580/ T1580], -[https://attack.mitre.org/techniques/T1110/ T1110] -| -Cloud Infrastructure Discovery, -Brute Force -| -Discovery, -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Aws_iam_delete_policy|AWS IAM Delete Policy]] - -| -[https://attack.mitre.org/techniques/T1098/ T1098] -| -Account Manipulation -| -Persistence - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Aws_iam_failure_group_deletion|AWS IAM Failure Group Deletion]] - -| -[https://attack.mitre.org/techniques/T1098/ T1098] -| -Account Manipulation -| -Persistence - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Aws_iam_successful_group_deletion|AWS IAM Successful Group Deletion]] - -| -[https://attack.mitre.org/techniques/T1069.003/ T1069.003], -[https://attack.mitre.org/techniques/T1098/ T1098], -[https://attack.mitre.org/techniques/T1069/ T1069] -| -Cloud Groups, -Account Manipulation, -Permission Groups Discovery -| -Discovery, -Persistence, -Discovery - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Aws_setdefaultpolicyversion|AWS SetDefaultPolicyVersion]] - -| -[https://attack.mitre.org/techniques/T1078.004/ T1078.004], -[https://attack.mitre.org/techniques/T1078/ T1078] -| -Cloud Accounts, -Valid Accounts -| -Defense Evasion, Persistence, Privilege Escalation, Initial Access, -Defense Evasion, Persistence, Privilege Escalation, Initial Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Aws_updateloginprofile|AWS UpdateLoginProfile]] - -| -[https://attack.mitre.org/techniques/T1136.003/ T1136.003], -[https://attack.mitre.org/techniques/T1136/ T1136] -| -Cloud Account, -Create Account -| -Persistence, -Persistence - -| TTP -|} - -====Kill Chain Phase==== - -* Actions on Objectives - -* Reconnaissance - - -====Reference==== - -* https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation/ - -* https://www.cyberark.com/resources/threat-research-blog/the-cloud-shadow-admin-threat-10-permissions-to-protect - -* https://labs.bishopfox.com/tech-blog/privilege-escalation-in-aws - - -''version'': 1 -
-
- ----- - -===Aws network acl activity=== -Monitor your AWS network infrastructure for bad configurations and malicious activity. Investigative searches help you probe deeper, when the facts warrant it. - -* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''Last Updated''': 2018-05-21 -* '''Use Case''': Security Monitoring - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Aws_network_access_control_list_created_with_all_open_ports|AWS Network Access Control List Created with All Open Ports]] - -| -[https://attack.mitre.org/techniques/T1562.007/ T1562.007], -[https://attack.mitre.org/techniques/T1562/ T1562] -| -Disable or Modify Cloud Firewall, -Impair Defenses -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Aws_network_access_control_list_deleted|AWS Network Access Control List Deleted]] - -| -[https://attack.mitre.org/techniques/T1562.007/ T1562.007], -[https://attack.mitre.org/techniques/T1562/ T1562] -| -Disable or Modify Cloud Firewall, -Impair Defenses -| -Defense Evasion, -Defense Evasion - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Detect_spike_in_blocked_outbound_traffic_from_your_aws|Detect Spike in blocked Outbound Traffic from your AWS]] - -| -| -| - -| Anomaly -|} - -====Kill Chain Phase==== - -* Actions on Objectives - -* Command and Control - - -====Reference==== - -* https://docs.aws.amazon.com/AmazonVPC/latest/UserGuide/VPC_Appendix_NACLs.html - -* https://aws.amazon.com/blogs/security/how-to-help-prepare-for-ddos-attacks-by-reducing-your-attack-surface/ - - -''version'': 2 -
-
- ----- - -===Aws security hub alerts=== -This story is focused around detecting Security Hub alerts generated from AWS - -* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''Last Updated''': 2020-08-04 -* '''Use Case''': Security Monitoring - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Detect_spike_in_aws_security_hub_alerts_for_ec2_instance|Detect Spike in AWS Security Hub Alerts for EC2 Instance]] - -| -| -| - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Detect_spike_in_aws_security_hub_alerts_for_user|Detect Spike in AWS Security Hub Alerts for User]] - -| -| -| - -| Anomaly -|} - -====Kill Chain Phase==== - - -====Reference==== - -* https://aws.amazon.com/security-hub/features/ - - -''version'': 1 -
-
- ----- - -===Aws user monitoring=== -Detect and investigate dormant user accounts for your AWS environment that have become active again. Because inactive and ad-hoc accounts are common attack targets, it's critical to enable governance within your environment. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''Last Updated''': 2018-03-12 -* '''Use Case''': Security Monitoring - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Aws_excessive_security_scanning|AWS Excessive Security Scanning]] - -| -[https://attack.mitre.org/techniques/T1526/ T1526] -| -Cloud Service Discovery -| -Discovery - -| TTP -|} - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Reference==== - -* https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf - -* https://redlock.io/blog/cryptojacking-tesla - - -''version'': 1 -
-
- ----- - -===Cloud cryptomining=== -Monitor your cloud compute instances for activities related to cryptojacking/cryptomining. New instances that originate from previously unseen regions, users who launch abnormally high numbers of instances, or compute instances started by previously unseen users are just a few examples of potentially malicious behavior. - -* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Change Change] -* '''Last Updated''': 2019-10-02 -* '''Use Case''': Security Monitoring - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Abnormally_high_number_of_cloud_instances_launched|Abnormally High Number Of Cloud Instances Launched]] - -| -[https://attack.mitre.org/techniques/T1078.004/ T1078.004], -[https://attack.mitre.org/techniques/T1078/ T1078] -| -Cloud Accounts, -Valid Accounts -| -Defense Evasion, Persistence, Privilege Escalation, Initial Access, -Defense Evasion, Persistence, Privilege Escalation, Initial Access - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Cloud_compute_instance_created_by_previously_unseen_user|Cloud Compute Instance Created By Previously Unseen User]] - -| -[https://attack.mitre.org/techniques/T1078.004/ T1078.004], -[https://attack.mitre.org/techniques/T1078/ T1078] -| -Cloud Accounts, -Valid Accounts -| -Defense Evasion, Persistence, Privilege Escalation, Initial Access, -Defense Evasion, Persistence, Privilege Escalation, Initial Access - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Cloud_compute_instance_created_in_previously_unused_region|Cloud Compute Instance Created In Previously Unused Region]] - -| -[https://attack.mitre.org/techniques/T1535/ T1535] -| -Unused/Unsupported Cloud Regions -| -Defense Evasion - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Cloud_compute_instance_created_with_previously_unseen_image|Cloud Compute Instance Created With Previously Unseen Image]] - -| -| -| - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Cloud_compute_instance_created_with_previously_unseen_instance_type|Cloud Compute Instance Created With Previously Unseen Instance Type]] - -| -| -| - -| Anomaly -|} - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Reference==== - -* https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf - - -''version'': 1 -
-
- ----- - -===Cloud federated credential abuse=== -This analytical story addresses events that indicate abuse of cloud federated credentials. These credentials are usually extracted from endpoint desktop or servers specially those servers that provide federation services such as Windows Active Directory Federation Services. Identity Federation relies on objects such as Oauth2 tokens, cookies or SAML assertions in order to provide seamless access between cloud and perimeter environments. If these objects are either hijacked or forged then attackers will be able to pivot into victim's cloud environements. - -* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint] -* '''Last Updated''': 2021-01-26 -* '''Use Case''': Security Monitoring - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Aws_saml_access_by_provider_user_and_principal|AWS SAML Access by Provider User and Principal]] - -| -[https://attack.mitre.org/techniques/T1078/ T1078] -| -Valid Accounts -| -Defense Evasion, Persistence, Privilege Escalation, Initial Access - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Aws_saml_update_identity_provider|AWS SAML Update identity provider]] - -| -[https://attack.mitre.org/techniques/T1078/ T1078] -| -Valid Accounts -| -Defense Evasion, Persistence, Privilege Escalation, Initial Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Certutil_exe_certificate_extraction|Certutil exe certificate extraction]] - -| -| -| - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_mimikatz_using_loaded_images|Detect Mimikatz Using Loaded Images]] - -| -[https://attack.mitre.org/techniques/T1003.001/ T1003.001], -[https://attack.mitre.org/techniques/T1003/ T1003] -| -LSASS Memory, -OS Credential Dumping -| -Credential Access, -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_rare_executables|Detect Rare Executables]] - -| -| -| - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#O365_add_app_role_assignment_grant_user|O365 Add App Role Assignment Grant User]] - -| -[https://attack.mitre.org/techniques/T1136.003/ T1136.003], -[https://attack.mitre.org/techniques/T1136/ T1136] -| -Cloud Account, -Create Account -| -Persistence, -Persistence - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#O365_added_service_principal|O365 Added Service Principal]] - -| -[https://attack.mitre.org/techniques/T1136.003/ T1136.003], -[https://attack.mitre.org/techniques/T1136/ T1136] -| -Cloud Account, -Create Account -| -Persistence, -Persistence - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#O365_excessive_sso_logon_errors|O365 Excessive SSO logon errors]] - -| -[https://attack.mitre.org/techniques/T1556/ T1556] -| -Modify Authentication Process -| -Credential Access, Defense Evasion, Persistence - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#O365_new_federated_domain_added|O365 New Federated Domain Added]] - -| -[https://attack.mitre.org/techniques/T1136.003/ T1136.003], -[https://attack.mitre.org/techniques/T1136/ T1136] -| -Cloud Account, -Create Account -| -Persistence, -Persistence - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Registry_keys_used_for_privilege_escalation|Registry Keys Used For Privilege Escalation]] - -| -[https://attack.mitre.org/techniques/T1546.012/ T1546.012], -[https://attack.mitre.org/techniques/T1546/ T1546] -| -Image File Execution Options Injection, -Event Triggered Execution -| -Privilege Escalation, Persistence, -Privilege Escalation, Persistence - -| TTP -|} - -====Kill Chain Phase==== - -* Actions on Objective - -* Actions on Objectives - -* Command and Control - -* Installation - - -====Reference==== - -* https://www.cyberark.com/resources/threat-research-blog/golden-saml-newly-discovered-attack-technique-forges-authentication-to-cloud-apps - -* https://www.fireeye.com/content/dam/fireeye-www/blog/pdfs/wp-m-unc2452-2021-000343-01.pdf - -* https://us-cert.cisa.gov/ncas/alerts/aa21-008a - - -''version'': 1 -
-
- ----- - -===Container implantation monitoring and investigation=== -Use the searches in this story to monitor your Kubernetes registry repositories for upload, and deployment of potentially vulnerable, backdoor, or implanted containers. These searches provide information on source users, destination path, container names and repository names. The searches provide context to address Mitre T1525 which refers to container implantation upload to a company's repository either in Amazon Elastic Container Registry, Google Container Registry and Azure Container Registry. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''Last Updated''': 2020-02-20 -* '''Use Case''': Security Monitoring - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#New_container_uploaded_to_aws_ecr|New container uploaded to AWS ECR]] - -| -[https://attack.mitre.org/techniques/T1525/ T1525] -| -Implant Internal Image -| -Persistence - -| Hunting -|} - -====Kill Chain Phase==== - - -====Reference==== - -* https://github.com/splunk/cloud-datamodel-security-research - - -''version'': 1 -
-
- ----- - -===Dev sec ops=== -This story is focused around detecting attacks on a DevSecOps lifeccycle which consists of the phases plan, code, build, test, release, deploy, operate and monitor. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud, Dev Sec Ops Analytics -* '''Datamodel''': -* '''Last Updated''': 2021-08-18 -* '''Use Case''': Security Monitoring - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Aws_ecr_container_scanning_findings_high|AWS ECR Container Scanning Findings High]] - -| -[https://attack.mitre.org/techniques/T1204.003/ T1204.003], -[https://attack.mitre.org/techniques/T1204/ T1204] -| -Malicious Image, -User Execution -| -Execution, -Execution - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Aws_ecr_container_scanning_findings_low_informational_unknown|AWS ECR Container Scanning Findings Low Informational Unknown]] - -| -[https://attack.mitre.org/techniques/T1204.003/ T1204.003], -[https://attack.mitre.org/techniques/T1204/ T1204] -| -Malicious Image, -User Execution -| -Execution, -Execution - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Aws_ecr_container_scanning_findings_medium|AWS ECR Container Scanning Findings Medium]] - -| -[https://attack.mitre.org/techniques/T1204.003/ T1204.003], -[https://attack.mitre.org/techniques/T1204/ T1204] -| -Malicious Image, -User Execution -| -Execution, -Execution - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Aws_ecr_container_upload_outside_business_hours|AWS ECR Container Upload Outside Business Hours]] - -| -[https://attack.mitre.org/techniques/T1204.003/ T1204.003], -[https://attack.mitre.org/techniques/T1204/ T1204] -| -Malicious Image, -User Execution -| -Execution, -Execution - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Aws_ecr_container_upload_unknown_user|AWS ECR Container Upload Unknown User]] - -| -[https://attack.mitre.org/techniques/T1204.003/ T1204.003], -[https://attack.mitre.org/techniques/T1204/ T1204] -| -Malicious Image, -User Execution -| -Execution, -Execution - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Circle_ci_disable_security_job|Circle CI Disable Security Job]] - -| -[https://attack.mitre.org/techniques/T1554/ T1554] -| -Compromise Client Software Binary -| -Persistence - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Circle_ci_disable_security_step|Circle CI Disable Security Step]] - -| -[https://attack.mitre.org/techniques/T1554/ T1554] -| -Compromise Client Software Binary -| -Persistence - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Correlation_by_repository_and_risk|Correlation by Repository and Risk]] - -| -[https://attack.mitre.org/techniques/T1204.003/ T1204.003], -[https://attack.mitre.org/techniques/T1204/ T1204] -| -Malicious Image, -User Execution -| -Execution, -Execution - -| Correlation -|- -| [[Documentation:ESSOC:detections:Detections#Correlation_by_user_and_risk|Correlation by User and Risk]] - -| -[https://attack.mitre.org/techniques/T1204.003/ T1204.003], -[https://attack.mitre.org/techniques/T1204/ T1204] -| -Malicious Image, -User Execution -| -Execution, -Execution - -| Correlation -|- -| [[Documentation:ESSOC:detections:Detections#Gsuite_email_suspicious_attachment|GSuite Email Suspicious Attachment]] - -| -[https://attack.mitre.org/techniques/T1566.001/ T1566.001], -[https://attack.mitre.org/techniques/T1566/ T1566] -| -Spearphishing Attachment, -Phishing -| -Initial Access, -Initial Access - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Github_dependabot_alert|GitHub Dependabot Alert]] - -| -[https://attack.mitre.org/techniques/T1195.001/ T1195.001], -[https://attack.mitre.org/techniques/T1195/ T1195] -| -Compromise Software Dependencies and Development Tools, -Supply Chain Compromise -| -Initial Access, -Initial Access - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Github_pull_request_from_unknown_user|GitHub Pull Request from Unknown User]] - -| -[https://attack.mitre.org/techniques/T1195.001/ T1195.001], -[https://attack.mitre.org/techniques/T1195/ T1195] -| -Compromise Software Dependencies and Development Tools, -Supply Chain Compromise -| -Initial Access, -Initial Access - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Github_commit_changes_in_master|Github Commit Changes In Master]] - -| -[https://attack.mitre.org/techniques/T1199/ T1199] -| -Trusted Relationship -| -Initial Access - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Github_commit_in_develop|Github Commit In Develop]] - -| -[https://attack.mitre.org/techniques/T1199/ T1199] -| -Trusted Relationship -| -Initial Access - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Gsuite_drive_share_in_external_email|Gsuite Drive Share In External Email]] - -| -[https://attack.mitre.org/techniques/T1567.002/ T1567.002], -[https://attack.mitre.org/techniques/T1567/ T1567] -| -Exfiltration to Cloud Storage, -Exfiltration Over Web Service -| -Exfiltration, -Exfiltration - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Gsuite_email_suspicious_subject_with_attachment|Gsuite Email Suspicious Subject With Attachment]] - -| -[https://attack.mitre.org/techniques/T1566.001/ T1566.001], -[https://attack.mitre.org/techniques/T1566/ T1566] -| -Spearphishing Attachment, -Phishing -| -Initial Access, -Initial Access - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Gsuite_email_with_known_abuse_web_service_link|Gsuite Email With Known Abuse Web Service Link]] - -| -[https://attack.mitre.org/techniques/T1566.001/ T1566.001], -[https://attack.mitre.org/techniques/T1566/ T1566] -| -Spearphishing Attachment, -Phishing -| -Initial Access, -Initial Access - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Gsuite_outbound_email_with_attachment_to_external_domain|Gsuite Outbound Email With Attachment To External Domain]] - -| -[https://attack.mitre.org/techniques/T1048.003/ T1048.003], -[https://attack.mitre.org/techniques/T1048/ T1048] -| -Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol, -Exfiltration Over Alternative Protocol -| -Exfiltration, -Exfiltration - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Gsuite_suspicious_shared_file_name|Gsuite Suspicious Shared File Name]] - -| -[https://attack.mitre.org/techniques/T1566.001/ T1566.001], -[https://attack.mitre.org/techniques/T1566/ T1566] -| -Spearphishing Attachment, -Phishing -| -Initial Access, -Initial Access - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Kubernetes_nginx_ingress_lfi|Kubernetes Nginx Ingress LFI]] - -| -[https://attack.mitre.org/techniques/T1212/ T1212] -| -Exploitation for Credential Access -| -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Kubernetes_nginx_ingress_rfi|Kubernetes Nginx Ingress RFI]] - -| -[https://attack.mitre.org/techniques/T1212/ T1212] -| -Exploitation for Credential Access -| -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Kubernetes_scanner_image_pulling|Kubernetes Scanner Image Pulling]] - -| -[https://attack.mitre.org/techniques/T1526/ T1526] -| -Cloud Service Discovery -| -Discovery - -| TTP -|} - -====Kill Chain Phase==== - -* Actions on Objectives - -* Exfiltration - -* Exploitation - - -====Reference==== - -* https://www.redhat.com/en/topics/devops/what-is-devsecops - - -''version'': 1 -
-
- ----- - -===Gcp cross account activity=== -Track when a user assumes an IAM role in another GCP account to obtain cross-account access to services and resources in that account. Accessing new roles could be an indication of malicious activity. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''Last Updated''': 2020-09-01 -* '''Use Case''': Security Monitoring - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Gcp_detect_gcploit_framework|GCP Detect gcploit framework]] - -| -[https://attack.mitre.org/techniques/T1078/ T1078] -| -Valid Accounts -| -Defense Evasion, Persistence, Privilege Escalation, Initial Access - -| TTP -|} - -====Kill Chain Phase==== - -* Lateral Movement - - -====Reference==== - -* https://cloud.google.com/iam/docs/understanding-service-accounts - - -''version'': 1 -
-
- ----- - -===Kubernetes scanning activity=== -This story addresses detection against Kubernetes cluster fingerprint scan and attack by providing information on items such as source ip, user agent, cluster names. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''Last Updated''': 2020-04-15 -* '''Use Case''': Security Monitoring - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Amazon_eks_kubernetes_pod_scan_detection|Amazon EKS Kubernetes Pod scan detection]] - -| -[https://attack.mitre.org/techniques/T1526/ T1526] -| -Cloud Service Discovery -| -Discovery - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Amazon_eks_kubernetes_cluster_scan_detection|Amazon EKS Kubernetes cluster scan detection]] - -| -[https://attack.mitre.org/techniques/T1526/ T1526] -| -Cloud Service Discovery -| -Discovery - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Gcp_kubernetes_cluster_pod_scan_detection|GCP Kubernetes cluster pod scan detection]] - -| -[https://attack.mitre.org/techniques/T1526/ T1526] -| -Cloud Service Discovery -| -Discovery - -| Hunting -|} - -====Kill Chain Phase==== - -* Reconnaissance - - -====Reference==== - -* https://github.com/splunk/cloud-datamodel-security-research - - -''version'': 1 -
-
- ----- - -===Kubernetes sensitive object access activity=== -This story addresses detection and response of accounts acccesing Kubernetes cluster sensitive objects such as configmaps or secrets providing information on items such as user user, group. object, namespace and authorization reason. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''Last Updated''': 2020-05-20 -* '''Use Case''': Security Monitoring - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Kubernetes_aws_detect_suspicious_kubectl_calls|Kubernetes AWS detect suspicious kubectl calls]] - -| -| -| - -| Hunting -|} - -====Kill Chain Phase==== - -* Lateral Movement - - -====Reference==== - -* https://www.splunk.com/en_us/blog/security/approaching-kubernetes-security-detecting-kubernetes-scan-with-splunk.html - - -''version'': 1 -
-
- ----- - -===Office 365 detections=== -This story is focused around detecting Office 365 Attacks. - -* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''Last Updated''': 2020-12-16 -* '''Use Case''': Security Monitoring - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#High_number_of_login_failures_from_a_single_source|High Number of Login Failures from a single source]] - -| -[https://attack.mitre.org/techniques/T1110.001/ T1110.001], -[https://attack.mitre.org/techniques/T1110/ T1110] -| -Password Guessing, -Brute Force -| -Credential Access, -Credential Access - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#O365_add_app_role_assignment_grant_user|O365 Add App Role Assignment Grant User]] - -| -[https://attack.mitre.org/techniques/T1136.003/ T1136.003], -[https://attack.mitre.org/techniques/T1136/ T1136] -| -Cloud Account, -Create Account -| -Persistence, -Persistence - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#O365_added_service_principal|O365 Added Service Principal]] - -| -[https://attack.mitre.org/techniques/T1136.003/ T1136.003], -[https://attack.mitre.org/techniques/T1136/ T1136] -| -Cloud Account, -Create Account -| -Persistence, -Persistence - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#O365_bypass_mfa_via_trusted_ip|O365 Bypass MFA via Trusted IP]] - -| -[https://attack.mitre.org/techniques/T1562.007/ T1562.007], -[https://attack.mitre.org/techniques/T1562/ T1562] -| -Disable or Modify Cloud Firewall, -Impair Defenses -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#O365_disable_mfa|O365 Disable MFA]] - -| -[https://attack.mitre.org/techniques/T1556/ T1556] -| -Modify Authentication Process -| -Credential Access, Defense Evasion, Persistence - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#O365_excessive_authentication_failures_alert|O365 Excessive Authentication Failures Alert]] - -| -[https://attack.mitre.org/techniques/T1110/ T1110] -| -Brute Force -| -Credential Access - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#O365_excessive_sso_logon_errors|O365 Excessive SSO logon errors]] - -| -[https://attack.mitre.org/techniques/T1556/ T1556] -| -Modify Authentication Process -| -Credential Access, Defense Evasion, Persistence - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#O365_new_federated_domain_added|O365 New Federated Domain Added]] - -| -[https://attack.mitre.org/techniques/T1136.003/ T1136.003], -[https://attack.mitre.org/techniques/T1136/ T1136] -| -Cloud Account, -Create Account -| -Persistence, -Persistence - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#O365_pst_export_alert|O365 PST export alert]] - -| -[https://attack.mitre.org/techniques/T1114/ T1114] -| -Email Collection -| -Collection - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#O365_suspicious_admin_email_forwarding|O365 Suspicious Admin Email Forwarding]] - -| -[https://attack.mitre.org/techniques/T1114.003/ T1114.003], -[https://attack.mitre.org/techniques/T1114/ T1114] -| -Email Forwarding Rule, -Email Collection -| -Collection, -Collection - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#O365_suspicious_rights_delegation|O365 Suspicious Rights Delegation]] - -| -[https://attack.mitre.org/techniques/T1114.002/ T1114.002], -[https://attack.mitre.org/techniques/T1114/ T1114] -| -Remote Email Collection, -Email Collection -| -Collection, -Collection - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#O365_suspicious_user_email_forwarding|O365 Suspicious User Email Forwarding]] - -| -[https://attack.mitre.org/techniques/T1114.003/ T1114.003], -[https://attack.mitre.org/techniques/T1114/ T1114] -| -Email Forwarding Rule, -Email Collection -| -Collection, -Collection - -| Anomaly -|} - -====Kill Chain Phase==== - -* Actions on Objective - -* Actions on Objectives - -* Not Applicable - - -====Reference==== - -* https://i.blackhat.com/USA-20/Thursday/us-20-Bienstock-My-Cloud-Is-APTs-Cloud-Investigating-And-Defending-Office-365.pdf - - -''version'': 1 -
-
- ----- - -===Suspicious aws login activities=== -Monitor your AWS authentication events using your CloudTrail logs. Searches within this Analytic Story will help you stay aware of and investigate suspicious logins. - -* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Authentication Authentication] -* '''Last Updated''': 2019-05-01 -* '''Use Case''': Security Monitoring - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Detect_aws_console_login_by_user_from_new_city|Detect AWS Console Login by User from New City]] - -| -[https://attack.mitre.org/techniques/T1535/ T1535] -| -Unused/Unsupported Cloud Regions -| -Defense Evasion - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Detect_aws_console_login_by_user_from_new_country|Detect AWS Console Login by User from New Country]] - -| -[https://attack.mitre.org/techniques/T1535/ T1535] -| -Unused/Unsupported Cloud Regions -| -Defense Evasion - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Detect_aws_console_login_by_user_from_new_region|Detect AWS Console Login by User from New Region]] - -| -[https://attack.mitre.org/techniques/T1535/ T1535] -| -Unused/Unsupported Cloud Regions -| -Defense Evasion - -| Hunting -|} - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Reference==== - -* https://docs.aws.amazon.com/IAM/latest/UserGuide/cloudtrail-integration.html - - -''version'': 1 -
-
- ----- - -===Suspicious aws s3 activities=== -Use the searches in this Analytic Story to monitor your AWS S3 buckets for evidence of anomalous activity and suspicious behaviors, such as detecting open S3 buckets and buckets being accessed from a new IP. The contextual and investigative searches will give you more information, when required. - -* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''Last Updated''': 2018-07-24 -* '''Use Case''': Security Monitoring - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Detect_new_open_s3_buckets_over_aws_cli|Detect New Open S3 Buckets over AWS CLI]] - -| -[https://attack.mitre.org/techniques/T1530/ T1530] -| -Data from Cloud Storage Object -| -Collection - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_new_open_s3_buckets|Detect New Open S3 buckets]] - -| -[https://attack.mitre.org/techniques/T1530/ T1530] -| -Data from Cloud Storage Object -| -Collection - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_s3_access_from_a_new_ip|Detect S3 access from a new IP]] - -| -[https://attack.mitre.org/techniques/T1530/ T1530] -| -Data from Cloud Storage Object -| -Collection - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Detect_spike_in_s3_bucket_deletion|Detect Spike in S3 Bucket deletion]] - -| -[https://attack.mitre.org/techniques/T1530/ T1530] -| -Data from Cloud Storage Object -| -Collection - -| Anomaly -|} - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Reference==== - -* https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf - -* https://www.tripwire.com/state-of-security/security-data-protection/cloud/public-aws-s3-buckets-writable/ - - -''version'': 2 -
-
- ----- - -===Suspicious aws traffic=== -Leverage these searches to monitor your AWS network traffic for evidence of anomalous activity and suspicious behaviors, such as a spike in blocked outbound traffic in your virtual private cloud (VPC). - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''Last Updated''': 2018-05-07 -* '''Use Case''': Security Monitoring - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Detect_spike_in_blocked_outbound_traffic_from_your_aws|Detect Spike in blocked Outbound Traffic from your AWS]] - -| -| -| - -| Anomaly -|} - -====Kill Chain Phase==== - -* Actions on Objectives - -* Command and Control - - -====Reference==== - -* https://rhinosecuritylabs.com/aws/hiding-cloudcobalt-strike-beacon-c2-using-amazon-apis/ - - -''version'': 1 -
-
- ----- - -===Suspicious cloud authentication activities=== -Monitor your cloud authentication events. Searches within this Analytic Story leverage the recent cloud updates to the Authentication data model to help you stay aware of and investigate suspicious login activity. - -* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Authentication Authentication] -* '''Last Updated''': 2020-06-04 -* '''Use Case''': Security Monitoring - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Aws_cross_account_activity_from_previously_unseen_account|AWS Cross Account Activity From Previously Unseen Account]] - -| -| -| - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Detect_aws_console_login_by_new_user|Detect AWS Console Login by New User]] - -| -| -| - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Detect_aws_console_login_by_user_from_new_city|Detect AWS Console Login by User from New City]] - -| -[https://attack.mitre.org/techniques/T1535/ T1535] -| -Unused/Unsupported Cloud Regions -| -Defense Evasion - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Detect_aws_console_login_by_user_from_new_country|Detect AWS Console Login by User from New Country]] - -| -[https://attack.mitre.org/techniques/T1535/ T1535] -| -Unused/Unsupported Cloud Regions -| -Defense Evasion - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Detect_aws_console_login_by_user_from_new_region|Detect AWS Console Login by User from New Region]] - -| -[https://attack.mitre.org/techniques/T1535/ T1535] -| -Unused/Unsupported Cloud Regions -| -Defense Evasion - -| Hunting -|} - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Reference==== - -* https://aws.amazon.com/blogs/security/aws-cloudtrail-now-tracks-cross-account-activity-to-its-origin/ - -* https://docs.aws.amazon.com/IAM/latest/UserGuide/cloudtrail-integration.html - - -''version'': 1 -
-
- ----- - -===Suspicious cloud instance activities=== -Monitor your cloud infrastructure provisioning activities for behaviors originating from unfamiliar or unusual locations. These behaviors may indicate that malicious activities are occurring somewhere within your cloud environment. - -* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Change Change] -* '''Last Updated''': 2020-08-25 -* '''Use Case''': Security Monitoring - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Abnormally_high_number_of_cloud_instances_destroyed|Abnormally High Number Of Cloud Instances Destroyed]] - -| -[https://attack.mitre.org/techniques/T1078.004/ T1078.004], -[https://attack.mitre.org/techniques/T1078/ T1078] -| -Cloud Accounts, -Valid Accounts -| -Defense Evasion, Persistence, Privilege Escalation, Initial Access, -Defense Evasion, Persistence, Privilege Escalation, Initial Access - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Abnormally_high_number_of_cloud_instances_launched|Abnormally High Number Of Cloud Instances Launched]] - -| -[https://attack.mitre.org/techniques/T1078.004/ T1078.004], -[https://attack.mitre.org/techniques/T1078/ T1078] -| -Cloud Accounts, -Valid Accounts -| -Defense Evasion, Persistence, Privilege Escalation, Initial Access, -Defense Evasion, Persistence, Privilege Escalation, Initial Access - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Cloud_instance_modified_by_previously_unseen_user|Cloud Instance Modified By Previously Unseen User]] - -| -[https://attack.mitre.org/techniques/T1078.004/ T1078.004], -[https://attack.mitre.org/techniques/T1078/ T1078] -| -Cloud Accounts, -Valid Accounts -| -Defense Evasion, Persistence, Privilege Escalation, Initial Access, -Defense Evasion, Persistence, Privilege Escalation, Initial Access - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Detect_shared_ec2_snapshot|Detect shared ec2 snapshot]] - -| -[https://attack.mitre.org/techniques/T1537/ T1537] -| -Transfer Data to Cloud Account -| -Exfiltration - -| TTP -|} - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Reference==== - -* https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf - - -''version'': 1 -
-
- ----- - -===Suspicious cloud provisioning activities=== -Monitor your cloud infrastructure provisioning activities for behaviors originating from unfamiliar or unusual locations. These behaviors may indicate that malicious activities are occurring somewhere within your cloud environment. - -* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Change Change] -* '''Last Updated''': 2018-08-20 -* '''Use Case''': Security Monitoring - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Cloud_provisioning_activity_from_previously_unseen_city|Cloud Provisioning Activity From Previously Unseen City]] - -| -[https://attack.mitre.org/techniques/T1078/ T1078] -| -Valid Accounts -| -Defense Evasion, Persistence, Privilege Escalation, Initial Access - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Cloud_provisioning_activity_from_previously_unseen_country|Cloud Provisioning Activity From Previously Unseen Country]] - -| -[https://attack.mitre.org/techniques/T1078/ T1078] -| -Valid Accounts -| -Defense Evasion, Persistence, Privilege Escalation, Initial Access - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Cloud_provisioning_activity_from_previously_unseen_ip_address|Cloud Provisioning Activity From Previously Unseen IP Address]] - -| -[https://attack.mitre.org/techniques/T1078/ T1078] -| -Valid Accounts -| -Defense Evasion, Persistence, Privilege Escalation, Initial Access - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Cloud_provisioning_activity_from_previously_unseen_region|Cloud Provisioning Activity From Previously Unseen Region]] - -| -[https://attack.mitre.org/techniques/T1078/ T1078] -| -Valid Accounts -| -Defense Evasion, Persistence, Privilege Escalation, Initial Access - -| Anomaly -|} - -====Kill Chain Phase==== - - -====Reference==== - -* https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf - - -''version'': 1 -
-
- ----- - -===Suspicious cloud user activities=== -Detect and investigate suspicious activities by users and roles in your cloud environments. - -* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Change Change] -* '''Last Updated''': 2020-09-04 -* '''Use Case''': Security Monitoring - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Aws_iam_accessdenied_discovery_events|AWS IAM AccessDenied Discovery Events]] - -| -[https://attack.mitre.org/techniques/T1580/ T1580] -| -Cloud Infrastructure Discovery -| -Discovery - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Abnormally_high_number_of_cloud_infrastructure_api_calls|Abnormally High Number Of Cloud Infrastructure API Calls]] - -| -[https://attack.mitre.org/techniques/T1078.004/ T1078.004], -[https://attack.mitre.org/techniques/T1078/ T1078] -| -Cloud Accounts, -Valid Accounts -| -Defense Evasion, Persistence, Privilege Escalation, Initial Access, -Defense Evasion, Persistence, Privilege Escalation, Initial Access - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Abnormally_high_number_of_cloud_security_group_api_calls|Abnormally High Number Of Cloud Security Group API Calls]] - -| -[https://attack.mitre.org/techniques/T1078.004/ T1078.004], -[https://attack.mitre.org/techniques/T1078/ T1078] -| -Cloud Accounts, -Valid Accounts -| -Defense Evasion, Persistence, Privilege Escalation, Initial Access, -Defense Evasion, Persistence, Privilege Escalation, Initial Access - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Cloud_api_calls_from_previously_unseen_user_roles|Cloud API Calls From Previously Unseen User Roles]] - -| -[https://attack.mitre.org/techniques/T1078/ T1078] -| -Valid Accounts -| -Defense Evasion, Persistence, Privilege Escalation, Initial Access - -| Anomaly -|} - -====Kill Chain Phase==== - -* Actions on Objectives - -* Reconnaissance - - -====Reference==== - -* https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf - -* https://redlock.io/blog/cryptojacking-tesla - - -''version'': 1 -
-
- ----- - -===Suspicious gcp storage activities=== -Use the searches in this Analytic Story to monitor your GCP Storage buckets for evidence of anomalous activity and suspicious behaviors, such as detecting open storage buckets and buckets being accessed from a new IP. The contextual and investigative searches will give you more information, when required. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''Last Updated''': 2020-08-05 -* '''Use Case''': Security Monitoring - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Detect_gcp_storage_access_from_a_new_ip|Detect GCP Storage access from a new IP]] - -| -[https://attack.mitre.org/techniques/T1530/ T1530] -| -Data from Cloud Storage Object -| -Collection - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Detect_new_open_gcp_storage_buckets|Detect New Open GCP Storage Buckets]] - -| -[https://attack.mitre.org/techniques/T1530/ T1530] -| -Data from Cloud Storage Object -| -Collection - -| TTP -|} - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Reference==== - -* https://cloud.google.com/blog/product/gcp/4-steps-for-hardening-your-cloud-storage-buckets-taking-charge-of-your-security - -* https://rhinosecuritylabs.com/gcp/google-cloud-platform-gcp-bucket-enumeration/ - - -''version'': 1 -
-
- ----- - - - -==Lateral Movement== - - -===Printnightmare cve-2021-34527=== -The following analytic story identifies behaviors related PrintNightmare, or CVE-2021-34527 previously known as (CVE-2021-1675), to gain privilege escalation on the vulnerable machine. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint] -* '''Last Updated''': 2021-07-01 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Print_spooler_adding_a_printer_driver|Print Spooler Adding A Printer Driver]] - -| -[https://attack.mitre.org/techniques/T1547.012/ T1547.012], -[https://attack.mitre.org/techniques/T1547/ T1547] -| -Print Processors, -Boot or Logon Autostart Execution -| -Persistence, Privilege Escalation, -Persistence, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Print_spooler_failed_to_load_a_plug-in|Print Spooler Failed to Load a Plug-in]] - -| -[https://attack.mitre.org/techniques/T1547.012/ T1547.012], -[https://attack.mitre.org/techniques/T1547/ T1547] -| -Print Processors, -Boot or Logon Autostart Execution -| -Persistence, Privilege Escalation, -Persistence, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Rundll32_with_no_command_line_arguments_with_network|Rundll32 with no Command Line Arguments with Network]] - -| -[https://attack.mitre.org/techniques/T1218/ T1218], -[https://attack.mitre.org/techniques/T1218.011/ T1218.011] -| -Signed Binary Proxy Execution, -Rundll32 -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Spoolsv_spawning_rundll32|Spoolsv Spawning Rundll32]] - -| -[https://attack.mitre.org/techniques/T1547.012/ T1547.012], -[https://attack.mitre.org/techniques/T1547/ T1547] -| -Print Processors, -Boot or Logon Autostart Execution -| -Persistence, Privilege Escalation, -Persistence, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Spoolsv_suspicious_loaded_modules|Spoolsv Suspicious Loaded Modules]] - -| -[https://attack.mitre.org/techniques/T1547.012/ T1547.012], -[https://attack.mitre.org/techniques/T1547/ T1547] -| -Print Processors, -Boot or Logon Autostart Execution -| -Persistence, Privilege Escalation, -Persistence, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Spoolsv_suspicious_process_access|Spoolsv Suspicious Process Access]] - -| -[https://attack.mitre.org/techniques/T1068/ T1068] -| -Exploitation for Privilege Escalation -| -Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Spoolsv_writing_a_dll|Spoolsv Writing a DLL]] - -| -[https://attack.mitre.org/techniques/T1547.012/ T1547.012], -[https://attack.mitre.org/techniques/T1547/ T1547] -| -Print Processors, -Boot or Logon Autostart Execution -| -Persistence, Privilege Escalation, -Persistence, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Spoolsv_writing_a_dll_-_sysmon|Spoolsv Writing a DLL - Sysmon]] - -| -[https://attack.mitre.org/techniques/T1547.012/ T1547.012], -[https://attack.mitre.org/techniques/T1547/ T1547] -| -Print Processors, -Boot or Logon Autostart Execution -| -Persistence, Privilege Escalation, -Persistence, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Suspicious_rundll32_no_command_line_arguments|Suspicious Rundll32 no Command Line Arguments]] - -| -[https://attack.mitre.org/techniques/T1218/ T1218], -[https://attack.mitre.org/techniques/T1218.011/ T1218.011] -| -Signed Binary Proxy Execution, -Rundll32 -| -Defense Evasion, -Defense Evasion - -| TTP -|} - -====Kill Chain Phase==== - -* Actions on Objectives - -* Exploitation - - -====Reference==== - -* https://github.com/cube0x0/CVE-2021-1675/ - -* https://blog.truesec.com/2021/06/30/fix-for-printnightmare-cve-2021-1675-exploit-to-keep-your-print-servers-running-while-a-patch-is-not-available/ - -* https://blog.truesec.com/2021/06/30/exploitable-critical-rce-vulnerability-allows-regular-users-to-fully-compromise-active-directory-printnightmare-cve-2021-1675/ - -* https://www.reddit.com/r/msp/comments/ob6y02/critical_vulnerability_printnightmare_exposes - - -''version'': 1 -
-
- ----- - - - -==Malware== - - -===Blackmatter ransomware=== -Leverage searches that allow you to detect and investigate unusual activities that might relate to the BlackMatter ransomware, including looking for file writes associated with BlackMatter, force safe mode boot, autadminlogon account registry modification and more. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint] -* '''Last Updated''': 2021-09-06 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Add_defaultuser_and_password_in_registry|Add DefaultUser And Password In Registry]] - -| -[https://attack.mitre.org/techniques/T1552.002/ T1552.002], -[https://attack.mitre.org/techniques/T1552/ T1552] -| -Credentials in Registry, -Unsecured Credentials -| -Credential Access, -Credential Access - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Auto_admin_logon_registry_entry|Auto Admin Logon Registry Entry]] - -| -[https://attack.mitre.org/techniques/T1552.002/ T1552.002], -[https://attack.mitre.org/techniques/T1552/ T1552] -| -Credentials in Registry, -Unsecured Credentials -| -Credential Access, -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Bcdedit_command_back_to_normal_mode_boot|Bcdedit Command Back To Normal Mode Boot]] - -| -[https://attack.mitre.org/techniques/T1490/ T1490] -| -Inhibit System Recovery -| -Impact - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Change_to_safe_mode_with_network_config|Change To Safe Mode With Network Config]] - -| -[https://attack.mitre.org/techniques/T1490/ T1490] -| -Inhibit System Recovery -| -Impact - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Known_services_killed_by_ransomware|Known Services Killed by Ransomware]] - -| -[https://attack.mitre.org/techniques/T1490/ T1490] -| -Inhibit System Recovery -| -Impact - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Modification_of_wallpaper|Modification Of Wallpaper]] - -| -[https://attack.mitre.org/techniques/T1491/ T1491] -| -Defacement -| -Impact - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Ransomware_notes_bulk_creation|Ransomware Notes bulk creation]] - -| -[https://attack.mitre.org/techniques/T1486/ T1486] -| -Data Encrypted for Impact -| -Impact - -| Anomaly -|} - -====Kill Chain Phase==== - -* Exploitation - -* Obfuscation - - -====Reference==== - -* https://news.sophos.com/en-us/2021/08/09/blackmatter-ransomware-emerges-from-the-shadow-of-darkside/ - -* https://www.bleepingcomputer.com/news/security/blackmatter-ransomware-gang-rises-from-the-ashes-of-darkside-revil/ - -* https://blog.malwarebytes.com/ransomware/2021/07/blackmatter-a-new-ransomware-group-claims-link-to-darkside-revil/ - - -''version'': 1 -
-
- ----- - -===Clop ransomware=== -Leverage searches that allow you to detect and investigate unusual activities that might relate to the Clop ransomware, including looking for file writes associated with Clope, encrypting network shares, deleting and resizing shadow volume storage, registry key modification, deleting of security logs, and more. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint] -* '''Last Updated''': 2021-03-17 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Clop_common_exec_parameter|Clop Common Exec Parameter]] - -| -[https://attack.mitre.org/techniques/T1204/ T1204] -| -User Execution -| -Execution - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Clop_ransomware_known_service_name|Clop Ransomware Known Service Name]] - -| -[https://attack.mitre.org/techniques/T1543/ T1543] -| -Create or Modify System Process -| -Persistence, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Common_ransomware_extensions|Common Ransomware Extensions]] - -| -[https://attack.mitre.org/techniques/T1485/ T1485] -| -Data Destruction -| -Impact - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Common_ransomware_notes|Common Ransomware Notes]] - -| -[https://attack.mitre.org/techniques/T1485/ T1485] -| -Data Destruction -| -Impact - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Create_service_in_suspicious_file_path|Create Service In Suspicious File Path]] - -| -[https://attack.mitre.org/techniques/T1569/ T1569], -[https://attack.mitre.org/techniques/T1569.002/ T1569.002] -| -System Services, -Service Execution -| -Execution, -Execution - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Deleting_shadow_copies|Deleting Shadow Copies]] - -| -[https://attack.mitre.org/techniques/T1490/ T1490] -| -Inhibit System Recovery -| -Impact - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#High_file_deletion_frequency|High File Deletion Frequency]] - -| -[https://attack.mitre.org/techniques/T1485/ T1485] -| -Data Destruction -| -Impact - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#High_process_termination_frequency|High Process Termination Frequency]] - -| -[https://attack.mitre.org/techniques/T1486/ T1486] -| -Data Encrypted for Impact -| -Impact - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Process_deleting_its_process_file_path|Process Deleting Its Process File Path]] - -| -[https://attack.mitre.org/techniques/T1070/ T1070] -| -Indicator Removal on Host -| -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Ransomware_notes_bulk_creation|Ransomware Notes bulk creation]] - -| -[https://attack.mitre.org/techniques/T1486/ T1486] -| -Data Encrypted for Impact -| -Impact - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Resize_shadowstorage_volume|Resize ShadowStorage volume]] - -| -[https://attack.mitre.org/techniques/T1490/ T1490] -| -Inhibit System Recovery -| -Impact - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Resize_shadowstorage_volume|Resize Shadowstorage Volume]] - -| -[https://attack.mitre.org/techniques/T1489/ T1489] -| -Service Stop -| -Impact - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Suspicious_event_log_service_behavior|Suspicious Event Log Service Behavior]] - -| -[https://attack.mitre.org/techniques/T1070/ T1070], -[https://attack.mitre.org/techniques/T1070.001/ T1070.001] -| -Indicator Removal on Host, -Clear Windows Event Logs -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Suspicious_wevtutil_usage|Suspicious wevtutil Usage]] - -| -[https://attack.mitre.org/techniques/T1070.001/ T1070.001], -[https://attack.mitre.org/techniques/T1070/ T1070] -| -Clear Windows Event Logs, -Indicator Removal on Host -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Wevtutil_usage_to_clear_logs|WevtUtil Usage To Clear Logs]] - -| -[https://attack.mitre.org/techniques/T1070/ T1070], -[https://attack.mitre.org/techniques/T1070.001/ T1070.001] -| -Indicator Removal on Host, -Clear Windows Event Logs -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Windows_event_log_cleared|Windows Event Log Cleared]] - -| -[https://attack.mitre.org/techniques/T1070/ T1070], -[https://attack.mitre.org/techniques/T1070.001/ T1070.001] -| -Indicator Removal on Host, -Clear Windows Event Logs -| -Defense Evasion, -Defense Evasion - -| TTP -|} - -====Kill Chain Phase==== - -* Actions on Objectives - -* Exploitation - -* Obfuscation - -* Privilege Escalation - - -====Reference==== - -* https://www.hhs.gov/sites/default/files/analyst-note-cl0p-tlp-white.pdf - -* https://securityaffairs.co/wordpress/115250/data-breach/qualys-clop-ransomware.html - -* https://www.darkreading.com/attacks-breaches/qualys-is-the-latest-victim-of-accellion-data-breach/d/d-id/1340323 - - -''version'': 1 -
-
- ----- - -===Coldroot macos rat=== -Leverage searches that allow you to detect and investigate unusual activities that relate to the ColdRoot Remote Access Trojan that affects MacOS. An example of some of these activities are changing sensative binaries in the MacOS sub-system, detecting process names and executables associated with the RAT, detecting when a keyboard tab is installed on a MacOS machine and more. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''Last Updated''': 2019-01-09 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Processes_tapping_keyboard_events|Processes Tapping Keyboard Events]] - -| -| -| - -| TTP -|} - -====Kill Chain Phase==== - -* Command and Control - - -====Reference==== - -* https://www.intego.com/mac-security-blog/osxcoldroot-and-the-rat-invasion/ - -* https://objective-see.com/blog/blog_0x2A.html - -* https://www.bleepingcomputer.com/news/security/coldroot-rat-still-undetectable-despite-being-uploaded-on-github-two-years-ago/ - - -''version'': 1 -
-
- ----- - -===Dhs report ta18-074a=== -Monitor for suspicious activities associated with DHS Technical Alert US-CERT TA18-074A. Some of the activities that adversaries used in these compromises included spearfishing attacks, malware, watering-hole domains, many and more. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint], [https://docs.splunk.com/Documentation/CIM/latest/User/NetworkTraffic Network_Traffic] -* '''Last Updated''': 2020-01-22 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Create_local_admin_accounts_using_net_exe|Create local admin accounts using net exe]] - -| -[https://attack.mitre.org/techniques/T1136.001/ T1136.001], -[https://attack.mitre.org/techniques/T1136/ T1136] -| -Local Account, -Create Account -| -Persistence, -Persistence - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_new_local_admin_account|Detect New Local Admin account]] - -| -[https://attack.mitre.org/techniques/T1136.001/ T1136.001], -[https://attack.mitre.org/techniques/T1136/ T1136] -| -Local Account, -Create Account -| -Persistence, -Persistence - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_outbound_smb_traffic|Detect Outbound SMB Traffic]] - -| -[https://attack.mitre.org/techniques/T1071.002/ T1071.002], -[https://attack.mitre.org/techniques/T1071/ T1071] -| -File Transfer Protocols, -Application Layer Protocol -| -Command And Control, -Command And Control - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_psexec_with_accepteula_flag|Detect PsExec With accepteula Flag]] - -| -[https://attack.mitre.org/techniques/T1021/ T1021], -[https://attack.mitre.org/techniques/T1021.002/ T1021.002] -| -Remote Services, -SMB/Windows Admin Shares -| -Lateral Movement, -Lateral Movement - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_renamed_psexec|Detect Renamed PSExec]] - -| -[https://attack.mitre.org/techniques/T1569/ T1569], -[https://attack.mitre.org/techniques/T1569.002/ T1569.002] -| -System Services, -Service Execution -| -Execution, -Execution - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Malicious_powershell_process_-_execution_policy_bypass|Malicious PowerShell Process - Execution Policy Bypass]] - -| -[https://attack.mitre.org/techniques/T1059/ T1059], -[https://attack.mitre.org/techniques/T1059.001/ T1059.001] -| -Command and Scripting Interpreter, -PowerShell -| -Execution, -Execution - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Processes_launching_netsh|Processes launching netsh]] - -| -[https://attack.mitre.org/techniques/T1562.004/ T1562.004], -[https://attack.mitre.org/techniques/T1562/ T1562] -| -Disable or Modify System Firewall, -Impair Defenses -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Registry_keys_used_for_persistence|Registry Keys Used For Persistence]] - -| -[https://attack.mitre.org/techniques/T1547.001/ T1547.001], -[https://attack.mitre.org/techniques/T1547/ T1547] -| -Registry Run Keys / Startup Folder, -Boot or Logon Autostart Execution -| -Persistence, Privilege Escalation, -Persistence, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Smb_traffic_spike|SMB Traffic Spike]] - -| -[https://attack.mitre.org/techniques/T1021.002/ T1021.002], -[https://attack.mitre.org/techniques/T1021/ T1021] -| -SMB/Windows Admin Shares, -Remote Services -| -Lateral Movement, -Lateral Movement - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Smb_traffic_spike_-_mltk|SMB Traffic Spike - MLTK]] - -| -[https://attack.mitre.org/techniques/T1021.002/ T1021.002], -[https://attack.mitre.org/techniques/T1021/ T1021] -| -SMB/Windows Admin Shares, -Remote Services -| -Lateral Movement, -Lateral Movement - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Sc_exe_manipulating_windows_services|Sc exe Manipulating Windows Services]] - -| -[https://attack.mitre.org/techniques/T1543.003/ T1543.003], -[https://attack.mitre.org/techniques/T1543/ T1543] -| -Windows Service, -Create or Modify System Process -| -Persistence, Privilege Escalation, -Persistence, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Scheduled_task_deleted_or_created_via_cmd|Scheduled Task Deleted Or Created via CMD]] - -| -[https://attack.mitre.org/techniques/T1053.005/ T1053.005], -[https://attack.mitre.org/techniques/T1053/ T1053] -| -Scheduled Task, -Scheduled Task/Job -| -Execution, Persistence, Privilege Escalation, -Execution, Persistence, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Single_letter_process_on_endpoint|Single Letter Process On Endpoint]] - -| -[https://attack.mitre.org/techniques/T1204/ T1204], -[https://attack.mitre.org/techniques/T1204.002/ T1204.002] -| -User Execution, -Malicious File -| -Execution, -Execution - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Suspicious_reg_exe_process|Suspicious Reg exe Process]] - -| -[https://attack.mitre.org/techniques/T1112/ T1112] -| -Modify Registry -| -Defense Evasion - -| TTP -|} - -====Kill Chain Phase==== - -* Actions on Objectives - -* Command and Control - -* Execution - -* Exploitation - -* Installation - -* Lateral Movement - - -====Reference==== - -* https://www.us-cert.gov/ncas/alerts/TA18-074A - - -''version'': 2 -
-
- ----- - -===Darkside ransomware=== -Leverage searches that allow you to detect and investigate unusual activities that might relate to the DarkSide Ransomware - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint] -* '''Last Updated''': 2021-05-12 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Attempted_credential_dump_from_registry_via_reg_exe|Attempted Credential Dump From Registry via Reg exe]] - -| -[https://attack.mitre.org/techniques/T1003.002/ T1003.002], -[https://attack.mitre.org/techniques/T1003/ T1003] -| -Security Account Manager, -OS Credential Dumping -| -Credential Access, -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Bitsadmin_download_file|BITSAdmin Download File]] - -| -[https://attack.mitre.org/techniques/T1197/ T1197], -[https://attack.mitre.org/techniques/T1105/ T1105] -| -BITS Jobs, -Ingress Tool Transfer -| -Defense Evasion, Persistence, -Command And Control - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Cmlua_or_cmstplua_uac_bypass|CMLUA Or CMSTPLUA UAC Bypass]] - -| -[https://attack.mitre.org/techniques/T1218/ T1218], -[https://attack.mitre.org/techniques/T1218.003/ T1218.003] -| -Signed Binary Proxy Execution, -CMSTP -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Certutil_download_with_urlcache_and_split_arguments|CertUtil Download With URLCache and Split Arguments]] - -| -[https://attack.mitre.org/techniques/T1105/ T1105] -| -Ingress Tool Transfer -| -Command And Control - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Certutil_download_with_verifyctl_and_split_arguments|CertUtil Download With VerifyCtl and Split Arguments]] - -| -[https://attack.mitre.org/techniques/T1105/ T1105] -| -Ingress Tool Transfer -| -Command And Control - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Cobalt_strike_named_pipes|Cobalt Strike Named Pipes]] - -| -[https://attack.mitre.org/techniques/T1055/ T1055] -| -Process Injection -| -Defense Evasion, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Delete_shadowcopy_with_powershell|Delete ShadowCopy With PowerShell]] - -| -[https://attack.mitre.org/techniques/T1490/ T1490] -| -Inhibit System Recovery -| -Impact - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_mimikatz_using_loaded_images|Detect Mimikatz Using Loaded Images]] - -| -[https://attack.mitre.org/techniques/T1003.001/ T1003.001], -[https://attack.mitre.org/techniques/T1003/ T1003] -| -LSASS Memory, -OS Credential Dumping -| -Credential Access, -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_psexec_with_accepteula_flag|Detect PsExec With accepteula Flag]] - -| -[https://attack.mitre.org/techniques/T1021/ T1021], -[https://attack.mitre.org/techniques/T1021.002/ T1021.002] -| -Remote Services, -SMB/Windows Admin Shares -| -Lateral Movement, -Lateral Movement - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_rclone_command-line_usage|Detect RClone Command-Line Usage]] - -| -[https://attack.mitre.org/techniques/T1020/ T1020] -| -Automated Exfiltration -| -Exfiltration - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_renamed_psexec|Detect Renamed PSExec]] - -| -[https://attack.mitre.org/techniques/T1569/ T1569], -[https://attack.mitre.org/techniques/T1569.002/ T1569.002] -| -System Services, -Service Execution -| -Execution, -Execution - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Detect_renamed_rclone|Detect Renamed RClone]] - -| -[https://attack.mitre.org/techniques/T1020/ T1020] -| -Automated Exfiltration -| -Exfiltration - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Extraction_of_registry_hives|Extraction of Registry Hives]] - -| -[https://attack.mitre.org/techniques/T1003.002/ T1003.002], -[https://attack.mitre.org/techniques/T1003/ T1003] -| -Security Account Manager, -OS Credential Dumping -| -Credential Access, -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Ransomware_notes_bulk_creation|Ransomware Notes bulk creation]] - -| -[https://attack.mitre.org/techniques/T1486/ T1486] -| -Data Encrypted for Impact -| -Impact - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Slui_runas_elevated|SLUI RunAs Elevated]] - -| -[https://attack.mitre.org/techniques/T1548.002/ T1548.002], -[https://attack.mitre.org/techniques/T1548/ T1548] -| -Bypass User Account Control, -Abuse Elevation Control Mechanism -| -Privilege Escalation, Defense Evasion, -Privilege Escalation, Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Slui_spawning_a_process|SLUI Spawning a Process]] - -| -[https://attack.mitre.org/techniques/T1548.002/ T1548.002], -[https://attack.mitre.org/techniques/T1548/ T1548] -| -Bypass User Account Control, -Abuse Elevation Control Mechanism -| -Privilege Escalation, Defense Evasion, -Privilege Escalation, Defense Evasion - -| TTP -|} - -====Kill Chain Phase==== - -* Actions on Objectives - -* Execution - -* Exfiltration - -* Exploitation - -* Lateral Movement - -* Obfuscation - - -====Reference==== - -* https://www.splunk.com/en_us/blog/security/the-darkside-of-the-ransomware-pipeline.htmlbig-game-hunting-with-ryuk-another-lucrative-targeted-ransomware/ - -* https://www.mandiant.com/resources/shining-a-light-on-darkside-ransomware-operations - - -''version'': 1 -
-
- ----- - -===Dynamic dns=== -Detect and investigate hosts in your environment that may be communicating with dynamic domain providers. Attackers may leverage these services to help them avoid firewall blocks and deny lists. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint], [https://docs.splunk.com/Documentation/CIM/latest/User/NetworkResolution Network_Resolution] -* '''Last Updated''': 2018-09-06 -* '''Use Case''': Security Monitoring - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Dns_exfiltration_using_nslookup_app|DNS Exfiltration Using Nslookup App]] - -| -[https://attack.mitre.org/techniques/T1048/ T1048] -| -Exfiltration Over Alternative Protocol -| -Exfiltration - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_hosts_connecting_to_dynamic_domain_providers|Detect hosts connecting to dynamic domain providers]] - -| -[https://attack.mitre.org/techniques/T1189/ T1189] -| -Drive-by Compromise -| -Initial Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Excessive_usage_of_nslookup_app|Excessive Usage of NSLOOKUP App]] - -| -[https://attack.mitre.org/techniques/T1048/ T1048] -| -Exfiltration Over Alternative Protocol -| -Exfiltration - -| Anomaly -|} - -====Kill Chain Phase==== - -* Actions on Objectives - -* Command and Control - -* Exploitation - - -====Reference==== - -* https://www.fireeye.com/blog/threat-research/2017/09/apt33-insights-into-iranian-cyber-espionage.html - -* https://umbrella.cisco.com/blog/2013/04/15/on-the-trail-of-malicious-dynamic-dns-domains/ - -* http://www.noip.com/blog/2014/07/11/dynamic-dns-can-use-2/ - -* https://www.splunk.com/blog/2015/08/04/detecting-dynamic-dns-domains-in-splunk.html - - -''version'': 2 -
-
- ----- - -===Emotet malware dhs report ta18-201a === -Detect rarely used executables, specific registry paths that may confer malware survivability and persistence, instances where cmd.exe is used to launch script interpreters, and other indicators that the Emotet financial malware has compromised your environment. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Email Email], [https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint], [https://docs.splunk.com/Documentation/CIM/latest/User/NetworkTraffic Network_Traffic] -* '''Last Updated''': 2020-01-27 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Detect_rare_executables|Detect Rare Executables]] - -| -| -| - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Detect_use_of_cmd_exe_to_launch_script_interpreters|Detect Use of cmd exe to Launch Script Interpreters]] - -| -[https://attack.mitre.org/techniques/T1059/ T1059], -[https://attack.mitre.org/techniques/T1059.003/ T1059.003] -| -Command and Scripting Interpreter, -Windows Command Shell -| -Execution, -Execution - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detection_of_tools_built_by_nirsoft|Detection of tools built by NirSoft]] - -| -[https://attack.mitre.org/techniques/T1072/ T1072] -| -Software Deployment Tools -| -Execution, Lateral Movement - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Email_attachments_with_lots_of_spaces|Email Attachments With Lots Of Spaces]] - -| -| -| - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Registry_keys_used_for_persistence|Registry Keys Used For Persistence]] - -| -[https://attack.mitre.org/techniques/T1547.001/ T1547.001], -[https://attack.mitre.org/techniques/T1547/ T1547] -| -Registry Run Keys / Startup Folder, -Boot or Logon Autostart Execution -| -Persistence, Privilege Escalation, -Persistence, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Smb_traffic_spike|SMB Traffic Spike]] - -| -[https://attack.mitre.org/techniques/T1021.002/ T1021.002], -[https://attack.mitre.org/techniques/T1021/ T1021] -| -SMB/Windows Admin Shares, -Remote Services -| -Lateral Movement, -Lateral Movement - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Smb_traffic_spike_-_mltk|SMB Traffic Spike - MLTK]] - -| -[https://attack.mitre.org/techniques/T1021.002/ T1021.002], -[https://attack.mitre.org/techniques/T1021/ T1021] -| -SMB/Windows Admin Shares, -Remote Services -| -Lateral Movement, -Lateral Movement - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Suspicious_email_attachment_extensions|Suspicious Email Attachment Extensions]] - -| -[https://attack.mitre.org/techniques/T1566.001/ T1566.001], -[https://attack.mitre.org/techniques/T1566/ T1566] -| -Spearphishing Attachment, -Phishing -| -Initial Access, -Initial Access - -| Anomaly -|} - -====Kill Chain Phase==== - -* Actions on Objectives - -* Command and Control - -* Delivery - -* Exploitation - -* Installation - - -====Reference==== - -* https://www.us-cert.gov/ncas/alerts/TA18-201A - -* https://www.first.org/resources/papers/conf2017/Advanced-Incident-Detection-and-Threat-Hunting-using-Sysmon-and-Splunk.pdf - -* https://www.vkremez.com/2017/05/emotet-banking-trojan-malware-analysis.html - - -''version'': 1 -
-
- ----- - -===Fin7=== -Leverage searches that allow you to detect and investigate unusual activities that might relate to the FIN7 JS Implant and JSSLoader, including looking for Image Loading of ldap and wmi modules, associated with its payload, data collection and script execution. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint] -* '''Last Updated''': 2021-09-14 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Check_elevated_cmd_using_whoami|Check Elevated CMD using whoami]] - -| -[https://attack.mitre.org/techniques/T1033/ T1033] -| -System Owner/User Discovery -| -Discovery - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Cmdline_tool_not_executed_in_cmd_shell|Cmdline Tool Not Executed In CMD Shell]] - -| -[https://attack.mitre.org/techniques/T1059/ T1059], -[https://attack.mitre.org/techniques/T1059.007/ T1059.007] -| -Command and Scripting Interpreter, -JavaScript -| -Execution, -Execution - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Jscript_execution_using_cscript_app|Jscript Execution Using Cscript App]] - -| -[https://attack.mitre.org/techniques/T1059/ T1059], -[https://attack.mitre.org/techniques/T1059.007/ T1059.007] -| -Command and Scripting Interpreter, -JavaScript -| -Execution, -Execution - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Ms_scripting_process_loading_ldap_module|MS Scripting Process Loading Ldap Module]] - -| -[https://attack.mitre.org/techniques/T1059/ T1059], -[https://attack.mitre.org/techniques/T1059.007/ T1059.007] -| -Command and Scripting Interpreter, -JavaScript -| -Execution, -Execution - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Ms_scripting_process_loading_wmi_module|MS Scripting Process Loading WMI Module]] - -| -[https://attack.mitre.org/techniques/T1059/ T1059], -[https://attack.mitre.org/techniques/T1059.007/ T1059.007] -| -Command and Scripting Interpreter, -JavaScript -| -Execution, -Execution - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Non_chrome_process_accessing_chrome_default_dir|Non Chrome Process Accessing Chrome Default Dir]] - -| -[https://attack.mitre.org/techniques/T1555/ T1555], -[https://attack.mitre.org/techniques/T1555.003/ T1555.003] -| -Credentials from Password Stores, -Credentials from Web Browsers -| -Credential Access, -Credential Access - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Non_firefox_process_access_firefox_profile_dir|Non Firefox Process Access Firefox Profile Dir]] - -| -[https://attack.mitre.org/techniques/T1555/ T1555], -[https://attack.mitre.org/techniques/T1555.003/ T1555.003] -| -Credentials from Password Stores, -Credentials from Web Browsers -| -Credential Access, -Credential Access - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Office_application_drop_executable|Office Application Drop Executable]] - -| -[https://attack.mitre.org/techniques/T1566/ T1566], -[https://attack.mitre.org/techniques/T1566.001/ T1566.001] -| -Phishing, -Spearphishing Attachment -| -Initial Access, -Initial Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Office_product_spawning_wmic|Office Product Spawning Wmic]] - -| -[https://attack.mitre.org/techniques/T1566/ T1566], -[https://attack.mitre.org/techniques/T1566.001/ T1566.001] -| -Phishing, -Spearphishing Attachment -| -Initial Access, -Initial Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Vbscript_execution_using_wscript_app|Vbscript Execution Using Wscript App]] - -| -[https://attack.mitre.org/techniques/T1059.005/ T1059.005], -[https://attack.mitre.org/techniques/T1059/ T1059] -| -Visual Basic, -Command and Scripting Interpreter -| -Execution, -Execution - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Wscript_or_cscript_suspicious_child_process|Wscript Or Cscript Suspicious Child Process]] - -| -[https://attack.mitre.org/techniques/T1055/ T1055], -[https://attack.mitre.org/techniques/T1543/ T1543], -[https://attack.mitre.org/techniques/T1134.004/ T1134.004], -[https://attack.mitre.org/techniques/T1134/ T1134] -| -Process Injection, -Create or Modify System Process, -Parent PID Spoofing, -Access Token Manipulation -| -Defense Evasion, Privilege Escalation, -Persistence, Privilege Escalation, -Defense Evasion, Privilege Escalation, -Defense Evasion, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Xsl_script_execution_with_wmic|XSL Script Execution With WMIC]] - -| -[https://attack.mitre.org/techniques/T1220/ T1220] -| -XSL Script Processing -| -Defense Evasion - -| TTP -|} - -====Kill Chain Phase==== - -* Exploitation - - -====Reference==== - -* https://en.wikipedia.org/wiki/FIN7 - -* https://threatpost.com/fin7-windows-11-release/169206/ - -* https://www.proofpoint.com/us/blog/threat-insight/jssloader-recoded-and-reloaded - - -''version'': 1 -
-
- ----- - -===Hidden cobra malware=== -Monitor for and investigate activities, including the creation or deletion of hidden shares and file writes, that may be evidence of infiltration by North Korean government-sponsored cybercriminals. Details of this activity were reported in DHS Report TA-18-149A. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint], [https://docs.splunk.com/Documentation/CIM/latest/User/NetworkResolution Network_Resolution], [https://docs.splunk.com/Documentation/CIM/latest/User/NetworkTraffic Network_Traffic] -* '''Last Updated''': 2020-01-22 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Create_or_delete_windows_shares_using_net_exe|Create or delete windows shares using net exe]] - -| -[https://attack.mitre.org/techniques/T1070/ T1070], -[https://attack.mitre.org/techniques/T1070.005/ T1070.005] -| -Indicator Removal on Host, -Network Share Connection Removal -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Dns_query_length_outliers_-_mltk|DNS Query Length Outliers - MLTK]] - -| -[https://attack.mitre.org/techniques/T1071.004/ T1071.004], -[https://attack.mitre.org/techniques/T1071/ T1071] -| -DNS, -Application Layer Protocol -| -Command And Control, -Command And Control - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Dns_query_length_with_high_standard_deviation|DNS Query Length With High Standard Deviation]] - -| -[https://attack.mitre.org/techniques/T1048.003/ T1048.003], -[https://attack.mitre.org/techniques/T1048/ T1048] -| -Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol, -Exfiltration Over Alternative Protocol -| -Exfiltration, -Exfiltration - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Detect_outbound_smb_traffic|Detect Outbound SMB Traffic]] - -| -[https://attack.mitre.org/techniques/T1071.002/ T1071.002], -[https://attack.mitre.org/techniques/T1071/ T1071] -| -File Transfer Protocols, -Application Layer Protocol -| -Command And Control, -Command And Control - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Remote_desktop_network_traffic|Remote Desktop Network Traffic]] - -| -[https://attack.mitre.org/techniques/T1021.001/ T1021.001], -[https://attack.mitre.org/techniques/T1021/ T1021] -| -Remote Desktop Protocol, -Remote Services -| -Lateral Movement, -Lateral Movement - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Remote_desktop_process_running_on_system|Remote Desktop Process Running On System]] - -| -[https://attack.mitre.org/techniques/T1021.001/ T1021.001], -[https://attack.mitre.org/techniques/T1021/ T1021] -| -Remote Desktop Protocol, -Remote Services -| -Lateral Movement, -Lateral Movement - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Smb_traffic_spike|SMB Traffic Spike]] - -| -[https://attack.mitre.org/techniques/T1021.002/ T1021.002], -[https://attack.mitre.org/techniques/T1021/ T1021] -| -SMB/Windows Admin Shares, -Remote Services -| -Lateral Movement, -Lateral Movement - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Smb_traffic_spike_-_mltk|SMB Traffic Spike - MLTK]] - -| -[https://attack.mitre.org/techniques/T1021.002/ T1021.002], -[https://attack.mitre.org/techniques/T1021/ T1021] -| -SMB/Windows Admin Shares, -Remote Services -| -Lateral Movement, -Lateral Movement - -| Anomaly -|} - -====Kill Chain Phase==== - -* Actions on Objectives - -* Command and Control - - -====Reference==== - -* https://www.us-cert.gov/HIDDEN-COBRA-North-Korean-Malicious-Cyber-Activity - -* https://www.operationblockbuster.com/wp-content/uploads/2016/02/Operation-Blockbuster-Destructive-Malware-Report.pdf - - -''version'': 2 -
-
- ----- - -===Icedid=== -Leverage searches that allow you to detect and investigate unusual activities that might relate to the IcedID banking trojan, including looking for file writes associated with its payload, process injection, shellcode execution and data collection. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint] -* '''Last Updated''': 2021-07-29 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Account_discovery_with_net_app|Account Discovery With Net App]] - -| -[https://attack.mitre.org/techniques/T1087.002/ T1087.002], -[https://attack.mitre.org/techniques/T1087/ T1087] -| -Domain Account, -Account Discovery -| -Discovery, -Discovery - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Chcp_command_execution|CHCP Command Execution]] - -| -[https://attack.mitre.org/techniques/T1059/ T1059] -| -Command and Scripting Interpreter -| -Execution - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Create_remote_thread_in_shell_application|Create Remote Thread In Shell Application]] - -| -[https://attack.mitre.org/techniques/T1055/ T1055] -| -Process Injection -| -Defense Evasion, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Drop_icedid_license_dat|Drop IcedID License dat]] - -| -[https://attack.mitre.org/techniques/T1204/ T1204], -[https://attack.mitre.org/techniques/T1204.002/ T1204.002] -| -User Execution, -Malicious File -| -Execution, -Execution - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Eventvwr_uac_bypass|Eventvwr UAC Bypass]] - -| -[https://attack.mitre.org/techniques/T1548.002/ T1548.002], -[https://attack.mitre.org/techniques/T1548/ T1548] -| -Bypass User Account Control, -Abuse Elevation Control Mechanism -| -Privilege Escalation, Defense Evasion, -Privilege Escalation, Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Fodhelper_uac_bypass|FodHelper UAC Bypass]] - -| -[https://attack.mitre.org/techniques/T1112/ T1112], -[https://attack.mitre.org/techniques/T1548.002/ T1548.002], -[https://attack.mitre.org/techniques/T1548/ T1548] -| -Modify Registry, -Bypass User Account Control, -Abuse Elevation Control Mechanism -| -Defense Evasion, -Privilege Escalation, Defense Evasion, -Privilege Escalation, Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Icedid_exfiltrated_archived_file_creation|IcedID Exfiltrated Archived File Creation]] - -| -[https://attack.mitre.org/techniques/T1560.001/ T1560.001], -[https://attack.mitre.org/techniques/T1560/ T1560] -| -Archive via Utility, -Archive Collected Data -| -Collection, -Collection - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Mshta_spawning_rundll32_or_regsvr32_process|Mshta spawning Rundll32 OR Regsvr32 Process]] - -| -[https://attack.mitre.org/techniques/T1218/ T1218], -[https://attack.mitre.org/techniques/T1218.005/ T1218.005] -| -Signed Binary Proxy Execution, -Mshta -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Nltest_domain_trust_discovery|NLTest Domain Trust Discovery]] - -| -[https://attack.mitre.org/techniques/T1482/ T1482] -| -Domain Trust Discovery -| -Discovery - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Office_application_spawn_regsvr32_process|Office Application Spawn Regsvr32 process]] - -| -[https://attack.mitre.org/techniques/T1566/ T1566], -[https://attack.mitre.org/techniques/T1566.001/ T1566.001] -| -Phishing, -Spearphishing Attachment -| -Initial Access, -Initial Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Office_application_spawn_rundll32_process|Office Application Spawn rundll32 process]] - -| -[https://attack.mitre.org/techniques/T1566/ T1566], -[https://attack.mitre.org/techniques/T1566.001/ T1566.001] -| -Phishing, -Spearphishing Attachment -| -Initial Access, -Initial Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Office_document_executing_macro_code|Office Document Executing Macro Code]] - -| -[https://attack.mitre.org/techniques/T1566/ T1566], -[https://attack.mitre.org/techniques/T1566.001/ T1566.001] -| -Phishing, -Spearphishing Attachment -| -Initial Access, -Initial Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Office_product_spawning_mshta|Office Product Spawning MSHTA]] - -| -[https://attack.mitre.org/techniques/T1566/ T1566], -[https://attack.mitre.org/techniques/T1566.001/ T1566.001] -| -Phishing, -Spearphishing Attachment -| -Initial Access, -Initial Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Registry_keys_used_for_persistence|Registry Keys Used For Persistence]] - -| -[https://attack.mitre.org/techniques/T1547.001/ T1547.001], -[https://attack.mitre.org/techniques/T1547/ T1547] -| -Registry Run Keys / Startup Folder, -Boot or Logon Autostart Execution -| -Persistence, Privilege Escalation, -Persistence, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Rundll32_create_remote_thread_to_a_process|Rundll32 Create Remote Thread To A Process]] - -| -[https://attack.mitre.org/techniques/T1055/ T1055] -| -Process Injection -| -Defense Evasion, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Rundll32_createremotethread_in_browser|Rundll32 CreateRemoteThread In Browser]] - -| -[https://attack.mitre.org/techniques/T1055/ T1055] -| -Process Injection -| -Defense Evasion, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Rundll32_dnsquery|Rundll32 DNSQuery]] - -| -[https://attack.mitre.org/techniques/T1218/ T1218], -[https://attack.mitre.org/techniques/T1218.011/ T1218.011] -| -Signed Binary Proxy Execution, -Rundll32 -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Rundll32_process_creating_exe_dll_files|Rundll32 Process Creating Exe Dll Files]] - -| -[https://attack.mitre.org/techniques/T1218/ T1218], -[https://attack.mitre.org/techniques/T1218.011/ T1218.011] -| -Signed Binary Proxy Execution, -Rundll32 -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Schedule_task_with_rundll32_command_trigger|Schedule Task with Rundll32 Command Trigger]] - -| -[https://attack.mitre.org/techniques/T1053/ T1053] -| -Scheduled Task/Job -| -Execution, Persistence, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Sqlite_module_in_temp_folder|Sqlite Module In Temp Folder]] - -| -[https://attack.mitre.org/techniques/T1005/ T1005] -| -Data from Local System -| -Collection - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Suspicious_icedid_regsvr32_cmdline|Suspicious IcedID Regsvr32 Cmdline]] - -| -[https://attack.mitre.org/techniques/T1218/ T1218], -[https://attack.mitre.org/techniques/T1218.010/ T1218.010] -| -Signed Binary Proxy Execution, -Regsvr32 -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Suspicious_icedid_rundll32_cmdline|Suspicious IcedID Rundll32 Cmdline]] - -| -[https://attack.mitre.org/techniques/T1218/ T1218], -[https://attack.mitre.org/techniques/T1218.011/ T1218.011] -| -Signed Binary Proxy Execution, -Rundll32 -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Suspicious_rundll32_plugininit|Suspicious Rundll32 PluginInit]] - -| -[https://attack.mitre.org/techniques/T1218/ T1218], -[https://attack.mitre.org/techniques/T1218.011/ T1218.011] -| -Signed Binary Proxy Execution, -Rundll32 -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Winevent_scheduled_task_created_within_public_path|WinEvent Scheduled Task Created Within Public Path]] - -| -[https://attack.mitre.org/techniques/T1053.005/ T1053.005], -[https://attack.mitre.org/techniques/T1053/ T1053] -| -Scheduled Task, -Scheduled Task/Job -| -Execution, Persistence, Privilege Escalation, -Execution, Persistence, Privilege Escalation - -| TTP -|} - -====Kill Chain Phase==== - -* Actions on Objectives - -* Exploitation - -* Privilege Escalation - -* Reconnaissance - - -====Reference==== - -* https://threatpost.com/icedid-banking-trojan-surges-emotet/165314/ - -* https://app.any.run/tasks/48414a33-3d66-4a46-afe5-c2003bb55ccf/ - - -''version'': 1 -
-
- ----- - -===Orangeworm attack group=== -Detect activities and various techniques associated with the Orangeworm Attack Group, a group that frequently targets the healthcare industry. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint] -* '''Last Updated''': 2020-01-22 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#First_time_seen_running_windows_service|First Time Seen Running Windows Service]] - -| -[https://attack.mitre.org/techniques/T1569/ T1569], -[https://attack.mitre.org/techniques/T1569.002/ T1569.002] -| -System Services, -Service Execution -| -Execution, -Execution - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Sc_exe_manipulating_windows_services|Sc exe Manipulating Windows Services]] - -| -[https://attack.mitre.org/techniques/T1543.003/ T1543.003], -[https://attack.mitre.org/techniques/T1543/ T1543] -| -Windows Service, -Create or Modify System Process -| -Persistence, Privilege Escalation, -Persistence, Privilege Escalation - -| TTP -|} - -====Kill Chain Phase==== - -* Actions on Objectives - -* Installation - - -====Reference==== - -* https://www.symantec.com/blogs/threat-intelligence/orangeworm-targets-healthcare-us-europe-asia - -* https://www.infosecurity-magazine.com/news/healthcare-targeted-by-hacker/ - - -''version'': 2 -
-
- ----- - -===Ransomware=== -Leverage searches that allow you to detect and investigate unusual activities that might relate to ransomware--spikes in SMB traffic, suspicious wevtutil usage, the presence of common ransomware extensions, and system processes run from unexpected locations, and many others. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint], [https://docs.splunk.com/Documentation/CIM/latest/User/NetworkTraffic Network_Traffic] -* '''Last Updated''': 2020-02-04 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#7zip_commandline_to_smb_share_path|7zip CommandLine To SMB Share Path]] - -| -[https://attack.mitre.org/techniques/T1560.001/ T1560.001], -[https://attack.mitre.org/techniques/T1560/ T1560] -| -Archive via Utility, -Archive Collected Data -| -Collection, -Collection - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Allow_file_and_printing_sharing_in_firewall|Allow File And Printing Sharing In Firewall]] - -| -[https://attack.mitre.org/techniques/T1562.007/ T1562.007], -[https://attack.mitre.org/techniques/T1562/ T1562] -| -Disable or Modify Cloud Firewall, -Impair Defenses -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Allow_network_discovery_in_firewall|Allow Network Discovery In Firewall]] - -| -[https://attack.mitre.org/techniques/T1562.007/ T1562.007], -[https://attack.mitre.org/techniques/T1562/ T1562] -| -Disable or Modify Cloud Firewall, -Impair Defenses -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Allow_operation_with_consent_admin|Allow Operation with Consent Admin]] - -| -[https://attack.mitre.org/techniques/T1548/ T1548] -| -Abuse Elevation Control Mechanism -| -Privilege Escalation, Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Attempt_to_disable_services|Attempt To Disable Services]] - -| -[https://attack.mitre.org/techniques/T1489/ T1489] -| -Service Stop -| -Impact - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Attempt_to_delete_services|Attempt To delete Services]] - -| -[https://attack.mitre.org/techniques/T1489/ T1489] -| -Service Stop -| -Impact - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Bcdedit_failure_recovery_modification|BCDEdit Failure Recovery Modification]] - -| -[https://attack.mitre.org/techniques/T1490/ T1490] -| -Inhibit System Recovery -| -Impact - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Cmlua_or_cmstplua_uac_bypass|CMLUA Or CMSTPLUA UAC Bypass]] - -| -[https://attack.mitre.org/techniques/T1218/ T1218], -[https://attack.mitre.org/techniques/T1218.003/ T1218.003] -| -Signed Binary Proxy Execution, -CMSTP -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Clear_unallocated_sector_using_cipher_app|Clear Unallocated Sector Using Cipher App]] - -| -[https://attack.mitre.org/techniques/T1070.004/ T1070.004], -[https://attack.mitre.org/techniques/T1070/ T1070] -| -File Deletion, -Indicator Removal on Host -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Common_ransomware_extensions|Common Ransomware Extensions]] - -| -[https://attack.mitre.org/techniques/T1485/ T1485] -| -Data Destruction -| -Impact - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Common_ransomware_notes|Common Ransomware Notes]] - -| -[https://attack.mitre.org/techniques/T1485/ T1485] -| -Data Destruction -| -Impact - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Conti_common_exec_parameter|Conti Common Exec parameter]] - -| -[https://attack.mitre.org/techniques/T1204/ T1204] -| -User Execution -| -Execution - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Delete_a_net_user|Delete A Net User]] - -| -[https://attack.mitre.org/techniques/T1489/ T1489] -| -Service Stop -| -Impact - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Delete_shadowcopy_with_powershell|Delete ShadowCopy With PowerShell]] - -| -[https://attack.mitre.org/techniques/T1490/ T1490] -| -Inhibit System Recovery -| -Impact - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Deleting_shadow_copies|Deleting Shadow Copies]] - -| -[https://attack.mitre.org/techniques/T1490/ T1490] -| -Inhibit System Recovery -| -Impact - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_rclone_command-line_usage|Detect RClone Command-Line Usage]] - -| -[https://attack.mitre.org/techniques/T1020/ T1020] -| -Automated Exfiltration -| -Exfiltration - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_renamed_rclone|Detect Renamed RClone]] - -| -[https://attack.mitre.org/techniques/T1020/ T1020] -| -Automated Exfiltration -| -Exfiltration - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Detect_sharphound_command-line_arguments|Detect SharpHound Command-Line Arguments]] - -| -[https://attack.mitre.org/techniques/T1087.002/ T1087.002], -[https://attack.mitre.org/techniques/T1069.001/ T1069.001], -[https://attack.mitre.org/techniques/T1482/ T1482], -[https://attack.mitre.org/techniques/T1087.001/ T1087.001], -[https://attack.mitre.org/techniques/T1087/ T1087], -[https://attack.mitre.org/techniques/T1069.002/ T1069.002], -[https://attack.mitre.org/techniques/T1069/ T1069] -| -Domain Account, -Local Groups, -Domain Trust Discovery, -Local Account, -Account Discovery, -Domain Groups, -Permission Groups Discovery -| -Discovery, -Discovery, -Discovery, -Discovery, -Discovery, -Discovery, -Discovery - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_sharphound_file_modifications|Detect SharpHound File Modifications]] - -| -[https://attack.mitre.org/techniques/T1087.002/ T1087.002], -[https://attack.mitre.org/techniques/T1069.001/ T1069.001], -[https://attack.mitre.org/techniques/T1482/ T1482], -[https://attack.mitre.org/techniques/T1087.001/ T1087.001], -[https://attack.mitre.org/techniques/T1087/ T1087], -[https://attack.mitre.org/techniques/T1069.002/ T1069.002], -[https://attack.mitre.org/techniques/T1069/ T1069] -| -Domain Account, -Local Groups, -Domain Trust Discovery, -Local Account, -Account Discovery, -Domain Groups, -Permission Groups Discovery -| -Discovery, -Discovery, -Discovery, -Discovery, -Discovery, -Discovery, -Discovery - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_sharphound_usage|Detect SharpHound Usage]] - -| -[https://attack.mitre.org/techniques/T1087.002/ T1087.002], -[https://attack.mitre.org/techniques/T1069.001/ T1069.001], -[https://attack.mitre.org/techniques/T1482/ T1482], -[https://attack.mitre.org/techniques/T1087.001/ T1087.001], -[https://attack.mitre.org/techniques/T1087/ T1087], -[https://attack.mitre.org/techniques/T1069.002/ T1069.002], -[https://attack.mitre.org/techniques/T1069/ T1069] -| -Domain Account, -Local Groups, -Domain Trust Discovery, -Local Account, -Account Discovery, -Domain Groups, -Permission Groups Discovery -| -Discovery, -Discovery, -Discovery, -Discovery, -Discovery, -Discovery, -Discovery - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Disable_amsi_through_registry|Disable AMSI Through Registry]] - -| -[https://attack.mitre.org/techniques/T1562.001/ T1562.001], -[https://attack.mitre.org/techniques/T1562/ T1562] -| -Disable or Modify Tools, -Impair Defenses -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Disable_etw_through_registry|Disable ETW Through Registry]] - -| -[https://attack.mitre.org/techniques/T1562.001/ T1562.001], -[https://attack.mitre.org/techniques/T1562/ T1562] -| -Disable or Modify Tools, -Impair Defenses -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Disable_logs_using_wevtutil|Disable Logs Using WevtUtil]] - -| -[https://attack.mitre.org/techniques/T1070/ T1070], -[https://attack.mitre.org/techniques/T1070.001/ T1070.001] -| -Indicator Removal on Host, -Clear Windows Event Logs -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Disable_net_user_account|Disable Net User Account]] - -| -[https://attack.mitre.org/techniques/T1489/ T1489] -| -Service Stop -| -Impact - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Disable_windows_behavior_monitoring|Disable Windows Behavior Monitoring]] - -| -[https://attack.mitre.org/techniques/T1562.001/ T1562.001], -[https://attack.mitre.org/techniques/T1562/ T1562] -| -Disable or Modify Tools, -Impair Defenses -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Excessive_service_stop_attempt|Excessive Service Stop Attempt]] - -| -[https://attack.mitre.org/techniques/T1489/ T1489] -| -Service Stop -| -Impact - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Excessive_usage_of_net_app|Excessive Usage Of Net App]] - -| -[https://attack.mitre.org/techniques/T1531/ T1531] -| -Account Access Removal -| -Impact - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Excessive_usage_of_sc_service_utility|Excessive Usage Of SC Service Utility]] - -| -[https://attack.mitre.org/techniques/T1569/ T1569], -[https://attack.mitre.org/techniques/T1569.002/ T1569.002] -| -System Services, -Service Execution -| -Execution, -Execution - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Execute_javascript_with_jscript_com_clsid|Execute Javascript With Jscript COM CLSID]] - -| -[https://attack.mitre.org/techniques/T1059/ T1059], -[https://attack.mitre.org/techniques/T1059.005/ T1059.005] -| -Command and Scripting Interpreter, -Visual Basic -| -Execution, -Execution - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Fsutil_zeroing_file|Fsutil Zeroing File]] - -| -[https://attack.mitre.org/techniques/T1070/ T1070] -| -Indicator Removal on Host -| -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Icacls_grant_command|ICACLS Grant Command]] - -| -[https://attack.mitre.org/techniques/T1222/ T1222] -| -File and Directory Permissions Modification -| -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Known_services_killed_by_ransomware|Known Services Killed by Ransomware]] - -| -[https://attack.mitre.org/techniques/T1490/ T1490] -| -Inhibit System Recovery -| -Impact - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Modification_of_wallpaper|Modification Of Wallpaper]] - -| -[https://attack.mitre.org/techniques/T1491/ T1491] -| -Defacement -| -Impact - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Msmpeng_application_dll_side_loading|Msmpeng Application DLL Side Loading]] - -| -[https://attack.mitre.org/techniques/T1574.002/ T1574.002], -[https://attack.mitre.org/techniques/T1574/ T1574] -| -DLL Side-Loading, -Hijack Execution Flow -| -Persistence, Privilege Escalation, Defense Evasion, -Persistence, Privilege Escalation, Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Permission_modification_using_takeown_app|Permission Modification using Takeown App]] - -| -[https://attack.mitre.org/techniques/T1222/ T1222] -| -File and Directory Permissions Modification -| -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Powershell_disable_security_monitoring|Powershell Disable Security Monitoring]] - -| -[https://attack.mitre.org/techniques/T1562.001/ T1562.001], -[https://attack.mitre.org/techniques/T1562/ T1562] -| -Disable or Modify Tools, -Impair Defenses -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Powershell_enable_smb1protocol_feature|Powershell Enable SMB1Protocol Feature]] - -| -[https://attack.mitre.org/techniques/T1027/ T1027], -[https://attack.mitre.org/techniques/T1027.005/ T1027.005] -| -Obfuscated Files or Information, -Indicator Removal from Tools -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Powershell_execute_com_object|Powershell Execute COM Object]] - -| -[https://attack.mitre.org/techniques/T1546.015/ T1546.015], -[https://attack.mitre.org/techniques/T1546/ T1546] -| -Component Object Model Hijacking, -Event Triggered Execution -| -Privilege Escalation, Persistence, -Privilege Escalation, Persistence - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Prevent_automatic_repair_mode_using_bcdedit|Prevent Automatic Repair Mode using Bcdedit]] - -| -[https://attack.mitre.org/techniques/T1490/ T1490] -| -Inhibit System Recovery -| -Impact - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Prohibited_network_traffic_allowed|Prohibited Network Traffic Allowed]] - -| -[https://attack.mitre.org/techniques/T1048/ T1048] -| -Exfiltration Over Alternative Protocol -| -Exfiltration - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Recon_avproduct_through_pwh_or_wmi|Recon AVProduct Through Pwh or WMI]] - -| -[https://attack.mitre.org/techniques/T1592/ T1592] -| -Gather Victim Host Information -| -Reconnaissance - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Recursive_delete_of_directory_in_batch_cmd|Recursive Delete of Directory In Batch CMD]] - -| -[https://attack.mitre.org/techniques/T1070.004/ T1070.004], -[https://attack.mitre.org/techniques/T1070/ T1070] -| -File Deletion, -Indicator Removal on Host -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Registry_keys_used_for_persistence|Registry Keys Used For Persistence]] - -| -[https://attack.mitre.org/techniques/T1547.001/ T1547.001], -[https://attack.mitre.org/techniques/T1547/ T1547] -| -Registry Run Keys / Startup Folder, -Boot or Logon Autostart Execution -| -Persistence, Privilege Escalation, -Persistence, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Remote_process_instantiation_via_wmi|Remote Process Instantiation via WMI]] - -| -[https://attack.mitre.org/techniques/T1047/ T1047] -| -Windows Management Instrumentation -| -Execution - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Resize_shadowstorage_volume|Resize Shadowstorage Volume]] - -| -[https://attack.mitre.org/techniques/T1489/ T1489] -| -Service Stop -| -Impact - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Revil_common_exec_parameter|Revil Common Exec Parameter]] - -| -[https://attack.mitre.org/techniques/T1204/ T1204] -| -User Execution -| -Execution - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Revil_registry_entry|Revil Registry Entry]] - -| -[https://attack.mitre.org/techniques/T1112/ T1112] -| -Modify Registry -| -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Smb_traffic_spike|SMB Traffic Spike]] - -| -[https://attack.mitre.org/techniques/T1021.002/ T1021.002], -[https://attack.mitre.org/techniques/T1021/ T1021] -| -SMB/Windows Admin Shares, -Remote Services -| -Lateral Movement, -Lateral Movement - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Smb_traffic_spike_-_mltk|SMB Traffic Spike - MLTK]] - -| -[https://attack.mitre.org/techniques/T1021.002/ T1021.002], -[https://attack.mitre.org/techniques/T1021/ T1021] -| -SMB/Windows Admin Shares, -Remote Services -| -Lateral Movement, -Lateral Movement - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Schtasks_used_for_forcing_a_reboot|Schtasks used for forcing a reboot]] - -| -[https://attack.mitre.org/techniques/T1053.005/ T1053.005], -[https://attack.mitre.org/techniques/T1053/ T1053] -| -Scheduled Task, -Scheduled Task/Job -| -Execution, Persistence, Privilege Escalation, -Execution, Persistence, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Spike_in_file_writes|Spike in File Writes]] - -| -| -| - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Start_up_during_safe_mode_boot|Start Up During Safe Mode Boot]] - -| -[https://attack.mitre.org/techniques/T1547.001/ T1547.001], -[https://attack.mitre.org/techniques/T1547/ T1547] -| -Registry Run Keys / Startup Folder, -Boot or Logon Autostart Execution -| -Persistence, Privilege Escalation, -Persistence, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Suspicious_event_log_service_behavior|Suspicious Event Log Service Behavior]] - -| -[https://attack.mitre.org/techniques/T1070/ T1070], -[https://attack.mitre.org/techniques/T1070.001/ T1070.001] -| -Indicator Removal on Host, -Clear Windows Event Logs -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Suspicious_scheduled_task_from_public_directory|Suspicious Scheduled Task from Public Directory]] - -| -[https://attack.mitre.org/techniques/T1053.005/ T1053.005], -[https://attack.mitre.org/techniques/T1053/ T1053] -| -Scheduled Task, -Scheduled Task/Job -| -Execution, Persistence, Privilege Escalation, -Execution, Persistence, Privilege Escalation - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Suspicious_wevtutil_usage|Suspicious wevtutil Usage]] - -| -[https://attack.mitre.org/techniques/T1070.001/ T1070.001], -[https://attack.mitre.org/techniques/T1070/ T1070] -| -Clear Windows Event Logs, -Indicator Removal on Host -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#System_processes_run_from_unexpected_locations|System Processes Run From Unexpected Locations]] - -| -[https://attack.mitre.org/techniques/T1036/ T1036], -[https://attack.mitre.org/techniques/T1036.003/ T1036.003] -| -Masquerading, -Rename System Utilities -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Tor_traffic|TOR Traffic]] - -| -[https://attack.mitre.org/techniques/T1071/ T1071], -[https://attack.mitre.org/techniques/T1071.001/ T1071.001] -| -Application Layer Protocol, -Web Protocols -| -Command And Control, -Command And Control - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Uac_bypass_with_colorui_com_object|UAC Bypass With Colorui COM Object]] - -| -[https://attack.mitre.org/techniques/T1218/ T1218], -[https://attack.mitre.org/techniques/T1218.003/ T1218.003] -| -Signed Binary Proxy Execution, -CMSTP -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Usn_journal_deletion|USN Journal Deletion]] - -| -[https://attack.mitre.org/techniques/T1070/ T1070] -| -Indicator Removal on Host -| -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Uninstall_app_using_msiexec|Uninstall App Using MsiExec]] - -| -[https://attack.mitre.org/techniques/T1218.007/ T1218.007], -[https://attack.mitre.org/techniques/T1218/ T1218] -| -Msiexec, -Signed Binary Proxy Execution -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Unusually_long_command_line|Unusually Long Command Line]] - -| -| -| - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Unusually_long_command_line_-_mltk|Unusually Long Command Line - MLTK]] - -| -| -| - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Wbadmin_delete_system_backups|WBAdmin Delete System Backups]] - -| -[https://attack.mitre.org/techniques/T1490/ T1490] -| -Inhibit System Recovery -| -Impact - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Wbemprox_com_object_execution|Wbemprox COM Object Execution]] - -| -[https://attack.mitre.org/techniques/T1218/ T1218], -[https://attack.mitre.org/techniques/T1218.003/ T1218.003] -| -Signed Binary Proxy Execution, -CMSTP -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Wevtutil_usage_to_clear_logs|WevtUtil Usage To Clear Logs]] - -| -[https://attack.mitre.org/techniques/T1070/ T1070], -[https://attack.mitre.org/techniques/T1070.001/ T1070.001] -| -Indicator Removal on Host, -Clear Windows Event Logs -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Wevtutil_usage_to_disable_logs|Wevtutil Usage To Disable Logs]] - -| -[https://attack.mitre.org/techniques/T1070/ T1070], -[https://attack.mitre.org/techniques/T1070.001/ T1070.001] -| -Indicator Removal on Host, -Clear Windows Event Logs -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Winevent_scheduled_task_created_within_public_path|WinEvent Scheduled Task Created Within Public Path]] - -| -[https://attack.mitre.org/techniques/T1053.005/ T1053.005], -[https://attack.mitre.org/techniques/T1053/ T1053] -| -Scheduled Task, -Scheduled Task/Job -| -Execution, Persistence, Privilege Escalation, -Execution, Persistence, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Winevent_scheduled_task_created_to_spawn_shell|WinEvent Scheduled Task Created to Spawn Shell]] - -| -[https://attack.mitre.org/techniques/T1053.005/ T1053.005], -[https://attack.mitre.org/techniques/T1053/ T1053] -| -Scheduled Task, -Scheduled Task/Job -| -Execution, Persistence, Privilege Escalation, -Execution, Persistence, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Windows_event_log_cleared|Windows Event Log Cleared]] - -| -[https://attack.mitre.org/techniques/T1070/ T1070], -[https://attack.mitre.org/techniques/T1070.001/ T1070.001] -| -Indicator Removal on Host, -Clear Windows Event Logs -| -Defense Evasion, -Defense Evasion - -| TTP -|} - -====Kill Chain Phase==== - -* Actions on Objectives - -* Command and Control - -* Delivery - -* Exfiltration - -* Exploitation - -* Privilege Escalation - -* Reconnaissance - - -====Reference==== - -* https://www.carbonblack.com/2017/06/28/carbon-black-threat-research-technical-analysis-petya-notpetya-ransomware/ - -* https://www.splunk.com/blog/2017/06/27/closing-the-detection-to-mitigation-gap-or-to-petya-or-notpetya-whocares-.html - - -''version'': 1 -
-
- ----- - -===Ransomware cloud=== -Leverage searches that allow you to detect and investigate unusual activities that might relate to ransomware. These searches include cloud related objects that may be targeted by malicious actors via cloud providers own encryption features. - -* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''Last Updated''': 2020-10-27 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Aws_detect_users_creating_keys_with_encrypt_policy_without_mfa|AWS Detect Users creating keys with encrypt policy without MFA]] - -| -[https://attack.mitre.org/techniques/T1486/ T1486] -| -Data Encrypted for Impact -| -Impact - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Aws_detect_users_with_kms_keys_performing_encryption_s3|AWS Detect Users with KMS keys performing encryption S3]] - -| -[https://attack.mitre.org/techniques/T1486/ T1486] -| -Data Encrypted for Impact -| -Impact - -| Anomaly -|} - -====Kill Chain Phase==== - - -====Reference==== - -* https://rhinosecuritylabs.com/aws/s3-ransomware-part-1-attack-vector/ - -* https://github.com/d1vious/git-wild-hunt - -* https://www.youtube.com/watch?v=PgzNib37g0M - - -''version'': 1 -
-
- ----- - -===Remcos=== -Leverage searches that allow you to detect and investigate unusual activities that might relate to the Remcos RAT trojan, including looking for file writes associated with its payload, screencapture, registry modification, UAC bypassed, persistence and data collection.. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint] -* '''Last Updated''': 2021-09-23 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Disabling_remote_user_account_control|Disabling Remote User Account Control]] - -| -[https://attack.mitre.org/techniques/T1548.002/ T1548.002], -[https://attack.mitre.org/techniques/T1548/ T1548] -| -Bypass User Account Control, -Abuse Elevation Control Mechanism -| -Privilege Escalation, Defense Evasion, -Privilege Escalation, Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Executables_or_script_creation_in_suspicious_path|Executables Or Script Creation In Suspicious Path]] - -| -[https://attack.mitre.org/techniques/T1036/ T1036] -| -Masquerading -| -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Malicious_inprocserver32_modification|Malicious InProcServer32 Modification]] - -| -[https://attack.mitre.org/techniques/T1218.010/ T1218.010], -[https://attack.mitre.org/techniques/T1112/ T1112] -| -Regsvr32, -Modify Registry -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Process_deleting_its_process_file_path|Process Deleting Its Process File Path]] - -| -[https://attack.mitre.org/techniques/T1070/ T1070] -| -Indicator Removal on Host -| -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Process_writing_dynamicwrapperx|Process Writing DynamicWrapperX]] - -| -[https://attack.mitre.org/techniques/T1059/ T1059], -[https://attack.mitre.org/techniques/T1559.001/ T1559.001] -| -Command and Scripting Interpreter, -Component Object Model -| -Execution, -Execution - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Registry_keys_used_for_persistence|Registry Keys Used For Persistence]] - -| -[https://attack.mitre.org/techniques/T1547.001/ T1547.001], -[https://attack.mitre.org/techniques/T1547/ T1547] -| -Registry Run Keys / Startup Folder, -Boot or Logon Autostart Execution -| -Persistence, Privilege Escalation, -Persistence, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Remcos_rat_file_creation_in_remcos_folder|Remcos RAT File Creation in Remcos Folder]] - -| -[https://attack.mitre.org/techniques/T1113/ T1113] -| -Screen Capture -| -Collection - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Remcos_client_registry_install_entry|Remcos client registry install entry]] - -| -[https://attack.mitre.org/techniques/T1112/ T1112] -| -Modify Registry -| -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Suspicious_image_creation_in_appdata_folder|Suspicious Image Creation In Appdata Folder]] - -| -[https://attack.mitre.org/techniques/T1113/ T1113] -| -Screen Capture -| -Collection - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Suspicious_process_file_path|Suspicious Process File Path]] - -| -[https://attack.mitre.org/techniques/T1543/ T1543] -| -Create or Modify System Process -| -Persistence, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Suspicious_wav_file_in_appdata_folder|Suspicious WAV file in Appdata Folder]] - -| -[https://attack.mitre.org/techniques/T1113/ T1113] -| -Screen Capture -| -Collection - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Vbscript_execution_using_wscript_app|Vbscript Execution Using Wscript App]] - -| -[https://attack.mitre.org/techniques/T1059.005/ T1059.005], -[https://attack.mitre.org/techniques/T1059/ T1059] -| -Visual Basic, -Command and Scripting Interpreter -| -Execution, -Execution - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Winhlp32_spawning_a_process|Winhlp32 Spawning a Process]] - -| -[https://attack.mitre.org/techniques/T1055/ T1055] -| -Process Injection -| -Defense Evasion, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Wscript_or_cscript_suspicious_child_process|Wscript Or Cscript Suspicious Child Process]] - -| -[https://attack.mitre.org/techniques/T1055/ T1055], -[https://attack.mitre.org/techniques/T1543/ T1543], -[https://attack.mitre.org/techniques/T1134.004/ T1134.004], -[https://attack.mitre.org/techniques/T1134/ T1134] -| -Process Injection, -Create or Modify System Process, -Parent PID Spoofing, -Access Token Manipulation -| -Defense Evasion, Privilege Escalation, -Persistence, Privilege Escalation, -Defense Evasion, Privilege Escalation, -Defense Evasion, Privilege Escalation - -| TTP -|} - -====Kill Chain Phase==== - -* Actions on Objectives - -* Exploitation - - -====Reference==== - -* https://success.trendmicro.com/solution/1123281-remcos-malware-information - -* https://attack.mitre.org/software/S0332/ - -* https://malpedia.caad.fkie.fraunhofer.de/details/win.remcos#:~:text=Remcos%20(acronym%20of%20Remote%20Control,used%20to%20remotely%20control%20computers.&text=Remcos%20can%20be%20used%20for,been%20used%20in%20hacking%20campaigns. - - -''version'': 1 -
-
- ----- - -===Revil ransomware=== -Leverage searches that allow you to detect and investigate unusual activities that might relate to the Revil ransomware, including looking for file writes associated with Revil, encrypting network shares, deleting shadow volume storage, registry key modification, deleting of security logs, and more. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint] -* '''Last Updated''': 2021-06-04 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Allow_network_discovery_in_firewall|Allow Network Discovery In Firewall]] - -| -[https://attack.mitre.org/techniques/T1562.007/ T1562.007], -[https://attack.mitre.org/techniques/T1562/ T1562] -| -Disable or Modify Cloud Firewall, -Impair Defenses -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Delete_shadowcopy_with_powershell|Delete ShadowCopy With PowerShell]] - -| -[https://attack.mitre.org/techniques/T1490/ T1490] -| -Inhibit System Recovery -| -Impact - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Disable_windows_behavior_monitoring|Disable Windows Behavior Monitoring]] - -| -[https://attack.mitre.org/techniques/T1562.001/ T1562.001], -[https://attack.mitre.org/techniques/T1562/ T1562] -| -Disable or Modify Tools, -Impair Defenses -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Modification_of_wallpaper|Modification Of Wallpaper]] - -| -[https://attack.mitre.org/techniques/T1491/ T1491] -| -Defacement -| -Impact - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Msmpeng_application_dll_side_loading|Msmpeng Application DLL Side Loading]] - -| -[https://attack.mitre.org/techniques/T1574.002/ T1574.002], -[https://attack.mitre.org/techniques/T1574/ T1574] -| -DLL Side-Loading, -Hijack Execution Flow -| -Persistence, Privilege Escalation, Defense Evasion, -Persistence, Privilege Escalation, Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Powershell_disable_security_monitoring|Powershell Disable Security Monitoring]] - -| -[https://attack.mitre.org/techniques/T1562.001/ T1562.001], -[https://attack.mitre.org/techniques/T1562/ T1562] -| -Disable or Modify Tools, -Impair Defenses -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Revil_common_exec_parameter|Revil Common Exec Parameter]] - -| -[https://attack.mitre.org/techniques/T1204/ T1204] -| -User Execution -| -Execution - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Revil_registry_entry|Revil Registry Entry]] - -| -[https://attack.mitre.org/techniques/T1112/ T1112] -| -Modify Registry -| -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Wbemprox_com_object_execution|Wbemprox COM Object Execution]] - -| -[https://attack.mitre.org/techniques/T1218/ T1218], -[https://attack.mitre.org/techniques/T1218.003/ T1218.003] -| -Signed Binary Proxy Execution, -CMSTP -| -Defense Evasion, -Defense Evasion - -| TTP -|} - -====Kill Chain Phase==== - -* Exploitation - - -====Reference==== - -* https://krebsonsecurity.com/2021/05/a-closer-look-at-the-darkside-ransomware-gang/ - -* https://www.mcafee.com/blogs/other-blogs/mcafee-labs/mcafee-atr-analyzes-sodinokibi-aka-revil-ransomware-as-a-service-what-the-code-tells-us/ - - -''version'': 1 -
-
- ----- - -===Ryuk ransomware=== -Leverage searches that allow you to detect and investigate unusual activities that might relate to the Ryuk ransomware, including looking for file writes associated with Ryuk, Stopping Security Access Manager, DisableAntiSpyware registry key modification, suspicious psexec use, and more. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint], [https://docs.splunk.com/Documentation/CIM/latest/User/NetworkTraffic Network_Traffic] -* '''Last Updated''': 2020-11-06 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Bcdedit_failure_recovery_modification|BCDEdit Failure Recovery Modification]] - -| -[https://attack.mitre.org/techniques/T1490/ T1490] -| -Inhibit System Recovery -| -Impact - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Common_ransomware_extensions|Common Ransomware Extensions]] - -| -[https://attack.mitre.org/techniques/T1485/ T1485] -| -Data Destruction -| -Impact - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Common_ransomware_notes|Common Ransomware Notes]] - -| -[https://attack.mitre.org/techniques/T1485/ T1485] -| -Data Destruction -| -Impact - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Nltest_domain_trust_discovery|NLTest Domain Trust Discovery]] - -| -[https://attack.mitre.org/techniques/T1482/ T1482] -| -Domain Trust Discovery -| -Discovery - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Remote_desktop_network_bruteforce|Remote Desktop Network Bruteforce]] - -| -[https://attack.mitre.org/techniques/T1021.001/ T1021.001], -[https://attack.mitre.org/techniques/T1021/ T1021] -| -Remote Desktop Protocol, -Remote Services -| -Lateral Movement, -Lateral Movement - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Remote_desktop_network_traffic|Remote Desktop Network Traffic]] - -| -[https://attack.mitre.org/techniques/T1021.001/ T1021.001], -[https://attack.mitre.org/techniques/T1021/ T1021] -| -Remote Desktop Protocol, -Remote Services -| -Lateral Movement, -Lateral Movement - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Ryuk_test_files_detected|Ryuk Test Files Detected]] - -| -[https://attack.mitre.org/techniques/T1486/ T1486] -| -Data Encrypted for Impact -| -Impact - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Ryuk_wake_on_lan_command|Ryuk Wake on LAN Command]] - -| -[https://attack.mitre.org/techniques/T1059/ T1059], -[https://attack.mitre.org/techniques/T1059.003/ T1059.003] -| -Command and Scripting Interpreter, -Windows Command Shell -| -Execution, -Execution - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Spike_in_file_writes|Spike in File Writes]] - -| -| -| - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Suspicious_scheduled_task_from_public_directory|Suspicious Scheduled Task from Public Directory]] - -| -[https://attack.mitre.org/techniques/T1053.005/ T1053.005], -[https://attack.mitre.org/techniques/T1053/ T1053] -| -Scheduled Task, -Scheduled Task/Job -| -Execution, Persistence, Privilege Escalation, -Execution, Persistence, Privilege Escalation - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Wbadmin_delete_system_backups|WBAdmin Delete System Backups]] - -| -[https://attack.mitre.org/techniques/T1490/ T1490] -| -Inhibit System Recovery -| -Impact - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Winevent_scheduled_task_created_within_public_path|WinEvent Scheduled Task Created Within Public Path]] - -| -[https://attack.mitre.org/techniques/T1053.005/ T1053.005], -[https://attack.mitre.org/techniques/T1053/ T1053] -| -Scheduled Task, -Scheduled Task/Job -| -Execution, Persistence, Privilege Escalation, -Execution, Persistence, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Winevent_scheduled_task_created_to_spawn_shell|WinEvent Scheduled Task Created to Spawn Shell]] - -| -[https://attack.mitre.org/techniques/T1053.005/ T1053.005], -[https://attack.mitre.org/techniques/T1053/ T1053] -| -Scheduled Task, -Scheduled Task/Job -| -Execution, Persistence, Privilege Escalation, -Execution, Persistence, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Windows_disableantispyware_registry|Windows DisableAntiSpyware Registry]] - -| -[https://attack.mitre.org/techniques/T1562.001/ T1562.001], -[https://attack.mitre.org/techniques/T1562/ T1562] -| -Disable or Modify Tools, -Impair Defenses -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Windows_security_account_manager_stopped|Windows Security Account Manager Stopped]] - -| -[https://attack.mitre.org/techniques/T1489/ T1489] -| -Service Stop -| -Impact - -| TTP -|} - -====Kill Chain Phase==== - -* Actions on Objectives - -* Delivery - -* Exploitation - -* Lateral Movement - -* Privilege Escalation - -* Reconnaissance - - -====Reference==== - -* https://www.splunk.com/en_us/blog/security/detecting-ryuk-using-splunk-attack-range.html - -* https://www.crowdstrike.com/blog/big-game-hunting-with-ryuk-another-lucrative-targeted-ransomware/ - -* https://us-cert.cisa.gov/ncas/alerts/aa20-302a - - -''version'': 1 -
-
- ----- - -===Samsam ransomware=== -Leverage searches that allow you to detect and investigate unusual activities that might relate to the SamSam ransomware, including looking for file writes associated with SamSam, RDP brute force attacks, the presence of files with SamSam ransomware extensions, suspicious psexec use, and more. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint], [https://docs.splunk.com/Documentation/CIM/latest/User/NetworkTraffic Network_Traffic], [https://docs.splunk.com/Documentation/CIM/latest/User/Web Web] -* '''Last Updated''': 2018-12-13 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Attacker_tools_on_endpoint|Attacker Tools On Endpoint]] - -| -[https://attack.mitre.org/techniques/T1036.005/ T1036.005], -[https://attack.mitre.org/techniques/T1036/ T1036], -[https://attack.mitre.org/techniques/T1003/ T1003], -[https://attack.mitre.org/techniques/T1595/ T1595] -| -Match Legitimate Name or Location, -Masquerading, -OS Credential Dumping, -Active Scanning -| -Defense Evasion, -Defense Evasion, -Credential Access, -Reconnaissance - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Batch_file_write_to_system32|Batch File Write to System32]] - -| -[https://attack.mitre.org/techniques/T1204/ T1204], -[https://attack.mitre.org/techniques/T1204.002/ T1204.002] -| -User Execution, -Malicious File -| -Execution, -Execution - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Common_ransomware_extensions|Common Ransomware Extensions]] - -| -[https://attack.mitre.org/techniques/T1485/ T1485] -| -Data Destruction -| -Impact - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Common_ransomware_notes|Common Ransomware Notes]] - -| -[https://attack.mitre.org/techniques/T1485/ T1485] -| -Data Destruction -| -Impact - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Deleting_shadow_copies|Deleting Shadow Copies]] - -| -[https://attack.mitre.org/techniques/T1490/ T1490] -| -Inhibit System Recovery -| -Impact - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_psexec_with_accepteula_flag|Detect PsExec With accepteula Flag]] - -| -[https://attack.mitre.org/techniques/T1021/ T1021], -[https://attack.mitre.org/techniques/T1021.002/ T1021.002] -| -Remote Services, -SMB/Windows Admin Shares -| -Lateral Movement, -Lateral Movement - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_renamed_psexec|Detect Renamed PSExec]] - -| -[https://attack.mitre.org/techniques/T1569/ T1569], -[https://attack.mitre.org/techniques/T1569.002/ T1569.002] -| -System Services, -Service Execution -| -Execution, -Execution - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Detect_attackers_scanning_for_vulnerable_jboss_servers|Detect attackers scanning for vulnerable JBoss servers]] - -| -[https://attack.mitre.org/techniques/T1082/ T1082] -| -System Information Discovery -| -Discovery - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_malicious_requests_to_exploit_jboss_servers|Detect malicious requests to exploit JBoss servers]] - -| -| -| - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#File_with_samsam_extension|File with Samsam Extension]] - -| -| -| - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Remote_desktop_network_bruteforce|Remote Desktop Network Bruteforce]] - -| -[https://attack.mitre.org/techniques/T1021.001/ T1021.001], -[https://attack.mitre.org/techniques/T1021/ T1021] -| -Remote Desktop Protocol, -Remote Services -| -Lateral Movement, -Lateral Movement - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Remote_desktop_network_traffic|Remote Desktop Network Traffic]] - -| -[https://attack.mitre.org/techniques/T1021.001/ T1021.001], -[https://attack.mitre.org/techniques/T1021/ T1021] -| -Remote Desktop Protocol, -Remote Services -| -Lateral Movement, -Lateral Movement - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Samsam_test_file_write|Samsam Test File Write]] - -| -[https://attack.mitre.org/techniques/T1486/ T1486] -| -Data Encrypted for Impact -| -Impact - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Spike_in_file_writes|Spike in File Writes]] - -| -| -| - -| Anomaly -|} - -====Kill Chain Phase==== - -* Actions on Objectives - -* Command and Control - -* Delivery - -* Execution - -* Exploitation - -* Installation - -* Lateral Movement - -* Reconnaissance - - -====Reference==== - -* https://www.crowdstrike.com/blog/an-in-depth-analysis-of-samsam-ransomware-and-boss-spider/ - -* https://nakedsecurity.sophos.com/2018/07/31/samsam-the-almost-6-million-ransomware/ - -* https://thehackernews.com/2018/07/samsam-ransomware-attacks.html - - -''version'': 1 -
-
- ----- - -===Trickbot=== -Leverage searches that allow you to detect and investigate unusual activities that might relate to the trickbot banking trojan, including looking for file writes associated with its payload, process injection, shellcode execution and data collection even in LDAP environment. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint] -* '''Last Updated''': 2021-04-20 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Account_discovery_with_net_app|Account Discovery With Net App]] - -| -[https://attack.mitre.org/techniques/T1087.002/ T1087.002], -[https://attack.mitre.org/techniques/T1087/ T1087] -| -Domain Account, -Account Discovery -| -Discovery, -Discovery - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Attempt_to_stop_security_service|Attempt To Stop Security Service]] - -| -[https://attack.mitre.org/techniques/T1562.001/ T1562.001], -[https://attack.mitre.org/techniques/T1562/ T1562] -| -Disable or Modify Tools, -Impair Defenses -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Cobalt_strike_named_pipes|Cobalt Strike Named Pipes]] - -| -[https://attack.mitre.org/techniques/T1055/ T1055] -| -Process Injection -| -Defense Evasion, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Mshta_spawning_rundll32_or_regsvr32_process|Mshta spawning Rundll32 OR Regsvr32 Process]] - -| -[https://attack.mitre.org/techniques/T1218/ T1218], -[https://attack.mitre.org/techniques/T1218.005/ T1218.005] -| -Signed Binary Proxy Execution, -Mshta -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Office_application_spawn_rundll32_process|Office Application Spawn rundll32 process]] - -| -[https://attack.mitre.org/techniques/T1566/ T1566], -[https://attack.mitre.org/techniques/T1566.001/ T1566.001] -| -Phishing, -Spearphishing Attachment -| -Initial Access, -Initial Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Office_document_executing_macro_code|Office Document Executing Macro Code]] - -| -[https://attack.mitre.org/techniques/T1566/ T1566], -[https://attack.mitre.org/techniques/T1566.001/ T1566.001] -| -Phishing, -Spearphishing Attachment -| -Initial Access, -Initial Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Office_product_spawn_cmd_process|Office Product Spawn CMD Process]] - -| -[https://attack.mitre.org/techniques/T1218/ T1218], -[https://attack.mitre.org/techniques/T1218.005/ T1218.005] -| -Signed Binary Proxy Execution, -Mshta -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Powershell_remote_thread_to_known_windows_process|Powershell Remote Thread To Known Windows Process]] - -| -[https://attack.mitre.org/techniques/T1055/ T1055] -| -Process Injection -| -Defense Evasion, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Schedule_task_with_rundll32_command_trigger|Schedule Task with Rundll32 Command Trigger]] - -| -[https://attack.mitre.org/techniques/T1053/ T1053] -| -Scheduled Task/Job -| -Execution, Persistence, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Suspicious_rundll32_startw|Suspicious Rundll32 StartW]] - -| -[https://attack.mitre.org/techniques/T1218/ T1218], -[https://attack.mitre.org/techniques/T1218.011/ T1218.011] -| -Signed Binary Proxy Execution, -Rundll32 -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Trickbot_named_pipe|Trickbot Named Pipe]] - -| -[https://attack.mitre.org/techniques/T1055/ T1055] -| -Process Injection -| -Defense Evasion, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Wermgr_process_connecting_to_ip_check_web_services|Wermgr Process Connecting To IP Check Web Services]] - -| -[https://attack.mitre.org/techniques/T1590/ T1590], -[https://attack.mitre.org/techniques/T1590.005/ T1590.005] -| -Gather Victim Network Information, -IP Addresses -| -Reconnaissance, -Reconnaissance - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Wermgr_process_create_executable_file|Wermgr Process Create Executable File]] - -| -[https://attack.mitre.org/techniques/T1027/ T1027] -| -Obfuscated Files or Information -| -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Wermgr_process_spawned_cmd_or_powershell_process|Wermgr Process Spawned CMD Or Powershell Process]] - -| -[https://attack.mitre.org/techniques/T1059/ T1059] -| -Command and Scripting Interpreter -| -Execution - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Write_executable_in_smb_share|Write Executable in SMB Share]] - -| -[https://attack.mitre.org/techniques/T1021/ T1021], -[https://attack.mitre.org/techniques/T1021.002/ T1021.002] -| -Remote Services, -SMB/Windows Admin Shares -| -Lateral Movement, -Lateral Movement - -| TTP -|} - -====Kill Chain Phase==== - -* Actions on Objectives - -* Exploitation - -* Installation - -* Lateral Movement - -* Reconnaissance - - -====Reference==== - -* https://en.wikipedia.org/wiki/Trickbot - -* https://blog.checkpoint.com/2021/03/11/february-2021s-most-wanted-malware-trickbot-takes-over-following-emotet-shutdown/ - - -''version'': 1 -
-
- ----- - -===Unusual processes=== -Quickly identify systems running new or unusual processes in your environment that could be indicators of suspicious activity. Processes run from unusual locations, those with conspicuously long command lines, and rare executables are all examples of activities that may warrant deeper investigation. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint] -* '''Last Updated''': 2020-02-04 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Attacker_tools_on_endpoint|Attacker Tools On Endpoint]] - -| -[https://attack.mitre.org/techniques/T1036.005/ T1036.005], -[https://attack.mitre.org/techniques/T1036/ T1036], -[https://attack.mitre.org/techniques/T1003/ T1003], -[https://attack.mitre.org/techniques/T1595/ T1595] -| -Match Legitimate Name or Location, -Masquerading, -OS Credential Dumping, -Active Scanning -| -Defense Evasion, -Defense Evasion, -Credential Access, -Reconnaissance - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Credential_extraction_indicative_of_fgdump_and_cachedump_with_s_option|Credential Extraction indicative of FGDump and CacheDump with s option]] - -| -[https://attack.mitre.org/techniques/T1003/ T1003] -| -OS Credential Dumping -| -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Credential_extraction_indicative_of_fgdump_and_cachedump_with_v_option|Credential Extraction indicative of FGDump and CacheDump with v option]] - -| -[https://attack.mitre.org/techniques/T1003/ T1003] -| -OS Credential Dumping -| -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Credential_extraction_indicative_of_use_of_mimikatz_modules|Credential Extraction indicative of use of Mimikatz modules]] - -| -[https://attack.mitre.org/techniques/T1003/ T1003] -| -OS Credential Dumping -| -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Credential_extraction_native_microsoft_debuggers_peek_into_the_kernel|Credential Extraction native Microsoft debuggers peek into the kernel]] - -| -[https://attack.mitre.org/techniques/T1003/ T1003] -| -OS Credential Dumping -| -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Credential_extraction_native_microsoft_debuggers_via_z_command_line_option|Credential Extraction native Microsoft debuggers via z command line option]] - -| -[https://attack.mitre.org/techniques/T1003/ T1003] -| -OS Credential Dumping -| -Credential Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_rare_executables|Detect Rare Executables]] - -| -| -| - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Detect_processes_used_for_system_network_configuration_discovery|Detect processes used for System Network Configuration Discovery]] - -| -[https://attack.mitre.org/techniques/T1016/ T1016] -| -System Network Configuration Discovery -| -Discovery - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#First_time_seen_command_line_argument|First time seen command line argument]] - -| -[https://attack.mitre.org/techniques/T1059/ T1059], -[https://attack.mitre.org/techniques/T1117/ T1117], -[https://attack.mitre.org/techniques/T1202/ T1202] -| -Command and Scripting Interpreter, -Regsvr32, -Indirect Command Execution -| -Execution, -, -Defense Evasion - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#More_than_usual_number_of_lolbas_applications_in_short_time_period|More than usual number of LOLBAS applications in short time period]] - -| -[https://attack.mitre.org/techniques/T1059/ T1059], -[https://attack.mitre.org/techniques/T1053/ T1053] -| -Command and Scripting Interpreter, -Scheduled Task/Job -| -Execution, -Execution, Persistence, Privilege Escalation - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Rare_parent-child_process_relationship|Rare Parent-Child Process Relationship]] - -| -[https://attack.mitre.org/techniques/T1203/ T1203], -[https://attack.mitre.org/techniques/T1059/ T1059], -[https://attack.mitre.org/techniques/T1053/ T1053], -[https://attack.mitre.org/techniques/T1072/ T1072] -| -Exploitation for Client Execution, -Command and Scripting Interpreter, -Scheduled Task/Job, -Software Deployment Tools -| -Execution, -Execution, -Execution, Persistence, Privilege Escalation, -Execution, Lateral Movement - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Rundll_loading_dll_by_ordinal|RunDLL Loading DLL By Ordinal]] - -| -[https://attack.mitre.org/techniques/T1218/ T1218], -[https://attack.mitre.org/techniques/T1218.011/ T1218.011] -| -Signed Binary Proxy Execution, -Rundll32 -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Rundll32_shimcache_flush|Rundll32 Shimcache Flush]] - -| -[https://attack.mitre.org/techniques/T1112/ T1112] -| -Modify Registry -| -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Suspicious_copy_on_system32|Suspicious Copy on System32]] - -| -[https://attack.mitre.org/techniques/T1036.003/ T1036.003], -[https://attack.mitre.org/techniques/T1036/ T1036] -| -Rename System Utilities, -Masquerading -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#System_processes_run_from_unexpected_locations|System Processes Run From Unexpected Locations]] - -| -[https://attack.mitre.org/techniques/T1036/ T1036], -[https://attack.mitre.org/techniques/T1036.003/ T1036.003] -| -Masquerading, -Rename System Utilities -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Unusually_long_command_line|Unusually Long Command Line]] - -| -| -| - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Unusually_long_command_line|Unusually Long Command Line]] - -| -| -| - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Unusually_long_command_line_-_mltk|Unusually Long Command Line - MLTK]] - -| -| -| - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Verclsid_clsid_execution|Verclsid CLSID Execution]] - -| -[https://attack.mitre.org/techniques/T1218.012/ T1218.012], -[https://attack.mitre.org/techniques/T1218/ T1218] -| -Verclsid, -Signed Binary Proxy Execution -| -Defense Evasion, -Defense Evasion - -| Hunting -|- -| [[Documentation:ESSOC:detections:Detections#Winrm_spawning_a_process|WinRM Spawning a Process]] - -| -[https://attack.mitre.org/techniques/T1190/ T1190] -| -Exploit Public-Facing Application -| -Initial Access - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Wscript_or_cscript_suspicious_child_process|Wscript Or Cscript Suspicious Child Process]] - -| -[https://attack.mitre.org/techniques/T1055/ T1055], -[https://attack.mitre.org/techniques/T1543/ T1543], -[https://attack.mitre.org/techniques/T1134.004/ T1134.004], -[https://attack.mitre.org/techniques/T1134/ T1134] -| -Process Injection, -Create or Modify System Process, -Parent PID Spoofing, -Access Token Manipulation -| -Defense Evasion, Privilege Escalation, -Persistence, Privilege Escalation, -Defense Evasion, Privilege Escalation, -Defense Evasion, Privilege Escalation - -| TTP -|} - -====Kill Chain Phase==== - -* Actions on Objectives - -* Command and Control - -* Denial of Service - -* Exploitation - -* Installation - -* Privilege Escalation - - -====Reference==== - -* https://www.fireeye.com/blog/threat-research/2017/08/monitoring-windows-console-activity-part-two.html - -* https://www.splunk.com/pdfs/technical-briefs/advanced-threat-detection-and-response-tech-brief.pdf - -* https://www.sans.org/reading-room/whitepapers/logging/detecting-security-incidents-windows-workstation-event-logs-34262 - - -''version'': 2 -
-
- ----- - -===Windows file extension and association abuse=== -Detect and investigate suspected abuse of file extensions and Windows file associations. Some of the malicious behaviors involved may include inserting spaces before file extensions or prepending the file extension with a different one, among other techniques. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint] -* '''Last Updated''': 2018-01-26 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Execution_of_file_with_multiple_extensions|Execution of File with Multiple Extensions]] - -| -[https://attack.mitre.org/techniques/T1036/ T1036], -[https://attack.mitre.org/techniques/T1036.003/ T1036.003] -| -Masquerading, -Rename System Utilities -| -Defense Evasion, -Defense Evasion - -| TTP -|} - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Reference==== - -* https://blog.malwarebytes.com/cybercrime/2013/12/file-extensions-2/ - -* https://attack.mitre.org/wiki/Technique/T1042 - - -''version'': 1 -
-
- ----- - -===Windows service abuse=== -Windows services are often used by attackers for persistence and the ability to load drivers or otherwise interact with the Windows kernel. This Analytic Story helps you monitor your environment for indications that Windows services are being modified or created in a suspicious manner. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint] -* '''Last Updated''': 2017-11-02 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#First_time_seen_running_windows_service|First Time Seen Running Windows Service]] - -| -[https://attack.mitre.org/techniques/T1569/ T1569], -[https://attack.mitre.org/techniques/T1569.002/ T1569.002] -| -System Services, -Service Execution -| -Execution, -Execution - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Illegal_service_and_process_control_via_mimikatz_modules|Illegal Service and Process Control via Mimikatz modules]] - -| -[https://attack.mitre.org/techniques/T1055/ T1055], -[https://attack.mitre.org/techniques/T1106/ T1106], -[https://attack.mitre.org/techniques/T1569/ T1569] -| -Process Injection, -Native API, -System Services -| -Defense Evasion, Privilege Escalation, -Execution, -Execution - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Illegal_service_and_process_control_via_powersploit_modules|Illegal Service and Process Control via PowerSploit modules]] - -| -[https://attack.mitre.org/techniques/T1055/ T1055], -[https://attack.mitre.org/techniques/T1106/ T1106], -[https://attack.mitre.org/techniques/T1569/ T1569] -| -Process Injection, -Native API, -System Services -| -Defense Evasion, Privilege Escalation, -Execution, -Execution - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Reg_exe_manipulating_windows_services_registry_keys|Reg exe Manipulating Windows Services Registry Keys]] - -| -[https://attack.mitre.org/techniques/T1574.011/ T1574.011], -[https://attack.mitre.org/techniques/T1574/ T1574] -| -Services Registry Permissions Weakness, -Hijack Execution Flow -| -Persistence, Privilege Escalation, Defense Evasion, -Persistence, Privilege Escalation, Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Sc_exe_manipulating_windows_services|Sc exe Manipulating Windows Services]] - -| -[https://attack.mitre.org/techniques/T1543.003/ T1543.003], -[https://attack.mitre.org/techniques/T1543/ T1543] -| -Windows Service, -Create or Modify System Process -| -Persistence, Privilege Escalation, -Persistence, Privilege Escalation - -| TTP -|} - -====Kill Chain Phase==== - -* Actions on Objectives - -* Installation - - -====Reference==== - -* https://attack.mitre.org/wiki/Technique/T1050 - -* https://attack.mitre.org/wiki/Technique/T1031 - - -''version'': 3 -
-
- ----- - -===Xmrig=== -Leverage searches that allow you to detect and investigate unusual activities that might relate to the xmrig monero, including looking for file writes associated with its payload, process command-line, defense evasion (killing services, deleting users, modifying files or folder permission, killing other malware or other coin miner) and hacking tools including Telegram as mean of command and control (C2) to download other files. Adversaries may leverage the resources of co-opted systems in order to solve resource intensive problems which may impact system and/or hosted service availability. One common purpose for Resource Hijacking is to validate transactions of cryptocurrency networks and earn virtual currency. Adversaries may consume enough system resources to negatively impact and/or cause affected machines to become unresponsive. (1) Servers and cloud-based (2) systems are common targets because of the high potential for available resources, but user endpoint systems may also be compromised and used for Resource Hijacking and cryptocurrency mining. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint] -* '''Last Updated''': 2021-05-07 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Attacker_tools_on_endpoint|Attacker Tools On Endpoint]] - -| -[https://attack.mitre.org/techniques/T1036.005/ T1036.005], -[https://attack.mitre.org/techniques/T1036/ T1036], -[https://attack.mitre.org/techniques/T1003/ T1003], -[https://attack.mitre.org/techniques/T1595/ T1595] -| -Match Legitimate Name or Location, -Masquerading, -OS Credential Dumping, -Active Scanning -| -Defense Evasion, -Defense Evasion, -Credential Access, -Reconnaissance - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Attempt_to_disable_services|Attempt To Disable Services]] - -| -[https://attack.mitre.org/techniques/T1489/ T1489] -| -Service Stop -| -Impact - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Attempt_to_delete_services|Attempt To delete Services]] - -| -[https://attack.mitre.org/techniques/T1489/ T1489] -| -Service Stop -| -Impact - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Delete_a_net_user|Delete A Net User]] - -| -[https://attack.mitre.org/techniques/T1489/ T1489] -| -Service Stop -| -Impact - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Deleting_of_net_users|Deleting Of Net Users]] - -| -[https://attack.mitre.org/techniques/T1531/ T1531] -| -Account Access Removal -| -Impact - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Deny_permission_using_cacls_utility|Deny Permission using Cacls Utility]] - -| -[https://attack.mitre.org/techniques/T1222/ T1222] -| -File and Directory Permissions Modification -| -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Disable_net_user_account|Disable Net User Account]] - -| -[https://attack.mitre.org/techniques/T1489/ T1489] -| -Service Stop -| -Impact - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Disable_windows_app_hotkeys|Disable Windows App Hotkeys]] - -| -[https://attack.mitre.org/techniques/T1562.001/ T1562.001], -[https://attack.mitre.org/techniques/T1562/ T1562] -| -Disable or Modify Tools, -Impair Defenses -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Disabling_net_user_account|Disabling Net User Account]] - -| -[https://attack.mitre.org/techniques/T1531/ T1531] -| -Account Access Removal -| -Impact - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Download_files_using_telegram|Download Files Using Telegram]] - -| -[https://attack.mitre.org/techniques/T1105/ T1105] -| -Ingress Tool Transfer -| -Command And Control - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Enumerate_users_local_group_using_telegram|Enumerate Users Local Group Using Telegram]] - -| -[https://attack.mitre.org/techniques/T1087/ T1087] -| -Account Discovery -| -Discovery - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Excessive_attempt_to_disable_services|Excessive Attempt To Disable Services]] - -| -[https://attack.mitre.org/techniques/T1489/ T1489] -| -Service Stop -| -Impact - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Excessive_service_stop_attempt|Excessive Service Stop Attempt]] - -| -[https://attack.mitre.org/techniques/T1489/ T1489] -| -Service Stop -| -Impact - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Excessive_usage_of_cacls_app|Excessive Usage Of Cacls App]] - -| -[https://attack.mitre.org/techniques/T1222/ T1222] -| -File and Directory Permissions Modification -| -Defense Evasion - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Excessive_usage_of_net_app|Excessive Usage Of Net App]] - -| -[https://attack.mitre.org/techniques/T1531/ T1531] -| -Account Access Removal -| -Impact - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Excessive_usage_of_taskkill|Excessive Usage Of Taskkill]] - -| -[https://attack.mitre.org/techniques/T1562.001/ T1562.001], -[https://attack.mitre.org/techniques/T1562/ T1562] -| -Disable or Modify Tools, -Impair Defenses -| -Defense Evasion, -Defense Evasion - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Executables_or_script_creation_in_suspicious_path|Executables Or Script Creation In Suspicious Path]] - -| -[https://attack.mitre.org/techniques/T1036/ T1036] -| -Masquerading -| -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Grant_permission_using_cacls_utility|Grant Permission Using Cacls Utility]] - -| -[https://attack.mitre.org/techniques/T1222/ T1222] -| -File and Directory Permissions Modification -| -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Hide_user_account_from_sign-in_screen|Hide User Account From Sign-In Screen]] - -| -[https://attack.mitre.org/techniques/T1562.001/ T1562.001], -[https://attack.mitre.org/techniques/T1562/ T1562] -| -Disable or Modify Tools, -Impair Defenses -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Icacls_grant_command|ICACLS Grant Command]] - -| -[https://attack.mitre.org/techniques/T1222/ T1222] -| -File and Directory Permissions Modification -| -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Icacls_deny_command|Icacls Deny Command]] - -| -[https://attack.mitre.org/techniques/T1222/ T1222] -| -File and Directory Permissions Modification -| -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Modify_acl_permission_to_files_or_folder|Modify ACL permission To Files Or Folder]] - -| -[https://attack.mitre.org/techniques/T1222/ T1222] -| -File and Directory Permissions Modification -| -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Modify_acls_permission_of_files_or_folders|Modify ACLs Permission Of Files Or Folders]] - -| -[https://attack.mitre.org/techniques/T1222/ T1222] -| -File and Directory Permissions Modification -| -Defense Evasion - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Process_kill_base_on_file_path|Process Kill Base On File Path]] - -| -[https://attack.mitre.org/techniques/T1562.001/ T1562.001], -[https://attack.mitre.org/techniques/T1562/ T1562] -| -Disable or Modify Tools, -Impair Defenses -| -Defense Evasion, -Defense Evasion - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Schtasks_run_task_on_demand|Schtasks Run Task On Demand]] - -| -[https://attack.mitre.org/techniques/T1053/ T1053] -| -Scheduled Task/Job -| -Execution, Persistence, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Suspicious_driver_loaded_path|Suspicious Driver Loaded Path]] - -| -[https://attack.mitre.org/techniques/T1543.003/ T1543.003], -[https://attack.mitre.org/techniques/T1543/ T1543] -| -Windows Service, -Create or Modify System Process -| -Persistence, Privilege Escalation, -Persistence, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Suspicious_process_file_path|Suspicious Process File Path]] - -| -[https://attack.mitre.org/techniques/T1543/ T1543] -| -Create or Modify System Process -| -Persistence, Privilege Escalation - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Xmrig_driver_loaded|XMRIG Driver Loaded]] - -| -[https://attack.mitre.org/techniques/T1543.003/ T1543.003], -[https://attack.mitre.org/techniques/T1543/ T1543] -| -Windows Service, -Create or Modify System Process -| -Persistence, Privilege Escalation, -Persistence, Privilege Escalation - -| TTP -|} - -====Kill Chain Phase==== - -* Actions on Objectives - -* Command and Control - -* Exploitation - -* Installation - - -====Reference==== - -* https://github.com/xmrig/xmrig - -* https://www.getmonero.org/resources/user-guides/mine-to-pool.html - -* https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ - -* https://blog.checkpoint.com/2021/03/11/february-2021s-most-wanted-malware-trickbot-takes-over-following-emotet-shutdown/ - - -''version'': 1 -
-
- ----- - - - -==Vulnerability== - - -===Apache struts vulnerability=== -Detect and investigate activities--such as unusually long `Content-Type` length, suspicious java classes and web servers executing suspicious processes--consistent with attempts to exploit Apache Struts vulnerabilities. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint Endpoint] -* '''Last Updated''': 2018-12-06 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Suspicious_java_classes|Suspicious Java Classes]] - -| -| -| - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Unusually_long_content-type_length|Unusually Long Content-Type Length]] - -| -| -| - -| Anomaly -|- -| [[Documentation:ESSOC:detections:Detections#Web_servers_executing_suspicious_processes|Web Servers Executing Suspicious Processes]] - -| -[https://attack.mitre.org/techniques/T1082/ T1082] -| -System Information Discovery -| -Discovery - -| TTP -|} - -====Kill Chain Phase==== - -* Actions on Objectives - -* Delivery - -* Exploitation - - -====Reference==== - -* https://github.com/SpiderLabs/owasp-modsecurity-crs/blob/v3.2/dev/rules/REQUEST-944-APPLICATION-ATTACK-JAVA.conf - - -''version'': 1 -
-
- ----- - -===Jboss vulnerability=== -In March of 2016, adversaries were seen using JexBoss--an open-source utility used for testing and exploiting JBoss application servers. These searches help detect evidence of these attacks, such as network connections to external resources or web services spawning atypical child processes, among others. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''':[https://docs.splunk.com/Documentation/CIM/latest/User/Web Web] -* '''Last Updated''': 2017-09-14 -* '''Use Case''': Advanced Threat Detection - -
-
- -====Detection Profile==== -{| -! style="text-align:left;"| name -! ID -! Technique -! Tactic -! Type -|- -| [[Documentation:ESSOC:detections:Detections#Detect_attackers_scanning_for_vulnerable_jboss_servers|Detect attackers scanning for vulnerable JBoss servers]] - -| -[https://attack.mitre.org/techniques/T1082/ T1082] -| -System Information Discovery -| -Discovery - -| TTP -|- -| [[Documentation:ESSOC:detections:Detections#Detect_malicious_requests_to_exploit_jboss_servers|Detect malicious requests to exploit JBoss servers]] - -| -| -| - -| TTP -|} - -====Kill Chain Phase==== - -* Delivery - -* Reconnaissance - - -====Reference==== - -* http://www.deependresearch.org/2016/04/jboss-exploits-view-from-victim.html - - -''version'': 1 -
-
- ----- - - - - -
-#############
-# Automatically generated by doc_gen.py in https://github.com/splunk/security_content
-# On Date: 2021-10-28 22:46:01.071905 UTC
-# Author: Splunk Security Research
-# Contact: research@splunk.com
-#############
-
\ No newline at end of file From 7f08b301abae9a07c3ece4f8200d0c500f19050c Mon Sep 17 00:00:00 2001 From: d1vious Date: Tue, 16 Aug 2022 15:24:07 -0400 Subject: [PATCH 2/3] cleaning up CI --- .github/workflows/build-and-validate.yml | 15 --------------- 1 file changed, 15 deletions(-) diff --git a/.github/workflows/build-and-validate.yml b/.github/workflows/build-and-validate.yml index cf3bf42fba..086323d8ba 100644 --- a/.github/workflows/build-and-validate.yml +++ b/.github/workflows/build-and-validate.yml @@ -106,16 +106,6 @@ jobs: with: node-version: '14' #can easily be changed to a different version - - name: contentctl docgen - run: | - source .venv/bin/activate - python contentctl.py -p . --skip_enrichment docgen -o docs - #Now generate the spec docs - npm install -g @adobe/jsonschema2md - jsonschema2md -d spec -o docs/spec -f yaml -e spec.json -x - - #Clean up extra properties on docs - rm -rf docs/spec/*-*.md - - name: contentctl generate run: | source .venv/bin/activate @@ -350,11 +340,6 @@ jobs: run: | echo "::set-output name=branch::${GITHUB_REF#refs/heads/}" - - name: Run doc-gen - run: | - source venv/bin/activate - python3 contentctl.py -p . docgen -o docs - - name: Run reporting run: | source venv/bin/activate From bd8ffeeb52090d5c8ea455a64fa23631fc8c16cf Mon Sep 17 00:00:00 2001 From: d1vious Date: Tue, 16 Aug 2022 15:29:43 -0400 Subject: [PATCH 3/3] removing playbooks --- docs/_playbooks/hunting.md | 45 -------------------------------------- 1 file changed, 45 deletions(-) delete mode 100644 docs/_playbooks/hunting.md diff --git a/docs/_playbooks/hunting.md b/docs/_playbooks/hunting.md deleted file mode 100644 index 1446023c79..0000000000 --- a/docs/_playbooks/hunting.md +++ /dev/null @@ -1,45 +0,0 @@ ---- -title: "Hunting" -last_modified_at: 2021-01-21 -toc: true -toc_label: "" -tags: - - Investigation - - Splunk SOAR - - Splunk - - Reversing Labs - - CarbonBlack Response - - Threat Grid - - Falcon Host API ---- - -[Try in Splunk SOAR](https://www.splunk.com/en_us/software/splunk-security-orchestration-and-automation.html){: .btn .btn--success} - -#### Description - -The hunting Playbook queries a number of internal security technologies in order to determine if any of the artifacts present in your data source have been observed in your environment. - -- **Type**: Investigation -- **Product**: Splunk SOAR -- **Apps**: [Splunk](https://splunkbase.splunk.com/apps/#/search/Splunk/product/soar), [Reversing Labs](https://splunkbase.splunk.com/apps/#/search/Reversing Labs/product/soar), [CarbonBlack Response](https://splunkbase.splunk.com/apps/#/search/CarbonBlack Response/product/soar), [Threat Grid](https://splunkbase.splunk.com/apps/#/search/Threat Grid/product/soar), [Falcon Host API](https://splunkbase.splunk.com/apps/#/search/Falcon Host API/product/soar) -- **Last Updated**: 2021-01-21 -- **Author**: Philip Royer, Splunk -- **ID**: fb3edc76-ff2b-48b0-5f6f-63da6351ad63 - -#### Associated Detections - - -#### How To Implement -Be sure to update asset naming to reflect the asset names configured in your environment. - -#### Playbooks -![](https://raw.githubusercontent.com/splunk/security_content/develop/playbooks/hunting.png) - -#### Required field - - -#### Reference - - - -[*source*](https://github.com/splunk/security_content/tree/develop/playbooks/hunting.yml) \| *version*: **1** \ No newline at end of file